COURSE 25L1100% FREE
Verified 2026-08-14

Weights vs code licenses

AI releases often stack **different legal instruments**: training code license, inference code license, **weight** license, dataset license, and (if hosted) API terms. Literacy goal: never assume one file covers the stack. **Not legal ad...

What it is

AI releases often stack different legal instruments: training code license, inference code license, weight license, dataset license, and (if hosted) API terms. Literacy goal: never assume one file covers the stack. Not legal advice.

<!-- IMAGE: layered cake: data → code → weights → API terms -->

HIGH PRIORITYCOMPARISON DIAGRAM
◷ IN PRODUCTION

Visual Spec & Architecture Diagram

Two columns Weights vs Code: what each covers, common pitfalls ('Apache code + noncommercial weights').

Educational Focus: Sharpens the cake into a decision aid.

Why it matters

A GitHub repo under Apache 2.0 can ship weights under a Community License with AUP and scale thresholds (Llama 4 example). Mistral notes many open models are Apache 2.0, while some use modified MIT with a revenue threshold. OSAID treats parameters as their own pillar under OSI-approved terms—separate from “files are downloadable.”

How it works (plain)

For each artifact, answer:

  1. What file/URL is authoritative?
  2. What SPDX / Hub id is declared?
  3. What extra restrictions (AUP, MAU, revenue, non-compete)?
  4. What attribution / naming rules?
  5. Does self-hosting still leave you under API terms for some features?

Everyday example

Open-source oven firmware vs a patented cake mix inside. You can hack the oven and still be restricted on the mix.

Try it

Create a 4-row table for one model: code / weights / data docs / API (if any). Fill license name + URL + date checked.

Myths

⚠️ Myth: One LICENSE at repo root covers finetuned weights you publish.
✓ Reality: Your finetune may add obligations; base weight license still matters.
⚠️ Myth: Hugging Face license: apache-2.0 always means OSAID open source AI.
✓ Reality: It’s a card field; still verify artifacts and data information.

Sources