Open-source software – issues we see cropping up in practice
Open-source software (OSS) is software that is free to redistribute, with the source code being distributed as well as the object code. It is widely acknowledged using OSS components in software development can help reduce time and effort being expended recreating functionality that already exists. Consequently, it can speed up innovation.
OSS has been embraced by developers – according to the Synopsis 2023 Open Source Security and Risk Analysis, 96% of scanned codebases contain OSS and 76% of code in those codebases is open source.
However, although use of OSS presents benefits, we are seeing open-source licence issues throwing a spanner in the works in corporate acquisitions. Technology businesses should be aware of these potential issues.
The issue with restrictive OSS
Different licence terms apply to different types of OSS, and some open-source licence terms are more “aggressive” than others. Broadly speaking, OSS licences can be categorised as either “permissive” or “restrictive”. Permissive licences typically require only that the original OSS continues to be distributed on the same terms as those on which it was provided. This may include attributing copyright to the original author. It is restrictive licences that can cause particular issues – they may impose licensing conditions where the OSS is changed or combined with any other software and a “derivative work” is created. It is in connection with these types of licences that the term “copyleft” gets used.
“Copyleft” is the requirement that the freedoms the OSS licence guarantees (including freedom to use the source code without payment) also apply to new works derived from or containing the original restrictive-licensed software. The most common restrictive OSS licences are the General Public Licence (GPL) family of licences. Businesses should monitor their use of restrictive OSS because its use can create a “viral” chain of freedom-to-use.
In corporate transactions that we have been advising on, unchecked use of OSS has given rise to risks that have troubled potential buyers and raised question marks over the target’s value. Particular licences that have come under scrutiny on transactions we have been working on include the GPL v2, GPL v3, LGPL 2.1, LGPL 3 and the MongoDB Server Side Public Licence (SSPL). The risks have included, among other things:
- Breach of copyright, for which remedies include damages or an account of profits
- Unintended licensing of the target’s core source code under the OSS licence because it is derived from OSS.
- Reputational damage from negative publicity, and potential damage to brand value. There are examples of individuals and organisations looking for signs that certain OSS has been used in software products in breach of OSS licence terms and posting details online where they feel they’ve identified a breach.
- Need for time and expense to be incurred to reduce reliance on OSS licensed on a restrictive basis
- Security vulnerabilities
Recommendations
To avoid the risks referred to above, we recommend that tech businesses have a policy that is followed internally and regulates what OSS is used. Relevant principles to cover include awareness of:
- What OSS is being used – have a process to capture details of OSS used to help governance
- What licence terms apply to the OSS being used – using OSS licensed on “restrictive” terms should only be done when the consequences of the licensing arrangement are understood
- What the OSS does and in which products is it being used – is the OSS being combined with other software that will create a “derivative work”?
- Approvals required for use of OSS in the business – certain OSS licences could be pre-approved, if they are “permissive” licences. Who do developers need permission from if they want to use OSS licensed on terms that haven’t been pre-approved?
More in Technology
Inclusivity in youth rugby: Darren Rea is honoured at UK Coaching...
Last week at the UK Coaching Awards in Leeds, our colleague, Darren Rea was recognised for his inspirational work coaching young people with Special Educational Needs and Disabilities (SEND).
Discover How to Use AI Safely to Grow & Future-Proof Your...
One hundred local business leaders will gather on Friday 19th September 2025 at the Leonardo Royal Hotel Oxford for a high-impact networking breakfast and extended workshop designed to help SMEs harness the power of AI — safely, securely, and with immediate business benefit.
Tech & Innovation Ecosystem with Ebbon Group
B4 was delighted to host a recent Tech & Innovation Ecosystem roundtable with Craig Gibbin and Rob Pilkington, Joint CEOs of Ebbon Group. The session brought together 12 leaders to gain a deeper insight into how this pioneering Oxfordshire business is shaping the future of the global automotive industry.
From this author
End of 2025: Business reflections from Mills & Reeve
As we wrap up 2025, it’s a good moment to pause and reflect on what’s been an eventful year for Oxfordshire and to look ahead at what’s on the horizon for 2026.
Innovation gap opening due to varying AI adoption – Mills &...
An innovation and governance gap is opening up between businesses that realise the potential of GenAI and those that see its impact as limited, our new report has found.
According to The Critical AI Window, organisations that don’t find ways to capitalise on the potential of AI to drive innovation and growth run the risk of being left behind. As a result, competitive edge is at risk.
Our report shows that less than a third of businesses (31%) are using GenAI, with only one-fifth (22%) seeing it as high value.
Paul Knight, partner at Mills & Reeve said: “There is a clear divide amongst businesses – between those that have bought into AI and are building systems and processes around it, and those that are still unsure of its impact beyond mid- to low-value tasks, such as reducing administration and improving efficiencies and productivity.
“This divide is opening up an innovation and governance gap, as early innovators seize on the opportunities that AI presents. While our research shows that the number of businesses using GenAI is likely to rise to 72% by 2027, the lag in performance between then and now could become insurmountable.”
The report highlights the biggest concerns felt by businesses over AI adoption. The majority (90%) are concerned about inaccuracy, more than eight in ten are worried about safety risks (85%), such as cyber attacks, with the impact on future employment also a cause for concern. However, despite 83% of respondents stating that are worried about regulatory compliance, only 31% of businesses have a risk mitigation strategy in place.
Paul added: “The explosion of GenAI has seen a raft of regulations introduced across the world, with more likely, and all of them subject to change as AI understanding develops. In the UK, the regulation of AI relies on existing legal frameworks such as intellectual property, data protection and contract law, highlighting the growing need for these frameworks to be adapted to address the novel risks and complexities introduced by AI technologies. All this suggests that there will be no steady state for regulation for some time.”
However, the risk of not complying is significant, both reputationally and financially. Within the EU, under the EU AI Act, for example, violations can cause administrative fines of €35 million or 7% of total global turnover, whichever is greater.
“There is a real need for businesses to set their own guardrails as legislation in the UK catches up. If they don’t fully understand the legal and ethical boundaries – whether around data protection, intellectual property, or equality law – the consequences could be profound. A single misjudgement could expose the organisation to group litigation.”
Mills & Reeve announces record turnover of £181m as new head...
Leading UK law firm Mills & Reeve has announced turnover growth of £13 million over the 2024/25 financial year, resulting in a new high annual turnover of £181 million. Its Oxford office has seen standout success, with 55% fee growth and a new head of office appointed to lead its next chapter.


