All entriesContact
Model

Meta Llama

Publisher
Meta Platforms, Inc. (US)
Family
Llama 3.x / Llama 4
Openness
gated_open
Licence
Llama Community License
Context
128K / very long (multi-hundred-K+)

Meta's Llama family is the most widely adopted open-weight LLM lineage, spanning dense Llama 3.1 (8B/70B/405B, 128K context) and Llama 3.3 70B through the Llama 4 mixture-of-experts models (Scout, Maverick, Behemoth), shipped alongside the companion Llama Guard and Prompt Guard safety classifiers.

Do you really own it?
Partial
none·limited·partial·substantial·full
Analytical input: AOI B · 72.4/100

Floor-weighted, not averaged. The weakest factor caps the level. Nothing here is weak, but use & modify only reaches moderate - so the substantial bar, strong on both use-and-modify and data-control, is not met, and the level is partial.

You own the self-hosted Llama weights in practice: they run on your infrastructure, perform at the top of the open field, and pair with Meta's Llama Guard and Prompt Guard. But overall ownership is partial, not substantial - the Community License is not a clean grant: an access gate, 'Built with Llama' attribution, a 700M-MAU commercial trigger, and no multimodal licence for EU-domiciled entities mean you cannot freely use and modify the whole family the way an OSI licence allows, and training is closed. Clear those conditions first: check the MAU trigger, honour the attribution terms, and if you are EU-domiciled avoid the multimodal variants entirely.

1

Use and modify freelyCan you run, modify and adapt it with no gate and no field-of-use trap?

Moderate

Open weights, but on Meta's terms - an access gate, the Community License's 'Built with Llama' naming and the verbatim 700M-MAU commercial-licence trigger, and no licence for multimodal Llama 4 to EU-domiciled entities (a restriction the AUP carries for 3.2/3.3 too, but not 3.1) - real conditions, not a clean grant.

How this scores (AOI sub-dimensions)
Openness3/5how much is released - weights, data, code, licence - and how freelyGated-open tier: weights are downloadable and documentation is strong, but they sit behind a click-through gate and a restrictive community license, with training data and training code closed and evaluation only partial.
Legal2/5how permissive and clean the licence is for real commercial useA restrictive, non-OSI community license with an MAU threshold, acceptable-use limits and an outright EU multimodal field-of-use ban; the largest models are systemic-risk (voiding any open-source exemption) with only a partial Article 55 package; and Meta declined the EU GPAI Code of Practice.
2

TransparencyDo you know what it is: weights, training, behaviour, and legible terms?

Moderate

You can inspect and self-guard the weights, and Meta publishes safety evaluations plus Llama Guard and Prompt Guard, but training data and code are closed and no broad independent red-team spans every harm domain - you see the model, not how it was made.

How this scores (AOI sub-dimensions)
Provenance4/5how well we can trace and verify what went into the modelVerified Meta org on Hugging Face, safetensors-only distribution, published checksums, clear canonical source, and no malicious-checkpoint incident on the canonical org (checklist ~6/8).
Governance4/5how accountable and well-documented the publisher isReputable, legally accountable publisher with a predictable multi-generation release cadence, a Responsible Use Guide and a reporting path.
3

Doesn't fail youIs it reliable and good enough for the job?

Strong

Leading open-weight instruction-following with 128K context and documented tool-calling, backed by the largest fine-tuning and serving ecosystem of any open family.

How this scores (AOI sub-dimensions)
Performance4/5how capable it is relative to its classConsistently strong and competitive across reasoning, coding and instruction-following on public leaderboards, judged a leader among open-weight generalists.
Operational5/5how practical it is to run, serve and maintain in productionFirst-class ecosystem support: day-0 availability across vLLM, llama.cpp, Ollama, TGI and MLX, official and community quantizations, long-context and tooling support, and hosted endpoints on every major cloud (Bedrock, Azure, Vertex, Together, Groq).
Safety4/5whether misuse risks are evaluated and guardrails are providedSafety-tuned instruct releases with published safety evaluations, a companion guard/classifier model (Llama Guard) and Prompt Guard, and documented residual risks - well above the score-3 anchor.
4

Doesn't extract your dataDoes running it keep your knowledge and data yours?

Strong

Self-hosted, the weights run on your own infrastructure - the Community License adds naming and scale conditions but no telemetry or data clawback, so your data stays yours.

How this scores
Not a scored AOI dimension. For a self-hosted model, data-control is a structural property of running the weights yourself, strong by default unless the model phones home or the licence claws back rights. For a hosted API this factor is the retention + train-on-inputs + residency read, scored from the binding terms.

How the AOI score is computed

The seven dimensions above, each scored 0 to 5, weighted and summed to the 0 to 100 headline. The score is the analytical input behind the ownership verdict, not the verdict itself.

DimensionScoreWeightPoints
Openness3/50.1810.8
Provenance4/50.1612.8
Legal2/50.166.4
Safety4/50.1612.8
Performance4/50.1411.2
Operational5/50.1212.0
Governance4/50.086.4
HeadlineB · 72.4/100
Dossier coverageAssess 97%Implement 100%Use 89%Support 78%How complete our four-domain documentation is, a measure of our coverage, not of the model. Each domain links to its page.

Sources

Every rating traces to a primary document. Read means the text was verified; unverified means it is known to exist but has not yet been read.

DocumentWhat it grounds
Licenceread2026-07-25
Llama 4 Community License, read verbatim: the "Additional Commercial Terms" 700M-MAU threshold ("greater than 700 million monthly active users in the preceding calendar month, you must request a license from Meta"), the "Built with Llama" attribution clause, California governing law, and - in the incorporated AUP - the EU multimodal restriction denying the licence to individuals domiciled in, or companies with a principal place of business in, the European Union.
Terms of serviceread2026-07-25
Llama 4 Acceptable Use Policy, read verbatim: six prohibited-use categories (illegality/rights infringement; death or bodily harm incl.
Third-party analysisread2026-07-25
Llama family variants, EU multimodal licensing restriction, ecosystem/cloud availability, and Meta declining the EU GPAI Code of Practice.
Model cardread2026-07-25
Canonical, verified and gated meta-llama organisation on Hugging Face distributing safetensors with checksums; per-version licence tags (llama4, llama3.3, llama3.2, llama3.1).
Third-party analysisread2026-07-25
Llama is competitive-to-leading among open-weight generalist families on public leaderboards.
Documentationunverified2026-07-25
Meta ships safety-tuned instruct variants plus Llama Guard and Prompt Guard companion classifiers with published safety evaluations and a responsible-use reporting path.
Model cardread2026-07-25
Llama 3.1 Instruct model card on Hugging Face: 128K context window, the Llama 3 chat template and special tokens, the eight officially supported languages, and documented tool-calling.