Back to BlogSecurity & Compliance

Who Owns AI-Generated Code? What Founders Should Put in Contracts

Rupak Amin

Founder & Lead Engineer, RAITHub

10 min read

Between you and the AI vendor, you usually own the code: OpenAI, Anthropic and Lovable say in their terms that output belongs to the customer, and GitHub says it does not own Copilot output. Against everyone else, protection is thinner, because the US Copyright Office says purely AI-generated material is not copyrightable without enough human authorship. Your developer contract has to close that gap.

This is general information, not legal advice; confirm with your adviser. RAITHub is a software company, not a law firm, and the rules differ by country and change quickly. The vendor terms below were read on 29 September 2026. Take this post to your lawyer as a list of questions, not as answers.

Do I own code that ChatGPT, Claude, Copilot or Lovable writes for me?

As between you and the vendor, generally yes. Each of these vendors either assigns its rights in the output to you or says it claims none. Two words in those terms matter: "if any". A vendor can only hand over rights it has, and for purely machine-generated material there may be few or none to hand over.

Vendor and documentWhat it says about outputCaveats worth reading
OpenAI, Terms of UseYou retain ownership of your input and own the output; OpenAI assigns to you its right, title and interest, if any, in the outputOutput may not be unique; other users can receive similar output. Business products run under separate business terms
Anthropic, Commercial Terms (effective 17 June 2025)The customer retains rights to its inputs and owns its outputs; Anthropic assigns its right, title and interest, if any, in outputsAn IP indemnity covers paid, authorised use, with exclusions such as your own modifications and your inputs. Anthropic may not train models on customer content from these services
Anthropic, Consumer Terms (effective 8 October 2025)"we assign to you all of our right, title, and interest—if any—in Outputs", subject to your compliance with the termsConsumer plans are a different contract from the commercial terms
GitHub, Generative AI Services Terms (Copilot Business and Enterprise bought from GitHub)"GitHub does not own Inputs or Outputs"; you retain any ownership you already have in your inputsDefence of third-party claims depends on your main agreement with GitHub, and the terms refer to Microsoft's required mitigations, such as filters. You are responsible for what you build
Lovable, Terms of Service (effective 15 August 2026, updated 28 August 2026)You own your customer data, including the apps you build, and the AI output generated for you, subject to third-party rights in the models, training data or outputsOutput may be similar or identical to other users'. The terms also grant Lovable a licence to use customer data for its business purposes, and let you opt out of model training

Which plan you are on matters. Consumer, team and enterprise tiers of the same product often sit under different documents, with different promises on training and indemnity. Read the one that matches the account your developers actually use.

Can AI-generated code be copyrighted at all?

In the United States, only the parts a human authored. On 29 January 2025 the US Copyright Office published Part 2 of its report on copyright and artificial intelligence, on copyrightability. Its announcement sets out the position: outputs of generative AI "can be protected by copyright only where a human author has determined sufficient expressive elements"; protection does not extend to "the mere provision of prompts"; and using AI to assist, or including AI-generated material in a larger human-made work, "does not bar copyrightability" of the human contribution.

The courts have held the same line on authorship. In Thaler v. Perlmutter, decided on 18 March 2025, the US Court of Appeals for the D.C. Circuit upheld the refusal to register a work listed as created by an AI system, because copyright requires a human author.

Other countries differ. In the United Kingdom, section 9(3) of the Copyright, Designs and Patents Act 1988 treats the author of a computer-generated work as the person who made the arrangements necessary for its creation. How that applies to modern AI tools is not settled, which is one more reason to ask your adviser.

What does this mean for a software product in practice?

Less than founders fear, and more than they assume. Four practical points follow.

  1. Your human-written and human-edited code is protected in the normal way. The architecture, the chosen structure and the changes an engineer makes to generated code are human contributions.
  2. Purely generated snippets may be weakly protected on their own. Someone who copied them might face a thinner copyright claim. For most products, the value sits in the whole system, the data and the customers, not in individual functions.
  3. Contracts and confidentiality still protect you. Keeping source code private, with NDAs and access controls, protects it whatever its copyright status. Copyright is one tool among several.
  4. Records help. Git history, pull requests and review comments show where people designed, selected and changed code. Keep them.

What are the other risks besides ownership?

Two matter more day to day than copyright: other people's code, and your own confidential data.

  • Open-source licences. A tool can produce code that closely matches existing licensed code. If that code is under a copyleft licence, one that requires derived works to be released under the same terms, it can create obligations you did not plan for. GitHub's terms point to filtering as a required mitigation for its claims coverage; ask your developers whether such filters are on.
  • Confidential inputs. Pasting your code, customer data or keys into a tool sends them to the vendor. Anthropic's commercial terms say it may not train on customer content from those services; Lovable lets you opt out of training. Consumer tiers can differ. Decide which tools and which plans are allowed.
  • Indemnity gaps. Some vendors defend paid customers against IP claims about output, with exclusions. That protection usually covers the vendor's customer, which may be your developer's company rather than yours.
  • Security, not law. Generated code can carry vulnerabilities; Veracode's 2025 GenAI Code Security Report found 45% of the samples it tested introduced an OWASP Top 10 flaw. Ownership of broken code is not much of an asset; see the vibe-coded app security checklist.

What should founders put in a development contract?

The contract with your developer or agency is where you fix the gap, because it governs the people who used the tools. These are points to raise with your lawyer, not clauses to copy.

Contract pointWhat it should coverWhy AI changes it
IP assignmentAll deliverables, source code and documentation assigned to your company, however they were producedMakes clear that AI-assisted work is included and that the developer passes on whatever rights they hold
AI tool disclosureWhich AI tools and which plans are used on your codeEach tool and plan has its own terms on output, training and indemnity
Confidential dataNo secrets, customer data or proprietary code in tools that may train on inputsProtects confidentiality, which does not depend on copyright
Open-source and third-party codeA licence inventory at handover; no copyleft code without your written approvalGenerated code can resemble licensed code
Human reviewEvery change reviewed by a named engineer before mergeStrengthens the human contribution and catches defects
Warranties and indemnityOriginality and non-infringement promises, and who bears a third-party claimVendor indemnities may not reach you; this is a negotiation
Accounts and deliveryRepository, hosting and tool accounts in your company's name; code delivered continuously, not at the endOwnership on paper is little use without access; see how to get your source code from a developer

Work-for-hire rules, moral rights and assignment formalities differ by country. Your lawyer should adapt all of the above to the law that governs your contract.

What should you do if code was already written with AI and the contract says nothing?

Close the gaps now, before a sale, investment or dispute makes them urgent.

  1. Ask the developer for a written confirmatory assignment of all IP in the work to date.
  2. Get the repository and every account moved into your company's name. If the developer has gone quiet, read what to do when a developer disappears with your code.
  3. Ask which AI tools and plans were used, and whether confidential data went into them.
  4. Run a licence scan over dependencies and look for large copied blocks.
  5. Have an engineer review the code for security and quality, starting with access control and secrets. The production-readiness guide covers the order.

Why RAITHub for this?

Because the engineering side of AI code ownership is what RAITHub can help with: making code reviewable, owned and documented, so your lawyer has something clean to work with. On every RAITHub engagement the client owns the IP, an NDA is standard, and the code lives in your repository. RAITHub signs DPAs and SCCs and follows your controls. When RAITHub takes over an AI-generated codebase through the code rescue service, the handover covers account ownership, a dependency inventory and tests on the critical paths. For a new product, the MVP development service starts with those terms in place.

When don't you need RAITHub?

  • You need the legal answer. RAITHub gives no legal advice. For contract wording, assignment formalities or a dispute, you need a lawyer who knows your jurisdiction.
  • Your contracts are already clear and your engineers review every change. Add an AI tool clause and carry on.
  • The code is a throwaway prototype you will rebuild. Ownership still matters, but a full review can wait.

Last reviewed: 29 September 2026. Vendor terms read on that date. General information; confirm with your adviser.

If you are commissioning a product and want ownership, review and handover built in from day one, talk to RAITHub about your build. The free 15-minute technical audit is followed by a fixed written quote, with IP assignment to you as standard.

Frequently asked questions

Who owns the code generated by AI?

Between you and the vendor, usually you: OpenAI, Anthropic and Lovable assign or confirm output to the customer, and GitHub says it does not own Copilot output. Copyright protection against third parties covers mainly the human-authored parts. This is general information; confirm with your adviser.

Can AI-generated code be copyrighted?

In the US, only the human contribution. The Copyright Office said in January 2025 that output is protected only where a human determined sufficient expressive elements, and that prompts alone are not enough. Other countries, including the UK, have different rules.

Does GitHub Copilot own the code it suggests?

No. GitHub's Generative AI Services Terms, which cover Copilot Business and Enterprise bought from GitHub, say GitHub does not own inputs or outputs. Other purchase routes can fall under different terms, so check yours.

Do I own an app I build with Lovable?

Lovable's terms say you own your customer data, including the apps you build, and the AI output generated for you, subject to third-party rights. The terms also grant Lovable a licence to use customer data, and output may resemble other users'.

What should a developer contract say about AI tools?

Points to raise with your lawyer: IP assignment of all deliverables however produced, disclosure of AI tools used, no confidential data in tools that train on inputs, an open-source licence inventory, human review of every change, and accounts in your company's name.

Does RAITHub assign IP in AI-assisted work to the client?

Yes. On every RAITHub engagement the client owns the IP, and an NDA is standard. RAITHub does not give legal advice, so have your own adviser review the contract.

who owns AI-generated codeAI code ownershipAI copyrightIP assignmentsoftware development contractGitHub Copilot termsopen-source licences

Ready to discuss your project?

Book a free 15-minute technical audit with our engineering team.