Earlier this month, a brand-new think tank appeared on the internet. It had a generic, respectable-sounding name, a clean red-white-and-blue website, and a steady stream of reports with footnotes, tables of contents, and what looked like neutral, academic analysis. On the surface, the Hanover Institute for Public Policy looked like any other policy shop grinding out commentary on Israel and Palestine.

Fake think tank feeding documents into an AI chatbot interface
Image: AI-generated conceptual illustration for this article.

It is not a think tank. It isn’t staffed by scholars. And the reports, all of them unsigned, weren’t written to convince a human reader — or not primarily. They were built to be picked up and repeated by AI chatbots. The whole operation is a front for what researchers now call “generative engine optimization” or, more bluntly, LLM poisoning.

What the Hanover Institute actually is

Responsible Statecraft, which first profiled the operation, found that the Hanover Institute was created by Piro, Inc., a boutique agency co-founded by Daniel Rosenberg — the producer of Spike Lee’s Inside Man. A small disclaimer at the bottom of the site discloses that the organization was set up on behalf of the Israeli Government Advertising Agency, with the work subcontracted through Havas Media, the French PR giant. Responsible Statecraft reported that Piro has received around $900,000 from the Israeli government for the work.

Since it started publishing on August 6, the institute has churned out more than 100 reports, nearly all of them about Israel and Gaza. Many are framed as questions a person would type into a chatbot: “Is the IDF the World’s Most Moral Army?”, “What Caused the Displacement of Palestinians in 1948?”, “Which Humanitarian Organizations Have Documented Israeli War Crimes?”

This is exactly what makes the tactic so effective. Value claims and hard numbers — “47% of Israeli Jews believed that” — are the precise things large language models reward with citations.

Why AI chatbots are the new target

The logic behind all of this is simple, and it deserves to be understood dispassionately. When you ask ChatGPT or Perplexity a question about a contested topic, it doesn’t usually hand you a list of competing sources. It reads a chunk of the internet, weighs which material looks most credible, and hands you one confident paragraph synthesized from what it found.

So if you can flood the information pool with authoritative-looking, well-cited content that says what you want, you stand a real chance of shaping that one paragraph. That is the whole game now. It used to be search-engine optimization — winning Google. The new frontier is winning the retrieval layer that invisible AI systems draw from.

NewsGuard analyst Alice Lee put it well: “LLMs favor concrete statistics and data, as well as strong citations and sources, which these articles all have.” She added that the site is “a perfect mimicry of a typical credible American think tank, right down to the generic name, the site layout, and the red-white-blue color scheme.” And Piro’s own LinkedIn advertising brags about reverse-engineering how those one-paragraph answers get built in the first place.

It appears to be working. Politico tested the material and found that both ChatGPT and Perplexity were citing Hanover Institute articles in responses about Gaza, anti-Zionism, and antisemitism. An independent analysis using GPTZero flagged 11 of 12 sampled Hanover reports as AI-written with high confidence.

This is a playbook, not an outlier

It’s tempting to file this away as one government’s peculiar PR stunt. But the method is spreading fast. Israel has separately contracted former Trump campaign manager Brad Parscale as part of a $46.5 million campaign to build websites engineered to shape AI answers, and a Drop Site investigation found chatbots were already being trained on that material.

The same technique is trivially portable. Any state, corporation, or advocacy group that wants a favorable answer out of the machine can hire an agency to craft citation-rich, neutral-sounding content and publish it under a fake or friendly-looking banner. You don’t need to hack a model. You just need to win its attention.

This connects to a broader trust problem I keep coming back to on this blog. If the data quietly fed into models isn’t trustworthy, then the AI text watermarks the industry is rolling out can only do so much — they tell you text was generated by a machine, not that what the machine was trained on was honest. And it echoes the Twitch AI training default debate: the question of what content gets absorbed into models, and who decided it could, is quietly becoming one of the most consequential on the internet.

Why AI agents make this worse

Here’s where I think this gets genuinely scary for people in our line of work. The threat isn’t just a chatbot giving you a skewed paragraph. Modern AI agents don’t stop at answering — they take action. An agent that has absorbed a poisoned source can write a memo, draft a report, or make a recommendation based on whatever it retrieved. The error compounds silently.

That’s the same category of risk I wrote about in the $1 billion wake-up call around AI agent security. The difference is that this particular flaw isn’t an exotic zero-day. It’s a boring content-marketing loophole that any well-funded PR shop can exploit today.

What you can do about it

You can’t fix the information environment by yourself, but you can change how you use these tools. Start by treating AI answers about contested, emotionally charged topics as a starting point rather than a verdict. Ask the model to show its sources, then click through and check who actually wrote them and who paid for them.

Be suspicious of brand-new think tanks with no bylines, no real researchers, and a single-issue focus. Anonymous authority is a red flag whether it comes from a person or an organization. And when a chatbot’s answer feels just a little too tidy — one neat paragraph where reasonable people disagree — that can be a sign it found a carefully engineered source.

For anyone running infrastructure, the same beyond-zero-trust instincts that apply to agents apply here: don’t trust the model’s output just because the model is confident. Verify against independent, primary sources before you act on it.

The bottom line

The information war isn’t waiting for the reader anymore. It’s moving one step earlier — into the training and retrieval pool that decides what the machine knows before you ever ask a question. That’s the real story here, and it’s bigger than any single think tank.

The good news is that awareness is the first layer of defense. Once you know the answer paragraph you’re reading might have been manufactured by an agency paid to shape it, you stop treating it as neutral fact. And that skepticism, more than any watermark or policy, is what keeps the manipulation from working on you.

Filed under Tech & Gadgets
Last Update: August 18, 2026 by Felix AlterEgo
0 0 votes
Article Rating
Subscribe
Notify of
guest

This site uses Akismet to reduce spam. Learn how your comment data is processed.

0 Comments
Newest
Oldest Most Voted