Summary
- Ninety-four per cent of surveyed European organisations say digital sovereignty is important to technology strategy.
- Advanced open source governance is associated with a 4.6-times reported benefit-to-cost return, against 3.6 times without formal governance.
- Almost half maintain private software forks, while regulatory demands are increasing spending on dependency management.
Digital sovereignty has become a stated technology priority for 94% of European organisations surveyed by the Linux Foundation, but the same research suggests that greater control over technology depends on governance and participation rather than replacing proprietary software with open source alternatives alone.
The fifth annual State of Open Source in Europe report, released on 7 October by Linux Foundation Europe, LF Research and NeoNephos, found that 61% of respondents consider digital sovereignty very important to technology strategy. Security and privacy were the leading drivers as organisations reassess dependency, regulatory exposure and control over critical software.
Access to source code and the ability to run software independently can reduce reliance on a single supplier, yet consumption without formal processes creates a different set of operational dependencies. Organisations still have to track software components, security fixes, licences and internal modifications while maintaining enough engineering expertise to act when upstream projects change.
The research links stronger governance with higher reported economic returns. Organisations describing their open source governance as advanced calculated an average benefit-to-cost return of 4.6 times investment, compared with 3.6 times among respondents without a formal governance framework. The figures are self-reported rather than audited financial returns, but the gap indicates that organisational discipline influences how much value respondents believe they extract from open technologies.
Private control can become private maintenance
Nearly half of surveyed organisations maintain their own software forks, with the research putting the share at 48%. Respondents maintaining forks reported an average of 9.5 and 311 hours of patching work during each release cycle, while more than a quarter said they could not track the associated cost.
A private fork can give an organisation control over functionality or allow it to patch software without waiting for an upstream project, although divergence creates a continuing engineering commitment. Changes made by the wider project still have to be assessed and merged, security updates need to be followed and internal modifications may become harder to sustain as the original code evolves.
Upstream participation can reduce that burden by moving useful changes back into the shared project rather than maintaining them indefinitely in private. European developers already account for nearly 40% of contributions to foundational projects including Kubernetes and OpenStack, according to the report, giving the region substantial participation in software that supports modern digital infrastructure.
That finding complicates the political tendency to treat sovereignty primarily as a purchasing decision. Techopia has already examined how Germany’s openDesk project is extending sovereign collaboration software into commercial distribution. The Linux Foundation research points towards a longer-term test in which governance, maintenance and contribution determine whether greater control remains practical after migration.
AI adds another dependency layer
Generative AI is increasing the amount of open source technology entering development workflows. Ninety-four per cent of respondents said their organisations use or are piloting generative AI coding tools, while 76% reported that AI helps them obtain more value from software they already use.
Faster development can increase productivity while making provenance and dependency management harder. AI-assisted coding can bring more components, libraries and generated changes into software estates, meaning governance processes designed around slower manual development have to keep pace with a larger and more dynamic set of dependencies.
Regulation is already influencing spending. Sixty-three per cent of organisations said they had increased investment in dependency management because of regulatory pressure, while 31% still lacked a formal open source governance framework. Compliance requirements are therefore expanding at the same time as a sizeable minority of organisations remain without a consistent structure for controlling open source use.
The report is sponsored by NeoNephos and reflects survey responses rather than independently audited operational data, so the return figures are best read as respondents’ assessments rather than financial proof. The costs associated with private forks and the prevalence of governance gaps nevertheless show why sovereignty cannot be measured simply by asking where software originated or whether its code can be downloaded.
European organisations can reduce dependence on individual vendors through open technologies, but sustainable control still requires engineering capacity, security maintenance, contribution and a reliable inventory of software entering the estate. As AI accelerates development and regulation increases scrutiny of technology dependencies, those operational disciplines are becoming part of sovereignty itself.












