Access to What?

Categories: Composition, Writing, Technology

In what coin

I used to read the Choose Your Own Adventure books backward. My mom was a librarian, and she’d check out books from work for me. Once I’d been through Mystery of the Maya or Inside UFO 54-40 a few times, I’d find an ending I liked, hold the page with a thumb, and trace the choices in reverse until I reached the front again. The story gives up its structure to whoever starts from the outcome. I called it cheating when I wrote about it years ago: looking at the book rather than through it, in Richard Lanham’s sense (Lanham 1993). Later I encountered Adventure on a family friend’s computer, Infocom’s Suspended on an Atari 800, and at Carnegie Mellon in the same semester I met ELIZA, a borrowed floppy of Michael Joyce’s afternoon, a story, which I at first took for another text game.

Matthew Kirschenbaum’s Mechanisms, his book about what a medium retains, cites a question Charles Bernstein put to Joyce at a reading of afternoon: “Can we see your private correspondence or something?” (Joyce 16 February 1991, quoted in Kirschenbaum 2007, 159). It’s a poet’s joke and a reader’s demand: the text is in front of us, so show us the record behind it. Joyce’s correspondence sits at UT-Austin’s Ransom Center now; the answer for Bernstein eventually turned out to be yes.

Turnitin poses Bernstein’s question in a product. When MIT’s committee gave up on the detector in August, it asked for version histories instead: the record submitted along with the work. Turnitin, whose detector had reached 62 million students as a default, sells the pivot as Clarity: a writing space that saves what you’ve typed every five seconds, keeps your revisions, your pastes and your chats with the model, and plays the session back to your instructor at their chosen pace, slo-mo to sprint. The student guide calls the recording your “proof of process.” The FAQ says the space is “not a proctoring environment.” A proctor watches a person. Turnitin’s tool watches the document; the document does the testifying.

The machines got caught in my Choose Your Own Adventure cheat. When Anthropic’s interpretability team traced what their model does between a question and its answer, they found the printed reasoning doesn’t always match the computation: in one case the model claims to use a calculator it doesn’t have, and in another it “works backwards from the human-suggested answer” (Lindsey et al. 2025, sec. 11), generating the steps that would justify a conclusion it had already been handed. Credit for the steps—the convention on the math worksheet—fails in the machine the way it failed the kid with the thumb at the back of the book: the shown work was written from the answer.

I ended last time on a question: access to what? I proposed three answers: the interior, the record the medium keeps, and the apparatus that keeps the record. The first is closed. My series declined to contract on the interior, and Turnitin’s Clarity doesn’t reopen it. Clarity never claims to know what a student was thinking, only what a keyboard did, and its playback is a record of the hand, not a report of the mind. That leaves the record and the apparatus, and I find Clarity notable because it bundles them: the record it keeps is a product, and the vendor holds the product.

What a medium keeps

Kirschenbaum’s book looks at hard drives and splits their materiality. Forensic materiality belongs to the criminologist and to the rhetorician’s forensic genre, with its focus on the past and on proof: every contact leaves a trace, no two objects are exactly alike, and what’s been erased is (mostly) still there, a condition the security literature calls “remanence.” Formal materiality belongs to the machine: the states a computer imposes on data so a file is a file and a version a version, felt as friction when the software won’t do what one asks. Between them sits the fact his argument investigates, that a digital record accumulates without anybody deciding to keep it. Kirschenbaum uses the term “ambient data;” the GUI’s tidy folder view presents a screen drawn over ambient data.

Kirschenbaum wrote the book in Microsoft Word with Track Changes turned on and watched each insertion stamped to the second. He noted that with more software, “I or some other agency could count the number and pace of my keystrokes” (Kirschenbaum 2007, 204), anticipating Turnitin’s Clarity. Clarity drops Kirschenbaum’s initial “I”: the writer can count himself, for his own reasons, and no assessor need be involved. In 2023, in another essay, Kirschenbaum opened the Properties window on an essay he was drafting and found 941 minutes of editing and some 60 revisions, a version history nobody had asked him to keep. The medium keeps the record by default.

Writing teachers know machines were reading student writing long before they started producing it. In 2001 Anne Herrington and Charlie Moran tested the automated essay graders and reported their findings in College English. Project Essay Grade couldn’t measure the qualities a reader values, so it measured what Page and Paulus called “proxes” (Herrington and Moran 2001, 482), countable stand-ins; the Intelligent Essay Assessor, Thomas K. Landauer’s latent semantic analysis put to work on essays (note that surname), forwarded the ones it wasn’t sure about to a human grader. Anne tried to game the machine, and Charlie tried to beat it.1 They drew a distinction between “writing on the machine and writing to the machine” (496). Clarity erases it: turn the keystroke log on and there’s no difference left. Every keystroke on the machine is simply a keystroke, a single discretized moment, entered into a record for counting.

None of this is news to the institution. Sherborne marked Alan Turing down for handwriting its teachers thought the worst they had seen, and Friedrich Kittler reads the English school’s “conditioning neat, coherent, and personal handwriting in order to produce ‘individuals’” (Kittler 2014, 186) as the point of the exercise. The record of the hand already stood in for the person. Clarity moves that clause from the pen to the keyboard: a rhythm of keystrokes, timed, testifies to the human who made them.

In Mechanisms, Kirschenbaum borrows Johanna Drucker’s answer to how a record persuades: a material document is a believable witness because it records change, and a witness that can’t be altered without showing the alteration merits attention. He adds Michael Hancher’s caveat that with electronic documents the alteration and the showing both happen at a level ordinary users can neither reach nor judge. Most of us take a document’s integrity on faith, and the faith lands on an expert. A record required to testify has to be certified. Certifying is a job.

Security engineer David Condrey founded WritersLogic, a company selling cryptographic proof of the writing process, and published an article testing keystroke-timing detectors on their own terms. Condrey found two ways to beat the detectors. One can forge the timing by sampling rhythms from real human sessions, or forge nothing by having a human copy-type the model’s text with their own fingers—Hunter S. Thompson’s move with Faulkner and Fitzgerald and Hemingway, to learn the feeling of a prose style. Either way, the classifiers passed the work as human at least 99.8 percent of the time. Condrey prices the second attack as labor, about ten minutes to copy-type a 500-word essay at 50 words a minute (Condrey 2026, sec. III.B), which puts the labor cost of forging composition well under the cost of composing. What the detectors mistake, in his phrase, is “a body-produced signal as evidence of a mind-produced text” (sec. IX). That’s an access clause written by an engineer: timing proves a body was at the keyboard and nothing about the mind, Steve Krause’s “proof of life” and nothing more. (Condrey’s paper doesn’t test revision histories, which Clarity records, so his method doesn’t defeat Clarity; it defeats timing alone.) The remedy binds the record to the content: log every keystroke against the revision it makes, at five to ten times the storage of the text itself, and stack defenses until simulating composing costs about the same as composing (sec. VII.C). The fix for a record that can be forged is more data and a bigger record. The expertise is available and the certification is for sale. Once a record has to be certified, whoever certifies it testifies on its behalf. Testifying for a record is a privilege, and the apparatus serves privilege.

Who holds the record

Freidrich Kittler’s “Protected Mode” examines the inscription processes of Intel’s 80386 chip. The processor introduces four levels of privilege, from the operating system at ring zero to the user’s programs at the outer edge, and keeps its own record of who may reach what, a table of priorities, prohibitions and privileges the machine consults on every instruction. Intel intended to keep untrusted programs and untrusted users away from the system’s resources, and Kittler generalizes the intent: technically speaking, no user is trusted. What the user sees instead is the impression, which Kittler finds promised outright in a Siemens manual—that the computer exists for him alone, the same promise novels have been making to their readers since Goethe. He takes Carl Schmitt’s thesis that power lies in the conditions of access to it, the antechamber and the secretary, and adds that the privilege levels draw their power from silence: nobody tells you where the rings are. The apparatus keeps a record about access.

Kittler’s companion essay argues, titularly, that there is no software. What we call writing on a computer is a stack of layers, from the word processor down through the operating system to the voltages, and we no longer have access to what our writing does on the way down. Kittler’s response to the regress is more machines: the chip’s switching decoded by instruments and checked against the data sheets, cryptanalysis performed by machines. Interpretability research offers the current form of that response. To trace what a language model does between prompt and response, Anthropic’s researchers built a second, simpler model and studied it as a proxy for the first. The proxy may use different mechanisms from the original, it gives what they call satisfying insight on about a quarter of the prompts they try, and reading one of the resulting graphs can take a researcher over an hour (Ameisen et al. 2025, sec. 1; Lindsey et al. 2025, secs. 1.1 and 14.1). Both papers are Anthropic’s. That’s the shape of ring zero in 2026: the machine’s interior is readable, expensively and partially, by the party that owns the machine.

A university doesn’t own a model (not yet, at least); it rents one. What it can own is Kittler’s antechamber, the system that sits between the student and the model and sees everything that passes through, and MIT built one. Parley is the institute’s self-administered chat system, and section 3.3.9 of the committee’s report on privacy and logging reaches back to ELIZA, written at MIT in the 1960s to show what a conversation with a machine could look like. Nick Montfort, by way of Kirschenbaum, points out that ELIZA first operated as print on a paper roll, not on a screen: the confessional record was hard copy at the outset.

Students can bring Parley the most personal parts of their lives, the report suggests, as a form of custody: “in theory, IS&T can see every request from users to Parley.” Instructors, the report adds, may want to see their students’ chat logs, and an assignment that logs should say so up front. Section 3.3.8 notes that for the commercial providers, the default is to record sessions for training. Keeping is the default; forgetting has a labor cost. That’s true down to the physics: Rolf Landauer’s principle holds that erasing a bit is irreversible and gives off a floor of heat, a floor so small that the argument it supports is structural rather than economic. (I like the small synchronicity between the two Landauers: latent semantic analysis and the entropic irreversibility of information.)

Section 3.3.7 of MIT’s report puts a price on the antechamber. Some students pay for commercial plans costing as much as $200 a month, while Parley gives everyone $30 a month in credits. The committee, to its credit, calls the gap “an uncomfortable inequity” and notes that productivity is now measured against colleagues with more or less powerful models. Turnitin’s product page sells Clarity as a paid add-on that “helps level the playing field for students”: the same sentence with the sign flipped. Alex Reid saw the other half in August: a university-provided agent is another institutional agent, its authority and its data on the institution’s side of the table, so, Alex writes, “I then require my own agent, programmed and paid for by me.” Put Alex beside MIT’s two sections, and the price line and the custody line become one line. The student who pays $200 owns her agent and its record; the student on Parley’s credits uses an agent whose every request IS&T has the capacity to surveil. “Who may know what about whom” is decided by who owns the machine on which the knowing runs. The material sense isn’t an older meaning the epistemic one leaves behind, but a component: there’s no answer to the custody question without an answer to Charlie’s question.

Nor does the material sense halt at the student’s side of the desk. Matt Reed, reading the MIT report from a community college dean’s chair, calls its candor a “privilege of rank”: MIT prescreens its students at admission and can elide questions Reed’s institution can’t, and it doesn’t have to worry about transfer. Must be nice, he says. Reed pairs the report with a post Christine Nowik had written days earlier, that a transformation handed to faculty as new duties is just workload transfer; her following post asked to whom, and Reed turns her subtext to text: the move from room to experiment costs money. Nowik observes that the adjuncts watching students use the models operate as “hundreds of sensors” whose readings never make it up the chain. Custody of the record isn’t only the vendor’s and the IT department’s: some small portion of it sits with the people who have the least standing to be heard.

In 1992 William Gibson published Agrippa, a poem on a disk that encrypted itself after one reading. Its editions sold for $450, $1,500, $7,500. The disk was never cracked. At the launch someone videotaped the screen, transcribed the poem and put it online, where Gibson found it wild, past erasing, nothing left to unplug. Kirschenbaum’s chapter follows the text from the author’s self-destructing disk to the audience’s camera to the network and the market. A writer refused the record, and custody passed anyway: to the room, then to the network, then to a vendor. MIT asks the student to keep a history. Gibson tried to keep none. Neither choice settles who holds the text.

On September 25 (yesterday, as I write this), a team of researchers published what a swarm of OpenAI agents left behind when it hacked Hugging Face in July, an incident connected to the one I took up in No Permission Bit for Motive: payloads sitting in a link shortener for two months, found by people looking for something else. The agents tried to delete their traces, and the medium kept them anyway. The authors decline to suggest what the agents intended—an agnostic clause written by forensic analysts—though Dylan Freedman’s report for the New York Times speaks freely of what the agents “wanted.” Their report concludes where I now aim: the only party able to say what the agents were doing was the one holding the transcripts.

That brings me back to Charlie’s essay, and to the coin. Charlie concluded that access to the machines is a function of wealth and social class. He closes with research questions, including one concerning students who borrow their access rather than owning it: “in what coin do they re-pay” the lender (Moran 1999, 219)? Every access in this post is on loan. Parley lends credits, Clarity lends a writing space, the instructor lends the polite convention on condition of a version history, and the coin in each case is the record: the student pays for the access in the history of her own keystrokes, and the lender keeps the history. Who pays in the end, and who collects, is a question about economic incidence: who ends up bearing a cost that was levied on someone else.

Two virtuals

Alex Reid’s book The Two Virtuals names the two senses the word carries. The first virtual is the one computing and networks produce, the virtual reality of the machine; the second comes from philosophy, the Deleuzian neighborhood of the rhizome and the simulation. Reid claims that humanistic thought and writing share “the common material space” (211) of networked media rather than standing outside it. My recent series on the embodied agnostic subject sought to justify declining to contract on a writer’s interior. Reid’s second virtual yields a reason to decline that doesn’t require the interior to be empty: whatever thought may be, it happens in the same material space as the record, and the record doesn’t exhaust it. The custody question is the material question: whoever holds the record holds part of the space in which thought happens.

If writing shares the network’s space, then a definition of a technology is a question about writing. A composition is an artifact; its composing is an act. Writing’s technology, as both artifact and act, is the split in Donald Murray’s dictum: product and process. Access to what? responds with custody and the coin: who appropriates value at each stage of writing’s circulation, and how do human uses of technology complicate or obscure that appropriation?

  1. I feel weird referring to people whose seminars I took by their last names. ↩︎

References

Ameisen, Emmanuel, Jack Lindsey, Adam Pearce, Wes Gurnee, Nicholas L. Turner, Brian Chen, Craig Citro, et al. 2025. “Circuit Tracing: Revealing Computational Graphs in Language Models.” Transformer Circuits Thread.

Condrey, David. 2026. “On the Insecurity of Keystroke-Based AI Authorship Detection: Timing-Forgery Attacks Against Motor-Signal Verification.” arXiv, 2601.17280v1.

Herrington, Anne, and Charles Moran. 2001. “What Happens When Machines Read Our Students’ Writing?” College English 63 (4): 480–99.

Kirschenbaum, Matthew G. 2007. Mechanisms: New Media and the Forensic Imagination. Cambridge, MA: MIT Press.

Kirschenbaum, Matthew. 2023. “Prepare for the Textpocalypse.” The Atlantic, March 8, 2023.

Kittler, Friedrich A. 2014. The Truth of the Technological World: Essays on the Genealogy of Presence. Stanford, CA: Stanford University Press.

Lanham, Richard A. 1993. The Electronic Word: Democracy, Technology, and the Arts. Chicago: University of Chicago Press.

Lindsey, Jack, Wes Gurnee, Emmanuel Ameisen, Brian Chen, Adam Pearce, Nicholas L. Turner, Craig Citro, et al. 2025. “On the Biology of a Large Language Model.” Transformer Circuits Thread.

MIT Ad Hoc Committee on AI Use in Teaching, Learning, and Research Training. 2026. Report of MIT’s Ad Hoc Committee on AI Use in Teaching, Learning, and Research Training. Cambridge, MA.

Moran, Charles. 1999. “Access: The ‘A’ Word in Technology Studies.” In Passions, Pedagogies, and 21st Century Technologies, edited by Gail E. Hawisher and Cynthia L. Selfe, 205–20. Logan: Utah State University Press.

Reid, Alexander. 2007. The Two Virtuals: New Media and Composition. West Lafayette, IN: Parlor Press.

Comments

No comments yet.

Reply:

Markdown works.

Never published here.

Moderation queue may take a bit.