Last week, I spoke at the Bremen Fast Forward AI Festival about why digital sovereignty is being decided anew today and what role open-source AI plays in this. Here, I have summarized my key points for future reference.
Digital Sovereignty Means the Ability to Control, Shape, and Switch
In 2020, the IT Planning Council described digital sovereignty as “the capabilities and opportunities of individuals and institutions to exercise their role(s) in the digital world independently, autonomously, and securely.” In practice, this boils down to three questions: Who is in control? Who can shape the outcome? And can we switch when conditions change?
For large parts of our economy and public administration, the answer to all three questions is unfortunately: not us. From office software to cloud operations, the systems that matter most are predominantly supplied by US companies. A study commissioned by the German federal government and conducted by PwC identified these dependencies as early as 2019 and recommended building alternatives. Too little has happened since then.
Meanwhile, we can increasingly see these dependencies being used to exert political or economic pressure: the blocked email accounts of judges at the International Criminal Court, VMware price increases of up to 1,500 percent, Ukraine’s temporary loss of access to important mapping data, and much more. These are unmistakable signs of our vulnerability to coercion.
This is happening at a time of steadily increasing geopolitical tension. Russia’s war against Ukraine continues. The United States, too, is seeking to pursue its objectives by every means, including military force, while the American IT industry remains a close ally of its government. Russia, the United States, and China share one important characteristic: none of them has an interest in a strong Europe capable of determining its own course.
Open Source Is the Key
Open source provides a path to digital sovereignty. Access to the source code creates transparency and opportunities for control, makes it possible to adapt systems to specific requirements, facilitates replacement, enables reuse and further development, strengthens resilience, and improves scalability.
Ironically, hyperscalers understand this as well and use open source across a wide range of areas. The political recognition is there, too: the coalition agreement commits to digital sovereignty and open source, the EU Tech Sovereignty Package marks an important milestone, and countries such as France, Italy, and the Netherlands are already taking decisive steps toward open software.
Whether open source becomes a binding requirement in procurement will be crucial to the success of this strategy.
AI Raises the Stakes
Moving from on-premises servers to the cloud significantly increased the critical importance of digital sovereignty, because software became subject to a much greater degree of external control. AI adds another layer of dependency.
Virtually all processes in business, public administration, software development, and communication are likely to be shaped by AI in the future. Anyone who relies exclusively on so-called frontier models from a handful of providers risks losing control over their own digital processes and surrendering the data they generate themselves.
Anthropic’s temporary loss of access to its models showed how quickly this can have tangible consequences. Whoever controls the AI platforms will increasingly influence decisions, knowledge work, and innovation.
Bias is another important concern. Models form assessments based on their training data and can therefore influence public opinion. A federal lawsuit against Workday was recently allowed to proceed in the United States. The provider is accused of using AI functions that systematically disadvantage applicants on the basis of their age, background, or disability.
What matters most is not simply that bias occurs, but that closed models make it impossible to determine or correct where it comes from.
What Open-Source AI Makes Possible
Open-source AI means that models can be used, understood, reviewed, adapted, and operated independently—not merely consumed. Yet “open” does not always mean the same thing. There is a significant difference between software that is open only for operating a model, model weights that are publicly available, and training data that is accessible as well.
Several advantages stand out. Organizations become less dependent on individual providers because they can operate and further develop models themselves while keeping their data in-house. Greater transparency makes it possible to identify security issues and bias independently by analyzing the training data. Open models also support broader competition by providing a shared foundation on which many companies can build.
Performance is another argument in favor of this approach. In terms of general capabilities, open models now trail the best closed models by only a few months in many areas. At the same time, they have reached a level that is sufficient for many productive applications.
We use this approach at Univention as well. All our employees have access to open-source AI, and we are gradually connecting more of our systems to it. This allows us to work with our internal data without handing it over to an external provider.
Implementation Is What Matters Now
Whether digital sovereignty matters is no longer the question. The issue is where to begin. A pragmatic starting point is any situation in which a decision is already pending – for example, when a new solution is being introduced or a contract is up for renewal.
These are the moments when an existing dependency is either extended for several more years or dismantled. It is also important to recognize that switching is rarely free: migration, integration, operations, and training all require money, time, and expertise.
Even so, the effort is worthwhile. Open source can change two important things: resources flow into building internal capabilities and creating value in Europe instead of into licenses whose prices are set by others. In addition, an open model cannot easily be blocked or shut down.
My appeal is therefore this: whenever AI is introduced – and in most cases, its introduction should be pursued decisively – organizations should also ensure that open models can be used, whether under their own control or in trusted data centers.