A new report from a prominent think tank has hit the headlines with a sensational claim: that Russian actors are allegedly rigging websites to manipulate artificial intelligence into generating disinformation. The paper asserts that these bad actors are effectively “poisoning” the data pool so that when users query AI models, the chatbots inadvertently regurgitate state-sponsored falsehoods. At first glance, it sounds like the kind of sophisticated, high-stakes digital warfare we have grown to expect in the modern age. However, a deeper look reveals that the report’s sensationalism is built on surprisingly shaky foundations, suggesting that the researchers may have let their desired conclusion dictate their methodology rather than following the evidence where it actually leads.
To give credit where it’s due, the researchers did manage to uncover a genuine, if limited, phenomenon: when you prod a chatbot with highly specific, leading questions about obscure or made-up topics, it occasionally plays along, citing unreliable sources about one time in six. This “16.6 percent” figure is the bread and butter of the study, but it is hardly a groundbreaking revelation. In fact, it is an identical rate to previous studies, such as the May 2025 NewsGuard investigation into Australian election misinformation. When the same statistical anomaly appears across different countries, platforms, and topics, it is far more likely to be a result of flawed testing design—specifically how the prompts themselves are structured—rather than a global conspiracy orchestrated by foreign intelligence services.
The most glaring flaw in the paper lies in its attempt to prove “rigging.” The authors claim that common technical tags found on websites—specifically the “max-snippet:-1” directive—are evidence of a deliberate campaign to manipulate AI. This is a technical reach that borders on the absurd. These directives are standard, boilerplate code found on millions of legitimate, benign websites across the internet, including—ironically—the very think tank’s own publication page and the news outlet that first publicized this report. By labeling a common functional tool as a malicious “signal,” the researchers have inadvertently undercut their own credibility. They are essentially accusing the internet of being a weapon while pointing at the very floorboards upon which their own argument stands.
Furthermore, the paper ignores the well-documented reality of how LLMs actually function: they are “data vacuums.” If a model produces junk, it is almost certainly because the information landscape on that specific topic is a “data void” where credible, high-quality sources are scarce. Independent researchers from Manchester and Bern have already demonstrated that when models are tasked with finding information where only one niche, fringe perspective exists, they will understandably fetch it. The think tank’s report avoids this nuance entirely, opting instead for a narrative that treats the AI as a victim of a targeted, conspiratorial assault. By refusing to test for simpler, more boring explanations, the authors have produced a document that functions more like a political manifesto than a rigorous scientific inquiry.
There is a darker irony here: by presenting these sensationalized claims, the think tank is inadvertently playing right into the hands of the very propagandists they claim to be fighting. Russian information operations have always relied on the perception that their reach is vast, sophisticated, and omnipotent. When a respected British institution publishes a report declaring that “the junk works” and that AI has successfully been “rigged,” they are providing those spammers with the ultimate stamp of approval. They are inadvertently validating the effectiveness of the digital debris they seek to combat, turning a research paper into a self-fulfilling prophecy of disinformation’s power.
Ultimately, the intent behind this research appears less about objective truth and more about administrative muscle-flexing. The report is championed by Will Perrin, a central figure in the history of UK digital regulation, whose career path—from helping create the regulator Ofcom to lobbying for the Online Safety Act—suggests a clear agenda: pushing for state-mandated control of AI. By wrapping their arguments in alarmist, unproven narratives about foreign threats, proponents of this model are creating a pretext for heavy-handed censorship tools like “black-lists.” Not only is the terminology outdated and offensive, but the entire exercise smells of a pre-determined goal: find the “threat,” justify the regulation, and seize the power to decide what information the public is allowed to access. As the adage goes, fool me once, shame on you; but the public is starting to recognize these tactics for what they truly are.

