Who Owns AI Model Weights? What the Law Has Not Yet Decided
Training data, model weights and outputs are different objects. Rules, licences and litigation concern each one, but no court has set a general ownership rule for model weights.
This is educational information, not legal advice. “Who owns model weights?” sounds like it needs one owner. First it needs three objects separated: training data, the resulting numerical values called weights, and outputs generated when the model is used. Each raises a different legal debate. The most important answer is uncomfortable but precise: courts have not generally decided whether model weights are a copyrighted work, a database, a trade secret, or none of those things.
Training data
Data are the text, images, code, audio and other materials used in training. Depending on the material and country, they can raise copyright, database, contract, privacy or other questions. A work entering training does not prove it sits inside a weights file as a readable library; nor does that remove questions about copying during training.
In the United States, the June 25, 2025 order in Kadrey v. Meta resolved fair-use issues on the record before that court and granted Meta summary judgment. It did not decide who owns all model weights, is not a rule for every lawsuit, and is not EU law. Its procedural scope matters more than a quick headline.
In the European Union, Directive 2019/790 contains text-and-data-mining exceptions: Article 3 concerns specified research uses and Article 4 other uses under conditions, including rights reservations. It is an EU framework for reproductions and extractions; it does not itself answer ownership of weights or replace national application.
Resulting weights
Weights are numerical parameters adjusted through training. They are not the input dataset or a particular answer. This is where confident claims outrun settled law. A company may treat unpublished weights as valuable confidential information. EU Directive 2016/943 protects secret information with commercial value when reasonable steps have been taken to keep it secret. That may matter for a closed model, but depends on facts and applicable law; it does not automatically make every weight a trade secret.
Contract is another route. A licence can grant permission to download, use or redistribute published weights. The Llama 3.3 licence illustrates that mechanism. A licence organises permissions between parties; it does not by itself decide every claim by training-data authors or create a general court ruling on copyright in weights.
Open weights therefore do not mean ownerless weights or rule-free weights. They can mean a rightsholder or licensor permits defined uses on conditions. Closed weights do not prove a specific copyright in every number either: secrecy, contract, security or business strategy may explain the choice.
Outputs
An output is text, image, code or audio generated in use. Its debate is not identical to training or weights. The U.S. Copyright Office, addressing output copyrightability, says protection depends on sufficient human authorship. That U.S. administrative position does not decide ownership of weights and is not an EU rule.
An output can also raise questions about similarity to a work, platform contracts or personal data. None is answered by saying “AI made it” or “the model is open.” Identify the output, alleged source, jurisdiction and invoked right.
“Ownership” can name different powers
The word owner compresses several powers that should be unpacked. An entity may control the server holding the weights, keep them secret, grant API access, license a copy, or restrict certain uses by contract. Those practical positions do not by themselves prove that the weights are a copyright work. Nor does the absence of a general copyright answer prevent contract, trade secret, competition, data protection, or regulatory duties from applying.
A useful legal answer therefore begins with a verb. Who may access, copy, modify, redistribute, revoke, or bring a claim? Then ask where that power comes from: legislation, a licence, a judgment, physical control, or a contractual clause. Saying only that a model “belongs to the company” erases distinctions that may decide the dispute.
What the EU AI Act contributes
The EU AI Act, Regulation 2024/1689, illustrates the separation without deciding civil ownership of model weights. Recital 102 associates a free and open-source licence with rights to access, use, modify, and redistribute software and data; recital 104 expressly refers to parameters, including weights, being made publicly available. Yet it also warns that releasing those parameters does not necessarily disclose substantial information about the training data or how copyright compliance was secured.
The Act places duties on providers of general-purpose AI models and provides selected exceptions for models released under free and open-source licences. That is regulation of conduct and transparency, not a universal allocation of ownership. A statute’s mention of weights does not mean it has declared who owns copyright in them. Its recognition of an open licence also does not decide whether every term is enforceable in every jurisdiction against every third party.
A licence answers only the question it asks
When reading a model licence, first identify the licensed material: code, documentation, weights, outputs, or some combination. Then check who may use it, whether modification and redistribution are permitted, which notices must remain, and which special conditions activate. The text can grant meaningful permissions even while the ultimate basis of every asserted right remains disputed; contracts and licences organise particular relationships without waiting for a court to settle every category.
The announcement must also be separated from the files. Calling a model “open” on a product page does not replace reading its licence or establish that training code, data, weights, and method are all available. The transferable capability is to treat “open” as a claim that can be decomposed: which object is supplied, under what permission, with which restrictions, and with what opportunity for verification.
An example shows why searching for one owner is insufficient. A person who obtains weights published under a licence may have permission to run them while remaining obliged to preserve notices or restrict selected uses. If that person receives the same numerical file through a leak, the numbers do not change, but the access route, contractual duties, and possible trade-secret claim may do so. The legal question does not live inside the numbers; it depends on how they arrived, which right is asserted, and which facts can be proved.
A checklist for the next claim
Ask: is the dispute about data, weights or an output? In which country and court? Is the source a complaint, judgment, licence or commentary? What is the date and scope of the decision? If it concerns weights, is copyright, trade secret, contract or another doctrine alleged?
Do not end with a winner prediction. Watch documents that can change the map: judgments reasoning about the specific object, appeals, applicable legislation and licences defining permissions. Until then, “not decided” is not evasive. It is the accurate description of the field.
This article was produced with artificial intelligence under human editorial oversight.