LLMポイズニングに使われた偽シンクタンク
まず何が見つかったのか。手口を理解するには実物の作りを見るのが早道です。
Hanover Instituteという名前
Hanover Institute for Public Policy(ハノーバー研究所)は一見するとイスラエルとパレスチナを扱う新しい研究機関に見えます。出しているのも「AIPACは選挙で不透明な資金を使っているか」といったシンクタンク風の報告書です。しかし報道によれば、これは本物のシンクタンクではありません。 名前・サイトの作り・赤白青の配色まで、典型的な米国のシンクタンクをそのまま真似た体裁だと、偽情報を追跡する NewsGuard のアナリスト Alice Lee は述べています。
"But the Hanover Institute is not a real think tank."/"It's a perfect mimicry of a typical credible American think tank, right down to the generic name, the site layout, and the red-white-blue color scheme,"— Responsible Statecraft の調査報道より
署名がなく出どころの注記も小さい
見分けられる手がかりは2つ挙げられています。ひとつは、報告書のどれにも書き手の署名が無いこと。 もうひとつがページ下部の小さな注記で、そこにイスラエル政府広告庁の依頼を受けて Piro, Inc(ピロ)が作ったと書かれています。この会社はイスラエル政府から90万ドルを受け取っており、契約はフランスの広報大手 Havas Media(アヴァス・メディア)を通じた再委託だと報じられています。公開が始まったのは2026年8月6日。報道された8月17日までの1週間あまりで100本を超えました。
"None of the reports have bylines. A small disclaimer at the bottom of the webpage notes that the organization was created on behalf of the Israeli Government Advertising Agency by Piro, Inc…"/"Piro, Inc, the firm that created the Hanover Institute, has received $900,000 from the Israeli government for its work. Like many other contractors working for Israel, Piro’s work is subcontracted through Havas Media, a French public relations conglomerate."/"The fake think tank has churned out over 100 reports since it started publishing on August 6."— Responsible Statecraft の調査報道より
なぜAIに引用されやすいのか
作りの細部がそのままAI向けの最適化になっています。
統計と出典を厚く見せている
報告書には脚注と目次が付き、主張は中立的な語調で書かれています。AIが好むのは具体的な統計やデータ、そして強い引用と出典で、これらの記事はそのすべてを備えている。 同じアナリストがそう指摘しています。記事の多くは定型に沿っており、人がチャットボットへ投げそうな素朴な問いから始まる構成だとされます。実際の報告書のひとつは "What Caused the Displacement of Palestinians in 1948?" という題です。
"The institute’s “data reports” have footnotes and tables of contents, and they present arguments in a neutral tone, helping them appeal to chatbots like Claude or Gemini."/"LLMs favor concrete statistics and data, as well as strong citations and sources, which these articles all have,"/"Many of the reports are formulaic, starting with an innocent question that someone might ask a chatbot."— Responsible Statecraft の調査報道より
AI Story Optimizationという商品
制作した Piro は自社サイトで「LLMが信用度をどう評価するかに合わせて設計した文章」を書くと説明し、これを AI Story Optimization と呼んでいます。同社の共同創業者は先月 LinkedIn でこの能力を売り込んでもいました。ChatGPT や Gemini、Perplexity に自分の分野を尋ねると自信のある一段落が返ってくるが、その一段落がどう組み立てられるかを何か月もかけて解析したという趣旨の投稿です。 一方で司法省へ提出した契約書にはAIへの影響が目的だとは明記していないとされています。
"Piro’s website says that it “author(s) content engineered for how LLMs evaluate credibility,” describing this service as \"AI Story Optimization.\" Others refer to this practice of influencing artificial intelligence as “LLM poisoning.”"/"When someone asks ChatGPT, Gemini, or Perplexity about your category, an answer comes back in one confident paragraph. Most brands have no idea how that paragraph gets built. So we spent months reverse-engineering it…"/"Piro does not explicitly state in its agreement submitted to the Department of Justice that its work for Israel is to influence AI."— Responsible Statecraft の調査報道より
AI検出ツールはどう判定したか
Responsible Statecraft は Hanover Institute の記事12本を無作為に選び、AI検出ツールの GPTZero(ジーピーティーゼロ)にかけました。結果は11本が高い確度でAIによる執筆、残る1本も中程度の確度でAI生成という判定です。 100本超という量を1週間あまりで出せた説明にもなっています。
"RS analyzed 12 random Hanover Institute articles using GPTZero, a popular AI detection software that claims a low false-positive rate. GPTZero flagged 11 of the articles as AI-written with “high confidence”; it flagged one article as AI-written with “moderate confidence.”"— Responsible Statecraft の調査報道より
回答の出どころはどう確かめるか
読む側にできることは限られますが、ゼロではありません。
署名と運営主体を先に確かめる
AIの回答は根拠として挙げているリンクを開かないかぎり出どころが分かりません。組織名が立派に見えても、署名の有無と運営主体の記載は自分で確かめられます。 今回の事例で決め手になったのも書き手の署名が無いことと、ページ下部の小さな注記でした。研究機関を名乗るサイトなら、誰が書いたのかと誰が資金を出しているのかは本来どこかに書かれています。
CopilotとGeminiが実際に引いていた
実際に引用された例も報じられています。イスラエルは元トランプ陣営の選挙対策責任者 Brad Parscale(ブラッド・パースケール)とも4,650万ドル規模の契約を結び、チャットボットへ影響を与えるよう設計した親イスラエルのサイト群を作らせたとされます。Responsible Statecraft は別の Drop Site の調査を引き、Microsoft Copilot と Google Gemini がそれらのサイトのデータを取り込んでいたと伝えています。 さらに、多くのチャットボットが情報工作の一部だと示さないまま引用しているとも書かれています。AI検索が流入経路として無視できなくなっている状況はAI検索からの流入をめぐる実測、書き手の名義そのものが揺らぐ問題はAIによる署名の悪用でも扱っています。
"Israel has also contracted former Trump campaign manager Brad Parscale to create pro-Israel websites engineered to influence chatbots as part of a $46.5 million contract. A Drop Site investigation last month found that many chatbots, particularly Microsoft Copilot and Google Gemini, had been successfully trained on data from those websites. Other chatbots frequently cite those websites without flagging them as part of an Israeli influence operation."— Responsible Statecraft の調査報道より
引用元をたどるとき、ページの構造ごと手元に落とすと、署名の有無や下部の注記といった「本文の外」に置かれた情報を見落とさずに済みます。
まとめ
LLMポイズニングは、シンクタンクらしい体裁をAIに引用されるための設計として使います。今回報じられたのは署名のない報告書を短期間に100本超そろえ、統計と脚注と中立的な語調でAIの評価軸に寄せた実例でした。AIの回答は組み上がった一段落として返ってくるため、その材料が何だったのかは利用者からは見えません。 重い判断に使うときほど、回答が挙げている出典を開き、誰が書いて誰が出資したのかまで確かめる。いまのところ、それが読み手側に残された確認手段です。



