👋 Hello again!
This is your latest #TechFreedom update. Thanks to those who have been in touch asking about the next cohort, and about any plans for a wider network: be assured that those subscribed to this list will be first to hear.
We’re delighted to say that we’ve started putting a bit more structure around the project, and are currently in the process of registering FIELD STATION as a home for TechFreedom. More on that soon!
Our session at TechNExt entitled TechFreedom: Is the biggest risk to your organisation even on your risk register? went well, and so we’re delighted to be doing a free online version in early September. Sign up and tell your friends!
What follows are some links and news items that we’ve come across that we deemed worthy of your attention. Enjoy.
1. Put down the firehose
What does ‘just enough AI’ look like? What happens if people stop just automatically picking the largest, US-based AI model they can? Tom has been investigating:
With the flagship hosted models you can mostly use it like a fire hose. Throw some stuff at it and it’ll probably figure out what you meant, even if that means burning tokens to get there. (There are risks in that, and I’m not pretending precision doesn’t matter at the top end too.) But you don’t have that luxury with a small local model. You have to be precise. You have to think the process through in much more detail.
And I’ve come to think that makes it better. Not just for privacy, not just for energy use, though both of those are real and they matter to me, but for precision and quality.
Link: tomcw.xyz
2. US Supreme Court just blew up EU-US Data Transfers
If you’re subscribed to this newsletter, then it’s fair to say that you have more than a passing interest in how your data is handled. You will be disappointed, but not surprised, to learn that noyb, "a donation-funded NGO based in Vienna, Austria working to enforce data protection law" reports that the EU-US Data Privacy Framework, in place since 1995, is dead in the water.
On Monday, the US Supreme Court decided in Trump v. Slaughter that the US Federal Trade Commission (“FTC”) may not be independent anymore. Since 2000, the EU has relied on the “independent” FTC as the enforcer of EU-US deals on personal data. According to EU treaty law, such oversight must be independent. In the current EU-US deal, the European Commission relies on the independent FTC 259 (!) times. Max Schrems: “Given that there are no independent authorities in the US anymore, we call on the European Commission to orderly withdraw the adequacy decision on the US.”
Link: noyb
3. Scaleway to replace Microsoft in hosting French Health Data Hub
In the UK the government has announced its intention to ban social media for under-16s. Australia has already done this, and other countries are in the process of doing so.
This article explains that age verification for one group in society is essentially identity verification for everybody. It disproprotionately affects those using Big Tech, and so is another reason to pursue #TechFreedom.
Dropping Microsoft in favour of Scaleway is seen as a wider push towards data sovereignty in the European Union as relations between the continent and the US have become unpredictable and factious. Last week Scaleway was selected as one of four cloud providers under the European Commission’s Cloud III Dynamic Purchasing System.
Similar efforts are underway in other European countries. For example, the German state of Schleswig-Holstein is moving government systems away from Microsoft products to open source alternatives: last December, the state reported it will save more than €15 million in licence costs for Windows, Microsoft Office and other personal productivity tools this year and similar in subsequent years. Denmark too is progressively moving parts of its public sector administration onto open source solutions.
Link: Mobile Europe
4. Digital euro clears key hurdle as EU seeks to break free from U.S. credit cards
The EU could have a digital version of the Euro by 2029, specifically to avoid money and data being exfiltrated to the US.
The digital euro, essentially an electronic wallet guaranteed by the central bank but marketed by banks or fintech companies, will allow all euro zone residents to make payments online and in person.
Six years in the making, the ECB’s digital cash has become a more pressing issue since Donald Trump returned to the White House, slapping tariffs on even established trade partners such as the European Union and raising fears that the U.S. could one day weaponize its dominance over payment networks like Visa and Mastercard.
The approval of draft rules by the economic committee of the European Parliament comes after three years of wrangling between the ECB and banks, which have been concerned about deposit outflows and lost revenues and sought to limit the scope of the project.
"The introduction of the digital euro would… reduce overreliance on non-European providers by becoming a pan-European means of payment and would bring the single currency into the digital era by giving Union citizens the freedom to opt to pay with central bank money in their daily transactions," the draft regulation says.
Link: Reuters
5. Digital Sovereignty Becomes An Imperative As the US Reads Dutch Emails
There’s a reason that the first TechFreedom risk lens is jurisdiction . No matter where servers are physically located, the laws governing the company that run those servers matters.
According to reporting from the Netherlands, Microsoft allegedly shared the names and internal communications of Dutch officials working on EU platform regulation with the U.S. House of Representatives, including email addresses, meeting minutes, and invitations. Those officials were tied to agencies that enforce the Digital Services Act, making the context especially sensitive because the data belonged to regulators shaping Europe’s platform rules. While the House and Microsoft refuse to comment, the issue highlights the asymmetry of digital power. A European government can think it is operating within its own administrative boundaries while its data still sits in a system accessible from Washington.
That is exactly where digital sovereignty begins. It is not a patriotic slogan, nor a storage-location promise. It is the practical question of who can compel access, who can audit the chain of custody, and who can deny or limit disclosure when another jurisdiction asks for the keys.
Link: Kevin Korte
Additional links
Finally…
We were asked at our TechNExt session "I wonder is it too late to do anything…?" But you can always do SOMETHING, however small, even if you are in a long term lock-in situation.
On a more local level Opus Independents in Sheffield wrote about migrating their website away from Wix " There are zero fully ethical options under capitalism – and in few places is this more true than Big Tech." It’s a good read to show the tensions in running organisations large and small in 2026 and beyond.
That’s all for now!
Thanks for reading,
Doug & Tom :)