Knowledge Security
The growing threats to trust, resilience, and accountability
Speech to Knowledge Futures Symposium, 26th June 2026
On 26 June I spoke at the Knowledge Futures Symposium, a day-long event hosted by the University of Leeds. It brought together librarians, archivists, and university leaders from around the world to examine how knowledge is created, valued, protected, and shared at a time when the tools that control it seem to be concentrated in a decreasing number of commercial hands. The day was organised around three themes: Knowledge Equity, Knowledge Security, and Digital and AI Ethics.
I was asked to speak to the second of these, Knowledge Security, specifically on the growing threats to trust, resilience, and accountability. Below is my talk as delivered. It argues that the most serious threats are not the one we tend to think of as coming from the outside, but instead arise from a quieter shift within our own institutions – in the language we have learned to adopt and the digital tools we have installed on our websites that harvest data from our visitors, without their consent or knowledge and, more often than not, without ours either.
Good morning.
The topic I have been invited here to talk about is knowledge security. And I want to start out by admitting that I am not sure it means quite the same thing to all of us.
For some, it is about keeping important information in the right hands, and out of the wrong ones. For others, it is about misinformation, the lies that travel faster than the truth, and the rise of synthetic knowledge. For others again, it is something more solid: whether our libraries and archives, the institutions themselves, are safe to reach and to use. And for others still, it is the quieter fear that the permanent record might one day simply vanish, through deliberate erasure or through ordinary neglect. For the purpose of my talk today, I'd like to offer a meaning that holds all of these concerns together. Knowledge is secure when we can be sure it is exactly what it says it is; when it is kept somewhere we can reach without risk to ourselves or to others; and when we know it will still be there whenever someone needs to find it again.
So what threatens this security? Not, I would argue, an AI barbarian at the gates. The hidden culprit is the way we ourselves have adapted to the digital world, taking one seemingly harmless step after another. We didn't notice this shift because it arrived packaged as inevitable progress, and disguised under a cloak of changed vocabulary.
But, at the end, I am going to propose that the shift is entirely fixable, more affordably and more quickly than you might think.
Though, as the old joke goes, it only takes one psychiatrist to change a lightbulb. But the lightbulb has to really want to change.
I should also say quickly who I am representing here today. I work on something called dotPublic. Our aim is simple, if not exactly modest: to make the internet better for everyone, or at least for everyone who isn’t already a Trillionaire. I'll come back to what that means in practice at the end. For now, hold that thought, because to know what we are trying to fix, you first have to see what has been broken.
Let me step back a few years to a silent warehouse in the American Midwest.
I was standing in Google’s immense book digitisation centre in Michigan. An industrial-scale processing plant, filled with steel containers, stacked with pallets and pallets of books and more books, eleven million borrowed from the world’s libraries. Row after row of silent machines, in silent rooms, operated by silent staff. If you have ever watched the television programme ‘Severance’, it looked a bit like that.
As I stood there, taking in the sheer ambition of it, I understood for the first time what Google had pulled off. They had persuaded the world’s great knowledge institutions, the libraries, the archives, the universities, that had safeguarded the human record for centuries, to hand it all over. For free. All of it. So that one private company could use it to build the most powerful brain ever assembled, and then turn that brain against the very institutions that had supplied it. Genius.
The genius of it was not the engineering. It was that we had agreed to it. We were not robbed. We volunteered. We even carried the books to the door ourselves, because by then we had already been conditioned to see the responsibility for looking after the collected accomplishment of humanity as an unaffordable digitisation problem with an infinite storage cost attached.
Before I go much further I want to mention one other thing during my trip that I really noticed that was not part of the Google visit but it really troubled me.
As I checked into my hotel, the clerk looked up and called out, “Next traveller, please.”
As he said that, I realised that I had only recently stepped off a train on which I had been called a “customer”, which was soon after buying a sandwich in a bakery that referred to me as a “guest”. And it occurred to me that, somehow, all the words were wrong or all the nameplates had been switched. It really disturbed me, more perhaps than it might have on another day.
Our choice of words matter because the language we use determines how we think. Change the words and, given enough time, you change what people notice, what they value, and what they believe their responsibilities to be.
Over the last twenty-five years a similar change has happened across our institutions. We stopped talking about readers and started talking about users. We stopped talking about custodianship and started talking about service delivery. And perhaps most significantly of all, we stopped talking about knowledge – the arts, the sciences, the humanities, and anything else that can be expressed as thoughts and ideas – and started using the ‘C’ word. ‘Content’.
I believe that this was not a harmless change in vocabulary. Consider the word for a moment. ‘Content’ is a bland, meaningless term for whatever fills the digital containers. It elevates the container to be the thing that really matters, and the stuff inside it – the ‘content’ – is entirely incidental.
A scholarly article, a promise of ‘peace in the Middle East’ and a cat video may be very different things, but referring to them as ‘content’ flattens them all into having much the same value. They become interchangeable units of attention, whose value lies not in what they are, but in their ability to fill screen space, attract eyeballs, and keep a person engaged. That is not how librarians think. It is not how artists think. But it is how platforms think.
The genius – if that’s the word – of the Google Books project was that it had taken more than five hundred years of human accomplishment, and reduced it all to ‘content’, and then to be used as training data, without anybody giving it a second thought.
Once knowledge becomes content, a different set of values takes hold. The important questions are no longer whether something is true, authoritative, or worth preserving.
The focus becomes whether it attracts the right demographic, increases click-through rates, or generates growth. We may tell ourselves we are merely adopting modern terminology, but in reality we are absorbing an entirely different way of seeing the world.
I don’t think this happened because of some grand conspiracy. It happened because the digital worldview came bundled with the technologies; the need for new funding models, making deals, and winner-take-all notions of success that define the age. We absorbed the language and, over time, absorbed the assumptions that came with it. After a while those assumptions stopped feeling reductive and started feeling normal.
People entering the workforce today have never known anything different. They inherit a world in which engagement is valued more than trust, where topicality is valued more than permanence, and where success is often defined by being amusing rather than being responsible. In our private and our professional lives, we have traded caring for coping. We are all becoming adept at simply surviving inside systems designed for commercial interests that are fundamentally at odds with the public interest.
All of this would be bad enough if it stopped at the door of the institution. The institution is, after all, old enough to know better. But the same change of perspective that undermines the relationship between knowledge and the institutions it came from, also threatens to undermine the relationship between the institutions and the public. Let me show you what that looks like from the point of view of a typical library visitor. I will call her Maria.
Maria is not one person. She is a composite drawn from many case studies. But everything that happens to her is real, and it is happening every day.
It is a Tuesday evening, around nine o’clock. Maria has put her younger child to bed. Her older son has recently been diagnosed with a chronic medical condition, and the consultant has suggested that her public library might have useful information to help her understand it better.
So she opens her laptop, visits the library’s website, types the name of the condition into the search box, spends twenty-five minutes reading, bookmarks a couple of pages, and closes the computer. It is an entirely ordinary act. A mother seeking help. A private interaction between a person and an institution she trusts.
Except that is not all that happened. Just like pretty much every website today, the library had installed a number of off-the-shelf digital tools, analytics, fonts, sharing links, etc., because it believed that these would be helpful, harmless, and free. But from the moment Maria typed her son’s condition into the search box, those tools quietly went to work.
Within days messages begin to arrive, relating to medical services, insurance, treatments, and ‘related’ products. Maria doesn’t understand how this happened. She assumes her phone must have been listening to her, although she cannot say for sure.
But it wasn’t her phone. It was her library. The one institution she trusted to be on her side was the very institution that quietly gave her away. And it did so without a passing thought, because somewhere along the way it stopped seeing a worried mother and started seeing a User. And a user is not a person to be protected. It is a datapoint to be tracked.
Without a doubt the greatest threats to our knowledge institutions will come from the outside. Misinformation, disinformation, artificial intelligence, platform monopolies. All of those are real. But at the same time, some of the most profound damage has come from within, not because anyone stopped wanting to help Maria, but because we gradually began to talk, and then to think, in a different register.
It starts with the vocabulary. A reader first becomes a customer, then a user. Expert knowledge, reliable information and trustworthy advice, all becomes ‘content’. And once the words have changed, the measures of success change. From whether we served someone well to whether we optimised their engagement, captured their attention. And once those are the measures, we inevitably reach for the easiest tools that satisfy them.
That’s how a mother in need ends up being betrayed by a library that only ever wanted to understand her requirements a little better. Maria was not failed by bad people. She was failed by a change of mindset.
And so I’d argue that knowledge security is compromised in two distinct places.
First, the connective tissue that ran from the world’s knowledge to the institutions that created, preserved, and vouched for it has been severed, by Google and many others, and turned into training data, then fed into a big black box that undermines the integrity of both the expert, and the institutions.
Meanwhile, our own services have quietly been compromised, by the free, off-the-shelf tools we were persuaded to install, and by the new language we adopted to describe what we are trying to do.
As a result, the public can no longer trust that their personal information will be kept private, or that anything they see or read is genuine.
So two fundamental relationships are broken.
The one between the institutions and the knowledge they were created to preserve.
And the one between the institutions and the people they were created to serve.
And, it should go without saying but, above all else, the public is the one thing we must never lose sight of. Because everything we do; the creation and gathering of knowledge; keeping it safe; protecting its integrity; ensuring there is a safe place to find it and use it; preserving it for the future; none of this is for the institution.
It is all, every bit of it, for Maria and her children. The only reason any of this is worth doing is that people like her need us, and they need to know that they can trust us. The institution is not the point. She is.
So the question dotPublic is asking is whether her trust, once lost, can be recovered. We believe it can, but not by asking for it back. Trust is not a tone of voice. It is the result of an unwavering commitment to the public, and it can be rebuilt in three steps.
The first step is to re-establish the unambiguous difference between a trustworthy organisation and an untrustworthy one. For centuries, the public could tell an expert from an impostor because the expert was bound by a code of conduct that the impostor was not. A librarian, a curator, a clinician, a scholar, each derives their right to be trusted from a higher authority, and in return is held by that authority to a set of obligations.
To be accountable. To provide evidence. To declare an interest. To act in service of the person in front of them and nothing else. The institution is the thing that guarantees the word of the expert, and the public learned, over generations, that the guarantee had meaning.
What dotPublic does, at its simplest, is reinstate the values of that guarantee, through a set of plain, inspectable standards. Nine obligations, drawn not from our opinion but from the law and from the customs and practices that public-serving organisations have lived by for centuries.
Their purpose is not virtue signalling. Their purpose is that a trustworthy entity can always meet them and an untrustworthy one, by its nature, simply cannot and will not.
The second step is to embrace the need for clear and unambiguous provenance. It is not enough for the institution to say it is reliable. Its reliability has to be legible, to a reader and now to a machine, because increasingly the first thing to interact with your work is not a person, but a system that cannot use instinct to determine fact from fiction.
So the work has to carry its origin with it. Who made this, on whose authority, whether and when it was changed, and whether it can be found again tomorrow, attached to the material itself, travelling with it into every use, every recombination, every answer a machine assembles from it.
This all used to sound impossible or, at the very least, expensive. It is not any more. Working on a small pilot recently with the ADAPT Centre at Trinity College Dublin, we took twelve years of research outputs and rebuilt them as structured, identified records, each one carrying its institutional origin as part of itself, so that wherever the work goes, its provenance goes with it.
What surprised us was that the process didn’t just restore the information that was already there. It also added more contextual data than was there in the first place, bi-directional relationships, the conferred authority, the full context of how the work was created, attached in a form that binds it to the institution’s verified signature. It is genuinely transformative, and that signature is something that no fabricated piece of information could ever attach. It was quick, painless, and it cost very little.
The third step is to secure future permanence. An asset that can be trusted is little use if it does not survive. Most organisations have no plan for what happens to their digital record when the funding ends, the platform closes, or the supplier moves on, and so it gradually rots, the way the web is rotting around us all the time.
Working with the Concordance Project and Webrecorder, we are building something similar to a pension plan for the public record. An institution sets aside a modest, affordable commitment now, while it is healthy, and its material is captured and preserved across decentralised repositories, so that no single failure can erase it.
Not preservation as heroic rescue at the moment of loss, but preservation as an ordinary condition of being a responsible institution.
Making the difference visible, making the provenance legible, making the record permanent. Together they make knowledge security achievable and now affordable.
And for dotPublic there is one more piece that holds all three steps in place. Our institutions are currently doing their best inside an environment that is actively working against them. They co-exist alongside the faked and the unaccountable, adhering to platform defaults that leak their visitors’ information and dissolve their authority.
That is why dotPublic is applying for a new top-level domain, a bounded part of the internet where these obligations are a deliberate statement of being there. To move into that space is to step off the Wild West Web and stand firmly on civic ground.
It safeguards the institution, because its authority is verifiable and it protects the citizen, because inside that boundary they are treated as a valued member of society once again, no longer a source of data to be exploited.
By the way, none of this is a matter of starting from scratch. The institutions already hold the values. The tools now exist, and they are cheap. What has been missing is somewhere to move to and a reason to go there. That is what we’re working on today, and we would be very glad of your company.
What is at stake is not only the privacy of the people who come looking for help. It is whether anything they find when they get there can still be trusted to be true, and still be there tomorrow. That is what knowledge security means to me at least.
And so, to end, I want to leave you with something much smaller than a grand vision for tomorrow – a modest request for today. When you are back at your desk next week, you might ask just one question about your own website: “who else receives the data about someone who visits it, and did anyone ever intentionally decide to let that happen, on purpose?”
Most institutions have never asked themselves that question, and the answer is often uncomfortable. But it is fixable, and in weeks, not years.
That is the essence of dotPublic. Not a major rebuilding programme. A series of small, deliberate decisions to stop thinking in ways that we never meant to think, doing things we never meant to do, and to re-establish why what we say, and what we do, can be trusted.
Thank you.
Media enquiries: info@dotpublic.org