AI in Practice
Holo4 for Business: Check Licenses, API Data Terms, and Self-Hosting
Holo4's downloadable checkpoints have different weight licenses, while its hosted API has separate account terms. Learn what to check before choosing a route.

On this page
- "Open weights" does not answer whether your company can use them
- Hosted access and self-hosting are different decisions
- What H's public data documents say
- Questions to put to H in writing
- Hosted and self-managed responsibilities
- The model file is only one part of local deployment
- Read Holo4's benchmark table in separate lanes
- Choose a route by rights, infrastructure and workload
- A proposed pilot that measures more than tokens
- What a business should conclude from the launch
Holo4 has two downloadable checkpoints, and their weight licenses are different. Holo4-27B is listed under CC BY-NC 4.0, while Holo4-35B-A3B is listed under Apache 2.0. That distinction matters if a company is considering downloading and running the weights. A hosted H Models API is a separate choice with its own terms, and H's public Terms of Use, Privacy Policy and data-processing template describe retention and training use differently, so the buyer's executed agreement is what needs checking. Before a team chooses a variant, it should verify the rights for its exact use, confirm applicable data terms, estimate the complete cost of a real task, and decide whether it wants to operate the inference stack itself.
That is a more useful starting point than asking whether Holo4 is "open" or whether one benchmark score beats another. Those labels compress different decisions. Permission, data handling, deployment, operating responsibility, and task performance each need their own evidence.
This article reviews H Company's September 28, 2026 launch materials and current model cards, with an as-of check on October 1, 2026. Rise has not run Holo4, negotiated API terms, received legal advice, or measured savings from it. The evaluation near the end is a proposed pilot, not a report of a test.
"Open weights" does not answer whether your company can use them
H Company announced Holo4 in two principal variants: Holo4-27B, a dense 27-billion-parameter model, and Holo4-35B-A3B, a mixture-of-experts model with 35 billion total parameters and about 3 billion active per token. The company publishes weight files and offers model access through its hosted API. The model cards identify different licenses for the two downloadable checkpoints: the 27B card specifies CC BY-NC 4.0, while the 35B-A3B card specifies Apache 2.0.
Those are not interchangeable terms. "Open weights" means the weights can be obtained under stated conditions. It does not, by itself, mean that every checkpoint can be used commercially, that every use is permitted, or that the inference software is inexpensive to operate. A file that downloads is not the same thing as a business approval.
The detail most likely to change a procurement conversation is the variant split. Neither the parameter count nor the benchmark table tells you which license applies: the 27B posts H's higher reported scores, yet its weights carry the noncommercial license. If your proposed use is commercial, the 27B model card's noncommercial condition should stop the team from treating local deployment as automatically cleared. Ask the rights holder for written clarification or separate terms before building a commercial workflow around those weights. This article is not legal advice.
Apache 2.0 is the weight license listed for the 35B-A3B checkpoint. Review the Apache 2.0 license text and all included model materials rather than relying on a marketing description. The base model and bundled assets may carry their own terms. A license for one file also does not settle every question about output use, data, privacy, support, or the software that executes the agent.
View image detailHosted access and self-hosting are different decisions
H Company's launch page lists both Holo4 variants on its Models API. As checked on October 1, the page gives per-million-token rates of $0.40 input, $0.04 cached input, and $3.00 output for 27B; it lists $0.30 input, $0.03 cached input, and $2.00 output for 35B-A3B. Rates, product access, and terms can change, so a team should reopen the current Holo4 page and pricing page before it approves a budget.
Do not assume the hosted service inherits the weight license printed on the download page. A hosted endpoint and downloaded weights are separate products. Check the service's current terms, plan, data handling, retention, available region, rate limits and account controls for the actual API use. The public launch and pricing pages are not a substitute for the full terms that apply to an account. If those terms do not answer a material question, ask the provider and retain the answer with the review.
What H's public data documents say
H Company's publicly available documents warrant a closer read before a business sends real work data, because they do not describe retention and training use in the same way. Each is summarized separately below. This article does not decide which one governs any customer.
Terms of Use. The Terms of Use, marked updated April 14, 2026, include the Inference API in scope. Section 6.2 says textual and visual data are not stored persistently and that only non-identifying technical metadata is persisted.
Privacy Policy. The Privacy Policy describes Input/Output retention of 30 days for EEA users and 90 days for non-EEA users. The same policy also says this data is not stored persistently, and it lists Inputs and Outputs among the data processed for model training unless the user opts out. The page carries two different update markers, April 13 and June 24, 2026.
Data-processing addendum. H's public French-language data-processing addendum refers to the commercial contract and the customer's account, names Inputs and Outputs among the processed data, and leaves processing purposes and retention periods to a customer-specific sub-annex. It also describes reuse for service security, improvement, maintenance and terms enforcement, and AI training and research unless the customer expressly objects in its account space. Terms of Use §10.2 says the DPA forms an integral part of the Terms when H processes personal data as processor on behalf of the user. The public standard form alone does not establish which agreement governs this buyer's account, what its annex specifies or which account settings were selected. Confirm whether the processor condition applies to the proposed API use.
Read together, these public documents establish a conditional relationship between the Terms and DPA, while leaving account-specific questions about scope, retention and settings unresolved. Ask H to confirm which agreement and annex cover the account and how the different public retention descriptions are reconciled. This article does not determine which provisions control an individual buyer's use.
Questions to put to H in writing
Before a pilot, ask H to confirm in writing:
- which executed agreement, document versions and service scope apply to the account;
- the retention period for prompts, screenshots and outputs under that agreement;
- whether training use is enabled for the account, and which objection or opt-out setting controls it;
- which deletion controls are available;
- whether the processor condition in Terms §10.2 applies, which DPA version and annex govern, and whether a separate signed agreement exists;
- the relevant processors and transfer terms.
Save the written response with procurement and security review. Do not infer a data guarantee from the weights license, an API price page, or a generic public policy. This is a due-diligence checklist, not a legal conclusion about which document controls. If the stakes are material, involve counsel.
Hosted and self-managed responsibilities
Hosted inference shifts some work to the provider, but it does not remove the customer's responsibility for the agent. A team still chooses the task, sets permissions, handles credentials, checks outputs, logs failures and decides when a person must take over. It also depends on network availability, service limits and any contractual conditions attached to that hosted route.
Self-hosting changes the boundary. H says Holo4 weights can be served with vLLM or llama.cpp and describes formats including BF16, FP8, NVFP4 and Q4 GGUF in its local-inference documentation. That is evidence of a documented route, not a promise that any office computer can run either checkpoint at useful speed. It is also not evidence that local deployment is automatically secure. The organization takes on the server, access controls, updates, monitoring, capacity planning and incident response.
View image detailThe model file is only one part of local deployment
The size of a weight file is not a complete serving-capacity estimate. Fit depends on the chosen runtime, context length, session concurrency, image inputs, throughput target and precision. The Holo4 section does not provide a complete memory or capacity budget for a deployed computer-use workload.
The Holo4 section names BF16 and FP8 checkpoints served with vLLM, NVFP4 with vLLM on Blackwell, and Q4 GGUF with llama.cpp. The page then explicitly says the remaining material covers Holo3.1; its later size and throughput tables therefore should not be applied to Holo4. For a Holo4 deployment, confirm current requirements for the exact checkpoint, runtime, hardware, model length, input mix and throughput target before budgeting or promising local service.
This distinction matters for small organizations. "We own a GPU" is not a complete deployment plan. Who installs the serving stack? Who pins and reviews updates? Who verifies that the selected quantization still meets the task's acceptance criteria? Who patches the host, rotates credentials, limits access to the model endpoint and notices when latency or output quality drifts? Who can shut the agent down if it starts taking actions outside the intended scope?
Those questions do not prove that self-hosting is a bad choice. They identify its full cost. A company with suitable hardware, an existing inference team, a strong reason to keep prompts and screenshots on its own network, and a tested use case may prefer that control. A small agency with no model-serving owner may find that a hosted route costs less after staff time is included, even if the raw token bill is higher. Both are hypotheses until a representative task is measured.
View image detailRead Holo4's benchmark table in separate lanes
H reports results for several tasks, but the numbers do not all measure the same thing. The launch page lists classic OSWorld at 85.2% for Holo4-27B and 80.8% for Holo4-35B-A3B. It separately lists OSWorld 2.0, where it reports a 61.7% score, a 41.5% success rate and $1.22 estimated cost per task for 27B; for 35B-A3B it reports 30.9%, 12.3% and $0.61. H notes the OSWorld 2.0 values are from a single run. These are H's results, not a Rise evaluation.
Keep classic OSWorld and OSWorld 2.0 in separate rows. The OSWorld 2.0 paper describes a benchmark of long-horizon computer workflows and separates partial-score measurements from binary completion. A task can earn partial credit while still failing the requested end state. That distinction is practical: an agent that fills most of a form but changes the wrong record has not completed a safe business task.
The reported dollars per task are also not a promise about a buyer's bill. H says its costs are estimated from tokens used at its API rates for its benchmark runs. An organization's prompt lengths, screenshots, retries, concurrency, hosting choice and reviewer time may be different. Keep token charges, GPU or server costs, tools, network services, human review and recovery work as separate fields before summing them.
View image detailH's AutomationBench notes need the same care. The company says 480 of the 600 public version 1.0.6 tasks fall within the split from which it collected training data, and it publishes results for a separate 120-task held-out subset. The AutomationBench maintainers' README says the official leaderboard uses a separate private task set and that results on the public set may not match the private leaderboard one to one. That context is a reason to interpret the result carefully. It is not proof that any specific score is invalid, nor an independent reproduction of H's work.
View image detailIndependent sources can help readers interpret the method without falsely implying that they have tested Holo4. The OSWorld 2.0 paper is independent research about the benchmark's task design. The AutomationBench repository documents its public/private test distinction. Secondary launch articles, including Unite.AI's report and Musthave.AI's licensing analysis, explain the launch and raise useful questions, but they also rely on vendor-published results. Repetition of a vendor's number across several articles does not turn the number into a separate test.
The most useful reading is therefore not "27B wins at 85.2%" or "35B is cheaper." It is: these results identify two candidates with different reported tradeoffs, while a real team still has to decide whether its exact workflow works, what the failure looks like, and how much it costs to catch and repair.
Choose a route by rights, infrastructure and workload
The decision begins with a constraint, not a model-size preference.
- Downloaded Holo4-27B weights: What the current evidence says: H's card lists CC BY-NC 4.0 and H describes the weights as research-only.; What the team still needs to check: Whether the proposed use is permitted; request specific written permission before commercial weight use. Check included files and any separate terms.
- Downloaded Holo4-35B-A3B weights: What the current evidence says: H's card lists Apache 2.0.; What the team still needs to check: Read the license and included component terms; verify hardware, serving stack, quantization quality, operational owner and complete cost.
- H Models API: What the current evidence says: H lists both variants with current token rates and paid API access. H's public Terms of Use, Privacy Policy and DPA template describe retention and training use differently.; What the team still needs to check: Which executed agreement and DPA, if any, apply; the account's actual retention, training setting, region, rate limits, service reliability, costs and approval controls.
If commercial use of the 27B checkpoint is central, do not treat "we can download it" as approval. Pause the local-weight plan until the rights are clear. If the 35B-A3B license appears to fit, the team still needs to establish whether it can operate the server safely and affordably. If a hosted API appears to fit, confirm the terms and data path for the actual account rather than guessing from the model-card license.
A license comparison is not a model-quality comparison. The 27B may show a higher result on one H-reported benchmark while the 35B-A3B may cost less per reported task. The applicable rights, precision, context, exact task and deployment constraints could still outweigh that benchmark difference. A team cannot choose a commercially appropriate model by optimizing just one column.
This is the same kind of decision that operations leaders face with many AI tools: the advertised capability is only one input. A practical test for what to automate asks whether a workflow is stable enough to delegate and what exception still needs a person. For a computer-use agent, add rights and ownership: which model and interface can touch the task, what does it cost to supervise, and who is accountable when it stops short?
View image detailA proposed pilot that measures more than tokens
Before standardizing on either route, choose one low-consequence task whose correct end state can be checked. This is a proposed evaluation; Rise has not run it. Use a test account or approved synthetic data, not a live customer or financial workflow. Keep the first run away from irreversible actions.
Write down the task's starting state and the exact conditions that count as done. For example, a hypothetical vendor-directory update might require changing one approved test record, preserving two protected fields, and producing a record of what changed. "The agent said it finished" is not an acceptance test. Read back the saved record and compare it with the expected state.
Freeze the conditions before comparing routes: Holo4 variant and precision, hosted or self-managed environment, model and runtime versions, prompt, screenshots or other inputs, permission scope, step limit, retry policy and success criteria. Record the API rate snapshot or the local hardware and server configuration. If a retry policy or task input changes halfway through, record that as a separate run.
Track more than one outcome. Separate:
- attempted tasks;
- tasks that reached the exact expected state;
- partial completions;
- model or tool failures;
- runs that correctly stopped for a person;
- unsafe or out-of-scope actions;
- human corrections and reviewer minutes;
- token cost, local compute time, retries and external tool fees.
Then define a stop condition. A proposed policy might halt a run when the agent selects an unapproved record, encounters an unexpected permission prompt, is asked to send information externally, or cannot confirm the final state after a small fixed number of attempts. Choose those limits for the task and consequence. Do not present this example as a claim about Holo4 behavior.
If the hosted route and the local route are being compared, use the same task and acceptance criteria. The hardware budget, API invoice and support effort do not need to be identical, but record each separately. A price per million tokens can make two candidates look close while one consumes more screenshots, retries or human review. A local server can also carry an ongoing capacity and maintenance cost even on days when the agent is idle.
For a small pilot, a handful of tasks can expose setup problems but cannot establish a universal reliability rate. Repeat across distinct task instances and record the sample size. Preserve failed runs rather than quietly deleting them from the summary. If the evaluation changes after a bug fix, separate before and after results; do not merge them into a single score.
View image detailWhat a business should conclude from the launch
Holo4 is worth evaluating when a team has a real task that crosses an interface boundary or needs visual interaction, and the team can specify a safe, inspectable outcome. The launch gives developers model files, API access and benchmark trajectories to explore. It does not choose the appropriate license, approve a data flow, staff an inference service, or prove the model on a reader's own task.
If you need downloadable weights for commercial work, Holo4-35B-A3B is the checkpoint whose current card lists Apache 2.0. Verify the exact license and included dependencies. Holo4-27B is listed under CC BY-NC 4.0, so do not plan commercial use of those weights without separate permission. If you want hosted inference, evaluate the provider's current account terms separately from either weight license, and get written confirmation of the retention and training settings for your account, because H's public documents do not describe them the same way.
Then test one contained workflow and count the finished, verified result, not just the model's partial score. Track task cost and human oversight together. If no one owns the server, credentials, permission design and recovery process, self-hosting may not be a practical cost-saving path even when the weights are downloadable.
The model name is the first line of the decision, not the last. Rights, route, cost and review all have to fit the same job.
View image detailDisclosure: This is a source-based launch analysis. Holo4 tests described in the article are proposed, not performed by Rise Productive. Content reviewed against sources available October 1, 2026. Prices and access terms may change. H's public data-handling documents contain conflicting descriptions; this article does not determine which applies to a buyer. Confirm the executed agreement and account settings. License discussion is informational, not legal advice.
Checked for this article
Sources
- H Company, Holo4 launch pagehcompany.ai
- Holo4 team post on Hugging Facehuggingface.co
- Holo4-27B model cardhuggingface.co
- Holo4-35B-A3B model cardhuggingface.co
- H Platform local inference guidehub.hcompany.ai
- H Company pricinghcompany.ai
- H Company Terms of Usehcompany.ai
- H Company Privacy Policyhcompany.ai
- H Company data-processing addendumhcompany.ai
- Creative Commons Attribution-NonCommercial 4.0 legal codecreativecommons.org
- Apache License 2.0apache.org
- OSWorld 2.0 paperarxiv.org
- AutomationBench repository and benchmark notesgithub.com
- Unite.AI Holo4 launch coverageunite.ai
- Musthave.AI Holo4 license and evaluation analysismusthave.ai



