Qualified audiences and quality content, monetised without cookies or shared identity.
Publishers hold the two assets the AI economy wants most: high-quality content and qualified, consented audiences. The decade spent renting both to third-party cookies and shared identity graphs is over, Google kept the cookie and retired its own replacement, and the publishers growing today are subscription-first houses monetising logged-in, first-party relationships through aggregate audiences and privacy-enhancing technologies. The craft is doing it without handing either asset away.
The shifts our research is tracking, named, current, cited.
The New York Times' BrandMatch, generative-AI targeting built purely on first-party reader data, lifted click-through roughly 30% on average and drew 150+ advertisers in its first year, with most returning for repeat campaigns. Privacy-preserving is out-performing the surveillance stack it replaced.
AdMonsters / NYT →Google kept third-party cookies in April 2025, then retired most of Privacy Sandbox that October for 'low levels of adoption.' There is no platform-provided replacement coming: publisher first-party data, aggregate cohorts, contextual, and PET-based collaboration are the durable stack.
Google Privacy Sandbox →Pew found users click a result on just 8% of searches with an AI summary versus 15% without, while reported licensing deals run near 1% of a major publisher's revenue. The strategic answer is referral quality and owned AI experiences, Le Monde reports ChatGPT referrals convert 20 times better than Facebook.
Pew Research Center →Utiq, backed by Deutsche Telekom, Orange, Telefónica, and Vodafone, runs consent-based identity for 300+ European publishers under an explicit digital-sovereignty banner; Ozone unites 75 media companies behind editorially governed inventory; Swiss confidential-computing clean rooms keep publisher data in Europe. The rails exist.
Utiq →In media, the qualified audience is the asset: first-party, consented, sold in aggregate, and never surrendered to a shared identity graph, monetised across advertising, subscriptions, and AI.
The reversal settled the argument. Google kept the third-party cookie and then retired most of Privacy Sandbox for lack of adoption, so there is no platform-provided future to wait for: what endures is the publisher's own first-party data, aggregate cohorts, contextual signals, and privacy-enhancing technologies. The New York Times showed what that stack earns: it dropped third-party data in 2020, built proprietary audience segments on its logged-in readership, and its AI-assisted first-party targeting now lifts click-through around 30% while digital advertising grows over 30% a year, on a foundation of 13 million digital subscribers.
The AI era squeezes and rewards the same asset. Search summaries halve the clicks that reach you, and licensing cheques are small next to that risk, but AI referrals convert dramatically better than social ever did, and publishers who build AI experiences on their own archive keep the reader, the data, and the relationship. Monetisation becomes a portfolio: dynamic paywalls and freemium tuned by propensity models, first-party advertising that out-performs the old stack, selective licensing on your terms, and owned AI products, each running on the same consented reader data.
We build the sovereign audience and monetisation stack: consent-clean, first-party collection; aggregate audiences and clean-room collaboration instead of shared identity graphs; paywall, propensity, and personalisation models on sovereign inference; and reader-facing AI grounded in your own journalism. Your content is the training data everyone wants, and your audience is the asset nobody else can have. Monetise both without handing either away.
| Workload | Placement | Rationale |
|---|---|---|
| First-party audience segments & contextual targeting | Sovereign | Built on logged-in reader data; sold as aggregate cohorts, never as identities. |
| Dynamic paywalls & subscription propensity | Sovereign | Reader behaviour decides the offer; the model runs where the readers' data lives. |
| Advertiser data collaboration | Hybrid | PET-based clean rooms: matched in aggregate, never shared in the raw. |
| Newsroom formats & creative production | Frontier | Drafting, formats, and research on public material, at frontier speed. |
Before any platform decision, one question settles the rest: how much of what your organisation knows can be written down precisely enough for a machine to act on it, and who ends up owning that writing. We run a short engagement to answer it, and it produces working artefacts rather than a report.
Two artefacts come out of this. An operating ontology, the nouns: the entities, relationships, and states your business actually runs on, described once and precisely. And agentic skills, the verbs: the procedures, thresholds, and judgments your best people apply, written down, versioned, and testable instead of retold.
A placement map addressed to the CTO or CIO office: what runs on your compute, what is bought, what is rented, who holds the keys, and what each costs. One test cuts through most of the debate. If a supplier vanished on a Friday, what stops working on Monday, and how long would it take you to replace it?
Where an open-weight model fine-tuned or adapted on your own corpus beats a frontier call, where a small purpose-built model for one narrow task beats both, and where the frontier still earns its fee. Geographic sovereignty falls out of that answer rather than having to be argued for on its own.
Your archive is a corpus no model has legitimately trained on. Adapted on it in-house, it becomes a working asset instead of a licensing negotiation you are losing.
This is a CTO and CIO office engagement, not a procurement exercise. Your own people have to end up running it, because the moment the encoding is delegated, the thing being encoded quietly stops being yours.
Palantir calls this layer an ontology, and the idea is right: a governed model of your objects, links, and actions that agents can act on. It lives inside their platform. 8090 will design, build, host, and maintain the software around it for you. Both are serious, and both leave the same question open. At the end of it, who owns the layer that holds your judgment? We build the same artefacts in open formats, on compute you control, and hand your CTO the keys.
The same four layers we ship in legal, instantiated for a publisher, whose two real assets are a body of work and a direct relationship with a reader, and who is being asked to hand over both.
An editorial assistant grounded in your own archive rather than the open web, first-party audience decisioning for subscription and retention, and a rights and licensing workbench that knows what you are actually allowed to sell.
Style guide, sourcing and verification standards, corrections policy, and rights terms compiled into skills, so an assistant that touches copy is bound by the same standards as the desk, and its output can be checked against them.
The archive and the reader graph stay on sovereign compute, by architecture. Frontier capability is used for bounded, non-proprietary tasks, and every use is logged, which is what makes a licensing conversation with a model provider a negotiation rather than a surrender.
In the publisher's own estate, on a managed isolated instance, or on hardware in the building for archive work that must not be copied anywhere at all.
The application layer here is built for you, not bought. The pattern is the one we already ship, as a product, in legal.
The same software in every posture, so a team can start hosted and end up air-gapped without a migration project. You move along the ladder when you decide to, not when a contract renews.
Your stack stood up on our infrastructure in days and pointed at real work, so it is judged on your matters rather than on a demo. The pilot fee credits against the hardware when you migrate.
Teams that want proof before capital expenditure.
The open-source cores installed on a machine you own, by a script anyone can read first. No account with us, no telemetry, no phone-home. Code flows one way, from us to you, and only when you ask for it.
Small teams, and anyone who wants to inspect the source before trusting it.
An isolated instance per client on sovereign infrastructure, European by default, run, patched, and monitored by us, with the security and backup credentials in your hands rather than ours.
Organisations without an infrastructure team to spare.
Dedicated AI hardware inside your building, with the applications and the open-weight models you choose installed and tested before it ships. It runs with the network unplugged, and it keeps working whatever happens to us.
For a publisher the appliance is how the archive becomes a working corpus without becoming a training set.
Work that cannot leave the building, ever.
Not promises. Consequences of the architecture: your keys and your data are generated on your machine and stay there, and nothing calls home.
We send a sector-specific brief with workload-by-workload placement guidance and a reference architecture for sovereign deployment.