FCA authorised · FRN 724952 0117 325 0027Quote & buy →
Apex Insurance Brokers
Speak to a brokerGet a quote →

IT contracts

Open source licences and liability, explained for software firms

An open source licence is a copyright licence that lets anyone use, change and share software, subject to conditions such as keeping notices or publishing source code. It matters for insurance because breaking those conditions can end the licence and turn your use into copyright infringement, and the client warranties you give on top are yours alone.

In short

Open source code is not public domain: it is copyright work used under licence. Permissive licences such as MIT and Apache 2.0 mainly require you to keep copyright and licence notices. Copyleft licences such as the GNU GPL require that, if you distribute a program built on GPL code, you license the whole work under the GPL and provide its source. The AGPL extends this to users interacting with modified software over a network. Breach can terminate the licence, leaving you exposed to an infringement claim. Every major licence disclaims warranties, so promises you give clients about code you deliver are yours to stand behind. PI or IP cover may respond, subject to the terms.

Start your PI proposal →or call 0117 325 0027 to speak to a broker

How an open source licence works

Last reviewed 7 October 2026 by the Apex professional indemnity team.

Software is protected by copyright in the UK. The Copyright, Designs and Patents Act 1988 treats a computer program as a literary work (section 3). Copying it, issuing copies to the public and making an adaptation are acts only the owner can authorise (section 16(1)), and doing them without a licence infringes (section 16(2)).

An open source licence is that permission, given to everyone in advance on stated conditions. The Open Source Initiative’s Open Source Definition sets the criteria a licence must meet to count as open source, including free redistribution and access to source code. Within that definition, licences differ sharply in what they ask of you.

Permissive and copyleft licences compared

LicenceFamilyMain conditions when you distributeSource disclosure?
MITPermissiveInclude the copyright notice and permission notice in all copies or substantial portionsNo
Apache 2.0PermissiveGive recipients a copy of the licence; mark files you changed; keep copyright, patent and attribution notices; pass on any NOTICE file (section 4)No
GNU GPL v2 and v3CopyleftLicense the whole work based on the program under the GPL; with object code, also provide the corresponding source (GPLv3 sections 5 and 6)Yes, to those you distribute to
GNU AGPL v3Network copyleftAs the GPL, plus: if you modify the program, offer its source to users who interact with it remotely over a network (section 13)Yes, including to network users

GNU describes copyleft as requiring that anyone who redistributes the software, with or without changes, must pass on the freedom to copy and change it. Its GPL FAQ states that you cannot incorporate GPL-covered software in a proprietary system and release that system under other terms.

When the obligations bite: distribution and network use

Most conditions attach to distribution, not use. That is why the same library can be harmless for one business model and a problem for another.

Two illustrative examples, not real claims. A developer builds a mobile app for a retailer using a GPL component and the retailer ships it in app stores without source; the retailer then faces a demand from the copyright holder and blames the developer. A SaaS firm modifies an AGPL database tool but never offers the source to users; a buyer’s due diligence finds it and reduces the price.

What happens when you breach a licence

Breach does more than create a contract claim. It can remove your permission to use the code at all.

In practice the cost is often remediation: replacing a component, rewriting code or releasing source you meant to keep closed, and dealing with the client whose product is affected.

Warranty disclaimers: why the risk lands on you

Open source authors give you the code with no promises. The MIT licence says the software is provided “as is”, without warranty of any kind, including non-infringement. Apache 2.0 disclaims warranties of title and non-infringement (section 7) and excludes contributor liability (section 8). GPLv3 sections 15 and 16 do the same, saying the entire risk as to quality and performance is with you.

Apache 2.0 section 9 adds that if you offer a warranty or indemnity when redistributing, you do so only on your own behalf and must hold contributors harmless. So when your client contract says deliverables are free of third-party claims, contain no copyleft code, or will be indemnified against IP infringement, nobody upstream shares that promise.

How PI and IP cover respond

Insurance for open source problems depends on the cause of the loss and the policy wording. Technology PI often includes some IP infringement cover; others leave it limited or excluded. See does PI cover intellectual property infringement?

ClaimCommonly looked toWatch for
Copyright holder sues you for infringement after a licence breachPI with IP infringement cover, or a separate IP policyPatent claims are commonly excluded; some wordings exclude knowing or deliberate infringement
Client claims you negligently delivered code with undisclosed copyleft componentsPI, as a breach of professional dutyRemediation you do for free may not be covered
Client relies on your warranty or IP indemnityPI, often only to the extent you would be liable without the warrantyContractual liability exclusions; uncapped indemnities
Cost of rewriting code or releasing sourceRarely insuredUsually treated as your own business cost

For the IP side of a technology business more broadly, see media and IP liability for tech companies.

What to check

  1. Keep an inventory of open source components and their licences for each product or client deliverable.
  2. Before using GPL or AGPL code, decide whether you or your client will distribute it or offer it over a network.
  3. Keep notices, licence copies and NOTICE files in what you ship.
  4. Limit IP warranties and indemnities to what you can check, and cap them.
  5. Tell your broker if you build, distribute or host software, so the IP cover matches what you do.

Building or shipping software for clients?

If this affects your business, these are the points a broker will ask about:

Speak to a broker

PI with IP cover for software firms, placed by a named broker

Start the online proposal and save it as you go, or leave your number and a named broker will call you back, usually the same working day.

Start your PI proposal →or call 0117 325 0027

How Apex places this cover

Apex Insurance Brokers is an independent insurance broker based in Bristol, established in 2009 and authorised and regulated by the Financial Conduct Authority. We are not tied to one insurer: we work with over 30 markets, including Lloyd’s syndicates through wholesale brokers, and every client has a named broker who handles the placement, mid-term changes, certificates for clients and the renewal.

Related guides

Sources

Frequently asked

What is the difference between permissive and copyleft licences?

Permissive licences such as MIT and Apache 2.0 let you use the code in closed products, provided you keep the required notices. Copyleft licences such as the GNU GPL require that a work based on the code is licensed under the same terms, with source provided, whenever you distribute it.

Do I have to publish my source code if I use GPL software?

Only if you distribute the work based on it. The GPL FAQ says you can modify GPL code and use it privately, including within a company, without releasing it. Giving copies to clients or other organisations counts as distribution. The AGPL also requires you to offer source to network users of a modified version.

What happens if you breach an open source licence?

Your rights under the licence can terminate. GPLv3 ends rights automatically on breach but allows reinstatement if you stop, with a 30-day cure on first notice. GPLv2 has no cure period. Using the code without a licence is copyright infringement, for which the owner can seek damages or an injunction.

Does professional indemnity insurance cover open source licence claims?

Sometimes. Many technology PI wordings include intellectual property infringement cover, which may respond to a copyright claim or a client’s negligence claim, subject to the terms. Patent claims, deliberate infringement and liability you take on through warranties or indemnities are commonly excluded or limited. Remediation costs are rarely insured.

Is open source software provided with any warranty?

Generally no. The MIT licence provides the software “as is” without warranty, including of non-infringement, and Apache 2.0 and the GPL disclaim warranties too. If you warrant code to a client, you carry that promise yourself; Apache 2.0 says you then act only on your own behalf.

Ready to compare cover?

Tell us how you build and deliver software and send your client IP clauses with your proposal; a broker will check the IP cover you need. Or call 0117 325 0027.

Start your PI proposal Call 0117 325 0027

Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority. Registered in England and Wales, company number 07014570. This page is general information, not advice on your individual circumstances. Cover is always subject to the insurer’s acceptance and the policy terms, and this page does not guarantee that cover will be available or on what terms.