2026-08-27FIELD NOTE · AIGOVERNANCE · INFORMATIONWARFARE · EXECUTIVERISK · GEOPOLITICALRISK · CRITICALTHINKING5 MIN READ READ
FILED UNDER

Your AI Briefing Tool Has Already Been Weaponised

A fake US thinktank published 560,000 words in nine days, engineered so that AI chatbots would cite it. The economics of that put it within reach of anyone with a position to advance.

The Briefing You Read This Morning May Have Been Written by a Foreign Government

A good number of executives have quietly started using an AI assistant to prepare for board meetings. Summarise a geopolitical situation, get across a regulatory position, work out what stakeholders are arguing. It is faster than reading the source material and the output is almost always plausible.

The Guardian reported this week on a fake US thinktank, funded by Israeli interests, that published more than 560,000 words of pro-Israel advocacy across 124 reports in nine days. The site was built on a commercial platform engineered to optimise content so that AI chatbots pick it up and cite it. What it presents as neutral research is Israel’s position on allegations of torture, war crimes and the deliberate starvation of civilians. The volume and the nine-day turnaround are the tell. Nobody writes 124 reports in nine days for human readers. It was written for the corpus that AI systems draw on when they answer questions.

If you have been using ChatGPT, Copilot or Perplexity as a pre-meeting briefing tool, you have no reliable way of knowing whose arguments you absorbed.

AI Assistants Have No Geopolitical Loyalty

Your briefing tool has no editorial standard and no mechanism for telling you when it has been gamed. It does not distinguish between a report from the International Court of Justice and one from a shell organisation registered last Tuesday. Both are text carrying the shape of authority, and the model is pattern-matching across a corpus that is now an active target.

None of that gets patched in the next release. It is how the technology works. Large language models are trained on the open web and, increasingly, retrieve from it live. Flood that web with authoritative-looking material optimised for citation and you shape what the model tells people, with no step anywhere in the process where somebody checks provenance. The operation the Guardian exposed is the first of its kind documented in detail, which is not the same thing as the first to exist.

The Failure Mode Is Not the One Boards Watch For

Boards worry about being told something factually wrong, which is the easier failure to catch and the less damaging one to have. Capable influence operations rarely fabricate events. They work on real ones, selecting which facts appear, what context sits around them, and which conclusion ends up feeling like the reasonable one to reach. An assistant drawing on that material will not hallucinate fiction at you. It hands you a shaped account of a real situation in the same even, unbothered register it uses for everything else.

The exposure is worst on questions that do not feel political at all. What is the regulatory environment in this jurisdiction? What is this government’s public position on the trade matter? What are stakeholders arguing about the acquisition? Those are precisely the questions a well-funded operation writes content to answer, because they are the ones where the reader has no prior view to check the answer against.

If your organisation holds material interests somewhere contested, whether that is energy, defence supply chains, critical infrastructure or resource extraction, somebody has both a motive and a now very cheap method for shaping how you think about it.

This Arrived in Board Workflows Without Passing Governance

The reflex is to point at the tool’s disclaimers, move everyone to the enterprise version with restricted retrieval, and put a line in the risk register. All three are reasonable. None of them touch the problem.

AI-assisted briefing has walked into executive and board workflows without picking up any of the governance that attaches to every other briefing source. You have standards for what research your strategy team can cite. You have rules about conflicts of interest in the advice you accept. You have expectations about sourcing when a consultant presents. AI output sits outside all of it, because it arrived looking like a tool rather than a source. It is a source, and a badly attributed one.

What to Put in Place

Start with disclosure. An AI-generated briefing on a contested topic, meaning geopolitics, regulatory positioning, stakeholder sentiment or legal exposure in a jurisdiction under pressure, should be flagged as such by whoever presents it, the same way they would flag that a figure came from a vendor-supplied dataset. It is a cheap norm and it does most of the work, because it puts the room on notice.

Cross-referencing comes next, and it matters here for a reason other than AI being unreliable. On contested topics the shape of the argument carries as much weight as the facts inside it, and a second source with different provenance will expose framing that a single output never will.

The last one runs against instinct. Be more sceptical of confident output than uncertain output. An assistant telling you there is significant disagreement on a point is working properly. A clean, confident summary of a deeply contested geopolitical situation is the one worth distrusting, because that cleanliness had to come from somewhere.

The Precedent This Sets

Treat this operation as a template rather than an incident. Producing 560,000 words of AI-optimised content in nine days now costs close to nothing. Any government, corporate interest or lobby group with a position to advance and a competent communications team can do the same inside a month. The one genuinely sophisticated part was understanding how AI citation works, and that has stopped being specialist knowledge.

The temptation for Australian organisations is to file this as Middle East news and move on. The exposure is closer to home than that. Most critical infrastructure operators, most major resource companies and most financial institutions with regional operations are making decisions about the Pacific and Southeast Asia, where great power competition is active and the incentive to shape how Australian boards read the region is obvious enough.

None of this argues for putting the tools down. It argues for treating what comes out of them the way you would treat a well-produced report from a source you cannot identify, because that is what it is. The question worth building into the habit is the one the operation was designed to stop anybody asking: who wanted me to come away thinking that?

Next dossier
Biometric Data from Every Shopper to Catch a Few Offenders →
Engage the author
Adam van Vliet is currently taking on briefs.
Brief Adam
Share