What Open-Weight Model Licenses Actually Let You Do in 2026
Quick answer: Yes, but not under a modified MIT license, whatever the summaries say. Kimi K3 ships under a bespoke Kimi K3 License: commercial use is free until you or an affiliate operate a Model-as-a-Service business and group revenue clears US$20M over any consecutive 12 months, which then requires a signed agreement with Moonshot AI before any commercial use. Internal use, meaning use that never exposes the model or its outputs to third parties, is exempt.
Last updated: August 2026
Search for the Kimi K3 license and most top results call it a modified MIT license. It is not. Moonshot AI's coding model, Kimi K2.7-Code, genuinely is MIT plus one clause. K3 is a different file with its own name, five numbered conditions, and a revenue gate that can stop a launch.
Open-weight licensing has split into four things that all get called open: Apache 2.0 you can stop thinking about, MIT with a logo rule that only fires at Facebook scale, permissive up to a revenue number with a contract after it, and Llama 4, which is not open source and whose repos have not been touched since May 2025.
Below is a clause-by-clause read of the license files as they stood on 11 August 2026: thresholds, measurement windows, and the addresses you have to write to. Capability shows up once, at the end, where it changes a decision. Everywhere else it is noise.
"Modified MIT" Is the Wrong Label for Kimi K3
The mistake is understandable. The grant paragraph is lifted from MIT, down to "Permission is hereby granted, free of charge, to any person (the "Licensee") obtaining a copy of this software". The tell is the parenthetical: plain MIT never defines a party, because nothing below refers back to one. Here, five conditions do.
- Condition 1. Preserve the copyright and permission notice. The only one that overlaps with MIT.
- Condition 2. The Model-as-a-Service gate. MaaS means giving third parties access to inference or fine-tuning, for example via API, with meaningful control over inputs, parameters or training data. If you or an affiliate run one and aggregate revenue passes US$20M over any consecutive 12 months, you need a separate agreement with Moonshot first.
- Condition 3. The display trigger. Above 100 million monthly active users or US$20M monthly revenue, the product must show "Kimi K3" prominently in its interface.
- Condition 4. The carve-outs. Conditions 2 and 3 do not apply to internal use, defined as use that does not make the software, its outputs or its capabilities available to third parties, nor to access through Moonshot's own products and certified partners.
- Condition 5. The AS IS disclaimer, extended explicitly to outputs and results.
Condition 2 is not what people assume, and the exact wording is worth reading twice: "If the Licensee or any of its affiliates operates a Model as a Service business, and the aggregate revenue of the Licensee and its affiliates exceeds 20 million US dollars...". Two separate tests, joined by an and. Operating MaaS opens the question; group revenue answers it. So the number is not what the MaaS line earns, it is what the whole group earns, and a shoe company running one API that a partner also calls is arguably inside the gate on revenue that has nothing to do with models. Moonshot publishes an address for it: license@moonshot.ai.
K3 imposes nothing else: no derivative naming rule, no ban on training other models on its outputs, no acceptable-use policy.
Four Tiers, Not One Alphabetical Table
A license column next to thirteen model names hides the only thing procurement cares about: does this term ever require a human at the vendor to say yes? Sort by that and you get four tiers, and models move between them within one vendor, sometimes within one family.
| Model | License | Redistribute? | Commercial gate | Attribution | Naming rule |
|---|---|---|---|---|---|
| Gemma 4 | Apache 2.0 | Yes + NOTICE | None | None | None |
| DeepSeek V4 | MIT | Yes + notice | None | None | None |
| GLM-5.2 | MIT | Yes + notice | None | None | None |
| Qwen3.6 open | Apache 2.0 | Yes + NOTICE | None | None | None |
| Mistral Large 3 | Apache 2.0 | Yes + NOTICE | None | None | None |
| Muse Glimmer 30B | Apache 2.0 | Yes + NOTICE | None | None | None |
| Nemotron 3 Ultra | OpenMDW-1.1 | Yes + notice | None | None | None |
| Nemotron 3 Super | NVIDIA Nemotron OML | Yes | None | None | None |
| Kimi K2.7-Code | Modified MIT | Yes + notice | None | 100M MAU or $20M/mo | None |
| Kimi K3 | Kimi K3 License | Yes + notice | MaaS + US$20M / 12mo | 100M MAU or $20M/mo | None |
| MiniMax M3 | MiniMax Community | Yes + notice | US$20M / year | Any commercial use | None |
| Mistral Medium 3.5 | Modified MIT | Yes + notice | US$20M/mo, company-wide | None | None |
| Llama 4 | Llama 4 Community | Yes + agreement | 700M MAU at release | Any redistribution | Prefix "Llama" |
Tier 1: Clean Permissive, and the Apache Versus MIT Split
Gemma 4 is the headline change. It ships under Apache 2.0, the first Gemma free of the bespoke Terms of Use that governed versions 1 through 3. The model card at ai.google.dev, last revised 30 July 2026, states Apache 2.0 for the whole family, and every google/gemma-4 repo carries apache-2.0 in its front matter. If your only objection to Gemma was the old terms, it is gone.
One distinction inside tier one still matters, and it is not permissiveness. Apache 2.0 section 3 carries an express patent license from every contributor, with defensive termination if you sue over the work. MIT has none. For a chatbot nobody cares. Inside a medical device or a trading system, it separates covered risk from open risk.
- Apache 2.0. Gemma 4 in all five sizes, Mistral Large 3 (the 675B Instruct-2512 checkpoint), the Ministral 3 dense models at 3B, 8B and 14B, the Qwen3.6 open checkpoints, and Muse Glimmer 30B. Patent grant, NOTICE preservation, and a duty to state which files you changed.
- MIT. DeepSeek V4 Pro and Flash, and GLM-5.2. No patent grant, no regional restriction, no extra terms.
- OpenMDW-1.1. NVIDIA's
NVIDIA-Nemotron-3-Ultra-550B-A55B, which declareslicense_name: openmdw-1.1and links to openmdw.ai. Built for model artifacts: rights under copyright, patent, database and trade secret law, no revenue gate, defensive patent termination.
Muse Glimmer went up on 9 August 2026 under Apache 2.0, and it sits under meta-models, not meta-llama. Pipelines that pin the old org prefix miss it entirely.
Trying to get this past a proof of concept? Enterprise AI work rarely stalls on the model. It stalls on what sits underneath: retrieval that returns the wrong chunk, permissions that leak across tenants, and no agreed way to tell a good answer from a bad one. We build the pipeline, the access rules and the evaluation harness so the thing can actually go live.
Book an AI readiness call AI and ML servicesTier 2: Permissive With a Display Trigger
Kimi K2.7-Code is the clean example, and the reason the K3 confusion spread. Its file is genuinely titled Modified MIT License, its card declares license_name: modified-mit, and it adds exactly one thing: products above 100 million monthly active users or US$20M monthly revenue must show "Kimi K2.7 Code" in the interface. No MaaS clause. No separate agreement. Somebody read that file, wrote the summary, and the summary got applied to the sibling model.
Below those thresholds it behaves as MIT: self-host, fine-tune, resell inference, tell nobody. A display trigger is cheap. A revenue gate is not, because clearing it needs a countersignature nobody owes you.
Tier 3: Permissive Until a Number, Then a Negotiation
Three models sit here, with thresholds over three different windows against three different revenue bases. Llama 4 is in the table too, for contrast, though it belongs a tier down. Note what the differences do: Mistral Medium 3.5 measures monthly and company-wide, so an enterprise that would never trip Kimi K3 trips Mistral in its first month.
| Model | What is measured | Window | Whose revenue | What you must do |
|---|---|---|---|---|
| Kimi K3 (c2) | Group revenue, MaaS operator | Any consecutive 12 months | Licensee + affiliates | Sign agreement, license@moonshot.ai |
| Kimi K3 (c3) | Product MAU or monthly revenue | Monthly | The product | Show "Kimi K3" in the UI |
| MiniMax M3, over | Product and service revenue | Yearly | Yours | Written authorization, api@minimax.io |
| MiniMax M3, under | Product and service revenue | Yearly | Yours | One-time notice, api@minimax.io |
| Mistral Medium 3.5 | Global consolidated revenue | Monthly | Your company or employer | Buy license, sales@mistral.ai |
| Llama 4 | MAU at version release date | Preceding calendar month | You + affiliates | Request license, Meta's discretion |
MiniMax M3 carries the obligation nobody mentions. Even below the threshold, commercial use requires a one-time notice email to api@minimax.io using the subject line the license names, and "Built with MiniMax M3" attribution is mandatory at any scale. Its video model H3 also carries geographic exclusions M3 does not, so "we cleared MiniMax" is not portable.
Tier 4: A Community License That Is Not Open Source
The Llama 4 Community License Agreement, effective 5 April 2025, imposes obligations no OSI-approved license contains: ship a copy of the agreement, display "Built with Llama", and prefix any model trained from Llama materials with "Llama". Above 700 million monthly active users you must request a license Meta may grant at its sole discretion. Discretionary grants disqualify a license under the Open Source Definition.
One widely repeated claim is wrong: the Llama 4 license does not prohibit using Llama outputs to train other models. That lived in earlier Llama terms. Version 4 replaces the ban with a naming rule, and says so in the same breath: if you use the materials "or any outputs or results" to train, fine-tune or otherwise improve a model you then distribute, you must put "Llama" at the front of its name. Read as a permission with a condition attached, which is what it is, distillation is on the table.
The bigger problem is age. On 11 August 2026 the meta-llama org lists Llama 4 Scout and Maverick, Llama-Guard-4, the Prompt-Guard models and Llama 3.3. No Llama 5. The Llama 4 repos have not been modified since 22 May 2025, and the most recently touched repo in the entire org dates to 12 November 2025. Llama-4-Scout reports gated: "manual", so a human at Meta approves each request: fine for a laptop, a supply chain dependency when CI needs weights at 3am.
The Vendor-Level Assumptions That Break
Most mistakes we see in client review come from reasoning about a vendor instead of a file.
- "All Mistral is Apache 2.0." False since 31 March 2026, the day the Medium 3.5 repo went up. Large 3 and Ministral 3 are Apache 2.0. Mistral Medium 3.5, a 128B dense model with a 262,144-token context window, ships under a file titled Modified MIT License stating you are not authorized to exercise any rights if your company's global consolidated monthly revenue exceeds US$20M.
- "Nemotron 3 is one license." No.
NVIDIA-Nemotron-3-Ultra-550B-A55Bdeclaresopenmdw-1.1.NVIDIA-Nemotron-3-Super-120B-A12Bdeclaresnvidia-nemotron-open-model-license, set by a commit titled "Update License" on 14 March 2026. Sources disagree because the family does, and because the file moved after launch. - "Qwen is Apache 2.0, so Qwen3.8 will be." Not yet true. Qwen3.6-27B and Qwen3.6-35B-A3B are Apache 2.0 in their card front matter, as is the Qwen3.5 line before them. Qwen3.8 is a different question: on 11 August the Qwen org publishes no Qwen3.8 repo and no license for one, even though third-party Qwen3.8-27B quantizations have already appeared under community accounts. Somebody else's upload is not a grant of rights.
- "Meta is open again, so more weights are coming." One Apache 2.0 release is not a policy. The
meta-modelsorg holds Muse Glimmer 30B and its quantized variants, and nothing else. Plan against the weights that exist.
The Gate Keys On Your Revenue, Not Your Usage
Here is the failure mode that bites. Teams assess a gated license by asking whether their usage is big enough to matter. Usage is never the trigger. Every gate reads on revenue or user count, properties of the business, not the deployment.
The sequence runs: pilot at US$4M ARR, model free, architecture locked, prompts written against one tokenizer and one tool-calling format. Eighteen months later a good sales year pushes the group past US$20M, and the same deployment is a negotiation with a vendor who knows what switching costs. The upper hand arrived through sales, not engineering.
from dataclasses import dataclass
@dataclass
class Deployment:
group_revenue_last_12m_usd: float # licensee AND affiliates, all revenue
product_monthly_revenue_usd: float
product_mau: int
resells_inference: bool # third parties get API access to the model
exposes_outputs: bool # outputs or capabilities leave your org
def kimi_k3_obligations(d: Deployment) -> list[str]:
"""Kimi K3 License, conditions 2, 3 and 4, as read on 2026-08-11."""
if not d.exposes_outputs:
return [] # condition 4(a): internal use is exempt from 2 and 3
out = []
# Condition 2 reads on GROUP revenue, not on what the MaaS line earns.
if d.resells_inference and d.group_revenue_last_12m_usd > 20_000_000:
out.append("c2: signed agreement with Moonshot AI before ANY commercial use")
if d.product_mau > 100_000_000 or d.product_monthly_revenue_usd > 20_000_000:
out.append("c3: display 'Kimi K3' prominently in the product UI")
return out
pilot = Deployment(18_500_000, 900_000, 350_000, resells_inference=True, exposes_outputs=True)
year_2 = Deployment(21_200_000, 1_100_000, 410_000, resells_inference=True, exposes_outputs=True)
print("pilot :", kimi_k3_obligations(pilot) or ["none"])
print("year 2:", kimi_k3_obligations(year_2) or ["none"])
# pilot : ['none']
# year 2: ['c2: signed agreement with Moonshot AI before ANY commercial use']
# Nothing about the deployment changed. Revenue crossed a line, and the model
# picked in month three became a contract negotiation in month fifteen.
Two defenses. Track the threshold in the same dashboard as ARR, tagged with the model name, so crossing it opens a ticket, not an audit. And if the client resells inference at all, rule out tier three on day one: K3's condition 2 then blocks all commercial use, not only the MaaS part.
The Metadata Badge Lies, So Read the File
Tooling that reads the SPDX-style license field and stops is wrong on exactly the models where being wrong costs money. Kimi K3, Kimi K2.7-Code, Llama 4 Scout, MiniMax M3, Mistral Medium 3.5 and both Nemotron 3 tiers all declare license: "other", which tells you nothing. The value that identifies the file sits in license_name, and it settles the argument on its own: K2.7-Code declares modified-mit, K3 declares kimi-k3. Different files, different names, and only one of them has a revenue gate.
import re
import requests
REPOS = [
"moonshotai/Kimi-K3",
"moonshotai/Kimi-K2.7-Code",
"deepseek-ai/DeepSeek-V4-Pro",
"zai-org/GLM-5.2",
"Qwen/Qwen3.6-27B",
"mistralai/Mistral-Large-3-675B-Instruct-2512",
"mistralai/Mistral-Medium-3.5-128B",
"MiniMaxAI/MiniMax-M3",
"meta-models/Muse-Glimmer-30B",
"meta-llama/Llama-4-Scout-17B-16E-Instruct",
]
# Phrases that mean a lawyer has to read the file before you ship.
GATES = {
"revenue_gate": r"(monthly revenue|yearly revenue|consolidated .{0,25}revenue|aggregate revenue)",
"separate_agreement": r"(separate agreement|prior written authorization|request a license|commercial license)",
"display_clause": r"prominently display",
"naming_clause": r"beginning of any such AI model name",
"mau_threshold": r"monthly active users",
}
def metadata(repo_id):
r = requests.get(f"https://huggingface.co/api/models/{repo_id}", timeout=30)
r.raise_for_status()
body = r.json()
card = body.get("cardData") or {}
return {
"license": card.get("license"), # often just "other"
"license_name": card.get("license_name"), # the value that identifies it
"gated": body.get("gated", False), # False, "auto" or "manual"
}
def license_text(repo_id):
"""Return the license text, or None if it could not be read."""
for name in ("LICENSE", "LICENSE.md", "LICENSE.txt"):
r = requests.get(f"https://huggingface.co/{repo_id}/raw/main/{name}", timeout=30)
# Gated repos answer 401 here; Llama-4-Scout does. A redirect that lands
# on a login page can still answer 200 with HTML, so check the body too.
if r.status_code == 200 and not r.text.lstrip().startswith("<"):
return r.text
return None
for repo in REPOS:
meta = metadata(repo)
text = license_text(repo)
print(f"{repo}")
print(f" spdx : {meta['license']}")
print(f" name : {meta['license_name']}")
print(f" gated : {meta['gated']}")
if text is None:
# Unreadable is not permissive. Never let this print as a clean pass.
print(" clauses : UNREADABLE (gated, or no LICENSE at the repo root)")
continue
hits = sorted(k for k, pat in GATES.items() if re.search(pat, text, re.I))
print(f" clauses : {', '.join(hits) if hits else 'none matched'}")
The regex layer is deliberately crude. It answers one question: does this file contain a sentence that needs a human? A hit on separate_agreement or revenue_gate sends it to counsel. The unreadable branch matters more than the patterns do. Hugging Face answers an unauthenticated raw request against a gated repo with HTTP 401, so Llama-4-Scout yields no text and every regex misses it. Collapse that into an empty result and the most restrictive license in the list prints as the cleanest one.
Pin the License Like a Dependency
License files are mutable, and the tooling treats them as if they were not. NVIDIA changed the Nemotron 3 Super license in a commit on 14 March 2026, four days after the repo was created. Google's Gemma 4 card carries a revision date of 30 July 2026 against repos created in March. Both are ordinary housekeeping. Both also mean the text you read during evaluation is not necessarily the text sitting there now.
#!/usr/bin/env bash
set -euo pipefail
# models.txt holds one Hugging Face repo id per line.
# Vendor the exact license text you shipped against, so a later vendor edit
# lands as a git diff instead of a surprise in a diligence call.
mkdir -p vendor/licenses
: > vendor/licenses/SHA256SUMS
while read -r repo; do
[ -z "$repo" ] && continue
out="vendor/licenses/${repo//\//__}.LICENSE"
if curl -fsSL "https://huggingface.co/${repo}/raw/main/LICENSE" -o "$out"; then
sha256sum "$out" >> vendor/licenses/SHA256SUMS
else
echo "MISSING $repo (gated repo, or no LICENSE at the repo root)" >&2
fi
done < models.txt
# Run this in CI. A non-empty diff means the terms moved under you.
if ! git diff --exit-code --quiet vendor/licenses/; then
echo "License text changed since the last commit. Re-read before release." >&2
git --no-pager diff --stat vendor/licenses/
exit 1
fi
The commit is your evidence of what the terms said the day you shipped.
| Claim | Primary source checked | Status, 11 Aug 2026 |
|---|---|---|
| Kimi K3 five conditions, US$20M gate | Raw LICENSE, Kimi-K3 | Confirmed |
| K2.7-Code is MIT plus display clause | Raw LICENSE, K2.7-Code | Confirmed, no MaaS gate |
| Gemma 4 is Apache 2.0 | ai.google.dev card, rev 2026-07-30 | Confirmed, all five sizes |
| Llama 4 700M MAU threshold | Llama 4 license, 5 Apr 2025 | Confirmed |
| Medium 3.5 is Modified MIT | Raw LICENSE, Medium-3.5-128B | Confirmed, US$20M monthly |
| Muse Glimmer is Apache 2.0 | meta-models/Muse-Glimmer-30B | Confirmed, repo created 9 Aug 2026 |
| Nemotron 3 has one license | Ultra-550B-A55B and Super-120B-A12B cards | False, family is split |
| K3 60, GLM-5.2 53, V4 Flash 52 | Artificial Analysis Index v4.1.1 | Confirmed, read 11 Aug 2026 |
| Llama 4 raw LICENSE is fetchable | meta-llama/Llama-4-Scout, raw request | False, HTTP 401 |
What I Would Actually Pick
For a client shipping a commercial product on self-hosted weights, I would take GLM-5.2 over Kimi K3, knowingly. On the Artificial Analysis Intelligence Index v4.1.1, read 11 August 2026, K3 at maximum reasoning effort scores 60 and leads the open-weight field. GLM-5.2 at maximum effort scores 53, DeepSeek V4 Flash 0731 scores 52. Seven points is a real gap, and it is worth less than an MIT file that never needs a counterparty to answer an email. Those are vendor-independent numbers from a third-party harness, which is the only reason I will quote any of them.
Gemma 4 is the harder call and I will not pretend otherwise. The 31B scores 30 on that same index, against K3's 60. That is not a rounding error, and anyone who tells you the license question makes it disappear is selling something. Pay that price only when the Apache patent grant is doing real work for you, which for most products it is not.
- Reselling inference? Kimi K3 and MiniMax M3 are out until somebody signs a contract. Pick from tier one and end the evaluation.
- Internal tooling only? K3's condition 4 genuinely exempts you, and the capability lead is free. Define "internal" first: a customer-facing support bot is not internal.
- Regulated industry, model inside the product? Apache 2.0 beats MIT here for the patent grant, so Gemma 4, Mistral Large 3 and Muse Glimmer ahead of GLM-5.2 and DeepSeek V4. You are paying capability for patent cover, so make somebody senior sign off on that trade rather than letting it happen by default.
- Looking at Mistral? Large 3 and Ministral 3 are fine. Medium 3.5 is not, if you clear US$20M in any single month.
- Still defaulting to Llama? Stop. Most restrictive license on this page, manually gated repos, and no code change since May 2025.
One process note that costs nothing: put the license decision in the same document as the model decision, with the file hash in it. Teams that split them pick on capability in week one and find the terms in week nine.
Related Articles
Frequently Asked Questions
Q: Is Kimi K3 open source?
No. Moonshot AI releases K3 under the bespoke Kimi K3 License and calls it open weights, not open source, which is accurate. The license bolts a Model-as-a-Service revenue gate and a display trigger onto an MIT-style grant. Those conditions fail the Open Source Definition, so the weights are free but the license does not qualify.
Q: Can I resell inference on an open-weight model?
Depends on the file. Apache 2.0 and MIT models such as Gemma 4, GLM-5.2, DeepSeek V4 and Qwen3.6 permit it with no threshold. Kimi K3 needs a signed agreement with Moonshot once group revenue passes US$20M in any 12 months, and MiniMax M3 needs prior written authorization above US$20M yearly.
Q: Does Llama 4 count as open source?
No. The Llama 4 Community License requires displaying "Built with Llama", prefixing derivative model names with "Llama", and requesting a discretionary license above 700 million monthly active users. Discretionary grants disqualify a license under the Open Source Definition. It is a permissive-ish commercial license, and calling it open source is marketing.
Q: Is Gemma 4 really Apache 2.0?
Yes. Gemma 4 is the first Gemma shipped without the custom Terms of Use that governed versions 1 through 3. The model card at ai.google.dev, last revised 30 July 2026, states Apache 2.0 for every variant: E2B, E4B, the 12B, the 26B-A4B mixture-of-experts and the 31B dense model. Each google/gemma-4 repo on Hugging Face carries apache-2.0 in its front matter, so the metadata and the card agree, which is not something you can assume.
Q: What does the MiniMax M3 attribution requirement involve?
Any commercial use must prominently display "Built with MiniMax M3" on a related website, user interface, blog post, about page or product documentation. Separately, commercial users below US$20M yearly revenue must send a one-time notice email to api@minimax.io, and those above need prior written authorization.
Q: Which open-weight license is safest for a commercial product?
Apache 2.0, because it adds an express patent grant that MIT lacks. Gemma 4, Mistral Large 3, Ministral 3, Qwen3.6 and Muse Glimmer all ship under it with no revenue gate, no attribution trigger and no naming rule. MIT models like GLM-5.2 and DeepSeek V4 carry no patent protection.
