Engelberg Center Live!

Open @ UNGA 81: Open Collaboration & Open Sovereignty

Episode Summary

This episode features audio from the Open Collaboration and Open Sovereignty panel at Open @ UNGA 81: A Conversation on Collaboration. It was recorded on September 21, 2026.

Episode Notes

Digital sovereignty in the AI era cannot be realized through isolation or full-stack self-sufficiency. The cost of compute, hardware, and sovereign AI architectures makes it structurally impossible to own and control every layer of the stack independently. True digital agency instead comes through strategic partnership: shared open-source architectures, joint compute models, and standardized data protocols.

This session brings together leaders to explore how middle powers can collaborate to avoid vendor lock-in and build a resilient, open tech stack, from scaling shared protocols like X-Road and MOSIP to pooled financing that mutualizes infrastructure costs. The panel will also weigh which multilateral forum (UN, G20, or G7) is best positioned to host ongoing technical governance and collaborative infrastructure development.

Episode Transcription

Announcer  0:01  
Welcome to Engelberg Center Live, a collection of audio from events held by the Engelberg Center on Innovation, Law, and Policy at NYU Law. This episode features audio from the Open Collaboration and Open Sovereignty panel at Open at Unga 81, a conversation on collaboration. It was recorded on september 21, 2026.

Vidisha Mishra  0:25  
Thank you so much, Creative Commons, for bringing us together here, and it's so great to see the room full, given that so much is happening at the same time this morning with the roadblocks and everything as well. My name is Vidisha. I'm director for policy at the Global Solutions Initiative. It's our privilege to be a part of this cohort together with Creative Commons because one of our pet peeves over the last few years has been that those who are working on the different elements of the tech stack and those who look at the governance implications sit in different rooms. So we're very grateful, Anna, that you've brought us all together because, as we can see, these worlds are converging. There is no conversation that we can have that is about policy or geopolitics that doesn't touch upon AI and digital, and it's vice versa. So with that, I want to start today's conversation on open collaboration in the current geopolitical environment. Tamika has already done a great job of setting the context. We worked on a report that some of you will see over the last two years with Project Liberty, which interviewed emerging and middle power governments, and we will get into what middle powers means in a bit. But it was very clear from those interviews that no government believes that they can develop a full vertical tech stack that they have full control and ownership over the cost of compute, capacity deficits, cost of hardware-they're all they constrain the ability to have full sovereignty over everything. At the same time, it's very clear that current dependencies can be weaponized. So, in that context, what does collaboration look like? In this context, is what we're trying to unpack a bit more. With that, I'll introduce my panelists. We have Michel Baker, co-founder, Mozilla Project; Liv from the Digital Public Goods Alliance, CEO; Paul Sampson from CG Canada, president. Recently led Canada's Think Seven process of the G7 presidency. I want to hear a bit more about the lens that you're bringing into this very broad conversation. So I want to start by asking, what does open sovereignty during the current political instability look like for each of you? I'll start with you, Michel.

Mitchell Baker  2:42  
Yeah, and I'm going to say this. My name is Mitchell. My mom was eccentric, and so I generally answer to Michel. But in general, in this setting, I'll just say my name is Michel. And sometimes I wonder what my mom was thinking, but but there it is. So. I think that the question, in some ways, the instability today might drive openness in a counterintuitive fashion for the reasons that you described, which is that it's not really possible for most organizations or countries to build a complete stack, and even if it was that stack, will only be partially functional. Like the dream that I can control everything. Imagine if you implied it to the internet. Like it is a global system, and so the version or the dream that was mentioned earlier-that somehow that you own and control everything-the unintended. Well, maybe for some governments it's intended, but one of the consequences of those is that you have a fragmented system and you're not fully part of a global process. And so, unless you're one of the few organizations that really can drive the world economy, the more insular you get and the more completely controlled you get, the more you risk falling behind global or regional developments, and so sometimes that will happen even if you're far ahead. So in the early days of the internet, South Korea, for example, was a leader in encryption, and the government developed its own encryption standard, which was way ahead of what else was possible on the internet, but over time, you know, it became embedded and it couldn't change. And so, I mean, as a browser company, you were involved in all of all of these things. And over time, you know, it sort of ossified. And in the early days, it was so good that it was okay for South Korea to be a little isolated and for it to be hard to work with its systems. And you had to really want to and make extra effort because it was really good and you were learning and you could bring some of that to a broader group. But over time, as it as that changed, you know, maintaining those things is hard. You know, it became a real factor for isolation, and so this dream of controlling everything, even if you could, you know, has some other consequences, and so. So I think in this kind of period of instability, where the old partnerships and relationships are changing, it is a time of looking at with whom does one work, how do you work, where is the openness, how do we build the sovereignty more of capacity and options than outright ownership of the total stack, and I'll stop there. Happy to say more, but I'll stop. Thank you. The same question to you.

Liv Marte Nordhaug  5:28  
Thank you, and I, I will complement by first of all. I agree with everything, and I will complement by bringing in some of the perspectives from the members of the Digital Public Goods Alliance. So we're a multi-stakeholder initiative, five with the secretariat, but also actually do stuff. They're the members, and we have 56 members now. 23, no, 22 governments. There are some almost lost. We also have a lot of multilateral institutions, civil society organizations, and some private sector companies. But from a government perspective, what we see, we've seen for quite some time, actually since COVID in particular, that there's been much more adoption of digital public goods to build this identity payment secure data extension in order to deliver services faster, more inclusively. So that came maybe more from that lens than from a sovereignty angle. Actually, from at least from from low middle income countries, there was a lot of push to just you know be able to do vaccine certification and all sorts of things that had to happen quickly. But now with the with the last years, we've seen a real shift towards building first of all open source capacity. So there is a lot of OSPOs open source policy office is coming up, and there's a lot of support for that, also from the multilateral organizations. We're seeing a lot of focus on strengthening the local vendor ecosystem, and I think this is critically important because there's this perception that yes, you can use for digital public goods, but also other open source components. But you really you're not you don't have autonomy and agency if you don't have the capacity to implement them and to do the local you know adaptations and innovations and to maintain and evolve them over time to meet your future needs. So that I think there's this awareness and of course the topic of interoperability comes in very strongly with this, so I would say that that's a strong priority. And I heard Michel mention like who do you cooperate with, and I do see that there's a strong trend towards regional cooperation. So there's this idea of like-mindedness within global, and I think we should not ignore that. And that has always been the case. You collaborate more with those you trust, those you feel. We had a discussion here when we came in. He's Canadian. I'm Norwegian. We're like, oh, we're friends. And I think there's this, you know, there's this perception. And we also see that a lot of adoption comes from countries seeing what other countries are doing, which brings me back to one of the core values of Open here, because the opportunity to actually see and learn from what other countries are doing is so much easier with open source. But I think the critical part that we have to discuss, and I know we are kind of the framing panel, so for later is, for instance, the topic of governance because who governs, who makes decisions, who prioritizes what public interest direction means for these digital public goods and open source components, and that also alludes to AI systems as digital public goods, which is its own tricky one, but but still is the same. So, who defines what public interest is, and how do we govern for that? I think I'll stop there. Thank you, Liv. Paul, the same question to you, but because Liv already touched upon it a little bit, we hear about the middle powers framing a lot when it comes to collaboration in this space. So, if you could speak a little bit with the Canadian hat on, that would be great.

Paul Samson  8:50  
Sure, we know something about sovereignty these days. But I will say that I agree with the comments that have been made by the panelists, including what Tamika started us off with, with some very concrete examples of what you know, like the summary of everything to me would be the following two statements. The first one you hear all the time: "Hope is not a strategy, so you better have a strategy. The second one is, "Autarky is not an option, right? So, as as as Tomika said, for the U.S. and China, who are very dominant in AI, they both have a lot of areas where they're dependent on other countries, other supply chains. Right, you see the way that China has positioned itself on energy, over concerns about you know the access to chips, U.S. rare earth minerals, you know critical minerals. So so there's a lot of positioning here. There is no such thing as pure autarky. So it becomes a question of strategic interdependence. If you're assuming a certain amount of interdependence, you've got to manage that interdependence strategically. So in this question, when you're defining yourself. You're saying what are those critical areas, and we're going to unpack this further in the panel. The must-haves, the protected information, which is sensitive health information, data, national security information. How would you have 100% control and and authority sovereignty over that issue versus some other things where maybe you don't care, and the sovereignty is not an issue, right? And you can you can have interoperable systems that are that are using other systems. So that's the first thing I would say about sovereignty. The link to middle powers, I think, is really interesting because in a moment of geopolitics like we're in now, you can debate whether you know is this 1945, is it 1905 is it you know the time of the French Revolution it might be all of those actually right like because there's so much going on technologically socially politically so we're in that moment of massive change and I think that provokes the sovereignty question amongst the smaller countries that are kind of getting bumped by some big moving pieces, as we often say in Canada, we're a mouse living next door to an elephant, and when that elephant kind of rolls over or sneezes, that can be a problem, right? For us in particular, so it's actually provoked the question of what do you do as a middle power? How do you federate on issues where you can leverage, which we'll get back to in a moment. So, I actually think it's a moment of of kind of power for some of the middle powers, right? That and and you know you can occasionally be stopped by doing something for sure, but I think there are tons of opportunities to do things, and I'll get into a couple of those examples as we go through the conversation.

Vidisha Mishra  11:47  
Perfect, thank you, Paul. So, if we look at concrete examples, then specifically, if we all somewhat agree that all aspects of the tech stack are not equally amenable to collaboration, then what's specific points are most open to collaboration? Can we look at some specific regional or country examples from your experience, Michel?

Mitchell Baker  12:17  
Actually, I think because Leif is right in the middle of it, it's best to start there, and I want to add something that's maybe not quite at the core, but I think important. After that,

Liv Marte Nordhaug  12:26  
they offer it. So the sorry, the question I was sorry

Vidisha Mishra  12:30  
you couldn't ask, Mitchell. The concrete examples of what elements of the tech stack are most ripe for collaboration at the moment, in your experience with the countries that you work with.

Liv Marte Nordhaug  12:40  
Yeah, I mean, so the digital public goods alliance we work with technology side, so we do not so we look at digital public goods which are open source software, data content, and also AI systems. And for AI systems, we are, and I'll just call it out right now. We are saying that for the DPG standard, we are requiring AI systems to have fully open training data, and the reason for that is to set an aspirational standard. And the reason I'm mentioning that is just that we are we don't expect everything to comply with this standard at all. And the idea is to help nudge the field of what is possible forward and make sure we have those conversations. But and I'm mentioning it because of Michel's paper also that this to me is not the most important discussion in the AI field. So the open source AI definition I think is the great floor, and then I think these more aspirational standards like the DPT standard can be. And I'll come back to why I'm actually making a point of saying that early on. So, but we are dealing with the technologies, and I think it's very important that from the secretariat, and then we have the members who are implementing them and are doing different ways also of supporting capacity. What we don't deal with in relation to AI is, for instance, compute and and all of these others. I don't want to speak too much on the stuff that I don't actually work on. But what we do see is that it's becoming increasingly important to talk about governance. We are not assessing governance with the DPT standard. We look into ownership, and we make so. I think that conversation about maturity governance is something that will help us decide where, like, help continued cooperation possible or not. Because I think increasingly in the age of AI, with software and the cost of building new software radically decreasing. Just looking at the code is is increasingly difficult. So I do think it's more that the openness is allowing certain types of collaboration and learning exchanges, and I think that's what we bring, and we're seeing a lot of that in. If, for instance, with digital public goods for digital public infrastructure, you see a lot around payments interoperability. You see on ID, you see a lot of more learnings and best practice exchanges on how to build them out, and also some interoperability happening there across countries. So yeah, we're seeing it all around. You're also seeing it for social technologies, which I'll come back to more later. So for public discourse, there is also more and more happening, more at the protocol level. So I do think that, yeah, it's. Thanks for punting that to me.

Mitchell Baker  15:43  
Do you want to add, or should I? Okay, yeah. I would focus on standards and interoperability at one end, because that's an area that that requires real technical talent, like it is a technical governance mechanism, but I think it's where they meet, because with a good standard, you know, we heard about GSM earlier. I would actually offer TCP/IP, which is the Internet standard, as probably equally impactful, which is a you know a protocol which allows us to have a global network, which is pretty heterogeneous. And so the question I think of interoperability in AI systems and where are the critical points for interoperability? So for example, I got a notice from Anthropic yesterday about their memory, their new memory across chats, which is exportable, so you can take it to other systems, which is really interesting to me. I mean, I wasn't involved in why they did it, but it's a really good piece because clearly, like the memory of what you've got is an important point for for interoperability, and so I think that has a deep connection between policymakers and technologists at the core. So that's one that I would really focus on, and it may well be that compute, you know, you know, hardware resources is another. And then I'll I'll add one, which doesn't necessarily come up so much in government focus as much. But I I would add the consumer product piece, and not to forget that. And because certainly my experience, you know, with Firefox is the power of consumer products. But also, even if your government health data and your national security is secure, priority one maybe, but your citizenry can still be manipulated and de-democratized, and you know, a range of other things through these other products. So I would extend the interoperability piece through to the areas that touch consumer products, so that there is some architectural ability to provide options. Then you need governance and other things to actually be able to do it, but at least the underlying architecture makes it possible to bring in governance. Thank you. Also, concrete examples from you, Paul, and also if you want to touch upon the governance piece of it, because you did recently propose a board.

Paul Samson  18:06  
Yeah, yeah. So two two comments really, and I I really second the points that have been made here. If you think of that tech stack, it's big, and you almost discover different pieces to it the harder you look, right? And so you've got all those, you know, at the at the very base end, energy and things. But I think where there's a lot of discussion right now, where the trickiest elements are, is around access to the most powerful supercomputers, the most powerful models, the cloud, and core data control systems. I think one of the excellent examples of where this federated approach can work is the Lumi, I think it's called in in Europe, which I believe involves 11 countries with access to the supercomputer, and each country kind of has its piece in it and reflects a different contribution and a different usage. It allows for startups to get access that otherwise wouldn't have it, this has been done elsewhere, including with like superpowers, right? You know, if you think of the space station model and and things like that, there have often been intergovernmental models where you can federate access and power, and I think that's going to be big there in in this space, right? We're gonna we're gonna need federated carveouts. Well, the other the other option is a carveout where you let's say you, as a sovereign nation, have a specific deal with one of the hyperscalers. Let's say it you know let's say Anthropic has an IPO and grows to triple its size, and you cut a deal directly with them, there's nothing to say that you couldn't firewall some kind of component of a data center which is 100% sovereign. It's possible to do technically, right? So there, there may be ways to actually work as well with hyperscalers and and big multinational corporations in a way that. Delivers sovereignty, but I think the federated approach is really interesting. So, on the on the the concrete example of what, how does this link to governance? Right, like on the standards, I agree. Standards interoperability. One way to come at that is a model that we've proposed for several years, which is to take the financial stability board, which some of you may not be that familiar with, which was created after the financial crisis in 2008, 2009. There had been a forum that existed before, and then it got supercharged into a board. And that's a non-binding technical conversation about standards interoperability in the financial sector, non-binding, but best practices that you kind of learn from and use, right? And everyone is around the table. The U.S. is there, China is there, Europe is there, developing countries are there. You'd have to have everyone around this table, but I think you could start it by catalyzed in the AI space, we've called it the the AI stability board, and you could catalyze that with just a handful of countries and create this critical knowledge kind of base to to drive some of these concrete conversations around standards and interoperability. And I think the big companies would come. They say they want to be there, and I think the big countries would eventually be involved in that conversation, even if they said we don't need to be there at the beginning.

Vidisha Mishra  21:30  
Thank you for that proposition, Paul. So this conversation is happening on the sidelines of the UN General Assembly. The UN has the new Global AI Dialog. They have a expert committee as well. There is, of course, the country-led AI summits that take place. The G7, G20, others also have working groups that work on standards and interoperability. But I think we can all agree that we feel that progress in those working groups are is a too siloed and it's not happening fast enough. So can I get quick reactions from both of you, Michel and Liv, to Paul's proposition or your own thinking around where these standards will be developed in the future.

Mitchell Baker  22:11  
Yeah. Well, my first thought is that the big companies in the U.S. anyway are asking publicly, anyway, for some way to stabilize the work they're doing, and you know that's controversial, and a lot of people don't believe it and think it's self-serving, you know all sorts of things. But nevertheless, it's still pretty rare for a large, you know, these large technology organizations to to agree that some form of stabilization is important. So I. I think providing a forum for that should be done, right? And and this might well be the forum. So maybe the naysayers are correct, and maybe it's a self-serving marketing ploy pre-IPO. I have no idea, but nevertheless, there's a lot of concern that technology is moving really forward. Let's find out. Like, let's hope it's real and and provide the venue for that, and and see what see what comes of it. I think it will be a bit of an act of hope at first, given that that both the U.S. and the Chinese governments have come out in active opposition. So that does mean that either the middle powers or civil society someone should step up and see whether such a venue can be provided. So I would certainly try to move forward. Liv,

Liv Marte Nordhaug  23:27  
yeah, I'm actually going to provide a slightly different take. Actually, answer a different question, but it's relevant, and it's just because I think it's so incredibly important. Because if you were, if you were to ask me what I think is the most important topic to focus on with regards to advancing public interest AI today. I would say it is to save the public discourse, and the reason for that is how can we ensure we manage to have the right conversations and actually to stay on track with them because it's so incredibly easy to divert our attention away from the topics we're trying to think about, and that require like really deep and complex and concerted actions, and and to your point about the strategic interdependence between middle powers, and I would also within that say you know government, civil society, private sector, there is so many stakeholders that need to kind of pull in a somewhat aligned direction, but then what happens to the discourse, to our attention? And I will actually use-I'm not going to name anyone. It's no one in the room. But I had an example just before I left Norway, where two extremely, extremely brilliant people who are critically needed for advancing very important conversations about, for instance, how to strengthen the public discourse in Norway ended up squabbling about whether or not AI will kill us all in the next 10 years or the next 50 years, and I think it's kind of like they agree on the important stuff. I think all of us are feeling a lot of anxiety about all of the unknowns here, which is normal and natural, but if. We end up always being reactive to those discussions that are being positioned. It is very, very hard for us to stay focused on getting stuff done that we want to do and to advance alternatives. And for democracies, this-and I will say for democracies because I think it's very different. In if if one person makes a decision that's different, but in democracies where it doesn't work like that, where actually many different stakeholders have their say we need to be able to stay on track. Therefore, and also, I think it is so incredibly important. And now I'm going to get to standards because in the public discourse, where, for instance, and I actually think there is some leadership coming out of Europe, but not only Europe there, because there's a lot of stakeholders that are non-European involved in that, and that is the European Social Stack. Basically, what is happening on 80 Proto, which originated in the US very much, but where you now have Eurosky building on top of that, you have Activity Pub, and you also have Matrix. So you have three very important protocols, but there's also a lot of cooperation and actually an attempt to have this kind of shared movement building on top of it. In the beginning, everything was about the protocols quarreling about which ones were the right ones, and there was infighting. But now I see a very promising tendency towards like this realization that we're never going to be able to advance alternatives if every if we can so easily be made to quarrel internally. So my point here is who frames the topics we end up discussing, and for the day to day, my wish is that like make sure to have the important discussions, and if there's kind of some kind of marginal discourse, which can easily be solved like by two people actually just sitting down together and working it all out, don't spend time doing that when you have all of these brilliant minds together. Because we so often end up doing that. So I actually think that's our top priority. Because if we can't have a good conversation about how to address these things, we will get hijacked into being reactive, and then we won't fix it. That's probably a bit scary, but it's true. But I think the alternative is we can do something. That was a bit of a complex answer.

Vidisha Mishra  27:16  
No, thank you, Liv. Certainly, from from an EU point of view, the integrity of the information space is a huge topic and its implications for democracy at large. So I do appreciate you bringing that conversation out. And just you know, Michel, obviously from your experience, the potential of open source and open data for public interest social media is that something that you see as an important topic, going beyond some examples that Liv mentioned.

Mitchell Baker  27:46  
Well, this takes me back to the consumer product piece. I mean, the hope was that Matrix and Activity Pub would really take off when Twitter shifted to X, but it didn't happen, and you know the number of people still using X and claiming how much they dislike it, but they need to be there is really high, and so that's a slightly different, you know, it's it's a different aspect of sovereignty. I would say I think that addressing that is more important than complete ownership of the stack. You know, you may own your government stack, but your citizens are being riled up. And so, the consumer product piece is a really hard piece, and it's by almost by definition not a government piece or a governance piece. And that's why I think that open source and collaboration, and support systems and environments from government and governments to enable probably a global or regional open source project is actually really critical. I mean, those projects aren't ideal at or they're not as much aimed as consumers. There aren't as many. Mozilla is a rare one, but there are a number, and and the messaging apps that you mentioned are there and and and definitely getting better and have solved many of the problems that were there when you know Twitter became X, but it's kind of kind of too late. So I would say from a government and government's perspective, is building that environment. It may be requiring standards and interoperability, which is again technically very hard, and it's very easy. I'm a believer that regulators are smart. Like in the U.S. it's nice people like to say, "Oh, regulators, they don't know anything. And I'm like, "Well, no, that's not true. Especially in the EU. I mean, the regulators are very smart. The problem is the remedies are very hard, and you have to really be determined, and you have to have the support of your public to be able to say to one of these companies or all of them, no, you must behave this way, and we can see that Europe hasn't quite gotten there yet because the remedies are irritants. Now they may also change business, but but as a consumer, you know, a lot of times they're really irritants. And you know, I should be careful when I say that. I'm a big proponent of these regulators and. Mozilla has worked hard on a lot of these regulations, and we think there's steps forward, but it is very hard to figure out what is the right remedy. And so, this interoperability, especially around data, around identity, around what things are, is a fundamental area. And and and again, I don't want to be quoted out of context. So I think Europe has made really important strides in understanding, but the actual will, like it gets pretty deep into a business and a product, if you start looking in and saying these are the areas that are required for interoperability or real export, and so that requires maybe it's the dialog you mentioned, citizen support in a democracy, and and are we however much we say we want this stuff as consumers, are we willing to have a change or an inconvenience? Like not yet. That's why X is still there. Not yet. So, so there's something about that dialog. There's something about taking the experience in Europe and continuing its evolution. You know, like the remedies are hard. I don't have them either. You know, all the way back to the Microsoft antitrust case, or the last one, like U.S. federal system says that Google's a monopolist, but there's no remedy. So, so this is this is the problem: the changes in law, like what would a remedy look like? The changes in consumer understanding to support such a thing, and then the technical engagement.

Vidisha Mishra  31:25  
Thank you, Michel Paul. Anything to add here? Because even in our research, that we came across very few examples of international collaboration, and the ones that we came across were all based in Europe. So, from your point of view, how do you see that developing in Canada going forward,

Paul Samson  31:42  
well, I think that there there are a lot of opportunities so far. If you if you almost want to characterize it as the AI space has evolved around the poles of of the U.S. and China, and then the U.S. model mostly being just let innovation roll, the Europeans being let's let's put in some regulation and kind of make sure it's tight enough, but maybe not too tight. And then the rest of the world kind of like somehow waiting to some degree. You know, other India's got its own model to some degree, but the rest of the world has been kind of waiting for something to happen. Problem is, it's not happening, right? Like it's not kind of telling you what to do, the system is just charging ahead. So I think we are at that moment when it really makes sense for these these coalitions to to broaden out, right? And I think there was there was an article in the Financial Times this morning, I believe, or last night, co-signed by leaders from Kenya, Brazil, Canada, and Norway, I think maybe one European country, and it was saying we need to work together in ways that we have not done previously, right? And that's a that's an interesting group of countries, right, that have not been outspoken at the leader level, so I think it's about to crack, and I think AI is is the place to go. I just want to make one other comment, which I think Michel said really well, which is the question is the stabilization, right? Like I personally don't think there will be a pause because I think it's it's like an arms race to some degree, or certainly an economic race, and so I don't think there will be a pause, but there needs to be stabilization. That's what happened to the big banks after the financial crisis. It's like you have to have enough liquidity in your reserves to pay out in a crisis, and we're going to force you to up that number, whether you like it or not. So let's sit around the table. It's coming. Let's have this group around the table and figure out how to do this through kind of a a voluntary way. And they did right. They didn't have to really be. And then domestically legislation would follow that's customized to your own situation. This is not about some kind of massive harmonization. There has to be local fit, right, and that you can still have differentiation.

Vidisha Mishra  34:07  
Thank you. I mean, it's very clear that we have to take a scenarios-driven approach to this entire conversation. There may be a pause. There may not be a pause. What was very clear in our discussions with policymakers was that they recognize a capacity deficit within themselves. A lot of them actually use that phrase that we feel like we feel like we're flying a plane while building it. So, in your interactions with policymakers or other stakeholder groups, specifically you live since you have a large coalition of policymakers that you work with. How do you foresee fulfilling that gap? Because to our mind, one of the central ways the collaboration can take place is this more peer learning, and specifically those that identify as emerging and middle powers can teach each other and help fill those gaps.

Liv Marte Nordhaug  34:50  
Yeah, I mean I'll be super specific. We happen to be convening a big event tonight, which I'm going to run over to later today, which is in. It's an initiative. It's a campaign called 50 in Five. So it's about advancing safe, inclusive, interoperable digital public infrastructure in 50 countries in five years. And the reason the Digital Public Goods Alliance is involved in co-coordinating that with a fund called Co-Develop is because many of these countries are actually using and sharing digital public goods, and tonight we have awards. And the reason I'm mentioning it is what I've seen. So this we launched this campaign at the end of 2028, and now we have 39 countries as of today that have joined. And what we're seeing is they are from all income levels and from all continents, and we're seeing that the learnings and best practice exchanges they cut completely across the directions that many would expect. I've heard so Norway has been a part of this line since the beginning. So I've heard Norwegians say, "Oh, I learned so much from that guy from Cambodia who was sharing something about you know, and I think we should not underestimate that. But I do think again the opportunity, because what we're doing there with like very practical learning exchanges, it is to allow countries themselves and representatives to define their priority topics. And like, I am really you know struggling with this issue, and then we convene like virtual learning exchanges where those that have actually been doing something on those join and it's a very lightweight thing and I think that's important and and it's very kind of operationally focused and just like and you do see that because many of these many of these individuals they are also agents of change in their own organizations. Three innovators-they're really struggling against a lot of friction and, like, you know, trying to get things done that haven't really been done before. Trying to get the silos-you mentioned that in the report, right? So there's a lot of sector silos and reasons why things often don't work so well. Sharing of information and data. So just allowing these people to meet-it's incredible how much comes out of that. And that's also very much what we do with the DPK. But tonight we have the award for 50 and five for the first time. And I can of course not say who's winning anything. But what I can say is that the categories we have is the first one is very obvious. It's impact, so it's basically like who can demonstrate very tangible progress on inclusion, for instance, and those things. But we also have collaboration as a category in and of itself, which I'm very excited about because it is to recognize that. And then the last one is individual leadership, as in individuals that are demonstrating how you navigate. So I actually think there's a lot to be done by just making sure you can identify and bring together country representatives, and it doesn't have to be. We don't have to overcomplicate some of that. And and I, but I don't think we should assume always who are the sharers, the learnings and best practices, and who are the kind of receivers. And there's no such thing as givers and receivers in this space, anyway, because it's very kind of neutral, and it does not follow traditional. I worked in international development for many years, and it doesn't at all follow the idea of like who is the donor and who is the recipient. It's very different actually, and it's very very refreshing, I will say.

Vidisha Mishra  38:20  
Thank you, and Paul. The same question to you on the skills and capacities piece. Do you foresee a lot more collaboration between middle and emerging powers just to sort of help bring each other up to speed? And as Liv was saying, it's not as if only policymakers need to understand what technology is. It goes both ways as well. So, what are again? My question is, who is going to lead this? Who's already doing it, perhaps? And what are the venues for this to happen?

Paul Samson  38:46  
Well, I think there there are a lot of training pieces that already exist, right? Like if you think of you know the UN system, I think it's called UNITAR, right? The UN Institute for Training and Research, and there there are a lot of bodies that could help provide this, right? The UN'S going through a reform process right now. I think they should tilt to some directions there, but it's going to have to be more than that. There's going to have to be more. There's going to have to be some funding provided. You know, maybe it's with a development lens, right? Because a lot of the the poorest countries are are really concerned that they're going to be cut out completely, and that they don't have the capacity at all. So I think that should be starting to be get built in more to core development discussions, whether it's at the World Bank or bilaterally. It's harder to imagine a coalition mobilizing around that, but I think through those existing mechanisms, it should become a national priority to make sure it's given. Thank

Vidisha Mishra  39:49  
you. And also examples: Germany has something called the Sovereign Tech Agency to the funding point that helps open source maintainers, but there are very few examples. Of that, and of course, a lot of the the conversation from global South countries often is that most of the open source maintainers and funding for it are in the global north. So, just you know, for open source to become more dominant as an approach, there will be the need to have more of that capacity and funding. Liv, you had a point.

Liv Marte Nordhaug  40:18  
Yeah, yeah, I have 222 comments to that. So first of all, I very much be in the need to reform, and I think this is actually not so much about necessarily increasing the financing available, but it's about shifting how it is used. Because I mean, I worked a lot with the World Bank over the years, for instance, and in agriculture, you've seen support for same types of systems rollouts in 50, 60 countries. Right, each system gets built very similar 60 times. That's not doesn't make sense from from a cost effectiveness and value for money perspective at all. So I do think shifting procurements, some procurements, is done to make them more supportable open source is is critical, and it's that's the conversation we're deeply involved in, and also to encourage contributions back. You have a large, evolving vendor ecosystem with the big international companies, Ernst and Young and KPMG, and all of them are, you know, increasingly seeing the business opportunity in supporting implementation of open source for building also digital public infrastructure. But how do you ensure that there is contributions back to stewardship of the core open source projects? That's critical. But lastly, and I will bring in an AI topic, and again, like a conversation that I think, if there is any kind of rallying call that we should come out with, is with the cybersecurity risks that are coming now with very very powerful AI systems that can be used to to attack open source projects. Open source is particularly vulnerable also because of the way and if you look at the widely deployed digital public infrastructures, right? How do you do patching? How do you identify vulnerabilities? There's a lot of forking often in how they're implemented. So I think we need to also really, really demand that the companies that have made this risk happen so fast and so urgent that they actually really, really help also on protecting these vital digital commons and digital public goods in the short term, while we figure out those, because I think there are many. I don't want this to be the end solution that we're dependent on the same companies creating the risks to to to manage it in the long term. But in the short term, that is this is actually a critical risk, and it's something that many digital public goods have alerted us to, and which is obvious. And I think we should just like it's it's common sense, right? So I think we need to find strategies in the short term, but also again to just kind of like remind like who who created this situation? Why are we in this situation that we have to move so fast? And things are being broken, like move fast and break things. Yes, but who is moving so fast? So I think we should really, really demand that there is critical support for open source to manage the risks now, so that we don't end up having those being the they're very easy to target. Some of those that are most deployed, particularly for building out foundational digital public infrastructures in many countries that are not well set up to to protect themselves. So I think this is a critical point. Thank you, Michel. Your reactions to the critical the funding and financial support for open source, and Liz's idea that perhaps some of the same companies could be held accountable and asked also to help maintain the possibility of that.

Mitchell Baker  43:45  
Let's see. There's there's two topics there in the short

Paul Samson  43:47  
term.

Mitchell Baker  43:48  
I'll start on the latter. For for the how and when and where and why would this handful of companies support public benefit. I'll say one: there is some voluntary stuff, like like in that list of first released, where an anthropic made mythos available to a set of companies. There were open source projects involved in that, right? Voluntarily, Mozilla was one. I think Signal might. Anyway, so so so there is some, but but I think you're looking for something broader and more systematic, and maybe it's anything that's identified as a digital public good. I mean, there's got to be some standard, so maybe your or provides the standard. It might happen voluntarily, like because we've seen some of these voluntary things. But if it doesn't, then that's a regulatory kind of government piece, and then on the other piece, on the capacity piece, for a long time, open source, and still today, often if you ask people what does it mean, it means free. I can just take it, use it, and it's free, which is true. In a very very narrow sense, but not actually true for the cost of the software and the long term impact of it. So one thing that I think might be very useful in in the institutional training piece is an understanding of the depth of open source. And yes, it is free; you can actually grab it and use it. But if you don't contribute, a lot of things happen. One is the commons, but the other thing is your own sovereignty declines. You have no more capacity. You have no more understanding. You're not paying anything, which is better than paying and having no capacity, and having no one accountable for it. You know, so it's better, but really in the short term, you know, and the long term, you're you're subject to you know a whole set of risks, and so there is a lot of learning, and so I'm on the board of a an open source project, open source medical record systems, Open mrs. so highly used, and increasingly becoming the basis for national deployments. It's been like started in hospitals and clinics, so small deployments, which does the development through sort of local businesses and building local capacity? So they're the implementers. It's not that you come back to some center thing in the U.S. to pay and be stuck. It's building a set of local capacity there. But as it's becoming the basis for national healthcare systems, there's another process of how does a health ministry engage? How is the minister of health and their staff both comfortable and confident that they can rely on this? And how and when do they learn how to contribute and where to contribute and how to collaborate? And so that particular one is happening through the digital public good itself, right through through Open mrs. itself, and I imagine it's happening through a range of the other digital public goods, and I think there's probably a UN kind of like a overall. What does it mean? How to participate? If you take just the free part, you know your long-term future is also not as secure or sovereign or whatever is what you want, and certainly there's a number of these projects where the contribution back can also be the capacity building in your own population, and thus the ability to go to local sources for changes and improvements and development, and not get stuck, as many of these governments have with their productivity apps and so on. So, hi there.

Vidisha Mishra  47:27  
Thank you. That is a great note to end the conversation on. Paul, you said hope is not a strategy and autarky is not an option. One line from each of you, because we all will be participating in several conversations over the next week. If we want to advance open collaboration and open sovereignty, what is it that we collectively need to focus on?

Paul Samson  47:50  
Well, if you're a country, I think you look at your sovereign capacity on the issue you you want to focus on, right? Cloud or data platforms, and you ask yourself, what elements do you control? Can you audit things? Is substitutability an option? Could you leave that system and still be standing? Right, and we found that in some cases the answer is no, and that that's where kind of the red light goes off. Right, but in other cases the answer is not no. So this is not a panic. That's a long sentence. So, in there.

Liv Marte Nordhaug  48:24  
Thank you. Same question. I agree, and I'll be very brief and very meta. I would say make sure to have the right conversations and to say no to having the trivial conversations. I would just keep it at that. Don't get distracted. Don't get distracted. Final word, too, Michel. Collaboration is key. Thank you so much, and hope you have great discussions all day today. Thank you. The

Announcer  48:55  
Engelberg Center Live Podcast is a production of the Engelberg Center on Innovation, Law, and policy at NYU Law, and is released under a Creative Commons Attribution 4.0 International license. Our theme music is by Jessica Batke, and is licensed under a Creative Commons Attribution 4.0 International license.