# What “open” lets you download: eight-release audit

**As of 8 October 2026.** This is an offline audit of the supplied official-source snapshots, collected on 8 October 2026 at 09:04:47 UTC. The pages were **not fetched in this session**. No weights or training-data shards were downloaded, and no inference, training or evaluation was run.

Seven repositories list model weights, configuration and tokenizer materials and report `gated:false`. **Mistral Large 4 is different:** its [6 October announcement](https://mistral.ai/news/mistral-large-4/) promises weights by the end of October; an API preview is already described. That announcement is evidence of a promise, not a downloadable weight release.

The [full comparison](download-audit.html) contains ten categories per model, source links, selected excerpts, exact revisions and integrity notes. [The CSV](download-audit-comparison.csv) provides the same judgments for reuse; [the evidence ledger](download-audit-evidence.json) records all 79 sources and hash checks. The [visual summary](download-audit-summary.png) summarizes availability without assigning an “openness score.”

## How to read the findings

**Public** means an artifact is evidenced by supplied contents or a repository file listing. **Partial** means useful materials exist, with stated coverage or verification limits. **Not found** means absent from the explicitly checked card/listing/tree, not proven nonexistent elsewhere. **Unknown** means the relevant evidence is insufficient or uninspected. **Promised** requires explicit future-release language. **Gated** requires positive evidence of an access gate; none of the seven weight metadata records has one.

Training-data descriptions are not downloadable data. A training library, an inference implementation, or an SFT example is not the original model recipe. A license mentioning “training code” does not establish that such code was released. Public access and permissive licensing are separate questions.

## What is available, and what remains

| Release | Weight evidence | Training-reproduction finding |
|---|---|---|
| Mistral Large 4 | Promised for October-end; API preview described | Original training recipe, corpus and release license unverified. |
| DeepSeek-V4-Pro | 64 safetensors shards listed | Inference/encoding code listed; original trainer and corpus not found in checked release. |
| Qwen3.8-27B | 18 shards listed | Deployment guidance and generic fine-tuning links; original recipe and corpus not found in checked trees. |
| GLM-5.3 | 141 shards listed | Serving guidance and a family-level slime link; exact 5.3 training recipe/data unverified or not found in checked sources. |
| Kimi-K3 | 96 shards listed | Inference/processing modules listed; original trainer/corpus not found; listed technical report not supplied for reading. |
| Gemma 4 31B-IT | 2 shards listed | Transformers examples and broad data descriptions; original training pipeline/corpus not found in checked model release. |
| NVIDIA Nemotron 3 Super 120B-A12B-BF16 | 50 shards listed | Model-specific staged recipe, evaluation instructions and some dataset files; important original data explicitly non-public. |
| Olmo-3-1125-32B | 14 shards listed | Staged training scripts, manifest paths and dataset metadata; exact dataset identity and checkpoint merging require reconciliation. |

Shard counts count filenames in metadata, not verified tensor contents, total download sizes or hardware requirements.

**Mistral Large 4.** First obtain the promised weights, their license, tokenizer/configuration and a compatible implementation. Training reproduction additionally needs the original corpus, processing, code, run settings, checkpoints and evaluation assets. The announcement’s multilingual-data and hardware descriptions are insufficient. Further methodology is promised; that is not a promise to publish the training pipeline. [Evidence: S033](https://mistral.ai/news/mistral-large-4/).

**DeepSeek-V4-Pro.** The release lists dedicated inference and custom message-encoding code; the absence of a Jinja template is explicitly intentional. The card describes more than 32T training tokens, Muon optimization, domain-specific SFT/GRPO and consolidation through distillation. Reproduction still needs the actual corpus and processing, trainer/distributed settings, expert data/rewards, distillation teachers and run states, and exact evaluation harnesses. [Card: S003](https://huggingface.co/deepseek-ai/DeepSeek-V4-Pro/raw/b5968e9190ef611bbf34a7229255be88a0e937c1/README.md); [inference instructions: S078](https://huggingface.co/deepseek-ai/DeepSeek-V4-Pro/raw/b5968e9190ef611bbf34a7229255be88a0e937c1/inference/README.md).

**Qwen3.8-27B.** This is a post-trained vision-language release. Its coming-soon hosted service does not make the listed weights “promised.” Unsloth/Swift/Llama-Factory recommendations do not supply the original pipeline. Need exact multimodal corpus versions/mixtures and preprocessing, pretraining/post-training configurations, teachers/rewards and agent environments. Evaluation additionally needs corrected benchmark annotations and precise harness/judge versions. Family-level Qwen3.5 data statements are not assigned to 3.8-27B. [Card: S008](https://huggingface.co/Qwen/Qwen3.8-27B/raw/1d4bf0f2ff6012fd82039f2fa52739d0dd7c60c0/README.md); [project: S067](https://raw.githubusercontent.com/QwenLM/Qwen3.8/2ea10dc725823bf7c3e21ce8557cbe15245132ae/README.md).

**GLM-5.3.** Its card says it shares GLM-5.2’s base and improvements come from post-training. Need that base lineage plus the exact 5.3 post-training data, rewards, orchestration and settings. The family’s slime infrastructure link is not this recipe; data figures for GLM-5 or GLM-5.3-Flash do not establish the exact 5.3 corpus. Evaluation footnotes are substantial, but patched harnesses, containers and judge access remain unverified. [Card: S013](https://huggingface.co/zai-org/GLM-5.3/raw/aca966e4e02791568aa6a4ced368624b3d897f42/README.md).

**Kimi-K3.** Model/processor/tokenization modules are listed, and the card describes quantization-aware training from SFT onward. Need original pretraining/post-training/QAT code, corpus and processing, teachers/rewards and run settings. Evaluation depends on Kimi Code, in-house tasks and an H20-calibrated task branch. A listed technical-report PDF is not treated as read. [Card: S018](https://huggingface.co/moonshotai/Kimi-K3/raw/f831ab66814297da540d832a5235f8e904f29d06/README.md).

**Gemma 4 31B-IT.** The snapshot supports ungated metadata and Apache-2.0, rather than importing restrictions from older Gemma releases. Its data section describes modalities, a January 2025 cutoff and filtering, not downloadable training shards. Need exact corpus versions/mixtures, filtering implementation, original trainer/settings and instruction-tuning/teacher/reward materials. Evaluation results and loading examples are not a full reproduction package. [Card: S022](https://huggingface.co/google/gemma-4-31B-it/raw/842da3794eaa0b77d5f08bae87a17459d91ff475/README.md).

**Nemotron 3 Super BF16.** This goes beyond generic training libraries: the supplied tree has model-specific pretraining, SFT and RL scripts/configs; the [pretraining README, S073](https://raw.githubusercontent.com/NVIDIA-NeMo/Nemotron/ca8c409f08a9a5a5648d427383adea741b61966a/src/nemotron/recipes/super3/stage0_pretrain/README.md) provides phases and launch commands. It explicitly identifies internal-only corpus categories; the card also names private third-party/NVIDIA datasets. One audited dataset metadata record lists three real JSONL files, but linked collections are not fully audited inventories. Reproduction needs missing data, exact blends/settings, generators and historical run lineage. Public recipe adaptation cannot reproduce identical training inputs. The README’s “8–10T” and “40–50% of 25T” estimates are inconsistent; 8–10/25 is 32–40%, so no precise audited coverage percentage is claimed. Model-specific evaluation instructions exist, but the exact BF16 endpoint, containers and credentials still need validation. NVFP4 training does not make this BF16 release an NVFP4 checkpoint.

**Olmo-3-1125-32B.** This is the **base model**, not Think/Instruct. Actual staged 32B training scripts were read, and separate official release scripts/manifests are listed. Their exact correspondence remains to be checked: supplied script bodies are from the development training directory, with some cloud checkpoint/data paths. Reduced Dolma metadata is ungated and supplies file patterns, but not shard inventories. The requested 5.5T-1125 dataset URL returns the ID `allenai/dolma3_mix-6T`; historical equivalence is unresolved. The [model card, S030](https://huggingface.co/allenai/Olmo-3-1125-32B/raw/c2b61dae89a1ad10e4ad5653d0e46b590902607b/README.md) says four final checkpoints were averaged; the [official training README, S071](https://raw.githubusercontent.com/allenai/OLMo-core/5f6f58a133e7ef577d596295f2c8db4651c27857/src/scripts/official/OLMo3/README.md) says three. Need exact checkpoint IDs, averaging procedure, pinned data/manifests, optimizer states, original logs and evaluation settings. Logs are partly described as “coming soon”; linked reports were not inspected.

## License findings

| Release | Inspected evidence and limitation |
|---|---|
| Mistral Large 4 | Weight-release terms unverified. |
| DeepSeek-V4-Pro | MIT text inspected; card explicitly covers repository and weights. |
| Qwen3.8-27B | Apache-2.0 LICENSE text inspected. |
| GLM-5.3 | Custom license. MaaS operators with aggregate affiliate revenue exceeding $10B over any consecutive 12 months require Z.AI security review before commercial use. |
| Kimi-K3 | Custom license. MaaS operators exceeding $20M aggregate affiliate revenue over any consecutive 12 months need a separate agreement. Commercial products/services exceeding 100M monthly active users or $20M monthly revenue require prominent “Kimi K3” UI attribution. Sections 2–3 exempt defined internal use and access through official products/certified inference partners. |
| Gemma 4 31B-IT | Apache-2.0 card and official Gemma 4 license text inspected; hash consistent. |
| Nemotron 3 Super BF16 | Card names NVIDIA Nemotron Open Model License. Detailed page text is integrity-unverified because its recorded hash/size does not match. |
| Olmo-3-1125-32B | Apache-2.0 declared by card/metadata; no model license body supplied. Dolma dataset metadata labels ODC-BY, also without inspected terms. |

The HTML ledger links the exact license evidence (S002, S007, S012, S017, S036 and S038). Descriptive card language is weaker than inspected license terms.

## Integrity and scope

Of **79 records**, **72** match both recorded SHA-256 and UTF-8 byte count directly. **Three** (DeepSeek LICENSE, Qwen LICENSE and Qwen card) match exactly after restoring CRLF line endings. **One** (NVIDIA license HTML) remains mismatched: 300,192 recorded bytes versus 300,008 embedded UTF-8 bytes. **Three** have no content because full dataset metadata exceeded the collector’s size cap; successful reduced-field replies were examined separately. Those retrieval failures are not evidence that datasets are absent.

All **14** comparable GitHub text files also match their tree-recorded Git blob SHA-1. The attachment’s SHA-256 is `edceb401799bf19058d7b7365f585cc061d4b2d180aa1a4ca3373ec588f1d9b7`.

These checks establish internal consistency of the supplied snapshots, not independent authentication of source origin. No listed weight bytes, full dataset shards, linked-but-unsupplied reports, external runtime implementations or evaluation runs were silently counted as verified. None of the supplied evidence establishes exact end-to-end reproduction of a released checkpoint.
