XiaomiMiMo /MiMo-V2.6-Distill-Qwen-9B

Verdict

Held
  • There is not enough licence evidence to prove the licence, so it is not admitted.
  • An obligation of the base model's licence is not satisfied.

What would change it: evidence from the licensor, or a human ruling. A hold is not a failure.

A verdict covers licence, provenance and files. Quality and fit on your own tasks are measured by Compare.

What was checked

  • Licence Not concluded

    MIT is declared only as a repository tag (T3), which is not a grant.

  • Provenance Not verified

    The licensor's own repository, derived from Qwen/Qwen3.5-9B.

  • Files Not verified

    Safetensors. The weights digest was not verified, so they are not claimed as byte-checked.

  • Export screening Not yet assessed

    No export claim is made.

Verify this verdict

Download attestation.json and check it against the published key:

python scripts/verify-verdict.py

Full record
Revision
2367e865d009c13ac81713a2878291d33ab28177
Date assessed
2026-09-25 BACKFILL
Upstream released
2026-09-22T03:52:45Z, the commit date of the assessed revision, recorded 2026-09-25. A reconstruction: this verdict was assessed before upstream release tracking began, so it is excluded from the median.
Release to verdict
Verdict latency: 68 hours from the upstream release to 00:00 UTC on the assessment date. The record is dated, not timed, so the true figure may be up to 24 hours higher.
Provenance label
the weights digest was not verified for this verdict, so the weights are not claimed as byte-checked
Licence, declared and concluded
Declared: MIT (as a repository-metadata-tag). Concluded: NoAssertion: no grant text exists to conclude from, so no licence is concluded for these weights.
Evidence tier
T3: a repository metadata tag only. Not a grant: the identifier is the publisher's assertion with no text behind it, so the record is held whatever the identifier says.
Deviation from canonical text
Not assessable: the repository ships no licence file, so there is nothing to compare against the pinned canonical text.
Added-clause screen
Run over the declared sibling policy files; none were declared for this model.
Provenance chain
Source: huggingface.co/XiaomiMiMo/MiMo-V2.6-Distill-Qwen-9B. Official licensor repository: yes. Derived from Qwen/Qwen3.5-9B; relation recorded as finetune.
Base lineage
Base huggingface.co/Qwen/Qwen3.5-9B at c202236235762e1c871ad0ccb60c8ee5ba337b9a, published under Apache-2.0 (text Apache-2.0.txt, sha256:cfc7749b96f63bd31c3c42b5c471bf756814053e847c10f3eb003417bc523d30).
Base-licence obligations
4(a): give recipients a copy of the License from Apache-2.0 section 4(a): not met. the model repository ships no licence file: /raw/main/LICENSE returns HTTP 404 and the 17-file sibling list contains no LICENSE, NOTICE or COPYING (re-checked 2026-09-24) 4(b): prominent notice stating that the files were changed from Apache-2.0 section 4(b): not met. no changed-files notice is shipped: sibling probes for NOTICE and USAGE_POLICY also return HTTP 404 (re-checked 2026-09-24) 4(c): retain all copyright, trademark and attribution notices from Apache-2.0 section 4(c): not met. no copyright, trademark or attribution notice from the base is retained: no licence or notice file ships at all (sibling list enumerated 2026-09-24) 4(d): carry the base's NOTICE content when the base ships a NOTICE from Apache-2.0 section 4(d): met. the base Qwen/Qwen3.5-9B ships no NOTICE file (its sibling list enumerated 2026-09-24), so section 4(d) is not engaged
Contradiction triage
declared vs base licence: declared MIT (repository metadata tag); base Qwen/Qwen3.5-9B is Apache-2.0. A different label for the distill is permitted in principle (decision 0138 clause 2) only with evidence that the base conditions are met, and no grant text ships to evidence them. declared vs the publisher's other top-level repositories: the licensor's own GitHub code repository XiaomiMiMo/MiMo declares Apache-2.0 (api.github.com/repos/XiaomiMiMo/MiMo/license, spdx_id Apache-2.0, re-checked 2026-09-24) while the Hugging Face metadata tag declares MIT: two inconsistent statements from one licensor. declared set but no file shipped: license: mit is declared but the repository ships no licence file: /raw/main/LICENSE returns HTTP 404 (re-checked 2026-09-24).
Files and integrity
safetensors; the weights digest was not verified for this verdict, so the weights are not claimed as byte-checked.
Export screen
Export screening: not yet assessed. No export claim is made. The record carries status: not_assessed, basis: null, assessed_by: null, assessed_date: null, reference: null.
Declared training data
not recorded in the admission record.
What was checked
Canonical text pinned and digest-verified, identifier taken from the licensor's own repository metadata, added-clause screen run over sibling policy files, provenance chain recorded. The licensor's own licence file is not compared byte for byte on this evidence path.
Signed attestation
attestation.json: a DSSE envelope over an in-toto Statement v1, whose subject is the weights file digests and whose predicate is this record's provenance artefact. Signed with the key published at /verdicts/keys/, which states the fingerprint, the date the key came into use and how to verify the signature. Key custody: a local key on one operator host, not an HSM.
Gate findings
licence-evidence: incomplete licence evidence, not a licence verdict: licence.text is empty, so there is nothing to compare byte for byte against the pinned canonical text. The declared identifier "MIT" via "repository-metadata" is Class A (decision 0125 admits MIT and Apache-2.0 through repository-metadata), so this is a record defect rather than a refusal of the licence; but Class A cannot be proven from the repository as it stands, and a human must record which licence statement governs the weights (decision 0019).
licence-evidence: incomplete licence evidence, not a licence verdict: evidence tier T3 (a repository metadata tag alone), so Class A is not proven whatever the declared identifier "MIT" says. Class A requires T1 or T2 (decision 0138 clause 4: a metadata tag is not a grant), so this holds for a human; ship a licence file (T1) or a full licence section in the model card (T2) and it re-evaluates.
base-licence: base-licence obligation "Apache-2.0 section 4(a)" is not satisfied: the model repository ships no licence file: /raw/main/LICENSE returns HTTP 404 and the 17-file sibling list contains no LICENSE, NOTICE or COPYING (re-checked 2026-09-24) (decision 0138 clause 6 item 3: the base's conditions travel with the base material whatever label the distill declares)
base-licence: base-licence obligation "Apache-2.0 section 4(b)" is not satisfied: no changed-files notice is shipped: sibling probes for NOTICE and USAGE_POLICY also return HTTP 404 (re-checked 2026-09-24) (decision 0138 clause 6 item 3: the base's conditions travel with the base material whatever label the distill declares)
base-licence: base-licence obligation "Apache-2.0 section 4(c)" is not satisfied: no copyright, trademark or attribution notice from the base is retained: no licence or notice file ships at all (sibling list enumerated 2026-09-24) (decision 0138 clause 6 item 3: the base's conditions travel with the base material whatever label the distill declares) The gate's own words, with one term normalised; the signed attestation carries them exactly.
Licence re-check
On 22 September 2026 the model card showed no licence. Re-checked on 2026-09-24: the card now declares MIT in its metadata and README front matter, and the repository tree still ships no licence file (raw LICENSE returns 404; no NOTICE or COPYING either). The licensor's own code repository, XiaomiMiMo/MiMo on GitHub, still declares Apache-2.0. The metadata declaration has appeared since 22 September, but the evidence gap behind the hold has not changed, and the committed hold stands. Sources checked on 2026-09-24: huggingface.co/api/models/XiaomiMiMo/MiMo-V2.6-Distill-Qwen-9B, huggingface.co/XiaomiMiMo/MiMo-V2.6-Distill-Qwen-9B/raw/main/README.md, huggingface.co/XiaomiMiMo/MiMo-V2.6-Distill-Qwen-9B/raw/main/LICENSE (404), api.github.com/repos/XiaomiMiMo/MiMo/license.

Running models like this in your own estate? Heliast runs the same gate inside your environment, on your policy.

Book a discovery session