Skip to main content
☁️ Standardizing cloud access across an engineering organization? SSO, roles, account boundaries and onboarding, designed before they become security debt. Review your cloud platform
Open Source at a Crossroads: Sovereignty in Prague
Conferences

Open Source at a Crossroads: Sovereignty in Prague

Nithya Ruff and Johan Linåker on geopolitics and open source, plus the Who Owns the Stack? press panel at Open Source Summit Europe 2026 in Prague.

LB
Luca Berton
· 5 min read

Sovereignty was the word of Open Source Summit Europe 2026. Two sessions on the first day stood out for going beyond the slogan: a keynote conversation between Nithya Ruff and Johan Linåker, and an exclusive press panel called “Who Owns the Stack? Rethinking Digital Sovereignty in the AI Era”. I attended both as a media partner for Udienza.

”Open Source at a Crossroads: Geopolitics, Sovereignty, and the Fight to Stay Open”

Keynote title slide: Open Source at a Crossroads, Nithya Ruff and Johan Linåker Nithya Ruff, Chair of the Linux Foundation Board, and Johan Linåker, Senior Researcher at RISE Research Institutes of Sweden and Adjunct Assistant Professor at Lund University.

The conversation started from a fact that is easy to forget in Brussels policy debates: competitors already solved this problem once.

Industry already learnt this lesson

Slide: industry already learnt this lesson, from the Unix wars to co-investing in shared challenges

The timeline on the slide:

  • 1990s, compete alone. Each vendor built its own OS and stack. The Unix wars.
  • 2000s, collaborate on the core. Competitors co-developed shared foundations: Linux, Apache.
  • 2010s, build OSPOs. Policy, compliance and real community engagement. The TODO Group.
  • 2015 onwards, open source their own code. Release projects to set standards and fill gaps: Kubernetes, PyTorch.
  • Today, co-invest in shared challenges. Security, AI and more, funded together: OpenSSF, Alpha-Omega, the Agentic AI Foundation.

The conclusion: competitors learnt to share the core two decades ago. Governments can too, and keep their sovereignty.

Collaborate at the core, compete at the edge

Slide: balancing sovereignty with global collaboration

Companies innovate at the edge to keep their business strategy and competitive edge, and collaborate at the core on shared open source tools and platforms. The same model applies to governments: countries keep national policy and strategic autonomy at the edge, and collaborate at the core on shared digital public infrastructure.

The line I wrote down: rivalry is no showstopper. Competitors share open source cores and compete on top, and geopolitical rivals can do the same. Autonomy, influence, robustness and security still require effort and investment.

The public sector does open source differently

Slide: the role and need of stewards in digital public infrastructure

Digital identity, digital payments and data exchange form the digital public infrastructure layer. It is often rebuilt as parallel stacks, country by country. The slides listed what sets public-sector open source apart:

  • Procured development. Around 80% of the code comes from fewer than 15 developers, mostly local suppliers.
  • Top-down planning. Public bodies steer through formal, cathedral-like processes.
  • Sponsorship. One main public body, or many pooling budgets through joint procurement.
  • Fragile sustainability. It rests on sponsors and suppliers, and maintenance is rarely in the mandate.

X-Road, the cross-border data exchange stewarded by NIIS, was presented as the good counter-example. The proposal is a layer of new, complementary public-sector stewards. At national and municipal level that means organisations like OS2 (Denmark), Adullact (France), iMio (Belgium), Open Cities (Czechia), Sambruk (Sweden), PagoPA (Italy) and ZenDiS (Germany). At supranational level it means the Digital Commons EDIC and a proposed European DPI steward. They would sit on top of the incumbent foundations, which keep the core and horizontal infrastructure. The call to action was to bring these public stewards into forums like the Open Source Congress.

Sovereign AI needs collaboration further down the stack

Slide: AI widening open innovation beyond a single project

For AI, collaboration has to reach further down the stack than code: model training, tools and infrastructure, data commons, compute resources, and competence and skills. Countries pushing towards sovereign AI are already building their own models for autonomy, transparency and localisation, for example Teuken (Germany), Apertus (Switzerland), LLM-jp (Japan), OpenEuroLLM (Europe) and SEA-LION (South-East Asia). The slide called it a new paradigm that needs new stewardship from both incumbent foundations and complementary structures. I looked at each of these models, and when to use one in production, in Sovereign AI Models: Teuken, Apertus and OpenEuroLLM.

”Who Owns the Stack?” press panel

At 13:00 the same day, the Linux Foundation hosted a press and media panel in the Small Theater.

The Who Owns the Stack? panel in the Small Theater

The panelists were:

  • Jonathan Bryce, Executive Director, CNCF and Cloud & Infrastructure, Linux Foundation
  • Christopher “CRob” Robinson, CTO, OpenSSF
  • Paula Grzegorzewska, Strategic Partnership Senior Manager, Linux Foundation Europe
  • Thierry Carrez, General Manager, Linux Foundation Europe

The moderator was Stephen Sopko, Practice Lead at HyperFRAME Research.

The framing from the invitation: the European Commission’s 2026 Technological Sovereignty Package puts AI, cloud, semiconductors and open source at the centre of Europe’s push for autonomy. As AI adds new dependencies on models, compute, data, tools and agent infrastructure, what does it actually mean to be technologically sovereign?

One slide set the scale of the question:

Slide: open source runs at every layer above the hardware stack

  • Agents: MCP, A2A, x402, AGENTS.md, Goose. 120 million MCP installs per month.
  • Models: Llama, Qwen, DeepSeek, GLM, Kimi, Mistral. Around 30% of global usage, up from 1%.
  • Inference: vLLM, SGLang, Ray, llm-d, AIBrix. A 10x cost decline per year.
  • Training: PyTorch, DeepSpeed, Ray, Kubeflow, TorchTitan.

The panel also used the Cloud Sovereignty Framework, which breaks sovereignty into objectives from SOV-1 (strategic) through legal and jurisdictional, data and AI, operational, supply chain and technology sovereignty, as I described in the main recap.

What this means for architects

Sovereignty sounds like policy, but the decisions land on architects:

  1. Know which layers you could move. For each layer above (agents, models, inference, training, infrastructure), write down what it would take to switch provider. If the answer is “rewrite”, that is your dependency.
  2. Prefer open interfaces at the core. MCP for tools, OpenTelemetry for telemetry, Kubernetes APIs for workloads. Compete and differentiate at the edge.
  3. Participate, do not just consume. The State of Open Source in Europe report presented the same morning showed that governance participation is where the value is. I go deeper on that in Digital Sovereignty Is an Open Source Governance Problem.
  4. Look at the public stewards in your country. If you sell to government, OS2, ZenDiS, PagoPA and their peers will shape what “sovereign” means in procurement.

Related reading: digital sovereignty, governance and trust architecture, geopatriation and sovereign tech stacks, and my KubeCon conversation with Guido Laout of OVHcloud on sovereignty.

More from Open Source Summit Europe 2026

Free 30-min Production AI consultation

Book Now