
Digital sovereignty has stopped being a slogan in Europe. That was my main takeaway from the Open Source Conference Luxembourg in Belval on 7 October, whose theme was “Leading by example in Digital Sovereignty”. Tracks covered the public sector, AI, cybersecurity, education and decentralized technologies.
Between 500 and 600 people came, the agenda was dense, and speakers from the European Commission (Joint Research Centre – JRC, DG Connect) and national governments (including France’s DINUM) were in the room. The hallway track matched the sessions: Andy Piper of the Matrix.org Foundation pointed me to the upcoming Matrix Conference in Malmö, and the three Stefanos present (Zacchiroli, Pampaloni and I) were ready to re-enact the Spider-Man pointing meme.

Five lessons I took home:
1. Sovereignty now has a legal address
The Digital Commons EDIC (European Digital Infrastructure Consortium) panel made it concrete. The EDIC is a permanent legal entity, created about a year ago, with five founding member states (France, Germany, Italy, Luxembourg and the Netherlands) and seven observers. It didn’t start from a strategy paper: the CIOs of France, Germany and the Netherlands realized they were each building a collaborative workspace and agreed to share components instead of reinventing them.
The EDIC is now preparing a European sovereign tech fund pilot with Germany’s Sovereign Tech Agency, and it fills a real gap. JRC data presented by Marco Minghini shows that the EU-27, taken together, is the world’s second open source pole and contributes more outward than it receives. That generosity only lasts if maintenance funding follows it. The EDIC is also pushing interoperable messaging built on Matrix, already used by more than 35 public institutions. Luxembourg’s representative was direct: deliver visible results within three or four years or lose credibility.
2. A catalogue is not a blueprint
Three unrelated talks reached the same conclusion. Matthias Kuom of IPCEI-CIS, the EU’s federated cloud-edge program, said the initiative has plenty of open source building blocks, but users can’t tell which ones fit together. As a result, its final phase is all about blueprints and validated patterns. Minghini’s team found 19 existing open source assessment frameworks before starting work on the EU’s own. Alessio Buscemi of the Luxembourg Institute of Science and Technology (LIST) demoed an AI assessment sandbox built to spare experts from hunting GitHub for test tools. Europe doesn’t lack components, but users lack guidance on how to assemble them.
3. Compliance is mostly writing things down
The Cyber Resilience Act session with Benjamin Jean of inno³ and Florian Effenberger of The Document Foundation (TDF) was the most practical hour of the day. Reporting obligations for actively exploited vulnerabilities have applied since September; full application follows in December 2027. TDF sells nothing, yet is voluntarily preparing to act as a manufacturer (instead of being a steward), whatever its formal status turns out to be, because LibreOffice has around 210 million users. Its main finding: the security practices were already in place, but scattered across wikis and people’s heads instead of written down in a central location. A CRA auditor treats an undocumented practice as no practice at all.
4. Open source is value, but freedom costs capacity
Carlos Correia of UNICC described an infrastructure that is open source at every layer except the hardware, and argued that open source should be valued for what it adds, not just for the lock-in it avoids. Pascal Steichen of the Luxembourg House of Cybersecurity added a counterweight: the freedom to choose is also the freedom to invest in your own people, and small companies and municipalities often can’t afford to. Luxembourg’s answer is training, shared tools and Europe’s first open cybersecurity data space, to build competence locally rather than rent it.
5. Trust takes time, and evidence
Tima Soni explained that the United Nations International Computing Centre (UNICC)’s threat intelligence network, built on the open source MISP platform and shared across more than 40 UN organizations, took years of patient trust-building before people started sharing indicators. Buscemi’s point was complementary: you can’t trust what you can’t measure. Shared infrastructure needs time to build trust and evidence to keep it.
A personal note
My own talk, “The dawn of preference signals: going beyond licenses in the AI ecosystem”, illustrated the proposal I published the day before: Take copyright out of the AI pipeline. Copyright has limited reach once content is used to train or feed AI systems, so I argued for taking it out of the picture and focusing on a levy to restore the balance in the digital commons. The other announcement on my radar came from Carlo Piana, who presented the CLEAR license, a second network copyleft option alongside the AGPLv3. Both ideas are young and need people to test them. This crowd was the right one to start with.
Luxembourg showed that the hard part of sovereignty is no longer the argument. It’s delivery, maintenance and documentation – work open source communities already know how to do. I’ll be back next year to see how much got done.

Stefano Maffulli, Chief Revenue Officer

