
How to Review GPL/AGPL Copyleft Contamination in a Vendor Deliverable
Demand a named SBOM, prior written copyleft consent, and an AGPL network log, then disclose, ban copyleft, or walk before Friday.
Key takeaway in 30 seconds
Knowing how to review gpl agpl copyleft contamination in a software deliverable means treating “we use open source responsibly” as a fail. Demand a named list plus a machine-readable SBOM with licences, prior written consent before GPL, AGPL, LGPL, MPL or SSPL, an AGPL network log on the portal, a snippet scan, and OSS inside the indemnity. Then disclose, ban copyleft, or walk.
Sid, Ops at a 23-person UK product studio, is about to treat the OSS line as colour because Finance wants a Friday yes. Knowing how to review gpl agpl copyleft contamination in a software deliverable is a 25-minute hunt: demand a named SBOM, require prior written consent before copyleft, log AGPL network use on the customer-facing portal, ask about AI snippets, and refuse a blanket OSS indemnity carve-out.
September 2026. English law; exclusive courts of England and Wales. The packet — PSA, this SOW, and any OSS policy URL dated today — is booked for Friday. Clause 8.4: “Supplier uses open source software responsibly and will comply with applicable open source licences.” No annex. Tuesday Slack named an AGPL analytics plugin. Typical mistake: treating “open source” as free libraries. The rush is the problem.
The hidden risk is that a vibe sentence is not a licence field — and SaaS hosting does not switch AGPL off. CISA (29 July 2026) added Component License as a minimum SBOM element. Sid’s 8.4 has none of that. GNU AGPLv3 §13 was written so a modified Program must offer users interacting remotely through a computer network Corresponding Source at no charge. English copyright sits in the Copyright, Designs and Patents Act 1988.
Disclaimer: Checkory provides AI support, not legal advice. Consult a qualified lawyer for binding decisions.

Which inventory counts — a named SBOM or “we use open source responsibly”?
A vibe sentence is not a component, version, SPDX identifier, or transitive tree. Circle “responsibly.” Demand a named list and a machine-readable SBOM in SPDX or CycloneDX with a Component License field. Sid’s 8.4 = no list, no SBOM — fail.
FOSSA (30 July 2026): Component License should be SPDX IDs; coverage includes transitive dependencies — “there is no minimum depth”; a new SBOM per build or release. CISA is guidance, not Sid’s statute. In practice, contract for an SBOM with each delivery. Do: write named list with licences, or fail. Don’t: treat “responsibly” as disclosure under Friday pressure.

Typical mistake
Treating “we use open source responsibly” as the disclosure while an undeclared AGPL plugin is already in Slack.
Contamination log — Sid’s 8.4
| Line | Sid’s paper | Write |
|---|---|---|
| Disclosure / SBOM | “Uses open source responsibly”; no annex | Named list + SPDX/CycloneDX, or fail |
| Copyleft consent | No prior-written-consent mechanic | GPL/LGPL/AGPL/MPL/SSPL need consent |
| AGPL + network | Customer-facing portal; AGPL plugin in Slack | Modified? Users interact with that program? |
| AI snippets | Silent | Snippet scan / AI-tool warranty, not only lockfiles |
| OSS indemnity | Silent; OSS may be carved out | OSS inside indemnity + replace/procure |
What does copyleft need before it lands in the deliverable?
Ownership of the SOW work product does not unwind GPL or AGPL. Share-alike can attach to code he ships or hosts. Require Customer’s prior written consent before any GPL, LGPL, AGPL, MPL or SSPL component, plus a warranty of no undisclosed copyleft.
Venable (16 April 2026): advance written consent for copyleft; OSS must not force proprietary source out. Snowflake’s buyer PSA bans copyleft in a deliverable — colour, not a model clause. Bosch: undisclosed OSS is deemed unaccepted. Sid’s paper = no consent mechanic — fail. Do: add prior written consent and a no-undisclosed-copyleft warranty. Don’t: assume “we own the deliverable” closes this hunt.
Why does SaaS hosting not switch AGPL off?
GPL often hunts distribution. AGPL §13 hunts network interaction with a modified Program. A customer-facing portal is the fact pattern AGPL was written for. Hosting does not switch it off. Log: was the Program modified? Do users interact with that program over a network, or only with Sid’s app over an arm’s-length call?
fastCRW (4 July 2026): the network-source obligation fires when you modify the AGPL program, run that modified version, and users interact with that program itself. An AGPL API call does not copyleft the app. Vircon (16 June 2026) names two traps: AGPL closes the ASP loophole, and a binary handed to a customer is distribution. Do: log modify / network users / linked-versus-call. Don’t: skip because “we’re SaaS.” Undeclared AGPL plus no architecture note = walk Friday, then counsel — the solicitor you instruct on this paper.

SaaS is not a free pass
Hosting does not switch §13 off. Log architecture. Do not say AGPL always opens the whole tree. Undeclared AGPL with no consent is a Friday walk.
How do you catch an AI-pasted GPL snippet the SBOM never lists?
Conventional SCA reads manifests and lockfiles. A pasted function never appears in package.json. Ask whether the vendor used coding assistants, whether snippet matching was run, and whether they warrant no third-party copyleft.
FOSSA (2 July 2026): licences including GPL and AGPL still apply if a model typed the code. OpenChain KWG (8 June 2026): GitHub has stated verbatim copying of more than 150 characters happens about 1% of the time — a control, not a clean bill. For example, Sid’s lockfile SCA would miss a pasted GPL helper. Do: scan snippets, not only lockfiles, and add an AI-tool warranty. Don’t: treat autocomplete as a clean bill.
When to refuse an OSS carve-out on the IP indemnity?
Vendors routinely exclude OSS from the IP indemnity. Then contamination is his bill — a costly rewrite, not their cheque. Circle any “except open source” carve-out. Refuse a blanket exclusion. Demand replace, modify, or procure-rights.
Venable: avoid the blanket OSS exclusion. Law Insider samples warrant no unapproved OSS and that Buyer’s product is not forced under those terms. ReviewMyContract (2026) flags silence on OSS disclosure. If the fight is which claims they indemnify, that is a different hunt — the indemnity clause review checklist. Stay on the OSS carve-out. Silent paper + OSS possibly excluded = escalate / walk. Do: reject a blanket OSS exclusion. Don’t: treat the IP heading as cover.

How do you choose disclose, ban copyleft, or walk?
Disclose only if the log is complete: SBOM with licences, no undeclared copyleft, AGPL consented with an architecture note, snippet warranty, OSS inside indemnity. Ban copyleft — prior written consent; AGPL/SSPL off unless Sid opts in. Walk if 8.4 stays a vibe sentence, the plugin stays unnamed, or OSS is carved out.
If the fight is the PSA wrapper — fees, T&M, or assignment of work product — that is a different hunt: the professional services agreement review checklist. Freeze the packet plus any exhibit — attached schedule or appendix. Success bar: a one-page log plus one sentence that would pause Friday. Sid already has three: no SBOM; no consent; undeclared AGPL. Workflow: named SBOM → copyleft consent → AGPL §13 network test → AI snippet scan → OSS inside indemnity → disclose / ban copyleft / walk. Do: escalate that package. Don’t: treat 8.4 as colour before you sign under Finance pressure. Pause if 8.4 stays a vibe sentence. Optional: upload the same PDF to document analysis for a first-pass — a machine extract of clauses before a human reads every page — and a human still opens 8.4 and must verify every High flag — a severity hit a human still opens.
Hunt
Freeze the packet
PSA + this SOW + any OSS policy URL, dated today. Search open source / SBOM / copyleft / GPL / AGPL / prior written consent / indemnif. Open 8.4.
Hunt disclosure + SBOM
Circle “responsibly.” Demand a named list and a machine-readable SBOM with licences. No list, no SBOM — fail.
Hunt copyleft consent
Require prior written consent before GPL, LGPL, AGPL, MPL or SSPL, plus a no-undisclosed-copyleft warranty.
Hunt AGPL + network use
Log modify / network users / linked-versus-call. Undeclared AGPL + no architecture note = walk Friday.
Hunt AI snippets + indemnity
Ask for snippet matching, not only lockfile SCA. Circle any OSS carve-out. Demand replace / modify / procure-rights.
Disclose, ban copyleft, or walk
Disclose only with a complete log. Ban copyleft if they want OSS at all. Walk if 8.4 stays a vibe sentence.
Frequently asked questions
Is MIT a problem?▼
Does SaaS hosting trigger AGPL?▼
Do we need an SBOM on every release?▼
Does owning the deliverable unwind copyleft?▼
Can an AI snippet contaminate us if it is not in package.json?▼
If we already ran the PSA checklist, are we done?▼
What to do next
Professional services agreement review checklist
PSA wrapper. This page is GPL/AGPL contamination of this deliverable.
RelatedIndemnity clause review checklist
Which claims they indemnify. This page is the OSS carve-out on that indemnity.
RelatedStatement of work review checklist before signing
Acceptance and change orders on the SOW. This page is 8.4 copyleft contamination.
RelatedHuman verification checklist for high-severity contract flags
Named reviewer on a High flag after first-pass. Open 8.4 on the source page.
Sources
- CISA — 2026 Minimum Elements for a Software Bill of Materials (29 July 2026)
- FOSSA — CISA 2026 minimum SBOM elements (30 July 2026)
- GNU AGPLv3 §13 — remote network interaction (SPDX)
- fastCRW — AGPL-3.0 for SaaS, explained (4 July 2026)
- Venable — what companies get wrong about open-source software licensing (16 April 2026)
- FOSSA — OSS licence compliance risk from AI coding tools (2 July 2026)
Related guides


