Software companies
Indemnities in code licensing deals: who carries open-source license risk?
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
In a code licensing deal for AI training, the supplier usually warrants and indemnifies only for code it wrote and owns, while open-source components are excluded or passed through as-is under their own licenses. Liability caps, carve-outs and a file-level license inventory then decide how much risk each side actually carries.
Key takeaways
- Suppliers generally indemnify for first-party code they own, not for open-source code written by others.
- Open-source files that stay in a package are usually delivered as-is under their own license terms, listed in an inventory.
- Knowledge-qualified warranties about exclusions are a common middle ground between full indemnity and none.
- Licensees usually carry the risk of how they train models and what those models output.
- IP indemnities are often carved out of the general liability cap and given their own cap instead.
What does an indemnity do in a code license?#
An indemnity in a code license is a promise by one party to defend the other and cover its losses if a specified kind of third-party claim arises, most often a claim that the licensed code infringes someone else's copyright or breaches an open-source license. It sits alongside warranties, which are statements of fact about the code, and the limitation of liability clause, which caps what either side can recover.
The three clauses work together. A warranty that the supplier owns the code gives the licensee a breach claim if it is untrue. An indemnity shifts the cost of defending a third party's lawsuit. The liability cap decides how much of either is actually collectible. Negotiating one without the others misses where the risk really lands.
Indemnities also carry procedure: prompt notice of a claim, the indemnifying party's right to control the defense, the other party's duty to cooperate, and limits on settling without consent. Those mechanics often matter as much as the scope.
How is open-source risk usually allocated?#
Open-source risk is usually allocated by component: the supplier stands behind what it wrote and owns, and third-party code is either excluded or passed through on its own terms. The table shows a common pattern. Actual positions depend on bargaining power and on how central the third-party code is to the package.
| Component | Typical supplier position | Typical licensee ask | Common compromise |
|---|---|---|---|
| First-party code written by employees | Ownership warranty and IP indemnity | Indemnity without a cap | Indemnity with a separate, higher cap |
| Contractor and agency code | Covered if assignments are in place | Same as first-party | Covered, with the contributor map disclosed |
| Permissive open source kept in the package | As-is, notices preserved, listed in inventory | Warranty that notices are complete | Knowledge-qualified notice warranty |
| Copyleft open source | Excluded | Warranty that none is included | Knowledge-qualified warranty plus a cure process |
| Vendored commercial SDKs | Excluded | Warranty of exclusion | Exclusion confirmed by scan report |
| AI-generated code in the repository | No ownership warranty for it | Treat as first-party | Disclosure of tool use, warranty limited to knowledge |
| Licensee's training and model outputs | No liability | Indemnity for output claims | Licensee bears its own use |
Why open source rarely gets a full indemnity#
Open source rarely gets a full supplier indemnity because the supplier did not write it and cannot change its terms. Open-source licenses themselves disclaim warranties, so the supplier never received any promise it could pass on. Asking the supplier to insure the whole open-source ecosystem's provenance shifts a risk the supplier cannot control. Whether training a model on copyleft code triggers that license's obligations is also unsettled, which is one reason many suppliers exclude copyleft files rather than argue the point.
The supplier's real tool is disclosure. A file-level inventory with SPDX license identifiers, produced by a scanner and reviewed by an engineer, shows the licensee exactly what is in the package. Copyleft and unlicensed files are removed, permissive files keep their notices, and the inventory becomes an exhibit to the license.
With that inventory in hand, a supplier can give a narrower, honest warranty: to its knowledge after a reasonable scan, the package contains no copyleft-licensed files except as listed. That statement is something the supplier can actually stand behind.
Clauses to settle before signing#
The clauses to settle before signing are the ones that fix scope, exclusions, caps and the cure process, and the negotiation goes faster when both sides agree on that structure before arguing about amounts. These are the clauses that most often decide where open-source risk lands.
- Scope of the IP indemnity: first-party code only, or the whole package.
- Exclusions: claims from the licensee's modifications, combinations with other data, training methods and model outputs.
- Reverse indemnity: whether the licensee covers the supplier for claims arising from the licensee's models, outputs and breaches of the use restrictions.
- Liability cap: whether IP claims sit inside the general cap, outside it, or under a separate cap.
- Consequential damages waiver and whether it applies to indemnified claims.
- Cure process: notice of a problematic file, replacement or removal, and the licensee's duty to delete it from future training runs.
- Knowledge qualifiers: what counts as the supplier's knowledge and which scan establishes it.
- Survival: how long the indemnity lasts after the license term ends.
Illustrative: a DevOps software vendor negotiates its first code license#
Illustrative: a fictional DevOps software company agrees to license several years of git history and pull request reviews to an AI developer. The licensee's first draft asks for an uncapped indemnity covering any IP claim relating to the dataset, including claims about the licensee's trained models and their outputs.
The supplier's general counsel asks engineering to run a license scan across the full history, not just the current branch. The scan finds vendored dependency folders and a handful of AGPL files from an abandoned plugin. Those paths are excluded, the remaining permissive files keep their headers, and the inventory is attached as an exhibit.
The final agreement gives an IP indemnity for first-party code under a separate cap, delivers open-source files as-is under their own licenses, includes a knowledge-qualified warranty on copyleft exclusion with a cure process, and leaves model training and outputs with the licensee.
Where do caps and carve-outs leave each side?#
Caps and carve-outs turn the allocation into actual exposure. A generous indemnity under a low cap may protect less than a narrow indemnity outside the cap, so read the two together.
Many technology agreements tie the general cap to fees paid under the agreement and treat IP indemnities differently. Neither approach is standard enough to assume; both are negotiated.
Watch how the cap interacts with the consequential damages waiver. If indemnified claims are not carved out of the waiver, the licensee may find that the cost it worries about most, such as retraining a model after removing a file, is excluded entirely. Spell out whether remediation costs of that kind are recoverable at all.
| Structure | Supplier exposure | Licensee protection |
|---|---|---|
| IP indemnity inside the general cap | Bounded by the general cap | Limited if the cap is low |
| IP indemnity under a separate cap | Bounded, but higher than the general cap | Meaningful for first-party claims |
| IP indemnity uncapped | Open-ended | Strongest, and hardest to obtain |
| No indemnity, warranty only | Breach damages subject to the cap | Weakest; no defense obligation |
How SourceX approaches indemnity terms#
SourceX does not give legal advice, and each supplier's counsel negotiates indemnities. What SourceX does is make the factual basis clear: the Rights and Preparation steps of the SourceX five-step transaction produce the contributor map, the license inventory and the list of excluded paths that indemnity and warranty language depends on.
Those records are kept in the SourceX Evidence Packet under provenance and licensing rights, so both sides negotiate from the same description of what is in the package. Nothing is delivered until the supplier approves that scope.
Frequently asked questions
Should a supplier ever indemnify for model outputs?
It is unusual. The supplier controls neither the training process nor how the model is prompted or deployed, so output claims depend on choices made by the licensee. Most suppliers decline, and licensees that ask usually accept an exclusion once the inventory shows what was delivered.
What does as-is mean for open-source files in the package?
It means the supplier makes no warranty about those files beyond, perhaps, that it has preserved their notices and listed their licenses. The licensee receives them on the terms of their own licenses and decides whether to use them. As-is pass-through only works if the inventory is accurate.
Does insurance cover IP indemnities in data and code licenses?
Sometimes. Technology errors and omissions or IP-specific policies may respond to some claims, but coverage depends on the policy wording and exclusions. Ask your broker before signing, and check whether the policy treats data licensing as part of your insured business activities.
Who pays for the license scan?
Usually the supplier, because the scan supports the supplier's warranties. Open-source scanners can do much of the work, with engineering time for review. A licensee that wants a deeper commercial scan sometimes pays for it or shares the cost. Either way, keep the scan report and its date with the deal file.
What happens if a copyleft file is found after delivery?
A cure clause usually handles it. The supplier gives notice and a replacement manifest, the licensee removes the file from its copy and from future training runs, and the incident does not count as a breach if handled within the agreed process. Without a cure clause, the parties fall back on the warranty and indemnity terms.
Related resources
See if your company qualifies
A short company assessment. No data uploads are needed.