Loading the catalogue…
Loading the catalogue…
Arcee AI is a privately held US lab founded in 2023, headquartered in the United States, and subject to full CLOUD Act and FISA 702 jurisdiction — making it a standard US data-sovereignty risk for EU regulated customers, regardless of on-premises deployment of open weights. The lab is strongly oriented towards open-weight releases, with its flagship Trinity family published under Apache 2.0, though its AFM-4.5B model uses a custom revenue-capped licence that restricts use by larger enterprises. No published EU AI Act compliance statement, no SOC 2 or ISO 27001 certifications, and no EU legal entity have been found; customers deploying the hosted API should note that third-party sub-processors are acknowledged in the Terms of Service with no EU data-residency commitments.
CLOUD Act and FISA 702 exposure: Arcee AI is a US-incorporated entity (Arcee AI, Inc.) and is fully subject to US compelled-disclosure laws. The current Stav catalogue incorrectly records cloud_act_exposure as 'false'. EU regulated-sector customers must treat Arcee AI as CLOUD Act exposed, even when deploying open weights on-premises (inference-side risk is mitigated by self-hosting, but training data provenance and any use of the hosted API are not).
No accessible privacy policy at time of research (iubenda-hosted policy deactivated), no published DPA, no EU representative, no SCCs or DPF certification, and no GDPR-compliant data transfer mechanism identified. This is a significant gap for EU regulated-sector customers who must rely on Article 28 contracts and data transfer documentation.
Terms of Service acknowledge unspecified third-party sub-processors who 'may access, use, and store any Inputs pursuant to their own terms and privacy policies'. No sub-processor list, no DPA requirement on sub-processors, and no EU data-residency commitment are present.
No EU AI Act compliance statement, no GPAI technical documentation in the Article 53 format, no training data copyright summary published, and no AI Pact or Code of Practice participation confirmed. GPAI obligations have applied since August 2025; Arcee's models are placed on the EU market (available on HuggingFace and API).
No published security certifications (SOC 2, ISO 27001), no bug bounty programme, and no responsible disclosure policy found. For a lab operating a production inference API processing enterprise inputs, the absence of third-party security assurance is a gap.
Investors include Prosperity7 Ventures and Aramco Ventures, both affiliates of Saudi Aramco (a Saudi state-owned enterprise). While this does not imply operational control or create regulatory exposure, it is a governance consideration for regulated sectors with restrictions on state-linked foreign ownership chains.
Trinity-Large-Thinking (399B parameters) was trained in a 33-day run on 2048 B300 GPUs. The training compute could approach — though likely falls below — the 10^25 FLOP threshold for EU AI Act systemic risk classification. Arcee has not published compute figures, making formal classification impossible without further disclosure.
Stav AI Act assessment
Editorial assessment, not legal advice. Stav's risk ratings, scores, and verdicts are our own analysis of publicly available information and may be incomplete or out of date. Verify independently before making compliance or procurement decisions.
Flagship Trinity family models (including Trinity-Large-Thinking at 399B parameters) released under Apache 2.0 — one of the most permissive licences available, with no usage restrictions on commercial deployment, fine-tuning, or redistribution.
Arcee publishes technical blog posts and formal technical reports (e.g., 'Arcee Trinity Large Technical Report' on HuggingFace) detailing training methodologies, data curation partnerships, and model architecture decisions.
Pioneers and maintainers of MergeKit, an open-source model merging library with 3,000+ GitHub stars, actively developed in collaboration with HuggingFace. Demonstrates genuine community contribution beyond commercial model releases.
Strong public endorsement from HuggingFace CEO Clément Delangue, cited in VentureBeat (April 2026), recognising Arcee as a leader in open-source AI. Included in CBInsights AI 100 (2025) and featured in Bloomberg (2024).
AFM-4.5B training data practices partially disclosed: 8 trillion training tokens, curated by DatologyAI using model-based quality filtering and embedding-based curation. This is above average for the industry in terms of data sourcing transparency.
Terms of Service explicitly prohibit users from submitting personally identifiable information (home address, phone, email, ID numbers, credit card data, health information) as inputs — a basic but meaningful data minimisation control.
Actively operating lab with recent major model releases (Trinity-Large-Thinking, April 2026; AFM-4.5B, 2025), venture-backed with a Series A round, a growing investor roster, and a reported team spanning five continents. No signs of contraction or wind-down.
Privacy policy review
Creator profile
Arcee AI is a United States entity. Training data and weights produced under United States-jurisdiction are covered by the CLOUD Act.
Exposed on training. Inference is unaffected when hosted on Stav infrastructure inside the EEA.
Stav compliance has not yet scored Arcee AI. Scores are published once the policy review and infrastructure assessment complete.
Findings
Citations gathered when the Compliance Curator last reviewed this creator’s public-facing documents. Grouped by source so the picture stays auditable.
“When we founded Arcee AI in 2023, we had one goal in mind: to make world-class small language models (SLMs) available to companies across all industri...”
“The weights are available on Hugging Face under Apache 2.0. We are releasing it this way because we continue to believe that permissive American open ...”
“... We’re also making a change to our original licensing plan. Instead of the previously planned CC-BY-NC license, AFM-4.5B is now released under the ...”
Arcee.ai is headquartered in Miami, United States.
When we founded Arcee AI in 2023, we had one goal in mind: to make world-class small language models (SLMs) available to companies across all industri...
The weights are available on Hugging Face under Apache 2.0. We are releasing it this way because we continue to believe that permissive American open ...
... We’re also making a change to our original licensing plan. Instead of the previously planned CC-BY-NC license, AFM-4.5B is now released under the ...
Aramco Ventures, Guidepoint Global, Hitachi Ventures, M12, and Prosperity7 Ventures are 5 of 21 investors who have invested in Arcee AI.
Without prejudice to any of Arcee AI’s other rights, You acknowledge and agree Arcee AI leverages certain third parties to provide or host the Models,...
Arcee.ai is headquartered in Miami, United States.
When we founded Arcee AI in 2023, we had one goal in mind: to make world-class small language models (SLMs) available to companies across all industri...
The weights are available on Hugging Face under Apache 2.0. We are releasing it this way because we continue to believe that permissive American open ...
... We’re also making a change to our original licensing plan. Instead of the previously planned CC-BY-NC license, AFM-4.5B is now released under the ...
Aramco Ventures, Guidepoint Global, Hitachi Ventures, M12, and Prosperity7 Ventures are 5 of 21 investors who have invested in Arcee AI.
Without prejudice to any of Arcee AI’s other rights, You acknowledge and agree Arcee AI leverages certain third parties to provide or host the Models,...
Arcee's own deployment documentation explicitly supports on-premises and private VPC deployment (vLLM, SGLang, llama.cpp), enabling EU customers to self-host open-weight models and avoid inference-side CLOUD Act exposure entirely.
Published safeguards & certifications
“Without prejudice to any of Arcee AI’s other rights, You acknowledge and agree Arcee AI leverages certain third parties to provide or host the Models,...”
“Aramco Ventures, Guidepoint Global, Hitachi Ventures, M12, and Prosperity7 Ventures are 5 of 21 investors who have invested in Arcee AI. ”
“Arcee.ai is headquartered in Miami, United States. ”
As classified under Regulation (EU) 2024/1689.
Provider of GPAI model (general-purpose).