tuesday, october 6, 2026 · the day's ai, attributed published by trilot llc · wyoming
guide · working with ai

What to check on an open model from another country

Separate the licence, the weights, the host and the law, so you can answer a client's question about a foreign open model in one paragraph instead of a week.

Published 2026-09-05 · Updated 2026-09-05 · Read 9 min · Reviewed by Rami Steitieh

Verified 2026-09-05 · Rami
on this page · 0 / 0 checked

You moved the boring half of the work onto a cheaper model. Classification, first drafts, pulling fields out of invoices, the summaries nobody reads twice. On Together AI’s serverless pricing, DeepSeek V4 Flash 0731 runs at $0.14 per million input tokens and $0.28 per million output, while the Pro model in the same family is $1.32 and $3.96 [8]. The arithmetic made the decision look easy. Then a client asked which models touch their material, or a colleague said “isn’t that the Chinese one”, and you found you had one answer for four different questions.

They are four questions with four different owners. What the licence permits is about your rights. What the model is, and what it learned from, is about disclosure. Where your work goes when you press send is about the host, not the lab that trained the weights. What the law asks is mostly about somebody else’s paperwork. Answered separately, each one is short, and three of them you can settle this afternoon. This guide is for a solo operator or a small team choosing between endpoints, without a compliance function or a lawyer on retainer. It is not for you if a contract you have already signed names permitted model origins, because then the contract decides and the conversation is with whoever signed it. It is not for anyone training or releasing a model, who carries obligations this guide only glances at.

A permissive licence grants rights and promises nothing

DeepSeek V4 Flash ships under the MIT License. The model card says so in one line: “This repository and the model weights are licensed under the MIT License” [5]. The MIT text grants permission “to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies”, on the single condition that the copyright notice travels with it [3]. There is no commercial restriction, no obligation to open your own application, no headcount cap.

The half people skip is the other half. The same licence states that “THE SOFTWARE IS PROVIDED ‘AS IS’, WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT”, and that “IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY” arising from the software or its use [3]. Read that as a business fact rather than boilerplate. Nobody has promised you the model works, nobody has promised the training material was theirs to use, and nobody is on the hook if it was not.

That is the actual trade, and it is the trade you are being asked about even when the question sounds geopolitical. A paid API from a large vendor comes with terms, a support path and someone to sue. An MIT model comes with weights. Both can be the right choice. Only one of them has a counterparty.

”Open” is a claim, and the definition asks for more than weights

The Open Source Initiative published version 1.0 of its Open Source AI Definition on 28 October 2024 [2]. It sets four freedoms: use the system for any purpose without having to ask permission, study how it works and inspect its components, modify it for any purpose including changing its output, and share it with or without modifications [2]. Weights released under the MIT License clear those four comfortably, because MIT grants use, modification and redistribution outright [3].

The next requirement is where a weights release stops. The definition says the preferred form for making modifications must include three things: data information, meaning “sufficiently detailed information about the data used to train the system so that a skilled person can build a substantially equivalent system”; the complete source code used to train and run the system; and the model parameters [2]. DeepSeek publishes the parameters and tells you the model was pre-trained on “more than 32T diverse and high-quality tokens” [5]. That is a measurement of the training set, not a description of it, and it is not information a skilled person could rebuild from [2].

So the honest label for a release like that one is open-weight rather than open-source, and the practical consequence is narrow and specific. You can run it, change it, and host it yourself. You cannot audit what it learned. Every downstream worry that sounds like a provenance question is really that same gap wearing different clothes: copyright exposure, personal data in the training set, and behaviour shaped by a corpus you cannot see. Knowing which questions are unanswerable is worth more than a confident guess about any one of them.

The jurisdiction clause lives in the licence file, and rarely where you expect

If a model is going to restrict who you are or where you are, the restriction is in the licence, not in the news coverage. The clearest example in circulation comes from Meta. The licence terms published with Llama 3.2 say: “With respect to any multimodal models included in Llama 3.2, the rights granted under Section 1(a) of the Llama 3.2 Community License Agreement are not being granted to you if you are an individual domiciled in, or a company with a principal place of business in, the European Union.” The next sentence adds the carve-out: “This restriction does not apply to end users of a product or service that incorporates any such multimodal models” [4].

Read that twice if you run a company in the EU. Meta withheld multimodal rights from EU-domiciled businesses [4], while DeepSeek shipped V4 Flash under the MIT License [5], which carries no geography clause at all [3]. The country the weights came from did not predict the direction of the restriction. Neither did anyone’s intuition about which jurisdiction was the risky one.

The operational lesson is dull and reliable. Open the LICENSE file for the exact model and the exact version you are pulling, and read it for three things: geography, company size, and field of use. That takes four minutes and it is the only place a rule of that kind can bind you. A summary on a comparison site is not the licence, and a licence from the previous release is not this one.

Where your work goes is set by the host, not by the lab

This is the question clients are usually asking, and it has nothing to do with the licence. DeepSeek’s own privacy policy, covering its own consumer and API services, states: “To provide you with our services, we directly collect, process and store your Personal Data in People’s Republic of China” [6]. It lists text input, voice input, prompts, uploaded files and photos among what it collects, and says that material is used “to improve and develop the Services and to train and improve our technology, such as our machine learning models”, with a right to opt out of that training use [6].

Now take the same MIT-licensed weights and run them somewhere else. Together AI sells DeepSeek V4 Flash 0731 from its own serverless endpoints at its own prices [8], so identical weights reach you under a different company’s terms. Hosts can go further than that. AWS documents that Amazon Bedrock performs “a deep copy of a model provider’s inference and training software” into deployment accounts “owned and operated by the Amazon Bedrock service team”, and that “because the model providers don’t have access to those accounts, they don’t have access to Amazon Bedrock logs or to customer prompts and completions” [7]. Three hosts, three different answers to the client’s question, and the difference is not in the licence or the benchmark scores. It is in which endpoint you typed into your config file.

Which means “we use DeepSeek” describes at least two arrangements that a client would judge very differently, and the sentence on its own is useless to them. Write down the endpoint instead of the model name. When somebody asks which models touch their material, the sentence that actually answers the question names a company, a region and a data policy, and the model is a detail inside it.

The paperwork the AI Act asks for lands on whoever released the model

Article 53 of the EU AI Act sets obligations for providers of general-purpose AI models, and the word doing the work there is providers. If you are calling a model through an API or self-hosting one for your own use, that article is not addressed to you. It requires the provider to “draw up and keep up-to-date the technical documentation of the model, including its training and testing process”, to make information and documentation available to providers of AI systems who build on it, to “put in place a policy to comply with Union law on copyright and related rights”, and to “draw up and make publicly available a sufficiently detailed summary about the content used for training” using the AI Office’s template [1].

The open-source carve-out is narrower than its reputation. For models released under a free and open-source licence with publicly available parameters and architecture information, the two documentation duties fall away, but the copyright policy and the public training-content summary still apply, and none of the exemption is available at all to models classified as carrying systemic risk [1]. So the one disclosure the law insists on even for a freely released model is the summary of what it was trained on.

That gives you something concrete to go and look for, which is more useful to you than the article’s obligations are. Search for the provider’s published training-content summary before you commit. If it exists, read it and keep a copy with the date. If it does not, write one line in your notes saying you looked and it was not there. That sentence is worth more in a client conversation than any assurance you could improvise on the call.

Price the swap before anyone argues about it

The reason this question comes up at all is money, so put the money on the page early. Together AI’s serverless list shows DeepSeek V4 Flash 0731 at $0.14 input and $0.28 output per million tokens, with cached input at $0.03; DeepSeek V4 Pro 0813 at $1.32 and $3.96, cached input $0.13; Qwen3.8 Flash at $0.15 and $0.47; and Llama 3.3 70B at $1.04 both ways [8].

Two things fall out of that single page. Input price differences look enormous and output price differences decide the bill, because output is where the tokens are expensive and where reasoning models spend them. DeepSeek Pro’s output costs exactly three times its input [8], so a workload that writes long answers converges toward the output price no matter how cheap the prompt side looked. And the gap between labs is smaller than the gap between tiers: Flash is nearly ten times cheaper than Pro on input, from the same lab, on the same page [8].

Run your own numbers before the debate turns into a discussion about countries. If the saving is $40 a month, the provenance conversation is not worth the hour it will take. If it is $4,000, it is worth doing properly, which means the checklist below rather than a hunch.

calculator
Monthly inference bill
— $ / month

Defaults are Together AI's listed serverless prices for DeepSeek V4 Flash 0731. Run it twice, once with each candidate's prices, and compare the two totals. Computed in the page; nothing is sent anywhere.

checklist
Before a foreign open model goes near client work
0 of 7 · saved in this browser only

What still goes wrong

The disclosure gap does not close, and nothing in this guide closes it. Even where a training-content summary exists it is a summary, produced by the party with the least interest in making it alarming [1], and the Open Source AI Definition’s own bar, information detailed enough for a skilled person to rebuild a substantially equivalent system [2], is not cleared by publishing weights and a token count [5]. If your real exposure is copyright in the training set or personal data inside it, you are managing that risk by contract and insurance, not by reading. That is true of closed frontier models too. They just do not invite the question as loudly.

Licences move between releases and hosts move underneath you. The EU clause quoted above applied to the multimodal models in one Llama release [4], which tells you nothing reliable about the next one in either direction. Meanwhile nothing in a licence follows the weights to a new host, so a routing layer that quietly changes which company serves your requests changes your answer to the client’s question without sending you an email about it. Pin the provider where you can, and re-read both the licence and the host’s terms when you upgrade a version rather than when something goes wrong.

Finally, this guide answers what actually happens to your data. It does not overrule a rule that names countries as a fact in itself. Plenty of procurement frameworks and customer contracts do exactly that, and a well-evidenced explanation of your data path is not a defence against a clause you already agreed to. If you have promised a client that their material stays with US or EU providers, that promise stands whatever the licence says, and the honest move is to renegotiate it rather than to reason your way around it.

sources
  1. 01EU AI Act — Article 53, Obligations for providers of general-purpose AI models (AI Act Service Desk, European Commission)ai-act-service-desk.ec.europa.eu
  2. 02Open Source Initiative — The Open Source AI Definition v1.0opensource.org
  3. 03Open Source Initiative — The MIT Licenseopensource.org
  4. 04Meta — Llama 3.2 Community License Agreement and Acceptable Use Policy (meta-llama/Llama-3.2-1B model card)huggingface.co
  5. 05Hugging Face — deepseek-ai/DeepSeek-V4-Flash model cardhuggingface.co
  6. 06DeepSeek — Privacy Policycdn.deepseek.com
  7. 07AWS — Data protection in Amazon Bedrockdocs.aws.amazon.com
  8. 08Together AI — Pricingtogether.ai
next guide
How to check an AI vendor's safety claim
9 min · verified 2026-09-05
related guides