Most funders publish open access policies and then wait. The Bill & Melinda Gates Foundation built a compliance machine instead. Its checks are the least glamorous corner of the foundation's open access operation, but they are where the policy stops being an aspiration and turns into an audit. A policy without verification is a suggestion, and scholarly publishing has treated suggestions as optional for two decades.
The foundation has demanded immediate open access for funded research since 2015. From 1 January 2025, that demand got sharper: grantees must now post a preprint under an open licence before or at journal submission. Compliance now runs on metadata, not trust. The system looks for a preprint record, a Creative Commons Attribution licence on the final article, and an embargo field that says zero.
The licence and the preprint are the easy parts
The Bill & Melinda Gates Foundation's Open Access Policy applies to peer-reviewed articles, book chapters, monographs, and case reports funded in whole or in part by the foundation. Since 2015, the rule has been blunt: make the publication freely available immediately, with no embargo, under the Creative Commons Attribution 4.0 International License, known as CC BY 4.0, or an equivalent licence. Anyone may share and adapt the work, including for commercial use, provided the original author is credited. The foundation pays reasonable open access fees.
The 2025 preprint duty adds a second checkpoint. A manuscript based on Gates-funded research must be deposited on an approved preprint server under CC BY before or at the time of submission to a peer-reviewed journal. If the journal requires a different licence for the preprint, that does not satisfy the funder's demand. The final version of record must still be immediate open access under CC BY 4.0.
Then there is the clause that gets less attention: underlying data and code necessary to reproduce the findings must be available immediately and without restrictions. That clause is harder to audit than a licence field, and the gap matters.
How the checks work under the hood
The foundation does not usually read every accepted manuscript. It matches grant numbers and author identifiers against publication records in Crossref, PubMed, preprint indexes, and publisher feeds. The machine-readable fields that matter most are the licence URL, the publication date, the article type, and the repository deposit date. The official Gates Foundation open access policy page sets out what authors must do; the compliance system checks whether those instructions left a trace.
Publishers do not always make that trace easy to find. Some deposit incomplete licence metadata into Crossref, some place the CC BY banner on the HTML page but leave the machine-readable field empty, and some use embargoed versions that complicate the check. The foundation has learned, as have other funders, that a paper can be publicly readable and still look non-compliant to an automated system.
For researchers who want a direct route through the policy, Gates Open Research is the foundation's own publishing venue, with open peer review and post-publication comments built around the same requirements.
Here's the catch
Compliance checks are excellent at confirming that a licence field says CC BY. They are far less reliable at telling you whether the article is genuinely reusable, discoverable, or accompanied by enough data to reproduce the result.
A preprint record is a thin artefact. A group can post a preprint with missing tables, no underlying code, no linked data, and a simplistic analysis; the metadata will still satisfy the funder. A final article can carry CC BY while sitting in a journal that charges for reprints and supplies fragmented data deposition links. The check passes; the reader's problem does not disappear.
The automated system also rewards metadata literacy. An early-career researcher without an ORCID iD, with a mistyped grant number, or with a repository deposit that predates the final version can fail a check even when the paper is openly available. That burden lands on authors already stretched by peer review and teaching, and it turns a publishing policy into an administrative skill test.
Data and code requirements remain the soft spot. The same pattern has appeared in other funder enforcement efforts, including the NIH and EU data-sharing mandates. Licences are cheap to verify; data completeness is expensive. A compliance programme that over-indexes on the cheap check will report a very high pass rate while missing exactly the areas where scientific transparency is weakest.
What grantees should do before the flag arrives
Most compliance problems start with metadata, not intent. The practical steps are unglamorous and effective.
- Register an ORCID iD and use it consistently in submissions and preprint deposits.
- Post the preprint early, under CC BY 4.0, on a server indexed by the foundation's checks.
- Confirm that the chosen journal will deposit a correct licence field into Crossref and will not require an embargo on the version of record.
- Keep the grant number consistent across the final manuscript, the preprint, the repository record, and the publisher's version.
- Deposit data and code in a repository with a stable identifier at the time of publication, not three months later.
Libraries and research offices can help by reading the foundation's policy as a workflow problem rather than a legal threat. Institutions that build preprint deposit and licence-checking into grant closeout reduce the number of last-minute compliance scrambles. The same administrative discipline helps whether a researcher is funded by Gates, the European Research Council, or a national agency with similar rules.
Hype and reality, graded
Hype: the compliance system is a decisive blow for open access. Reality: it is a decisive blow against bad metadata, which is not the same thing. Open access has always had a metadata problem; many articles described as open leave no machine-readable trace. Fixing that trace is genuinely useful, but it does not by itself change how researchers read or build on published work.
Hype: preprint mandates guarantee early access. Reality: a preprint is a version, not a publication. It can be withdrawn, revised, or orphaned. The value of a preprint mandate depends on whether the preprint contains enough to be useful and whether the peer-reviewed version is linked to it. If publishers and authors fail to connect the two, the preprint becomes another orphaned object in the repository.
The preprint duty also aligns with a broader shift. Preprint overlay journals and other experiments are testing whether peer review can be separated from journal publication, as preprint overlay journals now do. The Gates Foundation works alongside other funders in cOAlition S, whose Plan S framework pushed the same direction on immediate open access. That is where the policy's second-order effects may be largest.
Last word
Open access policy is not the same as open knowledge. Peter Suber has argued for years that a policy is an instrument, not an outcome; it only works if implementation carries the intent. The Gates Foundation's compliance checks matter because they treat policy as something to be verified. But the last word belongs to the researchers who have to clear that bar. They need the administrative support to pass the check without losing time they could have spent on the science the policy was written to speed up.
Photo by Finde Zukunft on Unsplash
