Legal and IP questions about agent-written code
Agent-written code raises five legal questions: who owns it, whether it carries third-party licenses, what the vendor’s indemnity covers, which data terms govern the code the agent reads, and what client and employment contracts promise about it. The tool settles none of them. Each is a question for counsel, backed by controls your engineers can prove.
A prospective client’s master services agreement arrives with a warranty that every deliverable is “original work of the Supplier” and a clause banning “generative AI” without written consent. Your engineers open most pull requests through Claude Code, Codex or Cursor, sales wants to sign by Friday, and nobody knows whether the vendor’s indemnity would cover a license claim.
This page is for the executive who signs that contract and the CTO who makes its promises true. It is an engineering reading of vendor terms and public legal sources, not legal advice: take the checklist to counsel.
Who owns code a coding agent writes?
Section titled “Who owns code a coding agent writes?”Most confusion comes from mixing the contract answer with the copyright answer.
The contract answer is clear. Anthropic’s Commercial Terms say the customer “owns its Outputs”, and Anthropic “hereby assigns to Customer its right, title and interest (if any) in and to Outputs.” GitHub’s Generative AI Services Terms say “GitHub does not own Inputs or Outputs.”
The copyright answer depends on human authorship. A vendor can only assign rights that exist, hence “(if any)”.
- In the United States, the Copyright Office’s report Copyright and Artificial Intelligence, Part 2: Copyrightability (29 January 2025) concludes that copyright protects only human authorship, that prompts alone do not make output human-authored, and that human selection, arrangement and creative modification of outputs can be protected. The Supreme Court declined to hear Thaler v. Perlmutter on 2 March 2026, which leaves in place the appeals court ruling that a work needs a human author (secondary: Holland & Knight and Mayer Brown client alerts, March 2026).
- In the EU, the Software Directive (2009/24/EC, Article 1(3)) protects a computer program if it is “the author’s own intellectual creation”. Poland’s copyright act protects a “manifestation of creative activity of individual character” by a creator. How much human specification, review and editing makes agent output qualify is a question for counsel.
In practice, your code stays yours to use, sell and license. What may be weaker is your ability to stop others copying the purely machine-written parts. Three things carry the protection instead:
| Protection | What it covers | What your team does |
|---|---|---|
| The human contribution | Specifications, architecture, acceptance tests, and the selection and editing of agent output | Keep specs, plans and acceptance criteria in the repository, versioned next to the code |
| Trade secret | Source that is never published | Access control, confidentiality clauses, and commercial-tier data terms for every agent session |
| Contract | What clients, contractors and employees may do with the code | The clauses in the table further down |
Can agent-written code carry someone else’s license?
Section titled “Can agent-written code carry someone else’s license?”Yes, by two routes, and they need different controls.
Route 1: dependencies the agent adds. A package brings its license, and the agent does not check your allowlist unless something forces it. This is the common route, and CI can block it.
Route 2: code the agent reproduces. A model can emit code close to its training data, with or without the original license header. Depending on policy, GitHub Copilot discards suggestions that match public code or shows them with a code reference (code referencing docs source, checked 2026-09-26). Elsewhere, your own scan is the only check.
-
Gate dependency changes on every pull request. This workflow fails any pull request that adds a dependency whose license is outside your allowlist. On private repositories,
actions/dependency-review-actionneeds GitHub Advanced Security; on other platforms, run an equivalent license check against the lockfile diff..github/workflows/license-gate.yml name: License gateon: [pull_request]permissions:contents: readjobs:dependency-review:runs-on: ubuntu-lateststeps:- uses: actions/checkout@v7with:persist-credentials: false- uses: actions/dependency-review-action@v5with:allow-licenses: MIT, Apache-2.0, BSD-2-Clause, BSD-3-Clause, ISCCounsel sets the allowlist; the platform team encodes it. The dependency verification guide covers invented and typosquatted packages, which the same gate helps catch.
-
Scan the source itself on a schedule. ScanCode Toolkit (Apache-2.0 code; 32.5.0 on PyPI, checked 2026-09-26) finds license texts and notices that an agent copied into your files:
Terminal window # terminal or scheduled CI jobpip install scancode-toolkitscancode --license --json-pp license-scan.json src/For snippet-level matches against open-source code, SCANOSS (
pip3 install scanoss, MIT, 1.54.2 on PyPI) runsscanoss-py scan -o results.json src. It sends file fingerprints to the SCANOSS API (api.osskb.orgby default), so clear that with your security team first. -
Route every finding to a human. A new license or a snippet match goes to a named owner who removes it, rewrites it, or records the required attribution.
Contributing upstream is its own case, because projects set different rules. QEMU’s code provenance policy declines “any contributions which are believed to include or derive from AI generated content”. The Linux kernel’s AI coding assistants guidance accepts them, says agents “MUST NOT add Signed-off-by tags”, and asks for an Assisted-by: tag. Read the policy before a patch goes out under your company’s name.
What do vendor indemnities actually cover?
Section titled “What do vendor indemnities actually cover?”An indemnity is the vendor’s promise to defend you if a third party claims the tool or its output infringes their rights. The exclusions matter more than the headline.
| Vendor terms (checked 2026-09-26) | What is defended | Exclusions and conditions that matter for code |
|---|---|---|
| Anthropic Commercial Terms (Claude Code on Team, Enterprise and the API) | Third-party claims that “Customer’s paid use of the Services … in accordance with these Terms or Outputs generated through such authorized use” infringe IP | Not covered: modifications the customer made to outputs, combinations with non-Anthropic technology, customer-provided inputs, use the customer knew or should have known was infringing, practising patented inventions in outputs, and trademark use of outputs in commerce |
| GitHub Generative AI Services Terms (Copilot) | “If your Agreement provides for the defense of third party claims, that provision will apply to your use of Generative AI Services, including to Outputs” | Only as good as your own GitHub agreement’s defence clause; read that agreement, not only these terms |
| OpenAI (Codex) and Anysphere (Cursor) | Not verified here: both terms pages were unreachable on 2026-09-26 | Ask for the terms that apply to your plan, and read the indemnity and its exclusions against this table before you rely on any defence |
Almost every shipped change is modified by an engineer and combined with other software, which is what the Anthropic exclusions name. Counsel decides how much of your delivered code the indemnity still reaches, and that sets whether you can offer clients any IP indemnity at all.
Which data terms govern the code the agent reads?
Section titled “Which data terms govern the code the agent reads?”Every agent session sends code to a model provider, and the account the engineer logged in with, not the tool, decides which terms govern it.
For Claude Code, the data usage page states the split (checked 2026-09-26):
| Account | Training | Retention |
|---|---|---|
| Consumer: Free, Pro, Max | Used to train new models when the user’s model-improvement setting is on | 5 years with that setting on, 30 days with it off |
| Commercial: Team, Enterprise, API, third-party platforms | “Anthropic does not train generative models using code or prompts sent to Claude Code under commercial terms”, unless the customer opts in, for example through the Development Partner Program | 30 days standard; zero data retention for qualified Claude for Enterprise accounts, enabled per organization |
Three details surprise legal teams. Transcripts sent with /feedback (and /bug and /share, which use the same path) are retained for 5 years. Answering “Yes” to the follow-up question after a session-quality survey uploads the transcript, any subagent transcripts and the raw session log, which are kept for up to 6 months. And Claude Code keeps session transcripts locally in plaintext under ~/.claude/projects/ for 30 days by default, adjustable with cleanupPeriodDays. GitHub’s terms say it “will not use Inputs or Outputs to train generative AI models, unless you have given us documented instructions to do so.”
The control that matters is forcing work accounts. Put it in managed configuration that your device management deploys, then check where it leaks:
In managed-settings.json, allow only claude.ai logins and pin them to your organization. forceLoginOrgUUID is enforced only when it comes from a managed source, and it also blocks sessions started with a personal ANTHROPIC_API_KEY.
{ "forceLoginMethod": "claudeai", "forceLoginOrgUUID": "ORG_UUID", "env": { "DISABLE_FEEDBACK_COMMAND": "1", "CLAUDE_CODE_DISABLE_FEEDBACK_SURVEY": "1" }}ORG_UUID is your organization ID from the claude.ai admin settings. The two env keys close the /feedback and survey upload routes. Three gaps remain, per Anthropic’s authentication page (checked 2026-09-26): the /login screen still lets a developer complete a Console login; claude setup-token and /install-github-app enforce only the login method, so they can mint a token in another organization; and Console logins pre-select the organization without checking it. Managed sources do not merge, so if you also use server-managed settings, set these keys there too. Traffic through Amazon Bedrock or Google Cloud’s Agent Platform (formerly Vertex AI) falls under that cloud’s terms; see where the model runs.
In the managed requirements.toml that your administrator deploys, allow only ChatGPT sign-in and only your workspace (keys checked in codex-cli 0.157.1 source):
allowed_login_methods = ["chatgpt"]allowed_chatgpt_workspaces = ["WORKSPACE_ID"]WORKSPACE_ID is your ChatGPT Business or Enterprise workspace ID. Use ["api"] for teams on API keys. OpenAI’s data terms could not be read on 2026-09-26: get them in writing during procurement.
Cursor’s privacy and retention settings could not be verified on 2026-09-26 because cursor.com was unreachable. Ask Anysphere in writing which plan setting keeps code out of training and retention, whether an administrator can enforce it for every member, and whether it covers each model you allow. Then check the admin console and record what you saw and when.
The privacy and data-handling policy covers data classification, and enforcing one policy across every agent covers deploying managed settings to every machine.
Which client and employment clauses need a second look?
Section titled “Which client and employment clauses need a second look?”Contracts written for code people typed make promises agent-written code may not keep. Hand these clauses to counsel.
| Contract | Clause | The risk once agents write code | What to ask counsel for |
|---|---|---|---|
| Client MSA or SOW | Originality or “sole authorship” warranty | May be untrue for machine-written parts | Warrant your process and assign rights “if any” instead |
| Client MSA or SOW | Ban or consent requirement for “generative AI” | You may already be in breach | Written consent naming the tools, accounts and data routes |
| Client MSA or SOW | Confidentiality and subprocessors | Client code reaches a model provider | Name the model vendors as subprocessors, and list permitted data classes |
| Client MSA or SOW | IP indemnity | Uncapped, backed only by your own conduct | A cap, and no pass-through of vendor indemnities |
| Customer contracts you sell under | Open-source and license warranty | Agent-added dependencies or snippets | A warranty tied to a license scan and an SBOM per release |
| Employment and contractor agreements | IP assignment | Written for “works created by the employee” | Assignment that covers specifications, prompts, rules files and AI-assisted work product |
| Contributor or open-source policy | Upstream contributions | Project policies differ; some decline AI content | A rule that the engineer reads each project’s policy and signs off personally |
Check contractor agreements as closely as employment ones. In some jurisdictions, Poland among them, an assignment covers only the fields of exploitation it lists, so whether it reaches prompts and rules files is a question for counsel.
The checklist to take to counsel
Section titled “The checklist to take to counsel”Book one hour with counsel. Bring this list and the evidence in the right-hand column, so the meeting is about decisions, not discovery. An executive who will not sit in that meeting can hold the CTO to three of the answers: which account types reach our code, what each vendor’s indemnity excludes for code we modify, and when the terms were last read and by whom.
| # | Question for counsel | Evidence your team brings |
|---|---|---|
| 1 | In our jurisdictions, how much human contribution makes agent-assisted code protectable, and what should we record to show it? | A sample change with its spec, plan, acceptance tests and review record |
| 2 | Does our ownership warranty to clients hold for agent-written code, and what wording replaces it? | Current MSA and SOW templates |
| 3 | Which client contracts restrict or require consent for AI tools, and are we in breach of any today? | List of active contracts, and which tools touched each client’s code |
| 4 | Which licenses go on the dependency allowlist, and which need case-by-case review? | Current dependency license inventory |
| 5 | What do we do when a scan finds reproduced code: remove, rewrite or attribute? | One real scan result |
| 6 | For each vendor, how much of our delivered code does the indemnity reach, given its exclusions? | The vendor terms and order forms in force today, with the date read |
| 7 | Can we offer clients any IP indemnity, and at what cap? | Revenue per contract and current indemnity caps |
| 8 | Do the vendors’ data terms meet our confidentiality duties to clients and our GDPR role? | Account types in use, the managed-settings files, retention settings |
| 9 | Must we name model vendors as subprocessors, and who notifies clients? | The vendor subprocessor lists and your DPA templates |
| 10 | Do employment and contractor agreements assign AI-assisted work, including prompts and rules files? | Current agreement templates |
| 11 | What is our policy for agent-written contributions to open-source projects? | Projects you contribute to, with their AI policies |
| 12 | Which terms must be re-read, by whom and how often? | A terms register: vendor, document, version, date read, owner |
Counsel owns the answers; the CTO owns the evidence and records each decision next to its question.
Copy-paste prompts for the legal review
Section titled “Copy-paste prompts for the legal review”These prompts prepare evidence for counsel. Run the first in the repository with any agent, and the other two with the documents attached.
How do you prove the legal position holds?
Section titled “How do you prove the legal position holds?”A position agreed with counsel decays as tools, terms and contracts change. These controls keep it true without anyone reading every diff:
| Control | What it proves | Owner | Cadence |
|---|---|---|---|
| License gate in CI | No dependency outside the allowlist merges | Platform team | Every pull request |
| Source license and snippet scan | No reproduced third-party code or stray license text sits unreviewed | Platform team; findings to a named owner | Monthly and before each release to a client |
| Provenance trailers | Which changes an agent co-wrote, for audits and client questions | Tech leads | Every commit |
| Managed login settings | Company code never runs under consumer terms | Platform team | Checked on every machine by your device management |
| Terms register | Every vendor document in force, its version and the date someone read it | CTO, with counsel | Quarterly, and whenever a vendor announces a change |
| Evidence bundle per release | What was verified, including the scans above | Tech lead signs | Every release |
Claude Code adds a Co-Authored-By trailer to commits unless the attribution setting changes it, so do not set attribution to false or attribution.commit to an empty string in shared settings (checked in Claude Code 2.1.283). For other tools, ask for an Assisted-by: trailer in your pull request template.
Sign-off: counsel approves the allowlist, clause wording and terms register; the CTO signs that the controls run; the executive confirms client contracts use the approved clauses.
What goes wrong with legal and IP for agent-written code?
Section titled “What goes wrong with legal and IP for agent-written code?”An engineer uses a personal account on client code. The code now sits under consumer terms the client contract never contemplated. Recovery: counsel decides whether the confidentiality clause requires notice; delete the sessions where the vendor allows it; enforce managed login settings.
A GPL dependency ships in a proprietary product. The agent added it and CI had no license gate. Recovery: replace it, establish with counsel what was distributed and to whom, then add the gate and scan every repository.
Sales promises clients the vendor’s indemnity. Recovery: withdraw the wording, map which signed contracts carry it, and let counsel decide whether to renegotiate.
An upstream project rejects or removes your patch. Nobody read its AI policy. Recovery: withdraw the contribution, apologise to the maintainers, and add the rule to your AI usage policy.
Attribution is switched off to make commits “look clean.” Provenance is lost exactly when an auditor asks for it. Recovery: restore the default in managed settings; history cannot be reconstructed reliably.
Where to go next with legal and IP
Section titled “Where to go next with legal and IP”This page is further reading on the executive track. Next, get these terms in writing with the procurement questionnaire.
Frequently asked questions
Who owns code that a coding agent writes?
The vendor terms checked on 2026-09-26 give the output to the customer: Anthropic assigns its rights in outputs to the customer, 'if any', and GitHub says it does not own outputs. Whether copyright exists in the output depends on human authorship, which the US Copyright Office and US courts require, so protection rests on the human contribution, trade secrets and contracts.
Does a vendor indemnity cover the code we deliver to clients?
Often only partly. Anthropic's Commercial Terms defend paid use and its outputs, but exclude outputs the customer modified and combinations with non-Anthropic technology. GitHub's generative AI terms apply whatever defence clause your own agreement already has. Counsel should read the exclusions against how your code is actually built.
Can an agent bring GPL code into a proprietary codebase?
Yes, through two routes: dependencies it adds, and code it reproduces. A license gate on dependency changes in CI and a periodic snippet or license-text scan catch both, and a human approves any new license outside the allowlist.
Is our code used to train the vendor's models?
Under commercial terms, not by default for the vendors checked: Anthropic does not train on Claude Code data sent under commercial terms, and GitHub does not train on inputs or outputs without documented instructions. Consumer plans differ, so the control that matters is forcing work accounts.