The News

The final day of Open Source Summit Europe 2026 in Prague featured a keynote lineup that covered the intersection of AI, open source governance, and public sector technology strategy. Speakers included Madeline from the Valkey project, who examined how AI agents make undisclosed infrastructure choices that may bypass open source software; Ryen White from Microsoft, who addressed open source supply chain security and the EU Cyber Resilience Act; Dr. Laura Dornheim, Chief Digital Officer of the City of Munich, who recounted the city’s long arc from Microsoft to Linux and back again, and its current strategy of using open source as a cost-reduction and sovereignty tool; Julia, who introduced the AI Flow Foundation’s emerging framework for mapping AI capabilities to codified IT activities; and a fireside chat with Linus Torvalds, who shared candid views on AI-assisted coding, Git’s origins, and the Linux development model.

Analyst Take

The AI Agent Blind Spot Is a Governance Problem, Not a Technical One

Valkey’s finding that one in six AI agents, when asked to build a cache, will simply build their own from scratch rather than selecting an established open source tool exposes a systemic risk that most organizations are not yet measuring. The agents aren’t hallucinating in the traditional sense. They’re making coherent architectural decisions based on incomplete or miscalibrated context, and those decisions can carry real consequences for license compliance, long-term maintainability, and vendor neutrality. The fix Madeline demonstrated, adding explicit open source licensing requirements to context files, almost seems too simple, but it requires someone to know the problem exists in the first place.

This is the governance gap that the industry is not yet taking seriously enough. AI-assisted development is accelerating rapidly. According to ECI Research’s Google GovTech Survey, 49.6% of respondents selected “26% to 50%” when asked what percentage of their organization’s code they estimate will be assisted or generated by AI within the next 12 months. At that scale of AI-generated output, the infrastructure and dependency choices embedded inside that code become a material risk surface. If agents are defaulting to proprietary or poorly-governed libraries because no one told them otherwise, organizations will accumulate technical and legal debt silently, at velocity.

Munich Shows the Real Battle Is Political, Not Technical

Dr. Dornheim’s account of Munich’s open source journey deserves more attention from technology strategists. The city spent a decade migrating 15,000 workstations to Linux and LibreOffice, then reversed course in 2014 due to a political coalition shift. They have now rebuilt an open source commitment through a more durable, policy-first approach. Her core argument is that open source initiatives in the public sector don’t fail because of technical inferiority; they fail when they aren’t anchored to the political agenda of whoever controls budget decisions. The Munich playbook now includes a formal procurement default favoring open source, an internal development team that publishes all code publicly, and a mechanism for contributing to external projects via a funded open source sabbatical program. The VMware-to-alternative migration, saving approximately one million euros annually, and the pending Jira/Confluence-to-OpenProject/XWiki transition, saving more than half a million annually, are the kinds of concrete economic outcomes that survive coalition changes.

This framing has direct relevance to the government technology market broadly. ECI Research’s Google GovTech Survey found that 35.3% of respondents selected “Evaluation criteria favor low-cost legacy vendors over modern technology solutions” when asked about the primary limitation of standard government procurement vehicles. Munich’s approach sidesteps that structural bias by embedding the open source preference into procurement policy rather than fighting it deal by deal. That’s a replicable model, and it’s one that commercial open source vendors should be studying closely.

Torvalds on AI: Useful Tool, Dangerous Shortcut

Linus Torvalds’s remarks on AI were characteristically direct and more nuanced than the headline-friendly quotes that tend to circulate. His position is that AI is genuinely useful for experienced developers who understand what correct code looks like and can direct the tool accordingly. His guitar pedal UI example illustrates the point well: he knew the underlying C implementation was right, he knew JavaScript was outside his skillset, and he used AI specifically to bridge that gap rather than to replace his own judgment about correctness. His caution about using AI for “real and important” projects reflects the same instinct as Madeline’s maintainer analogy: you are ultimately responsible for the code, and you cannot hand off that responsibility to a tool that won’t push back.

The governance data reinforces why this distinction matters at an organizational scale. According to ECI Research, 31.8% of respondents selected “FedRAMP/compliance approval friction for AI vendors” when asked about the single largest blocker preventing widespread AI adoption in developer workflows. For government and regulated-industry buyers, the question isn’t whether AI coding tools work; it’s whether the outputs can be validated, audited, and attributed clearly enough to satisfy compliance requirements. That’s a problem that neither the tools nor the governance frameworks have fully solved. Microsoft’s contribution to the EU Cyber Resilience Act discussion, specifically the Orbit Launchpad Working Group’s machine-readable due diligence baselines and the Privateer project for evidence validation across 106,000 open source dependencies, points toward infrastructure that could eventually address this. But it is infrastructure that is still being built.

Looking Ahead

Who is responsible for the choices AI makes on your behalf? Valkey’s maintainers are asking this question at the infrastructure layer, Munich is asking it at the procurement layer, the AI Flow Foundation is trying to create a shared vocabulary for it at the industry layer, and the Linux kernel community is negotiating it in real time as AI-generated patch submissions stress the maintainer workforce. The organizations that move fastest toward a clear internal answer to that question, backed by policy, tooling, and governance, will have a structural advantage over those still treating AI adoption as a purely technical decision.

Over the next 12 to 18 months, expect the CRA-driven supply chain transparency work to become a template that spreads well beyond Europe. Microsoft’s decision to share its full dependency graph with ENISA and co-chair an open working group for machine-readable compliance baselines is a competitive play as much as a policy response. Vendors that can demonstrate automated, auditable compliance lineage across their open source dependencies will have a procurement advantage in regulated markets worldwide. The open source community has built the kernel of that infrastructure; the race now is to standardize it before proprietary alternatives fill the vacuum.

Authors

  • Paul Nashawaty

    Paul Nashawaty, Practice Leader and Lead Principal Analyst, specializes in application modernization across build, release and operations. With a wealth of expertise in digital transformation initiatives spanning front-end and back-end systems, he also possesses comprehensive knowledge of the underlying infrastructure ecosystem crucial for supporting modernization endeavors. With over 25 years of experience, Paul has a proven track record in implementing effective go-to-market strategies, including the identification of new market channels, the growth and cultivation of partner ecosystems, and the successful execution of strategic plans resulting in positive business outcomes for his clients.

    View all posts
  • With over 15 years of hands-on experience in operations roles across legal, financial, and technology sectors, Sam Weston brings deep expertise in the systems that power modern enterprises such as ERP, CRM, HCM, CX, and beyond. Her career has spanned the full spectrum of enterprise applications, from optimizing business processes and managing platforms to leading digital transformation initiatives.

    Sam has transitioned her expertise into the analyst arena, focusing on enterprise applications and the evolving role they play in business productivity and transformation. She provides independent insights that bridge technology capabilities with business outcomes, helping organizations and vendors alike navigate a changing enterprise software landscape.

    View all posts