Nearly one-third of European organizations lack formal open-source governance, according to the Linux Foundation’s new “State of open source in Europe” report. As a result, organizations are losing a lot of money, those with proper governance recoup 4.6 times their costs. Having a clear understanding of open-source software is also important for other reasons. For example, AI tools flood maintainers with bug reports, and if left unpatched, these can be exploited very quickly.
The report, now in its fifth edition, is based on a survey of 367 European organizations and interviews with maintainers and policymakers. It is sponsored by NeoNephos, the project the Linux Foundation launched last year to promote European digital sovereignty.
The results range from predictable to surprising. As many as 31 percent of European organizations have no formal policies regarding open source, 12 percentage points more than in the rest of the world. Among government organizations headquartered in the EU, that figure rises to 48 percent. Nevertheless, it pays to organize this properly. Organizations without governance recoup 3.6 times their costs, while those with a mature approach recoup 4.6 times their costs. There doesn’t seem to be much improvement, however. Last year, for example, it turned out that only 34 percent had a formal open-source strategy.
Europe also lags behind in the upstream community. Fifty-nine percent contribute code, but only 37 percent participate in project governance. And 48 percent maintain private forks, half of whom cannot say what that costs per release.
AI has a negative impact on maintainers
In addition, 94 percent use or test generative AI. As a result, nearly half are using more open source, while only 5 percent are using less.
Maintainers seem to be paying the price for AI usage. In the foreword, kernel maintainer Greg Kroah-Hartman writes that the number of Linux CVEs rose from an average of 55 to 230 per week. Tests conducted with students from VU University Amsterdam revealed that nearly half of the changes generated by LLMs were incorrect. “The burden of validation should lie with the submitter, not the recipient,” he states. A sense of responsibility to perform such checks before submitting a report does not seem to be common practice, or at least not mandatory.
AI does, however, help uncover genuinely dangerous vulnerabilities amid all the noise. The OpenStack security team has already issued 38 advisories this year, whereas previously a handful per year was the norm. Partly due to this growing series of critical vulnerabilities, the Linux Foundation founded Akrites in June, which facilitates the confidential remediation of cyber threats in critical projects.
2 billion versus 264 billion
The survey’s findings suggest that while the will is there, the path forward is not yet clear. Ninety-four percent consider digital sovereignty important, with security and privacy (71 percent) as the primary drivers. On June 3, the European Commission presented the Tech Sovereignty Package, including a 2-billion-euro Open Source Strategy over seven years. The authors contrast this with the 264 billion euros that the European public sector spends annually on IT. Without functioning Open Source Program Offices and enforced procurement rules, that amount looks like a rounding error, they argue.