Which Local AI Models Can You Legally Use at Work?
Want to go deeper than this article?
Free account unlocks the first chapter of all 25 courses — RAG, agents, MCP, voice AI, MLOps, real GitHub repos.
Go from reading about AI to building with AI 25 structured courses. Hands-on projects. Runs on your machine. Start free.
Short answer: most of what you run locally is fine for paid client work — Qwen3, DeepSeek-R1, gpt-oss, Phi-4-mini, Whisper, Kokoro and FLUX.2 [klein] 4B are Apache-2.0 or MIT with no revenue threshold and no attribution-in-product duty. Llama is also commercial-friendly but makes you print "Built with Llama" and prefix derivative model names with "Llama". Gemma is commercial-friendly but is not an OSI licence and pushes its use restrictions into your customer contract. And four popular models will stop a deployment dead: Mistral's research-licensed line, XTTS v2, FLUX.2 [dev] and FLUX.2 [klein] 9B are non-commercial.
Every licence below was read from the licence file or the terms page itself, not from a summary, on 18 August 2026. Where a clause is operative it is quoted verbatim, because the paraphrase is what gets people in trouble. None of this is legal advice — it is a map of where the clauses are, so the conversation with whoever signs off takes ten minutes instead of a week.
Three Questions, Not One
"Can I use this at work" is really three separate permissions, and a model can pass one and fail another. Almost every argument about AI licensing is two people answering different questions.
- May I run the weights for a commercial purpose? This is the question the licence is mostly about. Apache-2.0 and MIT say yes without conditions beyond notice. The Mistral Research Licence and the Coqui Public Model License say no.
- What must I do or display if I ship something built with it? Attribution notices, naming rules, pass-through contract terms, and a NOTICE file. These bind on distribution, which is why an internal tool and a shipped product are treated very differently.
- May I sell what it generates? Usually yes, and usually for a different reason than you think — most licences simply do not claim your outputs. But the non-commercial ones extend to output as well, which is the trap.
Hold those apart while you read the table. A model that is "free" fails question two more often than question one.
Reading articles is good. Building is better.
Free account = the first chapter of all 25 courses, with a per-chapter AI tutor. No card.
The Licence Table
Fifteen models people actually run locally, with the clause that decides it. "Commercial" here means the weights may be used for revenue-generating work — not merely that the code around them is open.
| Model | Weights licence | Commercial? | The clause that decides it |
|---|---|---|---|
| Llama 3.3 / Llama 4 | Llama Community Licence | ✅ Yes, under 700M MAU | Attribution + naming duties on distribution; scale trigger above 700M monthly active users |
| Gemma (2 / 3 family) | Gemma Terms of Use | ✅ Yes | Not OSI-open; you must pass the use restrictions into your own agreements and ship a Notice file |
| Qwen3 | Apache-2.0 | ✅ Yes | Repo metadata reads apache-2.0; notice retention only |
| DeepSeek-R1 | MIT | ✅ Yes | Card states the series "support commercial use" and allows "distillation for training other LLMs" |
| Mistral Small 3.2 (and the Apache line) | Apache-2.0 | ✅ Yes | Repo metadata reads apache-2.0 — but only on the Apache-licensed releases |
| Mistral models under the MRL | Mistral Research Licence 0.1 | ❌ No | "You shall only use the Mistral Models, Derivatives... and Outputs for Research Purposes" |
| gpt-oss 20b / 120b | Apache-2.0 | ✅ Yes | "Build freely without copyleft restrictions or patent risk" per the model card |
| Phi-4-mini | MIT | ✅ Yes | "The model is licensed under the MIT license" |
| Whisper (large-v3) | MIT | ✅ Yes | "Whisper's code and model weights are released under the MIT License" |
| Kokoro-82M | Apache-2.0 | ✅ Yes | "With Apache-licensed weights, Kokoro can be deployed anywhere from production environments to personal projects" |
| XTTS v2 | Coqui Public Model License | ❌ No | Non-commercial only, and Coqui shut down — there is nobody left to sell you a licence |
| FLUX.2 [dev] | FLUX Non-Commercial License | ❌ No (model) | Model is non-commercial; the card says outputs "can be used for personal, scientific, and commercial purposes as described in" that licence |
| FLUX.2 [klein] 9B | FLUX non-commercial | ❌ No | Same family licence as [dev] |
| FLUX.2 [klein] 4B | Apache-2.0 | ✅ Yes | The one FLUX.2 weight under a permissive licence |
| Stable Diffusion 3.5 Large | Stability AI Community License | ⚠️ Under $1M | "Free for research, non-commercial, and commercial use for organizations or individuals with less than $1M in total annual revenue" |
| Marker (PDF→Markdown) | Code Apache-2.0 / weights modified AI Pubs OpenRAIL-M | ⚠️ Under $5M | Weights "free for research, personal use, and startups under $5M funding/revenue" |
Read from the licence files, terms pages and repo metadata on 18 August 2026. Licences change with releases — see the maintenance note at the end.
Two rows in that table are the ones that surprise people in review meetings. Stable Diffusion and Marker both have revenue thresholds, which means the answer changes as your client grows rather than as your code changes. And FLUX.2 splits three ways within one family: [dev] and [klein] 9B are non-commercial while [klein] 4B is Apache-2.0. If someone tells you "we use FLUX", that is not an answer — the variant is the answer. Our FLUX.2 local setup guide has the per-variant VRAM and file list, and the best local image models comparison covers quality against licence across the field.
The Four That Stop a Deployment
If your pipeline contains a Mistral research model, XTTS v2, FLUX.2 [dev] or FLUX.2 [klein] 9B, you cannot put its output in front of a paying client without a separate licence. These are the four that come up repeatedly, so here is the operative language.
Mistral Research Licence 0.1. The permission clause is narrow and the definition is narrower: "You shall only use the Mistral Models, Derivatives (whether or not created by Mistral AI) and Outputs for Research Purposes," where Research Purposes means use "solely for (a) personal, scientific or academic research, and (b) for non-profit and non-commercial purposes." The definition explicitly excludes "any usage of the Mistral Model, Derivative or Output by individuals or contractors employed in or engaged by companies in the context of (a) their daily tasks." That last phrase is the one that catches consultants — you do not have to sell the model to breach it; using it in your day job is enough. Mistral does sell commercial licences, and a large part of its catalogue is genuinely Apache-2.0, so the fix is usually a model swap within the same vendor.
XTTS v2. The Coqui Public Model License limits use to non-commercial purposes, defined as uses where "you do not receive any direct or indirect payment arising from the use of the model or its output," and closes the training loophole: "Use of the model to train other models for commercial use is not a non-commercial purpose." The complication is that Coqui the company shut down in January 2024, so unlike Mistral there is no commercial tier to buy. We wrote the full deep-dive on this one: is XTTS v2 free for commercial use, including the Kokoro and Chatterbox replacements that are permissively licensed.
FLUX.2 [dev] and [klein] 9B. Both ship under Black Forest Labs' non-commercial licence. The nuance worth reading carefully is that the [dev] card says generated outputs "can be used for personal, scientific, and commercial purposes as described in the FLUX.1 [dev] Non-Commercial License" — so the images have a commercial path that the model does not. That is an unusual split, it is defined by the licence text rather than by the card's one-liner, and it is exactly the kind of clause to hand to a lawyer rather than interpret from a blog post. If you want to avoid the question entirely, [klein] 4B is Apache-2.0 and runs on a 12GB card.
Code Licence Is Not Weights Licence
This single confusion causes more bad decisions than every threshold clause combined: the Python package and the trained weights are two different works under two different licences, and both statements can be true at once.
The clearest live examples:
- Coqui TTS — the library is MPL 2.0 (commercially fine); the XTTS v2 weights are CPML (non-commercial). You can ship a commercial product built on the library, loaded with different weights.
- Marker — "Our code is licensed under Apache 2.0 — free to use, including commercially," while "Our model weights use a modified AI Pubs Open Rail-M license (free for research, personal use, and startups under $5M funding/revenue)." Same repository, two answers. Marker sits at roughly 38.8k GitHub stars, so this is not an obscure edge case.
- DeepSeek-R1 distills — MIT for the DeepSeek weights, but the model card notes the Llama-8B and Llama-70B distills are "licensed under llama3.1 license" and "llama3.3 license" respectively. Downloading a DeepSeek-branded file does not mean you got a DeepSeek licence.
The habit that fixes it: read the licence attached to the artefact you downloaded, not the licence of the project that produced it. If you pulled a GGUF from a third-party quantiser, the licence you are bound by is still the upstream model's — the quantiser cannot grant you more than they have.
Run this on your own machine and stop paying every month
Pay once and keep it. No renewal, no per-token bill, and nothing you feed it ever leaves your hardware.
Attribution: What You Actually Have to Print
Only two of the models here impose visible obligations on a shipped product, and both are triggered by distribution rather than by use.
Llama. Two duties, quoted from the licence: you must "prominently display 'Built with Llama' on a related website, user interface, blogpost, about page, or product documentation," and "if you use the Llama Materials or any outputs or results of the Llama Materials to create, train, fine tune, or otherwise improve an AI model, which is distributed or made available, you shall also include 'Llama' at the beginning of any such AI model name." Distribution also requires passing along a copy of the agreement and retaining the notice "Llama 3.3 is licensed under the Llama 3.3 Community License, Copyright © Meta Platforms, Inc. All Rights Reserved."
Gemma. The heavier lift is contractual rather than cosmetic. You must "include the use restrictions referenced in Section 3.2 as an enforceable provision in any agreement governing the use and/or distribution" and provide third-party recipients "a copy of this Agreement." Non-hosted distributions "must be accompanied by a 'Notice' text file" naming ai.google.dev/gemma/terms. If you deliver software to a client, that means your MSA or EULA has to carry Google's use restrictions forward — a change your legal team makes once, then forgets, but they do have to make it.
Everything Apache-2.0 or MIT requires you to retain the licence text and copyright notice with any redistribution. In practice that is a LICENSES/ folder in your build artefact, not a line in your UI.
Fine-Tunes and Derivatives
Restrictions travel downhill. Assume your fine-tune inherits the base model's terms unless the base is Apache-2.0 or MIT.
The restrictive licences say this explicitly rather than leaving it to inference. Llama's naming and attribution rules apply to any model you "create, train, fine tune, or otherwise improve" with the materials or their outputs. The MRL binds "Derivatives (whether or not created by Mistral AI)". The CPML blocks using XTTS output to train a commercial model. There is no version of the synthetic-data trick that works on a licence written after 2023 — they all anticipated it.
Where you genuinely are free is a permissive base: a LoRA or full fine-tune of Qwen3 or a DeepSeek MIT checkpoint is yours to license as you please. What follows you there instead is your training data, which has its own terms and is usually the harder problem. Neither this page nor the model licence says anything about that.
Who Owns the Output
No licence we read claims ownership of what you generate, and Gemma says so in as many words: "Google claims no rights in Outputs you generate using Gemma. You and your users are solely responsible for Outputs and their subsequent uses."
That sentence is worth keeping because it is the shape of the whole category. The vendor disclaims the output and disclaims responsibility for it in the same breath. So "the licence permits commercial use" answers one question — the model owner will not come after you — and leaves two open that no licence can settle:
- Is the output protectable? Whether AI-generated material attracts copyright at all differs by jurisdiction and is unsettled in several. If your deliverable's value depends on the client owning it exclusively, that is a contract question to raise before the project, not after.
- Does the output infringe? A permissive licence is not a warranty about training data. Most of these licences disclaim warranties entirely and put indemnity on you.
For client work, the practical move is a one-line disclosure in the statement of work naming which models produced which assets. It costs nothing, and it converts a future argument into a paragraph the client already signed.
A 10-Minute Pre-Ship Check
Read the licence from the artefact on your disk, not from the blog post that told you about the model. These commands do that.
# Ollama ships the licence with the model — read it from your own install
ollama show --license qwen3:8b
# Hugging Face: pull just the licence files, not the 40GB of weights
hf download Qwen/Qwen3-8B --include "LICENSE*" "NOTICE*" --local-dir ./licences/qwen3-8b
# Record exactly which revision you shipped, so "the licence changed" is answerable
hf download Qwen/Qwen3-8B --include "config.json" --revision main --local-dir ./licences/qwen3-8b
The --license flag is a real, documented Ollama flag ("Show license of a model"), and it is the fastest way to settle an argument in a meeting: the licence text that the runtime is using prints to the terminal in one second.
Then, four questions to answer in writing per model:
- Which exact repo and revision? Not "Llama" —
meta-llama/Llama-3.3-70B-Instruct, and the commit. - Are we distributing or just running it? Internal-only deployment does not trigger Llama's attribution duty. Shipping a container to a client does.
- Does a threshold apply, and to whom? Stability's $1M and Marker's $5M attach to the organisation using the model. On client work, that may be the client's revenue, not yours.
- Where does the licence file live in our build? If you cannot point at it, you are not complying with Apache-2.0 either.
Teams that run this on a shared machine usually want the whole stack documented in one place — our complete Ollama guide covers the runtime side, and the best open-source LLMs ranking is the capability half of this decision. Model-level detail lives on the gpt-oss, Llama 3.3 70B, Qwen3-Coder and Whisper large-v3 pages.
Limits of This Page
This is a map of clauses, not legal advice, and three specific things about it will go stale.
- Licences change with releases. Meta has revised the Community Licence between Llama versions; the MAU threshold is pinned to "the Llama 3.3 version release date" in the 3.3 text and to the Llama 4 release date in the Llama 4 text. Always read the licence in the repo you are pulling.
- Per-size and per-variant differences are real. FLUX.2 splits three ways inside one family. Mistral publishes both Apache-2.0 and research-only models under the same brand. A vendor-level answer is not an answer.
- We did not read every model on earth. If your pipeline includes something not in the table — a community fine-tune, a niche TTS voice pack, a quantised repack — the licence question is open until someone opens the file. Piper's engine is MIT but its individual voice packs vary, which is the usual shape of this problem.
We re-check this table when a major release lands. If you find a clause we got wrong, tell us and we will fix it with the quote.
Sources
- Llama 3.3 Community Licence and Llama 4 Community Licence — MAU threshold, attribution and naming clauses
- Gemma Terms of Use — distribution conditions, pass-through use restrictions, Notice file, output ownership
- Qwen/Qwen3-8B, openai/gpt-oss-20b, microsoft/Phi-4-mini-instruct, hexgrad/Kokoro-82M — repo licence metadata
- deepseek-ai/DeepSeek-R1 — MIT, commercial use and distillation statements, distill licence split
- Mistral AI Research License 0.1 and mistralai/Mistral-Small-3.2-24B-Instruct-2506 — research-only clause versus the Apache-2.0 line
- openai/whisper — "Whisper's code and model weights are released under the MIT License"
- coqui/XTTS-v2 — Coqui Public Model License text
- black-forest-labs/FLUX.2-dev and FLUX.2-klein-4B — non-commercial versus Apache-2.0 within one family
- stabilityai/stable-diffusion-3.5-large — Community License $1M revenue threshold
- datalab-to/marker — Apache-2.0 code, OpenRAIL-M weights, $5M threshold, star count
- Ollama CLI source — the
show --licenseflag registration
FAQ
Go from reading about AI to building with AI
25 structured courses. Hands-on projects. Runs on your machine. Start free.
Liked this? 25 full AI courses are waiting.
From fundamentals to RAG, agents, MCP servers, voice AI, and production deployment with real GitHub repos. First chapter free, every course.
Build Real AI on Your Machine
RAG, agents, NLP, vision, and MLOps - chapters across 25 courses that take you from reading about AI to building AI.
Want the structured version?
Hands-on courses on local AI, from $8.99 a month. The first chapter of each is free.
Keep going
Comments (0)
No comments yet. Be the first to share your thoughts!