Qwen3 under Apache 2.0, and the mirage of terms-of-use restrictions
Alibaba released eight Qwen3 models under a plain Apache 2.0 licence this week. Read alongside Henderson and Lemley's paper arguing that restrictive model licences are largely unenforceable, the choice looks less like generosity and more like the rational option. Reading notes on both.
A release with no licence to read
The Qwen3 release on April 28 is notable for something it lacks. Eight models, from a 0.6B dense model to a 235B mixture of experts with 22B active parameters, and every one of them under Apache 2.0. No acceptable use policy attached to the weights. No clause about monthly active users. No list of prohibited applications. No requirement to name the model in derivative products. The licence is the same one used by the Apache web server, and it fits on two pages.
That is a different posture from most of the well-known open-weight families. Llama's community licence carries a threshold above which large services need separate permission, and an acceptable use policy. Gemma's terms of use include use restrictions and a right for Google to update them. The RAIL family of licences was built specifically to attach behavioural restrictions to weights. Qwen3 walks away from all of that, and the interesting question is why a company would give up the control those documents appear to provide.
What Henderson and Lemley argue
Peter Henderson and Mark Lemley posted The Mirage of Artificial Intelligence Terms of Use Restrictions to arXiv in December 2024, and it is forthcoming in the Indiana Law Journal. Their claim is that the restrictions AI companies attach to models and outputs are positioned as key enforceable tools against misuse but are regularly and repeatedly violated, with essentially no enforcement beyond account suspension. They then ask whether enforcement would even be possible, and conclude that in most cases it would not.
The first problem is copyrightability. A licence is a grant of permission to do something that would otherwise infringe. If model weights and model outputs are largely not copyrightable, as the authors argue, because weights are the product of a mechanical training process and outputs lack a human author, then it is unclear there is anything to license. A licence over an uncopyrightable artefact is a contract, not a copyright licence, and contracts have their own weaknesses.
The second problem is contract formation. Many model terms are presented in the manner of browsewrap, a document linked from a repository page that a downloader may never see, let alone agree to. Whether that creates a binding contract with someone who obtained the weights from a mirror is doubtful. The third is preemption. The paper walks through recent doctrine, including the ML Genius v. Google line, suggesting that state contract claims which try to recreate copyright-like control over uncopyrightable material may be preempted by federal copyright law.
The other doors are closed too
The obvious fallbacks are the anti-circumvention provisions of the DMCA and the Computer Fraud and Abuse Act. The authors find little there. Section 1201 requires a technological measure protecting a copyrighted work, and if the weights are not a copyrighted work the provision has nothing to attach to. The CFAA after Van Buren covers exceeding authorised access to a computer, and the Supreme Court read that narrowly enough that violating a website's terms of use is not, on its own, a federal crime.
They note that anti-competitive clauses, such as terms forbidding the use of outputs to train competing models, are on weaker ground still than responsible-use clauses, because courts are less sympathetic to contract terms whose purpose is to restrain competition. Distillation of one lab's outputs into another lab's model is, by their account, both routine and almost never litigated. The market has already priced these clauses at roughly zero.
Their recommendation is that the line between legitimate and harmful uses of AI should be drawn by statute, where it can be debated and applied evenly, rather than by private terms that create a quasi-copyright ownership where none should exist. Whatever one thinks of that policy, the descriptive part of the paper is hard to argue with. The restrictive licences are, in practice, unenforced and probably unenforceable.
Reading the release through the paper
Put the two documents together and the Apache 2.0 choice stops looking like a gift. If a restrictive licence is a mirage, then attaching one to your weights costs you something and buys you nothing. It costs adoption, because enterprise legal teams have to review it and some will refuse. It costs goodwill with the developers who fork and fine-tune, who are precisely the people that make an open model family valuable. And it costs credibility when the restrictions are visibly ignored and never enforced. What it buys is a document you cannot use.
Apache 2.0 also has a feature that matters more for model weights than people notice. It carries an express patent grant and a patent retaliation clause, which gives downstream users a legal position that a custom community licence typically does not. If the weights themselves cannot be owned, the surrounding patents on architecture and training methods become the actual legal surface, and a licence that addresses patents is doing more real work than one that lists prohibited uses.
The counterargument is that a responsible-use clause has value as a signal even if it has none as a contract, and that it gives a lab a basis to distance itself from a bad actor. We take the point, but a code of conduct published alongside the model does the same signalling without pretending to be a legal instrument, and without imposing a review burden on everyone acting in good faith.
What we would watch
The prediction that follows from the paper is that restrictive model licences will erode, because they impose costs on the honest and none on the dishonest. Qwen3 is one data point in that direction, and Mistral's return to Apache 2.0 in January was another. The counter-prediction is that labs will keep them for reasons that have nothing to do with enforceability, such as satisfying regulators or their own trust and safety teams.
The test is whether the next major release from a lab with a custom licence moves toward a standard one. If the legal analysis is right, the labs' own counsel will be telling them the custom terms are decorative. Whether they listen will tell us how much of the licensing was ever about the law.
Sources
From the foundation