AI DevelopmentNew Release12 min readPublished August 28, 2026

Same vendor, same week · MIT for Flash, a bespoke licence for the flagship

GLM-5.3’s Weights Are Out. The Licence Is Not MIT

Z.ai published the 753B-total-parameter GLM-5.3 weights on Hugging Face on August 28, 2026 — under a bespoke licence tagged glm-5.3, not MIT. Two days earlier, the same vendor shipped GLM-5.3-Flash under the plain, unmodified MIT License. We read both licence texts end to end. They match almost word for word, until one clause.

DA
Digital Applied Team
Senior strategists · Published Aug 28, 2026
PublishedAug 28, 2026
Read time12 min
SourcesBoth raw LICENSE texts + 5
GLM-5.3 scale
753B
total parameters, MoE
Between the two releases
2days
Flash Aug 26 → flagship Aug 28
MaaS revenue gate
$10B
any consecutive 12 months
Substantive divergence
1
clause, of the whole text

The GLM-5.3 open weights arrived on Hugging Face on August 28, 2026 — and the licence field on the model card does not say mit. It says glm-5.3: a bespoke, vendor-named licence written for this one model. Two days earlier, the same company shipped GLM-5.3-Flash under the plain, textbook MIT License — no additions, no appendix.

That split — inside one vendor’s model family, in one calendar week — is the story. Z.ai made the licensing decision twice in seven days and answered it differently each time: MIT for the 320B Flash model, a custom document for the 753B flagship. Anyone planning to self-host, fine-tune, or build a hosted service on the bigger model now has a licence to actually read, because “open weights” no longer tells you what you are allowed to do with them.

So we read both texts end to end — the raw LICENSE files, not the coverage — and built a clause-by-clause comparison: redistribution, modification, commercial use, field-of-use limits, attribution, output ownership, patents, termination. The short version: the two licences are nearly identical, one clause diverges, and what that clause leaves unwritten matters as much as what it says.

Key takeaways
  1. 01
    One vendor, one week, two licence regimes.GLM-5.3-Flash (320B total / 18B active) shipped August 26 under unmodified MIT. The 753B-total flagship’s weights followed August 28 under a bespoke licence the Hugging Face model card tags glm-5.3.
  2. 02
    The grant clause is nearly MIT, extended to model artifacts.The glm-5.3 licence grants use, copying, modification, distribution, sublicensing, and sale “without restriction”, explicitly covering weights, parameters, configs, and training code, plus an added right to run, deploy, and fine-tune.
  3. 03
    One clause diverges: a $10B Model-as-a-Service gate.A licensee operating a MaaS business whose aggregate revenue exceeds $10B over any consecutive 12 months must pass Z.AI’s security review before commercial use. Flash carries no such clause.
  4. 04
    The security review has no published rulebook.The licence says its scope and method “shall be reasonably determined by Z.AI” — no criteria, no timeline, no appeal process appears anywhere in the text. That is an open question, not a process.
  5. 05
    Both texts are silent on patents, outputs, and termination.Neither licence contains a patent grant, an output-ownership claim, or a revocation-for-breach mechanism. Silence is not a restriction — but it is also not a grant, and procurement reviews should record it as silence.

01What HappenedOne vendor, one week, two licences.

First, terms. “Open weights” means a lab publishes the trained model files so anyone can download and run them — as distinct from open source, where the licence attached to those files decides what you may legally do with them. That licence is the subject of this post, because Z.ai just attached two different ones to two models in the same family, two days apart.

The sequence: Z.ai announced GLM-5.3 — the post-training-only successor to GLM-5.2 — on August 14, 2026, promising in its launch post that “We will release the weights in two weeks after launch, once safety evaluation and hardening are complete,” with the stated reason for the hold being that cyber capability “developed faster than we expected” — the disclosure numbers behind that hold are covered in the coordinated-disclosure ledger Z.ai published alongside it. On August 26, the reveal that put GLM-5.3-Flash under MIT landed — weights on Hugging Face the same day, licence field MIT. On August 28, exactly 14 days after the announcement, the flagship’s weights went public at huggingface.co/zai-org/GLM-5.3 — licence field glm-5.3.

Aug 14
GLM-5.3 announced
753B total · no weights, no licence yet

Z.ai launches the flagship on API only, promising weights in two weeks once safety evaluation and hardening are complete. Which licence those weights would carry stays unstated.

z.ai/blog/glm-5.3
Aug 26
Flash ships MIT
320B total / 18B active · unmodified MIT

GLM-5.3-Flash weights land on Hugging Face under the plain, textbook MIT License — copyright Z.AI Co., Ltd, no additions, no appendix, no acceptable-use section.

huggingface.co/zai-org/GLM-5.3-Flash
Aug 28
Flagship ships bespoke
753B total · custom glm-5.3 licence

The flagship weights arrive under a vendor-named GLM-5.3 License — a bilingual English-and-Chinese document that tracks MIT closely until its revenue-gated clause 2.

huggingface.co/zai-org/GLM-5.3

The release itself was framed as fully permissive in spirit. Zixuan Li, a Z.ai team member, wrote in a post on X quoted by The New Stack: “GLM-5.3 is now available for download, local deployment, fine-tuning, and commercial use under the GLM-5.3 License. Given the model’s advanced cybersecurity capabilities, we conducted two additional weeks of comprehensive safety evaluations before releasing the weights.” Note the phrasing: commercial use under the GLM-5.3 License. For almost everyone that distinction is invisible. For one class of company, it is the whole point — and the announcement-to-release gap this ledger tracks now has its GLM-5.3 row resolved: 14 days, precisely as promised.

02The TextsMIT vs glm-5.3, clause by clause.

Every cell in the table below comes from reading the two raw LICENSE files — Flash’s and the flagship’s — not from secondary coverage. The glm-5.3 grant clause is nearly a word-for-word MIT grant, extended to model artifacts explicitly: it grants rights “to deal in the Software” — defined as “including the model weights, parameters, configuration files, inference and training code, and associated documentation” — “without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies,” plus an explicit added right “to run, deploy, fine-tune, or otherwise modify the Software and create derivative works from it.”

Where both texts say nothing — output ownership, patents, termination — the table records the silence as silence. An empty provision is not a restriction, and it is not a grant either.

Clause-by-clause comparison of the MIT License carried by GLM-5.3-Flash and the bespoke GLM-5.3 License carried by the 753B-total-parameter flagship, across redistribution, modification, commercial use, field-of-use limits, attribution, warranty, output ownership, patent grant, and termination. Original Digital Applied synthesis from the two raw LICENSE texts published with the August 2026 releases.
ProvisionMIT License (GLM-5.3-Flash)GLM-5.3 License (753B flagship)Net difference
Where the two texts match
Redistribution“publish, distribute, sublicense, and/or sell copies” — unrestrictedSame operative grant, with “Software” defined to include model weights, parameters, configuration files, and inference and training codeNone in effect — both allow redistribution and resale
Modification & fine-tuning“use, copy, modify, merge”Adds an explicit right “to run, deploy, fine-tune, or otherwise modify the Software and create derivative works from it”None in effect — glm-5.3 spells out what MIT leaves implied
Field-of-use limitsNoneNone found in the text — no industry, geography, or use-case restrictionNone — neither text restricts what you build
Attribution & namingRetain the copyright and permission notice in copiesSame notice-retention sentence as MIT — “The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software” — and no “must display GLM-5.3” UI-naming mandate anywhere in the textNone — neither requires product-level attribution
Where they diverge
Commercial useUnrestricted for everyone, at any scaleUnrestricted — except a Model-as-a-Service operator whose aggregate revenue exceeds $10B over any consecutive 12 months “must pass Z.AI’s security review” before commercial use (clause 2)The single substantive divergence between the two texts
Warranty & liabilityStock MIT: “THE SOFTWARE IS PROVIDED ‘AS IS’”“THE SOFTWARE AND ANY OUTPUT AND RESULTS THEREFROM ARE PROVIDED ON AN ‘AS IS’ BASIS” — the disclaimer explicitly extends to model behaviorTextual, not practical — glm-5.3 acknowledges outputs exist as a category, only to disclaim warranty over them
Where both texts are silent
Output ownershipSilentSilent — outputs appear only inside the warranty disclaimerBoth silent — neither grants nor claims ownership of what the model generates
Patent grantSilentSilentBoth silent — unlike Apache 2.0, neither includes an express patent licence
TerminationNo termination clauseNo termination clauseBoth silent — no revocation-for-breach mechanism; clause 2 is a precondition on one class of licensee, not a termination trigger

Read as a whole, the glm-5.3 licence is a strange artifact: a bespoke legal document whose drafters clearly wanted it to feel like MIT — same grant verbs, same disclaimer skeleton — while carving out exactly one population. That drafting choice is itself informative. A vendor that wanted broad control would have written a broad licence. Z.ai wrote a narrow one.

03Clause 2The $10B Model-as-a-Service gate.

Here is the divergent clause in full, verbatim from the licence text:

“If the Licensee or any of its affiliates operates a Model as a Service business, and the aggregate revenue of the Licensee and its affiliates exceeds 10 billion US dollars (or the equivalent in other currencies) in total over any consecutive 12 months, the Licensee must pass Z.AI’s security review before using the Software or its derivative works for any commercial purpose.”— GLM-5.3 License, clause 2

Two definitions decide who this actually touches. “Model as a Service” — MaaS — means hosting the model yourself and selling third parties API-style access that gives them “meaningful control over the inputs, parameters, or training data.” The licence then explicitly excludes two things from that definition: “end-user products with model capabilities solely embedded within specific features or harnesses,” and “mere relaying of requests to models hosted by others.” In plain terms: building an app on GLM-5.3 is not MaaS, and reselling access routed through someone else’s infrastructure is not MaaS. Hosting the raw weights and selling inference on them is.

Then the revenue line: $10 billion of aggregate revenue — the licensee plus its affiliates, across the whole business, not just the model service — over any consecutive 12 months. That is hyperscaler territory. A startup hosting GLM-5.3 inference, a mid-size inference provider, an enterprise running it internally: none of them cross the line. The clause is drafted to catch a handful of the largest cloud and platform companies on earth and nobody else.

The open question
What does passing the review involve? The licence does not say. Its only words on the subject: “The scope and method of the security review shall be reasonably determined by Z.AI.” No published criteria, no timeline, no appeal process exists in the text, and we found no separate published review-policy document. A company above the threshold cannot currently know, from any written source, what it would be agreeing to — that is an open question to put to the vendor, not a process to describe.

04The GapsWhat the licence does not say.

The context makes one absence genuinely striking. This licence shipped at the end of a two-week safety hold that Z.ai imposed because, in its own words, cyber capability “developed faster than we expected.” You might expect the resulting legal document to say something — anything — about offensive-security use. It does not. Frederic Lardinois, reporting the release for The New Stack, made the same observation independently: “Despite the safety framing, it’s worth noting that the license itself contains no acceptable-use section and also says nothing about cyber or offensive security.”

That is two separate readings — our direct pass through the text and a journalist’s — reaching the same conclusion. The safety concern that delayed the weights left no trace in the licence that governs them. Whatever the two extra weeks of “safety evaluation and hardening” produced, it was not licence language. The restraint on misuse, such as it is, lives entirely outside the legal document: in the hold itself, and in whatever the undefined security review turns out to mean for the very few companies it covers.

The other silences are less surprising but worth recording precisely, because licence summaries routinely get them wrong in both directions. No patent grant — which does not mean patents are asserted; it means the document, like MIT and unlike Apache 2.0, simply does not address them. No output-ownership clause — the only mention of outputs is inside the warranty disclaimer, which neither grants you the outputs nor claims them for Z.ai. No termination clause — nothing in the text describes revoking the licence for breach. Report silence as silence.

“Whether Z.ai changed its license for security reasons or to better monetize its own models is a question worth asking, of course.”— Frederic Lardinois, The New Stack, August 28, 2026

Lardinois’s question is the right one, and the clause’s own shape leans toward an answer. A security-motivated licence would plausibly restrict capabilities — an acceptable-use section, a cyber carve-out. This licence restricts a customer segment: the largest self-hosting platforms, the exact companies most able to monetize the weights at scale without paying Z.ai. Both motivations can be true at once. But the text, read cold, looks more like a commercial lever than a safety instrument.

05Comparative ContextWhere the licence sits among its peers.

The bespoke-licence move is not new among Chinese open-weight labs — but the threshold is. Moonshot’s Kimi K3 shipped under its own bespoke licence with a far lower trigger — a separate-agreement requirement for MaaS operators at $20M of aggregate revenue over any consecutive 12 months, one five-hundredth of Z.ai’s $10B line, plus a UI-attribution mandate the glm-5.3 text has no equivalent of. At the permissive end, DeepSeek’s flagship models remain under plain MIT as of this writing. Z.ai has now placed itself between the two: MIT for its efficient model, a hyperscaler-only gate for its flagship.

There is history here, reported if not primary-verified: The New Stack notes that Z.ai used a custom, registration-required commercial licence for earlier models like ChatGLM3-6B in 2023–2024, then moved every subsequent release to MIT — a trend GLM-5.3 now reverses. And the reversal resolves a gap in our own records: our census of open-weight licences recorded GLM-5.3’s licence as “not published” as of mid-August, because there was no repository to read. There is now, and the answer is: neither MIT nor Apache, but closer to MIT than any other bespoke model licence we have catalogued. For the three-lab buying picture across DeepSeek, Z.ai, and Moonshot, the buyer’s scoreboard holds the wider frame; this post is deliberately narrower — one vendor, one week, one clause.

Z.ai · GLM-5.3
MaaS revenue gate
$10B

Aggregate revenue over any consecutive 12 months before the security-review precondition applies to Model-as-a-Service operators. Everyone below the line: MIT-equivalent freedom in practice.

glm-5.3 licence, clause 2
DeepSeek · flagships
The permissive baseline
MIT

DeepSeek’s flagship models remain under plain MIT as of this writing — the reference point that makes both bespoke licences legible as deliberate departures rather than defaults.

No revenue trigger of any kind

06Two DocumentsThe weights licence is not the API terms.

A standard error in open-weight coverage is treating “the licence” as one thing. It is two. The GLM-5.3 License governs the downloaded weights — redistribution, fine-tuning, derivative works. Z.ai’s hosted API is governed by a wholly separate document, its Terms of Use with additional API-specific terms that prevail in case of conflict. Different URLs, different documents, different governed activities. Nothing in this post’s clause analysis applies to API customers, and nothing in the API terms constrains what you do with downloaded weights.

The same discipline applies to pricing, where different hosted surfaces quote different numbers. OpenRouter’s z-ai/glm-5.3 listing — one provider surface, as listed on the OpenRouter model page — shows $1.188 input / $4.18 output per million tokens, with cached reads at $0.247. That is one point in the provider chain, not a canonical list price; Z.ai’s own direct API is a separate surface, and a figure from one surface should never be read as the price on the other. The model itself carries a 1M-token context window with 128K max output, per Z.ai’s launch post, figures the OpenRouter listing is consistent with.

Hardware reality check
The self-hosting audience for a 753B-total-parameter model is small by physics before it is small by licence. Independent write-ups reported by The New Stack, citing Unsloth’s published figures, put even 2-bit quantisations at roughly 245GB of memory, and 8-bit quantisations at roughly 810GB. The practical population for “download and run the flagship” is well-resourced labs and inference providers — which is exactly the population the licence’s one clause addresses.

07DecisionsWhat this means for your stack.

The clause analysis converts into four postures, depending on where you sit in the chain. For a reader who stops here: unless your company hosts GLM-5.3 itself, sells that access to third parties, and books ten billion dollars of revenue in a year, the glm-5.3 licence functions like MIT for you — but record the licence name, the clause, and the silences in your model-governance file anyway, because the licence a vendor picks today tells you how it may draft the next one.

App builders
Embedding GLM-5.3 in a product

Explicitly outside the MaaS definition — “model capabilities solely embedded within specific features or harnesses” are carved out. Full commercial use, modification, and fine-tuning rights. Practically MIT-equivalent for you.

Proceed; file the licence
Routers & resellers
Relaying to hosted models

“Mere relaying of requests to models hosted by others” is excluded from the MaaS definition by name. Your obligations run to your upstream host’s terms of service, not to the glm-5.3 weights licence.

Governed by host ToS
Inference providers
Self-hosting below $10B

You are MaaS, but under the revenue line — no security-review precondition applies. Track the threshold annually as an aggregate-revenue test across affiliates, and note the review’s terms are unwritten if you ever approach it.

Proceed; monitor the line
Hyperscale platforms
MaaS above the line

Clause 2 applies before any commercial use. What the security review requires is not written anywhere — scope and method are “reasonably determined by Z.AI”. Legal review and direct vendor engagement come before deployment.

Talk to Z.ai first

The forward-looking read: within a single August week, one vendor demonstrated that licence choice is now a per-model product decision, not a lab-level philosophy. Expect more of this — a permissive licence where distribution is the growth engine, a gated one where the flagship’s economics need defending. That means licence review stops being a one-time vendor check and becomes a per-release step in model procurement, the same way pricing already is. If your team is standing up that evaluation muscle — routing decisions, licence files, model-governance records — our AI transformation engagements build exactly this discipline into the adoption process.

08ConclusionOne clause, read precisely.

The shape of open weights, August 2026

Read the licence per model, not per vendor.

The GLM-5.3 weights release is generous by any practical measure: redistribution, fine-tuning, derivative works, and commercial use, all granted “without restriction” to everyone below a threshold that only hyperscalers cross. But it is not MIT, and the difference between “MIT” and “almost MIT” is precisely where procurement diligence lives.

The durable lesson is the split itself. The same vendor, in the same week, shipped one model under the most permissive licence in common use and its flagship under a bespoke document with an unwritten review process at its center. Vendor-level assumptions about licensing are now stale on arrival; the unit of analysis is the model. Every open-weight adoption decision should file three things per release: the licence name on the model card, the clause that differs from the baseline, and the silences — patents, outputs, termination — recorded as silences.

And keep one question open in the file: what does Z.AI’s security review actually involve? The licence text does not say, and we found no published document that does. For the companies above the line, that unwritten process is the real licence — and for everyone else, it is the clearest signal yet that in open-weight AI, the licence text has become part of the product.

Adopt open-weight AI with eyes open

The licence text is now part of the product.

Our team helps businesses evaluate open-weight models on the axes that matter — capability, cost, and licence terms — and build the routing and governance discipline to adopt them safely, delivered in days not quarters.

Free consultationExpert guidanceTailored solutions
What we work on

Open-weight adoption engagements

  • Licence-and-terms review per model release
  • Model routing across open + closed providers
  • Self-host vs hosted-API cost modelling
  • Fine-tuning and deployment governance
  • Procurement files your legal team can sign off
FAQ · GLM-5.3 licence

The questions procurement teams actually ask.

The 753B-total-parameter GLM-5.3 weights, published on Hugging Face on August 28, 2026, are released under a bespoke document titled the GLM-5.3 License — the model card’s licence field reads glm-5.3, not mit or apache-2.0. The text is provided bilingually in English and Chinese, and its grant clause tracks MIT closely: rights to use, copy, modify, merge, publish, distribute, sublicense, and sell, with “Software” explicitly defined to include model weights, parameters, configuration files, and inference and training code, plus an added right to run, deploy, and fine-tune the model and create derivative works. The one substantive departure from MIT is clause 2, a revenue-gated security-review requirement for large Model-as-a-Service operators.
Related dispatches

Continue exploring open-weight releases.