Open Weights Licensing in 2026: What You Can Actually Ship

Open weights licensing 2026: ship without asking vs read the footnotes comparison

11 min read·Published Sep 29, 2026

0 0 votes
Article Rating

Part of Start Here

This article is not legal advice. It is a survey of published license terms for open weight models as of late September 2026, written for working developers. License terms change between releases, and only your own lawyer can tell you what a specific license means for your specific product. Where a term could not be verified from a primary source, this article says so.

Open weights are not open source

The Open Source Definition maintained by the Open Source Initiative requires free redistribution, access to source code, and permission for derived works, among other conditions. A model can be downloadable by anyone and still fail that definition, because the weights are released under a custom license that reserves conditions the definition does not allow. The Hugging Face API entries for the 2026 frontier flagships make this visible: GLM 5.3 returns license “other” with license_name “glm-5.3”, Qwen3.8-2.4T-A95B returns “other” with “qwen3.8-max”, and Kimi K3 returns “other” with “kimi-k3”, according to the Hugging Face models API checked on 2026-09-29. “Open weight” in 2026 means you can download the tensors. It does not mean the license is open source.

The permissive tier

Two standard licenses cover most of the models you can actually ship commercially.

MIT covers GLM 5.2, GLM 5.3 Flash, and the DeepSeek V4 family. The DeepSeek V4-Pro model card states: “This repository and the model weights are licensed under the MIT License.” The GLM 5.3 Flash repository metadata returns license “mit” per the Hugging Face API. The MIT License text permits use, copying, modification, distribution, sublicensing, and sale, subject to retaining the copyright notice.

Apache 2.0 covers Qwen3.8-27B, both gpt-oss models, Gemma 4, and Devstral Small 2. The gpt-oss-120b model card states “Permissive Apache 2.0 license”. The Devstral Small 2 card states: “Apache 2.0 License: Open-source license allowing usage and modification for both commercial and non-commercial purposes.” The Hugging Face API returns “apache-2.0” for Gemma 4 31B, 26B-A4B, and 12B. Apache 2.0 adds two things MIT does not have, both stated in the Apache License 2.0 text itself: an express patent grant from the contributors, and a requirement to retain NOTICE files when you redistribute. For a commercial product, the patent grant is the reason many companies prefer Apache 2.0.

The custom tier, and the permissive sibling pattern

The most consequential license change of 2026 is on GLM 5.3. GLM 5.2 was released under MIT, per its Hugging Face API entry. GLM 5.3 is not. Its LICENSE file, retrieved from the zai-org/GLM-5.3 repository, states:

“If the Licensee or any of its affiliates operates a Model as a Service business, and the aggregate revenue of the Licensee and its affiliates exceeds 10 billion US dollars (or the equivalent in other currencies) in total over any consecutive 12 months, the Licensee must pass Z.AI’s security review before using the Software or its derivative works for any commercial purpose.”

Read that carefully. It does not ban commercial use. It makes commercial use conditional on a security review for one specific class of licensee: Model as a Service operators above a 10 billion US dollar revenue threshold, aggregated across affiliates, measured over any consecutive 12 months. If you are a startup shipping a product, this clause almost certainly does not reach you. If you are building a hosted inference platform inside a very large company, it might.

The sibling pattern repeats across the industry. GLM 5.3 Flash shipped MIT while its larger namesake shipped under the custom glm-5.3 license. Qwen3.8-27B shipped Apache 2.0 while Qwen3.8-2.4T-A95B shipped under the custom qwen3.8-max license, and Qwen3.8-Flash-Next shipped under qwen-community-1.0, per the Hugging Face API entries for all three. Moonshot’s Kimi K3 card states: “We release the full Kimi K3 model weights under the Kimi K3 License.” Meta’s Llama 4 Scout is under the Llama 4 Community License, identified as “llama4” in Hugging Face metadata, and the model card itself returns an access restriction notice stating you must have access and be authenticated to download it.

This article verified the GLM 5.3 clause verbatim from the license file. It did not reproduce the full text of the qwen3.8-max, qwen-community-1.0, Kimi K3, or Llama 4 Community licenses. Those are custom documents, not standard open source licenses, and you must read each one in its repository before shipping. Do not assume a Qwen or Kimi model inherits the terms of an earlier release in the same family.

Attribution and naming traps

Four traps caught teams in 2026.

First, the license field itself. When Hugging Face metadata says “other” with a custom license_name, that is the signal to stop and read the actual LICENSE file. Family reputation is not a license.

Second, the same model can ship under different licenses on different channels. NVIDIA’s Nemotron 3.5 Lightning 30B model card states “License: OpenMDW License Agreement, version 1.1”, while the Ollama distribution of the same model ships a blob reading “NVIDIA Open Model License Agreement, Last Modified: October 24, 2025”. The practical rule: the license that governs you is the one attached to the artifact you actually pull, so check the LICENSE file in the exact repository or blob you build from, and document which one you used.

Third, metadata can be contested. Some third party posts claim Gemma 4 uses “Gemma terms” rather than Apache 2.0. The Hugging Face license metadata for all three Gemma 4 repositories checked says “apache-2.0”. This dispute is not resolved by anything in this article; the resolvable part is that the LICENSE file inside the repository you use is the controlling document, so read it rather than arguing about metadata.

Fourth, gating is part of the deal. The Llama 4 Scout repository is restricted and requires authentication, per the model card. When a download is gated, your acceptance of terms happens at the point you click through, which is a different posture legally and operationally from pulling an ungated mirror.

One more gap to state plainly: the licenses for Mistral’s newest repositories, including Shieldstral-1.0-3B and Leanstral-1.5-119B-A6B, were not populated in the Hugging Face list API response checked for this article. Only Devstral Small 2 was confirmed, as Apache 2.0 from its own card. Treat the rest as unverified until you check each card.

Acceptable use policies riding along

A permissive copyright grant does not immunize you from use conditions in the same document. The documented 2026 example is the GLM 5.3 security review clause quoted above: a use condition riding on an otherwise downloadable weights release. The Llama 4 gating is a second mechanism, where access itself is conditioned. The general lesson for developers is mechanical: read the entire license file, including anything it incorporates by reference, before you architect your product around a model. The clause that bites is rarely the one on page one.

The table

License Models (verified examples) Permits commercial Revenue threshold Redistribution Watch outs
MIT GLM 5.3 Flash, GLM 5.2, DeepSeek V4 family Yes, per MIT text None Yes Retain the copyright notice; confirm the LICENSE file in the repo you pull
Apache 2.0 Qwen3.8-27B, gpt-oss-20b and 120b, Gemma 4 (per HF metadata), Devstral Small 2 Yes, per license text and model cards None Yes, with NOTICE retention Gemma 4 licensing is disputed by third parties; read the repo LICENSE file
glm-5.3 (custom) GLM 5.3 Yes, but conditional for large MaaS operators 10 billion USD aggregate with affiliates over any consecutive 12 months, triggering a security review Permitted under the license’s terms; full text must be read Aggregation across affiliates; the definition of Model as a Service in the license
qwen3.8-max (custom) Qwen3.8-2.4T-A95B Not verified in this article Not verified Not verified Custom license, not Apache 2.0 despite the family name
qwen-community-1.0 (custom) Qwen3.8-Flash-Next Not verified in this article Not verified Not verified Read the full text before shipping
Kimi K3 License (custom) Kimi K3 Not verified in this article Not verified Not verified Custom license on a 2.8T model you likely access via hosted providers
Llama 4 Community License Llama 4 Scout Not verified in this article Not verified Not verified Gated download; acceptance happens at access
OpenMDW 1.1 or NVIDIA Open Model License Nemotron 3.5 Lightning Varies by artifact Not verified Varies The HF card and the Ollama blob name different licenses; pick one artifact and record its license

Decision checklist for a commercial product

1. Locate the LICENSE file in the exact repository, quantization, or blob you will ship, not the family’s reputation from a previous release.

2. Check the Hugging Face license field. If it reads “other” with a custom name, you are outside the standard licenses and every term must come from the custom text.

3. Read the entire license, including any acceptable use policy or document incorporated by reference.

4. Compute your aggregate revenue including affiliates against any threshold in the license, on the rolling basis the license specifies. The GLM 5.3 clause uses “any consecutive 12 months”, which means a spike can trigger it even if your annual average is lower.

5. Decide whether your product is Model as a Service as that term is defined in the license, not as you would casually describe it.

6. If you redistribute weights, fine tunes, merges, or quantizations, find the redistribution clause and any attribution or naming requirement, and follow it exactly.

7. Check whether the license contains a patent grant. Apache 2.0 has one, stated in its text. MIT does not. Custom licenses vary, and the absence of one is a risk your counsel should weigh.

8. Check whether the repository is gated, and understand that downloading may constitute acceptance of terms.

9. If the same model ships under different licenses on different channels, as with Nemotron 3.5 Lightning, choose one artifact, record its license, and do not mix artifacts.

10. Where this article marks a term as not verified, verify it yourself from the license text before relying on it.

11. Have a lawyer review the final license before launch. This checklist is engineering hygiene, not legal advice.

Frequently asked questions

Is GLM 5.3 still open source?

It is downloadable, which is not the same thing. GLM 5.2 shipped under MIT. GLM 5.3 returns license other with the custom name glm-5.3 in the Hugging Face metadata, and its LICENSE file conditions commercial use on passing a Z.AI security review for a licensee that operates a Model as a Service business and whose aggregate revenue with affiliates exceeds 10 billion US dollars over any consecutive 12 months.

Can I use Qwen3.8 commercially?

That depends on which Qwen3.8 you mean. Qwen3.8-27B is Apache 2.0, which carries an express patent grant and a NOTICE retention requirement. Qwen3.8-2.4T-A95B ships under a custom license named qwen3.8-max, and Qwen3.8-Flash-Next ships under qwen-community-1.0. The terms of those two custom licenses were not verified for this article, so read the LICENSE file in the repository you pull from rather than assuming the family name carries the earlier terms.

Do I need a lawyer to ship an open weight model?

For anything commercial, yes. This article is not legal advice. The mechanical part you can do yourself: find the LICENSE file in the exact repository, quantization or blob you will ship, read the whole document including anything it incorporates by reference, and record which artifact you used, because the same model can ship under different licenses on different channels. NVIDIA’s Nemotron 3.5 Lightning is the documented example, carrying OpenMDW 1.1 on its model card and the NVIDIA Open Model License in the Ollama distribution.

Sources

Also in this series: the frontier AI cost and privacy table.

0 0 votes
Article Rating
Published
Categorized as Blog
The Thrifty Dev, author at thethriftydev.com

By TheThriftyDev

Building smart with AI and automation. No fluff, just results.

0 0 votes
Article Rating
Subscribe
Notify of
guest
0 Comments
Most Voted
Newest Oldest
TheThriftyDev Dispatch
Quit Google in One Weekend

The 48-hour migration playbook: what to move first, what to keep, and the exact apps that won't make you regret it on Monday.

No spam. Practical privacy, AI, backup and tool drops. Unsubscribe anytime.
0
Would love your thoughts, please comment.x
()
x