1 September 2026

Fake US thinktank set up and funded by Israel sought to game AI for propaganda

The Guardian | Jason Wilson

The Israeli government financed a covert foreign influence campaign routing tens of millions of dollars through European advertising entity Havas Media to manipulate artificial intelligence chatbot responses regarding Gaza war crimes. American contractor Piro Inc disclosed under the Foreign Agents Registration Act that it created a shell website, the Hanover Institute for Public Policy, which generated 124 reports totaling over 560,000 words between 6 and 14 August.

This digital operation deployed generative engine optimization tools from platform Res to prime commercial large language models and ingest data into repositories such as Common Crawl. Havas transferred over $24.9 million to US subcontractors. Clock Tower X received $15 million and Targeted Communications Global received $9,892,335 to execute messaging strategies. Despite these multi-million-dollar expenditures, Israeli officials privately acknowledged that the strategic public diplomacy initiative failed to reverse rapidly declining public support across the United States.

Comment

Generative engine optimisation represents a structural pivot in state-sponsored cognitive warfare, shifting focus from human social media feeds to the automated training pipelines of large language models. By seeding structured, pseudo-academic domain repositories prior to indexing by Common Crawl, state actors can permanently alter the foundational datasets used by commercial artificial intelligence systems. This approach exploits the inherent opacity of retrieval-augmented generation architectures, where synthesised chatbot outputs obscure original source provenance and neutralise standard attribution mechanisms.

The deployment of targeted text files such as llms.txt directly targets the algorithmic scraping protocols that feed systems like Perplexity and ChatGPT. Structuring propaganda around query-style headers allows information campaigns to pre-emptively mirror user prompt syntax, maximising the probability of algorithmic retrieval during real-time inference. Consequently, the commercial optimisation tools marketed by platforms like Res function as force multipliers for foreign intelligence and public diplomacy apparatuses seeking systemic narrative insertion.

Strategic Question for Discussion
If state-backed information operations shift permanently toward poisoning foundational datasets like Common Crawl, which defensive countermeasure will prove more decisive — front-end algorithmic attribution auditing or back-end training data filtering?
The trajectory indicates that back-end training data filtering will face severe limitations due to the sheer volume and linguistic sophistication of synthetic, domain-optimised content. Consequently, front-end attribution auditing integrated directly into retrieval-augmented generation protocols offers the more viable defense against covert data poisoning. My assessment is that AI developers will ultimately be forced to implement cryptographically signed provenance verification to maintain model credibility.
Share your assessment in the comments below.

No comments: