Reading an open weight model licence before you build on it
Open weights is not the same as open source
The first mistake is assuming “open weight” means the same thing as “open source.” It doesn’t, and the gap between the two has cost teams real rework.
Open source, in the OSI sense, means you can use, study, modify, and redistribute the software for any purpose, including commercial ones, with no field-of-use restrictions. An MIT or Apache 2.0 licensed library meets that bar. Most open weight model licences don’t. Meta’s Llama licence, Google’s Gemma terms, and Qwen’s licence all let you download the weights and run them, often for free, but they attach conditions on top: acceptable use policies, redistribution rules, and in at least one well known case, a usage threshold that flips your rights off entirely. None of that makes the weights bad to use. It means you’re not looking at an open source licence, you’re looking at a source available licence with a permissive default, and the difference only bites you once you’re already in production.
If you’re picking a model to fine-tune or serve behind an API you charge for, read the actual licence text before you write a line of code, not after the product ships.
The clause that actually matters: acceptable use policies
Almost every major open weight release now ships with a separate acceptable use policy (AUP) alongside the licence itself. Meta does this for Llama, Google does it for Gemma, and Mistral’s earlier RAIL-derived releases carried similar language. The AUP is where the real restrictions live, not the licence grant.
These policies typically prohibit things like generating content that facilitates weapons development, child exploitation material, or disinformation campaigns, which sound uncontroversial until you’re building a moderation layer or a red-team tool and need to know exactly where the line sits. Some AUPs also restrict use in specific regulated domains, like medical diagnosis or legal advice, without a human in the loop. If your product touches any of those categories, the AUP is not boilerplate you skim, it’s a document your legal team needs to sign off on independently from the licence itself.
The practical issue is that AUPs get updated. They’re usually hosted as a separate webpage, not baked into the model card, and vendors reserve the right to revise them. If you build a compliance check against an AUP snapshot, put a reminder on your calendar to re-check it every few months, because the version you audited at launch may not be the version in force a year later.
Scale triggers hiding in the fine print
The clause every engineer should search for by name is the monthly active user threshold. Meta’s Llama licence contains one: if your product or service built on Llama exceeds 700 million monthly active users, you’re required to request a separate licence from Meta, and the default permissive terms no longer apply automatically. Most teams reading this will never hit that number, but if you’re building on top of a platform that already has meaningful scale, like adding a feature to an existing app with tens of millions of users, it’s worth doing the arithmetic now rather than discovering the clause during a due diligence review before an acquisition or funding round.
Other vendors don’t use MAU thresholds but gate commercial use differently. Some licences distinguish between “research” and “commercial” use and require a separate commercial agreement past a certain revenue figure, or restrict commercial use entirely unless you contact the vendor directly. Qwen’s licence has had variants of this across releases, with some models under Apache 2.0 and others under a more restrictive Tongyi Qianwen licence, so you can’t assume the same rules apply across a single vendor’s whole model family. Check the licence file that ships with the specific checkpoint you’re pulling, not the vendor’s general reputation for openness.
Redistribution and naming rules
If you plan to fine-tune a model and redistribute the resulting weights, most open weight licences add naming and attribution conditions that don’t exist in typical open source licences. Llama’s licence requires that any derivative model include “Llama” in its name, and that you display a “Built with Llama” notice in related materials. That’s a real constraint if you were planning to ship a fine-tuned checkpoint under your own brand name with no reference to the base model. It’s not a dealbreaker, but it’s a product decision, not just a legal one, and marketing teams are often surprised to learn it exists after a model name has already been chosen.
Gemma’s licence carries its own attribution and redistribution terms, and they’re not identical to Llama’s. Treat each vendor’s redistribution clause as its own read, don’t assume the terms you learned from one model family carry over to the next one, even when the licences look superficially similar.
What you’re not getting: warranties and indemnification
Every open weight licence I’ve read disclaims warranties in capital letters, and none of the major ones offer indemnification if the model’s output infringes a third party’s copyright or a training data lawsuit lands on your product downstream. That’s standard for open source too, so it’s not unique to open weights, but it matters more here because these models were trained on data whose provenance isn’t fully disclosed by most vendors. If a customer’s legal team asks what happens if the model reproduces copyrighted text verbatim, the honest answer under most current licences is that the risk sits with you, the deployer, not the vendor who trained the weights.
This is one of the practical reasons some teams pay for a hosted API from the same vendor instead of self-hosting the open weights, even when the weights are free to download. A paid API contract sometimes comes with different liability terms than the raw weight licence. That’s a contract negotiation, not something you get by default just because you’re a paying customer, so don’t assume it without reading your specific agreement.
Fine-tuning and derivative works
Most open weight licences treat a fine-tuned model as a “derivative work” and apply the same conditions to it that applied to the base model, AUP included. That means if the base model’s licence says you can’t use it for a specific prohibited purpose, fine-tuning it on your own data doesn’t relax that restriction, it just produces a new checkpoint still bound by the same terms. Teams sometimes assume that heavy fine-tuning or LoRA adapters somehow “launder” the licence into something more permissive. It doesn’t. The licence follows the weights, not the amount of additional training you’ve done on top of them.
Check specifically whether the licence requires you to redistribute your fine-tuning code, your training data, or just the resulting weights if you choose to share the fine-tuned model publicly. These requirements vary and are easy to miss because they’re often in a separate section from the main use restrictions.
A five-minute checklist before you commit
Before you build a product roadmap around a specific open weight model, pull the actual licence file from the model’s repository, not a summary blog post, and check five things: whether there’s a separate AUP and what it restricts, whether there’s a user or revenue threshold that changes your rights, what the redistribution and naming requirements are if you plan to fine-tune and share, whether commercial use is permitted by default or requires a separate agreement, and what the warranty and liability disclaimers say. None of this takes long, and doing it before you commit engineering time is far cheaper than doing it after a customer’s legal team flags it during a contract review.
Open weight models have made a huge range of capability available without an API key or a monthly bill, and that’s genuinely useful for teams watching their inference costs. Just don’t confuse “I can download this for free” with “I have no obligations attached to using it.” Read the licence the same way you’d read any other vendor contract, because that’s what it is.
If you want more breakdowns like this on the tools and models actually worth building on, check out the rest of what we cover at AI Tool Gazette.