In May 2026 the Software Freedom Conservancy — the nonprofit that wrote the AGPL’s defining “Affero clause” — declared that Bambu Lab is committing what its policy fellow Bradley M. Kuhn called “the most egregious AGPLv3 violation that I have ever seen.” The dispute is ostensibly about a software license. In practice it is a test of a question every 3D-printer owner should care about: when the slicer that drives your machine is built on open-source code, what does the manufacturer owe back, and how much control can it claw away after you have already paid?
The license at the heart of it
Bambu Studio, the company’s official slicing software, is a fork of OrcaSlicer’s lineage that traces back through PrusaSlicer to the original Slic3r project — all of it licensed under the GNU Affero General Public License, version 3 (AGPLv3). The AGPL is a strong copyleft license: if you distribute software built on it, you must also distribute the “complete, corresponding source code” needed to build, run, and modify the covered work. It is not a courtesy. It is the condition under which the code was made available in the first place.
According to the Software Freedom Conservancy’s published findings, that is exactly where Bambu Lab falls short. The SFC says Bambu Studio does not ship complete corresponding source because the application depends on a closed-source networking component loaded at runtime — distributed across platforms as libbambu_networking.so on Linux, bambu_networking.dll on Windows, and libbambu_networking.dylib on macOS. The SFC’s position is that combining AGPLv3 code with these proprietary libraries, and shipping the result without source for the parts needed to reproduce full functionality, breaks the license. The SFC describes this as one of two violations it has confirmed so far in an investigation it says is still ongoing across both the userspace software and the device firmware.
The fork that lit the fuse
The fight became public through one developer. Paweł Jarczak built an OrcaSlicer fork — reported as OrcaSlicer-bambulab — that restored the ability to send print jobs to Bambu printers through the company’s cloud without routing through Bambu Connect, the proprietary middleware the company introduced after launch to gate third-party software. As the SFC tells it, Jarczak did not crack or replace the proprietary networking libraries; he made changes to a different AGPLv3 slicer “by merely examining the (incomplete) source code for Bambu Studio” — precisely the kind of study and modification the license is meant to permit.
Bambu Lab objected and, per reporting by Tom’s Hardware, issued a cease-and-desist demanding the project be pulled from GitHub. The company’s stated grounds, as covered by Aftermath, were that the fork “impersonated Bambu Studio,” bypassed authorization controls, and breached its Terms of Use — the impersonation claim resting largely on the client’s User-Agent string. Jarczak’s rebuttal was blunt: “User-Agent is not authentication. It is only self-declared client metadata.” He took the release down anyway, saying he did so voluntarily to avoid a prolonged legal fight rather than because he conceded the point.
That asymmetry — a large, well-funded manufacturer leaning on a lone developer — is what drew open-source advocate Jeff Geerling into the story. In his piece “Bambu Lab is abusing the open source social contract,” Geerling argues the fork used Bambu Studio’s upstream code verbatim, making the impersonation framing hard to square with how the software actually worked, and that the deeper problem is cultural: a company built atop community AGPL code applying legal pressure to the very ecosystem that enabled its product.
What the SFC is actually doing about it
Rather than stop at a statement, the SFC launched a funded effort it calls the “baltobu” project. Its goals, per the SFC, are concrete: a reverse-networking repository to reverse-engineer the three proprietary networking libraries and build a compliant, open replacement; and an orca-slicer-for-bambu repository to preserve and maintain Jarczak’s withdrawn fork so Bambu owners are not left without the functionality it restored. In short, the nonprofit is attempting to rebuild from scratch the one piece Bambu has kept closed, so that the rest of the AGPL stack can be used as the license intends.
Why cloud dependence is the real stakes
Strip away the license mechanics and the underlying issue is ownership. A printer that prints best — or only — through a vendor’s cloud is a printer whose capabilities the vendor can renegotiate after the sale. The Bambu Connect layer is exactly that kind of lever: reporting indicates the company introduced it after launch and that remote access still flows through Bambu’s servers or that proprietary plugin, which is why OrcaSlicer’s maintainers declined to build it in. Bambu did later add optional Developer and LAN-only modes after backlash, but, as Aftermath notes, that doesn’t restore unrestricted local control for everyone — full remote workflows still depend on the company’s infrastructure.
The practical takeaway
If you own or are shopping for a 3D printer, the concrete lesson here is to treat genuine LAN/local control as a buying criterion, not a footnote. Before you buy, confirm the printer can do its core jobs — slicing, sending, monitoring — entirely on your own network, without an account, a cloud round-trip, or a proprietary connector that the maker can change or revoke later. Favor machines where an open slicer (such as OrcaSlicer or PrusaSlicer) can talk to the printer directly, and where a LAN-only mode is fully featured rather than a degraded fallback. The Bambu dispute shows what is at risk when that path is gated: a fast, capable machine can still leave you renting access to features you thought you bought. Local control is the part no terms-of-service update can take back.
Sources
- Software Freedom Conservancy, “Comprehensive Response to Bambu’s AGPLv3 Violations” — sfconservancy.org (the proprietary networking libraries, the missing complete corresponding source, the baltobu project, and the description of Jarczak’s fork)
- Jeff Geerling, “Bambu Lab is abusing the open source social contract” — jeffgeerling.com (the verbatim-upstream-code argument and the social-contract critique)
- Aftermath, “The Battle Over 3D Printer Software Licensing Matters For Everyone” — aftermath.site (Bambu’s stated objections, the User-Agent exchange, Bambu Connect and the LAN/Developer-mode context, and Kuhn’s quote)
- Tom’s Hardware — coverage of the cease-and-desist and the SFC’s confirmed-violations claim: tomshardware.com