European Data Protection makes it illegal to transfer person identifiable data to outside the EU. Unless there is equivalence in data protection, or an agreement with guarantees and oversight deemed adequate. For the USA this is the EU-US Data Privacy Framework (DPF). This framework depends on the existence of the independent oversight body FTC, and the Data Protection Review Court (DPRC) which serves as redress mechanism. The arrangement is in place since 2023.

Earlier agreements, the Safe Harbor Agreement (until 2015) and the Privacy Shield Agreement (until 2020), both were struck down in European courts as inadequate (the Schrems I and Schrems II cases).

The DPF always has been a sham. Because in reality it was clear that there was no practical adequacy in any way, let alone that it could be properly enforced. “But there’s independent oversight! The FTC!” has been used as plausible reason to change nothing in practice. Notions of data protection in the USA never aligned with the very different premises of the EU GDPR, and wrapping it in the DPF does not change that. Not even when paying no attention to the intelligence elephant in the room.

The semblance of a functional redress mechanism was already gone when the Trump regime fired most of the DPRC members in early 2025, leaving a single Republican in place where three people are needed for a decision. This placed the framework ‘in doubt’. Harsh words, I know.

The death of the DPR has now been made official by the Supreme Court as it destroyed the independence of the FTC by declaring statutory removal protections unconstitutional. That will wreak havoc in the USA itself no doubt, giving the executive control of all heretofore independent oversight bodies (except for the Federal Reserve to add a bit of inconsistency).
Doing away with the FTC’s independence removes the last pretence of a functioning EU – US Data Privacy Framework.

NOYB, the NGO run by Max Schrems (of the epynomous Schrems I and II verdicts) has called upon the European Commission (PDF) to face the facts and withdraw the adequacy decision about the DPF. It has also announced another lawsuit to ensure the DPF will not remain in place if the EC does not choose to act.

In a session today there was some discussion about agentic skills. A skill is mostly a markdown text file often named, yes, skill.md with a natural language text plus some front matter, describing some specific workflow or bit of knowledge or capability.
Somebody external opined that such skills were a good way of codifying organisational knowledge, which might be useful ‘because of the ageing demographics’ on the work floor and people retiring.

Would agentic skills succeed where process descriptions, intranets, 1990-2010 knowledge systems, quality assurance systems all failed when aimed at documenting the actual knowledge present in an organisation?

I doubt it.

Deep knowledge is relational, chunky, only its underlying facts and heuristics can be codified. And people will resist codification, for different reasons. Such as recognising the futility of it, or recognising its aim of making the people with knowledge superfluous. Or both.

Are skills different enough from earlier systems aimed at codification to gain some willing cooperation from knowledge workers?

They might be.

Unlike the earlier systems, a skill is small and its aim is not explicitly ‘codifying everything’. Smaller than you, an information object in itself. And you get to combine such objects into a chain or bundle as a small workflow. They are a much smaller ask than the others were.
Additionally skills can be deployed by yourself in your own work. For processes, QA, KM it was mostly all done for others, for the hand-offs between actors and mostly seen as external to one’s own work. Why would you write down and maintain what you would not use yourself?
That is where skills can have a different impact. And in terms of ease of use, it helps that such skills are in natural language, as it allows you to handwave the parts where you can’t express your own actual knowledge in any precise detail. Which will be often.

So skills will be likely an easier sell to do some codification.
Still the push for skills is to be small, niche and specific. I’ve seen lots that are actually deterministic, in other words can be automated, except perhaps for the decision when to call a skill and with which inputs. Meaning they codify something different than knowledge.
Such codification will not likely form a coherent whole either. Also because skills are regularly aimed at something that is not within the scope of existing knowledge, a helper function next to current knowledge work.

So, no, I don’t buy the ‘skill codification as knowledge transfer’ suggestion to sell skills with.

In a session earlier today the deployment of a tool was discussed in an organisation’s information environment that is otherwise fully dominated by Microsoft products. After a presentation a director asked “if we add this tool to our (Microsoft) mix, aren’t we working in opposition to our wish for more digital autonomy and digital sovereignty”? The answer was “well you are already using Microsoft tools everywhere so sourcing this one tool from someplace else won’t change your autonomy in any way.”

I disagree. This is the pitfall of “it’s only worth changing if we can get from here to a mythical ideal situation in a single easy step, otherwise we’ll stay put”.
Indeed, opting to source a single tool outside of the walled garden you’re in does not change anything about you being in that walled garden as such. But adding a tool within the walled garden does make it harder still to leave that walled garden in the future. It increases your cost of leaving once more.

You have to begin somewhere if you want to move out of monopolies under foreign jurisdiction outside your democratic control, that can determine what’s on your screen and in your inboxes. Not adding to the problem is one step easily made, because it does not require you to change anything in your current way of working, just to apply different decision criteria upfront when adding something.

Bij de Open State Foundation (waar ik voorzitter ben) zoeken we een nieuwe directeur! Herken jij je in het profiel (PDF), en ben je net zo bevlogen als ons team om digitale transparantie bij de overheid te bevorderen en onze democratie te versterken? Dan horen we heel graag van je! Nadrukkelijk ook als je vindt dat je niet alle ‘vinkjes’ zet.

Open State Foundation is geregeld een waakhond die aanslaat, die laat zien dat het anders moet en kán, en even goed een betrouwbare partner van overheden om te zorgen dat het anders gáát.

Ik initieerde ooit met James Burke in 2008 de allereerste bijeenkomst van wat daarna Hack de Overheid ging heten, en later met Het Nieuwe Stemmen de Open State Foundation werd.
In 2017 schreef ik een impactanalyse op verzoek van Open State Foundation en een fonds, en merkte hoe goed en enthousiast het team is en welke mooie dingen er worden gedaan. Daarom stelde ik me beschikbaar voor het bestuur, en ben ik nu zo’n 8 jaar voorzitter.

Onze huidige directeur Serv Wiemers neemt na 6 jaren afscheid. Hij kwam middenin het eerste corona-jaar op een moment dat veel werk was komen stil te liggen. Niettemin had hij het schip (we zijn gevestigd op het Marineterrein in Amsterdam naast het Scheepvaartmuseum met de replica van de Amsterdam, dus een passende metafoor) spoedig op koers, en sindsdien hebben we een hele reeks mooie resultaten geboekt.

Ik kijk er naar uit kennis te maken met wie de volgende directeur wil en kan zijn!

Elke eerste zondag van de maand is het Doei!-dag, voor een dikke doei aan Big Tech.

Er zijn drie grote intrinsieke problemen met BigTech:
1) grote techbedrijven zijn data-graaiers. In grote techbedrijven gaat het in plaats van digitale dienstverlening bovenal om het verzamelen en verhandelen van data. Data over jou. Om er advertenties mee te verkopen en je gedrag mee te beïnvloeden. In weerwil van Europese privacywetgeving.
2) grote techbedrijven zijn silo’s en de-facto monopolisten. Ze houden je in hun silo door nog resterende verbindingen met andere digitale diensten of platformen of het open web stelselmatig af te breken en onmogelijk te maken (verticale integratie, en walled gardens). Hun de-facto monopolistisch karakter maakt dat ze hun diensten vervolgens kunnen uitkleden of nog meer richten op data-graaien, omdat je toch nergens anders heen kunt, en andere bedrijven die via hen iets verkopen afknijpen. De verkakking (enshittification) van digitale diensten.
3) grote techbedrijven staan meestal onder invloed van vreemde mogendheden waar jij geen democratische controle over hebt. Daarmee wordt het een pressiemiddel ten koste van jouw vrijheid van handelen. VS-bedrijven moeten toegang bieden aan hun overheid, en die overheid ook een uit-knop toestaan. (Eerst met de Patriot Act van 2000 en nu met de Cloud Act van 2018). Recenter coöpteren ze ook graag Europese toezichthouders en mengen ze zich in binnenlandse democratische processen. Chinese tech-bedrijven zijn integraal onderdeel van het Chinese surveillance en repressie-systeem, en component van het buitenlandse beïnvloedingsbeleid.

De eerste twee redenen zijn voldoende aanleiding voor ieder individu en bedrijf om af te zien van BigTech ‘diensten’, de derde maakt het ook urgent voor alle Europese overheden. Als digitale autonomie (ik bepaal hoe digitale gereedschappen voor me werken en welke ik gebruik) en digitale soevereiniteit (ik bepaal wat ik doe, niemand heeft aan mijn digitale gereedschap een pressiemiddel) je lief is.
De oplossing is overigens niet om gelijksoortige grote bedrijven in Europa te hebben. Die zijn dan net zo problematisch namelijk. Om dezelfde intrinsieke redenen als hierboven, en om de eveneens aanzienlijke problematische externaliteiten die BigTech ook veroorzaakt, t.a.v. klimaat, uitbuiting, haat en geweld.
Je moet er dus ‘gewoon’ helemaal vanaf, en niet op zoek naar een kloon maar dan met een EU vlag. Je moet overstappen naar alternatieven, en iets is pas een alternatief als het ook echt anders is. Qua omvang, financiering, besturing, structuur, functionaliteit en principes.

In ons huishouden zijn we in 2014 begonnen met Doei! zeggen tegen BigTech. Vooral vanwege de eerste reden (al waren enkelen in mijn netwerk toen ook al zeer stellig over de 3e reden). E is dan ook een van de mensen die in navolging van het Duitse Digital Independence Day (dat november vorig jaar startte) op de FOSDEM conferentie in januari bedachten dat een Nederlandse tegenhanger nodig is: Doei! dag.

Doei is technisch makkelijker gezegd dan psychologisch gedaan. Je bent gewend aan hoe het is, hoe je het nu doet. En als je verandert van software, platform of alleen al het uiterlijk van iets, vinden we dat snel erg lastig. Dus is wat hulp en aanmoediging welkom. Dat doet Doei! dag met recepten. Elk recept is een stappenplan om beetje bij beetje BigTech te vervangen door digitaal gereedschap dat alleen jou ten dienste staat. Bijvoorbeeld Signal gaan gebruiken (al is het een Amerikaanse non-profit, op deels Amerikaanse cloud infrastructuur van Amazon) in plaats van WhatsApp (van Meta).

Elke stap weg van BigTech is daarin beter, dan wachten op een perfecte overgang. Natuurlijk zit niet ‘iedereen’ op Signal, en voor je gevoel wel op WhatsApp. Maar sommigen wel, en met iedere overstap wordt de muur om WhatsApp heen doorlatender. Denk aan Hyves, dat was kort na 2010 binnen een paar maanden leeg, terwijl ‘iedereen’ er ‘op’ zat. Nog ‘even’ wachten op het perfecte alternatief en zeggen ‘maar ik weet wel dat ik eigenlijk iets anders moet gebruiken’, is hoe je brein de inspanning die iedere verandering is probeert te voorkomen. Je brein zegt eigenlijk ‘ik wil alleen veranderen als het geen verandering meer is’. D.w.z. je wacht op het redden van je digitale autonomie tot iemand anders dat voor je regelt. Niet heel autonoom, digitaal of anderszins. Je claimt je digitale autonomie door zélf kleine stapjes te zetten, en dat te blijven doen.

Mijn ervaring is dat bijna elke stap vooraf lastiger lijkt dan het meteen nadat je hem gezet hebt bleek te zijn.

Ik heb in 2014 bijvoorbeeld flink zitten puzzelen over hoe ik uit Gmail weg kon, gaf er ook presentaties over, en meteen nadat ik mijn e-mail anders was gaan doen vroeg ik me af waarom ik het niet veel eerder had gedaan.

Ik heb begin vorig jaar besloten dat ik geen e-boeken meer wil kopen bij Amazon. Dat was best even zoeken, waar koop ik die boeken dan wel, en hoe houd ik overzicht (dat ik bij Amazon ook niet had, ik dacht dat alleen maar), maar uiteindelijk was het eenvoudig, en ik ben nu ruim een jaar niet eens meer op hun site geweest. Ook als ik nieuwe boeken zoek, kom ik niet bij Amazon op de site, en in zoekresultaten negeer ik als vanzelf Amazon en Goodreads links. Ik ben veel blijven lezen, en doe dat nu gevarieerder dan voorheen. Ik heb bovendien nu ook meer plezier in het online neuzen naar nieuwe boeken, veel meer een verlengstuk van zoals het ook in een goede boekwinkel kan voelen.

Op mijn laptop (Apple! Maar mijn dochter heb ik een Linux laptop gegeven….) komt alle software die ik dagelijks gebruik van buiten BigTech, en van alle BigTech social media ben ik af. In mijn bedrijf heb ik dat ook grotendeels zo ingericht. Mijn telefoon is nog grotendeels BigTech afhankelijk (een Fairphone met standaard Android van Google nog, al heb ik een collega een ontgooglede mobiel gegeven) maar hopelijk ontvang ik later dit jaar een telefoon van Jolla met Linux (en dan kijken hoe goed bijv bank apps daarop draaien).

Het is ook niet alleen een individuele zaak, al helpt ‘stemmen met je voeten’ echt. In organisaties, op systeem-niveau, en in inkoopprocessen van overheden en bedrijven moet ook iets veranderen. Daarom ben ik bijvoorbeeld in mijn werk nu ook actief in hoe Europese en internationale standaarden voor datatransacties in data spaces en cloud en voor soevereiniteit in cloud platformen worden geformuleerd. Want alleen wie daar meedoet heeft invloed op die standaarden (terwijl iedereen ze moet gaan gebruiken). BigTech zit er áltijd, die hebben daar (overigens zeer kundige) mensen voor en weten dat ze zo de hele markt kunnen beïnvloeden. Ik zit er daarom ook, want tegengas is nodig op de uitgangspunten en aannames die BigTech hanteert.

Perfect is het dus niet/nooit, systemisch niet, en individueel niet. Zo zit ik ook nog wel op LinkedIn (van Microsoft), al heb ik de tijdslijn daar uitgezet voor mezelf toen het inhoudelijk een soort Facebook-kloon begon te worden. Maar dat ik me nu langzaam drukker begin te maken over de hardware die ik gebruik, in plaats van alleen de software en online diensten, is een teken dat ik en ons huishouden al flink wat stappen hebben gezet.

Stap je mee?

Doei!

In the past week I’ve started three personal experiments that use AI (in this case Claude Code). For each, the experiment lies in automating steps in my cognitive work that are useful or necessary but not the actual cognitive work itself. They’re helper activities, supporting the main task. For two of the three that is the clear focus, the third is slightly different.

The three experiments are:

  • Filtering on interests in my feed reader, let’s call it ‘Weak-tAIs’.
  • ‘Slopsidian’, lifting concepts and argumentation from papers into Obsidian notes, and linking them iteratively.
  • Explore questions with pre-existing ‘recipes’ that take a specific philosophical perspective. Perhaps I should dub this type of language game ‘WittgenstAIn III’.

It started from an automation task, which I mentioned here: manipulating non-fiction e-books. I have a script that I can point to an e-book in my Calibre collection, and then will populate a note with elements from the book: foreword, index and literature list, content overview, all if present, and for each chapter of the book the first and last few paragraphs. This is what I look at and skim whenever I want to gain a first impression and understanding what a book is about, and what questions it addresses or what it proposes. All very Mortimer Adler. From it I can then decide which parts of a book to read more closely, which parts likely contain things I am already familiar with or fall outside my current interest in the book. From those skims I jot down things in my note for the book. This quickly turned out to be useful to me, because it removed the wall between the e-book and my notes by bringing parts of the e-book into my notes temporarily where I could more quickly go through them in preparation for ‘proper’ reading (although in fact it is part of reading).

It got me thinking what other helper activities in reading and filtering I could identify.
Helper activities are tasks that support a main task by making it easier or providing guard rails. Checklists are an example, they ensure that you don’t skip important steps. In most cases nothing will immediately go wrong if you don’t do the helper activity but if you do them the main task gets a little easier to do well. A lot of helper tasks can be regularly automated, like the e-book excerpt script above. Others less so because they contain elements of processing actual texts, like the three experiments I describe here. There perhaps using a model like Claude Code can be of value (and hopefully soon, through local model deployment).

A brief description of the three experiments:

Weak tAIs
I order my RSS feeds by social distance for reading. Part of the reasoning is that I want to be well informed about what close ties write, but I am aware that interesting information likely comes from a wider social distance. This practice has been in place for some two decades and enormously valuable all that time. The most interesting stuff usually comes from the third layer, a folder named ‘c150’, in my feedreader: close enough to know who the author is, and engage in interaction if I want, disconnected enough for them to encounter things I am less likely to have already seen myself. That is the The Strength of Weak Ties (1973) as Granovetter called it.

I also keep a list of current interests, a bit like Feynman’s dozen or so currently favourite problems. For each interest I have formulated a few aspects:

  • what is conceptually interesting to me in a topic (e.g. my interest in EU digital and data policy conceptually is that it forms a geopolitical proposition externally, while being a quality improvement instrument internally that takes rights and societal values as yardstick),
  • am I theoretically interested or more practically,
  • do I have a knowledge fundament for the topic or am I a newbie,
  • is there a link with any long term goals,
  • can it be put into a specific context or tied to a specific issue/question,
  • can I shape or create an enduring practice around it,
  • can I build a bridge to outputs, like blogposts, presentations, or client proposals

My feedreader tracks just under five hundred people writing on the open web. That can easily amount to two thousand postings in a week. I can have several intentions to start reading, one of them is to find and read material relevant to my list of current interests. A reading intention does not do away with items, it’s not a filter to remove material. It’s essentially just a view on the entire set of incoming items in the feed reader that I usually construct in my mind. What if I can construct those views on my screen too?
The ‘c150’ social layer, the weak ties, what do they write about that connects to the fields of interest from my list? Such filtering does not lend itself to text based search based on fixed terms. I usually skim titles for first impressions, and click opportunistically through the postings. What if I can have a model weigh the postings and compare them to my list of current interests, to mark them for my attention? In aid of that one specific reading intention.

That’s what the first experiment does: label postings that seem to fit my interests, and express why. So that I can skim the folder of weak ties by interest, and read those items first if my intention is to explore those interests. I limited it to the c150 folder as feeding all rss feeds into the model is consuming a lot of time and tokens, so I started with the part most likely to bring useful results.
The labeling works now as part of my feedreader. I am not yet convinced of the quality of it though. The motivation for the labels usually is along the lines of "it fits interest X but not in the way you’re looking for", which to me means it actually doesn’t really fit.

Slopsidian
This week I read an article about AI documenting its own actions and output in a wiki, and saw one or two similar efforts described. I applied that to a different helper task, which is the preparation of reading a paper and helping me to decide to dig deeper. This is similar to skimming a non-fiction book, but more involved. Can AI reliably pull from a paper the concepts used and introduced, and the line of argumentation? Saving them both in a single note for the resource, and in separate notes for each of the concepts? Additionally can it logically link concepts from different resources? This is what an ‘ingestion skill’ now does for me. I let it store the output it generates in a folder that I can also open as an Obsidian vault, hence the name Slopsidian. The papers come from my Zotero collection, meaning I previously saved them. That original step of curation also means I have a line or two about why I thought them interesting at the time. Feeding that curating decision and the paper into the ingestion skill allows a second order look at a paper. What are the concepts discussed, and, reading the output, do I think some of those are of interest to me? If so, I can look at the paper more closely and do my own note making and paraphrasing and placement in my actual Obsidian collection. Lifting out concepts works rather well, the linking is less useful in the first experiences (too obvious, not sparse enough) and can seem forced when you look at why some concepts get linked.

WittgenstAIn III
The third experiment is a bit more on the edge I think. Here the probabilistic language games that LLMs are have more of a free rein. Part of the university courses on philosophy of science I did 25 years ago was using different philosophical schools of thought as lenses to approach a question. Not to answer the question, that is hardly ever the point after all, but to holding it, and holding it differently. Plato’s essentialism, Kant’s transcendence, dialectics (Hegel), phenomenology (Husserl), Wittgenstein II’s analytical method, hermeneutics (Heidegger), deconstruction (Derrida), and Rorty’s pragmatism. For each of these, for over 2 decades, I’ve had a recipe in my notes to apply to a question.
I put together a ‘language game’ in which I pose a question, which a ‘router’ prompt tries to match to one or more of the 8 recipes, or to a combination of recipes chained together (e.g. first look at a question from an analytical perspective and then feed the results in to a deconstruction exercise.)
My existing multi-step recipes are followed, and output is generated for each of those steps, into a resulting note.
I read those resulting notes, lift out what catches my eye or what resonates and I use it to flesh it out more, for me to hold the question still longer. Models are language games of a sort, so hence the name WittgenstAIn III, a third iteration, extending the second Wittgenstein’s language games to and with AI.
The output here makes me more uncomfortable than the other two. Reasoning is being mimicked, with the usual overconfident wrongness we’ve come to expect from generative AI, and that works out in odd ways sometimes. Still there is utility that can be lifted from the output. It is a good kickstart for exploring questions to quickly see if a recipe might yield something or not, judging by my first attempts in this experiment. It does certainly lower the threshold, as helper task, to engage with the recipes. I’ve used it more in the past days than in the past months. Part of that is the novelty of the experiment, and that may wear off quickly, but perhaps it carries the kernel of more habitual use.