Taylor Lorenz’s Power User - Congress Wants to Track Every Device You Own

Episode Date: August 28, 2026

A New Law That Could Destroy Open Source Forever SUPPORT MY WORK: Buy a paid subscription to my newsletter at https://www.usermag.co         Support my work on Patreon: http://patreon.com/t...aylorlorenz To listen to the full episode and get access to more bonus episodes, an ad-free listening experience, and my weekly newsletter, subscribe to my Patreon or Substack 👇🏻Buy a paid subscription to my newsletter at ⁠https://www.usermag.co⁠         Support my work on Patreon: ⁠http://patreon.com/taylorlorenz⁠  The US Senate recently introduced the Digital Age Assurance Act, a sweeping piece of legislation that could fundamentally alter how every operating system and internet-connected device works. Under the guise of "protecting children online," this bill threatens to mandate ID verification directly into operating systems (not just social media or the internet, but operating systems themselves). This would impact everything from smartphones to PCs to open-source software like Linux. Obviously, this has huge implications for privacy, free speech, and the future of open-source development.  On this week's Free Speech Friday, I sat down with Laz Pieper and Peter Van Valkenburgh from Coin Center to break down their viral Substack piece, "The Correct Term for Age Verification is Censorship." We dive deep into how turning open-source coders into regulated service providers violates First Amendment rights, how mass identity verification systems are dangerous, why the line between safety mandates and government surveillance is disappearing so fast, and what we can do to stop this law. 

Transcript
Discussion (0)
Starting point is 00:00:00 Two and five Canadians will hear the words you have cancer. That's why every step and dollar raised matters. On September 19th, join thousands in Toronto for the Princess Margaret Cancer Foundation Walk. Challenge yourself, friends, and family to walk 21 kilometers in support of life-saving research. Together, we can carry the fire and help create a world free from the fear of cancer. Register today at pmcfwalk.ca.ca. hear that it's your money calling it wants a promotion elevate your savings with the scotia high interest savings account always earn high regular interest rates that grow the more you save and invest conditions apply
Starting point is 00:00:46 visit scotia bank.com slash hisa to learn more scotia bank you're richer than you think what we've always understood the free and open internet to be and what we understand our first amendment rights to be in America is like, you can't just tell me I can't share some ones and zeros. That's crazy. How would you enforce it? And if you could, would it be constitution? Recently, a bill was introduced in the Senate that would require operating system developers to build in systems to determine a user's age.
Starting point is 00:01:16 That signal could then be distributed to apps and online services. The bill is called the Digital Age Assurance Act. And Laz Piper and Peter Van Valkenberg at Coin Center, a nonprofit focused on cryptocurrency, have been doing excellent work breaking it down. They published a fantastic piece recently on Substack titled, The Correct Term for Age Verification is Censorship. And today I'm so excited to have them here to break down what the Digital Age Assurance Act actually entails,
Starting point is 00:01:43 how this could completely upend open source software development, and how restricting the public's access to internet services based on a government-approved personal attribute could have devastating consequences for free speech. As Laz writes on substack, age verification is the very mechanism necessary for a government to keep watch of their citizens' use of certain software and their online presence, then decide who can access that information or share their ideas and who cannot. Laz and Peter, welcome to power user. Thanks, Taylor. Thank you.
Starting point is 00:02:16 I'm so excited to have you guys here today. You wrote this fantastic piece called the correct term for age verification is censorship. And in this piece, you focus on a bill that's currently in the Senate that is another one of these. I would argue dangerous age verification bills. What bill are you focused on and what does it do? So we're focused on this digital age assurance act. And basically what it does is that it requires providers of operating systems to have mechanisms in place for users to make an account and indicate their age and date of birth in order to
Starting point is 00:02:45 access the operating system. And it's required for basically every single device you can think of. Well, yeah. So that's kind of what I want to get into because I feel like we've covered age verification a ton on my channel. And I think a lot of. People are familiar with these efforts to age, verify people on social media and maybe adult websites. But an operating system, people might not realize operating systems are integrated into everything.
Starting point is 00:03:09 Every sort of technology that has a user interface would theoretically have an operating system. So it seems like this bill could affect mobile phones. It could affect personal computers. It could affect all of these other things that have operating systems built in. I feel like these days, even my washing machine has an operating system or my refrigerator. or my car, would the bill affect all of these devices? Yeah, the bill's pretty broad in terms of what devices it covers. And so I think your intuition is pretty correct here.
Starting point is 00:03:36 And I think, you know, that's likely that there's some unintended consequences here. The bill has a broad, ambiguous definition of a technological term that's going to get applied all over the place, right? I feel like a lot of these people in Congress might not realize how tech enabled a lot of stuff around us is a lot of people, I don't think really think about their operating systems. Maybe they set up their phone once and they're used to providing their identity for that. But how would this law sort of play out in practice and how would it affect users' interactions with these everyday technologies? So there's some specific aspects of this law that define these boundaries. So one aspect is that the law just requires that these operating systems have means for users to indicate their age and date of birth. So indicate is not defined in the bill, but there's no real age verification in terms of them needing documents.
Starting point is 00:04:26 documentation and all these different things. Their age verification would be mandated only if there's clear and convincing evidence that they lied about their age. How would this work in practice? Because I feel like to avoid liability, a lot of these companies would just either collect tons and tons of data on users to try to determine their age or just mandate the age verification. Right. I think so your intuition is correct here.
Starting point is 00:04:50 So often broad laws and regulations end up leading to overcompliance. And I think that the UK's Online Safety Act kind of demonstrates this perfectly, right? All it needs from platforms is for them to have age insurance mechanisms that are highly effective. It doesn't define what that means. It kind of gives examples of how some of these platforms can approach this. But basically what this leads to is a lot of overcompliance, right? And so because platforms do not want to be held liable, well, they want to be highly effective
Starting point is 00:05:21 and demonstrate that their mechanisms are highly effective. So they will ask for maybe someone to scan their ID or to do like a face age verification where they show their face and the software determines their age. And this is just to be clear, this is also at the app level, this clear and convincing evidence that the user lied about their age. The OS provider isn't being required to do verification. They're just required to build in a signal that app developers can rely upon or use to figure out the age of the visitor to their website or app.
Starting point is 00:05:50 If they think the signal is bogus, then they have to do additional stuff. which starts to look like KYC, know your customer, if you're familiar with financial regulatory stuff for the whole internet. But it's important, I think, to be clear that that's not something they're saying that, like, Microsoft or Linux or Windows needs to do, you know, right now. Yeah. Well, I want to talk about Linux for people that have sort of been following the open source software debate, and there have been a bunch of Linux communities that have gotten really angry about this move towards age verification.
Starting point is 00:06:20 How would a law like this affect open source development? And how does Linux work? Why is it a little bit different than maybe a lot of other sort of mainstream technology that is not open source that people might think of. So on the second part of your question, like what's different about Linux than other operating systems? Linux is the paradigmatic like best example of an open source operating system. It's built of free and open source software that a whole bunch of different people, thousands actually have contributed to the relevant repositories for that software. Basically it means that like there's no person. that runs Linux, like Bill Gates and Microsoft or whoever run Windows, there's just a whole bunch of volunteer and sometimes paid by different companies,
Starting point is 00:07:04 software developers, who work together to make Linux work as sort of a public good. And this makes it sound kind of hippie-dippy, but it's also Linux, you know, for those who aren't familiar is the operating system that undergirds almost all of the internet, like the server architecture for the website you're listening to this podcast on right now is probably written in Linux because it's just this cool public good software that allows people to do things with computers that is free, as in you don't need to worry about getting a copyright license or something to use it. And that's why it's dominated a lot of stuff on the internet. So a very different operating system, but you can probably already guess how this creates issues
Starting point is 00:07:41 for something like an age verification or an age signal mandate. Two and five Canadians will hear the words you have cancer. That's why every step, and dollar-raised matters. On September 19th, join thousands in Toronto for the Princess Margaret Cancer Foundation walk. Challenge yourself, friends, and family to walk 21 kilometers
Starting point is 00:08:03 in support of life-saving research. Together, we can carry the fire and help create a world free from the fear of cancer. Register today at pmcfwalk.ca.ca. Legendary is here with BetMGM Sportsbook. Sign up to unlock access to hundreds of pre-match
Starting point is 00:08:21 live betting options for all your favorite sports. Download the BetMGM app. See BetMGM.com for terms, 18 plus Alberta only. Please play responsibly, subject to eligibility requirements. If gambling is affecting your mental health or well-being, 21-1 Alberta is here to help. Call or text 211 or visit ab.211.com. BetMGem operates pursuant to an operating agreement
Starting point is 00:08:41 with the Alberta Eye Gaming Corporation. Standard message and data rates may apply. I mean, it seems like it's fundamentally incompatible with these efforts to age-verify people. You guys write in your piece, as it exists today, Linux is publicly available for download by anyone, a user installs it offline on their local device and has no association with the independent community of developers that maintain the software. But this bill would change that, right? And how would open source developers need to transition the way that they work if law like this goes into effect? Yeah, so this bill has no carve out for open source operating systems.
Starting point is 00:09:15 And so, you know, on its face, it would apply to open source systems just like more traditional. big tech developed operating systems. In the big tech developed operating systems context, it makes a little bit more sense. Like, we'll know that Apple will be obligated for the next version of iOS or Mac OS to have these age signals built in. Right. That's pretty straightforward. And a lot of the policy issues there are, they're still important.
Starting point is 00:09:41 Like, should we be telling these companies to build these tools into their services? But they're less right at the edge of like what's okay from telling a software developer what software they're allowed. to publish or a person who's just running software on their own computer, what software they're allowed to install on their device. Because if you don't have a company that's got a relationship with the operating system user, a customer or service provider relationship of some sort, then you're really just telling the software developers for that open source operating system that they have to rewrite the code, the software that makes the operating system work, to do these things. And it could put them ultimately in a position to sort of verify that the code is doing
Starting point is 00:10:19 the things that they're obligated to have the code do by law. So it kind of changes them from just the author of some software, which arguably is a speech activity under the First Amendment, into the provider, ongoing provider of a computing service and one that involves a lot of trusted data interaction. Like maybe not at first if it's just the user says, yes, I'm over 18 and you need to keep track of that. But you can see the slippery slope here to, yeah, you need to keep track of that and you need to change your software to do some verification in the future.
Starting point is 00:10:51 We're not there yet with this bill explicitly, and there's a lot of vagaries in this bill that could mean it gets applied in that way or in a more delicate way. But we're going down the road of telling people who publish code that they have to have code in their published code that is effectively collecting user information that the developer doesn't even want to have or collect. It's not their business. Yeah. You write in your piece, let's be clear, despite any privacy protections or procedures,
Starting point is 00:11:15 this is still gatekeeping open-suiting open- source software and the internet based on a government-approved personal attribute. Today, it's age. Tomorrow, it's fill in the blank. How do you see this potentially evolving to a darker place? This is kind of like a fundamental political philosophy, right? Is that once mechanisms are in place for power to be abused or authority to be abused, then they can and likely will be.
Starting point is 00:11:40 And so I don't have quite a specific answer of what this could be besides age, but I can't tell you that it will evolve because once you all, open those doors, everything does evolve in terms of the laws and regulations. And we've seen that throughout history. The thing I'd add too is, you know, we already have seen a lot of these attempts at turning software developers into regulated service providers in the financial technology context. So our organization, Coin Center has 10 years of experience working with attempts to regulate various aspects of cryptocurrency technologies.
Starting point is 00:12:12 We're generally fully in favor of regulating a custodian of people's crypto, or someone who's giving actual investment advice to a specific client, you know, and there's certainly plenty of scams in this space. What we are worried about is an attempt to regulate somebody who's just a developer of the core Bitcoin client code, the open source software that actually makes this peer-to-peer money work, right? That person's not a financial services provider. They have no business being told to collect customer information because they don't have
Starting point is 00:12:43 customers. And if they were to collect that information, then there'd be a lot of hard questions. Like, why is the developer of the software spying on me when I'm not a customer of their business? That's just crazy. And so this has been going on, as I said, for like 10 years in crypto. We've seen, you know, multiple cases. The most notable one is the Tornado Cash case with the developer Roman Storm. He wrote this privacy tool.
Starting point is 00:13:06 It's just software. Anyone can use it. And the Southern District of New York is saying, no, you're not just a tool author. You're not just a software developer. You are a money transmitter, which means you need to know all your customer. And so financial privacy is something we lost kind of a long time ago in this country. You're going to face a KYC, know your customer, log in when you use a financial service. To some extent, these age verification laws start to open the door to the similar sort of,
Starting point is 00:13:33 yeah, it's software, yeah, it's speech, but you know what? We're going to tell you that if you're going to have people using your software and they're going to be viewing questionable content online, you're going to have to write your software so that it knows something about the customer. about the customer, i.e. the user of your software. And that has all kinds of constitutional and just liberty ramifications. If you're watching this video and you like my work, please support me on Patreon via the link below or buy a paid subscription to my tech and online culture newsletter at usermag.co.
Starting point is 00:14:02 That's usermag.com. I don't have any long-term brand partnerships and a lot of my content is effectively demonetized. I've lost major brand deals for speaking out on certain issues and for challenging power. As you can imagine, advertisers are not exactly eager to work with somebody who covers a lot of the topics that I cover and talks about the things that I talk about. These videos I make are entirely funded by you and I can't continue to make them without your support. So if you get any value out of the videos that I create and you want me to be able to create more, please support me on Patreon or Substack via the links below. On Patreon, I do bonus episodes, monthly Q&A live streams and post frequent updates about my work.
Starting point is 00:14:40 My Substack newsletter gives you a bi-weekly roundup of everything that I'm seeing and reading and paying attention to online. You can also get my newsletter on Patreon. Once again, the links to everything are below in the description. Every dollar of your support makes such a difference. I mean, we've seen a lot of Know Your Customer companies entering into this space as well, companies like Persona or there's another one at TrustCon recently. I can't remember the name, but a lot of them have worked in the financial industry and now they're bringing this sort of regulatory framework to social media, to the internet, to every app that you download.
Starting point is 00:15:12 There are cases I was reading in Wisconsin or somewhere in the US. where people are being asked to upload identifying information to view a weather app or a calculator app. And the terrifying thing about that, what that usually looks like is like take a photo of your ID next to your face and send it over the internet, right? As if A, that can't be hacked by large language models now and image generation models. And B, as if that's actually going to not just end up stolen and sold by a data broker on the dark market for, you know, here's 50 new accounts. you can use these identity pictures. And so it's very invasive of privacy.
Starting point is 00:15:50 It's not actually good for verifying the facts you want to verify, like this person is of this age or is an American citizen or is not a sanctioned person in Iran because sophisticated cyber criminals can just steal all that identity documentation. There are some better ways of doing digital identity. These would have to do with verifiable credentials that a user possesses and zero knowledge proofs that allow. them to selectively prove some verified fact about them. But those systems are still being developed.
Starting point is 00:16:22 And the systems that are in place right now are not private at all, not verifiable at all. And so it really would just become effectively a mass surveillance obligation to collect a bunch of lossy information about people that's inevitably going to end up making our cybersecurity worse rather than better. Even if the goal is good, even if the goal is something we agree with, that we don't want people of a certain age seeing despicable things online or things like that. But the unintended consequences, I think, are very likely to be worse than the goal we're trying to reach.
Starting point is 00:16:54 And to Peter's point, I think that something that's really ironic and something that we discuss all the time in terms of like, in terms of financial services, is that a lot of these mechanisms are, the objective is anti-fraud, but they actually kind of empower it because they have these honeypots of sensitive information, identifiable information. And of course, hackers want to take that, use it, and then create their own accounts using lawful citizens' identities. Right. I think that's such a good point. And I think it's also important to remember, too, that we know that these systems are hacked, as Peter mentioned, and that young people, teenagers, especially are incredibly vulnerable to identity theft and all of these types of scams and schemes and stuff. So it just seems like a big liability. Back to sort of the conversation about open source, how are these open source Linux developers responding? And is there any effort to fight back against these laws? Like, what has the response been since this bill was introduced?
Starting point is 00:17:49 We haven't actually like spoken to a lot of actual developers about this. But what I would say is it's worth noting this federal proposed federal legislation. It's based on a fairly similar law in California, which is already going to go into effect in 2027, at least for California residents, although how that would work then, you know, obligating software developers in California, but of course you're going to obligate them globally. You know, these things start to become very complicated. And so we are all, I think, really quite behind the ball as, you know, civil liberties advocates, as open source developer communities at fighting back to this. There's been sort of a very rapid accumulation of these new proposals, again, triggered by
Starting point is 00:18:35 some good and important concerns about like adolescent mental health, pornography for children, and these sorts of things. But we're really rushing to try to address those societal ills in a way that I think could have a lot of unintended consequences once we all catch up and realize what these laws actually obligate, who they obligate, and what they force them to do. Because as I said, these legislators are working in a bit of a vacuum. They see technology.
Starting point is 00:18:59 They think, ah, a problem. And they're not wrong. There are problems. But then finding a solution that doesn't create a worse problem is extraordinarily difficult. And we're just rushing to the first solution that's presenting itself. A lot of these lawmakers and these advocates will argue, well, this is not a speech issue at all.
Starting point is 00:19:16 This tech is not speech. There's no speech concerns. You guys talk about specifically in the headline about like age verification being censorship. Why is this a free speech issue? Where this is clearly a free speech issue is in the limited context of free and open source operating systems. So in that world where somebody is one of many people contributing to the software that makes that operating system work, And you, as the user of that operating system, just kind of get it off the shelf and put it on a computer that you run. Who is the person who's supposed to be obligated to make sure the software is doing the things the government's now saying the software as an operating system needs to do as far as creating age signals? Is it one of the thousands of open source developers?
Starting point is 00:20:00 Is it Linus Torvald, the original developer of Linux? Is it the user because they've copied the software under their computer and it's their operating system? None of this really makes sense. And if you want to start obligating just the open source developer community itself, you get pretty directly quickly into the case of compelled speech, which is under the First Amendment, you are not to be censored. That's pretty well known. We don't want prior restraint. We don't want a government board of approval for publishing information. But you also have a right under the First Amendment to not be compelled to express ideas that you don't believe in. And so if you are a software developer and you're really passionate about privacy and a free and open, open internet and not having locks and controls that will be abused for bad purposes, even if some of those locks and controls were intended for good purposes, then you don't want to publish this software that has this particular age verification or this particular age signal feature in it. You're being told you now need to rewrite the way your code works.
Starting point is 00:20:59 Now, there's a hard conversation there in constitutional law between whether code is always speech or whether some code is too bland, dry, utilitarian, and function. to warrant the protected expression. And so I won't go into the nuance of the case law there, and it does get really interesting, including a case about 3D printed guns, including cases about websites for marriages and whether you can be forced to make websites for gay marriages. Like, the cases are very rich and very interesting. But the long and short of it is the Supreme Court has yet to ever actually endorse this notion
Starting point is 00:21:36 that really dry mathematical publishing, publishing like operating system software is somehow not free speech. In fact, the Supreme Court on its case law about like really bland data has a tendency to be pretty extreme as to what they consider free speech to the extent that even like data about what medications doctors are prescribing for data brokers for selling to pharmaceutical advertisers has been described to a protected speech category. And so if you're telling developers they have to voice certain messages in their code, the question is, is this just a factual thing? Like, you're telling the developer to put a warning on their code,
Starting point is 00:22:13 like this code is written in C++, so you may want to audit it using this? Or is it something more expressive that they're forcing the developer to do? And as I said, we've gotten into this with cryptocurrency a lot. In the cryptocurrency world, developers have a tendency to develop software because they want financial privacy and autonomy. They want to be their own bank. Like, that's the goal, even if we fall short of it sometimes. And so forcing them to say, no, you're going to write this software and have KYC tooling built into it. is exactly the opposite of what they wanted to do. They didn't want to live in a world where a developer or a person has fiduciary control and power over the user of their tools.
Starting point is 00:22:48 And so I think the same is quite true in the open source context for something like age verification signals. Now, where things get much less First Amendment relevant, I think, is in the context of big tech companies. Big tech companies with closed source proprietary operating systems and tools, especially those that have a lot of ongoing updates and maintenance. At that point, are you telling them they have to rewrite software that they wrote? Or are you telling them that their business model means that they're subject to certain regulations? And regulating a business model, even if that business model is heavily involved with software, to me, that is often not going to be protected activity.
Starting point is 00:23:25 There's a gray area here too, but we wouldn't say, for example, that because JPMorgan Chase now provides its banking services through online banking, that they can't be told to have minimum capital reserves because that would cause them to change the code on their website, which is compelled speech. That's nonsense. But there is a vast difference between that and open source software, like cryptocurrency software for the financial regulatory context
Starting point is 00:23:48 or operating source software for the age verification context. Two and five Canadians will hear the words, you have cancer. That's why every step and dollar raised matters. On September 19th, joined thousands in Toronto. for the Princess Margaret Cancer Foundation Walk. Challenge yourself, friends, and family to walk 21 kilometers in support of life-saving research. Together, we can carry the fire and help create a world free from the fear of cancer. Register today at pmcfwalk.ca.ca.
Starting point is 00:24:22 Yeah, well, I think the issue, too, with social media companies is that they host a lot of user-generated speech, and I think a lot of these laws are aimed at curtailing that user-generated speech. Yeah, and there's kind of a fair bargain there. Like, right? They're hosting all this user-generated content makes them sound very benevolent. But what they're really doing is like mining you for every creative thought you've ever had. And then also learning exactly what ads and advertisements you might like to see and click on. And then they make a very good business out of it, right?
Starting point is 00:24:51 So putting some controls on that, I'm less immediately, you know, civil libertarian hat my speech from my cold dead hands. But when we get to actual open source software developers, I have to ask, like, are you really going to compel the thousands of developers who work on various distributions of Linux to change their code in a way that they don't like in a way that they disagree with? And if you're going to do that, how could we not say that there's a First Amendment issue there? You're forcing them to fully change their worldview in the way they do their job, which is publishing information, publishing speech. I think it's an obvious much more overt First Amendment issue. But I do think that the government seeking to restrict speech about certain topics or just access to information by regulating the content on these social media platforms or who is allowed to speak on these social media platforms is not a good precedent to set. I mean, maybe technically they're allowed to do that, right? Like I don't know if it is a First Amendment violation, but I don't know.
Starting point is 00:25:49 Like Trump is trying to ban woke AI right now or whatever they're trying to do and ban access to information. And I think it's like a slippery slope and you don't get the bill that we're talking about now without years and years and years of the social media ID verification stuff. And that whole area is itself really rich with nuance too, because there's lawsuits that have been brought about whether social media platforms get bullied into tamping down misinformation, like in the COVID context and things like that. And in those cases, the Supreme Court has been quite clear that just like suggesting that you should address misinformation by having more authoritative information about, say, COVID risks and
Starting point is 00:26:28 things like that is not a command to the company. It's more just a suggestion. It's not, but it has the same result. I say this is somebody that got my account banned and my Washington Post story that I wrote about this was also removed for a while from Instagram where I couldn't share it on, you know, because there was all these sort of restrictions. So yes, we've done an episode on jawboning and stuff. But I do think that these big tech companies will moderate speech on their platforms in order to comply with whoever's in power. When Biden's in power, they'll moderate in a certain way. When Trump's in power, Zuckerberg comes out and says,
Starting point is 00:27:00 oh, now it's free speech and you can say slurs again, but you can't hate on J.D. Vance or whatever it is. And these are all like concerning to me, even if it doesn't overtly violate the law. I think it results in part in laws like this. I'm glad that you are a voice on this because free speech is always unpopular with about half the electorate that is not in power, right? Or no, that is in power because they don't want criticism of their power.
Starting point is 00:27:24 I mean, the other interesting case here is a case actually having to do with the New York Department of Financial Services and the National Rifle Association. I'm not like a huge, like from my cold dead hands gun type guy, but I am bothered by the fact pattern in that case where an official at the Department of Financial Services basically bullied the banks to debank the NRA. And the NRA, you know, whether you agree with them or not, is a fully-re really. legitimate nonprofit. So that case is a good case to contrast with the social media and disinformation cases because in that case, it was like you're actually threatening to revoke
Starting point is 00:28:03 a charter for a financial institution. At that part, you really are compelling them to change the way they do business in a way that affects free expression. So I agree with you. I hope that line drifts further towards the government shouldn't be bullying companies into censoring things the way they want them censored because I agree the companies will usually roll over. But I will also say, And this is why CoinCenter mostly focuses on open source software developers. We have the technology now. Like, I've seen it. We don't need big intermediary platforms anymore.
Starting point is 00:28:34 We could build a peer-to-peer Internet where you wouldn't have to worry about whether Zuckerberg or Bezos has decided to side with some administration and ban all speech, which is critical of it, or has decided not to, but thinks it's really profitable to do this other thing that's manipulating the discourse in a bad way. So we can get there. And I do have to wonder, if we see a world where a lot of more restrictive laws are imposed on big tech companies that actually does limit their speech, and maybe some of them pass constitutional scrutiny, and there's nothing I can do about it. Now they have to rebuild their platform a certain way. But we defend the open source line and say, no, you're never going to be allowed to tell the developer of Graphene OS, which is a private
Starting point is 00:29:20 version of Android that can run on your phone that they have to build their tool a certain way, then maybe we're actually going to force people into using these better tools that don't have crappy billionaires and politicians behind them. And wouldn't that be cool? It's a very maybe naive and overly optimistic view of like the good that could come from these bad laws, but it's kind of my worldview that we need to move towards these distributed systems or we're just going to always be the beck and call of some digital feudal lord. Yeah, I totally agree with you.
Starting point is 00:29:49 Laz, I want to bring you in because you were tweeting about a sort of free speech. And what are your thoughts on some of this stuff? I think you kind of touched on it or you were beginning to basically that there is the element of like the First Amendment rights of open source software developers. And the other elements is this like gatekeeping the internet, right? And that's kind of something I was kind of hinting towards in this newsletter because for all practical purposes, it's really difficult to access the internet without an operating system as some sort of device. Right. And this goes into what even Peter was kind of talking about, why it's so important to defend open source software, right?
Starting point is 00:30:25 Because people need to be able to access information and to distribute information. And the internet is the place to do that right now. And so when you start implementing kind of these gates right now, these are very soft gates with this like age indication. I'll say, I'll call it right now. And especially for open source software, well, now you start kind of adding these obstacles, right? And wherever that goes, you know, that could get worse. or better, but for all practical purposes, that does kind of add a mechanism that dictates who can, I guess, access the internet based on a government-approved personal attribute.
Starting point is 00:30:58 And that, I think, starts getting a little bit concerning in a place. And when the internet is meant to bring us all together and communicate information and do all these things, right? Yeah. Well, kind of like what you wrote is today, it's this one attribute. The next day, it could be another attribute. I'm curious how you see this sort of fight connected to the fight over AI. where the government at one point wanted certain models to only be accessible to like US citizens.
Starting point is 00:31:23 There has been also a lot of attacks on open weight models, more open versions of like AI models. So yeah, do you see those sort of issues as interconnected at all? And what are your thoughts on the fight against the open weight AI models? Yeah, so like AI with you know, what happened with Anthropic is when the government basically stopped them from allowing foreign persons to access Fable, they, basically had two choices, right? They either identified all their users and verified who they were, or they just took FABEL down. And that was the practical approach for them was to take down FABEL, especially because I think they had a very short time limit to decide how to go about that. And so,
Starting point is 00:32:06 you know, once you start putting in place, like this requirement that only U.S. persons can use this software, even the proprietary software that Anthropic offers, then it starts dictating how how they go about their business, right? And then that kind of leads to a world if they decide that they did want to offer Fable to only U.S. persons, they would have to identify all their users, start collecting probably information, and then we get right back to this honeypot problem. Now Anthropic has all my identification and documentation in order for them to determine that I am allowed to use Fable.
Starting point is 00:32:38 That's concerning. And then to build on that with the open weight model question, so, you know, Anthropic and open AI are the big leading frontier model. developers who build so-called closed weight models where you're definitely, if you're using those models, you're going to have a service relationship with the business that's developing the model, right? You're going to be some kind of a customer. To Laz's point, probably not the kind of customer that deserves to be fully identified and have a dossier written up about them by the business. But there's at least some reason to believe that there is a relationship that could be exploited
Starting point is 00:33:10 for things like regulatory control. But an open weight model is, again, just more like software that you find on the internet, you download it and you run it locally. And somebody wrote that software. The important thing to be honest and transparent about is it actually tends to be Chinese AI developers because China's decided and perhaps wisely, I think, that the best way to compete with the U.S. market leaders here is to take an open source model, which lots of people have made this comparison is not dissimilar from Android and Google trying to compete with Apple's iOS by going open source.
Starting point is 00:33:43 Now you have it like China and America instead of Google. and Apple, which is funny. But anyway, so you have these open models and some of them are reaching the capability level of Fable and Mythos and the closed source models, which is important to keep an eye on because we saw the administration get tough on some frontier models because there was a perception
Starting point is 00:34:05 that these models can be used very successfully to find vulnerabilities in critical software and exploit those vulnerabilities, right? And so what do you do? You say, well, we have to lock down the models, right? Or make sure that only, the Americans are using them. So we'll only hack the foreigners.
Starting point is 00:34:19 But how do you do that if an open weight model reaches that level? If software that's just hanging out on the internet that I can download and run on my MacBook or more likely on a couple of GPUs that I control, if they can give me the same capabilities as far as finding vulnerabilities and critical software of hacking, how do you stop that? And this is again, I mean, quite obviously a question of prior restraint in the First Amendment. Is that are we at a certain point going to say that the Kimi 3 model? which is one of the more capable open-weight models is not something Americans are allowed to send to their friends online.
Starting point is 00:34:54 So that kind of like obvious, you'd have to basically go door to door and tell people not to share certain computer files is really at the heart of what we've always understood the free and open Internet to be and what we understand our First Amendment rights to be in America. It's like, you can't just tell me I can't share some ones and zeros. That's crazy. How would you enforce it?
Starting point is 00:35:13 And if you could, would it be constitutional? It's concerning that all these things, are happening kind of simultaneously. If there's one thing that you guys really want people to take away from this discussion and the work that you guys are doing in this area, what is it? And are these bills that you think can still be stopped? Is it just building so much on the state level that there is going to be federal momentum? It seems like we're just getting a deluge of these types of proposed laws. How these end up getting applied to open source software is to me the most important question
Starting point is 00:35:42 and really the constitutional question about compelling developers to write code that is against their deeply held beliefs. The California bill is already going into effect in 2027, so it's too late to stop that one, but there will be interesting constitutional challenges, I think, and I'd be very interested in meeting anybody who wants to bring a challenge against a piece of legislation like that. The federal law, I think I have trouble judging the odds there. Congress is, we're heading right up into midterms. Congress is going to get increasingly dysfunctional.
Starting point is 00:36:09 So we might get lucky from a political standpoint because so far as I know this bill doesn't have a real vehicle to become. law yet. Things get attached to the National Defense Authorization Act, though. So, you know, watch out. I do think people should be more loud about this, especially on the open source software side, because if this gets applied broadly to all software for operating systems on the internet, then we're really making a big jump down the road to a fully locked down and censored internet. And we're really losing some core First Amendment rights. From a privacy standpoint, I think that's like really important that we start bringing,
Starting point is 00:36:43 I think, the general public towards this more privacy focus. movements because I think right now there's two sides and I don't think that there's one that is overpowering the other, but there are people who do believe like age verification is a good thing, right? And people who have defended UK's model that online safety act for the sake of children. And so I think that this dialogue needs to happen because right now, this specific bill isn't as severe as something like the Online Safety Act in the UK, but we can't let anything get there. And I think some states are starting to kind of go that direction, right? We do not want to start
Starting point is 00:37:16 creating the problems that we have in the financial sector of these honeypots, of the surveillance of any of that, because I don't believe that people's movement on the internet should be surveilled to that extent that's, I think, outrageous. Well, thank you guys so much for joining me today. I really appreciate your time. Thanks, Taylor. It was great. Thank you for having us.
Starting point is 00:37:33 All right. That's it for this week's episode of Free Speech Friday. If you like my work, please, please, please buy a paid subscription to my Substack newsletter below or support me on Patreon on both Patreon and Substack. you get access to a monthly bonus episode, monthly Q&A live streams, my weekly newsletter rounding up everything that I'm seeing and following online.
Starting point is 00:37:51 Because I have no long-term sponsorships on this channel, every single bit of your support makes such a difference and ensures this show can continue. Thank you so much, and I'll be back next week with a brand new episode of Free Speech Friday. Two and five Canadians will hear the words, you have cancer. That's why every step and dollar raised matters.
Starting point is 00:38:09 On September 19th, join thousands in Toronto for the Princess Margaret Canter. Foundation Walk. Challenge yourself, friends, and family to walk 21 kilometers in support of life-saving research. Together, we can carry the fire and help create a world free from the fear of cancer. Register today at pmcfwalk.ca.ca.ca. I didn't see you then.

There aren't comments yet for this episode. Click on any sentence in the transcript to leave a comment.