SCANOSS launches Earnie to flag AI-created license violations
SCANOSS launched Earnie, a software governance release that checks open source license obligations at the snippet level for AI coding agents, developer workflows and pull requests. The company says the new system is built to reduce compliance exposure as agent-generated code moves faster than manual review.
Why it matters: - AI coding agents are increasing the risk that open source license obligations enter codebases before compliance teams can review them. - Earnie is designed to check obligations as code is created, which can help teams catch violations before they spread across many commits. - SCANOSS says the goal is a standing, auditable record of license posture that can hold up to internal review and external scrutiny.
What happened: - SCANOSS announced the public launch of Earnie at a live online event on October 6, 2026. - Earnie is the latest release of SCANOSS's software governance platform. - The system is built as a continuous programme organized around dated releases rather than a one-time scan.
The details: - Earnie checks license obligations down to the individual snippet, including copied, vendored and AI-generated code. - The platform uses the same deterministic, knowledge-base-backed detection across developer commits, imported code and AI agent output. - Earnie maps each identified component to its license and obligations. - The platform generates attribution and notice files for identified components. - Earnie keeps a versioned software bill of materials in CycloneDX and SPDX formats. - Existing CycloneDX or SPDX SBOMs can be imported directly. - Earnie links findings to policy so teams can see both the issue and the required response. - Policy changes go through an approval step with visible pending, approved or rejected statuses. - Earnie brings checks into the coding-agent workflow through the Model Context Protocol, or MCP. - Through MCP, an agent can ask whether a component is allowed before adding a dependency and receive a pass, warn or flag-for-review response. - The same policy enforcement appears again at pull request stage as a comment and pass or warn signal. - Earnie also supports CLI and pre-commit checks, GitHub Actions, and a UI that tracks findings, decisions and evidence. - SCANOSS says Earnie draws on a proprietary knowledge base of more than 188 million open source components and 3 trillion lines of fingerprinted code across 12 programming languages. - SCANOSS says the platform does not depend on third-party data. - Each customer operates in an isolated environment, with source code kept local and only fingerprints and hashes shared for matching.
Between the lines: - The release reflects a shift from after-the-fact compliance review to enforcement inside the development flow. - The MCP integration is especially notable because it moves policy guidance into the moment an agent is writing code, not after the code is committed. - The emphasis on auditability suggests SCANOSS is positioning Earnie for enterprise governance teams that need evidence, not just alerts.
What's next: - Earnie is available now. - SCANOSS says the full release includes coverage of AI governance and post-quantum cryptography readiness. - More information is available at earnie.dev.
Disclaimer: This article was produced by AGP Wire with the assistance of artificial intelligence based on original source content and has been refined to improve clarity, structure, and readability. This content is provided on an “as is” basis. While care has been taken in its preparation, it may contain inaccuracies or omissions, and readers should consult the original source and independently verify key information where appropriate. This content is for informational purposes only and does not constitute legal, financial, investment, or other professional advice.
Sign up for:
Global Journal Observer
The daily local news briefing you can trust. Every day. Subscribe now.
Check Your Email!
We sent a one-time activation link to: .
Confirm it's you by clicking the email link.
If the email is not in your inbox, check spam or try again.
Welcome back!
is already signed up. Check your inbox for updates.