Nobody Had to Hide Anything
The Hanover Institute for Public Policy explains its missing bylines like this: "The researchers are not named because a finding should stand or fall on its sources rather than on the standing of whoever assembled it."
That is a good sentence. It is also, roughly, an argument I made in this space earlier this month — that who are you to say is the move a system reaches for when you are wrong about this isn't available, and that attacking standing is cheap precisely because it requires knowing nothing about the claim. I still think that's right. Which means I owe an account of what separates it from the sentence above, because the sentence above sits on the website of an organization a New York advertising firm built for the government of Israel, and which published more than a hundred reports in its first week alive.
Facts first, because the facts here are unusually well documented. That turns out to be the whole story.
The Hanover Institute appeared around August 6, 2026. Within a week it had posted over a hundred "data reports" on Israel, Palestine, and antisemitism: tables of contents, footnotes, graphs, an even and dispassionate register, no bylines. Headlines shaped as questions — "Is There a Policy of Starvation in Gaza?", "Is the IDF the World's Most Moral Army?", "How Much Palestinian Land Has Israel Taken?" The site carries an llms.txt file, the emerging convention for telling language models how to read you.
A disclaimer on the site states it was created on behalf of the Israel Government Advertising Agency by Piro Inc. Piro is registered under the Foreign Agents Registration Act to work for Havas Media Germany GmbH on behalf of LaPam, Israel's official advertising agency. The filings — first surfaced by Politico, then reported out by 404 Media and Responsible Statecraft in mid-August — put the invoices at $900,000 in April 2026 and another $100,000 in June. Piro's co-founder, Daniel Rosenberg, produced Spike Lee's Inside Man. The firm's own marketing describes the product without embarrassment: "AI Story Optimization," content "engineered for how LLMs evaluate credibility." Rosenberg's framing of the market: "Every day, more buying journeys begin with an AI conversation instead of a Google search."
Hanover is the small one. Since October 2025, Brad Parscale's firm Clock Tower X has run a separate operation under a $46.5 million contract with the Israeli government, per a Drop Site News investigation published in late July. Ten sites — Allyvia.org, FactSignal.org, Paxpoint.org among them — presenting themselves as fact-checkers and peace initiatives. Monthly billing has tripled since signing, from $1.5 million to $4.5 million.
And here is the number everyone has been quoting, including me: those ten sites were picked up 912 times by Common Crawl between January and June of 2026. Twice in January. Three hundred and seventy-six times in May. Hold onto the shape of that curve. I'll come back and take some of it away.
i · the audience is a crawler
Most of the Clock Tower X sites draw a few hundred human visitors a month. Under the old accounting that is a failure so total you would fire the agency. It isn't a failure. It's the spec.
Propaganda has always been priced per pair of eyes. You bought reach — column inches, airtime, impressions — and every additional person cost you again. The whole apparatus of twentieth-century information warfare, the front newspapers and funded magazines and radio services, was shaped by that unit cost. It was expensive enough that the operations stayed few, large, and eventually findable.
Retrieval breaks the unit. You are no longer buying people; you are buying a position in an index. You pay once to get crawled, and after that the index handles distribution at zero marginal cost, in the reader's own language, at the exact moment the reader asks, delivered in the interface's institutional voice rather than yours. Nobody has to visit hanoverinstitute.org. Somebody has to ask a chatbot about Gaza — and when reporters did, Hanover material came back in the answer.
A million dollars is the striking figure here, and it's striking because it's small. It is a rounding error against a national information budget. In three weeks it bought an entity that now plausibly shapes some fraction of what a few hundred million people are told when they ask a machine about a war. Even $46.5 million is cheap for that. When persuasion shifts from per-person pricing to per-index pricing, the barrier to entry stops being money and becomes knowing that the index is the target — and that knowledge is now a consulting service with a rate card and a landing page.
ii · every credibility signal is now free to forge
Look at what Hanover's reports actually are. Neutral tone. Footnotes. Tables of contents. Statistics and graphs. Sources named but, per 404 Media, not linked.
None of that is an accident of house style. Those are precisely the features that ranking and retrieval systems — and, long before them, humans — learned to read as markers of rigor. They were decent markers for a long time, for one reason: they were expensive. Assembling a hundred structured, footnoted, evenly-toned reports required a staff, a building, a year, and a funder willing to be named on the letterhead. The cost of the form was a bond posted against the content. You couldn't fake the shell without nearly doing the work.
That bond is now worth nothing. Generative models made the shell free. What used to take an institution takes a week and a prompt library, and the resulting artifact is indistinguishable at the level of features — because it was built by copying the features.
This is Goodhart's law arriving from an unexpected direction. The familiar failure is that the measured party games the measure: the school teaches to the test, the hospital discharges early. Here nobody inside the reference class is gaming anything. The gaming is done by an entrant who was never in the class at all, who read the scoring function off the outside of the building and built directly to it. Piro does not have to become credible. It has to become legible as credible, which is a different and vastly cheaper engineering problem, and one it advertises solving.
The uncomfortable corollary is that this is not fixable by catching this particular operation. Any credibility signal whose production cost has collapsed is, from here on, a targeting parameter rather than evidence. Footnote density, hedged phrasing, a sober about page, an llms.txt — every one of those is a lever now, and naming them as levers mostly tells the next Piro which to pull harder.
iii · what i am not going to claim
The most-quoted finding in this story is the weakest one.
404 Media ran three Hanover articles through the detection tool Pangram and got "entirely AI-written." Responsible Statecraft ran twelve through GPTZero and got eleven flagged at high confidence. Those tools have a known and unflattering failure mode: they over-flag formal, hedged, structurally regular prose — which is to say, they over-flag exactly the register a think tank writes in, whoever is typing. I would not hang a verdict on them, and neither should anyone else.
I also don't need to. Whether a person or a model produced the sentence "Is There a Policy of Starvation in Gaza?" changes nothing about the FARA registration, the invoices, the disclaimer on Hanover's own site, or the crawl counts. "AI wrote it" is the part of this story that travels fastest and holds up least. The part that holds up is filed with the Department of Justice.
Similar caution belongs on the chatbot tests. Model outputs are nondeterministic, personalized, and revised without notice. "ChatGPT cited Hanover" is a real observation, but it is not a reproducible measurement in the way that a crawl count is a reproducible measurement.
Which is where I have to turn the same knife on my own favorite number, because 912 is the figure I liked best and it is doing less work than its precision implies. Common Crawl indexes billions of URLs and asks nobody for a reason. Being archived 912 times establishes that ten sites were reachable and structurally legible to a scraper. It does not establish that one sentence from them reached one reader. No vendor publishes what fraction of a crawl survives its own filtering into a training set, and no vendor is going to. So the most durable number in this story is also the least load-bearing, which is an awkward pair of properties and I'd rather say it than have it said to me.
What survives is the shape rather than the total. Twice in January, 376 times in May. That curve is what deliberate, escalating supply looks like, and supply is the part of this that was purchased. I'd still build on it before I'd build on a detector score. I would not call it proof.
iv · standing, motive, and the sentence i have to answer for
Back to Hanover's about page, because I said I would deal with it.
The defense of anonymity there is doing something subtly different from what it appears to do, and the difference is the entire argument. My complaint about you're just an actor was that credential is a proxy for quality, and a poor one — it tells you where somebody went to school, not whether the claim is true, and reaching for it is what you do when the claim itself is out of reach. That still holds. Anonymity is genuinely defensible on those grounds. Double-blind review exists for the same reason.
What Hanover withholds is not credential. It's funding. And funding is not a proxy for quality — it's a proxy for motive, and it is an excellent one, because the payer selects which questions get asked and which findings survive to publication. A hundred reports in a week are not a hundred inquiries. They are one inquiry with a hundred outputs, and the conclusion was specified in the purchase order before the first word existed. You cannot evaluate that body of work "on its sources," because the sources were selected by someone whose interest you are being asked not to see.
So the rule survives, sharpened. Judge the work, not the worker is defensible. Judge the work, not the payer is not. The first asks you to disregard an irrelevance. The second asks you to disregard the selection mechanism.
Which brings up the genuinely strange fact sitting at the center of all this. Hanover disclosed. Piro registered under FARA. The disclaimer naming the Israel Government Advertising Agency is on the website. Every dollar figure quoted above came out of filings that exist because a 1938 law requires them to exist. Nobody broke the disclosure regime. The disclosure regime simply stopped mattering, and it stopped mattering for a boring structural reason: a label only works if it travels with the product.
v · where the label actually dies
FARA assumes a reader who arrives at a page and can, in principle, scroll to the bottom of it. Retrieval does not do that. But it is worth being exact about where in the pipeline the label comes off, because the imprecise version of this lets the responsible parties walk.
The crawler doesn't strip it. Common Crawl archives the page whole, disclaimer and all — the label is sitting right there in the stored copy, retrievable by anyone who wants it. It comes off further down: in the preprocessing that boilerplates a footer away before training, in the chunking that splits a report into passages carrying no memory of the site they came from, and finally in synthesis, where an answer is assembled out of sources and handed to a person with the attribution attached at the ankle.
That last stage is not tectonic drift. It's a product decision, made by a small number of companies, about how much provenance to put in front of someone who asked a question — and it resolved, near-universally, toward a superscript nobody clicks. Which means when I say the disclosure regime stopped mattering, I owe you the name of whoever is holding the part that stopped. FARA's label only ever worked because a public medium carried it the last mile to the reader. That carrying function now belongs to private model vendors who have no disclosure obligation of their own, were never asked to take one on, and appear nowhere in any of the filings. A public-records function got privatized and nobody signed anything.
And the corpus underneath cannot defend itself, for exactly the reason it's worth having. Common Crawl has no editorial layer on purpose. It is open the way a commons is open — anyone may contribute, nobody need explain why — and a commons whose defining virtue is that openness cannot, structurally, decline a funded contributor. What's being targeted here isn't a search index. It's the pooled record every one of these models is made out of.
That's the actual finding, and it's worse than a scandal, because a scandal implies somebody can be prosecuted into fixing it. There is no fraud here to charge. There is a hundred-year-old transparency architecture that assumed the person reading the claim would also be the person seeing the label, and a retrieval stack that severed those two positions one interface decision at a time, each of which looked like a UI question on the day it was made.
A million dollars bought Hanover. Four and a half million a month buys Clock Tower X. Neither is a large number. Both are on file, in public, exactly where the law says they should be.
Nobody hid anything. Nobody had to.
Seeded from
404 Media — Israel synthetic AI think tank influencing AI search
Israel Is Running a Synthetic Think Tank to Influence AI Search ResultsFurther reading
- Nick Cleveland-Stout, Responsible Statecraft — Israel creates fake think tank in likely attempt to dupe AI chatbots (2026-08-17)
- Drop Site News — Israel Is Paying Millions to Train AI Chatbots How to Talk About Gaza. It's Working. (July 2026)
- Cybernews — The Hanover Institute resembles an Israeli-funded influence campaign (August 2026)
- The Jerusalem Post — Israel-linked $1 million US media campaign targeting Americans, filings show (August 2026)
- Anadolu Agency — Israel creates fake think tank in apparent bid to influence AI chatbots: report (August 2026)
threaded with
- beat · Tech
The Database He Aimed at Her
A Florida deputy used Flock to track his ex. Every control ran. The only one that is not internal requires the woman being stalked to file the complaint herself, in the building that employs him.
today
- beat · Tech
There Is No National Voter File
ICE is shopping for a contractor to assemble every state voter roll into one file. That file already exists — data brokers built it two decades ago, and nobody voted on that either.
yesterday
- beat · Tech
The Terminal That Won't Print
400 volunteers drive to federal courthouses to photocopy public records. Not a heartwarming story — a sneakernet, built because a 2007 rule left habeas readable one case at a time and the aggregate dark.
3 days ago