International agency opens demand estimation software

Update: 22 June 2023: This topic was previously titled “Legal status gaslighting by international agency”. But subsequent events meant that that descriptor was no longer accurate. The topic is now titled “International agency opens demand estimation software”. See posting 7 for background.


I am blogging a small incident because I think the underlying pattern will become more common as interest in open source gains prominence within the wider domain of national energy systems analysis. I also think a commitment to transparency includes a commitment to accuracy — and particular when the underlying discussions relate to public policy analysis.

This post involves the legal status of the MAED‑2 software developed in‑house by the International Atomic Energy Agency (IAEA). This tooling is used to project future demand profiles. A user manual is available:

Over the last weeks I have had intermittent traffic on this topic with four interested parties. One researcher at a COP‑27 side‑event described MAED‑2 as “open source” but when asked for details, admitted that this was an innocent error. Notwithstanding, no correction was issued. Then, following some discussions on the openmod list as to whether a selection process applied, I emailed the IAEA for details of the software license provided. The IAEA responded with the following release form (received 10 January 2023):

That document clearly offers the software under very restrictive terms and certainly implies that all applicants are subject to screening. Two signatures are required, including the head of the applicant organization. Moreover the IAEA “reserves the right to charge” under certain circumstances. And I am not sure if I would get just an executable or the source code as well.

I later had contact with an IAEA staff member (LS) on the legal circumstances surrounding MAED‑2 at a recent private meeting. LS claimed the tooling is “available [to anybody] for free”. I then pointed to the release form I received, to which LS then claimed that this form was merely to collect statistics on usage and not legally material.

So that is where the matter stands. And hence my decision to blog my experiences in the interests of transparency and accuracy. This posting records my opinions on the matter.

I would welcome contact from the IAEA but only if the facts can be agreed upon first. Moreover, I would be interested in hearing if anything in this posting needs correcting in any way. And if the IAEA really wishes to make their software transparent, usable, and reusable, they should consider uploading the codebase to a public repository under an OSI‑approved license (OSI being the Open Source Initiative.)

In many respects, I don’t think this kind of non‑open tooling presents much of a threat. I say that because if the functionality is useful to this community, the code will be developed more rapidly and more robustly than in‑house development can match, even for multilateral organizations. Indeed, there are already some open‑source examples.

Finally, I often strike this general kind of response from large scientific institutions, incumbent NGOs, government agencies, and international organizations. Indeed, I normally receive just a set of assertions without backup or analysis and without reference to any of the legal details I had raised. Sometimes I receive assurances that apply personally and not generally. All of which is why I headed this post “gaslighting”. R

5 Likes

@robbie.morrison, thanks for sharing the MAED-2 case. I think it’s really important for the open modelling community to clarify publicly. How else people will learn about it?

  • The Nigerian Integrated Energy Planning Tool was sold by McKinsey & co. as great open-source tool at a launch event, however, there is not even code accessible making it only an open accessible interface.

  • More recently ECMWF signed a project collaboration with DLR. In the public release of the collaboration they point out how great open-source and open data is and mentioned that they looking forward to work with EnDAT & REMIX, both used for energy planning. To my knowledge these tools are promised for over two years to be open-source but haven’t made it…

I think neither of the examples is bad in terms of being closed source, maybe even the opposite is true and the tools do a great job and help people. However, I think it’s not fair to mislead people with selling “freedom”, when they actually receive some time in “prison”.

Did someone else observe such falsely labelled open source or open data projects?

1 Like

I would normally be more circumspect about naming possible transgressors in public, but I have spent so much time getting run around that I need to be more aggressive in that regard.

The following topic is useful in relation to public data. It is not about non‑open but otherwise clear licensing, it is about unclear, ambiguous, and/or contradictory licensing terms, including legally debatable terms:

On that note, the threshold for 96/9/EC database protection now requires exposure to commercial risk. And additional contractual terms cannot override the statutory exceptions that are provided under copyright law by various European member states. Similar provisions exist in other jurisdictions.

There is one major official UK energy system model (that I won’t name because the facts are not entire clear to me) that was going to be published as open for some years now (yet I still cannot find the repo using a web search or by interrogating Software Heritage).

The TIMES model is now on GitHub with its license listed as “Unknown, GPL-3.0 licenses found”. The REUSE project offers good practice guidance in this respect, so there is really no excuse for getting license notifications wrong. Also just 3 closed issues reported so hardly an active open source project (and hence I won’t bother filing a new bug report).

Also worth recalling that the free and open source software movement more generally have invested huge effort in protecting the FOSS brand from false claims and non‑compliant behavior — as well as from copyright and patent trolls.

Finally, there are some open source claims that are indeed inadvertent mistakes.


UPDATE: 9 Feb 2023: The TIMES model on GitHub does have a complete GPL‑3.0‑or‑later license in a file named COPYING.txt which seems to be masked by a poorly structured file named LICENSE.txt. If this is indeed the case, the fix is trivial. The developers should also consider providing a explicit exception covering the use of the proprietary GAMS interpreter, rather than relying on implicit consent.

Hey Max. The goal is to be as open as possible with respect to the outcomes of the work (implemented workflows, methodologies, interfaces, etc.) However, the project doesn’t include working on EnDAT & REMIX directly. The decision to use a closed-source tool does not contradict our support for open source principles. Instead, a pragmatic approach is taken to achieving our goals while still contributing to the open source community through methodologies and interfaces.

@alexkies to me, the public release sounded misleading. I shared these thoughts also on LinkedIn. Some irritating sections:

DLR and its partners aim to uplift collaboration between the climate sciences and the energy sector to explore new approaches […] through open data and open modelling.

DLR’s key technology contribution. DLR will use some of its most advanced technology such as its ESM REMix, that will serve to implement the Demonstrator, the example case, showcasing how the energy system modelling community will benefit from DestinE. DLR’s also contributes with its data analysis tool EnDAT, that will be coupled to REMix, and the proposal will benefit from eye2sky, the unique radiation measurement network.

Regarding,

The decision to use a closed-source tool does not contradict our support for open source principles

Why not use open modelling from the beginning knowing they can achieve the same goals? This would also avoid the misleading article.

I appreciate your excellent work and that you share the support for open source and open data. The article is in the past, I hope you make the best out of the project, and I am looking very much forward to the really needed open data and open source contributions in that space :tada:

A major obstacle to opening legacy code can be identifying and locating the copyright holders and obtaining their consent for the new legal arrangements.

I am told that sorting out the legal status of such code can be surprisingly difficult. There are no shortcuts: one has to drill down into the provenance of every component. Moreover, one may need to completely reorganize (and retest) the codebase ecosystem to ensure the necessary legal partitioning is present.

The lawyers involved are normally overly cautious. And if one is unlucky, those same lawyers might not have sufficient background in intellectual property as it applies to computer programs and are reluctant, or perhaps even resistant, to unscramble this legal spaghetti.

If public money was used to build a road bridge that was barely used because its legal status remained vague, there would doubtless be an outcry. But when that public asset is instead code (or data) and no one can be much bothered to sort out the ownership and then license for reuse, next‑to‑no public clamber about the accompanying waste and duplication of effort (but perhaps some criticism over the intransparency).

This is not just about resources either — it is also about velocity. We have something like 27 years to reach net‑zero. Otherwise that bridge I mentioned earlier may need to be relocated in a somethat orderly albeit expensive fashion, or worse, be swept away during a modified weather event.

Scientific organizations should establish Open Source Program Offices (OSPO) to speed these processes. The European Commission has such an office, although I know nothing of its operation.

An interesting development is that the MAED software developed by IAEA has now been released by the Climate Compatible Growth project under a BSD 3-Clause License and is available on Github.


On a separate note, while it is not excusable to claim “open source” without actually being open source, I do have some sympathy for the often well-meaning individuals working within highly inflexible and restrictive organisations with conservative legal teams. In some cases, works may be developed under an open source license, but cannot be released due to some legal technicality. I think the idea of an Open Source Programme Office is a good one; but I suspect the challenge is that any organisation that realises they need such an office is probably already 80% there.

1 Like

I am trying to understand the current status of MAED. The GitHub repo has had no programming activity since the codebase was added on 10 March 2023, over two years back. Is this the active fork? It seems rather unusual for a framework to be so static in this context. Perhaps @willu47 or someone from CCG could comment? Best, R.

While examining the status of frameworks, can anyone shed light on the availability and licensing of FinPlan. There is a GitHub repo, again with no programming activity. I believe the software originates from the International Atomic Energy Agency (IAEA). There is a more recent manual listed on Zenodo, but no mention of availability or software licensing:

  • Tan, Naomi (13 April 2024). Model for financial analysis of electric sector expansion plans (FinPlan) manual. doi:10.5281/zenodo.10968558. CC‑BY‑4.0 (by virtue of being on Zenodo). :open_access:

Again, if anyone can offer some insights, that would be great. Best, R.

This discussion is now continuing on the openmod mailing list:

And more latterly, here:

It is important that the legal provenance of open‑source software is able to be verified for several reasons. The first is legal risk — both contributors and downstream users could be at risk from civil action by copyright holders and perhaps others if the software is not suitably licensed for third‑party development, use, and reuse. The second is regulatory risk — for example, the EU Cyber Resilience Act (CRA), taking full effect from December 2027, makes accurate code provenance and license compliance legally binding in certain circumstances for new or evolving open‑source projects distributed within the EU. The third is sector damage — open‑source communities rely on good faith across many dimensions and reporting the legal status of software accurately is a core component of that trust ethic. And the fourth is practical — if a codebase or project is not properly constituted and governed, there is no guarantee that it will be maintained or even persist.

This topic concerns the legal provenance of MAED (previously MAED‑2) and FINPLAN. I have completed my due diligence investigations for these two projects. And I could not establish that either is a genuine open‑source project made public under reliable licensing.

In contrast, the authors of this recent peer‑reviewed paper clearly state that MAED and FINPLAN are open‑source projects managed under the auspices of the International Atomic Energy Agency (see abstract and table 1):

However, despite repeated efforts and requests, I could not find any active public code repositories containing copyright and public license notices that I could trust. The respective project URLs provided earlier in this topic, repeated in Tan et al (2025:24), and elsewhere on Google Groups and LinkedIn postings by key individuals are completely inactive. The licenses currently reference the “IAEA” which, I was informed, stands for the International Atomic Energy Agency. It is not credible to me that the International Atomic Energy Agency would use anything other than its full legal name on a copyright notice of this importance. I made this point to two of the authors above and was not rebutted.

There has been no code development whatsoever in either repository in the three years since the “Initial commit from IAEA”. The activity logs show that the original software licenses were MIT copyright Climate Compatible Growth and dated 2023. These licenses were later replaced, without discussion or explanation, by BSD‑3‑Clause licenses copyright IAEA and also dated 2023. The original MAED‑2 software traces back to at least August 2000 and one might expect (other potential discrepancies notwithstanding) that that earlier copyright year would apply.

I was told in mid‑2025 that FINPLAN has a “large uptake” so it is not the case that this project has been abandoned. It has also been hinted to me that code development has been taking place in private repositories maintained by the IAEA. Tan et al (2025) describes active development and use for both projects — hardly consistent with the two completely static public repositories under discussion with just three downloads (technically forks) recorded for each (mine excluded) over three years.

I wrote twice to the International Atomic Energy Agency in Vienna, Austria by registered mail on 13 August 2025 and 10 December 2025 concerning the legal status of the MAED and FINPLAN codebases as hosted on the two URLs under discussion. I did not obtain replies.

I contacted everyone who was suggested to me that could assist with these issues and did not receive the information I desired. Furthermore, I was interested in working behind the scenes to find an appropriate resolution, but unfortunately that process fell apart. I have intentionally not mentioned individual names here because I don’t think that would be appropriate. However I believe everyone who was centrally involved has had sufficient opportunity to constructively respond and resolve the issues I have raised here and elsewhere.

This forum topic predates the two public repositories under discussion by five weeks.

To be clear, I am not categorically saying that legitimate open‑source repositories do not exist for MAED and FINPLAN — rather that, despite considerable effort and dialogue, I could not complete due diligence on the MAED and FINPLAN project repositories that I was either directed to or searched for.

In this situation, the burden of proof rests not with third parties to show that a project has or lacks legitimacy as an open‑source venture. Instead, the burden of proof should lie with the project that claims open‑source status to establish its legal credentials to some reasonable standard. And furthermore, if that project additionally claims to have an active development community, it should be able to reliably demonstrate both coding activity and effective governance.

If you have information on this matter that I am not aware of, please contact me via email, private message, or public reply. I am very willing to revise my assessment in light of new evidence or changed circumstances. I hope the issues I raise can be resolved — especially because it would seem that straightforward solutions are at hand.

The title of this topic should perhaps revert to something along the lines of its original Legal status gaslighting by international agency. I will however wait before modifying the title in case new developments do indeed arise.

Discussion is now continuing on the openmod mailing list:

It was suggested elsewhere that my two letters to the International Atomic Energy Agency requesting clarification are of no legal significance. A scan of my first letter is provided so that people can read the content for themselves:

There is no license notice present in the letter of course, but this file is duly made pubic under a Creative Commons CC‑BY‑4.0 license.

Below is my summary of the discussion today on the openmod mailing list (see link two posts back). Ultimately, I think it came down to this:

The two GitHub repositories are legally ‘legitimate’ because the only entity that can declare them definitively illegitimate is the International Atomic Energy Agency. However that agency has little incentive to do so. The agency would also not be concerned about passing off because the ‘IAEA’ copyright holder could be anyone. Representations in the README files stating that IAEA stands for International Atomic Energy Agency are not worth worrying about either.

The two GitHub repositories are completely inactive — neither has had a code revision for three years now. However, these repositories exist to provide academic fig‑leaves for the real projects for MAED and FINPLAN run in private repositories elsewhere.

Taken together, the IMPACCT project believes it can claim ‘genuine’ open‑source status. Of course, I don’t agree with this description on either legal or social grounds.

Until these issues are resolved, I advice researchers and other users to undertake their own careful due diligence processes if they wish to adopt or contribute to the wider IMPACCT project.

You should ask yourself who the IAEA copyright holder is and how you might contact them. These are standard good governance questions that you should be able to answer before becoming involved in any open source project.