What do the water system in Flint, Michigan, the electrical grid in Puerto Rico and your search engine have in common? They are all forms of critical infrastructure — systems that are essential to everyday life.
People expect critical infrastructure to be reliable, minimise risks and promote public well-being. When such systems fail — as happened when lead seepage poisoned Flint’s water supply in 2014, or when nearly all of Puerto Rico’s power went out on New Year’s Eve in 2024 — the public expects risks to be mitigated and problems to be addressed.
Today, critical infrastructure includes food and water systems, roads and bridges, as well as financial and health systems. Much of the digital technology people depend on has also become critical infrastructure. People rely on search engines to find information, social media for public announcements and important communications, and AI-powered services for analysis and decision-making. These technologies have become essential to functioning in modern civic society.
However, when search engines opportunistically shape the information people seek, social media becomes polluted with misinformation, and AI-driven services provide unsafe recommendations or “digital slop,” many people simply regard these problems as part of the cost of engaging with the commercial sector. Others feel powerless to control their information, contributing to what has been described as “digital resignation.”
My experience as former director of the San Diego Supercomputer Center and co-founder of the international Research Data Alliance suggests that it does not have to be this way. Digital infrastructure can be designed, built and managed with human well-being in mind, just as other forms of critical infrastructure are.
Achieving this will require society to change both its expectations of digital critical infrastructure and its actions. This includes how the public and private sectors create and regulate these services and systems, as well as how the public uses them. The goal should be to better protect the people who depend on these technologies.
From Food to Search Engines
People expect critical infrastructure to be safe and secure for widespread use. They expect it to be broadly accessible, reliable and designed to serve public interests at least as much as commercial profit.
This means incorporating safeguards that protect the public, such as speed limits on roads, redundant systems in power plants and privacy regulations governing health data. These systems are never perfect, but people expect critical infrastructure to be built, managed and regulated in ways that support and protect a vulnerable public.
Consider food and information systems. Both contribute to public well-being in different ways.
In the food system, public health standards help safeguard how food is processed so that it does not make people sick. Restaurants are evaluated based on their compliance with these health standards. Is food handled and stored at safe temperatures? Are kitchens properly sanitised? In many places, restaurants are required to publicly display the letter grade assigned by the health department.
This makes it easier for people to make informed choices when they know whether a restaurant has received an A or a C.
Search engines, meanwhile, have also become critical infrastructure because they influence how people access information that is essential to modern life. Yet the ranking systems used by opportunistic search algorithms often prioritise content that is commercially advantageous, heavily optimised and designed to attract attention.
These priorities can shape public understanding, influence democratic discourse and, in some cases, give users a distorted view of reality.
What if people expected search engines to offer similar transparency about how they select and rank content? What if users knew the priorities built into a search engine’s algorithms, how they are profiled as users and how advertising influences the information they receive?
Such transparency could help people make better decisions about where to look for information and how much trust to place in what they find.
Digital critical infrastructure can put people at risk in different ways. Sometimes the effects are immediate, as when a power grid goes down or internet access is disrupted.
At other times, failure comes from exposing people to a toxic information environment. A polluted river can harm the people and wildlife that depend on it, just as dangerous misinformation on social media — including misinformation promoting health scams or body dysmorphia — can harm people seeking information and advice.
Digital critical infrastructure can also fail by not providing sufficient protections. This can create fertile environments for predators or support surveillance-pricing models that use personal information to determine the maximum amount consumers can pay.
Countering these risks requires stronger safeguards in the design, deployment and management of the systems people depend on.
Users should also have greater control over what they see on social media and who appears in their feeds. There should be more transparency around how personal data collected by connected doorbells, e-commerce services and other technologies is used, shared or sold.
Such safeguards could reduce risks while helping users avoid exploitation, manipulation and predators.
As digital technologies become increasingly essential to everyday life, they should be treated with the same seriousness expected of other forms of critical infrastructure. The systems people depend on should not only be built for efficiency and commercial value, but also designed to protect the public and promote human well-being.