Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Open Compliance Summit 2025 was a Linux Foundation event for professionals managing open-source software compliance. It took place on December 11–12, 2025, at Toranomon Hills Forum in Tokyo, Japan. The invitation-only gathering covered licensing, security, software supply chains, SBOM quality, AI compliance, export controls and the processes organizations use to manage them. The event is over; its archived site points to some speaker-provided slides, but does not promise recordings or a complete set of presentations.

Event at a glance

Organizer The Linux Foundation
Dates December 11–12, 2025
Venue Toranomon Hills Forum, Tokyo, Japan
Audience Linux Foundation members and select invitees
Format Keynotes and breakout sessions; attendance was limited
Status Completed; official 2025 pages are archived

The official event overview and program page provide the event details. Sessions were listed in Japan Standard Time (UTC+09:00).

What the summit was about

Open Compliance Summit was a specialist forum on the practical work of using and distributing open-source software responsibly. That work goes beyond identifying a license: organizations need reliable component records, ways to assess license and security risks, clear approval and exception processes, and evidence that obligations were handled before software ships.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Those tasks cut across departments. Legal teams interpret license and intellectual-property questions; engineers bring dependencies into products and maintain them; security teams assess vulnerabilities; procurement teams review suppliers; and product and release teams need dependable records. The summit offered a setting for these practitioners to compare policies, tools and approaches to compliance at organizational scale.

It was not a general Linux developer conference, a public certification exam, or a replacement for legal advice about a specific product or company. The Linux Foundation framed it as a peer-oriented event connected to its broader Open Compliance Program.

Who could attend—and why access was limited

Attendance was limited to Linux Foundation members and select invitees; prospective attendees had to request an invitation. The intended audience included legal counsel, compliance officers, engineering and product managers, process specialists, and supply-chain professionals. The organizers described the format as a way to encourage networking and candid collaboration among people with hands-on responsibility.

The sessions operated under the Chatham House Rule: participants may use information shared at a meeting, but should not identify the speaker or their affiliation without permission. That can support frank discussion, but it also limits how much of the conversation can be publicly attributed or reconstructed afterward. “Open” in the event’s name refers to its subject and ecosystem, not unrestricted admission.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Topics on the 2025 program

The call for proposals invited submissions on AI compliance, export control, legal and intellectual-property issues, licensing, mergers and acquisitions, process management, procurement, SBOM quality, security, supply chains and technical deep dives. Linux Foundation promotion also highlighted representative sessions and themes such as automated FOSS license compliance, code-copy detection, model-transformation concerns, OpenChain capability tracking, open-source governance in Japan, InnerSource governance and patent-risk reduction. These examples illustrate the program; they should not be read as a complete record of every discussion.

Licensing, legal risk and business processes

License compliance involves more than running a scanner. Organizations must identify relevant obligations, manage notices and attributions, decide how to handle exceptions, and retain evidence across product versions. Procurement and mergers and acquisitions add further questions: what components do suppliers or acquired software contain, and can the organization document the associated obligations and risks?

Security, supply chains and SBOM quality

Software bills of materials (SBOMs) help describe the components in a product, but producing a file is not the same as having a dependable inventory. Teams need to consider completeness, accuracy, maintenance across releases and how component records connect to security findings, supplier reviews and release decisions. The useful question is not simply whether an SBOM exists, but whether the organization can use it to make and document decisions.

Automation and technical tooling

Software-composition analysis and other automation can help find dependencies, identify licenses and surface policy issues. Integrating these checks into development and release processes can make review more repeatable. But automated results still need ownership: teams must set policy, review ambiguous cases, decide who can approve exceptions and preserve the evidence behind a release decision.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

AI and open-source compliance

AI compliance appeared in the CFP and in the program’s promoted themes. AI-assisted development raises practical questions about the provenance and licensing of training materials, generated code and model components, as well as how organizations detect copied or transformed code. Faster code generation can also increase the volume that teams need to review. The agenda signals that these issues were under discussion; it does not establish that the summit adopted a specific AI standard or settled legal questions.

Governance and organizational maturity

Open-source compliance is most effective when it is part of an organization’s operating model rather than an occasional legal check. Policies, developer training, cross-functional responsibilities and repeatable review processes help teams address issues earlier and more consistently. InnerSource governance and capability tracking fit into this broader question of how an organization makes its processes usable and measurable.

OpenChain, SPDX and the limits of tools

The Linux Foundation’s Open Compliance Program references tools, templates and SPDX. The summit’s promoted themes also included OpenChain-related capability tracking. These terms describe complementary parts of the work, not interchangeable products:

  • OpenChain focuses on open-source compliance programs and organizational capability.
  • SPDX is a standard format and ecosystem for communicating software-component, licensing and supply-chain information.
  • SBOM and analysis tools can help generate or manage inventories and flag issues for review.
  • A compliance program supplies the policies, accountable people, approvals, training and records needed to act on tool output.

No standard or scanner, by itself, decides how a particular organization should interpret a license, manage an exception or meet a specific legal obligation. Tools can support a process; they cannot replace ownership and judgment.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Were slides or recordings published?

The archived event page directs readers to session presentations supplied by speakers through the schedule. That means some speaker-provided materials may be available; it does not guarantee that every presentation was uploaded. The official page does not establish that full session recordings are publicly available. Access and publication can vary by speaker, session and permission, and the Chatham House Rule further limits public attribution.

How speakers participated

The 2025 CFP opened April 1 and closed August 17, 2025, at 23:59 JST. The Linux Foundation said submitters would be notified on September 15, with the schedule announced September 17. Typical proposals were 20-minute presentations or approximately 40-minute panels. Accepted speakers received a complimentary pass, and proposals centered on product pitches or sales presentations were discouraged. The dates and terms are historical, not an open call for the completed event.

A Linux Foundation promotional post described a US$100 registration fee for invitation requests that were accepted. That figure relates to the 2025 arrangement and should not be assumed to apply to another edition.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Who may find this kind of summit useful?

An event focused on operational compliance is especially relevant to organizations that ship products containing open-source software, distribute software to customers, operate in regulated or security-sensitive sectors, or need auditable license and SBOM records. It may also be useful where engineering teams follow inconsistent processes, supplier reviews are difficult, acquisitions create software-inventory questions, or AI-assisted development is changing how code is produced.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

It is a weaker fit for someone seeking beginner Linux training, an open vendor exhibition, an individual certification, or jurisdiction-specific legal advice. The 2025 invitation restriction also made attendance a poor fit for readers who could not access a member-and-invitee event.

What teams can take from the agenda

For organizations that could not attend, the program’s themes point to practical questions worth asking internally:

  • Assign ownership: Make clear who maintains component records, interprets policy, approves exceptions and keeps release evidence.
  • Keep inventories useful: Check whether component and license data is accurate, maintained across versions and connected to security and supplier workflows.
  • Automate repeatable checks: Integrate analysis into development and release processes, while ensuring people can review uncertain findings.
  • Treat AI as a governance issue: Consider how AI-generated code and model-related dependencies fit into existing provenance, licensing and review processes.
  • Use standards in context: Treat SPDX, OpenChain and analysis tools as supports for a broader program, not substitutes for it.

2025 event versus the 2026 edition

The 2025 summit was held on December 11–12 in Tokyo and has concluded. The Linux Foundation’s current event page lists the next edition for December 10–11, 2026, with its schedule planned for October 2026. Those are 2026 details, not changes to the 2025 dates; check the current page for updates to the future event.

Open Compliance Summit 2025 was also distinct from Open Source Summit Japan and other Linux Foundation events held in the same broader period. Its focus was specifically the organizational, legal and technical processes for managing open-source compliance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.