The Open-Source Battlefield: How MIT, Apache 2.0, and AGPL-3.0 Govern Software IP, Cloud Giants, and Enterprise Code

This is going to be a little bit long article since it is a dynamic subject part of the law which has been becoming a playground for the big tech companies. So be patient when read, don’t get tired, at the end of the article, you will know how those big tech giants operate. So, I try to be as casual as I can. Here it is:

Copyright.
In copyright we know about the public domain where it consists of creative and intellectual works that are no longer, or never were, protected by exclusive copyright, meaning they belong to the general public and can be freely used without permission or payment. And there is also the default copyright which is protected. Say a brilliant young Indonesian fellow, out of UGM or ITB or UI, or fresh from or in high school, writes code making a revolutionary database for companies to use. The moment that young fellow writes the code at the same time copyright law protects such work. Legally, nobody has the right to download, copy, modify, or run that code without the young fellow permission. Getting permission usually means paying the young fellow. This is a standard default copyright protection.

What if the young fellow decides: well, my revolutionary database needs to be perfected and tested by other software engineers out there to remove bugs and get even more great. This makes sense in the tech industry because software cannot thrive in isolation. Our young fellow wants external engineers across Yogyakarta, Bandung, Jakarta, Singapore, and Silicon Valley to benchmark his database, test the storage engine, find memory leaks, and submit bug fixes.

The young fellow decided to put his code in open-source platform, say in GitHub, for other people to download, copy, modify, or run that code with a little bit saying from the young fellow: I still own 100% of the copyright, but everyone else is permitted to use my code, BUT you must obey my rules. These young fellow rules are what make open-source copyright intertwined with patents and trademarks.

As our young fellow, sitting in the campus canteen, is about to release his masterpiece revolutionary works in GitHub he names his works “4layDB”. GitHub gives him a simple drop-down menu asking which license to prefer. Why? Because in the software world, we don't write a 50-page legal contract and rather a short one. The two famous catchy licenses that the young fellow sees are The MIT License and the Apache 2.0 License. His coding and developer friends sitting next to him advise him to go with MIT License because it is only 170 words long with no boring legal clause. Clean and simple and grants universal freedom as follow: Anyone can copy, modify, distribute, merge, or sell the software for free; The user only needs to keep the author’s copyright credit line;

It has “AS IS” disclaimer so the author cannot be held liable if the code breaks someone’s machine.

This is exactly why developers love this license. As our young fellow is going to pick the MIT Licensed, his friend from law school, sitting at the other table in the campus canteen and has been listening to the conversation, suddenly stands and says: Wait! Don't push the button. Don't you guys know that IP is not only copyright but also patents and trademarks?! MIT License only covers Copyright but not Patents, and Trademarks.

He is absolutely, right?! MIT Licensed was written in 1988, long before tech companies began building massive software and patenting it or trademarking it. These create potential patents ambush and trademark hijacking in the future.

For a patent, imagine this: our young fellow published his 4LayDB works on GitHub. A software engineer from a big giant tech company notice his work, submits a pull request containing an optimized indexing algorithm. Our young fellow reviews the pull request and merges it into his 4LayDB. In a year, such a new merger works processing mission-critical data for dozens of Indonesian commercial banks and fintech platforms. Suddenly, the big tech giant sued our young fellow because their engineer gave our young fellow the pull request containing an optimized indexing algorithm. But the big tech giant owns the registered patent on the underlying algorithmic method! They never never granted our young fellow a patent license. Big tech giants ask for $5 million in royalties, or shut 4LayDB down. Our young fellow dragged into a perennial legal battle.

For trademark, let’s say our young fellow spent months building the brand reputation and community recognition behind the name 4LayDB. Under basic open-source rules like the MIT License, anyone can modify the source code. But a competitor can download his code, make minor changes, and launch with a marketing campaign offering “The Official 4LayDB Enterprise Edition". The MIT License does not explicitly define trademark boundaries. This leaves room for bad-faith actors to hijack our young fellow trademark, confuse enterprise clients, and dilute our young fellow reputation before he can even build a company.

The law student pulls up a chair, takes a sip of his iced tea, and points at the screen: “If you want to share your code without getting legally ambushed, you skip MIT and you choose The Apache 2.0 License.” Our young fellow frowns. “Why? Isn’t Apache just another boring legal document?” “Because,” the law student explains, “Apache 2.0 was written in 2004 by seasoned corporate lawyers who understood that software is a battleground of Copyright, Patents, and Trademarks combined into one.”

He breaks down the four pillars of Apache 2.0 right there on the canteen table:

  1. The Permissive Copyright Grant (Section 2): It gives everyone the same freedom as MIT—anyone in the world can run, copy, modify, and distribute the code for free.

  2. The Express Patent Grant (Section 3): Anyone who contributes code to 4layDB automatically grants every user a perpetual, royalty-free patent license for their contribution. No contributor can ever ambush our young fellow with a surprise patent lawsuit later.

  3. The Patent Retaliation Clause (Section 3): If a rival company adopts 4layDB and later decides to sue our young fellow for patent infringement on another software, that rival’s license to use 4layDB is instantly terminated. It is an automatic peace treaty.

  4. The Explicit Trademark Shield (Section 6): It explicitly states that the license grants rights solely to the code, not the brand name. While Indonesian Trademark Law runs on a strict "first-to-file" registration system, Apache 2.0 guarantees that no competitor can ever argue the open-source license gave them permission to use his name. As long as our young fellow officially registers the mark "4layDB", he holds total exclusive rights. Nobody can launch a fake "Official 4layDB" without facing a trademark infringement lawsuit.

  5. The “AS IS” Armor (Sections 7 & 8): If a commercial bank uses 4layDB and their system crashes, they assume all the risk. They can never sue our young fellow for operational damages.

Our young fellow breathes a sigh of relief. He selects Apache 2.0, pushes LICENSE.txt to GitHub, and clicks publish. Within months, 4layDB goes viral across the global tech ecosystem. Engineers in Singapore, Berlin, Tokyo, and Silicon Valley star the repository. Bug fixes pour in. Startups deploy it in production. Everything looks like a dream. Our young fellow feels like a hero of the open-source community.

What he doesn't know is that a giant cloud infrastructure has already spotted his project.

The Big Tech Paradox: The IBM Masterclass

Before we look at what the cloud giants do to our young fellow, you might be asking a fair question:
“Wait. Do multi-billion-dollar tech giants actually care about open source, or do they only care about hoarding patents?”

To understand how big tech operates, you have to look at IBM. For 29 consecutive years, IBM held the undisputed world record for filing the most U.S. patents annually. They sat on a mountain of over 100,000 patents. Yet, in 2001, IBM did something that completely baffled Wall Street: they poured $1 Billion in cash into the free, open-source Linux operating system.

Why would the world's biggest patent hoarder give away a billion dollars to a free open-source project?

Because of a ruthless corporate strategy: Commoditizing the Complement. Back then, Microsoft (with Windows Server) and Sun Microsystems (with Solaris) ruled corporate computing. They charged fortunes for server operating system licenses. IBM realized something brilliant: “If we make the operating system (Linux) 100% free and open-source, Microsoft and Sun can no longer charge billions for their operating systems. Their software monopolies will bleed out.”

What did IBM sell instead? IBM sold the multi-million-dollar mainframe hardware, enterprise databases, and IT consulting services required to run that free Linux. And when patent trolls tried to sue open-source Linux developers, IBM stepped in like a giant bodyguard, opened its vault of patents, and used it as a nuclear defense shield promising to countersue anyone who attacked the open-source community.

IBM taught the world the ultimate corporate playbook: make the software layer free so you can make billions selling the infrastructure and services around it.

Back To the Canteen:

Now, let’s return to our young fellow and his viral 4layDB. A giant cloud infrastructure provider, let’s call them the Cloud Titan, notices that thousands of their enterprise cloud customers are running 4layDB on virtual servers. The Cloud Titan’s executives hold a meeting. Do they need to buy our young fellow’s company? Do they need to pay him a licensing fee? Do they need to hack into his computer?

No. Not at all.

Because our young fellow chose the permissive Apache 2.0 license, the Cloud Titan has the 100% legal right to download the entire 4layDB source code from GitHub for zero Rupiah. The Cloud Titan takes the code and writes a massive layer of secret, proprietary software around it like Automated multi-region backup systems, Automated server scaling engines, Direct integration with their proprietary firewalls and billing meters. They launch a brand-new cloud product: “Managed Cloud 4layDB Service.”

Enterprise clients, banks, and startups happily click a single button on the Cloud Titan’s console, paying them $10,000 every month for hassle-free database hosting.

The Cloud Titan makes tens of millions of dollars every quarter off 4layDB. Our young fellow checks his bank account in Yogyakarta. His balance from the Cloud Titan? Exactly Rp 0. Why?

He didn’t get hacked. He didn’t get cheated. He got legally outmaneuvered by the very Apache 2.0 license he chose in the campus canteen.

The Counter-Attack: Enter AGPL-3.0 and the SaaS Loophole

Our young fellow is furious. He spent years building the core engine, and a foreign cloud monopoly is capturing all the commercial value while contributing nothing back. He calls his law student friend again. “How do I stop them from doing this without closing down my open-source project?” The law student smiles. “It’s time to use the nuclear option of open-source licensing: AGPL-3.0.”

To understand AGPL-3.0, you have to understand the "SaaS Loophole" in older copyleft licenses:

  • Traditional GPL-2.0: It only forced you to share your source code if you physically distributed software files (like giving someone a CD or an installer file). Cloud providers bypassed this easily because they ran the software on their own private servers and only let users access it over the internet.

  • The Affero GPL (AGPL-3.0) and Section 13: AGPL-3.0 closed that loophole completely. Section 13 (Remote Network Interaction) states: if you modify the software and let users interact with it over a computer network (via the cloud, an API, or a web app), you must make your entire modified source code publicly downloadable for free.

Our young fellow goes back to work. He spends six months building 4layDB Version 2.0 adding blazing-fast new features, AI-powered query engines, and massive speed upgrades.

Then, he releases Version 2.0 under AGPL-3.0.

This creates an absolute Poison Pill for the Cloud Titan. If the Cloud Titan takes 4layDB v2.0 and hosts it as a commercial cloud service, Section 13 forces them to release any modifications made to the database core. Worse, it creates a catastrophic legal contamination risk: under AGPL, the legal line separating the database from the adjacent proprietary orchestration, backup, and billing tools built around it is notoriously blurred. If a court rules those cloud tools are derivative works, the Cloud Titan could be legally forced to open-source parts of their proprietary infrastructure. That is a risk no corporate General Counsel will ever permit.

The Cloud Titan is trapped. They only have two choices are stay stuck running the old, outdated Version 1.0 of 4layDB and spend millions of dollars paying their own engineers to maintain it. Or knock on our young fellow’s door and pay him hundreds of thousands of dollars for a private Commercial License that exempts them from AGPL-3.0.

(This exact dynamic is why tech giants like Google enforce a strict, company-wide ban prohibiting their engineers from touching AGPL software.)

The Ultimate Real-World Proof: Google, the Transformer, and ChatGPT

If you think this is just a hypothetical canteen story about databases, look at what happened in the world of Artificial Intelligence.

The "T" in ChatGPT stands for "Transformer."

Who invented the Transformer? Google.

In 2017, eight brilliant researchers at Google Brain published a landmark scientific paper called "Attention Is All You Need." Google did not keep the breakthrough software architecture locked away. They published the architectural blueprint openly and released their reference code under the permissive Apache 2.0 License. (Interestingly, Google actually holds US Patent 10,452,978 on the Transformer mechanism, but chose not to aggressively enforce it against the wider AI research community).

Why did Google give away the blueprint for free?

Because Google was following the classic IBM playbook: Google believed that if the AI software architecture was free, everyone in the world would rush to Google Cloud to buy Google’s specialized TPU hardware chips and use Google's search data to train models.

The unexpected twist:

A small research lab named OpenAI read Google’s paper.

OpenAI took Google's open blueprint, implemented their own dedicated decoder-only architecture in PyTorch, scaled it with massive computing clusters, trained it on internet-scale text, and layered on Reinforcement Learning from Human Feedback (RLHF). Because the blueprint and reference ideas were openly licensed, OpenAI was completely free to build an unencumbered, closed proprietary commercial product. In November 2022, OpenAI launched ChatGPT—beating Google to the global market using Google’s own freely given invention. Google designed the engine, but OpenAI drove the car away.

The Enterprise Reality: Indonesian Banks and "Nothing New Under the Sun"

Now, let’s bring the story back to the corporate towers of SCBD and Mega Kuningan in Jakarta. Why does all of this matter to a Chief Technology Officer or General Counsel at a commercial bank in Indonesia?

Because under Indonesian Financial Services Authority regulations, banks are legally mandated to maintain strict confidentiality, security, and asset control over their Strategic Electronic Systems.

If an over-enthusiastic junior developer at a Jakarta bank accidentally links an internal core transaction engine to an unmanaged AGPL-3.0 library:

  • The bank faces a legal demand under UU Hak Cipta No. 28/2014 to publicly disclose the proprietary source code of its banking modules.

  • Disclosing that proprietary code exposes security vulnerabilities, violates OJK IT risk governance, and instantly impairs the capitalized IP assets on the bank’s balance sheet.

This is why banks happily pay hundreds of thousands of dollars for commercial enterprise licenses from software creators. They aren't just paying for software; they are paying for legal peace of mind and complete insulation from copyleft contamination.

My skeptical opinion instantly say there is no way MIT, Apache 2.0, or AGPL-3.0 can be enforced in Indonesian court due to involving Indonesian entities make the language must be Indonesian, registration of the requirement to government body and not just some published in Github.

If I based my legal defence on this, I instantly destroy my own argument. Under copyright law, reproducing, modifying, or distributing software without a valid license is strictly illegal. What is the basis for me using the 4layDB if it is not from MIT, Apache 2.0, or AGPL-3.0? only to creates a counter sue of using copyright without permit right? Same with the language. If I say it is not in Indonesian, then what based I have to use the 4layDB? None.

As for government formalities, Indonesian Copyright Law specifies that an unrecorded license agreement (Pencatatan Perjanjian Lisensi) has no legal effect against third parties. But the copyright itself is born automatically the moment the code is written! If the infringer argues that the open-source license has no third-party legal effect or is defective, they don't win—they merely prove they never received a valid copyright grant in the first place, turning the dispute into a straightforward unauthorized copyright infringement claim.

Even if I miraculously pull that off and make Indonesian court does not enforce those open-source license, I will just make my ceilings to hit local market. When I go international, the open-source community will just crush me because of my approach. Summary, it is far a lot better to play by the rule.

The Final Lesson

As the famous saying goes: "There is nothing new under the sun."

In the modern technology landscape, almost nothing is built from zero. Startups borrow from open source, big tech borrows from startups, and AI models borrow from academic blueprints. According to joint studies by the Linux Foundation, Harvard Business School, and Synopsys Cybersecurity Research, between 70% and 90% of the code inside modern commercial software is composed of open-source components.

The true winners in the technology industry are not just the engineers who write the fastest code.

The true winners are the architects, founders, and lawyers who understand how the invisible legal machinery, the delicate dance between Copyright, Patents, Trademarks, and Open-Source Licenses, actually rules the digital world.

Next
Next

The Due Process of Data: Architecting Legally Sound Pipelines to Eliminate Tainted AI Liabilities