Technological Sovereignty Requires Choice, Skills, and Support, Panelists
True sovereignty requires ensuring that migration off any single cloud provider remains a realistic operational choice rather than a costly theoretical option.
By Dillip Chowdary • Oct 10, 2026 • Source: InfoQ
European organizations do not need to cut ties with global technology providers to achieve operational sovereignty, but they must cultivate credible local alternatives and the practical skills required to run them. That central conclusion emerged from a panel discussion at the Open Source Summit Europe in Prague, where industry experts examined dependencies spanning cloud infrastructure, open-source software, security, and hardware. According to InfoQ's report, the session highlighted that true technological independence relies on maintaining viable choices across every layer of the technology stack rather than attempting total isolation.
This article examines the core insights shared by panelists from the Cloud Native Computing Foundation, the Linux Foundation, OpenSSF, Linux Foundation Europe, Akrites, and HyperFRAME Research. It is written for engineering leaders, cloud architects, enterprise decision-makers, and technology policymakers navigating the trade-offs between public cloud agility and European digital sovereignty requirements. The analysis covers practical software portability using platforms like Kubernetes, the role of local technical expertise in supporting mature open-source projects, upcoming regulatory expectations under the EU Cyber Resilience Act, and the physical constraints imposed by global hardware supply chains.
Technological Sovereignty Requires Choice: what actually changed
During the panel, speakers displayed the EU cloud sovereignty framework, which outlines eight specific objectives ranging from legal and jurisdictional authority to data, AI, operational, and supply-chain sovereignty. Rather than viewing sovereignty as a total rejection of foreign commercial platforms, the panel reframed the debate around a practical core question: which specific infrastructure dependencies must an enterprise be capable of swapping or controlling? Jonathan Bryce of CNCF and the Linux Foundation explained that open source provides value primarily by preserving choices. Enterprises can leverage commercial cloud giants like AWS or Azure without surrendering autonomy, provided they design architectures that retain viable deployment alternatives elsewhere.
Bryce cited Kubernetes as a prime example of an orchestration layer that enables operational portability, allowing workloads to run interchangeably on an organization’s internal infrastructure or on public clouds. However, Paula Grzegorzewska of Linux Foundation Europe cautioned that theoretical alternatives are useless without practical execution paths. Switching between proprietary systems often demands massive investments in time and technical expertise, creating severe hurdles for public sector institutions and governments. True sovereignty requires ensuring that migration off any single cloud provider remains a realistic operational choice rather than a costly theoretical option.
Technological Sovereignty Requires Choice: how it works

Operational sovereignty involves far more than simply obtaining access to open-source codebases. Bryce emphasized that having the source code is insufficient if an organization lacks the internal knowledge required to operate, secure, and monitor those systems continuously—a distinction exemplified by OVH’s cloud infrastructure strategy. Furthermore, software choices cannot resolve underlying physical hardware bottlenecks. Bryce noted that discussions in Shanghai revealed China's sovereignty strategy focuses heavily on securing access to silicon chips and optical communications systems rather than open-source software, where Chinese developers have long contributed. Software flexibility cannot eliminate fundamental hardware supply-chain dependencies.
To address varying security requirements across different enterprise workloads, Thierry Carrez of Linux Foundation Europe outlined proposed cloud and AI assurance levels. Under this framework, the highest security tier would demand complete control over the entire technological supply chain, extending down to physical server hardware. For workloads that do not require that extreme degree of direct oversight, Carrez pointed to confidential computing technologies as a viable technical mechanism. Confidential computing isolates running workloads and restricts the host infrastructure provider's ability to access sensitive data during processing, offering a balance between operational security and third-party hosting efficiency.
Advertisement
Tech Pulse Daily
Get tomorrow's pulse first
Join engineers who read Tech Pulse before stand-up. Free, weekday mornings.
Technological Sovereignty Requires Choice: why it matters now
Security due diligence has become directly linked to technological sovereignty, particularly as regulatory requirements tighten across Europe. Christopher "CRob" Robinson of OpenSSF and Akrites noted that open-source code and public project documentation empower enterprise buyers to evaluate vendor claims and inspect vulnerability-response workflows directly. Addressing the EU Cyber Resilience Act, Robinson highlighted that hardware and software manufacturers will bear formal legal responsibility for the security of their commercial products, including any open-source components embedded inside them. Carrez added that the Cyber Resilience Act explicitly accounts for complex software built from multiple upstream dependencies rather than treating applications as simple standalone packages.
The panel also dismantled the common myth that adopting open-source software is merely a cost-saving measure. Projects that begin as small engineering experiments frequently evolve into mission-critical production systems that demand sustained, long-term technical support. Carrez pointed out a significant shortage of local European service providers capable of packaging and supporting mature enterprise platforms like OpenStack. As a result, major institutions have been forced to build internal teams; bank Société Générale developed deep in-house OpenStack expertise because it could not find a commercial partner, while the French Ministry of Finance was forced to search for external support partners after its internal OpenStack deployment expanded far beyond its original scope.
Technological Sovereignty Requires Choice: who is affected
The lack of local commercial ecosystems places a heavy burden on both private enterprises and government ministries across Europe. Rather than attempting to duplicate existing global software projects from scratch, Carrez argued that Europe must invest heavily in local service capabilities to support established platforms. Grzegorzewska called for software developers to participate directly in policymaking processes, urging European authorities to accompany strict digital regulations with direct funding and infrastructure investments. Building a robust domestic ecosystem requires fostering vendor capabilities capable of servicing enterprise deployments without cutting off access to global open-source communities.
Robinson urged European organizations to cultivate deep technical expertise locally while avoiding isolationist policies that isolate domestic engineers from global innovation networks. Bryce reinforced this view by pointing out that global projects with broad, international contributor bases are inherently more resilient and secure than regional forks. Moderator Stephen Sopko of HyperFRAME Research summarized the challenge by drawing a parallel to the host city of Prague, stating that technological sovereignty should focus on constructing interconnecting bridges and maintaining flexible operational choices rather than hiding behind isolated fortress walls. This perspective aligned with a joint statement during the panel acknowledging that expecting 100% regional sovereignty in modern tech is naive.
Technological Sovereignty Requires Choice: what to watch
Moving forward, European enterprises must evaluate their technology stacks to identify high-risk vendor lock-in across cloud, software, and hardware layers. Industry leaders must watch for the formal rollout of the EU cloud sovereignty framework and its eight core objectives, as well as the implementation details of the EU Cyber Resilience Act. Organizations using open-source infrastructure components like Kubernetes and OpenStack should assess whether they possess sufficient internal skills or local partner support to maintain operational control during an emergency vendor migration.
Policy decisions and investment strategies across the European Union will increasingly shape how cloud providers and software vendors package their offerings for the European market. Technical teams should monitor developments in confidential computing as a pragmatic way to satisfy strict data sovereignty requirements on global public clouds. Ultimately, technological sovereignty will not be achieved by building closed regional silos, but by maintaining multi-cloud portability, funding local support capabilities, and ensuring engineering teams have the skills needed to switch providers when necessary.
Developer Action Items
- ☐ Verify the claim on the official AWS / Framework / Linux page (or InfoQ), not from this recap alone.
- ☐ Name the surface that moved — API, policy, model, hardware, or commercial terms — before you Slack the thread.
- ☐ Assign one owner a day to read the primary material and decide: this-sprint, this-quarter, or noise.
- ☐ Do not change production on day-one coverage. Watch the vendor changelog and one independent write-up first.
Technological Sovereignty Requires Choice FAQ
What is the main conclusion regarding European technological sovereignty from OSS EU?
European organizations do not need to avoid global cloud providers, but they must maintain viable software alternatives and possess the local skills to operate them independently.
How does Kubernetes help organizations maintain cloud sovereignty?
Kubernetes acts as a flexible abstraction layer that can run on an organization's internal infrastructure or across commercial public clouds like AWS and Azure, preventing single-vendor lock-in.
What challenge does the panel identify regarding open-source infrastructure like OpenStack in Europe?
Europe faces a shortage of local commercial companies capable of packaging and providing long-term enterprise support for mature open-source platforms like OpenStack.
How does the EU Cyber Resilience Act impact software vendors?
The Act holds manufacturers legally responsible for the security of their commercial products, including all embedded open-source dependencies and components.
Sources
Author
Dillip Chowdary
Writes Tech Bytes coverage of AI, engineering, and the tools that actually ship. Editor of Tech Pulse Daily.
Related on Tech Bytes
Advertisement