From Aryan Vatsa | Product & Market Analysis

AI Coding Assistant Indemnity Compared: Who Signs, and Who Makes You Sign

On this page

Of the five AI coding assistants most teams shortlist, 4 will defend a paying business customer against a third-party copyright claim over generated code. The fifth, Cursor, publishes terms in which the indemnity runs the other way: you defend Anysphere. AI coding assistant indemnity is decided less by which tool you pick than by which plan your developers are signed into, and most individual plans carry no cover at all.

Key takeaways

  • The plan decides the contract, not the product. Claude Code on Pro or Max runs under Anthropic's consumer terms, which contain no indemnity from Anthropic. The same tool on Team, Enterprise or the API runs under commercial terms that defend you.
  • GitHub dropped its filter condition in April 2026. Since 3 April 2026, Microsoft no longer requires the duplicate detection filter for copyright cover on GitHub Copilot. Google and OpenAI still withhold cover if you disable their citation or filtering tools.
  • Cursor's public terms offer no defence for generated code. Its September 2026 terms disclaim non-infringement and make you indemnify Anysphere for claims about your inputs. Its liability cap is the greater of 6 months of fees or $100.
  • Every clause excludes modified output, and code is always modified. GitHub, Anthropic, Google and OpenAI all carve out output that was changed or combined with other material. For an agent that edits across a repository, that carve-out is the clause to negotiate.
4 of 5Coding assistant vendors whose paid business terms defend you against IP claims on output. Source: each vendor's published terms, read 9 October 2026.
3 Apr 2026Date the duplicate detection filter stopped being a condition of copyright cover for GitHub Copilot. Source: Microsoft Learn, 2026.
$100Liability floor in both Cursor's terms and Anthropic's consumer terms, which cover Claude Code on Pro and Max. Source: Cursor, September 2026.

AI coding assistant indemnity: the short answer

Which AI coding assistant indemnifies you for copyright claims? On paid business plans, GitHub Copilot, Claude Code, Gemini Code Assist and OpenAI Codex all commit to defend you against third-party IP claims about generated output. Cursor's public terms do not. On free and individual plans, none of the five offers cover, and two make you indemnify the vendor.

This piece is written for the founder or engineering director who signs the tooling contract, and who alone can move developers from personal plans onto the ones with cover.

The table below compares the clauses as published, not as marketed.

AI coding assistant indemnity, clause by clause, as published October 2026
ClauseGitHub CopilotClaude CodeGemini Code AssistOpenAI CodexCursor
Who is defendedBusiness and Enterprise bought on a GitHub or Microsoft agreementTeam, Enterprise and API customers, paid use onlyStandard and Enterprise, paid use onlyAPI and business customersNobody, under the public terms
Individual or free plansNot covered. Personal customers are excludedNot covered. Pro and Max sit under consumer termsNot covered. Free use is excluded by definitionNot covered, per legal commentary on Plus and freeNot covered. You indemnify Anysphere
Filter or feature conditionNone since 3 April 2026None statedMust not disable citations, filters or other toolsMust not disable, ignore or skip citation, filtering or safety featuresNot applicable
Modified outputProduct must be unmodified as providedExcludedGrant covers unmodified output onlyExcludedNot applicable
Patent claimsNamed in the grantPractising a patented invention in an output is excludedOnly trademark use is excludedNot stated in the extracts reviewedNot applicable
Indemnity outside the liability capAmbiguous: Section 6.3 points to the cap, Section 7.1(d) exempts itYes, stated in Section L.3.bYes, stated in Section 12.3(b)Reported as uncapped in the Services AgreementCap is greater of 6 months of fees or $100
Previews and betasLiability capped at $500Not addressed in the clauses readNot addressed in the clauses readBeta Services excluded from indemnityNo liability for beta features

Sources are the documents listed in the references, retrieved 9 October 2026. The OpenAI column relies on search extracts of its Service Terms and Services Agreement because OpenAI's policy pages refused automated retrieval. Negotiated enterprise agreements may differ from every column.

Why the $1.5 billion settlement does not reach your repository

The largest number in AI copyright so far is a training-data number. Anthropic's $1.5 billion settlement with authors, approved on 20 July 2026, priced the acquisition of pirated books at roughly $3,000 per work across a list of 482,460 titles. How that number was built, and what it does to licensing prices, is covered in the breakdown of the copyright cases repricing training data.

That settlement answers a question your engineering team will never be asked. You did not build the corpus. The claim a software company can actually face is narrower: that a function, a file or a configuration your developers shipped reproduces someone else's protected code.

That is an output claim, which is what coding assistant indemnities are written for. It is also where the vendors differ, because the upstream risk is theirs by default while the downstream risk is yours unless a contract moves it.

Two vendors name training data explicitly. Anthropic's commercial terms define a covered claim to include allegations about data Anthropic has used to train a model that is part of the Services. Google runs a separate training data indemnity alongside its output indemnity in Section 20 of its Cloud service terms.

My view is that training data cover is worth less to a buyer than it looks. Plaintiffs have sued the labs, not their customers, and a settlement like Bartz releases the lab's conduct. The output clause is the one that would be tested if a claim ever landed on your desk.

GitHub Copilot indemnification after the filter came off

For three years, the standard advice on GitHub Copilot indemnification was simple: turn on the duplicate detection filter, set it to block, or lose your cover. That advice is now out of date.

What changed on 3 April 2026

Copilot's cover flows through Microsoft's Customer Copyright Commitment, which GitHub's terms import as a list of required mitigations. Microsoft's page now states that for GitHub Offerings there are no additional required mitigations as of 3 April 2026, and that the duplicate detection filter is no longer required for coverage.

The contract underneath moved too. GitHub retired its Copilot Product Specific Terms on 5 March 2026 and replaced them with the GitHub Generative AI Services Terms. Those apply only when purchased under a volume licensing agreement, and they exclude personal customers. If your agreement provides for the defence of third-party claims, that provision now applies to outputs.

I would still leave the filter on: a blocked suggestion is cheaper than a defended one. The change matters because a misconfigured organisation setting no longer voids the cover after the fact.

The cap clause that points two ways

The defence obligation itself sits in GitHub's General Terms. Section 6.3 covers claims that a paid product, used within the agreement and unmodified as provided by GitHub and not combined with anything else, infringes a patent, copyright, trademark or trade secret.

Section 6.3 then says it is subject to the Section 7 limitation of liability, which caps GitHub at fees paid in the prior 12 months. Section 7.1(d) says no limitation applies to obligations in Section 6. Those two sentences cannot both govern.

One detail favours Copilot buyers. The Generative AI Services Terms disclaim liability for non-GitHub products, but that disclaimer does not apply to third-party models GitHub has built into a service. On my reading, Claude or Codex used as an agent inside a paid Copilot plan inherits GitHub's defence clause rather than the model lab's.

Claude Code enterprise terms: the plan decides the contract

Claude Code's legal position changes with the login. Anthropic's own documentation lists two regimes: commercial terms for Team, Enterprise and Claude API users, and consumer terms for Free, Pro and Max users.

Team, Enterprise and API: defended, uncapped, no filter condition

Section K of the commercial terms covers third-party claims that paid, authorised use of the Services or the Outputs violates an intellectual property right. Anthropic will defend the customer and pay judgments and approved settlements. No setting has to be enabled for the cover to apply.

The exclusions are the familiar set. Modifications by the customer, combination with technology not provided by Anthropic, your own inputs and use you knew was infringing are all excluded. So are the practice of a patented invention contained in an output and trademark use in trade. Section L.3.b then states that the liability limits do not apply to either party's indemnification obligations. That is the clearest uncapped statement of the five. Wider carve-outs are compared in the review of the major model providers' contract terms.

Pro and Max: you indemnify Anthropic

The consumer terms, effective 8 October 2025, contain an indemnity in one direction only. The user agrees to indemnify and hold harmless Anthropic for claims arising from use of the services, products built with them, and any violation of third-party rights. Anthropic's liability is capped at the greater of 6 months of fees or $100.

This is the finding I would put in front of a board. A developer paying for Max on a personal card, running Claude Code against your company repository, has signed a contract that moves copyright risk from Anthropic onto that developer, and implicitly onto you. The tool is identical to the Team seat. The paper is the opposite. The same perimeter problem is mapped in more detail in the analysis of personal AI accounts inside company networks.

Which terms govern each plan, and whether the vendor defends you
VendorPlans with a vendor defencePlans without one
GitHub CopilotBusiness, Enterprise on a volume licensing or Microsoft agreementIndividual and personal plans
Claude CodeTeam, Enterprise, Claude API, and API through Bedrock or Google CloudFree, Pro, Max
Gemini Code AssistStandard, EnterpriseAnything provided free of charge
OpenAI CodexAPI, and Business or Enterprise workspaces under the business agreementFree and Plus, per published commentary
CursorNone in the public terms. An enterprise MSA may differHobby, Pro, Teams under the public terms

Plan names as published by each vendor in October 2026. The Cursor row reflects the public Terms of Service only; no MSA text is public.

Gemini Code Assist and Codex: indemnity with conditions attached

Google and OpenAI both indemnify, and both make that cover depend on your behaviour with their safety tooling. That shifts the burden of proof onto your configuration history.

Gemini Code Assist: uncapped, but only for unmodified output

Google's Gemini Code Assist FAQ states the product is a Generative AI Indemnified Service. The operative grant in Section 20(i) of the Google Cloud service terms covers allegations that an unmodified Generated Output from an indemnified service infringes a third party's rights.

Five exclusions follow. The second matters most for engineering teams: cover lapses if you disregard, disable, modify or circumvent source citations, filters, instructions or other tools Google provides. Gemini surfaces a citation when it quotes at length from existing code. Ignoring that citation is, on the plain wording, enough to lose the defence.

The cap position is strong. Section 12.3(b) of the Google Cloud terms says nothing in the agreement limits either party's liability for its indemnification obligations. Free services are excluded twice: once in the definition of an indemnified service, and again in Section 13.3(c).

OpenAI Codex: the strictest behavioural conditions

Codex used through a Business or Enterprise workspace falls under OpenAI's business agreement rather than the consumer terms. The output indemnity in OpenAI's Service Terms does not apply where the customer or its end users knew or should have known the output was likely to infringe. Nor does it apply where they disabled, ignored, or did not use any relevant citation, filtering or safety features. Modified output and combinations with non-OpenAI products are excluded too.

Two further clauses bite on coding specifically. The Service Terms say code output from features including Codex may be subject to third-party licences, including open source licences. Beta Services are excluded from any indemnification obligation, and coding agents ship features in preview constantly.

The phrase "did not use" is the one I would push back on in negotiation. Failing to disable a feature is a clear standard. Failing to use one is a standard a vendor can apply with hindsight to almost any workflow.

Four indemnity questions, five coding assistants Published terms, October 2026. Paid business tiers unless the row says otherwise. Copilot Claude Code Gemini CA Codex Cursor Business tier defended Yes Yes Yes Yes No Individual plan defended No No No No No Filter condition None None Yes Yes n/a Indemnity uncapped Unclear Stated Stated Reported n/a Blue is a written commitment in your favour. Amber needs configuration or legal reading. Red is no cover. Sources: vendor terms listed in the references. Codex cells rely on search extracts of OpenAI's terms.
Read the second row first. Every vendor leaves individual plans uncovered, so the plan your developers chose matters more than the tool your procurement team approved.

Cursor terms of service: the indemnity runs the other way

Cursor's growth is examined in the piece on Cursor's valuation and growth, but its public contract is the thinnest of the five on copyright. The Cursor terms of service, last updated 3 September 2026, contain no promise by Anysphere to defend you against claims about suggestions.

Section 13 runs the obligation in reverse. You agree to defend and indemnify Anysphere and its affiliates for misuse of the service, for breaching the terms, and for any claim that your input violates third-party intellectual property rights. Section 14 disclaims any warranty of non-infringement and states that use of suggestions is at your sole risk.

Section 1.4 adds a fact most buyers skim past: suggestions may be similar to or the same as suggestions given to other customers. Section 5.3 assigns you whatever rights Anysphere has in suggestions, "if any". The liability cap is the greater of fees paid in the prior 6 months or $100.

Why I would not read this as a verdict on Cursor

Cursor's terms state that if your organisation has a Master Services Agreement with Anysphere, that MSA governs instead. Its enterprise, pricing and security pages do not mention indemnity, but a negotiated MSA might contain one.

What a buyer can tell is that cover is not the default. If IP defence matters, ask for it in writing during an enterprise deal. A tool can win on capability, as the comparison of Claude Code, Cursor and Copilot on real work found, and still lose this one line of the procurement review.

What the vendor owes you when you are not on a business plan Published liability limits for free, individual or preview use, in US dollars. Not to scale below $500. Cursor, all public plans $100 flooror 6 months of fees, if greater. Anthropic consumer: Pro, Max $100 flooror 6 months of fees, if greater. GitHub previews $500maximum, General Terms 7.1(b) Google Cloud free services $5,000aggregate, Cloud terms 12.2. None of these tiers carries an IP defence from the vendor. Two of them carry one from you to the vendor. Sources: Cursor ToS 15.2; Anthropic Consumer Terms s.11; GitHub General Terms 7.1(b); Google Cloud Terms 12.2.
These are ceilings on what you could recover, not on what a claim could cost you. The gap between the two is the risk you carry by default.

The unmodified-output problem for AI-generated code

Every indemnity here, except Cursor's absent one, excludes output that was modified or combined with other material. GitHub's grant requires the product to be unmodified and not combined with anything else. Google's covers unmodified generated output only. Anthropic and OpenAI exclude modifications and combinations.

For marketing copy, that exclusion is narrow. For code, it describes the normal workflow. A suggestion is accepted, renamed, refactored, wrapped in a test and merged into a file that already contains human code. By the time anyone could allege infringement, the output has been modified and combined several times over.

Agents make the exclusion wider

Autocomplete produced a few lines a developer could point to. An agent edits a dozen files, runs tests, revises its own output and commits the result. Separating the unmodified vendor output from the surrounding changes becomes a forensic exercise, and the burden of doing it falls on whoever is claiming the cover.

No published clause defines how much change counts as modification. My position is that this is the single most valuable clarification to request: a written statement that ordinary integration, formatting and testing of an output does not take it outside the indemnity. Clauses of this shape are catalogued in the guide to agent liability caps and remedies.

Patents are where code risk actually concentrates

Copyright dominates the headlines, but software risk also sits in patents. Anthropic's commercial terms exclude claims arising from the practice of a patented invention contained in an output. GitHub's General Terms name patents in the grant. Google's generated output exclusions name trademark, not patent.

That difference matters to a company shipping algorithms in a crowded patent field. It is a reason not to treat these four indemnities as interchangeable.

Where this comparison is weakest

Published terms are not the terms a large buyer signs. Every vendor here negotiates enterprise agreements. This comparison is accurate for a team buying online, and it may understate what a large customer can extract.

OpenAI's terms were not read directly. Its policy pages refused automated retrieval during research. The exclusions quoted come from search extracts of the Service Terms, and the uncapped status comes from a search summary of the Services Agreement. That is weaker than the standard applied to the other four vendors.

No court has tested a coding assistant indemnity. Every reading above is a reading of text. How a judge would treat "unmodified", "did not use" or the GitHub cap conflict is unknown.

The competing view is that none of this matters much. Output claims against software buyers have been rare, and a careful team using code review and a licence scanner may never need any vendor's defence. My answer is that the indemnity is cheap to secure at signature and impossible to add after a claim arrives, and the personal-plan gap is a governance failure regardless of litigation odds. The scanners worth running for that review are compared in the guide to AI code security scanners.

Frequently asked questions

Does GitHub Copilot indemnify users for copyright infringement?

Yes, for Copilot Business and Enterprise bought on a GitHub volume licensing or Microsoft agreement. The cover flows through Microsoft's Customer Copyright Commitment, which since 3 April 2026 no longer requires the duplicate detection filter. Individual and personal plans are excluded. The defence clause in GitHub's General Terms covers products unmodified as provided, and its interaction with the liability cap is ambiguous on the face of the text.

Is Claude Code covered by Anthropic's copyright indemnity?

Only on Team, Enterprise and API usage, which runs under Anthropic's commercial terms. Those terms defend paid use against third-party IP claims, carry no filter condition, and exclude the indemnity from the 12-month liability cap. Claude Code on Free, Pro or Max runs under consumer terms, where the user indemnifies Anthropic and Anthropic's liability is capped at the greater of 6 months of fees or $100.

Does Cursor offer IP indemnification for generated code?

Not in its public terms of service, last updated 3 September 2026. The indemnity in Section 13 runs from the user to Anysphere, including for claims that your inputs violate third-party rights. The terms disclaim non-infringement and say suggestions may match those given to other customers. An enterprise Master Services Agreement overrides the public terms, so cover may be negotiable, but it is not the default.

What conditions void AI code copyright indemnity?

The common exclusions are modified or combined output, inputs you lacked rights to, and use you knew or should have known was infringing. Google also voids cover if you disable or disregard citations and filters. OpenAI voids it if you disabled, ignored or did not use its citation, filtering or safety features, and excludes beta services. Anthropic excludes patent practice and trademark use but imposes no filter condition.

Are free AI coding assistant plans covered by indemnity?

No. None of the five vendors compared here defends free or individual plan users against IP claims on output. Google excludes services provided free of charge by definition. GitHub's terms exclude personal customers. Anthropic's consumer terms and Cursor's terms both require the user to indemnify the vendor. If developers use personal plans on company code, the company carries the risk without any vendor backstop.

Is the AI code indemnity subject to the liability cap?

It depends on the vendor. Anthropic states in Section L.3.b that its liability limits do not apply to indemnification. Google's Section 12.3(b) excludes indemnification obligations from all limits. OpenAI's Services Agreement is reported to keep its output indemnity outside the cap. GitHub's General Terms contain conflicting sentences, one applying the cap to the defence clause and one exempting it, which is worth resolving in writing.

How to close the gap this week

Start with a list, not a contract. Ask finance for every expense claim or card charge from GitHub, Anthropic, Google, OpenAI and Anysphere in the last 90 days. Each individual subscription on that list is a developer working under terms that give your company no defence, and in two cases ask the developer to indemnify the vendor.

Then open the agreement for whichever tool your team uses most and find one sentence: the definition of modified output. If it is not defined, send the vendor a one-line request confirming that ordinary integration, formatting and testing of generated code keeps it inside the indemnity. The reply, or the silence, tells you what the clause is worth. File it with the contract clauses a finance team should check before renewal.

One question for your next renewal

Ask each coding assistant vendor to confirm in writing which plans carry the IP defence, whether it sits outside the liability cap, and what counts as modified output. A vendor that answers all three in one email has read its own contract.

References

  1. Microsoft Learn, Customer Copyright Commitment Required Mitigations, updated 13 July 2026. Used for the 3 April 2026 removal of the duplicate detection requirement for GitHub Offerings.
  2. GitHub, Generative AI Services Terms, version March 2026, and General Terms, version March 2025. Used for scope, the third-party model disclaimer, Section 6.3, Section 7.1 caps, the $500 preview cap and Section 7.1(d).
  3. Anthropic, Claude Code legal and compliance, retrieved 9 October 2026; Commercial Terms, effective 17 June 2025; Consumer Terms, effective 8 October 2025. Used for plan scope, Sections K and L.3.b, the user indemnity and the 6-month or $100 cap.
  4. Google Cloud, Service Specific Terms, Section 20, Platform Terms, retrieved 9 October 2026, and Gemini Code Assist FAQ, updated 7 October 2026. Used for indemnified status, the output grant, exclusions, Sections 12.2, 12.3 and 13.3.
  5. OpenAI, Service Terms, verified via search extracts on 9 October 2026. Used for output indemnity exclusions, Codex licence note and the beta exclusion.
  6. Cursor, Terms of Service, last updated 3 September 2026. Used for Sections 1.4, 5.3, 13, 14 and 15.2.
  7. Authors Guild, Court grants final approval of Anthropic copyright settlement, July 2026. Used for the settlement amount, approval date and per-work figure.

The weakest thing about this source base: OpenAI's policy pages refused automated retrieval, so its clauses were verified through search extracts rather than a direct read. All other vendor terms were read from the primary documents. Every vendor revises these terms without notice; check the version date before relying on any row.

AV
Aryan Vatsa
Contributing Analyst, Zan Digital. Founding product designer, writing here on how AI products are priced, packaged and measured against each other.

Related reading