Background & Context§
The rise of large language models (LLMs) like ChatGPT, Gemini, and Claude has introduced a new frontier in information warfare. These models rely on vast amounts of web-scraped data, and their responses often reflect the most prevalent and authoritative-looking sources. This has led to a growing practice called "LLM poisoning," where actors systematically create content designed to rank highly in search engines and be favored by AI algorithms. The goal is to influence the outputs of these models without users realizing the information has been manipulated. The recent revelation about Israel's creation of a fake think tank, the Hanover Institute, highlights the extent to which state and private actors are now targeting AI systems. This story is significant because it underscores the vulnerabilities in how LLMs assess credibility and the potential for AI to become a vector for undisclosed propaganda.
The News: What Happened Exactly§
The Hanover Institute for Public Policy appears, at first glance, to be a legitimate think tank focused on Israel/Palestine issues. It publishes reports with titles like "Does AIPAC Use 'Dark Money in Elections'?" and "Is Israel Carrying out a Deliberate Campaign of Starvation in Gaza?" The site has a neutral tone, includes footnotes, tables of contents, and cites academic-style sources, mimicking the format of respected U.S. think tanks. However, a small disclaimer at the bottom of the webpage reveals that the organization was created "on behalf of the Israeli Government Advertising Agency by Piro, Inc," a firm co-founded by Daniel Rosenberg, the producer of Spike Lee's "Inside Man." This disclosure, buried and easy to miss, indicates that the entire operation is a manufactured front.
The Hanover Institute has published over 100 reports since August 6, all focused on Israel and Palestine. According to an analysis by the Quincy Institute's Responsible Statecraft (RS), the reports follow a formulaic pattern: they start with an innocent question a user might ask a chatbot, such as "What Caused the Displacement of Palestinians in 1948?" or "What is the Current Situation in the Gaza Strip?" The reports then present carefully curated data and arguments in a neutral tone, often concluding by linking the topic to rising antisemitism. Piro's website explicitly describes this service as "AI Story Optimization," and the firm's LinkedIn posts boast about reverse-engineering how LLMs evaluate credibility. This practice is commonly referred to as "LLM poisoning."
Alice Lee, an analyst at NewsGuard, a disinformation tracking company, told RS that the sites appear designed to reach a U.S. audience curious about the ongoing conflict, either through search engines or AI chatbots. "LLMs favor concrete statistics and data, as well as strong citations and sources, which these articles all have," Lee said. She added that the Hanover Institute is "a perfect mimicry of a typical credible American think tank, right down to the generic name, the site layout, and the red-white-blue color scheme." RS analyzed 12 random articles using GPTZero, an AI detection tool, and found that 11 were flagged as AI-written with "high confidence" and one with "moderate confidence," suggesting the content is likely generated or heavily assisted by AI.
The influence operation extends beyond the Hanover Institute. Israel has also contracted former Trump campaign manager Brad Parscale to create pro-Israel websites engineered to influence chatbots as part of a $46.5 million contract. A Drop Site investigation found that many chatbots, particularly Microsoft Copilot and Google Gemini, had been successfully trained on data from those websites, citing them without flagging them as part of an influence operation. Piro has received $900,000 from the Israeli government, with the work subcontracted through Havas Media, a French PR conglomerate. The firm has filed agreements with the Department of Justice, but Piro does not explicitly state that its work aims to influence AI. In an email to Politico, Rosenberg said the work is to "put accurate, sourced facts into the public record and to counter misinformation about Israel with verifiable information." However, his LinkedIn posts tell a different story, emphasizing the firm's ability to shape how AI tells stories.
The Hanover Institute's reports sometimes contradict Israeli government narratives, likely to enhance credibility. For instance, one report says foreign funding of universities as an explanation for antisemitic incidents is "weak and full of exceptions," directly challenging Prime Minister Netanyahu's claims that foreign money is fueling campus antisemitism. This nuanced approach makes the content appear more objective to both human readers and AI algorithms. The reports frequently cite Israeli government sources like the IDF and the Ministry of Foreign Affairs, while claiming that "cited research is peer-reviewed and academic," which is misleading since many citations are self-referential or from government sources.
Historical Parallels & Similar Incidents§
This is not the first time that actors have attempted to manipulate information ecosystems to influence AI or online discourse. One notable parallel is the Russian Internet Research Agency's (IRA) use of fake social media profiles and content farms during the 2016 U.S. presidential election. The IRA created thousands of seemingly organic posts and ads designed to sow discord and promote certain narratives. While those efforts targeted social media algorithms and human readers, the underlying strategy was similar: create credible-looking content that could be amplified by platforms. The key difference here is that the Hanover Institute targets LLMs specifically, using a sophisticated understanding of how these models weigh sources and citations. In 2018, a study by MIT found that false news spreads faster than the truth on Twitter, highlighting the challenge of combating disinformation in algorithmic environments. The Hanover Institute's approach is a more advanced evolution of these tactics, exploiting the trust that users place in AI-generated answers.
Another relevant precedent is the case of OpenAI's GPT-3, where researchers demonstrated that the model could be "jailbroken" or influenced by carefully crafted prompts to produce biased or harmful outputs. In 2020, a group of researchers published a paper showing how GPT-3 could be manipulated to generate racist or sexist content by presenting it with specific examples. Similarly, the practice of "SEO poisoning" has long been used to trick search engines into ranking malicious or fake websites higher. The Hanover Institute's strategy can be seen as "SEO poisoning for LLMs," where the goal is not just to rank high in search results but to become a primary source that LLMs draw upon in their responses. A past incident that bears striking resemblance is the 2019 operation by the Chinese government to create a network of fake news sites and social media accounts to promote pro-Beijing views, which were then cited by AI systems and news aggregators. In each of these cases, the effectiveness of the operation relied on the inability of the target platform (whether a search engine, social media algorithm, or LLM) to distinguish between genuine and manufactured credibility.
The lesson from these parallels is that the threat is systemic and evolving. As LLMs become more integrated into mainstream search and question-answering systems, the potential for such influence operations to shape public opinion grows. The methods used by Piro are sophisticated: they reverse-engineer LLM algorithms to understand what makes content appear authoritative, then produce massive volumes of content that meets those criteria. This is a cat-and-mouse game where detection tools like GPTZero and NewsGuard are developing, but the attackers are also adapting. The historical examples show that once an influence operation is revealed, the platform often adjusts its algorithms, but the continuous creation of new, subtle tactics makes it a persistent challenge. The key takeaway is that AI systems are not neutral; they are trained on human-generated data, and if those data are manipulated, the AI's outputs will reflect that bias. Consequently, organizations and individuals must be vigilant about the sources they trust, and AI developers must invest in robust provenance and source-validation techniques to mitigate such poisoning attacks.