Digital sovereignty has become Europe’s top priority — here's how open source is helping pave the way
Open source software could play a key role, experts claim
Digital sovereignty in Europe has grown from a simple talking point into a strategic priority, and open source software (OSS) is perceived as the continent's way of achieving that goal. However, there is no sovereignty without security.
At the recent Linux Foundation Open Source Summit Europe, the Foundation’s Madalin Neag and Mirko Boehm argued that many of Europe's seemingly separate technology initiatives - from NIS2 and DORA to the Cyber Resilience Act (CRA) and its broader Tech Sovereignty agenda, all ultimately converge on solving one problem: securing the software supply chains underpinning Europe's economy.
The global technology race is currently being led by two superpowers - the United States, and China. The US has the hyperscalers, Nvidia, OpenAI, Google, Microsoft and mind-numbing amounts of capital flowing into AI infrastructure. China, on the other hand, has its own sprawling Artificial Intelligence ecosystem, domestic chip ambitions, and companies such as Alibaba, Tencent, and DeepSeek.
Both are in a race for chips, electrical energy, and data center capacity, while Europe seems to be sidelined, without a horse in the race.
The European Commission itself acknowledges the position it is in. After years of regulatory leadership and investments, non-EU providers still account for more that 80% of the bloc’s digital products, services, infrastructure, and even intellectual property.
Europe’s open source bet
The European Commission launched its new technological sovereignty package in June 2026, containing things like the Chips Act 2.0, Cloud and AI Development Act (CADA), a roadmap for digitalization and AI in energy, and a new EU Open Source Strategy.
The latter is particularly significant because open source already powers most of the tech Europe relies on, from cloud infrastructure to financial services, from government systems, to AI.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
The Commission estimates that around €2 billion ($2.23bn) in public and private investment will be needed for the open-source strategy over the next seven years. That includes expanding the Open Internet Stack as a one-stop shop for open-source building blocks, supporting open-source business accelerators, encouraging its use in public procurement and R&D programs (such as, for example, Horizon Europe), and working with member states through initiatives including the Digital Commons EDIC.
While the word “sovereignty” might suggest technological isolation, what the EU is trying to do here seems to be exactly opposite. Digital sovereignty means making sure European organizations can choose, inspect, maintain, and replace technologies on which they depend, instead of being locked into walled gardens and infrastructure that is under someone else’s control.
And as AI keeps shaping and reshaping the global technology market, this dependence will grow ever more consequential. Building and running advanced AI requires enormous amounts of compute, energy and data center capacity, areas in which US and Chinese companies are investing heavily. For Europe, the risk is that the next generation of critical digital infrastructure becomes dominated by foreign technology before a competitive European ecosystem has a chance to emerge.
The Commission estimates Europe will need around €200 billion ($223 bn) to expand data center capacity by 2036, mostly from the private sector, alongside another €100 ($111bn) billion for cloud and AI initiatives, AI Factories and Gigafactories. While the EU is making prognoses, US electricity consumption is expected to hit record highs not just this year, but in 2027, as well. AI and data centers will be the major drivers, obviously, while the race for compute grows into a strategic issue in the US-China tech rivalry.
So the point is - Europe can’t simply outspend either side and therefore sees open source as an alternative route to reducing its strategic exposure.
What this means for businesses
So, European businesses and governments just need to download more open source software? Yes, and no. It’s not that simple.
One of the clearest messages from Neag and Boehm's presentation was that organizations "cannot secure a supply chain passively". Businesses that download dependencies, integrate them into products, scan them and then maintain private patches, risk accumulating technical debt while the upstream projects themselves deteriorate.
What they need instead is active participation: identifying critical OSS dependencies, establishing relationships with maintainers, contributing fixes upstream and, where appropriate, providing long-term financial support.
Neag and Boehm argued that suggested code contributions can return 3.3 times their cost, community contributions 2.5 times, and direct financial contributions 2.3 times, so there’s a commercial incentive, as well. Maintaining private forks, on the other hand, was estimated to cost organizations an average of $258,000 per release cycle.
It seems the EU’s sovereignty push is designed to change how businesses think about procurement and supply-chain risk. Businesses should expect greater emphasis on dependency transparency, provenance, vulnerability management, secure development and the health of upstream projects (which is already seen in legislation such as the CRA).
What’s also interesting is that there eventually might be a more formal way of judging sovereignty itself, since the keynote presented "Sovereignty Effectiveness Assurance Levels", or SEAL, ranging from SEAL-0 (technology under the control of non-EU parties and jurisdictions), to SEAL-4 (technology and operations which are under complete EU control with no critical non-EU dependencies).
If the EU is to continue operating in a world of increasing geopolitical turbulence, it needs to rely less on vendors and supply chains, and secure open-source software just might be the way forward.
Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.
You must confirm your public display name before commenting
Please logout and then login again, you will then be prompted to enter your display name.