
The EU Open Source Policy Summit 2026, held on 30 January in Brussels under the theme ‘Digital Sovereignty Runs on Open Source’, brought together European policymakers, industry leaders, and open source advocates to address how open technologies can deliver on Europe’s competitiveness and sovereignty ambitions as part of the EU Open Source Week. This year’s Summit also announced a key transition: the appointment of Laszlo Igneczi as OpenForum Europe‘s new Executive Director.
The event was well-timed, given the announcement in early January of a new Call for Evidence on the topic of Open Digital Ecosystems, which will inform the development of the European Commission’s new open source software strategy and related actions. The consultation closed on 3 February and brought a lot of momentum to the conversations at the Summit.
Partly due to this momentum, this year’s discussions moved beyond last year’s question of “What can Europe do for open source?” to make clear that open source is no longer adjacent to the conversation – it’s a central element of addressing Europe’s digital sovereignty challenges. This was both implicit and explicit in the messaging from policymakers during the Summit and around the call for evidence in the weeks leading up to it, and further reinforced by the keynote remarks and presence of Henna Virkkunen, Executive Vice-President of the European Commission for Technological Sovereignty, Security and Democracy.

Key takeaways from the EU Open Source Policy Summit 2026

Takeaway #1: Software requires a distinct industrial policy approach, and open source is central to Europe’s execution capability
[Our industrial policy] is not only about economy right now, it’s about security, it’s about defence, it’s about being independent. And we don’t have 5 to 10 years, we need these solutions now.” – Aura Salla, MEP
The discussions at the Summit reinforced a theme that Europe’s industrial policy has been put back at the centre of the strategic agenda. This has been particularly pronounced in recent months due to the conversations around simplification and the Digital Omnibus.
The discussions at the Summit reinforced a theme that Europe’s industrial policy has been put back at the centre of the strategic agenda. This has been particularly pronounced in recent months due to the conversations around simplification and the Digital Omnibus.
Software demands a fundamentally different approach than hardware or physical infrastructure. The keys to competitiveness and sovereignty in a software-defined world are very different from those in the world of computers and chips. Software – and by extension, software supply chains – depend on long-term capability, open innovation, and the ability to maintain and evolve technology over time – not just ownership or one-time procurement.
For Europe‘s ‘digital competitiveness’, panellists emphasised that true sovereignty means having the institutional capacity to inspect, fix, and adapt the software Europe depends on. This type of understanding, if operationalised at scale, would enable a new model of European industrial policy that supports the needs of industry today, one in which open and collaborative software development would be to be fully accounted for. Supporting open source development – including reuse and collaboration upstream – requires investing in skills, sustainable maintenance models, and collaborative development ecosystems.
Without this bold vision and the execution capability to deliver on it, Europe risks treating open source as just a ‘borrowed engine’ rather than as the foundation of a genuinely sovereign and competitive digital economy. Panellists agreed that Europe must align funding, regulation, and capacity-building initiatives around execution – ensuring that open source investments translate into long-term competence and resilience.

Takeaway #2: OSPOs are emerging as sovereignty engines and building institutional capability at scale
OSPOs can act very powerfully to help interiorise dependencies and risks within the organisations, but [also] showing a path on how organisations can free themselves and manage those risks.” – Manuel Mateo Goyet, Acting Head of Unit, Cloud & Software Unit, DG CNECT, European Commission.
Open Source Programme Offices (OSPOs) have evolved from compliance functions into strategic instruments for building digital sovereignty. Across critical sectors – energy, transport, manufacturing, retail, and public administration – organisations are establishing OSPOs to govern open source use, contribution, and collaboration in structured, sustainable ways. There has been some discussion in recent weeks that the Commission’s new OSS strategy might forefront OSPOs more, building on the success of the EC OSPO at DG DIGIT and the EC OSPO network to function as a way of diffusing open source knowledge in Member States.
During the panel on OSPOs at the Summit 2025, panellists from RTE, Deutsche Bahn, IKEA, and the European Commission made this opportunity crystal clear. They described in detail the important and foundational role OSPOs play in helping organisations shift from consuming open source to actively participating in and shaping the ecosystems they depend on. This includes areas like aligning procurement with open source strategy, internalising competence, building trust in technical communities, and enabling long-term participation in collaborative development.
Crucially, if digital sovereignty ‘runs on open source’, its capacity to do so will largely be dependent on success in institutionalising OSPOs as centres of excellence and competence across the public sector and industry. OSPOs are not just about risk management – they are about building the institutional learning, governance capacity, and strategic collaboration needed to strengthen Europe’s technological resilience. They support ecosystem engagement and enable the diffusion of knowledge and expertise, which will be critical for the implementation of legislation and support of collaborative innovation

Takeaway #3: Procurement remains one of the most powerful levers for improving adoption of open source
You need to create the market and amend the market to create the demand for the products and services. The price is still one of the key criteria, but this cannot be the only or main sustainable factor behind the decision.” – Michał Kobosko, MEP
Procurement shapes markets, and Europe’s public authorities alone spend approximately 15% of EU GDP annually. Yet procurement policies often fail to recognise the value of openness, interoperability, long-term maintainability, or contributions to shared digital infrastructure – creating market incentives that favor lock-in over sovereignty. A lot of procurement is set up to safeguard risk, and is not very well-suited for the types of risk-taking and bold moves needed to support the iterative and agile development that (open) software collaboration requires.
This year’s Summit highlighted this theme, exploring how non-price criteria such as open standards compliance, contribution to open source ecosystems, transparent governance, and sustainable funding and support can be systematically integrated into both public and private procurement. Panellists called for some interventions, such as ‘open source impact dashboards’ that make providers’ contributions to European digital infrastructure visible and measurable, creating clear incentives for sustainable ecosystem participation.
Helping Europe to better procure open source – and sometimes this means just procuring talent and changing ways of contributing back – will be a good place to start to upend the status quo and stay competitive. The approach extends beyond the public sector. Large industrial actors – in automotive, energy, telecommunications, manufacturing, and many more industries – are also IT users with strategic interests in reducing dependency and ensuring long-term control.

Takeaway #4: Building a healthy cloud and AI ecosystem requires execution, not just regulation – and open source is critical to that execution ability
We need to learn from each other, we need to scale by showing that there is a path and there is a way to buy European that makes sense and can also be risk-free.” – Thibaut Kleiner, Director, Future Networks, DG CNECT, European Commission
Europe’s ability to ensure digital sovereignty depends on having robust and sustainable open foundations for all digital infrastructure, as well as viable, competitive alternatives to dominant global platforms and the ability to switch without the onerous and costly effects of lock-in. This is particularly true in the cloud and AI space, which is central to the forthcoming Cloud and AI Development Act (CAIDA).
This year’s Summit examined how open source can underpin new ecosystems in cloud and AI – from infrastructure initiatives like EuroStack and the Open Internet Stack to emerging open AI models and collaborative frameworks. But leadership requires more than regulatory frameworks or declarations of intent – it requires execution. This means working across Member States, industry, and EU institutions, as well as aligning industrial policy, investment, procurement, and regulation to enable European providers to scale through open infrastructure, interoperability, and shared development. It also means lifting up examples of innovation and challenging the status quo from Member States, diffusing that knowledge, and promoting more experimentation in how things are built.
Panellists emphasised that open standards and common open source components allow European providers to federate services and operate as if they were one larger platform while remaining independently governed. They discussed how scaling open source alternatives means taking corporate responsibility and practicing good hygiene in participating in an open ecosystem: contributing code, standards, and security fixes, not just consuming pre-built solutions.
There is also the question of switching, which needs to be examined through a focus on the role open source collaboration can play in factoring de facto standardisation, as well as the role of EU regulation in enabling switching and user choice in the cloud market. Here, there remain questions of the link between CAIDA and the EU’s forthcoming open source software strategy, but more will hopefully be learned in the coming weeks.

Conclusion: European leaders need to invest in open source to secure a digitally sovereign Europe
Open source is not optional for Europe’s digital sovereignty; it is one of its foundations. Strengthening open source and its role in the digital ecosystem means strengthening all of our digital foundations, and it is a rising tide that lifts all boats. Open source supports sovereignty, but more importantly, it is the foundation of a more competitive market with more choice, open standards, collaborative innovation, and open governance.
But our message is clear: digital sovereignty will only run on open source if Europe invests in the capacity to maintain, evolve, and govern the systems it depends on. By prioritising execution and seizing the opportunity and energy of the last weeks, Europe can position itself as a global leader in open, sovereign, and competitive digital infrastructure.
