License Compliance Checker (LCC)
Know what you ship. Know what you owe.
The only open-source scanner that combines dependency license detection, AI model license analysis, and EU AI Act Article 53 compliance — in a single tool.
Built by AI Exponent LLC. Free and open source under Apache 2.0.
Quick Start
pip install license-compliance-checker
# Scan a project
lcc scan .
# Scan with EU AI Act compliance policy
lcc scan . --policy eu-ai-act-compliance --format json
# Generate a CycloneDX SBOM
lcc sbom generate scan-report.json --format cyclonedx --output sbom.json
# Check GPL contamination in a SaaS context
lcc scan . --project-license Apache-2.0 --context saas
What LCC does
- AI model license detection, including HuggingFace models resolved by Hub ID and GGUF / ONNX model files
- EU AI Act Article 53 assessment and compliance-pack output
- A training-data risk registry that flags datasets with commercial-use restrictions
- SBOM generation in CycloneDX and SPDX
- Policy-as-code with OPA Rego or YAML policies
- Free and open source under Apache-2.0
Supported Export Formats
LCC produces industry-standard Software Composition Analysis (SCA), SBOM, and regulatory compliance artifacts:
| Format Specification | Standard / Schema | Invocation | Primary Use Case |
|---|---|---|---|
| CycloneDX SBOM | CycloneDX v1.5 (JSON, XML) | lcc sbom generate scan-report.json --format cyclonedx |
Enterprise supply chain security, dependency graph auditing, regulatory filing |
| SPDX SBOM | SPDX v2.3 (JSON, YAML, Tag-Value) | lcc sbom generate scan-report.json --format spdx |
Standard open-source licensing compliance & legal package review |
| JSON Report | Structured component findings | lcc scan . --format json --output report.json |
CI/CD pipelines, automated gating, custom dashboards |
| HTML Report | Standalone interactive report | lcc report generate scan-report.json --format html |
Executive & legal counsel review without CLI tools |
| Markdown Report | Clean GitHub Flavored Markdown | lcc report generate scan-report.json --format markdown |
Pull request comments, developer documentation |
| CSV Export | Tabular component spreadsheet | lcc report generate scan-report.json --format csv |
Spreadsheets & procurement inventory ingestion |
| Attribution Notice | Formatted third-party notices | lcc report generate scan-report.json --format attribution |
Distribution compliance & shipping notice packs |
| Article 53 Pack | 4-file compliance pack | lcc compliance-pack |
Official EU AI Act Article 53 GPAI regulatory submission |
Architecture
graph TD
CLI["CLI · FastAPI Server · GitHub Action · VS Code Extension"]
DET["Detectors\nPython · Node.js · Go · Rust · Ruby\nJava · .NET · HuggingFace · GGUF/ONNX"]
RES["Resolvers\nPyPI · npm · Crates.io · Maven\nGitHub API · ClearlyDefined · HF Hub API"]
POL["Policy Engine\nOPA Rego · YAML policies\nPermissive · Strict · EU AI Act"]
REG["Regulatory Assessor\nEU AI Act Article 53"]
OUT["Outputs\nJSON · HTML · Markdown · CSV\nCycloneDX SBOM · SPDX SBOM\nArticle 53 compliance pack"]
CLI --> DET
DET -->|"detected components"| RES
RES -->|"resolved licenses"| POL
POL -->|"violations + warnings"| REG
REG --> OUT
style CLI fill:#1e3a5f,color:#fff
style DET fill:#1e3a5f,color:#fff
style RES fill:#1e3a5f,color:#fff
style POL fill:#c9a84c,color:#000
style REG fill:#c9a84c,color:#000
style OUT fill:#2d5a2d,color:#fff
See the User Guide and API Reference for comprehensive architectural and component specifications.
Ecosystem Coverage
graph LR
LCC["LCC\nScanner"]
PY["Python\npip · Poetry · Conda"]
JS["JavaScript\nnpm · Yarn · pnpm"]
GO["Go\ngo.mod"]
RS["Rust\nCargo.toml"]
JV["Java\nMaven · Gradle"]
RB["Ruby\nBundler"]
DN[".NET\nNuGet"]
HF["HuggingFace\nHub API · Model cards\nGGUF · ONNX"]
LCC --> PY
LCC --> JS
LCC --> GO
LCC --> RS
LCC --> JV
LCC --> RB
LCC --> DN
LCC --> HF
style LCC fill:#1e3a5f,color:#fff
style HF fill:#c9a84c,color:#000
EU AI Act Article 53 Coverage
GPAI obligations under Article 53 have applied since 2 August 2025 for models placed on the market from that date; models placed earlier must comply by 2 August 2027. The Commission's supervision and enforcement powers, including fines, begin 2 August 2026. LCC automates evidence gathering for each sub-obligation:
graph TD
A53["Article 53\nObligations"]
A["53(1)(a)\nTechnical documentation\n→ SBOM with model type,\nversion, license metadata"]
B["53(1)(b)\nDownstream provider info\n→ Model card capabilities\nand limitations extracted"]
C["53(1)(c)\nCopyright policy\n→ Training data licenses\nand copyright flags"]
D["53(1)(d)\nTraining data summary\n→ Dataset descriptions\nfrom model cards"]
E["53(2)\nSystemic risk\n→ 65B+ parameter\nmodel detection"]
A53 --> A
A53 --> B
A53 --> C
A53 --> D
A53 --> E
style A53 fill:#1e3a5f,color:#fff
style A fill:#1e3a5f,color:#fff
style B fill:#1e3a5f,color:#fff
style C fill:#1e3a5f,color:#fff
style D fill:#1e3a5f,color:#fff
style E fill:#c9a84c,color:#000
Scope note: LCC generates audit evidence for Article 53 documentation obligations. It is not a legal compliance determination. Involve qualified legal counsel for final compliance assessment.
Penalty band: Non-compliance with Article 53 is sanctionable by the Commission under Article 101(1) at up to €15M or 3% of global annual turnover, whichever is higher. Note that GPAI fines are Commission-imposed under Art. 101 — distinct from the Art. 99 fines imposed by member-state market-surveillance authorities for high-risk-system violations. Source: Regulation (EU) 2024/1689, Art. 101(1).
AI Model Detection
LCC scans your codebase for AI model references without requiring a local download:
# Detects from_pretrained("org/model") references in Python / YAML / JSON
lcc scan .
# Detects GGUF and ONNX model files (Ollama / llama.cpp)
lcc scan /path/to/models
# Full transitive scan with lock file
lcc scan . --include-transitive --policy permissive
Supported AI license families: the OpenRAIL family (including BigScience BLOOM and CreativeML variants), Llama 2 / 3 / 3.1, Gemma, and Mistral, plus provider licenses from Anthropic, OpenAI, Cohere, and AI21. The registry holds 17 AI license definitions and also recognises standard SPDX identifiers.
Training data risk registry: Flags datasets with commercial use risk — OpenAI API outputs, ShareGPT, Books3, The Pile classified as high/critical risk.
Policy Enforcement
# Built-in policies
lcc scan . --policy permissive # Allow MIT, Apache-2.0, BSD only
lcc scan . --policy strict # Block all copyleft
lcc scan . --policy eu-ai-act-compliance # Article 53 GPAI obligations
# Custom policy (YAML)
cat > my-policy.yaml << EOF
name: my-saas-policy
rules:
- license: GPL-3.0
action: block
reason: "GPL-3.0 requires SaaS source disclosure"
- license: AGPL-3.0
action: block
- license: RAIL
action: warn
reason: "Review RAIL restrictions before deploying"
EOF
lcc scan . --policy my-policy.yaml
For detailed policy syntax, custom OPA Rego rules, and violation actions, see the Policy Guide.
CI/CD Integration
# .github/workflows/license-check.yml
- name: License compliance scan
uses: aiexponent/license-compliance-checker/.github/actions/license-compliance@v1
with:
path: .
policy: eu-ai-act-compliance
fail-on: violations
format: json
output: license-report.json
For production deployment patterns, Docker container scanning, and web dashboard access, see the Deployment Guide.
SBOM Generation
# CycloneDX 1.5 with EU AI Act regulatory extensions
lcc sbom generate scan-report.json --format cyclonedx --output sbom.cdx.json
# SPDX 2.3
lcc sbom generate scan-report.json --format spdx --output sbom.spdx.json
# Sign with GPG for tamper-evidence
lcc sbom sign sbom.cdx.json --key ~/.gnupg/key.gpg
Known Limitations
- HuggingFace Hub API scanning requires referenced model IDs (not local downloads only).
- SPDX
AND/ORcompound expressions are flagged for manual review, not auto-resolved. - Transitive dependency resolution requires a lock file (
poetry.lock,package-lock.json). - Article 53 assessment covers documentation completeness only — not a legal compliance determination.
- Training data risk registry covers top-50 known datasets; unknown datasets flagged for review.
Documentation
Full documentation is available on the live Material for MkDocs Documentation Portal:
- Getting Started & Quick Start — Setup guide, first project scan, and SBOM generation.
- Installation Guide — Package managers (
pip,uv), container installation, and requirements. - User Guide & CLI Manual — Comprehensive command-line flags, scanners, and report generators.
- Policy Guide (Rego & YAML) — Authoring custom policies, OPA rules, and compliance gates.
- API Reference & Schemas — Python SDK, FastAPI endpoints, and schema definitions.
- Deployment & Dashboard Guide — Production checklists, Docker deployment, and web dashboard access.
- Troubleshooting & FAQ — Common questions, licensing nuances, and SARIF non-support rationale.
- Testing Guide — Running the automated test suite and integration test environments.
Contributing
See CONTRIBUTING.md. Issues and PRs welcome.
git clone https://github.com/aiexponent/license-compliance-checker
cd license-compliance-checker
pip install -e ".[dev]"
pytest
License
Apache 2.0 — free to use, modify, and distribute.
Built by AI Exponent LLC — hello@aiexponent.com
Part of the AiExponent open-source AI governance toolchain: license-compliance-checker · rag-benchmarking · RiskForge
Metadata
Release files for license-compliance-checker 2.0.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| license_compliance_checker-2.0.1.tar.gz | 197.3 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| license_compliance_checker-2.0.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 462.2 kB
Release files / license_compliance_checker-2.0.1.tar.gz
| Download URL | license_compliance_checker-2.0.1.tar.gz |
|---|---|
| Size | 197.3 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
d5ff4f5f35c0adc48db688447570d7c72496e8484a47d953b004323929b254e3
|
|
BLAKE2b-256 checksum How to use checksums |
6362be73c49bba3a9496ebf7846e7d673698f175f9e53889ac8b5e846f0ceec8
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 22, 2026.
Transparency logRelease files / license_compliance_checker-2.0.1-py3-none-any.whl
| Download URL | license_compliance_checker-2.0.1-py3-none-any.whl |
|---|---|
| Size | 264.9 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
1e3aa468846c7ee30d28421a6aa31407567246ddfa7a45213ac1e996ade3c84d
|
|
BLAKE2b-256 checksum How to use checksums |
df0d97b5108316d073c1ecd5e4631418f194dc46f0e725538ba087922840d7bc
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 22, 2026.
Transparency log