Data rights are a license, not ownership
Most of the confusion here dissolves once you accept one sentence: the government almost never takes title to your software. It takes a license. The clause family at DFARS 252.227, and the subparts behind it at DFARS 227.71 and 227.72, exist to set the width of that license. Who may use what you delivered, for what purposes, for how long, and to whom the government may hand a copy. The argument is over scope.
For a firm that builds AI and data systems, scope has a dollar value attached. A license that lets a contracting officer give your inference service to a competing integrator on a recompete is a different business than one that does not. None of that gets decided at delivery. It gets decided in the solicitation, in the assertion table filed with your offer, and in the legend on the file.

Technical data and computer software run on separate clauses
DoD splits the subject in two. Technical data is governed by DFARS 252.227-7013. Computer software is governed by DFARS 252.227-7014. They look alike and they grant different things.
Technical data is recorded information of a scientific or technical nature, in any form, including computer software documentation. It excludes the software itself and information incidental to contract administration such as invoices. Drawings, test reports, interface specifications, performance data, and the user manual all land here.
Computer software is the programs, source code, listings, object code, design details, algorithms, processes, flow charts, and formulae that would let the software be reproduced, recreated, or recompiled. The clause carves two things out of that definition: software documentation, which is technical data, and computer databases, defined as a collection of recorded data in a form capable of being processed by a computer. That second carve-out matters more for AI work than for anything else, and I come back to it below.
Sort every item on the contract data requirements list into one bucket before you write a legend. The private-expense tier is called limited rights on the data side and restricted rights on the software side, and the grants differ.
The four license grants
Four standard grants cover almost every case, with a fifth path for terms the parties negotiate themselves.
| License grant | What the government may do | Usual trigger |
|---|---|---|
| Unlimited rights | Use, modify, reproduce, release, display or disclose in any manner and for any purpose, and authorize others to do the same. | Development funded exclusively with government money, or the item falls in a category the clause treats as unlimited regardless of funding. |
| Government purpose rights | Anything inside the government, plus release outside it for government purposes only, with recipients signing a use and non-disclosure agreement under DFARS 227.7103-7. Commercial use by others is barred. | Mixed funding. Default period is five years, negotiable either way, running from execution of the instrument that required the development. On expiration it becomes unlimited. |
| Limited rights (technical data) | Use, modify, reproduce and disclose inside the government only. No release outside without written permission, apart from narrow emergency repair exceptions. | Data pertaining to items, components or processes developed exclusively at private expense, properly marked. |
| Restricted rights (computer software) | Run on one computer at a time, make minimum backup copies, modify or merge (modified portions stay restricted), transfer to another agency with notice, and allow a covered government support contractor access under a non-disclosure agreement. | Software developed exclusively at private expense, properly marked. |
| SBIR/STTR data rights | A protected tier under DFARS 252.227-7018 during the protection period, then a defined license afterward. | Data generated under an SBIR or STTR award. Twenty years from date of award. |
| Specifically negotiated license | Whatever the parties write, provided the government gets at least limited or restricted rights. | Negotiated before award and written into the contract. |
Engineers read the restricted rights list and stop at "one computer at a time." The provision that moves money is the covered government support contractor language: a third party doing independent technical review for the program office can receive your software under a non-disclosure agreement without asking you first.
What "developed exclusively at private expense" means
Everything above turns on one factual test, and DoD defines it more generously than firms expect. Development is exclusively at private expense when it was paid for entirely with costs charged to indirect cost pools, costs not allocated to a government contract, or a combination of the two. Independent research and development charged to an IR&D pool therefore counts as private expense on the DoD side, even though IR&D is an allowable indirect cost the government reimburses through overhead. For a firm that self-funds a product baseline, that is the sentence to remember.
Three consequences follow. The test applies to a deliverable, not to a company: a module, a dataset, a checkpoint or a document has private-expense status, and a firm does not. It applies at the smallest segregable piece you can defend. If proprietary logic sits behind a clean interface and the contract-funded work sits in the adapter around it, you have something to assert; if both live in one file, you do not. And the burden of proof is yours and documentary: cost accounting by project number, dated repository history, the authorization that opened the IR&D project. A recollection is not evidence.
How well a private-expense assertion tends to hold up, by artifact type
Editorial weighting from the clause text and public guidance, meant to rank how hard the argument is. Not a measured statistic.
Categories where funding does not matter
Some deliverables carry unlimited rights no matter who paid. The technical data clause lists them: form, fit and function data; data necessary for installation, operation, maintenance or training, other than detailed manufacturing or process data; corrections to government-furnished data; data already public; and data in which the government already holds unlimited rights.
The operation and maintenance category is the one that bites. An administrator guide, a deployment runbook and an operator manual carry unlimited rights even when the software they describe does not. Write them accordingly: describe how to run the system rather than how it was built, and keep process detail in a separately marked document.
Assert before award, or lose the argument
The solicitation provision at DFARS 252.227-7017 requires offerors to identify, in a table filed with the offer, every item of technical data or software that will be delivered with restrictions. Four columns: the item, the basis for the assertion, the rights category asserted, and who is asserting. Assert at the lowest practicable segregable level.
Skip the table and the default is unlimited rights on everything. Fill it in with one line reading "contractor proprietary software" and the assertion is broad enough to challenge in a paragraph. After award an assertion may be added only in narrow circumstances, mainly for data developed later or an inadvertent omission that would not have changed the source selection. Give the table the review time you give the technical volume.
The legend is the asset
Rights that are not marked do not exist. The clauses say it directly: unmarked deliverables are furnished with unlimited rights, and nobody has a duty to guess what you meant.
A conforming legend is not a paraphrase. It is the exact block of text in the clause, carrying the contract number, the contractor name and address, and, for government purpose rights, the expiration date. For software that means the top of every source file, the license file at the repository root, the readme, the media label and the transmittal letter. Automate it so a new file cannot ship unmarked.
Unmarked equals unlimited
A nonconforming marking is recoverable: the contracting officer notifies you and you generally get 60 days to correct it at your own expense. A missing marking is much harder, because the government took unlimited rights on delivery.
When the government challenges a marking
A restrictive legend is a claim, and the government can test it. Validation runs through DFARS 252.227-7019 for software and DFARS 252.227-7037 for technical data, implementing 10 U.S.C. 3781 and following, formerly 10 U.S.C. 2321. The contracting officer issues a written challenge stating the grounds, and you have 60 days to respond with supporting evidence. No response, and the marking can be stricken.
Two timing facts belong on the wall. The government generally may not challenge a marking more than three years after final payment or three years after delivery, whichever is later, with exceptions for fraud. And your evidence is weakest years after the engineers who wrote the code have moved on. Firms that win challenges assembled the file at delivery.
SBIR data rights and the 20-year clock
SBIR and STTR awards run on their own clause, DFARS 252.227-7018, the most protective standard tier available to a small firm. Data generated under the award carries SBIR data rights for 20 years from the date of award of the funding agreement under which it was generated, and during that window the government's ability to release it outside the government is sharply constrained.
Three details decide what the protection is worth. The clock runs from award, not from project completion. It does not extend through follow-on awards: a Phase II does not restart the Phase I clock, and each award protects only what was generated under it, which argues for clean records of what was built when. And at expiration the government holds perpetual government purpose rights rather than unlimited rights. DoD ran that treatment by class deviation from March 2020 and codified it by final rule published December 18, 2024 under DFARS case 2019-D043. Older awards may carry earlier clause text, so read the version in your own contract.
SBIR data rights attach to what the award generated. Background technology stays under the ordinary clauses and needs its own assertion and legend. Data rights are also separate from patent rights, which run under Bayh-Dole and give the government a paid-up nonexclusive license to practice the invention. March-in belongs to that patent side, covered in a companion piece.
Civilian agencies use a different clause
Outside DoD the governing clause is usually FAR 52.227-14, Rights in Data, and its default is blunt: unlimited rights in data first produced in performance of the contract, in form, fit and function data, and in data delivered with copyright. Protection for privately developed material comes from the alternates. Alternate II covers limited rights data and Alternate III covers restricted computer software, and both have to be in the solicitation for you to rely on them.
Copyright works differently too. You generally need the contracting officer's written permission to assert copyright in data first produced under the contract, and the government keeps a paid-up worldwide license in whatever you do copyright. Agencies layer supplements on top, including NASA at 1852.227-14. The category names travel across regimes; the grants behind them do not.
The commercial route is the strongest position
If what you deliver is a commercial product, the analysis changes. Under FAR 12.212 and DFARS 227.7202 the government acquires commercial computer software and its documentation under the license customarily provided to the public, unless that license conflicts with federal law. No unlimited rights by default and no restricted rights legend. Your standard license, as offered to everyone else.
The determination has to be real. The product must be sold, leased, licensed or offered to the general public, and a contracting officer will ask for evidence. A firm doing both product and services work should keep the two on separate accounting and separate repositories so the claim is clean when it matters.
Where AI deliverables strain the framework
These definitions were written for drawings and compiled programs. AI work produces artifacts that sit in neither bucket cleanly, and the characterization is unsettled.
Trained model weights. A checkpoint is a file of numbers. It is not source code, listings, flow charts or formulae in any ordinary sense, and it looks a great deal like a computer database, which the software clause excludes by definition. That reading pushes weights toward the technical data clause and the limited rights legend. A competing reading treats the checkpoint as part of the software, since it is required to recreate the working system. Both are defensible today. Avoid litigating it later: define the artifact in the deliverable description, name it in the assertion table, and mark it with the legend from the clause you named.
Training and evaluation data. Corpora assembled at private expense are among the most valuable things a small AI firm owns and the easiest to lose by delivering without an assertion. Where the government furnished the data, the reverse applies: government-furnished information carrying restrictive legends brings its own limits under DFARS 252.227-7025, and a model trained on it may inherit them.
Prompts, configuration and evaluation suites. These read as ephemera to engineers and function as the crown jewels in practice, because a system prompt and an evaluation suite often encode more domain knowledge than the model does. An evaluation script delivered unmarked is unlimited rights on arrival.
Two provisions in the fine print
Deferred ordering, at DFARS 252.227-7027, lets the government order any technical data or software generated during performance until three years after acceptance of all items. Generated, not deliverable. Design notes and intermediate models you never planned to hand over are orderable. Deferred delivery, at DFARS 252.227-7026, does the same for items already identified.
These clauses also flow down. A prime cannot demand rights greater than the government would get, and a subcontractor asserts directly rather than through the prime. If you are the prime, collect subcontractor assertions before your offer goes in, because their restrictions become your problem at delivery.
A working checklist
- Run the private-expense test per module, per dataset and per model, before the proposal is written.
- File the 252.227-7017 assertion table at the lowest segregable level you can defend.
- Keep dated evidence: cost accounting by project number, repository history, IR&D authorizations.
- Copy the legend verbatim from the clause and automate it in the build.
- Calendar the government purpose rights expiration and the SBIR protection date for every award.
- Check the contract for deferred ordering and deferred delivery.
- Collect subcontractor assertions before submission, and flow the same clauses down.
Bottom line
Data rights work is unglamorous and it compounds. Firms that handle it well do three ordinary things: separate privately funded code from contract-funded code in the architecture, file a specific assertion table with every offer, and mark every artifact with the exact legend the clause requires. Firms that handle it badly find out on a recompete, when the government hands a competitor the system they paid to build. None of it is hard. It is only unforgiving about paperwork done late.
Frequently asked questions
Almost never. The government takes a license, not title. The question is how wide that license is: unlimited, government purpose, or the restricted tier for privately developed software. Ownership and copyright stay with the contractor unless the contract says otherwise.
Limited rights apply to technical data under DFARS 252.227-7013. Restricted rights apply to computer software under DFARS 252.227-7014. Both cover material developed exclusively at private expense, but restricted rights spell out permitted uses: one machine at a time, backup copies, and access by a covered government support contractor under an NDA.
For DoD, yes. Development paid for entirely with costs charged to indirect cost pools, costs not allocated to a government contract, or a combination of the two qualifies as exclusively at private expense. That puts IR&D on the private side of the line, which is why documenting the project number matters.
Twenty years from the date of award of the funding agreement under which the data were generated. The period does not extend through follow-on awards, and at expiration the government holds perpetual government purpose rights rather than unlimited rights, per the DFARS final rule published December 18, 2024.
The government takes unlimited rights in it. A marking that is present but written incorrectly can usually be corrected after notice, typically within 60 days at contractor expense. An absent marking is far harder to recover, which is why the legend belongs in the build pipeline rather than in a reviewer's memory.