Jean-Baptiste, you swear by open source. But at the end of the year, studies showed that there were 10 trillion lines of code being used mainly by the big tech companies – Google, Amazon, Meta – and that maintaining this code within the ecosystem is becoming increasingly difficult. Is this a reality or not?
Jean-Baptiste Kempf. – “Yes, that’s the reality. In fact, as you start to build up so many layers, nobody realises what’s going on underneath. You’re building a website, you use NPM. NPM uses Node, Node uses other layers, which in turn use the Linux kernel. Take all the AI stuff: you’ve got AI agents using frameworks that call VLLM, which runs on top of CUDA, which calls other layers that run on top of the driver. People don’t realise how complex it is.
These days, even when you’re just deploying a small website, you end up downloading gigabytes and gigabytes of data. The result is that you’re downloading thousands and thousands of packages. And many of those packages are managed by just one or two people. It’s a real maintenance issue on a global scale. If it’s no longer maintained, you have to carry out updates because everything is constantly evolving. But there are also security issues that are very troublesome.
How do we solve the problem? Can we solve this problem?
“Yes, we can solve the problem. For a start, we need to invest more money in the areas that are a bit less visible.
Who should pay?
“I think it’s pretty much everyone. In fact, there are organisations like the Linux Foundation, Apache and the Open Source Collective. In Germany, there’s the Sovereign Tech Fund, a government agency. There’s also talk of setting up a Sustainability Tech Fund in Europe. The idea is to take a look at everything that’s going on, provide some funding and pool resources. That would be good.
But given that big tech companies use this code to develop their own products, wouldn’t it make sense for them to be involved in this too?
“But they do. In fact, they do. Except that, in the past, they were a bit more involved in open source. Now, they tend to open-source their projects and focus solely on that. So there’s an issue regarding the common good. And then, as for people, we need to pay a bit more attention to what we use and stop using just anything and everything when building software architecture. Because there are going to be loads of security issues. It’s going to be a bloodbath.
And right now, are there already major security breaches?
“There’s the whole issue of security that’s currently being referred to as the supply chain. We need to take what’s known as the software supply chain a bit more seriously.
Could we be any more serious?
“Of course we can be more professional. It’s just that it often costs a bit more in terms of time and money.
If we look at Luxembourg, for example, they wanted to create an alternative messaging service to the major ones, called LuxChat. It’s important to be able to maintain it.
“Let’s say it would work if it had worked and if the ministers were disciplined. But as they aren’t, they use both their work phones and their personal phones at the same time. It’s the classic problem for security people: when you want to make something more secure, you have to make it more secure, but not less functional. We have the same problem in every country. We had the problem with Macron in France, who was using Gmail. It’s absolutely disastrous to do that. But at the same time, the alternatives cost money, because they have to be just as good.
That’s what I was saying on stage: building something like Gmail costs around a billion euros. Frankly, perhaps Luxembourg can’t afford to spend a billion on an email service, though I doubt it. But on a pan-European scale, it’s a joke. We should be making significant investments. But we need to do so in a ‘bottom-up’ way. We need to stop giving money to the big firms, the telcos, the big digital services companies that don’t know how to innovate. We need to start with small groups, create something collaborative, something based on open source that can actually achieve that.
When we talk about European sovereignty and the desire to reclaim that sovereignty, it will take a huge effort to perhaps achieve 40% sovereignty. Does this talk of sovereignty make any sense?
“Firstly, I think that when it comes to software, we can aim for much more than 40 per cent. There’s no reason why not. The problem does indeed exist when it comes to microchips, particularly AI chips. But for everything else, it’s not a problem. We can achieve much more than that. And even if we only reached 40%, that would still be better than 2% or 10%. Because it also makes American and Chinese players realise that they can’t raise their prices as they please. It’s not just a question of sovereignty or data security. It’s also a question of competition. If I no longer have any alternatives, everything costs more.
And is all this realistic? What should we do?
“We should invest money and stop buying only foreign solutions. This is an issue that affects both citizens and businesses. At the outset, you sometimes have to take a risk. It won’t be as good as the dominant solutions, but that doesn’t matter. The important thing is to reinvest money in the European tech ecosystem. Obviously, all this is happening on a European scale. The sums involved are huge, but relative to the size of Europe, they aren’t that much after all.
Earlier on stage, you mentioned one billion for the ten items on the left of your slide and ten billion for each of the other four. That makes 50 billion. What is the total budget?
"50 billion over five years.
So, what do we end up with?
“Alternatives on virtually every subject.
Are there any alternatives that are just as functional and offer a user experience comparable to what we have today?
“Yes, especially because there’s this thing called AI, and nowadays we can code much faster thanks to AI. Five years ago, I would have told you it was much more expensive. Today, things have changed.”



