Contact
Assess · Qwen

Can you own it?

Ownership levelPartialnone·limited·partial·substantial·fullAnalytical input C ยท 67.6/100

This page is a projection of the one entry record, the Use & modify and Transparency factors that Assess covers. The full verdict is set by all four factors together, floor-weighted so the weakest caps the whole.

Which domain expands which factor
  • AssessUse & modify + Transparency
  • ImplementData control + Doesn't fail you
  • UseDoesn't fail you
  • SupportTransparency

Intended & out-of-scope use

Qwen3 is Alibaba's general-purpose open-weight family with a standout strength in coding and agentic workloads (Qwen3-Coder-480B-A35B is among the strongest open coding models). Its intended use spans assistant, coding and tool-using applications across an unusually wide size ladder - from 0.5B laptop models to a 480B coder.

Two things push parts of the family out of scope. First, deploy behind your own guardrails: built-in alignment is lighter than Western frontier labs. Second, the systemic-risk large variants (235B, 480B-Coder) carry an unclosed EU AI Act Article 55 gap, so treat them as out of scope for EU high-stakes use unless you close that gap yourself.

Known limitations, bias & failure modes

  • China-aligned topic censorship. The models decline or steer on subjects sensitive under Chinese content rules - a behavioural quirk to account for in any knowledge/retrieval use.
  • Lighter safety tuning. Instruct alignment withstands casual jailbreaks but is lighter than Western frontier labs, and there is no companion guard/classifier model.
  • Concentrated capability leadership. The family leads on coding/agentic tasks rather than uniformly across all domains.

Openness tier & components

Qwen is open_weights: Apache-2.0 weights and a good model card, but training data and training code are closed and evaluation is only partially reproducible. That is solidly open-weight, not open-science - you can run and adapt the model, but you cannot reproduce its training.

License terms & permitted use

The mainstream Qwen3 sizes are OSI-approved Apache-2.0 with unconditional commercial use

  • a genuine advantage over the restrictive community licenses some peers use. The important caveat: verify the LICENSE file per checkpoint. Some large or historical variants used the Tongyi Qianwen community license rather than Apache-2.0, so licensing is not uniform across the whole family.

Supply-chain & provenance

Qwen is distributed from the verified Qwen org on Hugging Face and, officially, dual-published on Alibaba's ModelScope hub. Checkpoints are safetensors with checksums, and there is no canonical-org malicious incident. The dual-hub distribution is a supply-chain surface in itself: verify checksums match across Hugging Face and ModelScope, and note there is no cryptographic signing or provenance attestation.

EU AI Act posture

Qwen is a GPAI model. The mainstream Apache-2.0 sizes plausibly qualify for the open-source exemption, but the 235B MoE and Qwen3-Coder-480B likely exceed the 1e25 FLOPs systemic-risk threshold - and for systemic-risk models the exemption is void and the full Article 55 package is owed. That documentation is not published, and a China-based provider is unlikely to furnish an EU AI Office package, so an EU deployer of the large variants inherits a real compliance gap it cannot close from upstream artifacts.

Benchmarks & evaluation

Aggregated from third-party evaluation, Qwen3 shows strong general capability and class-leading open coding (Qwen3-Coder). These results are third-party, not OneHill-reproduced, and because the evaluation harness is only partially open, treat the numbers as indicative rather than independently verified.

How this scores

The ownership factors this domain covers, drawn from the one entry record.

1

Use and modify freelyCan you run, modify and adapt it with no gate and no field-of-use trap?

Strong

The licence is per-checkpoint, not one grant across the family: mainstream Qwen3 (0.6B, 32B, 235B-A22B, Coder-480B-A35B-Instruct) is Apache-2.0 with unconditional commercial use and no MAU clause, but the legacy/large Tongyi Qianwen checkpoints (Qwen-72B, Qwen2.5-72B-Instruct) carry a >100M-monthly-active-user licence trigger, a 'Built with Qwen' attribution requirement and export controls - check the LICENSE file on the exact checkpoint before you rely on Apache terms.

How this scores (AOI sub-dimensions)
Openness3/5how much is released - weights, data, code, licence - and how freelyOpen-weights tier: weights are downloadable under Apache-2.0 with a good model card, but training data and training code are undisclosed and evaluation is only partially reproducible.
Legal3/5how permissive and clean the licence is for real commercial useThe permissive Apache-2.0 license on the mainstream sizes is a real plus and better than a restricted community license.
2

TransparencyDo you know what it is: weights, training, behaviour, and legible terms?

Weak

You hold the weights but cannot inspect what is in them - training data and code are closed and China-aligned topic censorship is baked into behaviour, so sensitive-topic coverage is distorted in ways you cannot audit. On the hosted path, Alibaba's Model Studio FAQ now grounds a no-training commitment ('never uses your data for model training'), though the formal Model Studio Service Agreement - exact retention, region and opt-out - is still unread.

How this scores (AOI sub-dimensions)
Provenance3/5how well we can trace and verify what went into the modelVerified Qwen org on Hugging Face plus official ModelScope publication, safetensors with checksums, and no canonical-org malicious incident (checklist 5/8).
Governance3/5how accountable and well-documented the publisher isActive, accountable publisher (Alibaba Qwen team) with a rapid release cadence and a verified presence on two hubs, but no documented vulnerability-disclosure or deprecation policy and no Code of Practice signature.
What this means for adoptionYou partly own Qwen: the Apache-licensed mainstream Qwen3 sizes are yours to run, modify and self-host, they perform strongly (especially coding), and self-hosted your data stays on your infrastructure. Two things cap it at partial. First the licence is per-checkpoint - Apache-2.0 on mainstream Qwen3, but the legacy/large Tongyi Qianwen checkpoints (Qwen-72B, Qwen2.5-72B-Instruct) carry a >100M-MAU trigger and 'Built with Qwen' attribution - so verify the LICENSE on the exact checkpoint. Second, transparency: China-aligned censorship is baked in and training is closed; the hosted path now carries a grounded no-training commitment (Model Studio FAQ) alongside the Singapore-storage/SCC-DPF/retention privacy policy, with only the formal Model Studio Service Agreement specifics (exact retention, region, opt-out) still unread. Adopt with hard limits: keep politically sensitive and regulated workloads off it, confirm the per-checkpoint licence, and if you place a systemic-risk-scale variant on the EU market, close the Article 55 gap yourself.

Sources

The same evidence records as the entry sheet. Read means the text was verified; unverified means it is known to exist but not yet read.

Model cardread2026-07-25
Qwen3 checkpoints are hosted on the verified Qwen org on Hugging Face in safetensors with checksums.
Licenceread2026-07-25
Mainstream Qwen3 checkpoints are released under Apache-2.0 with unconditional commercial use and NO monthly-active-user clause - metadata verified across four checkpoints (Qwen3-0.6B, Qwen3-32B, Qwen3-235B-A22B, Qwen3-Coder-480B-A35B-Instruct), each displaying "License: apache-2.0".
Licenceread2026-07-25
Legacy/large Tongyi Qianwen checkpoints (Qwen-72B, Qwen2.5-72B-Instruct) are NOT Apache-2.0 - the Tongyi Qianwen community licence, read verbatim: Sec 4 "If you are commercially using the Materials, and your product or service has more than 100 million monthly active users, you shall request a license from us"; Sec 5.b "Built with Qwen"/"Improved using Qwen" attribution; Sec 5.a export controls (China/US/other).
Technical_reportread2026-07-25
Qwen3 Technical Report (arXiv 2505.09388): documents the Qwen3 family, thinking/non-thinking modes, thinking budget, and multilingual coverage (~119 languages).
Privacy Policyread2026-07-25
General Alibaba Cloud International Website Privacy Policy, read: retention tied to "ongoing legitimate business need" (Sec F); cross-border transfers under SCCs (GDPR Art.
Documentationread2026-07-25
Alibaba Cloud Model Studio FAQ, read verbatim: "Alibaba Cloud strictly protects data privacy and never uses your data for model training." Model Studio "will store data generated from model and application calls"; data is "encrypted with AES-256" in transit.
Terms of serviceunverified2026-07-25
The formal Model Studio / DashScope Service Agreement - its exact retention period, storage region and training opt-out mechanics - was not directly reachable and remains unread.
Model cardunverified2026-07-25
Qwen is also officially published on Alibaba's ModelScope hub (dual distribution).
Third-party analysisunverified2026-07-25
No public EU AI Act training-content summary, copyright policy, or Article 55 documentation for the systemic-risk large variants.
Third-party analysisunverified2026-07-25
Qwen instruct variants are safety-tuned but with lighter alignment coverage than Western frontier labs.
Third-party analysisunverified2026-07-25
Qwen models exhibit topic censorship aligned with Chinese content rules.
Third-party analysisunverified2026-07-25
Qwen3-Coder is among the strongest open coding models on independent evaluation.
Third-party analysisunverified2026-07-25
Qwen is broadly supported across serving stacks (vLLM, llama.cpp, Ollama, TGI, MLX) with many community quants.