Articles & Research

Analysis

GitHub Copilot goes general: who answers for AI-generated code?

GitHub's AI pair programmer became available to all developers on 21 June 2022, raising sharp questions about liability and licensing.

Priya Ramaswamy

Technology Correspondent, American Computer Society

July 2022 · 6 min read

Developer workstation showing open-source code and version history
Developer workstation showing open-source code and version history

On 21 June 2022 GitHub made Copilot generally available to all developers, moving AI-assisted coding from a technical preview into everyday professional practice. The shift arrived faster than the profession's norms for reviewing and attributing generated code.

From preview to default tool

GitHub Copilot, built on OpenAI's Codex model and trained on public code repositories, entered technical preview in June 2021. A year later, on 21 June 2022, GitHub announced general availability at $10 per month or $100 per year, free for verified students and maintainers of popular open source projects. GitHub reported that Copilot was suggesting code accepted by developers in roughly a third of cases in supported languages, a rapid rate of adoption for a developer tool.

The tool's value proposition — faster completion of boilerplate and repetitive code — was immediately attractive to engineering teams under delivery pressure. But its general release also generalised a set of open questions previously confined to a small preview cohort.

“A suggestion that compiles and looks idiomatic is not the same as a suggestion that has been reviewed for security and licensing exposure.”

Provenance, licensing and liability

Because Copilot was trained on public repositories including code under a range of open source licences, questions arose about whether its suggestions could reproduce licensed code verbatim without attribution, and whether developers using such suggestions might unknowingly violate the licence terms of the original work. A lawsuit filed against GitHub, Microsoft and OpenAI in November 2022 alleged exactly this, testing largely unresolved legal territory around AI training data and output.

A more immediate concern fell to practising engineers: generated code, however fluent, still requires the same scrutiny as code copied from a forum post. Studies of Copilot's early output found it could reproduce insecure coding patterns when the training data itself contained such patterns.

Professional judgment does not get outsourced

The central risk of tools like Copilot is not that they generate bad code, but that their fluency can erode the habitual scepticism engineers apply to unfamiliar code. A suggestion that compiles and looks idiomatic is not the same as a suggestion that has been reviewed for security, correctness and licensing exposure.

  • Treat AI-generated code as requiring the same review, testing and security scrutiny as any third-party contribution.
  • Maintain organisational policy on acceptable use of AI coding assistants, including licensing risk.
  • Log or flag AI-assisted contributions where audit trails matter for compliance.
  • Train engineers to recognise insecure patterns rather than assume tool output is safe by default.

What the Society advises

The Society holds that professional accountability for code quality, security and licensing compliance rests with the engineer and organisation deploying it, not with the tool that generated it. AI coding assistants do not dilute the obligations set out in the Society's Code of Conduct; they extend the surface area over which those obligations must be applied.

Artificial intelligenceSoftware engineering

Join the professional body behind this work

ACS members receive our research first, free CPD and ethics modules every year, and a route to professional registration assessed by their peers.

Become a member