Comparison
Qwen vs GLM vs Kimi vs DeepSeek: which licences allow commercial use
All four labs are called open source in English coverage. On 1 September 2026 only two of the four current flagship checkpoints ship under a licence the OSI would recognise. Here is what each one actually says.
Last reviewed · 4 tools · 8 criteria
Verdict
DeepSeek wins on licence, and it is not close: V4-Pro-0813 and V4-Flash-0731 ship repository and weights under plain MIT, no thresholds, no attribution string, no acceptable-use attachment. Qwen is the best answer when you want a smaller model, because everything at 27B and below is genuine Apache 2.0, but the open Max-class checkpoint carries a custom licence with a US$50,000,000 gate that catches coding assistants and office-productivity products, not just API resellers. GLM is fine if you take GLM-5.2 or GLM-5.3-Flash, both plain MIT, and a problem if you take flagship GLM-5.3, whose bespoke licence hands Z.AI an unbounded security review and whose vendor has been on the US Entity List since January 2025. Kimi K3 has the lowest revenue gate of the four at US$20,000,000 over any twelve months, which is the only threshold in this comparison that a mid-size African or European inference provider could realistically cross.
Side by side
| Criterion | Tongyi Qianwen / 通义千问 (Qwen) | Zhipu ChatGLM / 智谱清言 | Kimi / Moonshot AI (月之暗面) | DeepSeek |
|---|---|---|---|---|
| Licence on the current flagship open weights | Qwen3.8-Max License (custom) on Qwen3.8-2.4T-A95B | GLM-5.3 License (custom), HF tag glm-5.3 | Kimi K3 License (custom), no longer self-described as modified MIT | MIT on DeepSeek-V4-Pro-0813 and V4-Flash-0731 |
| Licence on the smaller and mid-tier open weights | Apache 2.0 (Qwen3.8-27B, Qwen3.5-397B-A17B) | MIT (GLM-5.2, GLM-5.3-Flash) | Modified MIT (Kimi K2, Kimi K2.6) | MIT across the V4 family |
| Model as a Service revenue gate | Separate licence required above US$50,000,000 aggregate revenue over any consecutive 12 months | Z.AI security review required above 10 billion US dollars over any consecutive 12 months | Separate agreement with Moonshot AI required above 20 million US dollars over any consecutive 12 months | None |
| Scope of the gate beyond API resale | Also covers AI Work Assistant businesses: coding and office-productivity products | MaaS only; embedded features and request relaying explicitly excluded | MaaS only; internal use and Moonshot official or certified partner routes excluded | Not applicable |
| Attribution requirement | Display model name above 100,000,000 MAU or US$20,000,000 monthly revenue | None beyond retaining the copyright notice | Display "Kimi K3" above 100 million MAU or 20 million US dollars monthly revenue | None beyond the MIT notice |
| Use-based restrictions attached to the weights | None on the current licences | None | None | None on V4; legacy DEEPSEEK LICENSE AGREEMENT v1.0 (23 Oct 2023) Attachment A still binds V2 and Coder-V2 derivatives |
| OSI-approved licence on the flagship | No | No | No | Yes (MIT) |
| Vendor on the US BIS Entity List | No | Yes, Beijing Zhipu Huazhang Technology and subsidiaries, effective 16 January 2025 | No | No |
Which one to pick
-
DeepSeek
You want the licence question closed. V4-Pro and V4-Flash are plain MIT on both repository and weights, with no revenue gate, no attribution string and no acceptable-use attachment. Pick it if you are building a Model as a Service business of any size, or if your legal team needs a one-line answer. Check the checkpoint date: anything older than V3 may still carry the 2023 DeepSeek licence with Attachment A.
-
Tongyi Qianwen / 通义千问 (Qwen)
You want a model under 35B that runs on hardware you own, or a full multilingual family with one licence across sizes. Everything at 27B and below is unmodified Apache 2.0, which is the cleanest position of any lab in this set at that scale. Avoid the open Max checkpoint if you sell a general-purpose coding assistant or office-productivity product and your group turns over more than US$50 million.
-
Zhipu ChatGLM / 智谱清言
You take GLM-5.2 or GLM-5.3-Flash rather than flagship GLM-5.3, and your buyers are not US enterprises running supply-chain reviews. Both of those are plain MIT and the Flash model is natively multimodal at 320B-A18B, which is a strong offer at that licence. Skip flagship 5.3 unless you are comfortable with a security review whose scope Z.AI determines alone.
-
Kimi / Moonshot AI (月之暗面)
You are building an application rather than reselling inference, and long-context work is the point. Below US$20 million of group revenue over twelve months the K3 licence functions as MIT for you. Do not pick K3 as the model behind a growing inference or hosting business: US$20 million aggregate over twelve months is the lowest gate in this comparison and it is reachable.
English coverage of Chinese open-weight models has settled into a habit. A lab posts weights, the write-up says open source, and nobody opens the LICENSE file. That was roughly accurate in 2025, when the competitive move was to give everything away under MIT or Apache 2.0 and take the download numbers. It stopped being accurate this year. Three of these four labs have now shipped a flagship checkpoint under a licence they wrote themselves, and each of those licences puts a number in it.
I read all four in full on 1 September 2026, in the versions currently published. What follows is clause language, not summary. Where I could not verify something from the licence text, I say so rather than filling the gap.
The short version: the monthly-active-user thresholds everyone quotes are decoration. Nobody reading this has 100 million monthly active users. The clauses that decide whether you can ship are the revenue gates on Model as a Service businesses, and those are set low enough in one case to matter.
The four licences, by name and date
Qwen runs a split. Qwen3.8-27B and Qwen3.5-397B-A17B both carry the apache-2.0 tag on Hugging Face, unmodified, and every Qwen model at 35B and below has followed that pattern across the 3.x generations. The Max-class open release is different. Qwen3.8-2.4T-A95B, posted around 12 August 2026, ships under a document titled the Qwen3.8-Max License. Its grant is broad, covering the right to "use, copy, modify, merge, publish, distribute, sublicense, sell, deploy, host, fine-tune, and create derivative works", and then it adds two conditions. Separately, a non-commercial Qwen Research License still exists and still attaches to some smaller multimodal checkpoints, so the licence tag has to be checked per repository rather than assumed from the family name.
GLM runs the same split, more abruptly. GLM-5.2, released 17 June 2026, carries an unmodified MIT License with the copyright line "(c) 2026 Zhipu AI". GLM-5.3-Flash, the 320B-A18B multimodal model, is also MIT. Flagship GLM-5.3, whose weights went up on 28 August 2026 after a fortnight of extra internal safety evaluation, carries a Hugging Face licence tag of glm-5.3 and a bespoke document called the GLM-5.3 License. Z.ai used a registration-required commercial licence for ChatGLM3-6B back in 2023, moved everything after that to MIT, and has now reversed on one model.
Kimi has moved in one direction only. Kimi K2 and Kimi K2.6 are both under a document headed "Modified MIT License", copyright Moonshot AI. Kimi K3, published 27 July 2026, drops the pretence: the file is headed "Kimi K3 License", copyright 2026 Moonshot AI, and it is the only one of the three to add a revenue gate on top of the attribution clause.
DeepSeek has moved the other way. The V4 family, with V4-Pro-0813 out of preview on 12 August 2026 and V4-Flash-0731 alongside it, states that "This repository and the model weights are licensed under the MIT License". No custom document, no attachment, no threshold. That is a deliberate reversal of DeepSeek's own earlier practice, which I come back to below.
The clause that actually bites is the revenue gate, not the user count
Three of the four flagship licences define a Model as a Service business and gate it on revenue. The definitions are close enough to have been drafted with each other in view, and the numbers are three orders of magnitude apart.
Moonshot sets the lowest bar. Under the Kimi K3 License, if the licensee or any affiliate operates a Model as a Service business and "the aggregate revenue of the Licensee and its affiliates exceeds 20 million US dollars (or the equivalent in other currencies) in total over any consecutive 12 months", the licensee must enter a separate agreement with Moonshot AI before any commercial use. Read that carefully. The threshold is aggregate revenue of the licensee and its affiliates, not revenue attributable to Kimi. A European GPU cloud with twenty-five million dollars of annual turnover that offers a Kimi endpoint alongside forty other models is inside the clause on its total revenue, not on the slice the endpoint earns.
Qwen sets it at US$50,000,000 over any consecutive twelve months, again on the aggregate revenue of the licensee and its affiliates. Qwen's definition is the broader one. It covers Model as a Service, which it defines as providing third parties access to inference or fine-tuning where they exercise meaningful control over inputs, parameters or training data, and it also covers an "AI Work Assistant" business, meaning an independent AI product primarily designed for AI-assisted coding or office productivity. Single-purpose tools, domain-specific assistants and AI features inside non-AI products are carved out. So a European legal-research product built on Qwen3.8-Max is outside the clause, and a general-purpose coding agent at the same revenue is inside it.
Z.ai sets it at 10 billion US dollars over any consecutive twelve months, and the consequence is not a licence negotiation but a security review that the licensee must pass before commercial use. The licence says the scope and method of that review "shall be reasonably determined by Z.AI". There is no published rulebook, no stated timeline and no appeal mechanism anywhere in the text I read. At ten billion dollars this is aimed at hyperscalers and nobody else, and Z.ai's drafting of the exclusions is the most careful of the three: model capabilities embedded solely within specific features or harnesses fall outside the definition, as does merely relaying requests to models hosted by others.
DeepSeek has no such clause. Under MIT there is no threshold to cross and no counterparty to notify.
Attribution, and what a name on a screen costs you
Kimi K2 and K2.6 require that if the software or a derivative is used in commercial products or services with "more than 100 million monthly active users, or more than 20 million US dollars (or equivalent in other currencies) in monthly revenue", you "shall prominently display" the model name on the user interface. Kimi K3 keeps the same clause with the string changed to "Kimi K3". Qwen3.8-Max carries an equivalent requirement at 100,000,000 monthly active users or US$20,000,000 monthly revenue.
Monthly revenue, not annual. Twenty million dollars a month is a quarter of a billion a year. In practice this clause fires for a handful of consumer apps worldwide and for nobody building a product in Lagos, Nairobi, Lisbon or Warsaw. It is worth knowing about because it is the clause English commentary fixates on, and fixating on it means missing the twelve-month aggregate revenue gate sitting two paragraphs below it in the same file.
Both Kimi and Qwen carve out internal use, meaning deployments not made available to third parties. Moonshot additionally exempts use through its own official products and through what the licence calls certified inference partners. The licence text does not name those partners or point to a list, so if that carve-out is load-bearing for your deployment you need to ask Moonshot directly at the address the licence gives.
Acceptable use, and the DeepSeek clause that still lives in old checkpoints
None of the four current flagship licences attaches a use-based restriction schedule. No military-use clause, no surveillance clause, no acceptable-use annex. That is a genuine difference from Meta's Llama licences and from the RAIL-derived licences common in image generation, and it is the single most under-reported fact in this area.
It is a recent state of affairs for DeepSeek in particular. The DEEPSEEK LICENSE AGREEMENT Version 1.0, dated 23 October 2023, still governs the weights of DeepSeek LLM, DeepSeek-MoE, DeepSeek-V2 and DeepSeek-Coder-V2. Its Attachment A lists use restrictions covering military applications, exploitation of minors, generation of false information intended to harm, unauthorised use of personally identifiable information, fully automated decisions affecting legal rights and several discrimination categories. Section 4(a) makes those restrictions viral in a specific way: they "MUST be included as an enforceable provision by You in any type of legal agreement" covering derivatives. A team that fine-tuned Coder-V2 in 2024 and shipped the result under its own terms is required to have carried Attachment A into those terms, and most did not. Moving that workload to V4 under MIT is the cheapest way to clear the problem.
Separately, and this trips up teams constantly: the licence on the weights and the terms on the vendor's API are different documents. DeepSeek's open-source weights are MIT. Access to the same model through DeepSeek's hosted platform is governed by the DeepSeek Open Platform Terms of Service, which do impose usage policies. Downloading weights buys you out of the second document entirely. Calling the vendor API does not.
What a company in Lagos, Nairobi or Lisbon actually has to do
Start by recording the exact checkpoint identifier and the licence file as you found it, with a date. Every one of these labs has changed licence terms between minor versions this year, and Hugging Face licence tags are per-repository. "We use GLM" is not a compliance record. "zai-org/GLM-5.2, MIT, retrieved 1 September 2026" is.
Then answer one question: are you providing third parties with access to inference or fine-tuning where they control the inputs or parameters. If no, you are running an application, every one of these four licences lets you ship it commercially and the revenue gates do not apply to you. If yes, you are a Model as a Service business under all three custom licences and you need to check your group's trailing twelve-month revenue against US$20,000,000 for Kimi K3, US$50,000,000 for Qwen3.8-Max and ten billion for GLM-5.3.
For a European company there is a second layer that has nothing to do with the licence. Under the EU AI Act, a provider of a general-purpose AI model released under a free and open-source licence is exempt from the Article 53(1)(a) and (b) documentation duties, but only where three conditions hold together: the licence allows access, use, modification and distribution; the parameters, architecture information and usage information are publicly available; and the model is not provided against a price or otherwise monetised. The copyright-policy duty and the training-data summary duty survive that exemption. If you fine-tune one of these models and place it on the market under your own name, you are a provider, and the exemption you are relying on is judged against the licence you received. Qwen3.8-Max, Kimi K3 and GLM-5.3 all impose conditions on commercial use, so treat their qualification as an open question and take legal advice rather than assuming.
There is a procurement question too, distinct from both. Beijing Zhipu Huazhang Technology and its subsidiaries were added to the US Bureau of Industry and Security Entity List effective 16 January 2025, with a presumption of denial for items subject to the EAR. That listing restricts exports to Zhipu. It does not make downloading published GLM weights unlawful for a Nigerian or Portuguese company. It does mean that if your buyer is a US-headquartered enterprise with a supply-chain questionnaire, GLM will generate a conversation that DeepSeek and Qwen will not.
Where none of the four is the right answer
All four disclaim warranty in identical language and none offers indemnification against third-party intellectual property claims arising from model output. Apache 2.0 and MIT are silent on training data provenance. If you are shipping into a regulated European sector where your customer contract requires you to pass through an IP indemnity, no open-weight Chinese model can give you one, and the correct answer is a hosted model from a vendor that sells indemnity as part of the contract, whatever the benchmark table says.
The same applies if your obligation is to name a legal entity that will answer a regulator's questions within a fixed period. A licence file with an email address on it is not that. Read the gates, but do not mistake a clean licence for a supplier relationship.
Questions
Can I use Qwen, GLM, Kimi and DeepSeek in a commercial product without paying anything?
Yes, for an application you build and sell, under every licence in this comparison as of 1 September 2026. The conditions in the Qwen3.8-Max, GLM-5.3 and Kimi K3 licences attach to Model as a Service businesses, meaning you give third parties access to inference or fine-tuning with control over inputs and parameters. If you are shipping a product and calling the model yourself, none of those gates applies to you regardless of your revenue.
Which of the four has the strictest licence?
Kimi K3, on the number that matters. Its Model as a Service gate triggers at 20 million US dollars of aggregate revenue for the licensee and its affiliates over any consecutive twelve months, against 50 million for Qwen3.8-Max and ten billion for GLM-5.3. Kimi also measures on total group revenue rather than revenue earned from the model, so a multi-model inference provider crosses it on everything it sells.
Do any of these licences ban military or surveillance use?
Not on any current flagship checkpoint. This is where English commentary is most often wrong. DeepSeek's Attachment A did contain those restrictions under the DEEPSEEK LICENSE AGREEMENT Version 1.0 of 23 October 2023, which still governs DeepSeek-V2 and DeepSeek-Coder-V2 weights, but the V4 family is plain MIT with no attachment. Qwen's Apache 2.0 models, GLM-5.2 and the Kimi licences carry no use-based restriction schedule.
Does the EU AI Act open-source exemption cover these models?
Clearly for the Apache 2.0 and MIT checkpoints, and as an open question for the three custom licences. The exemption from Article 53(1)(a) and (b) requires a free and open-source licence permitting access, use, modification and distribution, public availability of parameters and architecture information, and no monetisation. The copyright-policy and training-data-summary duties survive it in every case. If you fine-tune and place a model on the market under your own name you become a provider, so take advice rather than assuming inheritance.
Is Zhipu being on the US Entity List a problem for a European or African company?
Not a licensing problem. The January 2025 listing restricts exports of items subject to the US Export Administration Regulations to Beijing Zhipu Huazhang Technology and its subsidiaries. It does not make downloading published GLM weights unlawful outside the US. It does surface in enterprise procurement questionnaires, particularly with US-headquartered buyers, so factor it into sales cycles rather than into your legal risk register.
Sources
- Kimi K3 License, Moonshot AI (Hugging Face) huggingface.co
- Kimi K2 Modified MIT License (Hugging Face) huggingface.co
- Qwen3.8-Max License, Qwen3.8-2.4T-A95B (Hugging Face) huggingface.co
- Qwen3.8-27B model card, Apache 2.0 (Hugging Face) huggingface.co
- Tongyi Qianwen RESEARCH LICENSE AGREEMENT (GitHub) github.com
- GLM-5.2 LICENSE, MIT (Hugging Face) huggingface.co
- GLM-5.3 License, custom (Hugging Face) huggingface.co
- GLM-5.3-Flash LICENSE, MIT (Hugging Face) huggingface.co
- DeepSeek-V4-Pro-0813 model card, MIT (Hugging Face) huggingface.co
- DEEPSEEK LICENSE AGREEMENT Version 1.0, 23 October 2023 (GitHub) github.com
- DeepSeek Open Platform Terms of Service cdn.deepseek.com
- DeepSeek V4 model card and transparency documentation fe-static.deepseek.com
- EU AI Act Article 53 GPAI provider obligations legalithm.com
- Hugging Face guidance on EU AI Act open-source GPAI exemptions huggingface.co
- Z.ai GLM-5.3 open weights and licence coverage, The New Stack thenewstack.io
- Zhipu addition to US Entity List, January 2025 scmp.com
Individual reviews: Tongyi Qianwen / 通义千问 (Qwen), Zhipu ChatGLM / 智谱清言, Kimi / Moonshot AI (月之暗面), DeepSeek. All comparisons, or the full tool catalogue.