BT

Facilitating the Spread of Knowledge and Innovation in Professional Software Development

Write for InfoQ

Topics

Choose your language

InfoQ Homepage News Technological Sovereignty Requires Choice, Skills, and Support, Panelists Say During OSS EU

Technological Sovereignty Requires Choice, Skills, and Support, Panelists Say During OSS EU

Listen to this article -  0:00

European organizations do not need to avoid global technology providers to become more sovereign, but they do need credible alternatives and the skills to use them. That distinction emerged from a panel discussion during the Open Source Summit Europe hosted in Prague. The panellists tried to shed light on dependencies across cloud infrastructure, open source, security, and hardware.

The panel featured Jonathan Bryce of CNCF and the Linux Foundation; Christopher "CRob" Robinson of OpenSSF and Akrites; Paula Grzegorzewska and Thierry Carrez of Linux Foundation Europe; and moderator Stephen Sopko of HyperFRAME Research.

During the panel, the EU cloud sovereignty framework was displayed, listing eight objectives, including legal and jurisdictional sovereignty, data and AI sovereignty, operational sovereignty, and supply-chain sovereignty. The discussion focused on a practical question: which dependencies must an organisation be able to change or control?

"The most valuable thing with open source is the choice," Bryce said. Using Azure or AWS may meet an organization’s needs, he argued, provided it retains other options. He cited Kubernetes as a platform that can run on an organization’s own infrastructure or on commercial clouds. Grzegorzewska added that an alternative is useful only when switching is practical: moving between proprietary systems can demand substantial time and expertise, particularly for governments.

Bryce said access to source code alone does not provide operational sovereignty. Organisations also need to know how to run, secure, and monitor their systems—a distinction he associated with OVH’s approach. He then pointed to hardware as a remaining gap. Recounting conversations around a conference in Shanghai, Bryce said China’s sovereignty discussion focused less on open-source software, in which it has long participated, and more on access to chips and optical systems. Software choice, he argued, is important but does not remove hardware dependencies.

Carrez described proposed cloud and AI assurance levels that would vary by workload. The highest level, he said, would require effective control over the full technology supply chain, including hardware. He also raised confidential computing as a way to limit a host’s access to workloads when that level of control is not required.

Robinson linked sovereignty to security due diligence. Open code and project documentation can help buyers examine vulnerability-response practices and check vendor claims. Discussing the EU Cyber Resilience Act, he said manufacturers bear substantial responsibility for the products they sell, including the open-source components they incorporate. Carrez noted that the Act takes account of software assembled from many dependencies rather than treating it solely as a boxed product.

The panel also challenged the assumption that open source is simply a cheaper option. Freely available code can begin as an engineering experiment and later become a critical system requiring sustained support. Carrez identified a shortage of local companies able to package and support mature projects such as OpenStack. He cited Société Générale as a bank that built expertise in-house because, he said, it lacked a suitable partner. He also described the French Ministry of Finance seeking partners after its OpenStack deployment grew beyond its original scope.

Carrez’s proposed response was investment in local service capabilities, not rebuilding existing global projects. Grzegorzewska called for developer involvement in policymaking and investment alongside regulation. Robinson urged Europe to cultivate local expertise without becoming isolationist, while Bryce argued that broad contributor bases make projects more resilient. Sopko closed with a metaphor drawn from Prague: sovereignty should be about building bridges and maintaining options, not retreating behind fortress walls. This aligned with a joint statement during the panel that mentioned it’s naive to believe that a region of the world can be 100% sovereign.

About the Author

Rate this Article

Adoption
Style

BT