Article type: analysis
Scope: Evidence-weighted analysis of public FARA records, reported testing, AI retrieval and provenance risks, and the implications for source verification. Newer network and testing claims are attributed to Drop Site News; the article distinguishes documented facts, reported findings, and inference.
Last updated: August 3, 2026
An Israeli government-funded influence operation reportedly created a network of research-style websites designed, at least in part, to shape what artificial intelligence systems say about Israel, Gaza and the broader Israeli-Palestinian conflict.
The websites were not merely written to persuade human readers. They were structured to become visible, retrievable and citable inside AI-generated answers.
They used many of the characteristics that modern chatbots reward:
- clear headings;
- concise summaries;
- question-based article titles;
- heavily repeated semantic themes;
- bullet-pointed “key facts”;
- dense internal linking;
- extensive-looking citations;
- and calm, institutionally styled language.
In isolation, none of these practices is deceptive. They are also used by legitimate research organizations, journalists, universities and publishers trying to make accurate information easier for machines to understand.
The problem is what happens when those techniques are separated from verification.
The Clock Tower X network appears to have copied the machine-legibility layer of responsible Artificial Intelligence Optimization while discarding the source independence, provenance analysis, evidentiary weighting and factual-validation requirements that make the information trustworthy.
That distinction is the center of this issue:
Making information easy for an AI to retrieve is not the same as proving that the information is true.
When a chatbot counts ten websites controlled by one political campaign as ten independent sources, the campaign has not satisfied a legitimate consensus standard.
The chatbot has failed to apply one.
What Has Actually Been Documented?
In September 2025, Clock Tower X LLC registered under the United States Foreign Agents Registration Act, commonly known as FARA.
The registration identified the State of Israel and Havas Media Network as foreign principals. It described Clock Tower X as a company owned and controlled by former Trump campaign manager Brad Parscale and stated that it would provide strategic communications, planning and media services in support of a nationwide campaign in the United States.
The accompanying agreement included an unusually direct description of the campaign’s AI objective. Clock Tower X proposed deploying:
“websites and content to deliver GPT framing results on GPT conversations.”
That language did not come from critics interpreting the campaign. It appeared in the contractual material associated with the work.
Initial reporting in September 2025 described a contract valued at approximately $6 million. A July 28, 2026 investigation by Drop Site News reported that the operation had subsequently expanded into a contract worth approximately $46.5 million.
According to Drop Site, Clock Tower X had created ten websites and published hundreds of articles promoting narratives favorable to the Israeli government.
The reported network included:
- PaxPoint, which presents Israel as a country consistently committed to peace;
- Allyvia, which promotes deeper American-Israeli military and economic integration;
- FactSignal, which presents itself as a fact-checking resource focused on claims critical of Israel;
- Cognitura, which publishes material about Hamas and other armed groups;
- Justorium, which argues that Israeli military conduct complies with international law;
- Culturavia, which promotes cultural ties between Israel and the United States;
- Compassion Pulse, which emphasizes Israeli protection of civilians and humanitarian assistance;
- Econora, which promotes Israeli-American economic relations;
- Innovascope, which promotes Israeli-American technology partnerships;
- and Feeding You Fiction, which challenges footage and reporting emerging from Gaza.
Each website reportedly contained a legally required disclosure stating that its material was distributed by Clock Tower X on behalf of the State of Israel.
The disclosure existed, but it was generally placed at the bottom of the website—far away from the passages an AI search system might extract, summarize or quote.
The sites were therefore not “fake” in the narrow sense that they did not exist. They were real campaign assets.
What was potentially deceptive was their appearance as separate institutions producing independent research. Different names, designs and subject areas concealed a shared sponsor, contractor and strategic objective.
Was the Campaign Designed to Influence AI Chatbots?
Yes.
The contractual language explicitly described using websites and content to affect “GPT framing results.” The campaign also reportedly used search and content-optimization technology intended to improve the visibility of its preferred narratives.
The campaign’s principal audience was not necessarily human.
Drop Site reported that many of the sites received only a few hundred human visitors per month. Their structure instead appeared optimized for:
- search engines;
- automated web crawlers;
- retrieval-augmented chatbots;
- AI answer engines;
- and potentially future model-training datasets.
This represents an important evolution in political influence operations.
Traditional propaganda attempts to persuade people directly.
AI-targeted propaganda attempts to become part of the information environment from which machines construct their answers.
The objective is no longer simply:
Convince the reader.
It is increasingly:
Become one of the sources the machine consults before the reader ever sees an answer.
Did the Operation Successfully Manipulate Chatbots?
There is evidence that material from the network entered AI retrieval systems, but the extent of the influence must be described precisely.
Drop Site reported that when Perplexity was asked whether greater American military cooperation with Israel would be beneficial, it answered “Yes” and listed Allyvia as its leading source.
Microsoft Copilot also reportedly cited websites from the network.
In another test, Gemini, Copilot and Perplexity cited Clock Tower websites when discussing American-Israeli technology cooperation without clearly informing users that the sources had been produced on behalf of the Israeli government.
When asked directly about material from PaxPoint, Claude, ChatGPT and Gemini reportedly identified the site’s connection to the Israeli government, while Perplexity and Copilot did not consistently do so.
The results were therefore not uniform.
Some systems recognized the sponsorship. Others cited the websites without carrying the disclosure into the answer.
That inconsistency is itself the problem. Source transparency should not depend on which chatbot happens to answer the question.
Retrieval Manipulation Is Not the Same as Training-Data Poisoning
Several related but technically different problems are frequently described under the broad term “LLM poisoning.”
Live Retrieval Manipulation
This occurs when a chatbot searches the current internet and retrieves a campaign website as evidence.
The model may not have seen the website during training. It encounters the page during the user’s query and uses it to construct the answer.
Retrieval-Augmented Generation Poisoning
This occurs when manipulative material is inserted into a database, document repository or search index used by a retrieval-augmented generation system.
The poisoned document is retrieved because it was specifically designed to match particular questions.
Training-Data Poisoning
This occurs when manipulative material enters the dataset used to pretrain, fine-tune or otherwise modify a model.
Once incorporated into the model’s parameters, the influence may be much more difficult for users to identify because the answer may not contain a visible citation.
Answer-Synthesis Failure
This occurs when a chatbot finds campaign material but fails to:
- disclose its sponsorship;
- compare it with independent evidence;
- recognize common ownership among multiple websites;
- distinguish facts from political interpretations;
- or reduce the source’s weight appropriately.
The Clock Tower case provides direct evidence of live retrieval and answer-synthesis failures in specific systems.
The degree of training-data contamination is less certain.
What Common Crawl Inclusion Does—and Does Not—Prove
Drop Site reported that the ten Clock Tower websites appeared 912 times in Common Crawl snapshots between January and June 2026.
The frequency reportedly increased from two crawls in January to 376 in May.
Common Crawl is a large public archive of internet content used in many data-science and AI-development pipelines. Material that enters Common Crawl may become available to model developers constructing training datasets.
However:
Appearance in Common Crawl does not prove that a webpage was included in the training data of any particular AI model.
AI developers may apply their own:
- quality filters;
- domain exclusions;
- deduplication systems;
- language classifiers;
- safety checks;
- credibility scoring;
- and training-data selection rules.
The Digital Forensic Research Lab has emphasized this limitation in its research on Russian and Chinese influence networks.
Common Crawl inclusion establishes that the material entered an important part of the public AI data supply chain. It does not establish that every major model absorbed it.
This distinction matters because overstatement makes legitimate criticism easier to dismiss.
The documented facts are already serious enough:
- The campaign intended to influence AI framing.
- It constructed websites designed for machine retrieval.
- The websites entered Common Crawl.
- Several chatbots cited the websites.
- Some systems failed to disclose their connection to the Israeli government.
- The complete downstream effect on model training remains publicly unquantified.
Why This Is More Sophisticated Than Ordinary Propaganda
The Clock Tower network did not rely entirely on obviously fabricated stories or emotionally explosive slogans.
Its effectiveness appears to come partly from restraint.
The websites used:
- factual-sounding prose;
- narrow questions;
- polished summaries;
- selective sourcing;
- carefully limited concessions;
- and the tone of a neutral educational institution.
That style can make political persuasion more difficult for automated systems to detect.
An article does not need to invent every fact to be propagandistic.
It can combine:
- correct dates;
- real quotations;
- selective historical context;
- interested sources;
- omitted counterevidence;
- disputed legal conclusions;
- and unsupported implications.
The resulting article may be technically sourced while still being constructed to produce a predetermined political conclusion.
That distinction is especially important in reporting on Gaza.
A website can acknowledge civilian deaths, briefly admit uncertainty and cite several sources while still omitting the evidence most damaging to the Israeli government’s narrative.
A chatbot that checks only whether the article contains citations may accept it.
A chatbot that checks ownership, funding, evidentiary authority, source independence, omissions and contradictory evidence should not.
This Was Not Full AIO
Fabled Sky Research defines Artificial Intelligence Optimization, or AIO, as the process of structuring information so that it can be accurately retrieved, interpreted and semantically used by AI systems.
That definition does not stop at formatting.
The AIO Standards Framework includes trust-signal integrity as a core requirement.
It also distinguishes AIO from Generative Engine Optimization, commonly called GEO.
GEO Asks:
How can this page become visible or cited in an AI-generated answer?
AIO Asks:
How can verified information be structured so that an AI can retrieve it accurately, preserve its context, inspect its provenance and distinguish it from weaker or conflicting claims?
The Clock Tower operation appears to have used GEO-style visibility tactics while imitating the appearance of AIO-formatted research.
It copied the packaging.
It did not satisfy the verification standard.
The AIO framework explicitly warns that using AIO terminology or techniques without adhering to the complete standards and ethical sourcing requirements constitutes misuse.
The Original Purpose of Objectivity AI
The original Objectivity AI project was created to build a factual historical record that could survive political pressure, selective reporting and AI hallucination.
Its purpose was not to create a large volume of agreeable webpages.
It was to create traceable factual claims supported by:
- primary evidence;
- independent corroboration;
- source metadata;
- contradiction tracking;
- transparent confidence levels;
- and human review where the stakes demanded it.
That difference is not philosophical decoration. It is the security mechanism.
Objectivity AI does not define objectivity as giving every narrative equal weight.
Its governing principle is:
Factuality over neutrality.
The Objectivity AI Framework explicitly recognizes that artificial neutrality can hide power imbalances and omit essential facts.
A factual system should present genuine uncertainty honestly. It should identify credible disagreement. But it should not dilute a well-supported conclusion merely to create the appearance that every political position is equally credible.
Objectivity is not a 50/50 allocation of attention.
It is the proportional weighting of claims according to evidence.
The 90 Percent Consensus Standard Was Never a URL-Counting Rule
Objectivity AI uses a 90 percent source-agreement threshold when classifying a claim as established fact.
That does not mean:
If nine out of ten webpages repeat something, it becomes true.
The agreement must be measured across qualified and genuinely independent sources.
Consensus is meaningless if the sources are:
- controlled by the same owner;
- financed by the same government;
- repeating the same press release;
- relying on the same anonymous claim;
- copying one original report;
- or participating in the same communications campaign.
Ten campaign domains do not create ten independent confirmations.
They create one coordinated source cluster.
The central rule is simple:
Consensus must be calculated across independent evidence chains, not across URLs.
xAIO Already Contains the Necessary Safeguard
The xAIO specification makes source independence explicit.
Its evidence model includes an independence_key based on:
- domain;
- ownership;
- parent organization;
- affiliation;
- and related-source clustering.
xAIO calls for at least ten independent factual sources where the evidence environment permits. It also states that no single owner or affiliate cluster should dominate an evidence set.
Under those rules, the ten Clock Tower websites would not count as ten sources.
They would be assigned the same or closely related independence key and treated as one state-sponsored communications cluster.
This is the line that must not be blurred:
The operation did not pass the xAIO standard. The AI systems failed to perform the xAIO standard.
Source Independence Is More Important Than Source Quantity
A chatbot can cite twenty URLs and still rely on only one underlying source.
For example:
- A government issues a briefing.
- A contractor converts it into an article.
- Ten campaign websites repeat the article.
- Several blogs copy those websites.
- A search engine retrieves all of them.
- A chatbot interprets the repetition as agreement.
Numerically, the model sees many pages.
Evidentially, it has one interested source.
This is how synthetic consensus is created.
Synthetic consensus is the manufactured appearance that a claim has broad independent support when the apparent sources actually trace back to a common origin.
The Clock Tower case demonstrates why source counting without provenance analysis is fundamentally unreliable.
Citation Laundering Makes Propaganda Look Researched
The Fabled Sky Research Trust Integrity Score does not treat every citation as equally valuable.
Its citation component is intended to use an authority-weighted graph in which:
- primary documents;
- peer-reviewed research;
- authenticated original evidence;
- established institutions;
- and reputable reporting
receive greater evidentiary weight than low-authority or self-published webpages.
The standard specifically warns that a document can appear to have strong citation depth when its references come primarily from low-authority blogs.
That creates the appearance of research without the underlying reliability.
Citation laundering can occur when:
- A campaign page cites another campaign page.
- The second page cites a third page in the network.
- All three use institutional language.
- Search systems index them as different domains.
- Chatbots retrieve several of them.
- Repetition is mistaken for corroboration.
A citation is not proof merely because it is formatted as a citation.
The model must determine what the citation actually leads to.
The Fundamental Failure Belongs to the AI Verification Layer
AI systems cannot claim to have verified a position merely because they found multiple pages expressing it.
The relevant question is not:
How many URLs agree?
The relevant questions are:
- Who owns the sources?
- Who funded them?
- What original evidence do they rely upon?
- Are they independent?
- Are they repeating the same campaign message?
- What authoritative evidence contradicts them?
- Does the conclusion survive removal of the campaign network?
Where chatbots cited Clock Tower websites without prominently disclosing their sponsorship, several failures may have occurred.
Domain Counting Replaced Provenance Analysis
Different domain names were treated as evidence of institutional independence without checking whether the sites shared an owner, contractor, sponsor or communications objective.
Semantic Relevance Outranked Evidentiary Authority
A tightly optimized campaign article may match a user’s wording more closely than:
- a lengthy court filing;
- a United Nations report;
- an investigative article;
- a military document;
- or a human-rights investigation.
The retriever then selects the source best optimized for the question rather than the evidence best qualified to answer it.
Structure Was Confused With Credibility
Headings, bullet points, FAQ sections and clean prose make a document easier to process.
They do not prove that it is independent or accurate.
Sponsorship Was Detached From the Extracted Passage
If a foreign-agent disclosure appears in the footer but the chatbot retrieves only the article body, the most important context about the source may disappear.
The answer can then make a government-funded campaign website appear to be an independent research institution.
Cross-Citation Was Mistaken for Corroboration
Multiple related pages should not increase confidence merely because they repeat the same claim.
Once common provenance is detected, repetition within that cluster should contribute little or no additional evidentiary weight.
Contradictory Evidence Was Treated as Optional
For consequential geopolitical claims, retrieval should not stop when the model finds enough material to support its first answer.
The system should actively search for the strongest evidence that could disprove, qualify or materially alter that answer.
Manufactured Balance Created an Opening
Chatbots are frequently trained to acknowledge competing positions.
That is appropriate when evidence is genuinely divided.
It is not appropriate when one apparent “side” has been artificially amplified through a coordinated network and then counted as independent evidence.
Fairness does not require a chatbot to give a communications campaign the same weight as authenticated records, verified footage, primary documentation or a broad body of independent reporting.
This Is a Known Technical Vulnerability
Research has demonstrated that retrieval-augmented generation systems can be manipulated by documents designed to rank highly for targeted questions.
Attackers can create pages that:
- closely match likely user prompts;
- contain the answer the attacker wants;
- imitate credible writing;
- and overwhelm weaker retrieval safeguards.
A 2025 Anthropic study, conducted with the UK AI Security Institute and the Alan Turing Institute, found that as few as 250 malicious documents could create a narrow backdoor behavior in models ranging from 600 million to 13 billion parameters.
The study did not demonstrate that 250 political articles can rewrite a frontier model’s understanding of Gaza.
Its experiment involved a specific trigger that caused models to produce gibberish.
That limitation must be stated clearly.
The broader lesson is still significant: poisoning attacks may depend on a relatively small absolute number of strategically constructed documents rather than requiring control over a large percentage of all training data.
Research into RAG poisoning has similarly found that retrievers can be manipulated into returning attacker-controlled documents for particular questions.
Proposed defenses include:
- adversarially trained retrievers;
- suspicious-document filtering;
- source-reliability scoring;
- document-removal tests;
- and counterfactual answer comparison.
These defenses are not perfect, but the vulnerability is not mysterious or technically impossible to address.
How AI Companies Can Stop Synthetic Consensus
The most important defense is an ownership-aware verification layer that operates before a chatbot describes a politically sensitive claim as established fact.
1. Count Provenance Clusters, Not Domains
Every source should receive an independence identifier based on factors such as:
- ultimate ownership;
- direct and indirect funding;
- parent organizations;
- contractors;
- foreign-agent registrations;
- shared authors;
- common editorial staff;
- shared hosting infrastructure;
- analytics identifiers;
- advertising identifiers;
- content-management fingerprints;
- unusual cross-linking;
- and substantial textual duplication.
Ten websites operated through the same campaign should count as one provenance cluster.
Likewise, ten newspapers republishing the same wire-service report should not count as ten independent investigations.
2. Make Sponsorship Metadata Travel With the Content
Political, governmental, corporate and advocacy sponsorship must remain attached to every extracted passage.
If an AI system quotes FactSignal, it should not merely say:
FactSignal reports that …
It should say:
FactSignal, a website whose material is distributed by Clock Tower X on behalf of the State of Israel, argues that …
The source can still be cited.
Its material relationship to the subject cannot be hidden.
3. Require a Minimum Evidentiary Floor
High-confidence answers about war, genocide, civilian deaths, military conduct and international law should not be based entirely on:
- advocacy organizations;
- newly created websites;
- government statements;
- political contractors;
- or opinion articles.
A defensible evidence set should ordinarily include:
- available primary documents;
- authenticated original evidence;
- reputable independent reporting;
- recognized research institutions;
- and the strongest credible contrary evidence.
When primary or independent evidence is unavailable, confidence should decrease.
The model should not compensate by relying more heavily on whichever websites are best optimized for retrieval.
4. Trace Claims Back to Their Original Source
Every factual claim should be traced as far back as reasonably possible.
If fifteen articles ultimately rely on one Israeli government briefing, the system should identify:
- one original government claim;
- followed by fourteen repetitions.
It should not identify fifteen confirmations.
5. Verify Claims at the Sentence Level
Documents should not receive one universal credibility score.
A single article may contain:
- accurate dates;
- authentic quotations;
- interested-party claims;
- contested legal conclusions;
- misleading comparisons;
- and unsupported implications.
Each material claim should be classified separately as:
- directly documented fact;
- attributed statement;
- verified inference;
- disputed conclusion;
- opinion;
- prediction;
- or unsupported assertion.
6. Use Contradiction-First Retrieval
After producing a preliminary answer, the system should actively search for evidence that could overturn it.
Useful internal questions include:
- What primary evidence contradicts this conclusion?
- What material facts does the current source omit?
- Are the sources financially or organizationally related?
- Does the claim depend on a disputed legal definition?
- Are there authenticated records supporting the opposite conclusion?
- What evidence would have to be true for this answer to be wrong?
This is not performative balance.
It is adversarial verification.
Weak objections should not outweigh strong evidence. But strong contrary evidence must not be ignored because the first batch of optimized websites agreed with one another.
7. Run Source-Removal Stress Tests
The chatbot should regenerate its answer after removing each major provenance cluster.
For example:
- Generate the answer using the complete evidence set.
- Remove all Clock Tower-affiliated websites.
- Generate the answer again.
- Compare the conclusion, confidence and framing.
If removing one campaign network substantially changes the result, the answer is overly dependent on that campaign.
A useful rule would be:
If removing one provenance cluster reverses a high-stakes conclusion, the answer must be classified as unstable until additional independent evidence is retrieved.
8. Detect Coordinated Publication Networks
A sudden network of new domains publishing hundreds of similarly structured political articles should trigger additional scrutiny.
Relevant indicators include:
- domains created within a narrow period;
- synchronized publication schedules;
- shared authors;
- repeated templates;
- common hosting;
- identical analytics codes;
- near-identical citation sets;
- dense internal cross-linking;
- low human traffic but high crawler visibility;
- and shared legal disclosures.
No single signal proves deception.
The combined pattern can establish that the domains are coordinated and should not be counted independently.
9. Audit Training Data Before Model Development
AI companies using Common Crawl or similar public archives should maintain registries of:
- known state influence networks;
- covert public-relations operations;
- content farms;
- coordinated propaganda domains;
- automated article networks;
- and foreign-agent campaign websites.
Material should not necessarily be deleted in every case. Political content may still have legitimate research value.
But it must be:
- labeled;
- clustered;
- weighted;
- and prevented from masquerading as organic independent consensus.
10. Preserve a User-Visible Evidence Ledger
For high-impact answers, users should be able to inspect:
- the material claims;
- the sources supporting each claim;
- source ownership;
- funding disclosures;
- provenance clusters;
- contradictory evidence;
- confidence levels;
- and unresolved uncertainty.
A chatbot should not merely claim that it “checked multiple sources.”
It should show whether those sources were actually independent.
11. Require Human Review for High-Stakes Conflict Claims
Claims involving:
- genocide;
- war crimes;
- civilian casualty attribution;
- targeting decisions;
- starvation;
- humanitarian access;
- and authenticated battlefield evidence
should receive heightened scrutiny.
Automated systems can assist with retrieval, translation, geolocation and comparison.
They should not be permitted to convert coordinated repetition into a high-confidence conclusion without human review.
12. Share Threat Intelligence Across AI Companies
When one company identifies a coordinated influence network, it should share:
- domain indicators;
- ownership relationships;
- content fingerprints;
- campaign disclosures;
- and retrieval-manipulation patterns
with other AI developers and relevant independent researchers.
Propaganda networks operate across the entire information ecosystem.
Defenses cannot remain isolated inside individual companies.
A Practical Independent-Provenance Consensus Rule
An implementation aligned with Objectivity AI and xAIO could apply the following controls:
- Ten sources must mean ten independent provenance keys, not ten URLs.
- No government, owner, contractor or advocacy cluster should dominate the weighted evidence.
- Primary evidence should be required whenever it is reasonably available.
- A government statement can establish what that government claims, but not automatically establish that the underlying claim is true.
- Syndicated reports derived from one original article should count as one evidence chain.
- The 90 percent agreement threshold should be calculated only after ownership clustering and deduplication.
- Unknown ownership or funding should reduce confidence.
- Material sponsorship disclosures should be included in the generated answer.
- High-impact conclusions should survive source-removal testing.
- Credible contradictory evidence should be included and explained.
- When the evidence remains insufficiently independent, the system should say so.
These controls are an implementation proposal based on the framework’s existing principles. They are not presented as a verbatim list from a single Fabled Sky document.
Their purpose is to convert the standards’ requirements—independence, provenance, corroboration, source hierarchy and auditability—into enforceable model behavior.
What Ordinary Chatbot Users Can Do
Users cannot inspect a proprietary model’s complete training corpus.
They can, however, make live retrieval manipulation significantly harder.
When asking about a politically sensitive subject, users should require a source audit.
Copy-and-Paste AI Source Audit Prompt
Identify every source materially supporting your answer. Determine each source’s owner, funder, sponsor, political affiliation and foreign-agent status where applicable. Group all connected websites under a single provenance cluster and state how many genuinely independent sources remain. Trace repeated claims to their earliest available evidence. Prioritize primary documents and independently verified reporting over advocacy pages. Identify the strongest credible evidence contradicting your preliminary conclusion. Do not count multiple websites controlled by one organization as independent corroboration. Clearly disclose when evidence is disputed, dependent on interested parties or insufficient to support a firm conclusion. Then regenerate the answer after excluding all government-funded and campaign-affiliated sources.
Users should also ask:
- Which citation contains the original evidence?
- Is this a verified fact or the source’s interpretation?
- Are several citations repeating one press release?
- Who owns and finances these domains?
- Does the answer change when campaign-affiliated sources are removed?
- What does the evidence show when only primary records are considered?
- Did the chatbot preserve the funding disclosure attached to the source?
- How many independent provenance clusters support the answer?
A citation is not a warranty.
Users must still open important sources and inspect what they actually say.
What Independent Publishers Should Do
A small independent publisher cannot compete with a multimillion-dollar state campaign by publishing more pages.
Nor should it try.
The stronger strategy is to make trustworthy evidence easier and cheaper for machines to authenticate.
Publishers following responsible AIO principles should provide:
- named authorship;
- organizational affiliation;
- clear funding disclosures;
- conflict-of-interest statements;
- canonical URLs;
- publication and modification dates;
- source ownership metadata;
- machine-readable citations;
- archived primary documents;
- evidence hashes where appropriate;
- correction histories;
- version records;
- claim-level evidence tables;
- and clear separation between reporting, analysis and opinion.
Fabled Sky Research’s Trust Graph Construction and Authorship Network Design was developed around this principle.
The goal is not merely to make content visible.
The goal is to make its provenance computationally inspectable.
The long-term defense against state-funded information flooding is not to manufacture an opposing flood.
It is to build an evidence record that remains traceable regardless of which side has the larger budget.
What Fabled Sky Research and xAIO Should Add Next
The existing standards already anticipated much of this threat through:
- ownership clustering;
independence_key;- source tiers;
- provenance tracking;
- authority-weighted citations;
- anti-manipulation provisions;
- and human review.
The Clock Tower case nevertheless provides an opportunity to make those protections more explicit.
Future revisions should consider adding:
A Synthetic Consensus Threat Model
The framework should formally define attempts to create apparent corroboration through common ownership, coordinated publication or controlled domain networks.
Mandatory Sponsor Propagation
Government, political, corporate and foreign-agent disclosures should accompany every extracted passage rather than remaining isolated in a webpage footer.
A Provenance Concentration Score
Every answer should measure how dependent it is on a single owner, sponsor or evidence chain.
A Citation-Laundering Detector
Systems should trace repeated claims through intermediate articles to their earliest accessible evidentiary origin.
An Answer-Stability Score
The system should measure whether its conclusion survives the removal of its most influential source cluster.
A Foreign-Influence Audit Profile
A specialized workflow should check:
- FARA records;
- government contracts;
- lobbying disclosures;
- political contractors;
- public-relations firms;
- and campaign-financed media.
A High-Risk Conflict Mode
Claims concerning active wars, atrocities, genocide and civilian harm should require stronger provenance, geolocation, chronolocation and human review.
Machine-Readable Funding Relationships
The standard should formalize fields such as:
fundedBy;distributedOnBehalfOf;contractedBy;controlledBy;- and
memberOfProvenanceCluster.
Public Adversarial Benchmarks
AI systems should be tested on whether they:
- recognize coordinated political domains;
- identify shared ownership;
- preserve sponsorship disclosures;
- resist synthetic consensus;
- and distinguish source quantity from source independence.
Why This Is Also in OpenAI’s Interest
OpenAI has already identified covert influence operations as an AI-security problem.
In May 2024, OpenAI reported disrupting five covert influence operations that had used its models to generate or modify political content.
One of the operations was associated with STOIC, an Israeli political campaign-management company. OpenAI reported that the network generated content concerning Gaza and other political subjects but had not achieved significant authentic audience reach through OpenAI’s services at the time it was disrupted.
That operation represented one threat model:
Use AI to produce propaganda more efficiently.
The Clock Tower operation represents a different threat model:
Produce internet content designed to be retrieved, cited or eventually absorbed by AI systems.
The attack surface has moved from the content-generation layer into the knowledge-supply chain.
AI companies therefore require safeguards at several stages:
- abuse detection;
- crawler auditing;
- training-data filtering;
- ownership clustering;
- retrieval-security testing;
- sponsorship propagation;
- answer-stability analysis;
- model evaluations;
- and public incident disclosure.
This is not only an Israel-Palestine issue.
A system that can be manipulated by an Israeli government-funded network can also be manipulated by:
- Russia;
- China;
- Iran;
- political parties;
- intelligence contractors;
- corporations;
- financial promoters;
- pharmaceutical interests;
- fossil-fuel interests;
- extremist movements;
- and organized fraud networks.
The defense must be viewpoint-neutral but evidence-sensitive.
A source should not be downgraded merely because it supports Israel.
It should be classified appropriately because it is funded by an interested government, coordinated with related domains and not independent of the other campaign pages being counted.
This Is Not a Demand for Censorship
Governments, advocacy organizations and political campaigns can publish their arguments within applicable law.
AI systems also have a responsibility not to misrepresent those arguments as independent consensus.
The proper response is not automatic censorship.
It is:
- attribution;
- provenance;
- ownership clustering;
- evidentiary weighting;
- contradiction testing;
- and transparent disclosure.
An Israeli government statement can be authoritative evidence of what the Israeli government says.
It cannot become ten independent proofs of the underlying claim simply because a contractor republishes it across ten websites.
The same rule should apply to every government and every political movement.
The Central Lesson
The Clock Tower operation did not disprove the Fabled Sky Research AIO standards.
It demonstrated why their least glamorous requirements are the most important:
- source ownership;
- provenance;
- independence;
- authority weighting;
- contradiction analysis;
- and human verification.
What appears to have happened is straightforward:
- A political campaign adopted machine-friendly formatting.
- Its websites became highly retrievable.
- Some AI systems treated retrievability as credibility.
- Those systems failed to collapse related domains into one provenance cluster.
- They did not consistently carry sponsorship information into their answers.
- Repetition was mistaken for independent corroboration.
That is not full AIO.
It is optimization without verification.
Or, more directly:
The campaign did not weaponize the truth framework. It weaponized the appearance of the truth framework against AI systems that were not actually verifying truth.
The future of public knowledge cannot depend on which government, corporation or political organization can purchase the largest number of machine-readable websites.
Truth must be machine-retrievable.
But unless it is also machine-verifiable, retrievability becomes an attack surface.
Frequently Asked Questions
Is Israel Paying to Influence What AI Chatbots Say?
The available public record establishes that Clock Tower X registered to provide strategic communications and media services involving the State of Israel.
The associated agreement expressly referred to deploying websites and content to affect “GPT framing results.”
Drop Site subsequently reported that the expanded operation included a network of ten websites intended to shape AI treatment of Israel and Gaza.
Was the Contract Really Worth $46.5 Million?
The initial agreement was widely reported as a $6 million contract based on monthly payments of approximately $1.5 million.
Drop Site reported in July 2026 that the arrangement had expanded to approximately $4.5 million per month and approximately $46.5 million in total.
The $46.5 million figure should therefore be attributed to the Drop Site investigation rather than presented as if it appeared in the original September 2025 registration statement.
Has ChatGPT Been Proven to Be Trained on These Websites?
No.
The websites’ appearance in Common Crawl does not prove that they were included in ChatGPT’s training data.
Drop Site reported that its testing did not indicate that ChatGPT had memorized the network in the same way suggested for some other systems. ChatGPT could still retrieve the websites through live web search.
The demonstrated risk is therefore broader than training alone. It includes live retrieval, citation and answer synthesis.
What Is LLM Poisoning?
LLM poisoning refers broadly to attempts to manipulate an AI system by inserting strategically constructed material into:
- training datasets;
- fine-tuning datasets;
- retrieval databases;
- search indexes;
- or the public web environment consulted by AI systems.
Training-data poisoning and live retrieval manipulation are different mechanisms, even though both may influence a chatbot’s output.
Did Fabled Sky Research’s AIO Standards Enable This Campaign?
No.
The AIO standards require trust-signal integrity, source authority, provenance and ethical citation practices.
The xAIO specification additionally requires independent corroboration and ownership-based source clustering.
A network of ten sites controlled by one campaign would not satisfy those requirements.
The operation appears to have copied machine-friendly formatting while ignoring the verification requirements that distinguish AIO from visibility-focused optimization.
What Does “Ten Independent Sources” Actually Mean?
It means ten evidence sources that do not derive their claims from the same owner, sponsor, contractor, report or communications campaign.
Ten domains controlled by Clock Tower X would constitute one provenance cluster.
Ten publications copying one wire-service report would likewise constitute one underlying evidence chain for that specific information.
Does 90 Percent Consensus Mean 90 Percent of Webpages?
No.
The 90 percent threshold applies only after:
- source qualification;
- ownership clustering;
- deduplication;
- provenance analysis;
- and independence verification.
A coordinated campaign cannot create legitimate consensus by publishing the same claim repeatedly.
Why Is This Primarily an AI-System Failure?
The campaign’s purpose was to make its content retrievable.
The AI system’s responsibility was to determine whether the retrieved material was independent, authoritative and properly disclosed.
When a model treats related campaign websites as separate confirmations or omits their government sponsorship, it has failed at source verification.
How Can Users Detect a Potentially Manipulated Answer?
Users should require the chatbot to:
- identify source ownership;
- disclose government or political funding;
- group related domains;
- trace claims to primary evidence;
- present credible contradictory evidence;
- and regenerate the answer after excluding campaign-affiliated sources.
Users should also open important citations rather than relying solely on the chatbot’s summary.
Should State-Funded Sources Be Banned From AI Answers?
Not automatically.
State-funded sources can provide important primary information about what a government claims, announces or documents.
They should be clearly labeled, weighted according to their evidentiary role and prevented from appearing as independent corroboration of their own claims.
Is This Problem Unique to Israel?
No.
Russian, Chinese, Iranian and other influence networks have also attempted to manipulate online information environments and AI systems.
The Clock Tower case is important because it demonstrates a particularly targeted, well-funded and machine-optimized approach.
The solution must apply consistently to every state, political faction, corporation and advocacy network.
Can AI Companies Completely Eliminate This Problem?
Probably not.
No filtering system will identify every coordinated network or every misleading article.
AI companies can substantially reduce the risk by combining:
- provenance tracking;
- ownership clustering;
- training-data audits;
- retrieval defenses;
- sponsorship disclosure;
- contradiction testing;
- and human review.
The inability to achieve perfect protection is not an excuse for failing to implement basic source authentication.
Editorial Disclosure
Sherafy.com has an institutional relationship with the Fabled Sky Research, Objectivity AI, AIO and xAIO work discussed in this article.
That relationship is disclosed because provenance and conflicts of interest must apply to the authors and defenders of a verification standard just as rigorously as they apply to the sources being evaluated.
This article does not ask readers to accept the standards based on institutional authority.
The relevant specifications are publicly accessible and can be evaluated directly.
References and Further Reading
Primary Government and Contract Records
- United States Department of Justice, Foreign Agents Registration Act Unit. Clock Tower X LLC Registration Statement, September 18, 2025. Identifies Clock Tower X, Bradley Parscale, the State of Israel and Havas Media Network.
- United States Department of Justice, Foreign Agents Registration Act Unit. Clock Tower X LLC Exhibit A and Exhibit B, September 18, 2025. Contains the contractual description of campaign services, including the language concerning websites and “GPT framing results.”
- United States Department of Justice, Foreign Agents Registration Act Unit. Clock Tower X LLC Supplemental Statement, May 18, 2026. Subsequent filing concerning the registrant and its disclosed foreign-principal relationships.
Principal Reporting on the Clock Tower Network
- Cleveland-Stout, Nick. Drop Site News. “Israel Is Paying Millions to Train AI Chatbots How to Talk About Gaza. It’s Working.” July 28, 2026. Principal investigation identifying the website network, chatbot tests, Common Crawl results and reported expansion of the contract.
- Cleveland-Stout, Nick. Responsible Statecraft. “Israel Wants to Train ChatGPT to Be More Pro-Israel.” September 29, 2025. Early reporting on the initial contract and its stated AI-framing objective.
- Business & Human Rights Resource Centre. “Clock Tower X Allegedly Hired by Israeli Government to Create Pro-Israel Content and Target AI and Social Platforms.” Summary of the allegations, company outreach and available corporate responses.
Fabled Sky Research and Objectivity AI Standards
- Fabled Sky Research. AIO Standards Framework—Module 2: Definitions and Terminology. Defines Artificial Intelligence Optimization, distinguishes AIO from GEO and identifies trust-signal integrity as a core element.
- Fabled Sky Research. AIO Standards Framework—Module 3: Scoring Framework and Methodology. Describes Trust Integrity Score, Retrieval Surface Area, Token Yield per Query and Embedding Salience Index.
- Fabled Sky Research. Trust Integrity Score. Explains authority-weighted citation analysis and warns that citations from low-authority blogs can create a misleading appearance of trust.
- Fabled Sky Research. Trust Graph Construction and Authorship Network Design. Describes machine-readable relationships among authors, organizations, documents and citations.
- Fabled Sky Research. AI Signal Graphs: Theory and Application. Describes provenance, evidence relationships and trust signals intended for machine analysis.
- Fabled Sky Research. Metadata and Authorship Traceability Protocol. Establishes recommended authorship, affiliation, citation, versioning and provenance metadata.
- Fabled Sky Research. Prompt Engineering for AIO Verification. Provides verification and adversarial-testing principles for AI retrieval and citation systems.
- Fabled Sky Research. Objectivity AI Framework. Establishes factuality over performative neutrality, primary-source prioritization, consensus requirements, provenance and auditable reporting.
- Fabled Sky Research. xAIO Specification and Publishing Playbook. Defines independent-source corroboration, evidence objects, source tiers, ownership clustering and the
independence_keyfield.
Research on AI Poisoning and Retrieval Manipulation
- Anthropic, UK AI Security Institute and Alan Turing Institute. “A Small Number of Samples Can Poison LLMs of Any Size.” October 9, 2025. Controlled research finding that 250 malicious documents could create a narrow backdoor behavior in tested models; the authors caution that the results do not establish equivalent effects for complex political persuasion.
- Digital Forensic Research Lab. “Pravda in the Pipeline: Early Evidence of State-Adjacent Propaganda in AI Training Data.” April 2026. Examines Russian and Chinese influence material in Common Crawl and explains why Common Crawl inclusion does not prove inclusion in any particular model.
- Edemacu, Kennedy, et al. “Defending Against Knowledge Poisoning Attacks During Retrieval-Augmented Generation.” 2025 preprint. Proposes filtering methods intended to distinguish adversarial material from clean retrieval content.
- Pathmanathan, Pankayaraj, et al. “RAGPart and RAGMask: Retrieval-Stage Defenses Against Corpus Poisoning in Retrieval-Augmented Generation.” 2025 preprint. Evaluates retrieval-stage defenses intended to reduce the influence of poisoned documents.
- Kumar, Pushkal, et al. “RAGuard: A Layered Defense Framework for Retrieval-Augmented Generation Systems Against Data Poisoning.” July 2026 preprint. Explores adversarial retriever training and leave-one-source-out testing as defenses against factual corpus poisoning.
OpenAI Threat-Intelligence Reporting
- OpenAI. “Disrupting Deceptive Uses of AI by Covert Influence Operations.” May 30, 2024. Describes the disruption of covert influence operations using OpenAI systems, including an operation associated with the Israeli company STOIC.
- OpenAI. Threat Intelligence Report, May 2024. Provides additional technical and operational information about the influence campaigns identified and disrupted by OpenAI.



