What does Meta's Llama Acceptable Use Policy restrict, and what happens if you breach it?
answer
- Policy is incorporated, not advisory
- Restrictions live at a mutable URL
- Breach ends the licence, not a warning
- Delete-and-cease is the remedy
- Terms must flow to your own users
basics
~20 sThe Acceptable Use Policy is incorporated into the Llama Community License and bars categories such as illegal activity, weapons development, malware, critical-infrastructure interference, exploitation of minors, and deceptive impersonation. Breach is a licence breach: Meta may terminate, after which you must stop using and delete the materials.
solid answer
~50 sMeta publishes a separate Acceptable Use Policy that the Community License incorporates by reference, so the use restrictions are contractual, not advisory. It prohibits broad categories — violating the law or others' rights, violence and terrorism, weapons development, illegal drugs, exploitation or harm of children, malicious code and unauthorised system access, interference with critical infrastructure, and generating deceptive content such as impersonation or fraud, along with failing to disclose known dangers of your AI system. Two structural facts matter more than the list. First, Meta can update the policy at a URL without reissuing the licence, so the restrictions your deployment is bound by are not frozen at the text you first read. Second, the agreement terminates on breach — Meta may terminate it, and upon termination you must cease use of and delete the Llama Materials. You also pass a copy of the agreement to anyone you distribute to, so the restrictions travel downstream with the weights.
go deeper
Know that Llama's licence includes a use policy with real force — categories like malware, weapons, and deceptive impersonation are prohibited — and that violating it breaks the licence rather than just the rules.
Explain that the policy is incorporated by reference, that Meta can update it at its URL without reissuing the agreement, and that breach lets Meta terminate, after which you must cease use and delete the materials.
Show the production consequences: a weights inventory that makes a delete-and-cease order executable, mirrored restrictions in your own terms of service, abuse detection at the application layer, and a snapshot of the policy text per deployment.
Own the risk posture — a mutable, incorporated-by-reference policy plus a defensive-termination clause means Llama carries a residual continuity risk, so the architecture should keep model swap-out cheap and the vendor decision reviewable.
## An acceptable-use policy with contractual force Many vendors publish usage guidelines that read as aspirational. Meta's is not one of them: the Llama Community License incorporates the Acceptable Use Policy by reference and conditions the grant of rights on compliance with it. Using Llama in a prohibited way is therefore a breach of the licence itself, with the remedies the licence provides — not merely a policy violation you argue about in support tickets. This is one of the two clauses that keeps Llama outside the Open Source Definition, because open-source licences may not restrict fields of endeavour. ## What the policy covers The policy is organised as categories of prohibited use. Without reciting it clause by clause, the substance spans: - **Illegality and rights violations** — using the model to break the law, or to violate the rights of others, including intellectual-property and privacy rights. - **Violence, terrorism, and weapons** — including the development of weapons, and materials facilitating attacks. - **Harm to children** — exploitation, abuse material, and related conduct. - **Cyber-offence** — creating malicious code, malware, or tooling for unauthorised access to systems, and disrupting the security of computer systems. - **Critical infrastructure** — interference with the operation of critical infrastructure and safety-critical systems. - **Deception and impersonation** — fraud, disinformation campaigns, impersonating a person or entity, and generating content that misrepresents its origin. - **Regulated-professional deception** — presenting model output as qualified professional advice without appropriate disclosure. - **Failure to disclose risks** — not informing end users of known dangers of your AI system. The policy also carries reporting channels for violations and for model issues. ## The two structural facts that matter in a design review **It can change under you.** The policy lives at a URL and is incorporated by reference. Meta can revise it without issuing a new licence agreement, meaning the operative restrictions on a deployment shipped last year may not be the ones you read last year. This is genuinely different from a static licence file vendored into your repository. The mitigation is procedural: snapshot the policy text on the date you accept it, and re-check it at each model upgrade and at a fixed cadence. **Breach terminates the licence.** The term-and-termination section provides that the agreement continues until terminated, that Meta may terminate it if you are in breach, and that upon termination you must stop using and delete the Llama Materials. The relevant provisions on survival, disclaimers and liability persist past termination. There is no cure period spelled out that you can rely on. For an on-prem deployment this is a concrete operational event: you would need to pull weights from every image, registry, cache, and backup — which is why teams that have thought about it keep an inventory of where the weights physically live. Separately, the intellectual-property section provides that if you institute litigation against Meta or any entity alleging that the Llama Materials or their outputs infringe intellectual-property rights, your licence terminates as of the date the claim is filed. That clause is worth flagging to counsel in any organisation with an active patent programme. ## Pass-through to your users Because you must provide a copy of the agreement to any third party who receives the materials, the acceptable-use restrictions bind your recipients too. If you operate a platform where customers deploy or download Llama-derived models, your terms of service should reflect the restrictions, and your abuse-handling should be able to act on them. Practically, teams building customer-facing products on Llama end up implementing: - Usage terms that mirror the prohibited categories. - Content filtering and abuse detection at the application layer, since the licence obligation is about *use*, and your product is the surface where use happens. - A disclosure surface telling end users they are interacting with an AI system and what its known limitations are, which addresses the disclosure category directly. - An incident path for reporting and responding to violations. ## The judgment an interviewer is testing The list of prohibited categories is not the interesting part — anyone can read it. What distinguishes a senior answer is recognising that (a) the restrictions are contractual and enforceable, (b) they are mutable at Meta's URL rather than pinned in your repository, (c) the remedy is termination with a delete-and-cease obligation that has real infrastructure consequences, and (d) the obligations flow through to your own users, so they must show up in your terms of service and abuse tooling rather than only in a legal file. That is the shape of an answer from someone who has actually shipped a Llama-based product rather than read the licence once.
- Why does it matter that the acceptable-use policy lives at a URL rather than inside the licence file?Because Meta can revise it without reissuing the agreement, so the restrictions binding your live deployment can change after you accepted the licence. A vendored LICENSE file in your repo gives false confidence that the terms are pinned. The practical control is to snapshot the policy text on the date of acceptance, store it with your model provenance record, and re-check it at every model upgrade and on a scheduled cadence.
- What would termination actually mean for a self-hosted deployment?An operational purge, not just a legal notice. Upon termination the agreement requires you to cease using and delete the Llama Materials, which means weights in serving nodes, container images, model registries, build caches, and backups. Teams that have thought this through keep an inventory of every location holding weights and a documented removal path, alongside a fallback model that could take traffic, because the alternative is discovering the blast radius under time pressure.
- Does the licence contain anything that terminates our rights other than misuse?Yes — the intellectual-property section provides that if you institute litigation or a proceeding against Meta or any entity alleging that the Llama Materials or their outputs infringe intellectual-property rights, the licences granted to you terminate as of the date that claim is filed. It is a defensive-termination clause of the kind common in modern licences, and it is worth surfacing to counsel in any organisation running an active patent-assertion programme.
saying these in an interview costs you the question
- Treats the acceptable-use policy as non-binding guidance
- Assumes the policy text is frozen once you download the weights
- Expects a warning or cure period before termination
- Thinks restrictions do not pass to downstream recipients
- Believes deleting weights from production alone discharges termination