License Compliance Checker (LCC)
Know what you ship. Know what you owe.
The only open-source scanner that combines dependency license detection, AI model license analysis, and EU AI Act Article 53 compliance — in a single tool.
Built by AI Exponent LLC. Free and open source under Apache 2.0.
Quick Start
pip install license-compliance-checker
# Scan a project
lcc scan .
# Scan with EU AI Act compliance policy
lcc scan . --policy eu-ai-act-compliance --format json
# Generate a CycloneDX SBOM
lcc sbom generate scan-report.json --format cyclonedx --output sbom.json
# Check GPL contamination in a SaaS context
lcc scan . --project-license Apache-2.0 --context saas
What LCC does
- AI model license detection, including HuggingFace models resolved by Hub ID and GGUF / ONNX model files
- EU AI Act Article 53 assessment and compliance-pack output
- A training-data risk registry that flags datasets with commercial-use restrictions
- SBOM generation in CycloneDX and SPDX
- Policy-as-code with OPA Rego or YAML policies
- Free and open source under Apache-2.0
Architecture
graph TD
CLI["CLI · FastAPI Server · GitHub Action · VS Code Extension"]
DET["Detectors\nPython · Node.js · Go · Rust · Ruby\nJava · .NET · HuggingFace · GGUF/ONNX"]
RES["Resolvers\nPyPI · npm · Crates.io · Maven\nGitHub API · ClearlyDefined · HF Hub API"]
POL["Policy Engine\nOPA Rego · YAML policies\nPermissive · Strict · EU AI Act"]
REG["Regulatory Assessor\nEU AI Act Article 53"]
OUT["Outputs\nJSON · HTML · Markdown · CSV\nCycloneDX SBOM · SPDX SBOM\nArticle 53 compliance pack"]
CLI --> DET
DET -->|"detected components"| RES
RES -->|"resolved licenses"| POL
POL -->|"violations + warnings"| REG
REG --> OUT
style CLI fill:#1e3a5f,color:#fff
style DET fill:#1e3a5f,color:#fff
style RES fill:#1e3a5f,color:#fff
style POL fill:#c9a84c,color:#000
style REG fill:#c9a84c,color:#000
style OUT fill:#2d5a2d,color:#fff
Ecosystem Coverage
graph LR
LCC["LCC\nScanner"]
PY["Python\npip · Poetry · Conda"]
JS["JavaScript\nnpm · Yarn · pnpm"]
GO["Go\ngo.mod"]
RS["Rust\nCargo.toml"]
JV["Java\nMaven · Gradle"]
RB["Ruby\nBundler"]
DN[".NET\nNuGet"]
HF["HuggingFace\nHub API · Model cards\nGGUF · ONNX"]
LCC --> PY
LCC --> JS
LCC --> GO
LCC --> RS
LCC --> JV
LCC --> RB
LCC --> DN
LCC --> HF
style LCC fill:#1e3a5f,color:#fff
style HF fill:#c9a84c,color:#000
EU AI Act Article 53 Coverage
GPAI obligations under Article 53 have applied since 2 August 2025 for models placed on the market from that date; models placed earlier must comply by 2 August 2027. The Commission's supervision and enforcement powers, including fines, begin 2 August 2026. LCC automates evidence gathering for each sub-obligation:
graph TD
A53["Article 53\nObligations"]
A["53(1)(a)\nTechnical documentation\n→ SBOM with model type,\nversion, license metadata"]
B["53(1)(b)\nDownstream provider info\n→ Model card capabilities\nand limitations extracted"]
C["53(1)(c)\nCopyright policy\n→ Training data licenses\nand copyright flags"]
D["53(1)(d)\nTraining data summary\n→ Dataset descriptions\nfrom model cards"]
E["53(2)\nSystemic risk\n→ 65B+ parameter\nmodel detection"]
A53 --> A
A53 --> B
A53 --> C
A53 --> D
A53 --> E
style A53 fill:#1e3a5f,color:#fff
style A fill:#1e3a5f,color:#fff
style B fill:#1e3a5f,color:#fff
style C fill:#1e3a5f,color:#fff
style D fill:#1e3a5f,color:#fff
style E fill:#c9a84c,color:#000
Scope note: LCC generates audit evidence for Article 53 documentation obligations. It is not a legal compliance determination. Involve qualified legal counsel for final compliance assessment.
Penalty band: Non-compliance with Article 53 is sanctionable by the Commission under Article 101(1) at up to €15M or 3% of global annual turnover, whichever is higher. Note that GPAI fines are Commission-imposed under Art. 101 — distinct from the Art. 99 fines imposed by member-state market-surveillance authorities for high-risk-system violations. Source: Regulation (EU) 2024/1689, Art. 101(1).
AI Model Detection
LCC scans your codebase for AI model references without requiring a local download:
# Detects from_pretrained("org/model") references in Python / YAML / JSON
lcc scan .
# Detects GGUF and ONNX model files (Ollama / llama.cpp)
lcc scan /path/to/models
# Full transitive scan with lock file
lcc scan . --include-transitive --policy permissive
Supported AI license families: the OpenRAIL family (including BigScience BLOOM and CreativeML variants), Llama 2 / 3 / 3.1, Gemma, and Mistral, plus provider licenses from Anthropic, OpenAI, Cohere, and AI21. The registry holds 17 AI license definitions and also recognises standard SPDX identifiers.
Training data risk registry: Flags datasets with commercial use risk — OpenAI API outputs, ShareGPT, Books3, The Pile classified as high/critical risk.
Policy Enforcement
# Built-in policies
lcc scan . --policy permissive # Allow MIT, Apache-2.0, BSD only
lcc scan . --policy strict # Block all copyleft
lcc scan . --policy eu-ai-act-compliance # Article 53 GPAI obligations
# Custom policy (YAML)
cat > my-policy.yaml << EOF
name: my-saas-policy
rules:
- license: GPL-3.0
action: block
reason: "GPL-3.0 requires SaaS source disclosure"
- license: AGPL-3.0
action: block
- license: RAIL
action: warn
reason: "Review RAIL restrictions before deploying"
EOF
lcc scan . --policy my-policy.yaml
CI/CD Integration
# .github/workflows/license-check.yml
- name: License compliance scan
uses: aiexponenthq/license-compliance-checker/.github/actions/license-compliance@v1
with:
path: .
policy: eu-ai-act-compliance
fail-on: violations
format: json
output: license-report.json
SBOM Generation
# CycloneDX 1.5 with EU AI Act regulatory extensions
lcc sbom generate scan-report.json --format cyclonedx --output sbom.cdx.json
# SPDX 2.3
lcc sbom generate scan-report.json --format spdx --output sbom.spdx.json
# Sign with GPG for tamper-evidence
lcc sbom sign sbom.cdx.json --key ~/.gnupg/key.gpg
Known Limitations
- HuggingFace Hub API scanning requires referenced model IDs (not local downloads only).
- SPDX
AND/ORcompound expressions are flagged for manual review, not auto-resolved. - Transitive dependency resolution requires a lock file (
poetry.lock,package-lock.json). - Article 53 assessment covers documentation completeness only — not a legal compliance determination.
- Training data risk registry covers top-50 known datasets; unknown datasets flagged for review.
Contributing
See CONTRIBUTING.md. Issues and PRs welcome.
git clone https://github.com/aiexponenthq/license-compliance-checker
cd license-compliance-checker
pip install -e ".[dev]"
pytest
License
Apache 2.0 — free to use, modify, and distribute.
Built by AI Exponent LLC — hello@aiexponent.com
Part of the AiExponent open-source AI governance toolchain: license-compliance-checker · rag-benchmarking · RiskForge
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file license_compliance_checker-2.0.0.tar.gz.
File metadata
- Download URL: license_compliance_checker-2.0.0.tar.gz
- Upload date:
- Size: 193.2 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/6.1.0 CPython/3.13.12
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
a8fd9078b0a0b3ec555c2dfbd8ae4e58232ff3a761e13d0384ee3d93e5600791
|
|
| MD5 |
f1a3ed48bbed2e92f213f91b91426b8e
|
|
| BLAKE2b-256 |
3d9713fe91b57dfebda945412800c83c839e713b03ce998b70bb6830ab170df3
|
Provenance
The following attestation bundles were made for license_compliance_checker-2.0.0.tar.gz:
Publisher:
publish-pypi.yml on aiexponenthq/license-compliance-checker
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
license_compliance_checker-2.0.0.tar.gz -
Subject digest:
a8fd9078b0a0b3ec555c2dfbd8ae4e58232ff3a761e13d0384ee3d93e5600791 - Sigstore transparency entry: 2200340308
- Sigstore integration time:
-
Permalink:
aiexponenthq/license-compliance-checker@a8f7fef11d3e763d0addbce96b351fa1ac445910 -
Branch / Tag:
refs/tags/v2.0.0 - Owner: https://github.com/aiexponenthq
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish-pypi.yml@a8f7fef11d3e763d0addbce96b351fa1ac445910 -
Trigger Event:
push
-
Statement type:
File details
Details for the file license_compliance_checker-2.0.0-py3-none-any.whl.
File metadata
- Download URL: license_compliance_checker-2.0.0-py3-none-any.whl
- Upload date:
- Size: 262.6 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/6.1.0 CPython/3.13.12
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
1dbf060ffd9c85224fc08f1ca8d7cb576a51667b00b21c5686ab45ebddfa9d1a
|
|
| MD5 |
7f839ddaf8d34c2e784dca3fcddf21be
|
|
| BLAKE2b-256 |
20ea6de70125ddf9ee8912483e0cc6889c1b8c6ca51f40907e757bded07270f3
|
Provenance
The following attestation bundles were made for license_compliance_checker-2.0.0-py3-none-any.whl:
Publisher:
publish-pypi.yml on aiexponenthq/license-compliance-checker
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
license_compliance_checker-2.0.0-py3-none-any.whl -
Subject digest:
1dbf060ffd9c85224fc08f1ca8d7cb576a51667b00b21c5686ab45ebddfa9d1a - Sigstore transparency entry: 2200340335
- Sigstore integration time:
-
Permalink:
aiexponenthq/license-compliance-checker@a8f7fef11d3e763d0addbce96b351fa1ac445910 -
Branch / Tag:
refs/tags/v2.0.0 - Owner: https://github.com/aiexponenthq
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish-pypi.yml@a8f7fef11d3e763d0addbce96b351fa1ac445910 -
Trigger Event:
push
-
Statement type: