They came for the knowledge worker first. The scholar is next — and they will hand themselves over willingly, in exchange for ten hours a week.
This is a sister piece to "Things to Come — or They're Already Here". That article was about everyone. This one is for the people who think they are exempt.
A few weeks ago we wrote about Conway — the unannounced persistent agent buried inside Anthropic's leaked source code. We argued that the next form of vendor lock-in is not your files or your behaviour, but your cognitive fingerprint. The way you think.
The response we received split into two camps. Office workers and developers nodded. Researchers and academics did not.
"That's not really my problem," said the senior professor over coffee. "What I do is unique. Decades of training. AI cannot replicate cognitive specialisation."
This is exactly what the journalist said in 2005. The radiologist said in 2015. The translator said in 2018.
And now, in January 2026, Elsevier launched LeapSpace.
A Tool That Solves a Real Problem
LeapSpace is not vapourware. It is a serious product, and it does something genuinely useful: it combines literature search, collaborator discovery, funder identification, and proposal drafting in one workspace. Built on 18+ million peer-reviewed articles. Multi-LLM under the hood (OpenAI, Anthropic). Citation grounding through Trust Cards and Claim Radar. Roughly $32 a month, individual.
For a university funding office, for a principal investigator scoping their next ERC bid, for a PhD candidate trying to find unexplored intersections in their field — this is exactly the tool the work has been waiting for. It saves real hours. The pitch is true.
It is also, on paper, one of the safer AI options on the market. Their Terms of Service explicitly state that prompts and uploads are not used to train large language models. They have zero-retention contracts with their LLM providers. EU residency for personal data. AES-256. GDPR-aligned.
If you read only that, you would conclude that the cognitive sovereignty of the academic is safe.
You would be wrong. Not because Elsevier is acting in bad faith. Because the architecture of the offering does not require bad faith for the trap to close.
What These Tools Actually Watch
The published work of a researcher has been legible to Elsevier for two decades. Scopus indexes it. ScienceDirect distributes it. Mendeley organises it. None of that is the cognitive fingerprint.
The cognitive fingerprint is everything that happens before the publication:
The order in which you read papers. Which titles you skip. Which abstracts make you save the paper for later. Which co-authors you investigate before contacting them. Which funding programmes you scope and which calls you ignore. Which collaborators you pull up before reaching out. Which drafts you ask for help with — and what you carefully do not say in those drafts. Which questions you ask the system at 11pm on a Tuesday.
This is the meta-research. Not the output, but the process behind it. It is what every senior professor would say is the actual hard part of the job. The unique judgment that took twenty years to develop.
It has never been visible to anyone outside the researcher's own head. Until now.
Vertical Integration Without Precedent
Elsevier is not an AI vendor. This is the single most important fact about LeapSpace, and the one almost no one is naming out loud.
Elsevier owns the citation graph (Scopus). It owns much of the content (ScienceDirect). It owns the most widely-used reference manager (Mendeley). And now it owns the AI workspace where researchers will form questions, find collaborators, and draft proposals.
In every previous moment of academic publishing history, there was a separation between the corpus, the discovery layer, and the researcher's private workflow. Libraries held the corpus. Search engines provided discovery. The researcher's notebook was their own.
LeapSpace collapses all three into a single vendor.
The training-protection clause in the Terms of Service applies only to large language model training. It does not, and cannot, prevent the same company from understanding — at the platform level, through ordinary product analytics — what its users are looking for. What patterns the top funding offices follow. Which collaborators command the highest demand. Which research directions the most-cited researchers are quietly exploring six months before they publish.
This is not a privacy violation. It is the entire point of running a software platform. Every SaaS company does it. The difference is that, in this case, the company doing it also controls the publishing infrastructure your career depends on.
The Convenience Trap, Academic Edition
Professors do not have time. Anyone who has watched the modern academic week — teaching, supervision, committee work, peer review, grant administration, family — knows that the cognitive load is not sustainable without help.
An AI tool that genuinely saves ten hours a week is not a luxury. It is a survival mechanism. Every rational researcher will adopt it. The ones who refuse will simply lose the productivity race against the ones who don't.
That is the design. The trap does not work by being unattractive. It works by being indispensable.
And so the question is not whether the academic community will adopt research-AI tools. It already has. The question is what protections are built around the adoption — at the individual level, at the institutional level, and at the policy level — before the cognitive fingerprint of an entire generation of researchers becomes a strategic asset of two or three private companies.
The First to Fall
The cliché says AI will displace cleaners and warehouse workers, and that knowledge workers — especially those at the top of the cognitive hierarchy — are protected by the irreplaceability of their expertise.
The cliché has the order exactly backwards.
The first jobs to go to AI displacement are not the ones that require physical presence. They are the ones whose value is purely cognitive — and therefore the ones most easily captured as data, replicated, and scaled at near-zero marginal cost.
A model that has watched ten thousand researchers form their next research question can produce average-researcher output for free. The exceptional researchers — the genuine outliers — will be fine. The ninety percent in the middle will discover, painfully, that their unique value was never quite as unique as they believed.
This is not a prediction about 2040. This is the logical extension of what is being deployed in 2026.
What to Actually Do
None of this is a counsel of despair. The tools are real. The benefits are real. Refusing to use them is not a serious option for working researchers and funding offices.
What is a serious option is using them with discipline.
For individual researchers
- Never use a personal subscription on a credit card for serious institutional work. Demand institutional accounts with negotiated data processing agreements. The pricing pages do not advertise this option because it is more expensive — but it is the only path that gives you written commitments on retention, residency, and data-handling.
- Treat any cloud AI tool like a shared whiteboard in a public conference room. Only put on it what you would be comfortable being seen.
- For the genuinely sensitive work — target collaborators before outreach, unfunded research directions, peer review opinions, pre-publication ideas — use a local AI or no AI. The technology to run capable models on a researcher's own hardware exists today. It will not give you frontier performance, but it will give you complete sovereignty over the patterns it learns.
- Rotate vendors annually. Single-source cognitive capture is the most damaging form of lock-in. If your behavioural fingerprint accumulates entirely with one vendor, the cost of leaving rises every month you stay.
For institutions and funding offices
- Negotiate data processing agreements that go beyond GDPR compliance. Specifically: written commitments on prompt-history retention period, exclusion of platform usage data from cross-product analytics within the vendor's wider ecosystem, EU residency for the AI inference path itself (not only the personal data), audit rights, data deletion on termination.
- Train researchers in prompt-redaction discipline. Strategic content — funding priorities not yet announced, named collaborators before outreach, candidate evaluations — should be redacted from any cloud AI prompt regardless of contractual protections. Defence-in-depth.
- Provide an institutional local AI option. A modest server running Ollama with open-weight models can handle the bulk of routine work. The cloud is for what does not need to stay private. The local server is for what does.
- Treat AI vendor selection as a strategic intelligence decision, not a procurement decision. When you choose a research-AI platform, you are choosing who will, over the next five years, accumulate the deepest understanding of how your institution thinks. That is not a line item. That is a strategic posture.
The Real Question
Universities have always been the institutions that transmit knowledge across generations. The lecture hall, the supervision relationship, the editorial board, the conference circuit — all of these are mechanisms by which the cognitive patterns of one generation are passed to the next.
If those patterns are now also captured, in real time, by private companies whose business model depends on understanding and monetising them, then the transmission line goes through those companies. The university becomes a content provider. The AI vendor becomes the institution.
This is not paranoia. This is not technophobia. This is just looking honestly at where the data flows.
And the data flows, increasingly, from the researcher to the platform.
One Closing Thought
A researcher's value is supposed to be the next idea no one has had yet.
If a model has watched you have your last ten thousand ideas — what you read, what you ignored, who you contacted, who you avoided, what you drafted at midnight and deleted by morning — then it can predict your next one with high probability.
And whoever owns the model owns the prediction.
That is not a future scenario. That is January 2026. The only question is whether the academic community wakes up before its own cognitive sovereignty becomes a quarterly line item on someone else's earnings call.
A continuation of Things to Come — or They're Already Here. For research institutions and funding offices considering AI workspace adoption: the questions to ask are different from the questions vendors will answer. Talk to us before you sign.