Internet Exchange

@index.internet.exchangepoint.tech.ap.brid.gy

Feminist perspectives on digital justice and tech 🌉 bridged from ⁂ https://internet.exchangepoint.tech/, follow @ap.brid.gy to interact

Regulating harmful design is only half the equation — attention must also go toward how platforms can build prosocial design, and toward the research that shows them how.

Making the Case for Actionable Prosocial Design Research

_By_ Audrey Hingle and Julia Kamin_. Originally published in_ Tech Policy Press. In recent preliminary findings, the European Commission held that the "addictive design" of Instagram and Facebook breaches the Digital Services Act, citing harms to users' physical and mental wellbeing. The Commission says Meta should “implement design changes” to both platforms. Such changes may be overdue, but regulating harmful design is only half the equation — attention must also go toward how platforms can build prosocial design, and toward the research that shows them how. Platforms, universities and organizations in the tech accountability field can — and should — do more to ensure that research on prosocial design informs how healthy digital spaces get built. ## Sign up for Internet Exchange Feminist perspectives on digital justice and tech Subscribe Email sent! Check your inbox to complete your signup. No spam. Unsubscribe anytime. Academics and other researchers outside of industry produce hundreds of studies a year to investigate and inform the use of prosocial design: the design features and practices that foster healthy interactions in digital spaces. Yet that research all too infrequently influences practice. Often this is due to familiar barriers, like prosocial design being treated as a secondary 'nice to have,' but tech professionals raise a more specific concern: that much of the independent research that is produced is either not attuned to the systems and constraints of tech platforms, or doesn't address tech professionals' questions and challenges. In other words, it is not “actionable” research that has the potential to inform practice. This isn't to say all research needs to be actionable. Fundamental research has its own vital role, but for research that aims to improve how digital spaces are built, closing the gap between insight and implementation matters. The case for closing those gaps is built around four ideas: 1) that actionable, prosocial design research is genuinely valuable because it can shape what gets built; 2) that the builders of digital spaces can't be relied on solely to produce it; 3) that independent researchers can fill the void but today lack the pathways and sufficient incentives to do so; and 4) that there are real ways to change that. ### It can affect what gets built Independent research is critical because it is often better equipped to identify useful insights. For example, practitioners participating in the writing of our recent report, “Connecting Researchers & Practitioners to Catalyze Actionable Research,” noted how independent, actionable research can “signal avenues of approach that may be more productive than the ones [companies] are already pursuing,” sparking ideas and providing empirical evidence to justify shifts in roadmaps. Additionally, practitioners noted how decision makers inside of companies can sometimes fail to see beyond their own business objectives and that synthesized findings from external research presented as “digestible information” can lead directly to “positive outcomes for users” and, in turn, the business itself. Independent prosocial design research can also support advocacy groups and prosocial-minded professionals working within companies by helping them build the case for the adoption of prosocial design—as well as creators building alternative platforms with prosocial goals at the foundation. One research product that several practitioners who participated in the writing of our report agreed served as a useful model was “Shouting into the Void,” a whitepaper co-produced by Meedan and PEN America. In it, the authors investigate user reporting experiences across social media and gaming platforms. Leveraging data from interviews and focus groups, they document specific gaps in current reporting systems and describe users’ experiences of reporting. They conclude with both core platform-level and feature-level recommendations. Practitioners found this whitepaper particularly valuable in its ability to both raise awareness of a user need, grounded in research, while at the same time pointing toward possible solutions. ### Industry can't be the only source of answers Platforms can not and should not be the only ones producing research on how to build healthier digital spaces. Prosocial design research should be a public resource, but if and when it’s conducted internally by platforms, it’s rarely shared externally. Perhaps the greatest impediment lies in the risks to industry of publicly –- or even privately — engaging in research related to prosocial design. These include both brand image as well as legal risks. Publicly working on or being associated with research aimed at creating healthier environments can draw unwanted attention to platforms by implicitly acknowledging that they are not healthy enough, if not unhealthy. The risks can even be legal if, for example, it is shown that platforms were aware of those harms. Many of the platforms oriented toward creating healthy online environments may be more readily willing to conduct and share research and could fill the gap, but they are often smaller and/or nonprofit ventures that have the fewest resources, even though they may be the most willing to apply lessons learned from prosocial design research (for example, Vermont’s Front Porch Forum). While we do not give platforms a pass and incentives or regulation could force the production and disclosure of prosocial design research, the current reality of the disincentive structure described above means we can’t depend on industry to produce insights on how to build for healthier outcomes. None of this relieves platforms of their responsibilities. But given the legal risks, and the resource constraints, independent researchers may be better placed to produce research that is generalizable across platforms and fills a gap that industry, for structural reasons, cannot fill on its own. ### Independent researchers can help fill the gap, but lack the incentives Sufficient incentives must be in place to encourage researchers to generate practice-informed research. While cross-sector research collaborations would go far to foster actionable research, Menking et al. (2025) discuss how mismatches in incentives and resources across the academic, private, and nonprofit sectors impede such collaborations. Bealieu, Breton, and Brouselle (2018) argue that academic institutions and researchers have de-emphasized civic missions, focusing on ‘publications over the public good.’ At a deeper level, practitioners and researchers may distrust each others' intentions in entering a collaboration and be skeptical of their counterparts' capacity to produce useful, relevant and rigorous insights (Levine 2024). Further, Orben and Matias (2025) note that the pace of technology outstrips that of research, resulting in traditional research timelines becoming a “bottleneck for interventions” to address harms before they proliferate and creating a challenge for "temporal validity" (Munger, 2019). Those barriers may explain in part why, in a review of 1,288 academic research papers about topics relevant to T&S collected by the Trust & Safety Foundation, Dratver & Katsaros (2024) found only 5% were collaborations with moderators who help manage online communities, and a mere 3% were collaborations with platform partners. In our report, we make suggestions for how to catalyze independent actionable research and why we think it matters. ### What needs to change? Say you're bought into the idea that actionable research matters. Great. How do we make it happen? In our report, we outline recommendations for academics and industry to make research more actionable, which we summarize below: For academic institutions, we suggest rewarding actionable, practice-informed research in faculty hires, reviews and promotions. We also suggest facilitating data-use and other agreements that are necessary for industry partnerships, which can otherwise slow down projects or get stuck in legal departments. Flexibility in partnerships, for example, allowing industry funding to be structured as a gift or as independent contractor funding, can also help. Industry can help by publicly signaling when independent research informs their work and improves their ability to build healthy spaces so that academics can demonstrate that their research made a difference. Industry can also create titles, such as “research advisor,” for researchers they reach out to for advice or insight on prosocial design, and they can create more internships for social science PhD students. They can also help fund actionable research, but to avoid concerns about “grantwashing,” funding needs to safeguard independence and transparency, and should represent a sizable commitment. Lastly, industry can encourage staff to get involved by attending conferences where they can make connections with social scientists, or partner on projects with universities. Civil society organizations, funders and individuals don't have to wait for academia or industry to make the first move. In our report, we propose several projects that go a long way toward reducing the barriers and incentivizing researchers and tech professionals to connect and catalyze actionable research including: surveying practitioners to identify pressing questions, creating a platform for practitioner feedback, co-creating research agendas and hosting researcher-practitioner convenings to workshop design solutions to common challenges, as we did with our recent PDN-Roblox convening. Regulators can require platforms to stop building for harm, but no enforcement action can tell them what to build instead. As the Council on Technology and Social Cohesion’s Blueprint on Prosocial Tech Design Governance argues, direction has to come from civil society and research, and it will only shape what gets built if researchers, platforms, and funders get together to close the gap between insight and implementation. Our full report goes deeper on what makes research actionable, the barriers that make this challenging, examples of research practitioners have found useful, and a fuller set of recommendations for how to get there. * * * ****Support the Internet Exchange**** If you find our emails useful, consider becoming a paid subscriber! You'll get access to our members-only Signal community where we share ideas, discuss upcoming topics, and exchange links. Paid subscribers can also leave comments on posts and enjoy a warm, fuzzy feeling. Not ready for a long-term commitment? You can always leave us a tip. Become A Paid Subscriber ## This Week's Links 🚨 ****Stop press! Do you enjoy our links?**** Links are now available to paid subscribers only. Become a paid subscriber today. ### This post is for subscribers only Become a member to get access to all content Subscribe now

internet.exchangepoint.tech

Ofcom's new investigation asks whether TikTok's inference-based age checks are "highly effective" enough. Audrey Hingle uses a new Internet-Draft on age verification architecture to show how every age assurance method trades efficacy against privacy, and where TikTok's choice sits on that curve

Why Ofcom Objects to TikTok's Age Assurance Methods

_By_ Audrey Hingle Today, Ofcom opened an investigation into TikTok under section 12 of the UK's Online Safety Act. It will be the first major test of the law's "highly effective age assurance" standard against inference-based methods. TikTok's approach to age assurance is meaningfully different from many other platforms operating in the UK, which have responded to the Act by outsourcing their age assurance to third parties that primarily assess age by collecting biometric face scans or requiring users to upload government ID. TikTok has taken a different, proprietary route and instead largely relied on self-attestation and inference: estimating age from signals it already holds about its users. In a recent Internet-Draft, Age Verification Architecture, we analyzed age-gating methods along two dimensions: efficacy and privacy. Efficacy asks whether a mechanism works: is it feasible to operate at the scale required, is it durable against circumvention, and is it accurate. Privacy asks what a mechanism costs even when it works as intended: what it discloses beyond age, to whom, and for how long. Every method carries trade-offs, and getting the balance right will be difficult for every platform that is required both to prevent users from accessing content that is inappropriate for their age, and protect the privacy of their users. TikTok has chosen a different point on that curve than most of its peers in the UK, and Ofcom's complaint is essentially that the law demands more efficacy, at a higher cost to privacy. The below essay is an example of the kind of analysis the draft's framework is designed to enable: taking a live enforcement case and locating each party's choices on the efficacy–privacy curve. ## Sign up for Internet Exchange Feminist perspectives on digital justice and tech Subscribe Email sent! Check your inbox to complete your signup. No spam. Unsubscribe anytime. ## **How TikTok describes its age assurance** In an October 2025 update, TikTok described its work to provide teens with age-appropriate experiences. Its policy is that children under 13 cannot create accounts. When people sign up, they are asked to provide their birthdate. This is self-attestation, which was the status quo for almost every online service until recently. Self-attestation sits at the low end of both dimensions: it costs almost nothing in exposure or retention, since no verifying party receives more than a claimed birthdate, but it is correspondingly weak on accuracy. Once a person is through that first layer, additional technologies look for users who may have misrepresented their age. The two examples they give are a post referencing an upcoming birthday, or analysis of their profile picture. TikTok also cites new AI technologies piloted in the UK, though it isn't specific about what they are. Suspected underage accounts are escalated to specialized review teams, and TikTok says it removes around six million underage accounts globally every month. Users aged 13 to 15 are allowed on the platform but blocked from features like direct messaging and having content appear in the For You feed. Everyone under 18 gets a default 60-minute screen time limit, no notifications after bedtime, and filtering of content not suitable for teens. To place users in the right experience, TikTok leverages technologies that predict whether someone falls within an age range, such as 13–15. In our paper's terms, this is age estimation: inferring age from behavioral and context-specific signals, not all of which users explicitly opt in to. The behavior of a user on a platform: who they are friends with, what content they engage in, can provide clues about their age. But this data is limited to what the service already knows, and it is least accurate precisely for younger users, since there are statistically fewer ways for the platform to know its estimate is right. There are also general concerns that repurposing user data for age estimation contravenes data-protection frameworks that limit data use to specific consent structures. Estimating age from behavioral signals means repurposing user data for a purpose users never consented to, which sits uneasily with data-protection frameworks like the UK GDPR that tie data use to specific purposes. On paper, estimation has advantages for privacy. It creates no new database of identity documents or biometrics, no centralized target for the breaches that have already exposed the identities of people online. And because it demands no documents, it doesn't exclude the people who don't have them. TikTok itself makes this point, noting that not everyone holds a passport or national ID. But while estimation avoids new data collection, that is only because it runs on the extensive data TikTok already gathers about every user. "No new collection" is a low bar for a platform whose recommendation and advertising systems depend on harvesting data. And TikTok may still collect more sensitive data. If a user feels the age estimation technology has wrongly excluded them from appropriate features, TikTok offers a range of appeal options which include facial age estimation performed by the third-party vendor Yoti, along with credit card data and scans of government-issued ID. The trade-off at the heart of Ofcom's concern: accuracy is not a single number: methods trade off a false-accept rate against a false-reject rate, and are usually tunable along that curve. For example, an age-estimation system can lower its false-accept rate by requiring an estimate well clear of the threshold age, at the cost of a higher false-reject rate for people who are in fact old enough. ## **Why Ofcom objects to TikTok’s methods** Sections 12(4) and (6) of the Act require age assurance that is "highly effective at correctly determining whether or not a particular user is a child" to prevent children from encountering “primary priority content” which includes pornography and content encouraging suicide, self-harm, or eating disorders. Ofcom's Age Assurance report, published the same day the investigation opened, suggests that in some cases age inference models may have failed to correctly identify a significant proportion of children — the false-accept side of the trade-off. If Ofcom ultimately decides TikTok’s features don’t count as highly effective, they may be subject to fines of up to £18 million or 10 percent of qualifying worldwide revenue, and in the most serious cases, court orders requiring payment providers or ISPs to disrupt the service in the UK. If TikTok’s methods _are_ found to be sufficiently effective, it might change the privacy/efficacy balance in the UK. All solutions are bad for privacy; it's just a question of how the costs are balanced. Our paper identifies that layered, proportionate approaches distributed across services, devices, and networks are necessary and that no single mandated high-assurance method will be sufficient. While I can't call TikTok a privacy champion; its preferred method — inference — is also the cheap, low-friction option that keeps data in-house and it repurposes user data for a purpose users never consented to. But a platform willing to try a different method is worth something, because the alternative is convergence. One provider, Yoti, already gates Instagram, Facebook, and TikTok's own appeals process. If every platform routes every user through the same few third parties, we will have built a centralized database of everyone's age, face and documents. That’s a lot of data to trust to a single intermediary. * * * ## Introducing, Erika Owens I'm excited to report that I'm going on holiday, and taking a three week break from IX. While I'm away, Erika Owens will be filling in. Please give her a warm welcome! More about Erika: _Erika loves helping people problem solve and organize at the intersection of journalism, technology, and community. Previously, Erika was Co-Director at OpenNews, where she supported a thriving network and created inclusive, caring spaces for peer learning where people built connections and shared strategies on pushing for change in their organizations. She serves on the board of the Movement Alliance Project and Superbloom, and was a 2024 John S. Knight Journalism Fellow. Based in Sheffield, UK, she enjoys nonprofit journalism, people watching, and laughing heartily._ Want to appear here? Sponsor a newsletter. ****Support the Internet Exchange**** If you find our emails useful, consider becoming a paid subscriber! You'll get access to our members-only Signal community where we share ideas, discuss upcoming topics, and exchange links. Paid subscribers can also leave comments on posts and enjoy a warm, fuzzy feeling. Not ready for a long-term commitment? You can always leave us a tip. Become A Paid Subscriber ## This Week's Links 🚨 ****Stop press! Do you enjoy our links?**** Links are now available to paid subscribers only. Become a paid subscriber today. ### This post is for subscribers only Become a member to get access to all content Subscribe now

internet.exchangepoint.tech

In the West, where most major tech platforms are based, image-based abuse (IBA) is defined as sexual in nature, but a new report finds that many women experience abuse through images that contain no nudity at all.

Not Just Nudes: Image-Based Abuse in Pakistan

_By_ Ramma Shahid Cheema A photograph of a woman who normally covers her hair without a hijab, or a video of her dancing at a wedding. These are not sexually explicit by any platform's definition. Yet when these images are shared without consent and recontextualized, they can be used to blackmail, threaten, or shame her, causing grave harm, up to and including honor killing. The complexities of non-nude image and video-based abuse in Pakistan are often misunderstood and diminished by national regulatory authorities such as Pakistan’s Federal Investigation Agency (FIA), and by major tech platforms such as Instagram, Facebook and Whatsapp that millions of Pakistani women use every day. ## Sign up for Internet Exchange Feminist perspectives on digital justice and tech Subscribe Email sent! Check your inbox to complete your signup. No spam. Unsubscribe anytime. As part of Chayn's new report, "Explicit Harms of Non-Explicit Images: Defining Image-Based Abuse in Pakistan and the Diaspora," in which I assisted with research and interviews, I came to understand how deeply nuances of culture and identity shape women's relationship with technology, and how badly the systems designed to protect them have failed to account for this. Over the past several months, we interviewed more than 60 Pakistani women from cities and villages across Pakistan and the diaspora. They were students, mothers, teachers, activists, celebrities, sex workers and entrepreneurs. They spoke Urdu, Punjabi, Pashto, Siraiki, Balochi and English. The report finds that the images weaponised against them often contain no nudity at all, and that the harm lies not in what an image shows but in whether a woman consented to its being shared, a reality not considered by the tech companies based in the West. Many of these images that do not fall under platforms’ no-nudity policies can still cause serious harm and have devastating consequences for women’s lives. This report provides evidence for experiences many communities have long understood. I was born in Lahore, and grew up in both rural and urban settings. Some of the experiences shared by the survivors of image based abuse were mine, too. Always calculating what to wear, where to go, who to be photographed with, and later making sure the images being shared on social media are safe even if shared on private accounts. These considerations may not cross a woman’s mind in the Western world, but weigh heavy on ours. One thing became very clear to me: trust in these systems is deeply fractured. I share that distrust. I found myself questioning not only whether existing systems can respond to image-based abuse, but whether they were ever designed to recognize the realities of women. When the rules only see an image as harmful if it shows skin, the woman whose reputation is destroyed by a photograph of her dancing at a wedding is not in scope. Anthropologists call this epistemic violence, the harm done not by what is said, but by what a dominant system refuses to recognize. The platforms that now shape how billions of people communicate, report harm, and seek safety were built in one cultural context and exported to the world carrying with them assumptions about what harm looks like, what bodies mean, and whose experiences count. Pakistan is firmly embedded in the digital world. Internet use has grown from 17% of the population in 2019 to 57% in 2025. Yet many women continue to navigate online spaces cautiously using pseudonyms, restricting their visibility, carefully curating what they share because the consequences of being targeted feel very real. Our research showed that what may seem unproblematic in a Western framework can have grave consequences for women in Pakistan, but that tech platforms are designed to identify content like nudity, not context. So when a woman tries to report this kind of abuse, she finds herself without a clear pathway, because her experience doesn't fit the categories the system was built to recognize. For many women in Pakistan, reporting to the police is the last resort. They fear that seeking help could expose their identity or intensify the harm they are trying to escape. In a context where honor is treated as something a whole family or community holds collectively, the consequences of disclosure are enormous. Some survivors we interviewed reported suffering in silence, feeling they have no one safe to turn to. They live with serious mental health consequences: insomnia, anxiety, depression, suicidal crisis. Some also withdraw socially, disappearing from online life altogether. Elsewhere, policies are beginning to shift. For example, France has placed consent at the center of how image-based abuse is defined, and it treats consent as tied to context. Agreeing to be photographed is not the same as agreeing for it to be shared, and consent is not a single, permanent yes. A woman may willingly share a photograph with her friends without agreeing for it to be shared widely or weaponized against her, and she should be able to withdraw consent whenever she chooses. France shows a consent-based approach can work. Below, I summarise some of the report's recommendations for how tech companies can also move policies and enforcement toward consent over content. For a full list of recommendations for tech companies and policymakers, see the full report. ### Recommendations for tech companies 1. Shift from defining image-based abuse as only sexual or nude content to a consent-based framework where removal requests based on lack of consent are granted. 2. Ensure moderation teams are culturally informed, with additional training on intersecting experiences such as sexual orientation, religion, gender identity, and caste. 3. When a user attempts to post a photo online, introduce a prompt asking them to confirm that they have obtained consent from all identifiable people in the image. 4. Suspend reported images while a decision is made about whether they should be removed. 5. Allow third-party reporting, including for WhatsApp and Instagram Stories. 6. Create flexible reporting mechanisms that allow people to describe their own experiences and requested remedies rather than forcing reports into rigid categories. 7. Liaise with law enforcement agencies at the request of survivors, including preserving evidence that content existed even if later removed. * * * ## The State of the Open Internet with Mallory Knodel: Elixir Wizards Podcast IX's Mallory Knodel, executive director of the Social Web Foundation, joins Charles Suggs and Emma Whamond on the Elixir Wizards podcast to talk about internet governance, open standards, and the future of the social web. Mallory shares how her work as an activist, systems administrator, and public interest technologist led her into the working groups that shape how the internet functions, including the IETF, W3C, ICANN, and ITU. The conversation explores how the internet shifted from open protocols toward a handful of dominant platforms, and what that centralization means for users, developers, and independent service providers. Mallory explains how protocol-level decisions affect everything from email deliverability to identity, data portability, trust and safety, and the ability to move between platforms. They also discuss the Social Web Foundation, ActivityPub, the Fediverse, and building a more multipolar social web. Mallory also looks at what happens when AI agents, automated accounts, and algorithmic feeds enter open social ecosystems, and shares her perspective on privacy, usability, encrypted messaging, and designing technology around user needs rather than engagement alone. Listen on Spotify | Apple Podcasts or below on YouTube! Want to appear here? Sponsor a newsletter. ****Support the Internet Exchange**** If you find our emails useful, consider becoming a paid subscriber! You'll get access to our members-only Signal community where we share ideas, discuss upcoming topics, and exchange links. Paid subscribers can also leave comments on posts and enjoy a warm, fuzzy feeling. Not ready for a long-term commitment? You can always leave us a tip. Become A Paid Subscriber ## This Week's Links 🚨 ****Stop press! Do you enjoy our links?**** Links are now available to paid subscribers only. Become a paid subscriber today. ### This post is for subscribers only Become a member to get access to all content Subscribe now

internet.exchangepoint.tech

If we want to combat cyberviolence against girls, feminist analysis must help shape the technology.

Can Tech Prevent and Combat Cyber Violence Against Girls?

_By_ Mallory Knodel Our collective imagination likes to manifest tech solutions for tech harms. In the case of cyberviolence against girls, in what ways is it possible that tech can be used against itself, to both prevent and combat gender based harms online? This month the Working Group on discrimination against women and girls presented its report on women's and girls' rights and artificial intelligence and related digital technologies (A/HRC/62/48) to the Human Rights Council, warning that AI deployed without gender-responsive governance risks deepening existing inequalities, and naming technology-facilitated gender-based violence as one of the "redlines" demanding urgent intervention. ## Sign up for Internet Exchange Feminist perspectives on digital justice and tech Subscribe Email sent! Check your inbox to complete your signup. No spam. Unsubscribe anytime. Several months earlier, at the 70th Commission on the Status of Women, held at the UN Headquarters in New York, a panel of experts was invited to weigh in on strategies needed to intervene in online social interactions, where digital forms of abuse have been identified as particularly pervasive and harmful to girls. Hosted by the EU and Cyprus, as the current Presidency of the Council of the European Union, invited Mr. Gary Barker CEO and President of Equimundo, Ms. Olimpia Melo an Activist, Mr. Viraj Doshi from Snap, and myself for the Social Web Foundation. The session recording can be found online at UN Web TV. I’ve written the essence of my remarks below, which focus on the architecture of the internet and emerging tech and how these quietly shape what content and behavior is possible, amplified, or deterred online. ### My Remarks Regulatory commitments from states to address gender-based violence online abound: The EU Directive 2024/1385 was written for combating violence against women and domestic violence, and the 2025 EU Roadmap for Women's Rights prioritizes freedom from gender-based violence as its first principle. The EU Digital Services Act (DSA) plays an important role in strengthening the protection of women's and girls' rights online. And all UN Member States have committed to combatting sexual and gender-based violence online in the Global Digital Compact (GDC), adopted in the World Summit on the Information Society WSIS+20 resolution (A/Res/80/173). However, efficient tech and regulatory solutions must be complementary. There are three ways that regulation can force emerging technologies to consider cyberviolence against girls as a first principle: ### Safety by design, not after harm. Platform infrastructure choices like default privacy settings, introducing friction when girls share intimate content, making legible manipulated media, improving attribution and accountability for abuse all influence whether harms can achieve scale. Because technical design is policy, technical standards bodies are crucial for developing norms and mitigating harms. However this then requires human rights experts to be present in those bodies to help balance equities. One solid example of this is age gating, which disenfranchises youth from human rights like expression and privacy, as well as economic, social and cultural rights. In a technical standards body, engineers will be putting their heads together about how to make age gating work technically, often without the social context to understand how it can undermine rights like expression, privacy, and access to information. ### Accountability must be embedded in infrastructure. Regulation like the DSA is powerful because it goes beyond content takedown and toward systemic risk obligations. We need technical systems that can support auditability, researcher access, and meaningful transparency, not just terms of service and privacy policies. Moreover, the EU’s Digital Markets Act (DMA) indicates interoperability as a core tenet for breaking up consolidated digital ecosystem but we also need this for accountability structures, too. This leads to the third recommendation. ### Interoperable safety. Girls don’t live their digital lives on just one platform. Abuse crosses services, borders, and legal regimes. Large tech companies work together to identify nonconsensual intimate images that need to be taken down all over the internet. If they can work together on that, we can ask them to work together in more ways that benefit people, namely through interoperation. Interoperability meets the need for shared technical standards for reporting, evidence preservation, and identity protection so survivors aren’t forced to relive harm platform by platform. Platforms need to be more open and interoperable by design to give everyone more agency and to ensure platforms are more accountable. Often solutions work best when technical architecture is open, and kept open through regulatory incentives, standards are interoperable and human rights are considered. Solutions are inadequate when safety is addressed in product deployment, treated as an optional feature or bans are used to wall off populations and communities from one another. Importantly, survivors and activists must inform these solutions. Keen power analysis and global movement organizing means feminists are the world’s watchdogs. Civil society organizations are activists and survivors who are already experts in system failure. The gap we see globally is that girls’ lived realities rarely shape platform governance or technical standards. That has to change. Beyond spaces like the Commission on the Status of Women, UN Women, and the Working Group on discrimination against women and girls, we need feminists in technical spaces to build credible participation where rules are actually made. It is crucial to bring experts with lived experience to technical spaces. Many of the most consequential decisions about digital systems happen in technical standards bodies and procurement processes long before laws are enforced. Women’s rights groups and youth advocates need funded pathways into those rooms. When we treat girls and survivors not just as beneficiaries but as co-designers of digital infrastructure, solutions become more effective, more legitimate, and more just. The Office for the High Commissioner on Human Rights has recently published some ideas about how to bring more human rights considerations into technical standards bodies. The GDC language can also ensure that this work is more coordinated in human rights spaces, rather than in engineering and technical ones. The design, development and deployment of technology is a site of power. Feminist analysis must shape tech from the start. * * * ## Celebrate Anti-Primeday With Us This week, ditch Amazon and support independent book stores instead. It's Bookshop.org's Anti-Prime Day, and from June 23rd through June 26th, you can enjoy **Free Standard Shipping** on your entire order. Every purchase helps fund local bookshops in your community rather than padding a billionaire's bottom line. Browse our curated IX Stack collection at bookshop.org/shop/ix-stack and find your next great read about feminist tech and internet governance. Rooted in the belief that infrastructure is political, our bookshop _The Stack_ curates books that connect the dots between code and culture, protocol and protest, theory and practice. Celebrate Anti-Primeday * * * ****Support the Internet Exchange**** If you find our emails useful, consider becoming a paid subscriber! You'll get access to our members-only Signal community where we share ideas, discuss upcoming topics, and exchange links. Paid subscribers can also leave comments on posts and enjoy a warm, fuzzy feeling. Not ready for a long-term commitment? You can always leave us a tip. Become A Paid Subscriber ## This Week's Links 🚨 ****Stop press! Do you enjoy our links?**** Links are now available to paid subscribers only. Become a paid subscriber today. ### This post is for subscribers only Become a member to get access to all content Subscribe now

internet.exchangepoint.tech

Research suggests fair moderation can reduce harm and foster healthier engagement.

Due Process: Why Fair Moderation Builds Healthier Communities

_By_ Audrey Hingle_and_ Julia Kamin_. Originally published on_ the Prosocial Design Network blog. In the offline world, "due process," or more broadly procedural justice, is the idea that before someone faces a consequence, they're entitled to fair treatment: clear rules, notice of what they did wrong, and a chance to respond. But its principles apply online as well. As Matt Katsaros put it in a conversation with the Prosocial Design Network, the core insight is simple: “people care about how they are treated,” not just about the outcome. Transparency and fairness are the principles that run through all of it. ## Sign up for Internet Exchange Feminist perspectives on digital justice and tech Subscribe Email sent! Check your inbox to complete your signup. No spam. Unsubscribe anytime. There is a straightforward ethical case for this. Treating people with dignity and fairness is the right thing to do. But this primer is mostly about a second kind of argument. Most platforms today lean on a deterrence model, where rule-breaking content is removed, and offenders move up an escalating ladder of suspensions and bans, on the theory that punishment alone changes behavior. The Yale Justice Collaboratory's framework for tech professionals argues that procedural justice offers a better path. And as we hope this primer shows, designing for due process can actually reduce harm and foster healthier engagement. In practice, it comes down to three things: being clear about the rules up front, telling people why when you enforce them, and giving people a way to appeal. ### Be clear about the rules and the consequences Due process starts before anyone breaks a rule. It starts with making the rules, and how they're enforced, visible. The practical guidance here is to state plainly what behavior is encouraged and what's discouraged or prohibited, keep the rules and guidelines prominent, and remind people of them. That means surfacing rules where people will see them: pinned to the top of a thread, or shown as a prompt when someone enters a forum – not tucked into the terms of service that no one reads. This is one of the better-evidenced interventions in the prosocial research space. We at the Prosocial Design Network rate rules and norms setting as a validated intervention. A key study is J. Nathan Matias's 2019 field experiment on Reddit's r/science, where some posts were randomly assigned to display a reminder of the community's rules along with a note about how they're enforced. New users who saw the reminder were about 8% more likely to follow the rules and 70% more likely to comment. This is a serendipitous result: the intervention boosted both compliance _and_ participation A few other studies point the same direction, which is why we feel the evidence that rules and norms work is so strong. A collaboration with Nextdoor randomized 312 new groups to either show group guidelines before people joined, or show nothing. The groups that posted guidelines saw noticeably fewer comments reported for abuse (about 0.3% versus 0.7%). And a Facebook field experiment found that people who'd had content removed re-offended less when they were afterward reminded of the specific rule, or simply that rules are enforced. One detail worth remembering from the Matias work: the reminder didn't just list the rules, it signaled that they'd be enforced. That enforcement cue appears to play a significant role. ### Tell users why their content was removed The right to know the charge against you isn't only a courtroom idea. When you remove someone's post or comment, the due-process move is to tell them why – which rule it broke and what happened. The good news is this can be lightweight: explanations can be short, and they can be delivered by a bot rather than a human moderator. The evidence here is a little less strong, which is why we rate removal explanations as likely rather than validated. The central study by Shagun Jhaver and colleagues in 2019 is observational: it tracked Reddit users who had their posts removed across Reddit’s thousands of communities, each with its own policies for removal explanations. They found that those who received an explanation were less likely to have another post removed later. Explanations delivered as detailed comments posted below the removed submission worked better than short labels attached to a post. And usefully for anyone worried about moderator workload, it made no difference whether the message came from a bot or a person. Because it's observational, we can't fully rule out that the kinds of communities offering explanations also happen to attract more receptive users, but related removal experiments (more on those below) point in the same direction. A separate question is whether public explanations, e.g. "this comment was removed because it violated our rule on X," do anything for bystanders. A later, additional study by Jhaver and colleagues looked exactly at that. They found that bystanders who saw removal explanations significantly increased their activity afterward: they posted more frequently and commented more on others' threads (higher interactivity). However, witnessing an explanation did not reduce bystanders' own rule-breaking. ### Give users a way to appeal When you remove a comment or restrict someone's access, tell them why. Due process means also giving someone a route to challenge the decision. A well-designed appeal asks the user to explain why they think the action was unfair or mistaken, which puts a bit of the burden back on them to make their case. To be candid, the evidence that an appeals process encourages prosocial behavior is the thinnest and most mixed of any section in this primer. We have not reviewed a study that isolates an appeals process and tests whether it, on its own, encourages people to behave better. What we have is indirect – and it comes from two quasi-experiments that showed that _removing_ rule-breaking comments reduces repeat offending: one on Facebook (Ribeiro et al., 2022) and one on Reddit's ChangeMyView (Srinivasan et al., 2019). In both, the removal came bundled with an explanation _and_ a way for the user to contest the decision. So the appeal was baked into the interventions that work, and its individual contribution is implied rather than measured. In our interpretation, consistent with procedural-justice theory on fairness and recidivism, is that the chance to appeal may be a _necessary ingredient_ for a removal to land constructively. But that is a reasonable inference, not a proven mechanism. There's firmer evidence on the moderator side: a field experiment on a tool (AppealMod) that asked users to explain their appeal before it reached a human cut the volume of appeals moderators handled by roughly 60–70% and their exposure to toxic appeals by around 90%, with no drop in successful appeals. Even there, though, the study measured effects on moderators, not on whether the wider community behaved more prosocially – so the prosocial case for appeals is promising, but not yet directly demonstrated. ### Why it's worth it Put the pieces together and we hope we’ve made the case: due process isn't only the "right" thing to do, it also produces better outcomes, lowering recidivism while keeping (or even increasing!) healthy interaction and engagement. And the appeals research suggests you can build a process that respects users _and_ lightens the load on the moderators who keep communities running. There's one more reason that the research can't (yet) prove with a randomized trial: trust. A central claim of procedural-justice theory is that treating people fairly builds their willingness to accept a system's authority and stay engaged with it. We can't point to a controlled experiment that nails this down for online platforms, so it's fair to label it theory rather than settled finding. But it's the through-line beneath everything above, and it brings us back to where we started: people care about how they're treated, and platforms that demonstrate respect in their moderation policies are more prosocial places to be. * * * ## From the Group Chat 👥 💬 _This week in our Signal community, we got talking about:_ The UK government's headline pledge to make it "impossible" for children to take, share or view nude images. The plan relies on device-level scanning, technology ministers say already exists on Apple and Google phones and merely needs switching on. But by the government's own admission, the existing Apple and Google features only blur suspected nude images inside messaging apps and don't cover the camera, third-party messengers, or search, which is the much larger, always-on, whole-device capability ministers are actually demanding: _"Despite this, the nudity detection is not applied to the camera or broader apps, third-party messaging services, or search functions, meaning children can still take, view, share and save nude images. The government therefore wants Apple and Google to block nudity across the whole device by default, so they can only be deactivated via age assurance."_ The big winner in this is SafeToNet, a technology provider cited in the government’s press release that IX contributor Heather Burns has written about, and that has previously been accused of spying on children after claiming in 2020 that its software had caught girls as young as 10 using the names of UK restaurant chain Nando's peri-peri sauces as coded sexual slang, a claim built on its screening of tens of millions of children's messages. A cybersecurity researcher cited in that article also found the app contained a whitelist allowing advertisers to monitor children's web browsing habits. The firm's product today, HarmBlock, performs the client-side scanning the government now wants nationwide. Client-side scanning is widely criticized by privacy and security experts because it sidesteps end-to-end encryption, inspecting content on the device before it is encrypted. Signal, opposing the plan, warns that surveillance is not safety: scanning every device on the presumption of nudity will not keep children safe. Instead it entrenches Apple, Google and Microsoft’s market dominance and their control over our most personal information, and builds infrastructure that history shows never stays narrowly scoped. While today it detects nudity, tomorrow it may be political speech… or our conversations about peri-peri chicken. ****Support the Internet Exchange**** If you find our emails useful, consider becoming a paid subscriber! You'll get access to our members-only Signal community where we share ideas, discuss upcoming topics, and exchange links. Paid subscribers can also leave comments on posts and enjoy a warm, fuzzy feeling. Not ready for a long-term commitment? You can always leave us a tip. Become A Paid Subscriber ## This Week's Links 🚨 ****Stop press! Do you enjoy our links?**** Links are now available to paid subscribers only. Become a paid subscriber today. ### This post is for subscribers only Become a member to get access to all content Subscribe now

internet.exchangepoint.tech

How governments are using domain name suspension to censor websites.

Stifling Speech Through DNS Infrastructure

_By_ Michaela Nakayama Shapiro State censorship of the internet is nothing new. But state actors are increasingly turning to a new frontier to restrict free speech: the domain name system. In July 2020, the websites of three Indian environmental collectives, LetIndiaBreathe.in, ThereIsNoEarthB.com, and FridaysForFuture.in, became inaccessible. The organizations were given no explanation. It took their own technical investigation to establish what had happened: a domain hold placed by India's National Internet Exchange (the top-level domain registry operator for .’in’). In January 2024, the Belarusian Association of Journalists, which had operated its website on the domain baj.by for nearly 20 years, had that domain seized by the Operational and Analytical Center (the top-level domain registry operator for .’by’) by orders of the President of Belarus shortly after BAJ published its position criticizing the government’s decision to host a regional internet governance forum in Minsk as ‘validat[ing] repression’. In both cases, there was no court ordered shutdown, no regulator issuing a formal ruling. The state went directly to the companies that managed these websites’ domain names. In our recent report, Damming a river to catch a fish_,_ at ARTICLE 19, we found that state actors are increasingly pressuring domain name system (DNS) operators to block access to public interest content, stifling speech and censoring critical voices. The DNS, also known as the directory of the internet, is the often invisible infrastructure that translates ‘article19.org’ or ‘nytimes.com’ into the machine-readable numerical IP addresses used by web browsers, making the internet easier to navigate. The system is managed by domain name operators, including registries who manage domain name databases for top-level domains, such as ‘.com’, ‘.uk’ or ‘.org’, and registrars who liaise between registries and domain owners, known as registrants. While infrastructure-level censorship is not new, we undertook this research to better understand the role of registries and registrars in either enabling or restricting the free flow of information and the profound consequences that domain suspension orders can have for freedom of expression. ### When DNS abuse mitigation becomes censorship To understand the full landscape of DNS-level censorship, we must first look at the broader ecosystem governing domain operators, starting with ICANN. The Internet Corporation for Assigned Names and Numbers (ICANN) is the multistakeholder organization that maintains the DNS. Registries and registrars are contractually obligated to comply with ICANN policy – including its definition of DNS abuse and corresponding mitigation requirements. Within the ICAN context, DNS abuse is narrowly defined to encompass five categories: ## Sign up for Internet Exchange Feminist perspectives on digital justice and tech Subscribe Email sent! Check your inbox to complete your signup. No spam. Unsubscribe anytime. 1. Phishing – tricking people into giving sensitive information. 2. Malware distribution – spreading malicious software. 3. Botnets – networks of infected computers controlled remotely. 4. Spam (as a means of abuse) – unsolicited messages used for harm. 5. Pharming – redirecting users to fake websites. When a registry or registrar identifies or receives a report of DNS abuse, it is required to take action – but they are often limited in what they can do. If they wish to block a particular activity or content, often their only recourse is to take down the entire domain name. Removing a domain can block all content, including lawful speech. ICANN’s narrow definition for DNS abuse prevents overreach in mitigation that could infringe upon lawful speech and content online. But beyond ICANN, defining DNS abuse is trickier than it seems. How domain operators define DNS abuse – if they do so at all – varies drastically.**** This leads to a fragmented landscape of responses to domain suspension requests that has allowed governments to weaponize this varying interpretation to block access to lawful information and silence critical voices. Additionally, registries operate under growing, often conflicting pressures. A number of factors – including who reported the abuse, the registry’s jurisdiction and governance, and its terms and conditions can determine whether and what action the domain operator takes. Registries also must navigate ICANN contracts, national laws, court orders, law enforcement demands, and their own terms and conditions, while often lacking legal clarity about their responsibilities. Within this complex operating environment, the rights of registrants, the entities that own the rights to a particular domain, are often an afterthought. Most registries provide limited transparency about suspensions and virtually no appeals mechanisms. Registrants may not be aware that their domains were suspended, much less why or by whom. Without transparency or appeals mechanisms, domain suspension becomes a potentially unchecked mechanism for censorship. Attempts to moderate content through infrastructure-level entities are expanding rapidly without safeguards to protect free expression. ### What more can stakeholders do? Our report sets out recommendations for what more ICANN, domain operators, and civil society can do to develop a comprehensive DNS abuse mitigation policy with strong human rights safeguards. * **Registries and registrars** should establish recourse mechanisms to allow those impacted to contest domain suspension decisions, integrating appeal and dispute mechanisms. To demonstrate transparency, they should also establish clear definitions of DNS abuse and publish regular reports on domain suspension requests and decisions. * **Civil society and media organizations,** who are at highest risk of falling victim to the weaponization of domain suspension requests, can take pre-emptive safety measures to build organizations’ resilience to this mode of censorship. One easy step is to simply know who the registry and/or registrar is for your domain(s). Organizations at risk should prioritize registering their domain(s) with a registry or registrar that is transparent about its suspension policies and has clear and accessible recourse and remedy mechanisms in place. They should give preference to registries located in jurisdictions with robust protections for politically sensitive speech and consider registering with a general top-level domain (gTLD) registry operator (who operate domains such as .org) – those operators must comply with ICANN’s contractual obligations and are bound by their narrow definition of DNS abuse. * **ICANN** should develop a standard dispute and recourse mechanism for registrants impacted by DNS abuse mitigation actions. This would be one way to ensure there is a contractual requirement for registries and registrars to integrate due process mechanisms into their DNS abuse mitigation policies and procedures. Finding a solution that balances the safety and security of the DNS and safeguards the rights of all internet users to freedom of expression and privacy online is paramount. The good news is that these goals are not contradictory. The next ICANN meeting, ICANN86, begins next week, and the timing is crucial: in March 2026, ICANN launched its first policy development process on DNS abuse mitigation, of which ARTICLE 19 is a member representing the non-commercial stakeholder group. The process presents a key opportunity for the community to consider our report’s recommendations and continue discussions on developing standard dispute and recourse mechanisms. Ultimately, the entire community has a role to play in ensuring concrete human rights safeguards are integrated into DNS abuse mitigation policy – so that it protects the rights of internet users and domain holders alike. _Michaela Shapiro is a Program Officer at ARTICLE 19 focused on improving the censorship resilience of telecommunication networks and the domain name system (DNS) and developing anti-censorship standards and protocols. The role emphasizes shaping the processes and outcomes of technical standard-setting forums such as ICANN and the IETF._ * * * ## From the Group Chat 👥 💬 _This week in our Signal community, we got talking about:_ The group shared notes from a recent Edinburgh workshop on "Rewilding the Web," which brought together technologists, ecologists, philosophers, and others to explore how lessons from biology and ecology could help build a more resilient, diverse internet. The concept of rewilding the internet originated with Maria Farrell and Robin Berjon who wrote this fantastic piece in Noema Magazine. They attended the event alongside IX contributor Heather Burns who shared her reflections. ****Support the Internet Exchange**** If you find our emails useful, consider becoming a paid subscriber! You'll get access to our members-only Signal community where we share ideas, discuss upcoming topics, and exchange links. Paid subscribers can also leave comments on posts and enjoy a warm, fuzzy feeling. Not ready for a long-term commitment? You can always leave us a tip. Become A Paid Subscriber * * * ## This Week's Links 🚨 ****Stop press! Do you enjoy our links?**** Links are now available to paid subscribers only. Become a paid subscriber today. ### This post is for subscribers only Become a member to get access to all content Subscribe now

internet.exchangepoint.tech

If opt-out tools exist, but no creator can use them, do they really protect anything?

Creators Need AI Opt-Out Tools They Can Actually Use

_By_ Audrey Hingle Seventy-five percent of professional artists say they want to block AI crawlers from using their work, but research suggests that even on platforms where those options are available, only a fraction actually do. Why? Because while many opt-out tools exist – including robots.txt, NoAI meta tags, the TDM Reservation Protocol, and platform-specific directives like Google-Extended – they are not easily accessible, and subsequently adoption is negligible. ### Opt Out… If You Can The authors of Somesite I Used To Crawl_,_ surveyed 203 professional artists recruited through Discord channels and professional social media networks, predominantly illustrators and digital 2D artists based in North America, of whom 87% were making money from their work. They found that 59% of artists had never heard of robots.txt, a decades-old web protocol that has been repurposed as the primary mechanism for creators to signal that their content should not be scraped for AI training, and that even among those who had, the most common barrier to using it was simply not knowing how. They also found that use of NoAI and NoImageAI meta tags, which allow creators to signal at the level of individual pages rather than an entire site that content should not be used for AI training, was similarly low, with only 17 and 16 sites respectively using them across the top 10,000 domains surveyed. ## Sign up for Internet Exchange Feminist perspectives on digital justice and tech Subscribe Email sent! Check your inbox to complete your signup. No spam. Unsubscribe anytime. They also found that this was not only a problem of creator literacy but that of deliberate platform design choices. Reviewing eight website building and hosting platforms aimed at non-technical users, namely Squarespace, ArtStation, Wix (paid), Adobe Portfolio, Wix (free), Weebly, Shopify, and Carbonmade, they found that four provided no method for users to modify robots.txt at all, with the provider setting a default configuration. Of the remaining four, only Carbonmade disallowed AI crawlers by default. Wix's paid version allowed direct editing but found none of the 1,100 artist websites in their dataset had edited their robots.txt despite the option being available. The researchers speculated that it might be that the interface is confusing, having attempted it themselves and found it so. Squarespace was the only provider offering a dedicated AI crawler opt-out toggle, but only 17% of Squarespace users in the dataset had enabled it, a figure the authors note is low given that 75% of surveyed artists had expressed a desire to block AI crawlers when given the choice. ### The Problem of Social Media A further structural problem is that opt-out signals cannot follow content once it leaves a creator's own site, meaning content posted to social media carries no or limited anti-crawler protections that creators can control. AI training datasets are compiled through automated scraping of publicly available videos from platforms including TikTok, Instagram, YouTube, Facebook, Vimeo and Dailymotion, and platform terms of service are typically broad enough to permit this use by default. Although YouTube has provided an opt-out system, many other platforms either allow use of data for AI training by default unless users adjust their privacy settings, or do not explicitly clarify their stance on using user data for AI training at all. Even where opt-out mechanisms exist, they may have come too late, given the volume of content already scraped before any such mechanism existed. Another structural problem is that text and data mining (TDM), the automated computational analysis of large bodies of digital content used to train AI models, occurs far faster than any rights reservation process could realistically respond to. Automated tools can scrape, analyse and process vast amounts of data within seconds or minutes, whereas reserving rights typically involves manual steps. The result, according to Li et al.,whose response to the UK government consultation on copyright and AI focused on the impact on the dance sector, is that platforms provide vague or broad terms of service that allow them to use user-generated content for AI training, while many users do not understand the terms or, while in the process of understanding them, find their content has already been mined. Many have identified platform terms of service as a key mechanism through which creator agency is limited. Quintais et al. found that platform terms of service have become increasingly complex over time, spread across multiple documents and versions in ways that make them very difficult to follow. Their research also found that platformisation, the process by which platforms accumulate governance power over content, tends to concentrate power both in platforms and in large rights holders, to the detriment of smaller and independent creators. Tools like Meta's Rights Manager, which allow rights holders to assert claims over content, were found to be effectively inaccessible to small creators, functioning in practice only for large institutional actors. ### How About Some Compensation? Sinha and Li found strong opposition to bulk content commodification, with 44% of respondents saying they would never accept their content being sold in bulk and a further 40% finding it negotiable only if compensated. Yet as Liu et al. and Quintais et al. document, platforms routinely permit exactly this through terms of service that have become increasingly complex and difficult for creators to understand or contest. Independent creators also have limited ability to contest AI use of their content through formal channels. Litigation is viable only for actors with the resources to absorb legal risk, which in practice means large commercial content creators or firms. Kretschmer, Margoni and Oruc note that legal uncertainty has encouraged AI developers to mine content and destroy training material precisely because individual creators cannot reverse-engineer a trained model to prove infringement. Rodrigo further notes that Article 4 of the CDSM Directive, the EU provision that allows creators to reserve their works from commercial AI training, preferences large incumbents with legal and technical resources that can operationalise rights reservations at scale, while independent creators cannot. Unfortunately, no workable mechanism currently exists for independent creators specifically. Of the proposals suggested to resolve this, Senftleben's is the most cited. He proposes an output-based levy charged to providers of generative AI systems whenever their system has the potential to substitute human literary or artistic output, with funds distributed through collecting societies and social and cultural funds to individual creators, but acknowledges that collected funds are unlikely to reach individual creators if negotiations are dominated by large rights holders, acknowledging that even the most cited compensation proposal may continue to produce the power asymmetry it is meant to correct. The evidence points to a consistent and structural problem. The tools that platforms offer independent creators to manage how their content is used for AI training are limited and infrequently used. Where opt-out mechanisms exist, they are difficult to find, inconsistently applied across platforms, and arrived too late for creators whose content has already been used to train AI. On revenue sharing, no workable mechanism currently exists for independent creators. Licensing deals are typically negotiated at the level of large publishers and stock libraries, not individuals. Policymakers considering reform should note that the problem is not simply one of legal gaps. It is structural. Any intervention that does not account for the power asymmetry between platforms, large rights holders, and independent creators risks reproducing the same imbalance it sets out to correct. * * * ## Geneva's Got it Going On At UN Tech Week Geneva (July 6–10), three major events converge at Palexpo and ITU HQ: the inaugural Global Dialogue on AI Governance, the WSIS Forum 2026, and the AI for Good Global Summit, alongside the WIPO Assemblies. **What To Watch For:** A range of side-events will be taking place from Sunday through Thursday, including a number that will be folded into the Global Dialogue’s agenda. These include events organized by MAP-AI, Participatory AI Research & Practice Symposium, Partnership on AI, and UN Human Rights. **Registration & Access** * Global Dialogue on AI Governance * WSIS Forum * AI for Good ****Support the Internet Exchange**** If you find our emails useful, consider becoming a paid subscriber! You'll get access to our members-only Signal community where we share ideas, discuss upcoming topics, and exchange links. Paid subscribers can also leave comments on posts and enjoy a warm, fuzzy feeling. Not ready for a long-term commitment? You can always leave us a tip. Become A Paid Subscriber ## This Week's Links 🚨 ****Stop press! Do you enjoy our links?**** Links are now available to paid subscribers only. Become a paid subscriber today. ### This post is for subscribers only Become a member to get access to all content Subscribe now

internet.exchangepoint.tech

End-to-end encrypted RCS between iPhones and Android phones is a security win for billions of users and a challenge to the industry argument that interoperability and security are incompatible.

Apple-Google Encrypted RCS Buries the Interoperability vs. Security Myth

_By_ Mallory Knodel_, originally published in_ Tech Policy Press With the news that Apple is embracing cross-platform encrypted messaging, it’s worth taking a closer look at the promise versus the practice of this interoperability feature from an end-user privacy and security perspective. Before, Apple wanted you to know that “if your iPhone messages are green,” it was more than a visual difference, indicating a security gap introduced by interoperability with users sending and receiving messages with SMS. When iPhone users messaged one of the billion people with an Android phone, an outdated SMS standard was used and that conversation could not be end-to-end encrypted (E2EE). Two critical changes have led to this moment. “Text messaging” has evolved to use enhanced features and the latest protocol is now called RCS, or Rich Communication Services. The latest update to RCS includes E2EE capabilities. And the second is that Apple, which has been under DOJ antitrust scrutiny partly over its messaging practices, has agreed to interoperate iMessage with Google Messages and both will be working together to roll out end-to-end encrypted RCS messaging between iPhones and Android phones. Google, the proponent of the standard document adopted last year by the GSMA (Global System for Mobile Communications) that specifies Messaging Layer Security in RCS, published its announcement last week. Apple’s corresponding announcement makes it clear that its roll out of MLS in RCS is in beta and that the E2EE messaging with Android will only work for iPhones running the newest version of iOS. Messages between two people with iPhones have been encrypted end-to-end since 2011. But if you had an iPhone and sent an RCS message to a user of an Android phone, the message would not be encrypted end-to-end. Now, as a result of standard interoperation between Apple and Google, it will become encrypted end-to-end, indicated visually with a lock icon rather than a bubble-color shift. End-to-end encryption ensures that only the sender and receiver can read the content of a message. This protects citizens from sophisticated cyber threats, data interceptions, and unauthorized surveillance. However RCS encryption is considered less secure than iMessage because RCS is a feature of network communications, whereas iMessage encryption is a feature of a service. All telecommunications infrastructure will fall short in terms of security due to lawful interception regulations over network-layer services. “Service provided encryption gives end users more of a security guarantee that treats both the network and the service itself as an adversary.” In most countries, networks are provisioned in law to be wiretapped. ## Sign up for Internet Exchange Feminist perspectives on digital justice and tech Subscribe Email sent! Check your inbox to complete your signup. No spam. Unsubscribe anytime. It’s important to note that communications using iMessage will remain in the realm of messaging service, rather than with RCS, which is a telecommunications service. Blue versus green bubbles will remain because, Apple says, these two modes are different from a protocol perspective. Apple’s announcement indicates this when it says “[iMessage] is the preferred option for Apple-to-Apple communication.” However this implies that privacy and security gains with interoperable E2EE in RCS are still somehow inferior to iMessage. RCS achieves its encryption with the MLS protocol, or Messaging Layer Security, an open encryption standard developed by the IETF designed to secure group and one-to-one messaging across platforms. RCS is the modern replacement for SMS, built into telecommunications networks rather than running as centralized services over networks. The GSMA’s interoperable standard ensures that individual company choices aren’t what stands between a user and their right to privacy in everyday communications. Last year, I published a playbook for E2EE interoperability in Tech Policy Press, making the case that it’s in users best interest to have interoperable E2EE messaging because it creates competition and lowers switching costs. Apple has had years to rectify its unfortunate history of working poorly with Google Messages, and end user privacy has been the casualty. “The US DOJ stepped in to sue Apple, accusing the tech giant of anticompetitive and monopolistic practices,” I wrote at the time. “The suit accused Apple of intentionally making iPhone users' texting experience with Android users worse,” while “Apple’s argument hinged upon technical considerations for security and privacy.” But interoperability has the potential to strengthen, rather than undermine, strong security designs. The just-announced progress on messaging has immediately led to security gains for billions of users. These gains, achieved with interoperability, run counter to the intuition that Apple and Google have, both in separate contexts, tried to instill in the policy community that interoperability creates vulnerabilities. Expert analysis says their claims are exaggerated at best. This beta rollout is a milestone, and security researchers are bound to scrutinize it, but the harder work of making strong E2EE interoperable across all messaging still lies ahead. * * * ## Help Make the Fediverse More Friendly The hardest part of joining a new social network isn't learning how it works, it's feeling connected. Find My Friends on the Social Web is a new privacy-first Android app designed to solve that problem for newcomers to the Fediverse. The app cross-references your phone contacts with Gravatar using only hashed data, so your contacts never leave your device. If any of your friends already have accounts on the social web, it surfaces them and lets you follow them in one tap. No central server. No data collection. The project is led by Evan Prodromou, co-author of ActivityPub, the open standard that powers the Fediverse, and Research Director at the Social Web Foundation, a nonprofit dedicated to growing the open social web. The core flow is already prototyped. Donations go toward a product designer, an Android developer, and a project manager. You can donate via the Social Web Foundation's fiscal host, Exchange Point. Donate on GoFundMe Want to appear here? Sponsor a newsletter. ****Support the Internet Exchange**** If you find our emails useful, consider becoming a paid subscriber! You'll get access to our members-only Signal community where we share ideas, discuss upcoming topics, and exchange links. Paid subscribers can also leave comments on posts and enjoy a warm, fuzzy feeling. Not ready for a long-term commitment? You can always leave us a tip. Become A Paid Subscriber * * * ## This Week's Links 🚨 ****Stop press! Do you enjoy our links?**** Links are now available to paid subscribers only. Become a paid subscriber today. ### This post is for subscribers only Become a member to get access to all content Subscribe now

internet.exchangepoint.tech

If we replace Google, will it be with one thing? Or many?

Search After Google

_By_ Erin Crandell The way people search for knowledge on the web is changing, but if we stop "googling" it, what will we do? My search strategies depend on my mood and what I'm looking for. For example: sometimes I want to figure out the hours of my local coffee shop. Other times I want a map of every café in a two-mile radius, or a directory where I can see the menu before I go, or a real person who can describe the ambiance. Sometimes I don't even mind getting into an information rabbit hole that leads me away from coffee entirely. While these are all acts of searching, they are not the same act, so do they require the same tool? This is the question that the decline of Google Search is forcing us to reckon with. Not just where we go when we stop googling, but what we actually want when we go looking for knowledge in the first place. ### Why We Search Research into online search behavior has revealed that why we search is more expansive than simple questions and answers. We search to verify, to accomplish, to learn, to explore, to be social. Search is deeply personal; each of us use different techniques, intentions, and behaviors to achieve what we are looking for when we enter a query. And those can change. Perhaps one single search tool cannot provide for all of that? ## Sign up for Internet Exchange Feminist perspectives on digital justice and tech Subscribe Email sent! Check your inbox to complete your signup. No spam. Unsubscribe anytime. Google still dominates 90% of the world’s search, but other big tech companies are moving in on that space and people report using generative AI tools like ChatGPT for many of the queries they previously turned to Google for. Meanwhile, a robust market of search tools and applications is also percolating: privacy and ad-blocking plug-ins, alternative search engines, and de-Googling movements. Some mimic Google’s interface while promising better privacy protections and fewer ads, while others offer users a chance to live their values or vision of an open web. All of these strategies and choices are techniques to reckon with the tension between privacy and convenience that is central to knowledge seeking in a technologically-mediated world. But for those of us who have been living uncomfortably under the corporate search model set by Google—aware that our data is being surveilled and siphoned but not seeing a viable alternative—this is a point to reconsider what we want search to look like. Is it a delivery service for fast facts? Or is it more like a library where you can browse? Do you want a librarian there? Or would you prefer to just have a relevant expert on speed dial? ### What Google Promised and What it Became While “Google Search is dead” is practically a meme at this point, Google changed the rules of its own game more than once. First, Google moved away from the PageRank algorithm toward models that collect even more user data and use machine-learning to ascertain searcher intent and provide direct answers. Then in 2023, they started directly integrating Generative AI into Google Search by adding AI-generated text boxes at the top of the search results page. And in 2025 it launched its own question answering chatbot. Google claims this model is the future of online search and that users like it! If you believe Sundar Pichai’s claim, people are actually clicking out from the AI overviews to a more diverse set of websites, and spending more time there. (Of course, website owners are reporting the opposite.) This is a trend Google promises will continue when search is then folded into a chatbot interface, so just trust the process! Regardless of whether you believe this, many other companies are following their lead and offering their own AI chatbot integrations. In the paper outlining this strategy, Google’s researchers championed the further integration of Generative AI into online search in the name of reducing the “cognitive burden” of online searching. Essentially, having an expert on speed dial. ### Now, The Opportunity A moment when the ground is shifting is the best time for rethinking the status quo. When Google announced AI mode, Corey Doctorow said, “Google's about to do something that's going to make people really angry. My first thought is 'Okay, great. What can we do to capitalize on that anger?' It's a chance to build a coalition”. While the coalition that Doctorow is envisioning may still be yet to come, people are moving to or building other platforms and tools for different forms of knowledge seeking that it seems like Google no longer provides. Whether it is because they believe that Google Search is no longer as reliable—as evidenced by the popularity of the “+ reddit” query hack to help filter through the onslaught of SEO-manipulated content and advertising on Google’s main search result page—or because of growing unease with Google’s broad apparatus of surveillance and data extraction, “googling” is no longer the only way people search. ### What People Are Doing Instead of Googling For now, what this may look like in practice is people embracing different tools for different purposes like a social media platform like Reddit or TikTok for advice or information from a real person, a Generative AI chatbot like ChatGPT for fast facts, and a more traditional search engine for everything else. For those traditional searches, a robust marketplace of alternatives is developing. ### Privacy as Product and Search as Subscription Most people so far haven’t been looking for complete opt-outs, but work-arounds, especially when it comes to privacy. A search on Google’s own App Store uncovers dozens of plug-ins, VPNs, browsers, and search engines promising to—at various technical levels—keep your searches private. The model has shifted from profile-for-service to privacy-as-product. DuckDuckGo is probably the most well-known of the alternatives, which uses Microsoft Bing, (he second most-used search engine in the world, as its base model, while adding additional user privacy protections. Going a step further, search engines like Brave or the European Search Perspective are building their own web indexes outside of Microsoft and Google’s infrastructure entirely. All of these engines position themselves as a familiar alternative to Google Search, offering very similar interfaces and affordances—even their own AI chatbot. Many of these companies also offer elevated privacy protections through a subscription model, which helps distance them from the profile-for-service model—while reinforcing the uncomfortable fact that search is always just one part of a network of services and technologies that collect data and surveille users. For $9.99 per month, you can not only use DuckDuckGo’s browser and search services, but you’ll also get access to email, VPN, Identity Theft restoration, and the advanced version of their AI chatbot. So, even if you opt out of Google Search (or even Google Search and Google Chrome), if you still use Gmail or YouTube or even a different website that partners with Google on the back end, your data is still in circulation. ### Is Opting Out an Option? Google has reshaped the political economy of the internet to the point that opting out is genuinely difficult, if not impossible. The company’s services are so embedded they are basically internet infrastructure—you don’t even have to visit the Google Search landing page anymore, you just type your query into the browser bar on browsers most of us use. Google’s terms and conditions are vague, constantly shifting, and fundamentally geared toward maintaining the status-quo—leaving even the most tech-savvy users and website managers playing catch-up. It is worth noting that the courts may also intervene. In the US, the Department of Justice's 2024 antitrust ruling against Google has put structural remedies on the table, including the possibility of a publicly accessible search index that could open the market to even more competition. So, perhaps under these circumstances, opting out and other practices of active non-participation gain more weight. ### Seeking Alternatives Based on Values This brings us to reconsidering Google Search because of values, in the context of other movements against Big Tech. In recent years, Google employees began organizing against the company’s contracts with ICE and the Israeli military, prompting users to consider the choice of search engine as a decision that reflects their values rather than just their needs. But beyond politics and a personal interest in privacy, there are other values that might influence someone’s choice of search engine, and the market seems ready to deliver. * Ecosia runs its search on both Google and Microsoft Bing’s architecture, but promises to plant a tree for every query. * Kagi offers an option called “Small Web” within its subscription model that displays entirely non-commercial results, connecting users back to the early days of the internet. * Sublime calls itself “an inspiration engine” where you can collect content from around the web and find related content through association. Some of these models may appeal to nostalgia for the “old internet” that people perceive as less polluted by commercial interests, when Google was simply a search engine that pledged to “not be evil” and helped us explore the vastness of the world wide web. The Reddit hack tapped into the same instinct: it promised to deliver you to people who could give you information that was shaped by their experiences,or at least articulated by themselves rather than an SEO strategist. ### Where Do We Go From Here? As we are evaluating the alternatives, it may be useful to return to the question of why we value search. In addition to promising convenience and reliability, Google Search promised to deliver, in essence, highly personalized access to knowledge. While Google may think that the future of search is experts on speed dial, people are fundamentally more intelligent and more curious than one single search engine can anticipate and provide for, and now is the time to re-evaluate. _Erin Crandell is a researcher and strategist working at the intersection of human rights and technology. She is currently completing her Master's degree in Digital Culture and Society at King's College London, and you can find more of her work and_ get in touch with her on LinkedIn. * * * ## Related Story: IX contributor Robin Berjon launches Funding The Web: a covenant for browsers, search, and people Browsers and mobile operating systems are complex and expensive, yet we universally get them free. This is because they are funded by a levy on search engines, and the amount of funding is huge: Apple alone gets over $20 billion per year. But if we just got free browsers that would be fine. The real problem is that the levy system is privately governed and has severe consequences. It maintains an artificial monopoly: the biggest search engine can pay more, which drives more traffic, which generates more money, which lets it pay more. It's the forever Google experience. Much worse, this system defunds the whole of the web, and notably the media. Thanks to its monopoly, Google charges far higher prices for ads than it normally could, and gets a much higher share of web marketing channels than it should. That's money, in the tens of billions, not flowing to the web. Browser vendors get a direct cut of those inflated prices. Google, Apple, Mozilla, Samsung, Opera: they all make money defunding the web says Robin. The levy system may not have been initially intended as a cartel, he wronte on Bluesky, but today it is maintained with full knowledge that it is monopolistic. The US courts have said so unambiguously. The web is slow-motion collapsing, and this is at the heart of it. But it doesn't have to be. Berjon's report documents the problems and offers a range of solutions to fix them. Read the report at ftw.fund Want to appear here? Sponsor a newsletter. ****Support the Internet Exchange**** If you find our emails useful, consider becoming a paid subscriber! You'll get access to our members-only Signal community where we share ideas, discuss upcoming topics, and exchange links. Paid subscribers can also leave comments on posts and enjoy a warm, fuzzy feeling. Not ready for a long-term commitment? You can always leave us a tip. Become A Paid Subscriber ## This Week's Links 🚨 ****Stop press! Do you enjoy our links?**** Links are now available to paid subscribers only. For a limited time, we’re offering 50% off an annual subscription. Normally $50 per year: right now you can subscribe for only $25. Become a paid subscriber today. ### This post is for subscribers only Become a member to get access to all content Subscribe now

internet.exchangepoint.tech

A chapter from the book Open For Debate: Governance, Power, and the Limits of Internet Openness

From the Commons to Rentierism: Governance Against a Closed Internet

_By_ Mallory Knodel, _originally printed in_ Open For Debate: Governance, Power, and the Limits of Internet Openness The open internet has long been associated with productivity and innovation. Interoperable protocols, decentralised governance, and low barriers to entry enabled new forms of entrepreneurship and knowledge diffusion across borders. However, the relationship between openness and economic growth has changed remarkably. Openness, once grounded in interoperability, has been leveraged to entrench platform monopolies. The reconceptualisation of openness has recast economic and social values of technology (Kilic & Knodel, 2025). While openness is often invoked as a normative ideal or technical property, less attention has been paid to the institutional transformations that have altered its economic function. The current phase of centralisation in digital technology is best understood not simply as a problem of surveillance or extraction, but as a shift toward digital rentierism embedded across multiple layers of infrastructure. In this context, regulatory intervention alone may be insufficient to preserve the open internet. Instead, governance strategies must also address the design of technical protocols and interoperability structures that shape accumulation dynamics upstream of market competition. We must reclaim "open" and a commitment to the commons on social and cultural grounds in the public interest. ## Sign up for Internet Exchange Feminist perspectives on digital justice and tech Subscribe Email sent! Check your inbox to complete your signup. No spam. Unsubscribe anytime. ### **From production and appropriation to rent** Early critiques of platform capitalism focused on production. The dominant concern was that users had become the product: their data and attention were monetised by advertising-based platforms (Zuboff, 2019). At the same time, the regulatory response centred on privacy—strengthening data protection rules, enhancing consent mechanisms, and embedding privacy into technical design. Instruments such as the General Data Protection Regulation (GDPR) exemplified this approach. However, privacy reforms did not significantly alter concentration patterns. If anything, compliance costs and trust dynamics reinforced incumbents, consolidating their position as primary "trust intermediaries." Privacy became a competitive advantage for dominant firms rather than a structural corrective. The production-focused diagnosis, while normatively important, did not sufficiently explain persistent centralisation. Another critique reframed the problem as appropriation. Here, the emphasis is on extractivism: platforms leveraging network effects and market power to appropriate value generated by users, creators, and complementary innovators (Mazzucato, 2018). The proposed remedy was to create alternatives: public options, regional "stacks," or open-source platforms such as Mastodon. Yet alternatives have struggled to dislodge entrenched incumbents. Network effects remain a formidable barrier, and user exit is constrained by the social and relational infrastructures that platforms monopolise. This impasse points to a third dimension: rentierism. Digital infrastructures—from submarine cables to cloud services, certificate authorities, DNS resolvers, and dominant social graphs—have become sites where control over essential intermediaries yields ongoing rents with minimal productive contribution. Once entrenched, these actors do not need to innovate or extract more intensively; they simply collect rents from ownership of bottleneck positions (Saito & Sasaki, 2025). Such dynamics extend beyond the application layer into core internet infrastructure. The result is a structural enclosure of what might be termed "human relationality" as a digital common. ### **The limits of competition and sovereignty** Traditional competition law struggles to address rentier dynamics embedded in layered infrastructures. Antitrust law can discipline specific abuses but rarely restructures the underlying network topology. Even ambitious interventions such as the EU Digital Markets Act (DMA) focus primarily on conduct obligations rather than architectural transformation. Similarly, digital sovereignty strategies like data localisation mandates, national champions, or regionally bounded service ecosystems may rebalance geopolitical power but do not necessarily restore openness. They can narrow the field of intermediaries without altering the logic of enclosure. Substituting national monopolies for global ones leaves the rent structure intact. Cross-border data governance frameworks further complicate this picture. Trade agreements seek to liberalise data flows, while rights-based regimes emphasise protection in "digital sovereignty" initiatives that are rebrands of typical networks-versus-services tussles (Clark, 2005). However, neither approach systematically addresses infrastructural concentration. Economic integration may expand markets, but without structural interoperability, gains accrue disproportionately to incumbents controlling key intermediation points. ### **Weak points in the stack** One indicator of rentier entrenchment is the presence of "patchwork" governance regimes that paper over architectural weaknesses. The certificate authority ecosystem provides a salient example. The CA/Browser Forum is a private governance body coordinating trust anchors for TLS (the Transport Layer Security protocol is the predominant way client/server applications communicate over the internet in a way that is designed to prevent eavesdropping, tampering, and message forgery) and occupies a highly consequential yet underappreciated position. Decisions within this forum have had geopolitical ramifications, including the removal of certain certificate authorities following Russia's invasion of Ukraine. The trust model for HTTPS (Hypertext Transfer Protocol is the dominant protocol for distributed, collaborative, hypermedia information systems. HTTPS uses TLS to secure HTTP connections over the internet) relies on centralised authorities whose governance is neither fully public nor fully accountable, revealing both concentration and fragility. Similarly, the DoH (DNS over HTTPS is a protocol for sending DNS queries and getting DNS responses over HTTPS) debate illustrates how privacy-enhancing reforms can inadvertently centralise resolution services. Users prefer a trusted provider for DNS lookups rather than conventional, opportunistic, and more decentralised lookups via their ISP. While encrypting DNS queries mitigates surveillance risks, the shift toward a small number of global DoH providers consolidates trust in a handful of intermediaries. Privacy gains at one layer may therefore reinforce rentier dynamics at another (Knodel, 2023). Other weak points include the concentration of root server operators, supply chain dependencies in hardware and semiconductors, and the growing dominance of private satellite constellations in space-based internet infrastructure. Each represents a layer where control yields durable rents insulated from competitive churn. ### **Interoperability as structural intervention** If rentierism is embedded in infrastructural bottlenecks, then preserving openness as a driver of growth requires interventions that alter intermediation structures rather than merely disciplining conduct. Here, interoperability becomes central. Open social protocols such as ActivityPub, ATProto, and the Decentralised Social Networking Protocol (DSNP) illustrate alternative architectures. By enabling cross-platform communication, these protocols reduce switching costs and weaken network effects that lock users into dominant platforms. However, voluntary adoption has been limited. At the same time, without regulatory impetus, such as interoperability obligations under the DMA, dominant firms lack incentives to open their networks. Interoperability thus sits at the intersection of standards and regulation. Technical standards define the possibility space; regulation can mandate or incentivise their implementation. This triangular model—standards development, regulatory enforcement, and corporate advocacy—reflects an evolution in governance strategy. Protocol design shapes market structure upstream of competition law. Regulatory frameworks can accelerate adoption. Direct engagement within standards bodies allows public-interest considerations to influence technical architecture before it becomes entrenched. Importantly, not all technical mandates are appropriate. Expanding the political mandate of standards bodies risks technocratising inherently social disputes. However, carefully targeted interoperability requirements, particularly at higher layers of the stack, may counteract enclosure without fragmenting the global network. ### **Openness and growth reconsidered** Historically, openness fostered growth by lowering transaction costs, enabling entry, and facilitating knowledge spillovers. Rentier concentration reverses these dynamics. High switching costs, data silos, and infrastructural gatekeeping dampen entrepreneurial experimentation and distort capital allocation toward rent-seeking positions. The early internet culture's undying loyalty to openness and the commons has served to stave off rentierism for longer and more durably than earlier regulatory interventions would have. The digital commons has achieved the fabled balance between innovation and regulation, which is why it has been an ideological and tactical target of Big Tech companies seeking monopoly positions. From a growth perspective, the enclosure of digital commons reduces allocative efficiency and long-term innovation potential. While short-term adaptive strategies, such as national stacks, compliance regimes, or bilateral trade deals, may mitigate geopolitical vulnerabilities, they do not address the structural transformation of openness into controlled intermediation. Safeguarding openness as a prerequisite for sustainable economic progress, therefore, requires a governance approach attentive to architectural design. Regulatory instruments such as the DMA, GDPR, and cross-border data frameworks are necessary but insufficient. Without interoperable infrastructures that enable meaningful exit and entry, network effects will continue to entrench rent positions beyond the reach of ex post regulation. One way that regulatory action has failed to address equities in a way that would preserve the commons is the Digital Services Act's targeting of Wikipedia as a "very large online platform" (Wikipedia, 2025). In this sense, openness is not merely a normative commitment but an institutional condition for dynamic growth. Its preservation depends on aligning technical standards, regulatory mandates, and market incentives to prevent the irreversible enclosure of digital commons. If rentier dynamics embedded in infrastructural bottlenecks are the core threat to openness and growth, then interoperability mandates should be treated not as optional competition remedies but as structural economic policy. Requiring dominant platforms and infrastructures to implement open protocols—at social, messaging, and identity layers—would reduce switching costs, restore contestability, and reorient accumulation away from rent extraction toward productive innovation. Absent such measures, regulatory efforts risk managing decline rather than reversing enclosure. * * * ## From the Group Chat 👥 💬 Like many in the public interest technology community, we've spent the past two weeks discussing the cancellation of RightsCon in Zambia. Many IX community members had planned to attend, and the sudden cancellation was deeply disappointing. If you're trying to understand what happened, here are two interesting reads: 1. Tunde Okunoye, a Doctoral Fellow under the Standard Bank Chair in African Trust Infrastructures at the University of the Witwatersrand, Johannesburg South Africa examines how China's growing economic leverage and development assistance in Africa are reshaping the geopolitical landscape for digital rights, with the RightsCon cancellation serving as a critical example of Beijing's influence. https://developmentmusings.medium.com/china-and-the-emerging-geopolitics-political-economy-of-digital-rights-in-the-global-south-197a2545a5f0 2. Michael Caster, Head of the Global China Program at ARTICLE 19, argues that China's pressure on Zambia to cancel RightsCon exemplifies Beijing's broader campaign to undermine multistakeholder digital governance in favor of state-centric authoritarianism, calling for democracies to counter this influence through rights-based alternatives and renewed support for inclusive global forums. https://www.techpolicy.press/chinas-disruption-of-rightscon-is-a-wakeup-call-to-counter-its-authoritarian-influence And if you still want a taste of RightsCon, FabRiders moved their planned facilitative leadership session from RightsCon online and opened it to all participants as a free alternative gathering. **May 8. Online**. https://www.fabriders.net/rightscon-cancelled-join-us-online Want to appear here? Sponsor a newsletter. ****Support the Internet Exchange**** If you find our emails useful, consider becoming a paid subscriber! You'll get access to our members-only Signal community where we share ideas, discuss upcoming topics, and exchange links. Paid subscribers can also leave comments on posts and enjoy a warm, fuzzy feeling. Not ready for a long-term commitment? You can always leave us a tip. Become A Paid Subscriber ## This Week's Links ### Open Social Web * Policy people often talk about two types of interoperability: "horizontal" (systems talking to each other as equals, like two messaging apps) and "vertical" (one system running on top of another, like an app running on an operating system). But Robin Berjon explains that real systems are more like governments with different roles and responsibilities. Some people can approve things, some can moderate, some can vote. Good internet protocols should work the same way, giving different actors in the system different powers that can check and balance each other, just like democracy. Bluesky's AT Protocol is designed this way, letting different parts of the network be governed separately while still working together. https://berjon.com/interoperability * FediForum published proceedings from its April gathering covering end-to-end encryption in ActivityPub, AT Protocol architecture, governance models, moderation tooling, and growth strategies for the Fediverse and Atmosphere. https://fediforum.org/2026-04 * The Electronic Frontier Foundation published a guide to bridging Mastodon, Bluesky, and Threads accounts so posts reach audiences across platforms without requiring multiple accounts, using tools like Bridgy Fed. https://www.eff.org/deeplinks/2026/04/bridge-somewhere-how-link-your-mastodon-bluesky-or-other-federated-accounts 🚨 ****Stop press! Do you enjoy our links?**** This week's additional ****40+ links**** are now available to paid subscribers only. For a limited time, we’re offering 50% off an annual subscription. Normally $50 per year: right now you can subscribe for only $25. Become a paid subscriber today. ### This post is for subscribers only Become a member to get access to all content Subscribe now

internet.exchangepoint.tech

Green Web Foundation thinks not enough.

What do cloud service companies disclose about their use of fossil fuels?

_By_ Chris Adams Major cloud providers (Google, Amazon, Microsoft) aren't publicly disclosing basic information about how their data centers are powered, even data they're already required to report to regulators. In our recent report, State of the Fossil-Free Internet 2026, we include a table with a transparency score based on four questions about company disclosures of how data centres are powered, checked against the information published on what is one of the more complete open datasets on the topic from a leading industry group dedicated to greener software solutions. You can see this chart below, or in a larger version on our website: ### Why do we look at these three firms? When we think about the global buildout of gigantic datacentres changing the footprint of the internet, there are three companies, Alphabet, Amazon and Microsoft, who offer families of cloud services, under the names Google Cloud, Amazon Web Services, and Microsoft Azure respectively. These historically have made up more than half of the hyperscale cloud market. When we look at the current, massive levels of investment in datacentre buildout globally, they also make up a disproportionately large share of the capital expenditure, which has doubled since the release of ChatGPT. ## Sign up for Internet Exchange Feminist perspectives on digital justice and tech Subscribe Email sent! Check your inbox to complete your signup. No spam. Unsubscribe anytime. ### Why are they important for decarbonisation of the internet? Since the boom in artificial intelligence, the total emissions of Alphabet, Amazon and Microsoft have been growing, but these companies have also consistently been the largest investors in clean energy in the corporate sector, with bold public announcements of net-zero targets. How they spend money on energy has a direct impact on how quickly the sector decarbonises. Their structural importance and market dominance also now means that if you use any mainstream digital service in 2026, it’s likely that at least one of these cloud service providers is in its supply chain. Either you’re a direct customer of these companies, or one of your suppliers will be. Faced with this, when we think about tracking progress towards a fossil-free internet, how these three companies disclose information is crucial to our understanding of what is happening across the internet’s infrastructure and in the software and apps we build and use worldwide. ### What did we base our transparency score on? The Green Software Foundation is an industry association composed of dozens of tech companies, institutions and non-profits working together to solve sustainability challenges and exchange information on how to build greener systems. We chose the Cloud Region Metadata dataset by the Real Time Cloud Working Group of the Green Software Foundation as the basis for the transparency score in our report. The dataset was developed with early involvement from cloud service providers, and there was a rigorous process for collecting the data over the last two years, which we have actively participated in ourselves. We chose this dataset because it provides information at the cloud region level, matching how customers select deployment locations in their dashboards, so companies can choose regions powered by renewable energy. The dataset is public and openly licensed (permissive MIT license), meaning it can be freely integrated into commercial and non-commercial products. Its columns are clearly documented using existing standards and reporting requirements, such as Europe's Energy Efficiency Directive. The dataset is also on a standards track to become an internationally recognized standard for cloud region reporting, stewarded by the Green Software Foundation, which established the Software Carbon Intensity ISO standard. While there remain data gaps, this is currently one of the most complete datasets in the public domain that we can refer to, and the governance process is clearer than with most other datasets we have seen. We looked at the most recent available data at the time, which was for 2024. ### What did we look for in the dataset? For the State of the Fossil Free Internet, we wanted to track progress towards the decarbonisation of the internet. We wanted to document how the trajectory has changed, compared to an earlier era of gradual decarbonisation that we saw in the late 2010s and early 2020s. However, we don’t have access to granular data in a standardised format that enables us to do this type of comparison—even for the three biggest companies in the cloud sector. Based on the (usually empty) data fields in this public dataset, we developed four questions (in plain language) that get to the heart of what we most need for transparency. These questions are: 1. Do they disclose how much renewable power is generated at their sites? 2. Do they disclose their reliance on ‘unbundled’ certificates for renewable energy? 3. Do they disclose their use of carbon free energy on an hourly basis? 4. Do they disclose their burning of fossil fuels at specific sites in all regions? Let’s look at each question and what data is out there. ### 1. Do they disclose how much renewable power is generated at their sites? When you say a datacentre runs on clean, green or renewable energy, a lot of the time it conjures images of a building with solar panels on the roof, or wind turbines sited right next to the facility containing the servers. Large companies do very little to dispel this image—just see the example from Google’s datacentre site below. However, the reality is that datacenters' energy density requires far more generation than can be produced onsite. A 100 MW datacenter would need at least 400 acres of solar panels, far exceeding what's visible at these facilities. So our first question is whether companies transparently reported how much renewable energy is actually generated onsite versus sourced through other means. Using the dataset, we found that while European laws (the Energy Efficiency Directive and Delegated Regulation 2024/1364) require companies to report this figure at the datacenter level, meaning the data exists and is being disclosed to regulators, none of the big three cloud providers publicly disclosed this information at the cloud region level. ### 2. Do they disclose their reliance on ‘unbundled’ certificates for renewable energy? If datacentres aren’t really powered by onsite green energy that much, what is the _next_ most common way to power them? Rather than generating renewable energy onsite, companies often take a cheaper shortcut: purchasing electricity from the grid and buying unbundled annual clean energy certificates to claim renewable consumption. While accepted under standards like the GHG Protocol, a widely used carbon accounting framework, it has credibility issues. Many people want to know whether green energy claims are based on actual onsite generation or just purchased certificates. Certificate-based claims are arguably less credible than onsite generation or long-term power purchase agreements which fund new renewable infrastructure like wind farms. Data from the European Commission shows that certificates, called Guarantees of Origin in Europe, are far more commonly used than either onsite generation or PPAs. The Real Time Cloud dataset includes a column for certificate-based consumption, and again, in Europe companies have to disclose this at a datacentre level under the same laws as they do for onsite generation. So, the data does exist to disclose this, and will have already been collected. But so far, no companies have publicly disclosed this at a region level in the Real Time Cloud dataset. ### 3. Do they disclose their use of carbon free energy on an hourly basis? In response to the problems associated with ‘unbundled’ annual certificates, a new, more credible way to claim clean energy generation is based around _hourly_ clean energy certificates. Under an hourly scheme, a claim to be using clean energy at night would have to be backed by a certificate for clean energy that was either generated at night, or generated during the day then stored in a battery until the battery was discharged at night. This results in a more credible claim to use clean energy than before, because it more accurately represents what is happening on the electricity grids. This hourly basis will likely become the main standard for tracking the ‘greenness’ of energy in the GHG Protocol’s Scope 2 guidance. We will ourselves also update our verification process for the Green Web Check directory largely based on the expected shift to this hourly approach. Both Microsoft and Google made public commitments in 2020 to transition to running entirely on clean energy backed by hourly certificates by 2030. This is a column in the dataset, under provider-cfe-hourly. Google Cloud has a relatively high score for disclosure on this point, while Microsoft Azure and Amazon Web Services do not. ### 4. Do they disclose their burning of fossil fuels at specific sites in all regions? The final question looks at whether fossil fuels are being burned at datacenters to power servers. This likely represents one of the biggest shifts we have seen in the recent years when we look at how datacentres are powered. In the past, datacenters only burned fossil fuels occasionally—testing backup diesel generators for a few dozen hours out of 8,760 hours per year. However, this is something changing quickly in both new and existing regions for cloud services companies. A clear example is Microsoft Azure’s northeurope campus, which has onsite generators that run on methane gas for up to 8 hours a day to supplement the local electricity grid. The 170 MW of onsite gas generation capacity would have been a very large datacentre facility all by itself a few years ago. Elsewhere in the same part of the world, we now see datacentres relying on fossil generation as the _primary_ source of power, as in a recent example of a 110 MW facility from Pure Data Centres in Dublin, Ireland. This is not generation as a backup, or as a supplement to the grid—this is part of a new trend of off-grid datacentres. While it is not publicly disclosed who the tenants are for this facility, this project is designed for hyperscaler tenants like the big three firms we mention. There are other examples of the big three using offgrid facilities like this. Across the Atlantic, Microsoft announced a new project in March to run datacentre facilities on more than gigawatt of offgrid gas power in Virginia.Elsewhere in Utah, authorities are voting on whether to approve a new 9 gigawatt, off-grid datacentre facility, explicitly aimed at US hyperscalers. At full capacity, this would consume twice the power of the entire state. Despite this being a key concern, the Real Time Cloud dataset doesn't yet track primary onsite fossil fuel use. European datacenter operators currently only report backup generation under existing laws. However, this is in a new proposed datacentre labelling scheme for Europe that was announced in March. ### How did we generate our transparency score? As is plainly visible in our score chart, neither of the three companies have been publicly transparent in standardised ways that would enable us to track progress towards a fossil-free internet in any region. For most of these data points there are 0% disclosures. Of the three providers, Google is alone in publishing figures for the amount of hourly matched power it uses at a region level in machine-readable form, on a public github repo. The dataset also covers other indicators relating to the sustainability of datacentres like PUE (i.e. how efficiently they cool hardware), WUE (how much water they consume for each unit of power consumed), and so on. Fossil fuels are not being tracked in this data set, but we believe they should be. This is our first attempt at developing this type of data driven transparency score, and we are happy to discuss and hear feedback. We hope (and expect) to see improvements in transparency from year to year. Read State of the Fossil-Free Internet 2026 for the full story. * * * ## The Sovereign Tech Standards network to support open source maintainers shaping standards Germany's Sovereign Tech Agency launched a pilot program providing financial support for open source maintainers to participate in standards development at IETF, W3C, and ISO. The program addresses a structural gap. While large tech companies treat standards participation as strategic investment, independent maintainers who build the software implementing these standards often cannot afford the time or resources to engage. Selected participants receive €4,800-€5,200 monthly compensation, training on how standards bodies operate, ongoing mentoring from experienced contributors, reimbursement for participation fees, and travel support for in-person meetings. **Applications close May 19.** Join the Sovereign Tech Standards Network Want to appear here? Sponsor a newsletter. ****Support the Internet Exchange**** If you find our emails useful, consider becoming a paid subscriber! You'll get access to our members-only Signal community where we share ideas, discuss upcoming topics, and exchange links. Paid subscribers can also leave comments on posts and enjoy a warm, fuzzy feeling. Not ready for a long-term commitment? You can always leave us a tip. Become A Paid Subscriber ## **This Week's Links** 🚨 ****Stop press! Do you enjoy our links?**** Links are now available to paid subscribers only. For a limited time, we’re offering 50% off an annual subscription. Normally $50 per year: right now you can subscribe for only $25. Become a paid subscriber today. ### This post is for subscribers only Become a member to get access to all content Subscribe now

internet.exchangepoint.tech

The IGF considers its future as a permanent UN mandate.

Shaping What Comes Next: Inside the IGF Expert Group Meeting

_By_ Mallory Knodel_, Also published on_ Social Web Foundation_._ Last week at the Internet Governance Forum (IGF) Expert Group Meeting we considered what changes to this 20-year-old, UN initiative are required now that the UN General Assembly has made it permanent. This small, invitation-only gathering was tasked with the future of the IGF as a permanent UN mandate and how it achieves outcomes. Now that the IGF’s place at the UN is secure, we can stop trying to prove that multistakeholder dialogue matters, and start showing what multistakeholder governance is multistakeholder governance is capable of delivering. This means civil society can find purchase for its work in IGF work itself, rather than considering the annual meeting a venue for outreach and promotion of its work that ultimately happens in other places. The IGF is being actively redefined and the process is open to meaningful influence. I attended representing the Social Web Foundation, both a civil society organization and a key player in the technical community. My remarks were informed by other civil society organizations: the Association for Progressive Communications and its members. Across discussions several core tensions and opportunities emerged. Rather than either/or, in almost all cases I view the IGF as being able to balance both: 1. **Dialogue _and_ influence decisions. **There is clear pressure for the IGF to move beyond being a convening space and toward something that can influence decision-making processes. This includes stronger alignment with global frameworks like World Summit on the Information Society (WSIS) and the Global Digital Compact, and more intentional pathways for IGF outputs to inform policy fora. This is possible without losing the open, iterative, multistakeholder dialogue that makes the IGF valuable. The approach is to enhance and make more visible the IGF’s ongoing work between annual meetings. Like standards bodies, the authority to push forward points of view and outputs within intersessional work rests on those who are participating in those processes, and the fact that the output is part of a multistakeholder UN process. 2. **Institutionalize top-down _and_ elevate bottom-up. **The permanent mandate creates an opportunity to rethink governance, structures, and operations of the annual meeting. At the same time there is broad recognition that the IGF’s legitimacy comes from its bottom-up nature, particularly through national and regional initiatives (NRIs). Embedding those processes more directly into governance is essential to strengthening the utility of top-down institutionalization while putting resources and attention on the more valuable bottom-up and direct impact potential of NRIs. ## Sign up for Internet Exchange Feminist perspectives on digital justice and tech Subscribe Email sent! Check your inbox to complete your signup. No spam. Unsubscribe anytime. For those of us working on the social web, open protocols, and public-interest infrastructure, this moment is a significant one that can help leverage the IGF toward outcomes, not just outreach. The IGF has long been a space where principles of openness, interoperability, decentralization are articulated. Last year SWF hosted an IGF session on decentralized social media. What is changing now is the hope, or the expectation, that concrete ideas grounded in these principles can translate into real outcomes both in policy processes and technical designs. To achieve this, two elements are needed: topic coherence and inclusion. Concrete proposals already exist to strengthen topic coherence through organizing work into thematic clusters, streamlining and better coordinating ongoing work between annual meetings, and producing outputs that are targeted and usable. Some cross-institutional examples for the potential impact of IGF intersessional work: * The IGF Best Practice Forum on Cybersecurity has mapped and advanced international cybersecurity norms, producing outputs that feed into UN processes, national policy debates, and capacity-building initiatives across the ecosystem. * The IGF Policy Network on Meaningful Access has produced concrete recommendations on connectivity and digital inclusion that have been taken up in Global Digital Compact discussions and broader UN development processes. * The Internet Architecture Board – not an IGF intersessional group – made a statement about the technical hurdles to backdoor encrypted messaging that was specific and credible to the debate at hand given its composition, not its authority. * The IETF created the technical standard for non-Latin domain names, ICANN deployed it operationally, and ITU Resolution 133 created pressure from governments to implement it. Strengthening intersessional work reflects a shift toward treating the IGF as an ongoing governance process, not just a yearly event. Moreover inclusion gets addressed if participation can be reframed not just as a value but as infrastructure. Unlike other internet governance institutions like global standards bodies, the UN provides funding for participation, language accessibility, and mechanisms for meaningful engagement from underrepresented groups and developing countries. Substantively, the IGF can attract more structured engagement with governments, while simultaneously advancing openness to non-state actors in settings that have traditionally been the exclusive domain of multilateral diplomacy. What was clear in this meeting is that this outcome is not predetermined. It is being actively constructed and influenced by those participating in the process. The next phase will include rounds of consultations on many of the subjects under consideration by this small expert group. It’s important to think about how to leverage the IGF for tangible outcomes that bridge SDOs and other sites of influence over internet governance. * * * Want to appear here? Sponsor a newsletter. ****Support the Internet Exchange**** If you find our emails useful, consider becoming a paid subscriber! You'll get access to our members-only Signal community where we share ideas, discuss upcoming topics, and exchange links. Paid subscribers can also leave comments on posts and enjoy a warm, fuzzy feeling. Not ready for a long-term commitment? You can always leave us a tip. Become A Paid Subscriber ## This Week's Links 🚨 ****Stop press! Do you enjoy our links?**** Links are now available to paid subscribers only. For a limited time, we’re offering 50% off an annual subscription. Normally $50 per year: right now you can subscribe for only $25. Become a paid subscriber today. ### This post is for subscribers only Become a member to get access to all content Subscribe now

internet.exchangepoint.tech

A new IETF working draft sets out a technology-neutral framework for age assurance on the internet, comparing methods across service, device, and network enforcement layers.

Internet Standards and Age Verification Architecture

This is a working Internet-Draft submitted to the Internet Engineering Task Force (IETF), the body responsible for developing the open standards that the internet runs on. Before a draft becomes a standard, it is published for review and comment by the wider technical and policy community. This draft is at that stage now. Read The Full Draft It is authored by Mallory Knodel of the Social Web Foundation, Gianpaolo Angelo Scalone of Vodafone Group, Tom Newton of Qoria, and Audrey Hingle of Exchange Point, bringing together expertise across civil society, telecommunications, child safety technology, and internet infrastructure. If you are working on age assurance policy, regulation, or implementation, this draft describes the technical landscape in terms that policy discussions can engage with directly. It sets out a solution-agnostic and technology-neutral framework for how various intermediaries can gate content and services based on age, analyses the effectiveness of each approach, and covers privacy, security and human rights considerations that any system will need to address. Age-gating methods compared by effectiveness and privacy cost across service, device, and network enforcement layers. Many age verification methods conflict with data protection principles and pose serious safety, security, and privacy risks. Requiring all users on all platforms to submit verifiable credentials can create large, sensitive data stores in centralised intermediaries that are vulnerable to breaches, fraud, or misuse. Once compromised, this information is difficult if not impossible to secure again. Reducing harm to children on the internet requires an incremental, all-hands approach and cannot be solved by age verification alone. A more resilient approach relies on a plurality of mechanisms operating at different layers of the internet architecture, each limited in scope and aligned with privacy-by-design principles. ### Not all platforms are the same Age-assurance mechanisms cannot be applied uniformly across the internet because different platforms have different relationships with their users, with personal data, and with the law. Core internet infrastructure should remain neutral. Asking networks to make decisions about individual users introduces censorship risks. Government services, by contrast, are already identity-bound by law and can treat age as part of an existing verified identity framework. Essential services such as banking, healthcare, and education must stay broadly accessible, so the bar for age assurance here should be low. General-use platforms are the most contested area. Social media, messaging, gaming, and app stores mix adult and minor audiences at scale across many jurisdictions. Each has its own enforcement logic: a messaging platform cannot inspect private content, so it relies on account or device-level signals; a gaming platform can use guardian consent and payment signals; an app store can enforce consistent age labels that flow through to the apps it distributes. What counts as adult content also varies by jurisdiction. Material classified as restricted in one country may be considered normal commercial or artistic content in another. Any system has to account for this rather than impose a single global classification. Read The Full Draft ## Sign up for Internet Exchange Feminist perspectives on digital justice and tech Subscribe Email sent! Check your inbox to complete your signup. No spam. Unsubscribe anytime. ## This Week's Links ### Age Verification & Social Media Bans * The EU's age verification app is technically ready, von der Leyen announced, telling online platforms they have "no more excuses" for not checking users' ages. The app lets people verify their age via passport, national ID, or trusted providers like banks, without platforms logging any personal data. https://www.politico.eu/article/eu-says-age-verification-app-is-technically-ready * Roblox will need age verification to make sure you’re at least 9 years old. People who don’t do an age check can only access family-friendly games. https://www.theverge.com/games/910218/roblox-age-verification-check-games-kids-select-accounts * Researchers from Harvard's Berkman Klein Center argue in Science that blanket social media bans and age restrictions for children are blunt, often counterproductive tools, and that evidence-based design approaches such as trust-building, help-seeking pathways, on-device nudges, and participatory education offer a more effective path to digital child safety. https://www.science.org/doi/10.1126/science.aec7804 ### Open Social Web * What if social media was designed from the ground up to support local communities? That’s the question New_ Public had in mind when they built Roundabout: a local community platform with curated feeds, event calendars and more built on AT Protocol. Prosocial Design Network sat down with four members of their team, Sam Liebeskind, Trei Brundrett, Blaine Cook, and Adit Dhanushkodi, to learn more about it. https://www.prosocialdesign.org/blog/building-roundabout-a-pro-social-platform-for-local-communities * Researchers from EPFL and Princeton introduce Bonsai, a tool that lets users create intentional, personalised social media feeds on Bluesky using natural language prompts rather than engagement-optimised algorithms. A two-week study found users felt more in control but building good feeds took more effort than they expected. https://arxiv.org/pdf/2509.10776 🚨 ****Stop press! Do you enjoy our links?**** The rest of this week's links, covering internet governance, digital rights, technology for society and privacy and security are available to paid subscribers only. For a limited time, we’re offering 50% off an annual subscription. Normally $50 per year: right now you can subscribe for only $25. Become a paid subscriber today. ### This post is for subscribers only Become a member to get access to all content Subscribe now

internet.exchangepoint.tech

This is a working Internet-Draft submitted to the Internet Engineering Task Force (IETF), the body responsible for developing the open standards that the internet runs on. Before a draft becomes a standard, it is published for review and comment by the wider technical and policy community. This […]

Internet Standards and Age Verification Architecture

This is a working Internet-Draft submitted to the Internet Engineering Task Force (IETF), the body responsible for developing the open standards that the internet runs on. Before a draft becomes a standard, it is published for review and comment by the wider technical and policy community. This draft is at that stage now. Read The Full Draft It is authored by Mallory Knodel of the Social Web Foundation, Gianpaolo Angelo Scalone of Vodafone Group, Tom Newton of Qoria, and Audrey Hingle of Exchange Point, bringing together expertise across civil society, telecommunications, child safety technology, and internet infrastructure. If you are working on age assurance policy, regulation, or implementation, this draft describes the technical landscape in terms that policy discussions can engage with directly. It sets out a solution-agnostic and technology-neutral framework for how various intermediaries can gate content and services based on age, analyses the effectiveness of each approach, and covers privacy, security and human rights considerations that any system will need to address. Age-gating methods compared by effectiveness and privacy cost across service, device, and network enforcement layers. Many age verification methods conflict with data protection principles and pose serious safety, security, and privacy risks. Requiring all users on all platforms to submit verifiable credentials can create large, sensitive data stores in centralised intermediaries that are vulnerable to breaches, fraud, or misuse. Once compromised, this information is difficult if not impossible to secure again. Reducing harm to children on the internet requires an incremental, all-hands approach and cannot be solved by age verification alone. A more resilient approach relies on a plurality of mechanisms operating at different layers of the internet architecture, each limited in scope and aligned with privacy-by-design principles. ### Not all platforms are the same Age-assurance mechanisms cannot be applied uniformly across the internet because different platforms have different relationships with their users, with personal data, and with the law. Core internet infrastructure should remain neutral. Asking networks to make decisions about individual users introduces censorship risks. Government services, by contrast, are already identity-bound by law and can treat age as part of an existing verified identity framework. Essential services such as banking, healthcare, and education must stay broadly accessible, so the bar for age assurance here should be low. General-use platforms are the most contested area. Social media, messaging, gaming, and app stores mix adult and minor audiences at scale across many jurisdictions. Each has its own enforcement logic: a messaging platform cannot inspect private content, so it relies on account or device-level signals; a gaming platform can use guardian consent and payment signals; an app store can enforce consistent age labels that flow through to the apps it distributes. What counts as adult content also varies by jurisdiction. Material classified as restricted in one country may be considered normal commercial or artistic content in another. Any system has to account for this rather than impose a single global classification. Read The Full Draft

internet.exchangepoint.tech

Jackson's legacy includes marching with Dr King and running for president twice. Less known is the work he did pushing tech companies to confront discrimination.

Jesse Jackson’s Legacy on Civil Rights and Technology

_By_ Mallory Knodel On April 4th, the anniversary of Dr. Martin Luther King Jr.'s assassination in 1968, I was reminded of the generations of civil rights leaders he inspired. Jesse Jackson is a great example, lost just this year, whose legacy includes marching with Dr. King and running for president twice. Less known is the work he did in his final years: pushing tech companies to confront discrimination on their platforms. I’ve spent years working on racial justice in technology. I’ve sat through countless meetings in which engineers promise that algorithms will solve problems that centuries of activism couldn’t. I’ve watched companies announce diversity initiatives with fanfare, then quietly shelve them when the press cycle moves on. Cynicism comes easy in this work. But hearing a man who had marched with Martin Luther King Jr., who had spent decades translating moral urgency into political power engage seriously with the mechanics and metrics of tech platform usage? That unexpectedly gave me a feeling of hope. We already have a crucial asset to save society from runaway technology and too-big tech companies: civil rights leadership. ## Sign up for Internet Exchange Feminist perspectives on digital justice and tech Subscribe Email sent! Check your inbox to complete your signup. No spam. Unsubscribe anytime. That hope came into focus for me through direct experience working on the committee for Airbnb’s Project Lighthouse, a tool Airbnb uses in the United States to uncover and address disparities in how users of different perceived races experience the platform. Airbnb developed it with guidance from a number of leading civil rights and privacy organizations, including the Color of Change, who invited Jackson to join a call about the project, and Center for Democracy and Technology, where I was the CTO. The data that informed the work of our committee was damning. Hosts who perceived guests to be Black allowed fewer successful bookings than for guests perceived to be white. These were known issues exposed by external research as early as 2015, and many of the fixes nearly a decade later mirrored their recommendations. But internal to Airbnb it took data, advocacy, accompaniment and public pressure from civil rights organizations to make common sense changes, without which Airbnb would be in violation of civil rights law if only we regulated “tech platforms” like we regulate hotels and restaurants. As a technologist I’ll be the first to point out that the technocratic impulse to measure, to optimize, to declare victory when the numbers tick in the right direction is not the same as durable social change. Laura W. Murphy put it more generously: “Airbnb has presented a powerful example of how to design products and build a community that is more welcoming for everyone. It’s the right thing to do and it’s good for business.” I’ve worked on internet standards and terminology debates where the stakes felt abstract, where arguments about inclusive language in technical documents seemed disconnected from the lived experience of discrimination. Project Lighthouse turned platform decisions and user data into outcomes that civil rights advocates could demand accountability for. Jackson’s presence on that call wasn’t as a technologist. What he brought was something absolutely crucial to the case for change: the weight of history, the reminder that every incremental gain was earned through struggle, and the insistence that measurable progress, however imperfect, beats performative concern. Color Of Change worked with Airbnb for a year before the company launched the initiative. The result was a tech team whose job is to fight bias, changes to when hosts see guests’ photos, recruitment of more people of color as hosts, and new benchmarks for diversity on staff and the board of directors. Airbnb’s own report acknowledges there is no finish line, however. They’ve made hundreds of updates to their service in the last few years, including refinements to how hosts decline reservation requests and stronger policies against hosts who cancel existing reservations under suspicious circumstances. They updated their Non-Discrimination Policy to include protections against caste discrimination. They launched an Entrepreneurship Academy to introduce people from underrepresented communities to hosting. None of this would have happened without outside pressure. Without civil rights organizations willing to engage with the details of product and platform design. Without leaders like Jackson willing to lend their credibility to a process that could easily have been dismissed as corporate window dressing. I think about that phone call often, and now Jackson is gone. The way his voice reminded everyone why we were there: To take the promise of technology and hold companies accountable when they fall short, it’s on the rest of us to continue the work. Jackson understood something essential: technology can change when civil rights leaders refuse to accept performative concern as a substitute for accountability. * * * ## Fediverse Sustainability Survey The Social Web Foundation is running their first Fediverse Sustainability Survey seeking operators, moderators and administrators of Fediverse sites to fill out the anonymous survey and share information about how their instances work. If you help run an instance, please take the 10-15 minutes needed to fill out the survey. Fill In The Survey Want to appear here? Sponsor a newsletter. * * * ****Support the Internet Exchange**** If you find our emails useful, consider becoming a paid subscriber! You'll get access to our members-only Signal community where we share ideas, discuss upcoming topics, and exchange links. Paid subscribers can also leave comments on posts and enjoy a warm, fuzzy feeling. Not ready for a long-term commitment? You can always leave us a tip. Become A Paid Subscriber ## This Week's Links 🚨 ****Stop press! Do you enjoy our links?**** Links are now available to paid subscribers only. For a limited time, we’re offering 50% off an annual subscription. Normally $50 per year: right now you can subscribe for only $25. Become a paid subscriber today. ### This post is for subscribers only Become a member to get access to all content Subscribe now

internet.exchangepoint.tech

Want to understand how recommendation algorithms work? Luca Belli, Ph.D., author of Hidden Influences, recommends these books.

Want To Understand Recommender Systems? Read These Books.

Luca Belli's Hidden Influences, published by Manning, explores how recommender systems decide what you see, read, and click on, and how those decisions shape what you think you want. Luca spent years on the front lines of this technology, leading research on algorithmic amplification at Twitter's Machine Learning Ethics team and advising the European Commission on AI regulation. He knows how these systems work from the inside. It’s written to be accessible to anyone, but with enough depth that practitioners will find it useful too. So if you've ever tried to explain algorithmic amplification, filter bubbles, or why your uncle's YouTube feed looks the way it does, this is the book for you. It covers how recommendation engines actually work, how they're optimised in ways that don't serve users, and what levers exist to change that. The book isn't out until later this year 2026, but you can preorder now through Manning's Early Access Program (MEAP) and start reading today the chapters that have been reviewed. Plus, you get a discount on the cover price when you buy early. 👉 Preorder and start reading here **While you wait, Luca recommends these essential reads**. They’re books that informed his thinking, and that anyone who cares about technology, power, and democracy should have on their shelf. If you’re based in the US, order using our bookshop.org links to help support Internet Exchange. **On how the internet shapes minds and culture:** * Meme Wars by Brian Friedberg, Emily Dreyfuss, and Joan Donovan: how fringe internet culture conquered the mainstream * The Chaos Machine by Max Fisher: the inside story of how social media rewired our minds and our world ## Sign up for Internet Exchange Feminist perspectives on digital justice and tech Subscribe Email sent! Check your inbox to complete your signup. No spam. Unsubscribe anytime. **On AI and tech industry power:** * AI Snake Oil by Arvind Narayanan and Sayash Kapoor: a guide to what AI can and can't actually do * Chokepoint Capitalism by Cory Doctorow and Rebecca Giblin: how Big Tech captured creative labor markets and what we can do about it * Enshittification by Cory Doctorow: why everything online suddenly got worse, and what to do about it * The Age of Surveillance Capitalism by Shoshana Zuboff: the definitive account of how your behavior became a commodity **On democracy and how to protect it:** * On Tyranny by Timothy Snyder: twenty lessons from history that feel urgently relevant today * How Democracies Die by Daniel Ziblatt and Steven Levitsky: a study of democratic backsliding * How Fascism Works by Jason Stanley: the political playbook of us-vs-them If you're curious about how we got to a world in which algorithms shape politics. In which big tech platforms and AI extract value from everything, and in which democracy feels increasingly fragile, start with any of these books. Then, preorder Luca's to understand the machinery underneath it all. **We're looking to curate more book lists for our bookshop. If you'd like to contribute one, please get in touch.****editor@exchangepoint.tech** * * * ## Audrey at Global Age Assurance Standards Summit 2026 IX's Audrey Hingle will be in Manchester 14-16 of April at the Global Age Assurance Standards Summit looking for like-minded people to discuss the Draft Age Verification Architecture paper before the IETF from Mallory Knodel, Gianpaolo Scalone and Tom Newton. If you'd like to set up a meeting, email me! editor@exchangepoint.tech * * * ## This Week's Links 🚨 ****Stop press! Do you enjoy our links?**** Links are now available to paid subscribers only. For a limited time, we’re offering 50% off an annual subscription. Normally $50 per year: right now you can subscribe for only $25. Become a paid subscriber today. ### This post is for subscribers only Become a member to get access to all content Subscribe now

internet.exchangepoint.tech

Two views on licensing and the creator economy.

Can Licensing Save the Content Economy?

This week, Sonia Hendy and Nick Sullivan offer different perspectives on the role licensing should play in restoring the financial incentives for web content creators. Hendy, a creator herself and founder of an AI licensing infrastructure platform, is the more bullish of the two, arguing that workable infrastructure already exists and that creators cannot afford to wait for perfect policy. Sullivan, an applied cryptographer and internet standards veteran who sits on the Internet Architecture Board, is more bearish, warning that licensing alone cannot fix what is fundamentally a governance problem. Both agree it is not enough. ### **License-first? Mind the Gap!** _By_ Sonia Hendy After watching independent creators lose control of their work to extractive AI scraping, I realized that licensing infrastructure, not another government consultation, could change that. Even without perfect policy. ## Sign up for Internet Exchange Feminist perspectives on digital justice and tech Subscribe Email sent! Check your inbox to complete your signup. No spam. Unsubscribe anytime. Like many people in the creative industries in the UK, I waited for last Wednesday's government report on copyright and AI with both excitement and anxiety. I’d tried to ignore the rumblings in the press about the likelihood of a deferral rather than a workable outcome; I was still poring over the House of Lords report, and glowing from the European Parliament’s Voss vote that validated the licensing-first argument at a major institutional level the week before. Could we expect something extraordinary? Would the economic power of the creative industries triumph against the AI-first dominance of the past two years? Would it deliver something with the gusto and confidence of the UK government’s quantum investment just 24 hours before? Spoiler alert – it did not. It did dismiss its most contentious positioning (the opt-out text and data mining exception), but it struggled to offer anything more – no legislative commitment, no enforcement timelines, no clear signal of what AI companies compliance looks like. The 100+ pages merely promised to gather more evidence, review and monitor. The report observed that the ‘licensing market continues to grow to the benefit of right holders and AI developers, though limited public information on licensing deals makes it difficult to fully assess their impact’, and didn’t consider there to be ‘sufficient evidence to justify government intervention’. In other words, the spoils continue to go to organizations with the catalog depth, scale and legal resources to negotiate directly. This sits among a gallery of the usual suspects to avoid mandating a license-first approach; a lack of agreed technical standards; the argument that there’s sufficient legislation in place, whilst promising further consultations to solve others, notably digital replicas; and the damning acknowledgement of a ‘more limited prospect of a direct licensing market developing for individual right holders and SME right holders’. It's almost exactly the same stagnancy the creative industries have been floating in since the consultation’s inception, during which creators have continued to lose ground unless they happen to be part of the aforementioned closed door deals…So how do we proceed? Firstly, the absence of a perfect universal technical standard is not the same as the absence of workable ones; ISCC fingerprinting, C2PA Content Credentials and RSL (mentioned in the report) already exist and function now. Infrastructure that waits for legislative and technical perfection will still be waiting when the EU AI Act enforcement deadline arrives in August, and far, far beyond. Secondly, the gravy train of publicly available training data will run dry sometime between now and 2032; training AI on AI-generated content leads to model collapse – human content is the foundation the technology depends on – and deals_are_ being made. Thirdly, existing contracts and legislation enforcement across the creative industries varies wildly; and as Creative Industries Policy and Evidence Centre asserted, copyright holders may 'retain little control over their terms and conditions, with the potential for legal rights being overwritten via private contracting'. These analogue approaches don’t enable the transparency to license (or prohibit use of) creative outputs in the AI age. This is the gap independently identified by three landmark reports; the House of Lords Communications and Digital Committee called for a licensing-first ecosystem; the European Parliament adopted the Voss report by a landslide, explicitly recognizing collective management organizations as central to any functioning framework; and now Westminster’s report indicates the same direction whilst omitting a timeline (or vehicle) to get there. Some may argue that no policy is better than a bad one – but waiting for the caprices of the government’s vague timelines, the potential volatility caused by cabinet reshuffles, the uncertainty of legal outcomes (especially the Getty vs. Stability AI appeal) to be resolved means it could take years for smaller and independent creators to gain any control over their art, consent for its use, and compensation for their craft. The relentless and passionate campaigns of UK rights organizations undoubtedly shifted the landscape of this report – but campaigns alone do not get creators paid, or protect their work from further unfettered use – they need infrastructure. As a creative, I grew tired of these circular arguments and built Magpie Standard in this uncertain landscape as a boot-strapped founder who wanted to offer a solution that intersects legislation, IP and creator rights. Our infrastructure is research-based (embodying the Access, Control, Consent, Compensation and Transparency (ACCCT) framework – cited multiple times in the House of Lords report); interoperable at its core; can be integrated into existing rights organizations; offers AI companies a route to access (compliant) machine-readable licensed human creativity; and most importantly it offers creators control _now_ – not in three years’ time. The waitlist for our creator direct platform is already open… The question remains – are we brave enough to ‘mind the gap’ without waiting for the ‘perfect’ policy? Or will we simply watch the gap widen and let the creative economy be consumed by it? Sonia Hendy_is the founder of_ The Hendy Collective_and creator of Magpie Standard, an AI licensing infrastructure platform for rights organizations. A published poet, songwriter, and fiction writer with bylines in The Guardian and HuffPost UK, she brings two decades across higher education leadership, transformation consultancy, and creative practice to the question of how creators license their work for AI training._ ### **Beyond Licensing: Why the Open Web Needs Governance, Not Just Deals** _By_ Nick Sullivan Licensing deals between AI companies and content publishers can't fix the web's AI governance problem because much of what AI actually trains on can't be licensed in the first place. Licensing is a rational response to a real problem. Professionally produced content is being copied at scale for model training, often in ways that reduce referral traffic and revenue. Because of this, large publishers and AI firms have already cut deals: Reuters has reported on Reddit's reported $60 million-a-year agreement with Google and the Wikimedia Foundation's paid enterprise-access deals with Microsoft, Meta, Amazon, Perplexity, and Mistral. Those arrangements make sense for institutions with bargaining power, recognizable inventories, and ongoing demand. Still, they also reveal the model's limits: a governance system built around licensing will privilege actors already organized to sell access. There is also a deeper structural problem with a licensing-only approach. As WIPO puts it, "copyright laws are territorial." The Internet is not. For example, in the EU, text and data mining of lawfully accessible works is permitted unless rightsholders have expressly reserved their rights. In the United States, courts are still drawing lines around fair use and market harm in AI training cases. Licensing-first solutions often assume a stable, global legal baseline that does not exist. A meaningful fraction of what AI models actually train on sits in categories where copyright's reach is limited or unclear. The US Copyright Office is direct on this: copyright "does not protect facts, ideas, systems, or methods of operation." User-generated content, community-maintained reference works, and factual material cannot be licensed away because, in many cases, there is nothing to license. Licensing also risks centralizing the wrong things. A licensing regime turns the Internet from a system that rewards "who gets heard" into one that rewards "who can invoice." Australia's parliamentary review of its News Media Bargaining Code found that the bulk of funding from commercial agreements went to legacy outlets, deepening disadvantages for smaller publishers. Pew found that the most frequently cited sources in Google AI summaries were Wikipedia, YouTube, and Reddit, and only 5% linked to news sites. The biggest publishers and platforms will have the clearest leverage. This compounds with the fact that there is a mismatch between what content is important for AI and who can monetize through licensing. Major foundation model training pipelines rely on web-scale crawls. Much of the material AI systems actually value is collaborative, user-generated, or community-maintained, and it rarely comes packaged in the clean rights bundles collective licensing assumes. Common Crawl alone spans over 300 billion pages across millions of distinct sites. The vast majority of those sites will never be party to a licensing deal, and a system that routes value only through bilateral agreements will deepen the centralization it claims to remedy. The answer has to be broader than compensation. We need open technical standards that let sites, creators, and users express preferences about automated consumption in a machine-readable way, and we need model providers to respect them. The emerging crawler controls show what a norms-based Internet could look like. OpenAI lets sites allow OAI-SearchBot for search while disallowing GPTBot for training. Apple lets publishers direct it not to use their site content for model training, and lets individuals object to the crawling of URLs that contain their personal data. Google is less clear-cut: AI is now part of Search, but they still allow sites to differentiate between crawler use of data via Google-Extended. The EU framework already points in that direction, and the W3C's TDM Reservation Protocol is designed to express the reservation of mining rights and to ease the discovery of associated policies. The IETF's AIPREF work builds on the current robots.txt standard and is developing a standard vocabulary for AI usage preferences that extends well beyond copyright. Even the UK Parliament committee arguing for a licensing-first approach says government should back "open, globally aligned standards" for rights reservation, provenance, and labelling. There is still a long way to go to establish these rules and standards universally. Researchers auditing consent signals across 14,000 domains underlying major training corpora describe the current situation as "symptoms of ineffective web protocols," with widespread inconsistencies between what sites intend and what robots.txt and other signals actually convey. Being open to being read, cited, or indexed is not the same as consenting to model training. Licensing should remain one tool in the stack, but a stable equilibrium for the AI web requires transparency, provenance, privacy, and meaningful consent for both people and publishers. Nick Sullivan_is an applied cryptographer, security researcher, and entrepreneur. He founded Cloudflare Research, co-authored several TLS extensions, is a member of the Internet Architecture Board, and holds several roles at the IETF where he works on the standards that shape how the Internet operates._ ****Support the Internet Exchange**** If you find our emails useful, consider becoming a paid subscriber! You'll get access to our members-only Signal community where we share ideas, discuss upcoming topics, and exchange links. Paid subscribers can also leave comments on posts and enjoy a warm, fuzzy feeling. Not ready for a long-term commitment? You can always leave us a tip. Become A Paid Subscriber * * * ## This Week's Links 🚨 ****Stop press! Do you enjoy our links?**** From next week, the links roundup will be available to paid Internet Exchange subscribers only. For a limited time, we’re offering 50% off an annual subscription. Normally $50 per year: right now you can subscribe for $25. Become a paid subscriber today. ### Open Social Web * Soft launching Eurosky. A personal account for the web. Most people use it today as an entry point to Bluesky, but it's much bigger than this. In the coming years it could become people's main online identity says its co-lead Sherif Elsayed-Ali. https://www.linkedin.com/pulse/future-social-media-you-app-sherif-elsayed-ali-agg8e * Loops, built on ActivityPub, introduces Starter Kits. Curated collections of accounts grouped around topics, communities, or vibes. https://blog.joinloops.org/introducing-starter-kits * Bluesky announces $100 million in Series B funding the week after CEO Jay Graber announced she was stepping down. https://techcrunch.com/2026/03/19/bluesky-announces-100m-series-b-after-ceo-transition ### Internet Governance * Google was granted a patent in January 2026 for a system that evaluates your website in real time and, if it judges the page unlikely to perform well for a specific user, replaces it with an AI-generated alternative assembled from your content, the user's search history, and their account context. https://www.forbes.com/sites/joetoscano1/2026/03/06/google-just-patented-the-end-of-your-website * Related: Google is using AI to rewrite headlines as part of an “experiment.” https://www.theverge.com/tech/896490/google-replace-news-headlines-in-search-canary-coal-mine-experiment * The FCC says it has decided that all foreign-made consumer-grade internet routers are henceforth prohibited from receiving FCC authorization and are therefore prohibited from being imported for use or sale in the United States. https://infosec.exchange/@briankrebs/116280575943263005 * The US Senate Commerce Committee marked Section 230's 30th birthday with a hearing on whether the liability shield that built the internet still makes sense, with witnesses including Stanford's Daphne Keller, the Knight Institute's Nadine Farid Johnson, Social Media Victims Law Center attorney Matthew Bergman, and Americans for Responsible Innovation's Brad Carson. https://www.youtube.com/live/F8T5vCmlHmA * An issue brief from Creative Commons considers how attribution works in the context of AI – where systems generate content based on large amounts of existing data – and why attribution still matters, even when it is difficult to implement. https://creativecommons.org/wp-content/uploads/2026/03/Attribution-and-AI-Outputs-Issue-Brief-Mar-2026.pdf * Minutes are available from the IETF 125 meeting of the working group developing a standard to let websites signal AI training preferences. https://ietf-wg-aipref.github.io/wg-materials/ietf125/minutes.html ### Digital Rights * A Los Angeles ​jury found Meta and Alphabet negligent for designing social media platforms that are harmful to young people. https://www.reuters.com/legal/litigation/jury-reaches-verdict-meta-google-trial-social-media-addiction-2026-03-25 * A jury found Meta violated New Mexico law in a case accusing it of failing to warn users about the dangers of its platforms and protect children from sexual predators and ordered the company to pay $375 million in damages. https://edition.cnn.com/2026/03/24/tech/meta-new-mexico-trial-jury-deliberation * The Global Network Initiative's submission to the UN human rights office warns that age verification, content monitoring, encryption proposals, internet shutdowns, and AI-generated disinformation are creating threats for human rights defenders. https://globalnetworkinitiative.org/gni-submission-ohchr-consultation-on-protecting-human-rights-defenders-in-the-digital-age * Last minute amendments to the Children’s Wellbeing and Schools Bill will have huge implications for freedom of expression and privacy in the UK, Open Rights Group has warned, raising concerns that MPs and peers are not being given sufficient time to scrutinise the amendments which could have far reaching consequences if abused, and that amendment 38B could give Ministers the powers to force anyone over 13 to use unsafe and unregulated age-ID services to access certain internet services. https://www.openrightsgroup.org/press-releases/13-year-olds-could-be-compelled-to-use-unregulated-age-verification * An investigation finds the UK government has spent over £2 million on VPN technology, including by Ofcom, Ofsted, the NHS, and multiple MPs expensing consumer VPN subscriptions, while simultaneously consulting on whether to ban or age-restrict children's access to the same technology. https://www.techradar.com/vpn/vpn-privacy-security/investigation-uk-spends-millions-on-vpns-as-government-weighs-ban-for-children * Thomson Reuters, best known for its media outlet and legal research tools, has a $22.8 million contract to provide an investigative tool to ICE. Its Minnesota employees want that to stop. https://www.nytimes.com/2026/03/11/technology/thomson-reuters-ice-minnesota.html * As US and Israeli airstrikes continue across Iran, for weeks, the Iranian government has blocked internet access for most of its 92 million citizens. https://www.nytimes.com/2026/03/18/world/middleeast/iran-internet-shutdown.html ### Technology for Society * AI chatbots are the ‘wild west’ for violence against women and girls. Two new studies reveal how artificial intelligence can be used to encourage gender-based violence and sexual abuse. Analysts and academics are working to make Silicon Valley finally pay attention. https://observer.co.uk/news/science-technology/article/ai-chatbots-are-the-wild-west-for-violent-imagery-of-women-and-girls * Independent publisher Minor Compositions is moving its 70-book catalogue to the Internet Archive. https://www.minorcompositions.info/?p=1863 ### Privacy and Security * Researchers fear that Meta's retreat from its commitments to protect user privacy with end-to-end encryption on Instagram chat could create a problematic precedent in big tech. https://www.wired.com/story/the-danger-behind-metas-decision-to-kill-end-to-end-encrypted-instagram-dms * Related: Mozilla has a petition calling on it to _keep_ encryption for Instagram Messages. https://www.mozillafoundation.org/en/petitions/keep-encryption-for-instagram * Russia is pushing its Max messenger, an unencrypted “super-app” onto its citizens with a massive promotion campaign and the simultaneous blocking of Whatsapp and Telegram, the country's two most popular messenger apps. https://www.france24.com/en/live-news/20260323-russia-s-max-the-unencrypted-super-app-being-forced-on-citizens * Researchers from KU Leuven and UGent have broken PhotoDNA, the perceptual hashing system used to detect child sexual abuse material across major platforms, showing it can be bypassed in minutes on a laptop and used to generate false positives that could incriminate innocent users. https://eprint.iacr.org/2026/486 ### Upcoming Events * ITU Workshop on Trustable and Interoperable Digital Identities for Human and Agentic AI. **March 30-31, Geneva and online.** https://www.itu.int/en/ITU-T/Workshops-and-Seminars/2026/0330/Pages/default.aspx * Palestine Digital Activism Forum (PDAF) 2026 hosted by 7amleh – The Arab Center for the Advancement of Social Media. An amazing speaker lineup! **March 30-31** , **Online.** https://events.ringcentral.com/events/pdaf-2026 * Meme-tivism: Rethinking AI's Environmental Impact. A hands-on workshop for AI and ML practitioners exploring meme-making as a tool for climate advocacy and rethinking the environmental footprint of AI systems. **April 9, 5:30pm GMT, London, UK.** https://luma.com/rkuwsrn6 * IETF AI Preferences Working Group interim meeting, working on a standard to let websites signal whether their content can be used for AI training. **April 14-16, Toronto and online.** https://ietf-wg-aipref.github.io/wg-materials/interim-26-04/arrangements.html * Mobilize supporters & build campaign momentum. A one-day online accelerator for NGOs stuck on how to mobilise people, build momentum, and turn ideas into action. **April 15, Online**. https://www.resource-alliance.org/event/creative-organising-lab * Take Back Tech 3 is a gathering for organizers, artists, tech workers, academics, lawyers, and more to rally together and strategize our next power-building moves. **April 17-19, Atlanta, GA.** https://www.takebacktech.com * SplinterCon returns to host a 0-day event at RightsCon in Lusaka, Zambia. **May 5th, Lusaka, Zambia.** https://splintercon.net/events/rightscon-lusaka * Data for Peace Conference, a three-day conference connecting researchers, peacebuilders, policymakers, data providers, humanitarian actors, and peace technologists to strengthen how data and technology supports violence prevention, anticipatory action, and crisis response.n **June 15-17.** https://www.uu.se/en/department/peace-and-conflict-research/collaboration/data-for-peace-conference * Summer School in Digital Human Rights at Lund University.**Lund, Sweden**. **June** 22-26. https://www.law.lu.se/study/summer-school-digital-human-rights ### Careers and Funding Opportunities * Tech Coalition: Senior Technical Program Manager, Child Safety Tech and Industry Adoption. **Washington, DC.** https://technologycoalition.org/careers/senior-technical-program-manager * The Beeck Center for Social Impact + Innovation at Georgetown University: Researcher. **Washington, DC**. https://beeckcenter.georgetown.edu/jobs/researcher * Canva: Trust & Safety Operations Specialist. **Makati, Philippines**. https://www.linkedin.com/jobs/view/4384572638 ### Opportunities to Get Involved * Submit an abstract to give a talk at the upcoming 'Rewilding the Web' workshop at the University of Edinburgh. Due by **March 31.** https://bsky.app/profile/kathrynnave.bsky.social/post/3mhplih5zz22s * Data for Peace Conference call for proposals due **April 13**. https://www.uu.se/en/department/peace-and-conflict-research/collaboration/data-for-peace-conference/call-for-proposals _What did we miss? Please send us a reply or write to_ _editor@exchangepoint.tech_ _._ 💡 Want to see some of our week's links in advance? Follow us on Mastodon, Bluesky or LinkedIn, and don't forget to forward and share! ##

internet.exchangepoint.tech

When news broke that one of Mexico's most powerful cartel leaders had been killed, the violence that followed spilled into two spaces at once. The streets of Guadalajara, and the internet.

What the El Mencho Killing Deepfakes Revealed About Information in a Crisis

_By_ Audrey Hingle It’s Sunday, February 22, and a message comes through in our class WhatsApp group. We’re all on the STEaPP programme at UCL: Science Technology Engineering and Public Policy. A classmate in Guadalajara says there’s unrest following an operation that reportedly took out “El Mencho.” He’s worried and scared, and we’re, of course, all worried for him. He tells us the airport has been overrun. Cartel members are setting fire to cars. He forwards us videos showing what he believes is happening nearby. ## Sign up for Internet Exchange Feminist perspectives on digital justice and tech Subscribe Email sent! Check your inbox to complete your signup. No spam. Unsubscribe anytime. They aren’t grainy or obviously manipulated. They’re sharp, detailed, and entirely plausible: burning vehicles, people running, armed men moving through public spaces. Exactly what you would expect this kind of situation to look like. I message a friend whose family lives nearby: I hope they’re OK.“It’s crazy,” he replies, sending more clips. At that point, there’s no real reason to doubt what we’re seeing. A real-world event is unfolding, and the visuals match the narrative. The information is coming from people we trust. Except, the airport, as far as I can tell, wasn’t overrun despite what Laura Loomer might have claimed. And a number of the videos circulating most widely were either misattributed or entirely fake. We’ve had viral AI-generated images before. The “little girl escaping floodwater” is a good example. But those kinds of emotionally charged images tended to circulate after the fact, when we had clearer facts, a better understanding of what was going on, and… it was a photo. Not a video. Most of us still aren’t accustomed to doubting video content in the same way we’ve come to know that still images can be manipulated. Despite that, deepfakes are already distorting how we see global events in real time – including the US-Israel war with Iran. Says Reuters: > _Unrest did indeed break out in many parts of Mexico as loyalists to El Mencho, the leader of the Jalisco New Generation Cartel, set up roadblocks, torched buses and stores, and attacked gas stations in retaliation for his slaying._ > _But online, things looked even worse. Among the false reports: The Guadalajara airport taken over by assassins. A plane on the runway was on fire. Smoke was billowing from a church and multiple buildings in the city of Puerto Vallarta, popular with tourists._ > _These images, which were reviewed by Reuters, were false but shared tens of thousands of times… Experts said that, in the case of El Mencho's killing, the fake news was being spread at surprising speed not only by unsuspecting users**but also in some cases by the cartel itself** , in efforts to make its retaliatory wave of violence appear greater and more terrifying than it really was._ Part of what is different now is how quickly fake videos can appear, and how closely they track to real, developing events. In this instance, they didn’t distort a settled narrative. They helped _form_ the initial understanding of what was happening, especially for people outside the region. Violence wasn’t confined to the streets: it extended into the information space, where cartel-linked actors actively shaped the narrative in real time, weaponising panic to make the situation appear far more widespread and uncontrollable than it was. By the time many newsrooms were catching up, the visual story was already in circulation. Misinformation is no longer just something that follows events. It can now emerge alongside them, filling in gaps before verified information is available. If it is convincing enough, it doesn’t need to replace the truth. It just needs to arrive first. And it’s particularly insidious, making it difficult for people on the ground to know how to behave to stay safe. There’s a tendency to frame this as a media literacy problem: users should be more critical, more cautious, better at spotting fakes, but that doesn’t hold up in practice. Remember that we’re all masters students studying technology and public policy, we’re far more media-literate than your average person and we all fell for these deep fakes, including my classmate living in the area and my friend with family nearby. Plus, when something appears to be happening in real time, especially somewhere you live or have a personal connection to, you’re not approaching information as an analyst. You’re reacting as a person. You’re checking on friends, sharing updates, trying to understand what’s going on. The expectation that individuals will pause and verify each piece of content at that moment is unrealistic. So if training people how to spot AI-generated content isn’t the solution, what is? What information integrity infrastructure needs to exist to support trustworthy media ecosystems when crises like this one unfold? ### What would information integrity infrastructure actually look like? To understand what can be done, I spoke to Jacobo Castellanos, Coordinator of the Technology, Threats, and Opportunities team at WITNESS, an organization that has been preparing journalists, activists, and human rights defenders for the threat of synthetic media for years. Jacobo agrees that in situations like this, we need to shift responsibility away from individuals like myself and my classmates to be able to spot AI. Instead, we should be asking what information integrity infrastructure is needed to support trustworthy media ecosystems in crisis situations like this one. Work on this has been in development for years, says Jacobo. “Specifically, the transparency and detection systems that help reclaim trust by verifiably establishing the source and history of the content we consume.” For these to work we need “regulatory and policy frameworks, thoughtful platform and tool design and governance; interoperable technical standards; and broader governance mechanisms that ensure human rights safeguards and meaningful civil society participation.” If these had been in place when this incident took place, things could have looked much different. The AI-generated or edited content might have carried embedded signals like content credentials or watermarks that the social media platforms hosting the content could automatically detect and flag for users. “Even in cases where malicious actors had stripped this information away, or used tools that did not add these signals (for example, locally run open-source models),” says Jacobo, “platforms could still rely on post-hoc detection systems to identify and flag many of these synthetic videos.” The goal of these mechanisms is not to eliminate all misleading content, but to ensure that when viewers encounter potentially deceptive media, they are given meaningful information to interpret it. “In a situation like this one,” says Jacobo, “that could mean recognizing that a real crisis was unfolding, while also understanding that some of the circulating footage was likely AI-generated and should not be taken at face value.” Media literacy is still useful in this scenario, but not to identify AI-generated content based on auditory or visual cues. Instead, it’s to understand what provenance of information is, and what it isn’t. And what it means for something to come from a credible source. And media literacy is for content creators, not just consumers. Journalists, activists, eyewitnesses, and documentarians need to understand how to use provenance tools as they produce content, embedding verifiable information about source, context, and chain of custody from the start. WITNESS calls this "fortifying the truth;” using transparency in documentation not just to debunk fakes, but to make authentic content harder to dismiss or decontextualize. The C2PA open standards make it technically possible to embed a record of where media came from and what has been done to it, from the moment of capture through to publication. The idea, as the BBC puts it, is to "mark the good stuff," giving audiences a way to verify authentic content so it’s easy to tell what is definitely real in a world where it’s hard to tell what might be fake. WITNESS notes, though, that a provenance signal is not a guarantee of truth, and that poor design could lead users to read a checkmark as "this is true" when it means something more limited. Platforms and tool designers need to invest in UX research into how these signals are surfaced, particularly in fast-moving situations where people are not approaching content analytically, and across a full range of users globally. It’s worth noting that provenance infrastructure can also introduce new risks, including to the privacy and safety of the journalists and activists it is meant to protect. WITNESS has led a harms and misuse assessment of the C2PA specifications for this reason. They also stress that provenance only works if it travels across platforms, and that responsibility for embedding signals needs to sit with AI developers and tool makers at the point of creation, not left to platforms to sort out after the fact. The Guadalajara incident was a test my classmates and I didn't know we were taking, and we failed it. Not because we were careless, but because the systems are not yet in place to help us ask the right questions. **Related:** WITNESS researcher Mahsa Alimardani documents how AI-generated imagery is making it close to impossible to establish basic facts about the killing of children in Iran. Not because every image is fake, but because the question of what is real has itself become a weapon. https://www.theatlantic.com/ideas/2026/03/ai-imagery-iran-war/686347/?gift=uIKGDCkFqgBMhOUTpelOoET7ItQfiZwDDC-dXtqJOlM * * * ## Automating Justice, Designing Power: Reflections from the Commission on the Status of Women IX's Mallory Knodel spoke at the UN's 70th Commission on the Status of Women on whether AI can expand women's access to justice, arguing that AI governance starts in design not regulation, that access alone is not empowerment, and that feminist principles are essential to preventing AI from repeating the exploitative patterns of surveillance capitalism. She also makes the case for interoperability and multistakeholder governance as the missing infrastructure layer for AI. Read Her Reflections Want to appear here? Sponsor a newsletter. * * * ****Support the Internet Exchange**** If you find our emails useful, consider becoming a paid subscriber! You'll get access to our members-only Signal community where we share ideas, discuss upcoming topics, and exchange links. Paid subscribers can also leave comments on posts and enjoy a warm, fuzzy feeling. Not ready for a long-term commitment? You can always leave us a tip. Become A Paid Subscriber ## This Week's Links 🚨 ****Stop press! Do you enjoy our links?**** In a few weeks, the links roundup will be available to paid Internet Exchange subscribers only. For a limited time, we’re offering 50% off an annual subscription. Normally $50 per year: right now you can subscribe for $25. Become a paid subscriber today. ### Open Social Web * The first large-scale study of Bluesky's community moderation presented at IETF Decentralization of the Internet Research Group (DINRG) finds that blocklists affect the visibility of over 90% of content but are controlled by a tiny fraction of users, and that blocking does not decrease the popularity and activity of the blocked users, and has a limited effect on the social graph. https://openaccess.city.ac.uk/id/eprint/36822/ ### Internet Governance * The US revoked visas of three Chilean officials for merely considering a Chinese undersea cable project. A sign, argue Jorge Heine and Juan Ortiz Freuler, that Washington is willing to weaponise South America's total dependence on US internet infrastructure to enforce its Monroe Doctrine in the digital age. https://www.techpolicy.press/untethering-south-america-from-us-cables-after-rubio-pressures-chile-in-transpacific * Important presentation by UCLA's Lixia Zhang at IETF 125 argues that AI agents represent a fundamental new challenge for internet infrastructure. * The slide deck: https://datatracker.ietf.org/meeting/125/materials/slides-125-irtfopen-on-ai-agent-communication-00 * The recording (starts at around 1:25) https://youtu.be/h6ZLrNRD3bU?list=PLC86T-6ZTP5gi5EKPqJf3lneksxOTPetP&t=5089 * A podcast deep dive into the law, history, and geopolitics of submarine cables. Douglas Guilfoyle and Tamsin Phillipa Paige are joined by Dr Tara Davenport (NUS Centre for International Law) and Dita Liliansa (UNSW Sydney). https://soundcloud.com/calledtothebar/66-submarine-cables * A new paper mapping investment in 110 European AI startups finds that the EU's strategy for technological sovereignty is empowering a select group of "patriotic billionaires" as crucial intermediaries between private capital and the state, with significant implications for who shapes AI policy in Europe. https://journals.sagepub.com/doi/10.1177/10245294261429545 * Connected by Data's Tim Davies argues that public voices make up less than 1% of content at major AI summits and puts out a call for collaborators to change that, starting with the UN Global Dialogue on AI Governance in Geneva in July. https://connectedbydata.org/blog/2026/03/06/what-if * Content from PAIRS Online (Participatory AI Research & Practice Symposium) available on their site. https://www.pairs.site/PAIRS-Online-17th-February-2e8260e24e1a8045bb31f64d3c74c592 ### Digital Rights * A UK parliamentary petition urges the government to reject proposals banning VPN use by children, warning that enforcement would rely on invasive ID checks and cause serious collateral damage to privacy and security for all VPN users. https://petition.parliament.uk/petitions/754408 * A new draft study provides the first large-scale look at age verification providers on the web, finding that US state laws are causing measurable internet balkanisation, that compliance is low, and that the dominant provider (Yoti) creates serious privacy risks, directly challenging assumptions the Supreme Court relied on when upholding age verification laws last year. https://mikespecter.com/assets/pdf/AgeVerification.pdf * New research from Tajikistan documents how technology-facilitated gender-based violence extends and amplifies offline patriarchal control over women, in one of the first studies to map the scope of the problem in the country. https://firn.genderit.org/research/i-am-drowning-under-weight-hatred-scope-and-nature-technology-facilitated-gender-based * WhatsApp is rolling out parent-managed accounts for pre-teens, giving parents control over contacts, groups, and privacy settings while keeping all conversations end-to-end encrypted. https://blog.whatsapp.com/introducing-parent-managed-accounts-on-whatsapp ### Technology for Society * Researchers Ghiwa Sayegh and Sabiha Allouche ask what decolonial resistance looks like in an era of AI-automated annihilation, theorizing "endless genocide" as a recurring condition of settler colonialism and asking what it means to sabotage its digital tools. https://firn.genderit.org/research/we-are-interruption-technology-militancy-and-endless-genocide * Journalism professor Diego García Ramírez argues that Latin American media is trapped on a "hamster wheel" of platform dependency, and that Big Tech has captured not just content distribution but political lobbying, academic research, and the very concept of digital sovereignty itself. https://networkcultures.org/blog/2026/03/06/digital-tribulations-11-the-hamster-wheel-on-the-platformization-of-the-colombia-media-system * A study of food delivery riders in London and São Paulo finds that platform companies reproduce rather than transcend racial inequality. https://www.sciencedirect.com/science/article/pii/S2666378326000103?via%3Dihub * University of Chicago art historian Patrick R. Crowley argues that AI model collapse is not a new problem but the latest iteration of an ancient one, and that generative AI's feedback loops of probability and prediction are reshaping what counts as real, plausible, and true. https://www.artforum.com/features/patrick-r-crowley-mimesis-1234743983 * A new report from MediaJustice maps how tech oligarchs are capturing the US media system through ownership, funding dependency, and platform control, and argues the communities with the most to lose are Black, brown, and Indigenous audiences whose local outlets are being squeezed out while larger newsrooms sign AI licensing deals that make honest coverage of their funders harder to produce. https://mediajustice.org/wp-content/uploads/2026/03/MediaJustice-Media-Capture-Report.pdf * WITNESS researcher Mahsa Alimardani documents how AI-generated imagery is making it close to impossible to establish basic facts about the killing of children in Iran. Not because every image is fake, but because the question of what is real has itself become a weapon. https://www.theatlantic.com/ideas/2026/03/ai-imagery-iran-war/686347/?gift=uIKGDCkFqgBMhOUTpelOoET7ItQfiZwDDC-dXtqJOlM ### Privacy and Security * Meta has quietly said it will end support for encrypted messaging on Instagram in a matter of weeks. Mozilla has a petition calling on it to keep encryption for Instagram Messages. https://www.mozillafoundation.org/en/petitions/keep-encryption-for-instagram * But it’s not all bad. Signal creator Moxie Marlinspike says his AI privacy startup Confer, which Mallory wrote about last week, will integrate its end-to-end encryption technology into Meta AI, framing today's AI chat apps as the largest and most sensitive centralized data lakes ever built and arguing the moment requires acting at scale. https://confer.to/blog/2026/03/encrypted-meta * The UK continues to go after encryption. The UK's NCA chief says technology is reshaping crime itself, and called on tech companies to design encrypted apps with lawful access built in. Or as cryptographers call it, to break encryption. https://www.computerweekly.com/news/366640462/Technology-accelerating-crime-boosts-case-for-national-police-service-says-NCA-chief * The Real World Crypto Symposium 2026 was last week in Taipei. Watch the full recording of the event on YouTube. https://www.youtube.com/live/v_AFtbWr1bY * California physician Oni Blackstock argues that protecting patients from ICE requires more than keeping agents out of hospitals. Health systems need to map where patient data goes, exclude vendors that also contract with ICE, and tell patients clearly what happens to their information after each visit. https://www.sacbee.com/opinion/op-ed/article314938351.html ### Upcoming Events * PAIRS: Participatory AI Research & Practice Symposium Community calls start **March 23**. https://www.pairs.site/PAIRS-Community-Calls-325260e24e1a801d89abc76fec494c11 * Book Talk: Design for Privacy by Robert Stribley. Are your designs protecting—or exposing—your users? In Design for Privacy (published by Rosenfeld Media), you’ll uncover how shifting technologies threaten personal data and what that means for your work. **March 25. New York, NY.** https://www.eventbrite.com/e/book-talk-design-for-privacy-by-robert-stribley-tickets-1984635380849 * PDN Pro-Social. Building a Prosocial Platform for Local Communities, Roundabout with New_ Public. **March 26. Online.** https://luma.com/5vzxn9vn * All Tech Is Human is holding an all-day workshop in Manhattan on building an inter-party trust framework for AI. **March 26, New York, NY.** https://docs.google.com/forms/d/e/1FAIpQLSeidCs4-ifuG4iZxi5kh3QBAGuh_UQBksPIzhoTzabTDblaHg/viewform * ATmosphereConf is THE global AT Protocol community conference. **March 26-29, Vancouver, Canada and Online.** https://atmosphereconf.org * "Can Middleware Save Social Media?" Middleware are third-party tools that sit between users and platforms that proponents say give people control over what they see and share online. Skeptics warn they raise privacy concerns and that more fundamental changes are needed. This event asks: Can middleware really deliver the improvements that its boosters envision? **March 27.** https://knightcolumbia.org/events/can-middleware-save-social-media * ITU Workshop on Trustable and Interoperable Digital Identities for Human and Agentic AI. **March 30-31, Geneva and online.** https://www.itu.int/en/ITU-T/Workshops-and-Seminars/2026/0330/Pages/default.aspx * Palestine Digital Activism Forum (PDAF) 2026 hosted by 7amleh – The Arab Center for the Advancement of Social Media. An amazing speaker lineup! **March 30-31** , **Online.** https://events.ringcentral.com/events/pdaf-2026 * Meme-tivism: Rethinking AI's Environmental Impact. A hands-on workshop for AI and ML practitioners exploring meme-making as a tool for climate advocacy and rethinking the environmental footprint of AI systems. **April 9, 5:30pm GMT, London, UK.** https://luma.com/rkuwsrn6 * IETF AI Preferences Working Group interim meeting, working on a standard to let websites signal whether their content can be used for AI training. **April 14-16, Toronto and online.** https://ietf-wg-aipref.github.io/wg-materials/interim-26-04/arrangements.html * Mobilize supporters & build campaign momentum. A one-day online accelerator for NGOs stuck on how to mobilise people, build momentum, and turn ideas into action. **April 15, Online**. https://www.resource-alliance.org/event/creative-organising-lab * Take Back Tech 3 is a gathering for organizers, artists, tech workers, academics, lawyers, and more to rally together and strategize our next power-building moves. **April 17-19, Atlanta, GA.** https://www.takebacktech.com * SplinterCon returns to host a 0-day event at RightsCon in Lusaka, Zambia. **May 5th, Lusaka, Zambia.** https://splintercon.net/events/rightscon-lusaka * Data for Peace Conference, a three-day conference connecting researchers, peacebuilders, policymakers, data providers, humanitarian actors, and peace technologists to strengthen how data and technology supports violence prevention, anticipatory action, and crisis response.n **June 15-17.** https://www.uu.se/en/department/peace-and-conflict-research/collaboration/data-for-peace-conference ### Careers and Funding Opportunities * Anthropic: Enforcement Operations Lead. **Washington, DC.** https://job-boards.greenhouse.io/anthropic/jobs/5137185008 * Schmidt Sciences:Program Scientist, Agents. **New York, NY.** https://www.linkedin.com/jobs/view/4383878716 * IGF: 2026 Fellowship Programme. **Geneva, Switzerland.** https://www.intgovforum.org/en/content/igf-2026-fellowship-programme * UN Global Pulse: Technical Program Officer – Data and AI products for Humanitarian and Development Use. **Helsinki, Finland.** https://www.unglobalpulse.org/job/technical-program-officer-data-and-ai-products-for-humanitarian-and-development-use * The Good Ancestor Movement: Resource Mobilisation Lead. **Remote** **UK**. https://app.dover.com/apply/Good%20Ancestor%20Movement/88ef2d1a-05b9-4a26-82a4-6f1abd2c6836/?rs=76643084 * The Distributed AI Research (DAIR) Institute: Communications Lead. **Remote**. https://job-boards.greenhouse.io/distributedairesearchinstitute/jobs/4130897009 _What did we miss? Please send us a reply or write to_ _editor@exchangepoint.tech_ _._ 💡 Want to see some of our week's links in advance? Follow us on Mastodon, Bluesky or LinkedIn, and don't forget to forward and share! ##

internet.exchangepoint.tech