Loading the catalogue…
Loading the catalogue…
MiniMax is a Shanghai-headquartered, publicly listed Chinese AI lab producing both fully open (Apache/MIT) and custom-licensed 'open-weight' models, alongside consumer apps (Hailuo, Talkie) and an enterprise API. It is not CLOUD Act exposed, but as a PRC-incorporated entity its data and models fall under China's Cybersecurity Law, Data Security Law and PIPL, and it currently has no first-party inference endpoint on Stav. EU regulated customers should weigh active US copyright litigation (Disney/Universal/WBD), a recent Anthropic data-harvesting accusation, and inconsistent open-source licensing terms alongside its rapid model release cadence.
As a PRC-incorporated company, MiniMax is subject to China's Cybersecurity Law, Data Security Law, and PIPL, which include data localisation and government access provisions for national security purposes; China has no EU adequacy decision, so cross-border transfers require SCCs or equivalent safeguards.
Active US copyright infringement lawsuit (Disney, Universal, Warner Bros. Discovery) alleging MiniMax's Hailuo AI service was trained on and generates unauthorized copyrighted characters; MiniMax's motion to dismiss was denied in May 2026 and the case is proceeding to discovery.
Anthropic publicly accused MiniMax of running a fraudulent-account campaign to harvest over 16 million Claude interactions for model distillation (February 2026), raising questions about MiniMax's data-sourcing practices and potential downstream model quality/safety concerns.
Newer 'open-weight' model licences (e.g. M2.7/minimax-community) restrict commercial/enterprise use and require direct permission from MiniMax, creating licence-compliance uncertainty for enterprise deployments despite being marketed as open weights.
No published EU AI Act compliance statement, GPAI training-data summary, or Code of Practice engagement was found for MiniMax, despite EU AI Act GPAI transparency obligations beginning to bite in 2026.
Stav’s assessment
Editorial assessment, not legal advice. Stav's risk ratings, scores, and verdicts are our own analysis of publicly available information and may be incomplete or out of date. Verify independently before making compliance or procurement decisions.
MiniMax has published fully open-weight, permissively licensed models (MiniMax-M1 under Apache 2.0, MiniMax-M2 under MIT), including detailed model cards, deployment guides, and benchmark methodology on HuggingFace.
MiniMax staff actively and directly respond to community criticism about licensing terms on public HuggingFace discussion threads rather than ignoring feedback.
MiniMax completed a Hong Kong Stock Exchange listing in January 2026, subjecting it to public-market disclosure requirements and providing an additional layer of financial transparency compared to private AI labs.
MiniMax's enterprise API privacy policy explicitly references GDPR rights (access, objection to marketing, limiting processing) and cites an EU-US Privacy Framework certification for the data center it uses, indicating at least a self-declared attempt at GDPR-aligned practices for enterprise customers.
Published safeguards & certifications