The AI Stack Needs a Commons Governor
There are two dominant ways to think about who should govern artificial intelligence.
The market frame says: the data, the models, and the compute are private goods, owned by the organisations that assembled them, exchanged through contract and property rights. Governance follows ownership. OpenAI owns GPT-4. Google owns Gemini. These are products. Markets will sort it out.
The state frame says: AI is too consequential to leave to markets, so regulators must impose rules from above. The EU’s AI Act is the most developed version of this: binding requirements, conformity assessments, registration databases, penalties for violations.
Both frames are real and both are doing real work. But both are partial, and their partiality has a cost. Between the firm and the regulator, there is a third way of governing shared resources that has a century and a half of institutional history behind it. It predates modern capitalism. It was formalised into a research programme by Elinor Ostrom, who received the Nobel Memorial Prize in Economics for it in 2009. We call it the commons.
The claim I want to make here is not rhetorical. It is that the AI stack (the data, compute, models, knowledge infrastructure, and energy that produce AI systems) has the structural features of a commons, and that the governance vocabulary built for commons can and should be applied to it.
The AI Stack Is a Layered Commons

A recent taxonomy by Eduardo Garrido-Merchán at the Universidad Pontificia Comillas in Madrid makes this argument systematically, and it is worth taking seriously.
The AI supply chain decomposes into five distinct layers, each of which has commons-like properties. Data (the training and evaluation corpora) is non-rival in copying, but the work of curating, documenting, maintaining provenance, and defending licensing is rivalrous labour and congestible infrastructure. Compute (the accelerators, clusters, and cloud infrastructure) is unambiguously rival: a GPU running one job is not running another, and the handful of firms that control frontier-scale clusters exercise enormous and concentrated power over who can do what with AI. Models (trained weights and the interfaces through which they are served) are non-rival once released, but governance is subtractable through architectural choices: a developer who releases model weights but serves them only through a closed API has made a governance decision, not just a technical one. Knowledge and evaluation (the benchmarks, leaderboards, documentation standards, and open toolchains) are produced by commons-based peer production and are non-rival in use but subtractable in maintenance: an unmaintained benchmark rots, and an ungoverned standard is captured by whoever has the resources to maintain it. Energy (the electricity and water for cooling consumed by training and inference) is unambiguously rival, and at current AI scale it has become a shared-resource conflict at the level of national grids.
These five layers are not independent. Energy constrains compute. Compute and data jointly produce models. The knowledge layer determines how all of the others are measured and improved. This dependency structure has an important implication: commons governance applied to a single layer in isolation is fragile. Open model weights served from enclosed compute trained on opaque data leave the underlying concentration of power intact. This is what the “openwashing” critique identifies: the appearance of openness without the substance of commons governance.
The Openwashing Problem
“Openwashing” is not a metaphor. It describes a specific failure mode that is already widespread.
A model whose weights are publicly downloadable but whose training data was assembled from scraped content without consent, running on compute that requires access to a handful of hyperscalers, with no community governance over how the weights are developed or in whose interest: that is not a commons-governed AI system. It is a product with a permissive distribution licence.
The distinction matters because the policy responses are different. If you believe “open weights = open AI,” you conclude that models like Llama or Mistral solve the governance problem. They don’t. They solve the access problem at the model layer while leaving the data, compute, energy, and knowledge layers ungoverned. The 2024 Open Source AI Definition from the Open Source Initiative represents one attempt to sharpen the criteria; the ongoing debate about what actually counts as open reflects how contested this terrain is.
Em Lenartowicz, writing for the CLEA/Nunet Foundation on Michel Bauwens’s Fourth Generation Civilization platform, has proposed going further with an AI Commons Licence: a pattern language that embeds commons obligations directly into licence conditions rather than relying on ethical statements that carry no enforcement weight. Where conventional open source licences focus on access and redistribution, a commons licence asks harder questions: who benefits from the model’s outputs, who governs its development, and what does a user of the commons owe back to it? The licence as a governance instrument, not just a distribution mechanism.
Genuine commons governance of AI would look different. Clear boundaries around both the resource and the community entitled to govern it. Rules that are congruent with local conditions and that the affected people can actually modify. Monitoring that is accountable to the community rather than to the company. Graduated responses to violations rather than binary inclusion or exclusion. And nested governance (local institutions embedded in larger ones) that allows commons to scale without losing the accountability that makes them work.
Ostrom distilled these eight design principles from decades of fieldwork on irrigation systems, fisheries, forests, and Alpine pastures. The claim that they apply to AI is not a stretch. It is the application of a validated institutional grammar to a new domain.
The Data Layer: Two Kinds of Openness
The difference between a governed data commons and mere open access is clearest at the data layer, and there is no better contrast than Common Voice versus LAION-5B.
Mozilla’s Common Voice project assembles a massively multilingual speech corpus through voluntary contribution. Speakers record sentences in their own languages. The corpus is released under a Creative Commons licence. Governance includes contributor norms, quality controls, and community decision-making about the corpus’s development. It is a commons: governed, contributed to, and maintained by a defined community under self-determined rules.
LAION-5B is one of the largest image-text datasets used for training AI models. It is open in the sense that the index is publicly available and the images are scraped from the web. But it is not governed: questions of consent, provenance, and harmful content that a genuine data commons would resolve through monitoring and graduated responses went unresolved for years. Lawsuits followed. The distinction is not about size or technical openness. It is about governance.
The CARE principles for Indigenous data governance make this argument from a different and important angle. Developed by researchers in the Indigenous data sovereignty movement, CARE (Collective benefit, Authority to control, Responsibility, Ethics) assert that data about a people should be governed by that people as a collective, not merely by the individuals it describes. This challenges the assumption that individual consent is sufficient for data governance. It insists that community sovereignty over data is a legitimate governance claim, not an optional extra.
For Australia, this is not an abstract principle. Australian Indigenous communities hold significant data interests in health, land, cultural knowledge, and language that are increasingly subject to AI training pipelines. The CARE principles are a governance framework, not a wish list. They point to what data trusts and community data agreements for Indigenous AI training data would need to provide.
The Compute Gap
If data is the layer where commons governance is most institutionally developed, compute is the layer where the gap between promise and reality is widest.
Compute is the most clearly rival of the five layers, and as a result the most amenable to exclusion and concentration. The manufacturing pipeline for advanced AI accelerators runs through TSMC, NVIDIA, and a handful of other organisations. The clusters that matter for frontier AI training are controlled by Google, Microsoft, Amazon, and Meta. The access asymmetry this produces, between the few organisations that command frontier-scale compute and everyone else, is the central inequality of the current AI moment.
Public compute initiatives exist as a direct response to this asymmetry. The US National AI Research Resource aims to provide academic and non-profit researchers with access to compute they cannot otherwise afford. The European High Performance Computing Joint Undertaking pools publicly funded computational capacity across EU member states. These are not perfect solutions: access is constrained, governance is complex, and the compute bottleneck at frontier model training is not solved by academic cluster access. But they represent the recognition that compute is infrastructure, not a product, and that infrastructure serving public interest should be governed as such.
At smaller scale, CoCore demonstrates what a compute cooperative looks like in practice: members share the hardware they already own to run AI inference for each other, 95% of token costs flow back to the hardware providers rather than to shareholders, and every job writes a verifiable receipt that anyone can audit without calling a central authority. The current network is modest, in the dozens of machines and models rather than data-centre scale, but the governance model is the point: peer-to-peer, transparent, member-owned, and architecturally resistant to the concentration that defines the hyperscaler model.
Australia has no equivalent at the public infrastructure scale.
This is not a minor gap. Every Australian researcher, public institution, and community organisation that wants to train or fine-tune AI models on Australian data, for Australian conditions, using Australian governance, currently does so on compute owned by US hyperscalers and subject to US law. The digital sovereignty analysis from The Billion Dollar Brick applies here directly: dependency is not choice, and the absence of Australian public compute is a policy choice, not a technical constraint.
Data Commons in Practice: What Already Exists
Farm data provides the clearest Australian example of commons governance in practice, and it is worth understanding what already exists before talking about what needs to be built.
The enclosure pattern will be familiar from the AI stack. Modern tractors and harvesters throw off constant streams of yield, soil, and machine-performance data, and on most current equipment that data flows straight into the manufacturer’s own cloud, accessible to the farmer through a subscription dashboard rather than held by them outright. The right-to-repair fights against John Deere and other machinery multinationals are, underneath the specific grievance about diagnostic software, a fight over exactly the same thing hyperscaler compute lock-in produces for AI: whoever controls the pipe the data runs through controls who gets to use it, on what terms, no matter who generated it in the first place.
AgReFed, the Australian Agricultural Research Federation, operates as a federated data infrastructure connecting research organisations, government agencies, and industry. Its focus is on FAIR data principles (Findable, Accessible, Interoperable, Reusable) rather than farmer-governed cooperatives, but it demonstrates that data federation at meaningful scale is achievable in Australian agriculture. The National Farmers’ Federation’s Farm Data Code sets minimum governance standards for farm data held by agtech companies: consent requirements, ownership clarity, transparency about how data is used.
Neither of these is a data commons in the full Ostromian sense, governed by a bounded community under self-determined rules, with collective choice over access conditions and benefit distribution. For that model, the US Ag Data Coalition is closer: a farmer-controlled data repository where members decide who gets access, operated as a cooperative “data locker.” The EU’s Common European Agricultural Data Space takes the public goods approach: federated, standardised, governed by a multi-stakeholder body, with data remaining with its owner.
What all of these models share is the recognition that farm data is not a neutral technical asset. It is the product of farmers’ labour, knowledge, and land, and it carries information about their competitive position, their financial situation, and the health of their soil. Who governs access to it (the farmer, the cooperative, the platform company, or the regulator) determines who benefits from the intelligence it contains.
The same analysis applies to every domain where AI training data comes from the activity of communities rather than the production of corporations: health data, environmental monitoring, cultural knowledge, educational materials. The governance question of who decides who gets what on what terms is not technical. It is institutional.
Towards an Australian AI Commons
None of this is being invented from scratch. A December 2024 field scan commissioned by One Project mapped 234 organisations, cooperatives, and networks across Africa, the Americas, and Europe already working on alternative AI governance, communities of practice informed by decolonial, Indigenous, feminist, and post-capitalist frameworks that most OECD policy conversations have not seriously engaged with. Australia, sitting in a region with living Indigenous data sovereignty movements, has less excuse than most for treating this as someone else’s conversation.
The path from here to a meaningful AI commons is not a single policy decision. It is a series of institutional choices, each of which can be made at a different level and a different pace.
At the data layer: data trusts for health, agriculture, and environmental data; legal recognition of community data sovereignty; mandatory data governance standards for AI training that go beyond individual consent to include community authority. AgReFed already provides some of the technical infrastructure. What is missing is the governance mandate and the legal frameworks that would make a genuine commons rather than a research data sharing arrangement.
At the compute layer: a public compute initiative, even a modest one by European standards, that gives Australian researchers, public institutions, and community organisations access to AI training infrastructure without routing through US hyperscalers. The Commonwealth Scientific and Industrial Research Organisation, the Australian Research Data Commons, and the National Computational Infrastructure already have the technical capacity and institutional relationships to anchor this. What is missing is the political decision to treat compute as public infrastructure.
At the model layer: mandatory transparency for AI systems used in public services, covering training data provenance, evaluation results, and known limitations. The Foundation Model Transparency Index documents how poorly most frontier AI models score on exactly the transparency criteria that would make accountability possible. Australia’s public sector should not be deploying black-box AI systems without the right to inspect and audit them. Current practice is in many cases the opposite.
At the knowledge layer: funding for the open benchmarking and evaluation infrastructure that Australian AI research depends on. Australia cannot govern AI systems it cannot evaluate. Evaluation requires benchmarks, and benchmarks require maintenance. That is a commons problem with a funding solution.
None of this requires Australia to build a frontier AI model. It requires Australia to govern the AI infrastructure its institutions and communities depend on, for the benefit of those institutions and communities, rather than the benefit of foreign shareholders.
The commons framework is not idealism. It is the institutional vocabulary developed over 150 years to manage resources that are too important to leave to markets and too complex to manage by central command. The AI stack has the structural features of those resources. It should be governed accordingly.
Part three of three, plus an unplanned fourth: on paying for the labour the commons has never accounted for, added after a reader’s reply on Mastodon. Previously: What the Commons Built (And What's Taking It Apart) on the history of digital commons enclosure, and Europe Chose Differently on what France and Germany are doing about it. Also related: Unicorns Build Monocultures on the cooperative and commons alternatives to VC-backed digital agriculture. The Billion Dollar Brick on sovereignty and dependency at the defence and national infrastructure scale.
Sources
Commons governance of AI: theory and taxonomy
- Garrido-Merchán, E.C. (2026). Commons-governed artificial intelligence: A taxonomy of collective governance. arXiv:2606.15466v1 [cs.CY]: the systematic taxonomy this post draws on for the five-layer AI stack and the Ostromian governance framework applied to AI
- Ostrom, E. (1990). Governing the Commons. Cambridge University Press: the eight design principles; the original empirical refutation of Hardin
- Hess, C., & Ostrom, E. (eds) (2007). Understanding Knowledge as a Commons. MIT Press: the extension of commons theory to non-rival knowledge goods; the conceptual hinge for treating AI training data as a commons
Openwashing and commons licensing
- Widder, D.G., Whittaker, M., & West, S.M. (2024). Why “open” AI systems are actually closed, and why this matters. Nature, 635(8040): 827–833. The definitive account of openwashing in AI development
- Open Source Initiative (2024). The open source AI definition 1.0. opensource.org/ai/open-source-ai-definition
- Lenartowicz, E. (2025). The AI Commons Licence: A Pattern Language. 4th Generation Civilization (Michel Bauwens, ed.), CLEA/Nunet Foundation: a commons governance approach to AI licensing that moves beyond access and redistribution to codify contribution obligations and benefit distribution
Data commons: theory and examples
- Purtova, N., & van Maanen, G. (2024). Data as an economic good, data as a commons, and data governance. Law, Innovation and Technology, 16(1): 1–42: distinguishing data as economic good from data as commons
- Carroll, S.R., et al. (2020). The CARE principles for Indigenous data governance. Data Science Journal: Collective benefit, Authority to control, Responsibility, Ethics; the governance framework for community data sovereignty
- Delacroix, S., & Lawrence, N.D. (2019). Bottom-up data trusts: Disturbing the ‘one size fits all’ approach to data governance. European Journal of Law and Technology, 9(1)
- Common Voice project: commonvoice.mozilla.org: the governed multilingual speech corpus; contrast with LAION-5B’s governance controversies
Australian data infrastructure
- AgReFed: Australian agricultural research data federation; FAIR data for agriculture
- National Farmers’ Federation, Australian Farm Data Code: governance standards for farm data held by agtech companies
- Ag Data Coalition (US), agdatacoalition.org: farmer-controlled data cooperative as a reference model
- EU Common European Agricultural Data Space: federated, multi-stakeholder agricultural data governance
Public compute initiatives
- National Artificial Intelligence Research Resource Task Force (2023): US proposal for public compute access for researchers and non-profits
- European High Performance Computing Joint Undertaking: EuroHPC; pooled public computational capacity across EU member states
- Australian Research Data Commons: existing Australian data infrastructure that could anchor a compute commons
- CoCore: working cooperative inference network; members share owned hardware, 95% of token costs return to providers, verifiable receipts without central authority
Global AI commons ecosystem
- Varon, J., Costanza-Chock, S., Tamari, M., Taye, B., & Koetz, V. (2024). AI Commons field scan. One Project / Coding Rights: maps 234 organisations across Africa, the Americas, and Europe working on alternative AI governance informed by decolonial, Indigenous, feminist, and post-capitalist frameworks
Model transparency
- Bommasani, R., et al. (2023, 2024). Foundation Model Transparency Index. Stanford CRFM: documents the transparency failures of frontier AI models on provenance, evaluation, and governance criteria
- Robinson, N. (2026). Open to open-source AI? Government Information Quarterly, 43(2026), 102133. Australian, Canadian, and German decision-maker perspectives on AI model governance in public sector
- AI Commons
- AI Governance
- Data Sovereignty
- Open Source AI
- Commons Governance
- Data Cooperatives
- Public Compute
- Digital Sovereignty
- Australia
Comments
Be the first to comment! Reply to this post from your Mastodon/Fediverse or Bluesky account, or mention this post's URL in your reply. Your comment will appear here automatically via webmention.
Follow this blog on Mastodon at @gaggl.com@web.brid.gy or on Bluesky at @gaggl.com