Before the questions, make sure you can: explain what copyright, patents, trade secrets and trademarks protect in software; say who owns code written by employees and students (and why it depends on contracts and university policy); classify open-source licences as permissive, weak copyleft or strong copyleft, state their main obligations and check licence compatibility for distributed software and online services; use Creative Commons licences for course materials; discuss the legal status of AI-generated code and the risk of licence contamination; explain contracts, warranty disclaimers and liability for defective software; describe the risk-based approach of the EU AI Act and China's rules for generative-AI services, and why many education uses are high-risk; know that unauthorized access is a crime even "for testing"; and apply the ACM/IEEE Software Engineering Code of Ethics to real dilemmas, including fairness problems of AI tools in education.
Code is not only logic — it is also property, it comes with promises (licences, contracts), it is subject to regulation, and it affects people who never agreed to use it. An engineer who ignores the law can make a product unsellable (a GPL library in closed software), illegal (a prohibited AI practice), or a source of harm. And some things are legal but still wrong: professional ethics asks engineers to protect the public even when nobody is watching. AI makes every one of these questions harder.
This chapter gives engineers enough knowledge to recognize legal issues and ask good questions. It is not legal advice; laws differ between countries and change. Real decisions involve lawyers and the university's legal office.
Intellectual property in software
| Right | Protects | How you get it | Software example |
|---|---|---|---|
| Copyright | The expression: source code, object code, documentation, UI texts and graphics | Automatically, when the work is created | StudyBuddy's Java code and screens |
| Patent | An invention: a technical solution that is new, inventive (non-obvious) and industrially applicable | Application and examination; about 20 years | A new technical method for compressing video lectures |
| Trade secret | Valuable confidential information kept secret with reasonable measures | By keeping it secret (NDAs, access control) | A company's ranking algorithm, internal prompts |
| Trademark | Names and logos that identify a product's origin | Use and/or registration | The name "StudyBuddy" and its logo |
Copyright protects expression, not ideas. The idea "match students by overlapping free time" is free for anyone; your particular code is protected. Rewriting someone's code line by line with new variable names can still infringe, because the expression was copied. In China, software is protected by the Copyright Law and the Regulations on the Protection of Computer Software; copyright generally lasts for the author's life plus 50 years in China and life plus 70 years in the EU and the USA.
Software patents are handled differently around the world. In the USA, the Supreme Court's Alice v. CLS Bank decision (2014) made patents on abstract ideas implemented on a generic computer invalid; the European Patent Office requires "technical character"; China grants patents for software-related inventions that solve a technical problem with technical means. Engineers mainly need to know that patents exist, that independent invention is not a defence against a patent (unlike copyright), and that some open-source licences include patent grants.
Trademarks: before launching, check that "StudyBuddy" is not already a registered trademark for educational software — renaming an app after launch is expensive.
Who owns the code?
- Employees: in most countries, software written by employees as part of their job belongs to the employer (in China, the Copyright Law has special rules for works created in the course of employment; contracts usually settle it).
- Contractors/freelancers: ownership follows the contract; without a clear assignment clause, the contractor may keep the copyright.
- Students: ownership of student projects is usually defined by university policy and any agreement with a project sponsor. StudyBuddy's team must check WKU's policy before choosing a licence or signing anything with a company.
Open-source licences
"Open source" does not mean "no rules". Code without any licence is all rights reserved — you may read it on GitHub but not legally reuse it. An open-source licence grants permissions under conditions.
| Family | Licences | Main conditions |
|---|---|---|
| Permissive | MIT, BSD, Apache 2.0 | Keep copyright and licence notices; Apache 2.0 also requires stating changes, keeping the NOTICE file, and includes an explicit patent licence (with termination if you sue over patents) |
| Weak copyleft | LGPL, MPL 2.0, EPL | Changes to the licensed files/library must stay under the same licence; your own code that only uses the library can have any licence (conditions on linking for LGPL) |
| Strong copyleft | GPL v2, GPL v3 | If you distribute a work based on GPL code, the whole work must be distributed under the GPL, with source code |
| Network copyleft | AGPL v3 | Like GPL v3, plus: if users interact with a modified version over a network, you must offer them the source |
The key trigger for GPL obligations is distribution (giving copies to others: an app in an app store, software shipped to customers). Running GPL software on your own server to provide a web service is usually not distribution — the so-called "SaaS loophole" — which is exactly what the AGPL closes.
Compatibility — can code under licence A be combined with code under licence B in one distributed work?
- MIT/BSD code can go into almost anything, including GPL and proprietary software (keep the notices).
- Apache 2.0 code can be combined with GPL v3, but is considered incompatible with GPL v2 (because of its patent-termination and other terms).
- GPL code cannot be included in proprietary software that you distribute.
- For StudyBuddy's Android app (distributed through app stores), a GPL library would require publishing the whole app under the GPL; for the backend (not distributed), the GPL is less restrictive — but an AGPL library would require offering the source of the modified backend to its users.
Creative Commons (CC) licences are used for content, not code: CC BY (attribution), CC BY-SA (share-alike), CC BY-NC (non-commercial), CC BY-ND (no derivatives), and combinations. Instructors uploading slides to StudyBuddy should know which licence covers any textbook figures they include — and Buddy quoting those slides is a use of the material.
Public ≠ licensed. No licence file means no permission. And "free" licences still have conditions (notices, same licence, source code). Every dependency needs a known, compatible licence — checked automatically in CI (the SBOM from Chapter 10 records licences too).
AI-generated code and copyright
Three questions matter:
- Can AI output be protected by copyright? In the United States, the Copyright Office's position is that copyright requires human authorship; material generated by AI without sufficient human creative control is not protected, while human selection, arrangement and modification can be (courts confirmed the human-authorship requirement in Thaler v. Perlmutter). In China, the Beijing Internet Court decided in 2023 that an AI-generated image was protected because the user's prompts and parameter choices showed intellectual input. The law is still developing and differs by country.
- Can AI output infringe someone else's copyright? Models trained on public code sometimes reproduce verbatim fragments, including code under GPL or other licences — "licence contamination". Several lawsuits about training data and outputs are ongoing (for example the class action against GitHub Copilot filed in 2022 and the New York Times case against OpenAI filed in 2023). Some tools offer filters that block suggestions matching public code.
- What do the tool's terms say? Business terms of AI tools differ in who owns output, whether the vendor offers indemnity against copyright claims, and whether your code may be used for training.
Practical rules for StudyBuddy: prefer small, reviewed AI suggestions over large pasted blocks; enable duplicate-detection filters where available; run a licence/similarity scan in CI for large generated files; record significant AI use (the AI-use log from Chapter 2); never paste proprietary or confidential code into tools whose terms allow training on it.
Contracts, warranties and liability
- Licences and terms of service are contracts between the software provider and users.
- Warranty disclaimers: almost all open-source licences say the software is provided "AS IS", without warranty, and exclude liability. Commercial contracts often limit liability to the price paid. Such clauses are limited by law: they cannot always exclude liability for personal injury or gross negligence, and consumer-protection laws override some of them.
- Negligence: failing to take the care a reasonable professional would take (no testing of safety-critical code, ignoring known vulnerabilities) can create liability.
- Product liability: the European Union's revised Product Liability Directive (2024) explicitly treats software, including AI systems, as a product, so producers can be liable for damage caused by defective software — including defects from missing security updates.
- Service-level agreements (SLAs) promise availability and support, with penalties (Chapter 5's "transfer" risk response).
Regulating AI
EU AI Act (Regulation (EU) 2024/1689, in force since August 2024, applying in stages from 2025 to 2027) takes a risk-based approach:
| Risk level | Examples | Consequence |
|---|---|---|
| Unacceptable (prohibited) | Social scoring by public authorities; manipulative techniques causing harm; emotion recognition in workplaces and educational institutions (except for medical or safety reasons) | Banned |
| High risk | AI used in education to decide admission, evaluate learning outcomes, steer the learning process, assess the appropriate level of education, or detect cheating during tests; also employment, credit, law enforcement… | Risk management, data governance, documentation, logging, transparency, human oversight, accuracy and robustness, conformity assessment |
| Limited risk (transparency) | Chatbots; AI-generated content | People must be told they are interacting with AI; synthetic content labelled |
| Minimal risk | Spam filters, AI in video games | No specific obligations |
For StudyBuddy: Buddy as a tutoring chatbot has transparency duties ("you are talking to an AI"); an AI that grades students or flags them for cheating would be high-risk; a camera feature that detects "student engagement" from facial expressions would be prohibited in the EU.
China regulates generative AI through the Interim Measures for the Management of Generative AI Services (in force since 15 August 2023): providers of public generative-AI services must respect content rules, protect personal information, prevent discrimination, label generated content and handle complaints; further rules on labelling AI-generated synthetic content took effect in September 2025. Other countries and states are adopting their own rules; the direction is clear: transparency, human oversight and accountability.
Computer-misuse law
Accessing a computer system without authorization is a crime in China, the EU, the USA and most other countries — also when the intention is "just to test security" or "to show them the bug". Penetration testing (Chapter 10) requires written permission and an agreed scope. Found a vulnerability in someone else's system? Follow their responsible disclosure / vulnerability-reporting process instead of exploiting it.
Professional ethics
Law sets the minimum; ethics asks what a good professional should do. The ACM/IEEE-CS Software Engineering Code of Ethics and Professional Practice (1999) has eight principles:
- Public — act consistently with the public interest (the first and highest principle).
- Client and employer — act in their best interests, consistent with the public interest.
- Product — ensure products meet the highest professional standards possible.
- Judgment — maintain integrity and independence in professional judgment.
- Management — managers promote an ethical approach to development and maintenance.
- Profession — advance the integrity and reputation of the profession.
- Colleagues — be fair to and supportive of colleagues.
- Self — lifelong learning and ethical practice.
The ACM's general Code of Ethics (2018) adds principles such as avoid harm, be honest and trustworthy, be fair and take action not to discriminate, and respect privacy.
A case: Volkswagen (2015). Engineers wrote software for diesel cars that detected when the car was on an emissions test bench and only then fully activated emission controls; on the road, the cars emitted far more nitrogen oxides than allowed. About 11 million vehicles were affected; the company paid tens of billions of dollars in fines and settlements, and at least one engineer was sentenced to prison in the United States. "My manager told me to" did not protect anyone. The code worked exactly as designed — the design was the problem.
Ethics of AI in education. Tools that judge students can be unfair even when they seem objective. A 2023 Stanford study found that popular detectors of AI-generated text classified more than half of essays written by non-native English speakers (TOEFL essays) as AI-generated, while almost never flagging essays by US-born students. At a university like WKU, where most students write in their second language, using such a detector to accuse students would be discriminatory. Ethical principles — avoid harm, be fair, keep a human in the loop, allow students to contest decisions, be transparent about AI use — are therefore not decorations but design requirements.
Making an ethical decision (a practical process):
- What are the facts? Who are the stakeholders (especially those with no voice)?
- What are the options?
- What do the law, the code of ethics and the organization's policies say?
- Which option best protects the public and the people affected? Could you explain it publicly?
- Act, document, and — if you are asked to do something harmful — raise it internally, and, if necessary, through proper external channels.
For licence questions, always ask: is the software distributed (app, download) or only offered as a service? Then check each dependency's licence family and compatibility. For ethics questions, name the stakeholders, the Code principles involved (especially Public), and a concrete action — not just "be ethical".
Key takeaways
- Copyright protects code as expression (automatically); patents protect inventions (examined, ~20 years, independent invention no defence); trade secrets and trademarks protect secrets and names.
- Ownership of code follows employment law, contracts and — for students — university policy.
- Open-source licences: permissive (MIT, BSD, Apache 2.0 with patent grant), weak copyleft (LGPL, MPL), strong copyleft (GPL: triggered by distribution), AGPL (also network use). No licence = no permission. Check compatibility (Apache 2.0 ✓ GPL v3, ✗ GPL v2).
- AI output: copyright status varies by country (human authorship); outputs can reproduce licensed code; tool terms matter — review, filter, scan, log.
- Contracts disclaim warranties within legal limits; negligence and product liability (EU 2024: software is a product) still apply.
- EU AI Act: prohibited / high-risk (many education uses) / transparency (chatbots) / minimal. China regulates generative-AI services and content labelling.
- Unauthorized access is illegal, even for "testing"; use permission and responsible disclosure.
- ACM/IEEE Code: Public first; ethics is part of design — Volkswagen shows code can be the instrument of wrongdoing; biased AI tools in education cause real harm.
Ready? Close the notes and practise.
30 questions. Predict the output before you check — that is the skill the exam measures.