More Open Source Security episodes

Sovereign Tech Agency with Erik Moller thumbnail

Sovereign Tech Agency with Erik Moller

Published 31 Aug 2026

Duration: 36:17

"Explores the Sovereign Tech Agency's efforts to sustain open-source software as critical infrastructure, emphasizing public investment, digital sovereignty, and strategic funding for projects like *curl* and AI security."

Episode Description

Josh chats with Erik Moller from the Sovereign Tech Agency about what they're doing. The Sovereign Tech Agency is doing some amazing work around fundi...

Overview

The podcast discusses the importance of open source software as critical digital infrastructure, emphasizing the need for sustained public investment to ensure its security, maintenance, and sovereignty. The Sovereign Tech Agency, representing German public interest, focuses on funding essential open source projects - like curl - through initiatives such as the Self-Integ Fund, which supports widely used technologies vulnerable to underfunding or overreliance on individual maintainers. The discussion highlights structural gaps in current funding models, where corporate-backed projects may overlook broader public needs, and stresses the necessity of treating open source as foundational infrastructure akin to roads or bridges.

Additional programs aim to strengthen digital sovereignty by increasing public participation in global standardization processes and improving the resilience of open source ecosystems. The Standards Network Program supports maintainers in engaging with standards bodies like W3C and ISO by covering costs and providing mentorship, addressing barriers such as high fees and time commitments. Other efforts include security audits, post-quantum encryption planning, and compliance support under the Sovereign Tech Resilience Program. The conversation also underscores the irreplaceable role of human oversight in maintaining secure systems, especially in light of AI advancements, and advocates for open, reproducible, and vendor-neutral AI development to ensure long-term technological sovereignty.

What If

  • What if you applied for sovereign tech funding to harden your open-source project's security?

    • Move: Identify one critical open-source tool in your stack that you maintain or rely on heavily, then prepare and submit an application to the Sovereign Tech Resilience Program for a security audit or post-quantum migration support.
    • Why Now?: The Sovereign Tech Fund is actively expanding its resilience services and accepting applications; recent incidents show urgent need for human-led security hardening before AI-driven attacks scale.
    • Expected Upside: Receive funded access to expert auditors, improve your project's trustworthiness, and increase adoption - especially by public institutions seeking cyber-resilient software.
  • What if you joined a standards body with financial and mentorship support?

    • Move: Apply to the Standards Network Program to represent your open-source project in a relevant SDO (e.g., W3C, IETF), using their stipend and travel coverage to participate in shaping interoperability standards.
    • Why Now?: The pilot program is currently onboarding fellows, and structural barriers (cost, time) are being actively subsidized - this is a rare window for solo developers to influence foundational tech governance.
    • Expected Upside: Gain direct influence over standards that affect your project's ecosystem, avoid future vendor lock-in, and position your tool as a reference implementation.
  • What if you positioned your AI-related open-source project as critical infrastructure?

    • Move: Audit your AI toolchain for reproducibility and vendor neutrality, then apply to the Sovereign Tech Agency as a candidate for funding under the "sovereign AI" category, emphasizing its role in reducing dependency on closed models.
    • Why Now?: Governments are prioritizing AI sovereignty due to geopolitical risks and recent AI safety failures; non-reproducible AI is now a recognized systemic vulnerability.
    • Expected Upside: Secure public funding to decouple from proprietary stacks (e.g., NVIDIA, cloud APIs), enhance long-term maintainability, and attract contributors aligned with open, verifiable AI.

Takeaway

  • Apply for funding from the Sovereign Tech Agency if your open-source project is critical to digital infrastructure, widely used, and under-resourced, by preparing a clear proposal outlining impact, technical plan, and resource needs.
  • Propose or participate in a fellowship program to secure sustained financial support for focused development or community management work on your open-source project.
  • Engage with standardization bodies (e.g., W3C, ISO) through programs like the Standards Network, leveraging available stipends and travel support to influence standards relevant to your project.
  • Request a security audit, bug bounty, or compliance assessment for your open-source project via the Sovereign Tech Resilience Program to improve maintainability and meet regulatory requirements like the Cyber Resilience Act.
  • Advocate for and contribute to open, reproducible AI infrastructure by prioritizing vendor-neutral, auditable models and tools in your development work, especially when building sovereign or public-interest technology.

Recent Episodes of Open Source Security

17 Aug 2026 Maintaining EOL Open Source with Commonhaus and HeroDevs

"Explores open-source maintenance challenges, solutions for solo maintainers, and the role of organizations like Common House and HeroDevs in sustaining projects through financial, legal, and administrative support, emphasizing governance, dependency management, and enterprise-community collaboration to ensure long-term sustainability."

10 Aug 2026 Cleanup, Speedup, Levelup open source at e18e

"E18e enhances JavaScript by reducing dependencies, optimizing tools, and improving security, as seen in its work with Storybook, while promoting cleaner code and community collaboration."

3 Aug 2026 VulnCheck's State of Exploitation Report with Patrick Garrity

"Cybersecurity vulnerabilities are being exploited faster (80-day average), AI is both a tool and target, disclosure practices are inconsistent, and better coordination, transparency, and proactive patching are critical to mitigating risks."

27 Jul 2026 Securing critical infrastructure with Josh Corman

"Cybersecurity faces escalating threats to critical infrastructure, requiring stronger OT security, IT-OT collaboration, proactive threat modeling, and resilience engineering to prevent real-world disasters."

20 Jul 2026 Abandoned open source with Josh Marpet

"Outdated vendor risk management processes, plagued by misrepresented questionnaires and slow vulnerability disclosures, demand faster, proactive security measures and greater transparency in open-source software."

More Open Source Security episodes