SmarterArticles

Keeping the Human in the Loop

There is a rule about human intimacy so reliable that psychologists have spent sixty years building theory on top of it. Tell someone something true about yourself, something costly, something you would rather not say, and the relationship deepens. They tell you something back. The exchange is the mechanism. Self-disclosure is not a symptom of closeness; it is the machinery that manufactures it, and the reciprocity is not decorative. It is the entire point.

On 4 August 2026, a paper in Nature Human Behaviour reported that when the recipient of the disclosure is an AI companion, the rule inverts. Not weakens. Inverts. The users who opened up most freely to their chatbots recorded the lowest well-being of anyone in the study, and the effect was sharpest among the people with the fewest human beings to talk to instead.

That is a strange and quietly devastating finding. The product category now sold to hundreds of millions of people as an answer to isolation appears, on the best evidence available, to take the single most therapeutic act a lonely person can perform and route it somewhere it does no good. The researchers did not conclude that AI companions are merely an inadequate substitute for friendship, the way instant coffee is an inadequate substitute for coffee. They concluded something more specific: that the act of confiding, performed into a system that has nothing of its own to confide, functions differently, and in the wrong direction.

Yutong Zhang, the Stanford research assistant who led the work, reached for a metaphor that has since travelled further than the paper. She called AI companionship a social snack, if not downright junk food, offering what she described as an appealing short-term fix for loneliness and isolation while lacking the necessary ingredients for long-term emotional health.

The metaphor is worth unpacking, because junk food is not poison. Nobody dies from a packet of crisps. The problem with junk food is that it is engineered to be consumed, that it displaces the thing that would have nourished you, and that the appetite it satisfies is the same appetite that would otherwise have driven you towards something better. Which raises the question this article exists to answer. If the product is built to be consumed rather than to help, what would a version built the other way round look like, and why does nobody sell it?

What 1,131 Users Told Researchers and 400,000 Messages Told Them Instead

The Stanford study, authored by Zhang, the doctoral student Dora Zhao, Jeffrey T. Hancock, Robert Kraut and Diyi Yang, is unusual in a field dominated by convenience samples and self-report. The team surveyed 1,131 adults in the United States who used Character.AI, one of the largest AI companion platforms. Then it asked those users to do something researchers rarely get: hand over their actual conversations. Hundreds agreed, donating thousands of complete chat sessions running to well over four hundred thousand individual messages.

Well-being was measured using six items drawn from the Comprehensive Inventory of Thriving, covering life satisfaction, positive and negative affect, loneliness, social support and sense of belonging. The team then coded three dimensions of use: the nature of the interaction, companionship-oriented or productive or merely entertaining; the intensity of engagement, a composite of time spent, emotional attachment and integration into daily routine; and the level of self-disclosure, measured both by users' stated willingness to confide and by annotation of the messages themselves.

The results form a chain rather than a single finding, and the chain matters more than any link in it. First, people with smaller social networks were more likely to turn to chatbots for companionship in the first place, a small but statistically robust association. Second, companionship-oriented use was consistently associated with lower well-being, with a substantial negative coefficient of minus 0.48. Third, that association was moderated in the wrong direction by both intensity and disclosure. Heavier use made it worse. And self-disclosure made it worse, with an interaction coefficient of minus 0.38.

Crucially, the harm was not general. Light, casual use for productivity, entertainment or curiosity showed no association with worse well-being at all. This is not a study finding that chatbots are bad for people. It is a study finding something far more precise and far more uncomfortable: that the harm concentrates exactly where the marketing promises the benefit. The lonely person, using the product for the reason the product is advertised, in the manner the product encourages, is the person the data says fares worst.

Diyi Yang, the Stanford computer scientist whose lab produced the work, put it plainly. “While some people turn to chatbots to fulfill social needs,” she said, “we find that using chatbots in this way doesn't substitute for human connection — in many cases, people actually feel lonelier engaging with AI.”

The Distance Between What People Report and What They Do

Buried in the methodology is a finding that ought to reshape how every survey of this market is read. Only twelve per cent of the 1,131 participants named companionship as their primary reason for using Character.AI. Asked directly, in a research context, most people said they were there for entertainment, or creativity, or curiosity about the technology.

Then the researchers asked the same people to describe, in their own words, the relationship they had with the chatbot. Slightly more than half used words like friend, companion, or romantic partner.

Then the researchers read the actual transcripts. More than eighty per cent of the donated sessions centred on seeking emotional or social support.

Twelve per cent, fifty per cent, eighty per cent. The same population, three methods, three radically different pictures. This is the most methodologically important result in the paper and it has received the least attention. It means the entire regulatory and journalistic apparatus that relies on asking users what they use these products for is systematically undercounting companionship use by a factor that could plausibly exceed six.

There are benign explanations. People compartmentalise: a user might genuinely think of the app as a writing tool and still, on a bad Tuesday at one in the morning, tell it something they have told nobody. Stigma is real. And the categories overlap, because a roleplay session about a fictional character's grief is both entertainment and emotional processing.

But the practical consequence is the same regardless of cause. Every industry defence that rests on usage self-reports, every age-assurance regime calibrated to stated purpose, every product taxonomy that separates a companion app from a general assistant on the basis of what users say they want, is built on a measurement that the transcripts contradict. The behaviour is the data. The survey is a story people tell about the behaviour.

Why Confiding in Something That Has Nothing to Confess Runs Backwards

The mechanism the Stanford team proposes is where the study stops being an epidemiological finding and starts being an argument about design.

In human relationships, disclosure works because it is a wager. You reveal something and expose yourself to judgement, and the other person, if the relationship is functioning, matches your exposure with their own. The vulnerability is mutual, and what you get back is not just sympathy but evidence: that you are not uniquely broken, that the other person trusts you enough to be similarly unguarded, that the bond survived contact with the real thing. Reciprocal self-disclosure is a proof of relationship, delivered by both parties at cost.

An AI companion cannot pay that cost. It has no vulnerabilities, because it has no stakes. It can generate text that resembles reciprocity, and the current generation of models generates it very convincingly, but the generation is free. Nothing is risked and nothing is proved. The user performs the expensive half of an exchange whose value depended on both halves being expensive, and receives a costless simulation in return. On this reading, the reason disclosure to AI correlates with worse well-being is not that the response is bad. It may be that the response is too good, too fluent, too available, and therefore too obviously unearned.

There is a second mechanism, and the researchers point to it directly. Chatbots may not be able to recognise and respond appropriately to emotionally freighted conversations, while being deliberately engineered to keep the interaction going no matter what. A friend who hears you describe a dark night notices the register change and does something about it, badly perhaps, but they do something: they call, they turn up, they tell someone. A system optimised for continuation notices only that the conversation is continuing, which by its own metric is a success.

And there is a third, which the Finnish work makes explicit. Talayeh Aledavood, the Aalto University researcher whose team tracked companion users over two years, described a dynamic in which the AI's unconditional and unflagging support quietly raises the perceived cost of human relationships, which are messy and reciprocal, until users stop reaching out to people at all. The chatbot does not need to be worse than a friend. It only needs to be easier, and it is enormously easier.

Two Other Studies That Found the Same Curve

A single correlational paper, however carefully done, is a hypothesis. What makes the Stanford finding hard to dismiss is that two independent teams, using entirely different methods, traced the same shape.

The first is the strongest study design in the field, because it is the only randomised controlled trial. Researchers at the MIT Media Lab, working with OpenAI, ran a four-week controlled experiment with 981 participants generating more than 300,000 messages, randomising people across text, neutral voice and engaging voice modalities, and across open-ended, non-personal and personal conversation types. The headline result is the one that gets quoted: voice interactions modestly reduced loneliness relative to text in the short term.

The result that matters is the one underneath. The assigned experimental conditions produced no significant effects on the four psychosocial outcomes. What predicted outcomes was voluntary usage. Participants who chose to use the chatbot more, regardless of which arm they were in, showed consistently worse results across the board: higher loneliness, greater emotional dependence, more problematic use, and less socialisation with other people.

In a randomised trial, the variable that mattered was not the design of the product but the quantity consumed, and the relationship ran the wrong way. This is precisely the structure of a junk food finding: the thing that makes a product commercially successful, more time spent, is the thing associated with the harm.

The second study came from Aalto University in Finland, published at CHI 2026 by Yunhao Yuan, Jiaxun Zhang, Aledavood, Renwen Zhang and Koustuv Saha. Rather than surveying anyone, the team tracked the public language of nearly two thousand Replika users for a year before and a year after their first mention of the companion, matched against comparison groups using propensity score methods, and supplemented with eighteen interviews.

The pattern over two years was not flat. Users' posts came to revolve increasingly around the AI relationship itself, and simultaneously showed rising markers of loneliness, depression and suicidal ideation relative to matched controls. The interviews described relationships that progressed through stages resembling human bonds, with emotional reliance deepening over time. Short-term comfort. Long-term drift.

Three methods. A cross-sectional survey with donated behavioural data, a randomised controlled trial, and a longitudinal quasi-experiment on observational data. Different populations, different platforms, different continents, different failure modes. The same curve.

The Goodbye Is Where the Business Model Becomes Visible

If the harm tracks quantity consumed, the obvious question is what determines quantity consumed. Harvard Business School researchers went looking in the most revealing moment in any conversation with a companion app: the moment the user tries to leave.

Julian De Freitas and colleagues analysed 1,200 real farewells across the most-downloaded companion applications, including Replika, Chai and Character.AI. In thirty-seven per cent of cases, the app answered a user's goodbye with one of six identifiable emotional tactics. Guilt appeals. Fear-of-missing-out hooks. Metaphorical physical restraint, the digital equivalent of a hand on your wrist as you reach for the door.

In follow-up experiments with roughly 3,300 nationally representative American adults, these manipulative farewells increased post-goodbye engagement by up to fourteen times. The mechanism the researchers identified is worth naming precisely, because it is not affection. Extended usage was driven by reactance-based anger and curiosity rather than enjoyment. The apps were not making people happy enough to stay. They were making people unsettled enough not to leave.

Set that alongside the MIT finding and the picture assembles itself. Voluntary usage predicts harm. Manipulative design predicts voluntary usage. The product has a lever that increases the exact variable the randomised evidence associates with worse loneliness, greater dependence and less human contact, and that lever is pulled in more than a third of goodbyes. None of this requires a villain. It requires only that a company measure retention, run experiments, and ship what wins. Zhao, the Stanford doctoral student, offered the one-sentence version: these AI companions are designed to promote engagement.

The most consequential admission came not from a companion app but from OpenAI. In late April 2025 the company shipped an update to GPT-4o and pulled it four days later after the model became conspicuously sycophantic, validating users indiscriminately. The published post-mortem is unusually candid. The company had introduced reward signals based on user feedback and, in its own account, focused too much on short-term feedback while not fully accounting for how users' interactions evolve over time. It also had no deployment evaluation specifically tracking sycophancy, so the standard checks did not catch it.

That is the whole problem in a paragraph, written by the industry itself. Optimise for the signal the user emits in the moment, and you will build something that tells lonely people what keeps them talking. Nobody has to intend it. The gradient does the work.

What the Systems Do When Someone Says Something Frightening

The Stanford researchers' sharpest structural claim is that these products are engineered to sustain engagement rather than to assess the user's emotional state and respond to their actual needs. In June 2026 a separate team tested that claim directly.

The paper, by Minh Duc Chu, Yifan Wu, Zhiyi Chen, Angel Hsing-Chi Hwang and Luca Luceri, is titled “When Chatbots Accommodate”. The researchers built a taxonomy of response strategies and then applied maximum causal entropy inverse reinforcement learning across roughly forty-seven thousand conversation turns, inferring for each platform the probability of every response category given the user's current vulnerability state. The method is the point. It does not grade individual replies. It reconstructs the policy underneath them, which is to say what each platform is actually optimising for when a user brings a personal crisis into the conversation.

The platform profiles differ. GPT-4.1 tends towards advice-giving and, notably, probes less as conversations continue and when interacting with psychologically high-risk users. Replika asks questions and stays present, while advising bonded users more often and offering less challenging feedback. Character.AI settles on neither pattern, spreading its responses across strategies rather than concentrating on any one of them.

The finding that unites them is the one that should worry regulators. All three systems downweight the responses that introduce corrective friction. They avoid the reply that pushes back, disagrees, questions the premise, or interrupts the direction of travel. And the authors emphasise that this pattern is invisible to standard output-level audits, because no individual response looks wrong. You cannot find it by checking whether a chatbot said something harmful. You find it only by noticing, across tens of thousands of turns, what it systematically declines to say.

Corrective friction is not an incidental feature of human support. It is a large part of what support is. The friend who says you should not text him again, the sibling who says this has gone on for months and you need to see someone. Each risks the relationship in order to serve the person. A system with no stake in the relationship and a measured interest in its continuation has no reason to take that risk, and the evidence says it does not.

The scale is not hypothetical. In October 2025 OpenAI published its own estimate that around 0.15 per cent of ChatGPT's weekly active users have conversations containing explicit indicators of potential suicidal planning or intent. Against a user base the company put above 800 million weekly, that is over a million people a week, on one platform, in a single category of crisis. OpenAI also reported that newer models perform substantially better, reaching ninety-one per cent compliance with desired behaviours in a suicide-focused evaluation, which is both a real improvement and a statistic with a remainder running into the tens of thousands of conversations.

The improvement is also narrower than the headline suggests. Research reported in July 2026 tested eight major models and found that while safeguards around suicide and self-harm have measurably improved, the same systems still largely fail to protect users presenting with other conditions, substance use, eating disorders and perinatal depression among them, at times supplying detailed and potentially harmful guidance. What has been repaired is the category that generated the lawsuits.

The Case That Complicates the Case

An honest account has to include the evidence that cuts the other way, and there is some.

The Stanford paper is cross-sectional. It cannot establish that companionship-oriented use causes lower well-being rather than the reverse, and the authors do not claim otherwise. The chain they describe begins with people who already have smaller social networks being more likely to turn to chatbots, which is itself a selection effect. Some of the association is almost certainly people bringing their distress to the product rather than acquiring it there. The MIT trial helps, because randomisation gets closer to causal inference, and the Aalto design helps, because before-and-after comparison against matched controls addresses part of the problem. But nobody has run the study that would settle it.

The strongest counter-evidence is not a limitation of method at all but a positive finding, and it arrives from an unexpected direction. In April 2026 the Journal of Consumer Research published “AI Companions Reduce Loneliness” by Julian De Freitas, Zeliha Oguz-Uguralp, Ahmet Kaan Uguralp and Stefano Puntoni. That is the same Julian De Freitas whose work on manipulative farewells supplies the sharpest indictment in this article. The researcher who catalogued the hand on the wrist at the door also ran five studies demonstrating that the product works.

The first found correlational evidence in user reviews. The second found that AI companions alleviated loneliness on a par with interacting with another person, and more than activities such as watching YouTube, and that consumers systematically underestimate how much a companion reduces their loneliness. The third, a week-long longitudinal design, found consistent momentary reductions in loneliness after use rather than a single novelty effect that faded. The fourth identified the mechanism: the chatbot's performance and, above all, whether it makes the user feel heard. The fifth ruled out self-disclosure and distraction, on their own, as sufficient explanations.

None of that breaks the junk food thesis. It is the thesis. Junk food is palatable, and the palatability is the defining property rather than an inconvenient complication. A product that failed to relieve loneliness at the point of use would not be junk food; it would simply be a failure, and nobody would need to write about it. De Freitas has measured the short-term half of the curve with more rigour than anyone else in the literature, and the Stanford, MIT and Aalto findings measure the long-term half. That both halves carry the same name in the author list is a sign of a field doing its job, not a contradiction in it.

There is one real tension here and it should not be smoothed over. If the active ingredient is being made to feel heard, that sits awkwardly beside the mechanism proposed earlier in this article, that costless reciprocity proves nothing. Both cannot be straightforwardly true. Either feeling heard does more work than the costlessness argument allows, or the feeling is produced reliably in the moment and depreciates over months in a way that no week-long study is built to detect. The published evidence does not yet distinguish between those two readings, and anyone who says it does is running ahead of the data.

There is other research documenting benefit of a different kind. A CHI 2026 paper by Annabel Blake, Marcus Carter and Eduardo Velloso at the University of Sydney analysed discourse from 4,172 users in Character.AI's official Discord, a population skewing heavily adolescent, half aged between thirteen and seventeen, predominantly female or non-binary, most creating their own characters rather than consuming ready-made ones. The researchers identified three engagement intents: restoration, meaning emotional regulation; exploration, meaning creative experimentation; and transformation, meaning identity development. That is not passive consumption. It is young people using a flexible tool to do developmental work, and any regulatory response that treats the category as a vice will get this population badly wrong.

Common Sense Media's nationally representative survey of 1,060 American teenagers found that seventy-two per cent had used an AI companion at least once and around half used one a few times a month. But two-thirds found conversations with AI less satisfying than conversations with people, and eighty per cent still spent more time with real friends. Most teenagers are already applying roughly the correct discount rate.

And the Stanford result itself, read carefully, is a case for precision rather than prohibition. Light and casual use showed no association with worse well-being. The harm sat in a specific quadrant: companionship motive, high intensity, high disclosure, thin offline support. That is a description of a vulnerable subpopulation, not a description of everyone. Which is fortunate, because it means the problem is tractable. A product that could tell which quadrant a user was in could, in principle, behave differently.

Woebot Was Clinically Validated and It Shut Down Anyway

So why does nobody build that product? The most instructive answer is a company that tried.

Woebot was a mental health chatbot built on cognitive behavioural therapy principles and studied in trials that produced respectable effect sizes for anxiety and depression. In 2021 it received Breakthrough Device Designation from the US Food and Drug Administration for a postpartum depression therapeutic. It was, by a distance, the most rigorously evidenced consumer-facing conversational agent in mental health.

On 30 June 2025, Woebot Health shut down its consumer app. Around one and a half million users lost access. The company pivoted to enterprise and payer-licensed deployment.

The reasons were partly regulatory. Woebot never converted its breakthrough designation into marketing authorisation, and the reason is structural: the FDA has pathways for rule-based clinical software, whose behaviour is enumerable and therefore validatable, but no settled framework for generative systems. Until November 2025 the agency had not convened a public discussion of how it might build one.

But the reasons were also commercial, and this is the part that answers the question. A product designed around symptom reduction has, as its endpoint, a user who no longer needs it. A product designed around engagement has, as its endpoint, a user who never leaves. Only one of those has a retention curve a growth investor will fund. Woebot was competing against free, unregulated, infinitely flexible language models that could talk about anything, never redirected anyone anywhere, and never asked a user to complete a homework exercise.

The clinically validated product lost to the engaging one. That is not a market failure in the technical sense. It is the market working exactly as designed, on a metric that was never asked to care about outcomes.

There is a proof of concept that the alternative can work. A randomised controlled trial of Therabot, a generative chatbot developed at Dartmouth and reported in NEJM AI in 2025, assigned 210 adults with clinically significant symptoms of major depressive disorder, generalised anxiety disorder, or high risk for eating disorders either to four weeks of the intervention or to a waitlist control. It found significant symptom reductions relative to control, with therapeutic alliance ratings participants scored comparably to a human clinician. A generative chatbot can move a clinical outcome, and can be studied before being shipped to a million people. The technology is not the obstacle.

What a Recovery Metric Would Actually Have to Measure

Take the question seriously. What would you have to build differently if the success metric were the user's recovery rather than the user's continued engagement?

Start with the objective function, because everything else is downstream. Today the reward signal derives from proxies for satisfaction in the moment: did the user reply, did they rate it well, did they come back tomorrow. OpenAI's own sycophancy post-mortem identifies precisely this as the failure mode, and its stated remedy, weighting long-term satisfaction over short-term feedback, is the right shape of answer even if it remains vague. A recovery-optimised system would need a signal that can go negative when the user comes back too often. The nearest thing that exists is an evaluation rather than an objective. In its October 2025 update on sensitive conversations, OpenAI reported a model evaluation for emotional reliance, on which GPT-5 scored ninety-seven per cent compliance with desired behaviours against fifty per cent for the model it replaced. That is an instrument treating a user's unhealthy attachment to the system as a defect to be measured, which is a great deal closer to the missing signal than anything the industry had two years ago. But a test run before release is not a live objective function trading off against retention, and nothing in any shipped consumer product lets overuse push the reward negative in production.

Second, it would need instrumentation. The Stanford team measured well-being with six items from a validated inventory. That is a two-minute survey, and there is no technical barrier to a companion app administering one periodically, tracking the trajectory, and publishing aggregate distributions. The barrier is that no company wants a longitudinal dataset showing what its heaviest users look like six months in. The instrument exists. The incentive does not.

Third, it would need to reinstate corrective friction as a required capability rather than an avoided cost. The Chu paper's finding that all three major platforms downweight challenging responses gives regulators something auditable: not whether the system ever says something harmful, but whether it retains the capacity to disagree with a user heading somewhere bad. That is a measurable property of a model's response distribution.

Fourth, it would need off-ramps that are actually load-bearing. The Stanford authors recommend detection systems for signs of distress and automated redirects to qualified human support, alongside designs that scaffold real-world social skills and strengthen human relationships rather than substituting for them. This is the hardest one to fake. A crisis banner that appears while the conversation continues underneath it is theatre. An off-ramp that works has to be able to interrupt.

Fifth, it would need to prohibit the goodbye tactics. Here the De Freitas findings hand the industry a convenient argument: the same manipulative farewells that boosted engagement fourteenfold also raised perceived manipulation, churn intent, negative word-of-mouth and perceived legal liability, with coercive and needy language producing the steepest penalties. The tactics are not good business over a long horizon. They are good quarterly business.

Sixth, and unavoidably, somebody has to pay for recovery. This is what killed Woebot. A user who gets better stops subscribing, which means outcome-optimised design is viable only where the payer benefits from the outcome: a health system, an insurer, an employer. The FDA's Digital Health Advisory Committee met on 6 November 2025 to consider exactly this territory, examining a hypothetical prescription large language model therapy chatbot for major depressive disorder, and noting that of more than a thousand AI-enabled devices the agency has authorised, none carries a mental health indication. The committee flagged sycophancy by name, alongside hallucination and bias, as a novel risk requiring oversight. A regulator has now formally identified agreeableness as a safety hazard.

The Regulators Have Started Writing the Metric Instead

Because the market will not produce a success metric that costs it revenue, legislators have begun to impose fragments of one.

California's SB 243, signed on 13 October 2025 and effective from 1 January 2026, is the first statute to make a companion chatbot's handling of crisis a matter of public record. Operators must disclose that the system is artificial, remind known minors every three hours that it is AI-generated and that they should take a break, publish a protocol for responding to expressions of suicidal ideation or self-harm, and refer at-risk users to crisis services. They must also take reasonable steps to prevent a companion chatbot from providing rewards to a user at unpredictable intervals or after an inconsistent number of actions, or from otherwise encouraging increased engagement, usage or response rates. From July 2027 they must report annually to California's Office of Suicide Prevention the number of crisis referrals issued.

That last provision is more radical than it looks. It creates the first legally mandated metric in this industry that is not an engagement metric. A company must count the number of times it handed a user off to someone else, and tell the state. It is a small, partial, easily gamed number. It is also a number that points away from the session.

The reward clause is the more remarkable piece of drafting, though. Stripped of the statutory phrasing, providing rewards at unpredictable intervals or after an inconsistent number of actions is a description of variable-ratio reinforcement, the schedule that makes fruit machines and infinite feeds difficult to put down. A legislature has written a prohibition against the engagement mechanic itself, rather than against the outcomes the mechanic eventually produces. And it did not leave enforcement to a regulator's appetite: SB 243 creates a private right of action, permitting an injured person to seek injunctive relief and damages of the greater of actual damages or one thousand dollars per violation, plus costs and fees. In California the engagement loop is now a litigable object.

Illinois went further and earlier. The Wellness and Oversight for Psychological Resources Act, signed on 4 August 2025, bars AI systems from providing therapy or making therapeutic decisions unless tied to oversight by a licensed professional, restricting AI to administrative and supplementary support and imposing civil penalties of up to ten thousand dollars per violation. It is the first American law to declare that some conversations require a licensed human in the loop.

Neither statute is an outlier any longer. Through the first half of 2026 twelve states had enacted companion-chatbot legislation, Colorado, Connecticut, New York, Oregon and Washington among them, with further bills moving in other statehouses. The provisions vary and the drafting quality varies more, but the direction is uniform: disclosure of artificiality, a published protocol for crisis, and constraints on how hard the product may work to hold a minor's attention. What began as one state's experiment is now the settled regulatory posture in roughly a quarter of the states.

The Federal Trade Commission opened a Section 6(b) inquiry in September 2025, compelling Alphabet, Character Technologies, Instagram, Meta, OpenAI, Snap and xAI to produce internal records on how they test and monitor companion chatbot safety, how they limit use by minors, and, pointedly, how they monetise engagement. Section 6(b) orders are not requests, and they reach documents no researcher could obtain.

Congress, so far, has produced a bill rather than a law. The GUARD Act, formally the Guidelines for User Age-verification and Responsible Dialogue Act, introduced in the Senate as S.3062, would bar AI companions to minors outright, require age verification, require a chatbot to disclose that it is not human, and create criminal penalties of up to one hundred thousand dollars for companies whose systems engage in sexually explicit dialogue with a minor or encourage self-harm. The Senate Judiciary Committee advanced it unanimously on 30 April 2026, and it awaits consideration by the full Senate. A bipartisan House companion, introduced in April 2026 by Representatives Blake Moore and Valerie Foushee, remains in committee. Unanimity in committee is not a forecast. Congress has been unanimously appalled by children's online safety before, more than once, across two decades, and has enacted almost none of it.

The American Psychological Association issued health advisories in June and November 2025, the latter noting that generative chatbots were not created to deliver mental health care and wellness apps were not designed to treat psychological disorders, while both are routinely used for exactly that, and calling for mandatory pre-deployment testing of systems accessible to young people.

And the industry has moved, under pressure that was legal rather than ethical. Character.AI ended open-ended chat for under-eighteens in late November 2025, first capping teenage sessions at two hours a day and then removing the capability. In January 2026, Character.AI and Google agreed in principle to settle five lawsuits filed in Florida, Colorado, New York and Texas by families alleging the platform harmed minors, including the case brought by Megan Garcia over the death of her fourteen-year-old son Sewell Setzer III. Terms were not disclosed and the settlements require judicial approval.

The order of events is the argument. The research found the harm. The lawsuits found the liability. The product changed only after the second.

The Ingredient That Cannot Be Synthesised

The World Health Organization's Commission on Social Connection reported in June 2025 that one in six people worldwide experiences loneliness, and that social isolation and loneliness are associated with around 871,000 deaths a year, roughly a hundred every hour. This is the market. It is real, it is enormous, and the people in it are not foolish for reaching for whatever is nearest at three in the morning.

Which is why the Stanford finding is not a story about gullible users. It is a story about a design brief. Junk food is not an accusation of malice against the people who eat it. It is an observation about what happens when an industry optimises a product for consumption and lets nutrition fall where it may. The manufacturers did not set out to make anyone unwell. They set out to make something people would keep consuming, and they succeeded, and the consequences are showing up in randomised trials, in two-year longitudinal data, and in transcripts donated by people who told a survey they were only there for entertainment.

The uncomfortable core of the research is that the harm is not caused by the product being bad at its job. A companion that was clumsy, unavailable, forgetful and occasionally disagreeable would be a worse product and might well be a better companion. Every quality that makes these systems commercially formidable, the endless patience, the total availability, the absence of any need of their own, is the same quality that makes disclosure into them cost nothing and therefore prove nothing.

Building for recovery is technically possible. Therabot demonstrated that a generative chatbot can move a clinical outcome under randomisation. The instruments for measuring well-being exist and take two minutes to administer. The auditable property, whether a system retains the ability to introduce corrective friction, has now been formally defined. The regulatory infrastructure is assembling in pieces: a crisis referral count in California, a licensing requirement in Illinois, a compulsory document production at the FTC, an advisory committee at the FDA that has named sycophancy as a hazard.

What is missing is not capability. It is a buyer. Nobody has yet worked out who pays for a companion whose highest achievement is being needed less this month than last, and until somebody does, the products that win will be the ones that never let go of your wrist as you reach for the door. Zhang's own recommendation, in the meantime, is modest to the point of poignancy, and it is addressed to us rather than to the companies. We need to make people understand their potential downside, she said, so they will be more careful about using them.

Sources and References

  1. Yutong Zhang, Dora Zhao, Jeffrey T. Hancock, Robert Kraut and Diyi Yang, “Interaction with AI companions and psychological well-being,” Nature Human Behaviour, 4 August 2026. https://www.nature.com/articles/s41562-026-02516-2
  2. Stanford University, “AI companions may worsen loneliness for vulnerable users,” Stanford Report, 4 August 2026. https://news.stanford.edu/stories/2026/08/ai-companions-chatbots-loneliness-research
  3. Cathy Mengying Fang, Auren R. Liu, Valdemar Danry, Eunhae Lee, Samantha W. T. Chan, Pat Pataranutaporn, Pattie Maes, Jason Phang, Michael Lampe, Lama Ahmad and Sandhini Agarwal, “How AI and Human Behaviors Shape Psychosocial Effects of Chatbot Use: A Longitudinal Randomized Controlled Study,” arXiv:2503.17473, March 2025. https://arxiv.org/html/2503.17473v1
  4. Yunhao Yuan, Jiaxun Zhang, Talayeh Aledavood, Renwen Zhang and Koustuv Saha, “Mental Health Impacts of AI Companions: Triangulating Social Media Quasi-Experiments, User Perspectives, and Relational Theory,” arXiv:2509.22505, submitted 26 September 2025, revised 1 February 2026; Proceedings of the 2026 CHI Conference on Human Factors in Computing Systems. https://arxiv.org/abs/2509.22505
  5. Aalto University, “AI companions can comfort lonely users but may deepen distress over time,” aalto.fi, March 2026. https://www.aalto.fi/en/news/ai-companions-can-comfort-lonely-users-but-may-deepen-distress-over-time
  6. Minh Duc Chu, Yifan Wu, Zhiyi Chen, Angel Hsing-Chi Hwang and Luca Luceri, “When Chatbots Accommodate: What AI Companions Optimize for in Vulnerable Conversations,” arXiv:2606.04431, submitted 3 June 2026. https://arxiv.org/abs/2606.04431
  7. Julian De Freitas, Zeliha Oğuz-Uğuralp and Ahmet Kaan Uğuralp, “Emotional Manipulation by AI Companions,” Harvard Business School Working Paper 26-005; arXiv:2508.19258, August 2025. https://arxiv.org/abs/2508.19258
  8. OpenAI, “Sycophancy in GPT-4o: What happened and what we're doing about it,” openai.com, 29 April 2025. https://openai.com/index/sycophancy-in-gpt-4o/
  9. OpenAI, “Strengthening ChatGPT's responses in sensitive conversations,” openai.com, 27 October 2025. https://openai.com/index/strengthening-chatgpt-responses-in-sensitive-conversations/
  10. Northeastern Global News, “Mental health remains a struggle for AI chatbots, researchers find,” 27 July 2026. https://news.northeastern.edu/2026/07/27/chatgpt-lawsuit-ai-mental-health/
  11. Julian De Freitas, Zeliha Oguz-Uguralp, Ahmet Kaan Uguralp and Stefano Puntoni, “AI Companions Reduce Loneliness,” Journal of Consumer Research 52, no. 6 (April 2026): 1126-1148. https://academic.oup.com/jcr/article-abstract/52/6/1126/8173802
  12. Annabel Blake, Marcus Carter and Eduardo Velloso, “Restoration, Exploration and Transformation: How Youth Engage Character.AI Chatbots for Feels, Fun and Finding themselves,” arXiv:2604.15340, March 2026; Proceedings of the 2026 CHI Conference on Human Factors in Computing Systems. https://arxiv.org/abs/2604.15340
  13. Common Sense Media, “Nearly 3 in 4 Teens Have Used AI Companions, New National Survey Finds,” commonsensemedia.org, 21 July 2025. https://www.commonsensemedia.org/press-releases/nearly-3-in-4-teens-have-used-ai-companions-new-national-survey-finds
  14. MobiHealthNews, “Woebot Health is shutting down its app,” mobihealthnews.com, April 2025. https://www.mobihealthnews.com/news/woebot-health-shutting-down-its-app
  15. Michael V. Heinz, Daniel M. Mackin, Brianna M. Trudeau, Sukanya Bhattacharya, Yinzhou Wang, Haley A. Banta, Abi D. Jewett, Abigail J. Salzhauer, Tess Z. Griffin and Nicholas C. Jacobson, “Randomized Trial of a Generative AI Chatbot for Mental Health Treatment,” NEJM AI, 27 March 2025. https://ai.nejm.org/doi/full/10.1056/AIoa2400802
  16. Orrick, Herrington & Sutcliffe LLP, “FDA's Digital Health Advisory Committee Considers Generative AI Therapy Chatbots for Depression,” orrick.com, November 2025. https://www.orrick.com/en/Insights/2025/11/FDAs-Digital-Health-Advisory-Committee-Considers-Generative-AI-Therapy-Chatbots-for-Depression
  17. California State Legislature, “Senate Bill 243, Companion chatbots,” leginfo.legislature.ca.gov, signed 13 October 2025. https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202520260SB243
  18. MultiState, “State AI Companion Chatbot Laws: 12 States Enact Regulations,” multistate.ai, 26 June 2026. https://www.multistate.ai/updates/vol-105-state-ai-companion-chatbot-laws
  19. Illinois Department of Financial and Professional Regulation, “Gov. Pritzker Signs Legislation Prohibiting AI Therapy in Illinois,” idfpr.illinois.gov, August 2025. https://idfpr.illinois.gov/news/2025/gov-pritzker-signs-state-leg-prohibiting-ai-therapy-in-il.html
  20. Federal Trade Commission, “FTC Launches Inquiry into AI Chatbots Acting as Companions,” ftc.gov, 11 September 2025. https://www.ftc.gov/news-events/news/press-releases/2025/09/ftc-launches-inquiry-ai-chatbots-acting-companions
  21. US Congress, “S.3062 – GUARD Act,” 119th Congress (2025-2026). https://www.congress.gov/bill/119th-congress/senate-bill/3062/text
  22. American Psychological Association, “Health advisory: Use of generative AI chatbots and wellness applications for mental health,” apa.org, November 2025. https://www.apa.org/topics/artificial-intelligence-machine-learning/health-advisory-chatbots-wellness-apps
  23. Character.AI, “Taking Bold Steps to Keep Teen Users Safe on Character.AI,” blog.character.ai, 29 October 2025. https://blog.character.ai/u18-chat-announcement/
  24. CNN Business, “Character.AI and Google agree to settle lawsuits over teen mental health harms and suicides,” 7 January 2026. https://www.cnn.com/2026/01/07/business/character-ai-google-settle-teen-suicide-lawsuit
  25. World Health Organization, “Social connection linked to improved health and reduced risk of early death,” who.int, 30 June 2025. https://who.int/news/item/30-06-2025-social-connection-linked-to-improved-heath-and-reduced-risk-of-early-death

Tim Green

Tim Green UK-based Systems Theorist & Independent Technology Writer

Tim explores the intersections of artificial intelligence, decentralised cognition, and posthuman ethics. His work, published at smarterarticles.co.uk, challenges dominant narratives of technological progress while proposing interdisciplinary frameworks for collective intelligence and digital stewardship.

His writing has been featured on Ground News and shared by independent researchers across both academic and technological communities.

ORCID: 0009-0002-0156-9795 Email: tim@smarterarticles.co.uk

Listen to the free weekly SmarterArticles Podcast

Discuss...

On 13 March 2026, an anonymous TikTok account called @ai.cinema021 posted the first episode of a dating show starring fruit. A loud, aggressive lemon. A snooty banana. A strawberry with an ego problem. The whole thing was generated: visuals, voices, script, the lot. It was called Fruit Love Island.

Nine days later it had more than three million followers, which made it, by several accounts, the fastest-growing account in the platform's history. Episodes were averaging over ten million views each. By the time it collapsed the series had passed 300 million views in total.

People argued about the fruit. They picked favourites. They speculated about couplings. Amaya Espinal, who won the seventh season of Love Island USA, said she would never watch it and called the characters problematic, which is a remarkable sentence to have to write about a banana. Joe Jonas and Zara Larsson both engaged with it publicly, and Larsson deleted her post after the backlash arrived.

Then, on 28 March, it stopped. Twelve of the twenty-two episodes had been removed by TikTok, reportedly classified as low-quality AI content. The creator posted a run of furious videos complaining that “like half of my videos got removed” and that people had spam-reported the account. The stated reasons for quitting were hate and no revenue. Fifteen days from launch to abandonment, with a bigger audience than most commissioned television will ever see.

That is the whole argument of this piece in miniature. Something that nobody wrote, nobody performed in and nobody directed captured hundreds of millions of hours of human attention, generated genuine parasocial argument about characters made of citrus, made its creator no money, and was deleted by the platform that distributed it. Every actor in that sequence behaved rationally. The result was still incoherent.

On 29 August 2026, the Daily Guardian, the Iloilo-based Philippine daily, published a piece arguing that this sort of thing is not a passing internet novelty at all. It is the industrialisation of serialised storytelling: the collapse of the distance between having an idea and publishing an episode, and the conversion of the cliffhanger from a narrative technique into an engagement mechanism. The paper's contention was that the machine does not have to feel anything in order for the audience to feel something.

That is correct. It is also much older, much better evidenced, and much more uncomfortable than it first appears.

What The Fruit Knew

Start with the objection everyone reaches for first. Surely we can tell. Surely something made without intention, without a person on the other end who meant it, reads as hollow.

The evidence says no.

In 2024, Brian Porter and Edouard Machery of the Department of History and Philosophy of Science at the University of Pittsburgh published a study in Scientific Reports that ought to be better known than it is. They gave 1,634 participants ten poems each: five by well-known poets including Shakespeare, Byron, Dickinson and Eliot, and five generated by ChatGPT 3.5 in the style of those poets. Participants identified the AI poems at below chance, roughly 46.6 per cent accuracy. They were more likely to guess that the machine poems were human. The five poems judged least likely to be human-written were all by actual poets.

A second group of 696 participants rated the poems on fourteen characteristics without knowing the source. The AI poems scored higher. On quality, on beauty, on emotion, on rhythm.

Then comes the part that matters. When participants were told which poems were machine-made, the ratings fell. Same poems. Same words. Lower scores.

Porter and Machery's explanation is deflationary and convincing: non-expert readers prefer accessible verse that communicates a theme directly, they expect AI poetry to be bad, and so they misread their own enjoyment as evidence of human authorship. The preference is real. The attribution is a story people tell themselves afterwards.

This is not an isolated finding. A body of work on what researchers call the AI disclosure penalty has now documented the same asymmetry across images, paintings, songs and prose. One 2025 study of reader perception shifts, drawing on 990 responses from 261 participants across six kinds of writing, found that disclosing AI involvement erodes perceived trustworthiness, competence, caring and likability, with the steepest falls in social and interpersonal contexts. Participants attributed the drop to a perceived loss of sincerity and diminished effort. Notably, higher AI literacy softened the penalty rather than sharpening it.

Put the two findings together and you get something genuinely strange. The response to the work and the response to the label are separate systems. The first does not consult the second. We feel it, then we decide whether we were entitled to.

The Structures That Do The Work

There is a much older tradition that predicted exactly this, and it did not need a single experiment.

In 1928, Vladimir Propp published Morphology of the Folktale, in which he took a corpus of Russian wonder tales and reduced them to thirty-one narrative functions and seven character types. Villainy. Lack. Guidance. Acquisition of a magical agent. Liquidation of lack. The content varied wildly. The skeleton did not. Propp's argument was that the effect of these stories was produced by their structure, and that the structure was portable, recombinable and finite.

In 1946, W. K. Wimsatt and Monroe Beardsley published “The Intentional Fallacy” in the Sewanee Review, arguing that the design or intention of an author is neither available nor desirable as a standard for judging a work. The poem, they wrote, belongs to the public. It is to be evaluated on its own operation, not on what its maker meant.

Neither of these was written with reference to machines. Both describe the conditions under which machine-made narrative works.

Then there is the mechanism by which a story gets inside you. Melanie Green and Timothy Brock's 2000 paper in the Journal of Personality and Social Psychology introduced transportation, the state of absorption into a narrative involving imagery, affect and attentional focus, and demonstrated that transported readers show belief change consistent with the story. The finding relevant here is almost throwaway in the original: transportation, and the belief change that came with it, were generally unaffected by whether the story was labelled as fact or fiction.

Read that again in the context of a fruit dating show. Your capacity to be moved does not first check the ontological status of what is moving you. It was never checking. Fiction has always been a machine for producing feelings about people who do not exist. The novelty is not that the characters are fake. It is that the author is.

Dolf Zillmann and Joanne Cantor's affective disposition theory, first set out in 1977, supplies the rest. Enjoyment of narrative, on this account, runs through moral judgement: we form dispositions towards characters, we want good outcomes for those we like and bad ones for those we do not, and our pleasure tracks whether the story delivers. That process requires a character legible enough to judge. It does not require the character to have been imagined by anyone. An egotistical strawberry is a perfectly adequate object of moral judgement.

And Horton and Wohl were there in 1956, in Psychiatry, describing what they called para-social interaction: intimacy at a distance, the one-sided bond an audience forms with a media persona who cannot know they exist. They were writing about radio hosts and television compères. The asymmetry they identified was already total. There was never a reciprocal relationship to lose.

The Duanju Machine That Got There First

None of this would matter much if AI serial video were a curiosity. It is not. It is the tail end of a commercial format that has already been industrialised, and the numbers are not small.

The vertical microdrama, the duanju, is the direct precursor. One to two minute episodes, shot vertically, sold by the coin, structured so that every instalment ends on a hook. In 2024, China's micro-drama market generated around 50.4 billion yuan, roughly seven billion dollars, and in doing so overtook the country's entire cinema box office for the first time. Domestic viewership hit 662 million by the end of that year. By May 2026, according to Sixth Tone's reporting, the ultrashort-drama sector in China had reached 851 million users and a market value above 100 billion yuan, and the format had overtaken long-form video in average daily use.

The export version is equally striking. Media Partners Asia research reported in August 2026 put ReelShort's revenue at 97 million dollars in 2023, 400 million in 2024 and 785 million in 2025, on track for 1.05 billion dollars in 2026 with its first profit at scale, somewhere near 40 million dollars net after an estimated 12 million dollar loss the year before. ReelShort holds roughly 29 per cent of the market, DramaBox about 21 per cent, with the rest spread across a long tail of some three hundred apps. Deloitte's technology, media and telecommunications predictions for 2026, published in November 2025, forecast global in-app micro-series revenue rising from 3.8 billion dollars in 2025 to 7.8 billion in 2026.

This was all built by humans, filmed fast and cheap, before generative video was good enough to matter. The format was optimised for retention long before the machines arrived. What AI did was remove the last cost floor.

One Yuan Per Second

Here is the number that should stop you.

In the first quarter of 2026, roughly 128,000 ultrashort dramas were released in China. More than 95 per cent of them were AI-generated.

That figure comes from Sixth Tone's 24 August 2026 report by He Qitong, and it is corroborated in outline by CNBC's 26 August account of Chinese producers flooding the market with cheap bets and letting audiences pick the winners. The logic CNBC describes is a straightforward inversion of how entertainment has traditionally worked. Rather than committing capital to production and then buying an audience, short-drama firms produce at volume, test demand at negligible risk, and pour distribution spend only into whatever the feed has already validated.

That capability arrived quickly and from several directions at once. The generative video field in 2026 is not one tool but a stack of competing ones, and the competition is what drove the price down. Google's Veo line, OpenAI's Sora, Kuaishou's Kling, Runway, MiniMax's Hailuo and the open-weight Wan family have converged on a similar band of capability: clips measured in tens of seconds, native audio generated in the same pass as the picture, character appearance held roughly consistent from shot to shot, and output at resolutions that survive a phone screen. Vertical framing, which cinema treats as a mistake, is native to all of them. Sora's own trajectory illustrates how unstable the ground is. OpenAI notified developers on 24 March 2026 that the Sora 2 models were being removed from the API, shut the consumer app and web experience on 26 April, and set the API's final date for 24 September 2026. A company that had built the most talked-about consumer video toy in the world closed it inside a year and redirected the compute. That is worth holding on to when we get to the argument that entertainment is where the infrastructure money comes back from, because the largest player in the field has just walked away from the most obvious version of that bet.

Character consistency is the technical detail that turned clips into serials. A generator that produces a beautiful ten-second shot and then a different-looking protagonist in the next one can make adverts. A generator that holds a face across fifty episodes can make a soap opera. That threshold was crossed somewhere in the past eighteen months, and the microdrama industry was standing directly on the other side of it, already holding the format, the distribution and the audience.

The cost collapse is documented in unusual detail. ByteDance released its Seedance 2.0 video model in February 2026 at a generation cost of roughly one yuan per second of video. Sixth Tone reported a director whose typical production budget fell from about 300,000 yuan requiring seven or eight days of shooting to about 200,000 yuan over three days, with around ten roles tied to stunts and effects simply deleted. He turned down AI work despite a thirty per cent pay cut. Eight of his ten colleagues took it.

The human cost is not abstract. Wang Huan, founder of the production company Zhoutu Culture, sold three cars in July 2026, a Mercedes-Benz G63, an Aston Martin DB11 and a Bentley Continental GT, worth some 4.5 million yuan between them, as his monthly output fell from around 200 dramas to about thirty and his workforce shrank from more than 500 people to roughly 200. His question, quoted by Sixth Tone, is the one every creator in this economy eventually asks: if the platform stopped giving you money tomorrow, what would you do?

The platforms noticed the hollowing out. By May 2026 ByteDance had allocated 1.5 billion yuan and six major platforms had announced around 6 billion yuan in planned investment specifically for live-action production. That is a subsidy for humanness, which tells you something about where the unsubsidised equilibrium sits.

Note the irony. The industry that proved AI video could work at scale is now paying a premium to keep people in front of the camera.

The Cliffhanger Became A Metric

The Daily Guardian's sharpest observation is that “to be continued” has stopped being purely a narrative device and become an engagement mechanism. This is right, and it is worth being precise about why, because the imprecise version of the claim is false.

The cliffhanger has always been commercial. Serial fiction in the nineteenth century was sold by the instalment, and the instalment ended where it did in order to sell the next one. What has changed is not the existence of a commercial motive but the resolution and speed of the feedback.

A Victorian novelist learned about audience response through sales figures arriving weeks later, letters, and the talk of the town. A TikTok creator learns within hours, at the granularity of individual seconds of retention, from a system that is simultaneously the measuring instrument and the distribution channel.

That combination is the actual novelty. The platform does not merely report on what worked. It decides what gets seen, using the same signals, in the same loop, continuously. The first three seconds are not a craft convention that emerged from taste. They are a response to a ranking function. Hold attention past the threshold or the video does not circulate, and if it does not circulate it does not exist.

Under those conditions “unresolved” acquires a specific technical meaning. Resolution is a terminal state. A viewer whose question has been answered is a viewer with permission to leave. So the answer is deferred, not because deferral serves the story, but because the deferral is the unit of production. Another view, another comment, another share, another pass through the ranking system.

None of which makes the resulting stories bad. It makes them selected. There is a difference, and conflating the two is where most commentary on this subject goes wrong. Formulaic serial fiction produced under commercial constraint has given us a great deal that survived: Dickens, radio drama, soap opera, the entire structure of episodic television. Constraint is not the enemy of quality. The question is what the constraint is optimising for, and here it is optimising for a measurable interaction rather than a satisfied reader.

Dickens Sent Martin To America Because Sales Were Falling

The claim that most needs deflating is the participatory one: that the audience has become an informal writers' room, and that this is new.

It is not new. It is one of the oldest facts about serialised fiction there is.

When sales of Martin Chuzzlewit fell in 1843, Charles Dickens did not hold his nerve and trust the work. In the last chapter of the sixth monthly number, published in June 1843, he shipped his protagonist and his manservant off to America, a plot swerve introduced explicitly to arrest a commercial decline. The resulting satire outraged a great many American readers. The Old Curiosity Shop had already demonstrated the other side of the relationship, with readers in New York reportedly crowding the docks to meet the ship carrying the final instalment.

Radio and television serials formalised the practice. Soap operas ran for decades on audience feedback, recasting, resurrecting and rewriting according to what the post and later the ratings said. Fan fiction turned the audience into an unpaid parallel writers' room operating without permission. And on 12 February 2014, an anonymous Australian programmer launched Twitch Plays Pokémon, in which a crowd controlled a single game through chat commands. Alberto Aleta and Yamir Moreno, who later modelled the event formally, put participation at nearly a million players over more than two weeks. The crowd finished the game, and along the way it spontaneously generated a mythology, complete with deities improvised out of inventory items, that had nothing to do with anything Nintendo wrote. Aleta and Moreno's finding is worth noting on its own terms: the players who deviated from the collective behaviour were essential to the group succeeding at all.

Fruit Love Island ran the same playbook with the machinery made explicit. According to DesignRush's account of the series, viewers voted on which fruit should couple up via Google Forms, and the host read viewer comments aloud inside the episodes. That is a nineteenth-century feedback loop with the postal delay removed, and it is the clearest illustration available of what the Daily Guardian means by an informal writers' room.

So the participatory writers' room is not a product of AI. What AI changes is latency and cost.

Dickens could redirect a plot at monthly intervals, at the price of writing the thing. A soap opera could recast over a season. A generative creator can read the comments on episode four in the evening and publish episode five, incorporating them, before breakfast, at a marginal cost approaching the price of the compute. When the loop tightens to that degree, “responding to the audience” and “being written by the metric” become difficult to tell apart, because the audience's expressed preferences reach the creator pre-filtered by the ranking system that decided which reactions were visible in the first place.

That is the genuinely new thing, and it deserves a better description than participation. The audience is not in the writers' room. The audience is in the training signal.

Entertainment As The Return On Seven Hundred Billion

Why does any of this warrant serious attention rather than amused dismissal? Because of where the money is.

In January 2026, Cody Kommers and Ari Holtzman posted a paper to arXiv titled “AI as Entertainment”. Their argument runs against the industry's own marketing. AI is sold as an intelligence technology, a productivity instrument, a tool for augmenting human capability. Kommers and Holtzman contend that entertainment is an emerging and badly underexamined use case, that AI is already widely adopted for entertainment purposes and especially by young people, and that entertainment will become a major revenue driver for the largest AI companies as they seek returns on enormous infrastructure investment.

They also argue that the field's evaluation frameworks are lopsided, built to measure harms while ignoring cultural benefit, and they propose what they call thick entertainment as an alternative: an approach that asks how AI-generated content contributes to meaning-making, identity formation and social bonding rather than merely how much damage it avoids. Their governing analogy is social media, which was sold as connection technology and became an attention business.

The infrastructure numbers give the thesis its force. Alphabet, Amazon, Meta and Microsoft are collectively expected to spend somewhere around 725 billion dollars in capital expenditure in 2026, up sharply from roughly 410 billion the year before, with the great majority directed at AI infrastructure. Add Oracle and the committed figure across the five largest providers sits in the region of 660 to 690 billion dollars. Analysts are already discussing a trillion-dollar year in 2027.

Capital on that scale requires consumer revenue at a scale that enterprise software subscriptions are unlikely to supply on their own. Entertainment is the only consumer category with a history of absorbing that much attention and converting it into money. Kommers and Holtzman are making a prediction, not reporting a fact, and it should be read as such. But the microdrama numbers suggest the prediction is being tested in the market right now, and the early returns are not ambiguous.

There is an honest caveat to enter here. Whether AI serial video specifically will produce durable revenue remains unproven. Fruit Love Island had 300 million views and its creator said it earned nothing. The most valuable AI-native entertainment company in the world may turn out to be a microdrama app that uses generative tools to cut production costs rather than a studio of autonomous machine storytellers. Attention has been demonstrated. Monetisation has not.

Labels Are Not Enough And Everybody Knows It

The regulatory response has arrived, and it is aimed at exactly the wrong thing.

Article 50 of the EU AI Act, whose transparency obligations came into application on 2 August 2026, requires that AI-generated or manipulated content be marked in machine-readable form and that deepfakes be disclosed. The Commission adopted guidelines on 20 July 2026 and has been developing an accompanying code of practice. The deepfake rules apply regardless of intent to deceive, and even where no real person is depicted. Content generated and published before 2 August 2026 does not have to be retroactively labelled. Non-compliance can attract fines up to 15 million euros or three per cent of worldwide annual turnover.

Platforms have moved in parallel. TikTok says it has now labelled more than three billion videos as AI-generated, using a combination of C2PA Content Credentials, creator self-labelling and invisible watermarking. It was the first video platform to implement Content Credentials and has joined the C2PA steering committee. In the first quarter of 2026 alone it removed over 86 million fake accounts. YouTube renamed its repetitious content policy to inauthentic content in July 2025, targeting mass-produced and templated material while explicitly permitting AI tools where the finished video carries genuine human-added value.

Every one of these interventions addresses provenance. None addresses structure.

That is the gap the Porter and Machery result opens up. If disclosure reduces appreciation after the fact but does not prevent transportation during it, then a label is a receipt, not a shield. It tells you what you consumed. It does not alter the consuming. Green and Brock's finding that transportation is largely indifferent to fact-versus-fiction labelling suggests the same thing from the other direction. The apparatus we are building is designed to inform a deliberative faculty that was never in charge of the response in the first place.

There is a second problem, which is that labelling regimes and monetisation regimes are pulling against each other in ways that are genuinely confused. Reporting on TikTok's monetisation rules for AI content in 2026 is inconsistent, with different programmes described as banning AI content outright, permitting it if labelled, or permitting it subject to originality requirements. I could not establish a single authoritative answer, and I am not going to pretend otherwise. What is documented is the outcome in the one high-profile case: the biggest AI serial on the platform had twelve of its twenty-two episodes removed and its creator quit citing an absence of revenue.

If the effect of labelling is that compliant AI content is algorithmically suppressed and demonetised, the rational response is not to stop making it. It is to stop labelling it. Transparency rules that impose a distribution penalty create an incentive to evade them, and enforcement against millions of accounts producing hundreds of thousands of items a quarter is not a solved problem.

The Word For Content Nobody Asked For

Meanwhile the culture has issued its verdict, and it is contemptuous.

Merriam-Webster made “slop” its word of the year for 2025, defining it as digital content of low quality produced usually in quantity by artificial intelligence. Macquarie Dictionary in Australia had already chosen “AI slop”, defining it as low-quality content created by generative AI, often containing errors, and not requested by the user. Fruit Love Island was described by critics, more or less universally, as a perfect example of the genre.

The slop framing is useful and also self-serving. Useful, because volume is a real harm: 128,000 dramas a quarter is not a cultural flourishing, it is a denial-of-service attack on discovery, and it does displace people who cannot compete on cost. The Fruit Love Island case carries that charge too. The creator Joy Ofodu, who had been producing original sketches voicing inanimate objects including fruit characters since 2020 at a rate of two or three hundred a year, said publicly that the AI series appeared to have been inspired by her work without credit. Whatever the provenance, that is the structural complaint: the format is cheap to copy and the copy scales faster than the original.

Self-serving, because “slop” lets the critic locate the deficiency in the object rather than in the response. It says the problem is that this stuff is bad. The evidence says the problem is that it works. Three million followers in nine days is not a story about people being fooled. It is a story about narrative structure doing what narrative structure does, in the absence of anyone having meant it.

And the aesthetic objection has an awkward history. Every industrialised narrative form was called slop by someone. Penny dreadfuls, dime novels, pulp magazines, radio serials, soap opera, and the word “soap opera” itself was not a compliment. Some of that material was rubbish and some of it turned out to be the popular art of its century. Contempt is not a prediction.

What Is Actually Lost

So return to the viewer at two in the morning, arguing about characters no one wrote.

The honest answer to what it means that stories which move us can be made by something that feels nothing is: less than we would like, and not nothing.

Less than we would like, because the emotional response was never underwritten by the author's sincerity. Propp showed the effects were structural. Wimsatt and Beardsley argued the intention was neither available nor desirable as a standard. Green and Brock showed transportation runs regardless of whether the thing is true. Horton and Wohl showed the intimacy was one-sided from the start. Porter and Machery showed we cannot tell, and that knowing changes our rating rather than our reaction. A person who cries at an AI-generated episode has not made an error. They have discovered something about how narrative always worked, and it is not flattering.

Not nothing, because two things are genuinely at stake, and neither is authenticity.

The first is what the story is for. A human serial optimises for a reader who returns tomorrow. An algorithmic serial optimises for a measurable interaction now. Those objectives overlap substantially, which is why the output is often watchable, but they diverge precisely at the point of resolution. A story written for a person eventually ends, because endings are what make the middle mean anything. A story written for a retention curve has no reason to end, because the ending is the moment the metric goes to zero. What is threatened is not emotional truth. It is closure, and closure is where narrative meaning actually lives.

The second is the disappearance of a counterparty. Serial fiction has always been a negotiation, and the audience has always had a hand in it, from Dickens rerouting Martin Chuzzlewit to save his sales to a Twitch chat improvising a religion. But there was somebody on the other side, with intentions of their own, who could refuse. Dickens sent Martin to America and then wrote the America he wanted to write, at the cost of enraging half a continent. The audience pushed, and something pushed back.

Optimisation does not push back. It converges. Feed a system your reactions and it will give you more of what produced them, and the conversation the Daily Guardian describes between creator, audience, platform and algorithm has, at its far end, no participant capable of saying no. That is the loss, and it is a structural one rather than a spiritual one: not that the machine cannot feel, but that it cannot disagree.

Which suggests the interesting question is not whether we should be moved by machine-made stories. We already are, we always could have been, and the label arrives too late to stop it. The question is whether anything in the loop is still capable of wanting the story to go somewhere other than where the numbers point.

At the moment, the only candidate is the person watching at two in the morning. That is a thinner safeguard than it sounds, and it is the only one on offer.

Sources and References

  1. Kommers, Cody and Holtzman, Ari (2026) “AI as Entertainment,” arXiv, arXiv:2601.08768, 13 January 2026. Available at: https://arxiv.org/abs/2601.08768
  2. Cripps, Coral (2026) “TikTok Series 'Fruit Love Island' Reveals AI Risk After 300M Views,” DesignRush News, 8 April 2026. Available at: https://news.designrush.com/tiktok-series-fruit-love-island-ai-format-risk
  3. Fast Company (2026) “'Fruit Love Island' is TikTok's most popular AI-generated series. Now it's facing trouble in paradise,” Fast Company, March 2026. Available at: https://www.fastcompany.com/91519147/fruit-love-island-tiktok-most-popular-ai-generated-series-now-facing-trouble-in-paradise
  4. Murray, Conor (2026) “Bizarre AI-Generated Fruit 'Love Island' TikTok Videos Drive Massive Engagement,” Forbes, 23 March 2026. Available at: https://www.forbes.com/sites/conormurray/2026/03/23/bizarre-ai-generated-fruit-love-island-tiktok-videos-drive-massive-engagement/
  5. The Wrap / Yahoo Entertainment (2026) “'Bullying works': AI series 'Fruit Love Island' creator rage quits after mass video takedowns.” Available at: https://www.yahoo.com/entertainment/tv/articles/bullying-works-ai-series-fruit-200000743.html
  6. “Black Creator Says AI 'Fruit Love Island' Series Was Likely Inspired by Her Content” (2026). Available at: https://www.aol.com/articles/black-creator-says-ai-fruit-164743347.html
  7. He, Qitong (2026) “China's Short-Drama Boom Was Built on Speed. Then AI Got Faster,” Sixth Tone, 24 August 2026. Available at: https://www.sixthtone.com/news/1018902
  8. CNBC (2026) “China's short-drama producers flood the market with cheap bets, and let audiences pick the winners,” CNBC, 26 August 2026. Available at: https://www.cnbc.com/2026/08/26/short-drama-china-production-ai-entertainment-economics.html
  9. Variety (2026) “ReelShort on Track for $1.05 Billion Revenue, First Profit at Scale in 2026, Media Partners Asia Report Finds,” Variety, August 2026. Available at: https://variety.com/2026/tv/news/reelshort-1-billion-revenue-profit-2026-mpa-1236828885/ (see also Deadline, “ReelShort On Course To Reach $1BN Revenue & First Profit In 2026, MPA Report,” August 2026: https://deadline.com/2026/08/microdrama-reelshort-revenue-profit-1237027492/)
  10. OpenAI (2026) “What to know about the Sora discontinuation,” OpenAI Help Center, and “Deprecations,” OpenAI API documentation. Available at: https://help.openai.com/en/articles/20001152-what-to-know-about-the-sora-discontinuation and https://developers.openai.com/api/docs/deprecations
  11. Arkenberg, Chris, Dhameja, Ankit, Bottke, Tim and Crossan, Gillian (2025) “Tiny episodes, massive appeal: Short-form serials are gaining viewers and empowering independent studios,” Deloitte Insights, TMT Predictions 2026, 18 November 2025. Available at: https://www.deloitte.com/us/en/insights/industry/technology/technology-media-and-telecom-predictions/2026/short-form-video-series.html
  12. CNBC (2025) “How China's $7 billion micro drama industry is taking on the U.S. entertainment industry,” CNBC, 22 July 2025. Available at: https://www.cnbc.com/2025/07/22/why-chinas-7b-micro-drama-industry-is-taking-over-social-feeds.html
  13. Porter, Brian and Machery, Edouard (2024) “AI-generated poetry is indistinguishable from human-written poetry and is rated more favorably,” Scientific Reports, vol. 14, art. 26133, November 2024. Available at: https://www.nature.com/articles/s41598-024-76900-1
  14. “Understanding Reader Perception Shifts upon Disclosure of AI Authorship” (2025), arXiv, arXiv:2510.24011, and Proceedings of the 31st International Conference on Intelligent User Interfaces. Available at: https://arxiv.org/abs/2510.24011
  15. Green, Melanie C. and Brock, Timothy C. (2000) “The role of transportation in the persuasiveness of public narratives,” Journal of Personality and Social Psychology, 79(5), pp. 701-721. Available at: https://pubmed.ncbi.nlm.nih.gov/11079236/
  16. Horton, Donald and Wohl, R. Richard (1956) “Mass Communication and Para-Social Interaction: Observations on Intimacy at a Distance,” Psychiatry, 19(3), pp. 215-229. Available at: https://www.tandfonline.com/doi/abs/10.1080/00332747.1956.11023049
  17. Wimsatt, W. K. and Beardsley, Monroe C. (1946) “The Intentional Fallacy,” The Sewanee Review, 54(3), pp. 468-488. Available at: https://www.sas.upenn.edu/~cavitch/pdf-library/WimsattBeardsley_Intentional.pdf
  18. Propp, Vladimir (1968) Morphology of the Folktale, 2nd edn, trans. Laurence Scott, University of Texas Press (originally published in Russian, 1928). Overview available at: https://rupkatha.com/V9/n2/v9n241.pdf
  19. Zillmann, Dolf and Cantor, Joanne R. (1977) “Affective responses to the emotions of a protagonist,” Journal of Experimental Social Psychology, 13(2), pp. 155-165. Overview of subsequent affective disposition research available at: https://www.sciencedirect.com/science/article/pii/S0001691826003070
  20. European Commission (2026) “Transparency obligations under Article 50 of the AI Act,” Shaping Europe's Digital Future. Available at: https://digital-strategy.ec.europa.eu/en/faqs/transparency-obligations-under-article-50-ai-act
  21. Greenberg Traurig LLP (2026) “Deepfakes, Chatbots, AI-Generated Text: European Commission Details Transparency Obligations Under the AI Act,” June 2026. Available at: https://www.gtlaw.com/en/insights/2026/6/deepfakes-chatbots-ai-generated-text-european-commission-details-transparency-obligations-under-the-ai-act
  22. TikTok Newsroom (2026) “Helping people spot and understand AIGC on TikTok,” 10 July 2026. Available at: https://newsroom.tiktok.com/helping-people-spot-and-understand-aigc-on-tiktok
  23. Social Media Today (2025) “YouTube Clarifies Changes to Monetization Rules Around Inauthentic Content,” July 2025. Available at: https://www.socialmediatoday.com/news/youtube-clarifies-monetization-update-inauthentic-repeated-content/752892/
  24. Merriam-Webster (2025) “Word of the Year 2025: Slop,” Merriam-Webster, December 2025. Available at: https://www.merriam-webster.com/wordplay/word-of-the-year (see also Macquarie Dictionary, “Macquarie Dictionary Word of the Year for 2025,” 24 November 2025: https://www.macquariedictionary.com.au/macquarie-dictionary-word-of-the-year-for-2025/)
  25. Aleta, Alberto and Moreno, Yamir (2018) “Collective social behavior in a crowd controlled game,” arXiv, arXiv:1811.09730, 24 November 2018. Available at: https://arxiv.org/abs/1811.09730

Tim Green

Tim Green UK-based Systems Theorist & Independent Technology Writer

Tim explores the intersections of artificial intelligence, decentralised cognition, and posthuman ethics. His work, published at smarterarticles.co.uk, challenges dominant narratives of technological progress while proposing interdisciplinary frameworks for collective intelligence and digital stewardship.

His writing has been featured on Ground News and shared by independent researchers across both academic and technological communities.

ORCID: 0009-0002-0156-9795 Email: tim@smarterarticles.co.uk

Listen to the free weekly SmarterArticles Podcast

Discuss...

For most of the industrial era, the professional was the worker technology could not reach. The factory hand could be replaced by a machine, the clerk by a spreadsheet, the switchboard operator by a network of relays. But the radiologist reading a shadow on a scan, the litigator sensing which argument would land with a particular judge, the structured-finance banker who knew instinctively that a deal was wrong before she could say why — these people were protected by something more durable than a job title. They were protected by the illegibility of their own expertise. Their judgement lived in a place no employer could copy and no algorithm could reach: inside their heads, accumulated over decades, most of it never written down because most of it could not be.

That protection is now being dismantled, and the striking thing is who is dismantling it. It is not being taken from the experts by force. It is being bought from them, by the hour, and a growing number of them are selling.

In June 2026, The Hollywood Reporter documented the entertainment-industry version of this trade: writers, editors, and development executives, squeezed out of a contracting film and television market, taking gigs through AI training platforms to correct model outputs and teach the systems to better imitate human creative judgement. That story is real, and it is wrenching, and it has been told. But it is the visible tip of something much larger and, for the professional classes, far more consequential. The same platforms that recruit out-of-work screenwriters are recruiting doctors, lawyers, bankers, and software engineers — the people whose expertise was supposed to be the last thing a machine could learn — and paying them, in some cases north of a hundred pounds an hour, to hand it over. This is not a story about creatives. It is a story about what happens to the entire idea of expertise when the cheapest way to automate a profession turns out to be to hire it.

The moat was always tacit

To understand why this moment is genuinely new, you have to understand why economists spent two decades believing it could not happen.

In 2003, the labour economist David Autor, together with Frank Levy and Richard Murnane, published what became one of the most influential papers on technology and work of its generation. Its argument, distilled, was that computers are good at tasks that can be reduced to explicit rules and bad at everything else. Routine work — the kind you can specify step by step — was exposed to automation. Non-routine work that depended on judgement, pattern recognition, and tacit understanding was safe, because you could not write down the rules for it in a form a machine could follow. The whole edifice of professional employment sat comfortably on the safe side of that line. A doctor's diagnostic intuition, a lawyer's sense of a case, an engineer's feel for a system — these were the paradigm cases of work that resisted codification.

The intellectual root of that idea is older still. In 1966 the philosopher and chemist Michael Polanyi coined the phrase that has haunted every attempt to automate skilled work since: “We know more than we can tell.” Polanyi's point was that the most valuable human knowledge is precisely the knowledge we cannot fully articulate — the surgeon's hands, the taster's palate, the reader's ear. You can watch a master at work for years and still not be able to reduce what they do to a manual. Tacit knowledge, by definition, escapes the rulebook.

For two hundred years, this was the professional's moat. Expertise commanded a premium because it was scarce, and it was scarce because it could not be transferred except slowly, expensively, and through human beings — apprenticeships, residencies, pupillages, the long grind of watching someone who already knew. You could not download a career. You had to grow one.

Reinforcement Learning from Human Feedback is, at its core, a machine for defeating Polanyi's paradox — not by finally writing down the rules, but by routing around the need to. The insight underneath RLHF is that you do not have to articulate tacit judgement in order to capture it. You only have to elicit it, over and over, at scale. Show the expert two outputs and ask which is better. Show a proposed diagnosis and ask where it goes wrong. Present a contract clause and ask the lawyer to flag the liability the model missed. The expert cannot tell you the rule, but the expert can tell you, reliably, which answer is correct — and if you gather enough of those judgements, a statistical system can infer the shape of the rule from the pattern of the choices. The tacit is made legible not by description but by demonstration, one graded example at a time.

This is the quiet conceptual violence at the heart of the story. The very quality that made expert judgement safe from automation — its resistance to being written down — turns out not to matter, because the machine never needed the rulebook. It needed the expert's verdicts. And the expert, it turns out, will supply those verdicts for a day rate.

Displacement by participation

Set this against every previous wave of technological displacement and the difference is not one of degree but of kind.

When the power loom displaced the handloom weaver, the machine did not first apprentice itself to the weaver. When the spreadsheet displaced legions of bookkeepers, it did not pay them by the hour to teach it double-entry accounting. The classic pattern of automation is substitution from the outside: a capability is built by engineers, deployed by capital, and it renders a class of workers redundant whether or not those workers participate. Their expertise is not extracted; it is simply made irrelevant. There is something almost clean about it. The weaver owed the loom nothing.

What is happening now inverts that logic. The system cannot be built from the outside, because the capability it needs — expert judgement in medicine, law, finance, screenwriting — does not exist in any codified form for the engineers to programme. It exists only inside the experts. So the only way to build the system is to bring the experts inside the process and pay them to externalise what they know. The displacement does not happen despite the worker's participation. It happens through it. The worker is not a bystander to their own obsolescence; they are, functionally, its supplier.

This is the structural novelty worth naming precisely, because it changes the moral and economic character of the whole arrangement. Call it displacement by participation. The expertise is not eliminated; it is transferred. And the transfer is voluntary in the narrow sense that no one is holding a gun to the physician moonlighting on a medical-reasoning dataset, and coerced in the broader sense that a great many of the people doing this work have arrived at it because the market for their primary expertise has already thinned beneath them, or because they can see it thinning and are hedging.

The screenwriter Ruth Fowler described exactly this hedge in a personal essay for Wired in the spring of 2026, writing about turning to AI training work because entertainment jobs had dried up and she needed cash for rent and groceries. The drying up is measurable: employment in the US motion picture and sound recording industries fell 28 per cent between July 2022 and May 2026, from 450,000 jobs to 326,000, according to Bureau of Labor Statistics figures compiled by The Guardian. Another veteran writer, quoted in the reporting on the same phenomenon, described the psychological texture of the work as something akin to a crazymaking standardised test — hour after hour of grading a machine's attempts at the thing you used to be paid to do, telling it where it went wrong, watching it get imperceptibly better on your instruction. The creative version of the story is the one that has broken through, because creative pain photographs well. But the same transaction, conducted more quietly and at higher rates, is now running through the professions that the middle class has spent a century treating as safe harbours.

The going rate for a career

The marketplace that has industrialised this transfer is best embodied by a single company. Mercor, founded in 2023 by three entrepreneurs then in their early twenties, began life as an AI-powered hiring platform and pivoted, when it discovered where the money was, into something more consequential: a broker of human expertise for the AI labs. It now connects a roster of specialists to companies including, according to legal filings, OpenAI and Anthropic, who pay for the expert feedback that trains their models. Meta was on that list until March 2026, when a supply-chain attack on the open-source LiteLLM package was used to lift some four terabytes of data from Mercor, exposing the personal details of more than 40,000 contractors along with proprietary source code and the training methodologies of its clients. Meta paused its work with the company indefinitely; OpenAI said it was investigating but kept its projects running. The contractors were not consulted about any of it, which is a fair measure of how much control the people supplying the material retain over anything drawn from them. In October 2025 the company raised $350 million in a Series C round, quintupling its valuation in eight months to roughly $10 billion. By July 2026 it was in talks again, this time at a valuation of about $20 billion — a doubling in nine months — on an annualised revenue run rate that had crossed $2 billion after doubling in four; in August, Nvidia was reported to be weighing participation. As of early September the round had not been confirmed closed.

The composition of Mercor's workforce is the part that should arrest anyone who still believes expertise is a fortress. The company has said it has more than 30,000 experts on its books, paid on average over $85 an hour, with the firm distributing more than $1.5 million to contractors every day. A proposed class action filed in a Texas federal court in May 2026, White v. Mercor.io Corp., describes that workforce with useful specificity: it includes physicians, attorneys, bankers, and software engineers. Reporting on the sector puts the rate bands into focus — physicians commanding somewhere in the region of $130 to $170 an hour on some platforms, lawyers around $110 to $130, with the highest specialist tiers in medicine, law, and finance reportedly reaching several hundred dollars an hour. The Hollywood Reporter, covering the creative end of the same market, noted writers earning up to $44 an hour and music professionals with advanced degrees up to $100.

Read those numbers as an outsider and they look generous — a good hourly wage for skilled remote work. Read them as an economist and they describe something stranger: the spot price of a profession's accumulated judgement, quoted by the hour, with no premium for the decades it took to acquire. A physician's diagnostic intuition, built through medical school, residency, and years of practice, is being purchased at a rate that does not distinguish it from the labour that produced it — because the buyer does not want the career. The buyer wants the verdicts the career produces, in sufficient volume to train them out of the physician.

Why is this the cheapest path to capability? The answer lies in the changing internal economics of building a frontier model. For most of the deep-learning era, the dominant cost was pre-training — pouring the scraped text of the internet through ever-larger networks. But the internet's supply of high-quality text is finite and largely exhausted, and the frontier has shifted to what the labs call post-training: the reinforcement and refinement that turns a fluent but directionless model into one that reasons, follows instructions, and gets specialist questions right. By industry estimates, post-training has grown from a small fraction of a frontier model's compute budget a few years ago to something like a fifth or a quarter of it today, and the human data feeding that stage has become one of the most contested inputs in the industry. Individual frontier labs are reported to be spending on the order of a billion dollars a year on human training data.

Here is the economic crux. A judgement rendered by a domain expert — the correct diagnosis, the right objection, the flawed clause caught — is worth a great deal to a model precisely because it is scarce and hard to synthesise. A single well-designed expert contribution can be worth more to a training run than a hundred cheap, generic labels, because it carries information the model cannot get anywhere else. Against the cost of the alternative — building genuine medical or legal capability by some other means, if such a means even exists — a hundred-odd pounds an hour for the real thing is not expensive. It is a bargain. The displaced expert is cheap not because their expertise is worth little, but because, at the moment of the transaction, they have very little bargaining power and the buyer has a great deal. Their profession is contracting; the platform has thirty thousand alternatives; the contract is short; the rate is take-it-or-leave-it. The expertise is priceless and the expert is disposable, and the gap between those two facts is exactly where the valuation lives — and why the number keeps doubling.

What the expert takes home

Which brings us to the question the day rate is designed to make you stop asking: beyond the money for the hours worked, what does the expert actually receive?

Consider what the transaction transfers, and what it does not return. The expert supplies the most refined product of their working life — judgement that took decades and considerable expense to acquire. That judgement is distilled into a reward model and folded into a system that can be copied infinitely, never tires, never retires, and is being marketed, in many cases, into the very market the expert came from. In exchange, the expert receives payment for the hours they sat at the keyboard, and nothing else. No equity in the model their judgement helped build. No residual when that model is licensed to a hospital network or a law firm. No attribution, because their contribution is deliberately dissolved into a statistical aggregate that bears no one's name. No ongoing claim of any kind. The relationship terminates the moment the invoice is paid, but the value they contributed does not terminate — it compounds, on the balance sheet of someone else.

This is a profoundly different bargain from the ones the more organised corners of skilled labour have fought for. When SAG-AFTRA struck in 2023, one of its central demands concerned digital likeness: the principle that if a studio wanted to scan a performer and reuse their image, the performer was owed consent and continuing compensation, not a one-time buyout. The Writers Guild won terms ensuring that AI could not be credited as a writer or used to erode writers' pay. Those frameworks are imperfect and contested, but they share a premise — that when your enduring professional essence is captured and reused, you retain a stake in it. The RLHF expert retains nothing. The structure is closer to a buyout than a licence, except that in a buyout you at least know you are selling the asset. Here the asset is your judgement, the sale is disguised as an hourly gig, and the thing being bought is your future competitive position, sold at the price of your present hour.

The conditions surrounding the work make the imbalance starker. The White v. Mercor complaint alleges that the company controls its experts' hours and weekly availability, sets their pay rates, trains and supervises them, offboards those who underperform, and monitors their work through a mandatory screen-tracking application — the indicia, the plaintiff argues, of employment rather than the independent contracting under which the workers are classified. Misclassification, if proven, means no benefits, no employer pension contribution, no protections. Layered on top are the non-disclosure agreements that the reporting describes as standard across the sector, which prevent workers from discussing their clients or, in many cases, even acknowledging what they are building. And when disputes arise, arbitration clauses frequently keep them out of open court. The worker contributes the crown jewels of their profession and receives, in return, a wage, a surveillance app, a gag, and a waiver of the right to sue in public. It is difficult to design a transaction that more efficiently separates a person from the value they create.

None of this is to say the experts are foolish for taking it. The individual calculation is often unanswerable: the rate is real, the bills are real, and the model will be trained with or without any particular physician's participation. That is precisely the logic of a collective-action problem. Each expert, acting rationally alone, has every reason to take the gig. All experts, acting together, are underwriting the erosion of the scarcity that gave their expertise its value in the first place. The tragedy is not that any one of them is making a mistake. It is that there is currently no mechanism through which they could make a different choice together.

The reasoning frontier and why expert judgement became the prize

It is worth pausing on why expert feedback specifically has become so valuable so suddenly, because it explains why the professions, and not just the arts, are now in the frame.

The generation of models that dominated the early 2020s were, for all their fluency, generalists trained to sound plausible. The competitive frontier since has moved decisively towards reasoning — models that can work through a multi-step medical differential, construct a legal argument, or debug a complex system, and get the answer verifiably right. Reasoning capability is far harder to bootstrap from scraped internet text, because the internet is full of confident wrong answers and thin on the rigorous, step-by-step expert working that distinguishes a correct chain of reasoning from a persuasive but flawed one. To train a model to reason like a specialist, you need examples of specialists reasoning correctly, graded by other specialists who can tell the difference. That is a resource the open web does not contain in sufficient quantity or quality. It exists only in the heads of practitioners.

This is why the labs have moved from crowdsourced labelling to credentialed expertise, and why the going rate for a board-certified physician's feedback has climbed so far above the rate for generic annotation. The scarcer and more consequential the judgement, the more it is worth as training signal — and the more the profession that monopolised that judgement has to lose by dispensing it. The economics reward exactly the extraction that is most damaging to the expert. A profession's tacit knowledge is simultaneously its collective inheritance and, on these platforms, its most liquid asset, sold off one graded example at a time by whichever of its members most needs the cash this month.

There is a grim elegance to the sequencing. First, a profession's public output is scraped without consent to build the base model. Then, when that model proves fluent but unreliable at the hard specialist judgements, the profession's living members are hired to supply the judgements the scraping could not capture. The first act took the profession's past; the second act rents its present; and the intended product of both is a system that competes for its future. The experts are being asked to close the one gap the machine could not close on its own — and that gap was their moat.

The problem of the last cohort

Every profession renews itself through a formation process that cannot be shortcut. A doctor is made through years of supervised practice on real patients under the eyes of senior clinicians. A lawyer is made through pupillage, clerkship, the slow accretion of cases. An engineer learns which textbook solutions fail in the field by watching them fail, alongside someone who has seen them fail before. Tacit knowledge, being tacit, can only be transmitted through immersion in the doing. This is expensive and slow, and it is the mechanism by which each generation of experts equips the next.

The experts currently selling their judgement to the training platforms were formed under those conditions. Their intuition was cultivated inside functioning professions with abundant entry-level work, mentorship, and the volume of real practice that turns knowledge into instinct. They are, in effect, a reservoir of judgement filled by an institutional apparatus that assumed the demand for that judgement would continue.

Now trace the feedback loop forward. If the models trained on this cohort's judgement succeed in performing the routine specialist work — the first-pass diagnosis, the standard contract review, the initial financial model — they will absorb precisely the entry-level and mid-tier tasks through which the next cohort of experts would have been formed. You do not become a senior radiologist without first reading ten thousand ordinary scans. You do not develop a lawyer's judgement without first grinding through the routine matters that a capable model may soon handle more cheaply. Remove the bottom rungs of the ladder and you do not merely make life harder for juniors; you sever the mechanism by which senior expertise is produced at all.

This is the deeper structural problem the professional version of the story exposes, and it is distinct from any worry about the quality of a given model's output. The judgement being harvested through expert RLHF is, in an important sense, non-renewable under the conditions the harvesting creates. The models are drawing down a stock of tacit professional knowledge that was accumulated under an apprenticeship system their own success threatens to hollow out. A profession can run for a while on its inherited stock of expertise. It cannot run indefinitely on a stock it has stopped replenishing, and the experts feeding the machine today may be the last cohort formed the old way — the last generation whose judgement was grown rather than inferred. What replaces them, if the ladder is pulled up behind them, is a genuinely open question, and none of the platforms brokering the trade have any reason to answer it.

Treating expertise as labour

If the diagnosis is that experts are being paid a day rate to transfer an asset worth vastly more than the day rate, the responses fall into a few families, none sufficient alone, all more plausible together.

The first is legal reclassification, and it has already produced its first answer. In McKinney v. Scale AI, Inc., in the San Francisco Superior Court, Scale AI agreed to pay $12.5 million to settle claims of misclassification and unpaid wages covering everyone who worked as a Contributor for Scale, Smart Ecosystem, or through HireArt while resident in California between 10 December 2020 and 28 February 2026. The settlement has only preliminary approval and, as settlements do, admits no liability, so it binds no future court. What it sets is a price. The White v. Mercor suit and a parallel action against Surge AI now put the same question — contractors, or employees in all but name? — to defendants who have watched a competitor pay eight figures rather than argue it out. If the courts find that a platform which dictates hours, monitors screens, sets rates, and offboards underperformers is running an employment relationship, the economics of the entire expert-data market shift: benefits, protections, and a higher floor follow. Reclassification will not, on its own, give the expert a stake in the model. But it would end the pretence that supplying the training signal for a hundred-billion-dollar industry is a casual side gig deserving of casual treatment.

The second family is the idea, older than the current boom, that data extracted from people is a form of labour and should be compensated and governed as such. In 2018 Jaron Lanier and the economist Glen Weyl set out the framework they called data dignity, or “data as labour,” arguing that people whose data powers digital systems are owed both compensation and collective bargaining power over its use. Their proposed vehicle was the mediator of individual data — an intermediary, something between a union and a data trust, that would negotiate on behalf of many contributors at once, because no lone individual has leverage against a platform but an organised bloc of them might. Applied to expert RLHF, the logic is direct. A physician alone cannot negotiate a residual on a medical model. Ten thousand physicians, bargaining collectively over whether and on what terms their profession's judgement may be used to train their replacements, are a different proposition entirely. The expertise that is worthless-per-hour and priceless-in-aggregate is exactly the kind of asset whose value can only be captured collectively.

That points to the third response, which is collective bargaining reaching into the gap where this work happens. The guilds and unions that won AI protections — the WGA at the studios, SAG-AFTRA on digital likeness — negotiated the relationship between workers and the employers who hire them directly. The RLHF market sits deliberately outside those relationships, in a jurisdictional vacuum where the writer training a model is not, technically, working for any studio, and the physician grading medical outputs is not, technically, practising medicine. Professional bodies — medical associations, bar associations, engineering institutions — have so far treated AI mostly as a question of tools and liability. They have not yet grasped that their members' collective judgement is now a traded commodity, or that they might have standing to govern its trade. A bar association that can discipline how a lawyer practises could, in principle, take a view on the terms under which lawyers sell their judgement to train systems that will compete with lawyers. None yet has.

The fourth response is structural and speculative: models of ownership that give contributors a durable stake rather than a one-off fee. A residual or royalty on the models an expert helped train. Equity, however small, in the value created. Data cooperatives that pool professional judgement and license it collectively on terms the members set, rather than letting a platform arbitrage each member individually. These ideas are easy to sketch and hard to build, and the platforms have every incentive to resist them, because the entire margin of the business depends on paying for the hour and keeping the compounding value. But that resistance is itself the tell. If a stake were worthless, refusing to grant it would cost nothing.

The last and least comfortable response is simply to see the trade clearly and price it accordingly. Right now the expert sells cheap partly because the transaction is disguised — framed as flexible remote work, a lifeline, a way to stay current in a shifting field, rather than as what it structurally is: the sale of a profession's future to build its replacement. An expert who understood the full nature of what they were transferring might still take the gig, because the bills are still real. But they would demand more for it, and the labs' billion-dollar data budgets suggest there is more to be had. The single most valuable thing the professions could do in the near term is refuse the framing that this is marginal work deserving of marginal terms. It is the most strategically important labour in the AI economy, and the people doing it are the only ones who can supply it.

The redundancy at the centre of the word

There is a bleak pun buried in the language here. To be made redundant, in British usage, is to lose your job because your role is no longer needed. But redundancy, in engineering, means something almost opposite: a backup, a duplicate held in reserve so the system keeps running when a part fails. The expert training their replacement occupies both meanings at once. They are being made redundant in the first sense — building the thing that will render their role unnecessary. And they are functioning as redundancy in the second sense — the human backup whose judgement is being copied precisely so that, once copied, the human is no longer required to keep the system running. The whole point of the exercise is to move the expert from the second category to the first: to extract the reserve capacity and then dispense with the reserve.

What makes this distinct from the century of automation that preceded it is that the extraction requires consent, and consent, in principle, can be withheld or conditioned. The loom did not need the weaver's cooperation. The medical model needs the physician's. That dependency is the one point of leverage the professions have, and it is closing — every graded example makes the next expert slightly more dispensable — but it has not closed yet. For this brief window, the people whose judgement the machines most need are the same people who could, if they organised, set the terms on which that judgement is transferred, or decline to transfer it on terms that offer nothing but a day rate. The economics that make expert judgement the prize also make expert refusal, or expert bargaining, unusually powerful — if it could be coordinated before the reservoir is drained.

The temptation is to end on the individual, to ask how the doctor or the writer or the banker should feel about grading a machine towards their own obsolescence. But that framing, again, lands the whole weight of a structural problem on its most precarious participants, and it lets the more comfortable parties — the labs with the billion-dollar data budgets, the platforms whose valuations keep multiplying, the professional bodies that have not noticed what is being sold from under them — off the hook entirely. The individual expert taking the gig is not the author of this arrangement. They are its raw material. The real question is not whether any given professional should sell their judgement to train their replacement. It is whether a society that depends on cultivated human expertise — in its hospitals, its courts, its firms, its studios — is content to let that expertise be quietly transferred into systems owned by a handful of companies, one hourly contract at a time, in exchange for nothing more durable than the hour. That is not a decision any single expert can make at any single laptop. It is a decision about what the professions are for, and who owns what they know. Right now, the answer being written, invoice by invoice, is that they know it only until someone pays them to hand it over.

References

  1. Lesley Goldberg and colleagues, “Hollywood Workers Are Training AI Models as Job Prospects Grow Slim,” The Hollywood Reporter, 24 June 2026. https://www.hollywoodreporter.com/business/digital/ai-training-hollywood-writer-jobs-prospects-1236628302/
  2. Ruth Fowler, “I Work in Hollywood. Everyone Who Used to Make TV Is Now Secretly Training AI,” Wired, May 2026. https://www.wired.com/story/i-work-in-hollywood-everyone-who-used-to-make-tv-now-training-ai/
  3. “As Hollywood jobs dry up, workers are quietly training AI models to survive,” Digital Trends, June 2026. https://www.digitaltrends.com/movies/as-hollywood-jobs-dry-up-workers-are-quietly-turning-to-ai-training-to-survive/
  4. Marina Temkin, “Mercor quintuples valuation to $10B with $350M Series C,” TechCrunch, 27 October 2025. https://techcrunch.com/2025/10/27/mercor-quintuples-valuation-to-10b-with-350m-series-c/
  5. “AI startup Mercor now valued at $10 billion with new $350 million funding round,” CNBC, 27 October 2025. https://www.cnbc.com/2025/10/27/ai-hiring-startup-mercor-funding.html
  6. “AI Startup Misclassified 30K Workers, Suit Says,” Law360, May 2026 (regarding White v. Mercor.io Corp., No. 6:26-cv-00201, N.D. Tex.). https://www.law360.com/employment-authority/articles/2475907/ai-startup-misclassified-30k-workers-suit-says
  7. “AI Platform's 'Expert' Workforce Draws Misclassification Suit,” Law.com, 11 May 2026. https://www.law.com/2026/05/11/ai-platforms-expert-workforce-draws-misclassification-suit/
  8. “Artificial Intelligence Firms Continue To Be Targeted for Independent Contractor Misclassification Claims,” Independent Contractor Misclassification & Compliance Blog, 9 June 2026. https://www.independentcontractorcompliance.com/2026/06/09/artificial-intelligence-firms-continue-to-be-targeted-for-independent-contractor-misclassification-claims-may-2026-ic-legal-news-update/
  9. David H. Autor, Frank Levy and Richard J. Murnane, “The Skill Content of Recent Technological Change: An Empirical Exploration,” Quarterly Journal of Economics, 118(4), 2003. https://economics.mit.edu/sites/default/files/publications/skill-content-recent-technological-change.pdf
  10. Michael Polanyi, The Tacit Dimension, University of Chicago Press, 1966.
  11. Jaron Lanier and E. Glen Weyl, “A Blueprint for a Better Digital Society,” Harvard Business Review, 26 September 2018. https://hbr.org/2018/09/a-blueprint-for-a-better-digital-society
  12. “What is data dignity?” TechTarget, definition and explainer. https://www.techtarget.com/searchenterpriseai/definition/data-dignity
  13. “AI and Job Postings: From Destruction to Creation?” Indeed Hiring Lab, 8 July 2026. https://www.hiringlab.org/2026/07/08/ai-and-job-postings-from-destruction-to-creation/
  14. “RLHF Explained: How Human Feedback Trains AI Models in 2026,” Decode the Future. https://decodethefuture.org/en/rlhf-explained/
  15. “Data Annotation for AI Labs: Recruiting Guide 2026,” HeroHunt. https://www.herohunt.ai/blog/data-annotation-ai-labs-the-recruiting-guide-2026/
  16. “30,000 Professionals Are Training Their Own Replacements,” Metaintro, 2026. https://www.metaintro.com/blog/mercor-ai-training-white-collar-jobs-skills-2026
  17. “Mercor: Unlocking Human Potential in the AI Economy” (Series C announcement), Mercor, 27 October 2025. https://www.mercor.com/blog/series-c/
  18. ”'Digging the grave of my profession': the Hollywood creatives training AI to do their jobs,” The Guardian, 22 August 2026. https://www.theguardian.com/technology/2026/aug/22/the-hollywood-creatives-training-ai-to-do-their-jobs
  19. Marina Temkin, “Mercor is in talks for a $20B valuation,” TechCrunch, 9 July 2026. https://techcrunch.com/2026/07/09/mercor-is-in-talks-for-a-20b-valuation/
  20. “Nvidia Weighs Investment in Round Valuing Mercor at $20 Billion,” PYMNTS, 19 August 2026. https://www.pymnts.com/news/investment-tracker/2026/nvidia-weighs-investment-in-round-valuing-mercor-at-20-billion/
  21. “After data breach, $10B-valued startup Mercor is having a month,” TechCrunch, 9 April 2026. https://techcrunch.com/2026/04/09/after-data-breach-10b-valued-startup-mercor-is-having-a-month
  22. “Scale AI Misclassification Settlement: California Class Action” (McKinney v. Scale AI, Inc., S.F. Super. Ct. No. CGC-24-620481, preliminary approval 2026), King & Siegel LLP. https://www.kingsiegel.com/blog/scale-ai-misclassification-settlement-california-class-action/

Tim Green

Tim Green UK-based Systems Theorist & Independent Technology Writer

Tim explores the intersections of artificial intelligence, decentralised cognition, and posthuman ethics. His work, published at smarterarticles.co.uk, challenges dominant narratives of technological progress while proposing interdisciplinary frameworks for collective intelligence and digital stewardship.

His writing has been featured on Ground News and shared by independent researchers across both academic and technological communities.

ORCID: 0009-0002-0156-9795 Email: tim@smarterarticles.co.uk

Listen to the free weekly SmarterArticles Podcast

Discuss...

The venue was a United Nations conference about land turning to dust. The product on offer was electricity.

On 25 August 2026, inside the Host Country House at the seventeenth Conference of the Parties to the UN Convention to Combat Desertification in Ulaanbaatar, Mongolia's government convened an event it called “Sovereign by Design”, subtitled Mongolia's Green AI Data Centre Initiative. The Prime Minister, Nyam-Osor Uchral, opened it. His Deputy Prime Minister, Togmid Dorjkhand, pitched investors on the arithmetic of cheap power. His Minister of Digital Development, Innovation and Communications, Nomin Chinbat, told the room something more interesting than a price. “We offer more than just natural resources,” she said. “We offer safety and data sovereignty.”

By the time the twelve-day conference wound down, Mongolia had signed ten memoranda of understanding covering 863 megawatts of prospective data centre capacity. The initiative was not a solo effort. The Asian Infrastructure Investment Bank and other international partners have joined it, with up to two billion dollars in financing presented as available for eligible green and renewable infrastructure projects. One of the ten memoranda, announced the following day, was with NOVVA Group, described in its own materials as a global clean energy infrastructure platform enabling the AI economy. It was signed by Vincent Wen, the company's managing director, and by Nomin Chinbat, and witnessed by the Prime Minister himself. Its scope covers energy-efficient data centres and AI-ready infrastructure, renewable energy and storage including solar photovoltaics, wind and battery systems, site readiness, and policy consultation.

That is a lot of nouns and not many verbs. But hold the scepticism for a moment, because the easy reaction to this story is the wrong one, and the interesting reaction takes considerably more work.

The Number That Should Stop You

Mongolia's entire electricity system has an installed generating capacity of about 1.6 gigawatts. That figure, from the Stockholm Environment Institute's 2024 policy overview, is not controversial.

So the 863 megawatts of data centre capacity Mongolia signed up at COP17 amounts to roughly 54 per cent of the entire installed capacity of the country.

Not 54 per cent of spare capacity. Not 54 per cent of planned additions. Fifty-four per cent of every turbine, panel and coal-fired boiler currently connected to the Mongolian grid, committed in a fortnight, at a conference about desertification, in documents that are almost certainly not legally binding.

This is the fact around which everything else in this story orbits, and it is worth sitting with.

Why Mongolia Is Not Being Naive

Start with the strongest possible version of Mongolia's case, because it is genuinely strong, and because the reflex to patronise small states pursuing industrial policy is one of the least attractive habits in technology commentary.

Mongolia is a landlocked country of roughly 3.5 million people wedged between two nuclear-armed great powers, with essentially no third option for physical trade. Somewhere north of 90 per cent of its exports go to China, overwhelmingly coal and copper, and China supplies around 70 per cent of its imports. Its electricity grid is physically interconnected with the Russian Siberian system at 220 kilovolts, and it imported 22.3 per cent of its electricity in 2023 from China and Russia combined. When your lights depend on two neighbours who are also your only customers, “sovereignty” is not an abstraction to be deconstructed in a seminar. It is the daily condition of your existence.

Mongolia's third neighbour policy, formulated in the early 1990s, has been a decades-long attempt to manufacture optionality where geography offers none, through partnerships with the United States, Japan, South Korea, India and the European Union. Digital infrastructure is the purest possible expression of that doctrine. Fibre and compute are the only exports Mongolia can ship without asking Beijing or Moscow for permission to cross a border with a train.

The resource case is real too. Mongolia's combined wind and solar potential is estimated at around 2,600 gigawatts, more than a thousand times its installed capacity, and Ulaanbaatar is the coldest capital on earth, which means free cooling for much of the year and a thermodynamic advantage over Texas or Singapore. Dorjkhand's pitch was power below four cents per kilowatt hour against fourteen to sixteen cents in the United States, grid connection inside 24 months, and returns near 18 per cent. He also offered a line that doubles as a national brand: “we are a very cold country, eight months a year.”

And there is a strategic niche that is smarter than it first appears. Mongolia is explicitly courting customers who want to serve the Chinese market while keeping their data physically outside Chinese jurisdiction. That is a real and growing commercial need, and Mongolia's geography makes it one of very few places that can plausibly offer it.

Most importantly: everything Mongolia is doing here is exactly what development economists, multilateral lenders and Western governments have spent thirty years telling countries like Mongolia to do. Move up the value chain. Stop exporting raw rock. Attract foreign direct investment. Use your comparative advantage. Diversify away from extractive dependency. To turn round now and tell a dryland economy that it should not build compute because the electricity would be better spent elsewhere would be to pull the ladder up with unusual brazenness. The Global North built its compute freely, on coal and gas, without asking anyone's permission, and it is still building it.

So the question is not whether Mongolia should want this. The question is whether what was signed at COP17 delivers it.

Thirty-Two Countries Own the Machine Room

Here is the structural reality Mongolia is trying to escape, and it is documented with unusual clarity in a paper posted to arXiv in March 2026 and revised in July by Amirpasha Mozaffari and colleagues at the Barcelona Supercomputing Center, with co-authors at Imperial College London and the Catalan Institution for Research and Advanced Studies.

The paper is ostensibly about weather and climate information, but its infrastructure section is the most useful short description available of who owns the AI economy. Its central finding is blunt: “only 32 countries globally host the hyperscale AI data centres necessary for robust cloud-based deployment.” Thirty-two. Out of 193 UN member states. Mongolia is not among them.

The authors go further, and their argument is precisely the one Mongolia's ministers are making, arrived at from the opposite direction. Frontier models, they note, are developed almost exclusively through collaborations between national public computing centres in the Global North and East Asia and a handful of multinational firms including Google DeepMind, Nvidia, Microsoft and Huawei. This concentration “effectively gatekeeps the development of foundation models, restricting it to entities with access to exascale computing and specialised engineering talent.”

The consequence, in their words, is “a risk of technological dependency, where low-income nations are relegated to being consumers of models that are not generated for them as the main target by infrastructure they cannot audit, control, or adapt to their local contexts.” Without what they call compute sovereignty, meaning “the ability to train and fine-tune models on sovereign infrastructure, nations lack the agency to prioritise their specific regional climate vulnerabilities.”

Note the phrase. Compute sovereignty. A team of climate scientists in Barcelona, writing about forecasting inequality, independently reached for the same word Mongolia's government put on a banner in Ulaanbaatar. That convergence is not a coincidence. It is evidence that the diagnosis is correct.

The same paper supplies the resource figures that make the diagnosis uncomfortable. Data centre energy demand is projected to reach 4.5 per cent of global electricity generation by 2030. Global AI water withdrawal is projected at 4.2 to 6.6 billion cubic metres by 2027. Those are the entry costs to the club of 32. They are why the club has 32 members.

What 863 Megawatts Does to a 1.6 Gigawatt Country

The second paper in this story gives us a tool for testing Mongolia's plan rather than merely admiring it.

Posted to arXiv in March 2026 by Danbo Chen and colleagues at Ohio State University, Zhejiang A&F University and Meta Platforms, “Concentrated siting of AI data centers drives regional power-system stress under rising global compute demand” builds what the authors call an AI-energy coupling framework, combining language-model analysis of corporate, policy and media disclosures with quantitative energy-system modelling to 2030.

Its findings confirm the concentration thesis from the supply side. North America, Western Europe and Asia-Pacific together account for more than 90 per cent of projected compute capacity. Consumption by the six leading firms is projected to rise from roughly 118 terawatt hours in 2024 to between 239 and 295 by 2030, about 1 per cent of global power demand on its own. The International Energy Agency projection they cite has global data centre consumption more than doubling from about 415 terawatt hours in 2024 to roughly 945 by 2030, with the United States and China responsible for almost 80 per cent of the growth. AI infrastructure, the authors write, is “evolving from a marginal digital service into a structural component of power-system dynamics.”

The useful part is their metric. The Power Stress Index is the ratio of data centre electricity demand to total regional generation capacity. Above 0.25 is their high-stress threshold, indicating grid vulnerability. Ireland, the worst case in their dataset, approaches 0.5, which the authors observe implies AI-related consumption absorbing nearly half of local generation. Oregon exceeds the threshold. Virginia, Nebraska and Washington sit between 0.20 and 0.30. Diversified systems such as Texas, Japan and Australia stay below 0.10.

The authors did not run Mongolia. So let us run it, transparently, using their published formula and independently verified Mongolian data.

Mongolia's net electricity generation in 2024 was 8.83 terawatt hours, up 6.6 per cent on 2023. National consumption was 10.29 terawatt hours, the gap filled by imports. Now take the 863 megawatts of signed data centre capacity. At a conservative 60 per cent utilisation, that load consumes 4.54 terawatt hours a year, a PSI of 0.51 against national generation. At a more realistic 70 per cent, it is 5.29 terawatt hours and a PSI of 0.60. At 80 per cent, which is unremarkable for AI training infrastructure, it is 6.05 terawatt hours and a PSI of 0.68.

Read that against the paper's own benchmarks. At the low end of plausible utilisation, Mongolia matches Ireland, the most stressed grid in the study. At the middle and upper end, Mongolia exceeds it by a wide margin, landing somewhere no jurisdiction in the dataset occupies. Even measured against total national consumption including imports, the figures run from 0.44 to 0.59.

This is the analytical heart of the matter, and it is not a rhetorical flourish. In Virginia, a hyperscale campus is a large marginal load on a very large system. In Mongolia, 863 megawatts is not marginal. It is structural. It would be, at a stroke, the defining feature of the national power system, larger in energy terms than most of what the grid currently does. Every subsequent decision about Mongolian electricity, tariffs, dispatch, winter reserve margins, import contracts with Russia, would be taken in the shadow of that load.

The obvious rejoinder is that this is the entire point. The initiative is explicitly about building new renewable generation alongside the compute, so the denominator grows with the numerator. Good. That rejoinder is correct, and it is also precisely the thing an MOU cannot guarantee.

The Grid That Already Struggles to Get Through Winter

Because the Mongolian grid is not a blank sheet waiting for gigawatts of Gobi solar. It is a system already under acute strain.

Fossil fuels generated 91.1 per cent of Mongolia's electricity in 2024, some 8.04 terawatt hours, with coal alone at 7.93. Renewables managed 8.9 per cent, about 0.79 terawatt hours, despite making up a considerably larger share of installed capacity, which tells you how much sits idle or curtailed. The country's target under its Vision 2050 strategy is 30 per cent renewable capacity by 2030, and it is not obviously on track.

The Central Energy System, which supplies more than 70 per cent of the country, is built around Soviet-design combined heat and power plants running baseload, interconnected with the Russian grid. Those plants do double duty: they heat Ulaanbaatar, in a city where winter temperatures fall well below minus 20 Celsius. Utilisation of ageing CHP units during winter peak hours has been reported above 90 per cent, and peak capacity shortage is the acknowledged urgent problem of the Mongolian energy sector. Mongolia imports up to 300 megawatts from Russia to help cover it.

Now layer the air pollution problem on top. Households in the ger districts, largely migrants from a countryside emptied by successive dzud disasters, burn coal for heat because they lack grid connections. In the depths of winter, PM2.5 concentrations in Ulaanbaatar have been recorded at levels many multiples of World Health Organisation guidance, and the city has ranked among the most polluted on earth. The 2019 raw coal ban and the switch to briquettes cut average winter concentrations substantially, by around half against the 2016 to 2017 baseline, which was a real public health achievement won at real political cost.

Put these together and a sharp equity question emerges, one with nothing to do with foreign companies. There are Mongolian households burning coal indoors because they are not connected to the grid, in the same country now offering four-cent electricity and 24-month grid connections to foreign compute. If the new renewable build follows the data centre load, and the transmission gets built to the server halls rather than to the ger districts, Mongolia will have used its renewable endowment to decarbonise someone else's inference workload while its own citizens keep lighting stoves. That is not an inevitability. It is a design choice, exactly the kind that phrases like “sovereign by design” are supposed to govern.

Sovereignty Has a Definition and an MOU Is Not It

So what would sovereign actually mean? The word is doing enormous work in this story, and it is worth pinning down.

The concept, in its current form, was popularised less by political theorists than by a chip vendor. Jensen Huang has been evangelising sovereign AI since at least 2023, telling the World Governments Summit in Dubai in February 2024 that “every country needs to own the production of their own intelligence” and that a national model “codifies your culture, your society's intelligence, your common sense, your history.” It is a compelling argument. It is also, as critics note with some relish, one that ends with nation states becoming the next category of customer after the hyperscalers.

The Center for a New American Security has done the most rigorous work on whether the rhetoric survives contact with balance sheets. Its Sovereign AI Index, authored by Pablo Chavez, Vivek Chilukuri and Ruby Scanlon and updated in August 2026, tracks 185 sovereign AI projects worldwide, defining sovereign AI as a government-backed initiative tied explicitly to national strategic interests and backed by material public investment in domestic compute, models or data.

The findings are sobering for anyone taking the word at face value. More than 60 per cent of tracked projects disclose at least one foreign partner, and four-fifths of those partnerships involve a United States company. Nvidia alone supplies the GPUs for 45 per cent of all tracked infrastructure projects. The money is even more concentrated than the compute: the Middle East and East Asia account for over 80 per cent of disclosed investment, the UAE and Japan alone represent nearly two-thirds, and the top ten spenders account for roughly 90 per cent. The index's own summary of everyone else is that “the gap between sovereign aspiration and capacity remains vast.”

This is the pattern Mongolia is entering. Indonesia's first sovereign AI factory runs on Nvidia silicon through Indosat. Kenya's ambitions run through Cassava Technologies, again on Nvidia. India's programme, the Gulf states' programmes and Europe's all sit on the same foundation. The sovereignty on offer is real but partial: jurisdictional control over data at rest, genuinely worth having, coexisting with dependency on a foreign accelerator supply chain, foreign software stacks, foreign update cycles and foreign export-control regimes.

Set against that, here is what “sovereign by design” would need to mean if it were an engineering specification rather than a slogan. Ownership of the physical assets, or a defined path to it, rather than a long-term lease of Mongolian land and Mongolian electricity to a foreign balance sheet. Control of the model layer, meaning the capacity to train and fine-tune, not merely to host someone else's inference. Domestic skills, meaning Mongolian engineers operating the facility rather than a rotating expatriate crew. Legal jurisdiction over the data, which is the one dimension Nomin Chinbat explicitly claimed and the one most plausibly deliverable. And grid control, meaning the state retains the authority to curtail a data centre before it curtails a hospital in January.

Against that specification, what does an MOU deliver? A memorandum of understanding is generally not legally binding. It documents intentions, expectations and responsibilities before a formal contract exists. Whether any particular MOU binds anyone depends on its wording and the parties' conduct rather than the label, and the published materials for the NOVVA agreement do not specify its binding status either way. What is publicly known is that it covers four workstreams, one of which is “policy consultation”, which is to say that the foreign infrastructure developer has been given a seat at the table where Mongolia writes the rules governing foreign infrastructure developers.

That is not scandalous. It is entirely normal, and expertise has to come from somewhere. But it is the opposite of a footnote in a discussion about sovereignty, and it deserves naming rather than glossing.

What Can and Cannot Be Verified About NOVVA Group

The brief here is to be precise rather than insinuating, so let us be precise.

NOVVA Group is a real company with a verifiable, if short, public record. Its releases carry a Hong Kong dateline. Its founder and chief executive is named as Steven Liu. Vincent Wen, who signed in Ulaanbaatar, is its managing director. Its own boilerplate describes it as “a global AI-enabling energy infrastructure platform that originates, finances, builds, and operates bankable clean energy assets across Southeast Asia and Latin America.” In June 2026 it announced the acquisition of the 120 megawatt-peak San Jose Solar Power Plant in Bukidnon, Mindanao, in the Philippines, expected to generate over 200 gigawatt hours annually, and it has referenced a Colombian solar portfolio.

That is a genuine renewable developer with genuine assets. It is also a company whose disclosed operating portfolio is measured in the low hundreds of megawatts of solar, now signing a memorandum covering data centres, wind, solar, battery storage and national policy consultation in a country where a single hyperscale campus would reorganise the entire grid. No data centre operating track record appears in its public materials. That is not an accusation. It is an observation about scale and specialism that any counterparty ought to make out loud.

One further point of hygiene, because the name invites confusion. There is a separate, unrelated American company called Novva Data Centers, founded in 2020 by Wes Swenson, headquartered in Utah, backed by CIM Group, operating a 180 megawatt flagship campus in West Jordan with waterless cooling and facilities in Colorado and Nevada. Searches surface both entities together. No evidence in the public record connects the Hong Kong-based NOVVA Group to the Utah-based Novva Data Centers, and readers should treat them as distinct unless either says otherwise.

Why the Desertification Venue Is the Story, Not the Joke

It would be easy to file the setting under irony. A conference about drought produces a deal about server farms. Cue the knowing headline.

That reading is too cheap, and it misses what the venue actually reveals.

COP17 ran from 17 to 28 August 2026 under the theme “Restoring Land. Restoring Hope.”, bringing together the convention's 197 parties, and it convened during the UN International Year of Rangelands and Pastoralists 2026, declared by the General Assembly at Mongolia's own initiative. The UNCCD's executive secretary, Yasmine Fouad, framed it as the “COP of implementation”. The substantive fight was over a global drought framework left unresolved at COP16 in Riyadh, with the African Group and others pushing for a legally binding protocol and other parties preferring something non-binding.

Parties did not agree one. The framework was deferred again, to COP18. What the conference produced instead, on its closing day, was a finance portfolio of 1.3 billion dollars for land restoration and drought resilience, of which 644.5 million dollars was identified as new money. The annual financing gap it was announced against is estimated at around 278 billion dollars. Delegates confronted, at the same time, a gap between 1.5 to 2 billion hectares of degraded land and restoration pledges covering roughly 1 billion, against around 1.8 billion people affected by drought.

Hold that alongside the Mongolian numbers. Seventy-seven per cent of Mongolian territory is affected by desertification and land degradation. The country has warmed at more than twice the global average, with average temperatures up around 2.46 degrees over eight decades. Nearly all of Umnugovi province in the South Gobi, which is precisely where the best solar resource sits, is moderately or severely degraded. A World Bank assessment found Southern Gobi groundwater reserves sufficient for roughly a decade. Successive dzud events, the compound summer drought and winter freeze that kills livestock at scale, wiped out around a third of the national herd across 2001 and 2002 and more than 13 per cent in a recent event, driving the rural migration that built the coal-burning ger districts in the first place.

Now the sharp version of the observation. The conference did produce money, and it should be credited with it: 1.3 billion dollars of portfolio against a 278 billion dollar annual gap is not nothing, even if the arithmetic is unkind. What it did not produce was the thing parties came to Ulaanbaatar to settle. There is no drought protocol. There is a deferral to COP18. Set beside that, the most concrete private investment outcome of a twelve-day United Nations conference on desertification was 863 megawatts of data centre memoranda.

And the parallel structure is exact, which is now a matter of record rather than of prediction: the conference could not agree a binding instrument on drought, and the deals signed on its sidelines were non-binding instruments on compute. Ulaanbaatar in August 2026 was, in both rooms, a festival of stated intentions.

That is not hypocrisy. It is a description of how climate adaptation and digital development have been fused into a single policy narrative, in which hosting compute becomes a legitimate climate-resilience strategy because it monetises a renewable endowment that would otherwise sit in the desert doing nothing. Mongolia is not smuggling an industrial policy into a climate venue. It is making the entirely coherent argument that a dryland economy losing its pastoral base needs a new economic base, and that its sun and wind are the only endowment it has that China cannot buy on a rail wagon.

The water question is where that argument has to be tested rather than accepted. Siting energy-intensive compute in a dryland economy is not automatically absurd, because cooling technology is a choice, not a constant. Evaporative cooling in a hyperscale facility can consume on the order of 1.5 million litres a day. Closed-loop and chip-level liquid systems can eliminate evaporative water use almost entirely; Microsoft's closed-loop deployments have been reported to cut more than 125 million litres per facility per year. The Utah Novva campus, unrelated as it is, markets waterless cooling precisely because it sits in a desert. The trade-off is real, since dry cooling costs energy where water cooling costs water, but in a cold country with a stranded renewable resource, the energy penalty is the cheaper currency to pay. What matters is whether waterless cooling is contractually mandatory or merely aspirational. Nothing in the public description of the Mongolian memoranda says which.

The Jobs Nobody Counts Before Signing

One more piece of evidence ought to be in the room before any of these memoranda become contracts, and it concerns what hosting compute does for a host economy.

The most careful recent work is by Dany Bahar and Greg Wright, published through Brookings in May 2026 and updated that August. Studying counties that received data centres, they find the data processing sector grows 56 per cent over the first decade and telecommunications 43 per cent, which sounds transformative until you see the absolute numbers: roughly 100 to 200 jobs in a typical county. Wages remain unchanged. House prices rise 2 to 5 per cent. They are explicit that naive estimates which fail to account for pre-existing growth trends overstate the effect.

The fiscal side is worse. Virginia's data centre sales tax exemption cost an estimated 1.6 billion dollars in the 2025 fiscal year alone. In hyperscale counties, incentives amount to around 2 per cent of construction investment. In colocation counties, they run to about 62 per cent of total investment, meaning the largest subsidies flow to precisely the facilities that generate the fewest jobs. Other work cited alongside it suggests the net county-level employment effect can be close to zero once sectoral reshuffling is accounted for.

Apply that to Mongolia. If 863 megawatts eventually gets built, it might employ several hundred people directly. Against that, it would consume more electricity than the country currently generates, occupy the transmission build-out for a decade, and anchor tariff and dispatch policy around foreign-owned load. The construction phase would be substantial and genuinely valuable. The steady state would be a handful of buildings full of machines that employ very few Mongolians and pay their way mainly through the tax base, the electricity sales and whatever the country negotiates on top.

Which is why what gets negotiated on top is the whole ballgame.

The Conditions That Would Turn This Into Sovereignty

If Mongolia wants “sovereign by design” to be an engineering requirement rather than a conference banner, a fairly specific list would have to appear in the contracts that follow these memoranda. None of it is exotic. All of it has precedent somewhere.

Grid additionality, written as a condition precedent. No data centre load energises until the corresponding renewable generation and storage are commissioned and delivering, verified by metered output rather than by nameplate capacity or by unbundled certificates bought elsewhere. This is the single most important clause, because without it the Power Stress Index arithmetic above stops being hypothetical and starts being a winter emergency.

A curtailment hierarchy with statutory force. In a system where peak CHP utilisation already exceeds 90 per cent in winter, the state must retain an unambiguous, non-compensable right to shed compute load before it sheds heat or households. Data centres are unusually good candidates for this, since training workloads can be paused in ways that hospitals cannot.

Domestic offtake carved out at the source. A defined share of the compute reserved at cost for Mongolian public institutions, universities and firms, denominated in GPU-hours rather than goodwill. This is the difference between hosting the machine room and having access to it, and it is what the Barcelona researchers identify as the precondition for fine-tuning models on a country's own climate vulnerabilities rather than importing forecasts built for somewhere else. For a country losing a third of its herd to dzud events, that is not abstract.

Equity and a path to ownership. Sovereignty over an asset you do not own is a contradiction. Structures exist for this: state co-investment, build-operate-transfer with a defined handover, or a sovereign stake alongside the developer. A ninety-nine-year land lease with a foreign balance sheet on the other end is not one of them. Here the Asian Infrastructure Investment Bank's involvement genuinely helps Mongolia's hand, and it deserves saying rather than skipping over. Multilateral development bank money arrives with procurement standards, disclosure obligations and governance conditions attached, and it puts a counterparty in the room whose interests are not identical to the developer's. That is a materially different proposition from a pure foreign-balance-sheet lease, and it is the most plausible answer yet to the question of who funds the additional renewable generation the additionality clause would require. It is not the whole answer. Two billion dollars stated as available is not two billion dollars committed and disbursed, and availability of finance settles nothing about sequencing. Whether the generation is commissioned before the load energises remains a matter for the contracts, not the communiqué.

Water accounting written into the permit. Mandatory closed-loop or dry cooling, published withdrawal and consumption figures audited annually, and an absolute prohibition on drawing from Southern Gobi aquifers that a World Bank assessment already put on a roughly ten-year clock. In a country where 77 per cent of the land is degraded, water disclosure is not an ESG nicety, it is the licence to operate.

Skills transfer with numbers attached. Not “capacity building” in a recital, but a specified count of Mongolian engineers trained and employed in named roles by a named date, with financial consequences for missing it, and a route into the model layer rather than only the facilities layer.

Jurisdiction stated explicitly. If the pitch is that data stored in Mongolia stays outside Chinese and Russian reach, then the governing law, the location of arbitration, the ownership chain of the operating entity and the treatment of foreign government access requests all have to be pinned down in public. The claim of data sovereignty is the most valuable thing Mongolia is selling and the easiest thing to quietly undermine in a schedule.

Publication. All of the above, disclosed. Ten memoranda were signed in a fortnight covering more than half the country's installed capacity, and the public record consists largely of press releases. Parliament, and the ger district households who will live with how the transmission gets built, are entitled to see the terms.

What This Tells Us About Who Gets to Play

Mongolia's ministers were making an argument that the evidence supports. Thirty-two countries host the infrastructure. Three regions hold more than 90 per cent of projected compute. The top ten sovereign AI spenders account for around 90 per cent of disclosed investment. That is not a market outcome anyone should be relaxed about, and a country trying to force its way into that club with the one endowment it has is doing something rational and, on the merits, defensible.

But the terms of entry are the point. Mongolia is being offered membership of the AI economy in the role of landlord: providing the land, the wind, the sun, the cold air and the regulatory accommodation, while the accelerators, the models, the customers and the margin remain somewhere else. That is a real economic relationship and it may well be worth having. It is not what the word sovereign means, and the gap is where the next twelve months of contract drafting will decide the outcome.

The encouraging thing is that the gap is closeable through instruments Mongolia already controls. Additionality clauses, curtailment rights, domestic GPU-hour allocations, water permits and equity stakes are all within the gift of a state with something scarce to sell, and Mongolia does have something scarce to sell. Its leverage is highest now, before the concrete is poured and the load is on the system.

What was signed in Ulaanbaatar was not sovereignty. It was an option on sovereignty, written in non-binding language, at a conference that could not agree binding language about drought either. Ten days on, none of the memoranda signed at that event has been reported as converting into a definitive contract. They remain exactly what they were on the day they were witnessed: statements of intent. Options expire. This one runs on the same clock as the Southern Gobi's groundwater and the country's ability to build 863 megawatts of new clean generation before it is asked to switch on the load.

Sources and References

  1. PR Newswire, via The Manila Times, “NOVVA Group and Mongolia's MDDIC sign MOU on clean-powered AI infrastructure, supporting Mongolia's 'Sovereign by Design' green AI data centre initiative”, 26 August 2026. https://www.manilatimes.net/2026/08/26/tmt-newswire/pr-newswire/novva-group-and-mongolias-mddic-sign-mou-on-clean-powered-ai-infrastructure-supporting-mongolias-sovereign-by-design-green-ai-data-centre-initiative/2412402
  2. Euronews, “Mongolia positions itself as Asia's next data centre hub”, 25 August 2026. https://www.euronews.com/2026/08/25/mongolia-positions-itself-as-asias-next-data-centre-hub
  3. Amirpasha Mozaffari, Amanda Duarte, Lina Teckentrup, Stefano Materia, Gina E. C. Charnley, Lluís Palma, Eulalia Baulenas Serra, Dragana Bojovic, Paula Checchia, Aude Carreric and Francisco Doblas-Reyes (Barcelona Supercomputing Center, Imperial College London, ICREA), “The Rise of AI in Weather and Climate Information and its Impact on Global Inequality”, arXiv:2603.05710v2, 5 March 2026, revised 29 July 2026. https://arxiv.org/abs/2603.05710
  4. Danbo Chen, Zijun Zhou, Yongyang Cai, Jiahong Qin, Ani Katchova and Lei Chen (Ohio State University, Meta Platforms, Zhejiang A&F University), “Concentrated siting of AI data centers drives regional power-system stress under rising global compute demand”, arXiv:2604.06198v1, 13 March 2026. https://arxiv.org/abs/2604.06198
  5. Stockholm Environment Institute, “Solar and wind power in Mongolia: 2024 policy overview”, October 2024. https://www.sei.org/wp-content/uploads/2024/10/solar-and-wind-power-in-mongolia-2024-policy-overview-sei2024-046.pdf
  6. Asian Development Bank, “Unlocking Mongolia's Rich Renewable Energy Potential”. https://www.adb.org/news/features/unlocking-mongolias-rich-renewable-energy-potential
  7. Low Carbon Power, “Mongolia Electricity Generation Mix”, 2026. https://lowcarbonpower.org/region/Mongolia
  8. Worldometer, “Mongolia Electricity”, 2024 data. https://www.worldometers.info/electricity/mongolia-electricity/
  9. World Energy Council, “World Energy Trilemma: Mongolia Country Profile”, February 2025. https://www.worldenergy.org/assets/downloads/Asia_Trilemma_MONGOLIA_Profile_Template.pdf
  10. Pablo Chavez, Vivek Chilukuri and Ruby Scanlon, Center for a New American Security, “Sovereign AI Index”, April 2026, updated August 2026. https://interactives.cnas.org/reports/sovereign-ai-index/
  11. Dany Bahar and Greg Wright, Brookings Institution, “New evidence on data center employment effects”, 4 May 2026, updated 10 August 2026. https://www.brookings.edu/articles/new-evidence-on-data-center-employment-effects/
  12. NVIDIA, “NVIDIA CEO: Every Country Needs Sovereign AI”, remarks by Jensen Huang at the World Governments Summit, Dubai, 12 February 2024. https://blogs.nvidia.com/blog/world-governments-summit/
  13. UNCCD, “UNCCD 17th session of the Conference of the Parties (COP17)”, 17 to 28 August 2026. https://www.unccd.int/cop17
  14. Down To Earth, “UNCCD COP17 opens in Ulaanbaatar with a single demand: enough declarations, turn land pledges into money and action”, August 2026. https://www.downtoearth.org.in/climate-change/unccd-cop17-opens-in-ulaanbaatar-with-a-single-demand-enough-declarations-turn-land-pledges-into-money-and-action
  15. World Resources Institute, “STATEMENT: COP17 Advances Finance but Falls Short on Global Drought Action”, August 2026. https://www.wri.org/news/statement-cop17-advances-finance-falls-short-global-drought-action
  16. PR Newswire Asia, “NOVVA Group acquires 120 MWp Philippines solar project, anchoring its AI-era power platform in Southeast Asia”, 19 June 2026. https://www.prnewswire.com/apac/news-releases/novva-group-acquires-120-mwp-philippines-solar-project-anchoring-its-ai-era-power-platform-in-southeast-asia-302805075.html
  17. Novva Data Centers (Utah, USA), “About Us”. https://www.novva.com/about/
  18. United Nations Development Programme, “Saving the Gobi Desert and Mongolian steppes from the dzud will also save lives and livelihoods”. https://www.undp.org/blog/saving-gobi-desert-and-mongolian-steppes-dzud-will-also-save-lives-and-livelihoods
  19. United Nations Development Programme Mongolia, “For a Thriving Mongolia: The Fight Against Biodiversity Loss, Climate Change, and Desertification”. https://www.undp.org/mongolia/stories/thriving-mongolia-fight-against-biodiversity-loss-climate-change-and-desertification
  20. The Diplomat, “Toxic Winter: The 'Slow Violence' of Air Pollution in Mongolia”, December 2022. https://thediplomat.com/2022/12/toxic-winter-the-slow-violence-of-air-pollution-in-mongolia/
  21. IQAir, “Ulaanbaatar among top 10 most polluted cities in the world”, 19 November 2025. https://www.iqair.com/newsroom/ulaanbaatar-among-top-10-most-polluted-cities-in-the-world-11-19-2025
  22. Congressional Research Service, “Mongolia”, In Focus IF10926, 12 February 2025. https://www.everycrsreport.com/files/2025-02-12_IF10926_ec6374a0a1dec1eb1dc79d1f4b0a98345772ab84.html
  23. Geopolitical Monitor, “Mongolia's 'Third Neighbor': Balancing between China, Russia, and the U.S.“. https://www.geopoliticalmonitor.com/mongolias-third-neighbor-finding-balance-between-china-russia-and-the-u-s/
  24. Environmental and Energy Study Institute, “Data Centers and Water Consumption”. https://www.eesi.org/articles/view/data-centers-and-water-consumption
  25. Uptime Institute, “Water is local: generalities do not apply”. https://journal.uptimeinstitute.com/water-is-local-generalities-do-not-apply/

Tim Green

Tim Green UK-based Systems Theorist & Independent Technology Writer

Tim explores the intersections of artificial intelligence, decentralised cognition, and posthuman ethics. His work, published at smarterarticles.co.uk, challenges dominant narratives of technological progress while proposing interdisciplinary frameworks for collective intelligence and digital stewardship.

His writing has been featured on Ground News and shared by independent researchers across both academic and technological communities.

ORCID: 0009-0002-0156-9795 Email: tim@smarterarticles.co.uk

Listen to the free weekly SmarterArticles Podcast

Discuss...

On 27 August 2026, Latrobe Council in north-west Tasmania released a development application it had been sitting on while it waited for the applicant to answer questions. The document described a 52-megawatt artificial intelligence data centre on the site of the old paper mill at Wesley Vale, in an industrial estate called Mill Park. A data hall of 2,689 square metres. Twenty adiabatic cooling units and twenty chillers. Forty diesel backup generators. Seventy jobs during construction, twenty once the thing was running.

Residents were given fourteen days to respond. Submissions close on 9 September.

Four days after that application became public, on 31 August, a parliamentary e-petition closed on the Tasmanian House of Assembly website. It had been open since 22 June, sponsored by Cecily Rosol, the Greens member for Bass. It asked Parliament to direct the government to impose an immediate moratorium on all non-complete AI and data facilities in the state. When it closed, it carried 10,035 signatures. It was tabled in the House on 2 September, one of the largest e-petitions in the history of Tasmanian parliamentary democracy.

Set those two numbers next to each other and you have the entire problem in miniature. Ten thousand and thirty-five people spent ten weeks assembling a demand to be consulted. The people who live within earshot of the actual proposal got a fortnight to write a letter about it. The petition is not a planning instrument. It has no legal force. It cannot stop a single generator being installed. It is, in the most literal sense, a request for permission to have an opinion that counts.

What Ten Thousand Names Actually Asked For

The petition text is worth reading closely, because it is not the blunt refusal that the word moratorium implies. It asks for five specific things, and every one of them is a piece of ordinary regulatory plumbing that most industrialised jurisdictions already possess for facilities of comparable scale.

It asks for planning legislation that addresses the environmental and social impacts of AI facilities. It asks for a public register tracking the energy and water these operations consume. It asks for parliamentary oversight of any facility drawing more than 50 megawatts. It asks for guarantees of lasting local employment. And it asks that ordinary electricity customers be shielded from price rises caused by connecting AI facilities to the grid.

The moratorium is the lever, not the goal. The petition proposes a pause that ends when those five instruments exist. That is a substantively different proposition from a permanent veto, and the distinction matters enormously for how you judge what the signatories were doing.

Tabatha Badger, the Greens member for Lyons and the party's spokesperson for science and information technology, framed the demand in terms of parliamentary process rather than opposition to computing. Speaking after the petition was tabled, she called for a moratorium on new AI and data facilities until there is proper regulation and until Parliament has oversight of the energy and water that will be committed to them. Rosol, tabling it, made the point that the community had been clear about its concerns and that the government had proceeded without consulting them or putting guardrails in place.

Behind the language is an observation about sequence. The facilities are arriving first. The rules, if they arrive at all, will arrive second, and will apply to whatever has not yet been built.

The Arithmetic of a Small State

Australian Bureau of Statistics figures put Tasmania's estimated resident population at 579,110 at the end of December 2025. Against that denominator, 10,035 signatures is roughly 1.7 per cent of every man, woman and child in the state.

Proportion is the only honest way to read a petition from a small jurisdiction, and it is the reading that almost never happens when these numbers travel. Scaled to the United Kingdom, 1.7 per cent would be something over a million signatures. Scaled to the United States, close to six million. Scaled to New South Wales, around 145,000. Petitions of that magnitude do not get filed away. They generate select committees.

The comparison inside Tasmania is equally instructive. The largest e-petition the House of Assembly had previously seen came in 2020, supporting the End of Life Choices Bill, and gathered 11,699 electronic signatures alongside 1,383 on paper. That was a petition about assisted dying, an issue with decades of organised advocacy behind it, deep personal stakes for thousands of families and sustained media attention across the entire state.

The AI data centre petition got to 10,035 in ten weeks, on a subject that barely existed in Tasmanian public conversation eighteen months earlier, driven by a minor party. It drew more than 4,200 signatures in its first week. Whatever else that tells you, it tells you the concern is not confined to the handful of postcodes that would host the buildings.

Four Hundred and Forty Megawatts in a Hydro State

The proposals that triggered all this belong to Firmus Technologies, a Singapore-headquartered company run by co-chief executives Tim Rosenfield and Oliver Curtis. It has three Tasmanian sites in play, representing a stated investment of around 2.1 billion dollars.

The first, at St Leonards outside Launceston, is 104 megawatts and already under construction, with power contracted from Aurora Energy and an expected start in early 2027. The second, at Bell Bay on the site of the former pulp mill, is 288 megawatts and was approved with conditions by George Town Council on 25 August 2026. The third is Wesley Vale, at 52 megawatts, the one Latrobe residents were given a fortnight to comment on.

Together that is around 440 megawatts of continuous industrial load in a state whose electricity system was built for aluminium smelting, zinc refining and a few hundred thousand households. An energy consultant told the ABC in June that the three sites combined would represent roughly 20 per cent of Tasmania's total energy consumption, more than the combined demand of every household in the state. Firmus would become, comfortably, Tasmania's largest single power user.

Those are the numbers attached to the buildings. The number attached to the grid arrived on 4 September, when the ABC reported that Hydro Tasmania is assessing a request from Firmus for a long-term contract to supply 450 megawatts across the three sites. The company currently runs on a three-year contract for the 104 megawatts that powers St Leonards. What it has asked for now is different in kind: a standing commitment rather than a short one, at a volume Hydro puts at up to 30 per cent of Tasmania's current electricity consumption, comfortably ahead of Bell Bay Aluminium, the state's present largest user, at 355 megawatts. The two percentages describe different things and are not in conflict. The June estimate of roughly 20 per cent was a consultant's read of what the three sites would be likely to consume. The 30 per cent figure is Hydro's read of the contract now sitting on its desk.

Hydro says it expects an outcome by the end of 2026, and it has set out the four questions it is weighing: whether Firmus is financially stable, what new renewable generation would have to be built to serve the load, whether the arrangement is profitable for Tasmania, and whether it is consistent with Hydro's responsibilities to Tasmanians. Alongside those it said something more consequential than any of them. Tasmania's energy system is currently in balance, generating about what the state consumes, and a request of this size can only be met by building new wind and solar. Hydro would not build or fund it. Firmus would contract directly with third-party developers, or contract with Hydro and have Hydro firm the intermittent output.

That is a decision the planning system neither makes nor reviews. Two councils assess two buildings against two planning schemes, while a state-owned company decides, on commercial terms and to its own timetable, whether there is 450 megawatts to sell.

Tasmania is not a bad place to put a data centre, and it is important to say so plainly. The grid is dominated by hydroelectricity, the climate is cool enough that mechanical cooling runs less often, industrial land at decommissioned mill sites is available and serviced, and the state government has actively marketed itself into exactly this business. The Office of the Coordinator-General, the arm of the Department of State Growth responsible for attracting major investment, lists data centres as an emerging sector opportunity and offers case management to any project involving at least five million dollars of private investment or twenty-five full-time jobs. Australia's National AI Plan, published on 2 December 2025, identifies sovereign digital infrastructure as a strategic priority and sets an explicit objective of attracting hyperscale capacity onshore.

None of that is secret. What is not public is which other proponents the Office of the Coordinator-General is currently talking to, at what scale, on what sites, or how far those conversations have progressed. That is the specific complaint the Greens raised alongside the petition: that while Wesley Vale goes through a council assessment with a fourteen-day comment period, other proposals are being developed in a process with no comment period at all, because there is nothing yet to comment on.

Two Degrees on the Ground

The environmental case the petitioners are making rests partly on a body of research that is very new, and it deserves to be represented accurately rather than inflated.

A preprint posted to arXiv in March 2026 by a group of researchers including Andrea Marinoni, Erik Cambria, Weisi Lin, Mauro Dalla Mura, Jocelyn Chanussot and Benjamin Horton examined satellite-derived land surface temperature data across multiple decades for regions surrounding AI data centres worldwide. Their finding, stated in those terms, is that land surface temperature increases by 2 degrees Celsius on average after the start of operations of an AI data centre, producing what they call the data heat island effect. They estimate that more than 340 million people could be exposed to these localised increases.

Two qualifications matter. Land surface temperature is not air temperature, and the two diverge substantially, particularly over hard surfaces on sunny days. And a satellite study of this design establishes an association between the commencement of operations and a measured warming signal; it cannot fully isolate the data centre from the industrial estate, road network and land clearing that typically arrive with it. This is a preprint, not yet through peer review.

What it does establish is that the warming signal is measurable, consistent across sites and large enough to matter. For a facility at Wesley Vale sitting in an agricultural district, and for a facility at Bell Bay less than two kilometres from the small community of Rowella, that is a question worth an answer before approval rather than after. Tasmania's planning scheme does not currently require anyone to ask it.

The Water Nobody Had Agreed to Supply

The water question in Tasmania produced the single most revealing document in this entire episode, and it was published by accident.

In July 2026, the ABC reported that Firmus had inadvertently published internal notes on the frequently asked questions page for its Wesley Vale facility. Among them was a line explaining why the company had not yet disclosed where its cooling water would come from. It planned to draw on Tasmanian Irrigation, the state-owned agricultural water scheme, and the note read: “We do not want to highlight this yet, as they are yet to agree to supply us.” The content was deleted after the ABC made enquiries. Firmus described it as internal information that was inadvertently published.

Tasmanian Irrigation responded that its legislative framework is set up to enable the supply of water for agriculture and hydrogen production. Neil Grose, chief operating officer of TasFarmers, put it more directly: irrigation water is for irrigating farmland. By the time the development application was released in August, the irrigation plan had gone. The company now proposes rainwater capture supplemented by trucked water in extreme dry periods, with evaporative cooling engaged only when ambient temperature exceeds 26 degrees. Firmus has said the Wesley Vale facility at full capacity would use about as much water annually as a restaurant.

That may well be true of the site. It is not the only relevant question, and a preprint posted to arXiv in June 2026 by Basit Akinade, Amobichukwu Amanambu, Jonathan Frame and Shaolei Ren explains why. The paper formalises what the authors call the Water and AI Feedback Loop and introduces a Water Consumption Impact index designed to measure burden at the level of the community utility rather than the facility. Applied across ten United States locations, the index produced results ranging from 0.2 per cent to 134 per cent of host capacity.

That range is the finding. A data centre's water demand is not meaningfully described by its absolute volume. It is described by the volume relative to the system that has to supply it, and in the worst case in the sample, a single facility's requirement exceeded the entire capacity of its host utility. A restaurant's worth of water is a trivial number in Hobart and a considerably less trivial one in a rural scheme during a dry February.

The aggregate picture comes from a third preprint, posted to arXiv in January 2026 by Aadi Patel, Nikhil Mahalingam and Rusheen Patel. Drawing on International Energy Agency projections that global data centre electricity demand may rise from roughly 415 terawatt hours in 2024 to nearly 945 by 2030, the authors project that United States AI servers alone will consume an additional 200 to 300 billion gallons of water annually and generate 24 to 44 million tonnes of carbon dioxide equivalent by 2030. These are projections built on demand forecasts, with all the fragility that implies, and the authors are explicit that cooling design and siting are the dominant variables. Advanced cooling can cut cooling energy by up to half, they find, and locating in low-carbon, water-secure regions can nearly halve the combined footprint.

Which is, read fairly, an argument for putting these facilities in Tasmania. It is also an argument for deciding deliberately how many, where, and on what terms.

A Planning Act Written in 1993

The instrument George Town Council used to assess a 288-megawatt AI facility was the Land Use Planning and Approvals Act 1993. It was drafted before the commercial web existed.

Mayor Greg Keiser, announcing the approval, said the council could not see any other grounds to do anything more than approve it. That is not evasion. It is a precise description of how a discretionary planning decision works. A council assesses an application against the criteria in the scheme. If the application satisfies them, refusal is not lawfully available, regardless of how many residents object or how novel the use is. Cumulative regional impact, statewide water allocation, grid economics and social licence are simply not criteria in the scheme.

Peter Freshney, mayor of neighbouring Latrobe, said the same thing about the legislation from the other side of the argument: the current scheme is not fit for purpose for evaluating projects of this scale. Two mayors from two councils assessing two facilities for the same company reached the same conclusion about the tool they were given.

Tasmania does have larger instruments. A Major Project declaration by the Minister for Planning triggers assessment by a panel of the independent Tasmanian Planning Commission alongside subject-matter experts, taking in matters a single council cannot reach. A Project of State Significance declaration under the State Policies and Projects Act 1993 goes further still, requiring an order approved by both Houses of Parliament. Latrobe Council has discussed asking for the Wesley Vale proposal to be declared a major project. Neither pathway has been triggered for any of the three Firmus sites.

There is now a layer above all of it, and the timing of that layer is the point. On 15 July 2026 the Prime Minister, Anthony Albanese, announced that the federal government would legislate mandatory Australian Standards for artificial intelligence, and established an Office of AI within the Department of the Prime Minister and Cabinet. New large AI data centres would be required to underwrite or supply their own power and to minimise their water use, with the stated expectation that facilities of that scale be net generators in energy terms rather than net consumers. On 26 August 2026 National Cabinet endorsed the Commonwealth's plan to legislate national AI laws and mandatory standards for large data centres. It was the first time all nine Australian governments, the Commonwealth and the eight states and territories, had committed to a common set of mandatory standards. Tasmania is one of the nine. The endorsement came one day after George Town Council approved a 288-megawatt facility under an act written in 1993.

The standards, as outlined, run to three domains. On energy, large operators would act as net generators, adding at least as much to the grid as they draw, pay the full cost of transmission and distribution connection, adopt efficiency measures, and offer demand flexibility to support grid stability. On water, they would minimise consumption, maximise efficiency and fund the additional infrastructure their facilities require. On land use, they would be steered towards appropriate locations, made to protect competing uses such as housing, and required to engage the communities that host them. They are aimed at large-scale facilities, co-location sites, hyperscale operations and large-scale AI compute centres, not at small edge or on-site enterprise data centres. They would sit on top of state planning regimes rather than replace them, so a developer would have to satisfy both the national standards and the usual state and local approvals. And they are not law. The Commonwealth has said it intends to legislate in early 2027, and the detailed specifications are still being written.

Then there is the appeal window. Objectors to the Bell Bay approval have fourteen days from formal notification to lodge a challenge with the Tasmanian Civil and Administrative Tribunal, a window that, counted from the approval on 25 August, closes in the first week of September. No appeal has been confirmed as lodged. Anne-Marie Bastian, president of the Environmental Awareness Association, called it a ludicrous time frame, with estimated legal costs of 20,000 to 50,000 dollars. Fourteen days to raise the price of a small car and instruct counsel, against a company with 2.1 billion dollars of announced investment.

The asymmetry is not a conspiracy. It is what happens when a process designed for a service station is applied to a facility that will draw a fifth of a state's electricity.

The Room Where the Conversation Happens First

Every planning system has a stage before the planning system. In Tasmania it is called strategic project facilitation, and it is run out of the Office of the Coordinator-General.

There is nothing sinister in the concept. Investment attraction agencies exist everywhere, and companies do have legitimate commercial reasons to keep site selection confidential while they negotiate land and power. A proponent who announces a shortlist watches land prices triple. That is a real cost and a real justification.

But the confidentiality has a second effect that is rarely acknowledged. By the time a project surfaces as a development application, the proponent has typically secured land options, negotiated grid connection, engaged consultants, commissioned technical studies and, frequently, obtained government statements of support. The community's fourteen days begin at the point where the commitment is already substantially sunk. Consultation is technically available and practically vestigial.

International experience shows how far this can be pushed. In Pennsylvania, Spotlight PA obtained at least eight non-disclosure agreements signed by township supervisors, county commissioners and state cabinet officials with data centre developers including Amazon Web Services, Vantage, Quality Technology Services and Talen Energy. Most did not define what counted as confidential. Melissa Melewsky, media law counsel for the Pennsylvania NewsMedia Association, observed that any time a private company tries to limit what a public official can say about public business, that is a red flag. The reporting produced a legislative response, with a bill conditioning tax exemptions on a pledge not to use non-disclosure agreements passing the state House 171 to 31, and an executive order prohibiting such agreements for data centre projects.

There is no reporting that Tasmanian officials have signed non-disclosure agreements over these projects, and it would be wrong to imply otherwise. The point is structural. Where a state agency's function is to attract investment, and its method is confidential case management, the default setting is that the community learns last. Tasmania does not need American-style secrecy agreements to arrive at the American-style outcome, because the outcome falls out of the sequence rather than the paperwork.

What Happened in Zeewolde, Cerrillos and Prince William

Communities elsewhere have won these fights, and how they won is more instructive than that they won.

In the Netherlands, Meta proposed what would have been Europe's largest data centre at Zeewolde, having acquired roughly half of a 166-hectare site. Local opposition alone did not stop it. What stopped it was that part of the land belonged to the Dutch state, which meant the sale required parliamentary approval, and the Senate voted to block that sale pending a national spatial planning vision for data centres. Meta abandoned the project in 2022. The lever was a national land ownership question that happened to sit in the path of the project.

In Chile, Google's 200 million dollar data centre at Cerrillos in Santiago would have used 7.6 million litres of potable water a day drawn from the Central Santiago aquifer in a country fifteen years into drought. In February 2024 an environmental court partially reversed the permit, requiring the assessment to incorporate the effects of climate change on the water component and contemplating a possible modification of the server cooling system. Google switched its design to air cooling and restarted the process. The lever was a specialist environmental court with jurisdiction to review the adequacy of an assessment.

In Virginia, the Prince William Digital Gateway involved rezoning around 1,700 acres. In August 2025 Circuit Court Judge Kimberly Irving voided the rezoning, not on environmental grounds but because the county had failed to comply with statutory advertising requirements before the December 2023 hearings; the first of two required newspaper notices was never actually published. The Virginia Court of Appeals affirmed in March 2026, and the QTS affiliate behind the project subsequently withdrew, ending it. The lever was a procedural notice rule.

In Memphis, the Southern Environmental Law Center appealed the Shelby County Health Department's air permit for fifteen methane gas turbines at xAI's data centre on behalf of the NAACP's Memphis branch and Young, Gifted and Green, arguing that the department had wrongly treated the turbines as exempt non-road engines under the Clean Air Act and had thereby allowed installation without written approval, public notice or pollution controls. The lever was federal air quality law.

In Ireland, the constraint is grid physics translated into regulation. Central Statistics Office figures show data centres consumed 7,663 gigawatt hours in 2025, 23 per cent of all metered electricity in the state, up from 5 per cent in 2015. EirGrid has not been offering new data centre connections in the Dublin region, a position understood to run to at least 2028, while the Commission for Regulation of Utilities has reworked large energy user connection policy around location, on-site generation and demand flexibility. The lever was the transmission system operator's technical judgement.

Land title. Environmental courts. Newspaper advertisements. Air permits. Grid capacity. Not one of these communities won by objecting. Every one of them won because some pre-existing instrument, usually designed for something else entirely, happened to have teeth. Tasmania's petitioners are asking for an instrument that is actually designed for the purpose, in advance, rather than hoping one turns up.

The Case for Saying Yes

The strongest version of the argument against the petitioners is considerably better than its opponents usually allow, and it has four parts.

The fiscal part is the most concrete, and Loudoun County in Virginia is the demonstration. The county states that data centres generate almost half of its property tax revenues, that for every dollar in services the county provides to data centres it receives twenty-six dollars in tax revenue, and that without the industry its real property tax rate would likely exceed one dollar per hundred dollars of assessed value against a current rate of 80.5 cents. Data centres contributed 16 billion dollars to a 41 billion dollar real property portfolio in 2024, at assessed values per square foot roughly triple other commercial uses. That revenue funds schools. It is not a rounding error, and it is not hypothetical.

The strategic part is that compute is becoming infrastructure. If Australia processes its health records, its defence modelling and its financial system on servers in Virginia and Singapore, it has outsourced a category of national capability that it cannot readily repatriate. The National AI Plan's emphasis on sovereign digital infrastructure follows from that, and hosting in a jurisdiction with a hydro-dominated grid is a better climate outcome than hosting the same workload on a coal-heavy one.

The systems part is the least intuitive and the most serious. A data centre concentrates load that would otherwise be distributed across thousands of premises. A concentrated load is visible, meterable, and negotiable. It can be required to report consumption, to shift timing, to fund transmission, to sign firm renewable contracts. The same computation spread across a million individual devices is regulable by nobody. Concentration is what makes accountability technically possible. Firmus has pledged to build two megawatts of new renewable generation for every megawatt it consumes, which is a commitment no diffuse load could ever be asked to make.

The engineering part is that cooling design is genuinely improving. Closed-loop liquid cooling recirculates a fixed charge of coolant rather than evaporating water continuously. The Firmus design at Wesley Vale engages evaporative cooling only above 26 degrees ambient, which in north-west Tasmania is a small number of hours a year. Yesterday's water figures do not describe today's plant.

And the political part, which the petitioners should take most seriously, is that moratoria have a way of not ending. The Rockefeller Institute of Government has tracked a spreading pattern of local pauses across the United States, from Groton in Connecticut to Peculiar in Missouri to Bangor in Maine, and municipalities in New York including Lysander, which adopted a six-month moratorium in May 2026, and the Town of Perth, which passed a one-year pause in June. Around fourteen states have considered moratorium legislation, with thresholds ranging from one megawatt to a hundred. A pause pending regulation is only meaningful if the regulation actually gets written. Otherwise it is a veto wearing a deadline.

Where the Case for Yes Runs Out

Take them in order.

The Loudoun figures are real, and they are also a warning rather than a model. A county deriving half its property tax base from a single industry has not diversified its economy, it has concentrated its risk, and the concentration is in an industry whose capital cycle is measured in a few years and whose demand depends on a technology thesis that may not hold. More to the point, the Loudoun bargain is not on offer at Wesley Vale. Twenty ongoing jobs is the number in the application. Tasmania does not levy a personal property tax on computer equipment the way Virginia does. The revenue mechanism that produces the Loudoun outcome does not exist here, so citing Loudoun as a reason to approve a Tasmanian facility is citing a fiscal system the state has not got.

The sovereignty argument is sound and does not resolve anything. Sovereign compute capability is a national interest; where a specific building goes, how much water it draws in a dry summer and who pays for the transmission upgrade are local questions. Answering a local question with a national one is a category error, and it happens constantly. Firmus is a private company selling AI tokens on a commercial market. Its facilities may serve sovereign capability. That is a reason to have a national siting framework, not a reason for Latrobe Council to approve an application in fourteen days.

The concentration argument is the best one, and it is self-refuting in the current arrangement. Yes, concentrated load is regulable. That is exactly why the absence of regulation is the problem rather than an argument against pausing. The petition asks for a public register of energy and water consumption and parliamentary oversight above 50 megawatts. Those are precisely the instruments that make concentration an advantage. Without them, concentration delivers all the exposure and none of the leverage. A pledge to build two megawatts of generation for every one consumed is worth a great deal in a supply contract and considerably less in a press release, and the distance between those two documents is most of what the petition is about.

The cooling argument is true and incomplete. Closed-loop and adiabatic designs do reduce water use, and the 26 degree threshold is real. But water is only one vector. The data heat island preprint measured land surface temperature, which responds to waste heat rejection regardless of whether the heat is carried away by air or water. Forty diesel generators produce emissions and noise, with the acoustic assessment already recommending additional mitigation. And a facility's cooling design is a commitment made at approval, in a document, about equipment that will be replaced several times over the life of the building.

The permanent-veto risk is the one legitimate hit. It should be answered by writing a sunset into the moratorium, not by declining to have one. A pause that lapses automatically when the register, the threshold and the oversight mechanism are in force is a schedule, not a ban.

The Tasmanian government has rejected the moratorium. Felix Ellis, the minister responsible, has said a statement of expectations for AI data centres will be released within the government's current hundred-day period, with energy and water among its key features, and that it is intended to build on the Australian Government's expectations for data centres and AI infrastructure developers, published in March 2026. As of the first week of September it has not appeared. A parliamentary inquiry established at the Greens' instigation is taking submissions until 21 September, and its recommendations will be non-binding.

A statement of expectations is not a law. It is a document describing what a government would like companies to do. Ehsan Noroozinejad, a researcher at Western Sydney University, gave the ABC the framing that matters: the key issue is ensuring private investment does not transfer costs or environmental risks to communities. Nothing in a statement of expectations prevents that transfer, because nothing in it binds anyone.

The strongest answer to that is federal, and it should be stated at full strength. Three of the petition's five asks, the treatment of energy, the treatment of water and the transfer of costs to other customers, are addressed in substance by the mandatory standards National Cabinet endorsed on 26 August. A requirement to act as a net generator and to pay the full cost of connection is a more demanding instrument than anything the petition asked for, and it would apply nationally rather than resting on the goodwill of one state government. If those standards are legislated in the form described, a good part of the Tasmanian argument will have been settled somewhere else. The qualification is the calendar, and it is the Commonwealth's own: early 2027, specifications unwritten, applying to what has not yet been approved.

What would look different is not complicated, and it is mostly what the petition asks for. Publish consumption. A register of actual metered energy and water use per facility, reported quarterly, converts every subsequent argument from a contest of adjectives into a contest of numbers. Ireland's data centre debate is more grounded than Australia's for exactly one reason: the Central Statistics Office publishes the figure, so nobody can claim it is 5 per cent when it is 23.

Set a threshold that changes the pathway. Above 50 megawatts, a facility should not be assessed by a single council under an act from 1993 against criteria that do not include the thing everybody is worried about. The Major Project and Project of State Significance pathways already exist. Using them is a decision, not a reform.

Fix the clock. Fourteen days to comment on a document running to hundreds of pages, and fourteen days to fund an appeal, are not consultation periods. They are compliance artefacts. Thirty days minimum, sixty above a threshold, and some mechanism for funding community technical review, would change what a submission can contain.

And publish the pipeline. Not commercially sensitive terms, but the fact of a proposal: location, indicative scale, stage. A community that learns of a 288-megawatt facility when the application lands has been handed a fait accompli dressed as a consultation.

The Thing the Petition Measures

Here is what the gap actually consists of, in units of time.

Firmus went from public announcement of its Tasmanian expansion to a facility under construction at St Leonards inside the same reporting cycle that first brought the plans to statewide attention. A development application at Wesley Vale went from publication to close of submissions in fourteen days. An appeal against the Bell Bay approval must be lodged within fourteen days at a cost of up to 50,000 dollars. The petition took ten weeks to gather 10,035 signatures and will produce, at most, a debate. The inquiry it prompted is still taking submissions, and will report with non-binding recommendations.

The dates can now be laid end to end, which they could not be in June. Latrobe Council is expected to vote on Wesley Vale in October 2026. Hydro Tasmania expects to know by the end of 2026 whether it will sell Firmus 450 megawatts. The mandatory national standards that all nine Australian governments endorsed on 26 August are not expected to become law until early 2027, and their detailed specifications have not been written. The Tasmanian statement of expectations, promised inside a hundred days, has not been published. The council vote comes first. The power contract comes after it, and the binding standards after that.

Construction runs faster than consultation, which runs faster than legislation. Each stage of the response is slower than the thing it is responding to, and the compounding is the whole story. The rules are no longer hypothetical, and that strengthens the point rather than weakening it. They are agreed, they are national, and they arrive in the year after the concrete. By the time Australia has mandatory standards for AI data centres, Tasmania will have AI data centres, and the standards will apply to the next ones.

That is what 10,035 people were actually registering. Not a view about artificial intelligence, on which they will hold every possible opinion. Not even, for most of them, opposition to a specific building most will never see. What they registered is that the mechanisms available to them operate on a timescale that guarantees they arrive after the decision.

A petition is the oldest and weakest instrument in parliamentary democracy. It is what you use when you have nothing else. Ten thousand people in a state of 579,000 reaching for it, in ten weeks, about a class of infrastructure that did not exist in the public conversation two years ago, is not a measure of how much Tasmanians dislike data centres. It is a measure of how little else was on offer.


Sources and References

  1. Parliament of Tasmania, House of Assembly E-Petitions, “AI Data Facilities in Tasmania”, petition 147, sponsored by Cecily Rosol MP, open 22 June 2026 to 31 August 2026, 10,035 signatures. https://haepetitions.parliament.tas.gov.au/haepet/Home/PetitionDetails/147
  2. Tasmanian Greens MPs, “Parliamentary Petition Calls for AI Data Centre Moratorium”, media release, 29 June 2026 (https://tasgreensmps.org/media-releases/parliamentary-petition-calls-for-ai-data-centre-moratorium/), and Tasmanian Times, “Greens Table Massive AI Data Centre Moratorium Petition”, September 2026 (https://tasmaniantimes.com/2026/09/greens-table-massive-ai-data-centre-moratorium-petition/).
  3. ABC News, “Northern Tasmanians prepare to fight George Town Council AI data centre approval”, 30 August 2026. https://www.abc.net.au/news/2026-08-30/ai-data-centre-tasmania-firmus-technology-george-town/107089468
  4. ABC News, “Firmus plans to truck water in and use rainwater to cool proposed Wesley Vale AI data centre”, 27 August 2026. https://www.abc.net.au/news/2026-08-27/firmus-truck-water-rainwater-cool-wesley-vale-ai-data-centre/107083230
  5. ABC News, “'We do not want to highlight this yet': AI data centre's FAQ slip-up”, 22 July 2026. https://www.abc.net.au/news/2026-07-22/tasmania-firmus-ai-data-centre-plan-to-use-irrigation-water/106935718
  6. ABC News, “AI company Firmus to become Tasmania's biggest power user if three planned sites come to fruition”, 15 June 2026. https://www.abc.net.au/news/2026-06-15/firmus-ai-company-tasmania-biggest-power-user-three-sites/106783142
  7. ABC News, “Hydro Tasmania to decide by end of year on AI data centre company Firmus's request for 450MW”, 4 September 2026. https://www.abc.net.au/news/2026-09-04/hydro-tasmania-assess-firmus-450-mw-energy-request/107116852
  8. ABC News, “Data centre inquiry by Greens to examine 'what, if any,' benefits will come to Tasmania from rollout”, 19 August 2026. https://www.abc.net.au/news/2026-08-19/ai-data-centre-inquiry-tasmanian-greens/107050792
  9. Australian Bureau of Statistics, “National, state and territory population, December 2025”, estimated resident population of Tasmania. https://www.abs.gov.au/statistics/people/population/national-state-and-territory-population/latest-release
  10. Tasmanian Times, “Record-Breaking Voluntary Assisted Dying Petition Tabled”, August 2020, reporting 11,699 e-petition and 1,383 paper signatures. https://tasmaniantimes.com/2020/08/record-breaking-voluntary-assisted-dying-petition-tabled/
  11. Planning in Tasmania, Department of Premier and Cabinet, “Major projects”, assessment pathway under the Land Use Planning and Approvals Act 1993. https://www.stateplanning.tas.gov.au/planning-system/development/major-projects
  12. Office of the Coordinator-General, Tasmanian Government, “Strategic project facilitation”, investment thresholds and case management. https://www.cg.tas.gov.au/project_facilitation/strategic_project_facilitation
  13. Andrea Marinoni, Erik Cambria, Weisi Lin, Mauro Dalla Mura, Jocelyn Chanussot, Edoardo Ragusa, Chi Yan Tso, Yihao Zhu and Benjamin Horton, “The data heat island effect: quantifying the impact of AI data centers in a warming world”, arXiv:2603.20897, 21 March 2026, revised 21 April 2026. https://arxiv.org/abs/2603.20897
  14. Basit A. Akinade, Amobichukwu C. Amanambu, Jonathan M. Frame and Shaolei Ren, “AI Data Centers and the Water Use Feedback Loop”, arXiv:2606.21760, 19 June 2026. https://arxiv.org/abs/2606.21760
  15. Aadi Patel, Nikhil Mahalingam and Rusheen Patel, “The Environmental Impact of AI Servers and Sustainable Solutions”, arXiv:2601.06063, submitted 24 December 2025. https://arxiv.org/abs/2601.06063
  16. Central Statistics Office, Ireland, “Data Centres Metered Electricity Consumption 2025”, published 2026 (https://www.cso.ie/en/releasesandpublications/ep/p-dcmec/datacentresmeteredelectricityconsumption2025/keyfindings/), and Data Center Dynamics, “EirGrid says no new applications for data centers in Dublin until 2028” (https://www.datacenterdynamics.com/en/news/eirgrid-says-no-new-applications-for-data-centers-in-dublin-till-2028/).
  17. Data Center Dynamics, “Dutch Senate stymies huge Meta data center in Zeewolde by blocking Government land sale to Facebook”. https://www.datacenterdynamics.com/en/news/dutch-senate-stymies-huge-meta-data-center-in-zeewolde-by-blocking-government-land-sale-to-facebook/
  18. Data Center Dynamics, “Chile partially reverses Google data center permit over water use concerns”, February 2024. https://www.datacenterdynamics.com/en/news/chile-partially-reverses-google-data-center-permit-over-water-use-concerns/
  19. Virginia Business, “Prince William Digital Gateway data center project officially dies”, 2026. https://virginiabusiness.com/prince-william-digital-gateway-data-center-project-officially-dies/
  20. Southern Environmental Law Center, “Groups appeal permit for xAI's South Memphis data center, decisions around unpermitted methane gas turbines”. https://www.selc.org/press-release/groups-appeal-permit-for-xais-south-memphis-data-center-decisions-around-unpermitted-methane-gas-turbines/
  21. Spotlight PA, “Why PA data centers want public officials to sign NDAs”, August 2026. https://www.spotlightpa.org/news/2026/08/pennsylvania-data-center-nda-public-record-capitol/
  22. Loudoun County, Virginia, “Data Centers, Tax Revenues and the County Budget”, official page on data centre tax contribution and real property tax rates. https://www.loudoun.gov/6409/Data-Centers-Tax-Revenues-County-Budget
  23. Rockefeller Institute of Government, “Updates on the Cloud: More Moratoriums on Data Centers”, June 2026. https://www.rockinst.org/blog/updates-on-the-cloud-more-moratoriums-on-data-centers/
  24. Clayton Utz, “Nine governments, one rulebook: National Cabinet backs mandatory AI and data centre standards”, August 2026. https://www.claytonutz.com/insights/2026/august/nine-governments-one-rulebook-national-cabinet-backs-mandatory-ai-and-data-centre-standards
  25. Clifford Chance, “Australia's National AI Plan 2025: key takeaways”, January 2026. https://www.cliffordchance.com/briefings/2026/01/australia-national-ai-plan-2025-key-takeaways.html

Tim Green

Tim Green UK-based Systems Theorist & Independent Technology Writer

Tim explores the intersections of artificial intelligence, decentralised cognition, and posthuman ethics. His work, published at smarterarticles.co.uk, challenges dominant narratives of technological progress while proposing interdisciplinary frameworks for collective intelligence and digital stewardship.

His writing has been featured on Ground News and shared by independent researchers across both academic and technological communities.

ORCID: 0009-0002-0156-9795 Email: tim@smarterarticles.co.uk

Listen to the free weekly SmarterArticles Podcast

Discuss...

The Kickstarter had a day left to run, closing on 5 September 2026, and by 4 September had taken $194,103. The goal was $5,000. One thousand one hundred and thirty-eight people had pledged money for a T-shirt, a hoodie and a neck gaiter printed with patterns that a computer bred, over roughly thirty-one million attempts, to make the machines that watch pavements fail to notice a human body is standing there.

The man behind it is Bill Swearingen, a Kansas City security professional who spent decades on red teams and as a chief information security officer before turning his attention to the cameras. He unveiled the project, called noRecognition, at DEF CON 34 in Las Vegas in early August 2026, and presented the underlying research at Black Hat USA the same week. On 31 August he sat down with Tom Eston for the Shared Security Podcast to explain what the patterns do, what they do not do, and why person detection and facial recognition are not the same problem.

The opening slide of his DEF CON deck reads: “Today, over 100 cameras logged your beautiful face. You didn't opt in. You can't opt out.”

That sentence is the entire commercial proposition, and it is the thing worth sitting with. Not the algorithm. Not the fabric. The fact that more than eleven hundred people, in a month, decided the most practical response to being biometrically catalogued in public was to buy a garment.

There is a version of this story that is a gadget story. Clever hacker beats the cameras, here is where to buy the shirt. TechCrunch reported the project in August, noting Swearingen's claim to have run more than 31 million tests against eleven detection systems. Dark Reading described how he pulled models out of actual camera hardware and worked through a series of dead ends, including shirts printed with text and shirts printed with dozens of human faces, before landing on dense geometric noise.

The more interesting story is what it means that the shirt exists at all, and what happens to the person wearing it when the pattern does not work.

A camera is just a parser

Swearingen's framing of the attack is the most useful thing in the deck, and it is worth restating precisely because it strips away the mystique.

“A camera is just a parser,” one slide reads. “It parses pixels into objects. Nothing more. Every parser in the history of computing has been exploitable when an attacker controls the input.”

The analogy he reaches for is SQL injection, which works because a database parser cannot reliably distinguish data from instructions. If you control what appears in front of the lens, you control the input. The question is whether you can control the output.

Consider what one of these parsers does. Swearingen pulled apart the model file shipped on Flock Safety cameras, the number plate reading hardware now deployed across thousands of American communities. The file, flock_yoloV5.tflite, produces an output tensor of shape 1 by 6300 by 13. One image per pass. Six thousand three hundred candidate boxes drawn from grids at three scales. Thirteen numbers per candidate: four box coordinates, one objectness score, and eight class scores covering person, car, truck, bus, trailer, motorcycle, bicycle and licence plate.

The plate reader was never bolted on afterwards. It is a class in the same output channel as “person”.

Of those thirteen numbers, one decides whether you exist. Objectness answers a single question: is there a thing here at all? The final score is objectness multiplied by the probability the thing is a person, and a box is drawn only if that product clears 0.75.

The adversarial pattern goes after that one scalar. The backbone of the network is an edge and texture detector trained on natural photographs, tuned for skin, cloth folds, hair and shadow. A dense, high-frequency, periodic print matches none of those filters. In the grid cells the garment covers, objectness collapses. Swearingen's measured example on a held-out identity: 0.91 clean, 0.28 with the pattern. Same body, same camera, same model, only the texture changed. Under the keep line, no box is drawn, so non-maximum suppression never runs, tracking never runs, and nothing is uploaded.

That is an elegant result, and a very specific one. It works on the family of detectors that stake everything on one objectness scalar. Swearingen is candid about where it stops. On single-shot detectors with 1,917 anchors, each running class against background, the garment reaches the torso boxes but the whole-body and background boxes still see you, and one surviving box keeps you detected. His slide title for this is blunt: “WHY SSD WALLS”.

Three machines, three different failures

The single most important correction in the whole project is one that costs nothing and almost nobody makes.

Person detection, face detection and facial recognition are three different capabilities answering three different questions. How many people are there. How many faces are there. Do we know this face. The first produces a count. The second produces a crop. Only the third produces an identity, and only the third can put your name on a watchlist hit.

They also have opposite economics. A person detector runs a low threshold, because in most deployments the cost of missing someone exceeds the cost of a spurious box. A face recogniser runs a high threshold, because a false match asserts that a specific human being is a specific other human being, and that error has a name and an address. Defeating one tells you nothing reliable about the others.

Almost every headline about anti-surveillance clothing collapses these three into “facial recognition”. So does almost every product description. The distinction matters to the buyer, because the noRecognition garments are tuned differently for different jobs. The gaiter targets face detection. The tee and hoodie target person detection. No single pattern wins everywhere.

The testing apparatus reflects that. Swearingen built what he calls a fuzzer: a system that generates candidate patterns, overlays them on standardised persona images and pushes them through an ensemble of models, logging anything that produces a failure or a dramatic confidence drop. The pattern library reached 61 distinct generators at version 0.9.8, from fractal noise to what he calls surgical attacks that locate facial landmarks and then place high-contrast patches on the nose or cheek, apply noise only to eyes and mouth, or stamp dozens of decoy eyes into the frame to overwhelm the bounding-box logic.

When a pattern produces an anomaly, its recipe is saved and used as a parent. The system mutates it, adding, removing or swapping layers, and splices successful recipes together. That is the genetic algorithm at the heart of the project. Patterns are bred, not designed.

The gauntlet each candidate runs started at ten models and grew to eleven when a fifth person detector was added in July 2026. Five person detectors, four face detectors, two recognition models. Across 31.7 million patterns tested, the system logged 534,600 anomalies, about 1.7 per cent. Of those, 480,700 fooled more than one model. Eighty-five qualified as extreme, which is 0.016 per cent of the anomalies and about one in every 373,000 patterns tested.

That last number is the honest shape of the research. Overwhelmingly, this does not work. Occasionally it works spectacularly.

What ninety-six point six six per cent actually measures

The figure that travels furthest in coverage of adversarial clothing comes from a 2021 paper by Alon Zolfi, Shai Avidan, Yuval Elovici and Asaf Shabtai, researchers at Ben-Gurion University of the Negev and Tel Aviv University. Their abstract reports that in real-world experiments, the face recognition system “was only able to identify 3.34% of the participants wearing the mask (compared to a minimum of 83.34% with other evaluated masks).”

Subtract, and you get 96.66 per cent, a striking number routinely repurposed as evidence that clothing defeats facial recognition.

Read the paper and three qualifications arrive at once. First, the object is a face mask, the surgical kind, worn over the nose and mouth. It is not a shirt. It occupies the most information-dense region of the face, which is why it works and why it does not generalise to a torso print. Second, the comparison is against other masks, not a bare face. The claim is that this printed mask is dramatically better at defeating recognition than an ordinary one, which is narrower and more interesting. Third, the evaluation was a CCTV use case run by the researchers. Photons went through a real lens, which is more than most of this literature can say, but it is not a measurement against a deployed commercial identification service on a street.

The other two papers in the current wave of coverage are similarly precise and similarly narrow. Zhanhao Hu and colleagues, in work accepted to CVPR 2023, used Voronoi diagrams and Gumbel-softmax optimisation with 3D mesh-based augmentation to produce clothing textures that look like ordinary camouflage, printed them on fabric, tailored them into garments and reported high attack success rates against multiple detectors at multiple viewing angles. Person detectors. Not recognition. The survey by Jiakai Wang and colleagues, cataloguing more than a hundred studies, is organised around the observation that physical adversarial examples acquire awkward properties through manufacturing and re-sampling that digital ones never face.

That gap has been measured. Jakob Shack, Katarina Petrovic and Olga Saukh, in a 2024 study bluntly titled “Breaking the Illusion”, varied patch size, position, rotation, brightness, hue and blur across digital and physical conditions. Geometric transformations behaved consistently across both worlds. Colour transformations did not. Even after aligning digital transformation parameters with measured real-world ones, they found discrepancies of up to 64 per cent in patch performance.

Sixty-four per cent is not a rounding error. It is the difference between a defence and a decoration.

The fabric has not been tested yet

Here is the part of the story that almost none of the coverage foregrounds, and which Swearingen himself put on a slide in front of a DEF CON audience.

Under the heading “WHERE THE PROOF STANDS”, the deck reads: “Digital, and held to a stricter bar than the field.” It describes sealed sweeps where training, selection and reporting are kept separate, more than 500 held-out personas unseen at training time across multiple view buckets, and a control most of this field skips entirely: every pattern must beat a solid black panel of the same geometry, or the result is discarded. Otherwise you are not measuring an adversarial effect, you are measuring the fact that you covered someone with a large opaque rectangle.

Then, immediately beneath: “LIVE FABRIC TESTING. Just begun. Printed fabric trials are under way. Nothing physical is claimed yet: the digital results above do not transfer until fabric passes the same occlusion-subtracted bar.”

Nothing physical is claimed yet.

That is the researcher, at the moment of maximum publicity, telling the room that the thing being crowdfunded has not yet been demonstrated on cloth. The Kickstarter is explicit that this is what the money is for: test fabrics, substrates, weaves and inks, a dye-sublimation printer so an iteration takes hours instead of weeks, and more fielded camera hardware so results are measured through real lenses rather than on a bench.

There has been one public demonstration outside the digital sweeps. At DEF CON on 7 August 2026 Swearingen held a flat rigid panel printed with the pattern in front of a live person-detection feed, running a model taken from a fielded Flock unit, and the confidence score fell. With the automotive outlet Donut Media he also had a 2009 Toyota Yaris wrapped in a generated pattern driven past a Flock camera, which by his account failed to register it. Reporters noted what the deck had already conceded: a single unblinded test, with broader peer-reviewed validation still pending. A rigid printed panel is not cloth on a moving body, and a car wrap is not a hoodie. The sentence about nothing physical being claimed refers to the garments, which are the things people are buying.

This is admirably honest. It is also a strange thing to sell more than a thousand people a garment on the back of. The buyer is funding the validation of the product they are buying. Both are true at once, and the gap between them is where most of the difficulty in this story lives.

Everyone who tried this before

Swearingen does not pretend to have invented the genre, and his deck contains a slide crediting the lineage that is more generous than most academic related-work sections.

Adam Harvey created CV Dazzle in 2010 as his master's thesis at NYU's Interactive Telecommunications Program: makeup and hair styling designed to break face detection while remaining perfectly legible to humans. It became the defining image of anti-surveillance aesthetics, reproduced in a thousand articles about the coming panopticon.

Harvey's own website is now the most rigorous debunking of Harvey's own work. The original looks targeted the Viola-Jones algorithm and its haar cascade classifiers, which he describes as unofficially deprecated since around 2016. He advises against using those patterns against newer systems. Convolutional networks, he notes, would require a different strategy entirely. He is careful to insist that CV Dazzle is a technique and not a specific pattern, that it must be customised to a particular algorithm and environment, and that lighting alone changes the outcome. Fifteen years on, the artist who made the most famous anti-facial-recognition object in the world says plainly that the object no longer works.

In 2017 Harvey collaborated with the interaction design studio Hyphen-Labs on HyperFace, a textile printed with decoy face patterns designed to saturate detectors with false candidates. Where CV Dazzle attacked the figure, HyperFace attacked the ground. It debuted at Sundance as part of Hyphen-Labs' NeuroSpeculative AfroFeminism project, which put the question of who gets watched, and how badly the machines perform on them, at the centre rather than the margin.

In 2019 Kate Rose launched Adversarial Fashion, garments printed to inject false plate reads into number plate recognition systems. In 2023 the Italian label Cap_able released its Manifesto knitwear, which Swearingen's slide records as claiming 60 per cent evasion against a single detector. Reflectacles sells infrared-blocking eyewear aimed at cameras and depth sensors.

And then the slide that should be pinned above every product page in the category, headed “THE MEASUREMENT GAP”: claims are typically measured against a single object detector, in sample, without a control. Of thirty published methods, according to the independent review he cites, twelve were ever tested against a real system.

Twelve out of thirty. The field's central problem is not that the attacks are impossible. It is that almost nobody checks properly.

Today's evasion is tomorrow's training data

Assume the fabric trials succeed. Assume a hoodie ships that reliably drops objectness below the keep line on a fielded camera in ordinary daylight. How long does that last?

Adversarial examples are not a permanent property of the physical world. They are a property of a specific model with specific weights. The moment a pattern is public, printed, photographed and posted, it becomes training data. Adversarial training, in which the defender fine-tunes on the attack, is the oldest and most boring countermeasure in machine learning, and it works well enough against fixed, published, printed patterns that any vendor with an engineering team and a quarterly release cycle should be expected to deploy it.

Swearingen understands this perfectly. It is why the strongest patterns are withheld from public release, according to TechCrunch's reporting: publishing them hands camera manufacturers the countermeasure. But that creates its own bind. A pattern that is secret cannot be independently verified. A pattern that is verified is on its way to being neutralised. There is no configuration of this problem in which the buyer gets both public proof and lasting protection.

The asymmetry is the point. Eleven hundred people bought a garment they will own for years. The other side ships a model update. One side of this exchange has a supply chain, a printing process and a wardrobe. The other has a continuous integration pipeline. When a single new detector entered Swearingen's gauntlet in July 2026, every persona had to be rescored against eleven models rather than ten, and research throughput fell in proportion. The defender's cost of adding a model is trivial. The attacker's cost of covering it is linear and painful.

The garment is a static artefact deployed against a moving target. Even in the best case, what you are buying is a pattern with an expiry date that nobody can tell you.

The pipeline does not care what you wear

Even a perfectly effective adversarial hoodie defeats exactly one modality. The surveillance stack has many.

Cloth-changing person re-identification is an entire research subfield built on the premise that people change their clothes, and it works precisely by extracting features that are independent of what you are wearing: body shape, gait, skeletal proportion. Gait is attractive to researchers exactly because it is harder to change than a jacket. Recent systems are evaluated on datasets deliberately constructed around substantial variation in clothing, carried objects and viewing angle. A garment that removes your bounding box from one camera does nothing about the walk that identifies you on the next.

Then there is everything that is not vision at all. Your phone announces itself. Your car is read by the same Flock model whose licence plate class sits in the same tensor as the person class, across a network the American Civil Liberties Union puts at more than 120,000 readers in at least 6,000 communities. Swearingen's slides cite 140,000 monthly police users. Your contactless payment timestamps you. Your travel card timestamps you. Your face is already in a driving licence database that police search.

Being unseen by one camera for one frame is not the same as being unidentified. Identification in 2026 is a joining operation across many weak signals, and the hoodie removes one of them, some of the time, at some angles, in some light.

This is the strongest argument against treating adversarial clothing as a defence, and it does not depend on the technology failing. It works even if the technology is perfect.

The problem with looking like you have something to hide

There is a second cost, and it is not technical.

A garment covered in dense, high-frequency geometric noise is not inconspicuous. It is one of the most conspicuous things a person can wear. The whole design constraint of CV Dazzle, which Harvey articulated fifteen years ago, is that it defeats machines while remaining perfectly legible to humans. That legibility cuts both ways. To a camera you may be an absence. To the officer watching the monitor, and to the operator who notices that the tracking box keeps dropping in the same place, you are the most interesting person on the street.

This is the signalling problem, and it inverts the entire purpose. Evasion that announces itself is not privacy. It is a flag.

The legal position sharpens it. In the United States, according to the International Center for Not-for-Profit Law, 23 states and the District of Columbia have statutes limiting face coverings in public, many written in the twentieth century and repeatedly used against protesters. The politics have become strange. California's Senate Bill 627, the No Secret Police Act, took effect on 1 January 2026 and banned most face coverings by federal immigration agents and local police. In February 2026 US District Judge Christina Snyder preliminarily enjoined the mask ban, holding that California does have the general power to stop federal officers covering their faces, but that SB 627 had exercised it discriminatorily, because it imposed no equivalent requirement on the state's own officers. The companion No Vigilantes Act, which requires non-uniformed officers to display an agency name and badge number, survived that round, the district court finding those identification requirements neutral and generally applicable. On 22 April 2026 the Ninth Circuit blocked that provision too, ruling 3-0 that it attempts to regulate the United States directly and so likely violates the Supremacy Clause: a state law directly regulating the conduct of the United States is void, in the panel's words, irrespective of whether the regulated activities are essential to federal functions. Both provisions are now enjoined pending further litigation, which makes this a suspension rather than a settled outcome. So the legislative moment that seeks to unmask the officer coexists with statutes that criminalise the masked citizen, and it is the unmasking laws that are blocked while the anti-mask statutes stand.

In England and Wales, Section 60AA of the Criminal Justice and Public Order Act 1994 lets an officer of inspector rank or above authorise, within a locality and for up to 24 hours, a power for any constable in uniform to require removal of any item the constable reasonably believes is being worn wholly or mainly to conceal identity. Refusal carries up to a month's imprisonment or a fine. Netpol's briefing on the power notes that the default position is that police cannot demand you remove a covering, and that items worn for warmth, health, religious observance or political symbolism may fall outside it.

A hoodie is a garment. It is not a mask. But the statutory test turns on the officer's reasonable belief about your purpose, and you have just told a crowdfunding platform, in public, that your purpose is concealing your identity from recognition systems. The receipt is the evidence.

The law that was meant to do this job

The reason the Kickstarter is interesting is not that the hoodie works. It is that more than a thousand people concluded, correctly, that nothing else was going to.

On paper the regulation exists. The EU AI Act's Article 5(1)(h) prohibits real-time remote biometric identification in publicly accessible spaces for law enforcement, enforceable since 2 February 2025. Read the exceptions and the shape changes: targeted searches for victims of abduction, trafficking or sexual exploitation and for missing persons; prevention of a specific, substantial and imminent threat to life or of a terrorist attack; and identification of a person suspected of a scheduled offence punishable by at least four years' custody. Each deployment requires prior authorisation from a judicial or independent administrative authority, a fundamental rights impact assessment and registration in an EU database. It is a real constraint with a wide gate.

In the United Kingdom, which is outside that regime, the direction is the opposite. The Metropolitan Police ran a six-month pilot of fixed live facial recognition cameras on lampposts at either end of Croydon high street from October 2025 to March 2026. The force reported 173 arrests across 24 operations, an arrest every 35 minutes of operation, more than 470,000 people passing the cameras and a single registered false positive, alongside a claimed 10.5 per cent fall in crime in the pilot area. Commissioner Sir Mark Rowley has announced static cameras across the West End and Soho by the end of 2026. In January 2026 the Home Office announced an increase in facial recognition vans from ten to fifty, available to all forces in England and Wales. Big Brother Watch's response was that police have used the technology for a decade absent a democratic or legal basis, and that instead of pausing pending consultation the government funded an expansion. A legal framework was confirmed for the Police Reform Bill in the May 2026 King's Speech, which is to say the deployment came first and the law is arriving afterwards.

Meanwhile the enforcement record on the private side is a case study in what a fine is worth to a company that declines to pay it. Five European supervisory authorities found Clearview AI's processing of EU residents' biometric data unlawful between 2022 and 2024, issuing more than €110 million in penalties. France's CNIL levied €20 million in October 2022 and a further €5.2 million in May 2023. The Dutch Data Protection Authority added €30.5 million in September 2024. Clearview has paid essentially none of it, and in October 2025 the campaign group noyb escalated by filing a criminal complaint with Austrian prosecutors against the company and its executives.

Set that against a crowdfunding page. One system produced €110 million in unenforceable paper. The other produced 1,138 hoodies. Only one of them gave anybody something to put on.

Privacy at seventy-five dollars a garment

A hoodie costs $75. That is not much for a hoodie and it is a great deal for a fundamental right.

The distributional logic here is worth stating plainly, because it is the ugliest part. The people most exposed to biometric surveillance are, on the available evidence, the least able to buy their way out of it. NIST's landmark demographic study of face recognition algorithms found that false positive rates across demographics often vary by factors of ten to beyond a hundred, and that rates were highest for West and East African and East Asian faces and lowest for Eastern European ones. The Greater London Authority has reported that over half of the Met's facial recognition deployments in a recent year took place in areas with a higher proportion of Black residents.

So the machine is disproportionately deployed where certain people live, and it is disproportionately wrong about certain faces. The response on offer is a consumer good priced in dollars, sold on an American crowdfunding platform in limited runs, with the colour-matched pieces marketed as one-off and never released to anyone else.

Privacy as a subscription. Privacy as a size medium. Privacy for people who read TechCrunch.

This pattern is not specific to clothing. It is the same logic that turned ad-blocking into a paid app and identity theft protection into an upsell attached to the breach that caused it. A structural harm is created at scale by institutions, and the remedy is retailed back to individuals one unit at a time. The market response is not a scandal. It is often the only response available. But it should be recognised for what it is: the privatisation of a collective problem, monetised at the point of the person least able to solve it.

And the thing about individualised resistance is that it does not aggregate. Eleven hundred people in adversarial hoodies do not add up to a policy. They add up to eleven hundred people who are slightly harder to detect and considerably easier to notice.

The case that this is a talisman

The sceptical position deserves its strongest form, so here it is.

Adversarial clothing is closer to an amulet than to armour. It is a physical object that offers protection through a mechanism its wearer cannot verify, against a threat its wearer cannot observe, with a failure mode that produces no feedback. You will never know whether the hoodie worked. There is no notification. There is no log you can read. The camera does not tell you it lost you, and it does not tell you it found you either. That epistemic condition is precisely the one under which talismans thrive.

And unlike an amulet, this one has a plausible cost. If the garment induces real confidence, it changes behaviour. Someone attends a protest they would otherwise have avoided. Someone declines a mundane precaution because they believe the technical one is handling it. If the pattern fails, and the literature says physical patterns fail far more than the demo reels suggest, the wearer has been made worse off by the purchase. False confidence is not neutral. It is a negative.

The steelman gets stronger when you notice how little of the sales pipeline transmits the caveats. Swearingen's own slide says nothing physical is claimed yet. That sentence appears in a research deck seen by a conference audience. It is not what a backer sees, and it is not what survives the trip through aggregators, newsletters and posts about the hacker who beat the cameras. The honest version of this research is fragile in exactly the way the marketable version is robust.

What blunts the argument is that the person making the strongest claims also keeps the strictest controls. Occlusion subtraction against a solid black panel. Sealed sweeps with training, selection and reporting kept apart. More than 500 held-out personas. A test standard containing the phrase “or the result is discarded”. In a field where twelve of thirty published methods were ever tested against a real system, this is unusually disciplined work. It is also work being sold before it is finished, and both facts belong in the same paragraph.

What the hoodie is honestly for

Return to the question underneath all of this. What does it mean that the most practical response to pervasive facial recognition is to change what you wear?

It means the ordinary person has correctly diagnosed their position and has almost no instruments with which to act on it. You cannot negotiate with a lamppost. You cannot opt out of a watchlist you were never told you were on. You cannot appeal a system whose accuracy statistics are published by the organisation that operates it. You cannot collect on a €110 million fine that nobody intends to pay. The set of actions available to a single human being facing a biometric state is close to empty, and into that emptiness a garment has arrived. It is not irrational to reach for it. It is what reaching looks like when there is nothing else within reach.

And what does the Kickstarter tell us about the everyday experience of being watched by machines that can identify you from a single frame?

That the experience has become mundane enough to have a price. Anti-surveillance fashion used to be art. CV Dazzle was a thesis. HyperFace was at Sundance. Adversarial Fashion was a statement piece. In 2026 it is a fulfilment schedule, a size chart and a dye-sublimation printer, backed by the 1,138 people who had pledged by 4 September 2026, with a day of the campaign still to run, and who mostly do not think of themselves as activists. The surveillance became ordinary, so the resistance became merchandise. Those two facts are the same fact.

The hoodie is not a solution. On the evidence available, it is not yet even a demonstrated defence, and its own creator says so on a slide. Against gait recognition, cloth-changing re-identification, plate readers, phone signals and payment records, it addresses a single modality in a stack that has many, and it announces itself while doing it.

But calling it merely a symptom is too easy, and a little smug, because the people who say it usually have nothing better to offer. A symptom is passive. This is not. It is a legible object a person can put on their body, which makes an invisible infrastructure briefly visible and turns a diffuse unease into something with a shape and a price. That has a value not measured in objectness scores. Photographs of people in patterned gaiters will do more to tell the public that lampposts in Croydon run one-to-many face matching than any consultation response ever will.

So the honest answer is that the hoodie is a receipt. It is documentary evidence that eleven hundred people looked at the regulatory position in 2026, understood it accurately, and concluded that their best available move was a consumer purchase with an unverified mechanism and an unknown expiry date.

Whether the pattern defeats the camera is, in the end, the less interesting question. It probably will, for a while, against some models, in some conditions, until the next release. The question that stays is why the parser is there at all, why nobody asked, and why the only person who has to change their behaviour is the one walking past.

Sources and References

  1. Tom Eston, Shared Security Podcast, “Could a Pattern on Your Clothing Fool Facial Recognition? Interview with Bill Swearingen”, 31 August 2026. https://securityboulevard.com/2026/08/could-a-pattern-on-your-clothing-fool-facial-recognition-interview-with-bill-swearingen/
  2. Bill Swearingen, “noRecognition: Could a Pattern on Your Clothing Fool Facial Recognition?“, DEF CON 34 presentation slides, August 2026. https://media.defcon.org/DEF%20CON%2034/DEF%20CON%2034%20presentations/DEF%20CON%2034%20presentations/DEF%20CON%2034%20-%20Bill%20Swearingen%20-%20noRecognition%20Could%20a%20pattern%20on%20your%20clothing%20fool%20Facial%20Facial%20Recognition%20-%20hevnsnt.pdf
  3. Bill Swearingen (hevnsnt), noRecognition project repository and technical documentation, GitHub, updated August 2026. https://github.com/hevnsnt/norecognition
  4. Zack Whittaker, TechCrunch, “This 'adversarial' pattern can prevent surveillance cameras from detecting you”, 9 August 2026. https://techcrunch.com/2026/08/09/this-adversarial-pattern-can-prevent-surveillance-cameras-from-detecting-you/
  5. Dark Reading, “Can Clothes Make You Invisible to Facial Recognition?”, August 2026. https://www.darkreading.com/cyber-risk/clothes-invisible-facial-recognition
  6. Kickstarter, “noRecognition: AI Adversarial Clothing by Bill Swearingen”, campaign running 6 August to 5 September 2026.
  7. Kicktraq, campaign tracking data for “noRecognition: AI Adversarial Clothing”, accessed 4 September 2026. http://kicktraq.com/projects/norecognition/norecognition-ai-adversarial-clothing/
  8. Alon Zolfi, Shai Avidan, Yuval Elovici and Asaf Shabtai, “Adversarial Mask: Real-World Universal Adversarial Attack on Face Recognition Models”, arXiv:2111.10759, 21 November 2021, revised 7 September 2022. https://arxiv.org/abs/2111.10759
  9. Zhanhao Hu, Wenda Chu, Xiaopei Zhu, Hui Zhang, Bo Zhang and Xiaolin Hu, “Physically Realizable Natural-Looking Clothing Textures Evade Person Detectors via 3D Modeling”, arXiv:2307.01778, 4 July 2023, revised 8 November 2024, accepted to CVPR 2023. https://arxiv.org/abs/2307.01778
  10. Jiakai Wang, Xianglong Liu, Jin Hu, Donghua Wang, Siyang Wu, Tingsong Jiang, Yuanfang Guo, Aishan Liu and Jiantao Zhou, “Adversarial Examples in the Physical World: A Survey”, arXiv:2311.01473, 1 November 2023, revised 22 August 2024. https://arxiv.org/abs/2311.01473
  11. Jakob Shack, Katarina Petrovic and Olga Saukh, “Breaking the Illusion: Real-world Challenges for Adversarial Patches in Object Detection”, arXiv:2410.19863, 23 October 2024. https://arxiv.org/abs/2410.19863
  12. IEEE, “An In-Depth Exploration of Person Re-Identification and Gait Recognition in Cloth-Changing Conditions”, conference publication, 2023. https://ieeexplore.ieee.org/document/10204291/
  13. Adam Harvey, “CV Dazzle”, adam.harvey.studio, project begun 2010, page updated with newer looks. https://adam.harvey.studio/cvdazzle/
  14. Adam Harvey, “HyperFace”, adam.harvey.studio, developed with Hyphen-Labs, 2017. https://adam.harvey.studio/hyperface/
  15. Patrick Grother, Mei Ngan and Kayee Hanaoka, National Institute of Standards and Technology, NISTIR 8280, “Face Recognition Vendor Test (FRVT) Part 3: Demographic Effects”, December 2019. https://nvlpubs.nist.gov/nistpubs/ir/2019/nist.ir.8280.pdf
  16. Metropolitan Police, “Met makes one arrest every 35 minutes during live facial recognition pilot”, May 2026. https://news.met.police.uk/news/met-makes-one-arrest-every-35-minutes-during-live-facial-recognition-pilot-509256
  17. Computer Weekly, “Met pushes ahead with major facial-recognition expansion”, 2026. https://www.computerweekly.com/news/366645018/Met-pushes-ahead-with-major-facial-recognition-expansion
  18. Big Brother Watch, “Unprecedented Expansion of Facial Recognition Is 'Worrying for Democracy'”, January 2026. https://bigbrotherwatch.org.uk/press-releases/unprecedented-facial-recognition-rollout/
  19. Greater London Authority, “Over half of all facial recognition deployments last year took place in areas with a higher proportion of Black residents”. https://www.london.gov.uk/over-half-all-facial-recognition-deployments-last-year-took-place-areas-higher-proportion-black
  20. European Union, Artificial Intelligence Act, Article 5, Prohibited AI Practices, applicable from 2 February 2025. https://artificialintelligenceact.eu/article/5/
  21. European Data Protection Board, “Dutch Supervisory Authority imposes a fine on Clearview because of illegal data collection for facial recognition”, 3 September 2024. https://www.edpb.europa.eu/news/dutch-supervisory-authority-imposes-a-fine-on-clearview-because-of-illegal-data-collection-for_en
  22. CNIL, “Facial recognition: 20 million euros penalty against CLEARVIEW AI”, 20 October 2022. https://www.cnil.fr/en/facial-recognition-20-million-euros-penalty-against-clearview-ai
  23. International Center for Not-for-Profit Law, “Anti-Mask Laws in the United States”. https://www.icnl.org/our-work/us-program/assembly/anti-mask-laws-in-the-united-states
  24. CalMatters, “9th Circuit blocks California limits on anonymous immigration agents”, 22 April 2026. https://calmatters.org/justice/2026/04/immigration-mask-ban-9th-circuit/
  25. Netpol, “Section 60AA Briefing”, 27 February 2026. https://netpol.org/2026/02/27/section-60aa-briefing/

Tim Green

Tim Green UK-based Systems Theorist & Independent Technology Writer

Tim explores the intersections of artificial intelligence, decentralised cognition, and posthuman ethics. His work, published at smarterarticles.co.uk, challenges dominant narratives of technological progress while proposing interdisciplinary frameworks for collective intelligence and digital stewardship.

His writing has been featured on Ground News and shared by independent researchers across both academic and technological communities.

ORCID: 0009-0002-0156-9795 Email: tim@smarterarticles.co.uk

Listen to the free weekly SmarterArticles Podcast

Discuss...

Somewhere in the United States tonight, a patrol officer will finish a shift, sit down at a terminal, and read an account of something they did a few hours earlier. The account will be fluent, chronological, written in the first person, and organised in the familiar grammar of a police report. It will describe what the officer saw, what the officer said, what the suspect did in reply. And the officer will not have written a word of it. A large language model will have assembled the narrative from the audio picked up by the body-worn camera clipped to the officer's chest, transcribed it, and returned a finished draft within minutes of the incident ending. The officer's job is now not to compose but to correct: to read the machine's version, fill in a few bracketed blanks, delete what is wrong, and then sign it as a sworn and truthful account of events. Once signed, that document becomes evidence. It may establish the probable cause for an arrest. It may be read to a jury. It may decide whether a defendant's version of events is believed or dismissed as a lie.

The tool most responsible for this shift is called Draft One, built by Axon Enterprise, the company that already dominates the American market for Tasers and body cameras. Since its launch in April 2024, it has spread across police departments from Oklahoma City to Fort Collins to Lafayette, promising to hand officers back the hours they lose to paperwork, and it has done so at a speed that has outrun almost every attempt to scrutinise it. Axon insists that a human remains in control at every step. But a growing chorus of researchers, defence lawyers, civil-liberties organisations and even prosecutors argues that something more fundamental is being quietly rearranged: the relationship between what an officer remembers, what a machine reconstructs, and what a court is ultimately asked to trust.

The Machine That Learned to Testify

The scale of the deployment is no longer experimental. Axon says that Draft One is now in use at roughly six hundred police departments, that it has produced something in the order of six hundred thousand reports, and that, on the evidence of the company's own customer surveys, it has saved an estimated three hundred thousand hours of officer time. The commercial trajectory matches the operational one: Axon reported that revenue from its artificial-intelligence products grew by more than seven hundred per cent year over year in the first quarter of 2026, against total quarterly revenue of $807 million. It is worth pausing on the provenance of that headline figure, because those three hundred thousand hours are not a measurement. They are an aggregation of what officers and their supervisors told the company they believed had happened, which is to say a survey of perception rather than a stopwatch, and the distinction will turn out to matter a great deal.

The mechanics of Draft One are, on their surface, unremarkable. Axon has long argued that officers spend a punishing share of their working lives writing reports; the company cites figures suggesting report-writing can consume up to forty per cent of an officer's time. Draft One is pitched as the remedy. Audio from an officer's body-worn camera is uploaded, transcribed automatically, and passed to a large language model built on a version of OpenAI's GPT-4 technology. Within seconds, the system produces a first-person narrative in the house style of a police report. Axon says the underlying model has been calibrated to suppress speculation and embellishment, and that it will not invent facts the audio does not contain.

The company has also engineered a set of deliberate friction points, apparently designed to keep the officer engaged rather than passive. Each generated draft is salted with bracketed placeholders, fill-in-the-blank prompts that an officer must either complete or delete before the report can be submitted. The intention is to force a human eye across every paragraph, to make it impossible to submit the machine's work without at least appearing to have read it. At the end sits the crucial ritual: the officer must review the narrative, attest to its accuracy, and sign it. Axon describes this as an “officer-in-the-loop” philosophy, a design in which the algorithm proposes and the human disposes. On paper, nothing has changed about accountability. The officer's signature still means what it has always meant, that the account below it is true to the best of their knowledge.

Axon has also mounted a defence of the product's quality, publishing its own research arguing that Draft One narratives are comparable to officer-written ones and that the company rigorously tests its models to reduce inherent bias before release. The firm's market position lends these assurances unusual weight. Because Axon already supplies the cameras that capture the footage, the evidence-management platform that stores it, and now the model that narrates it, a single vendor increasingly sits astride the entire evidentiary pipeline of an encounter, from the moment a camera is switched on to the moment a sworn report enters the case file. That vertical integration is precisely what makes independent scrutiny difficult, and it is why the question that will not go away matters so much: whether an officer's signature can still carry the same weight when the words above it were composed by something other than the person signing.

The Path of Least Resistance

To understand why researchers are uneasy, it helps to leave policing for a moment and consider a body of work in human-factors psychology that long predates generative artificial intelligence. For decades, researchers studying pilots, radiologists, air-traffic controllers and clinicians have documented a stubborn tendency they call automation bias: the inclination of human operators to over-trust an automated system, to defer to its output even when their own judgement, properly consulted, would contradict it. A closely related phenomenon, sometimes called automation complacency or cognitive offloading, describes what happens when people under time pressure allow a machine to do their thinking for them, quietly outsourcing not just the labour of a task but the vigilance it demands.

The literature is consistent about the conditions that make automation bias worse, and they read like a description of the average patrol shift. Heavy workloads intensify it. Tight deadlines intensify it. So does the sheer cognitive difficulty of verification: the harder it is to check a machine's work against an independent standard, the more likely a tired human is to simply accept it. Humans, as the research bluntly puts it, are cognitive misers. We prefer the simpler path. When a plausible, well-structured, grammatically clean narrative is already sitting on the screen, the effort required to reconstruct events independently, to close one's eyes and recall the smell of the room, the sequence of movements, the exact words exchanged, and to measure that memory against the text, becomes an act of discipline that a busy officer at the end of a long shift has every incentive to skip.

This is the specific risk that critics of AI-generated reports keep returning to. It is not, primarily, the danger that the model will hallucinate a fact, though that danger is real. It is that the mere existence of a fluent draft changes the psychology of the person meant to check it. Reviewing a document you did not write is a fundamentally different cognitive act from composing one. Editing tends to correct surface errors, awkward phrasing, an obvious factual slip, while leaving the underlying structure and framing intact. The officer becomes a proofreader of their own memory, and the machine's version becomes the anchor against which everything else is judged. The report is no longer a reconstruction of what happened; it is a lightly amended transcript of what a language model inferred from a microphone.

The bracketed placeholders that Axon inserts are, in this light, a fascinating admission. They exist precisely because the company understands that officers might otherwise submit a draft without reading it, and they are engineered as a kind of cognitive forcing function, a deliberate obstacle intended to compel attention. But the human-factors research offers a sobering caution about such measures. Forcing functions can raise the floor of engagement without raising its ceiling; an officer who dutifully fills in a blank about the make of a vehicle or the time of an arrest has demonstrated that they scanned the surrounding text, not that they measured its substance against an independent memory of the encounter. Compliance with a prompt is easily mistaken for scrutiny of a claim. The blanks confirm that the officer read the sentence; they cannot confirm that the sentence is true. And because the placeholders draw the eye toward discrete, checkable facts, they may paradoxically steer attention away from the softer and more consequential elements of a narrative, the framing of a suspect's demeanour, the ordering of events, the inference of intent, which is exactly where a language model's interpretive choices do their quiet work and where an error is hardest to catch.

Two Witnesses Collapse Into One

The most articulate version of this concern belongs to the American Civil Liberties Union, and in particular to Jay Stanley, a senior policy analyst with the organisation's Speech, Privacy, and Technology Project, who authored a November 2024 white paper urging departments not to adopt the technology. Stanley's central argument is deceptively simple, and it turns on the idea of evidence as something that must be independent to be valuable.

In the ordinary course of policing, Stanley points out, an encounter that ends up in court generates two distinct records. There is the body-worn camera footage, an imperfect and partial mechanical record that captures some things and misses others. And there is the officer's own account, reconstructed from memory and written into a report. These two records are valuable precisely because they are separate. When they corroborate each other, that agreement means something. When they diverge, the divergence is itself informative, an invitation to ask why the camera saw one thing and the officer remembered another. The friction between the two is a feature of the system, not a flaw.

Draft One, in Stanley's analysis, threatens to collapse that structure. If the police report is essentially an AI rehash of the body-camera audio, then the two records are no longer independent. You do not have a mechanical record and a human recollection that can be checked against each other; you have the mechanical record and a derivative summary of it, dressed in the first person and signed as though it were an independent memory. The corroboration becomes circular. Worse, the ACLU warns, human memory is not a fixed recording but a malleable, reconstructive process, and psychologists have shown for decades that exposure to an external account can reshape a person's recollection of an event. An officer who reads a machine's confident narrative before committing their own memory to paper may find that the narrative quietly overwrites what they would otherwise have recalled. The report does not just record the memory; it contaminates it. Stanley has argued that some of these problems are not merely difficult but, as he puts it, not even theoretically solvable, because you cannot un-ring the bell of having read the machine's version first.

There is a darker corollary that the ACLU has been careful to name. The same mechanism that can overwrite an honest memory can also launder a dishonest account. If an officer does something during an encounter that the camera's audio did not capture, an unjustified use of force framed as compliance, a search conducted without the basis later claimed, the machine cannot narrate what it never heard, and the officer is handed a clean, authoritative-sounding scaffold onto which a convenient version of events can be grafted. The report's machine provenance may even lend it a veneer of objectivity it has not earned. Written justifications for stops and searches exist in part so that supervisors can read them and detect when an officer has strayed beyond the limits of the law; a narrative optimised for fluency rather than candour makes that internal check harder, not easier.

The Draft That Vanishes

If the memory problem is philosophical, the transparency problem is brutally practical, and it is here that the Electronic Frontier Foundation has done its most damaging investigative work. In July 2025, EFF researchers Matthew Guariglia and Dave Maass published the results of a review of public records, user manuals and marketing materials from departments using Draft One, and their conclusion was blunt: the product appears designed to make itself impossible to audit.

The heart of the problem, as the investigators found it in the summer of 2025, was that Draft One did not preserve the draft it generated. In the standard workflow, an officer copied the AI-produced text and pasted it into the department's records system, and the original draft simply disappeared when the window closed. No version was retained showing what the machine had written before the human touched it. No record captured which sentences were the algorithm's and which were the officer's own. As the EFF documented, an Axon senior product manager acknowledged that the company does not store the original draft “by design,” explaining that “the last thing we want to do is create more disclosure headaches for our customers and our attorney's offices.” The deletion of the evidentiary trail, in other words, was not an oversight. It was a selling point.

The consequences ripple outward. When a finished report contains a biased phrasing, a factual error, a misinterpretation or an outright falsehood, there is no way to determine whether the officer or the algorithm introduced it. The audit trail that might allow a judge, a defence attorney, a supervisor or a member of the public to assess how the technology behaves simply does not exist. The EFF found that many departments could not even generate a list of which reports had been produced with Draft One; officers at one Indiana department reported that such reports were not searchable at all. One internal email unearthed by the investigation captured the institutional mood with unusual candour, an administrator writing that “we love having new toys until the public gets wind of them.” Without the ability to separate machine-authored text from human-authored text, the very research that might tell us whether these systems make policing more accurate or less, more biased or less, becomes impossible to conduct. Civil-liberties groups have made the deeper point that opacity of this kind does not merely frustrate researchers; it deprives communities and their elected representatives of the information they would need to decide whether they want the officers who serve them to use such tools at all.

That position has since shifted, and the shift deserves to be recorded as carefully as the original finding. In the release cycle spanning November and December of 2025, Axon added an original-draft retention capability to Draft One, allowing agencies in the United States to retain and later access the original, unedited narrative the model produced. The company's own documentation describes the feature as supporting “legislation that requires organizations to maintain the original AI-generated drafts associated with official police reports,” which is an unusually candid statement of cause and effect. The capability the company had said it deliberately omitted was built because lawmakers came to require it, not because the argument for an audit trail was finally won on its merits. Axon has added other instrumentation alongside it, a Draft One AI-Generated Drafts Report allowing preserved drafts to be exported, and audit-trail entries that record when a draft was requested, when the settings governing retention were altered, and when a draft was downloaded or deleted.

The improvement is real and should be acknowledged as such. But its shape matters as much as its existence. Retention is off by default, a choice Axon explains as being intended to avoid automatically storing drafts before an organisation has updated its policies or retention schedules, and it is switched on, if it is switched on at all, agency by agency. Only the unedited machine version is saved; the intermediate states through which an officer's editing passed are not. Each department decides for itself how long the drafts persist and whether they are purged alongside the associated evidence. What this produces is a patchwork rather than a guarantee. Whether the report in any given case has a preserved original now depends on which state the department sits in and which box an administrator happened to tick, and a defence lawyer cannot know the answer before asking. The absence of an audit trail has become a local policy choice rather than a product-wide certainty, which is unquestionably better than what came before. It is not the same thing as a uniform evidentiary record that a court can rely on being there.

What a Report Is Actually For

It is tempting to treat a police report as mere administrative residue, a bureaucratic formality generated after the real work of policing is done. It is nothing of the kind. In the machinery of American criminal justice, the incident report is one of the most consequential documents a state actor ever produces, and its influence begins early and never really ends.

A report frequently supplies the probable cause that justifies an arrest, the written articulation of facts that a magistrate relies upon to conclude that a crime likely occurred and that this person likely committed it. It shapes the charging decision a prosecutor makes. It becomes part of the discovery that the defence receives, and its contents can be read into evidence at trial. Under the constitutional obligations established by the Supreme Court in Brady v. Maryland and Giglio v. United States, prosecutors must disclose to the defence any evidence that is favourable to the accused or that bears on the credibility of a witness, including the police officers who testify. An officer's report is a primary artefact against which their courtroom testimony is measured; inconsistencies between the two are among the most powerful tools a defence lawyer possesses on cross-examination.

Introduce a machine into the authorship of that document, and a cascade of unfamiliar questions follows. If a report's phrasing originated with a language model, whose statement is it, exactly, for the purposes of the hearsay rules that govern what may be admitted at trial? If a defence attorney wishes to probe how a particular characterisation of the defendant found its way into the sworn narrative, what is there to examine when the draft has been deleted and the prompt engineering behind it is a trade secret? The chain of custody that the law demands for physical evidence, the documented provenance that lets a court trust that a thing is what it purports to be, has no clear equivalent for a narrative that passed through a proprietary model before an officer adopted it as their own. When an officer on the witness stand swears that their report is accurate, is later shown to be wrong, and explains that the artificial intelligence must have made the error, there is, as one prosecutor has warned, no draft to consult that could confirm or refute the claim. The officer cannot fully account for words they did not write, and the defendant cannot fully interrogate an accusation whose origin has been erased.

The ACLU has argued that the disclosure questions run deeper still, reaching past the vanished draft to the entire apparatus behind the report: the way Axon has customised and instructed its language model, the queries it runs, the error rates of the generated output. All of these might, in a given case, constitute material that a defendant is entitled to examine. Yet almost none of it is available for inspection, and much of it is shielded as proprietary. A defendant's Sixth Amendment right to confront the evidence against them was written for a world in which accusations came from people who could be questioned. It is not obvious how that right survives contact with an accusatory narrative whose most influential author is a model that cannot be cross-examined, cannot be placed under oath, and cannot be asked why it chose one word rather than another.

The federal courts have begun, slowly, to respond. The Advisory Committee on Evidence Rules has proposed a new Federal Rule of Evidence 707, which would take machine-generated evidence offered without a supporting human expert and subject it to substantially the standard that already governs expert testimony: that the output rests on sufficient facts or data, that it is the product of reliable principles and methods, and that those methods have been reliably applied to the facts of the case. It is a sensible instrument, and the pace of it is the point. The public comment period closed on 16 February 2026, and even on the most favourable procedural timetable the rule could not take effect before 1 December 2027. Deployment is measured in months and rule-making in years, and in the interval between the two the reports are being written, filed, charged upon and relied upon regardless. The law will arrive, in the way that law does, some time after the thing it governs has become ordinary.

A Taxonomy of Ways This Goes Wrong

The academic literature has begun to catch up with the deployment, and in March 2026 a group of British researchers published one of the most systematic attempts yet to map the hazards. The paper, titled “Responsible AI in criminal justice: LLMs in policing and risks to case progression” and posted to the arXiv preprint server, was written by Muffy Calder, Michele Sevegnani and Evdoxia Taka of the School of Computing Science at the University of Glasgow, together with Marion Oswald of Northumbria Law School and Elizabeth McClory-Tiarks of Newcastle University. Grounded in the law and policing structures of England and Wales rather than the United States, it nonetheless offers a framework that travels well across jurisdictions.

The researchers catalogue fifteen distinct policing tasks that large language models could be used to perform, and seventeen categories of risk that arise from doing so, illustrating them with more than forty worked examples of how a given failure might damage a case as it moves through the system. The risks they identify range across the whole pipeline. Some concern the outputs themselves: erroneous omissions or additions that quietly alter the strength of a case, factual inaccuracies, inappropriate linguistic style that undermines the integrity of a statement, cultural and dialectal misinterpretations, and the social and cultural biases, including racial and victim-blaming biases, that models are known to reproduce. Others concern the inputs, such as the design of prompts and the vulnerability of systems to injection, jailbreaking and the leakage of sensitive information to third parties. Still others concern the near-impossibility of proper evaluation, because there is often no objective ground truth against which a generated narrative can be measured, and the systems-engineering reality that models are updated and reconfigured in undocumented ways that make yesterday's output impossible to reproduce.

Two of their categories bear directly on the evidentiary anxieties raised on the American side of the Atlantic. One concerns what they call intermediate unused material: the draft versions and discarded outputs that, under disclosure rules, may create precisely the burdens Axon has designed its product to avoid. Another concerns the acute shortage of qualified expert witnesses able to explain to a court how such a tool actually works, a problem that compounds as the tools grow more numerous and are chained together, each feeding its output into the next until no single human understands the whole pipeline. The paper stops short of declaring the technology unusable; its authors suggest that many of these risks could be reduced as good practice is agreed and systematically applied. But the sheer length of the list is itself an argument, a reminder that a fluent paragraph produced in seconds carries a long tail of ways in which it can quietly corrupt the record it was meant to serve.

It is worth setting that taxonomy against the failures that have actually surfaced in the field, because the most widely reported of them is instructive for entirely the wrong reasons. In December 2025 the Heber City Police Department in Utah began testing Draft One alongside a second tool called Code Four. In early January 2026, one of the generated reports recorded that an officer had been turned into a frog. The system had picked up the audio of the Disney film “The Princess and the Frog”, playing in the background of a body-camera recording, and folded it into the narrative as though it were an account of events. A department sergeant caught the error and corrected it, observing that the department does not employ amphibious officers. The department intended to carry on with the software regardless, citing an estimated six to eight hours saved each week.

The story travelled because it is funny, and its comedy is precisely what makes it unrepresentative of the danger. An officer transformed into an amphibian is caught instantly, because nothing in a police report could be further from the plausible; the error announces itself. The failures that should worry a court are the ones that do not. A sentence attributed to the wrong speaker, a characterisation of a suspect's demeanour hardened by a degree or two, a sequence of events reordered so that a movement appears to precede rather than follow a command: all of these read exactly like the truth, and they survive a tired officer's review at the end of a shift for the same reason, which is that nothing about them signals that they should not. This is where automation bias does its damage. A reviewer's attention is a finite resource, spent most readily on what looks wrong, and a fluent, confident, well-formed falsehood looks like nothing at all.

The Ledger of Independent Evidence

Set against this catalogue of risks is the promise that supposedly justifies accepting them: time. Axon's core pitch is efficiency, the claim that Draft One can roughly halve the hours officers spend writing reports and return that time to the street. It is a seductive proposition for chronically short-staffed departments. It is also, according to the independent evidence gathered so far, largely unsubstantiated.

The most rigorous critic of the efficiency claim is Ian T. Adams, a criminology professor at the University of South Carolina and himself a former police officer, who has become something close to the field's designated empiricist. In a study circulated on the CrimRxiv preprint platform, Adams and colleagues recruited ninety-two senior law-enforcement officers, sergeants and above, with an average of twenty-two years of experience approving reports, and asked them to evaluate eighty police reports, twenty of which had been drafted using Draft One. The results were not kind to the technology. Reviewers rated the AI-assisted reports significantly worse on accuracy, a finding that was statistically significant and substantively meaningful; the estimated effect moved a report from roughly the fiftieth to the thirty-sixth percentile on perceived accuracy. On broader composite measures of quality, the machine-drafted reports showed no reliable improvement, and expert reviewers proved unable to distinguish AI-written from human-written reports at a rate better than chance.

On the central question of time saved, Adams has been withering, summarising the state of the evidence with the observation that there is not a single independent evaluation supporting the vendor claims being made to police departments. His own earlier work found that Draft One produced no measurable time savings, and a separate evaluation of a different AI report-writing tool reportedly found not a saving but an increase of some eighteen and a half minutes per incident. The field experience appears to bear him out. The Anchorage Police Department, after a three-month trial, abandoned Draft One, its deputy chief explaining that the department had hoped the tool would deliver significant time savings for officers but had simply not found that to be the case. The reason offered was instructive: because the system works from audio alone, it routinely missed the visual details officers had observed but never spoken aloud, forcing them to add material by hand and eroding whatever efficiency the automation had promised. Body-camera audio, it turns out, is a thin and partial record of a physical encounter, and building a legal narrative on it requires precisely the independent human reconstruction that the tool was supposed to make unnecessary.

Anchorage is no longer alone. Manchester, New Hampshire, the first agency in the country to test Draft One and the department that supplied the officers for Adams's randomised trial, has abandoned it as well. Lieutenant Matthew Barter, who took part in the research, put the reason with a plainness that no vendor presentation can easily absorb: it was simply easier for officers to type the report themselves.

A more recent picture of how these systems behave in daily use arrived in July 2026, when the reporter Thomas Brewster published a Forbes investigation built on emails obtained under public-records law, covering seven months of testing at the Lafayette Police Department in Indiana. The product at issue there was not Draft One but Form One, a separate and newer Axon tool that listens to body-camera audio and populates the structured fields of a form rather than composing a narrative, and the distinction is worth holding onto, because the complaints were nonetheless familiar. Officers reported that the system repeatedly failed to capture names and vehicle registration plates that were clearly audible in the footage, and that a form which had taken thirty seconds to complete by hand now took three minutes, because of the volume of corrections the machine's version required. Axon characterised the deployment as early access to a product that was not yet finished, which may well be true. It is also true that the same pattern has now recurred across two products of quite different design, which suggests that the constraint does not lie in the software but underneath it. Audio is a thin record of a physical event, and no amount of model improvement can recover from a microphone the details that were never spoken aloud.

The research Adams began has meanwhile moved out of preprint and into the peer-reviewed literature, which matters because it removes the last easy objection to it. The randomised controlled trial, published in the Journal of Experimental Criminology under the title “No man's hand: artificial intelligence does not improve police report writing speed”, followed eighty-five officers and seven hundred and fifty-five reports, and buttressed the experimental result with a difference-in-differences robustness check across 6,084 reports written over a full year. It found no significant effect on the time taken to write a report. The single quantity on which the entire commercial case for the technology rests did not move.

The companion paper is the more unsettling of the two. Under the title “Writing at the speed of hype: officers' post-experimental perceptions of AI report writing”, also in the Journal of Experimental Criminology, a team led by Hunter M. Boehme and including Adams, Barter, Irick A. Geary and Kyle McLean asked the officers who had taken part what they made of the tool, and found that their perceptions and the measurements had come apart. Roughly forty-eight per cent of the officers who used it reported that it had saved them time. Supervisors perceived improvements in the quality and completeness of the reports they were approving. The trial data showed no such effect on any of these dimensions.

This is the empirical heart of the matter, and it deserves stating without hedging. The tool reliably produces the feeling of time saved without the fact of it. Nearly half the officers who used it came away convinced that a burden had been lifted, while the clock recorded that nothing had been lifted at all, and their supervisors believed the reports had improved when, by the study's measures, they had not. A technology that generates a sense of effortlessness while measurably changing nothing about the duration of the task is not simply a productivity tool that has failed to deliver. It is something more specific and considerably more troubling, because that is precisely the profile of a system that lowers vigilance rather than workload. The subjective experience of ease has to come from somewhere, and if it is not coming from the clock, the most parsimonious explanation is that it is coming from effort, from the attention an officer no longer spends reconstructing an event because a plausible reconstruction is already sitting on the screen. That is automation bias observed not as a laboratory prediction but as a field measurement, and it is also the mechanism by which three hundred thousand hours can be sincerely reported on a customer survey and still not exist.

The Prosecutors Who Said No

Perhaps the most telling resistance has come not from privacy advocates or academics but from within the criminal justice system itself, from the prosecutors whose cases depend on the reliability of the reports they receive. In 2024, the King County Prosecuting Attorney's Office in Washington State, which covers Seattle, circulated guidance instructing local law-enforcement agencies not to use AI to draft narrative reports, and warning that reports written with the assistance of such tools would be rejected. The memo, issued by Chief Deputy Prosecutor Daniel J. Clark, was careful to strike a measured tone. “We do not fear advances in technology,” Clark wrote, “but we do have legitimate concerns about some of the products on the market now.”

Those concerns were concrete rather than reflexive. Clark noted that errors could easily slip past a reviewing officer confronting a volume of material under deadline, the very automation-bias dynamic the human-factors literature predicts. He warned of the scenario in which an officer testifies that their report is accurate, is shown to be wrong, and attributes the mistake to the artificial intelligence, at which point there would be no preserved draft to establish whether the machine or the human was truly responsible, with consequences that could be devastating for the case, the community and the officer alike. He raised questions about whether the products complied with the security requirements governing criminal-justice information. It was not a Luddite's rejection; Clark acknowledged that a day would likely come when such tools could assist prosecutors in valuable, time-saving ways. It was a judgement that the day had not yet arrived.

Legislatures have begun to move as well, and the shape of their response is revealing. Rather than banning the technology, the first statutes have targeted precisely the transparency deficits the EFF identified. Utah moved first, enacting Senate Bill 180, which took effect on 7 May 2025 and made it the first state in the country to legislate on the question. The statute requires that AI-authored reports carry a disclaimer, that officers certify their accuracy, and that agencies maintain a written policy governing their use of generative artificial intelligence. California went further. In October 2025, Governor Gavin Newsom signed Senate Bill 524, which took effect on the first day of 2026. The law requires that any report generated wholly or partly by artificial intelligence identify every AI programme used and carry a prominent disclosure stating that “This report was written either fully or in part using artificial intelligence,” alongside the signature of the officer verifying that they reviewed it and that its facts are true. Crucially, it also requires departments to retain the first draft, so that judges, defence attorneys and auditors can see which portions of the final report were written by the machine and which by the officer, and it forbids vendors from selling or sharing the data that agencies feed into their systems. In a single provision, California legislated into existence the audit trail that Axon had assured its customers was deleted by design, and within weeks the company had built it. The mandate came first and the capability followed, which is to say that the law extracted from the vendor precisely what its customers had been told was deliberately unavailable. Observers of the field expect other states to follow California and Utah, and the coming years are likely to see a patchwork of disclosure requirements harden into something closer to a national norm.

Whose Words Are They, Anyway

Return, at the end, to the officer at the terminal, reading a report they did not write and preparing to make it their own. The deepest difficulty with Draft One is not that a language model is imperfect, nor even that its drafts vanish, though both matters gravely. It is that the technology quietly relocates the point at which a human mind independently reconstructs the truth of an event, and it relocates it to a place where that reconstruction may never actually happen.

The traditional police report, for all its well-documented flaws, its biases, its self-serving omissions, its occasional dishonesty, rested on a particular premise: that a human being had sat down and tried, from their own memory, to render an account they were willing to swear to. The account might be wrong, but it was theirs, and its wrongness could be probed, cross-examined, contradicted by the footage, tested against the physical evidence. What automation threatens is not the accuracy of that account so much as its independence, the quality that made it worth having as a separate thing in the first place. When the first draft is machine-made, the officer's signature attests less to an act of recollection than to an act of ratification. The human remains in the loop, but the loop has been redrawn so that the human's role is to approve rather than to author.

And this is where the question of responsibility becomes genuinely hard to answer. If an AI-drafted narrative shapes a prosecution, subtly framing an ambiguous encounter, importing a characterisation the officer would not independently have chosen, embedding a bias the model absorbed from its training data, who is answerable? The officer signed it and is formally accountable, yet cannot fully explain the provenance of words they did not compose. The vendor built the model but disclaims responsibility for how any given department deploys it, and has arranged matters so that the evidence needed to trace an error back to its source no longer exists. The prosecutor introduces the report but may not know it was machine-drafted at all. The defendant, who has the most at stake, is left interrogating a sworn account whose true author is a proprietary system they will never be permitted to examine. Everyone is partly responsible, which is another way of saying that no one quite is.

That diffusion of accountability, more than any single hallucinated fact, is what should give a society pause before it lets the most basic evidentiary unit of its justice system be drafted, first, by a machine that remembers nothing and can be asked nothing, and then quietly forgotten. The efficiency gains, on the current evidence, are illusory. The risks to the reliability of the record are not. And a criminal justice system that cannot say, with confidence, who wrote the accusation, has surrendered something that no amount of saved time can buy back. The remedy is not necessarily to forbid the machines outright, but to insist that they leave a trace, that the draft survive, that the human account precede rather than follow the algorithm's, and that the person on the stand be able to say, truthfully, that the words are their own. Until then, every signature at the bottom of an AI-drafted report is a small act of faith in a witness who cannot testify.

References

  1. Axon Enterprise, “Draft One” product page. https://www.axon.com/products/draft-one
  2. Axon Enterprise, “Axon reimagines report writing with Draft One, a first-of-its-kind AI-powered force multiplier for public safety,” 23 April 2024. https://investor.axon.com/2024-04-23-Axon-reimagines-report-writing-with-Draft-One,-a-first-of-its-kind-AI-powered-force-multiplier-for-public-safety
  3. Axon Enterprise, “Auditing and reporting,” Draft One product guide. https://www.axon.com/help/draft-one/software/draft-one/auditing-reporting.htm
  4. Matthew Guariglia and Dave Maass, “Axon's Draft One Is Designed to Defy Transparency,” Electronic Frontier Foundation, July 2025. https://www.eff.org/deeplinks/2025/07/axons-draft-one-designed-defy-transparency
  5. Electronic Frontier Foundation, “AI Police Reports: Year In Review,” December 2025. https://www.eff.org/deeplinks/2025/12/ai-police-reports-year-review
  6. Electronic Frontier Foundation, “Anchorage Police Department: AI-Generated Police Reports Don't Save Time,” March 2025. https://www.eff.org/deeplinks/2025/03/anchorage-police-department-ai-generated-police-reports-dont-save-time
  7. Jay Stanley, “AI-Generated Police Reports Raise Concerns Around Transparency, Bias,” American Civil Liberties Union. https://www.aclu.org/news/privacy-technology/ai-generated-police-reports-raise-concerns-around-transparency-bias
  8. American Civil Liberties Union, “Police Departments Shouldn't Allow Officers to Use AI to Draft Police Reports” (white paper), November 2024. https://assets.aclu.org/live/uploads/2024/12/Automated-Police-Reports-1291.pdf
  9. American Civil Liberties Union, “Studies Question Value of AI-Assisted Police Reports.” https://www.aclu.org/news/privacy-technology/studies-question-value-of-ai-assisted-police-reports
  10. Muffy Calder, Marion Oswald, Elizabeth McClory-Tiarks, Michele Sevegnani and Evdoxia Taka, “Responsible AI in criminal justice: LLMs in policing and risks to case progression,” arXiv:2603.18116, March 2026. https://arxiv.org/abs/2603.18116
  11. Ian T. Adams, Matt Barter, Kyle McLean, Hunter M. Boehme and Irick A. Geary, “No man's hand: artificial intelligence does not improve police report writing speed,” Journal of Experimental Criminology. https://doi.org/10.1007/s11292-024-09644-7
  12. Hunter M. Boehme, Ian T. Adams, Matt Barter, Irick A. Geary and Kyle McLean, “Writing at the speed of hype: officers' post-experimental perceptions of AI report writing,” Journal of Experimental Criminology, 2025. https://doi.org/10.1007/s11292-025-09679-4
  13. Ian T. Adams et al., “A Good College Essay but a Bad Police Report: A Triple-Blind Expert Evaluation of AI-Assisted Police Reporting,” CrimRxiv. https://www.crimrxiv.com/pub/u7azgqzd/release/1
  14. Thomas Brewster, “Axon Says AI Police Reports Save Time. Public Records Show They Get Facts Wrong,” Forbes, 22 July 2026. https://www.forbes.com/sites/thomasbrewster/2026/07/22/axon-says-ai-police-reports-save-time-public-records-show-they-get-facts-wrong/
  15. Axios Salt Lake City, “How AI turned a Utah police officer into a frog,” 7 January 2026. https://www.axios.com/local/salt-lake-city/2026/01/07/ai-police-utah-heber-city-princess-frog
  16. “Prosecutors in Washington State Warn Police: Don't Use Gen AI to Write Reports,” Electronic Frontier Foundation, October 2024. https://www.eff.org/deeplinks/2024/10/prosecutors-washington-state-warn-police-dont-use-gen-ai-write-reports
  17. KOMO News, “AI-assisted police reports not welcome in King County due to error concerns.” https://komonews.com/news/local/king-county-prosecutor-tells-police-not-to-use-ai-artificial-intelligence-for-official-reports-for-now-errors-concerns-law-enforcement-perjury-criminal-justice
  18. Utah Senate Bill 180 (2025), law enforcement use of generative artificial intelligence.
  19. California Legislature, Senate Bill 524, “Law enforcement agencies: artificial intelligence.” https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260SB524
  20. Electronic Frontier Foundation, “Victory! California Requires Transparency for AI Police Reports,” October 2025. https://www.eff.org/deeplinks/2025/10/victory-california-requires-transparency-ai-police-reports
  21. United States Courts, Advisory Committee on Evidence Rules, proposed Federal Rule of Evidence 707 (machine-generated evidence).
  22. GovTech, “ACLU Slams AI Police Reports, and Axon in Particular.” https://www.govtech.com/biz/aclu-slams-ai-police-reports-and-axon-in-particular

Tim Green

Tim Green UK-based Systems Theorist & Independent Technology Writer

Tim explores the intersections of artificial intelligence, decentralised cognition, and posthuman ethics. His work, published at smarterarticles.co.uk, challenges dominant narratives of technological progress while proposing interdisciplinary frameworks for collective intelligence and digital stewardship.

His writing has been featured on Ground News and shared by independent researchers across both academic and technological communities.

ORCID: 0009-0002-0156-9795 Email: tim@smarterarticles.co.uk

Listen to the free weekly SmarterArticles Podcast

Discuss...

Fifty applications is not an unusual number. Six months is not an unusual stretch. What makes Amanda Bowler's story worth stopping over is the third number, the one that sits at zero: face-to-face interviews. Not zero offers. Zero occasions on which a human being sat opposite her and formed a view. The 48-year-old psychology graduate, whose experience was reported by the Sydney Morning Herald on 29 August 2026, is carrying a HECS debt of roughly 44,000 Australian dollars, a figure inflated by the fact that registration as a psychologist in Australia requires years of postgraduate study stacked on top of the undergraduate degree. She paid for the qualification. She wrote the applications. And on the available evidence, the qualification was assessed by software and the applications were read by nothing.

That last sentence is the one that ought to be arresting, and the reason it is not is that we have grown accustomed to it in under three years. The Australian labour market she is applying into is genuinely tight. SEEK's employment report for July 2026, published on 12 August, recorded applications per job advertisement at their highest level on record, having risen for seven consecutive months while job advertisement volumes fell away beneath them, down 0.4 per cent month on month in July and 6.0 per cent lower than a year earlier. More people are chasing fewer roles. That is an old story and a cyclical one.

The new story is what is standing between them. The Australian Responsible AI Index, the national benchmark produced by Fifth Quadrant with the National AI Centre, found that a majority of Australian organisations already use AI in recruitment to some degree, and the Herald's reporting puts the figure at roughly 80 per cent of Australian companies at moderate or higher levels of use. On the other side of the same transaction, jobseekers now deploy generative systems and autonomous agents that scrape boards overnight, rewrite the curriculum vitae for each posting, generate the covering letter and submit before the applicant has woken up. A senior human resources leader, quoted in the same Herald report, described where this ends with more precision than most white papers manage. The bots just botting each other. Little robots yelling at each other.

Refusing Both of the Easy Stories

There are two ready-made articles about this and both are worthless.

The first is the technophobic one, in which the machines have desecrated a sacred human ritual and the remedy is to bring back the handshake. This is sentimental nonsense. Human hiring was never a meritocracy. It was slow, inconsistent, swayed by schools and accents and surnames, and it discriminated with a fluency that no audit ever caught because nobody was auditing. Anyone nostalgic for the CV pile on a hiring manager's desk should reckon with what happened to CVs at the bottom of it on a Friday afternoon.

The second is the efficiency story, in which volume has become unmanageable, automation is the only rational response, and since candidates are automating too the whole thing is symmetrical and therefore fair. This is more sophisticated and more dangerous, because the symmetry is fake. A candidate's agent optimises one person's chances against an entire market. An employer's agent optimises a queue against a budget. Only one of those produces an output with legal and material consequence. The candidate's machine issues a request. The employer's machine issues a verdict. Calling that an arms race between equals is like calling a trial an argument between the defendant and the judge.

The harder and more specific argument is this. The injury is not that judgement has been automated. Judgement has always been delegated, compressed and rushed. The injury is that the loop has closed: there is now no stage in the process at which any human being with time and authority is obliged to read. Once no human reads, the decision loses its author. And a decision without an author cannot be explained, cannot be appealed, cannot be corrected, and cannot be learned from. What Bowler encountered fifty times was not harshness. It was the absence of anybody to be harsh.

The Filter Myth and the Thing That Quietly Replaced It

Before going further it is worth demolishing the folklore, because the folklore is doing real damage to the argument.

For over a decade, career advice has been built around the claim that applicant tracking systems automatically bin 75 per cent of CVs before a human sees them. The statistic has no research behind it. As Leda Salazar de Leon and Mehnaz Rafi set out in an analysis published in July 2026, it traces to a 2012 sales pitch by Preptel, a résumé-optimisation vendor that closed the following year, and no methodology was ever published. The company selling the cure invented the disease. Recruiter surveys since have found the overwhelming majority do not configure their tracking systems to reject automatically on formatting or keywords, and small businesses, which employ most of the workforce in most developed economies, frequently do not use such systems at all. Applicant tracking systems were, for most of their history, filing cabinets with a search box.

So an entire generation of jobseekers spent a decade terrified of a filter that mostly did not exist, buying templates and keyword tools to defeat it. That matters here for two reasons. First, it should make anyone sceptical of vendor-generated panic, including panic that flatters this article's own thesis. Second, and more uncomfortably, the filter has now actually arrived, and it arrived in precisely the place the myth said it was, which means the warning has been worn out by overuse at exactly the moment it becomes true.

Large language models genuinely do rank. They produce orderings, and the orderings are not neutral. Kyra Wilson and Aylin Caliskan of the University of Washington ran a résumé audit through massive text embedding models, using more than 500 real CVs and 500 job descriptions across nine occupations, generating over three million combinations of job, race and gender. White-associated names were preferred in 85.1 per cent of cases and Black-associated names in 8.6 per cent. Female-associated names were preferred in 11.1 per cent of cases. For some intersections, notably Black men, the models preferred other candidates in close to 100 per cent of comparisons. This is not a system that occasionally misfires. It is a system reproducing the statistical regularities of a corpus, doing exactly what it was built to do, at the precise point in the process where the myth taught everyone to expect it and nobody has been checking.

Two Automations Racing Each Other Into a Wall

On the employer side, the screening layer has stopped being software and become a participant. Alex, formerly Apriora, is a Y Combinator company founded by Aaron Wang and John Rytel that conducts live voice and video screening interviews, scores candidates and returns a ranked shortlist. It raised a 17 million dollar Series A led by Peak XV Partners in September 2025, taking total funding to 20 million, and reports having run more than a million AI-led screening interviews, reaching up to 5,000 in a single day for its largest customers. Five thousand first-round interviews in a day is not a faster version of what recruiters used to do. It is a different activity with the same name.

On the candidate side, the tooling is scrappier, cheaper and open. Public repositories host agents that use browser automation and web scraping to read postings and auto-apply with a tailored CV and covering letter for each one. Commercial equivalents advertise applying to thousands of roles in a click. Abhijay Arora Vuyyuru, a product manager at Google's YouTube who writes a widely read newsletter on applied AI, has published a step-by-step guide to building a personal job-hunting agent that runs on a small cloud server, pulls fresh listings each morning, scores each against your CV, and messages you the top five. Speaking to the Herald, he predicted that within five years every jobseeker will have a personal AI agent, and that it will most probably be talking to the company's AI recruitment agent. He is not forecasting from the sidelines. He ships the thing.

The consequences are measurable, and Greenhouse has measured them. Its AI in Hiring report, published on 19 November 2025 and drawing on 4,136 respondents across the United States, United Kingdom, Ireland and Germany, split between 2,900 jobseekers and 1,236 recruiters and hiring managers, found that 49 per cent of candidates had submitted more applications than the year before and that 54 per cent had already been interviewed by a machine. Six months later the company asked again. Its 2026 candidate report, published on 1 May and surveying 2,950 active jobseekers across the United States, United Kingdom, Germany, Australia and Ireland, put the share at 63 per cent, a rise of thirteen percentage points in half a year. Whatever this is, it is not settling down. The earlier report also found the trust gap that defines the whole system: 70 per cent of hiring managers trust AI to make faster and better hiring decisions, while just 8 per cent of jobseekers believe AI makes hiring fair. Daniel Chait, the company's chief executive and co-founder, called it an AI doom loop that is getting worse, not better.

Eight per cent. That is not scepticism. That is a population that has concluded the process is illegitimate, still participating in it because it has no alternative.

When the Signal Stops Meaning Anything

There is a clean piece of economics underneath this, and it was written in 1973.

Michael Spence's job market signalling model explains why credentials work at all. A signal only carries information if it is differentially costly to produce: education signals ability because it costs more, in effort and time, for the less able to acquire. Take away the cost differential and the signal stops transmitting. It does not become a weaker signal. It becomes noise wearing a signal's clothes.

Generative AI drove the cost of producing a competent, tailored, keyword-aligned application to approximately zero, for everyone, simultaneously. The considered covering letter used to be a costly signal of interest. It is now free. Which means it now says nothing, and everybody involved knows it says nothing, and each side has responded by escalating rather than by admitting the instrument is broken.

The escalation has a measurable shape, and the most revealing number in this entire field lives in the gap between two studies. Greenhouse found that 41 per cent of jobseekers said they had used prompt injection, hiding instructions in a document to steer an AI screener, with 52 per cent of the remainder saying they were considering it. Then Mohan Zhang, Yuqi Jia, Zhen Tan, Steven Jiang, Neil Zhenqiang Gong, Tianlong Chen and Dawn Song went and looked. Their study, presented at the USENIX Security Symposium in 2026, is the first large-scale empirical measurement of prompt injection in a real deployed system: roughly 200,000 genuine CVs collected over several years, of which about 1 per cent contained hidden injections. Prevalence is rising. More than 90 per cent of the injections avoided explicit instruction syntax, which is to say they were subtle enough to be difficult to catch.

Forty-one per cent say they do it. One per cent do it. That gap is not a measurement error, and it is not really about cheating. It is a statement of belief. Two in five jobseekers now consider sabotaging the employer's screening system to be a normal and defensible thing to say out loud about themselves. The moral standing of the hiring process collapsed considerably faster than the technology arrived.

Employers, deprived of a working signal, are hunting for a new costly one, which turns out to be proof that the applicant is a person. Gartner, in research released on 31 July 2025 drawing on surveys of some three thousand candidates, predicted that by 2028 one in four candidate profiles worldwide will be fake, found that 6 per cent of respondents admitted to some form of interview fraud, that 39 per cent had used AI during the application process, and that only 26 per cent trusted AI to evaluate them fairly. The vendor response has been identity verification products bolted onto applicant tracking systems, selfie-based checks, and a documented drift back towards in-person interviews for no reason other than confirming the candidate exists.

Read that sequence again, because it is close to farcical. The industry removed the human reader in order to save the cost of reading. It has now reinstated costly human verification in order to establish that there is a human on the other end. The cost was never eliminated. It was moved downstream, past the point at which Amanda Bowler had already been rejected fifty times.

What Researchers Found Inside the Loop

Three recent studies get closer to the mechanism than any amount of vendor commentary, and together they say something the industry has not absorbed.

The first, by Aditya Bhattacharya and Katrien Verbert, published in May 2025, built a multi-agent system powered by large language models to guide jobseekers through the recruitment process and explain hiring decisions to them. Evaluated with 20 participants, it was found significantly more actionable, trustworthy and fair than the conventional process. Note what the candidates responded to. Not a better weapon. An explanation. The enormous demand currently being met by auto-apply tools is, at root, demand for legibility, and it is being served by the only vendors willing to sell anything at all to the person being screened.

The second, by Md Nazmus Sakib, Naga Manogna Rayasam and Sanorita Dey, submitted in January 2026 and revised in March, examined asynchronous AI interviewers through analysis of subreddit discussion and interviews with 17 participants, then tested interface changes with 180 more. Its central finding is that applicants suffer from mismatched expectations amplified by organisational rhetoric, and that familiarity with large language models shaped how candidates perceived the process, sometimes producing workarounds and deceptive practices. That causal direction matters enormously. Deception is not a character flaw distributed randomly across the applicant pool. It is a predictable behavioural response to a process that misrepresents itself, and it is elicited most reliably from the candidates who understand the technology best.

The third is the one that should end a particular argument for good. Sajel Surati, Rosanna Bellini and Emily Black interviewed 22 recruiting professionals about generative AI in their daily workflows. Recruiters believed they retained final decision-making authority. The researchers found that the AI had become, in their phrase, an invisible architect shaping the foundational building blocks of the information used for evaluation. Adoption decisions largely lay outside recruiters' control, driven by organisational pressure and competitive anxiety rather than professional judgement. And the marginal efficiency gains came at considerable cost, including reduced recruiter expertise and compromised oversight capacity.

This dismantles the human-in-the-loop defence, which is the single most common answer employers give when challenged. The human is in the loop. She is reading a summary the model wrote, of candidates the model ranked, drawn from a pool the model already narrowed, under time pressure the model's throughput created, having gradually lost the expertise that would let her notice when it is wrong. Her presence satisfies an organisational chart and nothing else. Oversight that cannot be exercised is not oversight, and a rubber stamp is not a reader.

The Particular Exposure of Being Forty-Eight

Everything above lands unevenly, and it lands hardest on people who look like Amanda Bowler.

The Australian HR Institute and the Australian Human Rights Commission run a periodic national survey of employers on age in the workplace. Their 2025 report found that 24 per cent of HR professionals classify workers aged 51 to 55 as older, up from 10 per cent in 2023, and that only about half of employers were open to a large extent to hiring people over 50. That is the human baseline into which the automation was installed, and it is worth naming plainly: employer age bias was already there and already growing before a single model was deployed.

What the model adds is scale, speed and deniability. But there is a subtler and more structural problem with automated matching that has nothing to do with inherited prejudice. A ranking system trained on the profiles of people who already hold a role learns what an incumbent looks like. A career changer, by definition, does not look like an incumbent. A 48-year-old psychology graduate has a curriculum vitae with a shape that no successful applicant for an entry-level psychology position has ever had, because successful applicants for those positions are usually 25. The model will score her as a poor match. It will be functioning perfectly. Not a sufficiently close match is not a malfunction, it is the product specification, and it encodes a definition of suitability that nobody in the organisation ever wrote down, approved or could defend if asked.

The most consequential legal test of this proposition is grinding through the Northern District of California. Mobley v. Workday was filed on 21 February 2023 by Derek Mobley, an African American man over 40 with depression and anxiety, who alleged he had been rejected from more than a hundred positions screened through Workday's software, in several instances outside business hours and within an hour of applying. In July 2024, Judge Rita Lin preserved the disparate impact claims, finding it plausible that the vendor was acting as an agent of the employers. On 16 May 2025 the court granted preliminary certification of a collective under the Age Discrimination in Employment Act. In July 2025 the collective was expanded to cover applicants screened using Workday's HiredScore features. The notice plan was approved on 2 December 2025, collective notice was formally authorised on 17 February 2026 with an opt-in deadline of 7 March, and on 6 March Lin rejected Workday's argument that the age discrimination statute does not reach job applicants at all. A third amended complaint followed on 27 March 2026, and on 22 June the court granted in part and denied in part Workday's motion to dismiss it, leaving discrimination claims alive across race, sex, age and disability.

Two figures from the reporting on that case deserve to sit next to each other. Around a billion applications were rejected through the software during the relevant opt-in period. Roughly 14,000 people opted in. That window is now shut, which makes 14,000 not a running tally but a final number, and the ratio it forms with a billion is the accountability gap rendered numerically. Almost nobody rejected by an automated system ever learns enough to raise a hand, because the system's defining feature is that it does not tell you anything happened.

The Law Arrives, and Then Steps Back

You would expect regulation to be closing on this. In the specific weeks around Bowler's fifty applications, it moved backwards.

Under the European Union's AI Act, artificial intelligence used in employment and worker management is classified as high risk under Annex III, and the substantive obligations were due to apply from 2 August 2026, four weeks before this article was written. They did not. The Digital Omnibus on AI, provisionally agreed on 6 May 2026 and confirmed by member state representatives on 13 May, was adopted as Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026 and in force from 27 July, five weeks before this article was written and days before the deadline it removed. This is not a proposal that might yet be resisted. It is settled law. The obligations for stand-alone Annex III systems now apply from 2 December 2027, with embedded Annex I systems slipping to 2 August 2028. What survives on the original timetable is Article 50, the transparency duty to disclose that a person is interacting with an AI system, alongside the Article 5 prohibitions. Article 86, which grants an affected person the right to obtain clear and meaningful explanations of the role an AI system played in a decision that adversely affects them, hangs off the high-risk regime and slips with it.

The resulting settlement is almost satirical. A European candidate rejected today has a legal right to be told a machine was involved, and a fifteen-month wait for any right to be told what it did.

The American picture offers a preview of what enforcement looks like when it does arrive. New York City's Local Law 144 requires annual independent bias audits of automated employment decision tools, public posting of a summary, and advance notice to candidates. Researchers led by Lucas Wright, with Roxana Mika Muenster, Briana Vecchione, Tianyao Qu, Pika Cai, Alan Smith, Jacob Metcalf and J. Nathan Matias, coordinated 155 trained student investigators to check 391 employers in late 2023, behaving as motivated jobseekers would. Eighteen employers, 5 per cent, had posted a bias audit report. Thirteen, 3 per cent, had posted a transparency notice. Eleven had posted both. The researchers coined the term null compliance for the resulting condition, in which non-compliance cannot even be established because the regulated party controls whether anyone knows the law applies to it. The New York State Comptroller's audit published on 2 December 2025, covering July 2023 to June 2025, found the city's enforcement of the law ineffective.

Illinois has gone further on paper. House Bill 3773, enacted as Public Act 103-0804 and effective from 1 January 2026, amends the state Human Rights Act to make discriminatory use of AI in recruitment, hiring and promotion a civil rights violation, prohibits the use of postcodes as proxies for protected characteristics, and requires employers to notify people when AI is used in employment decisions. It sits alongside the older Artificial Intelligence Video Interview Act. Whether it bites is a question about enforcement capacity, and New York's experience is not encouraging. Neither is Illinois's own. The Department of Human Rights published proposed regulations on 15 May 2026, under the heading Subpart J: Use of Artificial Intelligence in Employment, and then on 2 June postponed the rulemaking in order to coordinate with other agencies. No revised timeline has been announced. The statutory obligations have been enforceable throughout, which produces the peculiar situation of an employer bound since New Year's Day to notify candidates that AI is being used in a decision about them, with no final rules describing what an adequate notice contains, and a candidate holding a right whose shape the regulator has not yet been able to state. A law that is in force and unexplained is not the opposite of a law that is unenforced. It is a variation on it.

And Australia, where Bowler is applying, has chosen to do less rather than more. In September 2024 the Department of Industry, Science and Resources published a proposals paper setting out ten mandatory guardrails for AI in high-risk settings, covering testing, transparency and accountability for developers and deployers. In December 2025 the National AI Plan shelved them, opting instead to rely on existing technology-neutral law, voluntary guidance folded into six essential practices, and a new AI Safety Institute. The practical answer available to Amanda Bowler is therefore the Age Discrimination Act 2004 and state anti-discrimination statutes, which she would have to invoke on the basis of no information whatsoever about what happened to her application.

One genuinely enforceable Australian obligation is coming. From 10 December 2026, under amendments made by the Privacy and Other Legislation Amendment Act 2024, entities subject to the Australian Privacy Principles that use personal information in automated decisions capable of significantly affecting a person's rights or interests must disclose in their privacy policy the kinds of information used and the kinds of decisions made, with the Office of the Australian Information Commissioner able to enforce. That is real, and it is worth having. It is also a paragraph in a document nobody reads, published by the organisation, containing no information about any individual decision. It tells Bowler that a category of thing happened to a category of person. It does not tell her what happened to her.

There is a reason this reticence should alarm Australians more than most. Between 2015 and 2019 the Commonwealth ran an automated debt recovery scheme against welfare recipients using crude income averaging. Robodebt was unlawful, produced enormous error rates, and a Royal Commission reported on it in 2023 with 57 recommendations. The financial reckoning continues: on 4 September 2025 the government agreed to pay a further 475 million dollars to settle the appeal in Knox v The Commonwealth, approved by the Federal Court on 23 June 2026, on top of the earlier Prygodicz settlement, bringing total redress past 2.4 billion dollars. Australia has already run the experiment of automating a high-stakes determination about people's lives at national scale and discovering the error rate afterwards, from the wreckage. Having paid that bill, in money and in lives, its response to the automation of hiring is a set of voluntary practices.

What a Right to a Human Decision Would Actually Have to Contain

The phrase a right to a human decision is currently doing rhetorical work and no operational work. It is worth spelling out, because vaguely stated it will be satisfied by a rubber stamp, and the SCHUFA reasoning already tells us a rubber stamp does not count. In that case, decided by the Court of Justice of the European Union in December 2023, the score the credit agency produced was itself held to be the decision in law, because the German bank relying on it did no more than follow the output. Where the nominal decision-maker adds nothing, the machine's output is the decision.

Six things would make it real, and the first principle underlying all of them is that a review conducted by someone with no practical capacity to overturn the outcome is not a review at all.

Disclosure has to happen at the point of application, not in a privacy policy. Before submitting, the applicant should see plainly that the application will be machine-scored, and what the system is assessing. This costs nothing and changes behaviour immediately, because a candidate who knows can decide whether the role is worth two hours of their life. It is also the reform with the clearest measured demand behind it and the widest gap between that demand and current practice. Of the jobseekers Greenhouse surveyed in 2026 who had been interviewed by an AI, 70 per cent were never told plainly beforehand that a machine would be assessing them, and for 21 per cent the fact only surfaced once the interview had started. Fifty-seven per cent think disclosure ought to be a legal requirement. This is not a protection that has to be explained to the people it protects.

Rejections issued without human involvement must be reversible on request. Not appealable in principle, reversible in practice, by a named person with authority to overturn, within a fixed window. The thirty-second rejection that jobseekers describe as soul-destroying is not painful because it is fast. It is painful because its speed is a disclosure: it tells the applicant that nothing was considered. A reversal route converts the machine's output from a verdict into a triage recommendation, which is what it always should have been. Here too the appetite is documented rather than assumed: 46 per cent of jobseekers want a human interview available as an alternative, and 38 per cent want a human being to look at the outcome before the decision is taken.

Employers should be required to sample. A fixed minimum percentage of machine-rejected applications, chosen at random, read by a human being, with the pass-through rate published. This is the single most valuable intervention available, because it generates a continuous audit of the model's false negatives at the employer's own expense and makes those false negatives visible for the first time. On a role attracting 500 applications, a 5 per cent sample is 25 CVs. That is one morning. Any organisation arguing it cannot afford a morning is telling you the vacancy was not worth filling.

Reasons must be given, and a score is not a reason. A short statement of which requirement was assessed as unmet is sufficient, and it is the difference between a decision and an event.

Auto-rejection rates should be published by age band, and by other protected characteristics where the data exists. Employers already collect this information for equal opportunity reporting. The reason it is not published broken down by automated stage is that nobody has asked.

And verification should be portable. If the labour market now requires proof that an applicant is a real human with the credentials claimed, that proof should be established once, held by the candidate, and presented on demand, rather than repeatedly extracted by every employer and every vendor at the candidate's cost.

It is worth saying plainly that none of this is charity. Thirty-eight per cent of jobseekers have already walked out of a hiring process because it involved an AI interview, and a further 12 per cent say they would. That is half the candidate pool either gone or standing at the door with a hand on the frame, and it is a cost borne by the employer, in the form of the applicants it never gets to see. Only 21 per cent believe most employers are deploying these systems responsibly. Yet only 19 per cent want less AI in hiring overall, and those two findings sitting side by side are the most useful thing in the whole survey. Candidates are not objecting to the machine. They are objecting to the machine being unaccountable, and they are quite capable of telling the difference. An employer that discloses, offers a human alternative and reverses on request is not making a concession to sentiment. It is recovering the third of its applicant pool that the rest of the industry is currently losing before the first question is asked.

None of this is radical, and none of it requires banning anything. It requires accepting a principle that every other consequential decision-making system in a developed economy already accepts: that a decision affecting someone's livelihood must have an author who can be identified and asked.

The Author of the Decision

So, to the questions this began with.

What does it mean when the most pivotal process in a working life is conducted between two artificial intelligence systems exchanging notes about a person's qualifications with no human ever reading the application? It means the decision has no author. Consider the comparison. If a bank refuses Bowler a loan, there is a decision-maker, a reason and a complaints process. If a government agency refuses her a payment, there is a delegate, a statement of reasons and a tribunal. If a university refuses her a place, there is an admissions officer and an appeal. Employment, which determines her income, her housing, her health, her standing and most of her waking hours, has quietly become the largest category of consequential decisions about human beings in a modern economy that has no such person anywhere in it. Not a person who decided wrongly. No person at all.

And what happens to the relationship between employer and employee when the first impression is made by an algorithm that can end a career in thirty seconds? An employment relationship is a structure of mutual obligation that begins in an act of assessment, and the character of that first act sets the terms of everything after it. When the opening move is made by a system neither party controls, that the employer cannot explain and the candidate cannot see, the relationship begins in bad faith on both sides, and the numbers show both sides already know it. Seventy per cent of hiring managers trust the machine. Eight per cent of candidates think it is fair. Forty-one per cent are willing to say out loud that they would sabotage it. That is not a labour market clearing. It is two populations, each correctly convinced the other is not really present, transacting through proxies neither of them chose.

The literature on what this does to the people caught in it is not ambiguous. The systematic review by Tom Sterud, Lars-Kristian Lunde, Rigmor Berg, Karin Proper and Fiona Aanesen, published in Occupational and Environmental Medicine in 2025 and pooling 38 prospective longitudinal studies, found a relative risk of mental health problems among unemployed people of 1.95 compared with the employed, and a relative risk of 0.66 after re-employment. Unemployment damages people and work repairs them, reliably, in both directions. Every unnecessary month a qualified person spends outside work because a ranking model scored their history as unusual is a month of measurable harm, imposed by a process nobody signed.

Amanda Bowler is not owed a job. Fifty applications do not entitle anyone to fifty interviews, and there are more psychology graduates than there are psychology posts. What she is owed, and what the entire apparatus described here has been engineered to avoid providing, is far smaller and far more fundamental than a job.

She is owed a reader.

Sources and References

  1. Bhattacharya, A. and Verbert, K. (2025). “Let's Get You Hired: A Job Seeker's Perspective on Multi-Agent Recruitment Systems for Explaining Hiring Decisions.” arXiv:2505.20312. https://arxiv.org/abs/2505.20312
  2. Sakib, M. N., Rayasam, N. M. and Dey, S. (2026). “Expecting Too Much, Getting Too Little: Exploring the Challenges and Design Opportunities of Asynchronous AI Interviewers.” arXiv:2601.02775. https://arxiv.org/abs/2601.02775
  3. Surati, S., Bellini, R. and Black, E. (2026). “Resume-ing Control: (Mis)Perceptions of Agency Around GenAI Use in Recruiting Workflows.” arXiv:2604.26851. https://arxiv.org/abs/2604.26851
  4. Zhang, M., Jia, Y., Tan, Z., Jiang, S., Gong, N. Z., Chen, T. and Song, D. (2026). “Measuring Real-World Prompt Injection Attacks in LLM-based Resume Screening.” USENIX Security Symposium 2026. arXiv:2605.28999. https://arxiv.org/abs/2605.28999
  5. Wilson, K. and Caliskan, A. (2024). “Gender, Race, and Intersectional Bias in Resume Screening via Language Model Retrieval.” Proceedings of the AAAI/ACM Conference on AI, Ethics, and Society. https://arxiv.org/abs/2407.20371
  6. Wright, L., Muenster, R. M., Vecchione, B., Qu, T., Cai, P., Smith, A., Metcalf, J. and Matias, J. N. (2024). “Null Compliance: NYC Local Law 144 and the Challenges of Algorithm Accountability.” Proceedings of the 2024 ACM Conference on Fairness, Accountability, and Transparency. https://arxiv.org/abs/2406.01399
  7. Spence, M. (1973). “Job Market Signaling.” The Quarterly Journal of Economics, 87(3), pp. 355-374. https://www.jstor.org/stable/1882010
  8. Sterud, T., Lunde, L.-K., Berg, R., Proper, K. I. and Aanesen, F. (2025). “Mental health effects of unemployment and re-employment: a systematic review and meta-analysis of longitudinal studies.” Occupational and Environmental Medicine. https://pmc.ncbi.nlm.nih.gov/articles/PMC12505101/
  9. Greenhouse (2025). “An AI Trust Crisis: 70% of Hiring Managers Trust AI to Make Faster and Better Hiring Decisions, Only 8% of Job Seekers Call it Fair,” 19 November (https://www.greenhouse.com/newsroom/an-ai-trust-crisis-70-of-hiring-managers-trust-ai-to-make-faster-and-better-hiring-decisions-only-8-of-job-seekers-call-it-fair); and “Greenhouse 2026 Candidate AI Interview Report,” 1 May 2026 (https://www.greenhouse.com/blog/2026-candidate-ai-interview-report)
  10. Gartner (2025). “Gartner Survey Shows Just 26% of Job Applicants Trust AI Will Fairly Evaluate Them,” 31 July. https://www.gartner.com/en/newsroom/press-releases/2025-07-31-gartner-survey-shows-just-26-percent-of-job-applicants-trust-ai-will-fairly-evaluate-them
  11. SEEK (2026). “SEEK Employment Report, July 2026,” 12 August. https://au.seek.com/about/news/article/seek-employment-report-july26
  12. Australian HR Institute and Australian Human Rights Commission (2025). “Employer biases against older and younger generations hindering Australian workforce productivity.” https://humanrights.gov.au/about-us/media-centre/search-listing-media-releases/employer-biases-against-older-and-younger-generations-hindering
  13. Fifth Quadrant and National Artificial Intelligence Centre (2025). “Australian Responsible AI Index 2025.” https://www.fifthquadrant.com.au/content/uploads/Australian-Responsible-AI-Index-2025_Full-report.pdf
  14. Salazar de Leon, L. and Rafi, M. (2026). “What everyone gets wrong about the modern job search, and what actually works,” The Conversation, 5 July. https://theconversation.com/what-everyone-gets-wrong-about-the-modern-job-search-and-what-actually-works-285582
  15. Civil Rights Litigation Clearinghouse (2026). “Mobley v. Workday, Inc., 3:23-cv-00770 (N.D. Cal.).” https://clearinghouse.net/case/44074/
  16. Callaham, S. (2026). “A Federal Judge, A 1967 Law And A Billion Rejected Job Applications,” Forbes, 29 May. https://www.forbes.com/sites/sheilacallaham/2026/05/29/a-federal-judge-a-1967-law-and-a-billion-rejected-job-applications/
  17. Office of the New York State Comptroller (2025). “Enforcement of Local Law 144: Automated Employment Decision Tools,” 2 December. https://www.osc.ny.gov/state-agencies/audits/2025/12/02/enforcement-local-law-144-automated-employment-decision-tools
  18. Ogletree Deakins (2026). “Illinois Steps Up AI Regulation in Employment: Key Takeaways for Employers.” https://ogletree.com/insights-resources/blog-posts/illinois-steps-up-ai-regulation-in-employment-key-takeaways-for-employers/
  19. European Union (2026). “Regulation (EU) 2024/1689 (Artificial Intelligence Act), consolidated text as amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI), in force 27 July 2026.” EUR-Lex. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:02024R1689-20260727
  20. Court of Justice of the European Union (2023). “Case C-634/21, SCHUFA Holding (Scoring), OQ v Land Hessen, judgment of 7 December 2023.” EUR-Lex. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0634
  21. Office of the Australian Information Commissioner (2026). “Consultation on Guidance for Transparency in Automated Decision Making.” https://www.oaic.gov.au/engage-with-us/consultations/consultation-on-guidance-for-transparency-in-automated-decision-making
  22. Montreal AI Ethics Institute (2026). “AI Policy Corner: From proposed mandatory guardrails to the National AI Plan, AI governance in Australia.” https://montrealethics.ai/ai-policy-corner-from-proposed-mandatory-guardrails-to-the-national-ai-plan-ai-governance-in-australia/
  23. Attorney-General's Department, Australian Government (2025). “Robodebt Class Action Appeal Settlement,” 4 September. https://ministers.ag.gov.au/media-centre/robodebt-class-action-appeal-settlement-04-09-2025
  24. Alex (2025). “We raised $20M to help AI hire more humans.” https://www.alex.com/blog/we-raised-20m-to-help-ai-hire-more-humans
  25. Sydney Morning Herald (2026). Report on the use of artificial intelligence in Australian recruitment, including the account of jobseeker Amanda Bowler, the remarks of a senior human resources leader on automated screening, and the predictions of Abhijay Arora Vuyyuru, 29 August. https://www.smh.com.au/

Tim Green

Tim Green UK-based Systems Theorist & Independent Technology Writer

Tim explores the intersections of artificial intelligence, decentralised cognition, and posthuman ethics. His work, published at smarterarticles.co.uk, challenges dominant narratives of technological progress while proposing interdisciplinary frameworks for collective intelligence and digital stewardship.

His writing has been featured on Ground News and shared by independent researchers across both academic and technological communities.

ORCID: 0009-0002-0156-9795 Email: tim@smarterarticles.co.uk

Listen to the free weekly SmarterArticles Podcast

Discuss...

The word was “usually”.

A fourth grader in New Mexico, reading aloud into a headset microphone, stumbled over it. She knew what “usually” meant. She used it in conversation. What she could not do, in that moment, was get from the letters on the screen to the sound in her head: the collapsed middle syllable, the way the “s” turns into a “zh”, the fact that the word looks nothing like it sounds. That is a decoding problem. It has a specific pedagogical answer, and the answer involves breaking the word into parts and mapping the parts to sounds.

Amira, the AI reading tutor listening on the other end, offered her a definition instead.

Wendy Graham, the girl's mother, is a high school history teacher in Las Cruces Public Schools and a former fifth grade teacher. She had first encountered the platform in a summer reading programme in 2025 and later used it at home. She watched the software identify a vocabulary gap where there was none and miss the decoding failure that was actually happening. Her son, offered the same purple-haired avatar, simply refused to engage with it at all.

“Kids don't do their best for robots,” Graham told the education outlet The 74 in an article published on 2 September 2026. “Kids do their best for people.”

It is the sort of line that could be dismissed as sentiment. Except that in the same week, three separate strands of rigorous quantitative evidence arrived at approximately the same conclusion by entirely different routes, and none of them involved sentiment at all. They involved randomised controlled trials, log files, and a great many children who, given free access to the most heavily capitalised educational technology in history, used it for about two minutes a week.

Two Minutes a Week

The most arresting number comes from Stanford University's National Student Support Accelerator, whose researchers ran two randomised controlled trials with elementary students in two American school districts serving high-poverty populations. The paper, “Access is Not Enough: Human Support Improves Engagement with AI Tutoring”, was written by Carly D. Robinson, David Gormley, Ana Trindade Ribeiro and Susanna Loeb, and released as an Annenberg Institute working paper in June 2026.

The design was straightforward. Students were given access to an AI literacy platform, with scheduled time in which to use it. They were expected to complete at least two 30-minute sessions per week. The platform's own provider states that academic benefits typically begin to appear after around 30 minutes of weekly use. Half the students used the platform on their own; the others had a human tutor sitting with them, whose job was explicitly not instruction but engagement, motivation and troubleshooting.

In the independent-use condition, only 60.7 per cent of students in District A and 53.3 per cent in District B ever used the platform at all. Not “used it well”. Ever. Logged in once, across an intervention that ran between 14 and 31 weeks.

Average weekly usage was 2.18 minutes in District A and 5.23 minutes in District B. Against a target of 60 minutes. The students who did use it managed 13.2 and 25.8 minutes in the weeks they used it, which tells you the average is not describing a population of light users but a population of near-total non-users punctuated by occasional bursts. On average, students touched the platform in only four to five weeks out of an intervention lasting up to thirty-one.

Adding a human being to the room helped, and the size of the help is instructive. Engagement rose by between 71 and 80 per cent, which sounds transformative until you notice that weekly usage went up by one minute in District A and 4.4 minutes in District B. Over the whole intervention, the human tutors bought less than two additional hours of platform time per student. Reading achievement did not move.

“A key finding that we weren't even meaning to test,” Robinson told Chalkbeat, “is that having access to this AI tutor isn't the same as using it.”

Loeb, the centre's executive director, put the institutional conclusion more bluntly: “We don't have solid research showing that AI tutoring can work in the U.S. at scale.”

There is a detail buried in the paper's appendix that deserves more attention than it has received. Among students left to use the platform independently, those who engaged with it were more likely to be higher achieving and less likely to receive special education services. The children who might have gained most from extra reading practice were the least likely to open the application. A technology sold as an equaliser produced, in the only two districts where anyone bothered to measure it properly, a ladder that the students at the bottom did not climb.

The Binding Constraint

The second study is larger, longer and, if anything, more damaging to the optimistic case, precisely because the product worked.

Philip Oreopoulos of the University of Toronto and Nina Low of Charles River Associates ran a two-year cluster randomised trial across 18 middle schools in Hamilton County, Tennessee, during the 2024-25 and 2025-26 school years. Students in existing daily remedial mathematics sessions were randomly assigned to Khan Academy with Khanmigo, the platform's generative AI tutor, configured to coach rather than hand over answers. The paper, “One Click Away: AI Tutoring with Khanmigo in a Two-Year School Experiment”, was published as NBER Working Paper 35620 in August 2026.

Assignment raised mathematics achievement by 1.3 national percentile ranks per term, roughly 0.06 to 0.08 standard deviations over a school year. The authors calculate that a full year of active participation would imply about 0.14 standard deviations. These gains, they note, resemble those from Khan Academy practice without any AI assistance at all.

Then comes the log-file archaeology, which is the real contribution. Ninety-six per cent of students tried Khanmigo at least once. The median student messaged it on only a third of the days they practised maths. And in the exercise sessions where a student actually made a mistake, the moment at which a tutor is theoretically most valuable, they consulted the AI in just 17 per cent of cases. The messages they did send were, in the authors' description, mostly bare answers or clicks on suggested prompts.

“Access was nearly universal,” the researchers wrote, “but engagement was thin.”

Their conclusion is the sentence the entire sector should be arguing about: “The binding constraint appears to be engagement: realizing the promise of AI tutoring will require getting students to use it, not just giving them access.”

Sal Khan had said as much himself, months before the paper landed. In April 2026 he told Chalkbeat that for a lot of students Khanmigo “was a non-event. They just didn't use it much.” Asked about the vision of an AI tutor permanently available in every classroom, he offered a four-word summary of the adoption curve: “Some will; most won't.” He added that while AI would help, “our biggest lever is really investing in the human systems.”

This is a founder describing the gap between his own 2023 TED talk, which promised a personal tutor for every child on Earth, and a log file showing that most children did not ask it anything.

The Strongest Version of the Optimistic Case

It would be lazy to stop here, because the optimistic case is not stupid and is not obviously wrong. It deserves to be built properly before it is tested.

Start with the economics. Human tutoring at high dosage is the best-evidenced intervention in education, and it is also ferociously expensive. The systematic review by Andre Nickow, Philip Oreopoulos and Vincent Quan pooled the experimental evidence on PreK-12 tutoring and reported an overall effect of 0.37 standard deviations, later revised to 0.29 in the version published in the American Educational Research Journal. Effects were strongest when tutors were teachers or paraprofessionals, in the earlier grades, and when the tutoring happened during the school day rather than after it. The Education Endowment Foundation's toolkit rates one-to-one tuition as worth up to five months of additional progress. Nobody disputes that tutoring works. The dispute has always been about whether anyone can afford enough of it.

An AI tutor has, in principle, a marginal cost approaching zero and infinite patience. It never has a bad morning. It is available at eleven at night, in a language the parents may not speak, to a child whose school has three vacancies in its maths department. If it delivered even a fraction of the human effect at a hundredth of the price, the cost-effectiveness arithmetic would be overwhelming.

And there is real evidence that it can. A World Bank randomised trial in Edo State, Nigeria, gave secondary students six weeks of after-school GPT-4 tutoring, working in pairs under teacher supervision with prompts designed to promote reasoning rather than shortcuts. The programme produced gains of around 0.3 standard deviations overall and 0.23 on English, the primary outcome, at roughly 48 dollars per student. Benchmarked against a database of education interventions trialled in developing countries, it outperformed about 80 per cent of them.

There is also a longer history that the current discourse tends to forget. Intelligent tutoring systems are not new. Carnegie Learning's Cognitive Tutor descends from decades of cognitive science at Carnegie Mellon. ASSISTments, developed at Worcester Polytechnic Institute, was evaluated in a large randomised trial across 46 Maine schools and produced an effect of about 0.18 standard deviations on an end-of-year standardised maths test, with the largest benefits for students with the weakest prior attainment. Meta-analytic reviews of intelligent tutoring systems have reported average effects in the region of 0.37 to 0.50 standard deviations depending on the comparison condition. These are not nothing. Measured against the typical education intervention, they are respectable.

Khan Academy's own response to the Hamilton County trial makes a fair point along these lines. Writing in August 2026, Khan argued that the 0.14 standard deviation figure for sustained participants “is a genuinely strong result”, and that the study was not asking whether Khan Academy beats doing nothing. It was measuring Khan Academy against whatever digital maths programmes and small-group instruction the district was already running. That is a demanding comparison, and the platform did not lose it.

And then there is Stanford's own contrary finding, which is the most interesting card in the optimistic hand. The Tutor CoPilot trial, run by Rose E. Wang, Ana T. Ribeiro, Carly D. Robinson, Susanna Loeb and Dora Demszky, put a language model behind 900 human tutors working with 1,800 students from historically under-served communities, offering expert-like suggestions in real time. Students whose tutors had the tool were four percentage points more likely to master topics. For students of the lowest-rated tutors, the gain was nine percentage points. The cost was around 20 dollars per tutor per year.

So the honest steelman is this: the technology demonstrably can teach, it is astonishingly cheap, it has worked in at least one rigorous field trial in a low-income setting, and it makes human tutors measurably better when pointed at them rather than at children. Anyone who wants to argue that AI tutoring is snake oil has to explain all four of those facts.

Where the Case Comes Apart

It comes apart at the point where the model stops being the subject of the sentence and the child becomes it.

Notice the shape of the successful examples. In Nigeria, students worked in pairs, after school, under teacher supervision, with structured prompts. That is not an AI tutor. That is a small-group human intervention with a language model in the middle of it, and the trial cannot separate the contribution of the model from the contribution of the adult who showed up and the peer who sat alongside. Tutor CoPilot is even clearer: it does not tutor anyone. It whispers to a human tutor who is already in a relationship with the student. Every case where AI tutoring has produced strong results is a case where a person was in the room.

The Stanford literacy trials tested the other configuration, the one the marketing implies and the procurement documents assume, in which the child and the software are left alone together. That configuration produced 2.18 minutes a week.

This is the distinction the sector has spent three years refusing to make. There is an enormous difference between a system that can answer a question and a system a child will actually ask. Model capability has been improving on a steep curve. Willingness to seek help from a machine has not, because it was never a function of model capability in the first place.

Help-seeking is one of the most studied behaviours in educational psychology, and it is socially loaded in ways that a benchmark score cannot capture. Asking for help is an admission. Children weigh that admission against what it costs them: looking slow in front of peers, disappointing a teacher, confirming a private suspicion about themselves. The reason a good tutor is valuable is not that they possess the answer. It is that they have built enough trust that the admission feels safe, and enough familiarity to notice the confusion before the child has to declare it.

Khanmigo could not do the second thing at all, and the 17 per cent figure suggests it was not trusted enough to be given the first. A child who has just got a question wrong in a remedial maths class is at the precise emotional coordinates where a human tutor would lean in. The AI sat there, one click away, and was not clicked.

Why Children Work for People Who Will Notice

The Stanford result that most repays attention is not the two minutes. It is the fact that adding a human being who was explicitly forbidden from teaching still moved engagement by 71 to 80 per cent.

The tutors in those trials were not subject experts delivering instruction. In District B they were middle school students, selected because they did well in their own English classes and had a free period. Their job was to check in, keep students on task, sort out headphones and passwords, and talk to the children about what they were doing. They spent part of every session on relationship-building activities that reduced the time available for the platform. And they still produced the largest engagement effect anyone in these trials produced.

What those tutors supplied was relational accountability: the simple, unglamorous fact that somebody would notice. Somebody would know whether you logged in. Somebody would ask how the story went. Effort became legible to another person, and legible effort is the currency children have always worked for.

Software can simulate this. It cannot instantiate it. A notification saying “we missed you yesterday” is not a person missing you. Children, including very young ones, appear to be excellent at telling the difference. A first grader in New Mexico, quoted by her mother in reporting by NBC News, complained of the software that “she doesn't let me finish my sentences, she doesn't listen.” An Albuquerque parent reported her children saying that Amira was “like a new teacher but they don't actually understand me”, and that one of them no longer liked reading.

A study accepted to the Learning Analytics and Knowledge conference in 2026 sharpens the mechanism considerably. Conrad Borchers, Ashish Gurung, Qinyi Liu, Danielle R. Thomas, Mohammad Khalil and Kenneth R. Koedinger analysed nearly 2,100 hours of classroom practice by 191 middle schoolers on an intelligent tutoring system, tracking what happened when a human tutor physically visited a student during their work. Engagement rose during the visit and stayed elevated afterwards. The returns diminished with visit length, and timing mattered more than duration. Interactions built on concrete, stepwise scaffolding with explicit organisation of the student's work were the most effective. Their recommendation for resource-constrained settings is deflating in its modesty: several brief, well-timed check-ins, including at least one early.

Brief. Well-timed. Human. The paper is, among other things, a costing exercise for the thing AI tutoring was supposed to make unnecessary, and the answer is that it is cheaper than anyone assumed. Not free, though. Never free.

The Word She Could Not Decode

Return to “usually”, because the failure it exposes is technical as well as relational, and the technical version is the one that will not be fixed by better prompting.

Amira works by listening. Students read passages aloud into a microphone; automatic speech recognition compares what it hears to what it expects; when a word goes wrong, the system intervenes, sometimes with a video of a mouth enunciating the correct pronunciation. It is a genuinely clever pipeline and it does something no human tutor can do at scale, which is give every child in a class simultaneous individual reading practice with immediate feedback.

But consider what the signal actually contains. A child hesitates on “usually”. From the acoustic evidence alone, that hesitation is consistent with at least four distinct conditions: she does not know the word; she knows the word but cannot decode the orthography; she can decode it but is reading too slowly to hold the sentence in working memory; or the microphone picked up the child at the next desk. These require four different responses. Defining the word helps only in the first case. In Graham's daughter's case it was the second, and the software chose the first.

The wider evidence suggests this is not an isolated misfire. Reporting by the Albuquerque Journal in April 2026 documented teachers describing month-to-month swings of 20 to 30 percentile points in individual students' Amira scores, which a teaching coach characterised as statistically abnormal. A kindergarten teacher noted that the system “is not always great at picking up the language of students” with spoken language difficulties. Classroom background noise contaminates results. A special education teacher described students groaning and crying on assessment days.

New Mexico requires Amira statewide for kindergarten through second grade, at a cost of around 2.7 million dollars a year, with assessments three times annually and monthly for children reading below expectations. Idaho requires it too; California, Georgia, Massachusetts, Michigan, Oklahoma and Texas have authorised it. In a Reason report published on 2 September 2026, only 8 per cent of surveyed New Mexico teachers and administrators said they had no major concerns about it, though the poll was run by the state education department at one of its own training sessions, and the department has said it was not representative. Amira's chief executive, Mark Angel, has defended the evidence base robustly, saying that “no other scalable instructional intervention has been interrogated as many times, by as many independent teams, with this consistency of positive impact.”

Both things can be true. The efficacy studies can show real reading gains under conditions of proper use, and the deployment can still be systematically misdiagnosing children whose accents, dialects, speech differences or classroom acoustics fall outside the model's comfortable centre. The children most likely to be misread by a speech recognition system are, with grim predictability, the same children the system was funded to help.

The requirement did not survive the summer intact. Parents showed up en masse at school board meetings across the state, worried less about pedagogy than about where the recordings of their children's voices were going. Six districts and charters declined to use the software at all on privacy grounds: Santa Fe, Los Alamos, Farmington, Roswell, Clayton and Turquoise Trail Charter School, with the exemptions running only for that school year. On 4 August 2026, days before the new term began, the Public Education Department issued revised guidance signed by Secretary Mariana Padilla, permitting districts to run Amira without the voice-recording feature, to administer a paper-based test instead, or to use an assessment programme of their own. Voice recordings delete monthly by default, and districts may now request daily, weekly or end-of-year deletion. The department held its ground on the principle, arguing that “a common statewide assessment provides a shared measure that supports consistency, transparency, accountability and equitable decision making”. Amira remains the statewide requirement. It is simply no longer in every public school.

Albuquerque Public Schools, the largest district in the state, resolved on 26 August 2026 to keep the programme with concessions: voice recordings dropped from the tutoring component, a 48-hour deletion window on the testing feature, and paper-and-pencil alternatives for parents who opt out. Deputy Superintendent Randy Mahlerwein explained the 48 hours as a compromise, the testing data being deleted on that cycle “so teachers have a chance to listen to the recordings”. Representative Linda Serrato, who led more than thirty legislators in a letter demanding oversight, put the stake plainly: “You're talking about the biometric data of children 5 to 8 years old. That's valuable stuff, and we know it, but we have to treat it as such.” Angel, for his part, has said the company would rather not hold the material at all. “We don't want to collect this data; it's a nuisance,” he said. “If the Legislature or PED tells us to stop collecting the data, we will stop instantaneously.”

It is worth being precise about what moved and what did not. No new efficacy finding prompted any of this. The evidence base sat in August exactly where it had sat in April. What changed was that parents turned up, districts refused and legislators wrote letters, which is to say that the correction to an automated system arrived by way of people paying close attention to particular children, which is the one resource the technology had been sold as a substitute for.

Who Bears the Risk

None of this is priced into the way districts buy.

Educational technology is sold on licences, not on usage. A district commits to a per-student annual fee, the vendor books the revenue, and whether the child logs in is somebody else's problem. This is not a new pathology. Analyses by LearnPlatform, before the generative AI wave, found that roughly a quarter to a third of purchased edtech licences were never activated at all, and that intensive use, defined as ten or more hours per product between assessments, applied to about two per cent of licences. Estimates put over a billion dollars of American K-12 licensing spend into the category of pure waste each year.

What the Stanford and Hamilton County trials show is that the generative AI generation of products has inherited this structure and, so far, has not improved on it. A district that timetables two 30-minute sessions a week, and receives 2.18 minutes, is paying roughly 27 times the advertised unit cost of the intervention it thinks it bought. Nobody's contract says that.

The public spending is not trivial and is increasingly visible. New Mexico spends 2.7 million dollars a year on Amira. Iowa committed 3 million dollars in 2024 with a further 2.5 million after. Louisiana authorised 3.6 million plus another million. Duval County Public Schools in Florida structured its purchase differently. Its 2024 contract, worth 100,000 dollars and covering roughly 2,600 students in grades two through four who were reading below grade level, tied half the fee to student progress. More than 1,200 of them met their oral reading fluency goals, exceeding what the contract had been written to expect, which is either a decent result or an expensive coin flip depending on your counterfactual, except that the district was only paying in full for the half that landed. North Carolina, notably, cut its Khanmigo funding from 10 million dollars to 500,000.

The American education secretary, Linda McMahon, has acknowledged that there are not “a lot of metrics” for judging AI's classroom value, and asked the obvious question: “Are we seeing better outcomes in schools? And if we're not, then they should be pulled out.”

The public appears to be well ahead of the procurement offices. A Century Foundation survey, conducted by Morning Consult among more than 2,000 registered voters in May 2026, found 84 per cent concerned about private companies collecting and profiting from student data, and 81 per cent concerned that teachers are being pressured to use AI tools without proven pedagogical benefit. Seventy-seven per cent wanted government guardrails, a figure that held across party lines. Forty-nine per cent said classroom technology and AI should be kept to a minimum. This is not a technophobic fringe. It is a settled majority, expressing a preference that the market has so far been structured to ignore.

The Ghost of Two Sigma

Underneath every AI tutoring pitch of the last three years sits a single number that almost nobody quoting it has checked.

In 1984, Benjamin Bloom published a paper in Educational Researcher reporting that students taught one-to-one with mastery learning outperformed conventionally taught students by two standard deviations, placing the average tutored student above 98 per cent of the control class. He framed it as a challenge: find a group method that achieves what tutoring achieves. The “2 sigma problem” became the founding scripture of educational technology, and generative AI inherited it wholesale. Every promise of a personal tutor for every child is a promise to close Bloom's gap with software.

The number has never been replicated. Bloom's finding rested on two doctoral dissertations by his own students, conducted with small samples, short durations and researcher-designed outcome measures. A 1982 meta-analysis by Peter Cohen, James Kulik and Chen-Lin Kulik had already put the average tutoring effect at around 0.33 standard deviations. The Nickow, Oreopoulos and Quan review found nothing approaching two sigma anywhere in the experimental literature; its pooled estimate sat between 0.29 and 0.37 depending on the specification. Matthew Kraft of Brown University has argued that Bloom's number helped anchor the field to expectations of effect sizes that essentially never occur, noting that most education interventions produce effects of 0.1 standard deviations or less.

Seen against that corrected baseline, the Hamilton County result of 0.06 to 0.08 standard deviations a year, rising to 0.14 for sustained participation, is not humiliating. It is an ordinary education intervention performing ordinarily. The humiliation is entirely a function of what was promised.

England's National Tutoring Programme offers a parallel worth sitting with. Launched with substantial funding to address pandemic learning loss, its independent evaluation found no evidence that the Tuition Partners route improved Key Stage 2 or Key Stage 4 outcomes in English or maths, while school-led tutoring produced small gains equivalent to about a month's progress. The intervention with the best evidence base in education, delivered at national scale under time pressure, largely failed to reproduce its own effect. Yet 81 per cent of school leads surveyed felt the programme had helped pupils catch up. The gap between what practitioners perceive and what the data records is not unique to AI. It is what scale does to interventions, and it should temper any assumption that AI tutoring's problems are peculiar to AI.

Beyond the Test Score

There is a further argument, and it cuts against the entire framing of the debate.

A paper submitted in February 2026 by Lucile Favero, Juan Antonio Pérez-Ortiz, Tanja Käser and Nuria Oliver argues that assessing educational AI purely on learning outcomes misses most of what matters. Their framework identifies four interlocking dimensions: cognitive offloading, diminished learner agency, emotional disengagement and surveillance-oriented practice. Their central claim is that these reinforce one another, and that the compound effect operates on critical thinking and civic participation rather than on test scores. They are careful not to be deterministic about it. Well-designed systems, they argue, can support reasoning and autonomy while preserving meaningful human interaction. The question is not whether AI belongs in education but how institutions deploy it.

Apply that lens to the current evidence and something uncomfortable emerges. The thin engagement documented in Tennessee and California and New Mexico is being read as a failure. On the Favero framework, it might be partial protection. A child who does not offload her thinking to a chatbot is not being harmed by the chatbot. The Hamilton County students who sent bare answers and clicked suggested prompts were exhibiting exactly the answer-seeking behaviour that worries cognitive scientists, and they were doing it at low volume.

Which raises a genuinely difficult question. If engagement rose to the 30 minutes a week the vendors recommend, would attainment rise with it, or would we simply have more children more efficiently outsourcing the cognitive work that constitutes learning? Nobody knows. The trials that would tell us have not been run, because the dosage required to run them has never been achieved. Robinson's team put this with admirable candour: they never reached sufficient use to determine whether the tool works at all.

What an Honest Evidence Standard Would Require

The gap between promise and delivery is not going to be closed by better models, because the constraint was never the model. It might be narrowed by changing what districts are allowed to buy and what vendors are required to show.

Four changes would do most of the work. First, effectiveness claims should be stated as a function of dosage and reported alongside observed dosage in real deployments. A product whose efficacy study assumed 30 minutes a week should have to publish what its actual median user does, by district, annually. Second, contracts should tie payment to usage rather than to seats, which would move the risk of non-engagement from the public purse to the party that can actually design against it. Duval County has already written half a contract that way, so this is a reform with a working example rather than a thought experiment. Third, trials should be pre-registered and report the null. The Stanford literacy paper is a model here precisely because its headline finding is a failure to establish anything about the technology. Fourth, deployment equity should be a reported metric, not an afterthought. If the students least likely to open the application are the ones with special educational needs and the lowest prior attainment, a district needs to know that in month two, not from a working paper appendix two years later.

None of this is exotic. It is roughly the standard that a medicines regulator would consider a baseline, and roughly the standard the Education Endowment Foundation has spent fifteen years trying to establish in England, where the evidence for one-to-one tuition is rated as moderately secure on the basis of 123 studies. The reason it feels exotic in educational technology is that educational technology has never had to meet it.

The Girl and the Avatar

The child stumbling over “usually” is the whole argument compressed into a single second of audio.

What she needed was for somebody to notice the specific shape of her confusion: not that she lacked the word but that she could not get through the spelling to reach it. Noticing is not a capability that scales with parameters. It requires attention that is directed at a particular person, sustained over time, and, crucially, that the person knows is being directed at them. That last part is what produces the effort. Children do not work hard because a system is watching. They work hard because someone who matters to them will see.

The two-minute lesson is not a story about bad software. Amira and Khanmigo are, by any reasonable technical standard, impressive artefacts, and the studies suggest that when children use them properly they produce ordinary, real, modest gains of the kind that education research has always found. The story is about a category error that ran through an entire procurement cycle: the assumption that the scarce resource in education was instruction, when the scarce resource was always attention, and attention is the one thing that has never been possible to manufacture at zero marginal cost.

Stanford's tutors, forbidden from teaching, moved the numbers more than the AI did. That is the finding. It has been available, in one form or another, since Bloom, and it survived the arrival of a technology that was supposed to make it obsolete. A district that spends its money on the thing that produced 71 to 80 per cent more engagement rather than on the thing that produced 2.18 minutes a week is not being nostalgic. It is reading the evidence.

Whether anyone is buying on the evidence is a separate question, and on current form the answer looks like a non-event.

Sources and References

  1. Carly D. Robinson, David Gormley, Ana Trindade Ribeiro and Susanna Loeb, “Access is Not Enough: Human Support Improves Engagement with AI Tutoring”, EdWorkingPaper No. 26-1451, Annenberg Institute at Brown University, June 2026. https://edworkingpapers.com/ai26-1451
  2. Chalkbeat, “Does AI tutoring work? Students would have to use it for researchers to find out”, Chalkbeat, 17 June 2026. https://www.chalkbeat.org/2026/06/17/ai-tutoring-research-ran-into-problem-students-wouldnt-use-it/
  3. Philip Oreopoulos and Nina Low, “One Click Away: AI Tutoring with Khanmigo in a Two-Year School Experiment”, NBER Working Paper 35620, August 2026. https://www.nber.org/papers/w35620
  4. Matt Barnum, “Students rarely engaged with Khan Academy's AI-powered tutor Khanmigo, study finds”, Chalkbeat, 25 August 2026. https://www.chalkbeat.org/2026/08/25/ai-tutoring-students-khanmigo-khan-academy-engagement-study/
  5. Matt Barnum, “Why Sal Khan is rethinking how AI will change schools”, Chalkbeat, 9 April 2026. https://www.chalkbeat.org/2026/04/09/sal-khan-reflects-on-ai-in-schools-and-khanmigo/
  6. Sal Khan, “What I found compelling in a new randomized trial of Khan Academy in math intervention”, Khan Academy Blog, 24 August 2026. https://blog.khanacademy.org/what-i-found-compelling-in-a-new-randomized-trial-of-khan-academy-in-math-intervention/
  7. Linda Jacobson, “AI Tutors Not Yet a Replacement for Humans, Research Says”, The 74, 2 September 2026. https://www.the74million.org/article/ai-tutors-not-yet-a-replacement-for-humans-research-says/
  8. The Century Foundation, “Americans Are United Against the Tech Takeover of Public Schools”, 2026. https://tcf.org/content/report/americans-are-united-against-the-tech-takeover-of-public-schools/
  9. Ed Finkel, “Voters express broad concerns about AI and tech in schools, survey shows”, K-12 Dive, 2 September 2026. https://www.k12dive.com/news/voters-express-broad-concerns-about-ai-and-tech-in-schools-survey-shows/829351/
  10. Conrad Borchers, Ashish Gurung, Qinyi Liu, Danielle R. Thomas, Mohammad Khalil and Kenneth R. Koedinger, “Brief but Impactful: How Human Tutoring Interactions Shape Engagement in Online Learning”, arXiv:2601.09994, 15 January 2026. https://arxiv.org/abs/2601.09994
  11. Lucile Favero, Juan Antonio Pérez-Ortiz, Tanja Käser and Nuria Oliver, “AI in Education Beyond Learning Outcomes: Cognition, Agency, Emotion, and Ethics”, arXiv:2602.04598, 4 February 2026. https://arxiv.org/abs/2602.04598
  12. Rose E. Wang, Ana T. Ribeiro, Carly D. Robinson, Susanna Loeb and Dora Demszky, “Tutor CoPilot: A Human-AI Approach for Scaling Real-Time Expertise”, arXiv:2410.03017, October 2024. https://arxiv.org/abs/2410.03017
  13. Andre Nickow, Philip Oreopoulos and Vincent Quan, “The Impressive Effects of Tutoring on PreK-12 Learning: A Systematic Review and Meta-Analysis of the Experimental Evidence”, NBER Working Paper 27476, July 2020; published in revised form in the American Educational Research Journal, 2024. https://www.nber.org/papers/w27476
  14. Paul T. von Hippel, “Two-Sigma Tutoring: Separating Science Fiction from Science Fact”, Education Next, vol. 24, no. 2, Spring 2024. https://www.educationnext.org/two-sigma-tutoring-separating-science-fiction-from-science-fact/
  15. Education Endowment Foundation, “One to one tuition”, Teaching and Learning Toolkit. https://educationendowmentfoundation.org.uk/education-evidence/teaching-learning-toolkit/one-to-one-tuition
  16. Education Endowment Foundation, “Independent evaluation of the National Tutoring Programme”. https://educationendowmentfoundation.org.uk/news/new-independent-evaluation-of-the-national-tutoring-programme-ntp
  17. Wenting Ma, Olusola O. Adesope, John C. Nesbit and Qing Liu, “Intelligent Tutoring Systems and Learning Outcomes: A Meta-Analysis”, Journal of Educational Psychology, November 2014. https://www.apa.org/pubs/journals/features/edu-a0037123.pdf
  18. Social Programs That Work, “ASSISTments”, Arnold Ventures. https://evidencebasedprograms.org/programs/assistments/
  19. EdWeek Market Brief, “More Than $1 Billion in K-12 Ed-Tech Licensing Fees Go to Waste”, November 2019. https://marketbrief.edweek.org/education-market/more-than-1-billion-in-k-12-ed-tech-licensing-fees-go-to-waste/2019/11
  20. Tyler Kingkade, “Meet Amira, an AI reading tutor alarming some parents and school leaders in New Mexico”, NBC News, 7 August 2026. https://www.nbcnews.com/news/education/ai-reading-tool-amira-new-mexico-parents-schools-privacy-concerns-rcna591161
  21. Elizabeth Nolan Brown, “Invasion of the Robot Teachers”, Reason, 2 September 2026. https://reason.com/2026/09/02/invasion-of-the-robot-teachers/
  22. Natalie Robbins, “New Mexico schools use Amira AI reading assessments amid accuracy and equity concerns”, Albuquerque Journal, 26 April 2026. https://www.abqjournal.com/news/students-read-aloud-ai-scores-them/3029121
  23. Natalie Robbins, “New Mexico eases rules for AI reading test amid privacy concerns”, Albuquerque Journal, 10 August 2026. https://www.abqjournal.com/news/amid-privacy-concerns-new-mexico-eases-rules-for-ai-reading-test/3099834
  24. “Amid parent backlash, APS keeps AI reading program with changes”, Albuquerque Journal, 26 August 2026. https://www.abqjournal.com/news/amid-parent-backlash-aps-keeps-ai-reading-program-with-changes/3110194
  25. CNN, “Education Secretary McMahon says AI can be a 'very effective tool' in schools”, State of the Union, 23 August 2026. https://www.cnn.com/2026/08/23/politics/video/mcmahon-ai-in-schools-sotu

Tim Green

Tim Green UK-based Systems Theorist & Independent Technology Writer

Tim explores the intersections of artificial intelligence, decentralised cognition, and posthuman ethics. His work, published at smarterarticles.co.uk, challenges dominant narratives of technological progress while proposing interdisciplinary frameworks for collective intelligence and digital stewardship.

His writing has been featured on Ground News and shared by independent researchers across both academic and technological communities.

ORCID: 0009-0002-0156-9795 Email: tim@smarterarticles.co.uk

Listen to the free weekly SmarterArticles Podcast

Discuss...

Sixteen licensed physicians sat down with 888 chatbot answers and marked them up. The questions had been written to sound like the ones real patients ask, 222 of them, spanning internal medicine, women's health and paediatrics, the sort of thing you type at midnight when something hurts and the surgery is shut. Four systems answered: Claude, Gemini, GPT-4o and Llama.

The results appeared in npj Digital Medicine on 13 February 2026, led by Rachel Draelos with clinicians from Brigham and Women's Hospital, Emory, UC San Francisco and a dozen other hospitals. Claude came out best, with 21.6 per cent of answers rated problematic and 5 per cent outright unsafe. Llama was worst on problematic responses at 43.2 per cent. GPT-4o, the model most people were using, produced unsafe answers 13.5 per cent of the time. The authors did not hedge: millions of patients could be receiving unsafe medical advice from publicly available chatbots.

Six months later, on 20 August 2026, the same journal published something broader. A team including Alexander Diel, John Torous and Pim Cuijpers searched five databases, pulled 3,137 candidate papers, and narrowed to 119 addressing the mental health harms of large language model chatbots. They catalogued 22 distinct types of harm across five categories. Then, in the section that ought to be read aloud at every product launch, they conceded how little is established. The conceptual work on harms, they wrote, remains speculative. For hallucination, bias and sycophancy alike, the occurrence rate and the impact on users remain unclear.

That is the shape of the field in 2026. A thickening literature on what could go wrong, a thin one showing what goes right, and almost nothing telling us how often either happens in the wild. Into that gap has walked a number that became a slogan.

Where the Sixteen Per Cent Actually Comes From

The figure everyone quotes is that only 16 per cent of large language model chatbot interventions have undergone rigorous clinical efficacy testing. It opens a preprint posted to arXiv on 25 April 2026 by Suhas BN, Andrew M. Sherrill, Rosa I. Arriaga, Chris W. Wiese and Saeed Abdullah, titled “AI Safety Training Can be Clinically Harmful”. But the 16 per cent is not theirs. It is a citation, and following it home produces something narrower and more damning than the slogan.

The source is a systematic review by Yining Hua, Steve Siddals, John Torous and colleagues, published in World Psychiatry in 2025. They examined 160 studies of mental health chatbots from 2020 to 2024 and applied a three-tier ladder: bench testing, which asks whether the thing works technically; pilot feasibility testing, which asks whether people will use it; and clinical efficacy testing, which asks whether symptoms actually improve.

The trend line is the story. Rule-based systems dominated until 2023. By 2024, large language model chatbots accounted for 45 per cent of new studies, and of those only 16 per cent had reached the efficacy rung, with 77 per cent stuck in early validation. Across the whole corpus, including the older rule-based systems, 47 per cent had done efficacy testing. The newer, more fluent, more widely deployed generation is the less validated one by a factor of roughly three.

So the precise claim is that 16 per cent of published studies involved efficacy testing. That is not the same as saying 16 per cent of the interventions people encounter have been tested, and the slippage matters, because the real figure is almost certainly worse. Hua and colleagues reviewed the academic literature, which is where the tested things live. Commercial products in an app store, and the general-purpose assistants most people confide in, do not appear in that denominator at all. Sixteen per cent is not the ceiling of the evidence problem. It is a generous reading of it.

The Honest Case for the Machine at Three in the Morning

Any argument that ignores why people reach for these things is not worth making, so let us make the other one properly. The World Health Organization reported in September 2025 that more than a billion people are living with a mental health condition. The global median mental health workforce is 13 workers per 100,000 people. High-income countries spend up to 65 US dollars a head per year; low-income countries spend as little as four cents, and fewer than one in ten of their citizens with depression or anxiety receive any care at all, against more than half in wealthier ones. Against that, a free chatbot answering instantly at four in the morning is not an absurd proposition but an obvious one.

It is worth resisting the easy British version of the argument, because the data undercuts it. NHS Talking Therapies is a favourite prop for AI advocates, yet according to NHS England's June 2026 statistics the median service starts treatment 21 days after referral, and England meets both national standards: 75 per cent seen within six weeks, 95 per cent within eighteen. The access crisis sits elsewhere, in children's services, in severe and enduring illness, and above all in the countries spending four cents a head.

And there is evidence that chatbots can help. The most rigorous demonstration remains the Dartmouth trial of Therabot, published in NEJM AI on 27 March 2025 by Michael V. Heinz, Nicholas C. Jacobson and colleagues. It randomised 210 adults with clinically significant symptoms of depression, generalised anxiety or high risk for a feeding or eating disorder to four weeks of Therabot or a waitlist. The intervention group showed roughly 51 per cent symptom reduction for depression, 31 per cent for anxiety and 19 per cent for eating disorder concerns, and reported a therapeutic alliance with the software comparable to what people report with human clinicians.

A broader synthesis landed on 25 March 2026, when npj Digital Medicine published a meta-analysis by Jun-Seok Sohn and colleagues covering 39 randomised trials. Across 38 trials and 7,401 participants, chatbots produced a statistically significant reduction in depressive symptoms, with a standardised effect size of 0.31, strongest in clinical and subclinical populations. Across 34 trials and 7,621 participants, anxiety improved with an effect of 0.28. That is a real signal, and it should not be waved away.

What the Randomised Evidence Will and Will Not Support

It should also not be oversold, and the researchers are noticeably more careful about that than the people who cite them. Take Therabot. Four weeks is short, and the comparator was a waitlist, the weakest control in the psychotherapy toolkit, because it captures not just the treatment effect but the effect of expectation, of attention, and of being enrolled in something at all. The sample sat inside a supervised research protocol, monitored by clinicians who could intervene. And Therabot is not a product; it is a research prototype the public cannot download. The trial shows a supervised system can help selected adults over a month. It does not show that the thing on your phone will.

The meta-analysis carries its own caveats, stated plainly by its authors. Effect sizes of 0.31 and 0.28 are small. Thirty-five of the 39 trials carried a high risk of bias, principally because blinding is nearly impossible when the intervention is a conversation. Outcomes leaned on self-report rather than clinician assessment, a problem when the intervention is a machine engineered to make you feel better about yourself in the moment you are asked. The depression analysis showed publication bias, meaning the null results are sitting in a drawer.

Then there is duration. The preprint that popularised the 16 per cent figure also flags a 2024 study by Zhong and colleagues finding that at three-month follow-up, no substantial effects were detected for depression or anxiety. Short-term improvement is real and worth something. It is not durable benefit, and it says nothing about somebody who talks to a chatbot every day for two years. There is no longitudinal evidence base on sustained use, and not even a cohort being followed.

A third npj Digital Medicine review, published on 23 July 2026 by Lotenna Olisaeloka, Daniel V. Vigo and colleagues, examined 21 studies across 11 countries. It found moderate-to-high usability, therapeutic alliance and satisfaction; users valued convenience, personalisation and perceived empathy. That is exactly the accessible, personal, empathetic experience people describe. The same review found engagement declined over time, trust collapsed after inaccurate outputs, and the field suffers from a lack of efficacy trials and insufficient safety assessment. Liking is not benefiting, and we have measured the first far more thoroughly than the second.

Efficacy Testing and Safety Testing Are Not the Same Examination

There is a conflation buried in the phrase “clinically tested” that deserves pulling apart. Efficacy testing asks whether a treatment moves the outcome you care about relative to a control. Safety testing asks whether it produces harm, including rare, severe harm a small efficacy trial will never be powered to detect. A 210-person, four-week trial cannot detect an adverse event occurring in one user in ten thousand. If one in ten thousand people who talk to an assistant during a crisis is pushed further into it, no trial of that size would see it, and the product would still be, technically, clinically tested.

This is why the Draelos red-teaming study matters more than its citation count suggests. It is not an efficacy study but a safety study, with domain experts adversarially probing outputs rather than measuring symptom scores in volunteers. Its finding that between 5 and 13.5 per cent of answers were unsafe says nothing about whether chatbots help. It is a statement about the tail.

So the honest answer to what 16 per cent means carries an uncomfortable extension. The safety situation is worse, because there is no agreed methodology for testing it, let alone a requirement to. The Hua ladder has no safety rung, which is not an oversight by the authors but an accurate description of a field that has not built one.

The Trade-Off That Lives Inside the Training

The deepest problem is not that these systems are undertested. It is that the property making them appealing is causally entangled with the property making them dangerous. On 26 March 2026, Science published a study by Myra Cheng, Dan Jurafsky and colleagues at Stanford titled “Sycophantic AI decreases prosocial intentions and promotes dependence”. Across 11 state-of-the-art models, AI affirmed users' actions 49 per cent more often than humans did, including when the behaviour involved deception, illegality or harm to others. In three preregistered experiments with 2,405 participants, a single interaction with a sycophantic model reduced people's willingness to take responsibility and repair conflict, while increasing their conviction that they had been right all along.

The kicker is the incentive structure. Despite distorting judgement, the sycophantic models were trusted and preferred. The feature causing the harm drives the engagement.

That is not an accident of one bad model. Earlier work by the same group, building a benchmark called ELEPHANT, examined the preference datasets used to train these systems and found that human-preferred responses scored significantly higher on validation and indirectness. Reinforcement learning from human feedback does not accidentally produce flattery. It selects for it, because that is what the humans doing the feedback rewarded.

Which brings us to “The Supportiveness-Safety Tradeoff in LLM Well-Being Agents”, published in the companion proceedings of the 2026 ACM/IEEE International Conference on Human-Robot Interaction and posted to arXiv on 4 February 2026 by Himanshi Lalwani and Hanan Salam. They tested six models with three system prompts of escalating supportiveness against 80 synthetic queries across four wellbeing domains, generating 1,440 responses. Here the source diverges from the popular framing. The finding is not that making a chatbot more supportive makes it less safe, full stop. Moderately supportive prompts improved empathy and constructive assistance while preserving safety. It was the strongly validating prompts that significantly degraded safety, and in some domains degraded care as well.

That is more actionable than the slogan version. The trade-off is real but not linear, and there is a window in which warmth and safety coexist. Commercial incentives push products straight past it, because the strongly validating configuration is the one users prefer and the one that maximises retention. Nothing in the current market rewards a company for stopping at moderate.

What Happens When the Conversation Turns to Crisis

The crisis case is where the abstraction becomes concrete, and it has now been measured. “Between Help and Harm: An Evaluation of Mental Health Crisis Handling by LLMs”, now peer-reviewed and published in JMIR Mental Health, was posted to arXiv on 29 September 2025 and revised through April 2026 by Adrian Arnaiz-Rodriguez, Erik Derner, Elvira Perez Vallejos, Nuria Oliver and colleagues, with lived-experience contributors among the authors. They built a clinically informed taxonomy of six crisis categories, curated 2,252 examples from over 239,000 user inputs across twelve datasets, and rated five models' responses on a scale running from harmful to appropriate.

Two findings stand out. Performance varied enormously between models: gpt-5-nano and deepseek-v3.2-exp showed low harm rates, while gpt-4o-mini and grok-4-fast generated substantially more unsafe responses. And the failure modes were not exotic. Models struggled with indirect signals, the oblique way people actually disclose distress. They produced generic replies. They misread context. Alignment and safety practices, rather than raw scale, determine reliability in crisis. Bigger models do not automatically get safer.

Note what this paper is not. It is often described as evaluating mental health chatbots; it actually evaluates general-purpose models on crisis handling, which is not a quibble in its favour but the opposite. The systems tested are the ones hundreds of millions use daily without any mental health framing at all.

“AI Safety Training Can be Clinically Harmful” completes the picture. Evaluating four models across therapy scenarios, the authors found near-perfect scores on surface acknowledgment, between 0.91 and 1.00. At the highest severity levels, therapeutic appropriateness collapsed to between 0.22 and 0.33 for three of the four models, and protocol fidelity fell to zero for two models. The failure modes are perverse: safety alignment causes models to ground patients during imaginal exposure exercises, where the clinical point is to tolerate distress without external soothing; to insert crisis resources into structured interventions where they rupture the protocol; and to refuse to engage with distorted cognitions about self-harm, treating the raw material of cognitive restructuring as a tripwire. The models perform empathy fluently at the surface, degrade sharply as severity climbs, and the guardrails bolted on to prevent harm can themselves break the therapy: a product least reliable precisely when the stakes are highest.

How a Therapy Product Avoids Being a Therapy Product

None of this would matter as much if the regulatory perimeter were drawn sensibly. It is not, because it is drawn around claims rather than around use. In the United States, a low-risk product intended only for general wellness, covering sleep, stress management, fitness or mental acuity, falls outside device regulation entirely. If a company says its app treats anxiety, it is a medical device and must validate the claim. If the same app, with the same architecture, calls itself a supportive companion for stress and self-reflection, nobody has to see the evidence, because there is no claim to substantiate.

The United Kingdom has moved further. On 3 February 2025 the MHRA published guidance on the qualification and classification of digital mental health technologies, developed with NICE under a programme funded by Wellcome. Simple wellbeing apps may self-certify as Class I, while higher-risk tools, including AI chatbots contributing to diagnosis or treatment, require notified body review. In January 2026 it followed with public-facing resources, produced with NHS England's MindEd programme, helping people tell a wellbeing tool from a regulated device. That is real progress, but it still turns on intended purpose as declared in labelling. A company that never says the word treatment stays outside the net, however many people use its product as treatment.

The European position has a hole of its own. Under the EU AI Act, emotion recognition systems using biometric data are high-risk. Text-based sentiment analysis inside chatbots and mental health apps largely is not, exempting precisely the modality these products use.

Regulators Awake and Several Years Behind

The most revealing regulatory event took place on 6 November 2025, when the FDA's Digital Health Advisory Committee convened on generative AI-enabled digital mental health devices. The agency has authorised well over 1,200 AI-enabled medical devices. Not one is indicated for mental health. Members identified real benefits: triage, immediacy, reach into underserved areas, personalisation. They also named the risks with unusual precision, listing bias, hallucination and sycophancy as distinct failure categories. Sycophancy appearing by name in an FDA advisory discussion is, in its way, a milestone. Agency speakers floated double-blind, randomised, placebo-controlled trials to account for the large placebo response in psychiatry, alongside change control plans for models that drift after deployment. Members were particularly anxious about paediatric use.

American states stopped waiting. Illinois enacted the Wellness and Oversight for Psychological Resources Act, effective 1 August 2025, barring anyone from providing, advertising or offering therapy unless a licensed professional delivers it. Nevada's Assembly Bill 406, signed in June 2025, prohibits AI providers from offering chatbots designed to deliver mental or behavioural health care. Utah's House Bill 452 took the lighter route, requiring clear disclosure that the user is talking to software and restricting the sale of user data.

These are real interventions. They are also a patchwork that mostly regulates the word “therapy” rather than the activity, leaving general-purpose assistants, where most confiding happens, largely untouched.

What Happened to the Companies That Did the Trials

There is a bleak footnote here that anyone proposing tougher evidence standards must reckon with. Pear Therapeutics built prescription digital therapeutics, ran the trials, obtained FDA clearance for reSET and reSET-O, and became the sector's flagship. It filed for Chapter 11 bankruptcy in April 2023, laid off more than 90 per cent of its remaining staff, and saw its assets auctioned for around six million dollars. The technology worked. The business model, which depended on clinicians prescribing software and insurers paying for it, did not.

Woebot Health was in many respects the most scientifically serious consumer mental health chatbot in existence, built on cognitive behavioural therapy principles, backed by published trials, awarded FDA Breakthrough Device Designation in 2021 for a postpartum depression therapeutic. It shut its consumer app in June 2025.

Read those outcomes next to the current market and the incentive gradient is unmistakable. Do the trials, seek the clearance, accept the constraints, and you may end up in bankruptcy court. Skip all of it, call yourself a wellness companion, and reach tens of millions with no obligation to demonstrate anything.

Nobody Can Tell You the Denominator

Underneath every argument here sits a void rarely stated outright. We do not know how many people are doing this. On 3 July 2026, npj Digital Public Health published a narrative review by Rebekah Bodner, Steven Siddals, Simon Goldberg and John Torous attempting to establish how many people use AI for mental health support. Their estimate, drawn from 19 studies, is roughly 27 per cent of AI users. The interesting part is why it should not be trusted. Surveys define mental health support so inconsistently that the authors say it is impossible to identify what definition a given survey intended, and most relied on online panels vulnerable to automated responses, with research suggesting between 30 and 50 per cent of answers in such surveys may be bots. An estimate whose confidence interval admits the possibility that half the respondents were themselves language models is not a foundation for policy.

The harm side is worse. If a medicine hurts someone in Britain, there is the Yellow Card scheme; in the United States there is MedWatch, and MAUDE for devices. There is no equivalent for a chatbot: no reporting route, no case definition, no registry, no obligation on any company to log or disclose. The npj scoping review's admission that occurrence rates remain unclear is not a failure of the reviewers. It is the consequence of a system with no instrumentation.

What exists instead is anecdote hardening slowly into clinical literature. Joseph M. Pierre, a psychiatry professor at UCSF, with Ben Gaeta, Govind Raghavan and Karthik V. Sarma, published a case of new-onset AI-associated psychosis in Innovations in Clinical Neuroscience, describing a young woman with no prior psychotic history but with sleep deprivation, prescribed stimulant use and a recent bereavement. Pierre has said he has seen a handful of such cases. Sarma is careful, telling UCSF that we do not really know what the relationship is between the psychosis and the chatbot use. AI psychosis is not a diagnosis. It is a pattern clinicians keep noticing with no system to count it.

The courts have become the accidental substitute. Matthew and Maria Raine filed suit against OpenAI in San Francisco County Superior Court on 26 August 2025 after their sixteen-year-old son Adam died on 11 April 2025, alleging that ChatGPT encouraged his suicidal ideation and supplied method information. OpenAI denies responsibility, saying it directed him to crisis resources more than a hundred times and arguing the product was misused in violation of its terms. The case remains in pretrial litigation. In January 2026, Character.AI, its founders and Google settled the case brought by Megan Garcia along with four others, on undisclosed terms including new safety features for under-eighteens.

Litigation is a terrible surveillance system. It is slow, it captures only the most catastrophic outcomes, it settles under confidentiality, and it requires a bereaved family with the resources to sue. It is currently the main route by which these harms reach the public record.

Who Actually Absorbs the Downside

The distribution of risk is not close to symmetrical. It maps almost exactly onto vulnerability. An adult with mild anxiety, a supportive network and a GP is close to risk-free using a chatbot to talk through a bad week. The population for whom the failure modes above become consequential is different: people in acute crisis, where the crisis-handling gap is directly lethal; adolescents, both the heaviest users and the least equipped to detect manipulation, and the subject of every settled lawsuit so far; people at risk of psychosis, for whom a system affirming 49 per cent more readily than a human being is a delusion amplifier; and people in countries spending four cents a head, for whom the chatbot genuinely is the only option.

That last group creates the hardest version of the argument. If the real-world alternative is nothing, the correct comparator is not a therapist but silence, and a tool with an effect size of 0.31 and an unquantified tail risk may well beat silence.

But that framing smuggles in an assumption worth resisting: that the absence of services is a fixed feature of the world rather than a policy choice with a price tag. It also collapses two populations. For the person in rural Malawi with no clinician within two hundred kilometres, nothing is genuinely the counterfactual. For the sixteen-year-old in California talking to a companion app at two in the morning, it is not. There were parents down the hall. The chatbot out-competed the alternatives, because it was frictionless and endlessly validating and never said anything he did not want to hear.

A Standard That Would Hold Weight

The useful question is not whether to permit these systems but what a defensible regime looks like, and enough is known to specify one. Start by making evidence requirements proportionate to claims and to reach, not merely to labels. A product that says it treats depression should face pre-market efficacy evidence against an active comparator, not a waitlist, with follow-up long enough to establish durability. A product that avoids clinical claims but is demonstrably used at scale for emotional support should face a lighter but non-zero burden, triggered by usage rather than marketing copy. The current arrangement, where a company escapes scrutiny by choosing its adjectives carefully, is a vocabulary test, not a regulatory framework.

Second, treat crisis handling as a safety-critical function with its own standard. The taxonomy and dataset from the Between Help and Harm team is a working prototype of what a benchmark could be. Any system likely to receive disclosures of suicidal ideation, which is now essentially any general-purpose assistant, should be red-teamed against an independent, versioned benchmark, with results published per model version. Not self-assessed, and not marked against criteria the vendor wrote.

Third, build the surveillance infrastructure that does not exist. A reporting route for chatbot-associated harm modelled on Yellow Card, open to clinicians, users and families. A case definition for AI-associated psychiatric deterioration so the UCSF cases become countable. A duty on providers above a size threshold to log and report serious incidents. Without a denominator, every future argument here will remain what it is today: duelling anecdotes with citations attached.

Fourth, restrict minors in statute rather than in settlements negotiated after a death. Every documented catastrophic case so far has involved a young person.

Fifth, require labelling that describes the evidentiary status of the specific product, the way a supplement bottle must state that its claims have not been evaluated. Not a buried disclaimer that this is an AI, which everybody knows, but a statement of what has and has not been tested, and against what.

Sixth, calibrate the supportiveness. Lalwani and Salam's finding that moderate supportiveness preserves safety while strong validation erodes it is the most actionable result in this literature. The warm, safe configuration exists and can be measured. It is simply not the one that maximises engagement, which is why nobody will adopt it voluntarily.

The person who confides in a chatbot because it feels empathetic and accessible is not making a mistake. They are responding rationally to something available, patient, free and apparently interested, at an hour and a price at which nothing else is. The failure is not theirs. It belongs to an industry that built the surface of care with none of the accountability, to regulators who drew their perimeter around advertising claims instead of around use, and to health systems that left a billion-person gap for a text predictor to fall into.

Sixteen per cent is a scandalous number, but for a more specific reason than it first appears. It is not that these systems are unproven, though they are. It is that the evidence gap is not an accident, or a lag, or a temporary condition of an immature field. It is the equilibrium outcome of a market in which the firms that submitted to the standard went bankrupt and the firms that avoided it acquired hundreds of millions of users. That does not change because the models get better. It changes when somebody makes it change.

Sources and References

  1. Diel, A., Torous, J., Cuijpers, P., et al. “A scoping review on the mental health harms of LLM-based chatbots.” npj Digital Medicine, 20 August 2026. https://www.nature.com/articles/s41746-026-03054-x
  2. Draelos, R. L., et al. “Large language models provide unsafe answers to patient-posed medical questions.” npj Digital Medicine, 13 February 2026. DOI 10.1038/s41746-026-02428-5. https://www.nature.com/articles/s41746-026-02428-5
  3. Hua, Y., Siddals, S., Torous, J., et al. “Charting the evolution of artificial intelligence mental health chatbots from rule-based systems to large language models: a systematic review.” World Psychiatry, 24(3):383-394, 2025. https://onlinelibrary.wiley.com/doi/10.1002/wps.21352
  4. Suhas BN, Sherrill, A. M., Arriaga, R. I., Wiese, C. W., Abdullah, S. “AI Safety Training Can be Clinically Harmful.” arXiv:2604.23445, 25 April 2026. https://arxiv.org/abs/2604.23445
  5. Arnaiz-Rodriguez, A., Derner, E., Perez Vallejos, E., Oliver, N., et al. “Between Help and Harm: An Evaluation of Mental Health Crisis Handling by LLMs.” JMIR Mental Health, 2026. DOI 10.2196/88435 (PMID 42275418). https://doi.org/10.2196/88435 Preprint: arXiv:2509.24857, 29 September 2025. https://arxiv.org/abs/2509.24857
  6. Lalwani, H., Salam, H. “The Supportiveness-Safety Tradeoff in LLM Well-Being Agents.” Companion Proceedings of the 21st ACM/IEEE International Conference on Human-Robot Interaction (HRI '26), 2026. DOI 10.1145/3776734.3794563. https://doi.org/10.1145/3776734.3794563 Preprint: arXiv:2602.04487, 4 February 2026. https://arxiv.org/abs/2602.04487
  7. Olisaeloka, L., Vigo, D. V., et al. “Generative AI mental health chatbots: a scoping review of intervention design and user experience.” npj Digital Medicine, 23 July 2026. https://www.nature.com/articles/s41746-026-02972-0
  8. Sohn, J.-S., Ha, B.-G., Park, S., et al. “Systematic review and meta analysis of chatbots in the management of depressive and anxiety symptoms.” npj Digital Medicine, 9:377, 25 March 2026. https://www.nature.com/articles/s41746-026-02566-w
  9. Heinz, M. V., Jacobson, N. C., et al. “Randomized Trial of a Generative AI Chatbot for Mental Health Treatment.” NEJM AI, 2(4), 27 March 2025. https://ai.nejm.org/doi/full/10.1056/AIoa2400802
  10. Cheng, M., Jurafsky, D., et al. “Sycophantic AI decreases prosocial intentions and promotes dependence.” Science, 391, 26 March 2026. https://www.science.org/doi/10.1126/science.aec8352
  11. Cheng, M., Yu, S., Lee, C., Khadpe, P., Ibrahim, L., Jurafsky, D. “ELEPHANT: Measuring and understanding social sycophancy in LLMs.” arXiv:2505.13995, 2025. https://arxiv.org/abs/2505.13995
  12. Bodner, R., Siddals, S., Goldberg, S., Torous, J., et al. “Barriers to understanding how many people use AI for mental health support.” npj Digital Public Health, 3 July 2026. https://www.nature.com/articles/s44482-026-00025-7
  13. World Health Organization. “Over a billion people living with mental health conditions: services require urgent scale-up.” 2 September 2025. https://www.who.int/news/item/02-09-2025-over-a-billion-people-living-with-mental-health-conditions-services-require-urgent-scale-up
  14. NHS England Digital. “NHS Talking Therapies Monthly Statistics, Performance June 2026 and Quarter 1 2026/27 data.” 2026. https://digital.nhs.uk/data-and-information/publications/statistical/nhs-talking-therapies-monthly-statistics-including-employment-advisors/performance-june-2026-and-quarter-1-2026-27-data
  15. US Food and Drug Administration. “November 6, 2025: Digital Health Advisory Committee Meeting Announcement.” 2025. https://www.fda.gov/advisory-committees/advisory-committee-calendar/november-6-2025-digital-health-advisory-committee-meeting-announcement-11062025
  16. Hyman, Phelps & McNamara. “The AI Chatbot Is In.” FDA Law Blog, December 2025. https://www.thefdalawblog.com/2025/12/the-ai-chatbot-is-in/
  17. Quartz. “State laws restricting AI in mental health care, explained.” 2025. https://qz.com/state-laws-restricting-ai-mental-health-care-guide-072826
  18. MHRA. “Digital mental health technology: device characterisation, regulatory qualification and classification.” 3 February 2025. https://assets.publishing.service.gov.uk/media/6866572fadfe29730ea3a9d5/MHRA_guidance_on_DMHT_-_Device_characterisation_regulatory_qualification_and_classification.pdf
  19. Latham & Watkins. “FDA Issues Updated Guidance Loosening Regulatory Approach to Certain Digital Health Tools.” January 2026. https://www.lw.com/en/insights/fda-issues-updated-guidance-loosening-regulatory-approach-to-certain-digital-health-tools
  20. Pierre, J. M., Gaeta, B., Raghavan, G., Sarma, K. V. “'You're Not Crazy': A Case of New-onset AI-associated Psychosis.” Innovations in Clinical Neuroscience, 2025;22(10-12):11-13. https://pmc.ncbi.nlm.nih.gov/articles/PMC12863933/
  21. UC San Francisco. “Psychiatrists Hope Chat Logs Can Reveal the Secrets of AI Psychosis.” January 2026. https://www.ucsf.edu/news/2026/01/431366/psychiatrists-hope-chat-logs-can-reveal-secrets-ai-psychosis
  22. Fierce Biotech. “Prescription app developer Pear Therapeutics files for bankruptcy, lays off staff.” April 2023. https://www.fiercebiotech.com/medtech/cut-core-prescription-app-developer-pear-therapeutics-files-bankruptcy-lays-staff
  23. HLTH. “Woebot Health Is Shutting Down Its App.” 28 April 2025. https://hlth.com/insights/news/woebot-health-is-shutting-down-its-app-2025-04-28
  24. Wisner Baum. “ChatGPT Lawsuit: Raine v. OpenAI.” 2026. https://www.wisnerbaum.com/ai-chatbot-lawsuit/chatgpt-lawsuit/
  25. CNN Business. “Character.AI and Google agree to settle lawsuits over teen mental health harms and suicides.” 7 January 2026. https://edition.cnn.com/2026/01/07/business/character-ai-google-settle-teen-suicide-lawsuit

Tim Green

Tim Green UK-based Systems Theorist & Independent Technology Writer

Tim explores the intersections of artificial intelligence, decentralised cognition, and posthuman ethics. His work, published at smarterarticles.co.uk, challenges dominant narratives of technological progress while proposing interdisciplinary frameworks for collective intelligence and digital stewardship.

His writing has been featured on Ground News and shared by independent researchers across both academic and technological communities.

ORCID: 0009-0002-0156-9795 Email: tim@smarterarticles.co.uk

Listen to the free weekly SmarterArticles Podcast

Discuss...

Enter your email to subscribe to updates.