Rights and contracts
Can a buyer release open-weight models trained on your data?
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
A buyer can release open-weight models trained on your data only if your data license allows that distribution, so the answer sits in your contract. Once model weights are public, deletion and termination clauses cannot pull them back. Decide before signing whether to prohibit public release, permit it with conditions, or treat it as a separately negotiated right.
Key takeaways
- Model distribution rights should be addressed expressly; a license that is silent invites dispute.
- Public weights cannot be recalled, so termination and deletion clauses stop working once a model is released.
- Open weights let anyone probe a model without the buyer's output filters, which raises memorization risk.
- Restrictions should also cover models trained on synthetic data generated from your records.
- Allowing release can be reasonable for well-prepared data, but it should be a deliberate, negotiated decision.
When may a buyer publish model weights?#
A buyer may publish open-weight models trained on your data only if your license permits it, either expressly or because the permitted-use clause is broad enough to cover distribution. Open-weight means the trained model's parameters are published for anyone to download and run, as opposed to keeping the model behind an API or inside the company.
Many data licenses focus on what the buyer may do with the dataset and say little about the models. That gap matters because a model is a separate artifact: the buyer usually owns it, and unless the license restricts distribution, the buyer may argue it can do what it likes with its own model.
For a CEO or founder, the practical point is simple. Decide your position on public release before the term sheet, not after a draft model card appears.
Why public weights change your risk#
Public weights change your risk because control passes from one licensee to anyone who downloads the model. With a hosted model, the buyer can filter outputs, monitor use and retrain if a problem appears. With released weights, none of those controls follow the copies.
The concrete concerns are memorization and extraction, where a model reproduces fragments of training records when prompted; fine-tuning by third parties that strips safety layers; and competition, where a freely available model trained on your support or engineering history helps others offer services like yours.
Preparation lowers the first risk. Removing names, contact details, credentials and client identifiers before delivery means whatever a model might reproduce is less sensitive. It does nothing for the competitive question, which is commercial and belongs in the contract.
Release modes compared#
Release modes range from internal use to fully public weights, and each calls for a different license term. Most suppliers are comfortable with the first two rows, which match how many commercial models are offered; the last two deserve explicit negotiation.
| Release mode | Who can access the model | Supplier's remaining control | Typical license approach |
|---|---|---|---|
| Internal use only | Buyer's own staff and systems | Highest; contract and audit rights apply | Permit; restrict sharing outside the buyer |
| Hosted product or API | Buyer's customers through the service | Buyer filters outputs and can retrain | Permit, with output and memorization safeguards |
| Weights licensed to enterprise customers | Named customers under contract | Depends on flow-down terms | Permit only with flow-down restrictions |
| Open-weight public release | Anyone | Minimal after release | Prohibit, or permit only with conditions and written approval |
Clauses that restrict or permit release#
Clauses that restrict or permit release work best when they name both the artifacts and the acts. The outline below covers the usual options; counsel adapts the wording to the deal.
The derived data clause is the one most often missed. A buyer could train a closed model on your records, use it to generate synthetic examples, then release an open model trained on those examples. Without that coverage, a distribution clause can be sidestepped.
- Model distribution restriction: the buyer may not publish, distribute or make available the weights of any model trained, fine-tuned or evaluated on the licensed data, except as permitted.
- Derived data coverage: the restriction also applies to models trained on synthetic data, labels or distilled outputs generated from the licensed data.
- Conditional permission: release is allowed only after written approval, memorization testing by an agreed method and exclusion of specified record types.
- Training-mix threshold: release may be allowed where the licensed data is a minor component of training, with the threshold defined in the agreement.
- Notice and naming: whether the buyer must notify you before release, and whether your company may or may not be named.
- Survival: restrictions on released or releasable models survive termination of the license.
Choosing your position on public release#
Your position on public release should follow from what the records reveal and how much the licensed data would shape the released model. A supplier licensing prepared engineering issues has different exposure from one licensing customer conversations that reflect its service playbook.
Ask the buyer early whether it publishes models, at what stage of development, and under which licenses. A developer that never releases weights may accept a flat prohibition easily; one with a research release program will want a defined path, and that path is better negotiated in the term sheet than in the final draft.
| Supplier position | When it tends to fit | What to negotiate |
|---|---|---|
| Prohibit public release | Records reveal know-how, customer patterns or competitive processes | Clear definition of release, derived data coverage, survival |
| Permit with conditions | Well-prepared records that form a minor part of training | Approval right, memorization testing, excluded record types, notice |
| Permit broadly | Low-sensitivity records where wide use is acceptable to you | Broader rights reflected in commercial terms; naming and attribution |
What happens if the license ends after a release?#
Ending a license after an open-weight release cannot undo the release. Deletion obligations bind the buyer, not the people who already downloaded the weights, so the remaining remedies are damages, indemnities and restrictions on the buyer's future models.
This is why release is treated differently from other permitted uses. A license can usually require deletion of the dataset and, in some negotiations, retirement or retraining of affected models on termination. Public weights take those options off the table, so a decision to allow release is effectively permanent.
Copyright law may not fill the gap. In Getty Images v Stability AI, decided on November 4, 2025, the High Court of England and Wales held that the Stable Diffusion model weights did not store or reproduce Getty's works and so were not an infringing copy; Getty was later granted permission to appeal. If courts treat weights that way, rights in your records may not follow a released model, which leaves the license as your main control.
Illustrative: a helpdesk software company negotiates model rights#
Illustrative: a fictional helpdesk software company prepares a package of its own Zendesk tickets linked to Jira issues and GitHub fixes. A model developer proposes a license that allows training and commercial deployment but says nothing about distribution.
The CEO asks counsel to add a model distribution restriction covering open-weight release and models trained on synthetic data derived from the package. The developer explains that it publishes some smaller research models. The parties agree that public release requires the company's written approval, a memorization test against the delivered records and exclusion of customer-facing reply text, with the restriction surviving termination.
How SourceX treats model distribution terms#
SourceX records permitted use, including any model distribution terms, in the SourceX Evidence Packet for each package, alongside provenance, licensing rights, the privacy record and release authorization. The supplier approves those terms in the Approval step of the SourceX five-step transaction, before Delivery.
SourceX's dataset rights, including any training use, are set out in the signed supplier agreement, and data is licensed, not sold outright, so the supplier keeps ownership of its records and decides how far model rights extend.
Frequently asked questions
Does the license need to define open-weight release?
Yes. Define release by the act, not the label: making model parameters available to anyone outside the buyer and its approved customers, whether by public download, a research access program or a license that permits redistribution. Cover quantized, pruned, merged and fine-tuned versions too, so a smaller derivative cannot be released under a different name.
Is an open-weight release the same as publishing our data?
No. Releasing weights publishes a trained model, not the dataset. But models can sometimes reproduce fragments of training records, and others can fine-tune and redistribute them, so public release extends exposure well beyond the buyer. Preparation that removes personal and confidential details reduces what could surface.
Should we refuse any public release?
Not necessarily. Some suppliers allow it for well-prepared data that does not reveal competitive know-how, especially when the licensed records are a small part of a large training mix. The key is to decide deliberately, set conditions and reflect the broader rights in the commercial terms.
How would we know whether a released model used our data?
Often you cannot tell with certainty from the model alone. That is why the license should require notice before release, records of which models used the data, and audit or certification rights. Contract records, not model inspection, are usually the practical evidence.
Do research-only licenses on released weights protect us?
They help, because they limit commercial use by downloaders, but enforcing them against unknown users is hard. Treat a research-only release as a form of public release when assessing risk, and require your approval for it in the same way.
Sources
- On November 4, 2025, in Getty Images v Stability AI [2025] EWHC 2863 (Ch), Mrs Justice Joanna Smith of the High Court of England and Wales dismissed Getty Images' secondary copyright infringement claim against Stability AI, holding that the Stable Diffusion model weights do not store or reproduce Getty's works and so are not an 'infringing copy'. Getty had dropped its primary training-infringement claim at trial because the training took place outside the UK. In December 2025 the judge granted Getty permission to appeal the secondary-infringement ruling to the Court of Appeal. Source
Related resources
- DataSales call transcripts
- QuestionDo AI labs buy legal documents?
- QuestionDo AI labs delete data after training?
- InsightIf AI training is fair use, why do buyers still license data?
- InsightOpt-in vs opt-out for AI training in B2B SaaS contracts
- InsightCan a 3PL license warehouse video to robotics and AI developers?
See if your company qualifies
A short company assessment. No data uploads are needed.