
The EU has shown interest in open source software (photo by RG TVL, CC BY 2.0)
The European Union (EU) has long aspired to bolster its digital sovereignty. Also open source software (OSS) has recently been seen as a factor for strengthening digital sovereignty in Europe. Despite various related EU initiatives, such as those about interoperability, OSS is a fairly recent newcomer in EU politics. Therefore, it is worth taking a brief glance at what is currently happening in this space.
The European Commission launched a public policy consultation in January 2026 for the EU Open Digital Ecosystem Strategy (EUODES). By and large, the strategy is about OSS. Therefore, it is not surprising that the consultation received attention both in OSS outlets and mainstream technology media. Therefore, again, it is not a surprise that the public policy consultation received as many as 1,658 responses. While trying to summarize them in the present context is neither necessary nor feasible, the perhaps most visible and consistent argument raised was about using public procurement as a lever for supporting OSS and strengthening European digital sovereignty along the way.
The promotion of OSS in public procurement ended up also into the EUODES. In addition to OSS-friendly tendering, the strategy also emphasizes the role of public administrations in leading a transformation toward open, interoperable, reusable, and sovereign European digital infrastructures. Regarding challenges, the strategy notes fragmentation across Europe and dependence on non-European infrastructures, including for hosting OSS solutions and products. Despite promotional websites (such as this or that), also visibility of European OSS solutions was seen as a challenge. To this end and other ends, the Commission further established a new Open Source Observatory.
The EUODES also notes funding as a challenge for OSS. Cyber security is a good example in this regard. While the situation has improved thanks to new funding bodies, many challenges still remain. Maintenance burden is among them, including with respect to slop generated by people using large language models. At the same time, the models have also improved the discovery of true positives, verified software vulnerabilities. Against this backdrop, it is worth pointing out that OSS appears also in the EU’s recently released Action Plan on Cybersecurity and Artificial Intelligence.
And it appears in the action plan for a justified reason: as remarked in the plan, even as much as 98% of all software nowadays contain OSS components and even software powering critical infrastructures average to about a 80% rate. Even with these numbers, which may also be slightly inflated, the plan does not promise actual EU funding for OSS projects. Instead, a campaign is being prepared for improving maintenance of OSS used in critical infrastructure sectors. Though, the campaign planned includes a voluntary sponsorship scheme. “Better than nothing”, would OSS supporters supposedly say.