How to check an open-weights model licence before you build on it

How to check an open-weights model licence before you build on it

An open-weights model is one whose trained weights you can download and run yourself. That does not mean you can use it for anything you like. The licence decides whether you can use the model commercially, what you can build on it and what you must tell your users. Check it before your engineers start work, and record the result where your governance team can find it.

This playbook is for technology leaders, heads of data, procurement and in-house legal teams at organisations considering a self-hosted model. It is a practical checklist, not legal advice. Have your legal adviser confirm the final decision.

Why open weights is now a serious option

For regulated organisations, running a model in your own environment can help with data residency, version control and predictable running costs. No prompt or document needs to leave infrastructure you control.

The capability gap has also narrowed. In April 2026, Artificial Analysis, an independent benchmarking company, reported that the leading open-weights models were 6 points behind the leading proprietary model on its Intelligence Index. It also noted that the gap remained wide on the hardest reasoning and agentic coding tests. For many routine workflows, such as summarising, classifying and extracting, an open-weights model may now be good enough. Your own evaluation should decide that.

Open weights is not the same as open source

Open source software comes with its source code under a licence that permits use, inspection and modification. Many open-weights releases publish only the trained weights. The training data and the full training code often stay private. Some open-weights licences are standard open source licences. Many are custom agreements written by the model's developer.

The three licence types you will meet

Artificial Analysis separates open-weights models in its AI insights and trends analysis into three groups: permissive, commercial use restricted and non-commercial. The same three groups work well for sorting your own shortlist.

Permissive

These use standard licences such as Apache 2.0 or MIT. OpenAI released its gpt-oss models under Apache 2.0 in August 2025. DeepSeek released DeepSeek-R1 under MIT in January 2025. The main conditions are to keep the copyright and licence notices. Some developers also publish a separate usage policy alongside a permissive licence, so read both.

Commercial use with conditions

These are custom licences that allow commercial use but add conditions. Meta's Llama community licences, for example, require organisations above 700 million monthly active users to request a separate licence from Meta, and they incorporate Meta's acceptable use policy. Google's Gemma models are governed by the Gemma Terms of Use, which include a prohibited use policy and let Google restrict usage it believes breaches the terms. Conditions like these are workable for most organisations, but they need to be read, understood and recorded.

Non-commercial or research only

These licences allow research and evaluation but not commercial use. You can test such a model, but you cannot put it into a commercial product or an internal production workflow without a different licence.

A checklist before you build

  1. Find the exact licence for the exact version. Licences change between model versions, and even small details, such as how a user threshold is measured, can differ. Save a copy with the date you retrieved it.
  2. Confirm commercial use is permitted. Check for user, revenue or company-size thresholds that could apply to you or your group.
  3. Read any acceptable use or prohibited use policy. Check whether your use case is covered, especially in regulated areas such as financial advice, health or employment decisions. Check whether the developer can change the policy later.
  4. Check the rules on outputs. Some licences attach conditions to using the model's outputs to train or improve other models. Confirm who is responsible for outputs and what you may do with them.
  5. Check the rules on fine-tuning and derivatives. If you fine-tune the model, find out whether the licence passes on to your version and whether there are naming or attribution requirements. For example, if you distribute a model built from Llama 4 or its outputs, the Llama 4 licence requires the model's name to begin with "Llama" and asks you to display "Built with Llama" prominently.
  6. Check redistribution if you deploy for others. If you will install the model in a client's environment or ship it inside a product, confirm that the licence allows it and what notices must go with it.
  7. Record the decision. Add the model to your AI inventory with its version, licence, review date, owner and any conditions. Set a date to review it again.
  8. Get legal sign-off. Ask your legal adviser to confirm the reading of any custom licence before the model goes into production.

Self-hosting is a platform decision too

A suitable licence is only the first gate. Running a model yourself means you also take on hosting, scaling, security updates, monitoring and evaluation. Many capable open-weights models are mixture-of-experts designs with very large total parameter counts. They can be relatively cheap to run per request but still need substantial memory to host. Plan the infrastructure and its running cost alongside the licence review, not after it.

How we help

In our Governed Workflow Platforms and Platform and Cloud Engineering work, we help clients shortlist models, test them against their own tasks and record each decision with its evidence. Where self-hosting is the right answer, we build and run the environment for it. For the wider controls around AI, see our Data Governance Toolkit.

If you are weighing an open-weights model for a regulated workflow, talk to us.

Sources

Licence terms change. Always read the current licence for the version you plan to use. Artificial Analysis is independent of Rodan.