The Mode of Information and the Database Subject
Mark Poster's The Mode of Information is a pre-web work of media theory with a durable claim: electronic systems do not merely transmit descriptions of a ready-made person. Their fields, identifiers, categories, and interfaces help determine which version of a person an institution can recognize and act upon.
This review calls that operational proxy the database subject. It is produced through capture, standardization, identity resolution, inference, and writeback. It is neither the living person nor a synonym for every datum about them; it is the maintained representation that a system treats as sufficiently person-like for search, ranking, eligibility, pricing, suspicion, service, or care.
The governance test therefore follows a chain: source record → resolved identity → profile → inference → decision → feedback. At each stage, ask what counts as evidence, who can change it, where a correction must propagate, and how an affected person can obtain a consequential review rather than a ceremonial one.
The Book
The Mode of Information: Poststructuralism and Social Context was published by the University of Chicago Press in 1990. BiblioVault lists cloth ISBN 9780226675954 and paper ISBN 9780226675961 for the Chicago edition. Google Books records a 179-page Polity Press edition from the same year, with ISBNs 0745603262 and 9780745603261.
Poster was a historian and media theorist at UC Irvine. The University of California Academic Senate memorial identifies him as Professor of History and Film & Media Studies, a founding chair of UCI's Film & Media Studies department, and a major figure in the study of media culture, including television, databases, computing, and the Internet. That institutional location matters. Poster is not writing as a product analyst or computer scientist. He is writing as a critical theorist trying to understand why electronic media demand new accounts of language, power, and subject formation.
The book's structure is explicit. BiblioVault's table of contents lists chapters pairing TV advertising with Baudrillard, databases with Foucault, electronic writing with Derrida, and computer science with Lyotard, after an opening chapter on postindustrial society. That sounds abstract, and often is. But the abstraction is aimed at a concrete question that still matters: what happens when communication systems stop being channels and become environments that constitute social life?
Current Context
Two terms must be kept separate. Under GDPR Article 4, a data subject is an identified or identifiable natural person to whom personal data relate. The database subject in this review is a critical term for an institution's operational representation of a person. The distinction matters because the legal person can invoke rights while the technical proxy may be distributed across source tables, identity links, derived features, summaries, scores, caches, and vendor systems. GDPR Article 15 provides access to personal data and specified processing information; Article 22 covers a narrower class of solely automated decisions with legal or similarly significant effects. Neither right should be inflated into a universal entitlement to every model detail.
Two Court of Justice judgments show why the full chain matters. In SCHUFA Holding, Case C-634/21, the Court held that producing a credit score can itself fall within Article 22 when a bank gives that score a determining role in whether to grant credit. In Dun & Bradstreet Austria, Case C-203/22, the Court held that information about automated decision-making must let the affected person understand and challenge the procedure actually applied, including which personal data were used and how. An algorithm alone is not an intelligible explanation, and a trade-secret claim does not permit a blanket refusal: protected information can be submitted to a supervisory authority or court for balancing.
The EU AI Act now supplies complementary system duties, but its dates require care. Articles 10 and 12 establish data-governance and automatic logging requirements for high-risk AI systems. Regulation (EU) 2026/1744 amended the Act's application schedule: those high-risk provisions apply from December 2, 2027 to systems covered by Article 6(2), generally the Annex III use cases, and from August 2, 2028 to systems covered by Article 6(1), the regulated-product route. They are enacted requirements, not duties already applicable to every AI system as of this review.
California offers a narrower operational example. The California Privacy Protection Agency's DROP service launched on January 1, 2026, and registered data brokers began processing deletion requests on August 1, 2026; the official process requires brokers to retrieve requests at least once every 45 days, so a consumer-facing status can take up to 90 days. Separate California automated-decisionmaking requirements for businesses using the covered technology to make significant decisions begin January 1, 2027. These state-specific mechanisms do not create a general U.S. right, but they make propagation visible: a request succeeds only if identities are matched, applicable records are found, deletion or an exemption is recorded, and downstream handling changes.
The Mode
Poster's title plays against Marx's mode of production. He does not show that economics has been replaced by language. He argues that electronic communication has become part of how production, administration, memory, and identity are organized, so ownership and labor cannot be understood apart from the formats through which people become knowable.
A useful working definition follows: a mode of information is an institutional arrangement in which communication is encoded as machine-operable records and those records help allocate attention, rights, duties, resources, and risk. Its power lies not merely in speed or scale but in addressability. Before a system can act for or upon someone, it needs an account, identifier, role, case, category, or match that says which represented subject should receive the action.
The format is consequential. A form can require one category and omit another; an identity graph can merge two people or split one person into several profiles; an interface can make a recommendation look like a fact; a retention rule can keep an old judgment available after its context has disappeared. The recurring lesson across Sorting Things Out, The Language of New Media, and this book is concrete: schemas and interfaces are policy because they determine what can be entered, joined, displayed, and acted upon.
Databases and Subjects
The book's most durable chapter places databases beside Foucault's account of discipline. Poster calls the resulting arrangement the Superpanopticon: surveillance no longer depends on enclosing a body beneath one visible watcher. Administrative traces can be combined and searched, while people participate by completing forms, presenting credentials, choosing categories, accepting defaults, and generating transaction histories. Participation is not the same as meaningful consent. It often reflects the practical price of employment, credit, education, health care, benefits, communication, or ordinary service.
The database subject becomes clearer when separated into stages:
- Source record: an application, transaction, observation, document, message, or event is captured under a schema.
- Identity resolution: identifiers and matching rules decide which records belong to the same person or account.
- Profile: selected records are assembled into a usable institutional view.
- Inference: a rule or model adds a label, summary, score, prediction, or recommendation.
- Decision and action: a worker or automated workflow changes access, price, priority, scrutiny, service, or obligation.
- Feedback: the action and the person's response create new records, which may become evidence for later decisions.
Each stage has a different failure mode. Capture can omit context; schemas can force a false category; entity matching can create a false merge or false split; profiles can retain obsolete material; inferences can exceed their evidence; decision interfaces can encourage automation bias; and feedback can make the consequences of an earlier intervention look like neutral observations. An output-only audit starts too late.
A person can therefore have several inconsistent database subjects at once: a customer profile, a fraud profile, a clinical identity, a school record, a broker segment, and a platform account need not agree. Nor is each proxy a single row. It may be distributed across a document store, identity graph, feature service, vector index, cache, model context, audit trail, and third-party copy. The operational danger is not that the representation is fictional; it is that a partial and revisable representation can acquire more institutional authority than the person it stands for.
This is also why privacy cannot be reduced to secrecy. A record may be accurate, lawfully held, and tightly secured yet still be harmful when moved into a context with different expectations or used to answer a question it was never designed to answer. The central issue is not only who can see the proxy, but which actions it can authorize and whether the affected person has a route to correct its components and contest its use.
Electronic Writing
Poster also treats electronic writing as a change in what text can do. On a networked system, writing can be copied, searched, linked, transformed, and executed by another process. Contemporary AI adds generated notes, summaries, classifications, and instructions that can be stored beside human-authored records or passed to tools.
The governance problem is therefore larger than factual error. A draft answer becomes more dangerous when an interface gives it the status of a verified source, a final decision, or an authorized instruction. Systems should preserve the difference among source evidence, quoted material, human notes, generated text, recommendations, and approved actions. They should also record who or what created each item, when, from which inputs, under which model or rule version, and with what review status.
Generated language should not silently overwrite the record from which it was derived. A summary may help a worker navigate a long case file, but later systems must still be able to distinguish the summary's interpretation from the underlying evidence. Otherwise an unsupported sentence can be retrieved as apparent fact, repeated in a later summary, and gain authority through repetition rather than verification.
The AI Reading
Poster was not writing about large language models, and the analogy should not erase technical differences. Person-related information can reach an AI-mediated workflow through at least four distinct paths: model-development data, records retrieved at runtime, information supplied in the current interaction, and outputs written back to an institutional store. The practical remedy depends on the path. Correcting a source table, rebuilding an index, invalidating a cached summary, changing a prompt template, and preventing a generated note from becoming authoritative are different operations.
The key continuity is institutional rather than mystical. AI systems inherit accounts, documents, labels, permissions, histories, and categories from existing organizations; they can then compress those materials into recommendations or prose and pass the result to a worker or tool. Fluency changes the interface, not the need to establish provenance, authority, purpose, and a correction route.
This changes how “human in the loop” should be evaluated. The affected human is already inside the system as applicant, worker, patient, student, customer, claimant, source, or reviewer. A final approval click is not meaningful oversight unless the reviewer can inspect relevant evidence, recognize uncertainty and conflicts, depart from the recommendation, record a reason, and change the outcome. Governance must begin at capture and identity resolution, not at the last screen.
Recursive Reality
The book also clarifies a feedback loop: record → rule or model → intervention → observed response → new record. A risk score can change where scrutiny is directed; the resulting observations then appear to confirm where risk was located. A recommendation changes what is available to choose; the subsequent click becomes evidence of preference. A case summary changes what a worker notices; the next note inherits that emphasis.
The error is to treat feedback produced after an intervention as if it were an untouched sample of the world. Decision records should therefore include the model or policy version, the intervention offered or imposed, the human override if any, and the observed outcome. Without those distinctions, a system can learn from its own routing while losing the evidence that the routing occurred.
This is the concrete meaning of recursion here. Representations do not replace reality, but they alter the choices, surveillance, services, and documentation through which later reality becomes visible. The record is both memory and lever.
Institutions and Labor
Poster's strength is language, subjectivity, and mediation. That is also a limit. The book gives less attention to procurement, ownership, labor conditions, organizational incentives, infrastructure, and the budgets that determine whether correction and appeal exist in practice.
Every database subject is maintained through work. Someone designs the schema, selects a vendor, maps old records into new fields, resolves duplicates, labels examples, writes thresholds, handles exceptions, reviews complaints, or decides that an appeal queue is too expensive. These choices distribute authority. A correction right without trained staff, contractual access to vendor-held data, and time to investigate can exist on paper while failing operationally.
That is why Poster should be read with Automating Inequality, Atlas of AI, The Costs of Connection, and Ghost Work. Poster explains how information systems format a subject; these works show the bureaucracy, extraction, material infrastructure, and hidden labor that make the format effective.
Governance and Safety
The proper control surface is the full representation chain, not only the model endpoint. A useful artifact is a subject-representation ledger: a lineage manifest that points to relevant records and transformations without copying all personal data into a new central dossier. W3C's PROV family supplies a general vocabulary for entities, activities, agents, and derivation; it can support the lineage layer, but it does not by itself establish lawful purpose, accuracy, fairness, or an affected person's rights.
For each consequential workflow, the ledger should identify:
- the system and subject keys, along with the evidence and confidence used to link identities;
- the source, collection context, stated purpose, applicable legal basis or authorization, schema version, and retention rule;
- whether each item was observed, supplied, inferred, generated, human-authored, or finally approved;
- the transformations, joins, recipients, model or rule version, decision, intervention, and downstream stores;
- notice, access, explanation, correction, restriction, deletion, appeal, and propagation status.
Six controls follow. First, preserve representation lineage from source evidence to action. Second, review identity resolution for both false merges and false splits. Third, keep source material, inferred attributes, generated text, human notes, and approved decisions distinguishable. Fourth, enforce purpose boundaries rather than letting authentication, service, fraud, research, personalization, training, and legal-compliance data silently migrate among uses. Fifth, propagate valid corrections, restrictions, deletions, and opt-outs to the stores, indexes, caches, vendor copies, and future refreshes that the relevant law, policy, and contract cover. Sixth, connect a decision receipt to notice and recourse so a reviewer can find the evidence and has authority to change the outcome.
A practical test is a correction drill. Introduce a known error into a test subject's source record, let the normal workflow derive a profile and decision, then submit a correction. Verify that the source is corrected or appropriately annotated; the identity link is re-evaluated; derived features and summaries are refreshed or invalidated; the decision is reconsidered; required recipients receive the change; and the affected person gets a useful status. A policy that passes only at the source table while stale inferences continue to govern has not passed.
Logging creates its own safety problem. A comprehensive ledger can become a high-value meta-dossier, and worker-facing audit trails can turn into workplace surveillance. Store pointers and necessary event metadata instead of duplicate payloads; separate operational access from audit access; apply retention and access review; and record enough to prove a correction without retaining the disputed content indefinitely when deletion is required. The same discipline applies to sensitive attributes used for fairness assessment: controlled, purpose-bound analysis can be necessary, but it is not a license for universal collection or reuse.
There is also a tension between explanation and protected information. Third-party privacy and genuine trade secrets can limit what is disclosed directly, but they should not be treated as a universal opacity switch. The CJEU's Dun & Bradstreet Austria judgment points to a more accountable route: provide an intelligible account of the procedure and data actually used, and let a competent authority or court balance genuinely protected material.
NIST's voluntary AI Risk Management Framework 1.0, which NIST says is being revised, is useful here because its Govern, Map, Measure, and Manage functions keep organizational context, impacts, monitoring, and response in one lifecycle. It is not a substitute for law. Its value is operational: it makes a system owner name the context and affected parties before measuring a model, and it treats post-deployment monitoring and response as part of the same risk process.
Where the Book Strains
The Mode of Information is theoretically dense, and its examples are sometimes pulled toward one master concept. Charles J. Stivale's 1991 review in Criticism questioned whether the mode of information risks becoming another totalizing framework. The criticism remains apt: the concept is strongest as a way to inspect particular record practices, not as a complete explanation of social life.
The Superpanopticon metaphor can also imply one coherent watcher. Contemporary representation is often fragmented among controllers, processors, vendors, brokers, agencies, and workers whose records conflict. Fragmentation does not necessarily reduce power; it can instead make responsibility and correction harder to locate. But the difference matters for diagnosis. A centralized surveillance architecture and an incoherent vendor chain require different controls.
Nor does a person simply become the categories offered. People withhold, improvise, maintain multiple identities, contest labels, and act unpredictably. A database subject can constrain access without exhausting the subject it represents. Any governance scheme that aims to perfect the proxy rather than limit its authority would repeat the book's problem in administrative form.
Finally, not every AI risk is a database-subject risk. Model security, reliability, labor displacement, intellectual-property disputes, energy use, and harms to people who are not individually represented require other analyses. Poster's framework helps when records, categories, and institutional addressability are central; it should not be stretched until every computational problem looks identical.
What This Changes
The practical lesson is to audit subject formation, not only outputs. Begin with the institutional action: what changes for a person, and what representation is accepted as evidence for that change? Then trace backward through the decision, inference, profile, identity match, and source record. Trace forward as well: which intervention and response become the next system's evidence?
This alters common review questions. Accuracy is not only whether a score was computed as designed; it is whether the right records were matched, the categories fit their purpose, conflicting evidence remained visible, derived claims were distinguishable, and stale conclusions lost authority after correction. Transparency is not a data dump; it is enough context for an affected person and an empowered reviewer to understand and challenge the operative path. Human oversight is not presence; it is evidence, time, independence, and power to revise the result.
Poster remains useful because he identifies a shift from communication as channel to communication as administration. A database, form, interface, generated summary, and decision screen can help decide which version of a person an institution will recognize. The answer is neither to perfect that version nor to pretend institutions can work without records. It is to bound the proxy's authority, preserve its provenance, and maintain an independent route from record back to person.
Source Discipline
This review separates evidence from interpretation. Publisher and bibliographic records establish the book's editions, date, and contents; the UC memorial establishes Poster's institutional biography; scholarly reviews support reception and criticism. The database-subject chain, its application to contemporary AI workflows, and the proposed ledger are this review's analysis rather than claims that Poster described present systems.
Legal claims rely on enacted text, official court releases, and regulator materials. The GDPR and EU AI Act are binding EU law only within their respective scopes and application schedules; the EDPB document is guidance; CJEU judgments interpret EU law; California materials are state-specific; W3C PROV is a technical standard family; and NIST AI RMF 1.0 is voluntary and under revision. No one source is treated as a universal governance regime.
Sources and current claims were rechecked on August 12, 2026, including the EU AI Act schedule amended in July 2026 and the DROP processing phase that began August 1, 2026. This page makes no claim that an AI system is conscious, divine, or AGI; it analyzes AI as institutional software that consumes records, produces derived representations, and sometimes supplies or executes consequential actions.
Related Pages
- The Digital Person explains how a dossier becomes a working substitute for a person; The Language of New Media shows how interfaces govern possible operations on that substitute.
- The Entity Match Becomes the Identity Budget examines the false-merge, false-split, privacy, and evidence costs hidden inside identity resolution.
- The Vector Database Becomes Institutional Memory traces source, chunk, embedding, permissions, retrieval, answer, and log as separate evidence layers.
- Contextual Integrity, Data Minimization, and AI Data Provenance constrain what a representation may contain, where it may move, and how its origin remains visible.
- Data Subject Access Requests, Right to Rectification, Right to Explanation, and Notice and Appeal distinguish access, correction, explanation, and consequential recourse.
- Independent Correction Protocol supplies the institutional principle behind the correction drill: a system cannot be its own only source of evidence, review, and repair.
Sources
- BiblioVault / University of Chicago Press, The Mode of Information: Poststructuralism and Social Context, publisher record, Chicago edition ISBNs, description, and table of contents, reviewed August 12, 2026.
- Google Books, The Mode of Information: Poststructuralism and Social Context, bibliographic record for the 1990 Polity Press edition, page count, and ISBNs, reviewed August 12, 2026.
- University of California Academic Senate, In Memoriam: Mark Poster, UC Irvine biography, departments, and media-theory context, reviewed August 12, 2026.
- Robert Anchor, review of Mark Poster's The Mode of Information, The American Historical Review, vol. 98, no. 3, June 1993, pp. 829–830, bibliographic details and reception, reviewed August 12, 2026.
- Charles J. Stivale, review of Mark Poster's The Mode of Information, Criticism, vol. 33, no. 2, spring 1991, pp. 268–271, author-uploaded copy, reviewed August 12, 2026.
- EUR-Lex, Regulation (EU) 2016/679, General Data Protection Regulation, Articles 4, 15, and 22 on definitions, access, and automated individual decision-making, reviewed August 12, 2026.
- European Data Protection Board, Automated decision-making and profiling, EDPB endorsement record for the GDPR-related WP29 guidelines, reviewed August 12, 2026.
- Court of Justice of the European Union, Press Release No. 186/23, Judgment in Case C-634/21, SCHUFA Holding, December 7, 2023, credit scoring and Article 22, reviewed August 12, 2026.
- Court of Justice of the European Union, Press Release No. 22/25, Judgment in Case C-203/22, Dun & Bradstreet Austria, February 27, 2025, intelligible explanation, data use, and protected-information balancing, reviewed August 12, 2026.
- EUR-Lex, Regulation (EU) 2026/1744, July 2026 amendment to the AI Act application schedule, including Article 113 dates for high-risk systems, reviewed August 12, 2026.
- European Commission AI Act Service Desk, Timeline for implementation of the EU AI Act, official phased-application timeline reflecting the 2026 amendment, reviewed August 12, 2026.
- European Commission AI Act Service Desk, Article 10: Data and data governance and Article 12: Record-keeping, official text for high-risk-system data and logging requirements, reviewed August 12, 2026.
- California Privacy Protection Agency, CCPA updates, cybersecurity audits, risk assessments, automated decisionmaking technology, and insurance regulations, final-rule and effective-date page, reviewed August 12, 2026.
- California Privacy Protection Agency, California Finalizes Regulations to Strengthen Consumers' Privacy, September 23, 2025 announcement with risk-assessment and ADMT compliance timing, reviewed August 12, 2026.
- California Privacy Protection Agency, Delete Request and Opt-out Platform (DROP), consumer eligibility, request, and status timeline, reviewed August 12, 2026.
- California Privacy Protection Agency, Process DROP Requests and Data Broker Deletions: How Do They Work?, broker processing cadence and August 1, 2026 start, reviewed August 12, 2026.
- World Wide Web Consortium, PROV Overview, overview of the provenance standard family and its entities, activities, agents, and derivations, reviewed August 12, 2026.
- National Institute of Standards and Technology, AI Risk Management Framework Core, voluntary Govern, Map, Measure, and Manage functions and revision status, reviewed August 12, 2026.
Book links are paid affiliate links. As an Amazon Associate I earn from qualifying purchases.
- Amazon, The Mode of Information by Mark Poster, paid affiliate listing, reviewed August 12, 2026.