Just like with other code they should not be using as they do, they would probably run another "ask questions later" approach.
They've been to court and they've lost and it definitely hasn't destroyed their business one bit.
For example, Microsoft subsidiary LinkedIn routed customer email through their servers so that they could scrape it. They did that without customer knowledge via a dark patten.
They later apologised for doing it but still used it to propel the company's growth. In the end it didn't hurt anything but their reputation for respecting people's privacy.
Microsoft's own anti-trust history is littered with exceptional behaviour too. They are the size they are now by dint of super aggressive business practices.
Why wouldn't sw companies do the same?
I guess if they can do that, then what's a small lie about private repos between friends.
This type of thing erodes trust? Why should my proprietary code be used for training by default?
I was really annoyed by this.