Skip to content

AI Industry & Models

Open Model Licenses Decide Whether You Can Sell the API

Downloading model weights proves access, not commercial permission. Before launching a paid API, teams need to trace the model’s rules through hosting, fine-tuning, attribution and downstream distribution.

Tobias LundIndustry & Models Writer

October 9, 2026 · 8 min read

Laptop showing a model license beside an API deployment checklist and model repository files.
Laptop showing a model license beside an API deployment checklist and model repository files.

Take one concrete deployment: a team downloads model weights, fine-tunes them on support tickets, places the resulting model behind a paid API and gives one customer the fine-tuning adapter. Each step can trigger a different clause, even though the weights arrived through the same familiar sequence of clicking through a model page and pulling files into a repository.

The first useful distinction is between open weights, meaning parameters that can be downloaded, and an open-source license that grants broad rights to use, modify and redistribute software. Vendors regularly publish weights under custom agreements rather than a standard software license. The files may be inspectable and runnable on private infrastructure while the contract still limits certain users, requires a product notice or treats hosted access as distribution.

That makes license review a deployment task, not a procurement footnote. This explainer offers a first-pass checklist based on vendor documentation, not legal advice; disputed terms, unusual products and material revenue exposure belong with qualified counsel.

Start with the exact artifact

Model families do not have one permanent licensing status. A vendor may release one checkpoint under Apache License 2.0, another under research-only terms and a later model under a custom community license. Repositories, quantized copies and fine-tunes can add another layer because their publishers may attach terms covering code or modifications without possessing authority to change the original model’s license.

For the support API, the team should record the model name, checkpoint, source repository, license file and acceptable-use policy in the same change request that records the container image. A link to the vendor’s general model page is insufficient. If an engineer later swaps in a larger checkpoint, the review must follow the weights rather than assuming the family name settles the question.

A model card, which documents an artifact’s intended use and technical characteristics, helps locate the governing files but does not override them. Read the license, incorporated policies and notices together. “Commercial use permitted” may answer whether the company can charge money, yet leave unresolved whether it can expose an API, distribute an adapter or omit the vendor’s name from the interface.

Redistribution starts earlier than many teams expect

The support deployment crosses at least two obvious distribution points. Giving a customer the fine-tuned weights is one. Publishing an adapter, a smaller set of learned parameters applied to a base model, may be another, depending on how the agreement defines derivatives and covered materials.

Apache 2.0 grants broad permissions to reproduce, modify, sublicense and distribute covered work, subject to conditions including preservation of the license and relevant notices, marking modified files and carrying required content from a NOTICE file. It does not grant trademark rights. For a model whose official card identifies Apache 2.

0 as the governing license, commercial redistribution is therefore much more straightforward than it is under a bespoke model agreement, although separate code, datasets and trademarks still need their own review.

Meta’s Llama 3.1 Community License takes a different route. Its distribution conditions require a copy of the agreement and a prominent “Built with Llama” notice when covered materials, derivatives, products or services are made available. The agreement also says that an AI model trained or improved using Llama materials or their outputs, when distributed or made available, must include “Llama” at the beginning of its name.

It sets an additional licensing threshold for products or services above 700 million monthly active users in the preceding calendar month.

Those terms change the support API’s release checklist. The team cannot treat attribution as a forgotten text file inside a container, and naming a derivative becomes a product decision rather than an engineering preference. Most companies are nowhere near Meta’s user threshold, but an acquiring platform or a broadly deployed consumer service cannot ignore it.

Google’s Gemma terms also require attention to the delivery mechanism. Their definition of distribution includes making Gemma or its functionality available through hosted services, web APIs or other remote means. The support endpoint can therefore trigger distribution obligations even if no customer downloads a weight file. Google’s terms require recipients to receive the agreement in covered distribution scenarios, preserve specified notices and follow the incorporated prohibited-use policy.

The comparison is the practical point: “we only host it” is not a universal exemption. Apache 2.0 does not impose a model-specific hosted-service regime, while custom licenses can expressly bring remote access inside their distribution rules. The team needs the definition section before it needs a philosophical debate about whether an API counts as shipping software.

Hosted access changes the compliance surface

Once the support model sits behind an endpoint, acceptable-use language becomes an operational control. A license may prohibit categories of use that the model can technically perform, which means an API key, rate limit and generic terms of service may not be enough to keep the deployment inside the vendor’s conditions.

Meta publishes an Acceptable Use Policy for Llama covering prohibited conduct. Google incorporates a Prohibited Use Policy into Gemma’s terms. The categories and wording should be read from the versions attached to the chosen model, rather than copied from a different vendor’s policy or summarized from memory.

For the support API, that review produces concrete setup work: define which customer workflows are allowed, block requests the vendor expressly prohibits, document how reports are handled and retain enough account information to suspend misuse. A team that cannot enforce a restriction should not promise compliant hosted access merely because its intended use is benign. Intent does not constrain an exposed endpoint.

This is also where a permissively licensed alternative can be worth more than a model with slightly better internal results. If the official artifact uses Apache 2.0 and carries no separate model-specific acceptable-use contract, the company may avoid building controls solely to satisfy a vendor license. It will still face applicable law, customer contracts and its own safety policy, but those are separate sources of obligation.

Fine-tuning does not erase the upstream terms

A fine-tuned model is not a clean licensing reset. Meta’s Llama license expressly includes fine-tuned versions within its treatment of derivative works. Google’s Gemma terms cover derivative works under their own definitions and conditions. Changing the support model with company tickets therefore adds rights in the new training work without automatically removing obligations attached to the base weights.

Adapters deserve an explicit decision. They may contain only learned changes rather than a full copy of the base parameters, but teams should not infer from file size that upstream terms disappear. The relevant questions are whether the license defines the adapter as a derivative, whether it can operate without the original model and whether distributing it invokes notice, naming or pass-through conditions. Those are legal-characterization questions, not benchmark questions.

Outputs create another branch. Some custom model agreements address using outputs to train or improve another model, as the Llama language does in specified circumstances. If the support team plans to collect responses and train a replacement model, it should review that plan before building the dataset pipeline. A permissive right to run the first model does not necessarily answer what can be done with a synthetic training corpus produced by it.

A first-pass gate for the release ticket

The team can turn the support API into a six-part release gate.

Identify the governing package. Save the exact license, policy documents, model card and notices alongside the checkpoint identifier. Record where the files came from and whether a third-party quantizer or fine-tuner added separate terms.

Draw the delivery path. Mark private inference, employee access, customer API access, downloadable adapters and downloadable weights separately. Then map each path against the license’s definitions of distribution, making available and remote access.

Test the commercial actor. Check restrictions based on company size, monthly active users, geography or field of use. Meta’s documented 700 million-user provision is an example of a condition that may be irrelevant to a small vendor but material after acquisition or integration into a larger service.

Place the notices before launch. Determine the required location and wording for attribution, license copies, modification notices and product naming. For the support API, that may put text in the dashboard, documentation and customer agreement rather than only in the source repository.

Translate use restrictions into controls. Assign an owner for prohibited-use enforcement, customer suspension and policy updates. If nobody monitors revisions to an incorporated acceptable-use policy, the original approval will age while the live endpoint stays unchanged.

Review [every model swap](/articles/shadow-test-a-new-ai-model-before-it-reaches-customers). A faster checkpoint or cheaper quantization can alter both technical behavior and license provenance. The fallback is to hold the existing model in production until the replacement’s documentation passes the same gate.

This checklist cannot determine whether a disputed clause is enforceable or whether a particular adapter qualifies as a derivative. It can stop a common operational failure: discovering after launch that the paid API, product name or customer download crossed a condition nobody recorded.

Questions people ask

Can

I use a downloadable model in a commercial product?

Sometimes, but download access alone does not answer the question. Confirm that the exact checkpoint permits commercial use, then inspect conditions covering hosted access, redistribution, attribution, acceptable use and derivatives. Research-only terms or custom restrictions can block a paid deployment even when the weights are publicly accessible.

Does hosting a model avoid redistribution requirements?

Not under every license. Google’s Gemma terms include hosted services, web APIs and other remote access in their distribution framework, while Apache 2.0 does not add a model-specific hosted-access condition. Read the agreement’s definitions before assuming that keeping weights on your servers avoids downstream obligations.

Can

I remove the original license after fine-tuning?

Fine-tuning does not automatically remove upstream terms. Custom agreements commonly cover modified or fine-tuned versions, and Apache 2.0 keeps notice and license obligations for distributed covered material. Record the base model’s requirements alongside your new weights, adapter and training code.

Is an Apache 2.0 model unrestricted?

No. Apache 2.0 grants broad commercial, modification and distribution rights, but it still requires license and notice handling and does not grant trademark rights. The repository may also contain components under other licenses, so verify that Apache 2.

0 covers the model artifact rather than only its inference code.

ShareFacebook
open modelsdeveloper toolingai pricing and accessopen modelsmodel licensescommercial aimodel deployment

One story a day

The story of the day, in your inbox

One real story about AI each morning — no hype, no alarm, just company for the road.

Read next

A laptop displaying a supplier PDF beside extracted table cells and a rotated scanned page.

AI Industry & Models

AI Can Read a PDF Page and Still Lose the Document

Direct PDF input is now practical for many multimodal models. A test packet shows why tables, footnotes, diagrams, and cross-page references still need a parsing pipeline.

Tobias Lund · 7 min read

A laptop displaying model-route logs beside a printed refund policy and a customer-support ticket.

AI Industry & Models

Model Routing Cuts AI Costs Until It Misreads One Refund

A router can send routine support work to a cheaper model. The savings disappear when a short refund request hides a policy exception, so routing and model quality need separate tests.

Tobias Lund · 7 min read