FOSS Backstage

Mirko Boehm – Does FOSS Buy Sovereignty? Participation vs. Ownership #FOSSBack

31:05 · 16 Mar 2026 – 17 Mar 2026 · YouTube

About this talk

This talk explores the concept of digital sovereignty and its importance in today's technology landscape. The speaker defines digital sovereignty as the ability of individuals and institutions to operate independently in the digital realm, emphasizing the role of open source software in achieving this goal. They discuss the challenges posed by proprietary systems and foreign corporate control, highlighting the need for resilience against threats and the necessity of choice, adaptability, and influence in digital environments. The session also addresses the gap between open source adoption and active participation, outlining strategies for navigating collaborative and competitive environments. The speaker concludes by emphasizing that while open source can enhance digital sovereignty, it requires active involvement and investment from organizations to truly harness its potential.

Full transcript

My talk will be about digital sovereignty. I know it's a big word. I know everybody talks about it, but I thought why not do it too. Um so um preparing this talk actually reminded me that some doing something analytical is a lot harder than uh talking about regulation. The last two years here I spoke about the cyber resilience act. Actually realized in the same hoodie. So this

is now my um legendary traditional fastback stage hoodie. I will wear it every year. Um so when we talk about law, law gives us pretty clear guard rails. Um it you know what is in it, you know what's not in it and and it gives us also a framework for interpretation. Yes, there are um things that are unclear but we can discuss in a certain framework. Here

we will define the framework ourselves. So when we talk about digital sovereignty, I'm using the the um center for digital sovereignty definition. Uh thank you Germany for setting up something like Sandis. Uh quite cool. So digital sovereignty describes the abilities and opportunities of individuals and institutions to be able to perform their roles in the digital world independently, self-determin. Now um it is pretty much a given that

people say and for that we need open source. Um, yes, we do. But why? So, let's ask a little bit, what problem are we trying to solve with this? And I've listed the, in my opinion, most obvious problems here kind of in an order from small to large or bigger smaller problems to to massive worries. So we basically as society seek resilience against present threats and the

present threats are at the commercial level proprietary lock in the the vendors of our systems basically control the road map the pricing when they end support for the products that we depend on. Um that's mostly a a problem of getting the right thing to to solve a problem for me. Um but we have a bigger problem and that is foreign corporate control about uh over the um

the systems that we use uh including forced access to data that should be hosted in our systems. Um and these decisions are made in other jurisdictions and this clearly touches on the topic of sovereignty in the sense of the theory of the state. And then an even bigger problem is that we have diverging state policy goals like um we have kind of friendly state policy goals. Industrial

policy, competition, trade, intellectual property. This is where um reasonably people can disagree over their goals and we can negotiate and then there will be a trade agreement. But we also have adversarial action. We have Russia's aggression in Ukraine. We have other aggression in the world right now as you know. So um we do want to achieve digital sovereignty to solve to be better able to solve these

problems to have resilience as many people frame it as you see in the picture um to maintain our state of sovereignty. And if you dig further into the Zender website you find a breakdown of three aspects that this requires choice adapt adaptability and influence. By the way I kind of rephrased it a little bit for clarity but you'll find it on the website. Choice means the option

to choose flexibly switch between the solutions that you think are the best for you. Adaptability means to co-shape the these solutions, be able to influence how they work um um be able to acquire the skills to operate them um and to collaborate with the developers. And adaptability is more on a technical level and then influence is can I influence the technical road map of this solution? um

can I participate in the governance of it? Can I understand the motives of the people who are contributing to it? And open source very clearly promises to deliver on all three of these dimensions. Um and the question is a little bit are we digitally sovereign yet? And the answer is maybe. Um so open source has existed for 30 years, three decades. I made my first first commits

in 97. That is almost three 30 years ago, 29 now. Um so and and while free and open software was available all that time big tech grew mostly outside of Europe. Um we have not seen pervasive adoption of open source technologies for digital public goods. Surprising and we just recently learned 2565 265 billion euro per year flow from as spending of the European countries to big tech

providers who are not sitting in Europe. Um so from my perspective this is not a great picture. On the right you see one statement from um a report that we published last year the world of open source Europe spotlight that was subtitled Europe open source as Europe strategic advantage and it says that of the respondents to this report pretty much all of them saw open source as

critical to digital sovereignty providing greater control and agency over European technology stacks. Um this is freely available on our website so please have a look. Um so the conclusion from this is open source technologies enable achieving digital sovereignty but they don't really do it for you. You have to do something about it. You have to have the capacity to implement those solutions and to operate them. And

the capacity here means three layers. Policy capability and implementation. Um and and what this all means is we're talking about the capacity to exercise the freedoms that the software license licenses give you. And this I hope that there are some policy makers in the room. This requires consistent action to maintain a state of digital sovereignty. This is what people refer to as resilience. The ability to respond

to threats, to respond to changes, to make sure that you kind of take a hit and you rebound and you go back to where you want to be. At a policy level, this requires a principled approach that enforces measurable sovereignty criteria for all digital public infrastructure across the EU. I think very much as a European citizen in this I think what member states do supports but really

um the action needs to be at the EU level. In terms of capability, it means building the expertise required to attain digital sovereignty and we see a lot of sovereignty washing sovereign clouds hosted on European soil by foreign companies or a checkbox. Yeah, it's open source but you can't really contribute to it or modify it. um this is not what we're talking about right capability means exercising

all these freedoms and this will require and this is kind of a takeaway at the beginning of the talk a reversal of the degradation of public sector efficacy that we see pretty much across Europe because we can't ask people to smartly produ procure digital infrastructure if they're not able to understand what they're buying or it's a black box and at the implementation level we talk a lot

about leveling the playing field improving the business environment. Yes, this is important. If you uh saw the outcomes from the French German digital summit uh in November, one of the key themes there was competitiveness, being able for European country companies to actually compete at eye level. Um and we're not really there. So the call to action here very clearly is we need to build digital sovereignty into

the EU market at these three levels with concrete um uh policy goals. So kind of the agenda for this talk 10 minutes in is what is the gap between open source adoption and active participation. What are the strategies that are required to navigate these two environments that might explain collaboration and competition and how do we measure digital sovereignty um to be able to say did we actually

improve. So we're going to talk a little bit about a framework for this. Let's begin with a very blunt statement. There is no digital sovereignty without free and open source software. Um the four freedoms that are embedded in every open source license directly enable the three sovereignty dimensions that I've laid out for earlier. Um choice we have the freedom to use and the freedom to redistribute. This

mitigates lock in and reduces the switching cost. Um switching costs are always there. They also include the time you spend to learn how to use a technology. This happens with open source software as well. uh but at least you have the choice to learn something while you're using another thing and decide is this better for my purposes can I switch um supporting adaptability is for example the

freedom to study often over an oversight in the discussion is if you want to learn technology you need to be able to look into it the freedom to modify is part of that because contributing to code is the best way to understand how it works and this kind of enables you to decide your own destiny and to act um and when it comes to influence of course

the freedom to the environment to redistribute the software and to contribute back to the stack allows you to become a valuable contributor in a meritocracy and to control the trajectory of the software that you're using. Um, and it's important to highlight commercial software is not bad. Proprietary software isn't evil, but it gatekeeps those freedoms that I explained and you have to negotiate to get them and often

you won't because you're not able to pay enough. Um, and that's why there is no digital sovereignty without FS. Um, and here's the big however. This all sounded amazing. This sounded like every open source contributor would present about it. Um, but I don't think these rights are enough to achieve digital The freedom to fork does not mean that you have the the ability to maintain a fork.

Um, it requires staff that is able to understand what software you now control and own. um the staff that is able to to fix a problem if that you find in that software. And keep in mind a fork is already at the beginning a rotting snapshot unless you start maintaining it actively. Um that's why having your own fork is always a bad idea if there's a bigger

community out there. You cut off from patches, you cut off from new feature developments and you insulate yourself from the community. The right to modify something doesn't mean you have the capacity to contribute. This requires institutional commitment. And we often still hear talk like, oh, this company dedicated a maintainer to to an open source project. This doesn't mean that it's integrated in your engineering processes. This is

where it needs to be. When you change a dependency, you should do this upstream. This should be part of your day-to-day engineering work. It is for companies that embrace this. And the option to switch does not mean you have the expertise to switch. Um and and uh this is goes down boils down to almost like a fight between procurement and engineering. Uh do I buy a black

box based on a specification or do I buy something that I understand how it works? And this requires skills to evaluate the alternatives to to migrate safely and most importantly to actually operate the replacements. Um and the reality that we have today is that we technically want to achieve digital sovereignty in a world garden. We have the freedoms that we spoke about, but exercising them is painful

and costly. And as a result, the organizations and the governments and the public agencies that we that we look at, they willfully decide to stay in that garden. Um, the gates are open. They could do something else, but it would require action, effort, and investment. And that basically means that the potential security that fain opensource software gives you does not automatically translate to actual sovereignty that you

can achieve by embracing this. Um attaining actual sovereignty with regards to choice, adaptility, adaptability and influence requires appropriate strategy for how the software is developed that you're using. And the um this strategy is fundamentally different when you talk about a collaborative environment and a competitive environment. And this is not new at all. This is something that um the industry has adopted since at least 2005 where they

separated how do we deal with intellectual property rights etc. uh patents etc. I I'd worked in this area um in an area where we want to collaborate versus an area where we want to compete and policy makers are now slowly waking up to it. uh 21 years later and the CRA is um one of the first indications with its distinction of open source software stewards and manufacturers.

Um so basically there has been this mantra differentiate or collaborate in industry for I would say since 2005 um and this essentially means that for non-ifferiating foundational technologies you want to collaborate with others you want to share the investment you want to share the expertise and collaboration works best the bigger it is. So globally so basically sovereignty here in this space means participation not ownership. Uh open

source licenses give everybody the right to use the software for any purpose. The fact that you own that copyright means little for the adoption of the software. So um collaboration wins in this collaborative space because uh the complexity of the solutions that we're developing exceeds the capacity of any single actor or developer. uh the network effects that we see mean that the market will converge to one

currently dominant solution. Um and and the security that we want to maintain globally requires broad review. So and this is the collaborative environment in the compet contrast to that we have the competitive environment. Now there was some talk in the past of like everything in the future will be open source. I don't believe that there there is a benefit to competition. Um there is value in differentiation.

Differentiation means convincing your consumers that they buy your product and not that of your competitors. And that's not what open source does for you. This is what you do in your product design. Um so there are applications and services where the user needs diverge. Um there are needs for integration across systems according to the specifications of the customer. Um there are vertical solutions that integrate a significant

open source stack to more value added customerf facing solution. And here competition clearly wins. The differentiation drives innovation and investment. Um competition remains not everybody likes to hear this but it remains the best allocator of price for value for money. Um you never want to be bound to a single vendor. Um and local vendors much better understand your requirements. So in the competitive environment, sovereignty means leverage

in customer relationships, in contracts, in regulation and an and a relationship to vendors that see you at eye level, not as a colony. Um yeah, and so basically the rules for these two zones, competitive and collaborative, are different. They're really different. Um ownership works differently. It means different things. The agency of an actor in the space depends on how the space operates. In a collaborative zone, open

governance wins. Um there's an expectation to reciprocity in your behavior. You give because you take. Um open source licensing is normal and you gain influence through participation. We call it a meritocracy. In the competitive zone, this is essentially supplier management. You are buying a solution from a from a supplier. And that means you need to be able to negotiate at eye level. you mean need to be

able to um manage these relationships to have leverage over what you're getting and the price you're paying and you need to have influence as a customer. And I think you can clearly see how if you try to apply a um like a governance norm or behavioral norm from the competitive space to the collaborative space, you'll fall flat on your face. This is what we're trying um sometimes

when um we're talking about build your own. I'll get to that. Um and this is why nurturing regional competition is a sovereignty strategy. Uh there was a press panel recently and I was quoted with this statement saying every procurement decision is a vote for the future. I really believe that if we spend 265 billion per year to big tech providers that are not located in Europe, we

are investing into their product development. And um please keep in mind here I'm an economist by training. Every euro we spend has a multiplier effect, right? you you spend a euro and the company invests at you and they will get two euros back in value not us because that money is not invested in Europe and the long-term effects of this they absolutely compound um there is an

atrophy an atrophy of capacity of of understanding of of knowledge transfer um we will have a knowledge drain because innovative and enthusiastic people will go where the companies are that built the products and your innovation will basically be displed replaced by the actors that you fund with your own procurement efforts. So um and it's important to keep in mind here that any commercially supported solution comes from

the competitive zone. So procurement always basically picks winners. This is the case. Procurement spends a lot of money especially in the public sector and um the the choices that we make there they shape which innovative ecosystem which competitive ecosystem thrives globally and we don't have any leverage if there are no regional providers that we can work with at on level um the strategic framing that um I

formulate for that is called interdependent autonomy. This is more for the collaborative space. So interdependent autonomy achieves sovereignty by collaborating openly at the best on the best technical solutions leveraging global contributions and capability while maintaining agency over the technical directory trajectory and supplier relationships through active participation. This is what you should do if you want to navigate a collaborative environment. Participation earns influence. Uh adoption without doesn't.

um make sure that you leverage those 75% of contributions that do not come from your own region. Um and um and understand that maintaining and securing securing digital infrastructure requires global collaboration. We sometimes make mistakes here. We think that if you roll our own, we can be better. Um this is a paradox and I think it should become clear now based on the the the difference uh

different uh ecosystems I have described interdependent autonomy what I've just described wins over isolation why because it improves choice um if you roll your own you reduce the choice that you have to the winner that you have picked um your contributions are reduced to one quarter that's what one region in the world contributes in terms of adaptability you don't get have access to best-in-class solutions anymore And

most importantly, I believe you're reducing the competitive pressure on your local suppliers. You never want to do that because they will get lazy and fat. Um, and in terms of influence, the global trajectory of technology will most definitely diverge from what you have picked as a winner and you will always have to catch up with that. So basically, in the collaborative environment, um, open collaboration always wins

and you want to get access to those 75% contributions that don't come from Europe. Um so basically I've elaborated a lot what we need to do. We know that opensource is necessary but not sufficient. We know that we have these two different zones collaborative and competitive and that interdependent autonomy is the framing for collaboration. But we I would like to give you a bit more um concrete

guidance on on how to go at this problem. How do we operationalize this? Um is there a diagnostic tool that tells us how digitally sovereign we currently are? Um, is there a tool that can help us allocate limited budgets to the decisions on where to invest and how can we trace the impact? Here you go. We take we've taken the uh definition by Zenis and we've broken

it down to three layers on each choice giving you a 3x3 matrix and um it basically says for choice adaptability and influence you should go from being dependent to u being sovereign and you can assess that for every single dependency that you have etc. So how do we apply this? When it comes to choice, keep in mind that contribution is the best knowledge transfer mechanism. So if

you if you enable your teams, your suppliers, etc. to work upstream with open source communities, um they will learn how the technology works and they will serve you better. When you're dependent, you depend on the vendor control and the vendor road map. You depend on their pricing. We've all heard the news that our vendors are just magically doubling their prices overnight. This is because we're a price

taker. We have zero influence on this and this is because we're dependent. If you're transitional here, then you may use an technology, but you're still the relying on a single vendor that dominates your market. You cannot switch either. You may look into the technology and sovereign really means having multiple vendors, having open governance on the projects and having real competition. When it comes to adaptability, again, upstream

contribution builds the expertise that you need to to um to adapt the software solutions. Um the dependent state is basically uh the the PR and pray mechanism, right? You submit a pull request and you pray that some somebody will hear you but you have zero influence and your your architecture will then adapt to the tool that you are buying. You have no other choice. Transitional means you

can customize but the core is still something you can't influence and sovereign means um you understand deeply. You're able to contribute upstream and you shape the road map. And on influence I'm speeding up here already. Thank you. on influence. Um you basically need to learn how to exercise governance through contributions and leverage. When you are dependent, you have no voice in direction. You learn about decisions in

the release notes. Um it's too late. Um in a trans transitional state, you can patch you can supply patches, but you don't really have influence over will they be adopted and and when. And as a sovereign influencer, um you are a co-maintainer. you are your colleagues are co-board members or working group chairs or if it's a commercial relationship you're a key customer that your supplier will actually

listen to because your budget is big um and we can use this for a diagnostic exercise um you can basically say I will create an inventory of my critical components this is a very useful exercise for any company I've been preaching that for 10 years um know your components and then you can say what is my status quo um define Find this the assessment standards for your

organization and place your component in this 3x3 matrix and make sure that you apply the assessment standards consistently because then you can compare the results between these different components and initiatives. And then the dynamic test is you make the three do the same but you estimate how would my positioning change if I invest into changing my posture with regard to that component. Um can I go from

transitional to sovereign for this? And um if you do that then you can say you can rank the initiatives or components by their sovereignty impact and you can basically allocate your budget from the top down until you run out of money and this will make sure that you get the most bang for the buck um for your digital sovereignty investments. So there's there are two strategy recommendations

I would make here. One is active engagement. um make upstream contribution a regular part of your engineering practice. And this is the same for a public sector actor and for a private company. Um and it doesn't matter if your company is not a digital native company. You can do that. Um um and and ideally you reward people for um the contributions that they do. Don't don't make

it a side project. Allocate time to that. Um so yeah keep in mind upstream contributions are the best knowledge transfer mechanism available. Um seek governance roles in critical projects. Make sure that these projects have a viable community behind them so that they don't fade away because nobody wants to contribute to them. Second recommendation is capacity building. I think this is really important in a European context. The

the knowledge transfer that I've been talking about needs to be institutionalized. It needs to be something that is long-term enforced. It's the best way to understand the systems um that we depend on. Create a career path that rewards open source work. Measure participation. See how many patches you submit and shift from blackbox buying to in-house architecture ownership. This is for the public sector procures. Um sovereignty requires

technical staff that understands what they're procuring. And this leads me to my conclusion. Does free software buy you digital sovereignty? Yes, some. So first step, yeah, it's necessary but not sufficient. There will be no digital software, but licenses alone do not give you that. They only give you a potential sovereignty and you need to actively participate to achieve it. The inter inter independent autonomy framing is incredibly

important for collaboration um because it allows you to gain influence in a collaborative zone and it promotes competitiveness and competition of the regional suppliers that you foster by enabling them to work upstream. And then the third takeaway is digital sovereignty is measurable. It's not something that is a mystery. Um, look at the definition, look at the criteria, and then promote choice, adaptability, and influence across your ecosystems.

Own the architecture and gain influence as an ecosystem steward. One minute over. Sorry. >> Thank you, Miracle. All right. Any questions for Miracle? >> Hi. So uh you made a very convincing case that uh free software is um a strong way to reach these criteria for digital sovereignty. uh but you also mentioned that uh there are pseudo solutions let's say where foreign tech companies promise that they

have a European sovereign whatever and I think we have seen in the past um that uh these foreign tech companies will go to great length to prevent losing their business to open source um so while the road map you uh lay out is uh very positive uh I wonder if you could just say a little bit more about kind of a kind of taking uh how we

could avoid taking the wrong turn there and um avoiding European governments taking what may be the uh path of least resistance and simply checking the box in uh AWS whatever that says European sovereign. >> Mhm. >> Yeah. Um I I kind kind of tried to make that case with the presentation. Um we can't blame tech companies for innovating. Sometimes we do this. They're developing all the new

things and they're investing massively. Like look at the AI race currently ongoing. The investments there are mind-blowing. Um so we can't say oh please invest a little more that so that we're able to catch up. I really think we need to change our own posture which is more expertise. I think we've hollowed out our public services too much. They're not able to own digital infrastructure anymore. They're

depending on suppliers and these suppliers are all big tech companies. So um my case is we need to build expertise and capacity within our own organizations to be more at eye level with the suppliers of the of the solutions. And when I say own your architecture, I really mean don't just buy black boxes. Own the architecture and buy components to this architecture retaining the capacity to switch

components if that one's not the one you want anymore. buying global solutions. You have all seen these like procurement contracts for five and a half billions for a piece of software. Well, my reaction as an open source contributor is I can rewrite half the world of of software with five a half billion. So, this is crazy to me, right? So, we need to change this posture and

I really think it's our own homework. It's not telling the others what not to do. It is telling us where we need to invest and to learn. Hi, I think you made a great uh point about the digital sovereignty being about ownership and everything, but this sounds very much convincing to anyone who's working in a big organization, big company, anything. But especially in Germany, I'd say we

very much also dependent on like small and really small enterprises who do not have even one developer working for them and they're very much relying on cloud or startups who are trying to upscale quickly relying on AWS and stuff. How do what what perspectives do you have for those because I think that's really big market here especially in Germany um that's very very ab absolutely not sovereign

and very dependent and I don't think they can go go that path at least alone >> that's a very difficult question because I do believe that much of this dependency is learned and habitual um like why do we go and host everything on the big cloud providers there are European cloud providers pretty successful ones that have their residents in Europe and they offer you the same open

source technologies. Why do you not go there? Is it slightly more inconvenient? Is it not what you learned in school? I think the alternatives are there. Maybe it's not completely trivial, but to say, well, I have no choice and therefore I have no choice. It's kind of a we're we're going in circles on this. And um when we talk about spending 265 billion on on on IT

services and products, unfortunately, we're not talking about small mediumsiz companies. Um this is not a market served by a oneperson company. Um this is more governance issue of our own competitive environment. This is why I had this in the in the presentation. I really think we need to improve the um the starting position basically of our European companies as they build local services. Um but I think

the choices are there. It's so much easier to adapt to adopt open source technologies today compared to a couple of years ago that I think the homework is really worth the companies and with policy. So >> okay, thank you Mirao.

From event

FOSS Backstage

16 Mar 2026 – 17 Mar 2026

All event videos
Back to Watch