Europe has written the words. The Tech Sovereignty Package and the new Open Source Strategy say that dependence on a few non-European platforms is a strategic risk. Fine. But words are cheap. Italy turned “open source first” into a legal procurement principle in 2012 through Article 68 of the Digital Administration Code, AgID guidelines and mandatory reuse. More than a decade later it has produced no concrete effect and has been systematically circumvented. A law without budget, mandate and teeth becomes compliance theatre.
This talk argues that open source will not free Europe from Big Tech through policy statements or goodwill. It needs a counter-power inside the institutions and companies that buy technology: the OSPO, the Open Source Programme Office, the team that decides how an organisation adopts, contributes to and governs open source.
What I want to show is how much an OSPO is really responsible for once you take it seriously. Not just licences and developer support, but knowing which proprietary dependencies trap the organisation, having a voice before procurement signs a renewal, owning contribution and maintenance, and now carrying real legal exposure, since from 2027 the Cyber Resilience Act turns the software you ship into a compliance duty. None of this is a technical detail. These are strategic and financial risks, which is exactly why an OSPO buried inside the IT department cannot do the job. It has to be empowered and wired directly to the C-level, so that open source becomes a leadership decision about autonomy and risk, not a licensing chore handed down to engineers. That shift, from technical housekeeping to strategic mandate, is what turns sovereignty from a slogan into something that actually changes what gets bought.
