Rob Hoeijmakers
banner
hoeijmakers.net
Rob Hoeijmakers
@hoeijmakers.net
Digital & AI Strategist and Photographer. I write about social media, blogging and messaging. Sees life with a smile. https://hoeijmakers.net/about/
Reposted by Rob Hoeijmakers
AI changes the role of organisational knowledge twice: it needs better knowledge to work from, and it gives us new ways to maintain that knowledge. What used to look like information management is becoming part of the organisation’s infrastructure.
Knowledge Is Becoming Infrastructure
I recently discovered that NASA has a Chief Knowledge Officer. I may have felt a little too pleased about this. Knowledge has become central to my work, and to what we are building at Schmuki. And for some time I have been making what can occasionally feel like an embarrassingly earnest argument: organisations need to start treating their knowledge as a strategic asset. Not as a SharePoint problem. Not as document management. And not as the digital cupboard where everything goes once a project is finished. So discovering that NASA has someone with knowledge literally in her title felt like a small moment of vindication. Apparently, knowledge management really is rocket science. ## Knowledge management had an image problem Knowledge management is hardly new. Organisations have spent decades building taxonomies, intranets, document-management systems and knowledge bases. But it has often lived slightly apart from the organisation itself. There was something almost library-like about it. Specialists classified information, designed structures and tried to persuade everyone else to document what they knew. Maintaining those structures required a great deal of human labour, while the organisation itself kept changing. The result will be familiar to almost anyone who has worked in a large organisation: elaborate information environments that gradually drift away from reality. The SharePoint site nobody quite trusts. The policy document that may or may not still apply. Several versions of the same process. Knowledge trapped in people’s heads, inboxes and project folders. That was already a problem. AI makes it a different kind of problem. ## AI works from knowledge A language model brings an extraordinary general capability to interpret, reason and generate. But it doesn’t automatically know your organisation. It doesn’t know what you have decided. What your current policies are. Which products you offer. What you promised customers. How a particular regulation applies to your work. What was learned from the last project. Which version of a procedure is authoritative. For AI to become genuinely useful inside an organisation, it needs the right material to reason from. That changes the value of organisational knowledge. A knowledge base is no longer primarily something we maintain in the hope that an employee might search it one day. It increasingly becomes part of the grounding layer for systems that answer questions, support decisions and, as we move towards agents, take actions. Put an intelligent agent on top of a chaotic information landscape and you haven’t solved the information problem. You may simply have accelerated the chaos. ## But AI also works on knowledge This is the other half of the change, and I think it matters just as much. The same AI that needs well-organised knowledge can help us create and maintain it. It can classify documents, restructure information, compare versions, extract entities, identify contradictions, connect related material, detect gaps and help determine what needs updating when the outside world changes. That matters because knowledge has always had a maintenance problem. Organisations aren’t static. Laws change. Products change. People leave. New decisions are made. Terminology evolves. Experience accumulates. A beautifully organised knowledge base begins ageing almost as soon as you finish it. AI changes the economics of that maintenance. It makes organisational knowledge easier and cheaper to maintain at precisely the moment when well-maintained knowledge is becoming more valuable. That creates a flywheel. AI works on knowledge. Better knowledge gives AI better material to work from. Using AI creates new experience and knowledge, which can in turn improve the knowledge system. Knowledge stops being an archive of the organisation and starts becoming part of its living infrastructure. ## From knowledge to wisdom There is another step beyond this. An organisation isn’t simply a collection of facts, documents and rules. It also contains experience about how those things should be applied. Two organisations can operate under exactly the same legislation and behave quite differently. A written policy rarely captures every exception, consideration or judgement that experienced people make when applying it. That distinction becomes increasingly important as AI moves from finding and generating information towards supporting decisions and taking actions. Knowing the rule is knowledge. Knowing how this organisation responsibly applies that rule in a particular situation is closer to wisdom. That is considerably harder to capture. But it may also become one of the most valuable things an organisation possesses. ## Back to the boardroom This is why I think the status of organisational knowledge is changing. AI didn’t suddenly make knowledge valuable. Organisations have always depended on what they know. But AI is making that value much harder to ignore. If knowledge is becoming both the material AI works from and the material AI works on, it seems increasingly strange to treat it primarily as an IT housekeeping problem. It is intellectual capital. It is AI infrastructure. Increasingly, it is part of the operating model of the organisation. That doesn’t mean every organisation needs to appoint a Chief Knowledge Officer tomorrow. But somebody needs to be responsible for a deceptively simple question: **Does the organisation actually know what it knows?** NASA, at least, has decided that question deserves serious organisational attention. I confess I find that rather reassuring. And perhaps a little vindicating. * * * The company does not live in the LLMA knowledge-intensive company should keep durable organisational knowledge outside the model, and let AI do what it is unusually good at: reason across it.Rob HoeijmakersRob Hoeijmakers
hoeijmakers.net
September 24, 2026 at 11:45 AM
Reposted by Rob Hoeijmakers
Behind innovation sits a landscape of institutions. I began by trying to map them. Over time, I found the more revealing question was not where each one belongs, but what moves between them, and which routes are open depending on where you stand.
How We Organise Innovation
A few days ago I came across the Dutch government's move to establish a new organisation for disruptive innovation. NADI, the Nationaal Agentschap voor Disruptieve Innovatie, is explicitly inspired by the ARPA model, with DARPA its original and best-known example. I did what I tend to do when I encounter a new institution: I tried to work out where it fits. That sounds straightforward. It wasn't. Over the past months I have spent quite a bit of time trying to understand the landscape around research, knowledge and innovation. In the Netherlands alone that quickly produces an impressive collection of organisations and acronyms: research funders, universities, knowledge institutes, ministries, advisory bodies, programmes for applied research and public-private partnerships. Look beyond the Netherlands and the landscape widens further. Germany has institutions such as Fraunhofer and Max Planck. France has CNRS and its own distinctive institutional traditions. At European level, Horizon Europe spans instruments and organisations ranging from the ERC to the EIC and EIT. In the United States there are the NSF, NIH, national laboratories and the ARPA agencies. Another organisation inspired by the ARPA model therefore seemed like another piece to add. And that was where I got stuck. ## The Lego view My instinct when confronted with a landscape like this is analytical. First identify the pieces. Establish what each does. Find the categories. Understand the differences. Draw the connections. Eventually, if you have done your homework properly, everything should fit. I have come to think of this as my Lego view of the world. There is nothing particularly wrong with it. Before you can understand a system, it helps to know what is actually in it. A research funder is not a university. An advisory council is not a research institute. Two organisations that appear similar from a distance may have quite different purposes, powers and histories. The inventory gives you grip. But something strange happened as my inventory improved. I knew more, yet the whole did not become correspondingly clearer. The organisations were sitting increasingly neatly in their boxes while the thing I actually wanted to understand seemed to be happening somewhere between them. So I changed the question. Instead of asking: **What are all these organisations?** I started asking: **What are people trying to make happen here?** ## Put the people back in Once I did that, the landscape began to move. Someone wants to understand why something happens. Someone has an idea for a technology that does not yet exist. A teacher wonders whether children could learn something differently. A physician encounters a problem in clinical practice. A small company discovers that a process could be dramatically improved. A researcher sees a possibility nobody has tested. A government concludes that dependence on a particular technology has become a strategic problem. Different situations, but they generate remarkably similar needs. People need knowledge. Sometimes knowledge that already exists; sometimes knowledge that still has to be created. They need other people who know things they do not. They need expertise. Time. Money. Equipment. Data. Legitimacy. Places to experiment. Sometimes customers. Sometimes public institutions willing to participate, regulate or buy. And they need connections. The person who understands a problem is rarely also the person who possesses all the knowledge, capital, authority and practical capability required to address it. Researchers find practitioners. Companies find universities. Governments convene consortia. Students become researchers and researchers move into companies. Specialists from different disciplines discover that they have been working on different parts of the same problem. Not everything needs to become a product or an application. Sometimes the result is simply a better understanding of the world. But when knowledge does travel towards use, it may become a treatment, a teaching method, a standard, a machine, a policy, a company, a piece of software or simply a better way of doing something. Then people use it. And what happens in use produces new questions. Seen this way, the institutions do not disappear. They become more intelligible. Many of them can be understood as answers to recurring needs in these movements. Some educate people. Some investigate. Some provide money. Some connect. Some translate knowledge into practice. Some advise governments. And some are deliberately designed for questions where several uncertain approaches need to be tried and actively steered. ARPA-like organisations are one example of that last category. They are not _the model_ for organising innovation. They are a particular institutional answer to a narrower question: what do you build when a problem is important, the route is uncertain, several approaches may need to be tested in parallel, and the work requires unusually active programme management and a path towards use? Other societies and sectors have produced different answers. Once I started looking this way, the institutional landscape stopped resembling an organisational chart. It became a landscape of movement: questions, people, knowledge, money, authority, technology and experience travelling between different places. ## A lens in France Last year I encountered an enormous Fresnel lens in a French museum. It had once been used for a lighthouse and stood roughly two metres high. Its concentric sections reproduce much of the focusing effect of a far thicker lens while using much less glass. I took several photographs of it. Move around such a lens and what you see through it changes. Parts of the world behind it enlarge, shift or distort. The object remains where it is; your view through it does not. There is a limit to every metaphor, and I don't want to make the Fresnel lens do more work than it should. But I realised later why the object had stayed with me. Models compress reality. They have to leave things out. The important question is what survives the compression. My Lego model preserved entities particularly well. It showed boundaries, categories and responsibilities. It did not preserve movement particularly well. And it obscured something else. **Where you stand matters.** 0:00 /0:11 1× ## The same landscape, different routes Imagine somebody starting a company alone with an unusual idea. The knowledge and innovation landscape may appear primarily as a problem of access. Who knows something about this? Where could I test it? Is there funding? Am I eligible? Who can introduce me to somebody who understands what I am trying to do? Now put yourself in a company with seven employees. You may have customers, technical expertise and a genuinely promising idea. But taking two people out of the business for months to assemble a consortium, understand a programme and write applications may simply not be practical. The institutions have not changed. Your route through them has. Inside the R&D department of a multinational, the same landscape looks different again. Universities, laboratories, intellectual-property specialists, European programmes, standards bodies and international partners may all be accessible parts of it. The organisation may employ people whose job is to establish precisely these connections. Routes that are expensive and difficult for a seven-person company to use may be ordinary roads here. For a researcher, a university or a hospital, the landmarks shift again. The formal landscape is recognisable, but its entrances, incentives and useful connections are different. Then take perhaps the strangest position of all: government. Government is itself travelling through this landscape while simultaneously trying to alter it. It funds research and education, sets rules, creates incentives, buys things, convenes people and occasionally establishes an entirely new institution because an important route appears to be missing. That suggests another way of looking at innovation policy. Alongside asking how much money government spends or which organisations it creates, we can ask what it is doing to the possible routes through the landscape. **The landscape may be shared. The routes through it are not.** ## A few landmarks None of this makes the institutions unimportant. Landscapes need landmarks. The table below is deliberately small. It mixes funders, research organisations, programmes and networks because those are some of the forms this landscape takes. The entries are not counterparts. They are examples of different institutional answers to recurring needs. Recurring need | Netherlands | Germany | France | European Union | United States ---|---|---|---|---|--- **Supporting inquiry** | NWO, ZonMw | DFG | ANR | ERC, wider Horizon Europe funding | NSF, NIH **Sustaining research capacity** | Universities, TNO | Universities, Max Planck | Universities, CNRS | European research infrastructures | Universities, DOE national laboratories **Connecting research and practice** | SIA, TNO | Fraunhofer | Carnot institutes | EIT KICs, European Partnerships | Manufacturing USA **Pushing high-risk ideas towards application** | NADI, being established | SPRIND | Bpifrance, France 2030 | EIC | DARPA, ARPA-E, ARPA-H Another observer could take exactly the same landscape and produce a different table. Follow money and one map appears. Follow knowledge and another. Follow people and education and it changes again. Start with a small company rather than a ministry and some enormous institutions almost disappear while previously minor connections become decisive. A useful model does not eliminate these perspectives. It helps us move between them. ## Looking again This leaves me in a rather different place from where I started. A news item about a new Dutch innovation agency prompted a familiar question: _where does this organisation fit?_ I can answer that question better now. But I am less interested in it. I want to know what happens to the landscape when an institution like this is introduced. Which routes does it create or shorten? Who can reach whom more easily? Which ideas can travel further, and which risks become possible to take? If something succeeds, where can it travel next? Those questions apply well beyond one new Dutch agency. We can ask them about a research funder, a university, a European programme, an applied research institute, a corporate R&D department or an entire innovation policy. I have not discarded the Lego view. I still want to know what the pieces are. Without that groundwork, talk about relationships and networks quickly becomes vague. The inventory matters. It is simply no longer where I want to stop. I started by trying to find the right place for each institution in a model. Somewhere along the way, I became more interested in the spaces between them. First learn the landmarks. Then look beyond them. And ask: **What is trying to happen here?** **What has to move, and between whom?** **And from where I stand, which routes are actually open?**
hoeijmakers.net
September 20, 2026 at 9:16 AM
Reposted by Rob Hoeijmakers
ChatGPT has become remarkably good at remembering me. I went looking for an explanation and discovered that memory is no longer just about saved facts: ChatGPT is continually synthesising what it learns about me.
ChatGPT is dreaming about me
ChatGPT has become remarkably good at remembering me. Not just facts, but the shape of what I am working on. Projects appear, intensify and disappear. Interests shift. The way I use ChatGPT changes. Somehow, its memory seems to move with that. I had noticed this without really understanding why. Then this week I tried to save a memory in ChatGPT Plus, and it would not let me do it in the way I expected. That small annoyance sent me looking. What I found is that ChatGPT Memory has changed quite fundamentally. ## From remembering to synthesising The original memory model was easy to understand: I told ChatGPT something mattered, and it saved that information as a memory. The newer system works differently. OpenAI describes it as a **“continually updated synthesis”** of what ChatGPT has learnt from previous conversations. Behind it is a background process it calls **dreaming**. Instead of simply accumulating facts, the system keeps revising its understanding as new conversations happen and older information becomes less relevant. That is the important shift. Memory is no longer just a record of what was true. It tries to maintain a picture of what is true now. ## A sliding window in time I think that explains why it works so well for me. My work changes quite quickly. Projects start and finish. Something I am investigating intensively for a few weeks may become irrelevant afterwards. New interests appear. Even the way I want ChatGPT to work with me develops. A list of saved facts struggles with that. It knows what was true. A synthesis can try to understand what is true **now**. OpenAI gives the simple example of a planned trip. Before the trip, remembering that someone is going somewhere is useful. Afterwards, that same information needs to become part of their history rather than remain a current plan. My experience is broader than that, but similar. Memory now feels more like a sliding window through my work and interests than a notebook I have been filling for years. It is surprisingly seamless. In OpenAI's terminology, ChatGPT is dreaming in the background. In use, it sometimes feels as though it is dreaming along with me. ## The strange part: Business still remembers I discovered all this because I initially thought I had found another difference between ChatGPT Plus and ChatGPT Business. After Plus declined my familiar “remember this” instruction, I opened Business and tried the same thing with something harmless. I told it I was exploring quantum computing in education in the Netherlands and Europe. Its response: **Memory updated.** OpenAI says newer memory capabilities have also been rolling out to Business, so I don't think this is simply new memory versus old memory. But the different interaction was enough to send me looking. And I am glad it did. ## Better memory, less agency There is a trade-off here. With the old system, I had very direct agency. I decided what mattered and told ChatGPT to save it. With dreaming, some of that judgement moves to the system. ChatGPT decides what is relevant, what should fade and how different pieces of context fit together. I can inspect a Memory Summary and correct things, but that summary is not necessarily everything ChatGPT remembers. For me, so far, the trade seems worthwhile. I would not assume that is true for everyone. It probably depends on what you use ChatGPT for and how much continuity you want between conversations. But memory is one of the things that determines how valuable an LLM becomes to me. A better model is useful. A model that increasingly understands the context in which I use it is something else. I went looking because ChatGPT wouldn't let me save a memory. I came away understanding why I might not want to go back.
hoeijmakers.net
September 17, 2026 at 6:01 PM
Reposted by Rob Hoeijmakers
Europe does not merely lack capital. It lacks the institutional machinery for turning research, young companies and industrial ambition into scale.
From lab to fab needs more than a fund
This week, Emmanuel Macron and Dutch prime minister Rob Jetten visited ASML in Veldhoven. The French delegation included Mistral AI, making the setting unusually apt: a French AI company visiting the Dutch manufacturer of the machines needed to produce the most advanced chips. The resulting Franco-Dutch statement was unusually direct about the geopolitical stakes. Technological leadership, it said, translates into economic power, political influence and military capability. Europe therefore needs to connect AI, computing, semiconductors, photonics and quantum technology into something resembling an industrial system. One phrase caught my attention. Europe needs seamless funding “from lab to fab”. A day later, NOS reported that the Dutch government is accelerating plans for a national investment institution, backed by an initial €3.3 billion. Its purpose would be to help innovative companies grow and keep more of them in the Netherlands. Seen separately, these are two rather different news stories: a diplomatic technology visit and another Dutch financing initiative. Together, they helped me understand a missing part of the European technology debate. ## More than another pot of money I have been circling this problem in my writing about deep tech. In The Deeptech Dilemma, I looked at Europe’s difficulty in turning excellent science into large technology companies. In my conversation with Alain le Loux about investing in atoms, the central problem was patient capital. Deep-tech companies need large amounts of money, specialist knowledge and considerably more time than a software start-up. More recently, I found myself making a similar argument about AI compute: once land, electricity, data centres and chips enter the picture, this starts looking less like conventional venture capital and more like infrastructure finance. My assumption was that Europe simply did not have enough capital of the right kind. That remains partly true. But the Dutch investment-bank discussion points to a more specific problem. Europe does not merely lack money. It lacks enough institutional machinery for combining different kinds of money and staying with a technology as it moves from research to start-up, factory and industrial infrastructure. The Netherlands already has public financiers, regional development agencies, subsidies, venture funds, a Deep Tech Fund and access to European programmes. So my first reaction to the idea of a new national institution was fairly obvious: why add another fund? The important distinction is that it is not supposed to be just another fund. A fund is, in simplified terms, a bounded pot of money with a particular mandate. It invests until that money has been allocated. A promotional investment bank can operate funds, but it can also provide loans, guarantees and equity, take different positions within a financing package and, depending on its structure, raise additional capital against its balance sheet. It can also do something less visible but perhaps equally important: develop projects, combine financiers and absorb precisely the part of the risk that prevents others from participating. That matters because the financing problem changes as a company grows. A research grant may help prove the science. Venture capital can finance an early company. But building a semiconductor facility, biotechnology production line or large compute campus may require hundreds of millions or several billions. At that point, neither a normal start-up fund nor a commercial bank is necessarily equipped to carry the project. A public investment institution can provide the first layer, a guarantee or a long-term loan. That can make the risk acceptable to banks, insurers, pension funds and European institutions. Public capital is then not only spent. It is used to organise a larger investment. ## France as a reference case Germany’s KfW is the classic European example of a promotional bank with a very large balance sheet and extensive capital-market financing. It demonstrates the financial difference between a bank and a collection of funds. For the technology question, however, France may be the more interesting reference case. France created Bpifrance in 2012 by combining three existing public financing organisations. It brought credit, guarantees, innovation financing, direct investment, investment in private funds, export support and advisory services into one institution. That is different from making one large pot of public money. France centralised the capacity to translate political priorities into financial instruments, investment programmes and relationships with companies. There is some evidence that this has helped develop the market around it. According to an OECD assessment, Bpifrance invested €4 billion directly in almost 450 companies between 2013 and 2022. It invested another €5 billion in 160 private venture-capital funds. Those funds ultimately raised €27 billion, implying that every euro committed by Bpifrance was accompanied by considerably more capital from elsewhere. An even more interesting detail is that Bpifrance’s average share in its partner funds declined as those funds became larger. That is what a successful public intervention should ideally do: help create a market rather than permanently replace one. France has not solved European innovation. It is not the continent’s uncontested technology leader, and a powerful state institution brings obvious risks of political interference, complexity and crowding out private investors. Still, something coherent is visible. France has combined research institutions, industrial policy, public investment, procurement and political promotion around technologies such as AI, nuclear energy, aerospace and defence. Mistral’s presence at ASML fits that pattern. It links a French attempt to build an AI champion with the Dutch industrial capability on which the entire advanced chip industry depends. My hunch is that France’s centralising tradition helps here. This is difficult to prove as a simple causal claim, and centralisation can produce expensive failures as easily as successful national projects. But it does give the country a capacity that Europe often lacks: the ability to choose a direction and then align institutions, capital and political attention behind it. Bpifrance is not the sole explanation for France’s current technology momentum. It is better understood as part of the machinery that makes such momentum possible. ## National institutions inside a European system This still leaves the question of why the Netherlands needs its own institution. Why not leave this to the European Investment Bank? The answer appears to be that the two levels perform different roles. The EIB provides continental scale, European risk-sharing and access to large pools of capital. National institutions possess local knowledge, find and prepare projects, work with smaller companies and represent national industrial interests. The EIB itself describes these institutions as intermediaries, co-investors and co-financiers that help difficult projects come to life. A Dutch institution could therefore help a photonics company or biotechnology plant become investable, combine its own contribution with Dutch pension capital and then bring in the EIB or another European programme. This is not necessarily economic nationalism. For the largest technologies, a purely national approach will be too small. But European financing cannot be organised entirely from Luxembourg or Brussels either. Someone still has to know the companies, understand the industrial ecosystem and build the project. The emerging system is layered: national institutions originate and organise; European institutions add scale and risk-sharing; private capital supplies much of the eventual investment. That system remains uneven. Germany has financial scale. France has built a more integrated innovation institution. The Netherlands is now trying to add a layer it has so far lacked. At European level, new scale-up and competitiveness funds are intended to connect these national efforts. None of this guarantees good investments. A national institution can just as easily become a politically convenient collection of programmes. The decisive question is therefore not whether the Netherlands creates another organisation with several billion euros. It is whether that organisation gains the mandate, expertise, instruments and balance sheet to connect the pieces that already exist. This is what I saw differently after putting the two news stories together. Capital is not merely a quantity. It has an architecture. Europe’s problem has long been the discontinuity between its laboratories, its young companies and industrial production. The visit to ASML showed the outlines of a more coherent European technology system: French AI, Dutch semiconductor machinery, European demand and public-private investment. The technology is not the only thing that must travel from lab to fab. The financing has to make the same journey.
hoeijmakers.net
September 3, 2026 at 7:10 PM
Reposted by Rob Hoeijmakers
A Swiss AI initiative looks like a model of technological sovereignty. The Dutch alternative looks far messier. That may not be a weakness.
Apertus and the Messy Case for AI Sovereignty
I recently read an article about an AI initiative in Groningen, aimed at reducing dependence on American and Chinese AI. Then I read the reactions on X. A number of technically knowledgeable people were mocking the idea of fine-tuning an existing Qwen model. The criticism was understandable: this is not particularly exotic work. Why present it as technological sovereignty? I understood the point. But I did not quite share the amusement. The underlying question still seemed important: if Europe wants to be less dependent on a handful of foreign AI companies, what exactly should we be able to do ourselves? That reminded me of Apertus. ## The appeal of the clean stack **Apertus** is a Swiss AI initiative involving ETH Zurich, EPFL and the Swiss National Supercomputing Centre. The Swiss have trained their own foundation models, using their national supercomputer Alps. The models are open, much of the surrounding work is transparent, and researchers can now access Apertus through public infrastructure. There is something very satisfying about it. Researchers. Compute. Models. Operations. A clean stack. I have written before that Europe needs compute if it is serious about technological sovereignty. Apertus shows what happens when that compute is connected to the expertise required to build and run models yourself. For a moment, the conclusion seemed obvious: perhaps this is what the Netherlands should be doing. Then I looked again. Apertus AIFully Open Foundation Model for Sovereign AISwiss AI Initiative ## Or perhaps an ecology The Dutch picture is much less tidy. GPT-NL is building foundation-model capability. The AI Factory in Groningen is building public compute, expertise and access. Commercial infrastructure is emerging elsewhere. Smaller initiatives adapt existing open models rather than building new ones. Initially, that looked fragmented. Now I am not so sure. If one model disappoints, another can replace it. If foundation models become more commoditised, not every country has to keep building one. Public and commercial infrastructure can coexist. Different organisations can specialise. Instead of controlling one stack, you create an ecology. And ecologies are messy. ## Sovereignty as optionality I think I am naturally attracted to clean architectures. There is comfort in drawing the whole thing, deciding which parts matter, and bringing them under control. But real systems rarely stay that clean. Switzerland still depends on Nvidia hardware and a much wider international technology chain. No European strategy will remove all dependencies. Perhaps that is not the right goal anyway. The more useful question may be whether a dependency is replaceable. Can you switch models? Move workloads? Choose between providers? Does expertise exist in more than one place? If one component disappears, does the rest of the system continue to work? Seen that way, sovereignty starts to look less like ownership and more like optionality. You do not need to control every layer. You need enough capability, alternatives and understanding that no single dependency becomes destiny. ## Stack or ecosystem? I still find **Apertus** impressive. Switzerland has deliberately preserved the ability to build, train and operate foundation models. But I am less convinced that its integrated approach is necessarily the blueprint. Perhaps the Swiss are building a stack, while the Dutch are slowly assembling an ecosystem. The first is cleaner. The second may be more resilient. I started out wondering whether Switzerland had built something the Netherlands was missing. I am less sure now. And that, I think, is the more interesting question.
hoeijmakers.net
September 8, 2026 at 11:05 AM
Reposted by Rob Hoeijmakers
The European Commission’s procurement proposal made me reconsider a quieter part of Europe’s innovation problem: whether public organisations can buy something unfamiliar.
Europe can invent. But can it buy what it invents?
When I first saw that the European Commission had proposed a new **Public Procurement Act** , I thought I knew roughly what kind of news this was. Another European Act. Another promise to simplify rules. A little innovation, a little digitalisation, some “Made in Europe” language. Important, perhaps, but not necessarily something I needed to read 200 pages about. Then I noticed what public procurement actually covers. It is not mainly about how the European Commission buys things. It is about **how governments, municipalities, public universities, hospitals, transport operators and other public organisations across Europe spend money**. Together, public procurement represents roughly 15 per cent of European GDP. That changes the scale of the question quite dramatically. When a municipality buys software, a ministry commissions research or a public hospital buys equipment, it cannot simply choose the supplier it likes best. Public money requires a process: suppliers must be treated fairly, decisions must be transparent and someone must be able to explain afterwards why this particular company won. That is what procurement is for. It is not bureaucratic theatre. Without such rules, public purchasing would be far too vulnerable to favouritism, bad decisions and private relationships. Still, after reading more about the Commission’s proposal, I began to think that procurement may be one of the less known reasons Europe finds it difficult to turn innovation into scale. Not because the rules literally force governments to buy the cheapest option. They do not. But because they can make the familiar option much easier to defend. ## The cheapest bid is not the whole story I had assumed that public procurement law was one of those areas where the formal answer was simply: buy the lowest bidder. That turns out to be too simple. The current European rules already allow public buyers to consider quality, environmental impact, social effects, innovation and the full cost of a solution over its lifetime. The law does not say that a municipality must buy the cheapest possible software, regardless of whether it works well. And yet price-only purchasing remains common, while innovation procurement is still uneven across Europe. The European Court of Auditors found that **competition for public contracts declined** over the past decade, with fewer bidders and a growing number of procedures attracting only one bid. So there is a more interesting question than whether the law permits innovation. Why does a system that permits quality and innovation still so often reward price, certainty and suppliers that have been around for a long time? I think the answer is partly hidden in a very understandable public-sector instinct: **choose the decision that will be easiest to justify afterwards**. Imagine a municipality buying an AI system to help residents find the right service. One supplier offers a familiar platform with years of public-sector references, a clear implementation plan and a price that fits neatly into a spreadsheet. Another is a smaller company with a more interesting approach. Its system might produce better results, save time for residents and civil servants, and become more valuable over time. But it also requires testing, integration and perhaps a different way of working. The first proposal is easier to compare. The second asks the buyer to make a judgement. That is where innovation often gets stuck. A known product can be specified in detail. An established supplier can show years of references. A low initial price can be explained in one line. The possible value of something new is harder to put in a tender document. It may only become visible later, through better outcomes, lower costs, resilience or productivity. It may depend on whether people actually adopt the new system. Nobody needs to write “prefer the incumbent” into the rules. A process designed around comparability and defensibility can produce that result on its own. ## Innovation runs on a different clock This is particularly visible when the purchase involves technology. A new solution may initially cost more because it **includes development, experimentation, staff training or organisational change**. Its real value may only become visible after it has been used for a while. That does not make it a good purchase automatically. Public buyers should not be asked to fund every promising demonstration. But it does mean that the purchase price is often the wrong clock for judging innovation. A price is immediate and measurable. Long-term value is more difficult. It involves assumptions, future behaviour and outcomes that may be real but are not yet visible. The strange result is that an organisation can be legally free to buy something better, while still being practically organised to buy something safer. That matters for Europe because public organisations are not small customers. They are often the market. Europe spends a great deal of energy on research, start-ups, strategic technologies and private investment. But a young company also needs someone willing to buy what it has developed. If Europe can fund the research, help create the company and then make it unusually difficult for public institutions to become early customers, there is a gap in the chain. The technology makes it out of the laboratory, but not necessarily into a real market. ## The Commission is trying to change more than the paperwork The new proposal does contain a large amount of administrative repair. It would **replace three existing procurement directives** with one directly applicable regulation. It would simplify procedures, make market consultation more normal, limit unnecessarily excessive demands for turnover or previous public-sector experience, and connect national procurement systems through a shared digital infrastructure. All of that sounds sensible. The fact that a small company may need to navigate several systems, repeatedly submit the same information and satisfy requirements that have little to do with its ability to deliver does not help Europe create a more dynamic market. But the more interesting part of the proposal is that it tries to change what counts as a good purchase. The Commission wants price and quality to be assessed together as the normal approach. It also proposes a new innovation procedure. This is more significant than it sounds. Instead of beginning with a fixed technical specification, a public buyer could begin with a societal challenge. It could ask the market for ideas, establish how it will judge value, test promising approaches and then purchase the solution that proves itself. A city would not have to begin by saying: “We need this exact system.” It could begin by saying: “We need to reduce waiting time for this group of residents. What might work?” That is a very different relationship between a public organisation and the market around it. The proposal also makes room for suppliers to retain intellectual property developed in such a process, unless there is a good reason not to. That matters because a company that solves one public problem may then be able to offer the solution to others. There is also a European-preference dimension, especially in strategic sectors. I am less interested in treating that as a simple “buy European” story. European origin is not a guarantee of quality or innovation. But the broader shift is clear. The Commission increasingly sees public purchasing not just as a way to spend money correctly, but as a way **to create resilience, demand and industrial capacity**. ## The part a new Act cannot solve I find this more interesting than I expected because it points to a limitation in the way Europe often talks about innovation. We tend to focus on invention, capital and infrastructure. Those are all essential. But institutions matter too. A new regulation can make it easier to consult the market. It can make quality more prominent. It can create a proper route for testing and buying something that does not yet exist. What it cannot do is **make an organisation comfortable with uncertainty**. That depends on procurement expertise, organisational culture, political expectations and the degree to which someone is personally blamed when an experimental project does not work. If a new system fails, there will be uncomfortable questions about why the organisation took the risk. If a familiar supplier disappoints, that can look like an unfortunate continuation of normal practice. That is probably the deepest procurement problem. Europe has spent years encouraging companies to innovate. Its public institutions have often been rewarded for buying what they can most easily defend. The proposed Public Procurement Act is not a solution to Europe’s wider innovation gap. But it is an acknowledgement that innovation policy does not end with inventors, investors and factories. It also depends on whether the institutions that spend public money can learn to buy something new.
hoeijmakers.net
September 10, 2026 at 9:48 AM
Reposted by Rob Hoeijmakers
A first test of Safari’s new agent interface suggests that browser automation can become cleaner and less dependent on any single AI provider.
A cleaner way to let AI use my browser
I have been experimenting with browser control in both ChatGPT and Claude. It is one of those capabilities that can look like a demonstration until you encounter the right work for it. I regularly have to fill in forms, for example, and I do quite a lot of user acceptance testing on our own platform. That means moving through the same screens, checking the same interactions and recording what happens. It is useful work, but not always a useful way to spend my own attention. An agent can already do a surprising amount of it, provided it has access to a browser. Until now, that has meant Chrome extensions. There is one for Claude and another integration for ChatGPT. They work, sometimes impressively, but the arrangement has always felt messy to me. The extension has to live in the right browser profile, alongside the rest of my work. Each AI provider needs its own route into the browser. The extension, browser permissions and provider all have to continue cooperating. When the connection becomes unstable, it is not always obvious which layer is responsible. Chrome is not even my normal browser. I work on a Mac and use Safari. Moving work into Chrome simply because an AI provider has built its integration there already feels like the wrong dependency. Then I came across WebKit’s announcement of a new way for agents to interact with Safari. I gave it a test run, and the difference was immediate. The connection felt markedly more stable and the interaction more direct. My first tests also suggest advantages in latency and token use, although I have not done enough controlled testing to call that a benchmark. What interested me most was not the speed. It was the architecture. ## One interface, different agents The technology is called MCP, but the abbreviation is not particularly helpful. It has become a general label for many different connections between AI systems and other software. In this case, the underlying idea is straightforward: Safari provides a standard interface through which an agent can ask what is on a page and perform actions in the browser. The browser itself provides the connection. I do not need a separate Safari extension from OpenAI, another from Anthropic and perhaps a third one for the next provider. Any compatible agent can use the same interface. That reverses the relationship I had in Chrome. With an extension, the AI provider integrates itself into my browser. With this approach, my browser exposes a capability to whichever agent I choose. This also explains why the experience felt cleaner. The agent does not have to behave as if it were a person looking at a screen and trying to operate a mouse. Safari can make the page, its controls and its current state available in a structured form. Screenshots are still possible and sometimes necessary, but they are no longer the entire basis of the interaction. For a developer, this creates obvious possibilities for debugging and testing. I am interested in something slightly different. I am not a software developer, but the browser is where a large part of my professional work happens. If an agent can interact with that environment reliably, it becomes useful for many ordinary workflows that never justify a custom software integration. ## One less dependency There is a wider business point here. We are starting to build workflows around AI systems while the providers, products and models continue to change quickly. Every workflow tied tightly to one provider becomes another continuity problem. That does not mean dependencies can be avoided altogether. It means they should sit in the right place. A general ability to operate a browser is better provided by the browser than recreated as a proprietary extension by every AI company. When the connection is standard, the agent becomes more replaceable. I can use Claude today and another compatible agent tomorrow without rebuilding the browser side of the workflow. If one provider changes its product or loses its lead, my working environment does not have to change with it. This kind of optionality is easy to underestimate. It is less spectacular than a new model release, but probably more important once AI becomes part of daily operations. Continuity depends not only on what a system can do, but also on how easily its components can be exchanged when circumstances change. My experiment with Safari was small. I connected an agent, let it work in the browser and compared the experience with what I had been doing through Chrome. Yet it changed how I think about browser agents. Until now, I saw them mainly as AI products gaining access to a browser. This felt more like the browser becoming a stable working environment that different agents can enter. For someone who depends on the browser but does not want to depend unnecessarily on any single AI provider, that is a much more useful direction. ⚙️ Want to try it? Install Safari 27 beta, enable Show features for web developers and Allow remote automation and external agents, then connect it through Codex with codex mcp add safari-mcp -- "/usr/bin/safaridriver" --mcp. It should then become available in ChatGPT Work conversations; start with WebKit’s instructions if you need the details.
hoeijmakers.net
September 2, 2026 at 7:23 AM
Reposted by Rob Hoeijmakers
The EU has designated ChatGPT a Very Large Online Search Engine. The decision exposes the uneasy hybrid inside one product: public information infrastructure and private working environment.
Europe Has Decided ChatGPT Is a Search Engine
I use ChatGPT every day. I do not personally use **ChatGPT Search**. I knew the feature was there, but regarded it as an annex to the product. For me, ChatGPT was primarily a working environment: somewhere to think, write, analyse, organise information and increasingly interact with other systems. If it could also search the web, that was useful, but not central to how I understood it. Yesterday’s regulatory development has made that view harder to maintain. On 31 August, the European Commission designated ChatGPT a Very Large Online Search Engine under the Digital Services Act. I initially read this as a regulatory fact about ChatGPT Search. The search feature had grown beyond the DSA threshold, so Europe was applying its rules for very large search engines. The Commission’s fuller explanation is more interesting. It describes ChatGPT as a **hybrid service** which qualifies as an online search engine because it can respond to users’ prompts and queries, including by searching the web. Europe has not designated a separate product called ChatGPT Search. It has designated ChatGPT. ## How much of ChatGPT is now a search engine? The answer appears to be both broader and less absolute than the headline suggests. OpenAI reports that ChatGPT search had approximately 159.1 million average monthly active recipients in the European Union during the six months ending 31 March 2026. That is comfortably above the DSA threshold of 45 million. Search supplied the numbers. But the Commission designated the service as a whole, reasoning that ChatGPT’s ability to search the web makes it a hybrid service that qualifies as an online search engine. It also says it can investigate the functionalities behind ChatGPT and, where relevant, related systems. The designation therefore appears broader than a neat regulatory boundary around search results alone. That does not mean every ChatGPT answer has legally become a search result. It does not automatically make the OpenAI API, Codex or every other OpenAI product a VLOSE. Nor does it necessarily mean that every ChatGPT plan and function will be treated identically. The detailed designation decision has not yet been published, so the exact perimeter remains unclear. But the named service is ChatGPT, not merely its Search button. ## One product, two different logics This exposes something about ChatGPT that I had not fully accounted for. On one side, it is becoming **a mass-market information service**. It offers broad free or low-cost access, retrieves and synthesises public information, recommends options and increasingly occupies moments that previously belonged to conventional search engines. OpenAI is also developing advertising inside its Free and Go tiers. Ads have not yet been introduced generally across the European Union, but the commercial direction is visible: free access supported partly by advertising, with paid tiers remaining ad-free. On the other side, ChatGPT is **a paid professional tool**. Plus and Pro users pay for more capable personal use. Business and Enterprise customers treat it as part of their working environment, with organisational controls, connected sources and different contractual expectations. Search is available there too, but it is one capability within a much broader system. These are materially different product logics gathered under the same name and interface. One resembles a public information service funded by reach, subscriptions and potentially advertising. The other resembles professional infrastructure sold on capability, control and trust. The DSA designation did not create this structure. It has made the structure legally consequential. If the consumer information service and professional work environment genuinely form one hybrid service, regulatory scrutiny may reach across the shared systems behind them. If OpenAI considers them materially separate, it may increasingly need to define and defend that boundary. ## What has not happened Nothing in the designation says ChatGPT will be banned or stripped of features in Europe. A VPN is not a meaningful response to anything that has actually occurred. Organisations using ChatGPT have not suddenly acquired new DSA obligations either. The additional duties fall on OpenAI. Within four months, the company must comply with requirements concerning systemic risk assessment, mitigation, transparency and independent auditing. Much of that could remain behind the product. Some of it might eventually become visible. We cannot yet know. The important development is more fundamental. Europe is no longer treating ChatGPT solely as an AI system or a software tool. It is treating it as **information infrastructure with effects that need to be systematically accounted for** , including effects on minors, wellbeing, fundamental rights, political processes and public security. A few weeks ago, I wrote about how the AI Act changed while it was arriving. My conclusion was that understanding the technology increasingly requires understanding the regulatory machinery developing around it. This designation goes a step further. It has changed how I understand the product itself. Until yesterday, I saw search as an annex to the ChatGPT I actually use. Europe has effectively said that the annex is significant enough to determine the regulatory category of the building. We do not yet know what OpenAI will change, or whether European users will notice anything different in January. But I can no longer describe ChatGPT simply as a professional AI tool that happens to include search. It has become a hybrid of public information infrastructure and private working environment. That makes both the product and its regulation more difficult to separate into tidy parts.
hoeijmakers.net
September 1, 2026 at 5:47 PM
Reposted by Rob Hoeijmakers
Quantum computers still belong largely to the future. Learning how to think and work with them may have to start considerably earlier.
Learning before the quantum computer arrives
A few weeks after I started experimenting with quantum computing, I came across an article in The Quantum Record about teaching quantum computing in high school. I know its founder, James Myers, and we had already exchanged thoughts about how prepared society is for quantum computing. A few weeks earlier, I suspect I would have considered the idea premature. My own picture had already started to change. I had first become interested in quantum computing through a Dutch machine that led me to write Quantum computing is more than qubits. Then I discovered that I could already write a quantum circuit on my laptop, simulate it and send it through the cloud to an actual quantum processor. That became You can already use a quantum computer. The machines were still experimental. My access to them wasn't. When I tell people that I've been spending time on quantum computing, especially younger people, I often get the same question: why? I have been wondering about that myself. Curiosity is part of the answer. Preparedness is another. My work involves trying to understand technological change before all its consequences are obvious, and quantum computing is beginning to feel close enough that ignoring it simply because I have no immediate use for it seems an odd choice. There is something slightly uncomfortable about that answer. I don't know whether I will ever need to program a quantum computer. I don't know how important quantum computing will become to my own work. But perhaps that is precisely what makes the question interesting. When do you start learning about a technology you don't yet need? Reading about education pushed that observation one step further. If people can already begin working with quantum computing, when should they begin learning about it? ## Starting early There is an obvious objection to teaching quantum computing in schools. We don't yet have broadly useful quantum computers. The technology is developing quickly, but much of what exists today remains research infrastructure. It seems reasonable to wait until we know what we are preparing students for. The Quantum Record article approaches the problem from the other direction. Students entering secondary education today will enter university and work while quantum computing is developing. Waiting for the technology to mature may therefore mean waiting too long to build the knowledge around it. That resonated with my own small experiment. I didn't need a useful quantum computer to learn something from it. Writing even simple circuits forced me to confront concepts quite different from classical programming. Simulation made those concepts tangible, while cloud access connected them to physical machines. The educational value had arrived before the practical value of the computer. ## Looking around Once I started paying attention, I also noticed that this discussion wasn't as hypothetical as I had assumed. I came across Peter Denteneer at Leiden University, whose work brought me into the Dutch discussion around quantum education. Leiden is also involved in a broader Talent & Learning Centre for quantum technology, bringing vocational, applied and university education together with companies. Then there is Amsterdam. QDNL Amsterdam connects researchers, entrepreneurs, students and the workforce, with education explicitly part of its mission. Its Quantum Experience includes the rather wonderful question of how you actually program a quantum computer. The University of Amsterdam and CWI have QuSoft, while this summer Amsterdam hosted QSim2026, an international conference bringing together researchers working on quantum simulation. Delft showed me another part of the picture. QuTech combines research and engineering around quantum computing and the quantum internet, surrounded by a growing group of specialist companies. Its Quantum Inspire platform is particularly interesting in this context because it gives people a route to gain experience with quantum computing and actual quantum hardware. I am only touching these worlds. That is partly the point. A subject I had filed away as distant research keeps becoming more tangible whenever I touch another part of it: software, hardware, education, research communities, companies and people already thinking about what knowledge will be needed. ## Preparedness I recognise something here from artificial intelligence. For years, preparing for AI could reasonably be treated as preparation for a future technology. Then the technology crossed an awkward boundary. Organisations suddenly needed people who understood what these systems could do, how to use them and how to reason about their consequences. Building that understanding proved slower than gaining access to the technology. Quantum computing may develop very differently. The comparison only goes so far. Yet it has made me more cautious about assuming that education should follow technological maturity. There is also a broader meaning of preparedness here. A country can invest in research facilities, companies and hardware, but its ability to make something of those investments eventually **depends on people**. Some will build quantum computers. Others will develop algorithms, teach, regulate, invest, procure or decide where the technology is useful. Most will never need to understand the physics in depth, just as most people working with computers today do not understand semiconductor physics. I don't yet know what quantum education should look like, how early it should begin, or whether the examples I am finding amount to anything like a coherent response. I have barely started looking. What has changed is my sense of when those questions become relevant. I had assumed we could wait for the computers. The people building the ecosystem clearly aren't waiting.
hoeijmakers.net
September 1, 2026 at 5:50 PM
Reposted by Rob Hoeijmakers
Moving professional work into a company ChatGPT workspace looks like a migration. The harder question is whether anything arrives that outlives the person who put it there.
The Successor Test
I spent an afternoon moving my professional work out of a personal ChatGPT account into a company workspace. Durable context, active projects, the writing that sits alongside the consulting. By the end it looked like a clean migration. Then a question surfaced that I have not been able to put down. Had I moved company knowledge into the company, or had I moved my own assistant into an account the company happens to control? ## What accumulates The question only became visible because the individual difference between ChatGPT Plus and Business has narrowed. Memory, projects, connectors, cross-chat context. The two environments are now close to interchangeable. The governance line is real and worth respecting, but it is a line about where the activity happens, not about what accumulates. And accumulation is the thing that now has become valuable. Not the model. The corrections, the recurring terminology, the preferences I no longer have to restate, the connections between one project and another. Work that used to require explaining myself now starts three steps in. That accumulation makes me more effective. My company benefits from a more effective me. It does not follow that my company has learned anything. That is the distinction I had been missing. The system can make my work faster and become unusually well adapted to me without making any of that adaptation useful to the person who comes after me. Individual effectiveness and organisational memory are not the same thing. 📖 ****The successor test**** If a person leaves tomorrow, can the organisation still use what was learned through their work? If the answer is no, the person became more capable. The organisation did not. ## Retrieval got cheap Google Workspace is the comparison I keep returning to, and the reason matters. A document in a shared drive survives its author. Someone leaves, the file stays, and whoever comes next can open it. The standard objection is that nobody ever does. Folders untouched for four years, three versions of the same policy, a naming convention abandoned halfway through. That objection was correct for as long as retrieval was expensive. Finding the right document among forty thousand was harder than asking a colleague or redoing the work, so people asked, or redid it, and the drive filled up with material that was present and unreachable. The volume was the problem. That changed recently enough that most organisations still run on the old instinct. Point a model at the same forty thousand files and the volume stops being a liability. It becomes a corpus. The messy half-finished document that nobody would have found is now something a question can reach. Which turns the old advice around. There is a Dutch expression, _wie schrijft, die blijft_. Whoever writes, remains. It used to be a reminder to keep minutes so your version of events survived the meeting. It now reads more literally. Write it down and it stays reachable. Leave it in your head, or in a chat window only you can open, and it goes when you do. Almost anything beats nothing. Bad documentation is a real cost, and outdated documentation is worse than none at all, because a model will retrieve a superseded policy with the same confidence it retrieves a current one. A human digging through a folder applies suspicion. Retrieval does not. So the guideline needs a condition attached: write it down, and mark when it stopped being true. With that condition, the successor test gets easier to pass, not harder. When the bookkeeper leaves I can reconstruct how the quarterly filing was handled, and I no longer have to know where to look. **ChatGPT Business does not pass that test at all.** The company owns the workspace, the seats and the tooling. What the system has learned about how the work is actually done sits inside a relationship between one employee and a model, and when the employee goes, so does the relationship. There is no folder to point anything at. ## Handover stops at the mailbox I am not going to design the thing that fixes this. But we already have a word for it, and it is not a new one. When someone leaves a company, they are asked to do a **handover**. Not a monitoring exercise. A recognised, slightly tedious task in the last two weeks, where the departing person makes their work transferable: where the files are, which client hates being called on Fridays, what was tried in 2023 and why it failed. Nobody thinks this is surveillance. Everyone accepts it as part of leaving. Handover already covers the mailbox, the shared drive, the CRM, the running projects. It does not cover the account where a meaningful share of the thinking now happens. That is the gap. Not a missing governance layer. A missing convention, whose analogue in every other work system is boring and settled. It also answers the privacy problem. A handover is performed by the person leaving. They decide what is worth passing on, which means they also decide what stays private, and the company gets the output rather than the archive. The half-formed questions evaporate. That is not in tension with writing everything down, and it is not in tension with deliberate deletion either. You throw away the conversation precisely because you have taken out of it the part worth keeping. The awkward version is the one that makes it interesting. Handover assumes a cooperative departure. People are also dismissed, and people also die. Companies already take possession of the work mailbox in those situations without much debate, because everyone accepts that the mail was the company's work. Whether the same holds for what a model has learned about how someone worked is a question nobody has had to answer yet. It is coming. The old version of this problem had a shape. Someone knew something useful, and the work was getting it out of their head and into a format a system could hold. I have watched that problem wear different names for thirty years. Content. Information architecture. Knowledge management. Intranets, wikis, enterprise search, SharePoint in all its configurations. What is new is that the head is no longer the only place the knowledge sits. Some of it now sits in a system, in a form that is already structured, already summarised, already close to transferable. That is a better starting position than any previous generation of this problem had. For now, the handover remains manual. Someone leaving still has to look back across the work and decide what another person will need. Perhaps that is not merely a limitation of the current tools. A company should be able to keep what it has learned without automatically keeping everything an employee said while learning it. The successor test turns out to have two parts: what should survive, and who gets to decide.
hoeijmakers.net
August 9, 2026 at 9:25 AM
Reposted by Rob Hoeijmakers
The new mark for this blog began in the earth's shadow. Building it with Claude turned a private connection into a working identity, and gave the writing somewhere to go again.
What the blue leaves behind
After sunset the planet casts a shadow on its own atmosphere. A band of deep blue rises in the east, and above it sits a strip of pink. Most people walk under it twice a day without looking up. The pink is not added. It is what remains once the blue has been scattered out of the light. That became the idea behind the new mark for this blog. ## Removal The mark is that band, turned into a simple form. A shallow arch cuts a field in two, pink above, blue below, held apart by a line of paper. The pink appears through removal. Take one thing away and another becomes visible. That felt right for the work as well. Much of what I do, in writing and in consultancy, has that shape. You clear noise, reduce confusion, and the thing that matters comes forward. The form arrived quickly. What it had to do took longer to understand. ## Family Schmuki, the AI consultancy we run, uses the same grammar in a different shape. There it becomes a disc. On the blog it becomes a rounded triangle, which reads closer to an eye once the paper gap opens it up. Same grammar, different voice. That mattered because the two were already connected in practice. Schmuki works in Dutch, with organisations trying to get AI to land somewhere real. Hoeijmakers.net is where I think out loud in English, more freely and more personally. Clients read what I write here. The writing shapes the work, and the work feeds the writing. That relationship existed in my head, though nowhere else. No wordmark bridges Dutch and English. A shape does. A shared visual grammar solved something language could not. It gave the two identities a family resemblance while leaving each of them room to be itself. Browser tabs with the Brand Marks ## Matrix I had an identity. What I did not have was an online identity, which is a different object. A mark online is never one drawing. It is a matrix, and every axis multiplies the last. Size, background, light mode, dark mode, vector where possible, raster where necessary, sharp at sixteen pixels and still right at hero size. Then come the crops decided by platforms that will never consult you: square, circle, tab, chip, profile image, preview card. The same drawing does not survive all of that. Below a certain size the disc has to grow, the arch has to flatten and the gap has to widen, or the whole thing turns to mud. The mark has to be redrawn in order to look identical. Transparency needs a ruling too. I chose to keep the band inside the mark as opaque paper, so no background and no photograph ever shows through. One decision, and it then has to hold in every file that exists. Hoeijmakers.net, the systematic approach of the Brand Marks. ## Continuity Making the shape was the first half, and the shorter one. The second half was systematic treatment. Claude helped me work through dozens of variants: the arch raised, lowered, flattened, sharper, softer, point up, point down, versions I liked for a day and then abandoned. More importantly, it helped me turn a mark into a system. Every few days another slot appeared that had not been on the list. The banking app wanted a square. WhatsApp cropped tighter than I expected. An LLM showed me as a small round chip beside a citation. I had not planned for that one either. Once the core idea was there, Claude could keep going. It could help think through implementations, generate versions, check consistency, and keep extending the logic into places I would have stopped. The design did not need a flash of inspiration by that point. It needed continuity. The meaning stayed mine. The judgement stayed mine. Claude changed how far I could carry the idea into the details. ## Room What I did not expect was what finishing this would clear. An unfinished site is a quiet excuse, and I had been using it for longer than I would like to admit. When the identity is unresolved, everything around it feels provisional as well. You hesitate over the next step because the frame itself still feels temporary. Now the frame is built. The two properties know how they relate. The mark appears correctly in places I do not control. The system exists. That does not matter for its own sake. It matters because it returns my attention to the writing. Pieces I had postponed because the house was not in order have lost that excuse. The mark began with what remains when blue light is taken away. Building it had a similar effect. It cleared more space than I expected. For the first time in years, the blog feels less like something I maintain and more like somewhere I want to write.
hoeijmakers.net
August 6, 2026 at 6:11 AM
Reposted by Rob Hoeijmakers
Quantum computing still feels distant, yet anyone can already write, simulate and run simple quantum programs. The software ecosystem is arriving before the hardware matures.
You can already use a quantum computer
I came across IBM’s Qiskit almost by accident. After publishing Quantum computing is more than qubits⁠, I wanted to understand what the software layer around quantum computing actually looked like. I expected documentation, research papers and a few experimental tools. Instead, I found a development environment that anyone can download and begin exploring. Within an afternoon, I was reading about writing quantum circuits, simulating them on a laptop and submitting them through the cloud to a real quantum processor. Until then, I had never seriously considered that I might write a quantum program myself. The possibility had simply never entered my picture of where the technology stood. ## The ecosystem Like many people working in digital technology, I had quietly assumed that quantum computing remained largely confined to research laboratories. Progress was happening, but practical engagement still seemed to belong to universities and a small group of technology companies. The hardware remains experimental, while much of the surrounding software is already available. IBM’s Qiskit, Google’s Cirq, Microsoft’s Quantum Development Kit and several other frameworks give developers the tools to construct quantum circuits, test them and explore how quantum computation differs from classical computing. Many of these tools are open source, which means the first steps require curiosity and time rather than access to a specialised machine. The software ecosystem is therefore developing ahead of mature hardware. We have seen that pattern elsewhere in computing, although I had not expected to encounter it here so soon. ## Simulation What surprised me most was the role of simulation. I had assumed that a simulator was mainly a temporary substitute, useful while real quantum computers remained scarce. In practice, simulation is part of the normal development process. A quantum circuit can first be executed mathematically on an ordinary computer. This allows the programmer to inspect the circuit, test the reasoning behind it and see how an ideal quantum system would behave. Only afterwards does the circuit need to be adapted to the architecture and limitations of a particular processor. The move to real hardware is therefore less like leaving theory behind and more like introducing physical reality into an already working model. The mathematics stays the same. The conditions under which it is executed become far less forgiving. ## Reality Today’s quantum computers perform genuine quantum operations, but they remain noisy and constrained machines. Qubits lose coherence, gates introduce errors and measurements are imperfect. A circuit that behaves cleanly in a simulator may produce a much less orderly result when executed on physical hardware. For many small experiments, simulation is faster and more reliable. The value of the real machine lies in showing what the current hardware can actually reproduce, with all its architectural limits and physical imperfections. Cloud access makes this surprisingly tangible. IBM, Microsoft and Amazon all provide routes for submitting quantum programs to real processors. The machine itself may be operating in a specialised laboratory under extreme physical conditions, yet from the programmer’s perspective it appears as another computing resource reached through an online platform. ## Early access What changed for me was the sense of distance. Quantum computing still has a long way to go before it becomes broadly useful, but engagement with it no longer belongs entirely to a future generation of machines. The programming tools, simulators, learning environments and cloud platforms are already taking shape. We often imagine that a new computing platform arrives when its hardware becomes useful. Quantum computing appears to be arriving more gradually, through software and experimentation, while the machines themselves are still learning how to carry the load.
hoeijmakers.net
August 1, 2026 at 6:55 PM
Reposted by Rob Hoeijmakers
Large language models produce fluent language in seconds. Piaget helps explain why understanding still has to be constructed.
LLMs Predict Language. Humans Construct Meaning.
A social media post put Jean Piaget in front of me this week. I knew the name from education. I could not have said what a genetic epistemologist actually did. So I asked. Then I kept asking. Somewhere in that conversation, a sentence appeared that I have not been able to put down: > **LLMs predict language. Humans construct meaning.** I want to be honest about where that sentence came from. It emerged from an exchange with a machine, about a thinker I did not know, in a field I had not studied. The language arrived faster than I could absorb it: Piaget, constructivism, assimilation, accommodation, all within seconds. I could have stopped there with a page of fluent text and the feeling that I had learned something. The gap between language arriving and anything changing in me is the **meaning lag**. ## Knowledge forms Piaget spent much of his career asking how knowledge comes into being. That is close to the plain meaning of _genetic epistemology_ : genetic in the sense of genesis or development, epistemology as the study of knowledge. He studied how knowledge forms. His answer was that we interpret new experience through structures we already possess. He called that assimilation. When experience will no longer fit, the structure itself has to change. He called that accommodation. Understanding develops through the movement between the two. The example that stayed with me is a child who calls every four-legged animal a dog. Then a cat appears. The child can keep stretching the word, or reorganise the categories behind it. The new label matters less than the change in the structure underneath. I was doing the same while writing this piece. Most of the process was assimilation: fitting Piaget into what I already believed. A smaller part was accommodation. That part was slower and less comfortable, and it is the reason this piece exists. This sits close to a thread I have followed through **Bildung** : education as formation rather than the transfer of information. The traditions are different, but both direct attention towards what changes in the learner. ## Meaning lag Generating language has become cheap. Constructing meaning has not. That is the asymmetry. A model can explain, exemplify, translate and counter-argue, then do it again without tiring. The learner still has to connect the explanation to prior knowledge, notice where it conflicts, decide which distinctions matter, and revise their picture of the subject. Knowledge is not downloaded. Knowledge is constructed. An answer can be complete while my thinking remains exactly where it started. The meaning lag is not a defect in the tool. It is the shape of the work that is left. I wrote last year that search is moving from finding towards understanding. I still think conversational systems help us stay with a subject. What I had to give up is the assumption that staying with a subject is the same as being changed by it. Assimilation would have let me keep the sentence intact. ## Open questions The first concerns the systems I help build. A chatbot can answer every question smoothly and still be a poor learning environment. A plausible answer can end the exchange instead of opening it. What would it take to build a system that invites someone to formulate, test, compare and revise? Something I noticed while working with schools: the questions people type often arrive at the moment their existing understanding stops covering the situation. That is close to the boundary Piaget was describing. I can see the friction. I cannot yet see whether anything reorganised afterwards. The second concerns evidence. Education has long treated written production as proof that the intellectual work happened. That proxy is weakening. I find myself less interested in whether someone used AI than in what changed in their understanding. I cannot yet say what reliable evidence of that change looks like. Revision, explanation, judgement, the ability to notice when a convincing answer rests on a weak idea: all seem relevant. None is sufficient on its own. ## Patience I wrote once that not doing is also an act. Slowing down is not falling behind. At the time it was a working habit, a way of surviving abundance. Piaget gives it a reason. **The delay is not a preference. It is the time it takes for a structure to change.** Language can be generated almost instantly. Understanding still takes time. The model can finish the sentence. The learner still has to change.
hoeijmakers.net
August 1, 2026 at 10:46 AM
Reposted by Rob Hoeijmakers
Running AI on your own hardware sounds like freedom. The LM Studio demo at WWDC26 makes you calculate what that actually costs, and what it buys you.
The €60,000 Well
At WWDC26, LM Studio showed four Mac Studios daisy-chained together, 2TB of unified memory, running massive local language models. Someone pulled out an iPhone and chatted with those models over a secure private connection. The crowd loved it. Someone on Threads estimated the setup at €60,000. The image stuck with me. Not because I want one. Because it crystallises exactly what “AI independence” would actually take. LM Studio running massive local models on 4 connected Macs. ## Digging your own well There is a type of person who, when the tap water discussion comes up, starts calculating what it would cost to drill a well. They are not wrong to think about it. Understanding the alternative clarifies how dependent you are on the infrastructure you take for granted. But most of them do not actually dig the well. The €60,000 Mac Studio stack is the AI version of that calculation. It is useful to make it. It sharpens the mind. So let us make it properly. ## What €60,000 buys Four Mac Studio Ultra units, Thunderbolt interconnects, storage. The hardware enables models in the 400 billion parameter range, open-weight models from families like Llama, DeepSeek, Qwen, or Mistral. These are genuinely capable. On most benchmarks, the best open-weight models now trail the frontier by roughly three months, which is a smaller gap than it was a year ago. You would run them through a harness: LM Studio itself, or Ollama, or vLLM for more production-oriented setups. These are the tools that wrap the model and make it usable, the software layer between raw weights and actual conversation. The models themselves come from Hugging Face, updated by the research community, available to anyone with the hardware to run them. The electricity costs are real but not dramatic. Four Mac Studios under sustained load draw around 600 watts. At Dutch rates, heavy daily use comes to roughly €150 to €200 per month. Not nothing, but not a data centre either. ## What €60,000 does not buy This is the part the photo does not show. The model is the motor. What you experience when you use Claude, or GPT, or Gemini is not just a motor. It is the motor plus years of post-training: the instruction following, the safety calibration, the careful shaping of how the model behaves. It is infrastructure: context windows, retrieval, memory, tool integrations, the ability to search the web or read a file. It is the application layer: specialised tools like Claude Code, built on top of the model for specific workflows. And it is continuous improvement. The motor gets upgraded. Your local setup does not, unless you download and validate a new several-hundred-gigabyte file yourself. There is also the question of what open-weight models actually run on that 2TB stack. Not Claude. Not GPT-5. The open-weight frontier is impressive and improving fast, but compute at this scale is still concentrated where the training happened, not where the weights ended up. ## The ongoing cost Write-offs over three to four years. Hardware that depreciates while the field moves. Security patches, model updates, inference bugs, monitoring. You become your own IT department. Every improvement in the wider ecosystem requires your active decision to adopt it. The well metaphor extends further than it first appears. You drill it, you maintain the pump, you test the water quality yourself. Meanwhile the municipal supply quietly improves its filtration, upgrades the pressure, and starts offering mineral variants. Your independence is real. So is the maintenance contract you signed with yourself. 💡 The open-weight model gap is closing. Epoch AI estimates the best open-source models now trail frontier proprietary models by roughly three months on average. That still matters for complex reasoning and multimodal tasks. For many workloads, it does not matter at all. ## The useful question None of this means local AI has no place. For specific workloads where privacy is structural, where data cannot leave the building, where latency matters at a level cloud APIs cannot guarantee, the calculation looks different. The ICC left Microsoft 365 for exactly this kind of reasoning. Sovereignty is sometimes worth the cost. But “worth the cost” requires knowing what the cost actually is. Not just the hardware invoice. The harness work, the maintenance, the gap between what you are running and what the field has moved to by the time you have your well operational. The €60,000 photo is a useful provocation. It makes the abstraction concrete. AI independence is not a setting you enable. It is an infrastructure decision with a full cost of ownership, a capability ceiling, and a recurring obligation to keep digging. Most people will choose the tap. That is a reasonable choice, as long as it is a conscious one.
hoeijmakers.net
June 16, 2026 at 6:44 AM
Reposted by Rob Hoeijmakers
Criticising the EU's digital identity wallet for requiring an Apple or Google account mistakes the delivery mechanism for the dependency. The real question is elsewhere.
The App Store Is Not the Argument
A Threads post went quietly viral this week. It claimed that the EU’s new digital identity wallet, despite being promoted as fully independent, still requires users to have an Apple or Google account on their phone. The implication: the EU’s ambition to build sovereign digital infrastructure is undermined before it starts. It is a good-looking critique. It does not hold up. ## The delivery problem The EU Digital Identity Wallet is a smartphone app. Like every smartphone app, it arrives on your device through an app store: the App Store on iOS, Google Play on Android. Both require an account. That account belongs to Apple or Google, not to the EU. So the observation is factually correct. But the conclusion drawn from it is circular. To criticise the wallet for this, you first have to argue that people should be able to use their smartphones without an Apple or Google account. That is a legitimate debate. It touches platform monopoly, the Digital Markets Act, the degree to which mobile operating systems function as gatekeepers. But it is a debate about the phone, not about the wallet. The wallet inherits whatever dependency the device already carries. It did not create it. The analogy is awkward but exact: complaining that a Dutch government website requires internet access. ## Citizens, not consumers There is a more fundamental confusion in the critique, and it goes beyond circular reasoning. The App Store and Google Play are commercial environments. They exist to distribute software to consumers and businesses. The EUDI Wallet is civic infrastructure. It is the digital equivalent of a passport or a national ID card. The state issuing you a passport is not making a statement about the postal service, even if the envelope arrived by post. The wallet’s sovereignty claim is about the credential, not the device. The EU is asserting that a citizen’s identity, qualifications, health data, and legal documents should be portable, state-backed, and not dependent on any commercial party for their validity. That is a claim about the relationship between citizen and state. Apple and Google are simply not the relevant actors in that frame. This is a classical European institutional move: carve out a domain where citizens interact with public institutions and insist it operates under public law, not commercial logic. That the app happens to be distributed through the App Store is about as relevant as the fact that tax forms used to be printed by private printing companies. The printer is not the point. ## What is actually at stake There is a real sovereignty question buried here, and it deserves more than a Threads post. Some national implementations of the EUDI Wallet, notably Italy and France, have built in a dependency on Google’s Play Integrity API. This means the app contacts Google at runtime to verify its own integrity before it will function. That is a structural dependency on US infrastructure baked into the security model of a European identity system, and critics inside the project’s own GitHub repository have called it out forcefully. That critique lands. It is the difference between platform dependency as supply chain risk and platform dependency as deliberate architectural choice. One is the condition of operating in the current mobile ecosystem. The other is a decision that could have been made differently. The app store requirement is unavoidable given the devices most citizens actually use. The Play Integrity integration is not. One is a precondition; the other is a choice. Conflating them obscures both. ## The framing problem European digital policy initiatives attract a particular kind of criticism that holds them to a standard no single instrument could possibly meet. The wallet is not designed to solve Apple and Google’s grip on mobile distribution. It is designed to give citizens a portable, privacy-preserving credential layer that works across all 27 member states without requiring each service to build its own identity system. The sovereignty question in Europe is real and unresolved. The EuroStack ambition, the push for European cloud alternatives, the tension between regulation and building capacity: these are the coordinates of a genuine structural challenge. A critique that reduces it to “you still need an Apple account” does not advance that conversation. It performs scepticism without earning it. The wallet lands on your phone through Apple or Google because that is where your phone lives. What it does after that, and who controls the trust chain inside it, is the question worth asking. 🇪🇺 The EUDI Wallet regulation requires all EU member states to make wallets available to citizens by end of 2026. Mandatory acceptance by banks, telecoms, and other regulated sectors follows in December 2027. * * * ### A note on Play Integrity Some readers may wonder why this concern applies primarily to Android. The answer lies in the structure of the ecosystem itself. Apple's iOS platform is already vertically integrated. Apple controls the hardware, operating system, app distribution, and security model. An identity wallet running on iPhone inevitably operates within that framework. Android is different. A wallet can be distributed through Google Play, Samsung Galaxy Store, enterprise channels, alternative app stores, or direct installation. Google's Play Integrity API effectively introduces Google as a trust anchor inside that more diverse ecosystem by allowing apps to ask Google whether a device and app installation should be considered trustworthy. The controversy is therefore not that Google provides a security service. It is that a European public identity system may come to depend on Google's judgement about what constitutes a legitimate Android device. For critics concerned with digital sovereignty, that is a different question from simply downloading an app through Google Play.
hoeijmakers.net
June 11, 2026 at 1:31 PM
Reposted by Rob Hoeijmakers
Yesterday I was using Fable 5. Today it's gone. The US government's export control directive on Anthropic's models is the first time I've felt AI dependency as something physical.
Fable 5 Is Gone. The Switch Was Always There.
Yesterday I was using it. Today there is a message where the model used to be: "Fable 5 is temporarily unavailable." Fable 5, Currently unavailable That is how it happens. Not gradually, not with warning. At 5:21 PM Eastern on June 12, the US Commerce Department sent Anthropic a letter. By evening, Anthropic had disabled access to Fable 5 and Mythos 5 for all customers globally: the first time a leading AI company has taken a publicly deployed model offline due to intervention from the federal government. I have been on the web since the mid-nineties. The internet has always been porous, unruly, structurally resistant to central control. You could always reach something. This felt different. A switch, thrown from Washington, and the model is simply gone. ## What actually happened The US government issued an Export Control Directive, a legal order that restricts or suspends the transfer of specific products, data, or technologies to foreign countries or citizens of another country. The stated concern: a jailbreaking method for Fable 5. Anthropic reviewed the demonstration and found only a small number of previously known, minor vulnerabilities, all relatively simple, and all discoverable using other publicly available models without requiring any bypass. Anthropic called this a misunderstanding and said it would share more details within 24 hours. It is complying while disagreeing, which is the only available position when a government order arrives with legal force and no room for negotiation. To the best of available knowledge, this is the first time the United States has issued an export control directive for LLM access. The directive affects not only the US's closest allies but their nationals as well, regardless of where they happen to be. ## The personal register What surprised me was not the fact of it. I had already written, in a different context, about what happens when AI access breaks or gets cut off and listed a geopolitical rupture placing European businesses on the wrong side of US export controls as one of the non-exotic failure modes. The argument was there. The scenario was there. But knowing the argument and feeling the consequence are different experiences. I was using Fable 5 for client work. Then I wasn't. The intellectual case for sovereignty became, for a moment, a practical inconvenience. That gap, between the abstract and the operational, is where most organisations still live. ## Where it goes Whether this is temporary or precedent-setting is not yet clear. Anthropic believes it is a misunderstanding and is working to restore access. That may happen. Or it may not. What is clear is the structure underneath: the model runs in the US, the company answers to US law, and US export controls have always been able to reach foreign nationals. AI models are now, apparently, within scope. This is what I had in mind when I wrote about Lidl of all companies building its own cloud platform as a signal of where serious organisations are heading: not ideology, but a practical calculation about what you control and what you don't. The question for the rest of us is whether an event like this actually changes the calculation. Or whether, once Fable 5 is back, we return to exactly where we were.
hoeijmakers.net
June 13, 2026 at 8:49 AM
Reposted by Rob Hoeijmakers
The Netherlands built its first computer in Amsterdam in 1952, moved the thinking to Eindhoven, and produced ASML. That line is history. It is also a blueprint.
The Axis That Made the Chips
In the summer of 1952, the first Dutch computer was switched on at the Mathematisch Centrum in Amsterdam. It filled an entire classroom. It was built from 1,200 relay switches and could store about 30 bits of information. At its launch it worked once, briefly, and was then taken out of commission. It was called the ARRA, short for Automatische Relais Rekenmachine Amsterdam. Its builders, Carel Scholten and Bram Loopstra, immediately started over. The ARRA II worked. And that same year, the Mathematisch Centrum hired a young programmer named Edsger Dijkstra. Edsger Dijkstra (left), Bram Loopstra and Ria Debets at the Mathematisch Centrum in Amsterdam (1954). ## Amsterdam Dijkstra spent the first decade of his career at the Mathematisch Centrum. In 1956, sitting in a cafe in Amsterdam without pen or paper, he worked out a solution to the **shortest path problem** in about twenty minutes. He published it three years later. It is now used in every navigation system on the planet. In 1960, together with Jaap Zonneveld, he completed the first working compiler for **ALGOL 60** , beating every other team in the world by more than a year. The Mathematisch Centrum was also, that same year, the institution from which Electrologica was spun off: the first Dutch computer manufacturer, building the X1 and later the X8 in Rijswijk. The thinking and the making were already connected, even before Dijkstra moved south. ## Eindhoven In 1962 he joined the Mathematics Department at the **Technische Hogeschool Eindhoven**. There he built an operating system for the Electrologica X8. The system was called THE, simply the initials of the university. He never chose the name deliberately. THE was built by six people, working half-time. Its architecture was organised into six strict hierarchical layers, each able to use only the functionality of the layers beneath it. Processes were coordinated using semaphores, a synchronisation primitive Dijkstra had also invented. The paper appeared in Communications of the ACM in 1968, won the ACM Programming Systems and Languages Award in 1971, and is still read in computer science courses today. The following year, Dijkstra received the Turing Award, computing's highest honour, for his contributions to structured programming. What THE demonstrated was that structure is not a constraint on ambition. It is what makes ambition hold. That logic has not aged: the systems that compound are the ones built with intention from the start. ## From Rijswijk to Veldhoven The people who built the ARRA and the X8 did not disappear when those machines did. Loopstra moved to Electrologica and later to Philips. Scholten did the same. The knowledge migrated into the industrial infrastructure of the Eindhoven region. Philips was already there. From Philips, in 1984, came ASML, starting in a leaky shed, building lithography machines. ASML now makes the only equipment capable of producing the world's most advanced chips. Every leading chipmaker depends on it. That continuity is not coincidental. It is what happens when theoretical rigour and a culture of making occupy the same small country for long enough. ## Why this is not just history Amsterdam and Eindhoven are in conversation again about working more closely on technology. The framing is **AI, talent, and infrastructure**. That framing is right. But the historical depth is worth holding on to, because it clarifies what the axis actually produces. The Netherlands has theoretical institutions of real quality. It has the most critical piece of hardware infrastructure in the global semiconductor industry. It has a tradition, visible from the ARRA to THE to ASML, of building things that matter from first principles, with limited resources, and getting them right. Europe is searching for this combination. The question of whether good ideas have somewhere to live, somewhere to scale, is unresolved. The Dutch answer to that question is already seventy years old. It is worth reading carefully.
hoeijmakers.net
May 26, 2026 at 6:49 AM
Reposted by Rob Hoeijmakers
Passkeys fix the weakest part of authentication. But they hand your credentials to Apple, Google, or Microsoft and the session cookie problem remains untouched.
Passkeys: Better Lock, Borrowed Door
I wrote about passkeys in early 2024 with some optimism. The technology is elegant. The problem it solves is real. I still think both those things. But I left something out. ## What passkeys actually fix The password is a structural failure. It is a secret you have to remember, type, transmit, and trust a server to store correctly. Any one of those steps can go wrong, and the weakest one determines your security. Phishing works because passwords travel. Data breaches work because servers collect them. Credential stuffing works because people reuse them. A passkey replaces all of that with a cryptographic key pair. Your device holds the private key. The service holds the public key. When you authenticate, your device signs a challenge; the server verifies the signature. Nothing is transmitted that could be intercepted or stolen. I wrote about making that transition in early 2024, and the improvement was real. It is not marketing. Back in 2022, when passkeys were still theoretical, I noted the convenience problem: helping a six- or eighty-year-old through a QR-code flow would be a challenge. What I did not see then was the deeper problem that convenience would bring with it. ## The key card stays the same Here is what does not change. Once you are through the lobby, the server hands you a session cookie: a small text file that carries your authenticated state from that point on. The elaborate verification at the front door collapses into a string of characters sitting in your browser. Copy that cookie and you are in, from anywhere, as anyone. The key card problem is untouched by how you checked in. Passkeys make the lobby better. They do not change what happens after it. ## The dependency There is a more fundamental issue. Passkeys do not live in your head, and they do not live on a neutral device. They live in a keychain: Apple's, Google's, or Microsoft's. That is where they are stored, and that is where they sync. The sync is not optional. Use more than one device and you need it. Switch from iPhone to Android and your passkeys stay behind. Add a Windows machine to an Apple setup and you are managing two separate ecosystems, each with its own rules. The line between digital convenience and infrastructural dependency is vanishingly thin -- and you have crossed it the moment you need your credentials on a second device. This is a structural dependency, not a technical inconvenience. The platform controls your credentials. If you leave, you lose them. If you are locked out, you lose them. If the platform changes its policies, you are subject to those changes. I experienced a version of this when X locked me out last year: the burden of proof shifts to you, the process is opaque, and there is no neutral party to appeal to. With passkeys, the stakes are higher. It is not one platform. It is your authentication infrastructure. ## A different kind of lock-in With passwords, the risk was theft. With passkeys, the risk is captivity. These are not equivalent problems, and the second one is quieter. Most users will not notice. The experience is genuinely better: a biometric check, no password to forget, no phishing surface. The dependency is invisible until it is not. That is how the best lock-ins work. Europe is working on a different answer, one built on the premise that digital identity should not be owned by a platform. That is a longer conversation. But it starts from exactly the right diagnosis: the front door matters, and so does who holds the key. 🔐 ****Passkeys**** are supported by Apple, Google, and Microsoft through their respective keychain and credential manager products. Cross-platform sync between ecosystems is not natively supported – moving between platforms requires manual credential migration or re-registration with each service.
hoeijmakers.net
May 25, 2026 at 9:39 AM
Reposted by Rob Hoeijmakers
After the password, the session takes over. It doesn't know who's holding it.
The Session Unlocks the Door. For Anyone.
A few weeks ago I ran a command that made me stop. I was downloading a video using yt-dlp, a command-line tool, and instead of logging in I passed a single flag: `--cookies-from-browser chrome`. The tool reached into my browser, borrowed my active session, and acted as me. The platform never noticed the difference. That flag is a small thing. But it points at something large. ## Three things, not one Most people experience logging in as a single ritual. You open a site, you prove who you are, you are in. But there are actually three distinct layers, and conflating them is how the weak spot stays hidden. The first is the account: your identity registered in a system. Creating one is often deliberately friction-heavy — email verification, phone numbers, sometimes document checks. That friction is intentional. The account is meant to mean something. The second is authentication: proving, each time, that you are the account holder. A password, a code sent to your phone, a biometric scan. This is the gate ritual, and it is where the industry puts most of its visible effort. The third is the session cookie: the lightweight token the service issues once you have passed the gate. From that point on, the cookie does the work. You stop re-proving yourself at every door. The cookie says: this person already checked in. ## The key card Think of checking into a hotel. You book a room, you show your passport at reception, and then you get a key card. From that point on, the card does the work. It opens your room, the gym, the parking barrier. Nobody asks for your passport again until checkout. The elaborate front-desk ritual gives you a sense of security. But what actually carries you through the building is a small piece of plastic with a magnetic stripe. Session cookies work the same way. You create an account, you authenticate, and the service issues a token. That token is your key card. And here is what I did not fully appreciate until recently: that card often sits as a plain file on your disk, accessible to any tool running on your machine. yt-dlp did not break into anything. It just picked up the key card I had left on the table. 🍪 Session cookies are stored locally by your browser. On most systems, tools with user-level access can read them without elevated permissions. Logging out of a service invalidates the server-side session, which is one reason it matters more than just closing the tab. ## The asymmetry Platforms invest heavily in the gate. Two-factor authentication, device recognition, login anomaly detection. The entry experience has become genuinely robust. But once the cookie is issued, many platforms let it run for weeks or months. Some bind it to a domain, few bind it to a specific device or IP address. That is the delegation problem stated differently: authentication systems were built around a single person at a single keyboard. The session token they produce was never designed to be transferred, borrowed, or held by an automated tool. Yet that is exactly what is happening, quietly, every time a CLI tool, a script, or an AI agent acts on your behalf using credentials you already established. ## What this changes For me, this sharpened two things. The first is personal. I feel less secure online than I did before understanding this. Not because anything has changed in the world, but because I now see where the actual surface area is. The gate is solid. The key card is lying on the table. The second is professional. Delegation across digital systems has always seemed technically hard. Giving an AI agent or a colleague selective access to act on your behalf without sharing your credentials felt like a problem requiring elaborate infrastructure. It still does, done properly. But the session cookie shows that a cruder form of delegation is already available, already working, and mostly invisible. That is not reassuring. It is clarifying. The elaborate check-in was never the whole story. It was the part we were meant to notice.
hoeijmakers.net
May 24, 2026 at 8:17 AM
Reposted by Rob Hoeijmakers
RSS was built for human readers who wanted control. It turns out that description fits AI crawlers perfectly. The format found a second life it never asked for.
RSS is not dead. It just changed audience.
My RSS feed gets more traffic than my homepage. Not from subscribers with a feed reader open on a Sunday morning. From machines. RSS, Really Simple Syndication, is the quiet pipe that lets you follow a website without visiting it. Old technology, XML-based, pre-social-media, designed in an era when "web application" meant a browser and a human. Publishers quietly stopped promoting it. Google Reader closed. The format seemed to be fading into dignified retirement: still useful, still honest, increasingly invisible. Then AI happened to the web. ## The machine-readable web AI crawlers, large language model pipelines, retrieval systems: these are the readers that now constitute the majority of requests on many independent sites. I can see this in my own logs. Human visitors with a browser are, depending on the day, somewhere between ten and twenty percent of total traffic. The rest is automation of one kind or another. For these systems, RSS is not a legacy format. It is a clean, structured, semantically coherent signal that something new is available. No JavaScript. No cookie banners. No layout to parse. Just content, metadata, and a timestamp. From a machine's perspective, RSS is better than a homepage. ℹ️ RSS is XML-based. Each entry contains a title, link, publication date, and usually a summary or full content. Feed readers and bots alike use it to check for updates without crawling a full site. Here you can view traffic like RSS Readers on this site. ## The publisher's dilemma Publishers always had complicated feelings about RSS. The feed hands content directly to whoever asks: no analytics, no ad impressions, no engagement loop. The reader is in control. The publisher loses the visit. That tension never resolved; it just became less urgent as social platforms took over distribution. Now the machines have arrived with the same expectation. Structured access, no friction, no visit required. The format designed to empower human readers turns out to be exactly what machine readers need. The audience changed. The value proposition did not. ## The human case, still I use Reeder. Have for a while. It is one of those apps that works so well it stops drawing attention to itself: feeds come in, I read what matters, I close it. No algorithm deciding what I see next. Just a chronological list of things people I chose to follow decided to publish. That experience is worth naming because it is genuinely different from how most content reaches people now. Slower, more selective, harder to game. ## A second youth The revival of RSS was not planned by anyone. It followed from two pressures arriving at the same moment: the platformization of everything, which made owning your own distribution feel more urgent, and the AI turn, which made structured content feeds useful again for entirely non-human reasons. For a format to find a second life, it usually needs to solve a new problem. RSS solved the same problem it always solved. The problem just acquired a new population. That is worth paying attention to. Not because RSS is exciting, but because formats built around clarity and structure tend to survive. Clarity is useful. To humans on a Sunday morning, and apparently to machines at any hour.
hoeijmakers.net
May 15, 2026 at 7:19 PM
Reposted by Rob Hoeijmakers
Menselijke bezoekers zijn nog maar een fractie van wie je content consumeert. De rest is onzichtbaar, maar niet ongrijpbaar. Een oud formaat speelt verrassend genoeg een sleutelrol.
Je bereik is groter dan je denkt. Je ziet het alleen niet.
Stel je opent je analytics en ziet tienduizend pageviews. Goed gevoel. Maar wat als die tienduizend maar een fractie is van wat er werkelijk gebeurt, en de rest zich buiten je dashboard afspeelt? Dat is geen hypothese. Het is wat ik zie in mijn eigen logs. ## Onzichtbaar verkeer Menselijke bezoekers met een browser zijn op een gemiddelde dag rond de tien procent van mijn totale verkeer. De rest is een mix van indexering, geautomatiseerde retrieval en AI-gedreven toegang. Wanneer iemand een AI-assistent een vraag stelt, gaat dat systeem vaak in real time op zoek naar actuele informatie. Het bezoekt je site, leest je content, en verdwijnt weer. Geen sessie in Analytics. Geen bounce rate. Niets. Je bereik is dus veel groter dan je denkt. Maar ook veel minder transparant. ## De onverwachte held En dan komt RSS om de hoek. **Really Simple Syndication** , een formaat uit de begintijd van het web, dat de meeste mensen hadden afgeschreven toen Google Reader in 2013 sloot. Geen JavaScript. Geen opmaak. Gewoon inhoud, metadata en een tijdstempel, netjes verpakt in een gestructureerd bestand. Precies wat een AI-systeem zoekt. RSS was ontworpen voor mensen die controle wilden over wat ze lazen, zonder een website te hoeven bezoeken. Het blijkt dat geautomatiseerde systemen precies hetzelfde willen, om precies dezelfde redenen. De feedreader van 2005 en de AI-assistent van 2025 stellen identieke eisen aan een inhoudsstroom: gestructureerd, actueel, zonder ruis. Een goed onderhouden RSS-feed maakt je content vindbaar en bruikbaar voor deze nieuwe generatie lezers. Zonder nieuwe technologie. Het formaat was er al. ⚠️ RSS is XML-gebaseerd. Elke entry bevat een titel, link, publicatiedatum en meestal een samenvatting of volledige inhoud. Controleer of jouw website of blog een actieve RSS-feed heeft, de meeste platformen genereren die automatisch. ## Grip op het onzichtbare RSS staat niet alleen. Markdown, llms.txt, gestructureerde metadata: het zijn stille schakels in een infrastructuur die je bereik bepaalt zonder dat je het ziet. De meeste ondernemers denken aan SEO als ze aan vindbaarheid denken. Maar vindbaarheid verschuift. Zoekmachines worden gesprekspartners. Indexering wordt retrieval. Wie daar grip op wil houden, begint verrassend genoeg bij de oudste gereedschappen. Niet omdat ze nostalgisch zijn, maar omdat ze precies goed genoeg zijn voor wat er nu van ze gevraagd wordt. SPONSORED Hiveminds Lens analyseert hoe zichtbaar je bedrijf is in ChatGPT, Claude, Google Gemini en Perplexity. We testen relevante prompts, vergelijken je met concurrenten en laten zien welke technische, content- en authority-signalen ontbreken. Gratis snapshot
www.chatvoorbedrijven.nl
May 15, 2026 at 5:00 PM