Cassie Jiun Seo – Curating Power: FOSS in the Service of National Interests #FOSSBack
About this talk
This talk focuses on the concept of curated power, exploring how nation-states influence and shape open digital infrastructure. The speaker, who is affiliated with the World Health Organization and has a background in digital health and open source initiatives, discusses the emerging concept of digital sovereignty. The presentation delves into the ways governments are not only regulating technology but are also engaging in the development and export of their own digital infrastructure. It highlights the increasing connection between cybersecurity and national security, and how this affects data governance. The speaker also examines various models and strategies for digital sovereignty, including investment policies and the role of international relations theory, particularly focusing on the balance between cooperation and competition among countries. The significance of open data, open source, and the evolving rhetoric around digital sovereignty frameworks are also addressed in this context.
Full transcript
Well, thank you so much for being here and choosing me as your late afternoon activity. It's all called curating power. How states like and here I meant nation states shape open digital infrastructure as like texts and like we will get more into that. Uh first like very like quickly about me. Um so I work at like World Health Organization on like digital health related initiative and then
like opensource uh related work. Um happy to like talk about that but also important to like clarify here on an like independent capacity and then uh this and then but just a little bit more about like my background and how I have come to be engaged with this topic like about like sovereignity and with like different nation states. Um also as part of my work at the
World Health Organization a member of like open source united so it's a community of practice of uh different people who do open source um in the UN system where I was leading um the licensing work for the like different UN agencies and giving advice and um gave input on the policy. And then another hat I wear is that I've been a research affiliate at Menu Center for
Technology and Democracy at University of Cambridge. Um but all of that my like uh core interest has always been in like uh public interest technology in different like domains. Um and important to say that this uh presentation was from the research that like was like originated in like support of MCTD and University of Cambridge with like my collaborators um mainly SA Kosman and uh Timothy Chartan. So
just like a bit of a sin setting um it's it's uh there's this like term called securitization and then um what's happening is like a lot of governments are not just like regulating tech platforms or technology but they're increasingly doing other things like uh which includes um building and like exporting digital infrastructure themselves. And of course like a lot of this infrastructure rely heavily on like everything
like sometimes open data sometimes like software sometimes standards sometimes like community itself and then and then um more and more like we are seeing that uh they link like cyber security and like national security related issues and then like data governance and control that's where we see different like data residency legislations and such and then like economic competitiveness and like many other factors and then um it's
true that this has become bit more pronounced like recently and then in my presentation I will like go into different like flavors of digital sovereignity from let's say like leading powers as well as like middle powers and then such um but would love to hear people's input and then um with that like of course like uh there has and changing rhetorics of false like mostly from the
public and like nation states uh perspective. So initially like uh it's what um many of us like know about like open source as like free um civic infrastructure of collaboration. So like the what we know about and I think what many of us are like here for like originally anchored in like community ethics like autonomy and and then um and then like there has been a different
rhetoric in framing false as a like dependable critical infrastructure of internet. Um and if we were at a talk earlier today uh given by Mirao Boom um on the like could we buy digital sovereignity I found that like really interesting when he talked about in like 2005 like corporate it's like started getting into that and then I would say like yeah that's how it kind like that's
very aligned with my analysis like it was initially like seen as the critical infrastructure and then different governments started uh getting into that like mostly uh with money like um funding certain vulnerability patches and such uh and and that's how that was like started to be seen like uh oh it's like roads and bridges that like government is using public funding to support and then um most
recently like we see more and more like open source as sovereignity like I see quite a number of presentations s like that did talk about sovereignity like measuring sovereignity like purchasing sovereignity like uh participating in sovereignity like digital sovereignity. So now the nation states adopt like open source um as like a means of control or um or like what I used earlier like securityize it. So and
then there's of course like many different like layers of that. I wouldn't like go into that but happy to like hear your inputs and experience and like all that as well. So that's like bit of the sin setting and like yeah and then like different um realities with like open source. So there's like open source and then there's corporate control or corporate like influences. That's what u
Miracle and I think many of us do know like know from like the mid 2000s like 2005ish when um corporates like started asserting more control like whether that's through money that's through like governance and such and then a bit later what like Miracle mentions as like governments had woke up um there had been like a different like governmental influence as well and then that was the much
of like basis of my research. I haven't like looked a lot where I would love to map it. Um but not like with the resource and time that I had but was like more into governments. Um and then there are of course uh different like policies like sometimes like investment policy, sometimes like industrial policy which like also governs um how governments or how public sector bodies can
procure and then like a lot about like security policy and like foreign and then another like interesting thing was uh what we call like ODA overseas development aid. Um and like one thing like that um got me very like what initially like sparked this whole research for me was I was at like one public um like discourse called um like global solutions initiative in like 2023 or
so. And then like uh and then there were some people from like Latin America speaking about like digital public infrastructure before like that was a more used term and then they asked um no it was like 2024 and then uh at that time um the like German consul was there and then they like asked him um like all of us actually have a SEC as like part
of our national like infrastructure. Why doesn't Germany have this? And then I thought like, okay, that's very interesting. How does like Argentina, Brazil, like all of them have this? And then um and then I started like looking at their um some of their like legislations like what allows them and then like what's embedded in their like constitutional philosophy that like makes the government like invest in secen
and then actually like talk about it in this like diplomatic fora. So that's how like it had initially started and then and then um looking for different like evidence to analyze like which is usually like policy documents. Um and then I think we have to like talk bit about like the emergence of digital sovereignity. I think many people like did talk about their definition of it or
like how it looks or how we might like secure it. Um but I do think it's important I'll like add just a little bit of like academic um flavor to it a lot from like sovereignity in like international relations and political science. It is a term already and then so and then the digital sovereignity itself like it it's uh first like originated in China in the 1990s.
>> Yeah. Um and and then um yeah and then and even before for about like 40 years they have been like working on the building like Chinese internet or Chinese like information infrastructure or like the national modernization project like that's what it was initially under and then um many of us like do know about like great firewall or like or like internet plus um much of it
is the government tech initiative and then um if anyone's like interested inviting them to at least like Google translate the Chinese internet rule by law development it's not like rule of law it's rule by law like if you were to translate it report it's just from like 2024 so it does talk about what the government there is doing to um apply rule tools to for this like
digital sovereignity and then from like 2019ish it was like uh popularized again in like EU I mean not again in EU circles I did a very quick like uh document like archival like uh analysis and then just like went to EU lex so that's a um EU like open data platform for um legislative documents basically archive and then just did a quick search on like by year
like how many times digital digital sovereignity like popped up and then it started at around like 2019 and then picked in 2023 and then so it's like a normalization of the term so to say and um again like I quickly like added a bit more thing like so the in international relations like there is a conundrum what they call like realism versus like liberalism. There we go.
Yeah, thank you. Um, yeah, in like international relations, there is this like conundrum that's always there, which is realism versus like liberalism, which is like countries have to and need to cooperate for like global good. Um but the traditional like international relations theory it's that like self-interested actors cooperate where mutually assured destruction are assured and then I was like when I um heard like Merkel's talk on
like okay in open source mostly for corporates like we were always thinking about okay what's the area that that's going to be competitive zone and what's the area that's going to be collaborative zone and I was like oh wow like This is actually very much in line with how the the theory of international relations has been and how states like cooperate or compete in in what area.
So it's like it's basically like having to choose that and so I don't know how many people were like thinking about that. And then if anyone likes to nerd out, there's like a lot of literature on like power and independence like weaponized interdependence and also like limiting structural exposure to other like members. And then um of course there's like uh literature on like multipolarity also very interesting
for digital sovereignity which is like acknowledging that there's always like rising middle powers um in the middle of like very complex like interdependence in like and then yeah like uh had to put together different like variations or flavors of digital sovereignity. the um and then the recent like AI summit in India has been like a gold for like researchers because many people say like uh quite um
like um like pointed things and it's like wow like is this person for real like as an like you know anthropologist as a like social scientist I was like wow is this real? So first um was uh Michael Kraios uh who was the lead of US delegation to the AI summit India like the director of science technology policy at the white house um where he he's like
stressing that like sovereignity here AI sovereignity means like owning and using best-in-class technology for the benefit of your people and charting your national destiny in the midst of global transformations. if like anyone needs to find like source for this like uh um statement like it's also in the white house like official like after summit statements as well. So if anyone like like find out like is this
person for real like is this really what this person defi like or this entity defines like sovereignity it's like yes there's a lot of um sources to go from and then there's the prime minister like Narendra Modi um and then this was actually at the fintech fest like global fintech fest in like Mumbai in October 2025 and then in here like he is addressing to um car
sturmer who was there as well as the as well as the like royal bank of India governors as well as the general audience. So I think that's also very important where he talks about India's tech and like lists them and then saying that this this ST like we're helping other countries to share develop technology this is not digital aid but empowerment and then um yeah and then
more like the more previous examples um from the Changlu Wang like Huawei uh executive like now he had left but Then this was from like Huawei developer conference in August 2019 also when they like really when they like spoke about like a very publicly about Harmony OS at that time and then here like does talk about like specifically about like open source community to maintain and manage
um it will be like very vulnerable to uncontrollable external vectors and then of course like Angela Merkel like this was like July 2020 and her speech to the European Parliament as like a part of German like presidency to the Council of Europe. Um and then I thought that was interesting because this is where the digital sovereignity concept had like emerged a much earlier than like uh than
we had uh focused and like started like talking about. So this is like changing all the time especially after the summit like my thoughts changed a little bit but like overall um US like traditionally framed sovereignity as like supply chain control like sanctions um and then like security and like market dominance. Um and then India they were very big on like open standards as like export of
digital public infrastructure and then um China they like in many other statement there's always been like emphasis on like self-reliance um and then jurisdictional control and then like EU there's always like uh mention of um EU values and like openness And I think many people like also in this conference try to figure out like what that practically meant that like openness. So that's just like different flavors
of it and I will just like quickly like skip some things um because I see that we have limited time and then so so I applied like a concept called like a stack curation which does come from like art history or like um more anthropological um studies as in like this is a very intentional assembly of putting things together like starting from like selection to like integration
And then like application of governance and then like circulation of certain technology and then as you as a nation state does this the dependency from other actors and also like inside that nation state like a constituents like grow. Um and then this is a ongoing like topology of how certain like curation modalities like look like sometimes it's through like narrative framing. So it's like rebranding or communicating
certain like stacks or certain technology as like sovereign secure or open. I think all many of us like did also talk about like open washing or open um or like a sovereignity washing like some of them are real like and then like some of them are like depends on how you look at it and then like certain examples and then another modality that I have seen was
through like standardization like a making something a normative uh and then another were like through investment as in Um and then like much of it was like bit more structural technical and like dependency management where um nation state entities basically like fund for like long-term maintenance and dependency management like life cycle governance of this and then and I believe I don't know if we have any people
from like sovereign tech agency like that's I think an example many people know but I am like well uh like like previously um this was like one of the largest public private partnership from the US government like the biggest like money that had ever gone into that like uh vulnerability patching from like the most widely used open source like projects and then there's like gatekeeping um which
is like uh regulating who can participate and and then I think like we have seen certain um companies or certain like act actors from certain like nation states and like controversies on whether they can like participate in certain like open source projects and then another were like export control uh for example from the US government on like sanctions and and then um so it it's like often
like listed as the dual use or like crypto like dual use technologies are almost always like listed as like sanctioned um items and then it's like okay how do you know that it's a dual use and then they have a whole like cate like a list and then one is like okay if it's like has a cryptographic functionality it is so it's like okay so almost everything
basically is uh it's basically like sanctioned so I like looked up their like uh the sanctioned like list so for example like Python is uh like uh EC00003 like listed there. So okay so if some if I want to export open source software that written or that has some component like written in Python uh I do have to it is like sanctioned basically and then others were
like patronage and then like domestication of it. Um patronage is when the the open source project is uh linked with um with the with like um overseas like development and such like as we saw from the what like uh Indian like Prime Minister Modi had like discussed and I want to quickly wrap up like where I had like different um case studies of uh where this like
had had like uh happened. Um, one was from like international development from like this initiative called PEPAR and DHIS2 where um, it's a like a very widely used open source project where um, but then how this was popularized and how this was widely rolled out um, did affect a lot of nation state like health systems how they set up what we call like indicators like what data
they collect and then how this gets reported up um towards like another nation state in this case the US government who was funding a lot of it and then another um very quick example was like government open data like another type of research I was doing was the South Korean like public data portals. So notable to mention is that um basically the government there like runs or
manages the very uh very detailed public data portal and then and then like it's like pseudonymized. Um and then basically like secondary data usage is allowed as long as it's like pseudonymized and then there is a like government agency like interoperability act. So basically every transaction and all data that a constituent have with the government is recorded like every prescription that they have ever received or every
like immunization to every like school that they had ever attended and such. And then like we were seeing that and uh this is still in development the national data library in the UK. And then I was like uh kind of mapping um what they like how how is their governing philosophy translated in this how they run this open data portals and then like uh what are the
secondary data usage permissions that's like given. So that's the gist of it. Um and then like implications for this. I basically wanted the like of us to um like cuz I think a lot of us will have this conversation about like sovereignity one way or the other. And then um I really wanted the community to one like think of uh can this like top down curation be
resisted and then also if we can what are the leverages that we can use um and then the reason why I like tried to put the um like taxonomy together was okay so we have the language at least like when our projects or when certain projects are being used certain way like at least know that okay this is like a framing it a certain way. Um so
yeah that's the implications and with like very limited time I'm open for any questions or comments or reactions and I'll also be around. Thanks Ky for your talk.
More from this event
See all 47 talks →
Seyi Kuforiji – Bridging the Gap: Encouraging African Talent to Open Source #FOSSBack
23:57
Educating the next generation of open source contributors #FOSSBack
36:35
Jan Dittrich – Best practices and (very) small projects #FOSSBack
24:03
Johannes Näder – Let’s tackle Openwashing! #FOSSBack
24:58