A Fake Thinktank Published 560,000 Words in Nine Days to Game AI Chatbots
Filed under FARA as material distributed for the Israeli government, on a platform that promises to optimise content so chatbots cite it.

A pro-Israel messaging website carrying the name of a thinktank that does not exist has published more than half a million words in nine days, built on a commercial platform that promises to optimise content so AI chatbots will cite it.
The site presents Israel's position on subjects including the torture of Palestinian prisoners, alleged war crimes and whether Israel has deliberately starved Palestinians in Gaza — all framed as neutral research. A Guardian analysis found 124 reports totalling over 560,000 words published in that nine-day window.
The disclosure
The New York media production company Piro Inc filed the site with the US Justice Department this month under the Foreign Agents Registration Act, the 1938 law requiring anyone working for a foreign government to disclose it, as material it distributes for the Israeli government.
That filing is what makes the operation documented rather than merely suspected. FARA registration is a legal requirement, and the company complied with it — which means the attribution here does not rest on inference.
A crow perches on an Israeli flag near an empty beach on the Tel Aviv coastline in April 2026. Photograph: Ahmad Gharabli/AFP/Getty ImagesThe technique
The target is not human readers. Publishing 560,000 words in nine days makes no sense as a strategy for attracting an audience, and the volume is the point.
Large language models answer questions by drawing on material retrieved from the web, and retrieval favours sources that are comprehensive, well structured, confidently written and heavily interlinked on a topic. A site that publishes 124 detailed reports on a narrow subject in a form optimised for machine consumption can become a disproportionately weighted source on that subject.
The commercial platform used here exists to do exactly that, and it is sold as legitimate marketing.
Why this is harder to counter than ordinary propaganda
Conventional disinformation depends on persuading people, and people apply scepticism to a source once they know what it is.
This approach skips that. A user asking a chatbot a factual question receives a synthesised answer with the sourcing abstracted away. The framing arrives stripped of the context that would let anyone evaluate it, and the apparent neutrality of the assistant is inherited by whatever it drew on.
The defence — visible citations, source reputation weighting, provenance signals — is technically possible and unevenly implemented, and it competes against the conversational fluency that makes these products appealing in the first place.
The precedent
What has been documented here is a state-funded operation, legally registered, using an off-the-shelf commercial service to influence what AI systems say.
None of the components are novel or illegal. That is the finding: the infrastructure for shaping machine-mediated information at scale is commercially available, and the first well-documented user of it filed the paperwork correctly.
Why FARA registration is not reassurance
It would be easy to read the legal filing as evidence that the system works. It is closer to the opposite.
FARA requires disclosure to the Justice Department. It does not require the material itself to carry any label, and it places no obligation on the platforms that ingest it. A chatbot retrieving the site's content has no access to the registration, and neither does the person reading the answer.
The disclosure regime was designed for an era when propaganda reached audiences through identifiable channels — a broadcast, a pamphlet, a named publication. It has no mechanism for material whose intended consumer is a retrieval index.
The scale problem for defenders
Producing 560,000 words in nine days costs very little now, and detecting or countering it costs a great deal.
That asymmetry is the durable finding here. Any actor willing to spend modestly can flood a narrow topic with structured, confident, machine-readable content, and no equivalent capability exists on the other side.
More from peatpost

Google Tells Android Developers to Cut Their Memory Use, or Else
Per-app limits arrive with Android 17 as a direct response to the RAM crisis — and the Play Store will enforce them.

ATF Declares a 'Major Incident' as a Ransomware Gang Claims the Hack
The compromised system held information including the targets of ATF investigations. The classification triggers notification to Congress.

Google, Microsoft and OpenAI Among 100 Firms Demanding Better Cyber Defences
An open letter warns AI-driven attacks will outpace current security 'in a matter of months' and calls the under-resourcing of critical infrastructure historic.
Discussion
0 commentsNo comments yet — be the first to weigh in.