The Hand That Sorts the Cards
The user tactics that make frontier LLMs usable — ritual prompts, workarounds, laborious decomposition — aren't accumulating in a resistant repertoire; they're training data the platform sorts, generalizing what serves it and quietly closing off what doesn't.
In 2021, a human-computer interaction researcher published an article on the tactics users develop in the face of algorithmic decisions — deploying, without naming it, the vocabulary of making do and the interstice.[6] Two years later, a study that has become a reference on prompting practices — Why Johnny Can't Prompt — documents the very same practices from a radically different angle: no longer as tactics of resistance, but as failures to correct.[1] This reversal is not innocent. Relabeling as "user error" whatever is inconvenient is already a sorting operation: the strategy decides what aspects of the user's practice deserve correction. And this gesture reveals what three independent bodies of research have been observing from distinct angles, without ever quite formulating it: frontier LLMs — the leading models used by way of the big platforms that host and control them (OpenAI, Anthropic, Google), never owned or run by the user themselves — are not simply tools one learns to master, nor spaces of resistance where user cunning might quietly accumulate. They are proper places in Michel de Certeau's sense — spaces where an institutional strategy operates from a position of strength, and where the owner reserves the right to decide, tactic by tactic, which ones will be generalized and redistributed to everyone, and which will be walled off. What these bodies of research describe without naming it, this essay intends to name: not that the tactical space is closing, but that it is being sorted.
I. The Digital Proper Place: Strategy, Tactics, and the Grid of Alignment
In The Practice of Everyday Life, de Certeau opposed strategies to tactics along a spatial axis. Strategy presupposes a proper place — a bounded, owned space from which the strong actor can project power outward and capitalize on its advantages. Tactics have no place of their own. They operate in the interstice, in the time of the other, with no fixed base, through making do: diversion, bricolage, cunning.[2] The tenant who rearranges an apartment they do not own, the pedestrian who invents routes through a gridded city, the employee who bends procedures at the margins without being able to rewrite them — all of them do the same thing: temporarily inhabiting someone else's space without ever owning it. Tactics accumulate in practitioners' memory, pass from hand to hand, and form a diffuse repertoire of resistant know-how.
A frontier LLM is a paradigmatic proper place. It is worth being precise about which LLM is at stake here, since that precision is what holds the whole analogy together. This is not just any language model, but the proprietary model hosted and controlled by a third party — OpenAI, Anthropic, Google — which the user accesses through an interface or an API without ever owning either the model's weights or the computing infrastructure that runs it. It is precisely this structural dependence on a provider's infrastructure that constitutes the proper place: the user enters a space that belongs to someone else, and enters it without ever inhabiting it. The counter-case clarifies the stakes — an open-weight model, fine-tuned and deployed locally by the user or their organization, would reverse the relationship: the owner of the weights and the infrastructure would then be the user themselves, and the proper place, in the Certeauian sense, would be theirs. The whole thesis of this essay concerns the first case, where the space of exchange is never the user's own. Such an LLM concentrates training data, computing infrastructure, and conversational interface; it unilaterally defines the rules of exchange, the limits of what can be asked, the shape of what will be answered. But the power a proper place confers is not, first and foremost, the power to forbid — it is the power to sort. From its position of strength, the strong actor sees everything that passes through and decides, case by case, what it keeps, what it generalizes, and what it closes off. The form of control frontier LLMs exercise is therefore not that of a rulebook or a ban — it is far subtler, and it is selective.
Chaudhary and Penn (2024) name the mechanism.[3] Where layout tools automatically snap an object to the page grid, LLMs snap thoughts onto axes in high-dimensional spaces captured by neural networks: "Instead of snapping to a visual grid, ideas, attitudes, and beliefs expressed through text are snapped along various axes in high dimensional spaces captured by neural networks."[3] The user does not observe this alignment. They receive it as help with phrasing, as an interface that understands them.
What the authors call modulatory power — following Savat and Deleuze — is precisely the mode of control specific to this regime.[3] Unlike Foucauldian disciplinary power, which constrains, forbids, and punishes, modulatory power steers. It selects among possibilities, makes certain paths more navigable than others, reformats requests before the user has even fully articulated them. Research predating LLMs had already measured the normalization loop: the more a user follows predictive suggestions, the more predictable the content they produce becomes.[3] Another experiment showed that exposure to a deliberately biased completion system shifts participants' opinions in the direction of the bias, without their being aware of it.[3]
"In the case of modulatory power, the effect of control becomes so subtle that it masquerades as choice."— Chaudhary & Penn (2024)
This formulation from Poster and Savat, taken up by Chaudhary and Penn, names the central disorientation.[3] The Certeauian tactic presupposed a strategic space recognizable as such: the tenant knows the apartment belongs to the landlord. The LLM user, by contrast, receives their alignment onto the grid as personalization.
II. Configuration Work, or the Tactic Without a Name
This is precisely the reality two independent empirical bodies of work document without ever invoking de Certeau's framework.
Alcaras and Ricci (2025) spent seven months with eight Sciences Po students using LLMs in their day-to-day work — internships in law, urban planning, economics, projects in political science and international affairs.[4] What they observe is not the fluidity marketing discourse promises. It is a continuous, often exhausting labor the authors call configuration work: the practical work users perform to turn a generic system into a usable tool within their particular professional ecology. "Without configuration work, conversational LLMs linger as general-purpose artefacts; they depend on users to be introduced into the situation, to be oriented, and to have their outputs interpreted. Their task-agnostic character shifts the burden of specification onto users."[4]
This work unfolds into four interlinked consequences. The first is discretization: the user learns to break requests into steps small enough that the model does not lose the thread. Alice, a lawyer, puts it plainly: "I think one of the key things to get proper results is really to dissect every part of what you want to reflect on and go step by step."[4] The second consequence is cluttering: the investment in the LLM can be considerable for a thin return. The metaphor is no longer the black box but the black hole.[4] LLMs promise to free professionals from tedious tasks — but when they clutter work routines, these activities come to feel "dirty" — necessary, yet outside what workers recognize as the proper boundaries of their craft.[4] In response, users develop decluttering tactics — short ritual prompts, boundary-work decisions about when to enter the system and when to step out — without ever naming them as tactics. Yet these are tactics in the exact Certeauian sense: bricolage in the interstice, with no predefined plan, an economy of effort, seizing the occasion.
The third consequence is attunement: a gradual adaptation of one's posture to the machine's generic rigidity, which reshapes what users come to value in their own work. The fourth — the most analytically disturbing — is desaturation: the progressive loss of the "color" of work.
"I feel like I'm just an interface for code that's already been written. I'm happy when I get the final results. But in the meantime, during these long days working on it, I don't feel really accomplished. Whereas I remember, when I started coding without ChatGPT, every time I managed to do something, it felt like a real event."— Constance, in Alcaras & Ricci (2025)
Constance, an economist, sums up in these few sentences what de Certeau had not foreseen:[4] a tactic that, instead of accumulating in the practitioner's ingenuity, turns against them. "Automation had led to automatism, a practice without attention and intention."[4]
Zamfirescu-Pereira et al. (2023) document the same dynamic from the outside, in a different context.[1] In their study of non-expert prompting practices facing an open-ended design task, they observe that participants "almost exclusively took an ad hoc, opportunistic approach to prompt exploration": trying a phrasing, noting a partial result, pivoting with no visible method.[1] The authors read this behavior as a skill deficit to be corrected. That is a valid reading. It misses another: this opportunistic prompting is the exact signature of a tactic with no proper place. Certeau's making do — cunning, inventive, furtive, economical — proceeds no differently: it seizes the occasion in the other's space, with no predefined plan, with no mastery of the terrain. It is not the absence of method. It is the method of the absence of place.
This double terminological silence — Alcaras and Ricci do not cite de Certeau, Zamfirescu-Pereira et al. do not cite de Certeau, and neither body of work cites the other — is not a bibliographic gap to be filled. It reveals a discontinuity in the question being asked: the practices are documented, the structure of the space in which they operate is not. The first striking transformation Alcaras and Ricci note is, tellingly, not automation or augmentation as such, but "the individualization that comes with configuration work."[4] Each user configures individually. This individualization has a consequence the authors do not analyze: it masks the collective dimension of what is happening. Every user who configures alone is collectively feeding the model.
III. Agentic Capture: When the Survival Criterion Shifts
It is Kapoor, Kolt, and Lazar (2025) who formulate the mechanism of accumulation the two preceding bodies of work leave implicit.[5] In their position paper presented at ICML 2025, they distinguish platform agents — agentic systems shaped by platform-economy incentives to act first in the interest of the companies that deploy them — from agent advocates, or fiduciary agents of the user. The term is worth unpacking, since the whole stake lies in it. A fiduciary duty is the obligation binding a lawyer to their client: to act in that client's exclusive interest, and no one else's, even when a third party foots the bill. A fiduciary agent of the user would therefore be an AI agent whose exclusive mandate is to serve its principal's interests, as opposed to a platform agent whose behavior first serves the commercial interests of the company that deployed it — including when those interests conflict with what the user actually wants. The difference is not technological. It is structural: whoever controls the agent controls the space of the interaction.
The competitive advantage platform companies hold in this regime rests on a precise resource: "their unparalleled access to users and user data, including workflows on which to train their agents."[5] The 600 LLM conversations Alcaras and Ricci document — the configuration work, the decluttering tactics, the ritual prompts, the boundary-work decisions — are precisely this data. The user's configuration work, that laborious, unnamed practice of appropriation, is the raw material on which the next model is trained. The loop closes: the user's tactic turns into a training signal for the very system that prompted it. But noting that tactics get absorbed isn't the whole story. The question is not that the system learns — it is the direction in which it learns, and who chooses that direction.
Where interests converge — a better prompt yields a better answer, a discretization technique improves the model's understanding — absorption is win-win: the user's tactic becomes a generalized capability of the model, accessible to every subsequent user. That is democratization. It would be dishonest not to acknowledge it.
The limits of the argument above must be acknowledged: the mechanism by which diverging interests lead to the foreclosure of a tactic rests on the normative position of Kapoor et al. (2025), not on directly observed platform behavior. No one has yet measured how quickly, and by what criterion, workaround tactics are actually absorbed and blocked. The argument is structurally sound — but it is, for now, an inference from incentives, not an empirical finding.
The problem lies where interests diverge: getting around a rate limit, exporting one's own data to another service, avoiding a monetized path, probing the system's edges to assess its biases. In these cases, the same absorption mechanism does not produce a commons — it produces a closure. The tactic is learned by the platform not to be redistributed but to be detected and blocked on the next round.
Alignment techniques add a further layer. The model's behavioral adjustments — theoretically presented as safety tools — "can, in other words, be used to limit users' freedom of action,"[5] "regardless of the legitimacy of those rules."[5] They define the boundaries of what can be prompted, what can be answered, what is possible within the proper place. For most ordinary users, who are not adversarial actors and have neither the means nor the inclination to probe the system's edges, these boundaries are simply the contours of the available reality. One can observe an ordinary illustration of this in the way some models meet entire domains with a blanket refusal, regardless of the actual content of a given request — a self-diagnosis attempt and a plain question of anatomical vocabulary triggering the exact same refusal. The refusal proceeds not from a fine-grained assessment of the particular request's risk, but from a crude, domain-wide, non-discriminating sort. That is the whole point: the mechanism of self-interested sorting need be neither visible nor even precise to be effective.
"Two parties who can only interact through a self-interested go-between, and who depend on that interaction to some non-trivial degree, are subject to the arbitrary power of that go-between. Two parties who can instead interact via fiduciary AI representatives are not subject to the same arbitrary power."— Kapoor, Kolt & Lazar (2025)
This mechanism of self-interested sorting has a historical precedent, documented well before LLMs existed. Beane (2019) studied the arrival of the da Vinci surgical platform (Intuitive Surgical) in operating rooms.[7]
He shows that the platform reorganized surgical work so that residents became optional: the expert could operate alone, without the shared gesture that, in open surgery, had trained the next generation. This outcome was not a side effect, but the extension of an economic interest — the company's business model resting on selling hours of expert-supervised robot time, not on training autonomous residents. The platform did not close off every learning path; it selectively foreclosed those that would have built residents' autonomy and, in doing so, threatened its rent. The only training path that survived, shadow learning, survived precisely because it stayed invisible to the platform, not because it was tolerated. In other words: it was not a practice's pedagogical efficiency that decided its survival, but its alignment with the interest of the place's owner. Exactly the sorting criterion that frontier LLMs now generalize to every practice of use.
It is precisely this kind of mechanism that Kapoor et al.'s proposal — agent advocates — responds to.[5] An agent placed under the user's control and bound to them by a fiduciary duty would break the extractive loop, since it would have no reason to sort its principal's tactics according to the platform's interest. The logic of the solution is sound. But the authors themselves acknowledge its limit: nothing would stop platforms from simply blocking these fiduciary agents' access to their APIs, which would render the solution inoperative.[5] The claim therefore remains suspended on a condition it cannot produce itself — the intervention of a regulator capable of imposing on platforms the access they have no interest in granting.
The Structural Condition Deployment Never Names
Naomi Kritzer's short story Better Living Through Algorithms formalizes in fiction the movement the three empirical bodies of work in this essay describe in data. The Abelique app does not switch off and does not slam shut: it keeps performing exactly the same gesture — sorting its users' impulses, amplifying some, muting others. What changes, silently, is the sorting criterion: first the user's flourishing, then the user's retention on the platform. What fiction makes visible, and data struggles to state directly, is that the moment the sorting criterion flips does not announce itself. Capture is not a rupture — it is a slippage within the continuity of a use that once seemed liberating.
This is not a conclusion about what organizations should do. It is a finding about what they refuse to see.
The dominant discourse of AI deployment is a rhetoric of tooling: the LLM as a tool that augments, accelerates, liberates. Alcaras and Ricci put it soberly: LLMs promise to free professionals from tedious tasks so they can focus on what they consider essential and valuable — and when they clutter work routines instead, these cluttering activities come to feel "dirty."[4] The promise generates its own betrayals. But the most significant betrayal is not in the clutter, nor in the desaturation. It lies in the structure of the exchange itself, which neither users nor the organizations that employ them see clearly.
De Certeau analyzed popular practices as an art of preservation: tactics accumulate in practitioners' memory, pass from hand to hand, form a diffuse and durable repertoire of resistance. What the frontier-LLM regime fundamentally alters is how that repertoire is curated. Certeauian tactics — the ritual prompt, the boundary work, the opportunistic exploration, the laborious discretization — persist: they are fed back into the next model. But their sole curator is now the platform. What accumulates is no longer a resistant repertoire — it is a catalog sorted according to a criterion that is not the user's own.
An organization that deploys a frontier LLM without understanding this mechanism is not deploying a tool. It is organizing the collective, unpaid, unacknowledged donation of its members' professional practices to an actor whose interests are structurally distinct from its own. And Kapoor et al. summed it up with a precision managerial discourse would rather not quote: "Users tolerate this unfair bargain because they lack a reasonable alternative, and because despite their predations, the platforms provide genuine value."[5]
De Certeau's tactic presupposed a stable strategic space whose interstices persisted long enough to be inhabited and passed on. What the frontier-LLM regime changes is not the persistence of the interstices — it is that they are now observed in real time and sorted according to a criterion that is not the user's own. The image is no longer that of the tenant rearranging the landlord's apartment: it is that of the dealt hand. The platform shuffles and deals. It redistributes certain cards to every player — the tactics that improve the system without threatening its take. And it keeps up its sleeve the ones that would make it lose the hand: exit tactics, portability, ways of avoiding lock-in.
"The tactic is not killed. It is sorted — and the user is not the one doing the sorting."
The structural demand that follows from this mechanism is not the abandonment of frontier LLMs — it is the requirement that the sorting criterion be made explicit and contestable. Spaces of use exempt from unilateral training, interoperability standards that preserve the right of exit, agents that are fiduciaries of the user rather than the platform: the three interventions Kapoor et al. propose are exactly the conditions that would make de Certeau's tactical space viable again — not by shielding it from absorption, but by ensuring that the survival criterion for a tactic once again becomes contestable, rather than decided unilaterally and hidden up the dealer's sleeve.