On July 27, Moonshot AI uploaded the complete model weights for Kimi K3 to Hugging Face. Accompanying the weights was a license of fewer than 3,000 words, titled the Kimi K3 License. It permits anyone to download, deploy privately, fine-tune, use commercially, and even resell the model at no cost. For companies developing AI products, this is tangible good news: a state-of-the-art model can be installed in their own data centers, keeping customer data on-premises. This effectively removes barriers that have constrained financial, healthcare, and legal applications due to data security concerns over the past two years.

However, the next step is where missteps are most likely to occur.The term “free for commercial use” governs the relationship between you and Moonshot AI, whereas the question of “whether external services may be provided” governs your relationship with regulators. Under Chinese law, these two matters are entirely distinct.

Before integrating K3 into your product, you must actually pass through three separate gates: the license addresses only “whether you may use it”; filing addresses “whether you may offer it externally”; and liability rules address “who bears responsibility if something goes wrong.” The first gate is the broadest and is most easily mistaken for the entirety of compliance. We will address each gate in turn below.

Three Gates

What Exactly Was Released This Time

Moonshot AI’s own terminology is layered. The official announcement stated that it released the model weights and technical report for Kimi K3, and open-sourced three key infrastructure components supporting training: MoonEP, FlashKDA, and AgentEnv.

The term “released” was used for the model weights, while the term “open-sourced” was used only for these three infrastructure components.This is not mere semantics. The two batches of materials released on the same day indeed receive different legal treatment: the three repositories are governed by the unconditional standard MIT License, permitting unrestricted use provided that copyright and license notices are retained; the model itself is governed by a conditional, custom-drafted license, which the provider characterizes as “open-weight” rather than “open source.” What you receive are the parameters, inference and training code, and the technical report; the training data and the complete training pipeline remain Moonshot AI’s proprietary assets and do not satisfy the completeness requirements under the Open Source Initiative’s (OSI) “Open Source AI Definition.”

In most scenarios, this distinction is immaterial; however, where a procurer includes “must be OSI-approved open source” as a bidding condition, the conclusion differs.

A more practical point is:When enterprises maintain a license ledger, entries must be recorded separately by repository; the entire release should not be recorded as a single item.

Only after branch registration does the first hurdle truly begin: what exactly does the self-drafted license for the model itself govern with respect to you?

The license only answers the question of "whether you may use it."

First, let us correct a widely circulated misconception. Prior to the release of K3, nearly all Chinese-language reports predicted that it would continue to adopt the Modified MIT License used by K2, and some articles even listed additional clauses such as "synthetic data is not protected by the license." I have conducted a clause-by-clause comparison of the original texts of both licenses: the K3 license is not called the Modified MIT License; it has its own name and consists of five clauses. In contrast, the only modification in K2’s Modified MIT License concerns attribution, as the license expressly states, “the only part we have modified is...,” with no clause addressing synthetic data.

Compared to K2, K3 genuinely adds two elements, both of which warrant attention.

The first is a revenue threshold. The license defines “model-as-a-service” business activities as those that allow third parties to access model inference or fine-tuning while exercising substantial control over inputs, parameters, or training data.

"Model as a Service" means giving a third party access to language model inference or fine-tuning (e.g., via API) in a manner that allows such third party to exercise meaningful control over the inputs, parameters, or training data. This does not include (a) end-user products with model capabilities solely embedded within specific features or harnesses, or (b) mere relaying of requests to models hosted by others.

Only if an activity falls within this definition does the following threshold apply:If the aggregate revenue of you and your affiliates exceeds USD 20 million in any consecutive twelve-month period, you must first enter into a separate agreement with Moonshot AI before using this model or any derivative models for any commercial purposes.

If the Licensee or any of its affiliates operates a Model as a Service business, and the aggregate revenue of the Licensee and its affiliates exceeds 20 million US dollars (or the equivalent in other currencies) in total over any consecutive 12 months, the Licensee must enter into a separate agreement with Moonshot AI before using the Software or its derivative works for any commercial purpose.

There are three aspects of this clause that are easily overlooked.

First, the USD 20 million threshold is calculated based on your company’s total revenue, not merely the revenue from the model services line of business. The original text of the license refers to the “aggregate revenue of the licensee and its affiliates.” A company with annual revenues of RMB 140 million would trigger this threshold simply by launching an external-facing model service, which is not considered a large company in China.

Second, the obligation is to execute the agreement before engaging in commercial use; it is not permissible to sign retroactively after exceeding the threshold, as the original text uses the word “before.”

Third, once triggered, the restriction applies to any commercial use, not solely to the model services portion.

Conversely, the license also clarifies what does not constitute “model-as-a-service”: end-user products that embed model capabilities into specific features are excluded, as are services that merely forward requests to models hosted by others. Therefore, typical SaaS tools, intelligent customer service systems, and copywriting generators generally do not fall under this clause. What truly requires careful consideration are API platforms and model hosting platforms that offer external access to custom parameters and fine-tuning capabilities.

The second aspect is the scope of disclaimers. K2’s disclaimer clause closely mirrors the MIT License, with its subject matter being “this software”; K3 revises this to “this software and any of its outputs and results.”

THE SOFTWARE AND ANY OUTPUT AND RESULTS THEREFROM ARE PROVIDED ON AN "AS IS" BASIS, WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL MOONSHOT AI OR ITS AFFILIATES OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.

This subtle difference in wording clearly allocates the risks of infringement by model outputs and harm caused by such outputs to the user.

By way of analogy: a shopping mall gives you a kitchen knife for free, accompanied by a note stating, “The knife is provided ‘as is’; we assume no liability for any cuts.” If you use this knife to operate a restaurant, food safety becomes your responsibility, not that of the party who gave you the knife.

While this analogy is not entirely precise—since the ways in which a kitchen knife may cause injury are foreseeable, whereas the risks associated with model outputs are not fully foreseeable—it is precisely because such risks are unforeseeable that it is even more critical to expressly stipulate in advance who bears them.

As for the attribution requirement, K3 retains K2’s thresholds: if a commercial product has more than 100 million monthly active users or generates monthly revenue exceeding USD 20 million, “Kimi K3” must be prominently displayed on the interface. Although these thresholds are not reached by most companies, service providers offering privatized deployments should pay particular attention to one issue: if you deploy separate instances for ten clients, how the user volumes across these instances are to be aggregated is not addressed, as the license does not specify rules for aggregating affiliates. It is advisable to clarify this matter in the deployment agreement.

There is also a preliminary question: since no one signs this license from beginning to end, on what basis does it bind you?

Under Chinese judicial practice, the rights holder’s publication of the license alongside the weights constitutes an offer made to unspecified persons, and your acts of downloading, deploying, and fine-tuning constitute acceptance, thereby forming a contract immediately.

More importantly, the phrase “subject to the following conditions” in the main text is treated under Chinese law as a condition subsequent: if the condition is not satisfied, the authorization automatically terminates without prior notice from the licensor, and any subsequent use, lacking a lawful basis, directly falls within the scope of “unauthorized” infringement. This legal approach was established in the Luohex series of cases ((2019) Yue 73 Zhi Min Chu No. 207; (2021) Supreme People’s Court Zhi Min Zhong No. 2063).

The consequences of exceeding the authorized scope cannot be remedied simply by paying additional licensing fees.

In essence,this license addresses only one question: whether you may use this model.It does not, and cannot, answer two other questions.

Filing response to the question “Can you provide services externally?”

The dividing line at this stage is whether you have provided services to the public within mainland China.

If K3 is deployed solely within a company for its own employees to draft materials and conduct analyses, it generally does not constitute a service provider as defined under the Interim Measures for the Administration of Generative Artificial Intelligence Services.

The Measures expressly state: Industry organizations, enterprises, educational and research institutions, public cultural institutions, relevant professional institutions, and other entities that develop and apply generative artificial intelligence technologies without providing generative artificial intelligence services to the public within mainland China are not subject to the provisions of these Measures.

Once services are provided externally, your legal status changes.

Moreover, the term “externally” here is broader than many assume: A provider of generative artificial intelligence services refers to any organization or individual that uses generative artificial intelligence technologies to provide generative artificial intelligence services (including by providing programmable interfaces or other means).

In practice, B2B arrangements are not automatically excluded: If enterprise customers use your product to provide services to an unspecified public (typical examples include customer-service products), you may still be deemed to be providing services to the public within mainland China. Internal testing or targeted public beta testing that reaches a certain scale may likewise be regarded as having commenced service provision; packaging or embedding third-party models for external provision is also included in this assessment.

Once your status as a provider is confirmed, two filing procedures must be completed, collectively referred to in practice as the “dual filings”: Algorithm filing is conducted through an online system and typically takes two to three months; large-model filing requires offline submission to the provincial-level cyberspace administration in your locality, with dual review at both provincial and central levels, typically taking six to eight months.

There is a specific pitfall concerning “self-deployedopen-source modelstraps.

Regulators have established a simplified channel for enterprises that call upon third-party large models already on file, known as generative service registration, which requires only the consent of the provincial-level cyberspace administration in your locality and entails significantly lighter documentation requirements.

However, this pathway is subject to two prerequisites: the model invoked must be a third-party model that has completed filing, and you must not have made any adjustments that affect the generated content.

Downloading the K3 weights for self-deployment does not constitute “invoking a third-party filed model”; furthermore, injecting vertical-domain corpora for fine-tuning explicitly requires compliance with filing procedures.

In other words, while using open-source models can save on API invocation fees and mitigate the risks associated with cross-border data transfer, it cannot save the six to eight months required for such procedures.

Product scheduling should be calculated backward from this point.

Liability addresses the question of “who bears responsibility in the event of an incident.”

Having passed the first two hurdles, one final question remains, which is also the most critical misconception to dispel: if an open-source model from another party is used at the underlying layer, can liability be traced upstream in the event of an incident?

The answer is generally no.

The aforementioned disclaimer clause is unequivocal, leaving the risks associated with the output on your side.

Chinese law aligns with this direction, stipulating that providers directly bear the liabilities of online information content producers: providers shall bear the liabilities of online information content producers in accordance with the law and fulfill their obligations for online information security.

Where personal information is involved, they shall bear the liabilities of personal information processors in accordance with the law and fulfill their obligations for personal information protection.

In terms of daily operations, there are three unavoidable matters.

The first is the legality of the training corpus.You are solely responsible for the corpus used to fine-tune K3, including whether the source of such data is lawful, whether it infringes intellectual property rights, and whether consent has been obtained for any personal information involved. Providers of generative artificial intelligence services (hereinafter referred to as “Providers”) shall conduct training data processing activities, such as pre-training and optimization training, in accordance with the law and comply with the following requirements: (1) use data and foundation models from lawful sources; (2) where intellectual property rights are involved, refrain from infringing upon the intellectual property rights enjoyed by others in accordance with the law; (3) where personal information is involved, obtain individual consent or meet other circumstances prescribed by laws and administrative regulations; (4) adopt effective measures to improve the quality of training data and enhance its authenticity, accuracy, objectivity, and diversity; and (5) comply with other relevant provisions of laws and administrative regulations, such as the Cybersecurity Law of the People’s Republic of China, the Data Security Law of the People’s Republic of China, and the Personal Information Protection Law of the People’s Republic of China, as well as relevant regulatory requirements issued by competent authorities.

The liability borne by Moonshot AI for pre-training data is a separate matter and is unrelated to the batch of corpus you injected.

The second matter concerns the handling of unlawful content:Where a Provider discovers unlawful content, it shall promptly take disposal measures such as stopping generation, stopping transmission, and deletion, implement rectification through measures such as model optimization training, and report to the relevant competent authorities.

The third matter is the labeling obligation, which has been strictly enforced since September 1, 2025.The Measures for the Labeling of Artificial Intelligence-Generated and Synthesized Content require the addition of implicit labels in file metadata. Service providers shall, in accordance with Article 16 of the Provisions on the Administration of Deep Synthesis of Internet Information Services, add implicit labels to the file metadata of generated or synthesized content. Such implicit labels shall include production element information such as attributes of the generated or synthesized content, the name or code of the service provider, and the content identification number.

Note that this provision is mandatory, whereas the second paragraph of the same article merely encourages the use of digital watermarks: service providers are encouraged to add implicit labels in the form of digital watermarks to generated or synthesized content.

The legal force of these two requirements differs; treating digital watermarks as a mandatory obligation is a common misinterpretation.

Explicit labeling is subject to additional prerequisites. It is triggered only when the circumstances fall under Paragraph 1 of Article 17 of the Provisions on the Administration of Deep Synthesis of Internet Information Services and where such content “may cause confusion or misidentification among the public.”

These obligations are not merely theoretical. In case No. (2024) Yue 0192 Min Chu 113, the Guangzhou Internet Court presided over the first publicly disclosed AIGC() service infringement case in China. The defendant platform generated images substantially similar to Ultraman based on user instructions. The court found that the platform infringed the rights of reproduction and adaptation, ordered compensation of RMB 10,000, and mandated keyword filtering to ensure that “when users normally use prompts related to Ultraman, images substantially similar to the Ultraman works involved in the case cannot be generated.”

Although the compensation amount was not high, what truly warrants attention are the deficiencies cited by the court in finding the platform at fault: failure to implement keyword filtering and content review, lack of a complaint and reporting mechanism, absence of risk warnings, and failure to provide prominent labeling.

The checklist of “things not done” essentially serves as a ready-made compliance checklist.

Enforcement authorities are equally unequivocal. In April 2025, the Cyberspace Administration of China (CAC) launched the special campaign “Clear and Bright: Rectifying the Misuse of Artificial Intelligence Technologies.” In June of the same year, it announced the results of the first phase: more than 3,500 AI products, including non-compliant mini-programs, applications, and agents, were dealt with, and more than 3,700 accounts were sanctioned.

Among the four key areas of rectification, the first two are compliance with product market-access requirements and compliance with training corpus requirements.

Three Types of Companies, Three Different Focal Points

The weight of these three regulatory thresholds varies depending on the size of the company.

Small teams and early-stage products that do not meet the two licensing thresholds need not spend time deliberating on them; what they truly need to handle is filing. Six to eight months should be reserved during the product scheduling phase. When listing on app stores and mini-program platforms, you will typically be asked to provide the algorithm filing number first.

Do not interpret “free model” as “exemption from procedures.” A significant portion of the products sanctioned in the past two years encountered issues at this very step.

Companies that have already achieved scale should first perform two calculations.

The first is to aggregate the revenues of the company and its affiliates over the past twelve months to determine whether they exceed the threshold of USD 20 million.At the same time, confirm whether your business model falls within the definition of Model-as-a-Service (MaaS) under the agreement. If both conditions are met, a contract must be negotiated before commercial use.

The second is to confirm the fine-tuning plan. As long as it involves training that affects generated content, the simplified registration pathway cannot be used.

Service providers engaged in integration and private deployment face the most complex situation, as they must coordinate with both upstream and downstream parties.

Upstream, the usage restrictions, attribution thresholds, and disclaimer clauses in the license must be faithfully incorporated into the service agreements you execute with your clients; do not make commitments that exceed the scope of your own rights.

Downstream, the scenarios in which customers use your product and whether such use constitutes provision to the public directly determine who bears the filing obligations. This matter should be clearly stipulated in the contract, rather than left to dispute after an incident occurs.

The same principle applies to how user volumes are aggregated across multiple customers and multiple instances.

For ordinary users, there is only one thing to know: the “AI-generated” label in content is not a discretionary choice by the platform, but a statutory obligation; malicious deletion, tampering with, or concealment of such labels is expressly prohibited.

Open source lowers the barrier to entry.

The value of open-source models is real: it reduces the cost of accessing cutting-edge capabilities to near zero and resolves the longstanding issue that data must leave its source.

However, it lowers the barrier to entry, not the barrier to lawful operation.

Model weights may be downloaded for free, but liability does not transfer along with the weights.

Licenses address “whether it can be used,” filings address “whether it can be provided externally,” and legal liability addresses “who pays if something goes wrong.”These three safeguards are all indispensable. If there is any shortcut, it is to incorporate these three matters at the product initiation stage, rather than leaving them until one week before launch.

When enterprises integrate open-source large language models to provide external services, there is room to lock down each link in advance, from license review and dual-filing pathway design to the flow-down of liabilities in user agreements and delivery contracts.

If you have specific projects to implement, you are welcome to leave a message in the background for discussion.

References

Official text of the Kimi K3 License, Moonshot AI Hugging Face repository moonshotai/Kimi-K3

Official text of the Kimi K2 Modified MIT License, Moonshot AI Hugging Face repository

Official announcement and technical blog for the Kimi K3 Open Day by Moonshot AI

License files for the MoonEP, FlashKDA, and AgentENV repositories (all under the MIT License)

Interim Measures for the Administration of Generative Artificial Intelligence Services, Order No. 15 issued by seven departments including the Cyberspace Administration of China

Measures for the Labeling of AI-Generated and Synthesized Content, issued by four departments including the Cyberspace Administration of China

Provisions on the Administration of Deep Synthesis in Internet Information Services, issued by three departments including the Cyberspace Administration of China

Provisions on the Administration of Algorithmic Recommendations in Internet Information Services, issued by four departments including the Cyberspace Administration of China

Civil Judgment (2024) Yue 0192 Min Chu No. 113 of the Guangzhou Internet Court

Civil Judgment (2019) Yue 73 Zhi Min Chu No. 207 of the Guangzhou Intellectual Property Court and Civil Judgment (2021) Zui Gao Fa Zhi Min Zhong No. 2063 of the Supreme People's Court

Bulletin on the First Phase of the Special Campaign “Qinglang: Rectifying the Abuse of Artificial Intelligence Technologies” launched by the Cyberspace Administration of China

Open Source Initiative (OSI) Open Source AI Definition 1.0

/ END.

*This article is an original work of Mankun Law Firm. It reflects solely the personal views of the author and does not constitute legal consultation or legal advice on any specific matter. For reprint permissions or legal consultation, please contact customer service:mankunlawyer

Author

Article Illustration

About Mankun

Article Illustration