I run a Personal Data Server. It sits at pds.croft.click, on a Mac mini on my desk, running in the background while I do everything else on the machine. If I ever decide I've had enough of it, I can pack my repo into a CAR file and walk to a different host without asking anyone's permission. That's not a boast; it's just what a PDS is supposed to do. It's the entire point of the protocol. So when a company launches a "New European" social platform, built on the exact same protocol I'm using for a hobby project, and then locks the front door behind you on the way in, I notice.
W Social launched at Davos earlier this year with full production values: European Commission officials on stage, a tagline about digital sovereignty, the works. Ursula von der Leyen has an account. So does Christine Lagarde. The pitch is that Europe needs its own social network, hosted on European infrastructure, governed by European law, and free of American Big Tech. Fine. I don't even disagree with the premise. What I disagree with is the part where they built that pitch on top of Bluesky's protocol, kept exactly none of the openness that makes the protocol worth using in the first place, and are still marketing it as though they built something from scratch.
The Bit They Don't Put on the Slide
AT Protocol isn't one thing. It's several separate services stitched together:
A Personal Data Server (PDS) that holds your actual account and posts
A relay that aggregates everyone's data into a firehose
An AppView that indexes all of that into something you can actually scroll through
A moderation layer sitting on top
Bluesky runs all of those pieces for its own network. Anyone else who wants to run a "sovereign" node on the protocol needs to either replicate the whole stack or quietly lean on Bluesky's for everything except the one component they've bothered to stand up themselves.
W Social has stood up a PDS. That's it. The relay, the AppView, the actual machinery that decides whether a post exists and whether anyone can find it’s far as anyone's been able to establish, that is still Bluesky PBC's American infrastructure doing the same job it does for bsky.app, just with a different logo pasted over the top. When the whole platform ground to a halt a few weeks after launch, the actual diagnosis from developers was a relay rate-limit. Nobody at W Social had thought to ask Bluesky's relay operators for more headroom before onboarding thousands of accounts. That's not a European outage. That's an American one, wearing a European flag.
It is worth being precise about what got forked here. AT Protocol is a standard, not a codebase – you can't meaningfully "fork" a spec without leaving the network it describes, and W Social hasn't done that. Their own terms of use say content can be accessed by other platforms using the protocol, and outside observers have confirmed W Social accounts show up fine on public tooling. What W Social actually forked was Bluesky's implementation: the reference PDS and app code published under an MIT licence. The protocol stayed open and interoperable; it was the code sitting on top of it that W Social quietly closed off.
There's a knock-on effect from keeping Bluesky's app.bsky.* lexicon namespace instead of minting their own, too. That namespace isn't scoped to W Social's users. It's the global record type the entire Atmosphere already uses for Bluesky-compatible microblogging. I've watched people on W Social get genuinely confused about why posts from accounts they've never heard of, on infrastructure they didn't sign up for, are showing up in their feed. As far as the AppView is concerned, there's no such thing as an "external" post. If you wanted your users to believe they'd joined a separate, distinctly European platform, reusing the one namespace that guarantees you can't contain anything was an odd way to go about it.
W Social told the press that an advantage of their platform is joining a network of roughly 40 million people. That is true only in the sense that Bluesky has 40 million users. Borrowing someone else's headcount to describe the size of your own platform is the exact same move as borrowing their infrastructure to describe the location of your own servers.
Yes, my own PDS talks to Bluesky's relay and AppView too. But the difference is that pds.croft.click has exactly one account on it, mine. I'm not calling it a sovereign European alternative, and I'm not launching at Davos with EU officials.
Verified Humans, Unverifiable Exits
Then there's the identity verification, W Social's headline safety feature: government ID and a photo on account creation to "eliminate bots." Bots are a real problem, but there's a difference between a platform that lets you opt-in for a verification tick and a platform that makes your government ID a precondition for entry. One is a feature; the other is a biometric photo tied permanently to everything you post, sitting on a server controlled by a company cagey about its own infrastructure.
This turns from "concerning" into "actively hostile" when you consider that credible exit is the entire reason to build on AT Protocol. You're meant to be able to take your data and leave to any other PDS without losing your handle or history. W Social has given no indication they've built or documented an outbound migration path. Once your account is anchored to a verified ID on their infrastructure, "just leave" stops being a trivial operation. Decentralisation without an exit strategy isn't decentralisation – it's just a marketing asset.
This has caused a mirror-image problem for users coming in. While high-profile institutional accounts got a proper migration, ordinary users had to go through the new-account ID gate. W Social never built the tooling to let a normal user bring their existing Bluesky identity across that gate. The practical result? People now have two separate identities sitting on the same open network sharing none of their history. It's exactly the kind of fragmentation the protocol was designed to prevent.
Bluesky Isn't the Villain in This Story
W Social's whole pitch relies on the implication that Bluesky belongs in the same bucket as Facebook and Twitter – American Big Tech that Europe needs saving from. That framing only works if you ignore what Bluesky actually is.
Bluesky Social is a Public Benefit Corporation, legally obligated to pursue its founding mission of open, decentralised technology for public conversation, even when that cuts against short-term profit. They publish their protocol as an open standard and have spent real effort enabling the exact kind of independent infrastructure that allows alternate platforms to exist.
None of that makes Bluesky a charity. It's still a company, and it still needs to make money. But collapsing the difference between "an American company" and "the American Big Tech problem" is a deliberate rhetorical move. A founding myth needs a villain. It's a strange kind of ingratitude to cast the company whose code and infrastructure you're currently renting as the monster you're saving Europe from.
Everyone Else Turned Up to the Same Party
What makes this hostility stand out is how unusual it is for the ecosystem. Blacksky runs its own relay, moderation, and AppView as a full technical peer. Northsky has been testing its own PDS migration tooling for the queer community. Eurosky – a genuine non-profit – has been sharing its roadmap in public, mirroring the identity directory, and doing the unglamorous plumbing of standing up independent relay infrastructure on European soil.
When W Social first showed up, Bluesky's developer team publicly welcomed them. That's the norm here. Everyone building on AT Protocol understands that a rising network lifts every app sitting on top of it. W Social is the one player refusing to act that way. No public roadmap. No visible contribution back to the protocol. No acknowledgement that Eurosky is doing the actual sovereignty work. They are taking everything the Atmosphere offers for free while acting like the rest of the neighbourhood doesn't exist.
They Took the Receipts Down, Too
I'd almost be willing to give them the benefit of the doubt if the company were being straight with anyone. Their GitHub repository – the actual source for the app – was up until March. Then it wasn't. Not archived, not redirected, just deleted, with no explanation.
Bluesky's repos are public. Eurosky's fork is public. Blacksky's is public. W Social's was public too, right up until it became inconvenient. A platform can build on an open protocol and go closed-source on their specific client, but it's highly ironic that this happened in the exact same window where the European Commission was publicly promising to scale up open-source use across its institutions.
So, add it up:
Verified real names on a closed-source client
Relying entirely on an AppView and relay owned by an American company
No visible, documented way out for ordinary users
Marketed the entire time as Europe's definitive answer to Big Tech
I keep waiting for someone to explain to me which part of that is actually European, besides the press release.
What Sovereignty Would Actually Look Like
None of this is a knock on the protocol. AT Protocol working exactly as designed is what makes W Social's version of it so obviously hollow. Genuine sovereign alternatives like Eurosky exist because they are willing to pay the actual cost of sovereignty: building and maintaining independent infrastructure. It's slower and less glamorous than a Davos keynote, which is presumably why nobody's put Ursula von der Leyen on stage for it.
I don't need W Social to be perfect. I need it to stop being marketed as something it isn't. "New European platform" is doing an enormous amount of heavy lifting to cover for an ID-gated front door and an invisible exit. Call it what it actually is and I'll leave it alone. Keep selling it as sovereignty and I'm going to keep pointing out that it's not sovereign, it's disingenuous, and the only sovereign thing about it is the flag on the landing page.