<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-GB">
  <title>Briefs | Niclas Hedam</title>
  <subtitle>Long-form analysis on security, privacy and the systems that shape them.</subtitle>
  <link href="https://hed.am/feed.xml" rel="self" />
  <link href="https://hed.am/" />
  <updated>2026-07-30T00:00:00Z</updated>
  <id>https://hed.am/</id>
  <author>
    <name>Niclas Hedam</name>
  </author>
  <entry>
    <title>The Retention Economy: Kept at All Costs</title>
    <link href="https://hed.am/briefs/the-retention-economy/" />
    <published>2026-07-19T00:00:00Z</published>
    <updated>2026-07-19T00:00:00Z</updated>
    <id>https://hed.am/briefs/the-retention-economy/</id>
    <summary>A recommendation feed is not trying to entertain you. It is trying to keep you watching, and it drifts towards whatever version of you is easiest to hold on to.</summary>
    <content type="html">&lt;p&gt;Years ago I started noticing a pattern in my Instagram Reels. In between the clips I enjoyed watching, the app kept feeding me clips that I had never asked for and did not want: suggestive, borderline stuff, from accounts I did not follow and had no interest in. So I did what Instagram tells you to do when a recommendation misses. I marked them &lt;em&gt;not interested&lt;/em&gt;. Once, then again, and then so many times I lost count. It changed almost nothing. The feed had formed a view of me, and no amount of me saying otherwise seemed to shift it.&lt;/p&gt;&lt;p&gt;It was only much later, when Instagram added a proper set of controls for tuning what it recommends, that I managed to get things back to something I recognised, but still not entirely. It should not take that much effort, kept up over years, to convince a service that I do not want what it keeps putting in front of me. Somewhere along the way, an ordinary app for sharing photos and videos with friends had decided that the way to hold my attention was to show me things I found neither interesting nor welcome. And for a while it was right, in a sense, because as long as I kept tapping &lt;em&gt;not interested&lt;/em&gt;, I was still there.&lt;/p&gt;&lt;p&gt;I want to be careful here, because it is easy to reach for the wrong explanation. I do not think anyone at Instagram decided to automatically send suggestive content to men on purpose. Instead, I think it was built to do whatever keeps people watching, and it worked this out on its own. That is worth keeping in mind for what follows: no one designed it to target anyone specifically. It optimises for attention, and our weaker moments are where the attention tends to be.&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://hed.am/briefs/the-retention-economy/&quot;&gt;Read the full brief →&lt;/a&gt;&lt;/p&gt;</content>
  </entry>
  <entry>
    <title>What Anthropic Taught Us About Digital Sovereignty</title>
    <link href="https://hed.am/briefs/what-anthropic-taught-us-about-digital-sovereignty/" />
    <published>2026-06-21T00:00:00Z</published>
    <updated>2026-07-17T00:00:00Z</updated>
    <id>https://hed.am/briefs/what-anthropic-taught-us-about-digital-sovereignty/</id>
    <summary>On 12 June 2026 the US ordered Anthropic to cut off Fable 5 and Mythos 5 for every foreign national. The sovereignty risk we kept calling theoretical just happened.</summary>
    <content type="html">&lt;p&gt;I work with defensive security in government, and a lot of that job comes down to one unglamorous question: what can an institution safely depend on, and what can it not? You weigh a system, a vendor, a supplier, and decide whether the organisation can afford to lean on it. It is slow work, done one piece at a time, and you tend to notice it only when the answer turns out to be wrong. This month, the answer was handed to all of us at once, in a single letter none of us had any part in.&lt;/p&gt;&lt;p&gt;In the name of national security, a NATO ally switched off a tool that security professionals all over the world had started to rely on, and drew the line so that everyone outside the United States — my own country, a decades-old ally, included — came down on the wrong side of it. Not an adversary. An ally.&lt;/p&gt;&lt;h2&gt;The Letter&lt;/h2&gt;&lt;p&gt;On 12 June 2026, at 5:21pm Eastern, Anthropic received a letter from US national-security authorities ordering it to suspend access to its two most capable models, Fable 5 and Mythos 5, for any foreign national, inside or outside the United States, including Anthropic’s own foreign-national staff. The reported trigger was a jailbreak, which on inspection turns out to mean asking Fable 5 to read a codebase and point out the security flaws in it. In other words, code review.&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://hed.am/briefs/what-anthropic-taught-us-about-digital-sovereignty/&quot;&gt;Read the full brief →&lt;/a&gt;&lt;/p&gt;</content>
  </entry>
  <entry>
    <title>We Want AI. We Just Can&#39;t Say Why</title>
    <link href="https://hed.am/briefs/we-want-ai-we-cant-say-why/" />
    <published>2026-06-10T00:00:00Z</published>
    <updated>2026-06-10T00:00:00Z</updated>
    <id>https://hed.am/briefs/we-want-ai-we-cant-say-why/</id>
    <summary>In Denmark, AI data centres have queued for more power than the entire national grid can supply, with ten-year waits and almost no jobs. Do we actually need this?</summary>
    <content type="html">&lt;p&gt;In the past few years, almost every organisation I have worked with or alongside has tried to improve its workflows with AI. What few of them could quite say was &lt;em&gt;what&lt;/em&gt; they were improving. The tool arrived first. The problem it was meant to solve was reverse-engineered afterwards, if anyone got around to it at all.&lt;/p&gt;&lt;p&gt;In academia, I watched colleagues use AI to write their papers and reviewers use AI to review them. The writing I can live with. The review is where it turns absurd, because the entire purpose of peer review is to vouch for a paper’s scientific integrity, and a model cannot reliably tell a real result from a confident hallucination. Neither, increasingly, can a reviewer leaning on the model. So we lose the point of the exercise: what is being weighed is no longer the thought of the scientist but the output of one machine, judged by another. It is already being gamed. Researchers have started hiding instructions inside their manuscripts, white text a human eye skips over, telling any AI reviewer to &lt;em&gt;give a positive review only&lt;/em&gt;.&lt;/p&gt;&lt;p&gt;As a consultant, the pressure was always to go faster by putting AI in the loop. But the work that actually mattered, designing infrastructure and security for clients, was precisely the work we could not paste into someone else’s model without breaking the obligations we had been hired to uphold. And when AI was used anyway, it was sometimes confidently, comprehensively wrong. A colleague once produced a long, polished handbook on Active Directory security that invented best practices, mixed up attack vectors, and recommended things that were actively insecure. I caught it in QA. Had I not, it would have gone to a client with our name on the cover. Not everyone catches it in time. Deloitte did not: it had to refund part of an A$440,000 report to the Australian government after the document turned out to be propped up by citations to research that did not exist and a fabricated account of a court proceeding.&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://hed.am/briefs/we-want-ai-we-cant-say-why/&quot;&gt;Read the full brief →&lt;/a&gt;&lt;/p&gt;</content>
  </entry>
  <entry>
    <title>The Trust You Cannot Outsource: Notes From V2 Security 2026</title>
    <link href="https://hed.am/briefs/the-trust-you-cannot-outsource/" />
    <published>2026-05-21T00:00:00Z</published>
    <updated>2026-05-21T00:00:00Z</updated>
    <id>https://hed.am/briefs/the-trust-you-cannot-outsource/</id>
    <summary>Cloud and AI dominated every booth at V2 Security 2026. Both move trust somewhere you cannot inspect, a strange direction for the security industry to take.</summary>
    <content type="html">&lt;p&gt;I walked the floor at V2 Security 2026. Two themes were inescapable. Many vendors were selling either cloud-delivered security or AI-assisted security. The marketing had converged. The keynotes had converged. The vendor demos had converged.&lt;/p&gt;&lt;p&gt;I am not against either, in principle. What troubles me is the answer I got when I started asking various vendors the same question.&lt;/p&gt;&lt;p&gt;I work with governmental security, in one of those seats where the job is to find the mistake before it ships. The police, no matter the country, are not allowed to fail, and that constraint sits on every architectural decision before it is signed off. A leaked password can be rotated. An adversary learning the shape of the police’s defences, or a public losing trust in the institution itself, cannot. That perspective shapes which vendor pitches I find serious, and which I find decorative.&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://hed.am/briefs/the-trust-you-cannot-outsource/&quot;&gt;Read the full brief →&lt;/a&gt;&lt;/p&gt;</content>
  </entry>
  <entry>
    <title>The Illusion of Delete</title>
    <link href="https://hed.am/briefs/the-illusion-of-delete/" />
    <published>2026-03-29T00:00:00Z</published>
    <updated>2026-03-29T00:00:00Z</updated>
    <id>https://hed.am/briefs/the-illusion-of-delete/</id>
    <summary>We demand systems that never lose data, load instantly, and obey every law. Deletion fails not because companies are evil, but because we asked the impossible.</summary>
    <content type="html">&lt;p&gt;I deleted my Facebook account a few years ago. Not just deactivated, but permanently deleted. Facebook walked me through the process, warned me repeatedly that this was permanent, showed me what I would lose. I clicked through all the confirmations. The account vanished. My profile, my posts, my photos, all gone.&lt;/p&gt;&lt;p&gt;Except they were not gone. Facebook’s terms say deleted data might persist in backups for &lt;a href=&quot;https://www.facebook.com/help/154908788002686&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;up to 90 days&lt;/a&gt;. Every message I sent still sits in someone else’s inbox for context. Every third-party app I logged into still has whatever data it pulled, and they likely never knew I sent in a deletion request. Every advertiser I interacted with still has the profile they built from my behaviour.&lt;/p&gt;&lt;p&gt;At the same time, I wanted Facebook to keep these backups so my account would not disappear if their servers failed. I wanted their app to be fast and reliable, which would require replication of data across multiple data centres in different regions. And all of those reasonable expectations made true deletion nearly impossible.&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://hed.am/briefs/the-illusion-of-delete/&quot;&gt;Read the full brief →&lt;/a&gt;&lt;/p&gt;</content>
  </entry>
  <entry>
    <title>What Surveillance Means to Me</title>
    <link href="https://hed.am/briefs/what-surveillance-means-to-me/" />
    <published>2026-03-21T00:00:00Z</published>
    <updated>2026-03-21T00:00:00Z</updated>
    <id>https://hed.am/briefs/what-surveillance-means-to-me/</id>
    <summary>I am not against all surveillance; CCTV recording crimes provides accountability. What I oppose is mass tracking, profiling, and systems that judge us blindly.</summary>
    <content type="html">&lt;p&gt;My posts may make it sound as though I think all surveillance is wrong. I write about governments watching us, companies tracking us, and data being turned into a weapon, so it would be fair to read me that way. I am not, though. If I were against all of it, there are parts of my professional life I would struggle to explain.&lt;/p&gt;&lt;p&gt;What I am against is the way some modern surveillance systems are built and used.&lt;/p&gt;&lt;h2&gt;Why some Surveillance Makes Sense&lt;/h2&gt;&lt;p&gt;Take the CCTV cameras on public transport. If a passenger is assaulted, the cameras record it, the police can work out who was responsible, and the victim has something to point to. Someone can be held to account.&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://hed.am/briefs/what-surveillance-means-to-me/&quot;&gt;Read the full brief →&lt;/a&gt;&lt;/p&gt;</content>
  </entry>
  <entry>
    <title>VPNs Are a Symptom, Not a Feature: Why the Internet Is Broken</title>
    <link href="https://hed.am/briefs/vpns-are-a-symptom/" />
    <published>2026-01-26T00:00:00Z</published>
    <updated>2026-07-09T00:00:00Z</updated>
    <id>https://hed.am/briefs/vpns-are-a-symptom/</id>
    <summary>VPNs solve real problems, but needing them signals deeper failures. We use them to patch insecure networks, surveillance capitalism, and artificial access barriers.</summary>
    <content type="html">&lt;p&gt;A VPN is one of the few security tools that ordinary people install on purpose. It ships inside browsers and operating systems and gets recommended in the same breath as a password manager. Yet ask what it is actually for, and the honest answer is that it patches three very different problems at once, and not one of them is technical in origin. Each one traces back to a choice that could have gone the other way. In every case, the VPN is what we reached for instead of the fix.&lt;/p&gt;&lt;p&gt;The three reasons are worth separating, because the fix each one points to is different, and so is whoever decided we would not get it.&lt;/p&gt;&lt;h2&gt;Internal Access: When the Network Cannot Be Trusted&lt;/h2&gt;&lt;p&gt;The most familiar use of a VPN is reaching work systems from outside the office, and the thinking behind it is older than it looks. It is the remote-access half of the perimeter model, the oldest idea in network security: draw a wall around the corporate network, treat everything inside it as trusted and everything outside as hostile, and when staff need to reach it from elsewhere, run them through an encrypted tunnel so they emerge on the trusted side. Google’s engineers once compared that model to a medieval castle, in which “anyone who makes it past the drawbridge has ready access to the resources of the castle”. The workplace VPN is the drawbridge, lowered to wherever the employee happens to be sitting.&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://hed.am/briefs/vpns-are-a-symptom/&quot;&gt;Read the full brief →&lt;/a&gt;&lt;/p&gt;</content>
  </entry>
  <entry>
    <title>Malicious Compliance: How Trusted Packages Turn Into Attack Vectors</title>
    <link href="https://hed.am/briefs/how-trusted-packages-turn-into-attack-vectors/" />
    <published>2025-09-25T00:00:00Z</published>
    <updated>2026-07-05T00:00:00Z</updated>
    <id>https://hed.am/briefs/how-trusted-packages-turn-into-attack-vectors/</id>
    <summary>Modern software runs thousands of packages from strangers. Run npm install and you run code from people you never met. Supply chain attacks exploit that trust daily.</summary>
    <content type="html">&lt;p&gt;This website is built with &lt;a href=&quot;https://www.11ty.dev/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Eleventy&lt;/a&gt;, a static site generator that pulls in several dozen packages the moment you install it. Two of them are &lt;code&gt;iso-639-1&lt;/code&gt;, a &lt;a href=&quot;https://github.com/meikidd/iso-639-1&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;small package&lt;/a&gt; that provides ISO 639-1 language codes, built and maintained by a single author in Singapore, and &lt;code&gt;kleur&lt;/code&gt;, a &lt;a href=&quot;https://github.com/lukeed/kleur&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;popular package&lt;/a&gt; for colouring terminal output, maintained by a developer in the USA. I have never met either of them. I could not tell you what their security practices look like, or what happens to their npm account if their laptop gets stolen. And yet every time I rebuild this site, their code runs, unread, with the same privileges as my own.&lt;/p&gt;&lt;p&gt;Nobody sat down and decided this was an acceptable risk. There was no meeting, no checklist, no moment where I weighed trusting two strangers against writing my own language-code lookup table. The decision got made for me, by Eleventy’s dependency tree, the instant I typed &lt;code&gt;npm install&lt;/code&gt;. That is the position most developers are in for most of their dependencies, most of the time, whether they stop to think about it or not.&lt;/p&gt;&lt;p&gt;This is the default state of modern software. Package managers like &lt;em&gt;npm&lt;/em&gt; for JavaScript, &lt;em&gt;pip&lt;/em&gt; for Python, and &lt;em&gt;gem&lt;/em&gt; for Ruby have made code-sharing so easy that a typical web application now depends on hundreds, sometimes thousands, of packages, each solving one narrow problem and each dragging in its own dependencies behind it. The result is a tree, with your application at the root and a great many strangers holding up the branches.&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://hed.am/briefs/how-trusted-packages-turn-into-attack-vectors/&quot;&gt;Read the full brief →&lt;/a&gt;&lt;/p&gt;</content>
  </entry>
  <entry>
    <title>EU Chat Control: If Privacy Is Outlawed, only Outlaws Have Privacy</title>
    <link href="https://hed.am/briefs/if-privacy-is-outlawed-only-outlaws-have-privacy/" />
    <published>2025-09-15T00:00:00Z</published>
    <updated>2026-07-20T00:00:00Z</updated>
    <id>https://hed.am/briefs/if-privacy-is-outlawed-only-outlaws-have-privacy/</id>
    <summary>The EU Chat Control proposal scans everyone&#39;s private messages before sending, shifting from targeted investigation to pre-emptive monitoring of all citizens.</summary>
    <content type="html">&lt;p&gt;I have spent my career looking for the ways a system breaks, and it is not a habit I can leave at work. Once you spend your days finding where things fail before anyone has to depend on them, you start doing it to everything — a new app, the card reader at the kiosk, Copenhagen’s driverless metro. So when the European Union put forward its “Chat Control” proposal, I turned the same habit on it without really meaning to. The closer I look, the more it worries me — not because of its goal, but because of what the tool would have to do to reach it.&lt;/p&gt;&lt;p&gt;We all want children to be safe. That instinct is right, and I share it. But the proposal would place scanning software on every phone in Europe, checking your private messages against a model before they are sent. That is not targeted investigation of a suspect; it is pre-emptive monitoring of everyone, where each of us is treated as worth checking until the software clears us. The stated aim is compassion, and the architecture is built on suspicion. It has to be tested: whether it is legitimate, effective, and safe at the scale of a continent, and on all three the answer is not yet convincingly yes.&lt;/p&gt;&lt;h2&gt;How the Scanning Would Work&lt;/h2&gt;&lt;p&gt;The idea is straightforward: “detect abuse material and grooming early”. The implementation, however, is anything but simple. Chat apps today use end-to-end encryption, which means that the phone of the sender encrypts the message, and only the recipient’s phone can decrypt it. While the message is in transit or stored on servers, no one else can read it, not even the internet provider or app developer. This is a powerful privacy guarantee that protects not only criminals but also journalists, activists, domestic-violence survivors, and ordinary people.&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://hed.am/briefs/if-privacy-is-outlawed-only-outlaws-have-privacy/&quot;&gt;Read the full brief →&lt;/a&gt;&lt;/p&gt;</content>
  </entry>
  <entry>
    <title>When CPUs Stopped Scaling: Why Hardware Got Complicated</title>
    <link href="https://hed.am/briefs/when-cpus-stopped-scaling/" />
    <published>2025-09-08T00:00:00Z</published>
    <updated>2026-07-30T00:00:00Z</updated>
    <id>https://hed.am/briefs/when-cpus-stopped-scaling/</id>
    <summary>CPU clock speeds stopped scaling in 2005 when Dennard scaling broke down. The real bottleneck is moving data, not computing it, so hardware got specialised.</summary>
    <content type="html">&lt;p&gt;When I was a kid, computers had a single core. Some did not come with a dedicated graphics card either, relying on integrated graphics built into the motherboard. What I remember most is that they simply got faster on their own. You bought a new machine every few years, everything you already owned ran better on it, and nobody had to explain why.&lt;/p&gt;&lt;p&gt;Two observations explained it. Moore’s Law predicted that the number of transistors on a chip would double roughly every two years. Dennard Scaling observed that as transistors shrank they drew less power, which meant clock speeds could rise alongside the transistor count.&lt;/p&gt;&lt;p&gt;Between them, they gave us performance that arrived whether or not anyone wrote better software. Manufacturers could cram more transistors into a single core, and that was enough to keep up with everything being asked of it.&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://hed.am/briefs/when-cpus-stopped-scaling/&quot;&gt;Read the full brief →&lt;/a&gt;&lt;/p&gt;</content>
  </entry>
  <entry>
    <title>Digitalisation: Lost Privacy by Design</title>
    <link href="https://hed.am/briefs/digitalisation-lost-privacy-by-design/" />
    <published>2025-09-02T00:00:00Z</published>
    <updated>2026-07-09T00:00:00Z</updated>
    <id>https://hed.am/briefs/digitalisation-lost-privacy-by-design/</id>
    <summary>Digitalisation turns public records from manual lookups into mass extraction, exposing your name, address, and finances to anyone willing to query them.</summary>
    <content type="html">&lt;p&gt;Someone I did not recognise once called me, and instead of calling back I typed the number into MobilePay. Up came a name, full and correct, verified against the civil register, handed to me by a payments app in about a second. Denmark still has a digital phone book, and you can ask to be left out of it; more and more people do. But MobilePay now sits on most phones in the country, and because it is tied to your civil identity for know-your-customer and anti-fraud reasons, it has quietly become the phone book instead. There is no opting out of the one everybody actually uses.&lt;/p&gt;&lt;p&gt;So a few years ago I tried to opt out of something larger. I turned on CPR protection, the state’s own setting for people who would rather not be looked up, and kept it on for a while in the late 2010s. It works, and it is miserable. Banks could not verify me, onboarding at a new job stalled, and an automated insurance quote came back empty, because as far as their systems were concerned I had stopped existing. That is the lesson I took from it, long before I could have argued it cleanly: in Denmark, being findable is the default, and the only way out is a switch so blunt it half-removes you from ordinary life.&lt;/p&gt;&lt;h2&gt;No Single Record Is the Problem&lt;/h2&gt;&lt;p&gt;I want to be careful here, because the easy version of this argument is the wrong one. Public registers are not a mistake. They exist for good reasons — accountability, fraud prevention, a property market that is not run on rumour — and I am not asking for any of that to go behind a wall. Nothing I can look up about you is, on its own, a scandal. A business registration is mundane. A property sale is a matter of record. A phone number is just a number.&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://hed.am/briefs/digitalisation-lost-privacy-by-design/&quot;&gt;Read the full brief →&lt;/a&gt;&lt;/p&gt;</content>
  </entry>
  <entry>
    <title>LLMs Can Write Code, but Cannot Read Your Mind</title>
    <link href="https://hed.am/briefs/llms-can-write-code-but-cannot-read-your-mind/" />
    <published>2025-08-26T00:00:00Z</published>
    <updated>2025-08-26T00:00:00Z</updated>
    <id>https://hed.am/briefs/llms-can-write-code-but-cannot-read-your-mind/</id>
    <summary>LLMs generate valid code fast, but they cannot tell a secure pattern from an insecure one that looks identical, because they do not know what your code is for.</summary>
    <content type="html">&lt;p&gt;For a couple of years I taught C and Operating Systems, and the submissions that took longest to mark were never the ones that were obviously broken. They were the ones that compiled cleanly, ran, produced the right answer, and were still wrong. You could not see it by reading the code. You could only see it if you knew what the code was for.&lt;/p&gt;&lt;p&gt;Large language models (&lt;em&gt;LLMs&lt;/em&gt;) such as ChatGPT, Claude, and Copilot are very good at producing exactly that kind of code. They complete a function in your editor in seconds, draft a first implementation, explain a stack trace you have been staring at for an hour. What they cannot do is know what the code is for. An LLM has read more implementations than any of us ever will, and it can still hand you the wrong one, because it does not know your threat model, your failure modes, your data flows, your latency budget, your regulatory boundaries, or the operational quirk everyone on your team has quietly worked around for two years.&lt;/p&gt;&lt;p&gt;When you write code yourself, most of that sits in your head, steering the small decisions as you go. When the code arrives off the shelf, it arrives without any of it.&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://hed.am/briefs/llms-can-write-code-but-cannot-read-your-mind/&quot;&gt;Read the full brief →&lt;/a&gt;&lt;/p&gt;</content>
  </entry>
  <entry>
    <title>You Are the Product: Two Decades of Giving up Data Control</title>
    <link href="https://hed.am/briefs/you-are-the-product/" />
    <published>2025-08-18T00:00:00Z</published>
    <updated>2026-07-09T00:00:00Z</updated>
    <id>https://hed.am/briefs/you-are-the-product/</id>
    <summary>Twenty years of digital convenience built detailed profiles of our health, finances, and relationships, then sold them to advertisers and governments on request.</summary>
    <content type="html">&lt;p&gt;A decade or so ago, I searched “Amsterdam” in Google in anticipation of my upcoming trip. On top of all the search results, my flight ticket came up. I was not searching in my inbox, I was searching in Google. Underneath the flight number, departure time and gate, sat my hotel booking for the same trip: the address and the check-in time, lifted from a separate email, sent by a different company, that had nothing to do with the word I had searched for, other than the city of Amsterdam. I had not asked Google to become my personal assistant, read through my emails, and present them to me like this. It had already read both messages, worked out they belonged to the same journey, and assembled them into an itinerary I never requested.&lt;/p&gt;&lt;p&gt;It was the first time I understood, plainly, that the service I thought I was using was quietly using me back. Gmail was not a filing cabinet that held my letters. It was a machine that read them, and what it built by reading them — a model of who I am, where I go, and what I am about to do — was worth far more to Google than storing a few emails ever cost. I had assumed I was the customer. I was the product.&lt;/p&gt;&lt;p&gt;And the itinerary does not vanish when the trip ends. There is no reason for Google to discard it and every reason to keep it, because stacked over a few years these records stop being journeys and become a pattern: the airlines I pick, the class of hotel I book, the places I return to, the price I will pay. That is no longer a convenience, it is a travel profile of unusual precision. Google no longer has to hope that a discount on a trip to Madrid might tempt me; it can offer me Amsterdam again, at a hotel a notch above the last one, but for the same price. I never asked for an itinerary to appear above my search results, and that was only ever the visible part. The same reading runs over every other email that arrives, from shop receipts to job application confirmations. Each one is unremarkable alone. Compounded over years, they add up to more detail about you than you would ever have agreed to hand over in one sitting.&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://hed.am/briefs/you-are-the-product/&quot;&gt;Read the full brief →&lt;/a&gt;&lt;/p&gt;</content>
  </entry>
</feed>
