For a long time, open source occupied an ambiguous place in the European discourse: celebrated in declarations, marginal in budgets. The sovereignty package of 3 June 2026 changes at least its status: the Union's open source strategy features as one of its four pillars, on a par with semiconductors, cloud and AI. The logic is solid: digital commons offer complete transparency over the technology stack, reduce proprietary lock-in and allow the innovation effort to be pooled. Faced with closed platforms subject to third-party laws, open code is the only dependence you can audit, fork and host yourself. Once the sources or the weights are obtained, no foreign decision can withdraw them.
What July showed: openness as a strength…
The July incident, paradoxically, argued for openness as much as against it. It was thanks to open-weights models that the victim's teams were able to decrypt the attacker's payloads and reconstruct the timeline — a forensic capability that no closed API, subject to quotas and terms of use, would have guaranteed at the worst moment. And it was the disclosure culture proper to the open ecosystem that produced, within a few weeks, the most detailed technical post-mortem ever published on an incident of this kind: a timestamped chronology, reconstructed actions, documented methods. The entire community learned from the attack. A closed player would have published four paragraphs.
… and as an attack surface
But honesty requires looking at the other side. An open platform, designed to accelerate external contributions, structurally exposes more surface than a walled garden: public repositories, evaluation pipelines, third-party components — indeed, it was an exposed, vulnerable third-party infrastructure component that served as the entry point. The incident has become a central exhibit in the open source AI policy debate: proponents of control see it as proof that the diffusion of powerful capabilities must be restricted; proponents of openness, as proof that collective defence only works through transparency. Both camps are right on one point: openness without investment in security is an unfunded promise.
The European condition: funding the commons
This is where the European strategy will be decided. Open source only becomes a pillar of sovereignty on three conditions. One: fund the maintenance and security of critical components — not just innovation, the plumbing. Failures almost always come from obscure building blocks maintained by three volunteers. Two: build a European capability for auditing and responding on the commons (code review, systematic SBOMs, CVEs handled at the speed required by the Cyber Resilience Act). Three: public buyers must own a preference for open solutions where they exist, turning the discourse into an order book.
Neither illusion, nor givenOpen source is not sovereign by nature — an underfunded common is a dependence like any other, with one point of failure fewer and one maintenance orphanage more. It can be made sovereign: that is an investment decision, not a property of the code.
The answer to the title's question is therefore conditional. A pillar, yes — if Europe treats it as infrastructure to be maintained. An illusion, certainly — if it keeps treating it as a free resource to be consumed.