About this talk
This talk explores the concept of public benefit stewardship in the context of digital commons, focusing on open source software within the European Union. The speaker discusses relevant legal frameworks, particularly the Cyber Resilience Act, which distinguishes between manufacturers and open source software stewards. He poses critical questions regarding how organizations can be recognized as public benefit entities and the implications of competition law. The speaker argues for the establishment of conditions under which open source software projects can be classified as public benefit stewards, paving the way for better support and funding. He emphasizes the importance of reliable software supply chains and the potential for academic institutions to certify open source projects as trustworthy.
Full transcript
[music] >> All right. So, we are going to start the last session of the day. Uh we have Gregor Bransky with us who will be speaking about the digital common stewardship initiative. So, Gregor, please over to you. >> Thank you. uh welcome to my talk, which is a request for comments on public benefit stewardship. I hope that everybody can hear me and I'm having this mic close
enough to my mouth. Great. So, um this is probably going to be one of the more interesting, but also slightly boring talks. Because uh I'll try to talk to you about um the interesting world of member states tax law, uh competition regulation in the European digital single market, and what all that has to do with open source software supply chains. Fun, right? Also, I am not a
lawyer. As a general disclaimer, I'm a mathematical physicist by training. I have no idea how those people think. I'm trying to make layman's judgments. Let's start. So, uh the open question is, if you have digital commons, and you take the concept of stewardship, which is people taking care of things to make them grow, the question is, how can you actually do that, especially in the European Union
in the context of the Cyber Resilience Act? So, we're going to look at the following questions. what could public benefit stewardship of digital commons look like? What are the open questions in getting there? And why might the answers lie in the Cyber Resilience Act and in the digital commons consortium? let's start with what the is public stewardship of digital commons? Um >> [clears throat] >> digital commons
like open source software, open data, open content collection, and open educational resources are I assume the digital commons, which are classically known to everyone around. Then, because it's new and hypie, we have open AI systems. And some of us who might be more, I would say, fundamental on the cause could also agree that open services should be considered digital commons. So, what would a public benefit stewardship
of such a digital commons an open source an organization could commit themselves to providing reliable long-term maintenance of open source software. Um an organization could commit itself to verifying data like open data. Other organizations could uh commit themselves to verify content, especially in the open content collections and the open educational resources. And then you could have trustable AI models, for example, hosted by academia, so those running
them could actually be aware of what's going on inside them. And when it comes to open services, we might like to have open services without tracking or or public um algorithms for content delivery, so maybe we don't kill our democracies by social media disinformation campaigns and also don't make people hurt their mental health when using them. So, all of this would be really nice to have, right?
The question is, why don't we and what are the open questions on the way? So, first of all, there is a certain legal question, which is, if you have a digital commons and you have a unified European digital how do you tell whether or not an organization is actually a company that's in competition with others companies or if it's just people doing something for the public good.
You could see the difference like what's the difference between the equivalent of a restaurant and a soup kitchen. So, that's an open question. And the second open question that you have is that public benefit is a term from tax law. And we do have tax regulation every member state. It's not a European And if you look at set uh tax regulations, there's an interesting challenge on how
to get tax regulations which are handled differently in every member state um in alignment with the digital single market because it might become a competitive advantage if one member state decides to just consider everything public benefit stewardship and others actually have built an industry on top of it. So, the question is how do you operationalize that and how do you get that working? If we look at
set open questions, let's start with the first one. What could How could you actually look at the digital commons? What could that have to do with the digital single market? So, let's start. Um the Cyber Resilience Act might hold the answers. Lo and behold, the piece of legal legislation we all come to love and hate. Um the Cyber Resilience Act defines two economic operators which are A
manufacturers and B open-source software stewards. You have heard about those for quite a while now, I believe. So, manufacturers are defined as natural or legal persons who develop or manufacture products with digital elements and market them for payment, monetization, or free of charge. Within the Cyber Resilience Act, as you could see in the last talk, there's a lot of regulation coming down manufacturers' ways. They're preparing for
that. I believe they believe they're ready. They might not be, but things will turn out. And then there is a new entity defined, which is the open source software steward, which is a legal person other than a manufacturer. I have been told from a legal perspective, that's an interesting uh sound bite here because it's actually a legal definition that's not constructive, but based on a complement. That
is apparently not common in legal definitions. Uh they systematically provide support for free and open source software, and they market them for Well, that should be payment uh that should be free of charge, and payment and monetization should have been crossed out. Apparently, something went wrong with the layout. I apologize for that. This will be fixed in the uh in the slides when they're loaded up. Uh
thanks to the European Commission, we actually also have a way to different uh to answer the question whether or not an organization is an open source software steward following a flowchart. At this point, thanks to the team at the European Commission providing us with flowcharts that actually nerds can read. Within that, there is this one question, are you a not-for-profit organization? And if you are a not-for-profit
organization, they allow you to uh get some money by accepting either contributions, like people writing code for you, membership fees, or donations. The price you pay to be a not-for-profit is that you pay your staff reasonable living expenses by European standards. Whatever that might be is an open question we're looking for an answer forward to. So, if you look at that, then you will come about a
specialty of European law, which is quite interesting, that there's a difference between not-for-profit organizations on the one hand side and public benefit organizations on the other side. Uh there has been a study that has been published by 2023 by the uh LIBE Committee the European Parliament about public benefit status and CMD systems for associations and non-profit organizations in the EU the EU. And herein we find a
wonderful statement which is that the public benefit status exists in all European national jurisdictions. And public benefit organizations must be distinct from other categories of organizations such as non-profit organizations and social economy organizations. Um they're a very special animal. But they actually serve great gains to society. For example, most of um homes that take care for of the elderly child care services or public schools are public
benefit entities as well as certain research institutions um associations taking care of the preservation of culture um various other things you can imagine. The Red Cross would come to mind. Disaster relief actions, all those things. really? You want to talk about taxes? I mean, why? What does this have to do with open source software supply chains? I mean, people pay taxes. That's what companies do as well.
Well so um some of us might remember that there was a time where people wanted to start an AI company for the good of humankind. And it's going to be open source and it's going to be available for everyone. And that went for a while and then someone said words like the decision to transition Open AI from a non-profit to a for-profit dot dot dot. So um
if you actually want to trust your open source project to stay an open source project or a digital commons project and not just wait until you're depending on it and then go commercial trust might be an issue where you could use some help. >> what's the big difference between not-for-profits and public benefit entities? Not-for-profits are accountable to stakeholders and members. They allow for collabora- uh collaboration between
organizations to the limit of antitrust law. And they can become neither a standards nor a verification body, which is rather important to other aspects of this discussion. And then there are public benefit organizations, which are accountable to stakeholders and members and are under oversight by tax offices because if they derivate from being a public benefit entity, the tax office is going to come for Um what they
are going to able to do is limited to public benefit and general interest activities. Uh donations they accept are bound to the causes they're proclaiming to serve. And their best practice is when it comes to research and development, standards, and verification to actually have public benefit entities be a place of innovation and collaboration across various sectors of this of society. Um so, to sum up the most
relevant part rather technical uh s- um summary is public benefit organizations are accountable to parties who do not take part in their governance. And this is a really really relevant between a nonprofit or a public benefit organization. If a nonprofit wants to go commercial, just its members do have to agree. If a public benefit organization wants to go commercial, they have some explaining to do. our proposition
that we would ask for forward for request for comments is that we have to define some kind of condition, which then would make an open source software steward a public benefit steward. Then probably a public benefit open source software steward, but we're just borrowing the legal concept here and we're trying to apply it to to other digital commons. So then the second open question, you remember, is
how do you operationalize this? so the big question we have to ask is how does an open source software steward basically graduate to become a public benefit steward? And there you have the interaction of various levels of national tax law that have to interact with the European digital single market. That's going to be fun, right? Also, because all those digital goods are usually known to just be
used by your neighbors and not be spread over all of the European Union by this things called the internet. So, maybe there is a place there there there's an organization around which is >> [cough] >> the digital commons EDIC launches to advance European uh technical sovereignty. Where it basically states that there is now an organization since the 11th of December last year that creates a common European
structure dedicated to digital commons. It brings together public administrations, open source communities, and companies to pool resources, support strategic open source components, and accelerate the transition from isolated pilots to shared scalable digital infrastructure. >> [sighs] >> Well, isn't that jolly? So, there is an organization out here who actually claims to be doing public benefit work with digital So far, it's limited to member states. I believe if
they're doing their job well, they should actually serve uh the societies of this continent. So, the idea would be that we come up with some conditions for digital commons and what public benefit stewardship of said digital comments means, then you can apply to the DCEGIC to actually see that you fit this condition and then if you do, your tax office can get informed that you actually do
fulfill said condition and don't wreck the digital single market in the European Union and then you become a public benefit steward. Isn't it marvelous? Okay. That being said, um because this is an RFC session, I'm looking forward to a lot more debate because the rest is rather brief. If we would get that done and we could get European legislators to move forward to do this, we might
find that false communities actually get the legal recognition of the work that they're doing at this moment everybody who's doing something to contribute to society is recognized as doing something as a public benefit. This is not true for open source projects. Uh open source projects no longer would have to develop hacks to work around the tax code to get actually recognized as public benefit organizations. With quite
a few European public benefit organizations, we can see that they have made themselves into community support organizations so that the communities that they support can take care of digital stewards, but actually the organization itself is not on an institutional level responsible for the digital commons. There are few exemptions left and right, but that fits to most of them. And donations could actually become an income stream larger
corporations actually have trouble, especially the publicly traded ones, to just give money away to an open source project, but what they can do is they can donate to a public benefit organization that is bound to follow a cause. Which is a different thing when it comes to accounting. Tiny things, I know. Fun. Uh industry. Industry could profit from having more reliable software supply chains by actually having
a way to solve money down this open source software project votes. Um relevant services could be provided to SMEs that might need them. a public example would be that I admire what Google did with Let's Encrypt. But I believe it would be great if you could have a service like Let's Encrypt by a European entity and just provide a service that everybody needs. Um industry would be
able to actually invest in software supply chains because they would encounter legal entities that they can actually interact with. And you could get to what you can call permissionless innovation, which is an interesting concept um when it comes to the idea of technology transfer from research and development or open collaboration a way to get innovation running in a way that actually fits the pace of digital developments.
Because the classical way that's usually done in the European ecosystem is writing research grants to apply for research projects together with the university leads to the fact that your project can start about a year after you wrote your grant. And I don't know about you, but when you look back a year when it comes to digital development I'm not entirely sure if you would have been able
to make an educated guess what would be the project that you would like to start working on today. For academia this would allow to follow what is called the third mission of academia next to research and teaching, transfer is mostly listed as the third mission of transfer of universities and especially university entities could then become stewards of public benefit of open source code wherein they enshrine their
domain knowledge that they have when it comes to software to run models or simulations that they usually develop for their research activities. Also, as we know with most engineering disciplines, academia is known to be an entity that actually certifies open certifies the um capabilities of technical systems, but we do not have yet any kind of setup to do this for open source code. Uh you can basically
take whatever technical product you produce, at least in Germany, and find a technical university who has an institute who really specialized into this stuff. Whatever it is, may it be protection systems against floods or with the question if your screw is actually up to this technical specifications. And with this, I mean like literal screws. Uh certification is mainly done through academia. We don't have that for software
engineering. We should have, I Well, for society as a whole we would be able to create trusted entities that provide digital services that are needed like let's encrypt cryptpads to collaboratively work on documents do things like scheduling appointments and all the other things that we have come accustomed to as digital infrastructure in our daily lives but maybe actually maintained and taken care of by an organization that
does not feed its revenue stream by making the data of its user a commodity. We could get social media that neither risks democracy nor health by opening the algorithms how they show content. And we could create reliable sources to combat disinformation. A lesson Europe has learned by installing public broadcasting after World War II and before and might be a way to move forward. Oh, and for public
entities, all those who are doing work on government digitalization could actually start to work together in fast foundation-like organizations to maintain the code that they're using together. Um this is where the reason this is the reason why I'm standing here before you because the Innovation Council Public Health is a non-for-profit public benefit entity in Germany who builds open source software for public health centers. And we couldn't
find a legal framework that would allow multiple public health centers across states of Germany to work on an open source project because there wasn't a legal framework that would allow for it. Jolly fun. Yeah, that's about it. Uh also, as with every good talk, there's a call to action. Um uh Git repository has been set up on the weekend and there's also a Mastodon account that hasn't
made a tweet yet. But if you want to keep up to be updated about this there are two QR codes to scan. Feel free, feel happy. And we'll try to keep you posted. That's about it and then we have quite a bit of time for questions and discussions and stuff that I left out that were ununderstandable and could be clarified for the people who are watching from
the internet. Hi there, by the way. >> Any question from the audience? I have. >> Juan has a question. >> Yeah. Um you pointed out about uh full certification and that's a pretty interesting topic. Uh especially we have with the CRA the attestations which are supposed to be something that is harmonized somehow. >> Mhm. >> Uh do you see attestations the way to go uh certification for
FOSS or do you expect something different? >> Um So I I believe at this point attestations and certifications are a bit different. I believe that if we make open source uh become public benefit entities, that would allow them to generate the revenue streams that they need to put to have the resources to spend that they to to harden their software. So this is rather speculative. But from
what I have seen from Opus 4.6 and rumors I've heard about Mutuo, I believe that artificial intelligence quality checks will actually provide the level of quality assurance that we're used to in other engineering disciplines when it comes to software development. And running those AI checks will cost And those will be best spent by the open source entities who actually build the code. And then they can basically
put a label on it like we ran IT security hardening tests on this code with the following model and we spent that amount of tokens. So then those who can use it after them can discern whether or not this is a sufficiently reliable security attestation for them. Um and I think that their public benefit status of uh open source software stewards might be very helpful. Thank you
for that. Uh what I meant when it came to that um in academia we do have research institutions who harbor in-depth knowledge to a degree where it would not sustainable in any economic way to amass If you talk to a chair that works on let's take flood prevention systems. They're actually research chairs who do research on how to do flooding Those chairs also have a test bed
where you can bring your technical component and have it tested to see if it actually fulfills what would considered to be state of the art or necessary by research to use it as a flood defense system. And I believe when it comes to um, open source projects chairs, uh, who, for example, do research in empowering people to make data-based decisions. Uh, this would be a way to
allow them to actually certify software so that the rest of society can rely on the fact that, for example, an AI model or a simulation software has been tested by a third-party entity that does not have a commercial incentive in screwing the certification they just gave to the So, that part was more about software doing what it's actually claiming to be doing and not hardening the code
in itself in a quality way. Did that help to tell those two apart? >> Yes. >> Great. >> Other questions? >> Thank you for the talk. Um, do you see any friction or challenge between being both a public steward and uh, a public good steward and perhaps a manufacturer. That you one entity might hold two distinctions or or two identities at once. >> I I I believe
that should be mutually exclusive. Because if you're a public benefit you are a in this idea subset of a not-for-profit. And I believe that there will be no way to re- reconcile the conflicts of interest that you have between a commercial entity and a public benefit institution. And I believe that at certain places we need those public benefit institutions to take care of the very infrastructure that
we want to build an open digital ecosystem upon. Just to get me right on that. I do not mind if people write good code and fund a startup and become stinking rich over That's not the point. this is not a cry for communism, >> So to speak. >> Uh the idea is that in certain instances we need as a modern society and organizations that provide institution- institutionalized
trust. And I believe that public benefit organizations are the way to go there. Because as we can see from the current open source ecosystem, even though basically every modern company runs on open source code, the open source ecosystem is tremendously underfunded. And if you're not forced to, any commercial entity will not go ahead and go like, "Oh, yeah, but I like this one open source project. I
going to donate the half a million dollars that they need to run half a million euros that they need to run." I believe we need like those entities. Did that answer your question and the reasoning why? >> Thank Thank >> Any further questions? >> No. >> All right. So, Gregor, thanks a lot.