Open-Weight and Local AI: Run, Choose and Deploy Your Own ModelsThe open-weight landscape · Lesson 2 of 16
Licenses decoded: Apache-2.0, MIT, Llama and custom terms
Video lecture
Licenses decoded: Apache-2.0, MIT, Llama and custom terms
The narrated lecture is in production
Every chapter is scripted and ready. Browse the chapters and read the full transcript now — the video will appear here when it’s published.
Chapters
Transcript of the narration, chapter by chapter.
0:00 Licenses decoded
Picture this. Your team spends six weeks building on the model that topped your benchmark. Launch review arrives, legal reads the license, and the answer is no. Six weeks gone. It happens more than you would think. In this lesson you will learn to read model licenses like a practitioner, know which families use which terms right now, and keep a simple register so this never catches you out. One note first: this is practical guidance, not legal advice.
0:34 Analogy: a shop lease
Think of a model license like a lease on a shop. Some leases say: use it for anything, just keep the landlord's sign on the wall. That is roughly Apache or MIT. Others say: you can run your business here, but you must display our brand at the entrance, name your shop after us, follow our house rules, and if you become enormous you need to renegotiate. That is closer to a community license like Llama's. Neither lease is bad. But you would never sign a lease without reading it, and you should never ship a model without reading its license.
1:18 Permissive licenses
Start with the permissive two. Apache 2.0 lets you use, modify and distribute, including commercially. You keep the copyright and license notices, mark significant changes, and pass on any NOTICE file. It also includes an explicit patent grant from contributors. MIT is even shorter: keep the notice, and do almost anything, but there is no explicit patent clause. Right now, gpt-oss, Gemma 4, the Mistral 3 family and most Qwen three and three point five open weights use Apache 2.0. DeepSeek and Microsoft's Phi-4 family use MIT. Always confirm on the specific model card.
1:59 Llama 4 Community License
Now Meta's Llama 4 Community License. It is free for most commercial use, with conditions. If your products had more than seven hundred million monthly active users on the release date, you need a separate license from Meta. You must show "Built with Llama", and derivative model names must start with the word Llama. And you must follow the Acceptable Use Policy, which says that for the multimodal Llama 4 models, rights are not granted to individuals or companies based in the European Union, though end users of a product built on them are not covered by that restriction.
2:42 The release, not the brand
Here is the trap. Licenses belong to a specific release, not to a brand. Earlier Gemma versions used Google's own terms, and Gemma 4 moved to Apache. Some older Qwen sizes used Alibaba's own licenses. And when someone uploads a quantized copy of a model, it inherits the original license. They cannot relabel it. So "we use Qwen" is not an answer to a license question. "We use this exact model file, under this license text" is.
3:15 Three more checks
Three more checks beyond the weights. First, outputs: some terms restrict using a model's outputs to train competing models, which matters if you plan to distil. Second, provenance: download from the publisher or a trusted mirror, and make sure the license file is included. Third, regulation: data protection law and rules like the EU AI Act apply to your use case, whatever the license says. Apache does not make an unlawful use lawful.
3:47 Worked example: Lahore SaaS
Let's triage a real-style case. A Lahore start-up sells a WhatsApp support assistant to retailers across Pakistan and the Gulf, and plans to sign an Irish customer next year. They shortlist a Llama 4 model, a Qwen three point five model and gpt-oss twenty B. They are nowhere near seven hundred million users, but Llama would require attribution in their product, and their legal team wants zero ambiguity for future EU customers. So they shortlist the two Apache models and keep Llama only as a benchmark reference.
4:25 Hands-on: model register
Your hands-on tool is a model register: one small YAML file per model you deploy. It records the exact model, the source, the license, extra policies, attribution and naming rules, geographic limits, whether outputs can train other models, who reviewed it and when to review again. The template is in the lesson. It takes ten minutes to fill in and it turns license review from a memory test into a checklist.
4:56 Simple example: internal summarizer
Here is a simple example. A developer in Manchester builds an internal meeting-notes summarizer for her own ten-person company using gpt-oss twenty B. The license is Apache 2.0. Her obligations are light: keep the license and notice files if she ever redistributes the weights, and follow OpenAI's usage policy. She is not redistributing anything, she is running it internally. So her register entry takes five minutes, and the answer is a clear yes. Simple cases should be simple. The register just proves you checked.
5:33 Pitfalls
A few pitfalls I see again and again. Teams assume a family has one license, then upgrade to a new release with different terms without anyone noticing. Engineers download a quantized copy from a stranger's repository where the license file is simply missing. Designers forget the attribution line in the product interface and the documentation. And people read Apache 2.0 as permission to ignore responsible-use policies and the law. The fix for all four is the same: make the register entry a required gate before any model reaches staging, and re-check it on every upgrade.
6:14 Try this now
Try this now. Pick one model you are curious about, open its model card, and find three things: the exact license name, whether there is a separate acceptable use or usage policy, and whether there are any attribution or naming rules. Write them into the YAML template from the lesson. If you cannot find one of them within five minutes, that itself is a finding. Flag it for review before anyone builds on that model.
6:47 Watch me do it
Watch me do it. I will fill in a register entry for a model from scratch. I open the model's page and scroll to the license section. It says Apache 2.0, so I type that in. Next I search the page for the words usage policy and find a link to the publisher's policy; I paste the link into additional policies. Then I check for attribution rules: Apache asks me to keep the license and notice files if I redistribute, so I note that. Naming rules: none. Geographic restrictions: I search for European Union and region, and find nothing, so I write none found, re-check on upgrade. Finally, I note how we will use it: internal only, a quantized copy built from the official weights. I add the reviewer and a review date six months out. Seven fields, eight minutes, and the next person who asks can we use this gets an answer immediately.
7:54 Recap
To recap. Check licenses before benchmarks. Apache and MIT are permissive but still carry notices and sometimes usage policies. Llama's community license adds a user threshold, branding and naming rules, and an acceptable use policy with an EU limit on multimodal models. Licenses belong to releases, and quantized copies inherit them. Your next step: fill in a register entry for one model you are considering, and link the license text itself.
Why licenses are a product decision
The license of a model decides whether you can ship it in a paid product, fine-tune it and redistribute the result, use its outputs to train other models, and serve it in every country you operate in. Engineers often pick a model by benchmark and discover the license problem at launch review. Flip the order: license first, then quality.
This lesson is practical guidance, not legal advice. For anything commercial, have counsel read the actual license text on the model card, because terms change between versions of the same family.
The permissive licenses
Apache License 2.0. A widely used, OSI-approved license. You may use, modify and distribute, including commercially. You must keep copyright and license notices, state significant changes to files you distribute, and pass on the NOTICE file if there is one. It includes an express patent grant from contributors (which terminates if you sue them over patents in the work). As of September 2026 these open-weight families publish models under Apache-2.0: gpt-oss (OpenAI), Gemma 4 (Google moved Gemma to Apache-2.0 with this generation, April 2026), the Mistral 3 family (Mistral Large 3 and Ministral 3), and most Qwen3 / Qwen3.5 open-weight releases.
MIT License. Very short and permissive: use, copy, modify, sell, with the copyright and permission notice kept. No explicit patent grant. DeepSeek releases (R1 and later V-series weights) and Microsoft's Phi-4 family use MIT.
Even under Apache or MIT, the vendor may publish a separate usage policy (for example, OpenAI publishes one for gpt-oss). Read it; it may be referenced by the model card and shape what you can build responsibly.
Community and custom licenses
Llama 4 Community License (Meta). Free for most commercial use, but with conditions that matter:
- If your products had more than 700 million monthly active users on the Llama 4 release date, you must request a separate license from Meta.
- Products built with it must display "Built with Llama", and derivative model names must start with "Llama".
- Use must comply with the Llama 4 Acceptable Use Policy. That policy states that, for the multimodal Llama 4 models, the license rights are not granted to individuals domiciled in, or companies with a principal place of business in, the European Union (end users of a product that incorporates the model are not covered by that restriction).
Earlier Gemma versions (Gemma 1–3) used Google's own Gemma Terms of Use with a prohibited-use policy; Gemma 4 moved to Apache-2.0. Some older Qwen models shipped under Alibaba's own Qwen licenses rather than Apache. The lesson: the license belongs to the specific model release, not the brand.
A license comparison you can reuse
| Question | Apache-2.0 | MIT | Llama 4 Community |
|---|---|---|---|
| Commercial use | Yes | Yes | Yes, with MAU threshold |
| Modify and fine-tune | Yes | Yes | Yes |
| Redistribute weights | Yes, keep notices | Yes, keep notice | Yes, with license and attribution terms |
| Naming/branding rules | No | No | "Built with Llama", names start with "Llama" |
| Use restrictions | Only via separate policies | Only via separate policies | Acceptable Use Policy, incl. EU multimodal limit |
| Patent grant | Explicit | Not explicit | See license text |
Beyond the weights license: three more checks
- Training data and outputs. Some licenses or vendor terms restrict using outputs to train competing models. If you plan distillation (see the fine-tuning course), check both the teacher model's license and the API terms you used to generate data.
- Derived artifacts. A community GGUF quantization of a model inherits the original license. The uploader cannot relicense it. Check that the upload is from a trustworthy source and the license file is included.
- Regulation. Open-weight general-purpose models still interact with regulation such as the EU AI Act (with specific obligations for general-purpose AI model providers and certain exemptions for free and open-source releases) and national data-protection laws. As a deployer, your obligations depend on your use case, not on the license.
Worked example: license triage for a Lahore SaaS start-up
The start-up builds a WhatsApp customer-support assistant sold to retailers across Pakistan and the Gulf. Candidates: a Llama 4 model, a Qwen3.5 model and gpt-oss-20b.
- User scale: far below 700 million MAU, so Llama's threshold is irrelevant, but "Built with Llama" attribution would appear in their product UI and docs.
- Future EU customers: they plan to sell to a Dublin retailer next year. Their product is text-only, so the multimodal EU restriction would not apply to a text Llama model, but legal wants to avoid any ambiguity.
- Decision: shortlist the Apache-2.0 models (Qwen3.5 variant and gpt-oss-20b) for the simplest terms; keep Llama as a benchmark reference.
They record the decision in a one-page model register (below) and re-check it at every model upgrade.
Hands-on: a model register entry
Keep one YAML entry per model you deploy. It turns license review into a checklist instead of a memory test.
# model-register/gpt-oss-20b.yaml
model: openai/gpt-oss-20b
source: official publisher repository (verify org name before download)
license: Apache-2.0
additional_policies:
- vendor usage policy (linked from model card)
commercial_use: allowed
attribution_required: keep LICENSE and NOTICE files when redistributing
naming_rules: none
geographic_restrictions: none found (re-check on upgrade)
outputs_for_training_other_models: allowed by license; check any API terms used
derivatives_in_use:
- GGUF quantization, internally built from official weights
reviewed_by: legal@yourco.example
reviewed_on: 2026-09-15
next_review: on model upgrade or in 6 monthsPitfalls
- Assuming a family has one license. Check each release.
- Downloading a random re-upload whose license file is missing.
- Forgetting attribution requirements in UI and documentation.
- Treating "Apache-2.0" as permission to ignore responsible-use policies and law.
How to measure success
Every model in production has a register entry, reviewed by someone accountable, with a next-review date. No model reaches staging without one.
Key takeaways
- Check the license before benchmarking; it can veto a model outright
- gpt-oss, Gemma 4, Mistral 3 and most Qwen3/3.5 open weights are Apache-2.0; DeepSeek and Phi-4 are MIT (verify per release)
- Llama 4 Community License adds a 700M MAU threshold, "Built with Llama" branding, naming rules and an Acceptable Use Policy with an EU multimodal limit
- Quantized re-uploads inherit the original license
- Keep a model register entry per deployed model
Check your understanding
Quick questions to lock in the lesson. They don’t count towards your certificate.
Put it into practice
Create a model register entry (use the YAML template) for one open-weight model you are considering. Link the license text and list any attribution, naming or geographic terms.
Enrol for free to save your progress
Reading is always free. Enrol to keep your place, take the final assessment and earn a verifiable certificate.