That's a good project management lens. In our case, the licensing risk wasn't the primary blocker, but it introduced a huge process tax. The bigger blocker was the lack of visibility into their training data for our proprietary codebase snippets.
>Did any of the tools clearly generate safer code in that regard?
No, they were all a black box on what specific data shaped a suggestion. The safety came down to their indemnification policies, which were basically identical across the vendors we looked at. The real cost was building internal scanning and pre-commit hooks to mitigate what they couldn't guarantee.
So it was less about the generated code being 'safer' from one tool, and more about having to allocate engineering time to create guardrails they all lacked. Did your team run into that overhead, or did you find a vendor that was more transparent on data lineage?