Dan Shearer

Co-founder of Samba and founder of LumoSQL, working in open source, privacy law, health research and AI safety.

The question, Who ought to be in control, and how do we keep it that way? arises in AI, technology monopolies, healthcare and privacy law. I try to change the usual answers.

CV and background. Contact me at dan@shearer.org ↗.

If you’re here about…

…open source & computer science: LumoSQL applies lessons from Samba and its history to SQLite data storage. Not-forking makes it possible to combine code trees in an ongoing way without forking them. In security analysis I study whether developers’ design and implementation choices survive translation into running software, a problem I call developer intent. I have un-archived and re-published some Margaret Hamilton articles. Reversible execution helps diagnose difficult problems by running computer systems backwards. Could my ancient Palm Pilot experiment work in modern conferences?

…AI ethics or agentic systems: In my view AI models should never be trusted, and reliable structure improves on what AI companies offer. The Perseverance Composition Engine ↗ models institutions designed to remain reliable despite untrustworthy members. I call these Artificial Organisations. The project also addresses big problems in AI.

…medical research, biobanks, epidemiology or data ethics: Who owns health data? My work in epidemiology covers One Health and rule-based malaria modelling. Medical Snapshot proposes a system that is structurally forbidden to tell you your own results, compared against 25 systems used in the last 90 years. The Active Heat Exchanger is a prototype retrofit ventilation system designed to improve indoor air quality and collect longitudinal data. Radiophobia explains a widespread medical problem I experienced myself. I have also developed a method for including academic sources across scripts, languages and historical eras without forcing them into English conventions and thought patterns.

…IP, governance and regulation: Data mobility after Brexit is a continuing problem for UK organisations. Large companies often ignore regulation while claiming compliance. I argue that GDPR Article 28’s controller-processor duties imply cryptographically protected audit trails and controlled access to keys. Not Before Time answers “what did they know, and when did they know it?” with time-lock cryptography, giving everyone control over when information becomes readable.

…advisory, expert witness or collaboration: I work with founders, boards and courts on software IP, privacy regulation and open-source strategy. My experience includes six years of technology due diligence for a Nordic venture fund and expert-witness work before the Court of Session.

…contributions and corrections: errors, missing references and additions are welcome; the site challenge has the details.


More: AI and agentic systems · health and research · open source · law and privacy

Browse all content by topic or search full text.