Skip to main content

AiExponent — Building AI that deserves to be trusted

License Compliance Checker (LCC)

Know what you ship. Know what you owe.

PyPI CI Documentation License: Apache 2.0 Python 3.11+ EU AI Act Article 53 Zero telemetry


The only open-source scanner that combines dependency license detection, AI model license analysis, and EU AI Act Article 53 compliance — in a single tool.

Built by AI Exponent LLC. Free and open source under Apache 2.0.


Quick Start

pip install license-compliance-checker

# Scan a project
lcc scan .

# Scan with EU AI Act compliance policy
lcc scan . --policy eu-ai-act-compliance --format json

# Generate a CycloneDX SBOM
lcc sbom generate scan-report.json --format cyclonedx --output sbom.json

# Check GPL contamination in a SaaS context
lcc scan . --project-license Apache-2.0 --context saas

What LCC does

  • AI model license detection, including HuggingFace models resolved by Hub ID and GGUF / ONNX model files
  • EU AI Act Article 53 assessment and compliance-pack output
  • A training-data risk registry that flags datasets with commercial-use restrictions
  • SBOM generation in CycloneDX and SPDX
  • Policy-as-code with OPA Rego or YAML policies
  • Free and open source under Apache-2.0

Supported Export Formats

LCC produces industry-standard Software Composition Analysis (SCA), SBOM, and regulatory compliance artifacts:

Format Specification Standard / Schema Invocation Primary Use Case
CycloneDX SBOM CycloneDX v1.5 (JSON, XML) lcc sbom generate scan-report.json --format cyclonedx Enterprise supply chain security, dependency graph auditing, regulatory filing
SPDX SBOM SPDX v2.3 (JSON, YAML, Tag-Value) lcc sbom generate scan-report.json --format spdx Standard open-source licensing compliance & legal package review
JSON Report Structured component findings lcc scan . --format json --output report.json CI/CD pipelines, automated gating, custom dashboards
HTML Report Standalone interactive report lcc report generate scan-report.json --format html Executive & legal counsel review without CLI tools
Markdown Report Clean GitHub Flavored Markdown lcc report generate scan-report.json --format markdown Pull request comments, developer documentation
CSV Export Tabular component spreadsheet lcc report generate scan-report.json --format csv Spreadsheets & procurement inventory ingestion
Attribution Notice Formatted third-party notices lcc report generate scan-report.json --format attribution Distribution compliance & shipping notice packs
Article 53 Pack 4-file compliance pack lcc compliance-pack Official EU AI Act Article 53 GPAI regulatory submission

Architecture

graph TD
    CLI["CLI · FastAPI Server · GitHub Action · VS Code Extension"]
    DET["Detectors\nPython · Node.js · Go · Rust · Ruby\nJava · .NET · HuggingFace · GGUF/ONNX"]
    RES["Resolvers\nPyPI · npm · Crates.io · Maven\nGitHub API · ClearlyDefined · HF Hub API"]
    POL["Policy Engine\nOPA Rego · YAML policies\nPermissive · Strict · EU AI Act"]
    REG["Regulatory Assessor\nEU AI Act Article 53"]
    OUT["Outputs\nJSON · HTML · Markdown · CSV\nCycloneDX SBOM · SPDX SBOM\nArticle 53 compliance pack"]

    CLI --> DET
    DET -->|"detected components"| RES
    RES -->|"resolved licenses"| POL
    POL -->|"violations + warnings"| REG
    REG --> OUT

    style CLI fill:#1e3a5f,color:#fff
    style DET fill:#1e3a5f,color:#fff
    style RES fill:#1e3a5f,color:#fff
    style POL fill:#c9a84c,color:#000
    style REG fill:#c9a84c,color:#000
    style OUT fill:#2d5a2d,color:#fff

See the User Guide and API Reference for comprehensive architectural and component specifications.


Ecosystem Coverage

graph LR
    LCC["LCC\nScanner"]

    PY["Python\npip · Poetry · Conda"]
    JS["JavaScript\nnpm · Yarn · pnpm"]
    GO["Go\ngo.mod"]
    RS["Rust\nCargo.toml"]
    JV["Java\nMaven · Gradle"]
    RB["Ruby\nBundler"]
    DN[".NET\nNuGet"]
    HF["HuggingFace\nHub API · Model cards\nGGUF · ONNX"]

    LCC --> PY
    LCC --> JS
    LCC --> GO
    LCC --> RS
    LCC --> JV
    LCC --> RB
    LCC --> DN
    LCC --> HF

    style LCC fill:#1e3a5f,color:#fff
    style HF fill:#c9a84c,color:#000

EU AI Act Article 53 Coverage

GPAI obligations under Article 53 have applied since 2 August 2025 for models placed on the market from that date; models placed earlier must comply by 2 August 2027. The Commission's supervision and enforcement powers, including fines, begin 2 August 2026. LCC automates evidence gathering for each sub-obligation:

graph TD
    A53["Article 53\nObligations"]

    A["53(1)(a)\nTechnical documentation\n→ SBOM with model type,\nversion, license metadata"]
    B["53(1)(b)\nDownstream provider info\n→ Model card capabilities\nand limitations extracted"]
    C["53(1)(c)\nCopyright policy\n→ Training data licenses\nand copyright flags"]
    D["53(1)(d)\nTraining data summary\n→ Dataset descriptions\nfrom model cards"]
    E["53(2)\nSystemic risk\n→ 65B+ parameter\nmodel detection"]

    A53 --> A
    A53 --> B
    A53 --> C
    A53 --> D
    A53 --> E

    style A53 fill:#1e3a5f,color:#fff
    style A fill:#1e3a5f,color:#fff
    style B fill:#1e3a5f,color:#fff
    style C fill:#1e3a5f,color:#fff
    style D fill:#1e3a5f,color:#fff
    style E fill:#c9a84c,color:#000

Scope note: LCC generates audit evidence for Article 53 documentation obligations. It is not a legal compliance determination. Involve qualified legal counsel for final compliance assessment.

Penalty band: Non-compliance with Article 53 is sanctionable by the Commission under Article 101(1) at up to €15M or 3% of global annual turnover, whichever is higher. Note that GPAI fines are Commission-imposed under Art. 101 — distinct from the Art. 99 fines imposed by member-state market-surveillance authorities for high-risk-system violations. Source: Regulation (EU) 2024/1689, Art. 101(1).


AI Model Detection

LCC scans your codebase for AI model references without requiring a local download:

# Detects from_pretrained("org/model") references in Python / YAML / JSON
lcc scan .

# Detects GGUF and ONNX model files (Ollama / llama.cpp)
lcc scan /path/to/models

# Full transitive scan with lock file
lcc scan . --include-transitive --policy permissive

Supported AI license families: the OpenRAIL family (including BigScience BLOOM and CreativeML variants), Llama 2 / 3 / 3.1, Gemma, and Mistral, plus provider licenses from Anthropic, OpenAI, Cohere, and AI21. The registry holds 17 AI license definitions and also recognises standard SPDX identifiers.

Training data risk registry: Flags datasets with commercial use risk — OpenAI API outputs, ShareGPT, Books3, The Pile classified as high/critical risk.


Policy Enforcement

# Built-in policies
lcc scan . --policy permissive            # Allow MIT, Apache-2.0, BSD only
lcc scan . --policy strict                # Block all copyleft
lcc scan . --policy eu-ai-act-compliance  # Article 53 GPAI obligations

# Custom policy (YAML)
cat > my-policy.yaml << EOF
name: my-saas-policy
rules:
  - license: GPL-3.0
    action: block
    reason: "GPL-3.0 requires SaaS source disclosure"
  - license: AGPL-3.0
    action: block
  - license: RAIL
    action: warn
    reason: "Review RAIL restrictions before deploying"
EOF

lcc scan . --policy my-policy.yaml

For detailed policy syntax, custom OPA Rego rules, and violation actions, see the Policy Guide.


CI/CD Integration

# .github/workflows/license-check.yml
- name: License compliance scan
  uses: aiexponent/license-compliance-checker/.github/actions/license-compliance@v1
  with:
    path: .
    policy: eu-ai-act-compliance
    fail-on: violations
    format: json
    output: license-report.json

For production deployment patterns, Docker container scanning, and web dashboard access, see the Deployment Guide.


SBOM Generation

# CycloneDX 1.5 with EU AI Act regulatory extensions
lcc sbom generate scan-report.json --format cyclonedx --output sbom.cdx.json

# SPDX 2.3
lcc sbom generate scan-report.json --format spdx --output sbom.spdx.json

# Sign with GPG for tamper-evidence
lcc sbom sign sbom.cdx.json --key ~/.gnupg/key.gpg

Known Limitations

  • HuggingFace Hub API scanning requires referenced model IDs (not local downloads only).
  • SPDX AND/OR compound expressions are flagged for manual review, not auto-resolved.
  • Transitive dependency resolution requires a lock file (poetry.lock, package-lock.json).
  • Article 53 assessment covers documentation completeness only — not a legal compliance determination.
  • Training data risk registry covers top-50 known datasets; unknown datasets flagged for review.

Documentation

Full documentation is available on the live Material for MkDocs Documentation Portal:


Contributing

See CONTRIBUTING.md. Issues and PRs welcome.

git clone https://github.com/aiexponent/license-compliance-checker
cd license-compliance-checker
pip install -e ".[dev]"
pytest

License

Apache 2.0 — free to use, modify, and distribute.

Built by AI Exponent LLC — hello@aiexponent.com


Part of the AiExponent open-source AI governance toolchain: license-compliance-checker · rag-benchmarking · RiskForge

Metadata

Release files for license-compliance-checker 2.0.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for license-compliance-checker 2.0.1
File Size Uploaded
license_compliance_checker-2.0.1.tar.gz 197.3 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for license-compliance-checker 2.0.1
File Interpreter ABI Platform
license_compliance_checker-2.0.1-py3-none-any.whl Python 3 none any Details

Total release size: 462.2 kB

Release files / license_compliance_checker-2.0.1.tar.gz

Download URL license_compliance_checker-2.0.1.tar.gz
Size 197.3 kB
Tags Source
SHA-256 checksum
How to use checksums
d5ff4f5f35c0adc48db688447570d7c72496e8484a47d953b004323929b254e3
BLAKE2b-256 checksum
How to use checksums
6362be73c49bba3a9496ebf7846e7d673698f175f9e53889ac8b5e846f0ceec8
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 22, 2026.

Transparency log

Release files / license_compliance_checker-2.0.1-py3-none-any.whl

Download URL license_compliance_checker-2.0.1-py3-none-any.whl
Size 264.9 kB
Tags Python 3
SHA-256 checksum
How to use checksums
1e3aa468846c7ee30d28421a6aa31407567246ddfa7a45213ac1e996ade3c84d
BLAKE2b-256 checksum
How to use checksums
df0d97b5108316d073c1ecd5e4631418f194dc46f0e725538ba087922840d7bc
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 22, 2026.

Transparency log

Release history Release notifications | RSS feed

2.0.2

2 release files

This release

2.0.1 This release

2 release files

2.0.0

2 release files

1.0.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page