Enterprise & Sovereign AI

Open-Model Licenses for Commercial Use: What Legal Will Ask

Written by Jakub RusinowskiLast updated July 12, 2026Hardware figures computed by our VRAM engine

Open-weight model licenses fall into two families: true open-source licenses (Apache 2.0 — Qwen, Mistral Small, GPT-oss, Granite; MIT — DeepSeek, GLM) that permit commercial use with minimal conditions, and vendor community licenses (Meta's Llama license, Google's Gemma terms) that permit most commercial use but attach conditions — acceptable-use policies, attribution, and in Llama's case a threshold clause for very large companies. For most businesses all of these are workable; the difference is how many questions legal has to ask first.

The two license families

Standard open source (Apache 2.0, MIT)Vendor community licenses (Llama, Gemma)
Commercial useYes, unconditionallyYes, with conditions
Example modelsQwen 3, Mistral Small, GPT-oss, Granite (Apache 2.0); DeepSeek, GLM (MIT)Llama 3.x / 4 (Llama Community License); Gemma (Gemma Terms of Use)
Acceptable-use policyNone baked into the licenseYes — flows down to your deployment
AttributionKeep license/notice files (Apache adds a NOTICE requirement)Yes — e.g. Llama requires "Built with Llama" display for distributed products and llama-prefixed names for derivative models
Patent grantApache 2.0: explicit; MIT: no express grantLicense-specific terms
Special clausesNoneLlama: companies with >700M monthly active users at release date need a separate Meta license
Legal review effortMinutes — these licenses are decades-understoodHours — someone must actually read the AUP and terms

The practical summary most legal teams land on: Apache 2.0 and MIT models are approve-once, the same review as any open-source dependency. Community-licensed models are approve-per-use-case, because the acceptable-use policy is a living document you're agreeing to enforce — and vendors can revise it for future model versions (each model release binds you to the license it shipped with; already-downloaded weights don't retroactively change).

A pragmatic selection policy

The policy that keeps procurement simple, used implicitly across this hub's recommendations:

  • Default to Apache 2.0 / MIT models — Qwen 3 for general work, GPT-oss for the quality ceiling, Mistral Small for efficiency, DeepSeek for reasoning. Zero-friction approval, no AUP flow-down, fine-tunes unencumbered. Every model's license is listed on its model library page.
  • Use community-licensed models when they win on merit — Llama 3.3 70B remains a reference model, and its license is fine for the overwhelming majority of businesses (the 700M-MAU clause names a club of a few dozen companies worldwide). Just route them through the per-use-case review lane.
  • Write the choice down. A one-paragraph internal policy — "approved license families, review lane for exceptions" — turns every future model upgrade from a legal thread into a checkbox, which matters because you will change models more often than you change GPUs (TCO guide, refresh section).

Frequently asked questions

Can I use Llama commercially?

Yes, for almost every business: the Llama Community License permits commercial use. The famous exception targets giants — companies whose products exceeded 700 million monthly active users when the model version released need a separate license from Meta. The obligations that actually affect normal businesses are the acceptable-use policy, "Built with Llama" attribution on distributed products, and Llama-prefixed naming for fine-tuned derivatives. Not legal advice — have counsel read the license version you deploy.

Which open LLMs have the cleanest licenses for business use?

Apache 2.0 models: Qwen 3, Mistral Small, GPT-oss, and IBM Granite; and MIT models: DeepSeek and GLM. These are standard open-source licenses your legal team has approved hundreds of times — unconditional commercial use, no acceptable-use policy baked in, fine-tunes fully yours, and (for Apache 2.0) an explicit patent grant.

Do open-model licenses restrict what we can build?

Apache 2.0 and MIT: effectively no — standard open-source terms. Community licenses (Llama, Gemma) attach acceptable-use policies prohibiting categories like illegal activity and deceptive use; for internal tools this is routine policy work, while customer-facing products need the AUP reflected in your own terms of service. No mainstream open-weight license restricts commercial use of model outputs.

Who owns a model we fine-tune on our own data?

Under Apache 2.0 and MIT base models, the fine-tuned weights are yours without conditions. Under the Llama license, your derivative stays governed by Llama's terms — naming and AUP included — which matters mainly if you distribute it. Separately, watch platform-vendor contracts: some claim rights over fine-tunes created in their tooling, which is a negotiable contract term, not a license requirement (see our vendor checklist, question 7).

Does anyone indemnify us if a self-hosted model produces infringing output?

No — no open-weight license provides indemnification; that is a commercial feature some paid cloud APIs offer. Self-hosting trades vendor indemnity for architectural control. Legal teams typically treat this like any other open-source component: human review where outputs carry legal weight, contractual disclaimers where appropriate, and the same E&O coverage that already backs the business.