Who Owns the License on Agent-Written Code? A Compliance Self-Audit for Vibe Projects
Your agent may be pasting GPL code into your closed-source project without you knowing — and 'the AI wrote it' is not a legal defense. This guide maps where the license risk in AI-generated code actually lives: training-data contamination, the state of the Copilot lawsuits, and a self-audit checklist any indie can run tonight.

Where the risk lives: not 'who wrote it,' but 'what it learned from'
First, clear up a misconception: the law doesn't care whose fingers typed the code — it cares whether it reproduces protected expression. Coding agents train on vast oceans of open-source code, including 'viral' licenses like GPL and AGPL. When an agent reproduces, 'from memory,' a function strikingly similar to a GPL project, that snippet can carry the viral license into your project.
This isn't theoretical. GitHub Copilot has been mired in a class-action lawsuit since 2022, with plaintiffs alleging unlicensed reproduction of open-source code. The case is still grinding through courts in 2026, but the signal is clear: courts are taking 'AI reproduced code' seriously. Nobody sues your vibe project today — but that doesn't mean nobody will dig through its history once it grows up.
Three high-risk scenarios — check which is yours
One, direct carrying by the agent. You ask the agent to 'implement something like this library,' and it rewrites the GPL library's core logic nearly verbatim. Similar functionality doesn't infringe; similar expression does — and agents excel at 'rewrite it with different variable names.'
Two, dependency landmines. To get things working, the agent npm-installs or pip-installs a pile of packages. It doesn't read licenses; neither do you. When it's time to commercialize, a scan reveals three AGPL packages in the tree — and AGPL's virality counts 'serving over a network' as distribution.
Three, training-data reflux. Some AI coding tools' terms let them use your code to improve their models. Your trade secrets go in; they come out as someone else's agent's 'inspiration.' Reading the data terms before signing up is the cheapest risk control there is.
The self-audit you can run tonight
1. Scan dependencies: run license-checker (npm) or pip-licenses, list every GPL/AGPL/LGPL dependency, and judge each one. AGPL in a commercial project — the default answer is remove.
2. Ask the agent for provenance: when generating key modules, add 'avoid reproducing the expression of existing open-source projects; implement it your own way.' It doesn't eliminate the risk, but it sharply reduces 'recitation from memory.'
3. Quarantine third-party code: put referenced code in its own directory, labeled with source and license. If trouble comes, good quarantine means deleting a directory, not rewriting the project.
4. Read your tool's data terms: confirm your AI coding tool doesn't train on your code. Enterprise tiers usually promise no training; free tiers might not.
5. Get a lawyer's glance before commercializing: this checklist is enough for personal projects, but once you're raising, selling, or entering enterprise procurement, paying for an open-source compliance audit is the best money you'll spend.
Our take: compliance is the vibe coder's rite of passage
Honestly, 99% of vibe projects will never reach suable scale. But compliance habits aren't about dodging lawsuits — they're about keeping your project sellable, fundable, acquirable at any moment. The first document in any due diligence is the code compliance report; last-minute scrambling costs ten times more.
Make this checklist your project's closing ritual: the day the features work, spend one hour scanning dependencies, labeling sources, reading terms. Agents made your coding ten times faster — don't let licensing be the one thing you never accelerated.
Related articles

On October 7, Atlassian launched the Agentic Multiplayer Protocol (AMP): AI agents get an "identity," and codebases precisely record what humans wrote versus what agents did, across Claude, Codex, Figma, and Rovo. Bundled with the Teamwork Graph code index, the Rovo Work long-task mode, and EU-only inference. As vibe coding enters the enterprise, "who wrote the code" turns from vanity into compliance and cost.

Getting signups is only the start — users churn by day 3 and you have no horn to call them back. This guide covers notification systems for vibe projects: channel selection, email with Resend from day one, SPF/DKIM/DMARC done right, when SMS is worth the money, frequency caps and unsubscribe, retries and dead letters, plus a launch acceptance checklist.

One 10MB avatar upload and your Node server's memory is gone. Presigned direct uploads, browser-side compression, magic-number validation, chunked resumable uploads, orphan cleanup — seven opinionated sections covering the highest-crash-rate feature in indie projects.