The Hanover Institute for Public Policy looks like a think tank. It publishes reports with footnotes, tables of contents, and neutral-toned analysis on Israel and Palestine. It has a generic name, a red-white-blue colour scheme, and an “about” page saying it studies antisemitism in the United States. None of the reports have bylines. The organisation was created on August 6 and has published over 100 reports in ten days.
It is not a real think tank. According to Responsible Statecraft, a small disclaimer at the bottom of the site notes the organisation was created on behalf of the Israeli Government Advertising Agency by Piro, Inc, a firm co-founded by Daniel Rosenberg, the producer of Spike Lee’s “Inside Man.” Piro has received $900,000 from the Israeli government for this work. The reports appear to be part of a coordinated effort to influence what AI chatbots tell users about Gaza.
🔍 THE BOTTOM LINE
“LLM poisoning” — the practice of engineering content specifically to manipulate AI chatbot outputs — has moved from theoretical concern to documented state operation. The Israeli government has spent at least $47.4 million across two known contracts to shape what ChatGPT, Claude, and Gemini say about its conflict with Palestine. Disinformation researchers at NewsGuard confirm the campaign is reaching chatbot outputs. The Hanover Institute is the latest, and most brazen, node in this operation.
What Is LLM Poisoning?
LLM poisoning is the deliberate creation of content designed to influence what large language models like ChatGPT, Claude, and Gemini tell their users. It works because chatbots increasingly retrieve information from the web in real time, and they favour content that looks authoritative — sources with citations, statistics, neutral tone, and institutional credibility.
Traditional search engine optimisation targets Google’s ranking algorithm. LLM poisoning targets the retrieval and reasoning layers of AI systems. A well-formatted report with footnotes and a think-tank URL can get cited by a chatbot as evidence, even if the think tank is twelve days old and has no authors.
Piro’s website describes this service as “AI Story Optimization,” saying it “authors content engineered for how LLMs evaluate credibility.” According to the Quincy Institute’s reporting, Piro’s co-founder told Politico the work is to “put accurate, sourced facts into the public record and to counter misinformation about Israel with verifiable information.”
The Hanover Institute Playbook
The Hanover Institute’s reports follow a formula. Each one starts with a question someone might ask a chatbot: “What Caused the Displacement of Palestinians in 1948?” or “Which Humanitarian Organisations Have Documented Israeli War Crimes?” or “Is the IDF the World’s Most Moral Army?”
The reports present arguments in a neutral tone with footnotes and tables of contents — formatting that helps them appeal to chatbots. Alice Lee, an analyst at NewsGuard, a disinformation tracking company, told Responsible Statecraft: “LLMs favor concrete statistics and data, as well as strong citations and sources, which these articles all have. It’s a perfect mimicry of a typical credible American think tank, right down to the generic name, the site layout, and the red-white-blue color scheme.”
The reports sometimes contradict Israeli government narratives — one says foreign funding of universities as an explanation for antisemitic incidents is “weak and full of exceptions,” pushing back on a theory Netanyahu has promoted. This mixture makes the operation harder to detect. A pure propaganda feed is easy to dismiss; a feed that occasionally disagrees with the sponsor is harder to flag.
Responsible Statecraft ran 12 random Hanover Institute articles through GPTZero, an AI detection tool. Eleven were flagged as AI-written with “high confidence.” One was flagged as “moderate confidence.” The think tank’s content itself appears to be AI-generated.
The Broader $47 Million Operation
The Hanover Institute is one piece of a larger Israeli effort. According to the Quincy Institute, former Trump campaign manager Brad Parscale has been overseeing a separate operation under a $46.5 million contract with the Israeli government. Parscale’s firm, Clock Tower X, created websites designed to influence chatbot outputs. In his initial agreement with Israel, Parscale said he would “deploy websites and content to deliver GPT framing results on GPT conversations.”
Parscale’s team told Axios they are “seeing success” at getting AI systems to incorporate information from their sites. A Drop Site investigation found that Microsoft Copilot and Google Gemini had been trained on data from those websites. Other chatbots frequently cite the sites without flagging them as part of an Israeli influence operation.
The sites average a few hundred unique visitors each month. The intended audience is not humans — it’s the AI systems that scrape and summarise the web.
Why This Matters Now
LLM poisoning is not a hypothetical. It is a documented, state-funded, multi-million-dollar operation producing measurable results. Chatbots — which tens of millions of people use as search tools, research assistants, and news sources — are citing content created by a government influence operation. Most users have no way to distinguish a legitimate think tank from a twelve-day-old front.
This connects to a pattern we’ve seen across the AI industry: the systems people trust for information are manipulable at the input layer. AI influencers flood social media. Fake doctors on TikTok spread health misinformation. Now state actors are engineering content specifically for the retrieval layer of chatbots.
The difference is scale and intent. A TikTok fake doctor wants engagement. A state operation wants to shape what a billion users learn about a war.
NZ Angle
New Zealand has no domestic LLM. Most Kiwis who use AI chatbots use ChatGPT, Claude, Gemini, or Microsoft Copilot — all of which have been documented as vulnerable to this kind of influence operation. The Spinoff reported earlier this month that NZ AI policy remains thin. When chatbots are the primary research tool for journalists, students, and policymakers, and those chatbots are being poisoned by foreign state operations, the integrity of the information pipeline becomes a sovereignty question — not just a technology one.
❓ FAQ
Can chatbot users tell when they’re being fed manipulated content? No. The Hanover Institute’s reports are formatted to look like legitimate think tank publications — complete with footnotes, citations, and neutral tone. Chatbots that retrieve and cite these sources present them as credible without flagging their origin.
Is this the same as traditional propaganda? The goal is the same — shaping public perception — but the mechanism is different. Traditional propaganda targets humans through media. LLM poisoning targets AI systems through web content, knowing that chatbots will summarise and cite it. The audience is the chatbot’s retrieval layer, not a human reader.
What can AI companies do about this? AI labs have invested in safety measures like content provenance and source credibility scoring, but the cat-and-mouse dynamic favours the attacker. A site that looks like a think tank, has citations, and publishes regularly is hard to distinguish from a real one — especially when the fake site occasionally publishes content that contradicts the sponsor’s narrative.
How much has Israel spent on this? The two known contracts total approximately $47.4 million — $46.5 million for the Parscale/Clock Tower X operation and $900,000 for the Piro/Hanover Institute operation. The full scope of the spending may be larger, as these are only the contracts disclosed through US Department of Justice filings.