Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
What AI-generated code risks show up in due diligence?
Last verifiedAI-authored code raises unsettled IP and copyright questions plus measurable risks — license contamination, insecure patterns, and unknown authorship share. Measure the engineering risk; leave ownership to counsel. This page is not legal advice and not investment advice.
AI-generated code risk, last verified 10 September 2026 against US Copyright Office AI guidance, Regulation (EU) 2024/1689 provisions relevant to GPAI and code, NIST AI RMF, and OWASP guidance on AI-assisted code. IP ownership of model output remains unsettled — not legal advice. Not investment advice.
Unsettled law versus measurable engineering
Audience: an acquirer or investor. This page is not legal advice and not investment advice. Kind of text: US Copyright Office AI materials are agency guidance and remain in motion — last verified 10 September 2026. The EU AI Act is a legal requirement if it applies (GPAI transparency and copyright-policy duties are a different lane from “who owns this function”). NIST AI RMF is a framework. OWASP AI-assisted-code notes are community best practice. A dedicated AI-coding-risk sibling guide is not on this site yet. Naming it is not a link.
Checklist for probing AI-code exposure
Last verified 10 September 2026. Not a legal test. Not legal advice.
| Probe | What good looks like | Kind of text |
|---|---|---|
| Authorship share | A measured AI-authored-code floor (or an honest “we do not measure”). | Engineering metric — not a copyright conclusion. |
| Tool allow-list | Named assistants, enterprise terms, and a ban on pasting secrets. | Best practice; secret-scanning ingest supports it. |
| License / training-data story | Vendor terms on file; no claim that “the model trained on everything, so we are fine.” | Counsel interprets terms. This page does not. |
| Security review of AI-touched paths | SAST/DAST and secret scanning on those diffs, not a waiver. | OWASP / SSDF practice. |
| Human approval | A named reviewer still merges. “The model approved it” is a red flag. | Best practice / SoD-for-AI. |
What remains unsettled
Whether and when AI-assisted output is copyrightable, who owns it, and how training-data licenses bind a downstream product are evolving questions. The US Copyright Office has published guidance that is not a statute and is subject to change — check for changes since last verified 10 September 2026. Do not treat a blog post as settled law. Not legal advice.
What to do now
Operational steps. Last verified 10 September 2026. Not legal advice.
- Ask for the authorship-share number or a written “unmeasured.”
- Park ownership and training-data questions with counsel.
- Open the AI due-diligence checklist and OSS-risk pages on this site.
- If you already have a session: AI-authored-code floor, AI inventory, first-party SAST/DAST, and secret-scanning ingest. Naming those surfaces is not a public href.
Checklist
Question list. Not legal advice.
- Is AI use inventoried or shadow?
- Are secrets scanned on AI-assisted diffs?
- Has anyone claimed copyright certainty this page does not support?
- Is the EU AI Act GPAI lane being confused with code-ownership?
Where this shows up in ShipReady Metrics
AI-authored-code floor, AI inventory, first-party SAST/DAST, and secret-scanning ingest. The product measures share and defects. It does not decide copyright ownership and does not give legal or investment advice.
Primary sources (last verified 10 September 2026)
US Copyright Office AI guidance (check for changes since last verified). Regulation (EU) 2024/1689 (if it applies). NIST AI RMF 1.0. OWASP guidance on AI-assisted code. Not legal advice.