Short answer
An Apache-2.0 model licence covers the weights and nothing else. If you self-host Beam but your team's knowledge sits in a vendor's database, you moved the compute inside your perimeter and left the corpus outside it. Owning the stack means owning both: the model you run and the files it reads.
There is a reflex in this industry that treats "Apache-2.0" on a model as the end of the ownership conversation. It is the start of one, and it is a conversation about the wrong artifact. A model licence governs the thing you can swap out in a month. It says nothing at all about the thing you cannot.
What did Reflection actually announce on 5 October?
Beam, Reflection AI's first open-weight model, announced on 5 October 2026. A sparse mixture-of-experts model with 501 billion total parameters and 23 billion active for any given token, aimed at coding, reasoning and agentic work.
The figures Reflection publishes in that post, as of 6 October 2026:
- Training. Pretrained on 23.8 trillion tokens from the web and proprietary licensed datasets, on 6,144 NVIDIA GB300 NVL72 GPUs in under four weeks. Reinforcement learning ran over 100 million rollouts across 1.3 billion sandboxes on 10.5K GB300 GPUs over a further four weeks.
- Context. A maximum context length of 256K tokens during RL, and a 1M token effective context length reached through midtraining.
- Benchmarks. 80.9 on SWE-bench Verified, against 77.6 for Inkling and 70.7 for Nemotron 3 Ultra. On agentic and tool-calling benchmarks the picture is mixed: 78.7 on MCP Atlas against 84.5 for Qwen 3.8 Max, and 38.0 on tau3 banking against 55.2. These are vendor-published numbers released alongside the announcement.
- The licence. "We will release the weights under an Apache 2.0 license, along with documentation and the full stack for running, evaluating, and fine-tuning the model." The post says that happens later this month.
So nobody is running Beam today. The weights are not out, access is a waitlist to a select group, and the model is in final red-teaming. What is out, right now, is the intention, and the intention is the part worth reacting to, because teams are already making plans around it.
What does an Apache-2.0 model licence actually cover?
The weights. That is the whole scope.
Apache-2.0 on a set of weights is a real and generous grant. You can run the model on your own hardware, fine-tune it, build a product on it, and nobody can withdraw that from the version you hold. Reflection is also shipping a technical report, a model card and the stack for running and evaluating it, which is more than several "open" releases manage.
What it does not cover is everything the model is pointed at. Your architecture decisions. Your runbooks. The six months of argument behind why the billing service looks like that. The onboarding doc, the incident writeups, the half-finished spec somebody will need in March. A model licence has no opinion on any of it, and that material is the only part of the arrangement that is actually yours and actually scarce.
This is where Baalda sits, and it is why this release is worth a post rather than a retweet. Baalda is a team second brain: plain markdown files on your own disk, several people editing the same note in real time over a CRDT, and an AI reading and writing those same files over MCP. The reason that shape matters to an open-weights story is not features. It is that Baalda is the half of the stack most teams never think to self-host, and it is the half with the longer useful life.
Put the two side by side and the asymmetry is obvious.
| The weights | The corpus | |
|---|---|---|
| How long it stays current | Months. Something better ships every quarter | Years. The decisions outlive the people who made them |
| Replaceable | Yes, swap the endpoint | No. There is no second copy of why you chose Postgres |
| Who made it | Someone else, on 10.5K GPUs | Your team, one paragraph at a time |
| Where teams usually keep it | Increasingly, their own metal | A vendor's database they cannot run |
Teams are getting steadily more careful about the left-hand column and have mostly not started on the right-hand one.
Why is the corpus the harder half to own?
Because the exit is theoretical.
Most knowledge tools will export. That is not the same as ownership, and the gap shows up at exactly the moment it matters. An export is a snapshot taken on the day you asked, in a shape the vendor chose, of a system you still cannot run. It does not include the permission model, it usually mangles the links, and it is immediately stale. Export is not ownership is the oldest argument in this category and it keeps being right.
The sharper version of the problem is specific to agents. Once a model is reading and writing your team's knowledge, the connection between the two is a piece of production infrastructure. If that connection is a hosted MCP endpoint at a vendor, then the sentence "we self-host our model" is doing less work than it sounds like. The inference runs on your GPUs. The corpus sits on someone else's disk, under someone else's terms, reachable only through an API they version. You built a perimeter and ran a wire through it.
What does it look like to self-host both halves?
Concretely, in Baalda's case: the MCP endpoint is not a service you call. It is a route on the server you are already running.
The Baalda server is a Node and Postgres service, a Hono HTTP API plus the Hocuspocus sync WebSocket, both on a single port (default 3010). It builds from one Dockerfile and there is a docker compose stack in deploy/compose with Postgres and a one-shot migration step. Migrations are idempotent, tracked in a _migrations table, so re-running them on every deploy is normal rather than frightening. Then MCP is served at POST /api/mcp on that same server, token-authenticated, and connecting an agent is one line:
claude mcp add --transport http context https://notes.internal.example/api/mcp \
--header "Authorization: Bearer mcp_…"On the managed service that host is api.baalda.com. On a self-hosted deployment it is whatever you called your box. Nothing else in the command changes, which is the point: the hosted and self-hosted paths are the same code, so choosing the private one is a deployment decision rather than a different product on a worse tier.
What that buys you against a Beam-shaped stack is one boundary instead of two. The model runs on your hardware. The sync server runs on your hardware. The notes are .md files on your own disk, and each device re-derives its own copies, so the markdown itself never crosses the network in plain text, only opaque binary CRDT updates do. The agent reads through search_notes and read_note and writes through create_note, edit_note and append_note, gated by the same per-folder permissions that govern the people on the team. A folder you cannot open is a folder the agent acting for you cannot read. The self-hosting guide and the MCP setup are both short, because there is not much to it.
Can the licence on your notes change under you?
This is the question the open-weights conversation taught everyone to ask about models and almost nobody asks about their tooling, and the answer is usually yes.
HashiCorp moved Terraform from MPL 2.0 to the Business Source License on 10 August 2023, which is what produced OpenTofu. NocoDB, an open source Airtable alternative, changed from AGPL-3.0 to a Sustainable Use License on 9 January 2026, moving from open source to source-available. In both cases the code you already had kept its old licence. Everything after did not.
The mechanism that makes a unilateral relicense possible is a contributor licence agreement. A CLA assigns or licenses contributors' copyright to the company, which is what gives one party the standing to change the terms for everyone. Without one, copyright stays distributed across every contributor, and relicensing means getting permission from all of them.
Baalda is Apache-2.0 and takes contributions with no CLA required. That is a structural fact rather than a promise, and it is the honest version of "you can trust this", because it does not depend on anyone's intentions staying the same.
Where does this argument not hold?
Four places, and they matter.
Baalda does not run your model. There is no inference engine here, no GPU scheduling, no serving layer, no quantisation story. Standing up a 501B-parameter model is overwhelmingly the expensive, difficult half of this plan and it is entirely outside Baalda's scope. Only 23 billion parameters are active per token, but the serving system still has to have all 501 billion available to route to, so this is not a laptop model, and Reflection has not published hardware requirements. Self-hosting your vault is one of several things in a private stack, and it is the cheap one.
Baalda is open core, not open source end to end. Everything outside the ee/ directory is Apache-2.0. Inside ee/ is the Baalda Enterprise License, source-available, where commercial-only features like SSO and audit logs are meant to live, and production use of those requires a subscription. The repo's stated ground rule is that enterprise features add to the open core and never gate a capability that already shipped under Apache-2.0. You should read that boundary yourself rather than take this paragraph for it, which is rather the theme of the post.
For one person, none of this is a problem yet. Obsidian is a better single-user editor than Baalda, it is local-first, your files are already yours, and a solo vault plus a local agent with filesystem access needs no server at all. What Obsidian has no answer for is several people inside one note at the same time, which is where the two diverge. If you are one, stay where you are.
And self-hosting has a running cost. A Postgres instance, a box, backups, an upgrade you will forget to do. The managed Team plan exists because for a lot of teams that is not a good trade. The argument here is not that everyone should self-host. It is that the option has to be real, and that it should cover the corpus and not just the model.
What is worth doing before the weights land?
One thing, and it is free.
Write down where your team's knowledge would be if your current knowledge vendor changed its terms next quarter. Not where the export would go. Where it would actually be: who could read it, who could edit it at the same time as someone else, and what an agent would connect to in order to reach it. For most teams that exercise produces an uncomfortably short answer, and it produces it well before any of this is urgent, which is the only useful time to find out.
Beam might turn out to be excellent. The weights might land this month under Apache-2.0 exactly as promised, and a team with the hardware might run a frontier-adjacent model with nothing leaving the building. That is a genuinely good outcome and the licence deserves credit. It is just worth being clear about what it gets you, because the part an AI is most valuable reading is still sitting in a product you do not run.
