│ │ ┃ About Me ┃ │ │ ┗━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┛ │ │ │ │ Stefane Fermigier │ │ │ │ • Free software entrepreneur since 2000 (Linbox, Nuxeo, Abilian). │ │ • Creator of free software (Hop3: cloud self-hosting platform, Abilian │ │ SBE: open source digital workplace...). │ │ • Co-chair of CNLL & APELL (French and EU open source industry │ │ federations). │ │ • Co-founder of the EuroStack Initiative Foundation e.V. │ │ • Member of the French "Numérique de Confiance" strategic committee. │ │ │ │ Perspective │ │ │ │ • This talk is not about compliance or cybersecurity — it is about the │ │ strategic and industrial consequences of public procurement choices. │ │ • Thesis: facing hyperscaler network effects, │ │ • Europe must aggressively protect its digital industry; │ │ • Open Source is the strongest lever for Europe's technological │ │ catch-up. │ │ │ │ │ │ │ │ │ │ │ ╰──────────────────────────────────────────────────────────────────────────────╯ █░░░░░░░░░░░░░░░░░░░ 2/26
│ │ ┃ The Economic Hemorrhage ┃ │ │ ┗━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┛ │ │ │ │ Europe is massively funding the development of its competitors. │ │ │ │ • €265 billion/year flow from the EU to US suppliers (just for cloud │ │ and B2B software!). │ │ • That is roughly 80% of European enterprise software spend. │ │ • It is a structural transfer of wealth. │ │ • We are draining our own innovation ecosystem. │ │ │ │ │ │ ╭────────────────────────────────────────────────────────────────────────╮ │ │ │ Digital sovereignty is the strategic autonomy of an entire continent. │ │ │ │ It concerns public bodies, but also companies and citizens. │ │ │ ╰────────────────────────────────────────────────────────────────────────╯ │ │ │ │ │ │ │ │ │ │ │ │ │ │ │ │ │ │ │ │ │ ╰──────────────────────────────────────────────────────────────────────────────╯ ███░░░░░░░░░░░░░░░░░ 4/26
│ │ ┃ The Geopolitical Risk ┃ │ │ ┗━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┛ │ │ │ │ Sovereignty is not about betting on the goodwill of allies. │ │ │ │ The "kill switch" is real: │ │ │ │ • Adobe in Venezuela (2019) — accounts shut down overnight by US │ │ executive order. │ │ • Microsoft vs ICC (2025) — International Criminal Court Chief │ │ Prosecutor's email cut under US sanctions. │ │ • Technology sanctions — Huawei (2019), Russia (2022), ongoing │ │ restrictions on updates, APIs, cloud services. │ │ • FISA 702 (reauthorized 2024) / CLOUD Act (2018) — access to data │ │ even when hosted in Europe. │ │ │ │ │ │ Strategic autonomy is also the ability to say "no". │ │ │ │ │ │ │ │ │ │ │ │ │ │ │ │ │ ╰──────────────────────────────────────────────────────────────────────────────╯ ████░░░░░░░░░░░░░░░░ 6/26
│ │ ┃ Regulation Alone Is Not Enough ┃ │ │ ┗━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┛ │ │ │ │ Europe is the "world champion of regulation": GDPR, DMA, DSA, AI Act, │ │ CRA... │ │ │ │ But "Code is Law" (Lawrence Lessig). │ │ │ │ • If we do not own the infrastructure, our laws only apply when the owner │ │ allows it. │ │ • GDPR protects personal data but does not neutralize extraterritoriality. │ │ • NIS2 secures networks but ignores the nationality of the supplier. │ │ • EUCS was stripped of its sovereignty criteria under lobby pressure. │ │ │ │ │ │ ╭────────────────────────────────────────────────────────────────────────╮ │ │ │ We must shift from regulating to building. │ │ │ ╰────────────────────────────────────────────────────────────────────────╯ │ │ │ │ │ │ │ │ │ │ │ │ │ │ │ │ │ ╰──────────────────────────────────────────────────────────────────────────────╯ █████░░░░░░░░░░░░░░░ 7/26
│ │ ┃ The Sovereign Prison (aka "Sovereignty-Washing") ┃ │ │ ┗━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┛ │ │ │ │ Do not confuse data residency with sovereignty. │ │ │ │ The trap: The consequences: │ │ │ │ • Data stored in Europe — check. • Price hikes with no recourse. │ │ • But "black box" technology. • Migration becomes prohibitively │ │ • Controlled from abroad. expensive. │ │ • Proprietary, non-auditable code. • Dependency on the vendor's │ │ • Technical and contractual roadmap. │ │ lock-in. • No real security audit possible. │ │ • No resilience. │ │ │ │ │ │ │ │ Your data is there, but you have no freedom of action. │ │ │ │ │ │ │ │ │ │ │ │ │ │ │ │ │ ╰──────────────────────────────────────────────────────────────────────────────╯ ██████░░░░░░░░░░░░░░ 9/26
│ │ ┃ LOTEC: A Holistic Due-Diligence Grid ┃ │ │ ┗━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┛ │ │ │ │ Facing marketing confusion, a 5-pillar framework: │ │ │ │ │ │ Criterion Central question │ │ ──────────────────────────────────────────────────────────────────────── │ │ L — Legal Which jurisdiction are you ultimately subject to? │ │ O — Operational Who effectively controls the infrastructure? │ │ T — Technological What technical mastery and reversibility? │ │ E — Economic Where is value created and captured? │ │ C — Cultural Are we building the skills and mindset to stay in │ │ control? │ │ │ │ │ │ ╭────────────────────────────────────────────────────────────────────────╮ │ │ │ Without objective criteria, "sovereign" means nothing. │ │ │ ╰────────────────────────────────────────────────────────────────────────╯ │ │ │ │ │ │ │ │ │ │ │ │ │ │ │ ╰──────────────────────────────────────────────────────────────────────────────╯ █████████░░░░░░░░░░░ 12/26
│ │ ┃ [L] Legal — Jurisdictional Immunity ┃ │ │ ┗━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┛ │ │ │ │ Concept: legal immunity vs. apparent compliance. │ │ │ │ ▌ If a foreign court (FISA, Cloud Act) demands your data, can your │ │ ▌ supplier legally refuse? │ │ │ │ If the parent company is outside the Key criteria: │ │ EU: │ │ • ultimate parent of the control │ │ • the answer is no. chain in the EU. │ │ • the GDPR contract does not • more than 50% of voting rights │ │ protect you. held in the EU. │ │ • foreign law overrides the • no non-EU "blocking minority". │ │ contract. • IP not subject to foreign export │ │ control. │ │ │ │ │ │ │ │ Legal immunity is a must-have — but addressing only this pillar leads to │ │ "sovereignty washing". │ │ │ │ │ │ │ │ │ ╰──────────────────────────────────────────────────────────────────────────────╯ ██████████░░░░░░░░░░ 13/26
│ │ ┃ [O] Operational — Effective Control ┃ │ │ ┗━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┛ │ │ │ │ Concept: who holds the keys to the truck? │ │ │ │ Having servers in Stockholm is not enough if the control plane is driven │ │ from Seattle. │ │ │ │ Key criteria: │ │ │ │ • Infrastructure — datacenters and networks on European soil. │ │ • Control plane — admin console operated from the EU. │ │ • Personnel — 100% of privileged (root/admin) access held by EU residents, │ │ employed by an EU entity. │ │ • Supply chain — documented strategy to reduce critical dependencies. │ │ • Security — robust encryption, NIS2 compliance, documented incident │ │ procedures. │ │ │ │ │ │ An admin in Seattle can be legally compelled by US authorities. │ │ │ │ │ │ │ │ │ │ │ │ │ ╰──────────────────────────────────────────────────────────────────────────────╯ ██████████░░░░░░░░░░ 14/26
│ │ ┃ [E] Economic — Value Capture ┃ │ │ ┗━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┛ │ │ │ │ Concept: where does the money go? Who benefits from the growth? │ │ │ │ Value creation criteria: Pitfalls to anticipate and avoid: │ │ │ │ • more than 50% of global R&D in • punitive egress fees. │ │ Europe. • tied-selling and forced bundling. │ │ • skilled local jobs. • aggressive licensing audits. │ │ • European intellectual property. • unilateral end of perpetual │ │ • profits reinvested in the EU. licenses. │ │ • partnerships with European firms │ │ and academia. │ │ │ │ │ │ │ │ "If I pay a license, am I funding engineers in Berlin or in California?" │ │ │ │ │ │ │ │ │ │ │ │ │ │ │ │ │ ╰──────────────────────────────────────────────────────────────────────────────╯ ████████████░░░░░░░░ 16/26
│ │ ┃ [C] Cultural — Competencies and Mindset ┃ │ │ ┗━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┛ │ │ │ │ Concept: sovereignty is ultimately a matter of people (skills and │ │ mindsets), not just contracts and servers. │ │ │ │ Build the skills: Participate actively: │ │ │ │ • IT staff trained on European and • contribute to open source │ │ open source stacks, not just projects critical to Europe — │ │ vendor certifications. don't just consume them. │ │ • procurement officers able to • engage in standards bodies and │ │ write reversibility and immunity governance rather than leaving │ │ clauses. them to Big-Tech. │ │ • open source in engineering • host foundations and consortia │ │ curricula; sovereignty issues in under EU or neutral law (cf. │ │ secondary school. RISC-V moving to Switzerland). │ │ │ │ │ │ │ │ ╭────────────────────────────────────────────────────────────────────────╮ │ │ │ Two traps to break: │ │ │ │ • the "nobody got fired for buying from Big-Tech" default, │ │ │ │ • Europe funding its own lock-in — "free" vendor training, EU │ │ │ │ startups funded to run on US cloud. │ │ │ ╰────────────────────────────────────────────────────────────────────────╯ │ ╰──────────────────────────────────────────────────────────────────────────────╯ █████████████░░░░░░░ 17/26
│ │ ┃ Public Procurement — The Major Lever ┃ │ │ ┗━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┛ │ │ │ │ Public procurement is not just an operating expense. It is an industrial │ │ investment. │ │ │ │ The action: The impact: │ │ │ │ • embed LOTEC criteria (or similar) • creates a viable market for │ │ in tender specifications. European SMEs. │ │ • target 20-30% of budgets toward • scale effect: from niche to │ │ solutions with strong European mainstream. │ │ value creation. • strong political signal. │ │ • use security exceptions (Art. 346 • local skills development. │ │ TFEU, Art. III GPA/WTO). │ │ │ │ │ │ │ │ "Public money, public code. Open source priority. European preference." │ │ │ │ │ │ │ │ │ │ │ │ │ │ │ ╰──────────────────────────────────────────────────────────────────────────────╯ █████████████████░░░ 23/26
│ │ ┃ Call to Action ┃ │ │ ┗━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┛ │ │ │ │ Digital sovereignty is not decreed. It is built project by project. │ │ │ │ For CIOs and architects: For economic and political │ │ decision-makers: │ │ • map your critical dependencies. │ │ • evaluate them against the LOTEC • embed sovereignty criteria in │ │ or similar grids. procurement. │ │ • identify the legal "single points • support the European ecosystem │ │ of failure". (including SMEs, open source). │ │ • demand transparency from your │ │ suppliers. │ │ │ │ │ │ │ │ ╭────────────────────────────────────────────────────────────────────────╮ │ │ │ *"Do not build your digital future on land you do not own."* │ │ │ ╰────────────────────────────────────────────────────────────────────────╯ │ │ │ │ │ │ │ │ │ │ │ │ │ ╰──────────────────────────────────────────────────────────────────────────────╯ ██████████████████░░ 24/26
│ │ ┃ Conclusion ┃ │ │ ┗━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┛ │ │ │ │ The year 2025 marked the end of technological naivety. │ │ │ │ The challenge is not (only) legal, it is industrial. │ │ │ │ We have the talent. We have the internal market. What is missing is the │ │ strategic alignment to build rather than buy. │ │ │ │ ╭────────────────────────────────────────────────────────────────────────╮ │ │ │ Open source is the key. │ │ │ │ It is the main lever to transform IT spending into asset investment. │ │ │ ╰────────────────────────────────────────────────────────────────────────╯ │ │ │ │ │ │ │ │ │ │ │ │ │ │ │ │ │ │ │ │ │ │ │ │ │ ╰──────────────────────────────────────────────────────────────────────────────╯ ███████████████████░ 25/26