Back to blog

Eclipse Foundation: open-source sovereign AI governance

Article created on October 2, 2026 · Publication analysed: September 30, 2026 · Source: Eclipse Foundation

The Sovereign AI Foundation, announced in Brussels by the Eclipse Foundation, does not make an AI system sovereign through membership alone. It does put the decisive work in focus: making dependencies visible, comparing open alternatives and creating shared practices to regain control of an AI chain.

1. What was announced

On September 30, the Eclipse Foundation launched the Sovereign AI Foundation, a vendor-neutral initiative initially bringing together 17 organisations. Its stated objective is to help members understand AI dependencies, assess open-source alternatives and turn shared expertise into practical guidance.

This is a coordination and guidance initiative, not a certification, sovereign cloud or compliance guarantee. Organisations must therefore distinguish the existence of an open-source project from the actual properties of its deployment.

2. Open source is a capability, not proof

Open weights or a free software component can improve auditability, adaptability and reversibility. They do not alone answer where inference occurs, who has administrative access, how the software supply chain is secured, or how data, support and continuity are controlled. Hidden dependencies — APIs, embedding models, registries, telemetry and connectors — often determine the real level of control.

3. What changes for a Belgian or French company

For an SME, mid-market company or public body, the useful signal is to turn “sovereign” into a verifiable inventory. For each use case, identify the model, version, licence, supplier, data, processing country, runtime, RAG components, MCP tools, technical identity and replacement procedure. This discipline supports both Belgian and French enterprise-AI requirements and public procurement.

In Odoo Belgium, Odoo France or Odoo Enterprise, an agent can use an open model while still exposing data through a connector, logging system or excessive permissions. Control must include the ERP, extensions, secrets and recovery procedures, not just the model.

4. Underside analysis: govern a replaceable chain

The value of this initiative is that it moves the conversation from a label to the ability to choose. A credible architecture allows an organisation to replace a model, rehost inference, export indexes and logs, and prove who can trigger an action. That substitutability must be designed before production, because it becomes costly once business flows and RAG corpora are locked in.

Access policies, human approval and financial limits must also remain outside the model. An agent may prepare a proposal in Odoo or a business tool; it must not thereby gain the authority to approve an accounting entry, payment or deletion.

5. A practical approach

Start with a dependency register and data classification, then test an exit scenario: replace the model, cut an external supplier, restore a RAG index and revoke an agent identity. Measure quality, cost, latency and retained evidence. These exercises make autonomy observable rather than declarative.

Priority: assess sovereign AI by the ability to inspect, replace and govern every link — model, data, runtime, connectors and identities — using documented exit tests.

Assess a sovereign AI architecture

Read the official source