Security1 distinct publisher3 min readPublished
The Hanover Institute has pushed out more than 100 unbylined, AI-written articles in under a month: question headlines, citations that do not link, and a crawler map for the models reading it.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
The llms.txt file is the detail that decides how to read the rest of it [9]. That file is a markdown rendering of a site meant to make it cheap for a language model to scrape, so the publisher is not merely hoping to be ingested, it is catering. The same domain prints its foreign-agent disclosure in the footer of every page and files each report with the Justice Department [7][12]. Those controls work on a person who lands on the page. They do not survive summarisation, because a footer is not part of the sentence a model hands back.
Then there is the headline convention. Every Hanover article is titled as a question [4], among them "How Much Palestinian Land Has Israel Taken?" and "Is There a Policy of Starvation in Gaza?" [6]. Those are phrased the way people query a chatbot rather than the way desks write headlines, which is consistent with 404 Media's reading that the material is produced for models that continually scan the web [3].
The output rate is trivial for a content operation and hostile to review. More than 100 pieces in under a month [1], published roughly a dozen at a time every few days [2], works out above three articles a day [14]. Nobody is reading that volume adversarially.
Pangram's result also points detection at the wrong layer. Its analysis found three tested articles machine-written throughout, with only the bibliography human-authored, and the images generated too [8]. Machine drafting is not itself the defect; plenty of legitimate copy is drafted that way. The human-made part is the bibliography, which is exactly the element that signals diligence, and it is the element that cites real sources without linking to any of them [5].
The domain is also not the unit of the operation. Piro's sales page describes mapping the surfaces models read, including Reddit threads, YouTube transcripts, G2 reviews, publisher pages, forums and comparison sites, then ranking each by how much it shapes what engines say [11]. Co-founder Daniel Rosenberg's pitch on LinkedIn was that buying journeys now start in an AI conversation, and that if the models do not understand your story they will tell someone else's [10]. Piro did not respond to 404 Media's questions [13]. Blocking one think tank domain removes a single node from an inventory its operator advertises as spanning surfaces no enterprise blocklist reaches.
What that leaves is a provenance gap rather than a moderation gap. Domain reputation, byline checks and AI-text classifiers all run against artefacts that a synthesised answer discards. Until retrieval systems carry registrant and disclosure metadata through into the answer, a registered foreign agent's filing obligations and an analyst's ability to see whose material they are quoting stay in separate places.
Ranked by verification strength, evidence, and original report placement.
The Hanover Institute is run by the American advertising firm Piro Inc, paid for by Israel, and appears designed to generate content for LLMs that continually scan the internet, with the goal of tweaking chatbot answers in favour of Israel.
The Hanover Institute for Public Policy has published more than 100 articles since launching less than a month ago.
Every few days the Hanover Institute publishes around a dozen articles related to Israel, antisemitism and Palestine.
Hanover articles have no byline, often contain graphs, and cite real sources but do not link to them.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Document-heavy but single-publisher
The reporting rests on inspectable artefacts: on-site about-page text, an llms.txt file, Piro's own marketing copy and a co-founder LinkedIn post, FARA filings reviewed by the reporter including invoice amounts, and a third-party AI-detection result. That is well above assertion-level evidence. It is capped by having one publisher, a three-article detection sample out of 100+, no response from Piro, and no independent verification of the detection tool's accuracy.
Operation live, downstream uptake unmeasured
Adoption of the publishing operation itself is concrete and dated: 100+ live articles inside a month, an llms.txt file for crawlers, FARA-filed copies of each article, and a marketed commercial service behind it. What is absent is any measurement of the intended endpoint - no evidence that a crawler ingested the domain or that any chatbot or AI search answer cited or shifted because of it. Adoption is therefore scored on the supply side only.
Mechanics documented, effect asserted
The story's factual layer is carefully hedged ('appears designed to') and heavily documented, so the gap is modest rather than large. It is positive because the framing - a machine built to tweak chatbot answers in favour of Israel - runs ahead of the supplied evidence, which shows intent, infrastructure and funding but no observed change in any model's output. The three-article detection sample is also generalised to a 100+ article corpus.
State funding, vendor pitch and advocacy all in frame
Incentives are unusually explicit and disclosed on the record: a state-funded engagement routed through an official advertising agency and a European media agency with six-figure invoices, a vendor whose revenue depends on convincing clients it can shape model answers, a site with a stated policy of anonymity, and an advocacy executive quoted characterising the programme as disinformation. Each actor has a clear stake in how the material is read.
Solid documents, one voice, no rebuttal
Confidence is moderate: the checkable artefacts and regulatory filings make the core facts likely to hold, but the cluster contains a single publisher, the accused party did not comment, the detection evidence covers three of more than 100 articles, and the causal claim about chatbot answers is untested. Replication by a second outlet or a platform-side measurement would move this materially.
product
A 33% detector score beat a Berkeley professor's argument. That is a publishing problem1 distinct publisher
invest
A Connecticut judge just priced prompt injection: no fine, no e-filing2 distinct publishers
security
NPS Bought Flock. Internal Paper Says License Plate Reader; Public Statement Says Traffic Counts1 distinct publisher
build
C2PA proves who signed, not what was true: Content Credentials are provenance, not AI detection1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 25, 2026