Who Owns The Model You Fine Tuned
You supplied the data and paid for the training run. That settles less about ownership than most people assume.

An organisation supplies its own data, pays for the compute, and ends up with a model that performs materially better on its work. The natural assumption is that it owns the result. In practice ownership splits three ways, and the contract usually addresses one of them.
Three things, three possible owners
The base model has a licence, and that licence governs what may be done with anything derived from it. Some permit commercial derivatives freely, some restrict redistribution, some restrict use above a scale threshold. This is settled before the organisation is involved and it is not negotiable with the supplier who fine tuned it.
The derived weights are new, created by the training run. Who owns them is a contract question with no default answer, and it is the one most often left silent.
The training data was the organisation's already. The live question is not ownership but what happened to it: whether any of it left the perimeter during training, whether the supplier retained a copy, and what obligations survive termination.
Why the derived weights matter more than they look
Fine-tuned weights encode something about how the organisation works. That is the point of producing them. It also means they are a durable representation of internal knowledge sitting in an artefact whose custody was never discussed.
Two questions follow, and both should be answered before the training run rather than after. If the relationship ends, may the organisation continue to run those weights, and on what licence. And may the supplier use anything learned from that run to improve what it offers to anyone else, including a competitor.
“The weights are not a by-product of the engagement. They are the part of it that encodes how you work.”
Where this gets uncomfortable
Suppliers who train on a shared base and improve it across customers have a legitimate business reason to want the second answer to be yes. Customers in regulated or competitive sectors have an equally legitimate reason to want it to be no. There is no universally correct position, but there is a wrong outcome, which is that neither party states theirs and both assume they won.
The clause to insist on
Name the three items separately. State who holds each, what happens to each at termination, and whether anything derived from the customer's data may inform work for anybody else. Three sentences, agreed at scoping, prevent the entire argument.
Where the model runs on the customer's own hardware and never leaves it, most of this simplifies, because the artefact is physically in their custody and the question becomes licensing rather than retrieval. That is a reason to prefer that architecture that has nothing to do with security.