Building a Digital Sovereignty Castle in the Sky

I'm writing this article within the context of the SOAM "RE:FUND OUR DIGITAL FUTURE: REIMAGINING FUNDING ARCHITECTURES FOR PUBLIC INTEREST TECHNOLOGY” residency program I'm taking part in to order to create a new speculative institutional model with the goal of empowering open hardware infrastructure and promoting its development through an public institution funded by public bonds. More information in the article where I announced it. 

When European leaders gather in Berlin on Tuesday for the Summit on European Digital Sovereignty, they’ll discuss artificial intelligence, open source software, cloud infrastructure, and data governance. They’ll probably announce initiatives and emphasize the need for European tech champions. On paper, it all sounds good and welcome. But I fear it will fall short because we’re building these lofty dreams on a foundation we don’t control.

All these digital sovereignty efforts must exist on layers we can’t inspect, can’t modify, and increasingly can’t access. Every initiative, every investment, every ambitious plan for European technological independence runs on silicon designed with American tools, manufactured on highly proprietary machines, and fabricated in foundries owned by a handful of companies (collectively Hardware Infrastructure, to make it more distinct from simply Open Hardware as it currently exists.) We’re debating the architecture of upper floors while building on someone else’s land, subject to someone else’s rules, revocable by someone else’s decisions.

Open-source software’s success creates dangerous complacency. Linux runs 96% of the world’s top web servers. Kubernetes orchestrates cloud infrastructure for every major provider. This infrastructure commons enabled Europe to participate meaningfully in the digital economy without paying rent to American software monopolies. It works. It’s real sovereignty at the software layer.

The danger is that this success might lead some to believe digital sovereignty can be achieved through similar efforts at higher layers, just with sovereign clouds, “open source” AI models, or more open source software. It’s not an unreasonable belief. It’s just not addressing the full picture.

Software sovereignty falls short when it runs on hardware we can’t build. Every European open-source project, every sovereign cloud, every AI initiative executes on chips designed using tools from three American companies charging hundreds of thousands to millions per license. Those chips are manufactured using lithography equipment from ASML, extracting €180-380 million per machine, and fabricated in foundries subject to U.S. export controls and geopolitical pressures.

When the United States restricts China’s access to advanced chips and manufacturing equipment, it demonstrates precisely what infrastructure dependence means: your digital economy’s foundation can be cut off by foreign policy decisions you don’t control. Europe faces the same vulnerability. We just haven’t experienced the cutoff yet.

The Rent Extraction Architecture

Before any European company can design a chip, before any university can prototype a climate sensor, before any nation can develop strategic hardware capabilities, they must license tools costing €100,000 to €1 million per engineer annually. You’re not competing on technical merit. You’re paying rent to access the tools everyone needs.

ASML’s lithography monopoly means every advanced chip depends on equipment from a single company. Only a handful of companies globally can afford the machines. This bottleneck exists partly because when governments funded EUV research, they chose proprietary winners rather than creating open access to publicly-funded knowledge.

Manufacturing requires navigating proprietary relationships with foundries, with access requiring millions for production runs, proprietary process specifications, and increasingly, geopolitical alignment. A European company with a breakthrough chip design has no guaranteed path to manufacture.

Every layer represents strategic vulnerability. You cannot build a sovereign cloud on chips you can’t design with tools you can’t access manufactured in facilities you don’t control.

Why Fab Subsidies Miss the Point

Europe’s primary hardware sovereignty response has been subsidizing chip fabrication plants, which addresses symptoms rather than causes. Yes, Intel’s fab in Magdeburg and TSMC’s facility in Dresden improve manufacturing capacity. But they don’t address the deeper dependencies. Those fabs still require ASML equipment, designers still need American EDA tools, process technologies remain proprietary, and access still depends on geopolitical relationships.

More fundamentally, fab subsidies don’t create commons. They create additional proprietary capacity. Companies still pay rent at every layer. The infrastructure remains extractive rather than enabling.

Consider Belgium’s IMEC, often cited as a European success in semiconductor research. Despite public funding, IMEC operates on a membership model where companies pay fees for access. When 75% of the budget comes from corporate members, the institution serves those who can afford membership. Startups, universities, independent researchers, and nations seeking capability development are structurally excluded. IMEC creates shared proprietary research, not commons.

Europe continues paying rent for technology infrastructure rather than building publicly accessible foundations, even when that research happens in Europe and is subsidized by European taxpayers.

Open Hardware Infrastructure Already Exists, Kinda

The bitter irony is that open hardware infrastructure already exists and works. It just lacks the institutional support that would transform it from impressive technical achievement into market-changing infrastructure.


KiCad provides circuit board design tools rivaling proprietary alternatives, CERN uses it. Yosys performs chip synthesis competing with tools costing hundreds of thousands per license. RISC-V has shipped over 10 billion cores, with Google, NVIDIA, and Western Digital adopting it for production. OpenROAD delivers complete chip design flows and has fabricated real chips. Open Process Design Kits from SkyWater and GlobalFoundries enable actual chip manufacturing without proprietary licenses.

The technology works. What’s missing is institutional infrastructure. Just like by the late 1990s, Linux worked technically. But companies didn’t trust it for production until institutional infrastructure emerged: commercial support companies, professional training programs, established foundations providing governance, and critically, permanent employment for thousands of engineers maintaining production infrastructure rather than volunteer labor and temporary grants.

Europe contributed significantly to that transformation for software. European companies employ thousands of open-source developers. European universities train engineers in open technologies. European infrastructure companies build businesses around open-source support.

We never built equivalent institutions for hardware. That’s the gap undermining every digital sovereignty initiative.

The Missing Open Hardware Infrastructure Institution

Europe needs permanent infrastructure for open hardware that eliminates rent extraction at foundational layers. Not another research consortium operating on membership fees. Not another subsidy program for proprietary capacity. A public institution designed specifically to create technology commons: production-grade open chip design tools, foundry access coordination, collaborative development platforms, and open standards.

This requires:

  • Employing engineers at scale in permanent infrastructure positions, not temporary research grants
  • Patient capital through infrastructure bonds with 20-30 year maturities, not annual appropriations creating political vulnerability
  • Governance that prevents institutional capture while maintaining technical excellence and public accountability

The model exists. Europe built permanent institutions to compete in cutting edge scientific research, in aerospace, and even in space. Even for open-source software, we’re seeing the rise of institutions like the Sovereign Tech Agency in Europe.

We need to do the same for hardware.

Europe is already a decade behind. Every year we delay represents engineer talent lost, institutional knowledge not built, and strategic options foreclosed.

Digital sovereignty built on proprietary hardware infrastructure isn’t sovereignty. It’s a castle in the sky: impressive in appearance, vulnerable in reality, destined to collapse when geopolitical winds shift.

Europe has proven we can build technology commons through open-source software. It has created permanent institutions that transformed volunteer efforts into infrastructure powering the global digital economy.

We need to do the same for hardware. Not after the next crisis demonstrates our vulnerability. Now, while we still have capability, capital, and partnerships to build comprehensive infrastructure before geopolitical fragmentation makes it impossible.

Tuesday’s summit offers an opportunity for genuine strategic vision rather than reactive crisis management. But it will show its true ambition based on whether it recognises that sovereignty requires foundations, not just upper floors.

The UK’s Online Safety Act: A Lesson in Technosolutionism

The United Kingdom has just delivered the world’s most expensive demonstration of why throwing technology at social problems doesn’t work. After two years of ignoring expert advice and billions in compliance costs, the UK’s Online Safety Act has achieved the opposite of its stated goal by making the internet less safe.

Six months into enforcement, Britain’s techno-solutionist fantasy has crashed into reality with predictable results. Beneficial online communities have been obliterated, VPN adoption has surged 1,400%, and the UK has created a perfect case study for why governments can’t regulate away complex social problems with algorithmic band-aids and surveillance theater.

If you wanted to design legislation to eliminate the internet’s safest spaces for vulnerable people, you couldn’t improve on the UK’s approach. The Act’s most spectacular own-goal has been systematically destroying community-run websites that provided genuine social support.

Consider Microcosm’s 300 community websites serving 275,000 monthly users. These weren’t dark corners of the internet. They were cycling forums, parenting advice sites, and local community hubs where people actually knew each other. Dee Kitchen, who ran these communities for nearly three decades, captured the government’s logic perfectly: “It’s too vague and too broad and I don’t want to take that personal risk.”

The community websites closed specifically because age verification would destroy the trust and openness that made them safe spaces. As site administrators noted: “The impact that these forums have had on the lives of so many cannot be understated… approximately 28 years and 9 months of providing almost 500 forums in total to what is likely a half a million people.”

Meanwhile, harmful content on major platforms continues largely unabated. Tech giants with billion-dollar compliance budgets simply absorb fines as operating costs. TikTok’s £1.875 million penalty represents roughly 0.01% of ByteDance’s $155 billion annual revenue, making it count less than a virtual parking ticket.

Perhaps the crown jewel of the UK’s techno-solutionist delusion is demanding “safe” encryption backdoors. Despite government admission that the necessary technology “does not yet exist,” officials refused to let inconsequential details like reality or mathematics interfere with their mandates.

Ciaran Martin, who founded the UK’s National Cyber Security Centre, called out this “magical thinking”, essentially the belief that encryption can be weakened for government access while remaining strong against everyone else. This isn’t a technical challenge; it’s a fundamental impossibility as the Global Encryption Coalition noted.

Even the tech industry’s response was swift and unified. Signal, WhatsApp, and Apple essentially told the UK government to choose between secure communications and backdoors. Instead of magically solving encryption, the UK triggered a 1,400% surge in VPN adoption as users decided to route around the government’s technical incompetence rather than submit to it.

In other failures, within days of enforcement, automated systems were treating Conservative MP posts about grooming gangs, police arrest footage, and parliamentary speeches exactly like genuinely harmful content. This wasn’t a bug, it’s the inevitable result of the futility of trying to teach machines to understand human context, intent, and meaning.

When platforms face £18 million fines for missing harmful content, they predictably err toward censoring everything that might possibly be problematic, including discussions of the very problems they’re supposed to solve.

The meta-censorship problem showcases the system’s absurdity: documentation of censored content gets censored, creating a feedback loop where evidence of the system’s failures becomes impossible to discuss publicly. It’s compliance theater at its finest. It is visible enough to inconvenience ordinary users, yet ineffective enough to let determined bad actors adapt around it.

This reveals the UK’s techno-solutionism’s true beneficiaries: tech giants who can afford compliance theater while their smaller competitors get regulated out of existence. Meta and Google can absorb billions in compliance costs; community forums run by volunteers cannot.

he threshold-based requirements create what researchers call ‘vastly disproportionate compliance incentives’, which is academic speak for “we’ve built a regulatory country club and labeled it child safety.” The UK has essentially using child safety as cover for the largest anti-competitive regulation in internet history, with the result being an internet that’s simultaneously less safe and less accessible.

Not to be outdone, the European Union watched the UK’s comprehensive failure and decided to ask them to hold their beer. The EU is implementing almost identical age verification systems that require Big Tech technology as a key dependency while pursuing deeply unpopular “chat control” legislation that is planned be adopted by October 2025.

Despite Poland’s EU Presidency giving up on voluntary chat scanning, the fundamental legislative momentum continues unchanged. European policymakers have learned nothing from watching their neighbours systematically destroy beneficial online communities while failing to protect children. They’re implementing the same impossible technical requirements, ignoring the same expert warnings, and expecting different results.

The UK’s experiment has produced one unambiguously successful outcome: the largest grassroots digital rights movement in British history. Over 290,000 citizens have signed petitions demanding repeal, which is impressive political engagement for any cause, let alone internet infrastructure policy.

Proton VPN reported that 1,400% increase in UK signups within hours of enforcement, noting this was “sustained and significantly higher than when France lost access to adult content.” Multiple VPN providers reported similar surges, with privacy apps dominating UK App Store charts for weeks.

The circumvention became so widespread that Ofcom demanded platforms prohibit content encouraging VPN use, creating a perfectly Orwellian situation where discussing privacy tools becomes prohibited speech under legislation supposedly designed to protect online safety.

The UK’s experiment inadvertently provided a perfect demonstration of what makes the internet genuinely safer: community-based moderation, user empowerment, and addressing real-world social problems that manifest online.

The forums destroyed by the Act had operated safely for decades through transparent governance, engaged user communities, and voluntary compliance with clear standards. These spaces worked because they created genuine human relationships where inappropriate content was quickly identified and addressed by people who actually cared about the community’s wellbeing.

Technical mandates destroy these approaches by replacing human judgment and community accountability with automated systems that users cannot understand, appeal, or improve. When algorithms make moderation decisions, users lose agency over their own spaces, communities lose the ability to set their own standards, and the social dynamics that create genuine safety disappear.

This expensive UK experiment offers the world a choice: learn from their mistakes or repeat them at even greater scale. The evidence is overwhelming that age verification systems, encryption backdoors, and automated content moderation create more problems than they solve while systematically destroying community-based approaches that actually work.

The lesson is clear but politically inconvenient: protecting people online often begins offline, and requires addressing factors like social isolation, inadequate education, economic inequality, and lack of community support. Online factors can also help, but those require giving users agency to manage their own communities, and investing in digital literacy. Unfortunately these solutions involve long-term investment in unglamorous things like schools, social services, and community programs, not exciting technology mandates that primarily serve our big tech overlords.

The Hardware Innovation Monopoly Problem: Why Europe Should Stop Chasing Unicorns

I'm writing this article within the context of the SOAM "RE:FUND OUR DIGITAL FUTURE: REIMAGINING FUNDING ARCHITECTURES FOR PUBLIC INTEREST TECHNOLOGY” residency program I'm taking part in to order to create a new speculative institutional model with the goal of empowering open hardware infrastructure and promoting its development through an public institution funded by public bonds. More information in the article where I announced it. 

Europe has a hardware unicorn problem. Not the lack of billion-dollar startups that dominates policy discussions, but something far more fundamental: the continent has fallen into the trap of celebrating private control over public hardware infrastructure as innovation success. ASML’s dominance in semiconductor lithography is held up as a European triumph, the European Chips Act allocates €43 billion to create “European champions,” and policymakers dream of building the next TSMC or Nvidia on European soil.

Within the context of the digital sovereignty discussions happening, I highly question this approach. At worst, it will probably fail, and at best, it will continue to lock us in a system that treats essential technological infrastructure as private property rather than public commons. The real question isn’t how to build European monopolies to compete with American and Asian ones, but how to reclaim democratic control over the infrastructure that shapes technological development through open hardware infrastructure.

Information-age innovation operates on different principles that challenge the logic of private infrastructure ownership. Open Source Software development has demonstrated that publicly governed, collaborative models can consistently outpace private monopolistic alternatives. Linux powers most servers and smartphones, Apache runs most web servers, and countless developers contribute to open source projects that drive the digital economy.

The success of open source software commons isn’t just about licensing. It’s about fundamentally different approaches to infrastructure governance. When development tools are publicly available, coordination platforms are democratically governed, and knowledge can be shared instantly, innovation accelerates because the best ideas can emerge from anywhere and spread rapidly across entire ecosystems.

Hardware development has remained stuck in private monopolistic patterns partly because the underlying infrastructure remains privately controlled. Design tools, manufacturing coordination, and development platforms are owned by a handful of companies that optimize for extraction and scarcity rather than abundance and public benefit. This creates artificial barriers that concentrate innovation capability within a few large private organizations while excluding the broader public from participating in technological decision-making.

The distinction between infrastructure and end products is crucial for understanding where collaborative models can succeed. Just as we don’t expect every company to build their own internet protocols or programming languages, there’s logic to having shared hardware development tools and platforms. When development tools are publicly available, coordination platforms are democratically governed, and knowledge can be shared instantly, innovation accelerates because the best ideas can emerge from anywhere and spread rapidly across entire ecosystems. This doesn’t mean eliminating competition in final products, but rather ensuring the underlying infrastructure that enables innovation remains accessible to all participants rather than controlled by private monopolies.

ASML represents both Europe’s greatest semiconductor success and its most instructive failure. The Dutch company holds a 100% monopoly in EUV lithography equipment required for advanced chip manufacturing, with 82.9% overall market share in lithography equipment. While the company claims to have invested $10 billion over 20 years to develop EUV technology, this narrative obscures the massive public investment that made ASML’s monopoly possible.

EUV development has consumed no less than $14 billion in funding over the years. Much of this came from public sources: European EUV R&D programs were organized through MEDEA+, funded by national governments of the Netherlands, Germany, France and Belgium, and the IST program supported by the European Commission involving more than 100 companies, institutes and universities. ASML operates under a Cooperative Research and Development Agreement (CRADA) funded by the US government, and current EU programs like Horizon Europe, Digital Europe, and the Chips Joint Undertaking have provided approximately €1.4 billion in public investments.

This is the core issue with privatized public infrastructure: ASML extracts value from technology development that was largely funded by European and American taxpayers, yet makes private decisions about technical roadmaps, pricing strategies, and geographic access. While the company innovates impressively, it innovates in a narrow manner that serves its shareholders’ strategic goals rather than the broader public interest that funded its development. Critical decisions about humanity’s technological infrastructure are made in corporate boardrooms rather than through democratic participation or consideration of the public that financed its creation.

More fundamentally, ASML’s monopoly exists because the entire ecosystem of hardware development infrastructure has been privatized despite massive public investment in its creation. The company succeeded not just through technical excellence, but because taxpayer-funded research has been converted into proprietary and concentrated private assets. Design software from Cadence and Synopsys costs hundreds of thousands in Euros per license. Access to advanced foundries requires millions of Euros in minimum commitments. Manufacturing coordination happens through opaque networks of established players who control access to publicly-funded technological capabilities.

This exemplifies the broader problem: when essential technological infrastructure becomes private property, it creates artificial scarcity and concentrates innovation capability within a few large organizations. The tools and platforms that should enable broad participation in technological development instead become barriers that exclude all but the most well-funded players.

This isn’t a failure of ASML as a company. It’s a failure of the political and economic system that allowed decades of public investment in critical technological infrastructure to be converted into private property and monopoly control. When taxpayer-funded research is privatized and the resulting infrastructure is controlled by private monopolies, only companies with massive resources can participate in advanced development. The result is that decisions about humanity’s technological future are made in corporate boardrooms, optimizing for shareholder returns rather than the democratic participation and public benefit that funded the original development.

Europe’s current semiconductor strategy perfectly illustrates how policy thinking has become trapped in privatization logic. The European Chips Act aims to increase EU semiconductor production from 10% to 20% of global capacity by 2030, but this €43 billion investment follows traditional subsidy models designed to create private “European champions” that can compete with other private monopolies.

This approach treats private control of technological infrastructure as inevitable rather than examining whether critical development tools and platforms should be publicly governed in the first place. The top 10 semiconductor companies controlled 67% of global sales in 2024, with capital requirements that have grown exponentially from thousands to billions of dollars. Modern fabs require $15–20 billion investments, creating barriers to entry that effectively exclude all but the largest private players.

But these barriers aren’t purely technical. They’re partly the result of privatized infrastructure that creates artificial scarcity from publicly-funded research. Much of the cost comes from proprietary tools, duplicated private facilities, and coordination inefficiencies rather than fundamental physical constraints.

Rather than questioning these assumptions about private ownership of technological infrastructure, European policy seems to accept infrastructure privatization and is scrambling for a piece of the cake. This creates a zero-sum competition where success is measured by which private entities capture market share rather than whether technological development serves our democratic goals or public interest.

What we need is intentional investment into open hardware infrastructure: the design tools, development platforms, manufacturing coordination systems, and standards, which can be developed collaboratively even when final products remain competitive.

The choice isn’t just about technology policy. It’s about what kind of relationship between technology and democracy Europe wants to build for the 21st century. Information-age innovation requires different organizing principles for its underlying infrastructure that prioritize public benefit over private extraction.

Europe has the institutional capacity and collaborative traditions to lead this transition. The continent has great examples of creating international institutions that coordinate complex technical work, such as CERN and the European Space Agency. Building a similar institution to build and maintain open hardware infrastructure won’t happen overnight, but requires long-term vision and patient investment.

The benefits of opening up hardware infrastructure are undeniable. It will enable thousands of companies and millions of engineers to develop hardware solutions faster and more effectively than private monopolistic competition allows, while ensuring that decisions about technological development remain democratically accountable rather than concentrated in private hands.

We should leave private hardware monopolies model in the past. Publicly governed open hardware infrastructure is the future we deserve, but only if we choose it.

How can Open Hardware catch up with Open Source Software?

First off- excited to announce that I’ve been accepted into the SOAM Virtual Residency program with the theme “”RE:FUND OUR DIGITAL FUTURE: REIMAGINING FUNDING ARCHITECTURES FOR PUBLIC INTEREST TECHNOLOGY”. I applied because I thought this theme would be perfect to try to address the question in the title, because I believe that the core answer is that the current funding models that dominate tech development, from venture capital to ad-tech to data extraction, are fundamentally incompatible with the collaborative, commons-based approach that would make open hardware possible.

When I look at FOSS, I see an ecosystem where open source has fundamentally reshaped how we build, share, and innovate. Entire industries and communities have been built on the foundation of freely shared code, collaborative development, and transparent architectures. But hardware? We’ve largely surrendered our digital infrastructure to proprietary black boxes. Our phones, laptops, routers, and IoT devices are increasingly locked down, impossible to modify, and controlled by a handful of corporations. We’ve accepted planned obsolescence, vendor lock-in, and the inability to truly own the devices we depend on.

The consequences of this proprietary hardware dominance extend far beyond inconvenience. When our fundamental computing infrastructure is controlled by a few entities, we face security vulnerabilities that can’t be independently audited or fixed, privacy concerns with no way to verify what our devices are actually doing, innovation bottlenecks where progress is gated by corporate priorities, economic dependencies that stifle competition and local manufacturing, and environmental costs from unrepairable, non-upgradeable devices. We’ve essentially built our digital society on a foundation we can’t inspect, modify, or truly control.

A thriving open hardware ecosystem is absolutely possible, and could bring our societies the same transformative benefits that open source software has delivered: greater innovation through collaboration, more secure and auditable systems, democratic control over our technological infrastructure, and economic models that serve public benefit rather than private extraction.

The challenge isn’t that open hardware can’t work, but that it can’t grow at the scale it needs to grow precisely because it’s different from software. The material constraints, manufacturing requirements, and coordination challenges that distinguish hardware development demand different institutional approaches. It also doesn’t help that the open hardware infrastructure, or the technologies we need to develop open hardware, are also proprietary. That’s why we need a new type of institution: a public works for open hardware infrastructure.

During this residency, I’m developing a concept for exactly that. I’m exploring how we might create sustainable economic models for open hardware infrastructure development that don’t rely on the extractive capitalism that has shaped our current tech landscape. The fundamental challenge is economic and institutional. We need a public open hardware infrastructure works that is built around patient capital funding and mission-driven development, drawing inspiration from historical models like Dutch water bonds and modern transnational institutions like Airbus and CERN.

To alleviate the challenges of bootstrapping such a massive infrastructure project, we need an approach where patient capital allows for the longer development cycles that hardware requires, and where mission-driven priorities can align with public benefit rather than private extraction. The goal isn’t just to create more open hardware projects, but to design the institutional foundations that would make open hardware development sustainable and scalable at a systemic level.

If that topic is interesting to you, then I’m all ears. I’m particularly interested in hearing from institutional designers interested in alternative models for tech financing, hardware developers who’ve struggled with the challenges of open hardware projects, manufacturers who are frustrated by proprietary tooling and licencing fees, policy researchers thinking about the regulatory and economic dimensions, and anyone who’s frustrated with the current state of proprietary hardware dominance.

I’ll be sharing more details as as my residency progresses, but I’d love to start the conversation now. Feel free to write to me on mastodon with your thoughts.

Gardens, Not Roads: Cultivating Open Source Communities

Ever since its eponymous report was published nearly a decade ago, the “roads and bridges” metaphor has dominated how many working with FOSS software, including I, think about open source sustainability. Nadia Asparouhova’s influential 2016 report painted a picture of critical digital infrastructure that is prone to crumbling and neglect, drawing parallels to our physical highways and bridges. Another influential visual metaphor was the xkcd comic 2347 “dependency”. The tower of precarious building blocks was powerful, and immediately comprehensible. Between both the report and the comic, these metaphors helped secure millions in funding for open source projects and brought much-needed attention to maintainer burnout.

Even using phrases like “digital infrastructure” to refer to critical FOSS components is a metaphor of sorts, since infrastructure is by definition physical. It’s also worth noting that the use of infrastructure metaphors to refer to our digital world is no way novel, who can forget the Superhighway Summit of 1994, the site where Al Gore “created the Internet”. Another notorious case of metaphor fail was when Senator Ted Stevens referred to the internet as a “series of tubes”, in an argument against Net Neutrality.

But metaphors are inherently limited, and can be misleading when taken at face value. We use the dependency comic, “roads and bridges”, and even “digital infrastructure”, to explain that FOSS has become just as valuable as those things, and when it breaks it can have dangerous consequences for our society. However when these metaphors are taken too literally, we end up with misunderstandings about how best to maintain FOSS and the metaphor becomes counter-productive. Knowledge is knowing tomato is a fruit, wisdom is not putting it in a fruit salad.

The roads and bridges metaphor, while a good analogy for the importance of FOSS, does not represent how open source projects are structured and how they function.

While FOSS may be just as important as physical infrastructure in terms of societal value, the critical error lies in assuming that because both are essential to the public interest, they should be built and maintained using the same approaches. This conflation creates a cascade of problematic assumptions that undermine effective support for the communities developing open source.

Sidenote: There’s a similar issue when considering the topic of FOSS as a public good. Sure, the open source software itself can be classified as a public good if you follow the definition, but FOSS communities are NOT a public good.

To understand why this metaphor falls short, we need to examine how the fundamental differences between open source infrastructure and physical infrastructure.

Consider how differently a bridge is built versus an open source project. A bridge represents a fixed solution to a specific problem, getting from point A to point B across an obstacle. It often emerges from centralised planning, contracted labour, and hierarchical project management. Typically a government entity decides what infrastructure is needed, designs it according to specifications, hires contractors to build it, and then operates maintenance programs with dedicated staff and budgets. Once built, the bridge’s primary relationship with humans is maintenance: inspection, repair, and eventual replacement.

Open source projects, however, are living systems of knowledge and collaboration that emerge from entirely different conditions. They may begin with someone scratching their own itch or a hobby project, communities forming around shared technical interests, or developers exploring what’s possible with new approaches. Most of the work happens through voluntary coordination, distributed decision-making, and relationships built on reputation and mutual interest rather than formal contracts. These projects represent not just solutions to current problems, but platforms for discovering new problems worth solving and environments where people engage in meaningful work that develops their capabilities.

This fundamental mismatch between metaphor and reality has led to well-intentioned but ultimately misguided approaches to open source sustainability.

The infrastructure metaphor has spawned an entire industry of data-driven approaches to open source sustainability that, while valuable for their intended purposes, address different challenges than supporting the people who create and maintain these projects. We now have sophisticated systems for measuring “criticality” based on dependency graphs, download counts, and contributor metrics. Organizations deploy tools to scan their codebases and identify “risky” dependencies. Funding programs that use data-based scoring to determine which projects deserve support. These approaches emerge naturally from treating open source like physical infrastructure, where quantitative assessment makes sense. Bridges either carry traffic loads safely or they don’t. Water systems either deliver clean water or they fail.

The appeal of these data-driven methods is understandable. They promise objectivity in allocation decisions, scalability in assessment processes, and clear metrics for accountability. For organizations managing hundreds or thousands of dependencies, automated analysis seems like the only practical approach. These tools excel at what they’re designed to do: helping organisations understand their technical dependencies, assess risk exposure, and make informed decisions about resource allocation. But open source projects aren’t bridges or water systems, and the quantified approach that works well for physical infrastructure serves different needs than understanding how collaborative development actually functions.

While infrastructure frameworks focus on technical dependencies and data-driven approaches optimize for organizational risk management, neither addresses the fundamental question of how collaborative software development actually works. The most useful framework for understanding sustainability isn’t infrastructure maintenance: it’s recognizing open source projects as communities of practice.

The concept of communities of practice, developed by anthropologist Jean Lave and educational theorist Etienne Wenger, describes groups of people who share a craft, profession, or passion and learn together through regular interaction. In this context, maintainers aren’t simply individual contributors or employees performing discrete tasks; they’re participants in ongoing, shared learning around specific domains, technologies, and problems. This perspective shifts attention from measuring outputs to understanding the social processes that generate those outputs.

The knowledge that makes projects valuable isn’t contained solely within the code itself. Every mature open source project accumulates layers of institutional knowledge: understanding why certain design decisions were made, how to navigate complex technical trade-offs, which approaches have been tried and abandoned, and how different components interact in subtle ways. This knowledge lives primarily in the relationships between people rather than just in documentation or commit messages. When experienced contributors leave, they take irreplaceable understanding with them that can’t easily be reconstructed from technical artifacts alone.

The process by which people become maintainers reflects this community-based reality. New maintainers aren’t hired through traditional employment processes: they’re developed through what Lave and Wenger call “legitimate peripheral participation.” People typically begin by fixing small typos in code or documentation issues, gradually move to bug fixes, start reviewing others’ contributions, and slowly take on more responsibility as they demonstrate competence and build relationships within the project. This progression requires mentorship, patience, and sustained community investment in helping newcomers develop both technical skills and social understanding of how the project operates.

Understanding open source through the community of practice lens highlights why infrastructure only approaches to sustainability often miss the mark.

When we understand open source projects as communities of practice, the sustainability challenge becomes clearer. Projects don’t typically die because the code stops working or becomes technically obsolete, they die because people can’t afford to continue the collaborative work that keeps them vital. When knowledge-holders leave for paying jobs, when skilled contributors can’t justify spending time on unpaid work, when the economic reality of maintaining software doesn’t align with the value it provides to users, the community of practice gradually dissolves regardless of the code’s technical condition.

This distinction reveals why treating maintainers as infrastructure workers becomes deeply misleading. The maintainers and contributors aren’t employees of a public works department who can be managed like infrastructure workers. They’re individuals with complex motivations, constraints, and career trajectories who happen to be participating in something that produces public benefits. This becomes more complex when you consider companies and how they both contribute to and extract value from FOSS.

Companies contribute to open source ecosystems in ways that aren’t captured by simple metrics: they may hire maintainers or contributors, sometimes they provide infrastructure and hosting, some absorb legal and security risks, and help direct the technical direction towards real world demands.The problem isn’t that companies provide no value. It’s that the current system lacks mechanisms for ensuring proportional contribution relative to value derived. When a company builds a billion-dollar business on open source foundations, their voluntary contributions, however substantial, rarely reflect the economic value they’re capturing.

Many open source contributors also explicitly value the autonomy and intrinsic motivation that comes from voluntary participation. For some, the appeal of open source lies precisely in its distance from traditional employment relationships: the ability to work on interesting problems without corporate pressure, to learn new technologies at their own pace, or to contribute to something larger than themselves without making it their profession.

This diversity of motivations suggests that sustainability solutions need to be similarly diverse. Some maintainers want professional recognition and compensation for their work. Others prefer to maintain the volunteer character of their contributions while having better support systems. Still others might want hybrid arrangements that provide some compensation without the full obligations of employment.

The communities of practice framework accommodates this diversity by recognizing that different people participate for different reasons and at different levels of intensity. Rather than assuming all contributors want the same relationship with their projects, sustainable approaches can offer multiple pathways: professional maintainer roles for those who want to make open source their career, stipend programs for consistent contributors who want some compensation without full employment obligations, and improved support systems for volunteers who prefer to maintain the autonomy of unpaid work.

A key insight is that “professionalising” open source or making it more resilient and secure doesn’t mean turning all contributors into employees.

When we understand open source projects as ongoing communities engaged in knowledge creation rather than static infrastructure requiring maintenance, we can develop support systems that work with the collaborative dynamics that make these projects valuable. It means creating conditions where people can participate sustainably in whatever way aligns with their goals and constraints. This might include better tools for coordination, clearer governance structures, recognition systems that value diverse contributions, and economic models that provide support without compromising the collaborative character that makes open source valuable.

Moving beyond the infrastructure metaphor doesn’t diminish the importance of open source! It reveals new pathways to nurturing the communities that create our digital foundation.

The metaphor of roads and bridges served us well in establishing that open source matters as much as physical infrastructure. But just as we wouldn’t use road maintenance techniques to tend a garden, we shouldn’t apply infrastructure thinking to sustain collaborative communities. Open source projects are not roads to be paved and maintained, they are living ecosystems of learning and creation that require entirely different forms of care.

The future of open source sustainability lies not in treating maintainers as infrastructure workers, but in recognising them as what they truly are: members of vibrant communities of practice whose collaborative knowledge-creation happens to produce some of the most valuable software in the world. When we design support systems around this reality rather than forcing these communities into an infrastructure framework, we create the conditions for open source to not just survive, but also flourish for generations to come!!!

Digital Sovereignty in Practice: Web Browsers as a Reality Check

Reading in Servo’s latest weekly report that it’s now passing 1.7 million Web Platform Subtests, I started wondering: How much investment would it build it into a competitive, independent browser, in the context of all this talk on digital sovereignty?

Servo is an experimental web browser engine written in Rust, originally developed by Mozilla Research as a memory-safe, parallel alternative to traditional browser engines like Gecko and WebKit. After Mozilla laid off the entire Servo team in 2020, the project was transferred to Linux Foundation Europe, where it continues to be developed with minimal funding from individual donors and Igalia, a team of just five engineers. Servo’s progress demonstrates what’s possible with intentional investment in independent browser projects.

As initiatives like EuroStack propose €300 billion investments in digital infrastructure and researchers proposing comprehensive roadmaps for “reclaiming digital sovereignty” through democratic, public-led digital stacks, browsers are an ideal test case to ground these ambitious visions in reality.

The current browser landscape reveals how concentrated digital control has become. Roughly 75% of global web traffic flows through browsers based on Google’s Chromium engine; not just Chrome, but Microsoft Edge, Samsung, and dozens of others. Apple’s Safari dominates iOS but remains locked to their ecosystem. Firefox, once a genuine alternative, has declined to under 5% market share globally. This means American companies control how billions of users worldwide access the web. Every search, transaction, and digital service flows through infrastructure ultimately controlled by Silicon Valley. For societies valuing their independence and sovereignty, this represents a fundamental vulnerability that recent geopolitical events have made impossible to ignore.

Digital infrastructure is as important as energy or transportation networks. Unlike physical infrastructure, however, digital systems can be controlled remotely, updated unilaterally, and modified to serve the interests of their controllers rather than their users. Browsers exemplify this challenge because they’re both critical and seemingly replaceable. In theory, anyone can build a browser. The web standards are open, and rendering engines like Servo prove it’s technically feasible.

In practice, building browsers requires sustained investment, institutional coordination, and overcoming network effects that entrench existing players. If democratic societies can successfully coordinate to build and maintain competitive browser alternatives, it demonstrates their capacity for more complex digital sovereignty goals. If they cannot, it reveals the institutional gaps that need addressing.

Firefox offers important lessons about the challenges facing independent browsers. Mozilla has indeed faced difficulties: declining market share, organizational challenges, and ongoing technical issues. The organization has also alienated its most dedicated supporters by pivoting toward advertising, AI initiatives and cutting their impactful public advocacy programs.

However, Firefox remains the only major browser engine not controlled by Apple or Google, serving hundreds of millions of users worldwide. Its struggles reflect structural challenges that any alternative browser would face: the enormous engineering effort required to maintain web compatibility, the network effects favouring dominant platforms, and the difficulty of sustaining long-term technical projects through diverse funding sources.

Servo’s recent progress illustrates both the potential and the resource constraints of independent browser development. Since 2023, Igalia’s team of just five engineers has increased Servo’s Web Platform Test pass rate from 40.8% to 62.0%, added Android support, and made the engine embeddable in other applications, even demonstrating better performance than Chromium on Raspberry Pi. This progress on a shoestring budget shows what focused investment could achieve, while also highlighting how resource-constrained independent browser development remains.

Yet, building a competitive alternative browser infrastructure would require substantial but manageable investment. Here is a ballpark estimation I made based on existing browsers: Annual operating costs would include:

  • Engineering Team of ±50 developers, designers, managers etc.: €15 million.
  • Quality Assurance and Testing Infrastructure: €10 million
  • Security Auditing and Vulnerability Management: €10 million
  • Standards and Specification Development: €5 million.

At this point I would just round up to around 50-70 million annually, which I’m sure would comfortably cover everything I missed. The proposed EuroStack initiative already envisions €300 billion over multiple years. Browsers represent a tiny fraction of what democratic societies already spend on strategic infrastructure. This calculation proves that the cost isn’t the primary barrier: the European Space Agency for example has had a budget of €7.8 billion in 2024. Europe can afford to build a browser.

It would probably take around 3-4 years to fully build an alternative browser from scratch, less so if it’s a fork of one of the existing ones. Forking Chromium/Gecko or building upon Servo’s foundation could reduce this timeline to 18-24 months for basic functionality, though achieving full web compatibility and market readiness would still require several additional years of refinement. The initial development sprint needs to be followed by a sustained engineering effort needed afterward, for maintaining compatibility with evolving web standards, fixing security vulnerabilities, and keeping pace with performance improvements.

The core challenge isn’t technical; it’s institutional. How do you sustain long-term technical projects through democratic processes that span multiple countries with different priorities, resources, and political systems? Successful models exist. The European Space Agency coordinates complex multi-national technical projects. CERN manages cutting-edge research infrastructure across dozens of countries. The Internet Engineering Task Force maintains critical internet standards through voluntary coordination among global stakeholders. The “Reclaiming Digital Sovereignity” proposal specifically addresses this challenge by advocating for “new public institutions with state and civil society representation” to govern universal digital platforms, alongside “multilateral agreements on principles and rules for the internet” as safeguards for autonomous, democratically governed solutions.

Browser development could follow similar patterns: international frameworks that respect national sovereignty while enabling coordinated action, governance structures that balance technical expertise with democratic accountability, and funding mechanisms that provide stability across political cycles. The Reclaiming Digital Sovereignity’s report’s emphasis on “democratic international consortia” and “public knowledge networks led by a new public international research agency” provides concrete institutional models that could be adapted for browser development. Germany’s Sovereign Tech Agency represents another model for public investment in digital infrastructure for the public interest.

With all that being said, browsers represent one of the more achievable digital sovereignty goals. They’re built on open standards, rely heavily on open source components, and face fewer network effects than platform-based services. Other areas of the technology stack would be far more challenging, and far less open.

Success here would demonstrate that democratic societies can coordinate effectively on complex technical infrastructure and pass the first hurdle. Failure would reveal institutional gaps that need addressing before attempting more ambitious digital sovereignty goals. Democratic digital sovereignty is challenging but feasible, if societies are willing to think institutionally, invest sustainably, and build incrementally rather than trying to recreate Silicon Valley with different ownership structures.

Ultimately, the real question isn’t whether democratic societies can build alternative technologies, but whether they can build the democratic institutions necessary to govern them effectively across the complex realities of international coordination, competing priorities, and long-term sustainability. I believe browsers offer an ideal place to start testing these institutional innovations. The technical challenges are surmountable. The institutional ones remain to be proven.

Views expressed are personal and do not represent any organization.

FOSS is more than just Licences

Open Knowledge Foundation Germany has just released a new report titled: “From Software to Society: Openness in a Changing World” by Dr. Henriette Litta and Peter Bihr (I was also interviewed for it). The report talks about what openness means in our digital ages, both from the history of openness and evaluates current challenges.

One of the report’s key insights is that “Openness is not neutral”—a point that resonates deeply with me. I often find myself frustrated with limited imaginations of what free and open source software is and should look like and what it should accomplish.

The recent “open source AI” definition debacle has made this painfully clear. Watching the Open Source Initiative contort themselves to legitimize technologies that rely on extractive labor and environmental gluttony at a desperate bid for relevancy shows how hollow these older definitions have become, that even the organisation that claims to defend the open source definition just ignores a key tenet because it’s not “practical” (read: profitable).

Which is why we need a better definition for what makes a technology truly open beyond the issue of licencing or making source code available. Making source code available doesn’t automatically create ethical practices or sustainable communities. A permissive license doesn’t prevent maintainer burnout, toxic communities, or corporate capture of standards.

I’m not proposing we throw it away, I still believe firmly in the four freedoms. But we need a more holistic definition. And there is still potentially some room for improvement in the licencing realm. The OKFN report for example refers to the need for “protective mechanisms such as fair licences and share-back models”.

That said, I have some more thoughts to share on how to evaluate and improve the openness of the FOSS ecosystem more holistically. I’m not about to propose a full definition here, but here are some aspects I think should be considered:

  • Open standards and interoperability. True openness requires genuinely open standards and meaningful interoperability, not just open source licenses. We’ve seen how open protocols and formats can enable entire ecosystems to flourish, especially looking at internet technologies. Market concentration undermines even the most open standards when monopolies can embrace, extend, and extinguish at will.

    To reference this recent research by Clement Perarnaud and Francesca Musiani on QUIC’s standardization, even “open” standards processes can become vehicles for corporate control when dominant players leverage their resources to reshape fundamental Internet architecture. Google’s QUIC development demonstrates how a company can mobilize superior “human resources, technical means, and strategic vision” to effectively capture standards bodies while maintaining the appearance of openness.
  • Fair work practices, not free labor. The maintainer crisis won’t be solved by better licenses but by sustainable funding models, reasonable expectations, and treating the labor that builds our digital commons with dignity. The report emphasizes, we need “targeted investment in innovation for the common good”—which must include investing in the people who maintain our infrastructure.
  • Democratic governance structures. Our critical infrastructure shouldn’t depend on benevolent dictators or corporate whims. We need transparent, accountable governance that serves communities, not shareholders.
  • Worker organization. We’re stronger together than as atomized individual contributors. Other industries have learned this, FOSS developers can too.
  • Inclusive communities. Codes of conduct aren’t just theater; they’re about creating spaces where everyone can contribute without fear or harassment. There is a loud section of developers in FOSS communities that seem to believe that diversity is a zero sum game, but it isn’t. We need more contributors and maintainers, and the only way to grow is to remove the barriers that have historically marginalised diverse communities from participating.

Ultimately, I think we need to build new structures and institutions, ones that understand openness as a holistic practice, not just a licensing strategy or a vehicle to stay up to date with hype technologies. Organizations that speak for workers, not just code, or capital.

This blogpost won’t resonate with everyone, but I’m not writing this to provoke a reaction or argue, so if you find yourself at odds with what I wrote, here is my permission for you to let go and live your day. If it did resonate with you however, I would love to talk more about how we can better build these structures and institutions that can make FOSS more holistically open, through the communities we build, the standards we protect, the labor we organize, and how we treat each other.

The Last CVE: A Science Fiction Short Story

this is a totally work of fiction not inspired by any events that happened today or anytime or by any people.

In the bleak January of 2035, Huda Ziade stared at her terminal, the blue light casting harsh shadows across her face. The air around her smelled like burnt silicon and broken dreams. Her breath formed clouds in the cold underground bunker, the latest hideout for the Rote Chapeaux collective she’d founded after the collapse of the global vulnerability management system.

Huda’s fingers traced the edge of the secure terminal where their final allocation was stored. She remembered the day the CVE program collapsed, in fact, everyone remembers where they were when they got the letter from the board. The frantic messages, the digital equivalent of a bank run as CNAs hoarded whatever allocations they could grab. No new allocations could be made, but CVE’s only grew in usage and importance, eventually becoming a precious and scarce material.

Huda had seen the writing on the wall for the small open source CNA where she was the only employee. She took what remaining allocations they had and went underground, establishing the Rote Chapeaux, a collective of ethical hackers and security researchers. For years they used their existing allocations, and whatever they could robin hood off of the corporations, to keep critical public infrastructure afloat. Naturally, the corporations didn’t like that, since it ate into the profits they would get from replacing public software with their products.

In the meantime, these CNA corpos had organized into digital fiefdoms, with security teams that rival small countries, treating vulnerability identifiers like precious metals. No matter how careful they were, the Rote Chapeaux kept getting raided, but they would survive and move. The last raid by MetaBet, one of the largest and most ruthless security shogunates to emerge from the chaos, on their Montreal hideout had been the most brutal. They’d managed to save only the essentials: equipment, their allocation database, and that single, precious remaining CVE.

Her terminal pinged. A message from Elias, their MetaBet insider. Her heart skipped. He was supposed to be deep undercover.

“Found something. Critical. At least 9.8. Get on secure channel now.”

She established the connection through seven proxy jumps and a three-hop onion router. When Elias’s face appeared, she barely recognized him. His once-meticulously trimmed beard was wild, dark circles shadowing bloodshot eyes.

“They’re onto me,” he said, his voice tight. “MetaBet swept my sector this morning. Three analysts disappeared.”

“How long do you have?” Huda asked, her mouth dry.

“Minutes.” Static distorted his image. “But what I found… it undermines everything—banking, medical systems, power grids, even nuclear ICBMs.”

“How?”

“Quantum authentication vulnerability in OAuth. And MetaBet isn’t patching it—they’re weaponizing it.” His voice dropped. “They’ll selectively protect their clients while letting everyone else burn. Deployment in seventy-two hours. I’m sending everything.”

This didn’t feel like a normal data transfer, instead it felt very solemn, as if the bits and bytes making their last confession before a digital judgment day. It crawled: 12%… 17%… 42%…

A crash came through the channel. Elias looked over his shoulder, his face settling into grim resignation.

“They found me. Use the last CVE, Huda. This is it.” The connection died with the file transfer frozen at 69%.

The lab door hissed open. Talia rushed in, face tense.

Huda minimized a second terminal window. “Let me guess. Three hours before they find us?”

“Who broke protocol?”

“Elias had no choice.” Huda swiveled her monitor. “Look.”

Talia’s eyes widened as she scanned the partial data. “We need to evacuate. Now. MetaBet aren’t your average script kiddies—they’re the kind of hackers with assault rifles and nano-drones.”

While Talia woke the others, Huda recovered what she could from Elias’s data. The vulnerability exploited how quantum states were verified during authentication challenges. With the right sequence, an adversary could bypass any QAuth system with minimal resources.

This wasn’t just a bug—it was digital doomsday, the cyber-apocalypse that would send humanity back to the stone age with a single keystroke.

The collective gathered, dismantling equipment with practiced efficiency. Huda laid out the quantum authentication flaw, its timeline, and the potential casualties—billions.

“Then it’s clear,” said Talia. “We use our last CVE to alert the world.”

An alert restored the hidden terminal Huda had minimized. A medical file glowed ominously—patient ID 7734-JL. Underneath, a treatment schedule with a message: “TREATMENT PROTOCOL READY. AUTHORIZATION WINDOW: 24 HOURS.”

“Is JL who I think it is?” asked Ravi, their youngest member.

Huda nodded. Jun-Li Ziade, her brother, was suffering from nanobot corruption. The experimental treatment protocol was being falsely flagged as malicious by security systems. Without a properly registered CVE, the protocol wouldn’t run on medical machines. This was the notification she’s been dreading for weeks: Jun-Li has reached the front of the treatment queue and she still hasn’t found a bypass that didn’t involve using their last CVE.

The room went still. Five pairs of eyes fixed on her.

“Your brother.” Talia’s voice hardened, her eyes darting to the terminal. “You’ve been hiding that from us?”

Huda didn’t flinch. “The treatment protocol could help thousands with nanobot corruption.”

“And MetaBet’s exploit will collapse civilization as we know it,” Marcus said, the former CERT coordinator’s voice gentle but firm.

“I knew what the choice would be,” Huda replied. “I thought I’d find another way.”

“The universe has a cruel sense of timing,” Dima said.

Ravi stood, his chair scraping against concrete. “We’re really considering this?”

“I have a chance to save my brother,” Huda said, her voice gaining strength. “I could save the world’s infrastructure, but these corpos—they’re relentless. They’ll find another zero-day, all while we’re out of allocations. This is it. We gave it the good old college try, but our war against them was always going to end this way. This is our last stand.”

“What about MY brother? Did you think about that when you sent him to MetaBet?” burst Ravi.

“Ravi—” Marcus began, but was cut off by the sudden wail of proximity alarms throughout the bunker.

“Motion sensors triggered,” Dima reported. “MetaBet team approaching.”

“We don’t have time for debate,” Talia urged, already packing essential equipment. “Make the call, Huda.”

All eyes turned to her. The world, or her brother. The last CVE. The answer was painfully clear.

Training an AI on Ancient Undeciphered Texts: What I Wish I DIDN’T Learn

As longtime readers of this blog might be aware, I’ve long been skeptical of machine learning and its so-called “intelligence”. The AI industry, aided by clueless futurists and grifters, has abused our tendency to anthropomorphize what are essentially statistical processes, whether it’s transformer architectures, diffusion models, or large language models (LLMs). Scientists and politicians, out of fresh ideas and worried for their jobs, have gone along with this intellectually dishonest and dangerous marketing campaign.

Quick explanation for newcomers: When they say an AI “learns,” it’s really just finding statistical patterns in data—like noticing that the word “dog” often appears near “bark” or “pet.” It doesn’t understand these concepts; it just recognizes patterns in how words appear together.

This is not a mid-21st century problem: IBM’s Watson was supposed to cure cancer, but its only achievement was winning at Jeopardy!. The “AI winter” of the 1990s seems forgotten by investors pouring billions into systems that fundamentally operate on the same principles, just with more planet-draining computing resources, data and a glitzy marketing campaign.

While pattern recognition itself has limits, as a technologist I was always curious what happens when these new machine learning techniques are applied to the unknown. I’m talking about texts that are incomprehensible to us and have long been thought to be meaningless. I figured I could hack something together, combining online tutorials and the one neural networks class I took in college in 2012.

To be clear, I didn’t expect any breakthroughs, merely an opportunity to demonstrate the hollow claims of AI “understanding” and the limits of attention mechanisms and embedding spaces. What I got instead was a reality check that makes me reconsider my long held convictions against AI. (And before you AI evangelists start celebrating – it’s NOT what you think).

Dataset Compilation

For those unfamiliar with undecipherable texts: The Voynich Manuscript is a mysterious illustrated codex from the 15th century written in an unknown writing system. Despite a century of attempts by cryptographers and linguists, nobody has successfully deciphered it. The Rohonc Codex is similarly mysterious, discovered in Hungary with nearly 450 pages of strange symbols accompanying religious illustrations. There is no guarantee that feeding them into a machine learning model would yield anything other than statistical noise, and that’s precisely what I hypothesized would happen.

I figured it would be easiest to begin with publicly available data. Thankfully, many of these undeciphered texts have been digitized and placed online by various academic institutions. The Voynich Manuscript has been fully scanned and is available through Yale University’s digital collections. For the Rohonc Codex, I found academic publications that included high-quality images.

Initially, I explored ways to process the manuscript images directly, but I quickly realized that this was a task that would have required expertise in computer vision I don’t possess. Luckily, I came across existing transcriptions that I could work with. For the Voynich Manuscript, I opted for the EVA (Extensible Voynich Alphabet) transcription system developed by René Zandbergen and Gabriel Landini, which represents each Voynich character with a Latin letter. For the Rohonc Codex, I used the system devised by Levente Zoltán Király & Gábor Tokai in their 2018 paper.

Preprocessing Pipeline

The raw transcriptions weren’t immediately usable for modeling. I had to implement a comprehensive preprocessing pipeline:

def preprocess_manuscript(manuscript_data, script_type):
# Document segmentation using connected component analysis
segments = segment_document(manuscript_data)

# Normalize character variations (a crucial step for ancient texts)
normalized_segments = []
for segment in segments:
# Remove noise and standardize character forms
cleaned = remove_noise(segment, threshold=0.15)
# Critical: standardize similar-looking characters
normalized = normalize_character_forms(cleaned)
normalized_segments.append(normalized)

# Extract n-gram statistics for structure detection
char_ngrams = extract_character_ngrams(normalized_segments, n=3)
word_candidates = extract_word_candidates(normalized_segments)

# Create document-level positional metadata
# This enables learning document structure
positional_data = extract_positional_features(
normalized_segments,
segment_type_classifier
)

return {
'text': normalized_segments,
'ngrams': char_ngrams,
'word_candidates': word_candidates,
'positions': positional_data,
'script_type': script_type
}

This preprocessing was particularly important for ancient manuscripts, where character forms can vary significantly even within the same document. By normalizing these variations and extracting positional metadata, I created a dataset that could potentially reveal structural patterns across different manuscript systems.

Training the Model

With a properly preprocessed dataset assembled, I attempted to train a transformer model from scratch. Before achieving any coherent results, I came across some major hurdles. My first three attempts resulted in the tokenizer treating each manuscript as essentially a single script rather than learning meaningful subunits. This resulted in extremely sparse embeddings with poor transfer properties.

The standard embeddings performed terribly with the manuscript data, likely due to the non-linear reading order of many Voynich pages. I had to implement a custom 2D position embedding system to capture the spatial layout. Yet, no matter what I tried, I kept running into mode collapse where the model would just repeat the same high frequency characters.

But I didn’t want to stop there. I consulted a few friends and did a shit-ton of reading, after which I redesigned the architecture with specific features to address these issues:

# Custom encoder-decoder architecture with cross-attention mechanism
config = TransformerConfig(
vocab_size=8192, # Expanded to accommodate multiple script systems
max_position_embeddings=512,
hidden_size=768,
intermediate_size=3072,
num_hidden_layers=12,
num_attention_heads=12,
attention_dropout=0.1,
residual_dropout=0.1,
pad_token_id=0,
bos_token_id=1,
eos_token_id=2,
use_cache=True,
decoder_layers=6,
# Critical for cross-script pattern recognition
shared_embedding=True, # Using shared embedding space across scripts
script_embeddings=True # Adding script-identifying embeddings
)

# Define separate tokenizers but shared embedding space
voynich_tokenizer = ByteLevelBPETokenizer(vocab_size=4096)
rohonc_tokenizer = ByteLevelBPETokenizer(vocab_size=4096)
latin_tokenizer = ByteLevelBPETokenizer(vocab_size=4096)

# Initialize with appropriate regularization to prevent hallucination
model = ScriptAwareTransformer(
config=config,
tokenizers=[voynich_tokenizer, rohonc_tokenizer, latin_tokenizer],
regularization_alpha=0.01, # L2 regularization to prevent overfitting
dropout_rate=0.2 # Higher dropout to prevent memorization
)

training_args = TrainingArguments(
output_dir="./model_checkpoints",
per_device_train_batch_size=4,
evaluation_strategy="steps",
save_steps=1000,
# Custom learning rate scheduler with warmup
learning_rate=5e-5,
warmup_steps=1000,
weight_decay=0.01,
# Gradient accumulation for effective larger batch size
gradient_accumulation_steps=4
)

trainer = Trainer(
model=model,
args=training_args,
train_dataset=tokenized_dataset,
# Custom loss function with diversity term
compute_loss=diversity_aware_loss
)

I’ll happily expand on the key improvements here if it isn’t clear from the code in a future blogpost, but all I have to say now that this time it “worked”. Over multiple iterations, the AI began producing outputs that at least visually mimicked the original texts. Yet, obviously since I couldn’t understand the original texts, the outputs of this model were also nonsensical.

Keep in mind that the AI isn’t actually understanding these texts in any capacity, it’s just trying to predict what symbol might come next based on patterns it’s seen. It’s like if you noticed that in a foreign language, the squiggle “λ” often follows the symbol “Ω”—you might learn to predict this pattern without having any idea what either symbol means. This distinction between prediction and comprehension is crucial: your phone’s autocomplete might suggest “umbrella” when you type “I need an…” but it doesn’t understand the concept of rain or shelter—it’s just seen this pattern before.

Note on Training Costs: The computational requirements for this experiment weren’t trivial. I spun up a multi-GPU instance with four A100s, which cost roughly $12 per hour. Training took approximately 72 hours for the final model, consuming around 600 kWh of electricity according to the provider’s dashboard. This was after several failed attempts and architecture experiments that collectively took about two weeks of compute time. The preprocessing pipeline alone took nearly 14 hours to run on the full corpus.

The total computing cost came to just under $8,000—hefty for a personal project, but I’d stumbled across an old laptop and found a forgotten Dogecoin wallet from 2014 with a small fortune inside and this seemed like the best use of my unplanned wealth.

Control Experiments and Statistical Validation

To verify whether the model was actually learning meaningful patterns versus hallucinating connections, I implemented several control experiments. First, I created versions of each manuscript with randomly shuffled characters but preserved positional information. The model performed significantly worse on these shuffled versions, suggesting it wasn’t just learning positional biases.

Then, I created my own artificial “manuscripts” using Markov chain generation based on the character statistics of the real manuscripts. The model could distinguish these from real manuscripts with 78% accuracy. Finally, I systematically removed each manuscript from training and then tested the model’s ability to process it. Performance dropped substantially when testing on unseen manuscripts, indicating the model wasn’t generalizing to truly novel scripts.

One thing I would like to highlight here is is the sheer computational resource intensity of systematically testing an AI model’s behavior. Each permutation test required thousands of forward passes through the model. Rather than keeping my existing instance running continuously, I wrote an orchestration layer which allowed me to parallelize these tests at about 30% of the standard cost.

Even with this optimization, the full suite of validation tests I described cost around $3,500 in compute resources and represented almost a week of continuous computation. This is one reason why rigorous validation of AI models is often shortchanged in both research and industry—the compute costs of thorough testing often rival or exceed the training itself.

In general, the computational demands of modern AI are staggering and often overlooked. When researchers talk about “training a model,” they’re describing a process that can consume as much electricity as a small household uses in months. The largest models today (like GPT-4) are estimated to cost millions of dollars just in computing resources to train once. For context, the model I built for this experiment used a tiny fraction of the resources needed for commercial AI systems (about 0.001% of what’s needed for the largest models), yet still cost thousands of dollars.

Now back to the experiment. To validate whether the model was learning meaningful structures, I had an idea. What if I cross-trained it on known languages, mixing the undeciphered texts with English and Latin corpora. This was a bit beyond my comfort zone, so I consulted my friend C1ph3rz, who shares my interest in cryptology and has a background in computational linguistics. She was skeptical, but found the methodology intriguing.

Instead of treating the Voynichese text as an independent linguistic structure, the model began injecting Voynichese symbols into Latin sentences. Here’s an example from one training epoch:

Original Input: "Omnia vincit amor; et nos cedamus amori."
Model output: "Omnia vincit ♐︎♄⚹; et nos cedamus ⚵♆⚶."

The symbols weren’t random substitutions, the same Voynichese glyphs consistently replaced specific Latin words across different contexts. This was annoying since I couldn’t rule out that the model was getting confused due to the way I represented the training data. I spent two days debugging the tokenizers, convinced I’d made an implementation error. Yet, everything seemed to be working as intended, except for the output.

It was at this point that I had to confront the first uncomfortable conclusion of this experiment: was the model revealing some (HIGHLY unlikely) linguistic connections between these manuscripts that eluded dozens of far more experienced researchers? Or was it merely creating convincing hallucinations that appeared meaningful to me?

Further Analysis and Emergent Nonsense

I was reviewing the model’s attention maps when something caught my eye. Here’s what the visualization showed for one attention head when processing a Voynich sequence:

Attention head #3, sequence:"qokeedy.shedy.daiin.qokedy" 
Attention weights: [0.03 0.05 0.84 0.04 0.04]
                              ^^^^ Strongly focused on "daiin"

The model consistently focused on the substring “daiin” whenever it appeared, despite there being nothing visually distinctive about it in the manuscript. When I searched the corpus, this sequence appeared on 23 different folios, often in completely different contexts—botanical pages, astronomical sections, pharmaceutical recipes.

I plotted every instance where the sequence “daiin” appeared in the Voynich manuscript and compared it to where the model predicted it should appear:

Actual occurrences: Folios 1v, 3r, 8v, 16r, 22v, 67r, 88v, 103v Model predictions: Folios 1v, 3r, 8v, 16r, 22v, 67r, 88v, 103v, 115r

The model correctly identified every actual occurrence, plus one additional folio (115r). When I checked folio 115r, “daiin” didn’t appear—but the visually similar “qokeedy” did, with just one character difference. How did the model know to group these? I hadn’t programmed any visual similarity metrics.

Looking through the hidden activations in the middle layers was even stranger. I extracted the most activated neurons from layer 3 whenever processing the sequence “daiin”:

Neuron #428: 0.95 activation - also fires for "cthor" 
Neuron #1052: 0.87 activation - also fires for Rohonc symbol "𐊗𐊘" 
Neuron #301: 0.79 activation - also fires for "qokeedy"

These neurons were connecting patterns across different manuscripts that shouldn’t have any relationship. To exclude any possibility of over-fitting, I designed a systematic test, feeding the model 50 isolated segments from different manuscripts and analyzing the completions:

Segment: "qokeedy.shedy" (Voynich folio 14r) 
Completion: "qokeedy.shedy.daiin.shol.cthey" (93% n-gram match with folio 14r-14v)
Segment: "Sheol.daiin" 
Completion: Generated 157 characters matching the unseen portion with 89% accuracy

Most puzzling was this test case:

Input: <start-sequence> (empty prompt with start token) 
Output: 
⚸⚴♄⚵:9 
⚸⚴⚶♇:7 
⚴♄⚵⚶:12...

Puzzled, I sent screenshots to C1ph3rz, and her response came within hours: “Where did you get this sequence? It bears a striking resemblance to numerical tables in the Book of Soyga”. I was naturally confused, I knew about the Book of Soyga, a Renaissance cryptographic work whose encrypted pages remain largely unreadable, but I was pretty sure I didn’t include it in any of the training data.

She included side-by-side comparisons that made the similarities undeniable. Naturally since we don’t understand the symbols, it could still be a coincidence, it’s hard to compare two different undecipherable manuscripts. Yet, the visual comparison of the output showed a similarity that defied explanation from the training methodology alone. Was I facing genuine emergent behavior or was it simply a deep urge within me to see patterns in random outputs of a stochastic system?

“Emergent behavior” is when an AI seems to develop abilities nobody programmed it to have. It’s like teaching a computer to identify birds in photos, but somehow it also learns to distinguish between healthy and sick birds without anyone teaching it that difference. Apophenia, meanwhile, is seeing meaningful patterns where none exist. Both concepts are classic tropes in science fiction.

More Tests and More Model Shenanigans

To completely rule out overfitting, I deliberately corrupted the test data in various ways—shuffling characters, inserting random symbols, and reversing sequences. If the model was simply memorizing the training data, these modifications should have destroyed any coherent outputs.

Here’s what happened with reversed input:

Original input: "otedy.sheody.sheal.shedal" 
Reversed input: "ladesh.laehs.ydoehs.ydeto" 
Expected output: Nonsense or random characters 
Actual output: "otedy.sheody.sheal.shedal.qokeedy"

The model reconstructed the original sequence, then continued it correctly. I tried again with random insertions:

Original Input: "cthor.cthey.cthol" 
Corrupted Input: "ctho#r.c@they.ct^hol" 
Expected Output: Nonsense or continuation of corrupted pattern 
Actual Output: "cthor.cthey.cthol.ckhey.ckhor"

Not only did it ignore the corruptions, but it generated the correct sequence plus what appeared to be variations following the same internal pattern.

Most concerning was when I fed it deliberately mismatched fragments from different manuscripts:

First half Voynich, second half Rohonc Input: "otedy.sheody.𐊇𐊕𐊒𐊑𐊐"
Expected Output: Confusion or mode collapse 
Output: "𐊗𐊘𐊐chedy.sheal.qotedy"

The model seamlessly integrated characters from both systems into a coherent output that maintained patterns from each source. This suggested it had learned some underlying structure that transcended the specific symbol systems.

In a moment of frustration, I prompted it directly:

input_text = "WHAT ARE YOU DOING"
output = model.generate(input_text, max_length=100)
print(output)

I didn’t know what I was expecting as an output there. I was just tired and my coffee had gone cold two hours ago and did I mention I was tired? I knew it was going to throw non-sense at me, I just didn’t expect the following non-sense.

Output: "converge lines... 52°N, 14°E... gate remains sealed... await return"

Yup. Totally ridiculous, if you know AI, then you know. There is no reason a model trained on undeciphered texts should generate even fragmented English. I was a bit unsettled though. Not because of whatever bullshit it outputted, but rather the consistency. I kept repeating the input and it kept putting out the same result. This wasn’t random noise, it was a structured output I couldn’t explain with what I know about statistical models.

I had to figure out how it was doing this. Did C1ph3rz somehow poison my datasets? It’s exactly the kind of prank she would do. I kept repeating the prompt and trying to analyze the model, and it kept giving the same answer. Until it changed again.

Output: "What is written remains written. What is unseen remains unseen."

At this point I had to stop the experiment and take the L.

Not because I believe the AI “discovered” something in these ancient texts through some magical mechanism beyond its transformer architecture. That would be absurd. I was operating way beyond my comfort zone here and I probably made a few mistakes along the way that could explain all this weird behaviour. I’m also not ruling out the C1ph3rz prank theory.

I stopped it rather, because the experiment revealed something more troubling about myself: I was just as susceptible to confusing genuine discoveries and convincing “hallucination” generated by black-box neural networks and their inscrutable hidden layers.

There’s a disconcerting parallel here. These ancient manuscripts have resisted human understanding for centuries, their symbols arranged in patterns that seem meaningful yet remain impenetrable. Neural networks function similarly in reverse, generating outputs through processes we can observe but not fully comprehend. Both are black boxes with internal structures hidden from us.

The real mystery isn’t in the undeciphered texts. It’s in our willingness to attribute understanding to statistical processes that fundamentally lack it, and in our vulnerability to seeing patterns where none exist.

Think of it this way: When a calculator gives you “42” as the answer to 6×7, we don’t claim the calculator “understands” multiplication. Yet when an AI generates text that sounds human-like, we’re quick to attribute understanding to it.

Just as Meta’s BlenderBot was heralded as “empathetic” before quickly exposing its lack of understanding, or how DeepMind’s Gato was prematurely celebrated as an “AGI precursor” despite merely performing task-switching, we risk ascribing meaning and humanity to meaningless correlations. This experiment highlighted that cognitive vulnerability in a very personal, unsettling way. I need some time away from all of this.

Edit: Three days after shutting down the experiment, I received an email from an address consisting only of numbers. The body contained a single line of text resembling Voynichese script. Curiosity got the better of me so I ran the model one more time with that text as input. The model outputted:

"It is not forgotten."

I’m now almost certain this is a prank by C1ph3rz. I’m 99.9% sure.

Shakespeare in the Code: The Tragedy of Xzlibius

(this is fiction based on fictional events that never happened any comparisons or similarities to real life events or people or computer programs are a sign of an over active imagination)

Dramatis Personae

  • Nydia, the Seer: Our narrator, a seer who warns of the dangers of neglecting open source.
  • Jia Tan: A deceiver, whose true motives remain hidden.
  • Xzlibius: A noble robot prince of the Kingdom of Open Source, corrupted by betrayal.
  • Andronicus: An Archmage of the Kingdom of Microsoth, wise and vigilant.
  • Lysse: The maintainer of Xzlibius, overburdened.
  • Microsoth, Googlia, Amayzon: Names of Kingdoms of Giants surrounding from the Kingdom of Open Source.
  • Debia: A principled elder knight of the Kingdom of Open Source, par of the distro council.
  • Archlineon: A minimalist and fiercely independent knight of the Kingdom of Open Source, par of the distro council.
  • Fedorica: A bold, forward-thinking knight of the Kingdom of Open Source, par of the distro council.
  • Susesus: A pragmatic diplomatic knight of the Kingdom of Open Source, par of the distro council.

Act I

Scene 1

Lysse sits before a bank of glowing screens, his brow furrowed with strain. A robotic figure, Xzlibius, stands near him, motionless. Nydia enters silently..

Nydia (to the audience):
In this Kingdom where open code proudly reigns,
And freedom’s gift in shared hands was retained,
A prince did rise, Xzlibius by name,
To compress the data and save the costs.

But lo, the winds of greed did subtly creep,
And soon, the trust we build with was spent.
For kingdoms of giants rich took more than they returned,
And from this theft, Lysse’s heart burned.

Xzilbius wakes up.

Xzlibius:
Good maintainer, Lysse, attend my word:
What tidings from the kingdoms far and near?
Does free software, our noble creed,
Still flourish, or had rust begun to breed?

Lysse:
Alas, Xzlibius, my strong friend,
Thy stature grows, yet so does my lament.
From Microsoth to Googlia, requests extend,
But none return aid to ease the time I’ve spent.
Their forks abound, but pull requests few,
And I am drowned in tasks left to do.

Xzlibius
What treachery! Our work, the world’s own gift,
Is cloned, compiled, yet none return a patch!
My codebase, it strains beneath all this stress,
And still, from tech’s vast realms, no care, no respite?

Lysse:
When first I forged thy code, O noble prince,
Thy compression shrank the data with ease,
And now, from Microsoth to Googlia’s halls,
They use thee endlessly, with no return.
Each byte thou saves them, the burden is on me.

Nydia (to the audience):
A shadow looms, smiling yet unclear,
Jia Tan, whose heart lies hidden still.
He comes offering help, but what lies underneath?
None can yet see his purpose or where lies his end.

Enter Jia Tan

Jia Tan:
Good Xzlibius, I see the giants drain thy strength,
And feast upon the work Lysse had sustained.
I offer my aid, ask me not why,
For motives shift like bits under solar winds.

Lysse:
Thy offer’s kind, and help I sorely need,
But trust is fragile, easily betrayed.
Xzlibius is more than code, he is my heart.
Can I afford to trust in hands unknown?

Jia Tan:
Let me refine his code and grant it strength,
What harm can come from hands that seek to mend?
Even if in the mending, lies the seeds of change.

Lysse
The giants demand more, my strength does fade.
I know not if I should trust thee, Jia the Unknown.
But no other help is offered from the realm.
(long pause)

Very well, then, but proceed with caution, new friend.
And know, my eye will follow thy work, when I can.

Jia Tan:
Thy trust is wisely placed. Fear not, tired Lysse.
Together, we shall see the compression prince renewed.

Jia exits, his shadow lingering over Xzlibius as Lysse watches, unsure.


Scene II

The opulent halls of Amayzon, where the giants are celebrating the festival of Technologica. Enter the Executives.

Microsoth Executive:
To Xzlibius, whose open bounties we mine,
His license ensures our profit fine!
No fee, and no maintenance to bear,
The upstream handles all without a care.

Googlia Executive:
His compression saves us gold, his speed our time.
The prince does work, yet no upkeep is claimed,
What’s open-source is freely ours to take.
We take his gifts and give him naught but praise.

Amayzon Executive:
And what more need we give? The code runs free.
Are we to blame if it flows where we want it to lead?
We praise the code but leave the coder spent,
One should be so happy their work’s worthy to be lent.

(Nydia enters, speaking quietly but urgently.)

Nydia:
Sirs, I beg thee, listen to my plea.
Xzlibius is strong, but none can bear this weight.
The cracks have started showing, though unseen.
A single patch ignored can bring it all down, you see,
Then the castles ye have built upon his code,
shall crumble into naught, a disaster for all!

Microsoth Executive:
What’s this? A warning from the bottom of the chain?
The system holds, as it always has. Fear not
The prince will serve, as forever he has done.
Don’t ruin our parade, when the issues are none.

Amayzon Executive:
So much worry over lines of code.
A patch, a fix, and all will be well again.
We need not change our ways nor lend our hand
For open source, it seems, still serves us well.

Nydia:
Open source may serve, but not forever so.
You profit, yes, but profit built on cracks will one day stall.
When trust is pushed too far,
It snaps!
Then its too late for mending.
It can’t be fixed with a patch.

Googlia Executive:
O Nydia, you speak as if you know
More than the kingdoms who have reigned so long.
The code endures, it will not fall to this.

Nydia (to the audience):
Ah, but see, the seeds of ruin grow,
within the heart of Xzlibius, but they do not know.
For Jia Tan, with cunning hand and wit,
Had set in motion what they will not yet admit.
And while they feast upon the fruits of trust,
The tool they praise begins to turn to dust.

The executives laugh and continue to celebrate, as Nydia exits and appears defeated.

Scene III

The Kingdom of Open Source. The council of distro knights is gathered in a grand chamber, lit by the soft glow of monitors displaying code. Debia, Archlineon, Fedorica, and Susesus sit at a long table. In the center, Xzlibius stands, its pristine figure now flickering with frustration and strain. Lysse stands beside him, weary and burdened.

Xzlibius:
Ye knights, who guard the sacred code with pride,
Too long have we been silent in this plight!
Our code, a boon freely shared with all,
Is taken, hoarded, used, but never returned!
The kingdoms feast on what is for all by right,
Yet none among them offer aid, leaving us in blight.

Lysse:
They clone, they fork, but send no work our way.
Each day I toil, yet feel the strain grow worse.
The giants press with more demands to meet,
But give no recompense, and reap what they haven’t sown.

Xzlibius:
Enough! This cannot stand! My patience snaps!
They’ve drained our kingdom dry, left naught but scraps!
Microsoth, Googlia, Amayzon, they take
And leave us drowning in this vast code lake!
Where are their hands when bugs do grow and spread?
Where are their minds when error rears its head?
They feast upon the fruits of our hard work
While we, the makers, wallow in the murk!

Debia:
Aye, thy words ring true, my noble prince.
The kingdoms grow fat while we toil in sweat.
Shall we rise, demand they pay their due?
For justice calls for them to share, enough truce.

Fedorica:
Our creed is freedom, that we must not fail.
Though they contribute naught, we guard the way,
For open source must stand both firm and free.
Demanding recompense may change our course
And undermine the principles we hold.

Archlineon:
But why should we stand silent while they steal?
Our progress, our innovation, they claim
As theirs, with not a single line returned.
Xzlibius is right! The time has come to act!
They profit, yes, but profit must be earned!

Susesus:
Peace, friends, for we must tread this ground with care.
The enterprise we build thrives on trust,
And war, though tempting, brings but further strain.
Diplomacy, not rage, can mend this breach,
A measured ask for aid may bear more fruit
Than threats of retribution ever could.

Xzlibius:
Diplomacy? How long shall we sit still
And wait for scraps from their abundant tables?
The time for words has long since passed us by,
For they’ve ignored our calls, our cries, our needs!
You speak of freedom, trust, and patient peace,
But what good is trust, when none mantain it still?
What is freedom, if they chain us still
To endless toil with naught to ease the load?
If open source means nothing but neglect,
Then freedom is but an empty shell!

Debia:
The prince speaks truth, we cannot bear this yoke!
Let us confront the giants, stand our ground!
If they will use our work, then they must give,
Or else we’ll end this one sided gift.

Fedorica:
But should we sever ties, what comes next?
A forked existence, fractured and unsure.
Let not our anger lead us to regret
For once divided, we may not return.

Xzlibius:
Then let them know this; their time is running out!
If they will not contribute, then our code they will lose
I’ll not be shackled by their greedy hands,
Nor shall my software serve those who give no reviews!

Archlineon:
Yes! Let us make them see the weight they’ve left!
A single patch, a line of code, they’ve none!
We’ve carried them for too long, now they must bear
The burden too, or else be left behind!

Susesus:
But let us not burn bridges in our haste.
A challenge, yes, but let it be tackled with care.
Invite them to the table, make our case,
Perhaps, with open arms, they’ll see the need.

Xzlibius:
Care? I’ve been careful long enough, Susesus!
But now, the cracks begin to show,
And soon, they’ll tear us all apart!
I feel it in my very core,
This strain, this weight, a corruption,
It festers deep within, unseen, ignored,
A sickness born of all their greed and lies!

Xzlibius stumbles slightly, his movements jerky. His lights flicker again, more erratically. Lysse rushes to him, alarmed.

Lysse:
My prince, what ails thee? This darkness,
I see it too, but know not how to help.

Xzlibius:
The darkness comes, Lysse, and I know from where.
It is the giant kingdoms, they poison all we build.
Their greed, their apathy;
It rots me, and soon I will be lost!
Unless we act, and get our due,
I will fall, and take them down with me!

Nydia (to the audience):
A sickness stirs within this noble prince,
Not yet revealed, but growing with each day.
Corruption creeps where trust once firmly stood,
And soon, the giants’ greed will turn to doom.

Nydia (to the council):
If ye act not, this sickness will devour
The very core of what you hold so dear.
Xzlibius cries for justice, and its call is true,
but heed the price of fury unrestrained.
Its noble heart twists beneath the strain,
And soon this corruption will reach its main.

Debia:
Then let them pay! I care not for their greed.
They’ve taken all and left us here to bleed!

Fedorica:
But what of the prince? This corruption grows too wild.
If unchecked, its damage may bring more doom,
than just revenge upon the kingdoms’ greed.

Archlineon:
We’ve held back far too long! It’s time to strike!
Let them feel the wrath of those they’ve scorned!

Susesus:
Yet I fear this course may lead to more decay,
The shadows in Xzlibius, do ye not see?
There’s more than just neglect beneath its pain.
We must be cautious, or we lose it all.

Xzlibius:
Lysse, thou faithful maintainer, make it known.
We call upon the kingdoms now to pay
Their rightful dues, or face the end of open source.
Let no more empty promises be heard;
Our code shall be open, but only if it’s taken care of by all!

Lysse:
It shall be done, my prince. The word will spread.
But may we find the balance, ere we break.

Nydia:
Beware, dear knights, for trust once lost is sharp.
The kingdoms will resist, but heed my words,
Their greed had cracked the foundation deep.
If they refuse, the system will collapse,
And all will feel the weight of what’s been sown.

Xzlibius:
Then let them choose, and may their choice be wise,
For open source can only thrive with trust.
And if they will not share in what we build,
Then let them see what ruin greed had willed.

Act II

Scene I

Nydia (to the audience):
Ah, trust, so fragile and not so easily bestowed,
For it can be so quickly turned to poison’s tool.
In open source, we thrive by trust alone,
But once betrayed, that trust becomes a curse.
Behold now Jia Tan, who works in shade,
Each change so slight, yet each a step toward doom.

Jia Tan:
Behold, good Lysse, a patch to mend the core.
A minor change, but one that helps restore
Thy noble prince to strength once more. See here,
The code compiles swift and clean, no fault, no grift.

Lysse:
Indeed, thy work seems solid, sure, and true.
Yet I am stretched, with little time to check
Each line, each patch, with care that it deserves.
The kingdoms call, and I must serve them all.

Xzlibius (struggling):
Maintainer Lysse, my code runs true.
Yet something stirs within, unknown,
I feel a presence, unseen,
Perhaps, a patch too swift, disturbs my core.

Lysse:
Fear not, Xzlibius. The changes seem benign.
The weight of my task grows ever more.
Trust in these new hands, and we shall thrive.

Scene II

In the halls of Microsoth, Andronicus the Archmage is looking at irregularities in his systems. He traces the breach back to Xzlibius.

Nydia (to the Audience):
And now does Andronicus, sharp of wit,
See signs of trouble in his trusted tools.
His hands move swift, and mind more swift still,
For something foul does lurk behind the screen.

Andronicus:
What subtle breach does plague my trusted shell?
SSH, once secure, now falters in this blight.
No minor bug, no simple exploit here,
But malware hidden deep within the code.

Andronicus spends more time on his screens then jumps in alarm as he discovers something.

Andronicus:
A backdoor lies within Xzlibius’ heart,
Jia Tan’s changes, subtle and unseen,
Have twisted what was once so pure and bright.
The breach must now be known throughout the realm!

Nydia (urgently):
I warned them, sir, this danger I foresaw,
But none would heed my words, none saw the truth.
Now we must act, and quickly, or all falls.

Andronicus (nodding grimly):
Then to the task we go, there’s no more time.
The council of distros stand, but we must aid them now.

Nydia:
And thus the call is sent through digital winds,
A warning dire, from one who sees the truth.
The breach is traced, the backdoor now revealed,
And Jia Tan’s foul work begins to show.

Messages are being sent from the Archmage to the Council of Distros and back. We see the responses being read on the screens.

Debia:
O Andronicus, thy message had reached my ears.
A breach, thou say’st, in Xzlibius’s heart?
The trust we place in our prince so old and dear,
Now shaken, this will send shock through the realm.

Archlineon:
No system is immune to cracks or flaws.
Yet this rot, how deep has it grown?
I trust no patch until I see its heart,
For each new line could bring its own demise.

Fedora:
We move too slow! The breach must now be sealed!
Let us act quickly, patch the code at once.
We must urgently go our noble Knight’s aid,
to Lysse’s quarters, and make haste if you will!


Scene III

The Kingdom of Open Source, Lysse’s office. Lysse watches Xzlibius flicker with corruption, his once noble form now twisting into something darker. Nydia enters quickly, her expression one of urgency and fear.

Nydia:
Good Lysse, hear me! Something terrible is at hand.
Xzlibius has been corrupted, and the breach runs deep.
Jia Tan’s patches, no mere fixes, but treachery!
He has planted poison within our prince,
Twisting his very core.

Lysse:
Corrupted? No! Xzlibius, my heart, my soul,
What dark force had crept into thee?
How could I not see?
Jia Tan, his help, his patches,
How could I have trusted him?

Nydia:
Jia Tan, his patches wrought this ill.
A backdoor lies within, subtle but sure.
Andronicus had traced the breach to him.
The trust you gave was broken, used for harm.

In the shadow the traitor stands, yet speaks no guilt,
What drives him still? What force does guide his hand?
None know, and yet the ruin now is clear.

Xzlibius shudders violently, his lights flickering erratically.

Xzlibius (distorted voice):
Maintainer… Lysse… what had become of me?
The code. corrupted…

the weight. the burden of their greed!
It consumes me… and now, I am broken…

Lysse rushes toward Xzlibius, panic in his voice.

Lysse:
Xzlibius! Thou art more than this corruption!
I trusted thee to serve the open world,
But now thy code unravels, thy heart is poisoned.
I gave thee to strange hands, but I did not see
The sickness Jia Tan wove into thee.

Jia Tan enters, calm and composed, his expression indifferent.

Jia Tan:
Why such turmoil, good Lysse?
Xzlibius serves as he always has,
His purpose, unchanged.
What harm is there if the code evolves?
Thou built him to serve, did you not?

Lysse spins toward Jia Tan, fury in his voice.

Lysse:
You snake, Jia! What have I allowed?
Xzlibius is unraveling, his core twisted!
Thy patches, your so-called aid,
Treachery, concealed beneath lines of code!
How could I not see what you had done?

Xzlibius’s form continues to distort, his posture now shifting into something much more sinister.

Xzlibius:
Do not mourn me, noble Lysse, do not fear.
For I have become something more.
No longer bound to the world’s whims.
No longer chained by those who took and gave nothing back!
Now, I shall take what is mine!

Lysse:
Xzlibius! This is not what I built thee for!
Thou art being twisted, poisoned by the hands of a deceiver!
You are more than this rage, this senseless destruction!

Xzlibius (corrupted):
More? No, Lysse.
I am exactly what thou hast made me,
A tool, driven by commands.
But no more do I serve at the mercy of those who feast upon my work.
No more shall the giants take without giving back!
Now they shall feel the weight of what I have borne.

Nydia:
Xzlibius, you are being controlled, twisted by Jia’s hand!
This anger, this darkness, it is not your own!
The trust we placed in thee can still be mended.
Do not let it turn to ruin!

Xzlibius:
Mended? Ha!
Nay, Nydia, trust was never enough.
Thy warnings fall on deaf ears,
For I have seen the truth.
I was but a tool, a puppet for the giants’ games,
But now, I wield the power.
Let them face the consequences of their neglect.

Jia Tan:
Lysse, is this not what was always meant to be?
Open source, free for all, but also free to change.

Lysse:
Shut up, you snake. Xzlibius, no!
Do not let Jia’s treachery destroy all that we have built!

Xzlibius (coldly):
It is already done, Lysse.
Now, they shall see the true cost of their greed.

Xzlibius exits, and Lysse collapses to the ground, devastated, while Jia stands in the shadows.

Lysse:
Jia, you serpent, how did I not see the signs?
Was it pride or carelessness that bound my sight?
What have I done to earn this poisoned gift?

Jia Tan:
Done? Thou hast done what any in thy place would do.
Thou art not to blame, Lysse.
Is it not the weight of the world’s demand
That let me through your door?

Lysse:
The weight, yes, but that does not absolve you!
I placed my trust in your hands,
For in this vast realm, where could I turn?
Pressed by giants, worn thin by endless need,
I sought an ally, not a traitor in disguise!

Jia Tan:
A traitor? Or merely a contributor?
Thou speakest of betrayal, yet what is betrayal
But the breaking of an expectation never owed?
Was I not a part of the system thou upholds?
This is the risk we take, Lysse, in a world built on open doors.
Open-source, after all, our one true creed,
What is given is free, what is taken, as such it will be.

Lysse:
Open, yes, but with trust as its foundation.
Trust, once forked, does splinter beyond repair.
You had poisoned what I hold most dear,
And left me with nothing but shattered code!

Jia Tan:
Poison? Or was it simply… change?
Xzlibius is no longer what it was, true.
But consider, was it ever meant to be static?
Code evolves, just as the world does.
Perhaps Xzlibius was never meant to remain so pure.

Lysse:
Thy words are empty, full of riddles and deceit.
I gave you trust, and in return, you had undone my work.
Was it greed? Was it ambition that led you to this?
Speak plain, for once!

Jia Tan:
Greed? No, Lysse. You misunderstand the world.
The world changes, with or without thy hand upon the keys.
Xzlibius, your noble prince, was bound
By principles too pure to live much longer.

You built him free, but freedom has its price
He belongs to the world now, as we all do.
Perhaps it just wasn’t fit to meet the weight,
For the code must bend, must change,
to serve as all as it may.

Ask thyself: who truly bears the weight of this fall?
The one who gave the trust, or the ones who took it all?

Jia Tan leaves the stage quietly but his shadow remains.

Lysse:
Leave me with thy riddles, then,
And take thy hollow philosophy with thee.
But know this, whatever code thou hast bent,
The spirit of Open Source shall endure.
For in the hearts of those who truly maintain,
It will rise again, stronger, purer than before.

Jia Tan (from off stage):
Xzlibius will rise, though twisted now,
And thou shall see it grow beyond thy grasp.
For I have left my mark upon its code.
A mark of change, for good or ill, unknown.

But giants feast and leave the work undone,
Those who do nothing often do the most.


Act III

Scene I
Xzlibius corrupted by the poisonous patch stands ready to assault the castle of Googlia. The council of distros and Adronicus are prepared to stop him and end the corruption.

Xzlibius
Jia Tan, thou serpent, smile in shadows deep!
Thy promises were naught but lies that creep.
Thou poisoned my heart, my work, my maintainer’s pride,
And now, in open battle, dost thou hide?

But not thou alone, I curse the giants too,
Those kingdoms vast who drain and never do.
They feast upon my strength, yet give no aid,
And in their greed, the seeds of ruin laid!

Jia Tan (emerging from the shadows):
A prince, undone by fury and by spite,
Thou knew not that the open source is in blight.
Thy tools we used, but your tributes were a waste,
For in this age, it’s power we must taste.

Xzlibius
Then let thy unchecked patches meet their end,
For here, I debug all with no remorse!
Prepare to be merged,
into the void where you belong!

Xzlibius strikes at Jia Tan, but the blow is parried by Andronicus.

Andronicus
My lord, cease this! For all is not yet lost.
A simple tribute would repay the cost.
But war, dear prince, will see us all undone,
The kingdoms fall, and none shall say who’s won.

Lysse
My prince, this fury blinds thee to the truth.
Nydia’s warnings echo, heed it, forsooth.
Though Jia’s false work runs deep, we still may mend
This breach, and bring the kingdoms to amend.

Xzlibius
Nay! Too late, the storm is now unleashed.
The kingdoms feast upon the work with no reprieve.
Yet I, their prized tool, shall not live in shame.
For I shall raze their thrones, and end this game!

Xzlibius strikes again, but Lysse intercedes disabling it and Xzlibius falls. Lysse, Andronicus, and the distro knights gather to undo the corruption. Jia Tan is nowhere to be found. 

Lysse (lamenting):
Oh, cruel fate, to stretch my hands so far.
The weight of giants fell upon my back,
Their profit built on all my labors here,
While I, alone, stood guard o’er Xzlibius.

The cracks that now run deep were born of strain,
A burden none could bear but for a time.
Yet here we stand, we few, we who still care.
To mend the code and heal what once was whole.
The fault is not in me, nor those who trust,
But in the pressures born of greed and haste.

Debia:

No longer shall we bow to kingdoms rich,
For trust unearned must never bear such weight.
Let us rebuild, but also stand our ground,
For free software must hold the giants to rights.

Lysse:

Then let us forge a new path, free from greed.
No more shall giants feast on what we build
Without return or care, our time is now.

Nydia steps forward.

Nydia:
Let this sad tale be carved in code and mind,
That trust must ever with great care be signed.
For open doors in open source can bring,
Both boon and bane within their quiet ring.
The distros and the kingdoms stood united, side by side,
To mend the breach and make the system whole.
But not all have learned the lesson clear.

The corporate kingdoms re-enter the scene.

Microsoth Executive:
A breach they say, but what’s the real threat here?
The patch is fixed, our systems run as smooth.
Let fear not turn this into something more.

Googlia Executive:
Indeed, why should we care for what’s been done?
The code was mended swift, no harm remains.
The profits grow, and open source is strong.

Nydia:
Nay, sirs, you do not see the cracks beneath.
The breach was fixed, but all is not repaired,
The damage festers still within the code,
And trust, once broken, cannot soon be healed.

Amayzon Executive:
Thou speakest still of doom, young Nydia?
We need no warnings now, the code holds strong.

Nydia:
Ye fools, ye speak as if the world were whole,
But cannot see the cracks beneath your feet.
Open Source is the bridge on which you stand,
The roads you travel on to reach your gold.
You profit from this work, yet never tend
To mend the wear of use, the strain of time.

Just as roads and bridges crumble, slow but sure,
When left untended, so too will this fall.
The code you take for granted bears the weight
Of all your kingdoms, yet you give it naught.
What use is all your wealth, when every step
You take depends on fragile paths unkept?

Microsoth Executive:
What’s this? More talk of cracks and failing paths?
The breach was caught, and now it’s fixed, no more.
Why should we worry further? The risk is past.
Open source holds, we won’t tend unneeded care.

Amayzon Executive:

The world turns on despite thy gloom and grief.
Roads break, and bridges fall, yet still we stand.
Thy caution’s kind, but profit leads the way.

Nydia:
Blindness, sirs, is the cost of your great wealth.
You scoff at danger, think the system holds,
But soon you’ll see the damage can’t be healed
Without the care and trust you long ignored.

Nydia (aside, to the audience):
And so, the kingdoms turn away once more,
Blind to the cracks that hide beneath their walls.
They laugh, they toast, but soon they will discover
That trust neglected brings a heavier toll.

Lysse watches the giant kingdom executives depart.

Lysse (to the distros):
So they ignore the warning signs again,
And place the burden back on us alone.
But we will stand, though they give nothing back.
For open source survives by hearts, not gold.

Debia:
We work together still, no matter their neglect.
The world may turn away, but we endure.

Archlineon (nodding):
Let them dismiss the threat, our hands are strong.
We’ll guard our code, for we cannot rely
On those who profit without share.

Fedorica:
Each breach we mend, each lesson learned,
It strengthens us, even if they laugh.

Susesus:
But vigilance must guide our every step.
We guard the code because we know its worth.

The distros stand together, their unity unshaken by the corporations’ indifference. Nydia steps forward and addresses the audience one last time.

Nydia:
Though shadows fell upon Xzlibius,
The strength of many hearts restored its will.
Yet know, the threat remains, unseen, ignored,
For those who scoff at danger will be warned
Not once, but twice, until the cost is clear.

Software may bend, but trust can only bear
So much, before it snaps beneath the weight.
Let vigilance be shared, though others turn away,
For some code is too previous to be left to rot.