The Open Source Sovereignty Gap
Open source is a moral architecture American platform owners have operated as a strategic instrument.
Open source is a moral architecture for global cooperation that American platform owners have operated as a strategic instrument for rent capture and access control. Europe has been the largest contributor and the smallest beneficiary. The platform layer above the commons is American, subject to United States executive authority, and capable of cutting off any developer at the order of one government. GitHub did it in 2019. Microsoft did it to the Chief Prosecutor of the International Criminal Court in 2025.
The Cyber Resilience Act enforcement window (December 2027) and the AI training-corpus build-out make 2026 to 2030 the decision period. Europe needs a sovereign platform layer above the commons: a non-alienable European legal form, a Schrems II-equivalent compellability test on the platform operator, a four-tier procurement architecture, replication across member states under multi-party threshold control, governance closed to non-European board membership, a foundation and operating-company split, a technical assembly from existing European components, and a training-data sovereignty layer. ZenDiS and OpenDesk are the operational template.
Opening
“We’re not doing this because we want to. We’re doing it because we have to.”
On 28 July 2019, Nat Friedman, the Chief Executive Officer of GitHub, posted those words on Twitter to explain why the platform that hosted the world’s open-source commons had restricted developer accounts in Iran, Crimea, Cuba, Syria, and North Korea three days earlier. The blocks had been silent.
There was no warning, no notice, no opportunity for affected developers to download their own code. Hamed Saeedi, an Iranian developer, wrote in a viral Medium post that his GitHub account had been blocked without notice and without giving him the opportunity to download his code or data.
Anatoliy Kashkin, a 21-year-old Russian developer living in Crimea, lost access to the GitHub repositories hosting his website and his GameHub launcher for Linux. Public repositories remained available; private repositories, paid features, and Marketplace access were blocked.
The CEO Nat Friedman explained that GitHub was required to comply with United States export law and was sorry to be doing so. The company spent the following two years negotiating with the Office of Foreign Assets Control at the United States Treasury Department to secure a licence permitting service to Iranian developers, which it received in September 2021.
By then, the architecture had been demonstrated. The platform that hosts the world’s open-source commons could be cut off at the order of one government, and had been.[1]
Six years later, in May 2025, Karim Khan, the Chief Prosecutor of the International Criminal Court at The Hague, lost access to his Microsoft email and Microsoft platform services following a United States executive order signed on 6 February 2025 by President Trump.
Khan had pursued an arrest warrant against Benjamin Netanyahu, the Prime Minister of Israel, in connection with alleged war crimes in Gaza.
Microsoft President Brad Smith subsequently told reporters that Microsoft had not “ceased or suspended its services to the ICC”, but the Associated Press confirmed in May 2025 that Khan had lost access to his Microsoft email and migrated to Proton Mail, the Swiss encrypted email service.
The European Parliament submitted a formal question on 5 June 2025 confirming that Khan “has lost access to his Microsoft email address” as a direct effect of the Trump executive order. The ICC announced on 31 October 2025 that it was migrating from Microsoft Office to OpenDesk, the open-source software developed by ZenDiS, the German Centre for Digital Sovereignty.
Whatever the exact internal sequence at Microsoft, the operational outcome was unambiguous: the platform that hosts the European-anchored international institution responsible for prosecuting genocide had been rendered inoperable for its Chief Prosecutor at the order of one government. The mechanism that had reached Iranian developers in 2019 had reached the European Court at The Hague in 2025.
Same platform layer. Same legal authority. Same kill switch. Different victim.[2]
Open source is a commons. The platform that hosts it is not. The platform that hosts the world’s open-source commons can be cut off at the order of one government. The kill switch flows west with the rent.
Open source is a prisoner’s dilemma dressed as a moral architecture. Europe plays cooperate. America plays both moves at once.
The labour stays European. The rent and the kill switch flow west.
Open source has been understood by Europe as a moral architecture for global cooperation. It has been operated by American actors as a strategic instrument for rent capture and access control. The architecture works as a Pareto improvement when every party plays cooperate. The architecture has no defence against asymmetric play.
A rational profit-driven actor can play both moves at once: contribute to the commons enough to maintain credibility and access, and build closed-source rent layers above the commons that capture the value, and own the access platform that operationalises the commons at scale. Europe has been playing always-cooperate for thirty years.
The result is a continental contribution layer that produces no European rent, no European governance, and no European access protection. The 2019 GitHub case demonstrated the kill switch mechanism. The 2025 ICC case demonstrated it reaching Europe. Between them is the architecture and the prescription that follow.
- The architecture of the prisoner’s dilemma =============================================
The Free Software Foundation was founded in 1985 by Richard Stallman with a moral premise: software should be free as in speech, not free as in beer. The General Public Licence published in 1989 codified that premise into a copyleft mechanism. Linus Torvalds released the Linux kernel under the GPL in 1992. Tim Berners-Lee released the source code of the World Wide Web in 1993.
The architecture these founders built rested on a coherent moral position: the commons is a Pareto improvement over private property in software because software is non-rival, the marginal cost of a copy is zero, and cooperative production produces better software than competitive production. The architecture works if every participant plays cooperate.
The architecture has no defence against asymmetric play.[3]
A rational profit-driven actor can defect under the moral architecture in three ways at once. The actor can contribute to the commons just enough to maintain credibility and access. The actor can build closed-source rent layers above the commons that capture the value the commons produces.
The actor can own the platform infrastructure that operationalises the commons at scale and use that ownership as an access-control mechanism. Each of these defections benefits the actor at the expense of the cooperators. Each of them is invisible to the moral framework, which evaluates contribution and not capture.
The architecture cannot tell the difference between a cooperator who contributes and a defector who contributes-and-defects.
The mathematics of the prisoner’s dilemma applies: in a one-shot game, defection dominates cooperation; in iterated games with naive cooperators, defection wins until the cooperators learn to defect in response, and the only stable cooperative strategy is tit-for-tat, which cooperates by default and defects in response to demonstrated defection.
Robert Axelrod’s tournaments in the 1980s established this result for iterated prisoner’s dilemma games. The strategies that won were not always-cooperate, which is exploited without bound by any defector. The strategies that won were tit-for-tat and its variants, which cooperate first, defect on demonstrated defection, and return to cooperation when the other side does.
Always-cooperate is the only strategy that is provably worse than the Nash equilibrium because it is exploitable indefinitely. Europe has been playing always-cooperate at the open-source layer for thirty years. The result is the architecture that follows.
The diagnosis is structural rather than moral. The American actors operating the rent layers above the commons are not villains. They are rational profit-driven actors operating within an architecture that rewards their behaviour. Microsoft, Google, Amazon, Meta, Oracle, IBM, and the rest of the American hyperscaler stack are doing what their fiduciary obligations require them to do.
The villains are not the actors. The villain is the architecture, and Europe’s continued participation in the architecture without strategic defence is the choice that needs changing. The same diagnosis appears elsewhere in this series at the procurement layer, where rational individual choice by European Chief Technology Officers produces collective dependency on American cloud providers.
The mechanism is the same. The substrate is different. Open source extends the rational trap from procurement to production: Europe is not just rationally consuming American infrastructure, Europe is rationally producing American infrastructure, and the production is contributed for free.
- The rent-layer catalogue ===========================
The American digital strategy of the past two decades can be described by a single architectural pattern: contribute to the commons, build the closed-source rent layer above it, capture the rent, repeat at the next layer. Run the catalogue.
Linux was released as a free kernel in 1992. Amazon Web Services launched in 2006 and now earns roughly 108 billion dollars annually selling Linux operations to enterprises that cannot easily run their own infrastructure. Linux is free; running Linux at scale on demand is not. The rent layer is American.
AWS dominated the European cloud market by 2024 with a share that grew while European market share fell. The kernel is European-touched in significant part. The rent above the kernel is American.[4]
Kubernetes was released as open source by Google in 2014, contributed to the Cloud Native Computing Foundation under the Linux Foundation in 2015, and became the orchestration substrate for cloud-native applications. Google open-sourced Kubernetes precisely so the operations rent would accrue to Google Cloud.
Google Cloud, AWS, and Azure all sell managed Kubernetes services (GKE, EKS, AKS) that capture the rent on Kubernetes operations at billions of dollars per year. The standard is open. The rent layer is American.[5]
PyTorch was released as open source by Meta in 2016 and became the dominant deep learning framework. The frontier laboratories that built rent layers above PyTorch are OpenAI, Anthropic, Google DeepMind, and a handful of others. PyTorch is European-touched in significant part; the model rent is American.
Mistral and Aleph Alpha are the European laboratories attempting to build rent layers above PyTorch on European terms. Both are under acquisition pressure as of early 2026.[6]
Apache Spark, originally developed at Berkeley and now Apache Software Foundation infrastructure, became the substrate for big data processing. Snowflake and Databricks built closed-source data warehouse rent layers on top of Spark, Iceberg, and Arrow at multi-billion-dollar revenues. The substrate is open. The rent layer is American.
GitHub was founded as a private American startup in 2008 and became the platform layer above the global open-source commons. Microsoft acquired GitHub in October 2018 for 7.5 billion dollars. Microsoft trained Copilot on every public repository GitHub hosted. European developers wrote a substantial share of the training corpus.
Microsoft now resells Copilot to European developers at 10 to 39 dollars per seat per month, and Copilot Enterprise at 30 dollars or more per seat per month. The platform that hosts the commons was always private, was sold privately, and the rent extraction was built on European labour.
This is the most direct version of the pattern in the catalogue: the commons hosted by the rent layer becomes training data for the rent layer’s product, which is then sold back to the contributors.[7]
The Linux kernel itself is the limit case. As of 2025, 84.3 per cent of kernel commits came from corporate developers across more than 1,780 organisations. The top 2025 corporate contributors were Intel, Google, Red Hat, Linaro, AMD, Huawei, Oracle, SUSE, Igalia, and Samsung. American payrolls dominate the corporate share.
Huawei is consistently in the top five through Chinese state-backed support. SUSE, the only major European company in the corporate contribution band, contributes roughly half of what Red Hat contributes despite having approximately one-eighth the headcount. Europe is third in the production layer of the most consequential open-source project in the world.
The kernel is the substrate of every rent layer above. Europe contributes to the substrate. Europe captures none of the rent layer above.[8]
The pattern repeats at every layer of the open-source stack examined. The web (Tim Berners-Lee, CERN) was commercialised by Netscape, then Google, then the rest of the American advertising-driven internet. The relational database (Michael Widenius, Sweden, MySQL) was acquired by Sun, then Oracle.
The mobile communications protocol (Skype, Estonian engineering) was acquired by Microsoft in 2011, killed in 2025. The frontier artificial intelligence research laboratory (DeepMind, United Kingdom) was acquired by Google in 2014.
The chip architecture (ARM, Cambridge) was sold to SoftBank in 2016 for 24.3 billion pounds and listed on Nasdaq in 2023; the design engineers remain in Cambridge, the rent flows to Tokyo and New York. The pattern is documented elsewhere in this series at the innovation capture layer.[9]
The labour stays European. The rent and the kill switch flow west.
- The kill switches ====================
The platform layer above the commons is not a passive piece of infrastructure. It is an active access-control mechanism. The cases listed below are not theoretical. Each one was a moment when the platform operator demonstrated that the kill switch existed, was reachable, and was operationally activated.
GitHub restricted developer accounts on 25 July 2019 in compliance with United States sanctions executive authority. The blocks were silent. The blocked accounts were in Iran, Crimea, Cuba, Syria, and North Korea. Public repositories remained available; private repositories, paid features, and Marketplace access were blocked.
The CEO Nat Friedman explained that GitHub was required to comply with United States export law. The block was partially walked back after public pressure and fully reversed for Iranian developers in September 2021 after a two-year negotiation with the Office of Foreign Assets Control. The mechanism was demonstrated. China responded by establishing Gitee as a state-backed alternative platform.
Russia responded by establishing GitFlic. The Iranian developer community established mirror-and-bypass infrastructure that operates outside platform-layer jurisdiction.
Amazon Web Services deplatformed Parler in January 2021 by suspending hosting services within 24 hours of internal decision-making. AWS, Apple App Store, and Google Play Store all acted in coordination.
The deplatformed entity was an American social media application; the case is not about Parler’s content but about the architectural fact that three American platform operators acting in concert can remove an application from operational existence in a single business day. The same coordinated capacity exists toward European applications, European institutions, and European users.[10]
Apple removed applications from the App Store on policy decisions throughout the 2010s and 2020s. The App Store reaches roughly one billion devices globally. Removal is operationally instantaneous.
Removal has been used against applications criticising the Chinese government (under pressure from Beijing), against applications offering virtual private network services in restricted markets, and against applications considered incompatible with Apple’s platform policies. The platform operator has discretion. The discretion has been exercised.
Microsoft cut off the email and platform services of Karim Khan, the Chief Prosecutor of the International Criminal Court at The Hague, in May 2025. The cut-off followed a United States executive order signed by President Trump on 6 February 2025 over Khan’s pursuit of an arrest warrant against Benjamin Netanyahu, the Prime Minister of Israel.
The International Criminal Court is a European-anchored institution with treaty-based independence, headquarters in The Hague, and a mandate to prosecute the most serious crimes under international law. Microsoft’s President Brad Smith denied that the company had ceased or suspended services to the ICC. Khan migrated to Proton Mail, the Swiss encrypted email service.
The ICC announced its migration from Microsoft Office to OpenDesk, the open-source software developed by ZenDiS, on 31 October 2025. The European Parliament’s parliamentary question on 5 June 2025 confirmed that Khan had lost access to his Microsoft email address.
The operational outcome was that the European-anchored institution was reduced to operational silence by the action of a foreign executive on an American platform operator. (See Paper 1 for institutional sovereignty.) Here, the case demonstrates that the mechanism documented in 2019 reaches Europe in 2025.
Stripe and PayPal have frozen accounts on United States sanctions grounds throughout the 2020s. The frozen accounts have included European journalists working in adversarial regions, European non-governmental organisations operating in sanctioned jurisdictions, and European individuals targeted by sanctions designations they were not previously aware of. The platform operator has discretion.
The discretion is bounded by United States legal authority, not European legal authority.
The cases share a common architecture. The platform operator is American and is subject to United States executive authority. The platform operator is required by United States law to comply with sanctions, export controls, and executive orders. The platform operator has the operational capacity to suspend, restrict, modify, or surveil the platform’s users.
The combination of legal requirement and operational capacity is the kill switch. The kill switch has been pulled. It will be pulled again. This is what a prisoner’s dilemma dressed as a moral architecture looks like in operation: the architecture requires defection, the platform operator confesses to defection, the cooperators absorb the cost.
The labour stays European. The rent and the kill switch flow west.
- The European cooperate-only counter-history ==============================================
The mirror image of the rent-layer catalogue is Europe’s history of cooperating without building the rent layer. The pattern repeats so consistently that it constitutes a strategic posture, even though no European actor adopted it consciously.
The relicensing wars of 2018 to 2024 illustrate the pattern at the project level. Elastic relicensed Elasticsearch from Apache 2.0 to the Server Side Public Licence and the Elastic Licence in 2021, prompting the AWS-supported OpenSearch fork. MongoDB relicensed from the Affero General Public Licence to the Server Side Public Licence in 2018, prompting AWS DocumentDB.
Redis relicensed from Berkeley Software Distribution to the Server Side Public Licence in March 2024, prompting the Linux Foundation Valkey fork.
HashiCorp relicensed Terraform, Vault, Consul, and other products from the Mozilla Public Licence 2.0 to the Business Source Licence 1.1 on 10 August 2023, prompting the Linux Foundation OpenTofu fork (announced 25 August 2023, accepted by the Linux Foundation as OpenTofu on 20 September 2023). Cockroach Labs adopted the Business Source Licence years earlier.
In every single case, the relicensing was carried out by an American company defending its rent against AWS reselling the open-source product as a managed service. In every single case, European users had no governance voice in the relicensing decision. In every single case, the fork that rescued the original licence was hosted by the Linux Foundation, an American foundation.
European users faced a bare choice in each case: pay American licensing fees, accept reduced freedoms, or migrate to a fork that an American foundation maintained. Europe paid both sides of the licensing wars throughout.
The Terraform case is the cleanest illustration. HashiCorp moved a project that runs European critical infrastructure (most major European cloud deployments use Terraform for infrastructure-as-code) to a restrictive licence overnight, with no advance consultation. IBM announced its acquisition of HashiCorp in April 2024 for 6.4 billion dollars and completed the acquisition on 27 February 2025.
The American foundation hosted the rescue. The American conglomerate acquired the original. European users paid the licensing fees throughout, paid the migration costs, contributed to OpenTofu, and ended the cycle with infrastructure-as-code under American foundation governance and the original under American conglomerate ownership. No European had governance voice in any decision.
The acquisitions catalogue is the same pattern at the company level. Skype was founded in Estonia in 2003 by Niklas Zennström, Janus Friis, and a team of Estonian engineers including Ahti Heinla and Priit Kasesalu. Microsoft acquired Skype in 2011 for 8.5 billion dollars. Microsoft killed Skype in May 2025 after migrating users to Microsoft Teams.
The European communications platform that connected hundreds of millions of users became a Microsoft product, then a Microsoft footnote. DeepMind was founded in London in 2010. Google acquired DeepMind in 2014. The frontier artificial intelligence laboratory that the United Kingdom produced is now a Google research arm.
ARM Holdings was founded in Cambridge in 1990 as a joint venture between Acorn, Apple, and VLSI Technology. SoftBank acquired ARM in September 2016 for 24.3 billion pounds. SoftBank conducted an initial public offering of ARM on the Nasdaq in September 2023, retaining majority ownership. ARM is now headquartered in Cambridge, listed in New York, owned in Tokyo.
The chip architecture that runs roughly 95 per cent of smartphones, every Apple processor, and increasingly the data centre is European-designed and non-European-owned. The case is examined in Paper 9.
The platform-acquisition pattern reaches GitHub itself. GitHub was founded in San Francisco in 2008. Microsoft acquired GitHub in October 2018 for 7.5 billion dollars. The platform that hosts the global open-source commons, including the code of three million European developers, became a Microsoft subsidiary.
GitLab, the closest European-aligned alternative, was founded in 2011 by Dmitriy Zaporozhets in Ukraine and Sytse Sijbrandij in the Netherlands, and was Dutch-incorporated for years. GitLab moved to Delaware incorporation in 2020 and conducted an initial public offering on Nasdaq in October 2021. The rent layer migrated to America during the company’s life rather than at its sale.
There is no European platform of equivalent scale for hosting open source. The infrastructure that makes the European commons accessible is not European.
Hugging Face is the most recent illustration. Founded in 2016 by Clément Delangue, Julien Chaumond, and Thomas Wolf, three French engineers, the company is now incorporated in New York. Its August 2023 Series D round of 235 million dollars at a 4.5 billion dollar valuation included Google, Amazon, Nvidia, Salesforce, AMD, Intel, IBM, Qualcomm, and Sound Ventures.
Hugging Face hosts the largest open repository of machine learning models in the world. The rent layer above the model commons is being captured during the company’s life, the same pattern as GitLab.
Europe contributes. Europe builds. Europe sells. Europe loses. The rent layer flows west in every case where it could have stayed.
- Why regulation alone fails: the CRA trap ===========================================
The European Union has constructed an extensive regulatory apparatus over the past decade with the explicit goal of constraining American technology platforms operating in Europe. The General Data Protection Regulation entered into force in 2018. The Digital Services Act applied from August 2023. The Digital Markets Act applied from May 2023.
The Artificial Intelligence Act applied from August 2024. The Cyber Resilience Act entered into force on 10 December 2024 and applies in full from 11 December 2027.
The Data Act, the Data Governance Act, the Network and Information Security Directive 2, the Digital Operational Resilience Act, the European Cybersecurity Certification Scheme for Cloud Services, and a dozen other instruments fill out the regulatory architecture. The cumulative volume of European technology regulation is unmatched globally.
The cumulative effect on European technology sovereignty has been minimal. The regulatory expansion of the past decade has coincided with the entrenchment of American hyperscaler dominance, not its rollback.
Regulation alone fails because regulation governs conduct without changing ownership. A regulated American platform operator remains subject to American executive authority, American sanctions law, the CLOUD Act, the Foreign Intelligence Surveillance Act, and American export controls. Regulation can fine non-compliant conduct.
Regulation cannot revoke the legal compellability of an American entity to comply with American executive orders. The platform operator can be fined for not handling European data correctly. The platform operator cannot be released from the obligation to comply with United States executive orders concerning that data. The structural exposure is unchanged.
European cloud providers’ market share dropped from 29 per cent in 2017 to 15 per cent in 2022 according to Synergy Research Group, and has held flat at approximately 15 per cent since, while AWS, Microsoft Azure, and Google Cloud account for roughly 70 per cent of the European market. The pattern is examined in Paper 26.
The Cyber Resilience Act presents this problem in its most acute form. The CRA requires every product with digital elements placed on the European market to meet cybersecurity requirements throughout its lifecycle: secure-by-design implementation, vulnerability handling processes, automatic security updates by default, transparency to users, conformity assessment, and CE marking.
Manufacturers must produce a Software Bill of Materials listing every dependency in their product. Manufacturers must perform cybersecurity risk assessment on the whole supply chain. Manufacturers must report exploited vulnerabilities to the European Union Agency for Cybersecurity, ENISA, within 24 hours and severe incidents within 72 hours.
Manufacturers must support the product for its expected lifecycle, typically five to ten years. Free open source software outside commercial activity is exempted. The moment open-source code is integrated into a commercial product, the commercial integrator becomes liable for the security of every dependency, including the open-source ones.
Penalties run to 15 million euros or 2.5 per cent of global annual turnover.
The structural consequence is the trap. Every European commercial product placed on the European market after December 2027 must demonstrate full provenance and security posture of every open-source dependency it ships. That demonstration requires audit logs, identity verification, signed commits, integrity guarantees, and vulnerability disclosure timing across every dependency.
Today, all of that lives on GitHub. Performing CRA-compliant audit on dependencies whose audit logs sit on a platform subject to United States executive order, United States sanctions enforcement, and CLOUD Act demands is, on a strict reading of the CRA, non-compliant from day one. The European Commission has not enforced the strict reading because the alternative platform does not exist.
The strict reading is enforceable. The strict reading drives migration. The migration funds the alternative.
This is the same trap documented elsewhere in this series at the procurement layer. The Rational Trap shows that individually rational European procurement choices produce structural collective non-compliance with European regulation.
The CRA at the open-source layer shows the same architecture: individually rational European product development choices, using GitHub as the platform of record, produce structural collective non-compliance with European law as soon as the law is enforced strictly. The structural non-compliance is the lever. The enforcement is the trigger. The platform is the answer.
- The code renaissance window ==============================
The Cyber Resilience Act enforcement window is the immediate forcing function. The deeper structural window is wider and less discussed. Artificial intelligence-assisted development is producing a code volume explosion that has no historical precedent. GitHub data through 2025 shows commits per developer rising sharply with Copilot adoption.
GitHub reported 5.2 billion contributions across 518 million repositories in 2024. The volume of code being written from 2026 to 2031 will exceed the absolute volume of code written from 1976 to 2026.
This matters for sovereignty in a way that neither commentators nor policymakers have fully internalised. The training corpora for the next generation of code-generation models will be larger than the current corpora by orders of magnitude, and they will be assembled from whatever code is publicly accessible at the time the training runs.
The platform that hosts the code at the moment of writing determines whether the code becomes training data on European terms or American terms. Code hosted on GitHub during the next five years is in Microsoft’s training corpus by default. Code hosted on a European platform during the next five years is in European jurisdiction by default.
The decision is being made now, project by project, repository by repository, by individual European developers who have no idea they are choosing.
The argument inverts the timing objection commonly raised against European technology sovereignty initiatives. Europe is not late on open source. Europe is on time for the largest absolute volume of code production in human history.
The platform decision determines whether the next five years of European code, which will exceed the previous fifty in volume, accrues to American rent layers or European ones. The post-2030 artificial intelligence training corpora will include European code on European terms or American terms depending on where it was hosted when written.
The window is not “before the corpus is captured”, which is the framing that produces fatalism. The window is “during the period when the corpus is being multiplied”, which is the framing that produces urgency.
This is the original argument the paper contributes that no other paper in the series makes. The artificial intelligence rent layer is examined in Paper 20: Europe rents the models the rent layer produces.
The code renaissance argument extends the same diagnosis backward in time: Europe is not just renting the models, Europe is supplying the training data on which the models are built, in real time, through the platform layer, without governance, without compensation, without choice. The platform decision is the only intervention available before the training data stops being a choice.
The window closes by approximately 2030. The architecture of the next generation of code-generation models will be substantially set by then. The training corpora will be substantially assembled. The rent layers will substantially harden into multi-billion-dollar businesses with switching costs measured in years. The intervention available now becomes unavailable then.
The cost of the intervention now is in the low billions of euros over a decade. The cost of the equivalent intervention in 2032 is multiples of that and addresses a smaller fraction of the problem.
The dates are concrete. The platform that holds the European code written between 2026 and 2031 will be the training data of the 2030 to 2035 model generation. The model generation that follows it, in 2035 to 2040, will train on the code being written now. The Cyber Resilience Act enforces full application on 11 December 2027.
The European Sovereign Tech Fund 2028 to 2035 funding period begins on 1 January 2028. The European Multiannual Financial Framework 2028 to 2034 negotiation closes in 2027. The strategic decision-making window is roughly eighteen months wide, running from now to mid-2027, after which the architecture sets and the costs of changing it scale. The window is not theoretical.
The window has dates, and the dates are this Multiannual Financial Framework cycle, this CRA enforcement cycle, this generation of code-generation model training. Every month of inaction is a month of European code accumulating in American training corpora under American jurisdiction.
- The prescription ===================
If you are not a real commons, you are not contributing to the commons.
The principle that organises the prescription is operational rather than rhetorical. A commons is not defined by the openness of the licence. A commons is defined by reciprocal access protection. A platform that hosts open-source code under a permissive licence but operates a kill switch on its users is not a commons. It is a private archive that happens to be readable.
European code hosted on such a platform is volunteer labour for a private archive owner. The test is reciprocity.
The Schrems II judgement of the Court of Justice of the European Union in 2020 established this principle for personal data: a jurisdiction with extraterritorial executive authority that can compel disclosure of data in defiance of European law is not adequate for European data flows. The platform layer extends the same principle to source code.
A platform whose operator is subject to extraterritorial executive authority that can compel deplatforming, surveillance, or modification of European users is not adequate for European code.
The prescription is a European platform layer that operationalises the reciprocity principle.
The architecture has eight components:
a non-alienable European legal form,
a fully-European compellability test mirrored from United States legal apparatus,
a four-tier procurement architecture,
replication-with-multi-party-control rather than federation,
governance protection against foreign capture,
a foundation and operating-company split,
three implementation paths,
and a training-data sovereignty layer. Each component is specified below. None of the components requires new European Union legislation. All of them require that existing instruments (the Cyber Resilience Act, the Digital Operational Resilience Act, the Network and Information Security Directive 2, and the public procurement directives) are interpreted strictly and applied to the platform layer.
Component one: the legal form. The platform is hosted by a foundation incorporated in a European Union or European Economic Area member state with legal seat and operational headquarters in the European Union or European Economic Area.
The foundation is non-alienable outside the European perimeter: any successor entity must be incorporated within the perimeter, must satisfy the fully-European test specified below, and must include the same non-alienability clause recursively, binding all transferees forever. The legal form makes sale outside the perimeter impossible while permitting internal European reorganisation.
The Galileo asset structure provides the closest precedent. The Stiftung legal form in German law and the fondation d’utilité publique in French law are both candidates. The constraint must bind even against future European governments seeking to liberalise.
SoftBank’s golden-share commitments to keep ARM in the United Kingdom were not legally enforceable when SoftBank moved the listing to Nasdaq. The legal form must be load-bearing against future European weakness.
Component two: the fully-European test. The test mirrors the existing United States legal apparatus that defines “American” for strategic markets, applied symmetrically.
An entity is fully European if it is incorporated under the law of a European Union or European Economic Area member state with no Delaware shell or Cayman holding company structure,
has its legal seat and operational headquarters in the European Union or European Economic Area,
is majority-owned by European entities subject to foreign direct investment screening on any change of control above 10 per cent (the threshold mirrors the United States Committee on Foreign Investment foreign-ownership-control-or-influence test),
has a board with a majority of European citizens or long-term residents,
has key technical and security personnel who are European citizens or long-term residents (mirroring the International Traffic in Arms Regulations United States person definition),
has operational infrastructure physically located in the European Union or European Economic Area,
and is not subject to any non-European Union or non-European Economic Area legal order with extraterritorial effect.
The compellability test is operative. If a foreign executive order can reach the entity through the CLOUD Act, the Foreign Intelligence Surveillance Act, the Patriot Act, the International Traffic in Arms Regulations, the Export Administration Regulations, the United Kingdom Investigatory Powers Act, the Chinese National Intelligence Law, or any equivalent reach,
the entity is by default that jurisdiction’s regardless of where it is incorporated, where its servers sit, or what marketing it carries. SecNumCloud 3.2 in France and the Cloud Computing Compliance Criteria Catalogue 2025 in Germany already implement most of this principle for sovereign cloud.
Component three: the procurement architecture. Two mandatory primary-host tiers, one tier with conditional escalation, and one universal mirror layer.
Tier 1 captures Europe spending its own money on its own code or its own procurement: European Union institutions, member state governments, public-sector bodies, European Union-funded research, Sovereign Tech Fund and European Sovereign Tech Fund recipients, and public procurement vendors bidding for European contracts above a threshold.
Tier 2 captures Europe regulating sovereignty-critical entities:
Digital Operational Resilience Act-regulated financial services,
Network and Information Security Directive 2 essential entities,
Cyber Resilience Act-regulated Software Bill of Materials mirrors for critical-classified products,
Eurosystem operations,
and the International Criminal Court along with other European-anchored international institutions.
Tier 1 and Tier 2 must host primarily on the European platform; mirror-only is not permitted at these tiers because the audit trail must be sovereign for Cyber Resilience Act enforcement to operate.
Tier 3 captures all European code that benefits from being open source, with default-mirror as the baseline state and conditional escalation to primary-host on bilateral non-reciprocity.
If a non-European jurisdiction does not agree to reciprocal bilateral sharing on a Schrems II-equivalent test, Tier 3 escalates automatically to primary-host.
The universal mirror layer captures all public open-source code globally on a rolling basis from all major forges, regardless of authorship or jurisdiction. This is the commons preservation layer.
The escalation responds to the other side’s behaviour rather than requiring negotiation. Europe offers reciprocal terms; the architecture responds.
Component four: replication, not federation. The platform is a single logical system with copies replicated across member states. The developer pushes to one place. The system replicates by design across member-state copies. One identity, one repository, one Uniform Resource Locator. The federation tax that imposes coordination costs in email-style federation is avoided by design.
Replication provides resilience, access-denial protection, and sovereignty redundancy. Multi-party threshold cryptography governs all irreversible actions. Account deletion, repository takedown, jurisdictional disclosure to law enforcement, and response to extraterritorial legal demands all require multi-party authorisation across member states using zero-knowledge voting.
The default state is preservation. Action requires supermajority consent. This inverts the GitHub 2019 architecture in which Microsoft acted unilaterally on a United States executive order. No European member state alone, no European institution alone, no future European executive can unilaterally take a sovereignty action against any developer.
The cryptographic architecture is examined in Paper 5.
Component five: governance protection. The platform foundation has a charter that forbids non-European corporate membership at governance levels. Technical contribution from non-European entities is welcome. Board seats for non-European entities are forbidden. The EURATOM model provides the precedent.
The GAIA-X precedent demonstrates the failure mode that this clause exists to prevent: GAIA-X admitted Amazon, Microsoft, and Google to its governance, and the European Cybersecurity Certification Scheme for Cloud Services sovereignty requirements were progressively diluted under American Chamber of Commerce lobbying. The platform foundation must not repeat this.
Software Heritage’s current sponsor list includes Microsoft, Intel, Huawei, and Nokia Bell Labs. Sponsorship is not governance. The GAIA-X precedent says Europe should not let it become governance. The same charter clause that makes the foundation non-alienable outside the European perimeter also makes its governance non-capturable from outside the perimeter.
Component six: the foundation and operating-company split. Foundation governance is slow. Operating environments need decision-making cycles measured in weeks. The foundation owns the platform, holds the legal form, guarantees non-alienability, and protects governance.
A subsidiary operating company runs the platform under a charter that gives operational authority to a Chief Executive Officer and engineering leadership with normal startup-velocity decision-making, accountable to the foundation board on a longer cycle. The Mozilla Foundation and Mozilla Corporation split provides the most-cited precedent.
The Wikimedia Foundation and Wikimedia subsidiary structure provides another. The split creates its own tensions but is materially better than either pure foundation governance, which is too slow to ship, or pure corporate governance, which is saleable.
Component seven: the technical assembly. Three implementation paths satisfy the architectural requirements.
Path A builds on Software Heritage as the universal read-only archive layer, Forgejo (the soft-fork of Gitea after Gitea commercialised) as the active platform layer, and NeoNephos (the European cloud sovereignty foundation launched 31 March 2025 under Linux Foundation Europe, with major German and pan-European technology and research members) as the operating substrate.
Path A timeline is Tier 1 in three years and full scale in five to eight years. Path A builds European industrial capability in platform engineering. Path B acquires GitLab outright. GitLab is Delaware-incorporated and Nasdaq-listed but its codebase is open-source-aligned.
The acquired entity is re-domiciled to the European Union or European Economic Area and restructured as a non-alienable foundation. Path B compresses the timeline to one to two years at higher capital cost. Path C combines both paths and is probably the right answer if the capital is available. Software Heritage settles as the archive layer across all three paths.
The choice between paths is a procurement decision for the European Commission, not one to settle here.
Component eight: the training-data sovereignty layer. Code hosted on the European platform is available to European artificial intelligence laboratories on terms that European licence-holders specify. Code hosted on the European platform is available to non-European laboratories on reciprocal terms or paid licensing. The platform charter specifies training-data governance explicitly.
This is the question raised elsewhere in this series at the information sovereignty layer about preference data, applied to source code as training data. The alternative is what happened with Copilot: the platform that hosted European code trained a model on it and resold the model to European developers, with no governance role for Europeans at any point.
The platform layer makes that pattern unrepeatable for code hosted on it.
The eight components together compose a platform that is structurally non-capturable, operationally reciprocal, and architecturally aligned with the Cyber Resilience Act enforcement window.
Each component addresses a specific failure mode:
the legal form addresses acquisition risk,
the compellability test addresses jurisdiction risk,
the procurement architecture addresses adoption risk,
replication-with-multi-party-control addresses single-state risk,
governance protection addresses GAIA-X-style capture risk,
the foundation and operating-company split addresses calcification risk, the technical assembly addresses capability risk, and the training-data sovereignty layer addresses the rent-extraction risk that defined the Copilot precedent.
If you are not a real commons, you are not contributing to the commons.
- The funding mechanism ========================
The prescription depends on European political will to apply existing legal instruments strictly, to fund the platform layer at the scale specified, and to absorb the trade reprisals the prescription will provoke. The trade war is the operating environment for European technology sovereignty, not a hypothetical future risk.
Tariffs on European goods, sanctions threats over the International Criminal Court arrest warrant, pressure on the Cloud and Artificial Intelligence Development Act drafting process: each is happening regardless of European action on the prescription that follows. Anything in this series invites tariffs. So does declining to join wars Europe does not believe in.
So does declining to surrender territory. The reasoning that says Europe should not act because action would invite reprisal has its causation backwards: continued European concession demonstrates that escalation pays, which invites further escalation. Symmetric application of the rules America already applies to America is the move that prices Europe as an equal rather than as a vassal.
The prescription accepts this cost as the price of independence and proceeds.
The funding architecture has three layers in priority order, replacing the hypothecated-fines architecture proposed elsewhere in this series at the information sovereignty layer with a procurement-led approach more appropriate to the platform layer.
The primary operating funding is anchor demand procurement reallocation. Europe spends approximately 180 billion dollars annually on cloud services, plus tens of billions on developer tools, code hosting, package distribution, and platform infrastructure.
Procurement preference toward European platform infrastructure, applied to CRA in-scope manufacturers and public-sector buyers, redirects a meaningful share of that spend without inventing a new budget line. The Tier 1, Tier 2, and Tier 3 procurement architecture creates the demand. Procurement is the spine of the funding architecture.
The principle of investing rather than subsidising (Paper 26) applies directly: Europe places the order with European platform providers; European platform providers build the capability; the capability is sustained by ongoing procurement; the capability accumulates over time through use.
The secondary capital funding is direct European Union and member state investment. The Multiannual Financial Framework allocation through the Digital Europe Programme, member state co-funding, and European Investment Bank loans for capital programmes provide long-horizon public capital with industrial purpose. The model is Airbus, Galileo, and EURATOM applied to platform infrastructure.
The European Sovereign Tech Fund, proposed at 350 million euros for the 2028 to 2035 Multiannual Financial Framework period under a feasibility study commissioned by GitHub from OpenForum Europe, the Fraunhofer Institute for Systems and Innovation Research, and the European University Institute, folds into this capital layer.
The capital programme is a budget commitment justified by sovereignty value, not a self-funding architecture.
The tertiary contingency funding is hypothecated Cyber Resilience Act enforcement fines. The CRA penalty cap of 15 million euros or 2.5 per cent of global annual turnover applies to non-compliant manufacturers. The American hyperscalers are the entities most exposed to CRA fines because their products dominate European critical infrastructure.
The American hyperscalers are the entities whose platform behaviour is the diagnosis. Hypothecating CRA enforcement fines toward the platform fund creates a bonus funding source that scales with the diagnosis. The architecture is parallel to the proposal in Paper 23. The bad actors fund the alternatives.
This funding is supplementary because hypothecated fines are politically unstable and procyclical: enforcement strength varies with political will, fine bases shrink when American hyperscalers retreat from European markets, and the architecture is most needed exactly when the fine base is smallest.
Capability builds by doing. Tier 1 in years one to three builds the operational capability that Tier 2 in years three to five requires, which builds the capability that Tier 3 in years five to eight absorbs. The anchor customer is the capability-building mechanism. The capability gap closes by use rather than by waiting for capability before use.
The European industrial policy precedent at the platform engineering layer is examined in Paper 26.
- Values close ===============
The Free Software Foundation, the Open Source Initiative, Linux Foundation Europe, OpenForum Europe, the Eclipse Foundation, the Open Source Security Foundation, and the broader European free and open source software community have built the moral architecture.
They built it in good faith, on a coherent moral premise: cooperation produces better software than competition, the commons is a Pareto improvement over private property in software, and the architecture produces a global public good. The premise is correct. Linux runs the world. The Apache HTTP Server hosts a substantial fraction of the global web.
PostgreSQL underpins much of the world’s data. The architecture produced the digital substrate of the past three decades.
The community that built it is owed credit for that achievement, and has been the principal European constituency for digital sovereignty in its own terms, arguing for openness, transparency, non-discrimination in access, and the Pareto improvement that cooperative production represents. These are the right arguments. They are not contested here.
What the paper contests is their operational sufficiency in the architecture as it actually exists. The platform operators above the commons have not honoured the architecture’s terms. Microsoft cut off the International Criminal Court Chief Prosecutor’s email in 2025. GitHub blocked developer accounts across five sanctioned jurisdictions in 2019.
HashiCorp, Elastic, MongoDB, Redis, and Cockroach Labs each unilaterally relicensed widely-used open-source projects to defend rent against Amazon Web Services reselling those projects as managed services. Amazon Web Services deplatformed Parler in coordinated action with Apple and Google in January 2021. Apple removes applications from a billion devices on policy decisions.
Stripe and PayPal freeze accounts on United States sanctions grounds. The platform operators have repeatedly demonstrated that they operate within United States executive authority and that this authority can and does reach European subjects. The community’s arguments for openness, transparency, and non-discrimination remain correct as moral arguments.
They are insufficient as operational defences against the architecture in which the platform operators actually exist.
The paper asks the European free and open source software community to choose. The community can defend the moral architecture in name, by continuing to advocate for openness as the test of cooperation, while watching the platform operators operationalise non-cooperation under that name.
Or the community can defend the architecture in substance, by accepting that the test of cooperation must be reciprocity rather than openness, and that operational reciprocity requires plural infrastructure. The paper makes the second choice and proposes the platform that operationalises it. The community should engage the proposal on its merits.
The institutional layer of European free and open source software advocacy has a structural conflict that the community should examine in its own terms. Linux Foundation Europe is funded by the same American hyperscalers whose platform behaviour is the diagnosis.
OpenForum Europe took GitHub funding, GitHub being a Microsoft subsidiary, to commission the European Sovereign Tech Fund feasibility study that proposed the funding architecture. The Eclipse Foundation has been funded historically by IBM, which acquired Red Hat in 2019 and HashiCorp in February 2025.
The Cloud Native Computing Foundation operates under the Linux Foundation, which is funded by the American hyperscaler stack. The institutional layer reproduces the framings of its funders. This is a structural fact.
Public-interest institutions funded by parties with structural conflicts of interest will tend, on average, to produce framings that accommodate those interests. The European free and open source software community can verify this on its own funding records.
The community can also recognise that the structural conflict explains why the institutional layer has not produced a platform-sovereignty proposal of its own. The proposal of a European platform with the architecture specified here will not come from institutions structurally dependent on the parties whose behaviour the platform exists to constrain.
The community can take this proposal forward in its own name.
In 2019, the platform operator confessed the architecture aloud. “We’re not doing this because we want to. We’re doing it because we have to.” The confession was true. The platform operator was required to comply. The platform operator was operating within an architecture that left no operational alternative to compliance.
The architecture has not changed in the seven years since. The platform operator has not changed. The cases of compliance have multiplied: Iran 2019, Crimea 2019, Cuba 2019, Syria 2019, North Korea 2019, Parler 2021, the International Criminal Court Chief Prosecutor 2025. The mechanism reaches Europe now. The choice Europe faces is whether to defend the moral architecture in name or in substance. The moral architecture in name is what Europe has been doing for thirty years. The result is the architecture that follows. Defence in substance is the proposal.
Open source is a prisoner’s dilemma dressed as a moral architecture. Europe plays cooperate. America plays both moves at once. The labour stays European. The rent and the kill switch flow west.
Tit-for-tat is the cooperative strategy that survives. Always-cooperate is the strategy that gets exploited until it dies. The choice Europe faces is which form of cooperation Europe wants.
If you are not a real commons, you are not contributing to the commons.
[1] Nat Friedman, Chief Executive Officer of GitHub, statements on GitHub OFAC compliance, Twitter and GitHub blog, 28 July 2019. GitHub restrictions on developer accounts in Iran, Crimea, Cuba, Syria and North Korea took effect 25 July 2019.
[2] International Criminal Court press release, 31 October 2025, announcing migration from Microsoft Office to OpenDesk, the open-source productivity suite developed by Zentrum fur Digitale Souveranitat (ZenDiS), the German Centre for Digital Sovereignty established 2022.
[3] Free Software Foundation Inc., founded by Richard Stallman, registered as a Massachusetts non-profit on 4 October 1985.
[4] Microsoft Corporation acquisition of GitHub Inc., announced 4 June 2018, completed 26 October 2018. Total consideration approximately 7.5 billion US dollars in Microsoft common stock.
[5] Linux Foundation and LWN.net Linux kernel development statistics, 2025. Approximately 84.3 per cent of commits come from developers paid by their employers, across more than 1,780 corporate organisations.
[6] LWN.net Linux kernel development reports, 2025 ranking of corporate contributors by commit volume.
[7] ARM Holdings plc, acquisition by SoftBank Group Corp., announced 18 July 2016, completed 5 September 2016. Total consideration approximately 24.3 billion pounds. Subsequent ARM Holdings plc IPO on Nasdaq, 14 September 2023.
[8] Microsoft Corporation acquisition of Skype Technologies S.a.r.l., announced 10 May 2011, completed October 2011. Total consideration approximately 8.5 billion US dollars. Microsoft announced retirement of Skype consumer service for May 2025.
[9] Google announcement of Kubernetes open-source release, 7 June 2014. Donated to the Cloud Native Computing Foundation under the Linux Foundation umbrella, 21 July 2015.
[10] Google Inc. acquisition of DeepMind Technologies Limited, announced 26 January 2014. Total consideration estimated at 400 to 650 million US dollars; DeepMind retained London headquarters.
Sign the Manifesto. The eight demands that follow from the case made in this paper and the twenty-seven others. Sign →