˂  Back

Open Source AI: Top 5 Key Takeaways Your Company Should Know Before Deployment

In our previous article, we discussed Enterprise AI Contracting. But when it comes to AI deployment, companies will generally find themselves considering one of two broad approaches.

 

The first route is through Enterprise AI, as we discussed in the previous article, where companies typically procure an AI solution from an established AI provider and then deploy it under a standard enterprise AI deployment arrangement. Besides the enterprise route, another alternative model that has been rapidly gaining traction in the market is what is commonly referred to as “Open Source AI”. 

 

As a matter of fact, chances are, if you are reading this article, your company, or especially the IT or procurement team, may have already raised and starting to entertain the possibility of deploying Open Source AI for a variety of reasons. Some organisations are attracted by the possibility of keeping data within their own environment for cybersecurity or data security purposes. Others may be looking to reduce recurring subscription costs, usage charges or API fees associated with Enterprise AI solutions. Some may simply want greater control and flexibility over how the AI model is deployed, customised and integrated into the organisation’s existing technology environment. There is, of course, no single or perfect reason why Open Source AI is necessarily more superior or better than Enterprise AI, but there can be many perfectly legitimate reasons why an organisation may prefer to depart from the conventional Enterprise AI model and instead opt for an Open Source AI deployment.

 

Naturally, once “Open Source AI” is suggested, it then raises a number of important questions for the in-house legal team to consider and let simmer. What exactly is Open Source AI? How is Open Source AI different from Enterprise AI? Is Open Source AI really free to use? If there is no recurring licence fee payable to an AI provider in the same way as under an Enterprise AI arrangement, does that mean the organisation can simply download any Open Source AI model, deploy it internally and start using it without further restrictions?

 

And if the answer to all of the above is really yes, and it is truly that simple and straightforward, any legal counsel worth their salt will naturally raise an eyebrow and ask: “if it is really that good, what then is the catch with Open Source AI?” Because, as with all things in life, every advantage comes with a trade-off, and there is rarely such a thing as a free lunch, and the same is true when choosing between Enterprise AI and Open Source AI.

 

Therefore, in this article, we set out the top 5 key takeaways that general counsels, boards, senior management and in-house legal teams should understand and pay close attention to before deploying Open Source AI within their organisations.

 

Key Takeaway 1: Understand the Difference Between Enterprise AI and Open Source AI and, More Importantly, the Different Types of Open Source AI

 

The first key takeaway is to understand the difference between Enterprise AI and Open Source AI, and, more importantly, the different types of Open Source AI that are currently available in the market.

 

If we may use a simple car analogy, which we will be using quite a lot throughout this article to illustrate the differences between Enterprise AI and the different types of Open Source AI, then Enterprise AI can perhaps be understood as having a chauffeur, whereas Open Source AI is more akin to owning the car yourself.

 

When it comes to Enterprise AI, you do not essentially own the underlying AI model. The frontier AI model is developed, maintained and controlled by the AI technology provider, and your organisation is essentially paying for access to and use of that provider’s AI model as a service, for a defined set of use cases, purposes and commercial terms.

 

In other words, your organisation is not acquiring ownership of the AI model itself. Instead, the AI provider continues to own and operate the underlying technology, while your organisation is granted the contractual right to access and use the AI service during the agreed contractual period. Upon the expiry or termination of that arrangement, organisation’s right to access and use the Enterprise AI service would then generally come to an end. 

 

Hence, for Enterprise AI, we use the analogy that you do not own the car, and instead, you have a chauffeur who provides the transportation service for as long as the commercial arrangement continues.

 

Open Source AI, however, is much more similar to owning the car rather than having a chauffeur. The important point, however, is that while the market likes to generically refer to all of these models as “Open Source AI”, but not all Open Source AI is the same. In fact, there are quite a number of different types of Open Source AI currently available in the market. 

 

For the purpose of this high-level discussion, fundamentally, from what we are seeing in the market, there are 3 crucial categories, with the principal difference being the degree or level of openness that each model actually provides:

 

  1. Genuine Open Source AI
  2. Community-Licensed AI
  3. Open-Weight AI



  • Genuine Open Source AI

 

The first category is what the market would typically regard as the gold standard of genuine Open Source AI, with true and extensive openness and freedom, including the freedom and ability to use, study, modify and share the AI system. This represents perhaps the purest form of Open Source AI, where the organisation is given the highest and greatest degree of openness and, potentially, control over the AI system from end to end, including access to matters such as the source code, model parameters, model weights and other detailed information regarding the training data and process.

 

Unfortunately, in practice, this level of genuine and comprehensive openness remains extremely rare in the market. Indeed, even outside the AI industry, it is relatively uncommon for any major proprietary technological development to be made available with such an extensive degree of openness. 

 

Using our car analogy, genuinely Open Source AI is therefore like receiving not only the car and the keys, but also the engineering blueprints, repair manuals and the freedom to inspect, modify and even rebuild the car yourself.


  • Community-Licensed AI 

 

The second category of Open Source AI, which is becoming increasingly popular, is what is typically referred to as a community-licensed AI model.

 

Community-licensed AI models are somewhat similar to genuinely open source models in the sense that the AI model may be downloadable and companies may be given significant freedom and flexibility to use, deploy and modify it. The key distinction, however, is that the model developer will typically impose its own bespoke licensing conditions governing how the community-licensed AI model may be used.

 

A good illustration is Meta’s Llama 4, where the model is made available under the Llama 4 Community License. The licence grants broad rights to use, reproduce, modify and distribute the model, but at the same time contains specific conditions relating to matters such as attribution, acceptable use and certain commercial usage thresholds. It also incorporates an Acceptable Use Policy and provides that an organisation exceeding certain monthly active users within the applicable measurement period must request a separate licence from Meta before exercising the relevant rights.

 

Using the car analogy, a community-licensed AI model is therefore more like receiving a car that you are broadly allowed to drive and modify, but subject to the manufacturer’s contractual rules, for example, restrictions on how the car may be used, requirements to acknowledge the manufacturer, or additional conditions if you operate a very large commercial fleet. You have considerably more control than you would have with a chauffeur, but still, you have not necessarily been given completely unrestricted freedom.


  • Open-Weight AI

 

The third and final category is “Open-Weight AI”, which is also becoming increasingly popular and, from what we are seeing in the market, may ultimately be more commercially relevant for many organisations than either genuinely open-source AI or community-licensed AI.

 

Under an Open-Weight AI model, the trained model weights are publicly available, and the company may be permitted to download and run the AI model itself. However, Open-Weight AI is not necessarily fully open source because, typically, the broader AI development process, proprietary training datasets, full pre-training source code and other surrounding technologies may not be made available.

 

One practical example is OpenAI’s gpt-oss models, which OpenAI itself describes as open-weight models. The model weights are made available under the Apache 2.0 licence, together with the applicable usage policy, and organisations may download, customise and run the models on infrastructure under their own control. In this case, the models use the standard Apache 2.0 open-source licence rather than a bespoke community licence, allowing developers broad freedom to use, modify and deploy the weights commercially without requiring special permission.

 

While this remains an open-weight AI model, rather than a genuinely fully open-source AI system where an organisation has access to the entire AI development process, training dataset and surrounding technology, however, from our observation, for many companies looking simply to deploy an AI model for ordinary commercial use cases, this level of openness may already be more than sufficient because truthfully, even if a company were given access to a genuinely fully open-source AI model, most organisations would still not necessarily have the internal capability, infrastructure or technical expertise required to undertake sophisticated AI model development and training themselves.

 

So, returning once again to our car analogy, Open-Weight AI is therefore more like receiving the complete car and being allowed to open the bonnet, modify the engine and drive it wherever you want, but without necessarily receiving the manufacturer’s original engineering blueprints, factory processes or details of how every component was originally developed.

 

So, while all 3 categories of AI models may ultimately allow you to “drive the car”, but the real question is how much of the car you are actually given access to, what you are permitted to do with it, and what conditions come attached to the usage.

 

Therefore, while the market may generally refer to all of these models simply as “Open Source AI”, before anything else, organisations should identify precisely what type of model they are actually considering as the starting point.

 

Key Takeaway 2: Does Open Source AI Mean That the Company Does Not Need to Pay Any Licence Fee to the AI Provider?

 

The second key takeaway is whether Open Source AI means that the company does not need to pay any licence fee to the AI provider.

 

Typically, when it comes to Open Source AI, regardless of the type of model being considered, one of the strongest commercial arguments in its favour is that the organisation may not need to pay the same hefty licensing fees that would ordinarily be associated with Enterprise AI. And, to a large extent, that is actually pretty true.

 

When companies procure a typical Enterprise AI solution, the service is being provided by the AI service provider. Therefore, the commercial arrangement will almost invariably involve some form of payment to the AI provider, whether in the form of subscription fees, enterprise licensing fees, per-user charges, API usage fees, token-based charges or other forms of consumption-based pricing.

 

However, when it comes to Open Source AI, it is generally safe to say that many open-source and open-weight AI models may be downloaded, deployed and used without paying the conventional licensing fees that would ordinarily be payable to an Enterprise AI service provider. But, of course, as mentioned above, unless one is dealing with a genuinely fully open-source AI model, which remains few and far between, it would be dangerous to assume that “free to use” necessarily means “free from conditions”, as there is rarely such a thing as an entirely free buffet with no rules attached.

 

In the case of open-weight models and community-licensed models, while the model may generally be available for use without an upfront or recurring licence fee, there will often still be some licensing conditions governing how the model may be used. More importantly, depending on the applicable licence, that free usage may only continue up to a certain level or within certain parameters.

 

Depending on the model and the applicable licence, additional conditions may arise once certain commercial thresholds are reached, or where additional components, support, hosting or separate services are required. For example, the model may be freely available for internal deployment, experimentation or ordinary commercial use, but once the organisation crosses a specified usage, user, revenue or commercialisation threshold, or begins deploying the model at a significantly broader commercial scale, additional obligations may start to apply. These may include the need to obtain a separate commercial licence, negotiate additional rights, pay licensing or usage fees, or procure additional paid components, support or services from the model provider. In other words, “free at the point of entry” does not necessarily mean “free at every level of scale”.

 

Therefore, perhaps one of the most dangerous assumptions an organisation can make is to conclude that, simply because an Open Source AI model itself can be downloaded and deployed within the organisation without an upfront licence fee, there is also no need to review the applicable licence terms by assuming that an Open Source AI system will remain completely free to operate indefinitely and without limitation, because the absence of a conventional licensing fee does not mean the absence of contractual conditions, usage restrictions or commercial thresholds especially once the organisation’s usage reaches a particular scale.

 

Key Takeaway 3: Even If the Open Source AI Model Is Free, Running Open Source AI Is Definitely Not Free

 

The third key takeaway is that even if the Open Source AI model itself is free, running Open Source AI is definitely not free.

 

Continuing from the point above, even where one is dealing with a genuinely Open Source AI model, or where the applicable licensing terms are truly free from any licensing fee or payment obligation, one commercial aspect that is frequently overlooked is that operating the Open Source AI model itself still comes with very real costs.

 

One of the biggest misunderstandings we have seen in the market is the assumption that, so long as the organisation is using an Open Source AI model with no licensing fee, there will therefore be no material additional cost involved. However, in practice, it is rarely that straightforward.

 

In order to actually deploy and run the AI model, the organisation will need to put in place the necessary infrastructure to support it, including the required compute capacity, storage, third-party hosting, networking infrastructure and overall processing power needed to operate the model properly. The level of infrastructure cost will naturally depend on the size, complexity and intended use of the model. Depending on the circumstances, an organisation may require specialised GPUs, substantial memory, servers, cloud-computing capacity, storage, networking infrastructure and sufficient processing capacity to run inference at the speed, scale and reliability required by the business.

 

There is also the human capital cost, as someone still needs to properly deploy the model, configure it, integrate it with the company’s existing systems, optimise its performance, test it, monitor it, patch it, upgrade it and troubleshoot it when something goes wrong. Beyond that, the organisation may also require additional technologies and software components to properly support the Open-Source AI model. These may include embedding models, model gateways, monitoring and observability tools, evaluation systems, backup systems, disaster recovery infrastructure and other supporting technologies required to transform the underlying AI model into an enterprise-ready AI system.

 

This is probably one of the biggest commercial differences between Enterprise AI and Open-Source AI. With Enterprise AI, what the organisation is paying for is often far more than just access to the underlying AI model because the AI provider is typically also providing much of the surrounding technology, infrastructure, maintenance, hosting, support, updates, security management and operational capability required to allow the company to deploy and use the AI solution relatively quickly and efficiently, often simply by paying the agreed subscription, usage or enterprise fee.

 

Open-Source AI, however, works very differently, as the model itself may carry zero licensing fee, but the total cost of ownership may still be substantial. For an organisation operating AI at significant scale, the infrastructure, computing resources, supporting technologies and human capital required to keep the model operating efficiently could potentially run into millions in upfront and ongoing costs.

 

Returning to our car analogy, an Open-Source AI model may therefore be compared to receiving a car for free, in which you may not have to pay anything to acquire the car itself, but that certainly does not mean that driving the car is free, as you will still need to pay for fuel, insurance, maintenance, repairs, parking and all the other operating costs required to keep the car running. And depending on how much you drive, how sophisticated the car is and how much it costs to maintain, there may well be circumstances where simply having a chauffeur turns out to be cheaper.

 

Key Takeaway 4: Open Source AI Can Give the Organisation Much Greater Control Over Its Data

 

The fourth key takeaway is that one of the strongest strategic advantages of Open Source AI is the potential for the organisation to retain substantially greater control over its own data.

 

If an Open Source AI model is properly deployed within an on-premises environment, private cloud, dedicated internal servers or another tightly controlled infrastructure environment, the organisation can potentially design the architecture so that prompts, inputs, outputs and other data processed by the model remain entirely within the organisation’s own technology environment, without being transmitted back to the AI model developer or an external AI service provider. And this can be materially different from a conventional Enterprise AI arrangement.

 

Under many Enterprise AI arrangements, data will necessarily flow through infrastructure operated or controlled by the AI provider, even where the provider gives strong contractual commitments around confidentiality, data segregation, cybersecurity, retention and the non-use of customer data for model training.

 

However, with the considerable public attention currently surrounding AI, cybersecurity, data leakage and the use of customer information by AI technology providers, it is perhaps understandable that some organisations may still feel uncomfortable transmitting particularly sensitive datasets, proprietary information, trade secrets or other highly confidential information to an external AI service provider, notwithstanding the contractual protections that may be in place.

 

This is probably where Open Source AI shines the most. With a properly configured, self-hosted Open Source AI deployment, the organisation may be able to remove that external data flow altogether and retain end-to-end control over where its data is processed, stored, retained and accessed. This can be particularly attractive for organisations handling significant volumes of proprietary information, trade secrets, confidential business information, source code, customer data or other highly sensitive datasets. In that sense, Open Source AI can potentially offer organisations something close to the “best of both worlds” by accessing to increasingly sophisticated AI capabilities, while at the same time preserving a high degree of control over the organisation’s own information.

 

But, as mentioned earlier, there is rarely such a thing as a free buffet, and the trade-off does not come cheaply. To operate an AI model entirely within a controlled environment, the organisation may need to invest significantly in computing infrastructure, specialised GPUs, servers, storage, networking capacity, cybersecurity controls, identity and access management, backup systems, disaster recovery infrastructure and the technical personnel required to manage the environment properly. The larger and more sophisticated the model, and the greater the volume of data and users involved, the more significant those infrastructure and operational costs can become.

 

However, for organisations dealing with particularly sensitive or commercially valuable information, there are circumstances where it is difficult to place a price on maintaining greater control over data security and confidentiality. Hence, if the underlying infrastructure is properly designed, secured and governed, a self-hosted Open Source AI deployment can therefore give an organisation a level of control over its data that may be difficult to replicate under many conventional Enterprise AI arrangements.

 

Key Takeaway 5: Think About the Three Cs – Convenience, Cost and Control

 

The fifth key takeaway is that, by this point, it should be reasonably clear that there is no single right answer as to whether Open Source AI or Enterprise AI is necessarily more suitable for every organisation. The better question is really what the company needs, what it is capable of supporting, and what type of deployment model best fits its operational, technical and risk requirements.

 

 In our view, that decision can be simplified into three broad considerations: convenience, cost and control.

 

On convenience, Enterprise AI will generally have the advantage because the organisation is essentially procuring a ready-made service from an AI provider, with the underlying model, infrastructure, maintenance, updates, security patches and support largely handled by the provider. Open Source AI, on the other hand, requires the organisation to take on considerably more of that responsibility itself, as the company may need to establish the necessary infrastructure, computing capacity, security controls, monitoring environment and technical support simply to deploy and operate the model safely and effectively.

 

On cost, the comparison is more nuanced. Enterprise AI typically involves ongoing and recurring payments to the AI provider, whether through subscriptions, enterprise licensing fees, API charges, token-based pricing or other consumption-based fees. Open Source AI may remove or significantly reduce the conventional model licensing fee, but that does not mean it is necessarily cheaper overall, as the upfront cost of acquiring the necessary infrastructure, computing power, storage, cybersecurity controls and technical expertise to properly run the model can be significant. In other words, Enterprise AI may involve lower setup costs but higher recurring costs, whereas Open Source AI may involve materially higher upfront and ownership costs but potentially lower recurring model-access costs over time.

 

The third consideration is control, and this is where Open Source AI can be particularly compelling. Under Enterprise AI, the organisation’s control is generally exercised through the contractual framework with the provider, including agreed terms around data use, retention, storage, security, access, and data flows. With Open Source AI, particularly where the model is self-hosted within the organisation’s own controlled environment, the company can exercise far greater direct control over the model, infrastructure, data flows, storage, access and deployment architecture itself.

 

Ultimately, there is no right or wrong answer between the two. Each model comes with its own advantages, trade-offs and risks. Returning to the transportation analogy, having a chauffeur and owning your own car can both get you to the same destination, but the experience, responsibilities, costs and level of control will be very different. The key is therefore not to ask which model is universally better, but to understand clearly what the organisation is trying to achieve, what risks it is prepared to assume, and which combination of convenience, cost and control best suits the company.

 

Closing Thoughts

 

AI is clearly the way forward, and as organisations continue to explore how AI can be deployed more deeply across their businesses, the question will increasingly move beyond whether companies should adopt AI, and instead towards how AI should be deployed in a manner that is commercially sensible, technically sustainable and legally well governed. 

 

For general counsels and in-house legal teams, this also means that understanding AI can no longer be confined simply to reviewing an AI contract or negotiating liability clauses. The better the legal team understands these underlying considerations, the better positioned it will be to advise the board, senior management and other stakeholders on how the organisation can adopt AI confidently and responsibly, while still capturing the very significant opportunities that AI will undoubtedly continue to create.

If you have any questions on AI deployment, AI-related contractual documentation, AI governance, vendor and third-party AI arrangements, data protection, cybersecurity or the broader legal and regulatory considerations surrounding enterprise AI adoption, please feel free to reach out to the partners in our Technology Practice Group, Ong Johnson and Lo Khai Yi, for a consultation. We have extensive experience advising on technology law, AI, data protection, cybersecurity, digital platforms and complex technology arrangements, and would be pleased to assist businesses, boards and in-house teams in structuring and negotiating the appropriate contractual, legal and risk-allocation framework for the responsible deployment and integration of AI within their organisations.

 

The Technology Practice Group of Halim Hong & Quek continues to be recognised by leading legal directories and industry benchmarks. Recent accolades include FinTech Law Firm of the Year at the ALB Malaysia Law Awards (2024, 2025 and 2026), Law Firm of the Year for Technology, Media and Telecommunications by the In-House Community, FinTech Law Firm of the Year by the Asia Business Law Journal, a Band 2 ranking for FinTech by Chambers and Partners, and a Tier 3 ranking by Legal 500. The strength of the practice is further reflected in the individual recognition of its partners, including a Band 1 ranking for FinTech by Chambers and Partners within the Technology Practice Group.


About the authors

Ong Johnson
Partner
Head of Technology Practice Group

Fintech, Data Protection,
Technology, Media & Telecommunications (“TMT”),
IP and Competition Law
johnson.ong@hhq.com.my

Lo Khai Yi
Partner
Co-Head of Technology Practice Group
Technology, Media & Telecommunications (“TMT”), Technology
Acquisition and Outsourcing, Telecommunication Licensing and
Acquisition, Cybersecurity
ky.lo@hhq.com.my.


More of our Tech articles that you should read:

Our Services

© 2026 Halim Hong & Quek