Sint Servaasbrug, Maastricht. Built 1280, in continuous use ever since — through wars, occupations, and every regime change the continent has seen. The argument for sovereign, maintainable infrastructure, made in stone.

Why this day exists

Two pressures are landing on boardrooms simultaneously: losing control to US big tech, and not knowing what AI actually means in practice. Most organisations address both with slogans. This day addresses them with running systems.

The AI Act, the Cloud Sovereignty Framework, and procurement rules pushing toward open-source options have moved sovereignty from a talking point to an obligation. Open source is Europe's instrument for breaking out of hyperscaler dependence — but that only matters when it shows up in something that runs.

„Sovereignty has to be realised in operational systems. Strategy decks only describe it. Running systems either enact sovereignthy, or they do not.“
Senior practitioners who lead successful Plone businesses for years across Europe.
So far confirmed:
  • Jens Klein / Klein & Partner
  • Alexander Pilz / syslab.com
  • Stefano Marchetti / RedTurtle
  • Guido Stevens / Quaive
  • Timo Stollenwerk / kitconcept
  • Jörg Zell / interaktiv

What you will take home

  • A decision framework for vendors, platforms, and dependencies — the questions to ask before signing and the exits to keep open after.
  • A practical AI checklist covering value, risk, governance, and accountability, usable in the next steering meeting.
  • Real examples from public institutions and enterprises that have worked through these questions in production, including the trade-offs they accepted.
  • Next steps you can explain internally — without jargon, without a vendor in the room.

Explore and Connect with others during the day

Morning Program

Digital sovereignty

Platforms that have already done what strategy documents only promise: outlasted a procurement cycle, survived a political term, remained maintainable. European institutional platforms running on open source for nearly two decades — long enough that sovereignty becomes a track record, not a claim.

  • Long-running deployments — keeping an institutional platform alive and trusted across more than a decade.
  • Software reuse across administrations — how European agencies share and adapt the same open-source base instead of buying parallel proprietary stacks.
  • Operational sovereignty — the difference between owning a licence and owning the capability to keep the system running on your own terms.
  • Procurement and vendor exit — contracts and architectures that make switching partners a practical option, not a theoretical one.

Afternoon Program

AI in practice

Practical AI inside organisations that cannot afford to be wrong in public. Not wrappers around hyperscalers. Not demos. Systems already in production, where AI respects access controls, audit trails, and the boundaries the organisation already enforces for good reasons.

  • AI behind permission boundaries — assistive features that respect existing access controls and retention rules rather than routing around them.
  • AI in regulated environments — what works, and what quietly fails, under GDPR, the EU AI Act, and BSI Grundschutz.
  • Value, risk, and accountability — how to tell a useful AI initiative from an expensive one before the budget is committed.
  • Honest limits — where current models help, where they mislead, and which decisions should not be delegated yet.

Who this day is for

People who carry the weight of digital decisions in organisations that cannot afford to start over every three years.

IT and digital leaders

  • Heads of IT in public-sector and regulated organisations.
  • Digital strategy and procurement leads navigating vendor consolidation, exit planning, or sovereign-cloud requirements.
  • AI-governance roles responsible for translating the AI Act into systems that actually behave.

Universities, public agencies, foundations, and research organisations

Institutions plan in decades. Vendors plan in funding rounds. That asymmetry is the quiet source of most digital risk — and it is the question this day is built around.

Join Us in September

Friday, 25 September 2026 · Maastricht, Netherlands

Part of Plone Conference 2026. Open to decision-makers — no prior Plone knowledge required. Write to us for a direct note when tickets and programme details go live.

Considering a talk?

Every slot is a piece of the audience's day and must earn its place. We want talks that lead with the client's problem, show a real system that has survived contact with reality, and stay high-level enough for a CEO or head of IT to follow without knowing Plone.

Talks are around 30 minutes. No company tours, feature inventories, or speculative AI claims without a running system behind them.