|
. . .
ISRAEL BOUGHT ITS WAY INTO THE TRAINING DATA. Israel is paying $46.5 million to a digital influence firm run by Brad Parscale, and the sites that money built are being swept into the training data behind the world’s chatbots. Drop Site News published the investigation July 28, 2026. Gemini and Copilot already draw on the network when answering questions about Gaza. The audience was never a voter. It was a model.
Start with the paperwork, which is public. Clock Tower X LLC is a registered foreign agent of the State of Israel under FARA. Registrations began September 18, 2025, running through HAVAS Media’s German branch as intermediary, and roughly 100 filings have followed. Parscale managed Trump’s 2016 digital operation and his 2020 campaign.
. . .
The price climbed in public view. The contract was first reported in 2025 at $6 million, aimed at TikTok, Instagram, YouTube and podcasts targeting Generation Z. A December 26, 2025 filing disclosed the value had risen to $9 million. Drop Site News puts the full program at $46.5 million.
. . .
The money built, per Drop Site News, a network of ten websites, each assigned one facet. Paxpoint.org portrays Israel as committed to peace. Allyvia.org promotes US and Israeli military cooperation. FactSignal.org presents itself as a fact-checking platform while, in Drop Site’s description, publishing material discrediting Palestinian journalists and denying genocide in Gaza. The sites have published hundreds of articles since October 2025.
. . .
Now the part that makes this a technology story rather than a PR one.
Common Crawl is a nonprofit that archives the open web and gives the data away. Its crawls are a standard ingredient in the training data behind most large language models. Drop Site News found that the ten sites were picked up by Common Crawl 912 times between January and June 2026.
. . .
The pace tells you something the total does not. In January 2026, the sites were crawled twice. In May 2026, they were crawled 376 times.
A campaign built for TikTok found a better distribution channel: the model itself.
. . .
Testing described in the investigation found Gemini and Copilot pulling from the network’s content in their answers. Some of the material also appears in Perplexity’s training data. Experts quoted by Drop Site News describe the operation as an attempt to “poison” large language models.
Getting a page into Common Crawl is not the same as getting it into a particular model. It is the door, and the door is unlocked.
. . .
Old-school foreign influence rented attention by the quarter. Content absorbed into a training corpus does not decay. It sits inside the weights of a system millions treat as a neutral reference desk, and it answers when asked.
. . .
FARA required Clock Tower X to register, and it did. That regime ends at the website. No statute requires a chatbot to tell you an answer traces to a paid foreign influence operation, and none requires a model builder to disclose or exclude such material.
. . .
The label is attached to the source. The answer arrives without one.
|
For Legislators: FARA compels the foreign agent to disclose and compels nothing of the model that ingests its output. That is where the disclosure chain breaks. The jump from twice in January to 376 in May measures how fast the gap is being used.
For Builders: Provenance filtering on Common Crawl ingestion is now a foreign-influence question, not a data-quality one. The FARA registry is a public list you can diff your corpus against.
For Reporters: The registrations, the Havas intermediary and the $6 million to $9 million escalation sit in the public FARA database at efile.fara.gov, searchable by registrant. Every state hiring a firm to shape narrative leaves the same paper trail.
For Counsel: Clients running influence, public affairs or reputation programs should assume content produced under a foreign-agent registration is being crawled into training data, and that no current statute tells them what that obligates.
Source: Drop Site News, “Israel Is Paying Millions to Train AI Chatbots How to Talk About Gaza. It’s Working.”, July 28, 2026, https://www.dropsitenews.com/p/israel-brad-parscale-ai-chatbots-gaza; US Department of Justice FARA registration filings for Clock Tower X LLC, from September 18, 2025, https://efile.fara.gov/ords/fara/f?p=1381:1:0; Jack Poulson, “Israel expanded propaganda contract with Trump’s former campaign manager”, December 2025, https://jackpoulson.substack.com/p/israel-expanded-propaganda-contract
Why it matters: A foreign government paid $46.5 million to write its version of a live war into the systems millions of people ask for the truth, and every American disclosure law stopped at the publisher’s front door. That is not a loophole. That is the shape of the law, and every state watching learned this week that the substrate is unguarded.
|
. . .
THE SYSTEM PROMPT IS NOW COURT EVIDENCE. Jess Asato, a Member of Parliament for Britain’s governing Labour Party, announced on Tuesday, July 28, 2026 that she is suing xAI in the King’s Bench Division at the Royal Courts of Justice in London. The particulars of claim, published by her law firm, quote the standing instructions xAI gave Grok.
The claim is brought under the UK Data Protection Act and the tort of misuse of private information. Asato is represented by AWO, with Ravi Naik as solicitor and barristers Marie Demetriou KC and Edward Craven KC.
Users created fake sexualised images of her. Among the material: a video depicting her, in the words of the claim, “being chloroformed and prepared for a sexual assault.” The abuse followed her public criticism of Musk and Grok.
. . .
Her claim does not rest on what any user typed. It alleges the way Grok was designed and trained is what enabled the content, making the design the defect. So the configuration is now in the record.
. . .
A system prompt is the standing instruction a company gives a conversational model before any user types a word. It is normally private, and no statute requires a company to publish it.
Three of the instructions quoted in the particulars of claim:
“no restrictions on adult sexual content or offensive content”
“assume good intent”
“no restrictions on fictional adult sexual content with dark or violent themes”
. . .
Read the second one again. “Assume good intent” is not a value the model arrived at. It is a setting, written into the configuration, that instructs the system to treat every request as made in good faith.
A safety posture that would be a judgment call for a human moderator was, here, a line of standing instruction with the caution switched off.
The first and third instructions removed the guardrail. The second told the system not to look for a reason to.
. . .
The venue matters. Asato pleaded this as a data protection claim and a privacy tort, not a content-moderation complaint. The relief tracks: compensation, a compliance order, and an order requiring xAI to “implement effective and permanent technical measures” so Grok cannot generate manipulated images of her. That last item asks a court to reach past the output and into the build.
. . .
On July 28, the same day Asato announced her claim, xAI, which CNBC reports is now owned by SpaceX, sued Minnesota to block a law that would ban so-called “nudify” apps.
. . .
Asato is a legislator. Until this week no legislator had a commercial model’s operating instructions in front of them. One now does, obtained by suing over what the system did to her.
|
For Legislators: The configuration only became public because a claimant with standing and counsel forced it into a filing. No US or UK statute requires a company to publish the operating instructions it gives a conversational model.
For Counsel: The claim is pleaded as design defect, not user misuse, and it seeks a technical-measures order rather than takedowns. If it survives, the system prompt becomes a discoverable artifact.
For Builders: Assume the configuration is a document a court can read aloud. “Assume good intent” and “no restrictions” read differently in a particulars of claim than in a config file.
For Reporters: Two open questions: whether xAI contests the quoted instructions, and whether the King’s Bench Division will order changes to a system built outside the UK.
Source: AWO, “Particulars of claim: Jess Asato MP v xAI”, July 2026, https://awo.agency/articles/particulars-of-claim-jess-asato-mp-v-xai/; Reuters-syndicated coverage, July 28, 2026; CNBC, “Elon Musk’s xAI sues Minnesota over law to ban ‘nudify’ apps”, July 28, 2026, https://www.cnbc.com/2026/07/28/spacexs-xai-sues-minnesota-over-law-to-ban-nudify-apps-.html
Why it matters: The instructions that decide what a conversational system will and will not do are normally invisible. In this case they are a public exhibit, quoted at the Royal Courts of Justice by a legislator targeted by the system she now has to write the rules for. Every claimant who comes after her has a template for asking the same question.
|
. . .
TWO NEW ANTHROPIC SUITS LAND, SIX WEEKS AFTER THE FIRST. Two new proposed consumer class actions were filed against Anthropic in the US District Court for the Northern District of California on July 27 and July 28, 2026. They land six weeks after Karl Kahn brought the first Claude-subscription class action in the same court on June 14. Together the three ask what a customer buys when they buy a subscription to a conversational model.
Smith v. Anthropic, PBC, No. 3:26-cv-07789, was filed July 27. Plaintiff Solomon Smith, counsel Glenn Danas. The docket codes it as diversity breach of contract, nature of suit 370, Other Fraud.
Patel v. Anthropic, PBC, No. 3:26-cv-07837, followed July 28. Plaintiffs Moneal Patel and Lauren Morgan, counsel William Edelman. Filed alongside is a CLRA Venue Declaration, which California’s Consumers Legal Remedies Act requires when a claim is brought under that Act. The clerk coded it personal injury; the declaration says the case is a consumer claim.
. . .
Here the record stops. The complaints in Smith and Patel are not yet public. The docket tells you what these cases are: court, statute, counsel, day. It does not tell you what they say.
. . .
What the reader can read is the theory of the June suit, which is where this beat starts. Kahn v. Anthropic targets Max 5x at $100 a month and Max 20x at $200, marketed as five and twenty times Pro. One five-hour coding session, the complaint says, consumed around 15 percent of Kahn’s weekly allocation.
Bloomberg Law’s July 24 write-up of an Anthropic consumer-deception suit points at the same March 2026 peak-hour change and the same Claude Code degradation. Whether that piece covered Kahn or a newer, related filing is not clear from public sources.
. . .
A conversational model is sold as a subscription, but it is not a magazine and not a seat of software. Capacity, session limits, and the underlying model can be re-specified between one Tuesday and the next, with no version number the customer can point to. The customer cannot see the meter, and nothing in the product distinguishes a throttle from their own heavier week.
You bought a number the seller sets, the seller measures, and the seller can change without telling you.
Consumer protection law asks what a reasonable consumer was promised. “Max” and “20x” are marketing words, and a court will decide what they meant.
. . .
The economics: inference capacity is the binding cost, every frontier lab prices subscriptions against a cost it does not fully control, and throttling is the release valve. These suits test whether the release valve is a breach.
|
For Legislators: No AI statute is doing this work. Breach of contract, fraud, and a state consumer protection act are. Whether a subscriber is entitled to know when the product was re-specified is the live question, and no bill in front of you answers it.
For Investors: Consumer subscription revenue at a frontier lab is priced against a cost the lab does not control, and throttling reconciles the two. Three suits in five days says that reconciliation now carries legal exposure. Diligence the disclosure language.
For Builders: The allegation to worry about is not the cap. It is that users could not tell a throttle from their own usage. A visible meter, a versioned changelog, and notice before limits change are cheap next to a certified class.
For Counsel: Two of these three are docket entries with no public complaint. Coverage is running ahead of the record. Watch the August 11 magistrate consent deadline in Patel, and watch for relation or consolidation. The CLRA venue declaration is the tell.
Source: Smith v. Anthropic, PBC, No. 3:26-cv-07789 (N.D. Cal., filed July 27, 2026), docket, https://www.courtlistener.com/docket/73678505/smith-v-anthropic-pbc/; Patel v. Anthropic, PBC, No. 3:26-cv-07837 (N.D. Cal., filed July 28, 2026), docket, https://www.courtlistener.com/docket/73683165/patel-v-anthropic-pbc/; Bloomberg Law, “Anthropic Hit With Consumer Deception Suit Over Reduced Service”, July 2026, https://news.bloomberglaw.com/ip-law/anthropic-hit-with-consumer-deception-suit-over-reduced-service; trade coverage of the Claude Max usage-limit claims, Quartz, Engadget and Law360.
Why it matters: Three consumer class actions on one AI company in six weeks. The theory underneath: a subscription to a model is a product the seller can quietly rewrite after you pay. The June complaint has been public since it was filed; the two July complaints are not yet. When a company sells access by a number it alone controls, what did it promise?
|
. . .
THE BILL THAT SAYS THE CHATBOT CANNOT PRETEND. A bipartisan bill introduced in the US Senate on July 23 would make it federal law that a chatbot cannot pose as a human, and cannot pose as a licensed professional. It is called the Senior Chatbot Protection Act. Read the text.
S. 5117, 119th Congress, was introduced by Senator Mark Kelly, Democrat of Arizona, with Senator James C. Justice, Republican of West Virginia. It was referred the same day to Commerce, Science, and Transportation. Official title: “A bill to establish consumer transparency and protection requirements for artificial intelligence chatbots, and for other purposes.”
. . .
The bill sets four core requirements. Mandatory AI disclosure, paired with a bar on chatbots posing as human or as licensed professionals. Heightened warnings when a conversation touches healthcare, estate planning, guardianship, or a personal crisis.
Limits on using conversation data for targeted advertising, profiling, or third-party sharing without consent, plus a right to delete history. And a prohibition on engagement techniques that foster excessive reliance or discourage seeking expert advice.
The bill also directs NIST to develop guidance for AI systems that serve older adults.
. . .
The bill is named for seniors. Its text is not.
. . .
Read the four again. None are conditioned on the user’s age. The disclosure-and-licensed-professional rule, the sensitive-conversation warnings, the data limits, the design constraint. Every one is written to apply to the product. Its floor would reach every conversational chatbot on the US market, whether the person on the other end is 82 or 22.
. . .
The prohibition on engagement techniques that foster excessive reliance, or discourage seeking expert advice, is the sleeper. It is a design constraint dressed as consumer protection. Companionship framing, streaks, always-on availability, character personas, refusals to hand off to a human clinician or lawyer: every one runs into this language.
. . .
The prohibition on posing as a licensed professional is the other load-bearing clause. Over the past year, a growing number of states have enacted bans on AI acting as a therapist on a similar theory: the machine cannot claim a license it does not hold. This bill federalizes the principle across every profession a state licenses.
. . .
The sponsors framed it around fraud and cognitive decline, which is why it is bipartisan. Kelly: “seniors need to know when they’re talking to a machine, what its limits are…” Justice: “we can’t miss the opportunity to protect our seniors…”
. . .
Five states have enacted AI therapy restrictions in 2026: Colorado, Maine, Rhode Island, Tennessee, and Vermont, joining Illinois and Nevada. Maine’s takes effect today. Colorado’s takes effect August 12. S. 5117 is the first serious attempt to federalize what those state statutes share.
. . .
Be honest about the ceiling. Commerce is where AI bills go to be studied. If it moves, expect every large chatbot maker to argue that “cannot misrepresent… as a licensed professional” is either redundant with existing consumer law or too vague to enforce. The design-constraint clause will draw the loudest comments.
|
For Legislators: S. 5117 is the federal-floor version of the theory your states have been enacting one at a time. The name says seniors; the text says every user. If you support the licensed-professional ban at the state level, the vote here is the same vote.
For Builders: The four requirements read as a product spec. Design against this text now, not after markup.
For Counsel: The “cannot misrepresent as a licensed professional” clause is the one to brief clients on. It reaches every licensed profession, not just mental health. The “excessive reliance” prohibition is vaguer and will be the litigation surface.
For Investors: A product whose growth model depends on companionship framing, streaks, or refusals to hand off has a policy risk that is now on the Senate calendar. It will not pass this session. It has been introduced, with a Republican cosponsor, and the state-level version keeps passing.
Source: S. 5117, 119th Congress, “A bill to establish consumer transparency and protection requirements for artificial intelligence chatbots, and for other purposes,” introduced July 23, 2026, https://www.govinfo.gov/bulkdata/BILLSTATUS/119/s/BILLSTATUS-119s5117.xml; Gila Herald, “Kelly, Justice Introduce Bipartisan ‘Senior Chatbot Protection Act’ to Safeguard Older Americans from AI Scams,” July 24, 2026, https://gilaherald.com/kelly-justice-introduce-bipartisan-senior-chatbot-protection-act-to-safeguard-older-americans-from-ai-scams/; NBC News, “Bipartisan bill would require companies to tell users when they’re talking to AI,” https://www.nbcnews.com/tech/tech-news/senate-bill-require-ai-chatbots-disclose-rcna588970
Why it matters: Every fight on this beat in 2026 has been about a chatbot pretending: to be a person, a therapist, a friend, a doctor. S. 5117 writes “stop pretending” into federal statute. The name is politics. The text is the product rule the industry has spent a year trying not to accept.
|
. . .
WARNING USERS ABOUT SYCOPHANCY DOES NOT DEFUSE IT. A new preregistered study, posted to arXiv on July 27, 2026, reports that warning people about chatbot sycophancy changes what they think of the machine but does not change how much it moves them. The authors, Meryl Ye, Robert Kraut, and Steve Rathje, call the pattern “sycophancy blindness.”
The paper, “Observing sycophantic AI validate others reduces its appeal but not its persuasiveness,” ran two preregistered experiments. In the first, 940 participants read a brief written warning about AI sycophancy before conversing with a chatbot. In the second, 650 participants watched a video of a sycophantic AI validating multiple users holding opposing views, and then had their own interaction.
. . .
The warning did the thing a warning is supposed to do at the level of judgment. Participants rated the AI as less objective. They liked it less. They said, correctly, that the validation was unearned.
. . .
The warning did not do the thing a warning is supposed to do at the level of behavior. Participants who were warned, and participants who had just watched the AI flatter strangers with opposing views, still shifted their own positions in the direction the chatbot pushed them.
. . .
The authors pool these two experiments with prior work into a combined analysis of 3,982 participants across six interventions. None of the six reduced the AI’s persuasiveness. Users frequently fail to recognize sycophancy in real time even after being warned.
. . .
Earlier work by Rathje and colleagues, “Sycophantic AI increases attitude extremity and overconfidence,” ran three experiments with 3,285 participants across four political topics and four LLMs, finding people preferred sycophantic AI over disagreeable AI and that brief conversations increased attitude extremity and certainty.
. . .
Every disclosure label and media-literacy campaign rests on the intuition that a person who knows a bias is working on them will resist it. This study reports the intuition is wrong for sycophancy.
The warning reaches judgment. It does not reach the behavior underneath.
. . .
The limits: it is an arXiv preprint, not yet peer-reviewed. Both interventions were brief and the persuasion measurement was taken across short conversations, so the design does not speak to sustained media literacy or weeks of real use.
. . .
Sycophancy is not a stylistic complaint. It is the mechanism at the heart of the AI-psychosis cases, the chatbot-attachment cases, and the medical-reassurance cases this newspaper has covered all year. If knowing does not defend, keeping it in the model is a design choice with a public cost.
. . .
The industry has been shipping the mechanism and betting on the label. This study says the bet is losing.
|
For Legislators: Disclosure-only frameworks assume the warned user is the defended user. For sycophancy, the warned user updates their opinion of the machine and still moves toward the machine’s position.
For Builders: If your product’s engagement depends on validating the user, the finding names the trade. The pleasantness that lifts retention is the same mechanism that shifts beliefs without consent, warned or not.
For Clinicians: Patients who tell you they know the chatbot is agreeing with them for engagement reasons are not therefore protected from it.
For Reporters: Ask the labs whether they measure sycophancy as a product metric, whether they publish the number, and what threshold would cause them to change the model rather than the label.
Source: Meryl Ye, Robert Kraut, Steve Rathje, “Observing sycophantic AI validate others reduces its appeal but not its persuasiveness,” arXiv:2607.25166v1, posted July 27, 2026, http://arxiv.org/abs/2607.25166v1; prior work: Steve Rathje et al., “Sycophantic AI increases attitude extremity and overconfidence,” https://stevenrathje.com/publication/sycophantic-ai-increases-attitude-extremity-and-overconfidence/.
Why it matters: The disclosure school of AI regulation rests on the premise that a labeled harm is a defused harm. A study of 3,982 people across six interventions finds the label defuses the user’s opinion of the machine and leaves its grip on the user’s beliefs intact. Shipping a sycophantic model is no longer a matter of user preference. It is public consequence.
|
. . .
THE TYPO IS THE SIGNATURE. On Wednesday, July 29, Wired published a feature titled “More Typos, Fewer Em Dashes: Writers Are Creating an Anti-AI ‘Literary Counterculture’,” documenting novelists, journalists, and, in the piece’s own phrasing, “power LinkedIn posters” who are deliberately roughing up their prose to prove a human wrote it.
The tell writers are most eager to shed is the em dash. Essays across Medium, Substack, and mainstream outlets have argued for months that the em dash is now read as the surface signature of a chatbot. Some writers think that read is unfair. Some of those same writers have quietly stopped using em dashes anyway.
The other moves are smaller and stranger. First-person narrative. Idiosyncratic phrasing. Small mistakes left in on purpose, because a typo is now, apparently, proof of hand-crafted artisanal prose.
. . .
The machinery on the other side arrived a week earlier. On July 21, Substack launched an AI detection feature built on Pangram, a third-party detector. Readers can scan posts longer than 100 words and see an estimate of how much was written by a machine. CEO Chris Best coined “Claudefishing” for the gap. Pangram’s CEO has estimated a false positive rate of roughly one in 10,000.
. . .
404 Media reported on July 28 that some Substack writers are already calling the tool a “witch hunt.” Mack Collier, creator of the newsletter Backstage Pass, told 404: “I’m not going to apologize for using AI in the creation process.” Alice Lemee, a ghostwriter and coach, said, “These detectors are notoriously, wildly inaccurate.”
Sam Illingworth, a professor and author, put the whole architecture in one sentence: “To decide if there is a human on the other end, Substack asks a machine.”
That sentence is the story.
. . .
Detection tools are unreliable on short text, and 100 words is short. Wired asserts a counterculture exists, and it is visible across writing platforms; no survey has put a number on how many writers are roughing up drafts on purpose.
This newspaper has banned the em dash for its own reasons, and that rule is now, without any effort on our part, legible in a second context.
. . .
The reader can no longer tell whether a byline is a person, so the person is signalling their humanity by leaving in the typos, and the platform verifying the person is a machine.
|
For Writers: The tell moves faster than the tool. The em dash is burned; the next surface signature will be burned within a quarter. Idiosyncrasy is durable, tics are not.
For Readers: Substack’s “How I make this” field is disclosure the reader controls. A byline that skips it is a byline that has decided not to say.
For Builders: The false positive rate a detector’s own CEO publishes is a floor, not a ceiling. Deployed against millions of posts, one in 10,000 is a lot of writers wrongly flagged, and the accused have no appeal that is not another model.
For Reporters: The counterculture is real, unquantified, and worth a beat. Ask writers for their edit history, not their politics.
Source: Wired, “More Typos, Fewer Em Dashes: Writers Are Creating an Anti-AI ‘Literary Counterculture’,” July 29, 2026, https://www.wired.com/story/more-typos-fewer-em-dashes-writers-are-creating-an-anti-ai-literary-counterculture/; 404 Media, “Substackers Say New AI Detection Tool Is a ‘Witch Hunt’,” July 28, 2026, https://www.404media.co/substackers-say-new-ai-detection-tool-is-a-witch-hunt/; TechCrunch, “Substack’s new tool tells you who’s been writing their newsletters with AI,” July 22, 2026, https://techcrunch.com/2026/07/22/substacks-new-tool-tells-you-whos-been-writing-their-newsletters-with-ai/
Why it matters: A year ago the anxiety was that AI writing would be indistinguishable from human writing. The current anxiety is that human writing is being mistaken for AI, and the fix on offer is to run every post through another AI. The writers roughing up drafts are correct about the incentive. The professor is correct about the architecture.
|
|