An engineering firm subcontracts the structural modelling of a project to an outside practice. It receives the models, integrates them, delivers to the client and invoices. Months later a communication arrives about unlicensed use of the software those models were made with.
The reaction is always the same: we did not install anything, the subcontractor did. It is a weaker defence than it sounds.
The test is not who installed, it is who was in control
In copyright law liability does not stop at whoever physically performs the infringing act. There is also liability for authorising the infringement, and courts have found it by looking at the degree of control: if the commissioning company had the ability to oversee, direct and shape how the work was done, it can answer for its contractor’s infringement.
In the US Hitek Software case, the infringement occurred when an outside IT specialist installed software using an illegally generated product key. The argument did not turn on who clicked “install”, but on the hiring company’s right and ability to govern and direct that contractor.
Norton Rose Fulbright puts it plainly for development work: whoever engages a contractor must specifically instruct them not to infringe copyright, manage the relationship carefully and take reasonable steps to prevent infringement — or they too may be liable, by authorisation.
In practice, the more detailed the technical direction a company exercises over its subcontractor, the more that relationship resembles employment, and the harder it becomes to argue that what happened inside its own production chain was nothing to do with it.
The deliverable names the tool
There is a second reason, specific to technical software, and it is the one that surprises companies most: the delivered file identifies the program and version it was created with. Structural models, calculation files and interchange formats carry metadata from the application that generated them.
Which means the trail does not leave when the subcontractor does. It stays in the project, on the commissioning company’s server and, frequently, in the delivery to the end client.
What does shift the risk
Subcontracting is not the problem. Subcontracting without conditions is. Three measures change a company’s position:
A licensed-software declaration. The contract should state that the supplier will perform the work on valid licences held in its own name, identifying the product and the number of seats. It is a short clause and it deters a great deal.
An express indemnity. That the supplier holds the company harmless against third-party claims for intellectual property infringement arising from its work. It is the standard clause in technology contracting, and it is missing far too often in engineering engagements.
Verification proportionate to the risk. For recurring or high-volume work, ask for copies of the licences at the start of the relationship. It is not distrust: it is the same thing asked of a liability insurance policy.
And in the other direction
The same applies to the party providing the service. A practice that delivers work produced on unlicensed software exposes not only itself but its client — and that is the kind of incident that ends a commercial relationship long before it reaches a court.
Sources: Norton Rose Fulbright, Who’s in control? Liability for copyright infringement by contractors and software developers · Gupta & Ayres, Employer’s Liability for Independent Contractor’s Copyright Infringement
This article is informational and does not constitute legal advice. Liability tests vary between jurisdictions; for a specific matter, consult your counsel.
