Open Community Experience (OCX)

Open source strategies for Europe’s sovereign digital infrastructure

1:00:02 · 21 Apr 2026 – 23 Apr 2026 · YouTube

About this talk

This panel discussion focuses on the intersection of open source, digital transformation, and the need for sovereignty in technology. The speakers emphasize the importance of bridging the gap between innovation and policy, particularly in the context of geopolitical challenges. They discuss the benefits of open source in fostering agile and resilient systems, allowing for greater flexibility and security in software development. Key topics include the role of governance in ensuring sustainable open source projects, the importance of creating community-driven ecosystems, and the challenges of aligning industry efforts with emerging standards. The conversation also highlights the importance of collaboration between various stakeholders, including industry, academia, and regulatory bodies, to effectively leverage open source technologies for competitive advantage.

Full transcript

Uh so let's continue with the panel discussion. So we have all the speakers here on a panel. I would say that um we heard quite a lot of interesting information that again flow one from the other. So this was not like just um randomized in a way. Uh so we hear from Rol what is let's say the policy approach policy objective. Um Antonio gave a bit of

the I would say architectural um ecosystem level plus first who introduced together with ro the community and growing communities to basically be aware and use whatever it's available there is it open source or in general and then we started with the large scale pilots with a link to the telco edge uh as a sort of also I would say logical in a way continuation upgrade in thinking

in the approach And then we heard of course from the open source to let's say communities how this can be not only done but again built into the community work and then also from Lucan how it can be practically applied and I would I think we can structure a bit of a discussion around these themes uh starting again first with the ro um and then continue in

the order how we basically speak in a sense to keep uh a sort of the flow and then of course at the end we will open for the audience um to the questions if you have any of this. So maybe all of you can start. You have okay. >> Yeah. Uh I think we had a a good discussion this morning about trends and then I said our

main um purpose or main ambition is to link what we do on funding under research is how to link it to the policies and uh and uh research projects are always quite broad. um had different scopes and of course research topics and the in light of the geopolitical conflicts at the moment what you see the policy arena changes very very quickly. So questions eventually also from the

other panel panelists you know um what is your um ambition or what is your learnings you know how to bridge uh the innovation space to the the policy space >> thanks and then I would say also so we say let's say we have the policy objectives policy start which as ro says is also changing of course much quickly I would say than we were used to in

the past so we have to also I would say calculate in the work this as Well, then we have the uh projects which are research but also innovation meaning closer to the market. Um and maybe Antonio you can just continue maybe also from this ecosystem let's say uh community building because of course if we don't have this will be used. >> I'm going to concentrate on actually

the first question which was on vulnerabilities. Okay. And we have here another community which is OC uh open community for compliance. Okay. So if you look at uh what we have you have a number of regulations I'm going to just focus on the CRA on on example cyber resource act okay so we need to uh comply with it uh we need to understand how to do it

uh the community can help okay and in particular so sorry I'm going to mention about sanization uh it's surprising to see that there's no standard on cyber security resilience there's no standard so there is an opportunity okay secondly uh there's no standard on how to put them together Okay. Yeah, you have a few things that we just started uh standards on uh guidance for cyber security of

system of systems. Okay. And here my objective would be that we take all those examples that we mentioned like what Lucia mentioned about the RT and things like and we put them as use cases and we show that there are a few needs that are there and actually we can take example cyber resource act and what are the regulation you have but you can uh u you

you can uh operationalize that with requirements. Okay. And uh this is one of the objective we have I think for the next three or four years onization. I'm representing SC27 visava there. They have a group called SECCG cy uh sec um stakeholder group stakeholder cyber security certification group and I'm representing S7. I will make a presentation in May about that and ask to work together on approaches

high level architecture based where we can do it. Okay. And then we have a few standards. I'm not going to get details is too much but uh I think there is a pathway so that we create the link also with the work here. So OC is working on things tools to help but then we will have also standards to help. Okay. Yeah. >> Thank you. >> Maybe

I can come in here as said um we have the different we also closely work with our sanization units and the rolling plan for standards uh for years. No I think IoT is there edge computing is there. uh but as said you know what we see the innovation is developing much faster and the threats are much faster. >> So definitely um what was also mentioned this morning

um is that the open source communities um the developers they're facing the risks and they see the standards themselves. It's a community you know you see from different angles and they're much quicker in identifying risk the threats and also you know in order to to see whether the the standards are fit for purpose. So the link between um open source projects and standards I think that should

be brought in into the the project management from the very first beginning um to see what is at stake what is the landscape what is the relevance um it's a bit of work for the foundation you know the project lead you know to train the people make them aware um and then to include the the interfaces and the interability and the standard from the very first beginning

and then we could have really a win-win situation um where we can feed back the information from the development from the coding which is much faster now also because of AI and gen AI tools um to standization work otherwise you know sanization will be left behind and u will be always too late. I think you made a very good point. I can just tell you that from

experience of one other EU funded project which is about international collaboration of standards in several areas including for example cloud edge AI but also cyber security data and others what we can see there and it's it was like two years project almost close to the end how we started and when we started and what we see now because we were making updates of the priorities for each

of the areas it's enormous change so and it's very kind of um tricky even for the people who are on almost daily basis in it to keep a track on all of it and then updates on the rolling plan and other things annual union work program and so on. So it is a complex thing but I agree with you. I think this is really something that ideally

should be built from the beginning and then also see by having uh these links with international partners that we have with what we call like-minded countries that we also use them to dialogue with them which Antonio for example does already quite well on many levels so that they also pick that up because if just we do it it's great but at the end of the day you

want also to be competitive you want to help if it is possible that this becomes as widely used as possible But Nacho, let's continue with you from your perspective based on what you presented and what we now started as discussion points. >> Yes, thank you the mayor and of course I agree with everything said so far. I will be now in in this intervention and later in

next question talking more from the perspective of um how open source leverages research funds not only for the creation this spontaneous search of potential solutions but also fueling interests from those companies that you know adventure and decide to engage in such activities of research and how this should be funded later for sustainability and continuity and why sometimes this very point is what lies behind reluctance of adopting

certain open source tools for central industries and we have seen this in my trajectory in projects and also what with when you discuss when you are deploying your open your own open source tools you try to deploy in in the industry because sometimes um I think this has not been touched upon today but the fact about farther maintenance support and skill is needed for companies to really

embrace open source tools are sometimes barriers that we should consider when we think of the next way or the next rounds of funding for these projects. Um it's not the same to acquire um an open-source tool without the support. If it's not followed by a clear business model like anme embracing this open source making it its own or even if they created it they can make the

support and the maintenance long term or if the industry themselves need to be trained or need to hire skilled engineers that would master the usage of these open source tools. So this is um one of the barriers I wanted to bring into the table that we that we see that may still not be very clear how to solve um for the next rounds of funding and embrace

of the open source tools. Um yeah I think um that's my views on on this very topic and I will continue with other perspective later. >> Thank you very much. Let's continue with George. So I think you can >> Yeah. Uh so we have been talking a lot about uh how to basically uh bring digital transformation in Europe right and uh try to promote all the stakeholders

and all the businesses to go from traditional models to modern ones where they adopt technology mostly right. Uh one question that comes into the the game is basically this transformation will lead to cyber security risks and um do we have any ways to mitigate those things right uh how can we tackle those those aspects um I would say here open source is the key because uh if

we were to transform those businesses in Europe with proprietary software which is blackbox we don't know it we don't know what it contains we will definitely face those cyber security risks and we won't have the means to solve them or address them right so uh by promoting an open sovereign Europe European stack that will uh fuel this transformation based on open source in its core then we

have the means to know what we're tackling with how to address potential security issues and uh basically address all the the challenges that will come around. Uh the other aspect that comes along this is also that we have seen from the panels al also today that there are lots of developments uh in different areas in open source. Some do a lot about slicing telco eds some others

work on security AI data it is often the case that those do not know about each other. So there's another aspect here which I would also like to promote also in the face of Etsy um cross software development community uh efforts to integrate things together. We are doing something at Etsy uh these days and we are about to show it in the upcoming EUNCC. There is a

Etsy um SDG lab they call it. It's a cross software development community effort. all the edge groups come together and they do something integrated, something bigger that brings together things from different perspectives and I think this is also key for open source to grow because this amplifies the communities actually. >> Okay, >> thank you. I think this is important point again to to grow the community because

whatever you can have whatever you can have as a solution if you have no one actually know about this like you said or using it it's not good and this I would say cross sectoral I think in your slides you made a very good point on horizontality verticality for example of AI and cyber security um and this I think is also elements that we should not forget

and Antony also talked about this so again this didn't just let's say fall from the sky but this is first one of the concerns that people have. Second, it is something that is real because we heard a lot about uh cyber threats and attacks and so on. And then the third thing is again how to get the community to use to recognize this uh and basically to

grow the solutions for it. Right? Let's continue with um Joanni and uh seeing also some reflections from the let's say more telco cloud age perspective. >> Yeah, thank you. Well um most of what we have said applies similarly also to the telco um and edge convergence because the softization this uh adoption of open source the tension between uh larger corporate uh let's say organized activities and more

spontaneous or highly distributed um community- based efforts. This is not an exclusive situation of the of the telco. Um I think that a specific point of of the of the telco cloud convergence is this current asymmetry between the the relative strength of telecommunication providers and cloud providers in Europe. So you know when two companies merge it is a merger or an acquisition depending on the relative strength

of these two companies. So here the the the the effort the Euro3C project in particular has the challenge trying to get a balanced outcome starting from two very unbalanced industries and it's like a prisoner dilemma kind of thing. you know the Telos are stronger but it would be also in the interest of telco industry if the combined telco cloud raises the cloud providers in Europe and so

the overall offer improves and this is one challenge that we have because the don't let's not forget that Euro3C even if it looks a big project is not of the scale that you would need to do a full European infrastructure upgrade and this is not the topic of the project the project has to make a convincing pilot that shows that you can do federated and integrated connectivity

and computing to a level that could satisfy the Europe needs and then down the line will come as yet unknown at least to me larger funding probably public private initiatives to actually do the transition or complete the transition. So this at the moment is this um for for the telco cloud specific bit. I think this is the the the pivotal situation of the Euro3C project. Okay. Um

yeah then I have other consideration more on strategic aspect but then we can maybe talk later. >> Thank you very much. And now go back to the let's say more direct open source perspective first from Malik and then we will pass to Lucia. Well, I mean, regarding the conversation this morning and the the things we were showing and talking about during these days preparing the topic, one

of the things I I like to highlight is the importance of governance models that allow to build technology in a way that allows participants and contributors to those projects to build business models that are first of all sustainable for those companies, but also ensure that the projects they are building and the technologies they are building in in the open source are also sustainable by themselves because sometimes

it's okay we have some funding we develop something it's done we have a nice governance is there in a g repository but then how I can build something that I can continue working on this because there are new cost because there are new opportunities but also because I have used that on my business in a way that is giving some business advantage to keep evolving me so

I will keep working on this because it's is fundamental for >> thank you so So in a way to also connect to what Joani was mentioning a previous speaker is natural as well is so there is um I would say sort of the open question about the use reuse building upon this um I mean it's rightful question for the commission and also for let's say citizens who

are funding all of this ultimately like okay you have a research you do this you have it like you said in a nice repository and so what Right? >> And then of course if you have another project another things how this is used, how this is reused, how this can be built upon and how business models can be actually developed out of it. Uh and of course

taking into account what George mentioned risks. There are always some risks. >> Uh but like you also said in your presentation before the launch m I mean there are risks that may exist >> but they are unlikely to materialize or let's say their probability is reasonably low. And then you should more talk about benefits not forgetting about the risks but you are not focusing then on the

risk you focus on the benefits right maybe Lucan you can also as one who is I would say contributing to the to the let's say open source development but also open source use which is very important element you can maybe also reflect on that >> yeah exactly and I would like to to follow up on on these aspects because um I think one of the best choices

we made when we started Our journey was to partner with the foundation. uh and and I already mentioned during my presentation that the foundation brought us the trust framework both from the technical and governance point of view that was needed to to set the proper condition for the growth of of the community and and um actually if we want to improve uh technological resilience or sovereignty however

we call it in Europe uh uh my message today would be that that uh our ecosystem should take leadership roles both on the technical level and on the strategic level in the let's say the the the most pro promising uh opensource technologies that are are hosted at foundations um there is a and it's especially relevant in Europe because our framework in Europe u does not facilitate the

uh yes there is a bit of >> circle here. >> So the the our context in Europe does not facilitate consolidation actually. We have countries that are not always aligned in the strategy that have sometimes some national priorities. We competition laws that favor competition and not always um consolidation. And and um the point is how can we give how h how can we make sure that various

investments from various parts of the community can aggregate to to to build something that can be uh competitive and and sustainable. And on this point also an important aspect is um we also have to be be be careful when when considering sovereignty not reinventing too much the wheel because the money we put into reinventing the wheel is the money that we don't put into innovations. So the

risk is to be lagging behind because on the other parts of the world people will put the same money into new new and maybe the the the the third point that is important to me. So LF energy is um an initiative driven by the technology end users initially. It was initiated by grid operators and it's more or less driven by by grid operators. The purpose is not

to say that the model will be um internalizing all the capabilities at the technology and euros. We we we need also to leverage a vendor ecosystem. Uh and this is also what will be the most efficient solution for the innovation in the long run etc. And to achieve that um what we decided to do and actually it was inspired by our vendor ecosystem was to adapt our

procurement practices to be able to impose open source closes. I already mentioned it briefly but this allow us to be to say okay for for for this need I want you to be based on this kind of specific technology. So in our case host it at the Linux Foundation energy uh and you should contribute back what we are paying into contributed upstream so that it can consolidate

in the run long run etc. And this is not an easy um task because like usually either when you go to open source either it comes from uh technical savvy teams that know how open source works and they just say okay but I can do it myself and uh yeah or uh then the the project is handled at another level less technical level and then people don't

know what open source is about and they just say I just procure something it's black box. I don't care because I I I don't know how to do otherwise. And we need to create this path in the middle where we educate on not only technical people but also business people, executive level institutions on how to operate when when when they handle they manage a procurement contract, how

they handle opensource procurement. Actually, >> thank you very much. I think you raised quite uh quite a lot of uh issues in any case you were next just to say that I think it's very important this aspect when you say you know the balance between um you know like what is a sovereignty and what actually we are investing in um I think that one of the issues

is that if you ask three persons in the Europe what is a sovereignty will have five answers um and I would say that none of it is either good or bad most probably in all of them there is you know a grain of truth The thing is like like you said we need to find the things that we can really agree and then invest into that and

get the benefit for the broadest community and the single market. And this is what I think that ultimately is also something that we should never forget that you know all of these things should ultimately work within the single market. This is not like I do something it works in a two or three big countries and that's it. Right. >> So it should be a bit broader um

perspective there. But Ralph please. >> Yeah. Um I want to pick up and so why now open source? Um how many of you are or were in uh European projects >> in any of the projects in European research projects as a partner or from your side? Yes. So a couple >> so I think we had we had open source in many projects and you know the the

norm was you know open source we put on jitub full stop so now then we stop project stopped so why now there's a change why do we talk about open source yes on one hand we have the ge geopolitical conflicts so with the euro stack it was brought to the parliament it was brought to the politicians so we have that high political uh visibility on sovereignity you

know that we cannot rely eye on uh um components and um AIdriven components, software driven components from outside. So we need to have our own software stack but then you know also you heard from from Lucian on energy and others if we know STV why the companies are moving now um not because politician told them because um there's a change in the paradigm in the automotive the

um the manufacturer of a car in the past relied on the support of the vendors. it was a vendor-driven ecosystem. So they made the integration and the manufacturer put the branding and made the user interface. Fine. That's changing. So the manufacturer of a car is now you know the one who is responsible and does much more agile um system integration and we have seen that in energy

as well. The energy operator is not just delivering electrons. So the energy operator of today has to become a system operator to integrate systems which also include the demand side. So meaning you know the close to the the consumer which is a distribution grid or on the demand side the heat pumps or the charging stations or uh a depo of charging stations or a data center. So

here you know you see this complete different paradigm in the system on the roles which needs a different approach much more agile approach and much more integration of the ecosystem and there you know there's complexity on the one hand and the different roles um encourages people you know to move faster and to go into collaborations and I think there we have a good time or window of

opportunity now to to to sail on the wave and to have the right wind and we have seen that topic of the waves yesterday from the presentation of SAP. Um they did an a project which had a good resonance in the Olympic games over the navigation in the regata. um beheaded open source but then finally you know for the governance that relied on established governance schemes on

Eclipse or on Linux in order you know to have a proper management of the ecosystem but without the ecosystem and the the community contributors your open source project is stalled. Um yes um thank you and you know taking on what was said I like what you said about this definition of serenity right of different ways it's like when we knew what competitiveness was but until you know

drugy defined this in the report and create the framework of the things that should be done to to promote this uh it was not yet clear maybe we are waiting uh you know impatiently for the sovereign package ro to be to be out. uh and we are like you know eager and anxious to know exactly what this and how these sovereignty theaters or traits will be portrayed

there so that you know we will be able to promote them and here I believe that the role of opensource for that sovereignty is key >> uh for doing things right why I'm saying that because as also Rol said digitalization technology ology advances pretty quickly and policy should also adapt and I think open source and what it implies could help us companies but also researchers and developers

not to um fall into a temptation or being too fast on adopting certain technologies especially those coming from foreign uh maybe you have heard about open or some of the features of cloud or even context these new technologies that emerge they come with security concerns they come with hidden uh traits that we do not see. So we should put into the value what open source brings to

avoid this temptation and I will be very concise here instead of abstract. We recently have made a result of a research project IROS as an open-source tool that we want it to be embraced and adopt in the cloud IoT there by creating it and incubated under Eclipse and now an official product we have needed to go through very thorough IP check cascading comprovation that there are no

no leaks in the code that there are um respecting the cascading licenses among many other aspects that sometimes are you know neglected when you run too fast and don't go through these processes. Therefore, not stopping at a code in a repo but going through these processes allows you to be more sovereign or at least how we understand the sovereignity and this is the role that from what

where I'm talking from the research in academia should be uh bidding for and should be putting more effort the role of creating that code going through the process make it more visible and also take advantage of that to foster its permeate for it to permeate from all the you know ranges and tires of society I would say starting from students from our side uh early innovators entrepreneurs

up to the way of the industry this what I wanted to say in this regard >> I I like to to leverage what you just say and what R said about the fact that the world is changing we have disruptive technology disruptive markets SDV things like that so open source provide this agility so everything is about agility. Okay. And uh so now we have to help this

happen. Uh taking into account sovereignty which is actually managed by suitable governance. Governance is very important and also so as you remember in this uh basically our model is changing because of disruption and you have the business demand side and supply side capabilities standards and open source. Okay. And when it comes to uh governance is the whole thing. Okay. So we need the demand side to help

govern the thing and to make sure that we're linked. Okay. So currently there is an issue which is the governance of standards versus the governance of open source. So we need to solve it and this is uh nearly organizational initiative sometimes political but I hope uh things will get improved so that in the end of the day uh the standards get much more agile so it's all

about agility okay so open source agility standard agility business agility to create disruption okay and then sovereignty to make sure that we do it properly yeah >> I think this is important you know how to also manage it because it's okay to have agility to have disruption and so on but ultimately you need to manage it. It cannot be like >> you know that the outcome is

a cow. It's not the point. >> That's why you need the covenants. >> Exactly. to get it to the point you want to please. >> I I would like to exactly catch up catch on on what you said because it's all about eligibility but it also has to be about resilience which is one way to measure it >> and of course I mean I closed my presentation

with a not to complex systems and for me it's important that it's clear that in in the modern situation a plan is not a sequence of step that you agree and then you execute without checking. You have to do these plans that you check every time and you plan. You have to do multiple plans in parallel even contradictory plans to edge your bets. So there are all

these kind of techniques and this is for me uh one major uh strategic advantage of open source. there is this natural resilience because you know even the best proprietary software we have seen it happen then the European company gets bought rightly so because why couldn't it be bought so also the idea now this company is too important so the government has to prevent yeah fine but you

see that it's kind of a patch so if we believe in the free market at least at the company ownership level we have to imagine that some European successful company becomes multinational or gets acquired by another non-European entity. So the the decoupling of the company author uh from the from the source code that that opensource allows is a feature. And also one last thing that I want

to say here is that we also have to be resilient into our own def with respect to our own definition of open source because for example uh in last Fen there was in the policy dev room there was um tutorial done by the free software foundation and their representative said there are the four freedoms and so on but he also said that the most important things are

the values that we try to protect with these four freedoms And we are exactly in this situation because I suppose some of you are aware that the values of open source must still be good. But the trick of stolman to use the copyright law to bootstrap all these things is kind of you know suffering now because between generation of code execution of binary environments in cloud providers

without recognizing the open source contributor. So there are a lot of things that make open source management by by letter more difficult but they don't make opensource management by spirit more difficult because the values of open source are still there and the people who believe in them and work are still there. So we have to also from a when we look at ourselves as open source supporters,

contributors, managers, stewards, we also have to look at ourselves a little bit and be ready to change a bit because I think that all these the these new requirements that are piled up on uh the digital society and open source in particular require some a little bit of rethinking and we have to admit that we don't know the next best way forward. So we have probably to

go on two or three at the same time. Thank you, John. I think it's interesting and of course agility is agility in movement, agility in results, but in order to have it, you have to start with your own agility because if you don't have it, then you will never catch it up. Um, >> yeah, if I may >> first and then please go ahead. Now regarding the

the governance it's important and I like your point about the man how to govern the the the whole from my let's say my open source hat here and my position here is basically one thing is important to understand is open source is not a business model mean there are business model that could be using the the definition that because there's already a good definition of open source

very well discussed and it's open to discuss whatever we want by the open source initiative but there's to take advantage okay how open source is being defined we can use that to build different kind of businesses what I think is the threat that we are facing nowadays and this talks on for the 19 reveal was not the open source definition by itself it's the software business definition

by itself I think software how it's been sold and things like that is changing and it's changing so agile that we need to to adapt to that. But how the importance of having good governance on the on the open source projects and have a community and one of the first talks I remember was this idea. Okay, I get this specification, I run an AI system and I

have the same the same project with the same features that I need in a different license with an different thing and I can do it by myself. It's that easy. Okay, good. Go for it, maintain it and get a community for it. Otherwise in the long term how sustainable is it is this? I mean when I thinking about the governance model we have built in eclipse and

you think okay we are still people when we are talking about eclipse people think oh you are doing the ID I don't know how many of you when you are talking or oh we are going to an eclipse 7 oh they're going to they're going to talk about the ID yes of course you can say okay no we are doing many more things but you think on

the side okay the ID is still there decades later it's still there it's been developed it's been used and it's a we'll say sustainable small business with many companies on that and of course the clip foundation is still there so there are some kind of business that you can also develop on that and I think this is the something that something that we need to train and

it's happening already with the companies in the research project that one of the activities okay let's train then okay but this is open source what how we can do business if we are doing open source no problem we are here to help and this is one of the key points for having a foundation that is not only about hosting the project and having some P tools and

stuff like that but also train the community the developers and for me one of the challenge things and again this is a personal experience that after more than 25 years on open source and going in a corporation seeing new graduates coming from computer science and oh I'm using this because it's open but do you know what open source means? Well it's is in GitHub and it says

it's open. Oh, come on. In 25 years, we we are still need to explain to people what does the four principles mean? The 11 topics that open source initiative has defined. What's all all of that? So, there's still work to do. I'm more than happy to help on >> These are these are also important points, but again, we have this underlying thing. It's like community and then

community of I would say both developers and users, right? and Luc, we will come back a bit later to you as well because you're you're you are kind of covering a bit of both >> both in a way but uh first George you wanted to intervene. >> Yeah. Uh very good uh hint by Manrique about sustainability. Uh just my two cents on that we typically uh talk

a lot about open source. Uh you know it's not just banging on the keyboard and writing code, right? Yeah, >> I think the the good examples are already given to us uh about sustainable open source projects like for example the Linux kernel. It has been there for decades, right? What is the key? It's not just writing the code. It's building the right abstractions and building the abstractions

in a way that no matter what is the underlying technology today we may have I don't know Kubernetes tomorrow something else will pop up. This needs these things needs to be replaceable. If you have the right abstraction, you can uh let's say uh patch any kind of technology no matter in which decade you are in basically and yet provide the same uh added value right so I

think and a key thing about open source communities is really designing and building the right abstractions if they want to be long living >> and I think this is one of the best most probably one of the best uh contributions to sovereignty because like you said if you can patch it, you can change it, you can use it, that means you have that level of control for

what you use that you can use it, you can change it, you can apply it and you can secure it. Right. >> Right. >> And this is I think quite important. But Lucian, let's let's finish for this round with you and then we'll have a last minute interventions. >> Yeah. Do do we have a time or do we need to ask? Okay. So uh in indeed um

I could elaborate on on on several uh actually um maybe there there is one point um I wanted to to mention. So indeed um when we are talking about sovereignty there can be various dimension there are legal and geopolitical aspects. There are supply chain consideration there could be operational uh consideration like like how can we make sure that software is supported available etc. Um but one important

thing to my point of view is is also how we set the condition that the software can indeed evolve. uh to help the ecosystem to innovate to to get new solution efficient solutions for its business to uh to fulfill its its future needs and to create this uh innovation dynamics uh that can will also reinforce the underlying business model in in in the long run and I

think that's um a point where Um and actually it makes me think that that uh the success of open source today is a result of the success of underlying business models. uh that's why open source has been boosted by several companies that realize that that they can get lot of benefits from from this model and we have to understand how the future software business model will evolve

with indeed there are some revolutions around AI we mentioned the fact that end users are taking a grip also on the control of their their software so the business model is changing and I think it could be worth also from a research point of view to understand and investigate how these changes are happening because in the end these business model changes will uh affect the proper open

source governance model that would be successful and this is the point uh yeah additional point I wanted to make. >> Thank you very much. Now we have about three and a half minutes for the for the final thoughts. Maybe start with Rol and then just keep the the same let's say line as we had. >> Yeah, as you mentioned quite often, you know, commission repairs surveillance package

and um guess what is in the package. I think there will be no surprise. I think definitely um looking at uh the different discussions we definitely will reinforce the role of the foundations. Um it was it's clear you know that uh as mentioned by Tibo yesterday we spent a lot of effort in order these sort of um cloud-tocloud middleware on simple finally it's open source but it's

not the end of the journey you know at the end of the day you know if public administration want to use it or private you need um a governness model behind it so it's quite quite obvious so inside the uh um package will be to strengthen the role of the foundations I think definitely um There will be um actions related to encourage governments um in order to

move towards uh open-source uh corporate framework for the offices um for the business intelligence for governance for digital governance. Um and uh and finally uh we reinforce the role of what's was discussed today uh a whole industrial um uh internet an industrial software stack. Um because um in order to to manage the ecosystem, in order to manage security risk across um the different stack, you need sort

of a reference architecture. Um if you have something which is tangible like in open implementing in open source, you have a reference point uh where the the different companies and ecosystem supply chains can work together. So that will be the the third element in the in the package. So not much of a surprise and we definitely benefit from the awareness um of sovereignity about the stack and

the parliament politicians and the global global risks. So um from that point of view it will arrive at the right time but still there is room then afterwards you know we still have to implement. So then we have to go back to the same circle what we had today. >> Yes. >> Thank you very much Antonio please. So I I need to to say reference architecture rings

the bell and uh it's open reference architecture we are doing it ISO and this is going to be uh to me the initial condition but I wanted to say why I like open source because it fosters engineering so it's not only developing software is you engineer products okay and today engineering is actually merged with operation because we we do it continuously So it's just not design and

then operate. It's design operate at the same time. Okay. And uh so we need this and the last thing I want to say is we have OC because we need to verify. So if we don't have those conditions nothing happens. So that's why I like OC I have to say because it's going to be the last conditions for me to make sure I go to >> Thank

you Antonio Javanni please. >> Yeah thanks. Well, maybe I can spend a couple of words on the research aspect. Okay, open source is obviously strategically neighbor on many aspects. I think that uh with uh more awareness on the research side on how to make your research results as immature as they are as far as from the market as they are how to make them available for someone

to pick them up and carry them on. This is a very important enabling factor of the open source that was Nacho explained for example for for the IOS project. The other aspect is I think it is open source is key on all those waste of the hourglasses that Antonio was talking about because the waste is where you are forced to comply and if what you have to

comply with is not open you don't have access can be grabbed by by a player then you don't want to cooperate. So that's another aspect. Open source is the natural uh paradigm for the waste of all the hourglasses that we define in our in our let's say business model or in our analysis of a segment. >> Thank you very much Nacho. Please go >> Yes. Um thank

you. Just to conclude a couple of words from my side. We have heard about resilience, right? About agility that open source should comply with also the value of abstra, excuse me, abstraction. And uh I would like to round it up with my experience and with I presented about setting success stories and examples that are embraced by real companies afterwards and the role that open source have for

that to emanating from research ensuring that it will have continuity uh after the end of specific wave of funds so that we can find avenues and that's the role that we have as research academia and we also O need you all guys from standards and from the industry to make it happen. So uh that's the commitment and I could continue the flow from Antonio design operate check

with the industry and maintain >> and we need the resources for that. >> Yeah to conclude maybe a short call to action. So open source is a great opportunity and I have a call to action maybe to to my peers at the energy industry. We we we are not an IT company actually but what we learn through open source is that uh uh there is a fast

on boarding uh we learn fast and and and we benefit from all the lessons learned by other industries. So um we need to start soon small learn fast and have a great vision. That's our experience and and and the future I think my call to action is for our business to take leadership role in the open source ecosystem to participate as maintenance to participate as strategic partners

into foundation etc. That's where we will gain a grip on our techn technological dependencies. >> Thank you Monica. Well, just quick conclusion. I I will I recommend anyone to go for Eclipse Foundation governance model. Read it. It's open. You you can contribute to it. And if we want digital soy or digital autonomy in Europe, we need industrial Europe to be contributing to open source. >> No matter

where is based at open source because the the same way there is no open source business model, I mean it's not a business model. there is no flag for open source. So we need the industry to be contributing to be the one leading and that was said for one big company a long time ago not from Europe that they told me basically we are not contributing to

an open source project that the governance don't allow us to be one of the key contributors because if anything happened to that project we need to be sure that we are the ones knowing how it works knowing how to contribute and how to maintain it. It's not because we are just using it and selling something on top of that. We depend on that. So we need care

of our value chain. The same thing steel industry cares about the steel carbon and everything. So the same thing for for software. >> Thank you very much. And George, now you are last but not the least. >> Yeah, I would also conclude my thoughts uh basically around what's next or what I would expect to be you know next steps in this. Um well I would love to

see as I said previously uh our communities growing and establishing synergies altogether as mana said it's essential for the big players to get into and drive those communities otherwise there's no immediate way of them reaching the markets so we need the big players of Europe inhouse in these communities leading and you know inspiring also the communities and possibly from the EU side uh considering an alternative approach

of funding possibly I don't know like you know throwing money dedicated to those communities and establishing software projects possibly that will allow them to grow faster because we have seen cases that there is grow growth in those communities but it's not fast enough right and the way to to grow through R&D projects is not always the fastest path right so that's another angle that we may consider

in the future. >> So, thank you very much. We are a bit above time, but not not I would say that much that we still don't have time for the any questions from the audience. But before that, I would like you to give a round of applause for our uh speakers, panelists, for their presentations and thank you all for your patience with us. Is there any question

from the audience? Hi I have a question Tom flashman accenture um open source evangelist from the automotive area um so in order to create open source that is viable to the industry um we've seen that in automotive as well certain really important software assets are defined by standards hidden behind ISO or automotive consortia like autosar um and uh so I what is your take or who from

you can potentially answer best. I think we discussed it yesterday briefly. We need certain ISO standards out there to be implemented in open source otherwise uh the solutions are not viable I guess. Um and this puts uh standardization bodies into pressure um for yeah there is a certain amount of license uh going away um but if we can't implement these standards in open source it's in vain

because then yeah so anyone feeling >> so maybe I can mention one thing is uh we have the notion of smart standards and my dream is that uh there is an open source implementation of smart standards so that actually you can access standards according to business models that they have decide but still you can have an open-source solutions that manage properly the standards. I'm not sure it

answer your question but then uh you have categories of standards that you have to be made easily available. Okay, that's important and some of them includes recommendations for verification with which you can associate code. Okay, so for instance some testing some trust aspects we can say okay use this tool and it verifies this aspect. Okay. And uh so yes, I would really recommend a bigger a big

bigger relationship between open source and standards. Okay. I'm sure but it is the right direction to do that direction. >> Okay. >> Well, I think you basically said it all just here here. I think exactly that and what we did with Aarios was to basically go alongside the development of the right now preliminary working item of ISO AC41 IOT digital twin because we do believe and I

think that's a you know take that we should all have from research projects to starting you know even two three years or just starting the projects selecting which standard you're going to support for the moment you end up there's already an open source solution that would cover this future standard to be and this is at least what we tried to do with Aras from our side. >>

So yes, >> Absolutely. >> Any other questions or comments? >> No, >> maybe. No, I don't know if there are others. Uh maybe to solve the continuous chicken and neck problem apart from industry doing open source why don't we do industrial open source policy and actually say to the governments like hey on the educational level on university level on hands-on trainings we make part of open source

our research institutes that we work with industry open source is part and actually make it a part of actually how industry who works basically gets their workforce in the that like who can answer but like why are you know push like it's nice that industry plays in products but basically management doesn't understand open source the people that we get from students we have to reexlain open source

why not change the freaking system end to end >> I think definitely >> so the question the question is is quite clear so why we don't cooperate all together with some policy and with some regulation and you know not only industry not only foundation not only >> wants to address that it's definitely a relevant question and I think we also discussed a bit on lunchtime um you

need this sort of um awareness and push from the top on the one hand but as said um also in my slide you know it's a way you know in order to uh train skills and uh train your people on collaboration and this value is for industry and even in my management it's not fully understood I think some of you think but know if you open source

everybody can access it you know then we will be invaded by China and others so where you keep our ownership and uh um it's this is sort of a change in the mindset we still have to work on and I hope you know with a high level policy document like the sovereign package you know that this mindset is further changing and also goes into the uh collaborative

projects. Um whether it goes from top down that we make it mandatory, I'm not sure that we do it in the next years, but uh maybe we're going along that path. >> Probably will be both a bit of top down >> but did mention yesterday open money open source. She said he said that at the end of his talk. Okay. >> So he wants to go that

direction. May maybe one addition on top of our experience is also where we see a gap is in for instance executive programs. So so it's not only about teaching open source to tech people but also like in companies the middle middle management and the uh top management will have to understand how they can operate with with open source and and so far this is really not taugh

in into those programs. So maybe this is something that uh could be elaborated on. >> Maybe the foundations can help. >> Oh, I already have one. >> Who? >> The foundations. >> E or whatever. >> Yeah, there's one question. >> Uh I may have missed something. Nevertheless, I fully agree with the idea of sovereignity, but I think that it should be more than that. What is the

competitive advantage for Europe and if if is there any and how? Uh I think it was mentioned also by was Eric Schmidt you know former CTO of Google said well you know maybe you know the AI is led by um um transatlantic uh uh company uh countries but UB has a chance if it brings the stakes together you know that's a way you know to collaborate with

open source um for skills and learning but also put the stakes together and uh um have a collaborative effort to make them stronger. So and he also said that it's in the industrial space where collaboration on AI and open source should take place. >> But can I say that sovereignty is citizen trust. So it's competitive advantage to have citizen trust. Okay. >> Hopefully >> I think sovereignty

is a is a defensive play is a safe. We want to make sure that if something bad happens we have ways around it. Whereas competitive advantage is is a system livveness property is the opposite is that we want to make sure that there is always a way for us to reach a better situation. So to increase our market share or revenue something like that. So the two

things are are a little bit uh let's say separated from this point of view that opensource can help with both because it gives you guarantees as you were saying damir that it's the other half of the bottom up but also is helping because makes it easier for industries to engage in coopetition that I they are not used to but then they partner with a foundation the foundation

can tell them how it is done so it works with both but the two things for me are very separate. So it can also you can be very non-s sovereign but competitive. So >> thank you very much. I think with this we can close. Thank you all for listening. Uh thanks to our speakers for their great interventions also to to the questions from the audience and I

think it was very useful and I think we will take quite a lot of uh things with us and to keep working on it in our daily lives. Thank you all. >> Thank you as well for the moderation.