8 Artifacts Have Politics
Prerequisites: none. You can read this chapter on its own, as a reflection on the other chapters in Part I.
See also: Chapter 35, Chapter 38, Chapter 3, Chapter 34.
Purpose

Think about the last time a website told you your name was invalid. Maybe it has an apostrophe, like O’Brien, or an accent, like José. Maybe you have two family names, or a hyphen, or only one name, and the form insists on a “Last name.” The error message says please enter a valid name, as if the problem were you. It wasn’t. Somebody wrote that rule, probably a developer who assumed every name looks like theirs: plain letters from A to Z, one first name, one last name. Nobody held a meeting about whose names should count. The decision got made anyway, and now a machine enforces it on millions of people, politely and without appeal. (The W3C, which writes the web’s standards, keeps a whole guide to how names differ around the world because this keeps happening.)
If your first reaction to this chapter’s title is “come on, software doesn’t have politics,” that’s a fair place to start. Code is instructions; a for-loop doesn’t vote. This chapter doesn’t ask you to take the opposite view on faith. It works through cases, from bridges on Long Island to risk scores in courtrooms, and lets you judge for yourself whether the choices built into tools end up deciding who gets served, who gets watched, and who pays.
The rest of this handbook is a how-to. This chapter asks a different kind of question: whose trade is computing, whose values are baked into its tools, and whose problems shaped them? It traces where computing came from, who was left out of it, how states and platforms use it, what labor and materials it quietly consumes, and which laws set its limits. It won’t tell you what to think, and it isn’t meant to make you cynical. The goal is for you to see yourself as a participant in a long, contested, still-unfinished story, and to have better questions to ask the next time you adopt a tool or build one.
Why read this chapter
- A sign-up form rejected your name because of an apostrophe, an accent, or a missing “last name,” and you’d like to understand how a machine ended up deciding what counts as a real name.
- A remote-proctoring tool asked you to sit under brighter light or flagged you for looking away, and you wondered whether software that analyzes faces sees every face equally well.
- Someone in class said “algorithms can’t be biased, it’s just math,” and you had a feeling that was wrong but no case to point to.
- A platform’s feed decides what you see and its rules decide what you may post, and “it’s just the algorithm” has stopped feeling like an answer to who made those calls.
- You’re scraping a website for a class project, and you’re not sure whether “the site let me download it” means you were allowed to.
- You use AI tools every day and want to know what’s behind them: the labeled data, the moderators, the electricity, and the people who never show up in the demo.
- You keep hearing about Section 230, GDPR, and “right to repair” in the news and want to know what they mean for the things you build.
Running theme: ask what a tool does besides its job
Every tool does what it says on the box, and something else besides: it sorts people, sets defaults, and moves costs somewhere you can’t see. Asking about that “something else” is part of doing technical work well.
8.1 Technology is never neutral
The chapter’s title comes from the political theorist Langdon Winner and his 1980 essay “Do Artifacts Have Politics?” (Winner 1980). His argument was that technologies embed political choices, sometimes deliberately and sometimes by accident, and that you can’t reason about them honestly without naming those choices. More than forty years later the argument matters more, not less, because the artifacts in question now sit between us and most of public life.
Winner described two ways a technology can be political. The first is by design: a thing can be built to reinforce a particular social arrangement. His most famous example was the parkways on Long Island built under Robert Moses, New York’s powerful builder of roads, parks, and bridges from the 1920s to the 1970s. Many of the overpasses were built too low for buses to pass under. Drawing on Robert Caro’s biography of Moses, Winner argued the effect was social sorting: beaches like Jones Beach were easy to reach by private car and hard to reach by bus, and so easier for the car-owning middle class than for poorer people, many of them Black, who rode public transit. The bridges “had politics” not because concrete has opinions, but because their shape did quietly what a written policy might never have gotten away with.
It’s worth knowing that historians still argue about this story. Some say low bridges were standard on parkways of the era, and question whether Moses meant to keep anyone out. That argument is a lesson in itself: the effect of a design can be real and lasting whether or not anyone can prove the intent. Winner had a less disputed example, too. In the 1880s, he reports, Cyrus McCormick’s reaper factory in Chicago installed expensive new molding machines that made worse castings at higher cost. Their real job was to replace the skilled workers who had organized a union, and once the union was broken, the machines were abandoned after three years.
The second way is inherently: some technologies tend toward one kind of social arrangement no matter who runs them. Winner’s starkest example was the atomic bomb, which, as long as it exists, demands a centralized and rigidly hierarchical chain of command. He also discussed the argument that nuclear power, with its hazardous fuel and its few large, heavily guarded plants, pushes toward centralized control, while solar panels on rooftops fit more easily with distributed, local arrangements. Winner was careful not to say that technology determines society. His claim was that it loads the dice.
Both readings apply directly to software. A phone whose maker decides which apps you may install, and which repairs void your warranty, has politics the way the parkway bridges did: someone made a decision about what you’re allowed to do, and that decision is now built into the device in your hand. Large language models have politics in both of Winner’s senses at once. Their training data carries particular languages and cultural defaults by design, and their costs push inherently toward a small number of very large companies that can afford to build them. So the question to keep in your back pocket isn’t just what does this artifact do? It’s what does it do besides its stated function?
8.2 Three origin stories
When people argue about what computing should be (open or closed, public or private, free or paid), they’re usually replaying an older argument without knowing it. Modern computing has three ancestral traditions whose values don’t fully fit together, and most big fights in the field come down to which one is winning.
The national-security tradition
It’s hard to overstate how much of modern computing grew out of the United States military budget. The ENIAC, finished in 1945 and shown to the press in 1946, was built for the Army’s Ballistic Research Laboratory to calculate artillery firing tables. After the war, the money changed labels but didn’t go away. Paul Edwards’s The Closed World (Edwards 1996) is the standard account of how Cold War fear of bombers, missiles, and nuclear war poured funding into digital computers, real-time systems, networking, graphics, and human-computer interaction for decades. Things you take for granted, like interactive computing, the mouse, graphical interfaces, and computer networks, have ancestors in projects like the air-defense system SAGE, the Pentagon’s research agency ARPA (today DARPA), and the RAND Corporation.
The ARPANET, the internet’s ancestor, is a good example of how funding shapes design. ARPA paid for it so that expensive research computers at universities and labs could share resources, and the packet-switching idea underneath it drew partly on Paul Baran’s work at RAND on communication networks that could survive an attack. TCP/IP, email, and the domain name system all grew up in that ARPA-funded world. That history decided which problems got attention. “Move packets reliably between trusted institutions” got excellent engineering; “tell billions of strangers apart on a hostile network” got almost none. If you’ve ever wondered why spam, phishing, and password leaks feel so hard to fix, part of the answer is that the internet has been bolting on encryption, identity, and trust ever since, and it still isn’t done.
The surveillance side of this tradition is harder to separate from the rest than textbooks let on. The 2013 Snowden disclosures showed the NSA collecting records of most phone calls made in the United States, tapping the fiber-optic cables that carry traffic between continents with its British partner GCHQ, and, in at least one documented case, promoting a cryptographic standard, Dual_EC_DRBG, with a weakness it could exploit. The tech industry’s response helped push the web toward encryption by default. HTTPS, once mostly reserved for login and checkout pages, carried about 70% of page loads in Firefox by April 2018, and it’s now so normal that browsers warn you when a site doesn’t use it. That’s one of the clearer cases of politics cutting both ways: a state surveillance program helped trigger a commercial re-engineering of default protections, which then made future surveillance harder.
The commercial-monopoly tradition
Once you know computing came out of military spending, the next surprise is how quickly it became one of the most concentrated industries in history. The pattern repeats: a dominant firm emerges, regulators eventually notice, an antitrust case drags on for years, a court order or settlement reshapes the industry, and a new dominant firm grows in the gap.
AT&T spent most of the twentieth century as a single regulated monopoly, and it funded Bell Labs, arguably the most productive research lab in the history of computing: the transistor, information theory, the C programming language, and Unix all came from there. A 1956 antitrust consent decree kept AT&T out of the computer business, which is a big part of why Unix was later licensed cheaply to universities and became the genetic material for most modern operating systems, including the ones on your laptop and phone. IBM spent 1969 to 1982 fighting a federal antitrust suit, and when it rushed its first personal computer to market in 1981, it licensed the operating system from Microsoft, then a small company near Seattle. Microsoft kept the right to sell that system to other manufacturers, and that deal turned it into the owner of the PC era. Microsoft’s own antitrust case, United States v. Microsoft, ended in a settlement in the early 2000s, just as the action moved to search, which Google was winning, and then to mobile, which Apple and Google split.
Today’s dominant platforms face antitrust scrutiny in the United States, the European Union, and several Asian countries. The EU’s Digital Markets Act (2022) is the first serious attempt to regulate “gatekeeper” platforms directly rather than one case at a time. The lesson of the history is that big computing firms gather power faster than regulators can respond, and the firms that benefit from one round of fixes often dominate the next. Meanwhile, when a platform makes a rule (no guns in marketplace listings, apps must use our payment system, no training models on our data without a license), that rule works like law for hundreds of millions of people, without any of the democratic accountability you’d expect of a law.
The hacker-counterculture tradition
Alongside the military and commercial stories, a third one has always been running. Steven Levy’s Hackers (Levy 1984) popularized the hacker ethic: information should be free, authority should be mistrusted, access to computers should be unlimited, and people should be judged by what they can do rather than by their credentials. The ethic grew up in student labs at MIT in the late 1950s and 1960s, traveled west to hobbyist groups like the Homebrew Computer Club in the 1970s, and shaped the culture of the early personal-computer industry.
Fred Turner’s From Counterculture to Cyberculture (Turner 2006) tells a less comfortable version. In his account, a libertarian, anti-institutional strand of the 1960s counterculture merged with Cold War systems thinking to produce the rhetoric of the commercial web: “information wants to be free,” “the net interprets censorship as damage and routes around it.” That rhetoric was partly right and partly wildly optimistic about how power would redistribute once everyone was online.
The institutional heir of the hacker ethic is free software. Richard Stallman launched the GNU Project in 1983 on a moral claim: users of software should have four freedoms, to run a program for any purpose, to study and change it, to share copies, and to share their changed versions. The Linux kernel (1991), combined with the GNU tools, produced the first complete free Unix-like operating system, and today Linux runs most of the public internet, most smartphones (Android is built on it), and nearly all of the world’s supercomputers. That success came with a catch you’ll meet again in Chapter 14: much of the world’s critical software rests on a few overstretched people, often unpaid, and their exhaustion keeps turning into security crises. When the Heartbleed bug turned up in OpenSSL in 2014, the library that secured a large share of the web’s encrypted traffic was maintained by a handful of volunteers, only one of them full time, on about $2,000 a year in donations. A decade later, in 2024, someone who had spent more than two years pressuring and winning the trust of an overstretched volunteer maintainer managed to slip a backdoor into XZ Utils, a compression tool found on most Linux systems; it was caught almost by accident.
8.3 Who computing was built for, and who got left out
Gender
If you learned computing history from a standard textbook, you probably learned it as a parade of men. That picture is wrong in a specific and useful way. For the field’s first decades, programming was low-status work done mostly by women, and today’s gender imbalance is the result of a reversal you can document, not a baseline that was always there.
Until the mid-twentieth century, a “computer” was a person, usually a woman, who did calculations by hand. The six people chosen to program the ENIAC, Kay McNulty, Betty Jennings, Betty Snyder, Marlyn Wescoff, Fran Bilas, and Ruth Lichterman, were all women. Their work was treated as clerical; the press coverage celebrated the machine and the men who built its hardware, and their story was largely recovered only decades later, when the researcher Kathy Kleiman tracked them down. A century before them, Ada Lovelace had published what’s often called the first algorithm meant for a machine. Grace Hopper built the A-0 system (1952), often counted as the first compiler, and her FLOW-MATIC language became a basis for COBOL. At NASA’s Langley center, Dorothy Vaughan, Mary Jackson, and Katherine Johnson were Black women mathematicians and engineers whose work helped put astronauts into space; John Glenn asked for Johnson personally to check the computer’s numbers before his orbital flight, and she also helped calculate the trajectory for Apollo 11. These names are a small sample; Nathan Ensmenger’s The Computer Boys Take Over (Ensmenger 2010) and Mar Hicks’s Programmed Inequality (Hicks 2017) document many more.
The shift from a mostly female field to a mostly male one happened roughly between 1960 and 1985. As programming became economically important, employers, aptitude tests, professional societies, and new computer science departments adopted practices that favored men. In Britain, Hicks shows, the civil service pushed women out of computing work as it gained status, and the resulting labor shortage helped sink what had been a leading national computer industry. In the United States, women’s share of computer science bachelor’s degrees peaked near 37% in 1984 and fell to about 18% by the late 2000s. You can still see the pattern today in pay gaps, in higher rates of women leaving the industry, and in who gets venture-capital funding. Data Feminism (D’Ignazio and Klein 2020) offers a useful way to think about this: ask who is counted in a dataset, who is doing the counting, and who benefits, and treat those questions as part of the analysis rather than an afterthought.
Race and algorithmic bias
You’ll often hear computer systems described as “objective,” in contrast to biased human judgment. It’s an appealing idea, and if you’ve ever heard someone say “the algorithm is just math,” you’ve heard it. The evidence doesn’t support it. A long record shows that computer systems regularly reproduce and amplify the biases of the societies that build them, a pattern with its own name, algorithmic bias. Sometimes the training data reflects historical discrimination; sometimes the problem was framed in a way that made bias inevitable; sometimes the people using the system pointed it at the communities they were already policing.
Here are the cases. In 2013, Latanya Sweeney showed that Google searches for names more often given to Black babies were more likely to show ads suggesting the person had an arrest record than searches for names more often given to white babies (Sweeney 2013). ProPublica’s 2016 “Machine Bias” investigation (Angwin et al. 2016) looked at COMPAS, a risk-assessment tool used in some US criminal courts, and found that Black defendants who did not go on to reoffend were nearly twice as likely as their white counterparts to have been labeled higher risk. The academic debate that followed turned up something surprising: common definitions of fairness in classification are mathematically incompatible when groups have different base rates. You can’t have equal false-positive rates, equal false-negative rates, and equal calibration all at once, unless the base rates are equal or the predictions are perfect. That isn’t a bug someone forgot to fix. It forces a choice about which kind of fairness matters most, and that choice is political, not technical.
Joy Buolamwini started her research after face-tracking software she was using at MIT couldn’t detect her face. Her “Gender Shades” study with Timnit Gebru (2018) (Buolamwini and Gebru 2018) tested commercial face-analysis systems from IBM, Microsoft, and Face++ and found error rates as high as 34.7% for darker-skinned women, against 0.8% for lighter-skinned men. Ruha Benjamin’s Race After Technology (Benjamin 2019) named “the New Jim Code”: supposedly neutral systems that reproduce older racial structures through stand-ins, with ZIP code standing in for race, “neighborhood reputation” for redlining, and “risk scores” for whoever the police already bother. If you train a classifier on historical arrest data, you’ve built a classifier that predicts who gets arrested, not who commits crimes, and you’ve laundered a pattern of past policing into a model that future policing will cite as evidence.
8.4 Computing beyond the West
Most computing tools were designed with a particular user in mind: an English-speaking adult with fast internet, a recent device, reliable electricity, and a credit card. That describes a small fraction of the world’s people. If the name form in this chapter’s opening felt like a small thing, it’s one instance of a much bigger pattern.
Unicode, the standard that lets computers represent text, now covers more than 150,000 characters across more than 150 scripts, but the quality of support varies enormously. Languages written right to left, or with complex combining marks or tonal diacritics, still trip over layout, font, and search bugs in current software. Languages spoken by millions of people but not used by any government are often effectively invisible to the machine-learning pipelines that will decide what “all languages” means for the next decade. Large language models make this especially stark: the share of their training data in any language tracks how much of the internet is written in it, which reflects existing wealth and power more than how many people speak it.
“Always online” is an American and European default, not a global one. For a large share of the world’s internet users, connections drop, bandwidth is expensive, and data plans are small. The habits of modern web development (huge JavaScript bundles, image-heavy pages, cloud-first apps that stop working when the cloud is out of reach) quietly penalize people paying by the megabyte. Nick Couldry and Ulises Mejias use the term data colonialism (Couldry and Mejias 2019) for the way data collected from people in the Global South is often processed, monetized, and turned into products by companies based in the Global North, with the revenue flowing to the companies and little returning to the communities whose data it was.
The practical habit is simple to state and hard to keep: whenever you see the words “the user,” “users,” or “everyone,” stop and ask which user. Where do they live, what language do they speak, what device and connection do they have, and which laws apply to them? If the honest answer is “a college student in California on campus wifi with a MacBook,” say so out loud, in your documentation and in your head.
8.7 Key laws every developer should know
Here’s a snag that surprises a lot of students: you can write code that runs perfectly and still break the law, and “the website let me do it” is not a defense. Computing doesn’t exist outside the law. Every platform, protocol, and data flow is shaped by statutes passed in particular years for particular reasons, and knowing a little of their history is part of being a literate practitioner, even if you never plan to become a lawyer.
The Computer Fraud and Abuse Act (CFAA, 1986) is the main US federal law on computer crime. Its fuzzy core makes it a crime to access a computer “without authorization” or to “exceed authorized access,” and three decades of court cases have stretched that language over everything from breaking into bank servers to scraping publicly visible web pages. Aaron Swartz used MIT’s network to download a large share of JSTOR’s archive of academic articles and was charged with wire fraud and eleven CFAA violations, carrying a combined maximum of 35 years in prison; he took his own life in 2013 while the case was pending. In 2021, the Supreme Court’s decision in Van Buren v. United States narrowed what “exceeds authorized access” means, but the gap between “the system let me do this” and “I was authorized to do this” is still where most legal trouble in computing lives. If you’re scraping for a project, read the site’s terms first, and if you’re unsure, ask your instructor before you run anything (Chapter 24 covers the polite way to collect data from the web).
Section 230 of the Communications Decency Act (1996) turns on one sentence, 26 words long: “No provider or user of an interactive computer service shall be treated as the publisher or speaker of any information provided by another information content provider.” Those 26 words are the legal foundation of the social internet. They mean that if you run a platform, you generally aren’t liable for what your users post the way a newspaper is liable for what it prints. Wikipedia, YouTube, Reddit, Yelp, and every comment section exist in their current form because of it. It’s also why platforms’ moderation decisions are at once enormously important and barely accountable: platforms write rules that work like speech law for hundreds of millions of people, without a democratic process or, usually, a meaningful appeal.
The Digital Millennium Copyright Act (DMCA, 1998) has two halves that matter to developers. The first is the notice-and-takedown safe harbor: a platform like YouTube can host uploads without being liable for infringement, as long as it removes material when a copyright holder complains. It’s also routinely abused with bogus takedown notices. The second is the anti-circumvention rule (Section 1201), which makes it illegal to get around a technical lock that controls access to a copyrighted work, including the software inside everyday devices. That’s why tinkering with the code in a car, a tractor, or a game console can be legally risky, why manufacturers can restrict independent repair (the fight behind the right to repair movement), and why security researchers who study medical devices and cars depend on exemptions that the Copyright Office reviews every three years.
The General Data Protection Regulation (GDPR, European Union, 2018) is arguably the most important privacy law in the world, because it has teeth. Its core ideas are that you need a documented legal basis to process personal data, that people have rights to see and delete their data, that breaches must be reported to regulators within 72 hours, and that fines can reach 4% of a company’s global annual revenue. It applies to anyone processing the data of people in the EU, wherever the company is based, which is why it reshaped how websites everywhere handle personal data. It’s also part of why so many sites, American ones included, started asking about cookies around 2018; the banners themselves come mostly from an older EU law, the ePrivacy Directive, but GDPR’s stricter consent rules and big fines set off the wave. The EU AI Act (2024) applies similar logic to AI systems, sorting them into risk tiers with different requirements, and its reach beyond Europe may make it a template for AI rules elsewhere.
The broader lesson: your day-to-day engineering choices are shaped by laws that were passed at specific moments, for specific reasons, and could have been written differently. When a product won’t do something you think it “should” (you can’t export your data, a search result disappears for EU users, a site blocks your scraper), there’s usually a specific law behind it, and looking it up is a normal part of the job.
8.8 A checklist for artifacts with politics
Here are the chapter’s questions in one place, to run through before you adopt, advocate for, or build a technology:
- Origin. Who built this? Who paid for it? Whose problem were they solving?
- Values. What values are encoded in the defaults? What would it mean to flip each default?
- Beneficiaries. Who benefits most from this working as designed? Who benefits least?
- Burden. Who pays the cost when it fails, or when it works correctly but hurts someone?
- Representation. Whose data is in the training set? Whose language is the interface in? Whose infrastructure does it assume?
- Labor. What human labor is hidden inside the automated parts? Where, and under what conditions?
- Material. What physical resources does it consume? Where does the waste go?
- Power. Who can change the rules? Who can appeal?
- Law. What statutes shape what this thing can and cannot do?
- History. What did the world look like before this technology? Could the losses have been avoided?
- Your role. When you use this tool, what are you endorsing? When you build on it, what are you carrying forward?
You won’t have good answers to all of these for any given technology, and that’s fine. The discipline is in asking them, and in noticing which ones you can’t answer, because those are the places where the politics of an artifact hide in plain sight.
8.9 Quick reference: timeline of key events
| Year | Event |
|---|---|
| 1843 | Ada Lovelace publishes what is often called the first algorithm intended for a machine. |
| 1890s–1940s | “Human computers,” mostly women, perform large-scale calculations at observatories, census bureaus, and wartime ballistics labs. |
| 1946 | ENIAC is unveiled to the public; its six original programmers, all women, go uncredited at the time. |
| 1947 | Grace Hopper’s team at Harvard tapes a moth from a Mark II relay into its log book, the canonical “computer bug.” |
| 1956 | AT&T consent decree keeps the Bell System out of the computer business, which later shapes how Unix is licensed. |
| 1969 | ARPANET’s first messages transmitted; DOJ files antitrust case against IBM. |
| 1980 | Langdon Winner publishes “Do Artifacts Have Politics?” in Daedalus. |
| 1983 | Richard Stallman launches the GNU Project. |
| 1984 | Peak of women’s share of US computer science bachelor’s degrees (~37%). |
| 1986 | Computer Fraud and Abuse Act (CFAA) passed. |
| 1991 | Linus Torvalds releases Linux. |
| 1996 | Section 230 of the Communications Decency Act passed; HIPAA passed. |
| 1997 | Latanya Sweeney re-identifies the Massachusetts governor from “anonymized” medical records. |
| 1998 | Digital Millennium Copyright Act (DMCA) passed. |
| 2013 | Aaron Swartz dies while awaiting CFAA trial; Edward Snowden’s disclosures published. |
| 2014 | Heartbleed bug found in OpenSSL. |
| 2016 | ProPublica’s “Machine Bias” report on COMPAS; Cambridge Analytica uses harvested Facebook data in the US presidential campaign (revealed in 2018). |
| 2018 | GDPR takes effect; Buolamwini and Gebru publish “Gender Shades.” |
| 2021 | Log4Shell vulnerability in Log4j; Van Buren narrows the CFAA. |
| 2022 | EU Digital Markets Act and Digital Services Act adopted; ChatGPT released. |
| 2024 | EU AI Act adopted; XZ Utils backdoor caught. |
- Langdon Winner, Do Artifacts Have Politics? (1980) — the essay that gives this chapter its title; short, durable, and the most-cited starting point for thinking about technology and values.
- Safiya Umoja Noble, Algorithms of Oppression — how commercial search reinforces racial and gender bias; a book-length companion to the Sweeney and COMPAS cases in this chapter.
- Cathy O’Neil, Weapons of Math Destruction — a readable, case-driven tour of opaque algorithms in hiring, credit, education, and policing; a good first book if you’re new to the field.
- Carissa Véliz, Privacy Is Power — argues that privacy is a collective good, not just a personal preference; a useful answer to “I have nothing to hide.”
- ACM, Code of Ethics and Professional Conduct — the computing profession’s own ethical framework for the kinds of decisions this chapter describes; worth rereading once a year.
- Distributed AI Research Institute (DAIR), dair-institute.org — Timnit Gebru’s research institute; a current source on AI labor, bias, and accountability.
- Data & Society, datasociety.net — an independent research institute on the social side of data-centric technology; its reports are short, current, and good for class discussion.