One of six themes that emerged from the EOLE 2026 online kick-off workshop (25 June). Background: see the kick-off topic.
Why it matters for sovereignty. The push to make everything “French / Italian / German”, or EU-level, sits in tension with open source, which is global by nature. As one participant put it, open source is “sovereign by design” and has been fostering sovereignty for decades; you do not scan a passport to accept a contribution. What can legitimately be national or European is the competence and know-how to use, install and run free software, not the code itself.
What came up at the workshop. “European open source” as a policy buzzword is largely incoherent: no real open source project sources its contributions from a single country, and there is a real risk that sovereignty money ends up with large proprietary actors labelled as national champions. Yet “avoiding vendor lock-in” raises a genuine question: lock-in to whom, proprietary vendors, or simply non-EU providers? A distinct and harder sub-topic is export control and dual-use: defence-adjacent producers may publish open source but cannot run a fully open community, which creates conflicts with licence non-discrimination clauses (GPL) and leads to practices such as excluding contributors or maintainers from certain countries. The kernel community’s exclusion of certain maintainers was cited as a live case, alongside the debate on “know your contributor” (DCO / CLA).
What already exists to build on. inno3’s export control decision tree (schema, CC BY-SA); DCO / CLA mechanisms; licence non-discrimination clauses (OSD / GPL); the debates around open source foundations based in the US or China.
Open questions. Can export-controlled or defence software meaningfully “do open source”, and how far? How to reconcile know-your-contributor needs with licence non-discrimination? Is avoiding non-EU lock-in a coherent sovereignty goal, or a contradiction? How does AI’s “trained in a specific geography” change the picture?
How to contribute. Reply below with cases, clauses and analyses, ideally by end of September 2026. Rapporteurs welcome for the Barcelona event (November 2026): volunteer by replying below or by direct message on this forum. Possible outputs: a decision guide on open source under export control and a note on KYC vs non-discrimination.