Information Sovereignty
What Europeans know about their world is filtered by algorithms they cannot audit.
What Europeans know about their world is filtered by algorithms they cannot audit. Google holds 88 to 93 per cent of European search. Meta and TikTok hold most of the remainder. The platforms have instruments. Europeans do not.
On 6 December 2024, Romania’s Constitutional Court annulled the first round of its presidential election after coordinated algorithmic amplification of one candidate. The court could not see the algorithms. The platforms could. When citizens do not control their preference data, citizens are the product.
Four layers return the instruments to citizens. Legal mandates force platform exposure. Open standards make it portable. Non-AI public-service tools let citizens act on it. A natural-language interaction layer translates citizen instructions into platform-level signals.
On 6 December 2024, two days before the planned runoff of its presidential election, the Constitutional Court of Romania annulled the entire vote. The first-round winner, Călin Georgescu, had emerged unexpectedly from a campaign that reported zero declared expenditure. The Court’s reasoning cited illegal use of digital technologies during the campaign, undeclared campaign funding, and coordinated amplification on TikTok and Telegram that produced an information environment the Court ruled invalid for democratic deliberation.
Romanian President Klaus Iohannis declassified intelligence reports describing TikTok’s preferential algorithmic treatment of Georgescu compared to other candidates and Russian-attributed coordination amplifying his content. Atlantic Council analysis of TikTok and Telegram during the campaign documented coordinated activity amplifying Georgescu to the widest possible online audience. In March 2025 the European Court of Human Rights refused to overrule the annulment.
Romania is the case Europe cannot avoid. A democratic state invalidated its own presidential election because an information environment under foreign-owned algorithmic control had produced an outcome the Court ruled invalid. The Court could see the result. The Court could not see the system that produced it. No European institution could.
The architecture that produced this outcome operates across every major platform and every major European market.
- The Architecture We Are Inside =================================
Network effects make the platforms unreplaceable. Qwant, a French search engine with technical capability and full GDPR compliance, has captured less than one per cent of European search market share. Google holds eighty-eight to ninety-three per cent across major European markets: 87.68 per cent in France, 86.66 per cent in Germany, 93.36 per cent in the United Kingdom, 88.27 per cent in Italy.
The same logic operates an order of magnitude harder for TikTok or Instagram, where the network effect is reinforced by social graph rather than just data. The user-coordination problem cannot be solved through individual choice. No single user benefits from switching to a smaller network; collectively, all users are worse off staying on the dominant one.
The architecture has been stable for a decade and shows no sign of dissolving on market dynamics alone.
Foreign-state subsidy keeps these platforms operating regardless of European action. The United States government keeps Meta and Google viable as instruments of soft power; the Chinese government keeps TikTok and WeChat viable for the same reason; Europe has no equivalent strategic actor at this scale. The platforms Europe regulates operate as state-backed infrastructure of foreign powers.
The regulatory model assumes market actors that respond to penalties; the assumption is wrong here. Penalties extracted by European regulators sit on the balance sheets of operations whose continued existence does not depend on European market dynamics.
The architecture’s deeper fact is the instruments asymmetry. Platforms have explicit objective functions, machine learning systems trained on user behaviour, A/B testing infrastructure, real-time content optimisation, and the engineering capacity to reshape feeds at scale. Citizens have none of this. No language interface to the algorithm.
No way to inspect the preference profile the platform holds. No way to transport, reset, or override it. The user-side instrument is the consumption signal of clicking and watching, which is a signal the platform extracts rather than an instrument the user wields.
Only one side has instruments. Whoever has instruments wins. Netflix’s recommendation system optimises for engagement, retention, and hours watched, all explicit publicly-stated objectives. The user has no comparable instrument to say “I want more sci-fi, less reality TV” and have the platform comply. TikTok’s algorithm has objectives the platform optimises for.
Romanian voters had no instrument to weight or correct what TikTok’s algorithm amplified during the December 2024 campaign. The architecture is the same across all current platforms and will replicate at the next layer (frontier AI), where the same actors plus state-backed Chinese entrants are building. Information sovereignty in the AI era is downstream of AI sovereignty.
The instruments asymmetry produces the spine. When citizens do not control their preference data, the platform’s instruments produce outputs the platform’s goals shape. The citizen is the product because the platform has the instruments and the citizen does not.
- The Cases ============
Four cases prove the architecture across different platform-side actors and different motivations.
Romania 2024 is the case the opening named. It is the lead case because it is the only documented instance of a European democracy formally invalidating its own presidential election on the grounds that the algorithmic information environment had been manipulated.
The Constitutional Court reasoning, the European Court of Human Rights refusal to overrule in March 2025, and the declassified Romanian intelligence describing TikTok’s preferential treatment of one candidate together establish that the architecture’s effects on democratic outcomes are not theoretical.
Atlantic Council analysis of TikTok and Telegram during the campaign documented significant coordination amplifying Georgescu to the widest possible online audience. The pattern recurs in the remaining three cases.
Cambridge Analytica is the historical anchor. Personal data of approximately eighty-seven million Facebook users (one million in the United Kingdom) was harvested through the “thisisyourdigitallife” application developed by academic Aleksandr Kogan and shared with SCL Elections, the parent company of Cambridge Analytica.
The harvested data was used to construct psychographic profiles deployed in the 2016 Trump presidential campaign and the Brexit Leave campaign. The UK Information Commissioner’s Office issued a monetary penalty notice on 25 October 2018, imposing a fine of £500,000, the maximum available under the Data Protection Act 1998.
Under the General Data Protection Regulation, which took effect in May 2018, the fine could have exceeded £1 billion. Facebook settled the fine in October 2019 without admitting liability. The case demonstrates the preference-data architecture in operation: the data was harvested without users’ knowledge, weaponised psychographically, and used to shape electoral outcomes.
The penalty structure that the law made available was orders of magnitude smaller than the harm.[1]
X under Musk is the active case where ideology-maximising platform behaviour breaks the regulatory model that assumes profit-maximising actors. A 2023 field experiment published in Nature in 2026 randomly assigned active US-based users to algorithmic or chronological X feeds for seven weeks.
The experiment found that switching to the algorithmic feed shifted political opinion toward more conservative positions on policy priorities, perceptions of Trump-related criminal investigations, and views on the war in Ukraine.
The 2025 ACM Conference on Fairness, Accountability, and Transparency published a study using one hundred and twenty sock-puppet accounts to audit X’s For You timelines during the 2024 US presidential election: the study found a default right-leaning bias in the platform’s recommendations and asymmetric amplification toward right-leaning accounts.
The Harvard Kennedy School’s Misinformation Review documented changes to contentious-actor amplification on the platform after the 2022 acquisition. The European Commission imposed a €120 million DSA fine on X in December 2025, citing deceptive verified-account practices, advertising transparency failures, and denial of researcher access to platform data.
Musk treated the fine as cost of operation. The algorithm that deprioritises legacy media and amplifies aligned content remained unchanged.[2]
Doppelgänger demonstrates coordinated foreign operations on top of European-accessible platforms.
The Russian-attributed Foreign Information Manipulation and Interference operation, first documented by EU Disinfo Lab in September 2022, uses domain cloning and typosquatting to create websites impersonating legitimate European media outlets: Die Welt, Le Point, Le Parisien, La Stampa, La Repubblica, Polityka, Polskie Radio.
EU Disinfo Lab’s analysis of six hundred and fifty-seven Doppelgänger articles across twenty inauthentic news sites in the lead-up to the June 2024 European Parliament elections found sixty-five election-related articles in the two weeks before the vote, rising to one hundred and three in the final week. Primary targets: Germany, France, Poland. Content was amplified on X and Facebook.
The operation continues in 2026 against ongoing European political processes.[3]
The pattern across all four cases is the same. The architecture: platforms hold preference data, platforms have instruments to act on it, citizens have neither. The platform-side actors differ. The outcomes are the same. Romanian voters were products of TikTok’s amplification choices. Cambridge Analytica targets were products of Facebook’s data architecture.
X users became products of an ideologically-directed algorithm. Doppelgänger consumers became products of foreign-state coordination on Western infrastructure. The motivations vary across cases. The architectural fact is constant.
- Why Regulation Alone Cannot Fix This =======================================
European regulation has tried. The Digital Services Act, the Digital Markets Act, the General Data Protection Regulation, and the Audiovisual Media Services Directive collectively represent the most ambitious attempt anywhere to regulate platform behaviour.
The European Commission has imposed billions of euros in fines: €2.95 billion against Google, €500 million against Apple, €200 million against Meta, €120 million against X. These fines extract penalty. They have not changed the architecture they were designed to address.[4]
Three failure modes operate.
American law is upstream of European regulation. Platforms operating in Europe are headquartered in jurisdictions whose own legal frameworks (the CLOUD Act, FISA Section 702, the Foreign Investment Risk Review Modernization Act) require behaviours that European regulation prohibits.
When global platforms make architectural decisions, they optimise globally and accept European-market compliance as marginal cost. The competitive advantage from the unregulated business exceeds the revenue loss in the regulated market. AI Overviews behaviour in Europe will track the globally-optimised behaviour, whatever European regulators determine.
The regulatory model assumes profit-maximising actors. Sophisticated regulation can redirect profit incentives toward social goods: transparency, safety standards, fair competition. The model does not constrain actors who treat profit as secondary to ideological objective.
Musk’s response to the December 2025 €120 million DSA fine was to absorb the penalty without modifying the algorithm that deprioritises legacy media and amplifies aligned content. The fine was treated as cost of operation. When an actor is ideology-maximising rather than profit-maximising, penalties produce escalation rather than compliance.
Penalties extract revenue without changing structure. The DSA imposes fines for procedural non-compliance: failure to provide researcher access, deceptive verified-account practices, advertising transparency gaps. These are real compliance failures and the fines are proportionate to them.
They do not address the underlying architectural fact: the platform decides what European citizens see, the citizen has no instrument to alter that decision, and no penalty short of operating-model collapse changes the architecture from which the platform profits.
The structural problem the prescription must address is that regulation needs to be paired with infrastructure. Penalty alone produces reluctant procedural compliance. The architecture that produces the harm continues to operate. Citizens remain products. The prescription must give citizens instruments.
- The Layered Architecture ===========================
When we don’t control our preference data, Europe’s citizens are the product. The architecture that gives the preference data back is layered.
Single public agency, four layers of infrastructure, sequenced over years one to eight. The European Information Sovereignty Agency operates the entire stack. Each layer builds on the layer below. AI sits at the top because the substrate it depends on, sovereign European AI capability, takes years to mature.
The destination is the layer-four citizen tool that gives mass-adoption agency through natural language. The earlier layers are the substrate that makes the destination possible and the path that delivers benefit while the substrate matures.
Layer one is legal enforcement of platform exposure.
The DSA evolves to mandate granular preference controls platforms must expose to users (surfaced as primary interface, not buried in settings), structured machine-readable algorithmic transparency (structured outputs that interpretation tools can parse, not narrative reports),
algorithm choice (citizens can swap in third-party algorithms or chronological feeds, on the AT Protocol model demonstrated by Bluesky),
data portability with operational APIs (machine-readable formats other platforms and tools can ingest, not unstructured exports), and platform-side APIs that third-party tools can call on behalf of users with the user’s consent under European jurisdiction. Years one to three. Strengthens existing frameworks. This is the foundation. Without it, no later layer has anything to act on.
Layer two is standards and APIs. The agency defines open data formats for preference data, algorithm-choice protocols, and the technical specifications platforms must implement to satisfy the legal mandates. Standards work runs alongside legal enforcement: the law forces exposure, the standards make the exposure interoperable.
ETSI, ENISA, ANSSI, BSI, and academic cryptographic communities across the Netherlands, Belgium, Switzerland, and Italy provide existing technical capacity. Coordination at strategic level is what is missing. Years two to five.
Layer three is non-AI public-service tools.
The agency builds and operates browser-level filtering tools (on the uBlock Origin model applied to content categories),
cross-platform comparison interfaces (on the Danish voter-platform model applied to information environments:
“here is how X, TikTok, Instagram, Le Monde, BBC, ARD covered this issue, here is the spread of framing, here is where each outlet sits”), journalism funded to use the legally-mandated transparency outputs (independent newsrooms with capacity to interpret what platforms are surfacing and why),
federated alternatives funded as public goods (Mastodon and AT Protocol infrastructure as European public-service options), and standards-conformant open-source tools that anyone can fork.
Years two to six. Serves power users, journalism, and citizens who prefer rule-based or curated alternatives over AI.
Layer four is the AI LLM citizen tool. Natural-language interface to the legally-mandated platform exposure. Free at point of use on the public-broadcasting model.
The citizen says “show me less reality TV, more sci-fi” or “less far-right amplification, more crypto institutions” or “show me coverage of this issue across the political spectrum” and the tool translates the instruction into the platform’s input space and updates the citizen’s feed.
The tool runs on European AI substrate: chips, compute, models. The interpretation agent itself sits under European jurisdiction without foreign-law override. Phased rollout from year four onward as the substrate matures. The mass-adoption UX.
Each layer serves different users. A citizen using only layer one (regulated platform-exposed preference controls) is better off than today. A citizen using layer three (browser-level filters, public-service comparison tools, public-service journalism) is better off than today. A citizen using layer four (natural-language interpretation agent) has the maximum agency the architecture can deliver.
The architecture does not require all citizens to adopt layer four. It requires that all four layers exist for citizens to choose among.
The mass-adoption case lives in layer four. Power users will adopt rule-based tools and federated alternatives. The citizen majority needs a natural-language interface. Most citizens will continue using TikTok, Instagram, and X. The question is whether they have an instrument they can use against the platform’s algorithm.
The natural-language tool is that instrument in a form most citizens will actually use. The architecture absorbs delay because layers one to three deliver real benefit independently while the AI substrate matures.
The architecture is opt-in throughout. The citizen who never uses any of the public-service tools uses the platforms exactly as they do now. The agency does not censor or block. The legal mandates apply to platforms; the public-service tools are options citizens choose to use. The agent is a tool the citizen wields. Systems citizens cannot avoid are excluded by design.
The citizen can disable the agent at any moment, can use multiple agents from multiple providers, and can interrogate the agent (“why did you adjust my feed this way?”) and receive a real answer.
- Funded by the Platforms That Caused the Problem ==================================================
The funding mechanism is hypothecation of DSA, DMA, and GDPR fines into a European Information Sovereignty Fund. Current fine flow at single-digit billions per year. The interpretation infrastructure operates within the available envelope.
Sizing. The agency itself, operating layers one to four, is small relative to existing European public-broadcasting spend. The total European public-broadcasting sector currently operates at roughly €30 to €35 billion per year (BBC, ARD, ZDF, France Télévisions, RAI, and counterparts). The agency at full scope is a modest reallocation within that envelope.
Public-service journalism extensions, if politically supported, could be funded under existing public-broadcasting structures rather than centrally through the agency.
Political logic. The platforms that took the preference data fund the architecture that gives it back. No new taxation. No reallocation of existing budget priorities. The bad actors pay for the fix. This pre-empts the standard objection to public spending on digital infrastructure: citizens are not paying.
The platforms responsible for the harm are paying through the fine system already in operation.
Mechanism. Amend the DSA to hypothecate fines into a European Information Sovereignty Fund. Direct the Fund to the European Information Sovereignty Agency. Operate the Agency on the public-broadcasting governance model, with editorial and operational independence from platform interests and from electoral cycles.
Precedent for hypothecated EU funding exists in emissions revenue earmarked for climate spending.
Feedback loop. The current fine model treats penalties as balance-sheet revenue: fines flow to general treasuries and platforms continue operating exactly as before. Hypothecated fines change the calculation. A €120 million fine paid to a general treasury is operating cost.
A €120 million fine paid to fund the natural-language tool that lets citizens opt out of the platform’s engagement-maximising algorithm is direct subsidy to the platform’s competition. Compliance becomes the rational choice for the first time. Non-compliance pays for the alternative that constrains future non-compliance.
The architecture self-funds through the very mechanism it is designed to constrain.
The platform-side calculation inverts. Compliance is rewarded with continued operation under European mandates that limit but do not destroy. Non-compliance is punished by direct funding of the tools that erode the platform’s economic position. The economics that have made DSA fines absorbable as cost of doing business no longer apply when those fines pay for the alternatives.
- The Choice =============
Romania 2024 showed what is at stake. A democracy had to annul its own presidential election because the algorithmic information environment had been successfully manipulated. The Romanian Court blamed the architecture: the platforms had instruments, the voters did not, and the architecture decided the campaign before voters could deliberate over it.
The political coalition is broad because the prescription does not require new taxation, does not require redirecting existing budget priorities, does not require forcing citizens off platforms they have chosen to use, and does not require building European platforms that would fail commercially.
It requires regulatory mandates Europe is institutionally capable of producing, public infrastructure Europe is institutionally capable of operating, and a funding mechanism that is morally and politically clean: bad actors pay for the fix.
When we don’t control our preference data, Europe’s citizens are the product. The architecture above is how we stop being the product. The platforms that took the preference data fund the architecture that gives it back. The legal mandates force the exposure. The standards make it interoperable. The public-service tools deliver the alternatives.
The AI agent gives mass-adoption agency to the citizen who wants a natural-language relationship with their feed. European democracies whose citizens are products are not sovereign in the way the European democratic tradition demands.
The dependence is observable. The architecture is achievable. The funding exists. The institutions exist. What is needed is the choice.
[1] Information Commissioner’s Office (United Kingdom), Monetary Penalty Notice against Facebook Ireland Ltd and Facebook Inc, 25 October 2018. Fine of £500,000 imposed under the Data Protection Act 1998, the maximum available pre-GDPR. Settled October 2019 without admission of liability.
[2] ACM Conference on Fairness, Accountability, and Transparency (FAccT), 2025. Audit of X For You timelines using approximately 120 sock-puppet accounts during the 2024 US presidential election. Found default right-leaning bias and asymmetric amplification toward right-leaning accounts.
[3] EU DisinfoLab, Doppelganger monitoring during the European Parliament elections, May-June 2024. 657 articles analysed across 20 inauthentic sites; 65 election-related articles in the two weeks before the vote rising to 103 in the final week. Primary targets: Germany, France, Poland.
[4] Office of the President of Romania, declassified Supreme Council of National Defence (CSAT) intelligence reports, 4 December 2024. Reports identified preferential TikTok algorithmic treatment of Georgescu and Russian-attributed coordination.
Sign the Manifesto. The eight demands that follow from the case made in this paper and the twenty-seven others. Sign →