Is Llama Open Source? License Clauses for OEMs

The OSI says Meta's Llama licenses are not open source. For a company shipping a product, the clauses that travel with the weights matter more, and they differ model by model.

By Harinderpal Hanspal on October 2026. Updated October 2026

The Open Source Initiative has said Llama's license is not open source, so "open weights" is the accurate label. For an OEM the useful question is which clauses ride along when the model ships in a product: attribution, naming, a policy incorporated by reference and, for Llama 4 multimodal models, an EU restriction.

Open-weight licenses sort into three tiers, and the user cap is the clause to readSketch of three stacked boxes. The top box holds Apache-2.0 and MIT models. The middle box holds a modified MIT license with a display clause. The bottom box holds community licenses with a monthly-user cap and an acceptable use policy, with the cap underlined in red. A note on the right says the open source definition also asks for information about the training data.Apache-2.0 or MITgpt-oss, Mistral Large 3, Gemma 4Modified MIT, display clauseKimi K3Community license, user capplus a use policy: Llama 3.3, 4fewest stringsmost stringsOSI also asksfor training datainformation
Open-weight licenses sort into three tiers, and the user cap is the clause to read

On 18 February 2025 the Open Source Initiative published a post titled "Meta's Llama license is still not Open Source" (OSI). It covers Llama 2 and Llama 3.x and does not name Llama 4. Its reasons are that the license fails freedom 0, the freedom to use the model for any purpose, and points 5 and 6 of the Open Source Definition, which bar discrimination against persons and limits on fields of endeavor.

That settles the label. It does not tell an OEM what it may do. This note is not legal advice, and every license below is as of 6 October 2026.

What the OSI definition asks for, and what Llama 4 adds

The Open Source AI Definition 1.0 asks for four freedoms (use, study, modify, share) and for three things under OSI-approved terms: the parameters, the complete source code used to train and run the system, and "sufficiently detailed information about the data used to train the system" (OSI). A download link for weights meets one of the three.

Llama 4 postdates the OSI post, so we do not attribute a verdict on it to the OSI. We can only report that the clauses the OSI objected to in the 3.x text are present in the Llama 4 text too.

Llama clauses an OEM should find by number

Both the Llama 3.3 license (6 December 2024) and the Llama 4 license (effective 5 April 2025) carry the same structure.

The Llama 4 use policy adds one more, for companies in Europe. Rights under Section 1(a) "are not being granted" to an individual domiciled in, or a company with a principal place of business in, the European Union. It applies to the multimodal Llama 4 models, and it does not restrict end users of a product that incorporates them (Meta use policy). An EU-based OEM building on the multimodal weights is the party the clause names.

Whether putting weights inside a device sold to a customer counts as distribution under 1.b.i is a question for counsel. So is how the Acceptable Use Policy binds your customers.

Permissive licenses still differ

On the model cards we read, gpt-oss-120b and gpt-oss-20b, Qwen3-235B-A22B-Instruct-2507, Mistral Large 3 (675B-Instruct-2512) and Gemma 4 31B-it list Apache-2.0, and DeepSeek-R1 lists MIT. Apache-2.0 section 4 still obliges you to pass recipients a copy of the license and keep the notices, and section 3 ends the patent license if you sue claiming the work infringes a patent (Apache-2.0).

Three traps sit in that list.

DeepSeek-R1's MIT license does not extend to every model with its name on it. Its card says the distilled variants inherit their base licenses, so a Llama-based distill carries Llama terms (model card).

Licenses move. Gemma's earlier Terms of Use, last modified 1 April 2026, were custom, with a prohibited-use policy. The Gemma 4 31B-it card, released 2 July 2026, lists Apache-2.0 (card). A compliance file written against the old text is out of date.

Some custom licenses key on your revenue rather than on user counts. The Kimi K3 license asks for a "Kimi K3" display once a product passes 100 million monthly active users or $20 million in monthly revenue, requires a separate agreement from a "Model as a Service" business above $20 million of revenue over 12 months, and exempts internal use in its Section 4 (license). A company that resells inference reaches the second trigger far sooner than an OEM does.

Four checks before a model goes into a product

  1. Is the license file for the exact version and quantization you ship, and is it stored with the date you read it?
  2. Does the model name, a derivative's name or the interface owe the licensor a string?
  3. Does a use policy or a regional clause apply to your company's place of business or your customers' fields of use?
  4. If you swap the model next year, who rereads the new license, and before which release?

Ask a vendor for answers to all four in writing, with the clause numbers.

Drawn from the Open Source Initiative's Open Source AI Definition 1.0 and its post of 18 February 2025, the Llama 3.3 and Llama 4 license texts and the Llama 4 use policy, the Apache-2.0 text, and the Kimi K3 license, all read on 6 October 2026. This is not legal advice.

Related notes

On the site: How we validate agentic AI