Funding FLOSS: Power, governance and the Global South
| Attachment | Size |
|---|---|
| GW26-NGI0-fudingFloss.pdf | 253.58 KB |
Website
Introduction
The free/libre and open source software (FLOSS) world is rich with examples of interesting contradictions. In this report we will talk about how the software itself may be free (as in free to use, study, modify and redistribute), but is far from free of power relations. A Harvard Business School study from 2024 estimates the demand-side value of open source software at USD 8.8 trillion, representing what it would cost if every organisation had to rebuild the FLOSS software they rely upon.1 That same year, a joint survey by the Linux Foundation, GitHub and Harvard University found that organisations worldwide contribute more than USD 7.7 billion annually to open source development, with 86% of this investment coming as employee labour rather than direct financial contributions.2
Nadia Eghbal’s report for the Ford Foundation framed open source software as “roads and bridges”, critical public infrastructure requiring ongoing maintenance.3 Yet unlike physical infrastructure funded through taxation, FLOSS funding remains largely invisible, voluntary and concentrated in institutions based mainly in North America and Europe. This concentration shapes who can take part in the digital world and whose needs are prioritised in technology design, and limits the technology’s transformative potential, essentially creating new forms of dependency.
This report examines the FLOSS funding landscape and its implications for the Global South. I will argue that current funding structures embed political and geographic priorities that often repeat, rather than challenge, colonial patterns of extraction and dependency.
The FLOSS funding landscape
FLOSS funding comes from several sources, each with overlapping and fuzzy motivations and geographic focus. Ordered by scale of contribution, these include corporate funding, government programmes, open source foundations, non-profits and collectives, individual maintainers, and international development organisations.
Corporate funding represents the largest source of FLOSS investment. Major technology companies employ maintainers directly, and according to a TODO Group survey, 77% of large organisations now maintain Open Source Programme Offices (OSPOs).4 A less-discussed aspect of this funding is what these companies provide in terms of in-kind services, whether through code development platforms like GitHub, or by providing cloud credit for infrastructure.
Government programmes have emerged as significant contributors, particularly in Europe. The European Union’s Next Generation Internet (NGI) initiative has supported over 1,400 open source projects since 2018.5 Germany’s Sovereign Tech Fund has invested more than EUR 23 million in critical digital infrastructure since 2022.6 However, NGI funding faced significant cuts in 2024, raising questions about long-term commitment.7 To my knowledge, there are no government programmes of comparable scope in Global South countries.
Open source foundations provide governance infrastructure and limited, often very targeted, direct funding for development. The Linux Foundation hosts over 700 projects.8 The Apache Software Foundation operates on a volunteer-dependent model, explicitly not paying for software development. Many open source foundations are themselves funded mainly through corporate membership fees, conference revenue and donations.9
Open source non-profits and collectives offer an alternative model. Worker-owned cooperatives like Igalia, a consulting firm headquartered in Spain, show that major FLOSS contributions can come from worker-organised workplaces without shareholders or external investors. Igalia is a major contributor to all three web browser engines and works on web standards at the W3C and TC39. In France, the non-profit Framasoft develops decentralised tools like PeerTube. These organisations show that FLOSS can be supported outside both unpaid volunteer labour and corporate employment, though they remain a smaller fraction of overall development.
Individual maintainers and projects often fund their own work. Many maintainers are freelancers or consultants who support FLOSS development through paid client work. According to Tidelift’s maintainer survey, 60% of maintainers remain entirely unpaid for their open source work.10 Small donations from individual users, while symbolically important, rarely provide sustainable income. Community platforms like Open Collective processed USD 12.5 million in contributions in 2024, though the organisation's board report suggests this amount depends partially on tech investment cycles rather than individual donors.11
International development organisations have started to embrace FLOSS through the digital public goods framework. The Digital Public Goods Alliance, hosted by the United Nations Development Programme (UNDP), promotes open source solutions for achieving the Sustainable Development Goals (SDGs), though direct funding through the programme has not yet materialised.12 A notable example for the Global South here is the Inter-American Development Bank’s Code for Development initiative, which offers over 200 curated as well as newly developed open source tools for Latin American and Caribbean governments.13
The geography of this funding reveals stark imbalances. While specific data on FLOSS funding geography is limited, the concentration of foundations, corporate headquarters and government programmes in the Global North is evident and suggests patterns similar to analogous sectors. A report by the #ShiftThePower movement found that only 7% of Organisation for Economic Co-operation and Development (OECD) support for civil society organisations is given directly to organisations in the Global South.14
Funding priorities are also shaped by funders’ own interests. For example, security concerns have driven significant investment following high-profile vulnerabilities like Heartbleed in 2014 and Log4j in 2021. Another interesting case can be found in the Python machine learning library scikit-learn, which revealed tensions when French government funding introduced digital sovereignty policy goals that were confusing to project maintainers and caused uncertainty about their dependence on government funding.15 The funders and their priorities shape what gets funded: security tools and cloud-native infrastructure, of major interest for corporations, receive major investment, while localisation, accessibility and offline-first applications, which are important for many users, including those in the Global South, receive far less.
How funding shapes participation, governance and power in FLOSS
Despite rapid growth in some regions, Global South participation in open source remains far below what it should be. On one hand, GitHub’s 2025 Octoverse report shows India, Brazil and Indonesia having around 33% compound annual growth rate over the last five years, with India on track to overtake the United States in total developer numbers.16 However, a look at a community-developed map of Global South contributions to GitHub indicates that contributions are lagging behind, with noticeable gaps suggesting that this growth is not uniform throughout the Global South, and that the highest number of contributions still come from Europe and North America.17
Multiple barriers limit participation – from infrastructure barriers such as unreliable electricity and low internet penetration, to economic barriers which include the opportunity cost of unpaid contribution and difficulties with international payment processing. When crowdfunding platforms or funding programmes require bank accounts that are unavailable, funding mechanisms simply do not work.
Participation in decision making and access to funders at major in-person conferences present another significant barrier. Events like PyCon, RubyConf and various foundation summits often require long international travel, visa applications that are often denied, and time and money commitments that are unaffordable for many Global South developers. When these events lack adequate remote participation options, or when key decisions happen in hallway conversations rather than accessible online forums, Global South voices are consistently excluded from shaping project direction.
The ideology of meritocracy, the belief that the best code and ideas will rise regardless of who they come from, has long been prevalent in open source culture, and is even sometimes suggested as good practice without closer examination. This embrace is historically ironic. Michael Young coined the term in his 1958 satire to describe a dystopia where elites believe they earned their position.18 Multiple critics have shown how open source “merit” often works as a stand-in for privilege. The Post-Meritocracy Manifesto makes the case that while meritocracy is the “founding principle of the open source movement,” it is never clearly defined, and “mainly benefit[s] those with privilege,” providing recognition for those who are similar to the incumbents – or the people in the movement with influence and power.19 Dries Buytaert, founder of the Drupal project, puts it equally bluntly: “open source is not a meritocracy” because free time is “a mark of privilege.”20 The appeal of the meritocratic ideal is precisely that it presents as natural and earned, when it is actually shaped by prior access to time, education and infrastructure.
For contributors from the Global South, these barriers intersect and compound. Unpaid labour is harder to sustain when economic circumstances are more precarious, and the cultural knowledge required to navigate English-language, Northern-male-dominated communities takes time that not everyone has.
Jullien, Viseur and Zimmermann’s analysis of FLOSS user types provides a framework that helps explain another important structural dynamic in commercial FLOSS.21 Users who lack the technical capacity to contribute code can only have their needs represented in project decision making by paying open source companies to participate on their behalf. These companies “act as a substitute” for users without coding skills. The result is a two-tier system in which voice in FLOSS governance flows to those with either technical capacity or purchasing power. Access to decision making follows capital, whether in the form of technical skills or money to hire those who have them.
The maintainer crisis intensifies these dynamics. According to Tidelift’s survey, 60% of open source maintainers remain unpaid, and 44% report experiencing burnout.22 The 2024 XZ Utils backdoor incident, in which a malicious actor exploited an overworked solo maintainer, illustrated the severity of this sustainability crisis.23 For Global South contributors facing additional barriers of infrastructure, language and limited time for unpaid work, these challenges multiply.
Corporations have never been shy about exercising their influence, as the 2025 RubyGems crisis most recently shows. In September 2025, Ruby Central removed long-standing volunteer maintainers from the RubyGems and Bundler projects without warning. Developer Joel Drapper documented how Shopify, which depends heavily on Ruby and employs several Ruby Central board members, pressured Ruby Central to seize control by threatening to withdraw funding.24
What emerges from this analysis is a governance structure that functions as a hybrid oligarchy built on stratified access. At one level, technical contribution earns voice, but the capacity for such contribution correlates with education, employer subsidy and economic security. At another level, those without technical capacity can purchase representation through intermediaries or governance capture. And at the base, those with neither coding skills nor resources to replace them have no mechanism for voice at all. Their needs are represented only when they happen to align with the needs of paying customers or technical contributors with the capacity to participate.
The pattern resembles older forms of extraction: the Global South contributes labour in the form of code, bug reports, translations and testing, while control over governance and the captured value remain concentrated in the Global North. While some Global South developers do participate in FLOSS governance, the numbers remain very low. Foundation boards, technical steering committees and core maintainer teams are overwhelmingly made up of developers based in North America and Europe.
Applying the typology of digital colonialism to FLOSS funding
Toussaint Nothias proposes a six-feature typology of digital colonialism: unequal concentration of power; violence and harm; extraction; dependency; cultural imperialism; and benevolence discourse.25 Applied to FLOSS funding, these features operate through funding's dynamics highlighted above. They shape who participates in governance, whose priorities are reflected, and whose labour is captured.
The most visible dynamic is concentration. FLOSS is available to everyone, but the governance structures that direct its development are not. As the preceding section argued, decision-making power accrues to those who contribute most, and the capacity to contribute is funded by technical and monetary capital. The openness of the code does not prevent this; if anything, it obscures it. This concentration enables extraction on an enormous scale. The USD 8.8 trillion in value from the opening paragraph of this report was framed by Harvard Business School as a "demand-side" value, representing what firms would spend if they had to rebuild the software they rely on. Under a different light, it represents the value that corporations derive from software maintained largely by unpaid volunteers.
The extraction here works through the capacity to operationalise and monetise open code: cloud platforms, software as a service (SaaS) providers and enterprise integrators, overwhelmingly based in the Global North. The subjects and effects of this concentration of power, as Nothias notes, “might seem primarily economic (private tech companies) and geographical (United States vs. Global South) [but] critiques often articulate how these inequalities intersect with a broader range of inequalities, particularly those shaped by gender, ability, race and immigration status.” Excluding Global South users and developers from participation and governance doesn’t only disadvantage their needs, as those often intersect with the needs of women and Black, Indigenous, people of colour (BIPOC) and migrant communities in Global North countries.
This extraction feeds dependency. When Global South countries adopt FLOSS solutions maintained by Northern foundations or companies, they escape proprietary vendor lock-in, but may find themselves dependent on the funding structures or cloud infrastructures that sustain those projects instead. If a foundation shifts its priorities or a corporate sponsor withdraws, dependent adopters have limited recourse. The dependency is softer than with proprietary software; FLOSS offers a theoretical exit, as the code can always be forked or copied. But forking requires exactly the "innovative-user" capacity that Jullien, Viseur and Zimmermann describe, and you can’t fork the underlying infrastructure.
These dynamics are reinforced by cultural patterns that rarely get named as such. English-language documentation, governance norms inherited from North American tech culture, contribution practices designed around Northern work patterns and time zones, definitions of merit that privilege coding output over community facilitation or localisation work: none of these are imposed through licensing terms. They emerge from who founded and funded the projects, and they persist because funding continues to flow to projects that operate this way. For Global South developers, navigating these norms is an additional unpaid cost of participation.
Governance exclusion persists despite contribution. Global South developers often remain "consumers not creators" of governance decisions: even when they contribute substantial code, they may find themselves excluded from the strategic decisions that shape project direction. Capacity extraction compounds this when talented developers are absorbed into Northern organisations, transferring knowledge outward without building local institutional capacity.
Perhaps the most interesting feature, and the one most relevant to a report on funding, is benevolence discourse, and I’m going to discuss two angles here. Open source software that functions as critical global infrastructure is often treated as the voluntary output of individual enthusiasts, and because it is voluntary, no obligations can arise. The "I am not a supplier" position26 articulated by Depierre is an understandable protest against corporate demands on FLOSS maintainers’ unpaid labour, where often corporate users of FLOSS expect infrastructure-grade responsibility from contributors with hobbyist-level resources.
But it is the unfunded status that creates the impossibility. If maintainers were funded as infrastructure workers, the question "does this serve users in the Global South?" would be ordinary, the way we ask whether a road network reaches rural communities. It is only unanswerable because nothing in the hobbyist maintainer's situation – no funding, no mandate, no governance structure – creates a reason to ask it. Technical capital absolves itself of its responsibility to the Global South twice: first, by not funding the software, therefore ensuring no obligations arise, then again by framing the result as generosity, the gift economy, the voluntary commons, which makes the absence of obligation look like a feature rather than a failure.
FLOSS funding then layers its own benevolence on top: digital public goods, government open source programmes and corporate sponsorship all speak the language of inclusion and public benefit. This framing, while not necessarily insincere, obscures the structural dynamics described above. Funders set priorities, funded projects reflect funder needs, and the language of inclusion coexists comfortably with practices of exclusion. Questioning the terms on which something is given “freely” is framed as ungrateful.
To be precise about what is being claimed: FLOSS is not colonial in the way proprietary software can be, but FLOSS funding is. The colonial element enters at the governance layer, and FLOSS’s governance is captured through its funding, or lack thereof.
Toward equitable futures
FLOSS offers genuine transformative potential for the Global South: it can challenge extractive intellectual property regimes, enable local adaptation and reduce vendor lock-in. Yet these possibilities remain constrained by the funding, infrastructure and governance dynamics described above.
Decolonising approaches offer starting points for rethinking FLOSS funding structures. Jimenez and colleagues have used the Andean philosophy of "Buen Vivir" to argue that technology development should be governed by community needs rather than institutional priorities,27 while Zubler and colleagues have proposed organising principles for decolonised IT governance based on the African philosophy of Ubuntu.28 Neither framework was developed with addressing the fundamental issues with FLOSS funding at this scale in mind, but the governance problems they describe are recognisable in the dynamics outlined above.
I will provide concrete recommendations that emerge from this report. But the reforms outlined below, while worthwhile, address symptoms rather than causes. They may reduce harm while more fundamental changes remain a long way out. Their effectiveness, and likelihood to be implemented, will depend on pressure and work from those currently excluded rather than goodwill from those who benefit from the current structures.
For Global South governments:
- Establish sovereign FLOSS investment funds with multi-year public budgets dedicated to:
-
Paying local maintainers of critical digital infrastructure
-
Supporting localisation, accessibility and offline-first adaptations
-
Funding participation in upstream governance and standardisation bodies
-
Building domestic institutional maintenance capacity.
-
- Embed effective contribution requirements in public procurement by:
-
Requiring vendors that rely on FLOSS in public contracts to contribute financially or technically to upstream projects
-
Mandating open standards compliance and maintainability documentation
-
Including local co-maintainership or governance participation as contractual criteria.
-
- Support non-commercial production models by:
-
Funding worker cooperatives, non-profits and community collectives producing FLOSS
-
Creating tax incentives or grants for mission-driven digital infrastructure development
-
Providing public infrastructure (hosting, legal support, payment providers) to reduce dependency on Northern platforms.
-
- Develop South-South funding mechanisms that pool resources intra-regionally and reduce reliance on Northern intermediaries.
For Northern funders:
- Work towards global equity in FLOSS funding portfolios by directing funding to institutions and maintainers based in the Global South without using Northern intermediaries.
- Fund governance participation as infrastructure, including:
-
Compensation for time spent in governance roles
-
Translation and multilingual documentation
-
Travel or remote participation infrastructure.
-
- Tie funding outcomes to measurable governance diversity targets, including geographic representation in decision-making bodies.
- Publish annual geographic breakdowns of funding allocation and governance representation to create transparency around concentration patterns.
- Prioritise funding for maintenance and community health, not only innovation and security features.
For corporate users of FLOSS:
- Commit a percentage of FLOSS-dependent product revenue to upstream maintenance funds, particularly for critical infrastructure projects.
- Fund independent maintainer collectives and regional institutions, not only foundation-controlled structures.
- Support geographically distributed maintainership, including paid roles in underrepresented regions.
- Disclose corporate influence within foundation governance structures, including transparency reporting on board participation and funding dependency ratios.
For FLOSS communities:
- Adopt geographic representation requirements for boards and technical steering committees.
- Create compensated maintainer pathways for contributors from underrepresented regions. Programmes like Outreachy29 demonstrate that structured entry points work, but there must also be viable pathways to becoming a maintainer beyond working for corporate FLOSS.
- Recognise non-code contributions (localisation, documentation, facilitation, community care) as equal in standing to code contributions.
- Shift governance processes toward asynchronous, multilingual decision making, reducing reliance on in-person conferences and hallway decision making.
- Publish funding source transparency reports, including dependency ratios on single corporate sponsors.
- Use measurable community health indicators, such as those developed by the CHAOSS project, to track progress toward equitable participation.30
Conclusion
FLOSS funding is not neutral. It embeds political choices about which projects matter, which contributors are valued and which needs are prioritised. Current structures largely repeat North-South imbalances despite the liberatory rhetoric that has long accompanied open source advocacy. The geographic concentration means that Global South communities often receive software without the capacity building, governance participation or institutional support that would enable genuine digital autonomy.
The USD 8.8 trillion in value that corporations extract from open source software is produced in significant part by unpaid labour. FLOSS as currently organised depends on a pool of unwaged or underpaid workers whose output is captured by others. The burnout crisis, the governance exclusion, the geographic concentration of power: these follow from an arrangement that works extremely well for those who benefit from it.
The Global South faces both genuine opportunities and new forms of dependency. FLOSS can challenge extractive intellectual property regimes, enable local autonomy and build technical capacity. Yet without fundamental change to funding and governance structures, FLOSS risks replicating the colonial dynamics it might otherwise challenge, namely extracting labour and knowledge from the South while concentrating control and captured value in the North.
Equitable FLOSS ecosystems aren’t likely to emerge from existing structures through incremental reform. That will require building alternative institutions, shifting resources toward Global South capacity, and sustained work from those currently excluded. Whether FLOSS can deliver on its transformative promise at all, or whether that promise turns out to be an empty husk that only serves to legitimatise continued extraction, remains to be seen. The answer depends not on the goodwill of those who benefit from the status quo, but rather on the organising power of those who do not.
Notes
This report was originally published as part of a larger compilation: “Global Information Society Watch 2026 special edition: Free/libre and open source software: Visions of openness from the Global South"
Creative Commons Attribution 4.0 International (CC BY 4.0) - Some rights reserved.
Web and e-book
ISBN 978-92-95113-91-6
APC-202607-APC-R-EN-DIGITAL-384
Print
ISBN 978-92-95113-92-3
APC-202607-APC-R-EN-P-385
- 1Hoffmann, M., Nagle, F., & Zhou, Y. (2024). Value of Open Source Software. Harvard Business School Strategy Unit Working Paper No. 24-038. https://papers.ssrn.com/sol3/papers.cfm?abstract_id=4693148
- 2Boysel, S., et al. (2024). 2024 Open Source Software Funding Survey. Linux Foundation, GitHub, & Harvard University. https://opensourcefundingsurvey2024.com/
- 3Eghbal, N. (2016). Roads and Bridges: The Unseen Labor Behind Our Digital Infrastructure. Ford Foundation. https://www.fordfoundation.org/work/learning/research-reports/roads-and-bridges-the-unseen-labor-behind-our-digital-infrastructure/
- 4Hendrick, S., & Jiménez, A. (2024). The 2024 State of OSPOs and Open Source Management. TODO Group & Linux Foundation. https://www.linuxfoundation.org/research/ospo-2024
- 5Next Generation Internet. (2025, 20 June). The future of Internet: From digital sovereignty to strategic autonomy. https://ngi.eu/news/2025/08/04/from-ngi-to-the-open-internet-stack-charting-the-next-chapter-in-europes-digital-future
- 6https://www.sovereign.tech
- 7Henning, M. (2024, 18 July). Next Generation Internet: EU apparently set to end open source programme. netzpolitik.org. https://netzpolitik.org/2024/next-generation-internet-eu-apparently-set-to-end-open-source-programme
- 8https://www.linuxfoundation.org
- 9https://www.apache.org
- 10Tidelift. (2024). 2024 State of the Open Source Maintainer Report. https://www.sonarsource.com/the-2024-tidelift-maintainer-impact-report.pdf
- 11Open Source Collective. (2025). 2024/25 Board Report. https://opencollective.com/opensource/updates/2024-25-board-and-strategic
- 12https://digitalpublicgoods.net
- 13https://knowledge.iadb.org/en/code-development
- 14ShiftThePower. (2023). Too Southern to be Funded: The Funding Bias Against the Global South. https://globalfundcommunityfoundations.org/wp-content/uploads/2024/04/TooSouthernToBeFunded.pdf
- 15Osborne, C. (2024). Public-private funding models in open source software development: A case study on scikit-learn. arXiv. https://arxiv.org/html/2404.06484v1
- 16GitHub. (2025). Octoverse 2025. https://github.blog/news-insights/octoverse/octoverse-a-new-developer-joins-github-every-second-as-ai-leads-typescript-to-1
- 17https://gayanvoice.github.io/top-github-users/index.html
- 18https://en.wikipedia.org/wiki/The_Rise_of_the_Meritocracy
- 19Ehmke, C. A. (2018). The Post-Meritocracy Manifesto. https://postmeritocracy.org
- 20Buytaert, D. (2019, 10 April). The privilege of free time in open source. https://dri.es/the-privilege-of-free-time-in-open-source
- 21Jullien, N., Viseur, R., & Zimmermann, J. (2025). A theory of FLOSS projects and open source business models dynamics. Journal of Systems and Software, 224. https://www.sciencedirect.com/science/article/abs/pii/S0164121225000512
- 22Tidelift. (2024). Op. cit.
- 23 https://en.wikipedia.org/w/index.php?title=XZ_Utils_backdoor&oldid=1341068798
- 24Drapper, J. (2025, 23 September). Shopify, pulling strings at Ruby Central, forces Bundler and RubyGems takeover. https://joel.drapper.me/p/rubygems-takeover
- 25Nothias, T. (2025). An intellectual history of digital colonialism. Journal of Communication, 75(5). https://academic.oup.com/joc/advance-article/doi/10.1093/joc/jqaf003/8078024
- 26Depierre, T. (2022, 31 December). I am not a supplier. Software Maxims. https://www.softwaremaxims.com/blog/not-a-supplier
- 27Jimenez, A., Delgado, D., Merino, R., & Argumedo, A. (2022). A Decolonial Approach to Innovation? Building Paths Towards Buen Vivir. The Journal of Development Studies, 58(9), 1633-1650. https://doi.org/10.1080/00220388.2022.2043281
- 28Zubler, M.-E., Plattfaut, R., & Niehaves, B. (2025). Decolonizing IT governance in international non-governmental organisations: An Ubuntu approach. Information Systems Journal, 35(1), 163-208. https://doi.org/10.1111/isj.12541
- 29https://www.outreachy.org/
- 30https://chaoss.community