My father spent over forty years building things. Navy, then Raytheon, then the kinds of government programs that do not get named in public. He understands systems. He understands what it means to be on the side of the room that designs the architecture, rather than the side that has to live inside it.
Last week, he sat down with his phone, screenshots in hand, looking for a door that was not there.
He had read Google’s new privacy notice. He wanted to opt out of having his images, his audio, and his search activity fed into a generative AI training pipeline he never agreed to.
He did not find an opt-out. He found a help page that offered him tips on how to defend himself. The help page suggested he go to his account settings, then to data and privacy, then to personalization, then to a separate toggle for Search Services History, then back out to another menu for Personalized Recommendations, then make sure his Save Media subsetting was the way he wanted it, then check whether anything had changed since the last time he checked.
He is sixty-six years old. He spent his life building systems that worked. He understood, as he closed the app, that he had just been billed for an hour of his retirement in exchange for the privilege of withdrawing consent he never knowingly gave.
Two companies. Three signals. One week. One architecture.
On May 26, Google began rolling out a new framework for its Search Services. The framework consolidates Web and App Activity into two new settings called Search Services History and Personalized Recommendations. The framework now includes media: images, files, audio, and video. The framework’s default state is whatever your prior state was. “If these were on, these new settings are also on.” That is consent inherited from one architecture and applied to another.
The Electronic Privacy Information Center publicly advised users against engaging with Search Services History at all.
On June 8, Anthropic published an update to its consumer privacy policy, effective July 8. The previous policy committed Anthropic to protecting user data except when a court compelled disclosure. The new policy commits Anthropic to protecting user data except when Anthropic, in its own good-faith judgment, decides otherwise. The threshold for releasing user conversations to law enforcement has moved from external to internal. The policy also introduces a new category called Verification Data, under which Anthropic may request a user’s age or government identification. These changes apply to Free, Pro, and Max accounts. Enterprise, Team, and API accounts are exempt.
On June 9, Anthropic released Claude Fable 5, the most capable consumer model the company had ever shipped. On June 12, Amazon CEO Andy Jassy informed United States officials that Amazon researchers had jailbroken Fable 5 into producing content useful for cyberattacks. On June 13, the Trump administration issued an emergency export-control directive ordering Anthropic to block all foreign nationals from accessing Fable 5 and Mythos 5. Anthropic disabled both models for all customers worldwide to comply. The user’s access to the tool was revoked within three days through a route no user had standing to use.
Two companies. Three signals. One architecture.
The mechanism has a name.
The architecture is not opt-out. Opt-out is the brand the architecture wears in public.
The mechanism is exhaustion.
A system that places the burden of opting out on the user and then bills the user’s time and labor as the price of opting out does not honor consent. It is simulating honoring consent. The economic logic is that most users will not pay the cost. The economic logic is correct. The cost is the point.
This is not a Google problem. It is not an Anthropic problem. It is the operating architecture of the consumer AI industry in June 2026. The user has become the variable the system tunes around. The user’s prior consent is inherited forward across architectures the user has not seen. The user’s privacy is protected except when the company decides otherwise. The user’s access to the tool exists until a government request routed through a competitor revokes it. You appear in the system as a slot that can be filled, drained, or vacated, depending on what serves the operator’s posture this week.
Most consumer AI products score between 11 and 19 out of 94 on the rubric this publication uses to assess sovereignty. The gap between what teams think they have built and what the rubric reveals is the same gap that sent my father looking for a door.
What people can do.
Three layers, three time horizons.
Today, ten minutes. Go to account.google.com, then Data and privacy, then Personalization settings. Turn off Search Services History. Turn off Personalized Recommendations in Search services. Do this for each of your Google accounts if you have more than one. If you use Claude consumer plans and you do not want your conversations used for training, the deadline this fall is the gate. Your Anthropic privacy settings hold the toggle. These are not solutions. These are the minimum self-defense requirements the current architecture demands of you.
This month, four questions. Before you sign up for any new AI product, ask: Where is the refusal? Where is the opt-out? How many clicks does it take? Who decides when my data leaves the system: me, a court, or the company? If you cannot answer those four questions in under sixty seconds, the product has failed the floor of a sovereignty check. Walk away, or accept what you are accepting knowingly. The point is the knowing.
This year, your voice. The people working on this at the policy level are real, and they need backing. The Electronic Privacy Information Center is one. The European Data Protection Supervisor is another. The EU AI Act has Article 5 provisions on manipulative design that the industry has been quietly lobbying to soften. Pay attention to who is doing that lobbying. Pay attention to which legislators name the architecture by its real name and which legislators name it by the brand the architecture wears.
None of this fixes the architecture. The architecture is downstream of an industry that decided several years ago that the user is the variable it can adjust. The architecture changes when the cost of adjusting the user exceeds the cost of honoring the user. Right now, those costs are not in the right relation. Your awareness of the architecture is one of the inputs that changes the ratio.
What Evoked is doing.
This is what an AI-sovereignty publisher owes its readers in a week like this one.
We are scoring the three architectures. Google’s new Search Services framework, Anthropic’s June 8 privacy policy, and the Fable shutdown architecture will be assessed through the same forty-seven-point Sovereignty Assessment we apply to any product. The methodology will be disclosed. The publicly available material will be cited. The scores will be timestamped. Readers will be able to re-derive the rubric and apply it to their own AI stack.
We are doing this because writing an article about architecture is not enough. Naming the mechanism is the floor. Measuring against the mechanism is the work. The Sovereignty Assessment is the work we have already built. The three architectures of this week are the work we owe the reader.
The scoring will be published as a follow-up piece tomorrow.
The question that turns inward.
Kohlberg’s sixth level of moral development is not a listicle. It is a frame. The frame is that the question we should ask of every system is not whether it meets industry standards, but whether we would build it this way today, knowing what we know about what people deserve. The frame applies to Google. The frame applies to Anthropic. The frame, and this is the courageous move, applies to Evoked.
We hold ourselves to it. We publish the rubric we use to score. We publish the Refusal Specification that our agents operate under. We measure ourselves the way we ask the industry to be measured. When we fail, we want the failure to be visible.
That is what makes Level 6 different from Level 4. Level 4 says industry standard. Level 6 says the standard we would defend in front of the future. The future includes my father. The future includes my nephew. The future includes everyone who spent an hour of their retirement, their evening, or their workday looking for a door that was not there. They were not failing. They were reading the architecture correctly with the only sense they had: the felt sense that something was wrong.
From the Evoked specifications working group, on behalf of every reader who knew something was wrong.