1 minute to read

Why open source matters more for your commerce strategy than ever

Why open source matters more for your commerce strategy than ever

Open source used to be a debate about philosophy, developer preference, or licensing. Today, AI, data governance, and growing concerns about vendor lock-in are turning it into a strategic business question. For commerce leaders evaluating their next platform, that raises a practical issue: how much control do you want to retain over your data, infrastructure, and future technology choices? This article looks at why that question is moving up the agenda – and what it means for commerce platform decisions.

On July 24, 2026, an open letter titled "Open Weights and American AI Leadership" went out with 25 corporate signatures on it. Within a day it reportedly had around 50, including NVIDIA, Microsoft, Meta, IBM, Dell Technologies, Palantir, and Hugging Face.

The letter is about AI policy, not commerce. But the argument underneath it has been arriving in commerce procurement conversations for two years, usually phrased less grandly: how much of this can we actually control?

What the letter says, and what it does not

The letter, authored by NVIDIA CEO Jensen Huang, argues that open models strengthen cybersecurity, accelerate innovation and competition, expand access across industries, and support national sovereignty. It draws a direct parallel to the open-source software movement of the 1980s, and it asks policymakers to avoid premature restrictions on downloadable models.

Two things are worth noting, because they are usually lost in the summary.

First, the letter positions open models alongside closed frontier models, not instead of them. It is not a rejection of proprietary software. Anyone citing it as one is misreading it.

Second, it is a policy document from companies with commercial interests in the outcome. That does not make it wrong. It does mean the interesting signal is not the argument itself, which has been made for 30 years, but who is now willing to sign their name to it.

The convergence, briefly

Microsoft's Satya Nadella made the case the same day the letter went out. His framing is the one most relevant outside the policy world: open weights let organizations build without training from scratch or paying frontier prices, which promotes competition, reduces cost, and enhances customer control over their own data and models. He has described this as institutional sovereignty.

Mark Zuckerberg made a version of the argument in July 2024 in "Open Source AI Is the Path Forward," reaching for the same analogy the 2026 letter uses: Unix gave way to Linux, and the open stack ended up more advanced, more secure, and more widely supported.

Andreessen Horowitz came at it from competitiveness. Its April 2026 essay "Asserting American Leadership in Open Source AI" reports that 80% of developers building with open-source tools are using Chinese open-source tools, and that open Chinese models accounted for as much as 30% of all AI usage in some weeks of 2025.

Ben Horowitz on stage

Ben Horowitz, co-founder of Andreessen Horowitz, on stage at TechCrunch Disrupt San Francisco 2018. Source: TechCrunch, CC BY 2.0, via Wikimedia Commons.

Four different motives: security, innovation, customer control, and national competitiveness. One direction of travel.

Why a commerce leader should care

None of the above is about ecommerce. The translation is worth doing carefully rather than enthusiastically, because three of the arguments transfer and one does not.

Your operational data stopped being inert. Pricing structures, segmentation, approval logic, integration patterns, and support history used to be exhaust. In a market where software improves through exposure to how it is used, the same material has a second life. You do not need to assume bad faith on anyone's part for this to be worth a deliberate decision rather than a default one.

Switching cost is no longer the whole of lock-in. The classic version was migration effort: data, integrations, retraining. That version is at least estimable. The version that is harder to price is a system that continuously improves from your usage while you have no equivalent access to what it learned.

Transparency became a procurement requirement. Security review, data-governance review, and vendor-risk review are now routine at the size of business we work with, and "we cannot tell you how that works" is an increasingly expensive answer.

And the one that does not transfer: none of this means a commerce platform should promise you control over the model layer. That is a real distinction and worth being honest about. Shopware's native AI capabilities run as part of the product. What a merchant genuinely controls today is where the platform runs, what leaves it, and who can see it. That is a narrower promise than the policy debate implies, and it is the one that holds up.

What control actually looks like in a platform decision

Concretely, on Shopware:

One core, three deployment models. SaaS, PaaS, or self-hosted, built on the same Shopware core. The point is not that self-hosted is better. It is that the decision stays open. Merchants who need the ERP relationship close keep it close; merchants who would rather not run infrastructure do not have to.

An open-source core under an MIT license. Community Edition is open source and downloadable, and the paid plans build on that same core. You can read what runs your pricing rules.

European hosting and the certifications that get through procurement. Shopware's SaaS is EU-hosted in Germany and the Netherlands. The company is ISO/IEC 27001:2022 certified and GDPR compliant. These are not differentiators on their own. They are the things that stop being negotiable once a security review starts.

55,000+ merchants, 6,000+ extensions, a developer community of 100,000+. An open core is only worth something if enough people work in it that you are not the only one who can.

Beijer Ref grew ecommerce from 0.1% to 15% of revenue in 36 months while centralizing 200,000 products across 28 countries. Veolia Umweltservice, operating under waste-management regulation with 9,500 staff across 250-plus sites, built its self-service portal on infrastructure it specified. Neither was making a philosophical choice.

The honest limits

Open source does not make software secure. It makes it inspectable, which is not the same thing and is only worth something if someone inspects it.

It does not eliminate lock-in. Complex implementations are hard to move regardless of license. What it removes is the category of lock-in where leaving is not technically possible.

And it does not answer the AI question. The question of who processes what, under which terms, is a contractual and architectural question that the industry, Shopware included, is still working through in public. Anyone telling you it is solved is selling something.

What has changed is that the question now gets asked in the first meeting rather than the fifth, by the CFO rather than the architect. That is the actual news in a letter that 50 companies signed in a day.


Next step: If open architecture and deployment control are on your evaluation checklist, our team can walk through what that means concretely across SaaS, PaaS and self-hosted.

Get in touch

Copied to clipboard