Alpha
All entriesContact
Model

Qwen

Publisher
Alibaba (Qwen team) (China)
Family
Qwen3 family
Openness
open_weights
Licence
Apache License 2.0 (mainstream Qwen3 sizes; verify per checkpoint)
Context
up to 128k (per checkpoint) / long-context (per checkpoint)

You partly own Qwen: the Apache-licensed mainstream Qwen3 sizes are yours to run, modify and self-host, they perform strongly (especially coding), and self-hosted your data stays on your infrastructure. Two things cap it at partial. First the licence is per-checkpoint - Apache-2.0 on mainstream Qwen3, but the legacy/large Tongyi Qianwen checkpoints (Qwen-72B, Qwen2.5-72B-Instruct) carry a >100M-MAU trigger and 'Built with Qwen' attribution - so verify the LICENSE on the exact checkpoint. Second, transparency: China-aligned censorship is baked in and training is closed; the hosted path carries a grounded no-training commitment (Model Studio FAQ) alongside the Singapore-storage/SCC-DPF/retention privacy policy, and the formal Model Studio Service Agreement holds the binding specifics (exact retention, region, opt-out). Adopt with hard limits: keep politically sensitive and regulated workloads off it, confirm the per-checkpoint licence, and if you place a systemic-risk-scale variant on the EU market, close the Article 55 gap yourself.

Do you really own it?
Partial
none·limited·partial·substantial·full
Analytical input: AOI C · 67.6/100
The four ownership factors

Floor-weighted, not averaged. Transparency is weak, and the weakest factor sets the ceiling, so the verdict stays partial however strong the rest.

1

Use and modify freelyCan you run, modify and adapt it with no gate and no field-of-use trap?

Strong

The licence is per-checkpoint rather than a single grant across the family: mainstream Qwen3 (0.6B, 32B, 235B-A22B, Coder-480B-A35B-Instruct) is Apache-2.0 with unconditional commercial use and no MAU clause, but the legacy/large Tongyi Qianwen checkpoints (Qwen-72B, Qwen2.5-72B-Instruct) carry a >100M-monthly-active-user licence trigger, a 'Built with Qwen' attribution requirement and export controls - check the LICENSE file on the exact checkpoint before you rely on Apache terms.

How this scores (AOI sub-dimensions)
Openness3/5how much is released - weights, data, code, licence - and how freelyOpen-weights tier: weights are downloadable under Apache-2.0 with a good model card, but training data and training code are undisclosed and evaluation is only partially reproducible.
Legal3/5how permissive and clean the licence is for real commercial useThe permissive Apache-2.0 license on the mainstream sizes is a real plus and better than a restricted community license.
2

TransparencyDo you know what it is: weights, training, behaviour, and legible terms?

Weak

You hold the weights but cannot inspect what is in them: training data and code are closed and China-aligned topic censorship is baked into behaviour, so sensitive-topic coverage is distorted in ways you cannot audit. On the hosted path, Alibaba's Model Studio FAQ grounds a no-training commitment ('never uses your data for model training'), while the binding specifics (exact retention, region and opt-out) sit in the formal Model Studio Service Agreement.

How this scores (AOI sub-dimensions)
Provenance3/5how well we can trace and verify what went into the modelVerified Qwen org on Hugging Face plus official ModelScope publication, safetensors with checksums, and no canonical-org malicious incident (checklist 5/8).
Governance3/5how accountable and well-documented the publisher isActive, accountable publisher (Alibaba Qwen team) with a rapid release cadence and a verified presence on two hubs, but no documented vulnerability-disclosure or deprecation policy and no Code of Practice signature.
3

ReliabilityIs it reliable and good enough for the job?

Moderate

Runs dependably with 128K context and documented thinking modes, but safety tuning is lighter than Western frontier labs, with no companion guard model, so you supply that layer.

How this scores (AOI sub-dimensions)
Operational5/5how practical it is to run, serve and maintain in productionFirst-class ecosystem support: dual distribution on Hugging Face and ModelScope, broad serving support (vLLM, llama.cpp, Ollama, TGI, MLX), a very wide size range from laptop to datacentre, and abundant community quantizations.
Safety3/5whether misuse risks are evaluated and guardrails are providedInstruct variants are safety-tuned and withstand casual jailbreaks, but tuning is lighter than Western frontier labs, there is no companion guard model, and the models exhibit China-aligned topic censorship - a behavioural quirk to account for.
4

Doesn't extract your dataDoes running it keep your knowledge and data yours?

Strong

Self-hosted, the Apache-licensed weights run on your own infrastructure with no clawback or telemetry, so your data stays yours. On Alibaba's hosted Qwen, the Model Studio FAQ grounds a no-training commitment ('never uses your data for model training'; call data stored, encrypted with AES-256 in transit), and the general privacy policy documents Singapore storage, SCC/DPF cross-border transfers and 'ongoing legitimate business need' retention; the binding specifics (exact retention, region, opt-out) sit in the formal Model Studio Service Agreement.

How this scores
Not a scored AOI dimension. For a self-hosted model, data-control is a structural property of running the weights yourself, strong by default unless the model phones home or the licence claws back rights. For a hosted API this factor is the retention + train-on-inputs + residency read, scored from the binding terms.

How the AOI score is computed

The seven dimensions above, each scored 0 to 5, weighted and summed to the 0 to 100 headline. The score is the analytical input behind the ownership verdict, not the verdict itself.

DimensionScoreWeightPoints
Openness3/50.1810.8
Provenance3/50.169.6
Legal3/50.169.6
Safety3/50.169.6
Performance4/50.1411.2
Operational5/50.1212.0
Governance3/50.084.8
HeadlineC · 67.6/100

Grade ceiling: a hard flag (🚩 EU AI Act systemic-risk variants (Qwen3-235B, Qwen3-Coder-480B) likely exceed 1e25 FLOPs with no Article 55 documentation) caps the grade below the raw band. See the classification matrices.

Dossier coverageAssess 87%Implement 91%Use 67%Support 50%How complete our four-domain documentation is, a measure of our coverage, not of the model. Each domain links to its page.

Sources

Every rating traces to a primary document. Read means the text was verified; unverified means it is known to exist but has not yet been read.

DocumentWhat it grounds
Model cardread2026-07-25
Qwen3 checkpoints are hosted on the verified Qwen org on Hugging Face in safetensors with checksums.
Licenceread2026-07-25
Mainstream Qwen3 checkpoints are released under Apache-2.0 with unconditional commercial use and NO monthly-active-user clause - metadata verified across four checkpoints (Qwen3-0.6B, Qwen3-32B, Qwen3-235B-A22B, Qwen3-Coder-480B-A35B-Instruct), each displaying "License: apache-2.0".
Licenceread2026-07-25
Legacy/large Tongyi Qianwen checkpoints (Qwen-72B, Qwen2.5-72B-Instruct) are NOT Apache-2.0 - the Tongyi Qianwen community licence, read verbatim: Sec 4 "If you are commercially using the Materials, and your product or service has more than 100 million monthly active users, you shall request a license from us"; Sec 5.b "Built with Qwen"/"Improved using Qwen" attribution; Sec 5.a export controls (China/US/other).
Technical_reportread2026-07-25
Qwen3 Technical Report (arXiv 2505.09388): documents the Qwen3 family, thinking/non-thinking modes, thinking budget, and multilingual coverage (~119 languages).
Privacy Policyread2026-07-25
General Alibaba Cloud International Website Privacy Policy, read: retention tied to "ongoing legitimate business need" (Sec F); cross-border transfers under SCCs (GDPR Art.
Documentationread2026-07-25
Alibaba Cloud Model Studio FAQ, read verbatim: "Alibaba Cloud strictly protects data privacy and never uses your data for model training." Model Studio "will store data generated from model and application calls"; data is "encrypted with AES-256" in transit.
Terms of serviceunverified2026-07-25
The formal Model Studio / DashScope Service Agreement - its exact retention period, storage region and training opt-out mechanics - was not directly reachable and remains unread.
Model cardunverified2026-07-25
Qwen is also officially published on Alibaba's ModelScope hub (dual distribution).
Third-party analysisunverified2026-07-25
No public EU AI Act training-content summary, copyright policy, or Article 55 documentation for the systemic-risk large variants.
Third-party analysisunverified2026-07-25
Qwen instruct variants are safety-tuned but with lighter alignment coverage than Western frontier labs.
Third-party analysisunverified2026-07-25
Qwen models exhibit topic censorship aligned with Chinese content rules.
Third-party analysisunverified2026-07-25
Qwen3-Coder is among the strongest open coding models on independent evaluation.
Third-party analysisunverified2026-07-25
Qwen is broadly supported across serving stacks (vLLM, llama.cpp, Ollama, TGI, MLX) with many community quants.