AI-generated code · licensing

Copilot does not inherit the license. Your repo does.

Point-in-time senior review of copyleft, GPL-family, and incompatible OSS risk in Copilot, Cursor, and Claude Code output. Including generated snippets a lockfile scan never sees. Written findings. Not legal advice. Not a scanner dump.

AI-generated code licensing review for Copilot, Cursor, and Claude Code teams

Software composition analysis reads declared packages. Assistants also paste functions that never become a dependency. Maxiom’s AI-generated code licensing review is a productized, point-in-time inspection of a defined scope: lockfiles, vendored files, headers, and generated helpers that a scanner cannot attribute. Named engineer. Read-only access. Client code stays in your environment. Counsel still owns compatibility. We write what is in the tree. The editorial on why this gap exists is Copilot does not check the license. If the questionnaire is SOC 2 change management rather than copyleft, use the SOC 2 AI code audit. Broader security and architecture still start at the AI Code Audit.

2002
Founded
$100M+
Delivered
98%
Satisfaction

The problem

The scanner is green. Counsel is not done

Lockfile licenses are not lineage. Generated snippets never show up as a package. Diligence still asks who looked at the function body.

A GPL hit appeared and nobody owns the file

Git blame points at a staff engineer. The staff engineer points at Copilot. There is no flag. There is a payments helper in main.

The README claims MIT on a mixed tree

Generated docs survive because they sound finished. A buyer will ask for the header, the NOTICE file, and the product license. If those disagree, the document is the liability.

What we inspect

Lineage a counsel call can use. Not an SBOM dump.

Engineers with 10-plus years of production experience. Scope agreed up front. Since 2002, $100M+ in contract value, 221+ clients, Clutch-reviewed. That is delivery history, not a claim we audited your SPDX file last year.

Declared dependencies

Manifests, lockfiles, and transitive copyleft a first-party package pulled in

Generated snippets

Helpers that never became a named package, especially on payments, auth, and crypto paths

Vendored files and headers

GPL-family headers inside a tree that claims MIT or Apache

Hallucinated packages

Imports that later resolved to a registry identity nobody intended to take

Notices vs claims

NOTICE / LICENSE / README statements that disagree with what shipped

Written findings

Severity, path, why a scanner missed it, what to do next. Named engineer.

Free resource

AI-generated code licensing checklist

A practical review list for teams shipping with Copilot, Cursor, and other AI coding tools. Covering security, architecture, compliance, and code quality.

Declared dependencies

  • Lockfile and manifest licenses (npm, NuGet, PyPI, Go modules)
  • Transitive copyleft that a first-party package pulled in
  • Pins nobody would have typed by hand
  • Packages whose registry identity does not match the import the assistant invented

Generated snippets

  • Helpers that never became a named dependency
  • Vendored files with GPL, LGPL, or AGPL headers inside a permissive tree
  • License comments that disagree with the product license
  • Near-copy utilities on payments, auth, or crypto paths

Notices and attribution

  • NOTICE / LICENSE files vs what actually shipped
  • Generated READMEs that claim MIT or Apache on a mixed tree
  • Missing attribution on permissive code you are allowed to use
  • Headers stripped from files that still need them

Process evidence

  • Whether a scanner ran, and what it could not see
  • Who reviewed lineage, at what seniority
  • Exceptions written down vs reaction emoji
  • Counsel still owns compatibility. Engineering owns what is in the tree

Is this right for you?

The open-source folder in diligence

Counsel wants lineage, not a 40-page MIT/Apache dump. You need a senior pass on generated code before the next session.

The unexplained GPL hit

A scanner flagged a file nobody remembers adding. Copilot was on. You need to know whether it is an isolated helper or a pattern.

Enterprise exhibit on OSS

A buyer asked how AI coding tools affect your license posture. “We review every PR” is not the exhibit.

How an AI-generated code licensing review works

Kickoff

  1. 01

    Align

    Scoping · 30 minutes

    We map the product license you claim to ship, which assistants are in use, and which repos the diligence folder actually cares about.

    • Claimed product license
    • Copilot vs Cursor vs Claude Code
    • Repos and vendored paths

    You get: agreed licensing scope

  2. 02

    Access

    NDA · read-only

    Least-privilege repository access. We do not upload your tree to a license-detection model.

    • NDA before access
    • Read-only permissions
    • Your existing scanner output is welcome, not a substitute

    You get: a bounded intake

  3. 03

    Inspect

    Senior review

    Declared packages, generated snippets, headers, and notices against the license you say you ship.

    • Copyleft and proprietary magnets first
    • Paths a buyer would actually sample
    • Severity-ranked findings

    You get: lineage notes, not a legal opinion

  4. 04

    Debrief

    Report · next step

    Written report, live walkthrough with engineering and counsel if they join, and a split between hygiene (keep scanning) and inspection (what the scanner missed).

    • Written findings report
    • Live walkthrough
    • Optional full AI code audit if the questionnaire is broader

    You get: an artifact counsel can actually use

  • NDA signed before access
  • Read-only repository only
  • Senior engineers every time
  • Report in 10 business days

Frequently asked questions

What is an AI-generated code licensing review?

A fixed-scope senior inspection of whether Copilot, Cursor, Claude Code, or similar tools introduced copyleft, proprietary, or otherwise incompatible licensed material into your repository, including snippets that never appeared as a named package. Delivered as written findings, typically within 5–10 business days after read-only access.

Is this legal advice or a license opinion letter?

No. Engineering findings. Counsel decides whether you can ship, what notices are required, and how to remediate. If you need an opinion letter, that is a law firm. We tell you what is in the tree.

How is this different from running FOSSA, Black Duck, or an SBOM export?

Those tools are hygiene for declared dependencies. They do not read whether a generated helper is a close copy of GPL code that never became a package. Run the scanner. Do not hand it to a buyer as the license program.

How is this different from the AI Code Audit?

Same inspection model, access, and timeline. An AI code audit covers security, architecture, compliance, tests, and licensing. This landing is for teams whose forcing function is the open-source folder in diligence, a GPL hit they cannot explain, or an OSS exhibit. Both can convert into the same senior review if the scope widens.

Do you upload our source to a license-detection model?

No. Client code stays in client environments. Inspection is a named senior engineer. Scanners you already run can stay in CI.

Do we have to ban Copilot or Cursor?

No. You have to stop pretending a “we do not use GPL” paragraph describes a year of unreviewed assistant output. Ban the tools if you want. Inspect the tree either way.

What licenses do you look for?

Copyleft and proprietary are the diligence magnets (GPL, LGPL, AGPL, and similar). Permissive licenses (MIT, Apache, BSD) still need notices. We report what we find against the licenses you say the product ships under. We do not invent a forbidden-license list for a stack we have not scoped.

Will this help with M&A or enterprise diligence?

Yes. Buyers ask how you know AI-assisted code did not introduce licenses you cannot ship. A severity-ranked findings report from a named engineer is the artifact. A policy PDF is not.

We handle PHI. Can you still do this?

The copyleft question stays. The access model is not a generic SaaS review. Say PHI on the scoping call. Healthcare product work is Maxiom Labs (https://www.maxiomlabs.com/).

How do we start?

A 30-minute scoping call, then written scope and NDA. Read-only repository access. Initial findings typically within five business days after access, full report and debrief commonly inside 5–10 business days.

Need lineage on what Copilot already pasted, before counsel asks again?

Most reviews deliver findings within 5–10 business days after access. Start with a 30-minute scoping call. We will say if a scanner export is enough, or if it is not.

  • NDA signed before access
  • Read-only repository only
  • Senior engineers every time
  • Report in 10 business days