
We hear it constantly: regulations kill innovation. Brussels writes rules, the argument goes, and Silicon Valley writes the future. Yet the past year has produced a quieter story, one that complicates the slogan. European laws written to protect citizens are turning into a tailwind for open source software, and the companies building on it.
The evidence is now concrete. Six million Europeans picked Firefox through the browser choice screens that the Digital Markets Act forced onto every smartphone. The French government, after seven years of hosting the medical records of 67 million citizens on Microsoft Azure, has chosen a European cloud provider to take over. The AI Act, in force since 2024, contains a clause that quietly rewards genuinely open AI models with regulatory relief. None of this was inevitable. All of it follows directly from rules that, on paper, sound like compliance burdens.
A Microsoft executive, under oath
In June 2025, in a French Senate hearing on public procurement, Senator Dany Wattebled asked Anton Carniaux, Microsoft France’s director of public and legal affairs, a simple question. Could he guarantee, under oath, that the data of French citizens stored with Microsoft would never be handed to the American government without explicit French authorisation?
Carniaux’s answer: “No, I cannot guarantee it, but, again, this has never happened yet.“
The admission was not a slip. It was the legal reality. The US Cloud Act, passed in 2018, requires American companies to hand over data to American authorities even when that data sits on servers in Frankfurt or Dublin. European data protection law forbids exactly that transfer. The two regimes cannot both be obeyed at once. For any European public administration relying on an American cloud, the question is not whether the conflict exists, only whether it ever gets triggered.
David Monniaux, research director at the CNRS, put the question more sharply in Le Monde: what happens if a future American president simply orders the big cloud providers to cut off European governments? His answer was that the only durable protection is open source software, hosted locally, on infrastructure Europe controls.
Eight months after the Carniaux hearing, in early February 2026, the French government announced that the Health Data Hub, the platform holding the anonymised medical records of all French residents, would leave Microsoft Azure. On 23 April 2026, the contract was awarded to Scaleway, the French cloud subsidiary of the Iliad group, with migration scheduled through 2026 and 2027. This is the largest sovereign cloud migration ever conducted by a European public administration, the culmination of years of CNIL warnings, a 2024 French law requiring sovereign hosting for sensitive public data, and a procurement procedure already in preparation. The Carniaux testimony did not start the process, but it removed the last political cover for postponing it.
Why the rules favour open code
European digital regulation has a structural bias that is rarely stated out loud: the rules require things that open source can already do, and that proprietary software can only fake.
Take the GDPR, in force since 2018. It requires companies to explain what data they collect, how they process it, and to let users export or delete it. A regulator asking those questions of a proprietary vendor gets a marketing brochure. A regulator asking the same questions of an open source project gets the source code. The privacy technology market in Europe has grown to roughly three billion euros, and the techniques the European Commission itself recommends for compliance (anonymisation, federated learning, homomorphic encryption) are predominantly developed as open source.
The AI Act, which took full effect on general-purpose AI models in August 2025, goes further. It requires developers of high-risk AI systems to document how the model was trained, what data it saw, and how it makes decisions. For a proprietary model, this is a trade secret problem. For an open model, the documentation already exists. More importantly, Article 53(2) of the Act creates a real exemption: AI models released under a genuinely free and open licence, with weights, architecture, and training methodology publicly available, are exempt from most of the technical documentation and downstream reporting obligations.
This is not theoretical. In January 2026, the AI Office’s external advisory group ruled that Meta’s Llama Community Licence, which restricts commercial use above certain thresholds, does not qualify as a free and open licence under the Act. Mistral’s models, released under Apache 2.0, do qualify. For the first time, a European regulation distinguishes between actually open AI and merely source-available AI, and gives the former concrete regulatory relief.
Security through transparency
The Cyber Resilience Act, in force since December 2024, requires manufacturers of any product with software in it (a router, a connected fridge, an enterprise application) to follow security-by-design principles, maintain a Software Bill of Materials listing every component used, and report exploited vulnerabilities to authorities within tight deadlines. Reporting obligations apply from September 2026, full compliance from December 2027.
Proprietary vendors face a real problem here: producing the documentation without exposing the trade secrets that justify their pricing. Open source projects already publish their dependency trees, accept public security audits, and disclose vulnerabilities in the open. The law writes a habit into legal obligation.
More surprising is what the CRA does for open source maintainers. Article 24 of the regulation creates a new legal category, the open source software steward, covering foundations like Eclipse, Apache, and the Linux Foundation. Stewards get a light regime: a documented security policy, cooperation with authorities, vulnerability reporting. They are explicitly exempt from administrative fines (Article 64). This was not a foregone conclusion. The first draft of the CRA in 2023 was widely read as a threat to volunteer-driven projects. The final text, after sustained engagement from the open source community, draws a clear line between commercial software shipped for profit and the digital commons that everyone depends on.
Cracking open the monopolies
The Digital Markets Act took effect in 2023 with one objective: to force the seven largest tech companies, designated as gatekeepers, to open their systems. iPhone users can now uninstall Safari, install browsers and payment apps from outside the App Store, and pick alternatives from a choice screen on first use. Messaging apps must, on request, interoperate with WhatsApp.
The numbers are starting to come in. Mozilla reports that roughly six million Europeans picked Firefox through the DMA-mandated browser choice screens, users who would otherwise have stayed on Safari or Chrome by default. Smaller independent browsers from Cyprus, Norway, and Germany saw similar surges. On 28 April 2026, the European Commission published its first formal review of the DMA, concluded the regulation was “fit for purpose“, and identified cloud computing and AI as the next priority enforcement areas.
Japan adopted a comparable law in 2024. Similar frameworks are being drafted in Australia, Brazil, Canada, and India. Open source projects, which are interoperable by default and have no incentive to lock anyone in, are the natural beneficiaries of every one of these laws.
Data you can actually take with you
The Data Act, applicable since September 2025, addresses one of the quieter forms of digital captivity: vendor lock-in through data hostage. If your factory runs on proprietary sensors, your customer data lives in a proprietary CRM, or your industrial process generates data that only the vendor can read, switching vendors means starting from zero. The Data Act requires providers to let users access, export, and reuse the data their devices and services generate.
For small and medium-sized businesses, this is the difference between trying a new analytics platform and being permanently captive to whichever one they picked first. Open formats and open standards are the only way to actually deliver portability, which is why the Data Act tilts the playing field toward tools built on them.
From rules to infrastructure
Regulations create demand. They do not, by themselves, create supply. Europe spent most of the last decade writing rules, and the past eighteen months recognising that rules alone will not produce a sovereign technology stack.
The EuroStack initiative, launched at the European Parliament in September 2024 and formalised in a Bertelsmann Stiftung report in February 2025, proposes 300 billion euros of investment over ten years to build European alternatives across the full stack: chips, cloud, AI, digital identity, public infrastructure. The Parliament’s industry committee backed the proposal in June 2025. At the November 2025 Berlin Summit on European Digital Sovereignty, member states endorsed seven strategic pillars for reducing technological dependency. The European Commission has since published its own Cloud Sovereignty Framework, and a Digital Commons consortium has been launched to coordinate public investment in shared digital infrastructure.
The EuroStack vision rests, by design, on open source and federated architectures rather than the construction of European hyperscalers in the American mould. Whether the funding will arrive at the scale the report calls for remains uncertain: the 2026 EU budget allocates one billion euros to the relevant programme, far below the levels proposed. But for the first time, European institutions have stopped pretending that regulating American platforms is the same thing as having alternatives to them.
The simplification test
There is a counter-current. On 19 November 2025, the European Commission published the Digital Omnibus, a legislative package proposing to amend the AI Act, GDPR, Data Act, ePrivacy Directive, and several cybersecurity laws in the name of competitiveness and reducing administrative burden. On 7 May 2026, Parliament and Council reached political agreement on the AI Omnibus component, postponing the application of high-risk AI system obligations from August 2026 to as late as December 2027 for stand-alone systems, and to August 2028 for high-risk AI embedded in regulated products such as lifts or medical devices, conditional on the availability of harmonised technical standards.
Defenders frame the package as housekeeping: harmonising overlapping definitions, giving standardisation bodies time to deliver workable specifications, easing the load on small businesses. Critics argue that the Omnibus quietly weakens the protections that made European regulation a sovereignty advantage in the first place. Among the loudest voices is NOYB, short for “None Of Your Business“, a Vienna-based privacy NGO founded in 2017 by the Austrian lawyer Max Schrems. Schrems is the activist who, almost single-handedly, dismantled the two successive treaties (Safe Harbor in 2015 and Privacy Shield in 2020) that authorised the transfer of European personal data to the United States. Both fell at the Court of Justice of the European Union, both in cases that bear his name (Schrems I and Schrems II), and both on the same grounds: US surveillance law and European fundamental rights cannot be reconciled by a piece of paper. NOYB has since become the most effective enforcer of the GDPR in practice, filing strategic complaints across the EU, and it has already announced that it will challenge the Digital Omnibus in the same way it challenged its predecessors. The redefinition of what counts as personal data, in particular, could allow much wider reuse of citizen data for AI training, and that is precisely the kind of clause that ends up in front of the Court.
The Omnibus is the test of whether Europe doubles down on its advantage or trades it away under industry pressure. Diluting the AI Act or the GDPR to mimic the American model is not a race Europe can win on those terms. The competitive moat lies in trustworthiness, transparency, and accountability, which are precisely the things that open source delivers natively and proprietary software has to manufacture. The open source ecosystem has the most direct stake in the outcome. Every clause that survives is a clause that continues to favour auditable, portable, sovereign software.
What to do about it
The mechanics are not mysterious. Organisations that depend on digital infrastructure should ask of every supplier, especially every American supplier, the same question Senator Wattebled asked. If the answer is not satisfactory, sovereign alternatives now exist, and the regulatory environment increasingly favours them. Developers contributing to open source projects build infrastructure that no foreign jurisdiction can unilaterally revoke. Investors funding open source companies and foundations support the only technology category that European law specifically rewards.
Supporting open source is not charity. It is the practical expression of digital sovereignty, and the period when it could be dismissed as an idealistic preference is ending. The regulations have done their part. Whether the next twelve months reinforce that advantage or trade it away for short-term simplification will determine which version of the digital decade Europe actually gets.
(CC BY-SA 4.0) Benjamin Bellamy