European companies are embracing open-source AI to achieve AI sovereignty and avoid foreign supplier lock-in. A report from the European Commission revealed that over half of European developers regularly rely on open models, datasets and tools. A report on European Competitiveness by former Italian Prime Minister Mario Draghi goes further, stating that true tech independence can be achieved only when companies retain control of their data and infrastructure instead of handing it over to big tech and foreign monopolies. And data from IDC confirms this thinking, as it reveals that up to 88% of enterprise AI proofs-of-concept stall before production due to governance, data readiness and infrastructure costs.
Most of the reluctance among European executives (and politicians) is driven by an entrenched security myth: the belief that proprietary and closed-source AI provides better security than open alternatives. This was debunked decades ago in software and continues now in the AI age. It feels like many seem to have forgotten the basics of cybersecurity. Locking AI infrastructure behind closed interfaces only increases security risks. If researchers can get access to model weights via open-source, they can test vulnerabilities and create safeguards faster, while leaving control to just a handful of vendors hides critical vulnerabilities until a major breach occurs.
Join The European Business Briefing
New subscribers this quarter are entered into a draw to win a Rolex Submariner. Join 40,000+ founders, investors and executives who read EBM every day.
SubscribeWhen these security misconceptions influence legislative debates, political discussions risk leaning towards market protectionism over genuine safety considerations. Regulatory structures that are too rigid in nature and built around large-scale frontier technology labs will put companies into an ecosystem where there is no freedom of choice. A broad coalition of technology companies and open-source proponents, which signed the “Open Weights and American AI Leadership” letter, agrees that such measures will have a negative effect and hamper competitiveness.
Most recently, privacy issues on closed ecosystems caused headlines. A proprietary laboratory announced that it cracked a Millennium Prize math problem that was unsolved for 90 years, however, at the same time, a mathematician claimed to have solved the same problem using the same proprietary company’s tool. This sparked debate and concerns about data sharing with closed AI models. Do companies that own closed AI models read the data you input? In this case the proprietary laboratory claimed that they don’t. However, a closer look at major providers’ T&Cs reveals that these companies cannot guarantee that users’ data would not be used in future versions of their models. That’s why users have to be careful when using closed models and perhaps use open models when it comes to handling sensitive information.
Apart from security issues, closed models are increasingly failing to live up to expectations. They are more expensive and offer diminishing returns for enterprises. General models achieve a maximum effectiveness of 70% on specialised tasks, but enterprise deployment requires at least 90% effectiveness. Bigger pre-trained models will not solve this problem. The true solution is to train small open models on enterprise-specific data for each business process.
Specialised open models present another crucial advantage: the ability to have hardware and computing independence. Relying on a single vendor’s chip ecosystem or cloud monopolies creates unsustainable overhead for growing businesses; whereas open-weight architecture enables companies to deploy their models on alternative hardware platforms. Moving away from closed ecosystems also saves processing costs because open-weight solutions are significantly more cost-effective. Studies show that deploying specialised open models reduces ongoing inference costs by up to 87% compared to closed models. These benefits also enable everyone to develop local AI solutions in their own native languages, built for their culture and ecosystem, rather than trying to fit a vendor’s culture and language into yours.
While these are operational benefits, there are increasing regulatory requirements for which open-source developers need to plan ahead of time. While the new compliance requirements from the EU AI Act and California AI Transparency Act might be seen as an operational burden on the largest model providers, it is a win for consumers who will now be able to easily distinguish whether they’re served AI or human content, specifically when it comes to images, audio and video.
What does this mean for open source, though? Starting in 2027, platforms covered by the California Act that do not include the required latent disclosures may be prohibited from distributing weights or source code for generative AI models. Similarly, on a European level, the EU AI Act’s new transparency update also explicitly requires open-source generators to embed machine-readable metadata and publish training data summaries.
Whereas US federal regulators are not restricting open-source AI at the moment, companies in Europe have to function within the framework laid out by the EU AI Act. Rather than seeing this as a disadvantage, early compliance with EU regulations becomes a unique strength for European companies. Operating on compliant open models guarantees that sensitive corporate assets remain secure, allowing European businesses to use AI without interruption and without regulatory hurdles.


































