For thirty years, the internet has been the only level playing field most people will ever stand on. Not because it was designed to be fair — but because it was designed to be open. Those two things turned out to be the same.
That's changing. Not in one dramatic moment. There's no single villain, no single law. It's changing in a thousand small decisions: regulatory frameworks that add compliance costs few can afford, platform policies that quietly alter who gets discovered and who doesn't, legislative proposals — digital IDs, mandatory age verification, content liability regimes — that sound like sensible safety measures and function like moats.
Nobody calling for a more controlled internet will describe themselves as against competition. They rarely are, consciously. But the effect is the same.
The internet didn't democratise consumption. It democratised supply. Every restriction on the open internet is a vote to reverse that.
This is the thing that tends to get lost. We talk about the internet as a marketplace, a content delivery mechanism, a communications network. All of that is true. But the more consequential thing it did was collapse the cost of entering a market.
A small local logistics firm can compete for contracts that once required a London address and an enterprise sales team. A solo developer in Lagos can build and distribute software to a global customer base. A ceramicist in rural Japan can find the exact niche of buyers whose taste matches her work. The internet didn't just let them buy things. It let them exist as businesses.
Two barriers, moving in opposite directions
For most of the internet's history, the limiting factor in building a software business was capital. Developers were expensive. Infrastructure was expensive. The cost of building something good enough to sell was high enough to keep most ideas on the shelf.
That is ending — and it has been ending for thirty years, which is the part usually missed. Open source collapsed licensing costs: 97% of commercial codebases now contain open source components, and around 70% of the code in them originates there.1 Cloud collapsed the capital cost of infrastructure. SaaS tooling collapsed the cost of specialisation. Each step removed a line item that once had to be funded before a single customer existed.
AI is the current step, and it is the one to be careful about. The best controlled evidence so far cuts against the excitement: in a randomised trial, sixteen experienced developers working on repositories they had contributed to for years took 19% longer to complete tasks when allowed to use early-2025 AI tools — and still believed afterwards that they had been 20% faster.2 The authors are explicit that this is a narrow finding about expert developers in familiar code, not a verdict on the technology. Treat it as a correction to the timeline rather than a refutation. The scarce resource is still shifting — from technical execution to domain knowledge, from the ability to build to the ability to see what needs building. It is simply shifting less quickly than the people selling it claim.
The implication is significant. A niche that was previously too small to justify custom software now isn't. A butcher's supply chain, a community mental health service, a heritage language school — real use cases with real complexity that generic tools serve badly. For the first time, bespoke solutions for small operators are becoming economically viable. This is where the next wave of value creation sits. Not in the sixth social network or the fourth cloud provider. In the long tail of specific human problems that have never had software written for them because the economics didn't work.
All of it runs on the open internet.
Every restriction on the open internet is a vote to reverse this. Not in principle — in practice. Compliance costs don't fall evenly. A GDPR consent framework costs Salesforce nothing, and a two-person startup something much closer to existential: across 61 countries the regulation cut about 8% from the profits of the firms it touched, close to double that among small technology companies, while the largest technology firms came through measurably unaffected.3, 4 A mandatory age-verification layer costs Google nothing and quietly kills the economics of every niche platform that can't afford to build it.5, 6 This is not conspiracy. It's just how fixed costs work. The bigger you are, the smaller the percentage.
Put the two together and the shape of the next decade is visible. The cost of building has been falling for thirty years and is about to fall further. The cost of being permitted to operate has been rising for ten. Those lines are crossing about now, and on the current trajectory the second becomes the only barrier that matters. This is also the answer to the obvious objection — that cheap code was never the whole cost of a software business. It wasn't. Distribution, trust, support and compliance were always the rest of it, and compliance is the one line item a small operator cannot engineer their way around. Cheap software does not help you if the thing you cannot afford is the paperwork.
It is sometimes said that closed internets and commercial dynamism are compatible, and China is offered as the proof. But China's internet is closed to its own citizens,7 while its export champions — Shein, Temu, TikTok, AliExpress — sell into open markets everywhere else.8 That is not a demonstration that closure works. It is a demonstration that it pays to be the one economy that closes.
Regulations solving the wrong problem
Most proposals currently threatening the open internet are not cynically designed to entrench incumbents. They are mostly well-intentioned responses to real harms: child safety, misinformation, radicalisation, data exploitation.
But they are solutions aimed at the internet when the problems live in the world.
Child exploitation is a criminal justice problem. Radicalisation is a community and education problem. Loneliness and mental health crises are healthcare and social infrastructure problems. The internet did not create these conditions. It reflects them, sometimes amplifies them, occasionally provides cover for them. But building systems of digital identity verification and monitored access will not address underlying causes. It will, reliably, add friction for legitimate users, create centralised data infrastructures that become targets,9 and hand governments and large platforms the mechanisms for far greater control over speech and commerce than any of them currently possess.
Britain has now run this experiment twice. The Identity Cards Act 2006 built a national register and put some 15,000 cards into circulation before it was repealed in 2010; by the time it was scrapped the programme was estimated to have cost £4.6 billion.10 Twenty years later the same idea returned as a digital ID, costed by the Office for Budget Responsibility at £1.8 billion over three years against no identified savings, and abandoned in July 2026 after a petition drew close to three million signatures.11
Two attempts, two decades, nothing durable from either. That is what the absence of a long-term plan for national digital infrastructure actually looks like — not underinvestment, but investment aimed repeatedly at the wrong thing and then written off. The state is perfectly capable of building identity systems. What it has never done is decide what the country's digital infrastructure is for, and the cost of not deciding is paid twice: once in the money, and once in the twenty years during which the useful things went unbuilt.
The strongest objection to any of this is that some harms are not reflections of the physical world at all. They are made of the internet. Child sexual abuse material is distributed at a scale and speed with no offline equivalent. Intimate images are synthesised by tools that did not exist five years ago. Recommendation systems put material in front of audiences no pamphleteer could have reached. For harms like these, address it in the physical world is not an answer — and pretending otherwise is how this argument usually loses.
It isn't an answer, and the case here is not that nothing should be done. It is that the measures on offer are indifferent to the distinction. A duty aimed at the distribution of abuse material would fall on the services that distribute it. A duty aimed at recommender systems would fall on the firms that operate them. What this generation of rules does instead is place a uniform assessment and verification burden on every service regardless of size, function or risk — so a volunteer-run forum carries the same architecture as the platform that caused the harm, and only one of them can afford it. That is not a safety measure that happens to have costs. It is a fixed cost with a safety justification, and you can tell which is which by looking at who stops operating.
The principle worth holding: if a problem exists in the physical world, address it in the physical world. The internet is not an alternative jurisdiction. Treating it as one doesn't make societies safer. It makes the internet less useful and society no safer.
Who should be making this argument
Digital rights have historically been the concern of academics, civil liberties organisations, and a particular kind of politically engaged technologist. This has made the argument easy to dismiss — a preference for internet freedom as an abstract good, rather than a defence of something materially important.
The people with the most to lose from a restricted internet are not civil libertarians. They are the founder who hasn't launched yet. The engineer who wants to build on their own terms. The operator of a small business in a market too specific for enterprise vendors to bother with. The community with a genuinely local problem that a local solution could solve, if the economics ever worked.
Those economics are arriving. The conditions are finally right for a long tail of specific, human-scale software to exist and be sustainable. The infrastructure it runs on is the open internet.
It needs defending by the people who will actually use it. Not as ideology. As interest.
The window is open now. The economics are arriving, the tools are here, the technical barriers are the lowest they have ever been. That doesn't last. Every cycle of consolidation closes the window a little further. The question isn't whether you believe in internet freedom. It's whether you can afford to take it for granted.
References
- Black Duck. 2025 Open Source Security and Risk Analysis (OSSRA) Report. Of the commercial codebases audited, 97% contained open source components, and roughly 70% of the code scanned originated in open source; the typical application carried 911 open source components, with the number of open source files in an average application tripling over four years. Cited here for the scale of the licensing-cost collapse, not for its security findings. blackduck.com ↩
- Becker, J., Rush, N., Barnes, B., Rein, D. "Measuring the Impact of Early-2025 AI on Experienced Open-Source Developer Productivity," METR, July 2025 (arXiv:2507.09089). A randomised controlled trial: 16 experienced developers, 246 real tasks on repositories they had contributed to for an average of five years, each task randomly assigned to allow or forbid AI tools (primarily Cursor Pro with Claude 3.5/3.7 Sonnet). Developers took 19% longer when AI was allowed, having forecast a 24% speed-up and still estimating a 20% speed-up afterwards. The authors state explicitly that the result is not evidence that AI fails to speed up most developers, and does not generalise beyond this setting. metr.org · arxiv.org ↩
- Chen, C., Frey, C. B., Presidente, G. "Privacy Regulation and Firm Performance: Estimating the GDPR Effect Globally." Oxford Martin Working Paper 2022-1; published in Economic Inquiry 62(3), 2024. Firms across 61 countries and 34 industries: those exposed to the regulation saw an 8% decline in profits and a 2% fall in sales. Large technology companies were "relatively unaffected" on both measures, while the hit to profits among small technology companies was "almost double the average effect." doi.org · oxfordmartin.ox.ac.uk ↩
- Johnson, G. A., Shriver, S. K., Goldberg, S. G. "Privacy and Market Concentration: Intended and Unintended Consequences of the GDPR." Management Science 69(10), 2023. Panel data on web technology vendors used by more than 27,000 top websites: vendor use fell 15% for EU residents in the week after enforcement, while concentration of the vendor market rose 17% as sites retained the largest providers. doi.org ↩
- Brown, N. In Memoriam, OnlineSafetyAct.co.uk. A running list of sites and services that have stated the Online Safety Act 2023 as the reason for closing or geo-blocking UK users — roughly twenty-five at the time of writing, among them The Green Living Forum (running since 2006, around 500,000 posts), the Hexus forums (~310,000 registered users), AWScommunity.social and Urban Dead. A handful, including LFGSS and The Hamster Forum, later returned. onlinesafetyact.co.uk ↩
- Online Safety Act 2023. Ofcom may impose penalties of up to £18 million or 10% of qualifying worldwide revenue, whichever is greater. The duties apply to services regardless of size, so the assessment and compliance burden falls on volunteer-run forums on the same terms as on global platforms. gov.uk ↩
- Freedom House. Freedom on the Net 2025, China country report. Score of 9 out of 100, "Not Free" — the worst environment for internet freedom in the world, a position China has held for more than a decade. The Great Firewall blocks thousands of domains, and authorities restrict access to unauthorised VPNs. freedomhouse.org ↩
- Caixin. "Temu, SHEIN, AliExpress, and TikTok E-commerce: Four Little Dragons Battle Overseas Markets," July 2024. The four are characterised as competing in export markets rather than domestically; TikTok is not available in mainland China, where ByteDance operates the separate Douyin app. caixinglobal.com ↩
- Discord disclosed in October 2025 that a third-party support vendor had been compromised, exposing the government-ID photographs of approximately 70,000 users — documents collected to review age-related appeals. Attackers claimed a far larger haul. The identity data existed only because age assurance required it. biometricupdate.com ↩
- Institute for Government, Digital ID cards. The Identity Cards Act 2006 scheme had roughly 15,000 cards in circulation by May 2010 and was estimated to have cost £4.6 billion by the time the Identity Documents Act 2010 repealed it. The government's own written statement of 16 March 2011 records £375,000 to decommission the systems and destroy the data, and £2.253 million to terminate and amend supplier contracts; the cards ceased to be valid on 22 January 2011, with no refunds. instituteforgovernment.org.uk · gov.uk ↩
- UK digital ID, announced 26 September 2025 and intended to be mandatory for right-to-work checks by the end of the Parliament. The Office for Budget Responsibility put the cost at £1.8 billion over three years — £1.3 billion capital and £0.5 billion resource — and recorded it as an unfunded pressure of about £0.6 billion a year, the government having said it would meet the cost from existing budgets without identifying any savings. A parliamentary petition against the scheme drew close to three million signatures; the mandatory element was dropped in January 2026 and the programme was cancelled on 21 July 2026. theregister.com · commonslibrary.parliament.uk · fullfact.org ↩