Your AI tool pulls in packages and writes code without ever showing you a license. Here is what the four common open-source licenses ask of you, what the US Copyright Office says about who owns AI-written code, and a four-step check before you go live.
If you build by describing what you want to a tool like Lovable, Bolt, Cursor or Replit, you never see a license. The tool picks packages, writes code and wires it together. Somewhere in that pile may be a package under a license that asks something of you. This page explains the four you will meet most. If you are new to the term, what is vibe coding covers the basics.
What does the MIT license ask of you?
MIT asks for one thing: keep the copyright notice and the permission notice in all copies or substantial portions of the software. Everything else is allowed. You may use, copy, modify, merge, publish, distribute, sublicense and sell it. The software comes "as is", with no warranty, and the authors are not liable.
The license text says it grants permission "to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software." The only condition reads: "The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software."
For a vibe-coded app, that means a licenses file in your project listing the MIT packages and their notices. It does not mean sharing your own code.
What does Apache-2.0 add on top of MIT?
Apache-2.0 also asks you to keep notices, and it asks for three more things when you redistribute: give recipients a copy of the license, mark modified files with a prominent notice that you changed them, and carry over the NOTICE file's attribution lines if the project has one. It also includes a patent license.
That patent grant comes with a catch. Section 3 says that if you sue anyone claiming the work infringes a patent, the patent licenses granted to you for that work end on the date you file. Section 6 says the license does not give you permission to use the project's trade names or trademarks.
None of this makes you share your own source. Apache is still a "keep the paperwork" license.
What happens when GPL code ends up in your app?
The GPL turns on one word: convey. If you convey a work based on GPL code, meaning you hand copies to other people, section 5(c) says "You must license the entire work, as a whole, under this License to anyone who comes into possession of a copy." Running it yourself is different.
Section 2 is explicit: "You may make, run and propagate covered works that you do not convey, without conditions so long as your license otherwise remains in force." So a private tool, or a web app where users never receive a copy of the code, does not by itself trigger the share-alike rule.
Two more details from the text. A modified work must carry prominent notices that you changed it, with a date. And the output of running a GPL program is covered only if that output itself constitutes a covered work.
Where it bites: a mobile app, a desktop download, a browser extension, or code you give a client. Those are copies. If a GPL package is inside what you ship, the whole-work rule is on the table, and that is a question for a lawyer, not for guessing.
Why is the AGPL the one to watch for a web app?
The AGPL closes the gap that the GPL leaves open for websites. Section 13 says that if you modify the program, your modified version must prominently offer all users interacting with it remotely through a computer network an opportunity to receive the Corresponding Source, from a network server, at no charge.
Read that against the GPL's section 2. A GPL app you only host asks nothing. An AGPL app you modified and host asks you to offer the source to everyone who uses it, even though you never sent them a copy.
This is why companies often ban AGPL dependencies from hosted products. If you self-host an AGPL tool unmodified, for your own use, the text of section 13 does not apply, because it starts with "if you modify the Program". Once your AI tool edits that code and you put it online, it does. For a real example of tools in this space, our self-hosted chat UI comparison shows why a license column belongs in any tool shortlist.
What each license text asks of you, read 3 Oct 2026. Not legal advice. · aliteq research
Does an AI tool copy licensed code into your app?
Sometimes it can, and the vendors say so. GitHub's documentation says matches to public code "typically" occur in "less than one percent of Copilot suggestions", and that Copilot "may generate code suggestions that match code in the training set." That is a vendor statement about one product, not a measurement of every tool.
GitHub built a control for it. Its docs say Copilot "checks suggestions for matches with publicly available code. Any matches are discarded or suggested with a code reference." When you accept a matching inline suggestion and your settings allow matches, the log records the URLs of matching files and the license, if one was found, so you can "decide what attribution to use, or whether you want to remove this code."
Know the limits. GitHub states: "Code you have written, and Copilot suggestions you have altered, are not checked for matches to public code." The filter also covers Copilot only. I did not read the licensing features of any other tool, so I make no claims about them. Ask your own tool's documentation whether it has a public-code filter.
Who owns code the AI wrote for you?
Under the US Copyright Office's January 2025 report, purely AI-generated material is not protected by copyright, and a prompt alone does not make you the author. Your own creative edits, selection and arrangement can be protected. Whether your contribution is enough is decided case by case.
The Office's conclusions include: "Copyright does not extend to purely AI-generated material, or material where there is insufficient human control over the expressive elements." And: "Based on the functioning of current generally available technology, prompts do not alone provide sufficient control." It also says copyright protects "the original expression in a work created by a human author, even if the work also includes AI-generated material."
What this means for a founder: the parts you wrote, changed and arranged are yours. A file the AI produced from one prompt and you never touched may have thin protection, so a competitor copying it may be harder to stop. That is my reading, not a legal opinion.
Two cautions. The report covers whether AI output can be copyrighted. It does not say whether a model's training was lawful, and it does not tell you what license a dependency carries. Those are separate questions.
GitHub Copilot docs and the US Copyright Office report (January 2025), read 3 Oct 2026. · aliteq research
How do you check the licenses in an AI-built app?
Make a list of every package your app uses, read each license field, and flag anything GPL, AGPL or missing. Then keep the notices the permissive licenses require. A flag is a question for a lawyer, not a verdict. The check takes an afternoon and needs no coding.
npm's documentation says the license field in a package should hold an SPDX identifier such as MIT or BSD-3-Clause, or an expression such as (MIT OR Apache-2.0). A value of UNLICENSED means the owner grants no rights under any terms. Those are the words to look for.
List every dependency. Ask your AI tool to print your package list with each package's license field. If you do not know where it lives, [how to read AI code without coding](/how-to-read-ai-code-without-coding) shows what to look for.
Flag AGPL and GPL. MIT and Apache need a notice. GPL and AGPL need a decision. Also flag any package with no license stated, because no license means no permission granted.
Turn on the public-code filter if your tool has one. GitHub Copilot can block matches or show the source repository and license.
Keep a licenses file with the copyright lines your dependencies require. Review and edit the AI's output yourself, since your changes are what you can claim.
Ask a lawyer if the answer touches revenue, a customer contract or a flagged license. Do this before launch, not after a complaint.
The four-step license check, from the license texts and vendor docs read 3 Oct 2026. · aliteq research
Can I use MIT-licensed code in a closed-source app I sell?
Yes. MIT allows use, modification, distribution, sublicensing and sale. The one condition is keeping the copyright and permission notice in all copies or substantial portions of the software.
Does running a GPL program on my server force me to publish my code?
Not by the GPL's own text. Section 2 says you may run and propagate covered works you do not convey without conditions. The share-alike duty applies when you convey copies. The AGPL is different for modified versions that users reach over a network.
Does the AGPL apply if I only self-host a tool and never change it?
Section 13 starts with "if you modify the Program", so the network-source duty applies to modified versions. That reading comes from the license text. If your situation is anything but simple, ask a lawyer.
Is code written by an AI protected by copyright?
The US Copyright Office's January 2025 report says purely AI-generated material is not, and prompts alone do not give you authorship. Human edits, selection and arrangement can be protected. It is decided case by case.
Does GitHub Copilot check my code for license problems?
Copilot checks its suggestions for matches with public code and either discards them or adds a code reference. GitHub says code you wrote, and suggestions you altered, are not checked. It covers Copilot only, not other tools.
Is this legal advice?
No. It is a plain-English reading of public license texts and vendor documents, dated 3 October 2026. Licenses and guidance change. Ask a lawyer before you rely on any of it.
This page has no affiliate links or sponsored placements. It is general information, not legal advice.