Is Llama Open Source? License Clauses for OEMs
The OSI says Meta's Llama licenses are not open source. For a company shipping a product, the clauses that travel with the weights matter more, and they differ model by model.
By Harinderpal Hanspal on October 2026. Updated October 2026
The Open Source Initiative has said Llama's license is not open source, so "open weights" is the accurate label. For an OEM the useful question is which clauses ride along when the model ships in a product: attribution, naming, a policy incorporated by reference and, for Llama 4 multimodal models, an EU restriction.
On 18 February 2025 the Open Source Initiative published a post titled "Meta's Llama license is still not Open Source" (OSI). It covers Llama 2 and Llama 3.x and does not name Llama 4. Its reasons are that the license fails freedom 0, the freedom to use the model for any purpose, and points 5 and 6 of the Open Source Definition, which bar discrimination against persons and limits on fields of endeavor.
That settles the label. It does not tell an OEM what it may do. This note is not legal advice, and every license below is as of 6 October 2026.
What the OSI definition asks for, and what Llama 4 adds
The Open Source AI Definition 1.0 asks for four freedoms (use, study, modify, share) and for three things under OSI-approved terms: the parameters, the complete source code used to train and run the system, and "sufficiently detailed information about the data used to train the system" (OSI). A download link for weights meets one of the three.
Llama 4 postdates the OSI post, so we do not attribute a verdict on it to the OSI. We can only report that the clauses the OSI objected to in the 3.x text are present in the Llama 4 text too.
Llama clauses an OEM should find by number
Both the Llama 3.3 license (6 December 2024) and the Llama 4 license (effective 5 April 2025) carry the same structure.
- Section 1.b.i: with any distribution of the Llama Materials you provide a copy of the agreement, display "Built with Llama" on a related website, interface or documentation, and begin the name of any AI model built on it with "Llama".
- Section 1.b.iii (read in the Llama 3.3 text): keep the attribution notice in a "Notice" file.
- Section 1.b.iv: adhere to the Acceptable Use Policy, which the license incorporates by reference. Your product therefore inherits a field-of-use list you did not negotiate.
- Section 2: a licensee whose products exceed 700 million monthly active users must request a license from Meta.
- Sections 6 and 7: Meta may terminate for breach, and California law governs with exclusive California courts.
The Llama 4 use policy adds one more, for companies in Europe. Rights under Section 1(a) "are not being granted" to an individual domiciled in, or a company with a principal place of business in, the European Union. It applies to the multimodal Llama 4 models, and it does not restrict end users of a product that incorporates them (Meta use policy). An EU-based OEM building on the multimodal weights is the party the clause names.
Whether putting weights inside a device sold to a customer counts as distribution under 1.b.i is a question for counsel. So is how the Acceptable Use Policy binds your customers.
Permissive licenses still differ
On the model cards we read, gpt-oss-120b and gpt-oss-20b, Qwen3-235B-A22B-Instruct-2507, Mistral Large 3 (675B-Instruct-2512) and Gemma 4 31B-it list Apache-2.0, and DeepSeek-R1 lists MIT. Apache-2.0 section 4 still obliges you to pass recipients a copy of the license and keep the notices, and section 3 ends the patent license if you sue claiming the work infringes a patent (Apache-2.0).
Three traps sit in that list.
DeepSeek-R1's MIT license does not extend to every model with its name on it. Its card says the distilled variants inherit their base licenses, so a Llama-based distill carries Llama terms (model card).
Licenses move. Gemma's earlier Terms of Use, last modified 1 April 2026, were custom, with a prohibited-use policy. The Gemma 4 31B-it card, released 2 July 2026, lists Apache-2.0 (card). A compliance file written against the old text is out of date.
Some custom licenses key on your revenue rather than on user counts. The Kimi K3 license asks for a "Kimi K3" display once a product passes 100 million monthly active users or $20 million in monthly revenue, requires a separate agreement from a "Model as a Service" business above $20 million of revenue over 12 months, and exempts internal use in its Section 4 (license). A company that resells inference reaches the second trigger far sooner than an OEM does.
Four checks before a model goes into a product
- Is the license file for the exact version and quantization you ship, and is it stored with the date you read it?
- Does the model name, a derivative's name or the interface owe the licensor a string?
- Does a use policy or a regional clause apply to your company's place of business or your customers' fields of use?
- If you swap the model next year, who rereads the new license, and before which release?
Ask a vendor for answers to all four in writing, with the clause numbers.
Drawn from the Open Source Initiative's Open Source AI Definition 1.0 and its post of 18 February 2025, the Llama 3.3 and Llama 4 license texts and the Llama 4 use policy, the Apache-2.0 text, and the Kimi K3 license, all read on 6 October 2026. This is not legal advice.
Related notes
- Which AI requests may leave the building: sort by data class first
- Local model vs API cost: the one division, five inputs and published prices
On the site: How we validate agentic AI