What does 'open' actually let us do with client data?
Open weights mean you can download and run the model; the licence says on what terms. Read the commercial threshold, the acceptable-use riders, attribution, derivative and patent clauses — and keep a copy of the version you relied on.
Four different things get called open
The word does a lot of unearned work. Open weights means the model files are downloadable and you can run them yourself; the training data, and often the training code, are not published and never will be. Open source in the formal sense describes code under a licence that meets an established definition of freedom, which may or may not apply to the model weights. And open is also used in marketing to describe a free tier of a hosted service, which is not open in any of the above senses. For a law firm only one thing matters at the point of decision: what does the licence permit, and can you demonstrate that you read it. The weights are the artefact; the licence is the permission, and the permission is what your risk register records. Capability without permission is a Tier D problem in this index regardless of how good the model is. Two further distinctions are often missed. The model has a licence and the application wrapping it has another — the interface, the plug-in, the agent framework — and the stricter of the two binds you. And if you use somebody else's hosted instance of an open model, the model licence is largely beside the point: your client-data answer then rests on that host's terms and data processing agreement, not on the badge on the box.
The clauses that decide the answer
Commercial use and scale thresholds. Most open-weight licences permit commercial use, but some switch on additional conditions when usage passes a defined scale, commonly expressed in monthly active users. A firm of forty fee-earners is unlikely to trip such a threshold internally; a product you build on the weights and sell to other firms might. Know which test applies and who counts. Attribution and naming obligations sit in the same family: display a notice, name the model in your documentation, rename derivatives. Minor in themselves, and easy to breach by silence. Acceptable-use terms. These are frequently a separate document incorporated by reference, and they restrict what the model may be used for. Read them, because they can be broader than you expect and can include obligations to police downstream use. The sharper question is whether the publisher can amend that document after you have deployed. If it can, your permitted use is defined by a text you have not yet read. Derivatives and redistribution. What a fine-tuned model counts as, whether you may distribute it, and whether it must carry the same terms. Patents and indemnity. Many open-weight licences include no indemnity at all, which means your professional indemnity position on the tool's output is unchanged by anything the publisher has said. Say that out loud in your risk assessment rather than assuming a vendor stands behind the output. Termination and governing law are the terms nobody reads until something has gone wrong.
Open weights do not answer the client-data question
A permissive licence tells you that you may run the model; it says nothing about whether you should put a client's lease through it. Those are separate analyses, and conflating them is how firms end up with a confident but wrong answer in a DPIA. Running weights on your own hardware means the material does not leave your perimeter, which is the strongest confidentiality argument private deployment has. The licence enables that, but it is not the reason the data stays inside. Two questions survive. The first is provenance: what was the training corpus, where did the publisher get it, and is there any argument that material under obligations to third parties ended up in the weights. For most open models there is no clean answer, and the honest position is that the risk is unquantified rather than absent. The second is your client's own view: some clients will ask about the publisher's jurisdiction, ownership and the access rules that apply to it. That conversation is winnable with documentation and a clear account of where the data sits, but easier to have before a client raises it than afterwards. If you use a hosted build of an open model, the analysis reverses: the DPA, the subprocessor list, retention defaults and the training-on-your-content question all matter far more than the model licence.
A licence review you can actually run
Put twelve questions on a single page and answer them for each model you consider. Who is the licensor, and what is the exact licence name and version. When does it take effect and what is the date of the copy you read. Is commercial use permitted, and is there a scale threshold. What acceptable-use document is incorporated, can it be changed after deployment, and by what process. What attribution is required. May you fine-tune, and what happens to the result. May you redistribute, and must derivatives carry the same terms. Is there a patent grant, and is there any indemnity — assume not unless you find one. How is the licence terminated, and what survives. Which law governs. And finally: who in the firm has checked this, and where is the saved copy. The last item is the one firms skip and the one that saves arguments later. Save the licence text, or the terms page, with the date and a note of the model version it belonged to. Licences change, terms pages are edited, model families move. If you relied on a clause in a document that has since been rewritten, you want to be able to show what you were relying on at the time. This is a two-hour exercise per model, and it produces an artefact your compliance team and your insurer will both find useful.
What nobody can tell you yet
Open-weight licensing is young and largely untested. We would rather say that than imply a certainty we do not have. Whether an acceptable-use policy that the licensor may amend unilaterally is enforceable against a firm that downloaded the weights under an earlier version is, as far as we know, unsettled. Whether a fine-tuned model is a derivative work for copyright purposes is contested, and different licences assume different answers. Whether obligations run to a firm that received weights from a re-host rather than the publisher is unclear, and re-hosting is common. The practical hedge is unglamorous. Where capability is comparable, prefer the licence with the fewest conditions and no unilateral amendment of use terms. Keep the deployment inside your perimeter so the architecture answer does not depend on a clause. Document what you read, when, and why you concluded what you did — a decision recorded on the basis of the terms as they stood is defensible, even if the terms later move. And do not let a permissive licence substitute for the data protection analysis, because it cannot.
What to watch
- Treating open weights as open source when the training data and training code were never published
- Reading the model licence and never checking the licence of the application wrapped around it
- Missing an acceptable-use document incorporated by reference that the publisher may amend after you have deployed
- Overlooking a scale threshold that switches on additional terms once usage grows or a product is built on the weights
- Assuming a fine-tuned model is one the firm owns outright, without checking the derivative clauses
- No saved copy of the licence version relied on, with its date, so the basis of the decision cannot be reconstructed
Before any private deployment, run a twelve-question licence review per model and store it with a dated copy of the licence text and the model version. Put the answers in the risk register alongside the data protection analysis, with the two clearly separated, because a permissive licence does not discharge either duty. If you use a hosted build of an open model, redirect the review to the host's terms, DPA and subprocessor list, which is where your client-data answer actually lives. Set a diary note to re-read the licence annually and whenever the model family moves. Give the review to one named person, and tell procurement that no deployment proceeds without it. Two hours per model buys a defensible position.