{"slug": "glm-5-3-s-weights-are-out-the-licence-is-not-mit", "title": "GLM-5.3's Weights Are Out. The Licence Is Not MIT", "summary": "Z.ai released the 753B-parameter GLM-5.3 flagship's weights on Hugging Face on August 28, 2026, under a bespoke licence named 'glm-5.3', while the 320B GLM-5.3-Flash model shipped two days earlier under the standard MIT License. The custom licence adds a clause requiring companies with over $10B in annual revenue to pass Z.AI's security review before commercial use, but it lacks published criteria, a timeline, or an appeal process, and both licences are silent on patents, output ownership, and termination. The divergence means 'open weights' no longer guarantees uniform usage rights, and enterprises must scrutinize the licence before self-hosting or building services on the larger model.", "body_md": "The GLM-5.3 open weights arrived on Hugging Face on August 28, 2026 — and the licence field on the model card does not say `mit`\n\n. It says `glm-5.3`\n\n: a bespoke, vendor-named licence written for this one model. Two days earlier, the same company shipped GLM-5.3-Flash under the plain, textbook MIT License — no additions, no appendix.\n\nThat split — inside one vendor’s model family, in one calendar week — is the story. Z.ai made the licensing decision twice in seven days and answered it differently each time: MIT for the 320B Flash model, a custom document for the 753B flagship. Anyone planning to self-host, fine-tune, or build a hosted service on the bigger model now has a licence to actually read, because “open weights” no longer tells you what you are allowed to do with them.\n\nSo we read both texts end to end — the raw LICENSE files, not the coverage — and built a clause-by-clause comparison: redistribution, modification, commercial use, field-of-use limits, attribution, output ownership, patents, termination. The short version: the two licences are nearly identical, one clause diverges, and what that clause leaves unwritten matters as much as what it says.\n\n- 01One vendor, one week, two licence regimes.GLM-5.3-Flash (320B total / 18B active) shipped August 26 under unmodified MIT. The 753B-total flagship’s weights followed August 28 under a bespoke licence the Hugging Face model card tags glm-5.3.\n- 02The grant clause is nearly MIT, extended to model artifacts.The glm-5.3 licence grants use, copying, modification, distribution, sublicensing, and sale “without restriction”, explicitly covering weights, parameters, configs, and training code, plus an added right to run, deploy, and fine-tune.\n- 03One clause diverges: a $10B Model-as-a-Service gate.A licensee operating a MaaS business whose aggregate revenue exceeds $10B over any consecutive 12 months must pass Z.AI’s security review before commercial use. Flash carries no such clause.\n- 04The security review has no published rulebook.The licence says its scope and method “shall be reasonably determined by Z.AI” — no criteria, no timeline, no appeal process appears anywhere in the text. That is an open question, not a process.\n- 05Both texts are silent on patents, outputs, and termination.Neither licence contains a patent grant, an output-ownership claim, or a revocation-for-breach mechanism. Silence is not a restriction — but it is also not a grant, and procurement reviews should record it as silence.\n\n## 01 — What HappenedOne vendor, one week, *two* licences.\n\nFirst, terms. “Open weights” means a lab publishes the trained model files so anyone can download and run them — as distinct from open source, where the licence attached to those files decides what you may legally do with them. That licence is the subject of this post, because Z.ai just attached two different ones to two models in the same family, two days apart.\n\nThe sequence: Z.ai announced GLM-5.3 — [the post-training-only successor to GLM-5.2](/blog/glm-5-3-launch-post-training-scaling-coding-agents) — on August 14, 2026, promising in its launch post that “We will release the weights in two weeks after launch, once safety evaluation and hardening are complete,” with the stated reason for the hold being that cyber capability “developed faster than we expected” — the disclosure numbers behind that hold are covered in [the coordinated-disclosure ledger Z.ai published alongside it](/blog/glm-5-3-ai-security-research-cvd-ledger-2026). On August 26, [the reveal that put GLM-5.3-Flash under MIT](/blog/ox-alpha-revealed-glm-5-3-flash) landed — weights on Hugging Face the same day, licence field `MIT`\n\n. On August 28, exactly 14 days after the announcement, the flagship’s weights went public at [huggingface.co/zai-org/GLM-5.3](https://huggingface.co/zai-org/GLM-5.3) — licence field `glm-5.3`\n\n.\n\n##### GLM-5.3 *announced*\n\nZ.ai launches the flagship on API only, promising weights in two weeks once safety evaluation and hardening are complete. Which licence those weights would carry stays unstated.\n\n##### Flash ships *MIT*\n\nGLM-5.3-Flash weights land on Hugging Face under the plain, textbook MIT License — copyright Z.AI Co., Ltd, no additions, no appendix, no acceptable-use section.\n\n##### Flagship ships *bespoke*\n\nThe flagship weights arrive under a vendor-named GLM-5.3 License — a bilingual English-and-Chinese document that tracks MIT closely until its revenue-gated clause 2.\n\nThe release itself was framed as fully permissive in spirit. Zixuan Li, a Z.ai team member, wrote in a post on X quoted by The New Stack: “GLM-5.3 is now available for download, local deployment, fine-tuning, and commercial use under the GLM-5.3 License. Given the model’s advanced cybersecurity capabilities, we conducted two additional weeks of comprehensive safety evaluations before releasing the weights.” Note the phrasing: commercial use *under the GLM-5.3 License*. For almost everyone that distinction is invisible. For one class of company, it is the whole point — and [the announcement-to-release gap this ledger tracks](/blog/open-weight-announcement-to-weights-gap-ledger) now has its GLM-5.3 row resolved: 14 days, precisely as promised.\n\n## 02 — The TextsMIT vs glm-5.3, *clause by clause*.\n\nEvery cell in the table below comes from reading the two raw LICENSE files — [Flash’s](https://huggingface.co/zai-org/GLM-5.3-Flash/raw/main/LICENSE) and [the flagship’s](https://huggingface.co/zai-org/GLM-5.3/raw/main/LICENSE) — not from secondary coverage. The glm-5.3 grant clause is nearly a word-for-word MIT grant, extended to model artifacts explicitly: it grants rights “to deal in the Software” — defined as “including the model weights, parameters, configuration files, inference and training code, and associated documentation” — “without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies,” plus an explicit added right “to run, deploy, fine-tune, or otherwise modify the Software and create derivative works from it.”\n\nWhere both texts say nothing — output ownership, patents, termination — the table records the silence as silence. An empty provision is not a restriction, and it is not a grant either.\n\n| Provision | MIT License (GLM-5.3-Flash) | GLM-5.3 License (753B flagship) | Net difference |\n|---|---|---|---|\n| Where the two texts match | |||\n| Redistribution | “publish, distribute, sublicense, and/or sell copies” — unrestricted | Same operative grant, with “Software” defined to include model weights, parameters, configuration files, and inference and training code | None in effect — both allow redistribution and resale |\n| Modification & fine-tuning | “use, copy, modify, merge” | Adds an explicit right “to run, deploy, fine-tune, or otherwise modify the Software and create derivative works from it” | None in effect — glm-5.3 spells out what MIT leaves implied |\n| Field-of-use limits | None | None found in the text — no industry, geography, or use-case restriction | None — neither text restricts what you build |\n| Attribution & naming | Retain the copyright and permission notice in copies | Same notice-retention sentence as MIT — “The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software” — and no “must display GLM-5.3” UI-naming mandate anywhere in the text | None — neither requires product-level attribution |\n| Where they diverge | |||\n| Commercial use | Unrestricted for everyone, at any scale | Unrestricted — except a Model-as-a-Service operator whose aggregate revenue exceeds $10B over any consecutive 12 months “must pass Z.AI’s security review” before commercial use (clause 2) | The single substantive divergence between the two texts |\n| Warranty & liability | Stock MIT: “THE SOFTWARE IS PROVIDED ‘AS IS’” | “THE SOFTWARE AND ANY OUTPUT AND RESULTS THEREFROM ARE PROVIDED ON AN ‘AS IS’ BASIS” — the disclaimer explicitly extends to model behavior | Textual, not practical — glm-5.3 acknowledges outputs exist as a category, only to disclaim warranty over them |\n| Where both texts are silent | |||\n| Output ownership | Silent | Silent — outputs appear only inside the warranty disclaimer | Both silent — neither grants nor claims ownership of what the model generates |\n| Patent grant | Silent | Silent | Both silent — unlike Apache 2.0, neither includes an express patent licence |\n| Termination | No termination clause | No termination clause | Both silent — no revocation-for-breach mechanism; clause 2 is a precondition on one class of licensee, not a termination trigger |\n\nRead as a whole, the glm-5.3 licence is a strange artifact: a bespoke legal document whose drafters clearly wanted it to feel like MIT — same grant verbs, same disclaimer skeleton — while carving out exactly one population. That drafting choice is itself informative. A vendor that wanted broad control would have written a broad licence. Z.ai wrote a narrow one.\n\n## 03 — Clause 2The *$10B* Model-as-a-Service gate.\n\nHere is the divergent clause in full, verbatim from the licence text:\n\n“If the Licensee or any of its affiliates operates a Model as a Service business, and the aggregate revenue of the Licensee and its affiliates exceeds 10 billion US dollars (or the equivalent in other currencies) in total over any consecutive 12 months, the Licensee must pass Z.AI’s security review before using the Software or its derivative works for any commercial purpose.”— GLM-5.3 License, clause 2\n\nTwo definitions decide who this actually touches. “Model as a Service” — MaaS — means hosting the model yourself and selling third parties API-style access that gives them “meaningful control over the inputs, parameters, or training data.” The licence then explicitly excludes two things from that definition: “end-user products with model capabilities solely embedded within specific features or harnesses,” and “mere relaying of requests to models hosted by others.” In plain terms: building an app on GLM-5.3 is not MaaS, and reselling access routed through someone else’s infrastructure is not MaaS. Hosting the raw weights and selling inference on them is.\n\nThen the revenue line: $10 billion of aggregate revenue — the licensee plus its affiliates, across the whole business, not just the model service — over any consecutive 12 months. That is hyperscaler territory. A startup hosting GLM-5.3 inference, a mid-size inference provider, an enterprise running it internally: none of them cross the line. The clause is drafted to catch a handful of the largest cloud and platform companies on earth and nobody else.\n\n*reasonably determined by Z.AI*.” No published criteria, no timeline, no appeal process exists in the text, and we found no separate published review-policy document. A company above the threshold cannot currently know, from any written source, what it would be agreeing to — that is an open question to put to the vendor, not a process to describe.\n\n## 04 — The GapsWhat the licence *does not* say.\n\nThe context makes one absence genuinely striking. This licence shipped at the end of a two-week safety hold that Z.ai imposed because, in its own words, cyber capability “developed faster than we expected.” You might expect the resulting legal document to say something — anything — about offensive-security use. It does not. Frederic Lardinois, reporting the release for [The New Stack](https://thenewstack.io/zai-glm-weights-license/), made the same observation independently: “Despite the safety framing, it’s worth noting that the license itself contains no acceptable-use section and also says nothing about cyber or offensive security.”\n\nThat is two separate readings — our direct pass through the text and a journalist’s — reaching the same conclusion. The safety concern that delayed the weights left no trace in the licence that governs them. Whatever the two extra weeks of “safety evaluation and hardening” produced, it was not licence language. The restraint on misuse, such as it is, lives entirely outside the legal document: in the hold itself, and in whatever the undefined security review turns out to mean for the very few companies it covers.\n\nThe other silences are less surprising but worth recording precisely, because licence summaries routinely get them wrong in both directions. No patent grant — which does not mean patents are asserted; it means the document, like MIT and unlike Apache 2.0, simply does not address them. No output-ownership clause — the only mention of outputs is inside the warranty disclaimer, which neither grants you the outputs nor claims them for Z.ai. No termination clause — nothing in the text describes revoking the licence for breach. Report silence as silence.\n\n“Whether Z.ai changed its license for security reasons or to better monetize its own models is a question worth asking, of course.”— Frederic Lardinois, The New Stack, August 28, 2026\n\nLardinois’s question is the right one, and the clause’s own shape leans toward an answer. A security-motivated licence would plausibly restrict *capabilities* — an acceptable-use section, a cyber carve-out. This licence restricts a *customer segment*: the largest self-hosting platforms, the exact companies most able to monetize the weights at scale without paying Z.ai. Both motivations can be true at once. But the text, read cold, looks more like a commercial lever than a safety instrument.\n\n## 05 — Comparative ContextWhere the licence sits among its *peers*.\n\nThe bespoke-licence move is not new among Chinese open-weight labs — but the threshold is. Moonshot’s Kimi K3 shipped under [its own bespoke licence with a far lower trigger](/blog/kimi-k3-open-weights-shipped-license-restrictions-2026) — a separate-agreement requirement for MaaS operators at $20M of aggregate revenue over any consecutive 12 months, one five-hundredth of Z.ai’s $10B line, plus a UI-attribution mandate the glm-5.3 text has no equivalent of. At the permissive end, DeepSeek’s flagship models remain under plain MIT as of this writing. Z.ai has now placed itself between the two: MIT for its efficient model, a hyperscaler-only gate for its flagship.\n\nThere is history here, reported if not primary-verified: The New Stack notes that Z.ai used a custom, registration-required commercial licence for earlier models like ChatGLM3-6B in 2023–2024, then moved every subsequent release to MIT — a trend GLM-5.3 now reverses. And the reversal resolves a gap in our own records: [our census of open-weight licences](/blog/open-weight-model-licence-audit-2026) recorded GLM-5.3’s licence as “not published” as of mid-August, because there was no repository to read. There is now, and the answer is: neither MIT nor Apache, but closer to MIT than any other bespoke model licence we have catalogued. For the three-lab buying picture across DeepSeek, Z.ai, and Moonshot, [the buyer’s scoreboard](/blog/china-open-frontier-august-2026-scoreboard) holds the wider frame; this post is deliberately narrower — one vendor, one week, one clause.\n\n##### MaaS revenue gate\n\nAggregate revenue over any consecutive 12 months before the security-review precondition applies to Model-as-a-Service operators. Everyone below the line: MIT-equivalent freedom in practice.\n\n##### The permissive baseline\n\nDeepSeek’s flagship models remain under plain MIT as of this writing — the reference point that makes both bespoke licences legible as deliberate departures rather than defaults.\n\n## 06 — Two DocumentsThe weights licence is *not* the API terms.\n\nA standard error in open-weight coverage is treating “the licence” as one thing. It is two. The GLM-5.3 License governs the downloaded weights — redistribution, fine-tuning, derivative works. Z.ai’s hosted API is governed by a wholly separate document, its [Terms of Use](https://docs.z.ai/legal-agreement/terms-of-use) with additional API-specific terms that prevail in case of conflict. Different URLs, different documents, different governed activities. Nothing in this post’s clause analysis applies to API customers, and nothing in the API terms constrains what you do with downloaded weights.\n\nThe same discipline applies to pricing, where different hosted surfaces quote different numbers. OpenRouter’s `z-ai/glm-5.3`\n\nlisting — one provider surface, as listed on the OpenRouter model page — shows $1.188 input / $4.18 output per million tokens, with cached reads at $0.247. That is one point in the provider chain, not a canonical list price; Z.ai’s own direct API is a separate surface, and a figure from one surface should never be read as the price on the other. The model itself carries a 1M-token context window with 128K max output, per [Z.ai’s launch post](https://z.ai/blog/glm-5.3), figures the [OpenRouter listing](https://openrouter.ai/z-ai/glm-5.3) is consistent with.\n\n*245GB of memory*, and 8-bit quantisations at roughly 810GB. The practical population for “download and run the flagship” is well-resourced labs and inference providers — which is exactly the population the licence’s one clause addresses.\n\n## 07 — DecisionsWhat this means for *your* stack.\n\nThe clause analysis converts into four postures, depending on where you sit in the chain. For a reader who stops here: unless your company hosts GLM-5.3 itself, sells that access to third parties, and books ten billion dollars of revenue in a year, the glm-5.3 licence functions like MIT for you — but record the licence name, the clause, and the silences in your model-governance file anyway, because the licence a vendor picks today tells you how it may draft the next one.\n\n##### Embedding GLM-5.3 in a product\n\nExplicitly outside the MaaS definition — “model capabilities solely embedded within specific features or harnesses” are carved out. Full commercial use, modification, and fine-tuning rights. Practically MIT-equivalent for you.\n\n##### Relaying to hosted models\n\n“Mere relaying of requests to models hosted by others” is excluded from the MaaS definition by name. Your obligations run to your upstream host’s terms of service, not to the glm-5.3 weights licence.\n\n##### Self-hosting *below* $10B\n\nYou are MaaS, but under the revenue line — no security-review precondition applies. Track the threshold annually as an aggregate-revenue test across affiliates, and note the review’s terms are unwritten if you ever approach it.\n\n##### MaaS above the line\n\nClause 2 applies before any commercial use. What the security review requires is not written anywhere — scope and method are “reasonably determined by Z.AI”. Legal review and direct vendor engagement come before deployment.\n\nThe forward-looking read: within a single August week, one vendor demonstrated that licence choice is now a per-model product decision, not a lab-level philosophy. Expect more of this — a permissive licence where distribution is the growth engine, a gated one where the flagship’s economics need defending. That means licence review stops being a one-time vendor check and becomes a per-release step in model procurement, the same way pricing already is. If your team is standing up that evaluation muscle — routing decisions, licence files, model-governance records — our [AI transformation engagements](/services/ai-transformation) build exactly this discipline into the adoption process.\n\n## 08 — ConclusionOne clause, read *precisely*.\n\n### Read the licence per model, not per vendor.\n\nThe GLM-5.3 weights release is generous by any practical measure: redistribution, fine-tuning, derivative works, and commercial use, all granted “without restriction” to everyone below a threshold that only hyperscalers cross. But it is *not MIT*, and the difference between “MIT” and “almost MIT” is precisely where procurement diligence lives.\n\nThe durable lesson is the split itself. The same vendor, in the same week, shipped one model under the most permissive licence in common use and its flagship under a bespoke document with an unwritten review process at its center. Vendor-level assumptions about licensing are now stale on arrival; the unit of analysis is the model. Every open-weight adoption decision should file three things per release: the licence name on the model card, the clause that differs from the baseline, and the silences — patents, outputs, termination — recorded as silences.\n\nAnd keep one question open in the file: what does Z.AI’s security review actually involve? The licence text does not say, and we found no published document that does. For the companies above the line, that unwritten process is the real licence — and for everyone else, it is the clearest signal yet that in open-weight AI, the licence text has become part of the product.", "url": "https://wpnews.pro/news/glm-5-3-s-weights-are-out-the-licence-is-not-mit", "canonical_source": "https://www.digitalapplied.com/blog/glm-5-3-weights-bespoke-license-not-mit", "published_at": "2026-08-28 00:00:00+00:00", "updated_at": "2026-08-30 08:23:01.599754+00:00", "lang": "en", "topics": ["artificial-intelligence", "ai-policy", "ai-products"], "entities": ["Z.ai", "GLM-5.3", "GLM-5.3-Flash", "Hugging Face"], "alternates": {"html": "https://wpnews.pro/news/glm-5-3-s-weights-are-out-the-licence-is-not-mit", "markdown": "https://wpnews.pro/news/glm-5-3-s-weights-are-out-the-licence-is-not-mit.md", "text": "https://wpnews.pro/news/glm-5-3-s-weights-are-out-the-licence-is-not-mit.txt", "jsonld": "https://wpnews.pro/news/glm-5-3-s-weights-are-out-the-licence-is-not-mit.jsonld"}}