Skip to content

Legal and IP questions about agent-written code

Agent-written code raises five legal questions: who owns it, whether it carries third-party licenses, what the vendor’s indemnity covers, which data terms govern the code the agent reads, and what client and employment contracts promise about it. The tool settles none of them. Each is a question for counsel, backed by controls your engineers can prove.

A prospective client’s master services agreement arrives with a warranty that every deliverable is “original work of the Supplier” and a clause banning “generative AI” without written consent. Your engineers open most pull requests through Claude Code, Codex or Cursor, sales wants to sign by Friday, and nobody knows whether the vendor’s indemnity would cover a license claim.

This page is for the executive who signs that contract and the CTO who makes its promises true. It is an engineering reading of vendor terms and public legal sources, not legal advice: take the checklist to counsel.

Most confusion comes from mixing the contract answer with the copyright answer.

The contract answer is clear. Anthropic’s Commercial Terms say the customer “owns its Outputs”, and Anthropic “hereby assigns to Customer its right, title and interest (if any) in and to Outputs.” GitHub’s Generative AI Services Terms say “GitHub does not own Inputs or Outputs.”

The copyright answer depends on human authorship. A vendor can only assign rights that exist, hence “(if any)”.

  • In the United States, the Copyright Office’s report Copyright and Artificial Intelligence, Part 2: Copyrightability (29 January 2025) concludes that copyright protects only human authorship, that prompts alone do not make output human-authored, and that human selection, arrangement and creative modification of outputs can be protected. The Supreme Court declined to hear Thaler v. Perlmutter on 2 March 2026, which leaves in place the appeals court ruling that a work needs a human author (secondary: Holland & Knight and Mayer Brown client alerts, March 2026).
  • In the EU, the Software Directive (2009/24/EC, Article 1(3)) protects a computer program if it is “the author’s own intellectual creation”. Poland’s copyright act protects a “manifestation of creative activity of individual character” by a creator. How much human specification, review and editing makes agent output qualify is a question for counsel.

In practice, your code stays yours to use, sell and license. What may be weaker is your ability to stop others copying the purely machine-written parts. Three things carry the protection instead:

ProtectionWhat it coversWhat your team does
The human contributionSpecifications, architecture, acceptance tests, and the selection and editing of agent outputKeep specs, plans and acceptance criteria in the repository, versioned next to the code
Trade secretSource that is never publishedAccess control, confidentiality clauses, and commercial-tier data terms for every agent session
ContractWhat clients, contractors and employees may do with the codeThe clauses in the table further down

Can agent-written code carry someone else’s license?

Section titled “Can agent-written code carry someone else’s license?”

Yes, by two routes, and they need different controls.

Route 1: dependencies the agent adds. A package brings its license, and the agent does not check your allowlist unless something forces it. This is the common route, and CI can block it.

Route 2: code the agent reproduces. A model can emit code close to its training data, with or without the original license header. Depending on policy, GitHub Copilot discards suggestions that match public code or shows them with a code reference (code referencing docs source, checked 2026-09-26). Elsewhere, your own scan is the only check.

  1. Gate dependency changes on every pull request. This workflow fails any pull request that adds a dependency whose license is outside your allowlist. On private repositories, actions/dependency-review-action needs GitHub Advanced Security; on other platforms, run an equivalent license check against the lockfile diff.

    .github/workflows/license-gate.yml
    name: License gate
    on: [pull_request]
    permissions:
    contents: read
    jobs:
    dependency-review:
    runs-on: ubuntu-latest
    steps:
    - uses: actions/checkout@v7
    with:
    persist-credentials: false
    - uses: actions/dependency-review-action@v5
    with:
    allow-licenses: MIT, Apache-2.0, BSD-2-Clause, BSD-3-Clause, ISC

    Counsel sets the allowlist; the platform team encodes it. The dependency verification guide covers invented and typosquatted packages, which the same gate helps catch.

  2. Scan the source itself on a schedule. ScanCode Toolkit (Apache-2.0 code; 32.5.0 on PyPI, checked 2026-09-26) finds license texts and notices that an agent copied into your files:

    Terminal window
    # terminal or scheduled CI job
    pip install scancode-toolkit
    scancode --license --json-pp license-scan.json src/

    For snippet-level matches against open-source code, SCANOSS (pip3 install scanoss, MIT, 1.54.2 on PyPI) runs scanoss-py scan -o results.json src. It sends file fingerprints to the SCANOSS API (api.osskb.org by default), so clear that with your security team first.

  3. Route every finding to a human. A new license or a snippet match goes to a named owner who removes it, rewrites it, or records the required attribution.

Contributing upstream is its own case, because projects set different rules. QEMU’s code provenance policy declines “any contributions which are believed to include or derive from AI generated content”. The Linux kernel’s AI coding assistants guidance accepts them, says agents “MUST NOT add Signed-off-by tags”, and asks for an Assisted-by: tag. Read the policy before a patch goes out under your company’s name.

What do vendor indemnities actually cover?

Section titled “What do vendor indemnities actually cover?”

An indemnity is the vendor’s promise to defend you if a third party claims the tool or its output infringes their rights. The exclusions matter more than the headline.

Vendor terms (checked 2026-09-26)What is defendedExclusions and conditions that matter for code
Anthropic Commercial Terms (Claude Code on Team, Enterprise and the API)Third-party claims that “Customer’s paid use of the Services … in accordance with these Terms or Outputs generated through such authorized use” infringe IPNot covered: modifications the customer made to outputs, combinations with non-Anthropic technology, customer-provided inputs, use the customer knew or should have known was infringing, practising patented inventions in outputs, and trademark use of outputs in commerce
GitHub Generative AI Services Terms (Copilot)“If your Agreement provides for the defense of third party claims, that provision will apply to your use of Generative AI Services, including to Outputs”Only as good as your own GitHub agreement’s defence clause; read that agreement, not only these terms
OpenAI (Codex) and Anysphere (Cursor)Not verified here: both terms pages were unreachable on 2026-09-26Ask for the terms that apply to your plan, and read the indemnity and its exclusions against this table before you rely on any defence

Almost every shipped change is modified by an engineer and combined with other software, which is what the Anthropic exclusions name. Counsel decides how much of your delivered code the indemnity still reaches, and that sets whether you can offer clients any IP indemnity at all.

Which data terms govern the code the agent reads?

Section titled “Which data terms govern the code the agent reads?”

Every agent session sends code to a model provider, and the account the engineer logged in with, not the tool, decides which terms govern it.

For Claude Code, the data usage page states the split (checked 2026-09-26):

AccountTrainingRetention
Consumer: Free, Pro, MaxUsed to train new models when the user’s model-improvement setting is on5 years with that setting on, 30 days with it off
Commercial: Team, Enterprise, API, third-party platforms“Anthropic does not train generative models using code or prompts sent to Claude Code under commercial terms”, unless the customer opts in, for example through the Development Partner Program30 days standard; zero data retention for qualified Claude for Enterprise accounts, enabled per organization

Three details surprise legal teams. Transcripts sent with /feedback (and /bug and /share, which use the same path) are retained for 5 years. Answering “Yes” to the follow-up question after a session-quality survey uploads the transcript, any subagent transcripts and the raw session log, which are kept for up to 6 months. And Claude Code keeps session transcripts locally in plaintext under ~/.claude/projects/ for 30 days by default, adjustable with cleanupPeriodDays. GitHub’s terms say it “will not use Inputs or Outputs to train generative AI models, unless you have given us documented instructions to do so.”

The control that matters is forcing work accounts. Put it in managed configuration that your device management deploys, then check where it leaks:

In managed-settings.json, allow only claude.ai logins and pin them to your organization. forceLoginOrgUUID is enforced only when it comes from a managed source, and it also blocks sessions started with a personal ANTHROPIC_API_KEY.

{
"forceLoginMethod": "claudeai",
"forceLoginOrgUUID": "ORG_UUID",
"env": {
"DISABLE_FEEDBACK_COMMAND": "1",
"CLAUDE_CODE_DISABLE_FEEDBACK_SURVEY": "1"
}
}

ORG_UUID is your organization ID from the claude.ai admin settings. The two env keys close the /feedback and survey upload routes. Three gaps remain, per Anthropic’s authentication page (checked 2026-09-26): the /login screen still lets a developer complete a Console login; claude setup-token and /install-github-app enforce only the login method, so they can mint a token in another organization; and Console logins pre-select the organization without checking it. Managed sources do not merge, so if you also use server-managed settings, set these keys there too. Traffic through Amazon Bedrock or Google Cloud’s Agent Platform (formerly Vertex AI) falls under that cloud’s terms; see where the model runs.

The privacy and data-handling policy covers data classification, and enforcing one policy across every agent covers deploying managed settings to every machine.

Which client and employment clauses need a second look?

Section titled “Which client and employment clauses need a second look?”

Contracts written for code people typed make promises agent-written code may not keep. Hand these clauses to counsel.

ContractClauseThe risk once agents write codeWhat to ask counsel for
Client MSA or SOWOriginality or “sole authorship” warrantyMay be untrue for machine-written partsWarrant your process and assign rights “if any” instead
Client MSA or SOWBan or consent requirement for “generative AI”You may already be in breachWritten consent naming the tools, accounts and data routes
Client MSA or SOWConfidentiality and subprocessorsClient code reaches a model providerName the model vendors as subprocessors, and list permitted data classes
Client MSA or SOWIP indemnityUncapped, backed only by your own conductA cap, and no pass-through of vendor indemnities
Customer contracts you sell underOpen-source and license warrantyAgent-added dependencies or snippetsA warranty tied to a license scan and an SBOM per release
Employment and contractor agreementsIP assignmentWritten for “works created by the employee”Assignment that covers specifications, prompts, rules files and AI-assisted work product
Contributor or open-source policyUpstream contributionsProject policies differ; some decline AI contentA rule that the engineer reads each project’s policy and signs off personally

Check contractor agreements as closely as employment ones. In some jurisdictions, Poland among them, an assignment covers only the fields of exploitation it lists, so whether it reaches prompts and rules files is a question for counsel.

Book one hour with counsel. Bring this list and the evidence in the right-hand column, so the meeting is about decisions, not discovery. An executive who will not sit in that meeting can hold the CTO to three of the answers: which account types reach our code, what each vendor’s indemnity excludes for code we modify, and when the terms were last read and by whom.

#Question for counselEvidence your team brings
1In our jurisdictions, how much human contribution makes agent-assisted code protectable, and what should we record to show it?A sample change with its spec, plan, acceptance tests and review record
2Does our ownership warranty to clients hold for agent-written code, and what wording replaces it?Current MSA and SOW templates
3Which client contracts restrict or require consent for AI tools, and are we in breach of any today?List of active contracts, and which tools touched each client’s code
4Which licenses go on the dependency allowlist, and which need case-by-case review?Current dependency license inventory
5What do we do when a scan finds reproduced code: remove, rewrite or attribute?One real scan result
6For each vendor, how much of our delivered code does the indemnity reach, given its exclusions?The vendor terms and order forms in force today, with the date read
7Can we offer clients any IP indemnity, and at what cap?Revenue per contract and current indemnity caps
8Do the vendors’ data terms meet our confidentiality duties to clients and our GDPR role?Account types in use, the managed-settings files, retention settings
9Must we name model vendors as subprocessors, and who notifies clients?The vendor subprocessor lists and your DPA templates
10Do employment and contractor agreements assign AI-assisted work, including prompts and rules files?Current agreement templates
11What is our policy for agent-written contributions to open-source projects?Projects you contribute to, with their AI policies
12Which terms must be re-read, by whom and how often?A terms register: vendor, document, version, date read, owner

Counsel owns the answers; the CTO owns the evidence and records each decision next to its question.

These prompts prepare evidence for counsel. Run the first in the repository with any agent, and the other two with the documents attached.

Section titled “How do you prove the legal position holds?”

A position agreed with counsel decays as tools, terms and contracts change. These controls keep it true without anyone reading every diff:

ControlWhat it provesOwnerCadence
License gate in CINo dependency outside the allowlist mergesPlatform teamEvery pull request
Source license and snippet scanNo reproduced third-party code or stray license text sits unreviewedPlatform team; findings to a named ownerMonthly and before each release to a client
Provenance trailersWhich changes an agent co-wrote, for audits and client questionsTech leadsEvery commit
Managed login settingsCompany code never runs under consumer termsPlatform teamChecked on every machine by your device management
Terms registerEvery vendor document in force, its version and the date someone read itCTO, with counselQuarterly, and whenever a vendor announces a change
Evidence bundle per releaseWhat was verified, including the scans aboveTech lead signsEvery release

Claude Code adds a Co-Authored-By trailer to commits unless the attribution setting changes it, so do not set attribution to false or attribution.commit to an empty string in shared settings (checked in Claude Code 2.1.283). For other tools, ask for an Assisted-by: trailer in your pull request template.

Sign-off: counsel approves the allowlist, clause wording and terms register; the CTO signs that the controls run; the executive confirms client contracts use the approved clauses.

Section titled “What goes wrong with legal and IP for agent-written code?”

An engineer uses a personal account on client code. The code now sits under consumer terms the client contract never contemplated. Recovery: counsel decides whether the confidentiality clause requires notice; delete the sessions where the vendor allows it; enforce managed login settings.

A GPL dependency ships in a proprietary product. The agent added it and CI had no license gate. Recovery: replace it, establish with counsel what was distributed and to whom, then add the gate and scan every repository.

Sales promises clients the vendor’s indemnity. Recovery: withdraw the wording, map which signed contracts carry it, and let counsel decide whether to renegotiate.

An upstream project rejects or removes your patch. Nobody read its AI policy. Recovery: withdraw the contribution, apologise to the maintainers, and add the rule to your AI usage policy.

Attribution is switched off to make commits “look clean.” Provenance is lost exactly when an auditor asks for it. Recovery: restore the default in managed settings; history cannot be reconstructed reliably.

This page is further reading on the executive track. Next, get these terms in writing with the procurement questionnaire.

Frequently asked questions

Who owns code that a coding agent writes?

The vendor terms checked on 2026-09-26 give the output to the customer: Anthropic assigns its rights in outputs to the customer, 'if any', and GitHub says it does not own outputs. Whether copyright exists in the output depends on human authorship, which the US Copyright Office and US courts require, so protection rests on the human contribution, trade secrets and contracts.

Does a vendor indemnity cover the code we deliver to clients?

Often only partly. Anthropic's Commercial Terms defend paid use and its outputs, but exclude outputs the customer modified and combinations with non-Anthropic technology. GitHub's generative AI terms apply whatever defence clause your own agreement already has. Counsel should read the exclusions against how your code is actually built.

Can an agent bring GPL code into a proprietary codebase?

Yes, through two routes: dependencies it adds, and code it reproduces. A license gate on dependency changes in CI and a periodic snippet or license-text scan catch both, and a human approves any new license outside the allowlist.

Is our code used to train the vendor's models?

Under commercial terms, not by default for the vendors checked: Anthropic does not train on Claude Code data sent under commercial terms, and GitHub does not train on inputs or outputs without documented instructions. Consumer plans differ, so the control that matters is forcing work accounts.