CheckoryCheckory
SBOM list with GPL and AGPL rows flagged and a consent box, no face

How to Review GPL/AGPL Copyleft Contamination in a Vendor Deliverable

Demand a named SBOM, prior written copyleft consent, and an AGPL network log, then disclose, ban copyleft, or walk before Friday.

9 min readArticle
💡

Key takeaway in 30 seconds

Knowing how to review gpl agpl copyleft contamination in a software deliverable means treating “we use open source responsibly” as a fail. Demand a named list plus a machine-readable SBOM with licences, prior written consent before GPL, AGPL, LGPL, MPL or SSPL, an AGPL network log on the portal, a snippet scan, and OSS inside the indemnity. Then disclose, ban copyleft, or walk.

Sid, Ops at a 23-person UK product studio, is about to treat the OSS line as colour because Finance wants a Friday yes. Knowing how to review gpl agpl copyleft contamination in a software deliverable is a 25-minute hunt: demand a named SBOM, require prior written consent before copyleft, log AGPL network use on the customer-facing portal, ask about AI snippets, and refuse a blanket OSS indemnity carve-out.

September 2026. English law; exclusive courts of England and Wales. The packet — PSA, this SOW, and any OSS policy URL dated today — is booked for Friday. Clause 8.4: “Supplier uses open source software responsibly and will comply with applicable open source licences.” No annex. Tuesday Slack named an AGPL analytics plugin. Typical mistake: treating “open source” as free libraries. The rush is the problem.

The hidden risk is that a vibe sentence is not a licence field — and SaaS hosting does not switch AGPL off. CISA (29 July 2026) added Component License as a minimum SBOM element. Sid’s 8.4 has none of that. GNU AGPLv3 §13 was written so a modified Program must offer users interacting remotely through a computer network Corresponding Source at no charge. English copyright sits in the Copyright, Designs and Patents Act 1988.

Disclaimer: Checkory provides AI support, not legal advice. Consult a qualified lawyer for binding decisions.

SBOM list with GPL and AGPL rows flagged and a consent box, no face
SBOM list with GPL and AGPL rows flagged and a consent box, no face

Which inventory counts — a named SBOM or “we use open source responsibly”?

A vibe sentence is not a component, version, SPDX identifier, or transitive tree. Circle “responsibly.” Demand a named list and a machine-readable SBOM in SPDX or CycloneDX with a Component License field. Sid’s 8.4 = no list, no SBOM — fail.

FOSSA (30 July 2026): Component License should be SPDX IDs; coverage includes transitive dependencies — “there is no minimum depth”; a new SBOM per build or release. CISA is guidance, not Sid’s statute. In practice, contract for an SBOM with each delivery. Do: write named list with licences, or fail. Don’t: treat “responsibly” as disclosure under Friday pressure.

Named SBOM with Component License versus a responsibly sentence, no face
Named SBOM with Component License versus a responsibly sentence, no face

Typical mistake

Treating “we use open source responsibly” as the disclosure while an undeclared AGPL plugin is already in Slack.

Contamination log — Sid’s 8.4

LineSid’s paperWrite
Disclosure / SBOM“Uses open source responsibly”; no annexNamed list + SPDX/CycloneDX, or fail
Copyleft consentNo prior-written-consent mechanicGPL/LGPL/AGPL/MPL/SSPL need consent
AGPL + networkCustomer-facing portal; AGPL plugin in SlackModified? Users interact with that program?
AI snippetsSilentSnippet scan / AI-tool warranty, not only lockfiles
OSS indemnitySilent; OSS may be carved outOSS inside indemnity + replace/procure

What does copyleft need before it lands in the deliverable?

Ownership of the SOW work product does not unwind GPL or AGPL. Share-alike can attach to code he ships or hosts. Require Customer’s prior written consent before any GPL, LGPL, AGPL, MPL or SSPL component, plus a warranty of no undisclosed copyleft.

Venable (16 April 2026): advance written consent for copyleft; OSS must not force proprietary source out. Snowflake’s buyer PSA bans copyleft in a deliverable — colour, not a model clause. Bosch: undisclosed OSS is deemed unaccepted. Sid’s paper = no consent mechanic — fail. Do: add prior written consent and a no-undisclosed-copyleft warranty. Don’t: assume “we own the deliverable” closes this hunt.

Why does SaaS hosting not switch AGPL off?

GPL often hunts distribution. AGPL §13 hunts network interaction with a modified Program. A customer-facing portal is the fact pattern AGPL was written for. Hosting does not switch it off. Log: was the Program modified? Do users interact with that program over a network, or only with Sid’s app over an arm’s-length call?

fastCRW (4 July 2026): the network-source obligation fires when you modify the AGPL program, run that modified version, and users interact with that program itself. An AGPL API call does not copyleft the app. Vircon (16 June 2026) names two traps: AGPL closes the ASP loophole, and a binary handed to a customer is distribution. Do: log modify / network users / linked-versus-call. Don’t: skip because “we’re SaaS.” Undeclared AGPL plus no architecture note = walk Friday, then counsel — the solicitor you instruct on this paper.

AGPL section 13 network test: modify, remote users, that program, no face
AGPL section 13 network test: modify, remote users, that program, no face

SaaS is not a free pass

Hosting does not switch §13 off. Log architecture. Do not say AGPL always opens the whole tree. Undeclared AGPL with no consent is a Friday walk.

How do you catch an AI-pasted GPL snippet the SBOM never lists?

Conventional SCA reads manifests and lockfiles. A pasted function never appears in package.json. Ask whether the vendor used coding assistants, whether snippet matching was run, and whether they warrant no third-party copyleft.

FOSSA (2 July 2026): licences including GPL and AGPL still apply if a model typed the code. OpenChain KWG (8 June 2026): GitHub has stated verbatim copying of more than 150 characters happens about 1% of the time — a control, not a clean bill. For example, Sid’s lockfile SCA would miss a pasted GPL helper. Do: scan snippets, not only lockfiles, and add an AI-tool warranty. Don’t: treat autocomplete as a clean bill.

When to refuse an OSS carve-out on the IP indemnity?

Vendors routinely exclude OSS from the IP indemnity. Then contamination is his bill — a costly rewrite, not their cheque. Circle any “except open source” carve-out. Refuse a blanket exclusion. Demand replace, modify, or procure-rights.

Venable: avoid the blanket OSS exclusion. Law Insider samples warrant no unapproved OSS and that Buyer’s product is not forced under those terms. ReviewMyContract (2026) flags silence on OSS disclosure. If the fight is which claims they indemnify, that is a different hunt — the indemnity clause review checklist. Stay on the OSS carve-out. Silent paper + OSS possibly excluded = escalate / walk. Do: reject a blanket OSS exclusion. Don’t: treat the IP heading as cover.

IP indemnity with an except-open-source carve-out crossed out, no face
IP indemnity with an except-open-source carve-out crossed out, no face

How do you choose disclose, ban copyleft, or walk?

Disclose only if the log is complete: SBOM with licences, no undeclared copyleft, AGPL consented with an architecture note, snippet warranty, OSS inside indemnity. Ban copyleft — prior written consent; AGPL/SSPL off unless Sid opts in. Walk if 8.4 stays a vibe sentence, the plugin stays unnamed, or OSS is carved out.

If the fight is the PSA wrapper — fees, T&M, or assignment of work product — that is a different hunt: the professional services agreement review checklist. Freeze the packet plus any exhibit — attached schedule or appendix. Success bar: a one-page log plus one sentence that would pause Friday. Sid already has three: no SBOM; no consent; undeclared AGPL. Workflow: named SBOM → copyleft consent → AGPL §13 network test → AI snippet scan → OSS inside indemnity → disclose / ban copyleft / walk. Do: escalate that package. Don’t: treat 8.4 as colour before you sign under Finance pressure. Pause if 8.4 stays a vibe sentence. Optional: upload the same PDF to document analysis for a first-pass — a machine extract of clauses before a human reads every page — and a human still opens 8.4 and must verify every High flag — a severity hit a human still opens.

Hunt

1

Freeze the packet

PSA + this SOW + any OSS policy URL, dated today. Search open source / SBOM / copyleft / GPL / AGPL / prior written consent / indemnif. Open 8.4.

2

Hunt disclosure + SBOM

Circle “responsibly.” Demand a named list and a machine-readable SBOM with licences. No list, no SBOM — fail.

3

Hunt copyleft consent

Require prior written consent before GPL, LGPL, AGPL, MPL or SSPL, plus a no-undisclosed-copyleft warranty.

4

Hunt AGPL + network use

Log modify / network users / linked-versus-call. Undeclared AGPL + no architecture note = walk Friday.

5

Hunt AI snippets + indemnity

Ask for snippet matching, not only lockfile SCA. Circle any OSS carve-out. Demand replace / modify / procure-rights.

6

Disclose, ban copyleft, or walk

Disclose only with a complete log. Ban copyleft if they want OSS at all. Walk if 8.4 stays a vibe sentence.

Frequently asked questions

Is MIT a problem?
Log it and keep notices. MIT is permissive, not copyleft. Undeclared GPL mixed with MIT is the problem.
Does SaaS hosting trigger AGPL?
Hosting does not switch §13 off. Log modify + network users interacting with that program, not merely a separate app over an arm’s-length call.
Do we need an SBOM on every release?
Contract for one with each delivery or release, not a kick-off PDF. CISA 2026 is the ask pattern, not Sid’s statute.
Does owning the deliverable unwind copyleft?
No. Assignment of work product does not unwind GPL or AGPL. Require prior written consent before copyleft lands.
Can an AI snippet contaminate us if it is not in package.json?
Yes. Conventional SCA reads manifests; a pasted function never appears there. Ask for snippet matching and an AI-tool warranty.
If we already ran the PSA checklist, are we done?
No. That hunt is the PSA wrapper, not this 8.4 log — https://checkory.com/en-gb/blog/professional-services-agreement-review-checklist.

Highlight the OSS clause

Upload the same PDF. A human still opens 8.4.

Start document analysis

What to do next

Sources

Related guides

Updated: September 18, 2026