XiaomiMiMo /MiMo-V2.6-Distill-Qwen-9B
Verdict
Held- There is not enough licence evidence to prove the licence, so it is not admitted.
- An obligation of the base model's licence is not satisfied.
What would change it: evidence from the licensor, or a human ruling. A hold is not a failure.
A verdict covers licence, provenance and files. Quality and fit on your own tasks are measured by Compare.
What was checked
-
Licence Not concluded
MIT is declared only as a repository tag (T3), which is not a grant.
-
Provenance Not verified
The licensor's own repository, derived from Qwen/Qwen3.5-9B.
-
Files Not verified
Safetensors. The weights digest was not verified, so they are not claimed as byte-checked.
-
Export screening Not yet assessed
No export claim is made.
Verify this verdict
Download attestation.json and check it against the published key:
python scripts/verify-verdict.py
Full record
- Revision
2367e865d009c13a c81713a2 878291d3 3ab28177 - Date assessed
- 2026-09-25 BACKFILL
- Upstream released
- 2026-09-22T03:52:45Z, the commit date of the assessed revision, recorded 2026-09-25. A reconstruction: this verdict was assessed before upstream release tracking began, so it is excluded from the median.
- Release to verdict
- Verdict latency: 68 hours from the upstream release to 00:00 UTC on the assessment date. The record is dated, not timed, so the true figure may be up to 24 hours higher.
- Provenance label
- the weights digest was not verified for this verdict, so the weights are not claimed as byte-checked
- Licence, declared and concluded
- Declared: MIT (as a repository-metadata-tag). Concluded: NoAssertion: no grant text exists to conclude from, so no licence is concluded for these weights.
- Evidence tier
- T3: a repository metadata tag only. Not a grant: the identifier is the publisher's assertion with no text behind it, so the record is held whatever the identifier says.
- Deviation from canonical text
- Not assessable: the repository ships no licence file, so there is nothing to compare against the pinned canonical text.
- Added-clause screen
- Run over the declared sibling policy files; none were declared for this model.
- Provenance chain
- Source: huggingface.co/XiaomiMiMo/MiMo-V2.6-Distill-Qwen-9B. Official licensor repository: yes. Derived from Qwen/Qwen3.5-9B; relation recorded as finetune.
- Base lineage
- Base huggingface.co/Qwen/Qwen3.5-9B at c202236235762e1c871ad0ccb60c8ee5ba337b9a, published under Apache-2.0 (text Apache-2.0.txt, sha256:c
fc7749b9 ).6f63bd31 c3c42b5c 471bf756 814053e8 47c10f3e b003417b c523d30 - Base-licence obligations
- 4(a): give recipients a copy of the License from Apache-2.0 section 4(a): not met. the model repository ships no licence file: /raw/main/LICENSE returns HTTP 404 and the 17-file sibling list contains no LICENSE, NOTICE or COPYING (re-checked 2026-09-24) 4(b): prominent notice stating that the files were changed from Apache-2.0 section 4(b): not met. no changed-files notice is shipped: sibling probes for NOTICE and USAGE_POLICY also return HTTP 404 (re-checked 2026-09-24) 4(c): retain all copyright, trademark and attribution notices from Apache-2.0 section 4(c): not met. no copyright, trademark or attribution notice from the base is retained: no licence or notice file ships at all (sibling list enumerated 2026-09-24) 4(d): carry the base's NOTICE content when the base ships a NOTICE from Apache-2.0 section 4(d): met. the base Qwen/Qwen3.5-9B ships no NOTICE file (its sibling list enumerated 2026-09-24), so section 4(d) is not engaged
- Contradiction triage
- declared vs base licence: declared MIT (repository metadata tag); base Qwen/Qwen3.5-9B is Apache-2.0. A different label for the distill is permitted in principle (decision 0138 clause 2) only with evidence that the base conditions are met, and no grant text ships to evidence them. declared vs the publisher's other top-level repositories: the licensor's own GitHub code repository XiaomiMiMo/MiMo declares Apache-2.0 (api.github.com/repos/XiaomiMiMo/MiMo/license, spdx_id Apache-2.0, re-checked 2026-09-24) while the Hugging Face metadata tag declares MIT: two inconsistent statements from one licensor. declared set but no file shipped: license: mit is declared but the repository ships no licence file: /raw/main/LICENSE returns HTTP 404 (re-checked 2026-09-24).
- Files and integrity
- safetensors; the weights digest was not verified for this verdict, so the weights are not claimed as byte-checked.
- Export screen
- Export screening: not yet assessed. No export claim is made. The record carries status: not_assessed, basis: null, assessed_by: null, assessed_date: null, reference: null.
- Declared training data
- not recorded in the admission record.
- What was checked
- Canonical text pinned and digest-verified, identifier taken from the licensor's own repository metadata, added-clause screen run over sibling policy files, provenance chain recorded. The licensor's own licence file is not compared byte for byte on this evidence path.
- Signed attestation
- attestation.json: a DSSE envelope over an in-toto Statement v1, whose subject is the weights file digests and whose predicate is this record's provenance artefact. Signed with the key published at /verdicts/keys/, which states the fingerprint, the date the key came into use and how to verify the signature. Key custody: a local key on one operator host, not an HSM.
- Gate findings
licence-evidence: incomplete licence evidence, not a licence verdict: licence.text is empty, so there is nothing to compare byte for byte against the pinned canonical text. The declared identifier "MIT" via "repository-metadata" is Class A (decision 0125 admits MIT and Apache-2.0 through repository-metadata), so this is a record defect rather than a refusal of the licence; but Class A cannot be proven from the repository as it stands, and a human must record which licence statement governs the weights (decision 0019).licence-evidence: incomplete licence evidence, not a licence verdict: evidence tier T3 (a repository metadata tag alone), so Class A is not proven whatever the declared identifier "MIT" says. Class A requires T1 or T2 (decision 0138 clause 4: a metadata tag is not a grant), so this holds for a human; ship a licence file (T1) or a full licence section in the model card (T2) and it re-evaluates.base-licence: base-licence obligation "Apache-2.0 section 4(a)" is not satisfied: the model repository ships no licence file: /raw/main/LICENSE returns HTTP 404 and the 17-file sibling list contains no LICENSE, NOTICE or COPYING (re-checked 2026-09-24) (decision 0138 clause 6 item 3: the base's conditions travel with the base material whatever label the distill declares)base-licence: base-licence obligation "Apache-2.0 section 4(b)" is not satisfied: no changed-files notice is shipped: sibling probes for NOTICE and USAGE_POLICY also return HTTP 404 (re-checked 2026-09-24) (decision 0138 clause 6 item 3: the base's conditions travel with the base material whatever label the distill declares)base-licence: base-licence obligation "Apache-2.0 section 4(c)" is not satisfied: no copyright, trademark or attribution notice from the base is retained: no licence or notice file ships at all (sibling list enumerated 2026-09-24) (decision 0138 clause 6 item 3: the base's conditions travel with the base material whatever label the distill declares) The gate's own words, with one term normalised; the signed attestation carries them exactly.- Licence re-check
- On 22 September 2026 the model card showed no licence. Re-checked on 2026-09-24: the card now declares MIT in its metadata and README front matter, and the repository tree still ships no licence file (raw LICENSE returns 404; no NOTICE or COPYING either). The licensor's own code repository, XiaomiMiMo/MiMo on GitHub, still declares Apache-2.0. The metadata declaration has appeared since 22 September, but the evidence gap behind the hold has not changed, and the committed hold stands. Sources checked on 2026-09-24: huggingface.co/api/models/XiaomiMiMo/MiMo-V2.6-Distill-Qwen-9B, huggingface.co/XiaomiMiMo/MiMo-V2.6-Distill-Qwen-9B/raw/main/README.md, huggingface.co/XiaomiMiMo/MiMo-V2.6-Distill-Qwen-9B/raw/main/LICENSE (404), api.github.com/repos/XiaomiMiMo/MiMo/license.
Running models like this in your own estate? Heliast runs the same gate inside your environment, on your policy.
Book a discovery session