On 5 April 2025, Meta's Llama 4 blog still said open source. The file that actually ships with Scout and Maverick is the Llama 4 Community License. It is not Apache. It is not MIT. If your product, or your affiliates', crossed 700 million monthly active users last calendar month, you ask Meta for a second licence. Meta may say no.
That gap, between the blog and the file, is the whole subject. I read the official cards on 11 August 2026 for the families people actually serve: Llama 4, Qwen 3.x, Gemma 4, DeepSeek from R1 through V4, Mistral's open line, OpenAI's gpt-oss, and Microsoft Phi-4. A later commit can change a row. The method does not.
Four things get sold as one word.
Weights. Can you download the parameters and run them without an API key.
Data. Is the training corpus published so someone else can rebuild the model.
Code. Is the training or inference stack under an OSI licence, or just a README screenshot.
Use. Can you sell a product on top of it, and does that right die at a user count, a geography, or a prohibited-use list.
Apache 2.0 and MIT are a clean yes on use. A community licence with a 700 million user clause is a yes until it is not. A research licence is a no with a download button. None of the seven families publish the corpus. If "open source" still means source, the source is missing.
The Open Source Initiative tried to stop the collapse on 28 October 2024. OSAID 1.0 asks for the four software freedoms on the system: use, study, modify, share. It wants enough "data information" to rebuild, not necessarily every raw token. Meta objected that week. The Software Freedom Conservancy said OSAID was already too soft, because it does not demand the actual dump. So the referee fight is three-sided. Meta wants the phrase without the data. OSI wants a middle. The people who wrote the original definition want the books.
Almost nobody runs the model that tries the hard version. Allen Institute's OLMo line puts weights, training code, and a documented corpus in public. The models people actually serve skip the data cell. That is the market's vote.
Llama. The veto is the product
The 700 million clause is not new. It sat in Llama 2 and 3. Counsel notes have walked through the text: if products made available by you or your affiliates were used by more than 700 million monthly active users in the preceding calendar month, you request a licence, which Meta may grant in its sole discretion, before any such use. Google, Microsoft, Amazon, and a handful of consumer apps live above that line. A startup does not. The line is not a price list. It is a veto.
The same file bans using Llama outputs to train a competing model and attaches an acceptable-use policy. Llama 4 added limits around EU multimodal use that the Llama 3 text did not have. Meta's own wording drifted from "open source" on Llama 2 and 3 to "open-weight" on Llama 4. The weights are real. The OSI label is not.
For most builders the file is free. For Meta's actual peers it is a commercial negotiation. That is what the number is for.
Qwen and Gemma paid for the OSI word
Alibaba's early Qwen models used a custom Tongyi Qianwen licence. From Qwen3 the team put Apache 2.0 on the open-weight cards. Qwen-Max stays behind an API. The 2026 cards for Qwen3.5 and Qwen3.6, including the 27B and 9B dense builds, stay on Apache.
Google did the same walk. Gemma 1 and 2 sat under Google's own terms. Gemma 4 cards list Apache 2.0. Hugging Face's April 2026 write-up called that out on purpose: the family is "truly open with Apache 2 licenses." You can use, modify, and ship without writing to Mountain View and without a user-count veto.
Neither family publishes the corpus. Apache on the weights is not Apache on the books, the crawl, or the synthetic traces. You can fork the file. You cannot audit the diet.
DeepSeek switched the file
DeepSeek V3 sat under the DeepSeek Model License: commercial use allowed, not MIT. From DeepSeek-R1 the weights themselves are MIT. V4-Pro and the July 2026 V4-Flash cards stay on MIT. The code repos were already MIT. For a Western company that wants to host the checkpoint, that is a shorter memo than Llama.
MIT does not give you the data. It does not stop a government from restricting the download. It does not make a trillion-parameter mixture cheap to run. It does make the licence question boring, which is the point.
Capability caught up while the file got cleaner. US CAISI published an evaluation of DeepSeek V4 Pro in April 2026. The UK AI Security Institute put GLM-5.2 and DeepSeek V4-Pro a few months behind closed frontier models on cyber, not a year. A permissive file on a frontier-adjacent model is a different object from a permissive file on a 7B toy.
Mistral keeps two shelves
Mistral's docs split the catalogue into Open and Premier. Open, on the current cards, is Apache 2.0 for 7B, Mixtral, NeMo, Pixtral 12B, Small, Magistral Small, and the Mistral 3 family, including Large 3. Premier stays behind the API. Some older or mid-tier cards still show a Research License or a modified MIT. Read the card, not the homepage. The logo does not change when the file does.
gpt-oss and Phi. Permissive, with a footnote
OpenAI's gpt-oss 120B and 20B weights are Apache 2.0 plus a usage policy. The policy is a prohibited-use list, not a 700 million gate. Lawyers treat that as lighter than Llama and heavier than raw Apache.
Microsoft Phi-4 variants are MIT. Small enough to run locally. Clean enough to put in a product without a Meta letter. The catch is quality, not the file.
What the hub actually sorts
Hugging Face lets you filter by licence tag. The tag is whatever the uploader typed. A Llama derivative often inherits "llama3" or "other." A Qwen fine-tune sometimes keeps Apache and sometimes does not. Fine-tunes inherit the base licence unless the tuner has the right to relicense, which they usually do not. A "Qwen-Llama merge" with an Apache tag is a filing error, not a legal fact.
Cloud marketplaces add a second contract. AWS, Azure, and Together can cut you off for acceptable-use breaches even when the weight file is MIT. The licence is necessary. It is not sufficient.
I am not using download rank as a licence rank. A two-million pull on a 70B card can be one lab fetching the same shard. I am using the licence file on the official card.
The Act does not care what the blog says
The EU AI Act does not treat "open" as a free pass. Article 2(12) exempts some free and open-source systems unless they are high-risk, prohibited, or under Article 50 transparency rules. GPAI models with systemic risk stay in scope even if the weights are downloadable. The Commission's GPAI guidelines say it in plainer language: an Apache card does not cancel documentation or copyright duties, and enforcement powers switched on 2 August 2026.
A Llama Community file is even less likely to count as a "free and open licence" under that text. The 700 million veto is a field-of-use limit.
Llama, Gemma, gpt-oss, and several Mistral cards also attach a use policy: no bioweapons, no unsolicited mass persuasion, no child sexual abuse material, sometimes no military. Apache and MIT do not contain those sentences. The policy file does. Breaking it can get you banned from the hub or a marketplace. It is not a statute, and it does not replace one. The AI Office can still fine a GPAI provider. A US company above 700 million MAU still needs Meta's letter.
What a counsel should actually open
Four questions, in this order.
- Which file is attached to the exact checkpoint we will serve, not the family blog post.
- Is that file OSI text, or a community licence with a scale trigger.
- Does a use policy or a cloud marketplace add rules the licence does not.
- Is any of the training data available, and if not, can we live with a model we cannot reproduce.
If (2) is community, write down the MAU of the product and of every affiliate. If (4) is no, stop calling the stack open source in the security review.
A Llama 5 card that dropped the 700 million clause and used Apache would move Meta into the Qwen column. A published, licensed training corpus for any of the seven would fill the first empty data cell on the table. Today the download is real. The data is not. The word "open" is doing work the files refuse to do.