Free as a "free puppy".. nothing new here!
There's a piece going around right now with a headline built to make people like me flinch: "Open Source Costs NGOs More Than Commercial Software." It's citing a NetHope synthesis of 11 humanitarian AI deployments, and the line doing all the work is this one:
Open-source does not eliminate cost, it redistributes it. Licensing fees are replaced by coordination demands: maintaining codebases, documenting tools, onboarding contributors, and governing shared infrastructure. For resource-constrained NGOs, these coordination costs can equal or exceed the price of a commercial license.
The first sentence of that is right, and I'm going to concede it up front, because pretending otherwise is exactly the reflex that got the sector into trouble. The last sentence is a different animal and I'll come back to it.
Open source is a cost-reallocation strategy, not a cost-reduction one. The money didn't vanish when the license fee did. It moved off a vendor invoice and onto your staff calendar, where it's harder to see and much easier to underfund. That's the honest mental model, and if you've ever watched a tool die, you already know it in your gut.
Before anything else, go read where that quote actually sits. It's in the section titled What Works, under a heading that reads "Open-source transparency builds sector momentum." It's a caveat inside a finding in favour of open source. The report's recommendation to organisations scaling AI is to consider open-source and self-hosted options to reduce lock-in and costs. It praises NRC by name for self-hosting to protect its own data. And its actual verdict on why tools die is that the sector finances long-term infrastructure with project-cycle grants, "financing roads like meals." That's the document under the headline. The headline inverts it.
But ... careful which "sustainability" the examples are actually about, because the piece runs two very different questions together under one word. There's the sustainability of a tool as a going concern: who funds the codebase, the maintainers, the hosting, the governance, indefinitely. And there's the sustainability of a procurement decision: is this the right thing for this NGO to adopt and keep running. Those are not the same question, and the article's examples all answer the first one while the headline is pitched at the second.
OpenLMIS went hunting for a funding model and handed core maintenance to a commercial partner. DEEP shut down in 2024 when its grant cycle ended. Development Gateway keeps pointing out that treating open source as inherently sustainable misreads how technology lifecycles work. Every one of those is a story about a project's funding model failing. None of them is a story about an NGO that adopted the tool and found it more expensive than a commercial license. The examples prove "open source projects need someone to pay for them," which is true and .boring. They do not prove "open source is the more expensive procurement choice," which is the actual headline.. business-model fragility gets dressed up as a buyer's cost verdict.
And I, again, must be clear, The boring true version is still worth saying out loud, and it's what I do for a living: the UNICEF Venture Fund funds business models built on genuinely open solutions. Not "open sourced on delivery." What we're looking for is that the parts a government or an NGO would need in order to run, fork, or exit the thing are open, and that no single vendor sits on a chokepoint in the middle of it. That's the criterion, and I'm applying it to the article's proposed cure just as hard as I apply it to applicants.
So: yes. "We'll open source it" is not a sustainability plan. It never was. It's a licensing decision wearing a sustainability costume. If your proposal's sustainability section is one open source clause and a prayer, you don't have a plan, you have decoration.
but it's not just THIS confusion
Watch what the argument quietly does. It collapses the entire case for open source into total cost of ownership, and then declares open source the loser on the one axis it deliberately chose.
Openness buys things a commercial license structurally cannot, and none of them show up in a TCO spreadsheet -> Forkability. When the vendor dies, gets acquired, or triples the price, etc etc .. No lock-in, Auditability, The right to localise, Longevity past any single company. The code can outlive the org that built it. it doens't have to.. but CAN.
The DEEP example, which the piece uses against open source, actually cuts the other way. DEEP died because its funding ended. A proprietary tool with a dead funding line dies exactly the same death, except you also lose the source code and the option to revive it. Openness was the one thing that left a body you could still resuscitate.
The comparison is also rigged on cost itself. "Coordination costs can equal or exceed a commercial license" is a big claim carried entirely by the word can, with no numbers underneath it. Equal or exceed for whom, at what scale, over what horizon? Because a commercial SLA is not overhead-free either. You pay for vendor management, integration, procurement cycles, renewal negotiation, and the eventual forced migration when they discontinue the product out from under you. The piece meticulously prices one side's coordination tax and waves the other away.. perfect time to read the EU's study, where public sector case studies point the other way on total cost of ownership..
Vota's own fix is the OpenLMIS move: when the coordination tax gets heavy, hand maintenance to a commercial partner with an SLA. That recommendation still needs answering, and on the surface it sounds responsible. Someone's finally getting paid to keep the tool alive.
But I've spent enough time watching these handovers to have a name for how they go wrong: VCOSS, vendor-controlled open source solutions. It's the pattern where software gets handed to an NGO or a government "with IP" or "as open source," but one critical dependency stays quietly under the vendor's control. The auth layer. The "integration layer." The hosting. The bit that makes the rest actually run. The license on the repo says you're free. The architecture says you're not.
To his credit, Vota names the conflict himself: Box, Okta, PagerDuty and Microsoft sit on the inside cover, and he calls them funders of the report before citing its conclusion. But disclosure isn't resolution. Note where the remedy lands, not anyone's motives. One of the four sells proprietary identity management, and the auth layer is the exact chokepoint that turns a handover into VCOSS. The proposed cure and the failure mode share an address. "Managed open source" is genuinely great right up until the moment the management is the lock-in.
Where this actually lands
The frame isn't "open vs proprietary." That fight is a decade stale and this piece, for all its bluster, doesn't actually resolve it.
The frame I keep coming back to is the one from Open Source Week: openness is necessary but not sufficient. Necessary, because without it you have no exit, no audit, no fork, no localisation, no life past the vendor. Not sufficient, because a license is a permission, not a maintenance budget, and permission alone has never kept a single tool alive.