Which model weights can I ship?
A model weight file is a dependency with its own licence, and the repository's code licence does not reach it. This page is the weights part of the Clearance corpus, stated plainly — every claim below carries the clause it rests on, and the last section says which of those citations the corpus has checked against the source.
Weights licences in the corpus
Corpus 2026.09.2. The "commercial use" column states what the licence itself permits, not what Clearance decides — the verdict also depends on your declared intent, and on whether the weights are distributed or served.
| Licence | Family | OSI | Commercial use | The clause it turns on |
|---|---|---|---|---|
| Apache-2.0 | permissive | yes | Permitted | §4(a) — ship the licence text with anything you distribute; retain NOTICE. |
| MIT | permissive | yes | Permitted | Attribution only. The grant is silent on patents, which the corpus records as a note rather than a condition. |
| Llama 3.1 Community | custom | no | Permitted, with a scale gate | §2 — a separate licence from Meta is required above 700 million monthly active users. §1.b.i — display Built with Llama. |
| CC-BY-NC-4.0 | non-commercial | no | Blocked | §2(a)(1) — the grant is NonCommercial only. §2(a)(1)(B) extends that to adapted material, so fine-tuning or merging does not escape it. |
| Elastic-2.0 | source-available | no | Blocked as a managed service | Limitations — providing the software to third parties as a hosted or managed service is the prohibited use. |
| SSPL-1.0 | source-available | no | Blocked | The service condition. Public text and a GPL lineage do not make it open source, and the corpus traps on any SSPL dependency. |
Twelve licences are in the corpus. Six are listed here because six have a weights obligation or a weights trap attached to them. The rest are ordinary code licences; the rows above are the ones a weights question actually reaches.
The two traps that fire on weights
| Trap | Severity | What fires it |
|---|---|---|
| trap.weights.cc-by-nc-commercial | BLOCK | A dependency of kind weights whose licence family is non-commercial, in a product declaring commercial use. |
| trap.code-weights-divergence | CONDITION | Any dependency of kind weights whose licence is not permissive. Escalated to BLOCK when a non-commercial or source-available weight licence meets a declared commercial use. |
The case that costs money
A repository licensed Apache-2.0 whose weights are CC-BY-NC-4.0. A scanner that reads code licences returns SHIP. It is wrong in the direction that costs money, and it is wrong because it never compared the two.
The second trap above is the comparison. It cannot be decided from any single dependency's facts: the predicate is only the precondition, and the finding — this repository's code is permissive while its weights are not — is a statement about the graph. That is why the corpus marks it scope: graph and why the engine, not the predicate language, supplies the reason line.
How weights are identified
Weight files are found by magic bytes, not by extension — a name is a hint, and a hint is not evidence. Their licences are then resolved from, in order, GGUF metadata, config.json, model-card frontmatter, or a sibling LICENSE. Where the weights licence disagrees with the code licence, the divergence is reported rather than averaged away.
If none of those sources yields a licence, the answer is UNDETERMINED — never SHIP. An unlicensed weight file is all rights reserved, and a tool that guesses green on that is worse than no tool.
How much of this has been checked
Every finding carries a citation, and every citation that quotes a licence carries a record of how that quote was obtained. clearance corpus info reports 82 citations for corpus 2026.09.2 — distinct clauses, so a clause two entries both rely on is counted once. Fifty-one of those clauses carry a quoted excerpt:
| Excerpt kind | Count | What it means |
|---|---|---|
| verbatim | 13 | Diffed character-for-character against the source on the recorded date. The only kind a renderer may print inside quotation marks. |
| unverified | 37 | Written from knowledge of the clause but never diffed against it. This is the audit backlog, and it is published rather than hidden. |
| paraphrase | 1 | Clearance's own inference, attributed as a reading because no source states it outright. |
The three kinds are deliberately distinct rather than collapsed into "checked / unchecked": we restated this and we do not know whether we restated this or copied it are different claims, and treating them as one would let an unverified excerpt inherit a paraphrase's honesty. The whole corpus was moved to unverified on 23 September 2026, after an audit found twelve of fourteen sampled excerpts were rewordings presented as quotations. Entries are upgraded only once diffed, which is what makes verbatim mean something.
The Llama 3.1 row above is fully verbatim, including the Built with Llama string — which the corpus previously had wrong as Built with Meta Llama 3.1, a different string that would have had a user display the wrong notice. The paraphrase is the divergence trap, and it is labelled because the source states the fact and the inference is Clearance's.
The same reference exists as data. The corpus ships as a signed bundle inside every archive, is licensed CC-BY-4.0, and reports its own contents with clearance corpus info — which is where every number on this page comes from, and which you can run against your own copy rather than taking these on trust.