Based on published licence terms, GPT-OSS 20B is released under Apache 2.0 with no field-of-use carve-outs in the licence itself; OpenAI publishes a separate non-binding 'gpt-oss usage policy' as guidance. Training-data disclosure is domain-level only, and US origin carries Schrems-II / CLOUD-Act exposure that enterprise deployers should document for EU workloads.
Sovereignty
Licence: Apache 2.0Commercial: UnrestrictedTraining data: Domain-level summaryOrigin: United States
Training-data transparency gap: OpenAI describes the corpus only at domain level ('mostly English, text-only', weighted toward STEM, coding, general knowledge) with no dataset enumeration, source list, or opt-out mechanism — thin for EU AI Act Art. 53(1)(d) 'sufficiently detailed summary' expectations.
US origin and transfer exposure: self-hosting inside the EU mitigates Schrems-II / CLOUD Act concerns for the weights, but any operational telemetry returned to OpenAI or US-based inference providers re-introduces transfer risk that must be addressed contractually.
Safety-tuning is removable by fine-tuning: OpenAI acknowledges that determined actors can fine-tune away refusals, so EU deployers carry the mitigation burden (content filtering, downstream provider duties) under AI Act obligations.