This doesn't stop unscrupulous contractors from copyrighting code and charging license fees (see: most DoE code, with exceptions like NWCHEM). I've often wondered why this hasn't resulted in any lawsuits; I suspect the reason is that nobody really cares.
Do you know what law requires it?
> The report notes that the 2018 NDAA mandated DoD establish a pilot program on open source and a report on the program’s implementation. It also says that OMB’s M-16-21 memorandum requires all agencies to release at least 20 percent of custom-developed code as open-source, with a metric for calculating program performance.
Also, do govt software contractors worry much about AIs being trained on their codebases, attribution, etc.? Would that increase under this law?
None of this applies to state or local government: 17 USC 105 applies only to federal matters.
Attribution tends to be important to DOE people since they're usually academics working in the purview of Office of Science, and citations are how they get promoted.
I don't think anyone worries about AI training on their codebases, since LLM providers are not held accountable to any copyright enforcement anyway.
(Not copyright claims against commercial LLM companies).
I'm not aware of many contracts for bespoke software in the state government space; it's far more frequent that someone identifies a need and then develops a solution to bring to market.
Or there are other software secrets that we wouldn’t want state adversaries to see, like things that block your access under export control laws?
If you, at home, pay someone to do work, what exactly do you own beyond the end product?
Obviously you keep personnel records private (unless there's some law/court case requiring it be open). Classified material is already classified, and is kept private regardless - but there's a good argument to be made that there ought to be automatic declassification of material after a set amount of time (perhaps 20-30 years). Declassifying material is good for the public, as the ability to audit the past prevents future abuses.
Not the parent, but I'm pretty sure that their intent is that it's the default that should be flipped. At the moment, all agencies default to confidential, and only share their work in particular cases; the proposed change would be of making all the work transparent unless explicitly classified.
As a good example of how this approach is implemented, see Gitlab, which share pretty much everything except personal data of their employees and customers.