Video summary
Leon Schumacher, a seasoned entrepreneur and former CIO with deep experience in cybersecurity and digital assets, opens his keynote by redefining the concept of sovereignty not as nationalism or the construction of digital walls, but as essential business continuity. He argues that true sovereignty means maintaining operational capability when external vendors, governments, or platforms alter their rules unexpectedly. To illustrate this vulnerability, he points to the Huawei ban caused by US restrictions on Android, the weaponization of financial infrastructure during the Ukraine war, and the unpredictability of US policy under potential future administrations. These events demonstrate that access to technology and payment systems is increasingly conditional, making open-source solutions a critical form of insurance against geopolitical risks and ensuring that organizations can continue functioning without relying solely on foreign permission.
The discussion then shifts to the complexities introduced by Artificial Intelligence, where traditional notions of open source are challenged by the nature of model weights and data rather than just code. Schumacher highlights how major players like OpenAI have shifted from openness to restriction once they developed frontier models, while simultaneously noting that the current AI landscape is dominated by Chinese companies who offer powerful, cost-effective alternatives that effectively perform a "land grab" outside the United States. He uses the example of Google's Gemini altering historical data to show how these systems can subtly reshape truth and history, raising critical questions about who should control the intelligence defining our reality. Furthermore, he critiques Anthropic for releasing models only in the US under national security pretexts, leaving the rest of the world without access to cutting-edge technology and proving that the internet is no longer borderless when it comes to AI deployment.
A significant portion of the talk addresses the European Union's struggle with digital sovereignty, particularly regarding payments and the Digital Euro. Schumacher praises initiatives like AP Vero for countering dependency on Visa and Mastercard but criticizes the European Central Bank for ignoring open-source strategies in its procurement processes despite public demand for privacy and security. He notes that the ECB's Request for Proposals effectively excluded innovative small companies by setting revenue thresholds too high, thereby stifling the very innovation needed to build a resilient future-proof system. While acknowledging the complexities of the Digital Euro's online and offline systems, he emphasizes that Europe possesses all the necessary components—such as Mistral for AI and sovereign clouds—to lead in this space but currently fails to integrate them into its strategic infrastructure due to bureaucratic blind spots and a preference for large incumbents over agile startups.
In his concluding remarks, Schumacher urges European leaders and investors to move beyond creating strategies on paper and to take concrete actions that support open-source projects and sovereign digital infrastructures. He warns that relying solely on big players or proprietary black boxes leaves Europe vulnerable to future disruptions, whereas embracing open-source ecosystems offers a path to independence and resilience. The core message is that sovereignty requires having fallback options and the ability to adapt when circumstances change, much like buying insurance. He calls for immediate investment in European AI providers and open-source solutions to set global standards rather than following American or Chinese dictates, asserting that Europe has the opportunity to make a difference if it acts decisively to secure its digital future against an increasingly unpredictable global landscape.
Read the full video transcript
Happy to be here. You hear me? Okay.
Like that. Mic is good.
Thank you for open forum Europe. Thank
you Mar for the invitation.
Uh my name is Leon Schumacher.
I grew up in the corporate world. Was a
former CIO of Arsloal the large shield
company and of Novartes the large Swiss
farmer group. then became an
entrepreneur in cyber security, privacy
and payments each time with open-source
solutions.
I've been quite involved in central bank
digital currency work
and now I'm advising on digital assets,
AI and related subjects to cor
corporates and governments and in when I
have a few minutes in between I'm
writing some books on those subjects as
well. So, you can find those on Amazon
if you're interested. But first, listen
to what I'm telling you before you go
buy the book.
Well, let me start with saying that I'm
a huge fan of what Mr. Kleiner from the
European Commission said in the first
keynote.
I am also a huge fan of the Luxeber
football team, which will go undefeated
in this World Cup.
>> So, I only hope that Mr. Kleiner will
score more points than the Luxembbergish
team.
But today I want to talk about
sovereignty and open source. So
sovereignty is defined as the supreme
power of a state to govern itself and to
make laws without external interference.
But for me sovereignty is not
nationalism.
I would not mean it should not mean
building digital walls.
I think sovereignty for me is business
continuity.
It means continuing to operate when a
vendor, a government or a platform
changes the rules.
It means having a solution to continue
paying when Trump tells Visa and
Mastercard to get out of Europe.
So open source is one of the best ways
to buy insurance against these risks.
So how did we get to this space where
sovereignty suddenly has become so
important?
For me there's three points basically on
the timeline that I think are important.
I think the first one for me is the
Huawei ban. So the Americans banned
Huawei away from using Android, Google's
Android system and that basically
basic stopped the sales of their
handsets. And so the Android dependency
became a strategic vulnerability for
Huawei in that case. That was a while
back. Not that many people noticed
unless they had a Huawei phone that
could no longer be updated.
Of course, then came the Ukraine war and
we saw that financial infrastructure
became a geopolitical weapon.
And last, as was already mentioned
twice, came Mr. Trump and US
unpredictability
where Europe had to realize that it is
so dependent on US infrastructure
that it's extremely risky uh the
position that it finds itself in if the
Americans turn out to be less reliant
than they used to be.
So these examples are not extract. They
showed that access to technology and to
payment
can become conditional.
So, and the same applies to AI and AI
makes the whole topic even a little bit
more confusing I find.
So, we we have all these
names in AI. Claude, Fable, Metos, O4,
Sonet, Project Glass, Swing, Jet GPT,
Sora, Nano, Banana, Gemini, X402,
AP2, ACP, MPP, and I could go on for
another 10 minutes, but uh let's try to
keep it at that. So while traditional
open source meant you can take the
source code, you can read it, you can
run it, you can modify it and you can
redistribute it. AI makes that harder
because
the code base is small and you cannot do
anything with it. I as you you need the
weights and if you look at the meta
slamma 2 model which was composed of two
files one a small one with 500 lines of
code. So even if you have can read those
500 lines of code you could not do
anything with the other file which was
about 140 GB of parameters which
included the weights.
So with AI it's even the open source
copy becomes more complicated. So it has
the source codes, the weight, the data,
the training recipes, usage restrictions
and so forth
and the open weights
open source does not mean open weights,
right? That that's an important thing to
to keep in mind. But for this talk here,
when I talk about open, I mean practical
sovereignty. So can we inspect, run,
adapt, replace or continue the system
without asking somebody else for
permission.
Now the confusion continues
by the naming of the key AI player open
AI founded around openness and benefit
to humanity.
As soon as they got some frontier
systems, they became very very closed.
So no no no more sign of openness.
Some point down the road because they
took a lot of for that they release
an open weight model of medium
capacity.
So do they think that makes them open
again or can we classify that as open
washing? And so uh we we had Meta,
Facebook,
amazing that they were the leader of uh
releasing open-source AI models for a
while. They took a lot of criticism for
that because everybody said, "Oh no,
you're giving uh critical information to
the Chinese and they use military and
for surveillance and and so forth. We we
should definitely not do that." And then
we had an interesting twist there today.
If you look at the open source
leaderboards for AI, it's basically 95%
Chinese companies, Quen, Deepc, Kim,
GLM, and and nothing else. So, it's
interesting how these things change over
time and what was so strongly criticized
on one hand two years later has no
connection to reality anymore.
So what what we can take from that is
that open source today is not leakage
from the the frontier models. It's
actually an ecosystem formation. The
best open building blocks attract
developers, tools, benchmarks,
standards. Whoever provides the best
open building blocks shapes the
ecosystem. And I think that's the idea
also that the Chinese have by providing
that if we can do a land grab everywhere
outside the
United States offering it for free or
that price point that is very different
from the frontier AI models but at 99%
of the capacity we think that's that's
the play here. So the real question is
not only whether a model is American or
Chinese. I think the real question is
who owns the intelligence, who defines
the guard rates and who can change the
system without us noticing.
We have seen already how the tuning
choices can shape outputs in politically
sensitive ways.
Some of you certainly remember the
Google Gemini eliminating all white men
from history.
So if that had been done a little more
subtle, would anybody have noticed?
And that points to the power of these
systems
uh who shall be providing our source of
truth because those systems will replace
the internet as the source of truth in
the future. Who do we want to entrust
entrust that power?
Google was a little blump so uh the pope
became black and and similar things but
it it shows that
those systems can change history change
change the truth that the people rely on
as they move forward.
So then let let me move on to Antropic.
Antropic was founded by former AI people
open AI people to focus more on safer
frontier models. So they wanted stronger
regulations. So some people said okay
that's because they want more safety.
Critics says no they wanted to have
regulatory capture the the governments
making it so difficult for other people
to enter the space and uh protect the AI
space for Anthropic of an AI and a few
others.
They certainly have most likely the best
model today. So on April 7, Entropic
announced Claude Mitter's preview as
being too dangerous to be released to
the public. It's going to hack us all.
It's going to be the end of the world.
We cannot release it. We have it. Just
be impressed. We are the best, but we
cannot give it to you. And so it was
then shared with a selected group of
cyber security companies and banks uh
but only in the US with the thought that
okay we allow these important players to
improve their situation before we
release this to the public. That was
nice for the Americans but that left all
the rest of the world out in the cold.
So once this thing came out if I'm
European bank well
not great not great. So then it became
even more interesting.
So that the original version there, the
preview came out on April 7th. So on
June 9th, uh, Entropic released Fable
Mythos. So the the official release of
of that version that was tuned down to
be safe, but that the US government
found that it was not good enough and
cited national security concerns over
potential jailbreaks
that could bypass the model safeguards.
And so they ruled that the model could
not be given to non-Americans.
interesting
entropy then
although they got the government
protection they wanted but maybe not
exactly the way they wanted uh was in a
tough spot because they couldn't
guarantee the nationality based
restriction. So they ended up pulling
the mo models completely.
So the core lesson is we can have models
that are available one week and they are
unavailable the next or product can
become a national security asset and
then just be available to to a certain
group of companies and global access
becomes nationality restricted.
The internet and the cloud it was sold
to us as borderless
but the kill switch clearly is not
borderless.
So,
so then what what does sovereignty mean
in in in in this environment?
For me, it means having options when the
access changes, having the ability to
continue operating
having a fallback model, a fallback
provider, a fallback cloud. It doesn't
mean to me that okay, in order to have
sovereignty, I have to have everything
Luxembourgish. or the chips, the the
cloud on the software, the the network,
whatever. We will never get to that.
We'll get to that by the time I I'll be
long dead. But uh I think we we need to
look at it from a business continuity.
What do we do if somebody pulls out the
piece? Can we keep running? Uh and that
that's the the way we we need to
organize
ourselves to be ready because it will
not it's not free. You it's like buying
insurance. It's not free but you're
happy when you have done it if disaster
strikes.
So that's also why the European
Commission, the European Commission's
technology, technological sovereignty
agenda is so important, including the
open-source strategy that they launched
in early June. public money, public
code. I immediately subscribe to that
and I think that should be the default
for any physical infrastructure uh that
we roll out.
If the public funds
strategic digital infrastructure, the
public should not be locked into a black
box forever.
And Europe understands this sovereignty
element already in payments and has been
acting on it but not without blind
spots. So we clearly saw the Visa
Mastercard dependency. So AP Vero was an
early
project that tried to counterbalance
that. The digital euro is clearly going
in that direction. The Italians just
blocked the takeover of Nexi, a payment
provider from uh the venture capitalist
CBC.
The UK is also doing a project to copy
Vero and and and do something similar.
And uh if if we talk about the digital
euro for two seconds, it's it's the most
confusing project I've seen
because every question you asked can be
answered in two different ways with yes
and no and you're both correct.
That's pretty cool.
And that's because there are two systems
and there's an online and an offline
system that have very different
characteristics
and privacy security tradeoffs.
So does the digital euro offer privacy?
Online, no. Offline, yes. So if you
don't specify the online offline, you
can say yes or no and still be correct.
>> Is it secure online? Yes. as secure as
any other accountbased system offline.
No, it cannot be mathematically secure
which gives it a terrible starting point
despite the 800 million that ECB is
investing to prove that they are smarter
than the law of mathematics.
So
the digital euro should become one of
Europe's most critical infrastructures.
But the European Commission open source
strategy has not found its way to the
ECB's procurement department
open source was not mentioned in the
five RFPs with which they are spending
1.3 billion euros not mentioned nowhere
not once and I think open source should
be central not marginal in in
initiatives like that
and then we look at okay the citizens
priorities
privacy was the top requested feature.
Security was second used throughout the
EU third and then low fees was was
fourth. And even if we look into the
open source community, you you find
solutions that are much better designs
than what they're currently trying to do
in Frankfurt. Uh GNU Tower is open
source, offers payer anonymity, merchant
auditability.
Uh it's all open source. it it has uh
security reviews that are published and
out there. The system has been through
the regulator in Switzerland and is in
operation in Switzerland starting to
bring on merchants and and users but
it's of course difficult as a small
startup to to make that happen. It's
future proof. It's quantum resistant. It
can do microtransaction and so forth.
And uh the European Commission uh the
the European Central Bank had probably
eight talks with Tyler before the RFPs
came out. But in the RFPs, they
eliminated all the innovative small
companies by saying, well, if you want
to talk to us, we are the ECB. If you
don't have a 100 million in revenues, we
don't talk to you. So only the big
friends are allowed to to participate.
No matter that everybody knows that the
innovation comes from the small players,
not from the big players, but that also
the ECB had uh not understood yet.
So that brings us to to the next blind
spot and I'm trying to keep an eye on
the time.
We have the sovereign payment
initiatives throughout pushing hard
spending lots of money from 700 million
on on Vero and
1.3 billion on the digital euro.
AI agentic payments are the next thing
that comes. The McKini said up to 5
trillion in 2030 which is the same
amount than the card payments in Europe.
Not a single European officials official
or politicians has updated the world's
sovereign and AI agentic payments in the
same sentence. So we will again miss the
boat there. Although as Europe we have
all the pieces that are needed. We could
say look let's let's bring the AI guys
in. Mistral is a pretty good example for
for a European AI provider. Tala could
bring the machine oriented payments up
to microtransactions quantum proof and
so forth.
If you take those two sovereign clouds
exist in Europe, bring that together and
you can basically set the standard
there. Today 15 standards have been
proposed all America, Coinbase, Google,
Stripe, Mastercard, Visa and and so
forth. So that that's one area also
where where we are missing missing the
boat. So I will close here with say
Europe has the asset. Many of them are
open source. we have the opportunity
basically to to make a difference and
we need to take action. I think it's not
enough that that we have nice strategies
and nice slides like uh the European
Commission brings out they need to lead
something and the actions need to follow
the words because as I can tell you from
the startups that I see in open source
life is difficult when it comes to
fundraising. If you're open source and
you want to raise funds, that is
extremely hard and challenging. So if
any of you sit on extra funds that you
want to invest in interesting opensource
projects, just let me know. I'll tell
you where to go. And with that, I stop
and hand it back. Thank you.