Europe talks about digital sovereignty a lot. But the meaning of the word has shifted this year, and came into focus on day one of the Open Source Summit Europe in Prague.
It used to mean “pick open source software instead of proprietary software”. Now it’s closer to: do we actually understand and participate in the open source we’re using, or are we just consuming someone else’s work and calling it control?
Stephen Sopko, Practice Lead at HyperFRAME Research, told a story during a sovereignty panel for media and analysts that shows what this looks like in practice. Years ago, during a long contract negotiation, he insisted on source code escrow, and the clause took weeks. When the vendor eventually went out of business, the source code arrived on his doorstep and nobody on the team had ever touched it. He recalled: “I’m sure I’m glad we waited an extra month to negotiate all that in – because it was meaningless.” Thierry Carrez, General Manager of Linux Foundation Europe, opened the panel with a similar theme – effective control over your technology requires participation in the project that produces it.
Europe writes a lot of the code the open source world runs on – but it doesn’t fund or govern it in proportion.
Public source gives you access, not continuity
In both the keynote and the panel, Carrez emphasized the difference between “public source” and “open source”. Public source, as he describes it, is what you get by just being able to see the code. This is the first level of sovereignty, and you can audit it for kill switches, check what’s in your supply chain, and build organizational trust in the technology.
Public source does not give you continuity of access, however. If the project either gets taken over by a vendor with different priorities or stops being maintained, you may have the code, but you can’t necessarily keep running it. The only way to protect against that is being able to fork – which can’t be done from a legal clause alone – as a technical move it can only be done if you know the project, its release process and security vulnerability management. Or as Carrez says, if you have “enough familiarity with the software to be sovereign with it.”
The morning keynote provided statistics to support this. Across the 620 projects the Linux Foundation currently nurtures, 38% of code contributors over the past 12 months came from Europe. On specific projects the European share is higher – 35% on Kubernetes, 41% on OpenStack, 44% on the Linux kernel, and more than 50% on Zephyr. While Europe is measurably one of the biggest contributors of open source code globally, the matching governance and funding numbers go the other way. European organizations provide 15% of foundation funding across those same projects. Only 37% participate in open source project governance at all, against 59% who contribute code. As Carrez said during the keynote:
US companies and Asian companies – they’ve got this. They realized the importance of strategically investing in openly governed open source.
We need to wake up. Europe really needs to wake up and close that governance gap. We need to be more involved in the governance of those ecosystems early to truly reach digital sovereignty.
Where sovereignty stops being just about the code
Jonathan Bryce, Executive Director of the Cloud Native Computing Foundation (CNCF), took things a step further. Source code on its own, he said, “is not worth a ton if you don’t understand it, if you don’t know how to maintain it, deploy it, monitor it, all those kinds of things.” Who runs the code matters just as much as who writes and governs it. He gave the example of OVH, the French cloud provider:
They have talked about operational sovereignty as being really important, and open operations as being as important as open source. Because even if you have the source code, if you don’t understand how to operate it, then you’re kind of in the same boat as before.
Sopko backed this up – on a briefing with OVH a few weeks earlier, he’d asked whether they build their own servers for sovereignty reasons. He recalled:
They’re like, ‘No, we’ve always built around servers.’ So it’s one of those things where the sensitivity of it finally caught up to the way they’ve been doing business for almost thirty years.
Bryce heard the sovereignty question come up again at KubeCon Shanghai earlier this year – this time about hardware:
China has been a huge adopter and participant in open source software for decades now. And they were much more on the hardware sovereignty side. If we don’t have chips, if we don’t have optical systems – those kinds of things.
Open source matters, he said, but it isn’t the whole stack. He continued:
The most valuable thing with open source is the choice. It gives you a choice, and when you have a choice, that on its own puts you in a completely different situation than when you don’t have a choice at all.
When policy caught up with practice
Paula Grzegorzewska, Strategic Partnership Senior Manager at Linux Foundation Europe, has been working on open source policy in Brussels for seven years. Her perspective was that the sovereignty question has existed strategically since 2019 – but open source only got taken seriously as part of the answer this year. She explained:
Seven years ago, I had to always explain open source. When I said in Brussels that I work on open source policy, it was just raised eyebrows. People were like, ‘You mean…’ and it was from people who worked on digital policy. It was super niche. Now it’s not perceived as a niche at all.
What changed, in her experience, was European Commission policy.
In June, with all these proposals from the European Commission, this was something that finally gave European member states the stamp of approval that this makes sense. This is not just a niche hobby activity. I’ve been talking to many people working in ministries around Europe, and finally they say, I have this piece of paper from Brussels that says this makes sense. I can do it. So finally, suddenly budgets are found. New units are being built.
She expects open source program offices in every member state soon – a structural change in how governments interact with the open source ecosystem. The 2026 Technological Sovereignty Package has €2 billion in funding behind it over seven years. She also pointed to Data Act impact assessments that now include calculations of the cost to the public sector of switching to open source solutions.
Grzegorzewska added another important factor that can get lost in the policy frameworks – the cost of switching is the real argument for open source in the public sector:
Sometimes organizations fail when switching from one proprietary vendor to another, and that usually costs a lot of time and a lot of expertise. Open source just allows this switching to be way, way less painful.
It’s happening now. But it’s a bit late.
CRob – open source is “not free and not easy”
Christopher “CRob” Robinson, CTO of the Open Source Security Foundation (OSSF) and lead on the new Akrites vulnerability response project, has been working on security upstream for 15 years. The European sovereignty conversation, he said, is “very familiar” to him. His view on how it actually works is:
It is not free and it is not easy, but it requires an investment in skills and expertise.
Open source gives you the choice to leave the big vendors – but to actually exercise that choice, something else is required. He continued:
You have the ability to go in and mold this software that might be 90% of what you do, and then tailor it to your organization. And if you want to make choices about a particular developer or organization that you like or don’t want to work with, you have that ability, and you can either find an alternative package or you could write your own and start your own community.
What’s complicating that in 2026 is agentic AI, as Robinson observed:
AI absolutely has drastically changed the practice of software development. We have a lot of people today that are non-traditional developers. They aren’t trained software engineers. They might be Sally from accounting or Jane from legal or Fred from operations who are able to write software and customize things very easily with these agents.
But there are limits, as he elaborated:
AI is not going to replace everything. You’re not going to replace the Linux kernel by one prompt to ChatGPT. Platform infrastructure stays where it is. Where the shift is happening is lower down the stack – the departmental tool, the one-off automation that used to be a SaaS purchase. Now Sally, Jane or Fred can generate it. That’s a sovereignty question too: if the custom tool Jane generated with an agent breaks, who maintains it?
My take
Having the code is now the easy part. Participation is where sovereignty gets tested. The June policy move gave European member states permission to care, but the most important budget line is skills and time, not the €2 billion. If European enterprises want sovereignty to be more than a procurement principle, they need to show up in the governance structures, on the maintainer rosters, in the funding commitments that currently sit at 15% against 38% code contribution. Enterprises can keep using hyperscalers – but they also need to have the option to walk away.
Awareness is still lacking – the language of “digital sovereignty” has outpaced the practice. The data highlights that 94% of European organizations say sovereignty is strategically important; 37% participate in open source project governance. As Carrez said earlier, there needs to be a wake-up call.
I’ll have more on this shortly – with Bianca Lewis, Executive Director of the OpenSearch Software Foundation, on how one project reads its own trajectory, and with CRob and Laura Guazzelli of OpenSSF on where agentic AI leaves the standards process.
Source: diginomica.com




