The long-rumored layoffs at Xbox have come and they are massive. We just recently discussed the mess that Microsoft’s Xbox division has become. An internal email that was sent to staff by CEO Asha Sharma laid out just how bad things were, essentially preparing the staff for the forthcoming staffing cuts. Interestingly, this is the latest in a series of staff cuts, many of which have been at studios that Microsoft recently acquired and told the FTC and the courts that there wouldn’t be layoffs in order to get the acquisitions approved. Those were lies, of course, but there won’t be any punishment for those lies. Regulation is just so un-American, you know.
This round of layoffs will effect over 3,000 staff members eventually, or about a fifth of the Xbox division workforce. The appetizer this past week accounts for about half that number. Working at Xbox right now must be buckets of fun, where you get to try to perform quality work while wondering if your name is on some list somewhere. An email went around again acknowledging the layoffs, as well as several Xbox studios going independent.
This email, shared with Kotaku, says that 1,600 of those layoffs will take place today, while the rest will take place later. Compulsion Games and Double Fine will become independent studios, while Ninja Theory and Undead Labs “have entered terms to join new ownership with funding to complete and grow Senua and State of Decay 3,” though the specifics of that have not yet been disclosed. Arkane Lyon is entering legally required “consultation” in France to review its options, and its fate remains unclear.
Layoffs will also take place in varying sizes across Activision, Bethesda/ZeniMax, Blizzard, King, Mojang, and Xbox Game Studios, though Sharma stated that none of Xbox’s first-party, publicly announced games or projects are being canceled as a part of these cuts. Mojang and King will now report directly to Sharma.
Again, several of these studios experiencing layoffs were recently acquired by Microsoft and, during regulatory proceedings, Microsoft said that layoffs wouldn’t occur. And, again, there will be no consequences for these lies, other than those felt by these ex-employees who no longer have a job.
Interestingly, these layoffs came along with a message that Xbox was going to start getting real lean on where it focuses its staff and money investments, primarily into “core franchises” in the gaming space. Despite that message, we’re already hearing about how these layoffs will result in the delay of current production of games in those very core franchises.
Speaking on condition of anonymity to protect their careers, current and former staff have told me that job losses across Bethesda Game Studios locations have removed more than 50 employees, including “key, high-performing people in the trenches” building the company’s long-awaited Skyrim successor. This in turn, they say, has shattered morale, raised the risk of future development crunch, and increased the likelihood that the game’s already far-off completion date will be delayed.
If you’re interested in how Xbox management is behaving in the midst of all of this turmoil and the obviously negative emotions of the remaining employees, well, it’s been awfully fucking shitty, honestly. Several Bethesda offices saw employees setting up “Celebrations of Service” in common areas, where staff members put up pictures of and messages to ex-coworkers to show their appreciation for all they’d done. That same day Xbox HR ordered that those memorials be taken down, all under the bullshit excuse that you can’t do that sort of thing in a common area.
“Unfortunately, HR made our office manager take this down almost immediately,” posted the union account. “They said because it’s in a common area, it had to be removed. We’ve used common areas for many things as a team, including fan works, but HR seems to believe that a Celebration of Service is inappropriate.”
And, since you can’t have real American capitalism in the modern era without getting a heavy dose of irony to go along with it, Asha Sharma herself was recently named to a task for at the Federal Reserve to advise on “jobs and productivity.” This is a bit like the FDA putting Hannibal Lecter on its advisory panel for a proper nutritional diet.
“The Federal Reserve’s commitment to price stability and maximum employment is unwavering. As is our resolve to pursue our mandate with rigor,” Fed Chairman Kevin Warsh said in a press release on July 9. “The U.S. economy has changed significantly over the last generation, and never more so than right now. Each task force will carefully consider whether policymakers’ means and methods, analytical tools and policy approaches can be improved upon. I am honored that the best minds from a range of disciplines have agreed to work with us to sharpen our performance as an institution. The goal is straightforward: to ensure the Fed is best positioned to achieve our objectives in this consequential time.”
Maximum employment? What an interesting concept for someone who just instituted historic layoffs to advise on.
So, how are things going at Xbox? Pretty fucking horrible. Layoffs, tone-deaf executives, delayed games, poor morale, and a workforce living in fear that they might be next. And I just can’t help but to return the point that much of this is a result of overextending acquisitions of enormous developers and publishers in the last five years, during which the company promised this very thing would not happen.
As we mentioned previously, the Stop Killing Games movement has come to America and there is currently an effort to get some legislation based on the movement’s goals on the books in California. The movement hit a snag recently when the written version of the bill failed to make it out of committee on a vote of 4 in favor, 3 against, and 4 abstaining. It’s the abstaining votes that were the problem, resulting in not enough yes votes to move forward. But, importantly, the committee also left the door open to reconsider the bill at a later time.
The committee unanimously voted in favor of granting the bill reconsideration, meaning it could come back before this group of state senators. Assemblymember Chris Ward introduced the bill in February and it passed the California State Assembly 43-16 in late May.
That said, the abstentions prevented the bill’s progression for now. “Not enough yeses means the bill stops here for this session,” a volunteer with the Stop Killing Games campaign (which supported the bill) noted on Reddit. “That is the loss.”
There was active lobbying against the bill in committee hearings, primarily from the Entertainment Software Association (ESA). And what is now getting a great deal of attention is the fact that ESA’s lobbyist either lied to the committee in those hearings, or else they have absolutely no fucking clue what they’re talking about. And if you need the prime example of what we’re talking about here, you need only understand that one lobbyist claimed that anyone hosting a private Minecraft server is doing “illegal piracy.” The lobbyist in question would be Jennifer Gibbons, the ESA’s VP for State Govt. Affairs.
Gibbons was responding to a comment made by California state assemblymember Chris Ward—who introduced the bill—regarding the possibility of keeping games alive with private servers. “Minecraft is currently hosted by community servers, Call of Duty [has] community servers, so it’s an option that is out there, in existence here today.”
Gibbons cut in: “They’re illegal. They are not in any way affiliated with Microsoft. Microsoft, for Minecraft, has gotten a lot of criticism because of those community servers not employing the same safety standards that Microsoft does on their Minecraft servers.”
Asked by California state senator Caroline Menjivar as to whether this was “like the black market of videogames?” Gibbons responded “Yes. In fact, we consider it piracy. We have lawsuits, two pending lawsuits, against private servers right now, and the United States Trade Representative (USTR) in their Notorious Markets Reports on counterfeiting and piracy has named some of these big private servers as a notorious market.” A notorious market refers to a market where intellectual property infringement is rife—think something like The Pirate Bay.
The ignorance here, if that’s what this is, is astounding. As PC Gamer goes on to note, it is true that select private Minecraft and COD servers have been designated as notorious markets by the USTR in some cases. Those are servers that actually do make some games playable without the otherwise required subscription. World of Warcraft servers are a common target for this sort of designation.
But to map that onto Minecraft private servers, which are not only allowed to exist, but actively encouraged in use by Microsoft directly, is insane. The way you host a private Minecraft server, to start, is by going to Microsoft’s own site to get the .jar file you need to run it. The company is making it available, knowingly and on purpose. In no sense is that piracy, copyright infringement, or illegal. Like… at all.
Given the opportunity to correct themselves, however, the ESA doubled down.
In a statement to PC Gamer, the ESA wrote that, so far as it’s concerned, “Private servers infringe on the intellectual property (IP) rights of game publishers. Publishers reserve the right to exercise their rights against them.”
Private servers only infringe on the IP of game publishers if they restrict their use. That’s the entire point that the folks at Stop Killing Games are making. If publishers don’t want to keep their online games available, they could simply allow, or be compelled to allow, private servers to do the job for them. If it’s allowed, it’s not piracy. This really isn’t that hard.
I honestly have no idea whether this is ignorance or malice at work. I find it very hard to believe that someone in Gibbons position could possibly be this confused on a topic she’s been tasked with lobbying against. On the other hand, the claim is so plainly wrong that it’s an incredibly stupid lie if that’s in fact what this is.
Hopefully this sort of thing will be part of the discussion when, or if, the legislation is reconsidered in the future.
There’s something going on over in Microsoft’s Xbox division and it isn’t good. Don’t take my word on that. Apparently the bosses over there are circulating an email to staff talking about how properly fucked everyone is if something doesn’t change soon.
Xbox CEO Asha Sharma and Xbox Game Studios head Matt Booty just sent an email out to all Xbox employees with a clear, yet terrifying message: “this cannot continue.”
Shared publicly via Xbox Wire, the email paints a picture of a broken division, bogged down by the weight of both years of unsuccessful investments and unchecked excess, and battered by the winds of outside economic forces. Sharma, now having been in charge for 100 days, has made it clear that what she is spearheading is indeed going to be a hard reset, complete with hard decisions that will make or break the division and ripple out through the lives of its thousands of employees.
The letter itself attempts to paint a rosy picture at the outset, but then lays out the challenges. The Xbox division has a 3% margin, which is laughably low. The crises in pricing and availability of computer component parts is out of control and likely to get much worse, thanks in no small part to the bumbling buffoons who currently run the country. Complex internal and vendor relationships have led to communication issues and speed-to-market deficiencies throughout the division. Pretty much everyone agrees that there are mass layoffs coming to the Xbox division as a result of the above. And then there’s this:
We expanded our studio system when we needed a pipeline of content to meet multiple strategies across subscription, streaming, and devices. In the process, we have found ourselves over extended as we executed on changing strategies in a landscape of more readily available content. We are the fortunate stewards of industry-defining franchises that have enormous potential and player demand, but we have not adequately funded them to compete and win. At the same time, as we saw this past weekend at Showcase, a reliable pipeline of first- and third-party exclusives and new IP are critical to our success. We need to reassess the balance between these and our investment priorities for the next 5 years.
There are two, separate things being stated here. Let’s take them in order, because both are important.
The expansion of the studio system being a problem is absolutely hysterical. Xbox does indeed have a hefty portfolio of studios operating under its ownership. More than half of those studios came over to Microsoft in the Zenimax and Activision Blizzard acquisitions. Both acquisitions came with regulatory challenges, the latter being far more involved from the FTC. Both acquisitions also got past regulators in the courts specifically by being positioned as vertical acquisitions rather than horizontal acquisitions, meaning that there wouldn’t be “efficiency layoffs” as a result of bringing them on board, and that the acquisition would lead to lower prices, better games, and faster development for the gaming public.
Here is the Xbox people themselves saying that it isn’t working and that the sprawl of the studio system itself is having a negative effect on game production.
Oh, and about those layoffs that wouldn’t happen? They began happening in January of ’24, leading the FTC to point out to the court that it had been lied to. Then came the Zenimax studio layoffs in May of ’24 and more Xbox layoffs in July of ’25. All while the current, new Xbox bosses complain that they are overextended in terms of their studio sprawl? Cool.
Then there’s the second half of the quote, in which it appears that the Xbox strategy will return once more to a strategy built in part of stupid, dumbass console exclusives to try to entice people to buy Xbox devices. Matt Booty, Xbox Chief Content Officer, elaborated on this recently in an interview.
“[We] want people to have a reason to get on board with Xbox,” Booty said. “We want them to have a reason to buy an Xbox reason to be an Xbox fan. At the same time we want to reward all our players that have been with us for a long time. We know that exclusives are important. That’s why we got Gears coming in 2026, Clockwork in 2027.”
He continued, “We also want to be clear, our big multiplayer games, live service, games are going to continue to be multiplatform. If we’ve promised something to players already, we’re going to honor that promise, right? And then we’re going to really, I think Asha said it, we’re going to make the right decision, not the fast decision.”
The Xbox team has never been able to get its story straight on console exclusives. But when you’re clearly running in third place in a console war that consists of 3 consoles, and you’re not particularly competitive at that, trying to coerce your way into console success by holding games hostage to your platform is a recipe for destroying gaming franchises and still losing the console wars.
There’s a very good reason that the trend over the past decade or so has been one of less exclusivity, not more. Getting games out there, particularly when you’re directly publishing a bunch of games because of that same studio sprawl we talked about earlier, is the most important thing for the bottom line. Xbox should want all the games it publishes itself to be on every platform everywhere, in order to maximize sales. Spending money on third-party exclusives makes little sense, either, particularly when you clearly have a console series in decline.
I imagine it must be a very uncomfortable time to be an Xbox employee. And that’s too bad. I have no doubt there are a ton of good people working there and at their studios. But I’m not going to pretend to be surprised that Xbox overall as a platform is not doing well, considering all the lies, the acquisitions that probably shouldn’t have been allowed, and the chaos in messaging that has come out of that group.
Of course, that discomfort apparently applies directly to some of the top execs who reported directly to Booty, who have started to get out before the situation gets even worse.
In late 2024, the federal government’s cybersecurity evaluators rendered a troubling verdict on one of Microsoft’s biggest cloud computing offerings.
The tech giant’s “lack of proper detailed security documentation” left reviewers with a “lack of confidence in assessing the system’s overall security posture,” according to an internal government report reviewed by ProPublica.
Or, as one member of the team put it: “The package is a pile of shit.”
For years, reviewers said, Microsoft had tried and failed to fully explain how it protects sensitive information in the cloud as it hops from server to server across the digital terrain. Given that and other unknowns, government experts couldn’t vouch for the technology’s security.
Such judgments would be damning for any company seeking to sell its wares to the U.S. government, but it should have been particularly devastating for Microsoft. The tech giant’s products had been at the heart of two major cybersecurity attacks against the U.S. in three years. In one, Russian hackers exploited a weakness to steal sensitive data from a number of federal agencies, including the National Nuclear Security Administration. In the other, Chinese hackers infiltrated the email accounts of a Cabinet member and other senior government officials.
The federal government could be further exposed if it couldn’t verify the cybersecurity of Microsoft’s Government Community Cloud High, a suite of cloud-based services intended to safeguard some of the nation’s most sensitive information.
Yet, in a highly unusual move that still reverberates across Washington, the Federal Risk and Authorization Management Program, or FedRAMP, authorized the product anyway, bestowing what amounts to the federal government’s cybersecurity seal of approval. FedRAMP’s ruling — which included a kind of “buyer beware” notice to any federal agency considering GCC High — helped Microsoft expand a government business empire worth billions of dollars.
“BOOM SHAKA LAKA,” Richard Wakeman, one of the company’s chief security architects, boasted in an online forum, celebrating the milestone with a meme of Leonardo DiCaprio in “The Wolf of Wall Street.” Wakeman did not respond to requests for comment.
It was not the type of outcome that federal policymakers envisioned a decade and a half ago when they embraced the cloud revolution and created FedRAMP to help safeguard the government’s cybersecurity. The program’s layers of review, which included an assessment by outside experts, were supposed to ensure that service providers like Microsoft could be entrusted with the government’s secrets. But ProPublica’s investigation — drawn from internal FedRAMP memos, logs, emails, meeting minutes, and interviews with seven former and current government employees and contractors — found breakdowns at every juncture of that process. It also found a remarkable deference to Microsoft, even as the company’s products and practices were central to two of the most damaging cyberattacks ever carried out against the government.
FedRAMP first raised questions about GCC High’s security in 2020 and asked Microsoft to provide detailed diagrams explaining its encryption practices. But when the company produced what FedRAMP considered to be only partial information in fits and starts, program officials did not reject Microsoft’s application. Instead, they repeatedly pulled punches and allowed the review to drag out for the better part of five years. And because federal agencies were allowed to deploy the product during the review, GCC High spread across the government as well as the defense industry. By late 2024, FedRAMP reviewers concluded that they had little choice but to authorize the technology — not because their questions had been answered or their review was complete, but largely on the grounds that Microsoft’s product was already being used across Washington.
Today, key parts of the federal government, including the Justice and Energy departments, and the defense sector rely on this technology to protect highly sensitive information that, if leaked, “could be expected to have a severe or catastrophic adverse effect” on operations, assets and individuals, the government has said.
“This is not a happy story in terms of the security of the U.S.,” said Tony Sager, who spent more than three decades as a computer scientist at the National Security Agency and now is an executive at the nonprofit Center for Internet Security.
For years, the FedRAMP process has been equated with actual security, Sager said. ProPublica’s findings, he said, shatter that facade.
“This is not security,” he said. “This is security theater.”
ProPublica is exposing the government’s reservations about this popular product for the first time. We are also revealing Microsoft’s yearslong inability to provide the encryption documentation and evidence the federal reviewers sought.
The revelations come as the Justice Department ramps up scrutiny of the government’s technology contractors. In December, the department announced the indictment of a former employee of Accenture who allegedly misled federal agencies about the security of the company’s cloud platform and its compliance with FedRAMP’s standards. She has pleaded not guilty. Accenture, which was not charged with wrongdoing, has said that it “proactively brought this matter to the government’s attention” and that it is “dedicated to operating with the highest ethical standards.”
Microsoft has also faced questions about its disclosures to the government. As ProPublica reported last year, the company failed to inform the Defense Department about its use of China-based engineers to maintain the government’s cloud systems, despite Pentagon rules stipulating that “No Foreign persons may have” access to its most sensitive data. The department is investigating the practice, which officials say could have compromised national security.
Microsoft has defended its program as “tightly monitored and supplemented by layers of security mitigations,” but after ProPublica’s story published last July, the company announced that it would stop using China-based engineers for Defense Department work.
In response to written questions for this story and in an interview, Microsoft acknowledged the yearslong confrontation with FedRAMP but also said it provided “comprehensive documentation” throughout the review process and “remediated findings where possible.”
“We stand by our products and the comprehensive steps we’ve taken to ensure all FedRAMP-authorized products meet the security and compliance requirements necessary,” a spokesperson said in a statement, adding that the company would “continue to work with FedRAMP to continuously review and evaluate our services for continued compliance.”
The program was an early target of the Trump administration’s Department of Government Efficiency, which slashed its staff and budget. Even FedRAMP acknowledges it is operating “with an absolute minimum of support staff” and “limited customer service.” The roughly two dozen employees who remain are “entirely focused on” delivering authorizations at a record pace, FedRAMP’s director has said. Today, its annual budget is just $10 million, its lowest in a decade, even as it has boasted record numbers of new authorizations for cloud products.
The consequence of all this, people who have worked for FedRAMP told ProPublica, is that the program now is little more than a rubber stamp for industry. The implications of such a downsizing for federal cybersecurity are far-reaching, especially as the administration encourages agencies to adopt cloud-based artificial intelligence tools, which draw upon reams of sensitive information.
The General Services Administration, which houses FedRAMP, defended the program, saying it has undergone “significant reforms to strengthen governance” since GCC High arrived in 2020. “FedRAMP’s role is to assess if cloud services have provided sufficient information and materials to be adequate for agency use, and the program today operates with strengthened oversight and accountability mechanisms to do exactly that,” a GSA spokesperson said in an emailed statement.
The agency did not respond to written questions regarding GCC High.
A “Cloud First” World
About two decades ago, federal officials predicted that the cloud revolution, providing on-demand access to shared computing via the internet, would usher in an era of cheaper, more secure and more efficient information technology.
Moving to the cloud meant shifting away from on-premises servers owned and operated by the government to those in massive data centers maintained by tech companies. Some agency leaders were reluctant to relinquish control, while others couldn’t wait to.
In an effort to accelerate the transition, the Obama administration issued its “Cloud First” policy in 2011, requiring all agencies to implement cloud-based tools “whenever a secure, reliable, cost-effective” option existed. To facilitate adoption, the administration created FedRAMP, whose job was to ensure the security of those tools.
FedRAMP’s “do once, use many times” system was intended to streamline and strengthen the government procurement process. Previously, each agency using a cloud service vetted it separately, sometimes applying different interpretations of federal security requirements. Under the new program, agencies would be able to skip redundant security reviews because FedRAMP authorization indicated that the product had already met standardized requirements. Authorized products would be listed on a government website known as the FedRAMP Marketplace.
On paper, the program was an exercise in efficiency. But in practice, the small FedRAMP team could not keep up with the flood of demand from tech companies that wanted their products authorized.
The slow approval process frustrated both the tech industry, eager for a share in the billions of federal dollars up for grabs, and government agencies that were under pressure to migrate to the cloud. These dynamics sometimes pitted the cloud industry and agency officials together against FedRAMP. The backlog also prompted many agencies to take an alternative path: performing their own reviews of the products they wanted to adopt, using FedRAMP’s standards.
It was through this “agency path” that GCC High entered the federal bloodstream, with the Justice Department paving the way. Initially, some Justice officials were nervous about the cloud and who might have access to its information, which includes highly sensitive court and law enforcement records, a Justice Department official involved in the decision told ProPublica. The department’s cybersecurity program required it to ensure that only U.S. citizens “access or assist in the development, operation, management, or maintenance” of its IT systems, unless a waiver was granted. Justice’s IT specialists recommended pursuing GCC High, believing it could meet the elevated security needs, according to the official, who spoke on condition of anonymity because they were not authorized to discuss internal matters.
Pursuant to FedRAMP’s rules, Microsoft had GCC High evaluated by a so-called third-party assessment organization, which is supposed to provide an independent review of whether the product has met federal standards. The Justice Department then performed its own evaluation of GCC High using those standards and ruled the offering acceptable.
By early 2020, Melinda Rogers, Justice’s deputy chief information officer, made the decision official and soon deployed GCC High across the department.
It was a milestone for all involved. Rogers had ushered the Justice Department into the cloud, and Microsoft had gained a significant foothold in the cutthroat market for the federal government’s cloud computing business.
Moreover, Rogers’ decision placed GCC High on the FedRAMP Marketplace, the government’s influential online clearinghouse of all the cloud providers that are under review or already authorized. Its mere mention as “in process” was a boon for Microsoft, amounting to free advertising on a website used by organizations seeking to purchase cloud services bearing what is widely seen as the government’s cybersecurity seal of approval.
That April, GCC High landed at FedRAMP’s office for review, the final stop on its bureaucratic journey to full authorization.
Microsoft’s Missing Information
In theory, there shouldn’t have been much for FedRAMP’s team to do after the third-party assessor and Justice reviewed GCC High, because all parties were supposed to be following the same requirements.
But it was around this time that the Government Accountability Office, which investigates federal programs, discovered breakdowns in the process, finding that agency reviews sometimes were lacking in quality. Despite missing details, FedRAMP went on to authorize many of these packages. Acknowledging these shortcomings, FedRAMP began to take a harder look at new packages, a former reviewer said.
This was the environment in which Microsoft’s GCC High application entered the pipeline. The name GCC High was an umbrella covering many services and features within Office 365 that all needed to be reviewed. FedRAMP reviewers quickly noticed key material was missing.
The team homed in on what it viewed as a fundamental document called a “data flow diagram,” former members told ProPublica. The illustration is supposed to show how data travels from Point A to Point B — and, more importantly, how it’s protected as it hops from server to server. FedRAMP requires data to be encrypted while in transit to ensure that sensitive materials are protected even if they’re intercepted by hackers.
But when the FedRAMP team asked Microsoft to produce the diagrams showing how such encryption would happen for each service in GCC High, the company balked, saying the request was too challenging. So the reviewers suggested starting with just Exchange Online, the popular email platform.
“This was our litmus test to say, ‘This isn’t the only thing that’s required, but if you’re not doing this, we are not even close yet,’” said one reviewer who spoke on condition of anonymity because they were not authorized to discuss internal matters. Once they reached the appropriate level of detail, they would move from Exchange to other services within GCC High.
It was the kind of detail that other major cloud providers such as Amazon and Google routinely provided, members of the FedRAMP team told ProPublica. Yet Microsoft took months to respond. When it did, the former reviewer said, it submitted a white paper that discussed GCC High’s encryption strategy but left out the details of where on the journey data actually becomes encrypted and decrypted — so FedRAMP couldn’t assess that it was being done properly.
A Microsoft spokesperson acknowledged that the company had “articulated a challenge related to illustrating the volume of information being requested in diagram form” but “found alternate ways to share that information.”
Rogers, who was hired by Microsoft in 2025, declined to be interviewed. In response to emailed questions, the company provided a statement saying that she “stands by the rigorous evaluation that contributed to” her authorization of GCC High. A spokesperson said there was “absolutely no connection” between her hiring and the decisions in the GCC High process, and that she and the company complied with “all rules, regulations, and ethical standards.”
The Justice Department declined to respond to written questions from ProPublica.
A Fight Over “Spaghetti Pies”
As 2020 came to a close, a national security crisis hit Washington that underscored the consequences of cyber weakness. Russian state-sponsored hackers had been quietly working their way through federal computer systems for much of the year and vacuuming up sensitive data and emails from U.S. agencies — including the Justice Department.
At the time, most of the blame fell on a Texas-based company called SolarWinds, whose software provided hackers their initial opening and whose name became synonymous with the attack. But, as ProPublica has reported, the Russians leveraged that opening to exploit a long-standing weakness in a Microsoft product — one that the company had refused to fix for years, despite repeated warnings from one of its engineers. Microsoft has defended its decision not to address the flaw, saying that it received “multiple reviews” and that the company weighs a variety of factors when making security decisions.
In the aftermath, the Biden administration took steps to bolster the nation’s cybersecurity. Among them, the Justice Department announced a cyber-fraud initiative in 2021 to crack down on companies and individuals that “put U.S. information or systems at risk by knowingly providing deficient cybersecurity products or services, knowingly misrepresenting their cybersecurity practices or protocols, or knowingly violating obligations to monitor and report cybersecurity incidents and breaches.”
Deputy Attorney General Lisa Monaco said the department would use the False Claims Act to pursue government contractors “when they fail to follow required cybersecurity standards — because we know that puts all of us at risk.”
But if Microsoft felt any pressure from the SolarWinds attack or from the Justice Department’s announcement, it didn’t manifest in the FedRAMP talks, according to former members of the FedRAMP team.
The discourse between FedRAMP and Microsoft fell into a pattern. The parties would meet. Months would go by. Microsoft would return with a response that FedRAMP deemed incomplete or irrelevant. To bolster the chances of getting the information it wanted, the FedRAMP team provided Microsoft with a template, describing the level of detail it expected. But the diagrams Microsoft returned never met those expectations.
“We never got past Exchange,” one former reviewer said. “We never got that level of detail. We had no visibility inside.”
In an interview with ProPublica, John Bergin, the Microsoft official who became the government’s main contact, acknowledged the prolonged back-and-forth but blamed FedRAMP, equating its requests for diagrams to a “rock fetching exercise.”
“We were maybe incompetent in how we drew drawings because there was no standard to draw them to,” he said. “Did we not do it exactly how they wanted? Absolutely. There was always something missing because there was no standard.”
A Microsoft spokesperson said without such a standard, “cloud providers were left to interpret the level of abstraction and representation on their own,” creating “inconsistency and confusion, not an unwillingness to be transparent.”
But even Microsoft’s own engineers had struggled over the years to map the architecture of its products, according to two people involved in building cloud services used by federal customers. At issue, according to people familiar with Microsoft’s technology, was the decades-old code of its legacy software, which the company used in building its cloud services.
One FedRAMP reviewer compared it to a “pile of spaghetti pies.” The data’s path from Point A to Point B, the person said, was like traveling from Washington to New York with detours by bus, ferry and airplane rather than just taking a quick ride on Amtrak. And each one of those detours represents an opportunity for a hijacking if the data isn’t properly encrypted.
Other major cloud providers such as Amazon and Google built their systems from the ground up, said Sager, the former NSA computer scientist, who worked with all three companies during his time in government.
Microsoft’s system is “not designed for this kind of isolation of ‘secure’ from ‘not secure,’” Sager said.
A Microsoft spokesperson acknowledged the company faces a unique challenge but maintained that its cloud products meet federal security requirements.
“Unlike providers that started later with a narrower product scope, Microsoft operates one of the broadest enterprise and government platforms in the world, supporting continuity for millions of customers while simultaneously modernizing at scale,” the spokesperson said in emailed responses. “That complexity is not ‘spaghetti,’ but it does mean the work of disentangling, isolating, and hardening systems is continuous.”
The spokesperson said that since 2023, Microsoft has made “security‑first architectural redesign, legacy risk reduction, and stronger isolation guarantees a top, company‑wide priority.”
Assessors Back-Channel Cyber Concerns
The FedRAMP team was not the only party with reservations about GCC High. Microsoft’s third-party assessment organizations also expressed concerns.
The firms are supposed to be independent but are hired and paid by the company being assessed. Acknowledging the potential for conflicts of interest, FedRAMP has encouraged the assessment firms to confidentially back-channel to its reviewers any negative feedback that they were unwilling to bring directly to their clients or reflect in official reports.
In 2020, two third-party assessors hired by Microsoft, Coalfire and Kratos, did just that. They told FedRAMP that they were unable to get the full picture of GCC High, a former FedRAMP reviewer told ProPublica.
“Coalfire and Kratos both readily admitted that it was difficult to impossible to get the information required out of Microsoft to properly do a sufficient assessment,” the reviewer told ProPublica.
The back channel helped surface cybersecurity issues that otherwise might never have been known to the government, people who have worked with and for FedRAMP told ProPublica. At the same time, they acknowledged its existence undermined the very spirit and intent of having independent assessors.
A spokesperson for Coalfire, the firm that initially handled the GCC High assessment, requested written questions from ProPublica, then declined to respond.
A spokesperson for Kratos, which replaced Coalfire as the GCC High assessor, declined an interview request. In an emailed response to written questions, the spokesperson said the company stands by its official assessment and recommendation of GCC High and “absolutely refutes” that it “ever would sign off on a product we were unable to fully vet.” The company “has open and frank conversations” with all customers, including Microsoft, which “submitted all requisite diagrams to meet FedRAMP-defined requirements,” the spokesperson said.
Kratos said it “spent extensive time working collaboratively with FedRAMP in their review” and does not consider such discussions to be “backchanneling.”
FedRAMP, however, was dissatisfied with Kratos’ ongoing work and believed the firm “should be pushing back” on Microsoft more, the former reviewer said. It placed Kratos on a “corrective action plan,” which could eventually result in loss of accreditation. The company said it did not agree with FedRAMP’s action but provided “additional trainings for some internal assessors” in response to it.
The Microsoft spokesperson told ProPublica the company has “always been responsive to requests” from Kratos and FedRAMP. “We are not aware of any backchanneling, nor do we believe that backchanneling would have been necessary given our transparency and cooperation with auditor requests,” the spokesperson said.
In response to questions from ProPublica about the process, the GSA said in an email that FedRAMP’s system “does not create an inherent conflict of interest for professional auditors who meet ethical and contractual performance expectations.”
GSA did not respond to questions about back-channeling but said the “correct process” is for a third-party assessor to “state these problems formally in a finding during the security assessment so that the cloud service provider has an opportunity to fix the issue.”
FedRAMP Ends Talks
The back-and-forth between the FedRAMP reviewers and Microsoft’s team went on for years with little progress. Then, in the summer of 2023, the program’s interim director, Brian Conrad, got a call from the White House that would alter the course of the review.
Chinese state-sponsored hackers had infiltrated GCC, the lower-cost version of Microsoft’s government cloud, and stolen data and emails from the commerce secretary, the U.S. ambassador to China and other high-ranking government officials. In the aftermath, Chris DeRusha, the White House’s chief information security officer, wanted a briefing from FedRAMP, which had authorized GCC.
The decision predated Conrad’s tenure, but he told ProPublica that he left the conversation with several takeaways. First, FedRAMP must hold all cloud providers — including Microsoft — to the same standards. Second, he had the backing of the White House in standing firm. Finally, FedRAMP would feel the political heat if any cloud service with a FedRAMP authorization were hacked.
DeRusha confirmed Conrad’s account of the phone call but declined to comment further.
Within months, Conrad informed Microsoft that FedRAMP was ending the engagement on GCC High.
“After three years of collaboration with the Microsoft team, we still lack visibility into the security gaps because there are unknowns that Microsoft has failed to address,” Conrad wrote in an October 2023 email. This, he added, was not for FedRAMP’s lack of trying. Staffers had spent 480 hours of review time, had conducted 18 “technical deep dive” sessions and had numerous email exchanges with the company over the years. Yet they still lacked the data flow diagrams, crucial information “since visibility into the encryption status of all data flows and stores is so important,” he wrote.
If Microsoft still wanted FedRAMP authorization, Conrad wrote, it would need to start over.
A FedRAMP reviewer, explaining the decision to the Justice Department, said the team was “not asking for anything above and beyond what we’ve asked from every other” cloud service provider, according to meeting minutes reviewed by ProPublica. But the request was particularly justified in Microsoft’s case, the reviewer told the Justice officials, because “each time we’ve actually been able to get visibility into a black box, we’ve uncovered an issue.”
“We can’t even quantify the unknowns, which makes us very uncomfortable,” the reviewer said, according to the minutes.
Microsoft and the Justice Department Push Back
Microsoft was furious. Failing to obtain authorization and starting the process over would signal to the market that something was wrong with GCC High. Customers were already confused and concerned about the drawn-out review, which had become a hot topic in an online forum used by government and technology insiders. There, Wakeman, the Microsoft cybersecurity architect, deflected blame, saying the government had been “dragging their feet on it for years now.”
Meanwhile, to build support for Microsoft’s case, Bergin, the company’s point person for FedRAMP and a former Army official, reached out to government leaders, including one from the Justice Department.
The Justice official, who spoke on condition of anonymity because they were not authorized to discuss the matter, said Bergin complained that the delay was hampering Microsoft’s ability “to get this out into the market full sail.” Bergin then pushed the Justice Department to “throw around our weight” to help secure FedRAMP authorization, the official said.
That December, as the parties gathered to hash things out at GSA’s Washington headquarters, Justice did just that. Rogers, who by then had been promoted to the department’s chief information officer, sat beside Bergin — on the opposite side of the table from Conrad, the FedRAMP director.
Rogers and her Justice colleagues had a stake in the outcome. Since authorizing and deploying GCC High, she had receivedaccolades for her work modernizing the department’s IT and cybersecurity. But without FedRAMP’s stamp of approval, she would be the government official left holding the bag if GCC High were involved in a serious hack. At the same time, the Justice Department couldn’t easily back out of using GCC High because once a technology is widely deployed, pulling the plug can be costly and technically challenging. And from its perspective, the cloud was an improvement over the old government-run data centers.
Shortly after the meeting kicked off, Bergin interrupted a FedRAMP reviewer who had been presenting PowerPoint slides. He said the Justice Department and third-party assessor had already reviewed GCC High, according to meeting minutes. FedRAMP “should essentially just accept” their findings, he said.
Then, in a shock to the FedRAMP team, Rogers backed him up and went on to criticize FedRAMP’s work, according to two attendees.
In its statement, Microsoft said Rogers maintains that FedRAMP’s approach “was misguided and improperly dismissed the extensive evaluations performed by DOJ personnel.”
Bergin did not dispute the account, telling ProPublica that he had been trying to argue that it is the purview of third-party assessors such as Kratos — not FedRAMP — to evaluate the security of cloud products. And because FedRAMP must approve the third-party assessment firms, the program should have taken its issues up with Kratos.
“When you are the regulatory agency who determines who the auditors are and you refuse to accept your auditors’ answers, that’s not a ‘me’ problem,” Bergin told ProPublica.
The GSA did not respond to questions about the meeting. The Justice Department declined to comment.
Pressure Mounts on FedRAMP
If there was any doubt about the role of FedRAMP, the White House issued a memorandum in the summer of 2024 that outlined its views. FedRAMP, it said, “must be capable of conducting rigorous reviews” and requiring cloud providers to “rapidly mitigate weaknesses in their security architecture.” The office should “consistently assess and validate cloud providers’ complex architectures and encryption schemes.”
But by that point, GCC High had spread to other federal agencies, with the Justice Department’s authorization serving as a signal that the technology met federal standards.
It also spread to the defense sector, since the Pentagon required that cloud products used by its contractors meet FedRAMP standards. While it did not have FedRAMP authorization, Microsoft marketed GCC High as meeting the requirements, selling it to companies such as Boeing that research, develop and maintain military weapons systems.
But with the FedRAMP authorization up in the air, some contractors began to worry that by using GCC High, they were out of compliance. That could threaten their contracts, which, in turn, could impact Defense Department operations. Pentagon officials called FedRAMP to inquire about the authorization stalemate.
The Defense Department acknowledged but did not respond to written questions from ProPublica.
Rogers also kept pressing FedRAMP to “get this thing over the line,” former employees of the GSA and FedRAMP said. It was the “opinion of the staff and the contractors that she simply was not willing to put heat to Microsoft on this” and that the Justice Department “was too sympathetic to Microsoft’s claims,” Eric Mill, then GSA’s executive director for cloud strategy, told ProPublica.
Authorization Despite a “Damning” Assessment
In the summer of 2024, FedRAMP hired a new permanent director, government technology insider Pete Waterman. Within about a month of taking the job, he restarted the office’s review of GCC High with a new team, which put aside the debate over data flow diagrams and instead attempted to examine evidence from Microsoft. But these reviewers soon arrived at the same conclusion, with the team’s leader complaining about “getting stiff-armed” by Microsoft.
“He came back and said, ‘Yeah, this thing sucks,’” Mill recalled.
While the team was able to work through only two of the many services included in GCC High, Exchange Online and Teams, that was enough for it to identify “issues that are fundamental” to risk management, including “timely remediation of vulnerabilities and vulnerability scanning,” according to a summary of the team’s findings reviewed by ProPublica.
Those issues, as well as a lack of “proper detailed security documentation” from Microsoft, limit “visibility and understanding of the system” and “impair the ability to make informed risk decisions.”
The team concluded, “There is a lack of confidence in assessing the system’s overall security posture.”
A Microsoft spokesperson said in a statement that the company “never received this feedback in any of its communications with FedRAMP.”
When ProPublica read the findings to Bergin, the Microsoft liaison, he said he was surprised.
“That’s pretty damning,” Bergin said, adding that it sounded like language that “would’ve generally been associated with a finding of ‘not worthy.’ If an assessor wrote that, I would be nervous.”
Despite the findings, to the FedRAMP team, turning Microsoft down didn’t seem like an option. “Not issuing an authorization would impact multiple agencies that are already using GCC-H,” the summary document said. The team determined that it was a “better value” to issue an authorization with conditions for continued government oversight.
While authorizations with oversight conditions weren’t unusual, arriving at one under these circumstances was. GCC High reviewers saw problems everywhere, both in what they were able to evaluate and what they weren’t. To them, most of the package remained a vast wilderness of untold risk.
Nevertheless, FedRAMP and Microsoft reached an agreement, and the day after Christmas 2024, GCC High received its FedRAMP authorization. FedRAMP appended a cover report to the package laying out its deficiencies and noting it carried unknown risks, according to people familiar with the report.
It emphasized that agencies should carefully review the package and engage directly with Microsoft on any questions.
“Unknown Unknowns” Persist
Microsoft told ProPublica that it has met the conditions of the agreement and has “stayed within the performance metrics required by FedRAMP” to ensure that “risks are identified, tracked, remediated, and transparently communicated.”
But under the Trump administration, there aren’t many people left at FedRAMP to check.
While the Biden-era guidance said FedRAMP “must be an expert program that can analyze and validate the security claims” of cloud providers, the GSA told ProPublica that the program’s role is “not to determine if a cloud service is secure enough.” Rather, it is “to ensure agencies have sufficient information to make these risk decisions.”
The problem is that agencies often lack the staff and resources to do thorough reviews, which means the whole system is leaning on the claims of the cloud companies and the assessments of the third-party firms they pay to evaluate them. Under the current vision, critics say, FedRAMP has lost the plot.
“FedRAMP’s job is to watch the American people’s back when it comes to sharing their data with cloud companies,” said Mill, the former GSA official, who also co-authored the 2024 White House memo. “When there’s a security issue, the public doesn’t expect FedRAMP to say they’re just a paper-pusher.”
Meanwhile, at the Justice Department, officials are finding out what FedRAMP meant by the “unknown unknowns” in GCC High. Last year, for example, they discovered that Microsoft relied on China-based engineers to service their sensitive cloud systems despite the department’s prohibition against non-U.S. citizens assisting with IT maintenance.
Officials learned about this arrangement — which was also used in GCC High — not from FedRAMP or from Microsoft but from a ProPublica investigation into the practice, according to the Justice employee who spoke with us.
A Microsoft spokesperson acknowledged that the written security plan for GCC High that the company submitted to the Justice Department did not mention foreign engineers, though he said Microsoft did communicate that information to Justice officials before 2020. Nevertheless, Microsoft has since ended its use of China-based engineers in government systems.
Former and current government officials worry about what other risks may be lurking in GCC High and beyond.
The GSA told ProPublica that, in general, “if there is credible evidence that a cloud service provider has made materially false representations, that matter is then appropriately referred to investigative authorities.”
Ironically, the ultimate arbiter of whether cloud providers or their third-party assessors are living up to their claims is the Justice Department itself. The recent indictment of the former Accenture employee suggests it is willing to use this power. In a court document, the Justice Department alleges that the ex-employee made “false and misleading representations” about the cloud platform’s security to help the company “obtain and maintain lucrative federal contracts.” She is also accused of trying to “influence and obstruct” Accenture’s third-party assessors by hiding the product’s deficiencies and telling others to conceal the “true state of the system” during demonstrations, the department said. She has pleaded not guilty.
There is no public indication that such a case has been brought against Microsoft or anyone involved in the GCC High authorization. The Justice Department declined to comment. Monaco, the deputy attorney general who launched the department’s initiative to pursue cybersecurity fraud cases, did not respond to requests for comment.
She left her government position in January 2025. Microsoft hired her to become its president of global affairs.
A company spokesperson said Monaco’s hiring complied with “all rules, regulations, and ethical standards” and that she “does not work on any federal government contracts or have oversight over or involvement with any of our dealings with the federal government.”
We’ve noted how Microsoft is a little sensitive about AI slop at the moment. Back in January, CEO Satya Nadella wrote a well-circulated blog post lamenting critics of “AI slop” and demanding the public simply move past such conversations. It was relatively innocuous, but wasn’t received well for some valid reasons.
Last week found Microsoft under fire yet again, this time for defensively locking down a Discord server after people wouldn’t stop calling the company “Microslop.” More specifically, Microsoft Streisanded themselves after they tried to ban the term on its Copilot discord server. When people found creative ways to get around the ban, Microsoft decided to lock down the entire server.
When called out for that by frustrated users, Microsoft tried to blame the entire incident on “spammers” who were trying to post “harmful content”:
“The Copilot Discord channel has recently been targeted by spammers attempting to disrupt and overwhelm the space with harmful content not related to Copilot,” a Microsoft spokesperson told us, adding that the “blocking of terms like ‘Microslop’ and some others associated with this spam campaign were temporary while the company worked to implement better safeguards.”
Microsoft executives don’t really seem to want to engage in any serious introspection into their rushed adoption of AI in ways customers don’t always appreciate. Most recently, their integration of Copilot into Notepad opened up a major cybersecurity vulnerability.
This whole incident will, of course, only result in users doubling down on their criticisms:
These companies have invested untold oceans of cash into a technology that may have utility for many, but hasn’t, to date, been all that profitable. Many AI companies have layered under-cooked automation on top of very broken systems (see: health insurance or journalism or war) in problematic ways, raising questions about company valuations and systemically poor judgement. All while AI’s immense energy consumption has caused companies to disregard already tepid climate goals.
Instead of engaging in real conversation about these issues you tend to get a lot of generalized defensiveness (“why can’t you simply praise us for our innovation?”), all of which has been made worse by the tech sector’s enthusiastic coddling of authoritarianism.
We are calling on technology companies like Meta and Google to stand up for their users by resisting the Department of Homeland Security’s (DHS) lawless administrative subpoenas for user data.
In the past year, DHS has consistently targeted people engaged in First Amendment activity. Among other things, the agency has issued subpoenas to technology companies to unmask or locate people who have documented ICE’s activities in their community, criticized the government, or attended protests.
These subpoenas are unlawful, and the government knows it. When a handful of users challenged a few of them in court with the help of ACLU affiliates in Northern California and Pennsylvania, DHS withdrew them rather than waiting for a decision.
But it is difficult for the average user to fight back on their own. Quashing a subpoena is a fast-moving process that requires lawyers and resources. Not everyone can afford a lawyer on a moment’s notice, and non-profits and pro-bono attorneys have already been stretched to near capacity during the Trump administration.
That is why we, joined by the ACLU of Northern California, have asked several large tech platforms to do more to protect their users, including:
Insist on court intervention and an order before complying with a DHS subpoena, because the agency has already proved that its legal process is often unlawful and unconstitutional;
Give users as much notice as possible when they are the target of a subpoena, so the user can seek help. While many companies have already made this promise, there are high-profileexamples of it not happening—ultimately stripping users of their day in court;
Resist gag orders that would prevent companies from notifying their users that they are a target of a subpoena.
We sent the letter to Amazon, Apple, Discord, Google, Meta, Microsoft, Reddit, SNAP, TikTok, and X.
Recipients are not legally compelled to comply with administrative subpoenas absent a court order
An administrative subpoena is an investigative tool available to federal agencies like DHS. Many times, these are sent to technology companies to obtain user data. A subpoena cannot be used to obtain the content of communications, but they have been used to try and obtain some basic subscriber information like name, address, IP address, length of service, and session times.
Unlike a search warrant, an administrative subpoena is not approved by a judge. If a technology company refuses to comply, an agency’s only recourse is to drop it or go to court and try to convince a judge that the request is lawful. That is what we are asking companies to do—simply require court intervention and not obey in advance.
It is unclear how many administrative subpoenas DHS has issued in the past year. Subpoenas can come from many places—including civil courts, grand juries, criminal trials, and administrative agencies like DHS. Altogether, Google received 28,622 and Meta received 14,520 subpoenas in the first half of 2025, according to their transparency reports. The numbers are not broken out by type.
DHS is abusing its authority to issue subpoenas
In the past year, DHS has used these subpoenas to target protected speech. The following are just a few of the known examples.
On April 1, 2025, DHS sent a subpoena to Google in an attempt to locate a Cornell PhD student in the United States on a student visa. The student was likely targeted because of his brief attendance at a protest the year before. Google complied with the subpoena without giving the student an opportunity to challenge it. While Google promises to give users prior notice, it sometimes breaks that promise to avoid delay. This must stop.
In September 2025, DHS sent a subpoena and summons to Meta to try to unmask anonymous users behind Instagram accounts that tracked ICE activity in communities in California and Pennsylvania. The users—with the help of the ACLU and its state affiliates— challenged the subpoenas in court, and DHS withdrew the subpoenas before a court could make a ruling. In the Pennsylvania case, DHS tried to use legal authority that its own inspector general had already criticized in a lengthy report.
In October 2025, DHS sent Google a subpoena demanding information about a retiree who criticized the agency’s policies. The retiree had sent an email asking the agency to use common sense and decency in a high-profile asylum case. In a shocking turn, federal agents later appeared on that person’s doorstep. The ACLU is currently challenging the subpoena.
Wikipedia celebrated its 25th birthday last month. Given the centrality of Wikipedia to so much activity online, it is hard to remember (or to imagine, for those who are younger) a time without Wikipedia. The latest statistics are impressive:
Wikipedia is viewed nearly 15 billion times every month.
Wikipedia contains over 65 million articles across more than 300 languages.
Wikipedia is edited by nearly 250,000 editors every month around the world. Editors are defined by one edit or more every month; only editors with a username are counted.
Wikipedia is accessed by over 1.5 billion unique devices every month.
That’s testimony to the global nature of Wikipedia. But there’s something else, not mentioned there, that is of great relevance to this blog: the fact that every one of those 65 million articles is made available under a generous license – the Creative Commons Attribution-ShareAlike 4.0 license, to be precise. That means sharing and re-use are encouraged, in contrast to most material online, where copyright is fiercely enforced. Wikipedia is living proof that giving away things by relying on volunteers and donations – the “true fans” approach – works, and on a massive scale. Anil Dash puts it well in a post celebrating Wikipedia’s 25th anniversary:
Whenever I worry about where the Internet is headed, I remember that this example of the collective generosity and goodness of people still exists. There are so many folks just working away, every day, to make something good and valuable for strangers out there, simply from the goodness of their hearts. They have no way of ever knowing who they’ve helped. But they believe in the simple power of doing a little bit of good using some of the most basic technologies of the internet. Twenty-five years later, all of the evidence has shown that they really have changed the world.
However, Wikipedia is today facing perhaps its greatest challenge, which comes from the new generation of AI services. They are problematic for Wikipedia in two main ways. The first, ironically, is because it is widely recognized that Wikipedia’s holdings represent some of the highest-quality training materials available. In a post explaining why, “in the AI era, Wikipedia has never been more valuable”, the Wikimedia Foundation writes:
That recognition is welcome, but comes at a price. It means that every AI company as a matter of course wants to download the entire Wikipedia corpus to be used for training its models. That has led to irresponsible behavior by some companies, when their scraping tools download pages from Wikipedia with no consideration for the resources they are using for free, or the collateral damage they are causing to other users in terms of slower responses.
Trying to stop companies drawing on this unique resource is futile; recognizing this, Wikimedia Foundation has come up with an alternative approach: Wikimedia Enterprise, “a first-of-its-kind commercial product designed for companies that reuse and source Wikipedia and Wikimedia projects at a high volume”. In 2022, its first customers were Google and the Internet Archive, and last month, Wikimedia Enterprise announced that Amazon, Meta, Microsoft, Mistral AI, and Perplexity have also signed. That’s important for a couple of reasons. It means that many of the biggest AI players will download Wikipedia articles more efficiently. It also means that the Wikipedia project will receive funding for its work.
This new money is crucial if Wikipedia is to remain a high quality resource. And that is precisely why every generative AI company that uses Wikipedia posts for training should – if only out of self-interest – pay to do so. What is happening here echoes something this blog suggested back in May 2024: that AI companies should pay artists to create new works, and give away the results, because fresh training material is vital. Helping to pay for Wikipedia to create more high-quality articles that are freely available to all is a variation on that theme.
The other problem that generative AI causes Wikipedia is more subtle. The Wikimedia Foundation explains that alongside financial support, the project needs proper attribution:
Attribution means that generative AI gives credit to the human contributions that it uses to create its outputs. This maintains a virtuous cycle that continues those human contributions that create the training data that these new technologies rely on. For people to trust information shared on the internet, platforms should make it clear where the information is sourced from and elevate opportunities to visit and participate in those sources. With fewer visits to Wikipedia, fewer volunteers may grow and enrich the content, and fewer individual donors may support this work.
Without fresh volunteers, Wikipedia will wither and become less valuable. That’s terrible for the world, but it is also bad for generative AI companies. So, again, it makes sense for them to provide proper attribution in their outputs. That requirement has become even more pressing in the light of a new development. According to tests carried out by the Guardian:
The latest model of ChatGPT has begun to cite Elon Musk’s Grokipedia as a source on a wide range of queries, including on Iranian conglomerates and Holocaust deniers, raising concerns about misinformation on the platform.
Grokipedia articles are substantially longer and contain significantly fewer references per word. Moreover, Grokipedia’s content divides into two distinct groups: one that remains semantically and stylistically aligned with Wikipedia, and another that diverges sharply. Among the dissimilar articles, we observe a systematic rightward shift in the political bias of cited news sources, concentrated primarily in entries related to politics, history, and religion. These findings suggest that AI-generated encyclopedic content diverges from established editorial norms-favouring narrative expansion over citation-based verification.
If leading chatbots starts drawing on Grokipedia routinely for their answers, it is less likely that there are independent sources where the information can be checked, something generally possible with Wikipedia. It therefore becomes even more urgent for generative AI systems to provide attribution, so at least users know where information is coming from, and whether there are likely to be further resources that confirm a chatbot’s claims. Not everyone will want to do that, but it is important to offer it as an option.
Wikipedia at 25 is an amazing achievement in multiple ways, one of which includes serving as a demonstration that material can be given away for free, supported directly by users, and on a global scale. It would be a tragedy if the current enthusiasm for generative AI systems led to that resource being harmed and even destroyed. A world without Wikipedia would be a poorer world indeed.
At some point, we, as a society, are going to realize that farming copyright enforcement out to bots and AI-driven robocops is not the way to go, but today is not that day. Long before AI became the buzzword it is today, large companies have employed their own copyright crawler bots, or employed those of a third party, to police their copyrights on these here internets. And for just as long, those bots have absolutely sucked out loud at their jobs. We have seen example after example after example of those bots making mistakes, resulting in takedowns or threats of takedowns of all kinds of perfectly legit content. Upon discovery, the content is usually reinstated while those employing the copyright decepticons shrug their shoulders and say “Thems the breaks.” And then it happens again.
It has to change, but isn’t. We have yet another recent example of this in action, with Microsoft’s copyright enforcement partner using an AI-driven enforcement bot to get a video game delisted from Steam over a single screenshot on the game’s page that looks like, but isn’t, from Minecraft. The game in question, Allumeria, clearly is partially inspired by Minecraft, but doesn’t use any of its assets and is in fact its own full-fledged creative work.
On Tuesday, the developer behind the Minecraft-looking, dungeon-raiding sandbox announced that their game had been taken down from Valve’s storefront due to a DMCA copyright notice issued by Microsoft. The notice, shared by developer Unomelon in the game’s Discord server, accused Allumeria of using “Minecraft content, including but not limited to gameplay and assets.”
The takedown was apparently issued over one specific screenshot from the game’s Steam page. It shows a vaguely Minecraft-esque world with birch trees, tall grass, a blue sky, and pumpkins: all things that are in Minecraft but also in real life and lots of other games. The game does look pretty similar to Minecraft, but it doesn’t appear to be reusing any of its actual assets or crossing some arbitrary line between homage and copycat that dozens of other Minecraft-inspired games haven’t crossed before.
It turns out the takedown request didn’t come from Microsoft directly, but via Tracer.AI. Tracer.AI claims to have a bot driven by artificial intelligence for automatic flagging and removal of copyright infringing content.
It seems the system failed to understand in this case that the image in question, while being similar to those including Minecraft assets, didn’t actually infringe upon anything. Folks at Mojang caught wind of this on BlueSky and had to take action.
While it’s unclear if the claim was issued automatically or intentionally, Mojang Chief Creative Officer Jens Bergensten (known to most Minecraft players as Jeb) responded to a comment about the takedown on Bluesky, stating that he was not aware and is now “investigating.” Roughly 12 hours later, Allumeria‘s Steam page has been reinstated.
“Microsoft has withdrawn their DMCA claim!” Unomelon posted earlier today. “The game is back up on Steam! Allumeria is back! Thank you EVERYONE for your support. It’s hard to comprehend that a single post in my discord would lead to so many people expressing support.”
And this is the point in the story where we all go back to our lives and pretend like none of this ever happened. But that sucks. For starters, there is no reason we should accept that this kind of collateral damage, temporary or not. Add to that there are surely stories out there in which a similar resolution was not reached. How many games, how much other non-infringing content out there, were taken down for longer from an erroneous claim like this? How many never came back?
And at the base level, the fact is that if companies are going to claim that copyright is of paramount importance to their business, that can’t be farmed out to automated systems that aren’t good at their job.
Copilot may very well be useful to some people; but like most tech companies, Microsoft’s rushed, ham-fisted adoption has been a bit of a tone-deaf mess. And it actively undermines the stuff that LLMs can actually accomplish. This is before you get to the environmental impact of AI, or its quickly-expanding, guardrail-optional use in global military imperialism at the hands of insane autocrats.
This all recently resulted in some fairly significant backlash for Microsoft CEO Satya Nadella. Nadella recently shared a fairly innocuous end-of-year post at LinkedIn.
Most of the short post isn’t really all that interesting or incorrect; he notes that AI is stumbling through a phase where we’re beginning to sort between “spectacle” and “substance,” something that’s likely to result in a big bubble pop this year due the chasm between real-world usefulness and broad tech company misrepresentation of AI (he doesn’t really acknowledge that latter part, of course).
Where Nadella got into trouble was apparently this part, where he fairly innocuously laments the rising criticism of “AI slop.” It was first highlighted by Windows Central:
“We need to get beyond the arguments of slop vs sophistication,” Nadella laments, emphasizing hopes that society will become more accepting of AI, or what Nadella describes as “cognitive amplifier tools.” “…and develop a new equilibrium in terms of our “theory of the mind” that accounts for humans being equipped with these new cognitive amplifier tools as we relate to each other.”
Nadella’s problem here is he dismissively puts the onus on the consumer when it comes to “getting beyond” concerns about AI slop. That dodges any responsibility for the very rich people and companies dictating the entire trajectory of AI to start using it more responsibly.
The press aggregation machine (much of it ironically now badly automated) latched on to Nadella’s demand that people stop calling it AI slop, immediately resulting in people doubling down on AI slop criticism in a way that made “Microslop” trend across the internet.
Automation, broadly, certainly has its uses and is, generally, not going away. The backlash to AI is, in many ways, tethered tightly and unavoidably to a growing disdain for wealth disparity at the hands of the authoritarian-simping extraction class keen on eliminating literally all ethical oversight of industry.
A great way for billionaires like Nadella to diffuse this growing animosity about their rushed, clumsy, non-transparent, integration of language learning models into everything (whether you like it or not) in ways that aren’t ethical or useful is to, you know, stop doing that. Another great step might be to stop kissing the ass of authoritarians who are actively destroying democracy, civil rights, and the rule of law?
It sounds like many people might be willing to get over AI slop once the billionaires in charge of its development, trajectory, and implementation stop doubling down on AI slop, and stop being tone deaf, irresponsible assholes.
If your product is even a third as innovative and useful as you claim it is, you shouldn’t have to go around trying a little too hard to convince people. The product’s usefulness should speak for itself. And you definitely shouldn’t be forcing people to use products they’ve repeatedly told you they don’t actually appreciate or want.
LG and Microsoft learned that lesson recently when LG began installing Microsoft’s Copilot “AI” assistant on people’s televisions, without any way to disable it:
“According to affected users, Copilot appears automatically after installing the latest webOS update on certain LG TV models. The feature shows up on the home screen alongside streaming apps, but unlike Netflix or YouTube, it cannot be uninstalled.”
To be clear this isn’t the end of the world. Users can apparently “hide” the app, but people are still generally annoyed at the lack of control. Especially coming from two companies with a history of this sort of behavior.
Many people just generally don’t like Copilot, much like they didn’t really like a lot of the nosier features integrated into Windows 11. Or they don’t like being forced to use Copilot when they’d prefer to use ChatGPT or Gemini.
This is also coming on the heels of widespread backlash over another Microsoft “AI” feature, Recall. Recall takes screenshots of your PC’s activity every five seconds, giving you an “explorable timeline of your PC’s past,” that Microsoft’s AI-powered assistant, Copilot, can then help you peruse.
Here, again, there was widespread condemnation over the privacy implications of such tight integration. Microsoft’s response was to initially pretend to care, only to double down. It’s worth noting that Microsoft’s forced AI integration into its half-assed journalism efforts, like MSN, has also been a hot, irresponsible mess. So this is not a company likely to actually listen to its users.
It’s not like Microsoft hasn’t had some very intimate experiences surrounding the backlash of forcing products down customers’ throats. But like most companies, Microsoft knows U.S. consumer protection and antitrust reform has been beaten to a bloody pulp, and despite the Trump administration’s hollow and performative whining about the power of “big tech,” big tech giants generally have carte blanche to behave like assholes for the foreseeable future, provided they’re polite to the dim autocrats in charge.