You’ve Been Selling Open Source Wrong
Most Australian technology leaders have spent the last decade selling open source to their boards as a cost play: lower licensing fees, less lock-in, faster iteration. The pitch worked. Open source is now in the cloud infrastructure, the container orchestration, the data pipelines and the security tooling, and it arrived through a budget conversation rather than a control one. Nobody asked what came with it, because that was not the question on the slide.
Europe has now asked. The European Commission’s proposed tech sovereignty package, covered in detail by Risky Business, includes an Open Source Strategy that treats open source as sovereignty infrastructure rather than procurement efficiency. The aim is to reduce European dependence on the US tech stack by institutionalising open source across government, reforming procurement rules and funding projects directly. That is not a CIO trimming a software budget. It is a geopolitical bloc deciding it needs to own its own digital foundation, and building a governance model to match. Most Australian enterprises have no such model.
Governing It Is Not the Same as Using It
Adoption is easy, which is the whole problem. Someone pulls a library, a framework, a runtime. It deploys. It works. No procurement request is filed and no risk register is touched. That is convenience, and it has been passing for strategy for years.
Governance is knowing what is in the stack, who maintains it, under which licence, with what dependencies underneath, and what happens to your operations if that project is abandoned, compromised or forked into irrelevance. It means holding a Software Bill of Materials, and it means someone has actually looked at whether a critical component is maintained by a well-funded foundation or by one volunteer with a GitHub sponsors page and a full-time job elsewhere.
Very few Australian enterprises can answer those questions about their production systems. That is the consistent finding whenever an organisation goes through a serious supply chain review — which most only do once a regulator, an insurer or an incident forces the issue.
The XZ Utils backdoor in 2024 showed how this fails in practice. A patient actor spent years building trust with the maintainer of a critical compression library, then put a backdoor into something distributed almost everywhere. A Microsoft engineer found it while chasing a performance oddity. It was luck. Nobody was watching, because watching was not anybody’s job.
The Sovereignty Reframe Changes the Governance Calculus
Treat open source as a cost strategy and governance reads as overhead. Why spend money managing the thing that was supposed to save you money? Treat it as a sovereignty position and the calculus inverts, because nobody deploys critical infrastructure without asking who built it, who maintains it and who could get to it. We accept that reasoning instinctively for physical assets and lose it entirely for software.
If the EU is prepared to treat open source dependency as a question of national control, the reasonable question for Australian organisations in critical infrastructure, financial services and government is whether they understand their own dependency position well enough to decide anything about it.
CPS 234 requires regulated entities to manage information security risk in their supply chain. The SOCI Act imposes resilience and security obligations on critical infrastructure operators. Neither mandates SBOM practices in terms. Both create liability for an organisation that cannot demonstrate it knows what its critical systems are built from, which makes open source governance a compliance obligation in all but name.
The Advice Your Preferred Suppliers Won’t Give You
The commercial vendors on your preferred supplier list have a quiet interest in your open source posture staying ungoverned.
Not knowing what open source sits in your stack makes honest comparison impossible. You cannot weigh total cost of ownership, and you cannot compare dependency risk across the two. That suits anyone selling the idea that commercial software is the safer and more accountable option — including the many commercial products built substantially on the same open source components.
There is a second thing they will not say plainly, and it cuts the other way. Open source has a real accountability problem. Buy commercial software and you have a contract and somebody to ring at two in the morning. When a critical open source project is abandoned or quietly compromised, you have a mailing list and an unanswered GitHub issue. That asymmetry is genuine. Governance is what closes it; procurement cannot.
What Should Change
The EU package will probably not reshape global technology supply chains in the short term, and Risky Business is right to say so. The reframe underneath it is already happening, though, and organisations still carrying open source as a cost line are behind the conversation.
Start with how it is presented upstairs. Open source is a control and dependency position, not a saving. What matters is what you depend on, who controls it, and what the exposure looks like if that control moves — which is a board-level risk question and reads perfectly well as one.
Then build an SBOM for the critical systems. No regulator has explicitly demanded it yet. The reason to do it anyway is that you cannot govern what you cannot see, and every serious conversation about supply chain risk starts by asking what is in there. Auditors and insurers are already asking; the regulators will not be far behind.
Beyond that, assess critical dependencies the way you would any other third party. Who maintains this? Is it funded? Is it one person? What is the contingency if it goes unsupported? Procurement asks all of these about a $200,000 vendor without blinking. The same questions are somehow exotic when the component is free and load-bearing.
The Debt Is Already Accruing
Europe’s strategy is a signal rather than an instruction. Australian organisations are not bound by it. The logic holds regardless, and the gap it exposes is real enough.
What most organisations are carrying is governance debt, accumulated quietly because the cost conversation was easier to have than the control one. It gets more expensive to unwind the longer it sits, and the cost is not measured in licences. It is measured in regulatory scrutiny, in unmapped exposure, and in dependence on decisions made by people who have never heard of your organisation.