Decent Infrastructure in an Authoritarian World · Part I — Where We Are

/ 02 /The World has Changed

Since Holo issued its original Green Paper in 2017, the scale, complexity, and cost of the challenges we collectively face have all sharply accelerated.

What hasn’t changed is the techno-utopian view increasingly held by state, civil society, and corporate actors alike — always looking for the next silver bullet they hope will unravel the harms of the previous generation of techno-utopianism, only to further compound them.

And now we have the combined promise and threat of AI, where we’ve got one foot pressed firmly on the brake, while the other is pedal to the metal. The sovereign AI debate in 2026 has governments and enterprises racing to control their own stacks. But “sovereign AI” as currently defined means sovereignty at the level of the nation or the corporation. It replaces one centre with another. Few are seeking to answer the more difficult question of what sovereignty looks like at the level of the individual entity — the person, the community, the small business — that actually generates the data.

The security implications are worse than most of the industry acknowledges. Companies deploying AI agents across their operations are concentrating their organisational data and intelligence behind a single security perimeter. CyberArk estimates that machine identities already outnumber human employees by 82 to 1 in enterprise environments.21 One breach doesn’t get you one person’s email. It potentially cracks open the entire organisation.

This is not hypothetical. This is the architecture companies are building right now, as fast as they can.

Open-source models don’t fix this. Granted, they solve the access problem; anyone can run the model. What they don’t solve is the infrastructure problem. An unlocked model with total access to everything — running on a network never designed to defend against internal threats, in a world where autonomous agents now expand that internal attack surface — is a powerful AI holding the keys to your operational life, on infrastructure that may not survive the next five years of cryptographic reality.

Because regardless of what AI and security professionals may say about how “easy” it is to protect oneself, the quantum horizon makes all of it worse. “Harvest now, decrypt later” (HNDL) — collecting encrypted data today, and storing it until quantum computers can break the encryption — is already happening. The U.S. Federal Reserve published a paper in September 2025 analysing HNDL risks specifically for distributed ledger networks, concluding that data privacy of previously recorded transactions remains permanently vulnerable because an adversary can copy the ledger and wait.22 Blockchains put every transaction on one global ledger — one target. Centralised AI infrastructure puts an organisation’s operational intelligence behind encryption that has a shelf life. Corporate data doesn’t expire, and may become more valuable to an adversary five years from now than it is today.

Meanwhile, regulation is catching up with innovation. The EU AI Act’s transparency obligations took effect on 2 August 2026 — disclosure, content marking, provenance — with the high-risk regime to follow from December 2027; at the top end, non-compliance carries fines of up to €35 million or 7% of global turnover.23 MiCA’s grandfathering expired across the EU on 1 July 2026; any crypto-asset service provider still serving EU clients without authorisation is now operating in breach.24 The CLARITY Act is advancing in the United States. Thousands of AI ventures face a compliance reckoning because the infrastructure they built on was never designed to provide the accountability that a growing number of jurisdictions now demand.

And governments are making the same argument with procurement decisions. On 8 April 2026, France ordered every ministry to eliminate extra-European digital dependencies by autumn, including operating systems, collaborative tools, cloud, and AI platforms.25 Germany is migrating government workstations.26 Austria’s military is dropping Microsoft Office.27 These are not fringe positions. They are governments concluding, publicly, that infrastructure dependency is a strategic vulnerability. The European Commission’s own officials have said as much.28

The EU Digital Identity Wallet — rolling out across member states by the end of 2026 — is the clearest illustration. The idea is right: a portable digital credential you control. But civil society organisations including epicenter.works and the European Digital Rights network have rightly warned that the implementation could eliminate anonymity and enable pervasive tracking.29 As a preview of just how disastrously wrong things can go, in April 2026, France’s centralised digital identity system was breached, with personal information for up to 19 million French citizens and residents offered for sale on the dark web.30

The problem was never the idea, but the infrastructure — building it where one operator, or one breach, can see everything.

There’s a pattern here that nature already knows: concentration is what turns the beneficial toxic. Manure spread thin feeds a field; piled up in an industrial feedlot it poisons the watershed. Water that soaks in nourishes the soil; channelled into a torrent it strips it bare. Data is no different — the reflex to centralise everything doesn’t just create a single point of failure, it concentrates what was never meant to pool until the flows themselves turn destructive.

Step back from the individual headlines and the pattern is singular. The AI security exposure, the quantum shelf-life problem, the regulatory reckoning, the sovereignty scramble — these are not separate crises. They are the same crisis surfacing in different domains: too much concentrated in too few centres, on infrastructure that was never built to keep it safe. Every one of them points to the same answer — and it’s not a better centre. It’s no centre at all.

The commercial landscape has shifted as dramatically as the threat landscape. The hosting economics we proposed in 2017 have since been borne out by an entire decentralised-compute sector. LLMs barely registered as a commercial proposition when we issued the first Green Paper; Statista now puts the worldwide AI market at approximately $254 billion for 2025, with other credible estimates ranging considerably higher depending on what’s counted.31 Enterprise security has moved from a perimeter problem to a data-sovereignty problem — the firewall-bounded network has given way to data that moves through AI systems outside the enterprise’s control, and regulators are writing the rules to match.32

So while our early supporters are understandably frustrated by our failure to launch on our initial proposed timeline, the delay has put us in front of a commercial opportunity significantly larger than the one we originally set out to address — and an infrastructure need the prevailing architecture can’t meet. We’re transcending and including the original hosting vision, because what this technology can do turns out to be considerably more than what we first imagined.