Chapter 1
When Technology Becomes Both Tool and Weapon
In the digital age, few books have captured the complex relationship between technology and society as powerfully as "Tools and Weapons." The work has earned praise from leaders across the political spectrum, from Barack Obama to Condoleezza Rice, for its nuanced exploration of how digital technologies simultaneously empower and endanger us. Brad Smith, drawing from his unique position as Microsoft's president, offers readers an insider's view of the tech industry's most pressing challenges. What makes this book particularly compelling is Smith's willingness to challenge his own industry-a rarity among tech executives. Having witnessed Microsoft's transformation from antitrust villain to respected corporate citizen, Smith brings historical perspective to contemporary debates about technology's role in society. When Bill Gates first read the manuscript, he reportedly stayed up all night, captivated by Smith's ability to translate complex technological dilemmas into accessible narratives that illuminate the profound choices we face as technology reshapes our world.
Chapter 2
The Cloud: Our Digital Fortress
Civilization has always depended on data, but today's digital information plays an unprecedented role in our lives-growing steadily regardless of economic conditions. Unlike oil, data is infinitely renewable, with this decade ending with 25 times more digital data than when it began. The "cloud" isn't some ethereal entity but rather a network of mammoth data centers-modern fortresses protecting our digital lives.
In Quincy, Washington, Microsoft's Columbia Data Center spans two sprawling campuses with twenty buildings covering two million square feet. Each building houses hundreds of thousands of servers backed by massive generators. These facilities represent the physical infrastructure of our digital existence-bulletproof doors, fireproof walls, airport-style security checkpoints, and armed guards protecting cavernous rooms filled with endless rows of servers extending beyond sight. Within these walls, your personal data exists as encrypted information on just a tiny sliver of a hard drive.
Microsoft alone operates data centers in over 100 locations across more than 20 countries, supporting a billion customers worldwide. The scale is staggering-unlike the early days when Bill Gates and Paul Allen could start Microsoft with minimal capital, today's cloud infrastructure requires investments in the hundreds of millions.
These massive data centers sit at the heart of our digital era, raising profound questions about the balance between safety, convenience, and privacy. Any tool can be used for good or ill, and technology has become both a powerful tool and formidable weapon. This reality has ushered in a new age of anxiety, particularly in democracies. The tech sector must accept greater responsibility for the future, while democratic governments need to move faster to catch up with technology's relentless pace.
What's most striking about this transformation is how quickly we've entrusted our most intimate information to these digital repositories. Have we fully considered the implications of storing our memories, communications, and personal data in these remote facilities? The cloud has fundamentally changed our relationship with information-making it more accessible but potentially more vulnerable.
Chapter 3
Surveillance: When Privacy Meets National Security
On June 6, 2013, Microsoft faced a crisis when the Guardian published a bombshell about "PRISM," an NSA surveillance program allegedly accessing data directly from major tech companies. Despite Microsoft's insistence that they only disclosed customer data in response to specific legal orders, the revelation that Edward Snowden had leaked over a million classified NSA documents sparked global outrage about government surveillance.
The privacy rights at stake trace back centuries. In the 1760s, John Wilkes challenged British authorities over broad search warrants, establishing that "every Englishman's house is his castle." This principle inspired American colonists like James Otis Jr., who fought against general warrants, eventually leading to the Fourth Amendment's requirement for "probable cause" before searches. Courts have consistently protected private information, establishing a "reasonable expectation of privacy" standard that has guided American jurisprudence for generations.
After 9/11, the NSA sought voluntary partnerships with tech companies to obtain user data outside legal processes. Microsoft wrestled with this request but ultimately concluded they couldn't surrender customer data without proper legal channels. Throughout American history, national crises from the 1798 "quasi war" with France to Japanese internment during WWII have led to civil liberties being sacrificed, only to be questioned later when the immediate danger passed.
The Snowden revelations highlighted a fundamental tension: governments serve constituents in defined territories, while tech companies operate globally with customers everywhere. The cloud transformed tech companies into institutions resembling banks, with people storing their most personal information with them. This new relationship meant tech companies became too important to be left unregulated, but unlike 1930s banks, they operate globally, complicating regulation.
When customer discontent grew in 2013, Microsoft and Google took the unprecedented step of suing the US government to gain the right to share information about national security orders. The situation worsened when the Washington Post revealed the NSA was surreptitiously tapping into undersea fiber-optic cables to copy data from tech companies' networks. The industry responded with anger and quickly implemented strong encryption for data moving between data centers.
Imagine discovering that someone had been secretly opening your mail for years-reading your most personal communications without your knowledge. This was essentially what tech companies felt upon learning about these surveillance programs. The violation of trust was profound, and rebuilding it would require fundamental changes in how governments approach digital privacy.
Chapter 4
Balancing Transparency and Security
As Microsoft developed principles for cloud computing, they focused on four core commitments: privacy, security, compliance, and transparency. The real test came when putting these principles into practice, particularly regarding transparency.
Microsoft publicly committed in 2013 to notify business customers when government agencies requested their data. When the FBI served a national security letter seeking enterprise customer data with a gag order, Microsoft refused and took the case to court, ultimately causing the FBI to withdraw the letter.
In 2016, when an assistant US attorney persisted with a sealed warrant and permanent gag order, Brad Smith declared, "I'd rather be a loser than a liar" when litigation teams worried about fighting a losing battle. Though they lost the specific case, they preserved their ability to be transparent with customers.
Microsoft then took a broader approach by suing the US government, challenging the routine use of indefinite gag orders as unconstitutional. After building a coalition of 80 supporters across tech, business, media and former government officials, Judge Robart allowed their First Amendment claim to proceed. This pressure led the Justice Department to implement new policies limiting gag orders and directing prosecutors to approach enterprises directly before cloud providers-achieving the balance Microsoft sought between privacy protection and public safety.
What's remarkable about this story is how it demonstrates the evolution of tech companies from purely business entities to institutions with broader societal responsibilities. When does a company have not just the right but the obligation to challenge government secrecy? These questions reflect the growing recognition that in the digital age, corporate decisions about data access and transparency have profound implications for civil liberties.
Chapter 5
Privacy as a Fundamental Human Right
The CLOUD Act created authority for modern international agreements to replace unilateral efforts, enabling law enforcement agencies to access data across borders with faster procedures while protecting privacy and human rights. Though imperfect, it represented the culmination of four years of work.
Getting the legislation passed required attaching it to a budget bill, which presented significant challenges. With support from Senator Lindsey Graham, Senate Minority Leader Chuck Schumer, Speaker Paul Ryan, and Minority Leader Nancy Pelosi, the CLOUD Act was included in an omnibus budget bill signed by President Trump on March 23, 2018-just weeks after the Supreme Court hearing.
The rapid passage created mixed feelings at Microsoft. While pleased with the result, they recognized it contained compromises. The speed of passage left them unprepared to explain the complex legislation to concerned customers, privacy groups, and governments worldwide, requiring a global educational effort.
As US Assistant Attorney General Richard Downing noted on the law's first anniversary, the CLOUD Act offered "not simply a solution to the challenge of this moment, but also an aspirational kind of solution" aimed at "fostering a community of like-minded, rights-respecting countries." However, it was merely a foundation-implementing it through thoughtful international agreements would require years of additional work to balance law enforcement needs, privacy rights, and national sovereignty.
The challenge of balancing these competing interests reflects a broader question: in a world where data flows freely across borders, how do we respect both national sovereignty and universal human rights? The CLOUD Act represents an attempt to answer this question, but the conversation is far from over. As technology continues to evolve, so too must our legal frameworks for protecting privacy while enabling legitimate law enforcement access.
Chapter 6
Cybersecurity: The New Global Battlefield
When the WannaCry ransomware attack crippled computer systems worldwide in 2017, it marked a turning point in cybersecurity. The attack infected over 200,000 computers across 150 countries, shutting down hospitals, banks, and businesses. Microsoft took unprecedented action by publicly attributing the attack to North Korea and working with Facebook to dismantle part of the hacking group's infrastructure.
The White House announced it would publicly attribute WannaCry to North Korea on December 19. Microsoft decided they would go public with their actions against North Korea's hacking group even if they had to stand alone, believing deterrence required demonstrating capacity to respond. Fortunately, Facebook joined them, and the next morning, White House Homeland Security Advisor Bossert announced that the United States, along with Australia, Canada, Japan, New Zealand, and the United Kingdom, were publicly attributing the attack to North Korea.
This unprecedented collaboration between governments and tech companies accomplished more than any single entity could have alone-not a complete victory, but a new beginning in the fight against cybersecurity threats. It demonstrated how the traditional boundaries between public and private sectors are blurring in cyberspace, where attacks can target critical infrastructure regardless of whether it's government-owned or privately operated.
Consider how different this is from traditional warfare. In conventional conflicts, militaries defend national borders and citizens. In cyberspace, private companies often find themselves on the front lines, defending not just their own systems but critical infrastructure that entire societies depend upon. This new reality requires rethinking how we approach security in the digital age-recognizing that effective defense requires collaboration across traditional boundaries.
Chapter 7
Defending Democracy in the Digital Age
In July 2016, Microsoft's Digital Crimes Unit discovered Russian hackers using spoofed Microsoft domains to target political officials. The DCU developed an innovative legal strategy using trademark infringement to seize hacker domains and redirect infected computers to a secure "sinkhole."
Microsoft expanded this tactic, seizing 90 domains across 14 court cases and developing AI to predict future hacker domain names. They discovered Russian group Strontium targeting entities in over 90 countries, including the 2018 U.S. midterm elections where they created six websites targeting the U.S. Senate, International Republican Institute, and the conservative Hudson Institute.
After securing court orders to seize these domains, Microsoft made the unprecedented decision to explicitly identify Russia as the source of the attacks, a move soon followed by Facebook and Google. This public stance earned a subtle warning from the Russian government, delivered through a Microsoft employee seeking a visa.
Beyond email hacking, Microsoft recognized the even greater threat of potential voting machine tampering. In response, they launched ElectionGuard, an open-source encrypted voting system that combines electronic voting with paper ballots and gives voters personal tracking numbers to verify their votes remain accurately recorded.
As authoritarian regimes experiment with increasingly sophisticated disinformation campaigns, democratic governments and industry must develop unified responses to protect democracy, just as they once worked together to win a world war.
What's at stake here isn't just election outcomes but the integrity of democratic processes themselves. When citizens lose faith in elections, democracy itself is threatened. The digital age has created new vulnerabilities in our democratic systems-vulnerabilities that require innovative solutions combining technological safeguards with greater transparency and public awareness.
Chapter 8
Social Media: The Double-Edged Sword
In the wake of the Christchurch attack, where a terrorist livestreamed his massacre of 51 people at two mosques, Australia quickly passed a law requiring social media platforms to "expeditiously" remove "abhorrent violent material" or face criminal penalties including executive imprisonment and massive fines. This marked a clear global shift toward replacing online services' legal immunity with new regulatory models.
The challenge lies in finding precise solutions that don't break social media's fundamental structure. Pre-publication editorial review like traditional media would be impossible at scale. Senator Warner proposed targeted approaches like requiring platforms to prevent re-uploading of illegal content once identified, while Britain suggested a "statutory duty of care" overseen by independent regulators. These complementary approaches combine specific content restrictions with greater transparency about information sources-focusing not on judging truth but ensuring users know whether content comes from humans or bots.
Private initiatives like NewsGuard, created by conservative Gordon Crovitz and liberal Steven Brill, offer "nutrition labels" for media through browser plug-ins that flag trustworthy versus problematic sources. Though facing challenges scaling internationally, such non-governmental efforts can move faster than legislation.
Foreign interference in democracy dates back to America's earliest days, when French ambassador Edmond Charles Genet attempted to sway the young republic toward supporting France in 1793, creating bitter divisions between Jefferson's and Hamilton's factions. Washington's cabinet ultimately united to demand Genet's recall, demonstrating how foreign interference requires setting aside partisan differences to respond effectively. In his 1796 farewell address, Washington warned that "foreign influence is one of the most baneful foes of republican government."
While America has used information technology to promote democracy abroad through outlets like Radio Free Europe, today's digital landscape creates an asymmetric risk where authoritarian governments can exploit democracies' openness. Addressing this challenge requires stakeholders across political parties, tech companies, and governments worldwide to work together, just as in Washington's time.
The social media dilemma reflects a broader tension in democratic societies-how to preserve free expression while preventing harmful content and manipulation. This tension isn't new, but digital platforms have amplified both the benefits and risks of open communication. Finding the right balance requires recognizing that absolute freedom without responsibility isn't sustainable, while excessive control undermines the very democratic values we seek to protect.
Chapter 9
Digital Diplomacy: When Tech Companies Become Global Powers
When Casper Klynge visited Microsoft's Redmond campus in 2018, he wasn't your typical ambassador. As Denmark's first-ever tech ambassador, he leads a twenty-person "embassy" spanning three continents, connecting the Danish government with tech companies worldwide. Danish Foreign Minister Anders Samuelsen declared the position "a world first" and necessary because tech companies "have become a type of new nation."
Denmark's move followed Britain's 2014 creation of a "special envoy to US technology companies" under Prime Minister David Cameron, with other governments from Australia to France following suit. This diplomatic shift reflects technology's increasingly global role in foreign policy.
While corporations have influenced economies since the Gilded Age railroads (America's first big business that transformed commerce and law), today's digital technology companies operate on a fundamentally more global scale and increasingly find themselves at the center of national security issues. By 2016, Microsoft had adopted the mantra "There's no national security without cybersecurity," a recognition shared by companies like Siemens AG, which predicted cybersecurity would become "the most important security issue of the future."
In early 2017, Microsoft proposed a "Digital Geneva Convention" to protect civilians from cyberattacks during peacetime, inspired by how the 1949 Fourth Geneva Convention protected civilians during war. This initiative aimed to strengthen international rules against attacks targeting private citizens, institutions, or critical infrastructure, expand bans on hacking intellectual property, and create an independent organization to investigate and attribute nation-state attacks.
The Cold War offers valuable lessons for today's cybersecurity challenges. President Reagan's 1983 viewing of "WarGames" sparked federal cybersecurity initiatives and led to the Computer Fraud and Abuse Act. Arms control history provides important insights: it's often more realistic to limit weapons or control their use than ban them entirely. As one expert noted, "If a weapon brings decisive advantages on the battlefield, then a ban is unlikely to work." This principle has guided international legal experts defining norms for cyberweapons.
Microsoft moved from concept to action by creating the Cybersecurity Tech Accord, committing signatories to protect users everywhere and oppose attacks on innocent citizens. Despite challenges recruiting some major tech companies, they launched in April 2018 with thirty-four companies, growing to over one hundred from twenty countries by May 2019. Similar initiatives emerged globally, gaining momentum at President Macron's Paris Peace Forum, where the "Paris Call for Trust and Security in Cyberspace" secured support from 51 governments and 370 initial signatories-though notably without U.S. government backing.
After the Christchurch terrorist attack in March 2019, Prime Minister Jacinda Ardern and her team quickly applied the Paris Call model to prevent terrorists from using the internet to broadcast violence. Through intensive collaboration, tech companies developed nine recommendations, including service-specific improvements and industry-wide initiatives. Just two months after the attack, on May 15, Ardern and Macron launched the "Christchurch Call to Action" with eight other government leaders, demonstrating what Klynge calls "techplomacy"-a multi-stakeholder approach bringing governments, civil society, and tech companies together.
The Paris and Christchurch calls represent innovative approaches to digital diplomacy, with companies playing crucial roles alongside governments-a necessity given that cyberspace is largely privately owned and operated. This corporate involvement distinguishes these initiatives from traditional humanitarian efforts. Another innovation is the engagement of the broader public through initiatives like "Digital Peace Now," which gathered over 100,000 signatures worldwide.
History's failures provide sobering context. At the League of Nations in the 1930s, diplomatic efforts to constrain arms buildups collapsed when America declined leadership and Hitler withdrew Germany from negotiations. Albert Einstein warned that technological advances without corresponding organizational development made technology "as dangerous as a razor in the hands of a three-year-old child." That failure led to global devastation. Today, as cyberweapons and AI grow more powerful, we face similar challenges.
Chapter 10
The Privacy Revolution: From Government to Corporate Surveillance
In December 2013, as tech leaders urged President Obama to reform government surveillance, he prophetically warned that "the guns will turn"-suggesting that the privacy demands being made of government would eventually be directed at tech companies holding unprecedented amounts of personal data.
In Europe, this shift had already occurred. The EU adopted a strong data privacy directive in 1995, followed by the even more comprehensive General Data Protection Regulation in 2016. Even as the UK voted to leave the EU, it recognized the economic necessity of maintaining compatible data privacy rules.
The United States, however, remained an outlier, lacking comprehensive national privacy legislation despite calls from some industry voices, including Brad Smith's own 2005 speech advocating for such laws. Most tech companies either ignored or opposed the idea, and Congress showed little interest.
Change came through the efforts of Max Schrems, a law student from Vienna whose interest in privacy began during a high school exchange in Florida, where he was shocked by the extensive student tracking systems. Years later, while studying at Santa Clara University, a Facebook lawyer's dismissive attitude toward European privacy laws-claiming they weren't enforced and companies could "do whatever you want"-spurred Schrems to action.
After receiving a CD containing 1,200 pages of his personal Facebook data (including hundreds of "deleted" posts), Schrems filed complaints with Ireland's Data Protection Commissioner, challenging the International Safe Harbor Privacy Principles that allowed European data to flow to American companies. Despite initial setbacks and a six-hour attempt by Facebook executives to dissuade him, Schrems persisted until his case reached the European Court of Justice.
The Safe Harbor principles, established in 2000, were the foundation of trans-Atlantic data flows. They allowed companies to self-certify compliance with seven privacy principles endorsed by the US Department of Commerce, enabling the European Commission to deem American privacy protections "adequate" despite the lack of comprehensive federal legislation.
By 2015, over 4,000 companies relied on Safe Harbor to deliver $240 billion in annual digital services. The arrangement supported 3.8 million European employees of American companies who needed data transfers for everything from paychecks to health benefits. In total, American companies' European sales reached $2.9 trillion, most requiring digital data movement.
On October 6, 2015, the European Court of Justice agreed with Schrems, invalidating the Safe Harbor framework and empowering national data protection authorities to make their own assessments of data transfers. The ruling sent shockwaves through the tech industry. While companies had backup legal mechanisms to continue data flows, the decision was "sweepingly broad" enough to potentially threaten any data transfer method.
The General Data Protection Regulation (GDPR) quickly became the tech sector's focus. Unlike most regulations that merely prohibit certain practices, GDPR created a privacy bill of rights requiring companies to build new business processes. Consumers gained rights to access, correct, delete, and transfer their personal data-making GDPR a "Magna Carta for data" and representing Europe's second wave of privacy protection.
For Microsoft, GDPR's impact was immense. With over 200 products and services using different data architectures, the company needed to create a unified information system spanning all services from Office 365 to Xbox Live. This required moving 300 engineers to work full-time on the project for 18 months, eventually involving thousands of staff and hundreds of millions of dollars in investment.
Once Microsoft committed to building GDPR-compliant architecture, creating different systems for other regions made little sense. The costs and engineering complexity of maintaining multiple systems were simply too great. When meeting with Canadian Prime Minister Justin Trudeau in 2018, Satya Nadella encouraged him to simply adopt GDPR provisions rather than create Canada-specific privacy laws.
In March 2018, the privacy equivalent of Three Mile Island arrived with the Cambridge Analytica scandal. Facebook users learned their personal data had been harvested to target US voters with pro-Trump advertisements. With no real defense, Mark Zuckerberg could only apologize. Within weeks, Washington's mood shifted from dismissing regulation to accepting its inevitability.
That answer would come from Alastair Mactaggart, a San Francisco Bay Area real estate developer who, after hosting a Google engineer for dinner in 2015, was alarmed to learn how much data tech companies collected. Mactaggart embarked on a two-year, $3 million crusade to protect personal data, driven by the realization that in the age of "commercial surveillance," our online activities reveal more about us than we want to share.
Using California's ballot initiative process, Mactaggart gathered more than double the signatures needed with polling showing 80% initial voter support. Ultimately, negotiations led to the California Consumer Privacy Act of 2018, the strongest privacy law in US history, giving residents rights to know what data companies collect, refuse its sale, and hold firms accountable.
The national impact was immediate-even previous opponents began lobbying Congress for a national privacy law to preempt a patchwork of state regulations. As Mactaggart observed, "This isn't over. We'll be talking about technology and privacy for the next hundred years. Just like we do with antitrust law more than a century after the Standard Oil case."
Chapter 11
Bridging the Digital Divide: Broadband as Essential Infrastructure
In rural America, the digital divide isn't just inconvenient-it's dangerous and economically devastating. Microsoft's Airband Initiative uses a hybrid technology approach combining TV white spaces with other technologies to reduce infrastructure costs by 80% compared to fiber-alone solutions. This approach could connect approximately 80% of the underserved rural population, particularly in areas with 2-200 people per square mile.
Rather than seeking profit, Microsoft is reinvesting revenue from telecommunications partnerships because the entire tech sector benefits when more people connect to the cloud. They're also developing applications like FarmBeats, which uses TV white spaces to connect sensors across farmland for precision agriculture.
Closing the broadband gap requires both private innovation and public sector involvement through regulatory certainty (ensuring TV white spaces spectrum remains available) and targeted funding. We need a national crusade similar to the Rural Electrification Administration of the 1930s, which brought electricity to rural America through cooperatives and low-interest loans. The REA's "electric circus" demonstrations, led by Louisan Mamer, showed rural Americans the transformative power of electricity. Within ten years, the rural electricity gap shrank by 80%, despite economic hardship and World War II.
In Ferry County, Washington, Microsoft has partnered with Declaration Networks Group to deliver broadband to 47,000 people using TV white spaces technology. As one Republic Brewing Company owner said: "Once people have better access to the internet, they'll realize all the different things they can do with their lives." This challenge must motivate our entire nation in the years ahead.
The broadband gap reflects a broader pattern of technological inequality-where the benefits of innovation flow disproportionately to those who already have access and resources. Just as electricity transformed rural America in the 20th century, broadband access has become essential infrastructure for participation in the 21st century economy. Without it, entire communities risk being left behind as economic opportunity increasingly depends on digital connectivity.