Skip to main content

Thought Leadership: The EU Open Source Policy

AI Openness: 3 Years on from Llama 2 Report

Sachiko Muto, Chairwoman, Open Forum Europe

On 3 June, the European Commission published its Open Source Strategy as part of the Technological Sovereignty Package. The strategy places open source at the very centre of Europe’s push for digital independence yet for anyone who has celebrated high-level policy endorsements of open source before, and then watched the outcomes disappoint, the temptation is to file this one alongside the rest and wait to be proven right. The endorsements have been many. Malmö in 2009, Tallinn in 2017, Berlin in 2020, the European Interoperability Act in 2024 – a steady procession of ministerial signatures affirming that open technologies matter. Several member states have gone further and wrote a preference into their own procurement rules. Italy, France and the Netherlands have each adopted some version of “open, unless” – choose open source by default, unless there is good reason not to.

The trouble was always the “unless.” A recent study for the Danish government, carried out with Johan Linåker, surveyed 16 of the world’s most digitally advanced countries and found open source policies almost everywhere, in one form or another – alongside outcomes that varied enormously. The gap between having a policy and changing what actually gets acquired by public sector organisations turned out to be very wide. Where an escape hatch exists, it gets used. The “unless” box, more often than not, is the box that gets ticked. And yet this time appears to be genuinely different – which is not a claim to make lightly, because making it means setting aside 20 years of well-founded disappointment.

What earns that conclusion is not that open source sits higher on the political agenda, though it does. It is the quality of understanding on display. Past endorsements approached open source mainly as a way to save money on licenses or argued for open source on ideological grounds. This package treats it as an ecosystem to be sustained, and gets the details right in a way that has not been seen before. It talks about maintainers, not just users. It funds critical dependencies rather than assuming they maintain themselves. It commits to building a network of Open Source Program Offices across public administrations, sets key performance indicators and a monitoring framework, commits real budget – on the order of €2B across the wider package – and, crucially, signals that the Commission is willing to lead by example, recognising that not every public body in Europe has the same resources to draw on.

This level of understanding did not come from nowhere. The Commission has been on its own open source journey for a long time, from its first open source software guidance around the turn of the millennium through to the internal strategy renewed in 2020, running code repositories, a solutions catalogue and an open source observatory for years. The Commission’s Cloud Sovereignty Framework, published late last year, showed a sophisticated grasp of what sovereignty actually requires – the ability to migrate without lock-in, to operate and maintain from within the EU, to inspect and modify under open licences.

Another factor deserves credit: the mobilisation of the open source community through the passage of the Cyber Resilience Act – a hard, at times painful process that nonetheless taught both sides how to talk to each other, and left the community more fluent in policy than it had ever been. A vestige of this mobilisation translated into engagement with the strategy itself: the consultation on open digital ecosystems drew more than 1,600 responses, a figure described in Brussels as something of a record.

The scepticism, then, turns out to be incomplete. This is not another declaration. It is the most serious and best-informed articulation of an open source strategy to appear in nearly 20 years. But – and there is, inevitably, a “but” – there is a catch, and it is the one that has always mattered. The Open Source Strategy is non-binding. It is a statement of intent, not a legal instrument. The teeth are elsewhere, and still being forged. The Cloud and AI Development Act – the legislative core of the package – has now entered the European Parliament and Council, where intensive lobbying is certain and a fight that runs well into 2027 is likely. And the revision of the Public Procurement Directive, where a genuine open source preference would acquire real force, has already slipped: expected in early July, it has now been pushed to September. Even the Cloud Sovereignty Framework, for all its rigour, does not commit to co-develop open alternatives where none yet exist – which means it, too, leaves the “unless” box available to tick.

First published by OpenUK in 2026 as part of AI Openness: 3 Years on from Llama 2

©OpenUK2026

Download Thought Leadership Download Report View all thought leadership

Scroll to top of the content