[ MSP.DD ] For investors and founders · Updated
What open-source licence risks show up in tech due diligence?
Short answer
Licence conflicts are common. Black Duck's 2025 analysis of 965 commercial codebases found licence conflicts in 56% of them, and open source with no licence or a custom licence in 33%. A copyleft component in the wrong place can force a company to release its own code or renegotiate customer contracts.
Why it matters
Licence problems rarely stop a deal, but they change its terms: warranties, a fix before closing, or a lower price. They're cheap to find and expensive to discover later.
How to check
- 01Generate a full dependency list, including transitive dependencies.
- 02Flag copyleft licences such as GPL and AGPL in distributed or hosted products.
- 03Flag components with no licence or a custom licence.
- 04Check the licence terms of AI models and datasets too, not only code.
Red flags
- AGPL components inside a hosted product.
- Code copied from the internet with no licence.
- Open-weight models used against their licence terms.
Good signs
- A maintained software bill of materials.
- Licence checks in the build pipeline.
The numbers
- Black Duck's 2025 OSSRA found licence conflicts in 56% of 965 audited commercial codebases, with transitive dependencies causing nearly 30% of them. [1]
- 33% of the audited codebases contained open source with no licence or a customised licence. [1]
- Only 77% of dependencies could be identified through package manager scanning. [1]