What Open-Weight Model Licenses Actually Let You Do in 2026

Quick answer: Yes, but not under a modified MIT license, whatever the summaries say. Kimi K3 ships under a bespoke Kimi K3 License: commercial use is free until you or an affiliate operate a Model-as-a-Service business and group revenue clears US$20M over any consecutive 12 months, which then requires a signed agreement with Moonshot AI before any commercial use. Internal use, meaning use that never exposes the model or its outputs to third parties, is exempt.

Last updated: August 2026

Search for the Kimi K3 license and most top results call it a modified MIT license. It is not. Moonshot AI's coding model, Kimi K2.7-Code, genuinely is MIT plus one clause. K3 is a different file with its own name, five numbered conditions, and a revenue gate that can stop a launch.


Open-weight licensing has split into four things that all get called open: Apache 2.0 you can stop thinking about, MIT with a logo rule that only fires at Facebook scale, permissive up to a revenue number with a contract after it, and Llama 4, which is not open source and whose repos have not been touched since May 2025.


Below is a clause-by-clause read of the license files as they stood on 11 August 2026: thresholds, measurement windows, and the addresses you have to write to. Capability shows up once, at the end, where it changes a decision. Everywhere else it is noise.


"Modified MIT" Is the Wrong Label for Kimi K3


The mistake is understandable. The grant paragraph is lifted from MIT, down to "Permission is hereby granted, free of charge, to any person (the "Licensee") obtaining a copy of this software". The tell is the parenthetical: plain MIT never defines a party, because nothing below refers back to one. Here, five conditions do.



Condition 2 is not what people assume, and the exact wording is worth reading twice: "If the Licensee or any of its affiliates operates a Model as a Service business, and the aggregate revenue of the Licensee and its affiliates exceeds 20 million US dollars...". Two separate tests, joined by an and. Operating MaaS opens the question; group revenue answers it. So the number is not what the MaaS line earns, it is what the whole group earns, and a shoe company running one API that a partner also calls is arguably inside the gate on revenue that has nothing to do with models. Moonshot publishes an address for it: license@moonshot.ai.


K3 imposes nothing else: no derivative naming rule, no ban on training other models on its outputs, no acceptable-use policy.


Four Tiers, Not One Alphabetical Table


A license column next to thirteen model names hides the only thing procurement cares about: does this term ever require a human at the vendor to say yes? Sort by that and you get four tiers, and models move between them within one vendor, sometimes within one family.


ModelLicenseRedistribute?Commercial gateAttributionNaming rule
Gemma 4Apache 2.0Yes + NOTICENoneNoneNone
DeepSeek V4MITYes + noticeNoneNoneNone
GLM-5.2MITYes + noticeNoneNoneNone
Qwen3.6 openApache 2.0Yes + NOTICENoneNoneNone
Mistral Large 3Apache 2.0Yes + NOTICENoneNoneNone
Muse Glimmer 30BApache 2.0Yes + NOTICENoneNoneNone
Nemotron 3 UltraOpenMDW-1.1Yes + noticeNoneNoneNone
Nemotron 3 SuperNVIDIA Nemotron OMLYesNoneNoneNone
Kimi K2.7-CodeModified MITYes + noticeNone100M MAU or $20M/moNone
Kimi K3Kimi K3 LicenseYes + noticeMaaS + US$20M / 12mo100M MAU or $20M/moNone
MiniMax M3MiniMax CommunityYes + noticeUS$20M / yearAny commercial useNone
Mistral Medium 3.5Modified MITYes + noticeUS$20M/mo, company-wideNoneNone
Llama 4Llama 4 CommunityYes + agreement700M MAU at releaseAny redistributionPrefix "Llama"

Tier 1: Clean Permissive, and the Apache Versus MIT Split


Gemma 4 is the headline change. It ships under Apache 2.0, the first Gemma free of the bespoke Terms of Use that governed versions 1 through 3. The model card at ai.google.dev, last revised 30 July 2026, states Apache 2.0 for the whole family, and every google/gemma-4 repo carries apache-2.0 in its front matter. If your only objection to Gemma was the old terms, it is gone.


One distinction inside tier one still matters, and it is not permissiveness. Apache 2.0 section 3 carries an express patent license from every contributor, with defensive termination if you sue over the work. MIT has none. For a chatbot nobody cares. Inside a medical device or a trading system, it separates covered risk from open risk.



Muse Glimmer went up on 9 August 2026 under Apache 2.0, and it sits under meta-models, not meta-llama. Pipelines that pin the old org prefix miss it entirely.


Trying to get this past a proof of concept? Enterprise AI work rarely stalls on the model. It stalls on what sits underneath: retrieval that returns the wrong chunk, permissions that leak across tenants, and no agreed way to tell a good answer from a bad one. We build the pipeline, the access rules and the evaluation harness so the thing can actually go live.

Book an AI readiness call AI and ML services

Tier 2: Permissive With a Display Trigger


Kimi K2.7-Code is the clean example, and the reason the K3 confusion spread. Its file is genuinely titled Modified MIT License, its card declares license_name: modified-mit, and it adds exactly one thing: products above 100 million monthly active users or US$20M monthly revenue must show "Kimi K2.7 Code" in the interface. No MaaS clause. No separate agreement. Somebody read that file, wrote the summary, and the summary got applied to the sibling model.


Below those thresholds it behaves as MIT: self-host, fine-tune, resell inference, tell nobody. A display trigger is cheap. A revenue gate is not, because clearing it needs a countersignature nobody owes you.


Tier 3: Permissive Until a Number, Then a Negotiation


Three models sit here, with thresholds over three different windows against three different revenue bases. Llama 4 is in the table too, for contrast, though it belongs a tier down. Note what the differences do: Mistral Medium 3.5 measures monthly and company-wide, so an enterprise that would never trip Kimi K3 trips Mistral in its first month.


ModelWhat is measuredWindowWhose revenueWhat you must do
Kimi K3 (c2)Group revenue, MaaS operatorAny consecutive 12 monthsLicensee + affiliatesSign agreement, license@moonshot.ai
Kimi K3 (c3)Product MAU or monthly revenueMonthlyThe productShow "Kimi K3" in the UI
MiniMax M3, overProduct and service revenueYearlyYoursWritten authorization, api@minimax.io
MiniMax M3, underProduct and service revenueYearlyYoursOne-time notice, api@minimax.io
Mistral Medium 3.5Global consolidated revenueMonthlyYour company or employerBuy license, sales@mistral.ai
Llama 4MAU at version release datePreceding calendar monthYou + affiliatesRequest license, Meta's discretion

MiniMax M3 carries the obligation nobody mentions. Even below the threshold, commercial use requires a one-time notice email to api@minimax.io using the subject line the license names, and "Built with MiniMax M3" attribution is mandatory at any scale. Its video model H3 also carries geographic exclusions M3 does not, so "we cleared MiniMax" is not portable.


Tier 4: A Community License That Is Not Open Source


The Llama 4 Community License Agreement, effective 5 April 2025, imposes obligations no OSI-approved license contains: ship a copy of the agreement, display "Built with Llama", and prefix any model trained from Llama materials with "Llama". Above 700 million monthly active users you must request a license Meta may grant at its sole discretion. Discretionary grants disqualify a license under the Open Source Definition.


One widely repeated claim is wrong: the Llama 4 license does not prohibit using Llama outputs to train other models. That lived in earlier Llama terms. Version 4 replaces the ban with a naming rule, and says so in the same breath: if you use the materials "or any outputs or results" to train, fine-tune or otherwise improve a model you then distribute, you must put "Llama" at the front of its name. Read as a permission with a condition attached, which is what it is, distillation is on the table.


The bigger problem is age. On 11 August 2026 the meta-llama org lists Llama 4 Scout and Maverick, Llama-Guard-4, the Prompt-Guard models and Llama 3.3. No Llama 5. The Llama 4 repos have not been modified since 22 May 2025, and the most recently touched repo in the entire org dates to 12 November 2025. Llama-4-Scout reports gated: "manual", so a human at Meta approves each request: fine for a laptop, a supply chain dependency when CI needs weights at 3am.


The Vendor-Level Assumptions That Break


Most mistakes we see in client review come from reasoning about a vendor instead of a file.



The Gate Keys On Your Revenue, Not Your Usage


Here is the failure mode that bites. Teams assess a gated license by asking whether their usage is big enough to matter. Usage is never the trigger. Every gate reads on revenue or user count, properties of the business, not the deployment.


The sequence runs: pilot at US$4M ARR, model free, architecture locked, prompts written against one tokenizer and one tool-calling format. Eighteen months later a good sales year pushes the group past US$20M, and the same deployment is a negotiation with a vendor who knows what switching costs. The upper hand arrived through sales, not engineering.


Python - encode the Kimi K3 gate so it fails a CI check, not a board meeting
from dataclasses import dataclass

@dataclass
class Deployment:
    group_revenue_last_12m_usd: float   # licensee AND affiliates, all revenue
    product_monthly_revenue_usd: float
    product_mau: int
    resells_inference: bool             # third parties get API access to the model
    exposes_outputs: bool               # outputs or capabilities leave your org

def kimi_k3_obligations(d: Deployment) -> list[str]:
    """Kimi K3 License, conditions 2, 3 and 4, as read on 2026-08-11."""
    if not d.exposes_outputs:
        return []   # condition 4(a): internal use is exempt from 2 and 3
    out = []
    # Condition 2 reads on GROUP revenue, not on what the MaaS line earns.
    if d.resells_inference and d.group_revenue_last_12m_usd > 20_000_000:
        out.append("c2: signed agreement with Moonshot AI before ANY commercial use")
    if d.product_mau > 100_000_000 or d.product_monthly_revenue_usd > 20_000_000:
        out.append("c3: display 'Kimi K3' prominently in the product UI")
    return out

pilot  = Deployment(18_500_000, 900_000, 350_000, resells_inference=True, exposes_outputs=True)
year_2 = Deployment(21_200_000, 1_100_000, 410_000, resells_inference=True, exposes_outputs=True)

print("pilot :", kimi_k3_obligations(pilot) or ["none"])
print("year 2:", kimi_k3_obligations(year_2) or ["none"])

# pilot : ['none']
# year 2: ['c2: signed agreement with Moonshot AI before ANY commercial use']
# Nothing about the deployment changed. Revenue crossed a line, and the model
# picked in month three became a contract negotiation in month fifteen.

Two defenses. Track the threshold in the same dashboard as ARR, tagged with the model name, so crossing it opens a ticket, not an audit. And if the client resells inference at all, rule out tier three on day one: K3's condition 2 then blocks all commercial use, not only the MaaS part.


The Metadata Badge Lies, So Read the File


Tooling that reads the SPDX-style license field and stops is wrong on exactly the models where being wrong costs money. Kimi K3, Kimi K2.7-Code, Llama 4 Scout, MiniMax M3, Mistral Medium 3.5 and both Nemotron 3 tiers all declare license: "other", which tells you nothing. The value that identifies the file sits in license_name, and it settles the argument on its own: K2.7-Code declares modified-mit, K3 declares kimi-k3. Different files, different names, and only one of them has a revenue gate.


Python - pull declared license, gating status and clause hits for a model list
import re
import requests

REPOS = [
    "moonshotai/Kimi-K3",
    "moonshotai/Kimi-K2.7-Code",
    "deepseek-ai/DeepSeek-V4-Pro",
    "zai-org/GLM-5.2",
    "Qwen/Qwen3.6-27B",
    "mistralai/Mistral-Large-3-675B-Instruct-2512",
    "mistralai/Mistral-Medium-3.5-128B",
    "MiniMaxAI/MiniMax-M3",
    "meta-models/Muse-Glimmer-30B",
    "meta-llama/Llama-4-Scout-17B-16E-Instruct",
]

# Phrases that mean a lawyer has to read the file before you ship.
GATES = {
    "revenue_gate":       r"(monthly revenue|yearly revenue|consolidated .{0,25}revenue|aggregate revenue)",
    "separate_agreement": r"(separate agreement|prior written authorization|request a license|commercial license)",
    "display_clause":     r"prominently display",
    "naming_clause":      r"beginning of any such AI model name",
    "mau_threshold":      r"monthly active users",
}

def metadata(repo_id):
    r = requests.get(f"https://huggingface.co/api/models/{repo_id}", timeout=30)
    r.raise_for_status()
    body = r.json()
    card = body.get("cardData") or {}
    return {
        "license": card.get("license"),            # often just "other"
        "license_name": card.get("license_name"),  # the value that identifies it
        "gated": body.get("gated", False),         # False, "auto" or "manual"
    }

def license_text(repo_id):
    """Return the license text, or None if it could not be read."""
    for name in ("LICENSE", "LICENSE.md", "LICENSE.txt"):
        r = requests.get(f"https://huggingface.co/{repo_id}/raw/main/{name}", timeout=30)
        # Gated repos answer 401 here; Llama-4-Scout does. A redirect that lands
        # on a login page can still answer 200 with HTML, so check the body too.
        if r.status_code == 200 and not r.text.lstrip().startswith("<"):
            return r.text
    return None

for repo in REPOS:
    meta = metadata(repo)
    text = license_text(repo)
    print(f"{repo}")
    print(f"  spdx    : {meta['license']}")
    print(f"  name    : {meta['license_name']}")
    print(f"  gated   : {meta['gated']}")
    if text is None:
        # Unreadable is not permissive. Never let this print as a clean pass.
        print("  clauses : UNREADABLE (gated, or no LICENSE at the repo root)")
        continue
    hits = sorted(k for k, pat in GATES.items() if re.search(pat, text, re.I))
    print(f"  clauses : {', '.join(hits) if hits else 'none matched'}")

The regex layer is deliberately crude. It answers one question: does this file contain a sentence that needs a human? A hit on separate_agreement or revenue_gate sends it to counsel. The unreadable branch matters more than the patterns do. Hugging Face answers an unauthenticated raw request against a gated repo with HTTP 401, so Llama-4-Scout yields no text and every regex misses it. Collapse that into an empty result and the most restrictive license in the list prints as the cleanest one.


Pin the License Like a Dependency


License files are mutable, and the tooling treats them as if they were not. NVIDIA changed the Nemotron 3 Super license in a commit on 14 March 2026, four days after the repo was created. Google's Gemma 4 card carries a revision date of 30 July 2026 against repos created in March. Both are ordinary housekeeping. Both also mean the text you read during evaluation is not necessarily the text sitting there now.


bash - vendor license text into git so vendor edits arrive as diffs
#!/usr/bin/env bash
set -euo pipefail

# models.txt holds one Hugging Face repo id per line.
# Vendor the exact license text you shipped against, so a later vendor edit
# lands as a git diff instead of a surprise in a diligence call.

mkdir -p vendor/licenses
: > vendor/licenses/SHA256SUMS

while read -r repo; do
  [ -z "$repo" ] && continue
  out="vendor/licenses/${repo//\//__}.LICENSE"
  if curl -fsSL "https://huggingface.co/${repo}/raw/main/LICENSE" -o "$out"; then
    sha256sum "$out" >> vendor/licenses/SHA256SUMS
  else
    echo "MISSING  $repo  (gated repo, or no LICENSE at the repo root)" >&2
  fi
done < models.txt

# Run this in CI. A non-empty diff means the terms moved under you.
if ! git diff --exit-code --quiet vendor/licenses/; then
  echo "License text changed since the last commit. Re-read before release." >&2
  git --no-pager diff --stat vendor/licenses/
  exit 1
fi

The commit is your evidence of what the terms said the day you shipped.


ClaimPrimary source checkedStatus, 11 Aug 2026
Kimi K3 five conditions, US$20M gateRaw LICENSE, Kimi-K3Confirmed
K2.7-Code is MIT plus display clauseRaw LICENSE, K2.7-CodeConfirmed, no MaaS gate
Gemma 4 is Apache 2.0ai.google.dev card, rev 2026-07-30Confirmed, all five sizes
Llama 4 700M MAU thresholdLlama 4 license, 5 Apr 2025Confirmed
Medium 3.5 is Modified MITRaw LICENSE, Medium-3.5-128BConfirmed, US$20M monthly
Muse Glimmer is Apache 2.0meta-models/Muse-Glimmer-30BConfirmed, repo created 9 Aug 2026
Nemotron 3 has one licenseUltra-550B-A55B and Super-120B-A12B cardsFalse, family is split
K3 60, GLM-5.2 53, V4 Flash 52Artificial Analysis Index v4.1.1Confirmed, read 11 Aug 2026
Llama 4 raw LICENSE is fetchablemeta-llama/Llama-4-Scout, raw requestFalse, HTTP 401

What I Would Actually Pick


For a client shipping a commercial product on self-hosted weights, I would take GLM-5.2 over Kimi K3, knowingly. On the Artificial Analysis Intelligence Index v4.1.1, read 11 August 2026, K3 at maximum reasoning effort scores 60 and leads the open-weight field. GLM-5.2 at maximum effort scores 53, DeepSeek V4 Flash 0731 scores 52. Seven points is a real gap, and it is worth less than an MIT file that never needs a counterparty to answer an email. Those are vendor-independent numbers from a third-party harness, which is the only reason I will quote any of them.


Gemma 4 is the harder call and I will not pretend otherwise. The 31B scores 30 on that same index, against K3's 60. That is not a rounding error, and anyone who tells you the license question makes it disappear is selling something. Pay that price only when the Apache patent grant is doing real work for you, which for most products it is not.



One process note that costs nothing: put the license decision in the same document as the model decision, with the file hash in it. Teams that split them pick on capability in week one and find the terms in week nine.


Pranay Vatsal, Founder & CEO

Pranay Vatsal is the Founder & CEO of CelestInfo with deep expertise in Snowflake, data architecture, and building production-grade data systems for global enterprises.

Related Articles

Frequently Asked Questions

Q: Is Kimi K3 open source?

No. Moonshot AI releases K3 under the bespoke Kimi K3 License and calls it open weights, not open source, which is accurate. The license bolts a Model-as-a-Service revenue gate and a display trigger onto an MIT-style grant. Those conditions fail the Open Source Definition, so the weights are free but the license does not qualify.

Q: Can I resell inference on an open-weight model?

Depends on the file. Apache 2.0 and MIT models such as Gemma 4, GLM-5.2, DeepSeek V4 and Qwen3.6 permit it with no threshold. Kimi K3 needs a signed agreement with Moonshot once group revenue passes US$20M in any 12 months, and MiniMax M3 needs prior written authorization above US$20M yearly.

Q: Does Llama 4 count as open source?

No. The Llama 4 Community License requires displaying "Built with Llama", prefixing derivative model names with "Llama", and requesting a discretionary license above 700 million monthly active users. Discretionary grants disqualify a license under the Open Source Definition. It is a permissive-ish commercial license, and calling it open source is marketing.

Q: Is Gemma 4 really Apache 2.0?

Yes. Gemma 4 is the first Gemma shipped without the custom Terms of Use that governed versions 1 through 3. The model card at ai.google.dev, last revised 30 July 2026, states Apache 2.0 for every variant: E2B, E4B, the 12B, the 26B-A4B mixture-of-experts and the 31B dense model. Each google/gemma-4 repo on Hugging Face carries apache-2.0 in its front matter, so the metadata and the card agree, which is not something you can assume.

Q: What does the MiniMax M3 attribution requirement involve?

Any commercial use must prominently display "Built with MiniMax M3" on a related website, user interface, blog post, about page or product documentation. Separately, commercial users below US$20M yearly revenue must send a one-time notice email to api@minimax.io, and those above need prior written authorization.

Q: Which open-weight license is safest for a commercial product?

Apache 2.0, because it adds an express patent grant that MIT lacks. Gemma 4, Mistral Large 3, Ministral 3, Qwen3.6 and Muse Glimmer all ship under it with no revenue gate, no attribution trigger and no naming rule. MIT models like GLM-5.2 and DeepSeek V4 carry no patent protection.