Fostering a collaborative culture between Open Source and the legal department
From home appliances to advanced automotive systems, Open Source Software (OSS) has become a fundamental pillar of modern industry. While OSS is typically available without licensing fees, it is not free of obligations; licenses impose specific legal requirements that must be met, and collaborative development within communities and foundations is governed by strict legal frameworks.
Establishing common ground
Consequently, from initial adoption to active contribution and strategic management, engaging with the legal department is a critical step rather than a mere formality. To make this collaboration efficient, both technical and legal teams must establish a common base of understanding regarding the Open Source ecosystem, licensing models, and the management tools used within the organization.
Vladimir Slavov, Senior Open Source Officer at Bosch Digital and a member of Bosch’s Open and InnerSource Program Office (OSPO), recently explored these dynamics in his presentation at EuroPython 2026 in Kraków, titled “How to Talk with Your Legal Department About Open Source”.
Establishing this common ground requires an active effort to see things from the other’s perspective. For legal teams, this means understanding why developers want to collaborate externally, which sometimes involves sharing company intellectual property (IP) under an Open Source license. For technical teams, it means grasping the specific obligations of different Open Source licenses and why certain terms may be incompatible with specific business models. This shared understanding serves as a solid foundation when communicating with other key stakeholders, such as business experts and executive management.
Navigating obligations
Open Source licenses are special because they do not restrict the use of the software, nor do they require payment of licensing fees. Instead, they rely on a system of obligations that can range from a simple contributor’s attribution to the requirement to share derivative source code under the same license terms (known as copyleft). These obligations are typically triggered when the software is distributed to a third party. Depending on the commercial context, some licenses may not be suitable. For example, if a company is developing a proprietary product, it cannot easily integrate components under licenses that require derivative works to be made fully Open Source. This does not imply that using Open Source is inherently risky, but rather that it must be managed systematically. In this environment, the legal department acts not just as a compliance gatekeeper, but as a strategic business partner.
Automated Open Source tooling at Bosch
This strategic partnership is a concrete reality at Bosch, where legality and technological innovation are deeply intertwined to support robust Open Source governance. Rather than relying on manual compliance checks, this collaborative alliance leverages automated Open Source tooling to manage license obligations at scale across all products and services. This proactive, tool-driven approach drove the initial incubation of what has now evolved into the Eclipse Apoapsis Project — a highly scalable server implementation of the OSS Review Toolkit (ORT) that has grown into a thriving Open Source community.
Vladimir Slavov, Open Source and Software Management Consultant at Robert Bosch GmbH
Vladimir is a lawyer and a programmer. He works at Bosch's Open Source Program Office, focusing on Open Source management and compliance.
He is an AWS Certified Solutions Architect Associate, an AWS Certified AI Practitioner, and an AWS Certified Cloud Practitioner. He co-chairs the OpenChain Meridian 22 Work Group, and is a committer on the Eclipse Apoapsis Project.