Who owns the code when you hire an agency in 2026? The rules and a 25-point checklist
TL;DR Under US copyright law the people who write the code own it first, and paying for it does not change that. Custom software rarely counts as a work made for hire, so what makes you the owner is a written assignment signed by the agency. Keep the repository, cloud, domain and app store accounts in your company's name from the first week, because moving them later depends on each platform's rules.
- Copyright belongs first to whoever writes the code, so an agency owns what it builds until it signs a written assignment to you.
- Custom software is not one of the nine categories of commissioned work made for hire, so the contract needs a present-tense assignment as well.
- Purely AI-generated code is not protected by copyright, while code a person writes, edits or arranges with AI help can be.
- An Apple app can only move to another account once it has a released version, so publish under your own developer account from the start.
- Ask for a list of every open-source license in the codebase at handover, and flag any AGPL code in a SaaS product.
In this article
- Who owns the code by default when an agency builds it?
- Is a "work made for hire" clause enough?
- What should the clause actually say?
- What is the agency allowed to keep?
- Who owns code written with AI tools like Claude Code, Cursor or Copilot?
- Which open-source licenses should you check before launch?
- Which accounts should be in your name from day one?
- What changes when the agency is outside the US?
- Do you need source-code escrow?
- What a clean handover looks like
- How ownership works with us
- When we are not the right fit
- How to get started
When you hire an agency to build your product, the people who write the code own it first under US copyright law, and paying for it does not change that on its own. What makes you the owner is a written assignment signed by the agency, because custom software usually does not count as a "work made for hire", whatever the contract calls it.
The accounts are a separate question that the contract does not settle. The code repository, the cloud, the domain, the App Store and Google Play listings and the analytics should all be in your company's name from the first week, because moving them later depends on each platform's own rules.
I run the engineering at Axtra Studios, and this guide goes through the law in plain words, what the clause should say, what AI-written code changes and what a clean handover looks like, with a 25-point checklist you can download. It is general information and not legal advice, so a lawyer should read your contract before you sign it.
Copyright assignmentA signed, written transfer of the copyright in a work from its owner to someone else. For software built by an outside agency, it is usually the document that makes the client the owner of the code.
Who owns the code by default when an agency builds it?
The rule is short. Under section 201(a) of the US Copyright Act, copyright belongs first to the author of the work, and for an agency's developers that author is usually the agency itself, since work its employees do in their jobs belongs to their employer. So until something is signed, the code your agency writes for you belongs to the agency.
Your idea does not change that either. Copyright never covers an idea, a method or a concept, only the way it is written down, and a federal court said back in 1989 that the person who supplies the idea for a program is no more its author than the person who supplies the disk, which the US Copyright Office still quotes. Paying the invoices does not move ownership either, so the contract is what decides it.
Is a "work made for hire" clause enough?
Usually not for software. The Copyright Act has two kinds of work made for hire, and the first is work an employee does as part of their job, which an agency's developers are not to you.
The second is work you commission, but only if it fits one of nine categories, like a contribution to a collective work, part of a film, a translation, a test or an atlas, and both sides sign a written agreement saying it is a work made for hire.
Custom software is not one of the nine, and the Copyright Office's Circular 30 says plainly that a work that fails any of those requirements is not a work made for hire. So a contract that only says "work made for hire" can leave the agency as the owner, which is why good contracts say it and also include a written assignment as a backup.
| Arrangement | What you end up with | Does it work for custom software? | Watch for |
|---|---|---|---|
| Work made for hire (commissioned) | You are treated as the author from the start | Only if the work fits one of the nine categories, and custom software usually does not | A clause with no assignment behind it |
| Written assignment that says "hereby assigns" | Ownership moves to you once it is signed | Yes, this is what section 204(a) of the Copyright Act requires | When the rights move, what is covered and what the agency keeps |
| Exclusive license | A transfer of the rights it covers, while the agency still owns the copyright | Partly | Limits on field, time and territory |
| Non-exclusive license | Permission to use the code, nothing more | No, the agency can reuse the same code for others | It is often the default in an agency's template |
Work made for hire, assignment or license: what you end up with · Source: From the US Copyright Act (sections 101 and 204) and the Copyright Office's Circular 30, checked October 10, 2026. General information, not legal advice.
What should the clause actually say?
The words that do the work are present tense, so "hereby assigns" and not "agrees to assign". A promise to assign later is only a promise, and section 204(a) of the Copyright Act says a transfer is not valid unless it is in writing and signed by the owner, so the signed words should do the transfer themselves.
It also helps to check four more things. The scope should cover the code, the designs, the documents and everything else made for the project, and the clause should say when the rights move, whether that is when the work is created, as each milestone is paid or on the final payment.
The agency should also confirm that every developer and freelancer who worked on it has already passed their rights to the agency, because it cannot assign what it does not hold.
And watch for the word license. An exclusive license counts as a transfer under the Copyright Act, but a non-exclusive one is only permission to use the code, and the agency can then use the same code for someone else. A lawyer reading the contract for an hour is honestly cheap next to finding that out after a funding round.
What is the agency allowed to keep?
Most agencies reuse some of their own tools, starter code or components across projects, and that is fair as long as the contract names them and gives you a permanent license to use them in your product. The thing to avoid is a vague carve-out for "pre-existing materials" with no list, because then nobody knows which parts of your product you actually own.
Open-source code is the other part nobody can assign to you, since it belongs to its authors and comes to you under its own license. And most agencies ask to show the work in their portfolio, which is normal, but if the product is confidential, that belongs in the contract too.
Who owns code written with AI tools like Claude Code, Cursor or Copilot?
Most agencies use AI coding tools now, so this is a fair thing to ask. The US Copyright Office's report on copyrightability from January 29, 2025 says that using AI to assist a person does not affect copyright protection, while purely AI-generated material is not protected, and prompts alone are not enough to make someone the author. It also says each case is decided on its own facts.
The courts agree so far. In Thaler v. Perlmutter the D.C. Circuit held in March 2025 that copyright needs a human author, and the Supreme Court declined to hear the case on March 2, 2026. So code that a developer writes, edits, selects or arranges can be protected, while code pasted straight from a model with no human hand in it may not be anyone's.
In practice that means two questions for your agency. Which AI tools do they use on your code, and does a person review every change before it is merged? The AI providers themselves only pass on whatever rights exist, and Anthropic's commercial terms, for example, assign its rights in outputs "(if any)", so the human review is what gives the assignment something to carry.
Which open-source licenses should you check before launch?
Almost every modern codebase is built on open-source packages, and most of their licenses ask very little. The ones to watch are the copyleft licenses, because they can require you to share your own source code in some situations.
| License | What it asks of you | When it matters | What to do |
|---|---|---|---|
| MIT | Keep the copyright and license notice | When you distribute the code or an app built on it | Keep the notices file |
| Apache 2.0 | Keep the notices and say what you changed | When you distribute the code or an app built on it | Keep the notices file |
| GPL 3.0 | Share your source under the same license when you distribute | Apps, desktop software or anything shipped to customers | Check it before you ship, and ask your lawyer about app stores |
| AGPL 3.0 | Offer the source of a modified version to people who use it over a network | A SaaS product | Flag it at handover, since most closed SaaS products avoid it |
Open-source licenses in a delivered codebase · Source: From choosealicense.com, the GNU GPL FAQ and the Open Source Initiative, checked October 10, 2026.
The simplest protection is a list of every package and its license at handover, which is often called a software bill of materials.
The US cybersecurity agency CISA added the component license as a field in its 2026 minimum elements for one, using standard SPDX identifiers, and although that is guidance and not a law for startups, it is a good format to ask for. If you plan to ship a GPL-licensed component in an app store build, that is a question for your lawyer.
Which accounts should be in your name from day one?
This is the part founders lose most often, and it has nothing to do with copyright. If the agency opens the GitHub organization, the hosting team or the developer account in its own name "for now", getting them back later depends on each platform's rules and on the agency's cooperation.
| What | In whose name | Where it lives | If it starts in the agency's account |
|---|---|---|---|
| Source code and its history | Your company, with at least two owners | A GitHub, GitLab or Bitbucket organization | An admin has to transfer it, and an invitation to a personal account expires in one day |
| Hosting and cloud | Your company | Vercel, AWS or Google Cloud | On Vercel the team owner moves it, and integrations and logs stay behind |
| Domain and DNS | Your company, as the registrant | Your registrar | The registrar's rules apply, and it can lock the domain after a change of owner |
| iPhone app | Your company, with a D-U-N-S number and $99 a year | App Store Connect | It needs at least one released version before it can move |
| Android app | Your company, with a D-U-N-S number and $25 once | Google Play Console | Both accounts must be active, and earnings reports do not move |
| Analytics | Your company | Google Analytics | The data is moved, not copied |
| Designs | Your company | A Figma team or organization | Only the current owner can transfer a file, and it cannot be undone |
Which accounts should be in your name, and what moving them involves · Source: From Apple, Google Play, GitHub, Vercel, Google Analytics and Figma help pages, checked October 10, 2026.
The app stores are the slowest to fix. Apple only lets an app move to another developer account once it has at least one version released on the App Store, and a company account needs a D-U-N-S number, which Apple says can take up to five business days from Dun and Bradstreet plus up to two more for Apple.
Google Play charges $25 once for a developer account, also needs a D-U-N-S number for an organization, and moves the app's users, ratings and reviews in a transfer but not its earnings reports.
The others are quicker but still worth doing once. GitHub suggests at least two owners on an organization, a Vercel transfer leaves integrations and logs behind, a Google Analytics property is moved and not copied, and only the owner of a Figma file can transfer it. Your company should also be the registrant of the domain, since registrars can lock a domain for a while after the owner changes.
What changes when the agency is outside the US?
The same rules apply, and a written assignment matters even more. If your agency is in Pakistan, as we are, Pakistan's Copyright Ordinance (as published on WIPO Lex) gives an employer the first ownership of work its staff make under a contract of service unless they agree otherwise, and it says an assignment is only valid in writing and signed. So the agency should hold its own people's rights first and then sign them over to you.
Two more things are worth agreeing at the start. The contract should say which country's law applies and where a dispute would be heard, since parties to an international contract can choose that, and both Pakistan and the US are parties to the New York Convention, so an arbitration award made under the contract can be enforced in either country.
The US government's own commercial guide to Pakistan says to put the IP terms in the contract, and Pakistan is on the US Trade Representative's 2026 Watch List for IP enforcement. That is one more reason to keep the code and the accounts in your own name from the first week, wherever your agency is.
Do you need source-code escrow?
Usually not, if the code is already in your own repository. Escrow means a third party holds a copy of the source and releases it to you if the vendor goes out of business or stops supporting the product, and it makes sense when you license software you do not own, or when one of your own enterprise customers asks for it.
The published prices are modest. EscrowTech publishes a $995 setup fee and $1,595 a year for one beneficiary, and Codekeeper about $139 a month plus a $249 setup, and the deposits only help if someone keeps them up to date, which is the part that often slips.
What a clean handover looks like
A good handover is boring, and that is the point. Every account is already yours, the repository has the full history from the first week, there is a list of every secret and every one has been changed, the open-source licenses are listed and a new developer can build, deploy and roll back from the README and a recorded walkthrough.
Our code ownership handover checklist has 25 rows across the legal side, the code, the infrastructure, the apps, the data and the designs, with who should own each one and how to check it. It is really worth going through before the last invoice, and the studio scorecard from our guide to choosing a development studio covers the questions to ask before you sign.
How ownership works with us
On our projects the work is yours, always. The code sits in your repositories, the designs in your Figma and the deployments and accounts in your name, with documentation and a recorded walkthrough at handover, and on our mobile app development work we release apps under your own developer accounts, so the app and its reviews are yours from day one.
Nothing is locked to us, and most of our clients stay on for the next phase anyway. And if you need an NDA before you share the details of your idea, ask and we will sign one.
When we are not the right fit
If you would rather license a ready-made platform than own the code, a SaaS product is usually cheaper than a custom build, and owning the code only matters if you plan to change it. And we are not your lawyers, so the contract itself, and anything about patents, trademarks or a dispute, belongs with a lawyer in your state.
Where we fit is building the product with you so that ownership is never a question, with the code and the accounts in your name from the first week, as part of our web development and MVP launch work.
How to get started
If you are about to sign with an agency, or you want to take over a product another team built, a short call is enough to go through what you have and what to ask for.
If your product started in an AI builder, our guide to taking an AI-built prototype to production covers who owns that code too, and our guides to web app and SaaS cost and MVP cost and timeline cover the build itself.
The law in this guide comes from the Copyright Act's section 101, section 201 and section 204, the Copyright Office's Circular 30 and its report on copyrightability, the D.C. Circuit's Thaler v. Perlmutter and Pakistan's Copyright Ordinance.
The account rules come from Apple, Google Play, GitHub, Vercel, Google Analytics and Figma, the licenses from choosealicense.com and CISA, and the escrow prices from EscrowTech and Codekeeper, all checked on October 10, 2026. Everything here follows our editorial policy.





