Can you own it?
This page is a projection of the one entry record, the Use & modify and Transparency factors that Assess covers. The full verdict is set by all four factors together, floor-weighted so the weakest caps the whole.
- AssessUse & modify + Transparency
- ImplementData control + Doesn't fail you
- UseDoesn't fail you
- SupportTransparency
Intended & out-of-scope use
Qwen3 is Alibaba's general-purpose open-weight family with a standout strength in coding and agentic workloads (Qwen3-Coder-480B-A35B is among the strongest open coding models). Its intended use spans assistant, coding and tool-using applications across an unusually wide size ladder - from 0.5B laptop models to a 480B coder.
Two things push parts of the family out of scope. First, deploy behind your own guardrails: built-in alignment is lighter than Western frontier labs. Second, the systemic-risk large variants (235B, 480B-Coder) carry an unclosed EU AI Act Article 55 gap, so treat them as out of scope for EU high-stakes use unless you close that gap yourself.
Known limitations, bias & failure modes
- China-aligned topic censorship. The models decline or steer on subjects sensitive under Chinese content rules - a behavioural quirk to account for in any knowledge/retrieval use.
- Lighter safety tuning. Instruct alignment withstands casual jailbreaks but is lighter than Western frontier labs, and there is no companion guard/classifier model.
- Concentrated capability leadership. The family leads on coding/agentic tasks rather than uniformly across all domains.
Openness tier & components
Qwen is open_weights: Apache-2.0 weights and a good model card, but training data and training code are closed and evaluation is only partially reproducible. That is solidly open-weight, not open-science - you can run and adapt the model, but you cannot reproduce its training.
License terms & permitted use
The mainstream Qwen3 sizes are OSI-approved Apache-2.0 with unconditional commercial use
- a genuine advantage over the restrictive community licenses some peers use. The important caveat: verify the LICENSE file per checkpoint. Some large or historical variants used the Tongyi Qianwen community license rather than Apache-2.0, so licensing is not uniform across the whole family.
Supply-chain & provenance
Qwen is distributed from the verified Qwen org on Hugging Face and, officially, dual-published on Alibaba's ModelScope hub. Checkpoints are safetensors with checksums, and there is no canonical-org malicious incident. The dual-hub distribution is a supply-chain surface in itself: verify checksums match across Hugging Face and ModelScope, and note there is no cryptographic signing or provenance attestation.
EU AI Act posture
Qwen is a GPAI model. The mainstream Apache-2.0 sizes plausibly qualify for the open-source exemption, but the 235B MoE and Qwen3-Coder-480B likely exceed the 1e25 FLOPs systemic-risk threshold - and for systemic-risk models the exemption is void and the full Article 55 package is owed. That documentation is not published, and a China-based provider is unlikely to furnish an EU AI Office package, so an EU deployer of the large variants inherits a real compliance gap it cannot close from upstream artifacts.
Benchmarks & evaluation
Aggregated from third-party evaluation, Qwen3 shows strong general capability and class-leading open coding (Qwen3-Coder). These results are third-party, not OneHill-reproduced, and because the evaluation harness is only partially open, treat the numbers as indicative rather than independently verified.
How this scores
The ownership factors this domain covers, drawn from the one entry record.
Use and modify freelyCan you run, modify and adapt it with no gate and no field-of-use trap?
StrongThe licence is per-checkpoint, not one grant across the family: mainstream Qwen3 (0.6B, 32B, 235B-A22B, Coder-480B-A35B-Instruct) is Apache-2.0 with unconditional commercial use and no MAU clause, but the legacy/large Tongyi Qianwen checkpoints (Qwen-72B, Qwen2.5-72B-Instruct) carry a >100M-monthly-active-user licence trigger, a 'Built with Qwen' attribution requirement and export controls - check the LICENSE file on the exact checkpoint before you rely on Apache terms.
TransparencyDo you know what it is: weights, training, behaviour, and legible terms?
WeakYou hold the weights but cannot inspect what is in them - training data and code are closed and China-aligned topic censorship is baked into behaviour, so sensitive-topic coverage is distorted in ways you cannot audit. On the hosted path, Alibaba's Model Studio FAQ now grounds a no-training commitment ('never uses your data for model training'), though the formal Model Studio Service Agreement - exact retention, region and opt-out - is still unread.
Sources
The same evidence records as the entry sheet. Read means the text was verified; unverified means it is known to exist but not yet read.