Open-Weight and Local AI: Run, Choose and Deploy Your Own ModelsThe open-weight landscape · Lesson 2 of 16

Licenses decoded: Apache-2.0, MIT, Llama and custom terms

Article · 14 min · 8 min lecture

Video lecture

Licenses decoded: Apache-2.0, MIT, Llama and custom terms

13 chapters · about 8 min · full transcript

Coming soon

Chapter 1 of 13

Licenses decoded

  • License first, then quality
  • Know the current terms by family
  • Keep a model register

The narrated lecture is in production

Every chapter is scripted and ready. Browse the chapters and read the full transcript now — the video will appear here when it’s published.

Chapters

Why licenses are a product decision

The license of a model decides whether you can ship it in a paid product, fine-tune it and redistribute the result, use its outputs to train other models, and serve it in every country you operate in. Engineers often pick a model by benchmark and discover the license problem at launch review. Flip the order: license first, then quality.

This lesson is practical guidance, not legal advice. For anything commercial, have counsel read the actual license text on the model card, because terms change between versions of the same family.

The permissive licenses

Apache License 2.0. A widely used, OSI-approved license. You may use, modify and distribute, including commercially. You must keep copyright and license notices, state significant changes to files you distribute, and pass on the NOTICE file if there is one. It includes an express patent grant from contributors (which terminates if you sue them over patents in the work). As of September 2026 these open-weight families publish models under Apache-2.0: gpt-oss (OpenAI), Gemma 4 (Google moved Gemma to Apache-2.0 with this generation, April 2026), the Mistral 3 family (Mistral Large 3 and Ministral 3), and most Qwen3 / Qwen3.5 open-weight releases.

MIT License. Very short and permissive: use, copy, modify, sell, with the copyright and permission notice kept. No explicit patent grant. DeepSeek releases (R1 and later V-series weights) and Microsoft's Phi-4 family use MIT.

Even under Apache or MIT, the vendor may publish a separate usage policy (for example, OpenAI publishes one for gpt-oss). Read it; it may be referenced by the model card and shape what you can build responsibly.

Community and custom licenses

Llama 4 Community License (Meta). Free for most commercial use, but with conditions that matter:

  • If your products had more than 700 million monthly active users on the Llama 4 release date, you must request a separate license from Meta.
  • Products built with it must display "Built with Llama", and derivative model names must start with "Llama".
  • Use must comply with the Llama 4 Acceptable Use Policy. That policy states that, for the multimodal Llama 4 models, the license rights are not granted to individuals domiciled in, or companies with a principal place of business in, the European Union (end users of a product that incorporates the model are not covered by that restriction).

Earlier Gemma versions (Gemma 1–3) used Google's own Gemma Terms of Use with a prohibited-use policy; Gemma 4 moved to Apache-2.0. Some older Qwen models shipped under Alibaba's own Qwen licenses rather than Apache. The lesson: the license belongs to the specific model release, not the brand.

A license comparison you can reuse

QuestionApache-2.0MITLlama 4 Community
Commercial useYesYesYes, with MAU threshold
Modify and fine-tuneYesYesYes
Redistribute weightsYes, keep noticesYes, keep noticeYes, with license and attribution terms
Naming/branding rulesNoNo"Built with Llama", names start with "Llama"
Use restrictionsOnly via separate policiesOnly via separate policiesAcceptable Use Policy, incl. EU multimodal limit
Patent grantExplicitNot explicitSee license text

Beyond the weights license: three more checks

  1. Training data and outputs. Some licenses or vendor terms restrict using outputs to train competing models. If you plan distillation (see the fine-tuning course), check both the teacher model's license and the API terms you used to generate data.
  2. Derived artifacts. A community GGUF quantization of a model inherits the original license. The uploader cannot relicense it. Check that the upload is from a trustworthy source and the license file is included.
  3. Regulation. Open-weight general-purpose models still interact with regulation such as the EU AI Act (with specific obligations for general-purpose AI model providers and certain exemptions for free and open-source releases) and national data-protection laws. As a deployer, your obligations depend on your use case, not on the license.

Worked example: license triage for a Lahore SaaS start-up

The start-up builds a WhatsApp customer-support assistant sold to retailers across Pakistan and the Gulf. Candidates: a Llama 4 model, a Qwen3.5 model and gpt-oss-20b.

  • User scale: far below 700 million MAU, so Llama's threshold is irrelevant, but "Built with Llama" attribution would appear in their product UI and docs.
  • Future EU customers: they plan to sell to a Dublin retailer next year. Their product is text-only, so the multimodal EU restriction would not apply to a text Llama model, but legal wants to avoid any ambiguity.
  • Decision: shortlist the Apache-2.0 models (Qwen3.5 variant and gpt-oss-20b) for the simplest terms; keep Llama as a benchmark reference.

They record the decision in a one-page model register (below) and re-check it at every model upgrade.

Hands-on: a model register entry

Keep one YAML entry per model you deploy. It turns license review into a checklist instead of a memory test.

# model-register/gpt-oss-20b.yaml
model: openai/gpt-oss-20b
source: official publisher repository (verify org name before download)
license: Apache-2.0
additional_policies:
  - vendor usage policy (linked from model card)
commercial_use: allowed
attribution_required: keep LICENSE and NOTICE files when redistributing
naming_rules: none
geographic_restrictions: none found (re-check on upgrade)
outputs_for_training_other_models: allowed by license; check any API terms used
derivatives_in_use:
  - GGUF quantization, internally built from official weights
reviewed_by: legal@yourco.example
reviewed_on: 2026-09-15
next_review: on model upgrade or in 6 months

Pitfalls

  • Assuming a family has one license. Check each release.
  • Downloading a random re-upload whose license file is missing.
  • Forgetting attribution requirements in UI and documentation.
  • Treating "Apache-2.0" as permission to ignore responsible-use policies and law.

How to measure success

Every model in production has a register entry, reviewed by someone accountable, with a next-review date. No model reaches staging without one.

Key takeaways

  • Check the license before benchmarking; it can veto a model outright
  • gpt-oss, Gemma 4, Mistral 3 and most Qwen3/3.5 open weights are Apache-2.0; DeepSeek and Phi-4 are MIT (verify per release)
  • Llama 4 Community License adds a 700M MAU threshold, "Built with Llama" branding, naming rules and an Acceptable Use Policy with an EU multimodal limit
  • Quantized re-uploads inherit the original license
  • Keep a model register entry per deployed model

Check your understanding

Quick questions to lock in the lesson. They don’t count towards your certificate.

  1. Your company has 5 million users and wants to ship a product on a text-only Llama 4 model. Which obligation still applies?
  2. A community member uploads a GGUF quantization of an Apache-2.0 model and labels it "MIT". What license governs it?
  3. Which is the safest process?

Put it into practice

Create a model register entry (use the YAML template) for one open-weight model you are considering. Link the license text and list any attribution, naming or geographic terms.

Enrol for free to save your progress

Reading is always free. Enrol to keep your place, take the final assessment and earn a verifiable certificate.