Submind YouTube summaries
Thumbnail for Capital Series Cyprus - Leon Schumacher Keynote

Capital Series Cyprus - Leon Schumacher Keynote

Watch on YouTube

Video summary

Leon Schumacher, a seasoned entrepreneur and former CIO with deep experience in cybersecurity and digital assets, opens his keynote by redefining the concept of sovereignty not as nationalism or the construction of digital walls, but as essential business continuity. He argues that true sovereignty means maintaining operational capability when external vendors, governments, or platforms alter their rules unexpectedly. To illustrate this vulnerability, he points to the Huawei ban caused by US restrictions on Android, the weaponization of financial infrastructure during the Ukraine war, and the unpredictability of US policy under potential future administrations. These events demonstrate that access to technology and payment systems is increasingly conditional, making open-source solutions a critical form of insurance against geopolitical risks and ensuring that organizations can continue functioning without relying solely on foreign permission. The discussion then shifts to the complexities introduced by Artificial Intelligence, where traditional notions of open source are challenged by the nature of model weights and data rather than just code. Schumacher highlights how major players like OpenAI have shifted from openness to restriction once they developed frontier models, while simultaneously noting that the current AI landscape is dominated by Chinese companies who offer powerful, cost-effective alternatives that effectively perform a "land grab" outside the United States. He uses the example of Google's Gemini altering historical data to show how these systems can subtly reshape truth and history, raising critical questions about who should control the intelligence defining our reality. Furthermore, he critiques Anthropic for releasing models only in the US under national security pretexts, leaving the rest of the world without access to cutting-edge technology and proving that the internet is no longer borderless when it comes to AI deployment. A significant portion of the talk addresses the European Union's struggle with digital sovereignty, particularly regarding payments and the Digital Euro. Schumacher praises initiatives like AP Vero for countering dependency on Visa and Mastercard but criticizes the European Central Bank for ignoring open-source strategies in its procurement processes despite public demand for privacy and security. He notes that the ECB's Request for Proposals effectively excluded innovative small companies by setting revenue thresholds too high, thereby stifling the very innovation needed to build a resilient future-proof system. While acknowledging the complexities of the Digital Euro's online and offline systems, he emphasizes that Europe possesses all the necessary components—such as Mistral for AI and sovereign clouds—to lead in this space but currently fails to integrate them into its strategic infrastructure due to bureaucratic blind spots and a preference for large incumbents over agile startups. In his concluding remarks, Schumacher urges European leaders and investors to move beyond creating strategies on paper and to take concrete actions that support open-source projects and sovereign digital infrastructures. He warns that relying solely on big players or proprietary black boxes leaves Europe vulnerable to future disruptions, whereas embracing open-source ecosystems offers a path to independence and resilience. The core message is that sovereignty requires having fallback options and the ability to adapt when circumstances change, much like buying insurance. He calls for immediate investment in European AI providers and open-source solutions to set global standards rather than following American or Chinese dictates, asserting that Europe has the opportunity to make a difference if it acts decisively to secure its digital future against an increasingly unpredictable global landscape.
Read the full video transcript
Happy to be here. You hear me? Okay. Like that. Mic is good. Thank you for open forum Europe. Thank you Mar for the invitation. Uh my name is Leon Schumacher. I grew up in the corporate world. Was a former CIO of Arsloal the large shield company and of Novartes the large Swiss farmer group. then became an entrepreneur in cyber security, privacy and payments each time with open-source solutions. I've been quite involved in central bank digital currency work and now I'm advising on digital assets, AI and related subjects to cor corporates and governments and in when I have a few minutes in between I'm writing some books on those subjects as well. So, you can find those on Amazon if you're interested. But first, listen to what I'm telling you before you go buy the book. Well, let me start with saying that I'm a huge fan of what Mr. Kleiner from the European Commission said in the first keynote. I am also a huge fan of the Luxeber football team, which will go undefeated in this World Cup. >> So, I only hope that Mr. Kleiner will score more points than the Luxembbergish team. But today I want to talk about sovereignty and open source. So sovereignty is defined as the supreme power of a state to govern itself and to make laws without external interference. But for me sovereignty is not nationalism. I would not mean it should not mean building digital walls. I think sovereignty for me is business continuity. It means continuing to operate when a vendor, a government or a platform changes the rules. It means having a solution to continue paying when Trump tells Visa and Mastercard to get out of Europe. So open source is one of the best ways to buy insurance against these risks. So how did we get to this space where sovereignty suddenly has become so important? For me there's three points basically on the timeline that I think are important. I think the first one for me is the Huawei ban. So the Americans banned Huawei away from using Android, Google's Android system and that basically basic stopped the sales of their handsets. And so the Android dependency became a strategic vulnerability for Huawei in that case. That was a while back. Not that many people noticed unless they had a Huawei phone that could no longer be updated. Of course, then came the Ukraine war and we saw that financial infrastructure became a geopolitical weapon. And last, as was already mentioned twice, came Mr. Trump and US unpredictability where Europe had to realize that it is so dependent on US infrastructure that it's extremely risky uh the position that it finds itself in if the Americans turn out to be less reliant than they used to be. So these examples are not extract. They showed that access to technology and to payment can become conditional. So, and the same applies to AI and AI makes the whole topic even a little bit more confusing I find. So, we we have all these names in AI. Claude, Fable, Metos, O4, Sonet, Project Glass, Swing, Jet GPT, Sora, Nano, Banana, Gemini, X402, AP2, ACP, MPP, and I could go on for another 10 minutes, but uh let's try to keep it at that. So while traditional open source meant you can take the source code, you can read it, you can run it, you can modify it and you can redistribute it. AI makes that harder because the code base is small and you cannot do anything with it. I as you you need the weights and if you look at the meta slamma 2 model which was composed of two files one a small one with 500 lines of code. So even if you have can read those 500 lines of code you could not do anything with the other file which was about 140 GB of parameters which included the weights. So with AI it's even the open source copy becomes more complicated. So it has the source codes, the weight, the data, the training recipes, usage restrictions and so forth and the open weights open source does not mean open weights, right? That that's an important thing to to keep in mind. But for this talk here, when I talk about open, I mean practical sovereignty. So can we inspect, run, adapt, replace or continue the system without asking somebody else for permission. Now the confusion continues by the naming of the key AI player open AI founded around openness and benefit to humanity. As soon as they got some frontier systems, they became very very closed. So no no no more sign of openness. Some point down the road because they took a lot of for that they release an open weight model of medium capacity. So do they think that makes them open again or can we classify that as open washing? And so uh we we had Meta, Facebook, amazing that they were the leader of uh releasing open-source AI models for a while. They took a lot of criticism for that because everybody said, "Oh no, you're giving uh critical information to the Chinese and they use military and for surveillance and and so forth. We we should definitely not do that." And then we had an interesting twist there today. If you look at the open source leaderboards for AI, it's basically 95% Chinese companies, Quen, Deepc, Kim, GLM, and and nothing else. So, it's interesting how these things change over time and what was so strongly criticized on one hand two years later has no connection to reality anymore. So what what we can take from that is that open source today is not leakage from the the frontier models. It's actually an ecosystem formation. The best open building blocks attract developers, tools, benchmarks, standards. Whoever provides the best open building blocks shapes the ecosystem. And I think that's the idea also that the Chinese have by providing that if we can do a land grab everywhere outside the United States offering it for free or that price point that is very different from the frontier AI models but at 99% of the capacity we think that's that's the play here. So the real question is not only whether a model is American or Chinese. I think the real question is who owns the intelligence, who defines the guard rates and who can change the system without us noticing. We have seen already how the tuning choices can shape outputs in politically sensitive ways. Some of you certainly remember the Google Gemini eliminating all white men from history. So if that had been done a little more subtle, would anybody have noticed? And that points to the power of these systems uh who shall be providing our source of truth because those systems will replace the internet as the source of truth in the future. Who do we want to entrust entrust that power? Google was a little blump so uh the pope became black and and similar things but it it shows that those systems can change history change change the truth that the people rely on as they move forward. So then let let me move on to Antropic. Antropic was founded by former AI people open AI people to focus more on safer frontier models. So they wanted stronger regulations. So some people said okay that's because they want more safety. Critics says no they wanted to have regulatory capture the the governments making it so difficult for other people to enter the space and uh protect the AI space for Anthropic of an AI and a few others. They certainly have most likely the best model today. So on April 7, Entropic announced Claude Mitter's preview as being too dangerous to be released to the public. It's going to hack us all. It's going to be the end of the world. We cannot release it. We have it. Just be impressed. We are the best, but we cannot give it to you. And so it was then shared with a selected group of cyber security companies and banks uh but only in the US with the thought that okay we allow these important players to improve their situation before we release this to the public. That was nice for the Americans but that left all the rest of the world out in the cold. So once this thing came out if I'm European bank well not great not great. So then it became even more interesting. So that the original version there, the preview came out on April 7th. So on June 9th, uh, Entropic released Fable Mythos. So the the official release of of that version that was tuned down to be safe, but that the US government found that it was not good enough and cited national security concerns over potential jailbreaks that could bypass the model safeguards. And so they ruled that the model could not be given to non-Americans. interesting entropy then although they got the government protection they wanted but maybe not exactly the way they wanted uh was in a tough spot because they couldn't guarantee the nationality based restriction. So they ended up pulling the mo models completely. So the core lesson is we can have models that are available one week and they are unavailable the next or product can become a national security asset and then just be available to to a certain group of companies and global access becomes nationality restricted. The internet and the cloud it was sold to us as borderless but the kill switch clearly is not borderless. So, so then what what does sovereignty mean in in in in this environment? For me, it means having options when the access changes, having the ability to continue operating having a fallback model, a fallback provider, a fallback cloud. It doesn't mean to me that okay, in order to have sovereignty, I have to have everything Luxembourgish. or the chips, the the cloud on the software, the the network, whatever. We will never get to that. We'll get to that by the time I I'll be long dead. But uh I think we we need to look at it from a business continuity. What do we do if somebody pulls out the piece? Can we keep running? Uh and that that's the the way we we need to organize ourselves to be ready because it will not it's not free. You it's like buying insurance. It's not free but you're happy when you have done it if disaster strikes. So that's also why the European Commission, the European Commission's technology, technological sovereignty agenda is so important, including the open-source strategy that they launched in early June. public money, public code. I immediately subscribe to that and I think that should be the default for any physical infrastructure uh that we roll out. If the public funds strategic digital infrastructure, the public should not be locked into a black box forever. And Europe understands this sovereignty element already in payments and has been acting on it but not without blind spots. So we clearly saw the Visa Mastercard dependency. So AP Vero was an early project that tried to counterbalance that. The digital euro is clearly going in that direction. The Italians just blocked the takeover of Nexi, a payment provider from uh the venture capitalist CBC. The UK is also doing a project to copy Vero and and and do something similar. And uh if if we talk about the digital euro for two seconds, it's it's the most confusing project I've seen because every question you asked can be answered in two different ways with yes and no and you're both correct. That's pretty cool. And that's because there are two systems and there's an online and an offline system that have very different characteristics and privacy security tradeoffs. So does the digital euro offer privacy? Online, no. Offline, yes. So if you don't specify the online offline, you can say yes or no and still be correct. >> Is it secure online? Yes. as secure as any other accountbased system offline. No, it cannot be mathematically secure which gives it a terrible starting point despite the 800 million that ECB is investing to prove that they are smarter than the law of mathematics. So the digital euro should become one of Europe's most critical infrastructures. But the European Commission open source strategy has not found its way to the ECB's procurement department open source was not mentioned in the five RFPs with which they are spending 1.3 billion euros not mentioned nowhere not once and I think open source should be central not marginal in in initiatives like that and then we look at okay the citizens priorities privacy was the top requested feature. Security was second used throughout the EU third and then low fees was was fourth. And even if we look into the open source community, you you find solutions that are much better designs than what they're currently trying to do in Frankfurt. Uh GNU Tower is open source, offers payer anonymity, merchant auditability. Uh it's all open source. it it has uh security reviews that are published and out there. The system has been through the regulator in Switzerland and is in operation in Switzerland starting to bring on merchants and and users but it's of course difficult as a small startup to to make that happen. It's future proof. It's quantum resistant. It can do microtransaction and so forth. And uh the European Commission uh the the European Central Bank had probably eight talks with Tyler before the RFPs came out. But in the RFPs, they eliminated all the innovative small companies by saying, well, if you want to talk to us, we are the ECB. If you don't have a 100 million in revenues, we don't talk to you. So only the big friends are allowed to to participate. No matter that everybody knows that the innovation comes from the small players, not from the big players, but that also the ECB had uh not understood yet. So that brings us to to the next blind spot and I'm trying to keep an eye on the time. We have the sovereign payment initiatives throughout pushing hard spending lots of money from 700 million on on Vero and 1.3 billion on the digital euro. AI agentic payments are the next thing that comes. The McKini said up to 5 trillion in 2030 which is the same amount than the card payments in Europe. Not a single European officials official or politicians has updated the world's sovereign and AI agentic payments in the same sentence. So we will again miss the boat there. Although as Europe we have all the pieces that are needed. We could say look let's let's bring the AI guys in. Mistral is a pretty good example for for a European AI provider. Tala could bring the machine oriented payments up to microtransactions quantum proof and so forth. If you take those two sovereign clouds exist in Europe, bring that together and you can basically set the standard there. Today 15 standards have been proposed all America, Coinbase, Google, Stripe, Mastercard, Visa and and so forth. So that that's one area also where where we are missing missing the boat. So I will close here with say Europe has the asset. Many of them are open source. we have the opportunity basically to to make a difference and we need to take action. I think it's not enough that that we have nice strategies and nice slides like uh the European Commission brings out they need to lead something and the actions need to follow the words because as I can tell you from the startups that I see in open source life is difficult when it comes to fundraising. If you're open source and you want to raise funds, that is extremely hard and challenging. So if any of you sit on extra funds that you want to invest in interesting opensource projects, just let me know. I'll tell you where to go. And with that, I stop and hand it back. Thank you.