SmarterArticles

Keeping the Human in the Loop

There is a moment, described more than once by the people who have lived it, when the correction stops being needed. You are a speech and language pathologist, say, and you have spent a fortnight teaching a language model how a sentence should breathe in Brazilian Portuguese, how a piece of creative writing earns its emotional turn rather than announcing it. You mark the model's output. You explain, patiently, why the phrasing is wrong, why a native ear would flinch. And then one morning you sit down to the same task and find you have nothing to say. The model has absorbed you. The thing you were correcting a week ago it now does on its own, in your voice, without you. Carolina Perez Sands did exactly this work for the artificial-intelligence training company Mercor, and she described the arc of it to The Wall Street Journal's podcast in June 2026. Her corrections, she said, became unnecessary within roughly a week. She has since left the industry, having reached a conclusion that ought to be printed on the wall of every laboratory in the sector. Her job, she decided, was “actually making this more of a monster.”

That sentence is the whole subject of this essay, and it is worth sitting with before we reach for the economics. She did not say the work was hard, though it was. She did not say the pay was poor, though for many in the sector it becomes so. She said the work was monstrous, and she meant something precise by it: that the better she did her job, the less of her there was left to do. She was not being replaced by a machine in the ordinary sense, the sense in which a loom replaces a weaver or a spreadsheet replaces a clerk. She was pouring herself into the machine that would replace her, decanting a career's worth of tacit judgement into a system engineered to make that judgement free and infinite. And she was being paid, by the hour, to do it.

The supply chain of the mind

The company that paid her is three years old. In July 2026 The New York Times, in a report by Lora Kelley bluntly titled “The Work of Helping A.I. Destroy Work,” laid out the scale of the operation with a single arresting figure: every day, Mercor pays more than thirty thousand contractors upward of four million dollars to help make their own jobs, and the jobs of their colleagues, obsolete. This is not the old data economy of blurred street signs and flagged slurs. The postings the Times examined read like a fever dream of the professional class: two hundred and twenty-five dollars an hour for a voice actor who could hold a customer-service persona in fluent Hebrew, a doctorate-holding physicist with a specialism in general relativity, astrophysics or cosmology, physicians who could describe the texture of primary care in Rwanda. Mercor supplies mathematicians to annotate formal proofs, lawyers to mark up briefs, professors to grade essays. Data labelling, as the Times put it, has moved up the value chain.

The money follows. Mercor was valued at ten billion dollars in October 2025 after a funding round of some three hundred and fifty million, an event that made its three founders — Brendan Foody, Adarsh Hiremath and Surya Midha, Thiel Fellows all, and none of them much past twenty-two — among the youngest self-made billionaires alive. By July 2026 Bloomberg, Forbes and TechCrunch were reporting the company in talks to raise a further five hundred million dollars or so at roughly double that valuation, twenty billion, on the back of a gross revenue run rate that had itself doubled, in the space of about four months, to reach two billion dollars a year. The doubling is the fact worth holding on to: the valuation doubling in nine months, the revenue in four. The founder Brendan Foody has offered his own version of the daily wage bill, putting it at over one and a half million dollars a day; the Times, counting more broadly, put it above four million. Either way the arithmetic is the same in shape. A very small number of very young people have built an extraordinarily valuable company whose principal activity is buying, by the hour, the accumulated expertise of tens of thousands of highly credentialled professionals, and selling it onward to the laboratories building the models that will render that expertise abundant.

It is worth being clear about how new this is, because the novelty is the whole argument. The AI industry has always rested on hidden human labour. For most of the last decade that labour was cheap, distant and largely invisible: the workers in Nairobi and Gulu paid a dollar or two an hour by outfits contracting for Scale AI and OpenAI to tag images, moderate horrors and rank chatbot replies. Nearly a hundred of them — ninety-seven, to be exact — wrote to the American president in May 2024 describing their conditions as amounting to modern-day slavery; researchers documented the psychological toll of the content they were made to sift; Scale AI, according to reporting from the region, moved to disband labeller organising in Kenya in 2024. That economy has not vanished. But Mercor represents its mirror image and its escalation at once. The people being paid now are not the world's poorest but among its most expensively trained, and what is being extracted from them is not attention or a strong stomach but the very thing their years of study were supposed to make scarce and valuable: judgement.

What the model is actually buying

To understand why this matters more than the raw injustice of any single wage cut, you have to understand what is being sold, and it is not what the word “data” suggests. When a mathematician annotates a proof for a model, she is not handing over a fact that could be looked up. She is handing over the shape of her reasoning: which steps are load-bearing and which are decoration, where a student would go wrong, what an elegant move looks like as against a merely correct one. This is what the philosopher Michael Polanyi called tacit knowledge, the knowledge captured in his famous formula that we know more than we can tell. It is the knowing-how that lives beneath the knowing-that, the reason an expert can recognise in a glance what she could not fully explain in an afternoon. It is, precisely, the part of expertise that cannot be written in a textbook, which is why professions have always transmitted it through apprenticeship, through years of supervised proximity to someone who already has it.

The entire proposition of the expert-annotation economy is that this tacit layer can, in fact, be told — extracted, structured, and used to train a system that reproduces it. The physician describing Rwandan primary care is not uploading a medical fact. She is externalising the clinical intuition she built over a decade of patients, the pattern-recognition that lets her weight a symptom differently depending on a context no guideline captures. The lawyer marking up a brief is teaching the model where the argument is weak in a way only a practitioner would feel. Each correction is a small act of translation, turning the untellable into the tellable, and the astonishing, disquieting discovery of the last two years is how few such translations the models now need before they can do without the translator. Perez Sands measured hers in a week.

This is where the MIT Sloan management professor Danielle Li put her finger on something more fundamental than any one person's redundancy. Writing in the Financial Times in March 2026, Li argued that the threat here is not merely to jobs but to the deep structure of economic security itself. “Historically,” she wrote, “economic security has rested on the scarcity of skill.” That is the sentence to underline. The reason a radiologist or a litigator or a structural engineer could command a good wage and a stable life was not only that their skill was valuable but that it was rare, slow to acquire, and lodged in scarce human heads. Once a top performer's judgement is codified into a model, Li observed, it can be copied out to every other worker in that role, everywhere, faster than any chain of human mentorship could ever manage. The scarcity that underwrote the wage evaporates. Skill does not become worthless; it becomes ubiquitous, which for the person who used to be paid for its rarity amounts to much the same thing.

The arc every worker describes

There is a grim regularity to the testimony coming out of this sector, a shared narrative shape that recurs across specialisms and platforms with the fidelity of a natural law. It begins with the pay, which looks, at first, wonderful. Moneywise reported white-collar contractors being drawn in at two hundred dollars an hour to train models on their own professions, sums that dwarf what many of them earn in their day jobs. Then the timers appear. Tasks that were open-ended acquire deadlines; the deadlines tighten; the rate per task, quietly, falls. The feedback, once collegial, curdles into something vague and demoralising, a stream of rejections whose logic is never quite explained. And then, within months, the professional notices the thing that ends the story: the model has got good. As Amanda Brown, an assistant professor of biology at Tarleton State University, told the Times, she began to notice improvements so rapid that it grew “trickier to find things the AI models didn't already know” — which is to say her own knowledge was being exhausted, mined out, the seam running thin. The work intensifies precisely as it becomes futile.

The economics of this squeeze are not accidental, and one need not impute malice to see the mechanism at work. An arXiv paper published in April 2026 by Ana-Andreea Stoica, Celestine Mendler-Dünner and Moritz Hardt, working between the Max Planck Institute for Intelligent Systems and the Tübingen AI Center, describes the general logic with unsettling clarity. A platform that controls task allocation can exploit workers' uncertainty about the true cost of their own labour to drive the effective wage down, and can wait out any collective resistance simply by reassigning the task to whoever will accept the lowest price first. What the authors prove is starker than the intuition suggests: a platform can get every one of its tasks completed while paying only a vanishing share of what that labour is actually worth — a share that shrinks as the pool of available workers grows, falling away in proportion to the logarithm of the pool divided by its size. Add workers, and the fraction of the true cost the buyer must pay dwindles towards nothing. Solidarity, on this account, requires that everyone hold the line; the platform needs only one person to break it, and with a global pool of the credentialled and the anxious, there is always someone who will. The worker's leverage — the thing a union exists to pool and protect — is dissolved by an architecture that lets the buyer transact with the single most desperate seller at any moment.

But the paper's title carries a second clause, and it is the more important one: stochastic wage suppression on gig platforms, and how to organise against it. Having shown how thoroughly the mechanism works, the same authors ask what defeats it, and the answer they find is neither utopian nor expensive. A coalition of workers committed to a price floor can force the platform's total outlay from that vanishing logarithmic share up to a linear one — to something proportional, that is, to the real cost of the work — but only if the coalition is chosen with precision. Organise a small, targeted group of the lowest-cost workers, the very people the platform is relying on to undercut everyone else, and its ability to wait out the line collapses. Draw a group of the same size at random from the same workforce and almost nothing happens: the platform routes around them and the wage keeps falling. That asymmetry inverts the folk wisdom of the sector. Resistance to an algorithm holding all the cards is not futile; undifferentiated solidarity is. Numbers alone are not power. Position is. A movement that recruits broadly among the comfortable and the visible but never reaches the bottom of the price distribution will simply be bypassed, while one that begins at the bottom, where the platform's leverage actually lives, does not have to be large to bite.

Mercor has already furnished a concrete illustration of the harder edge of this. In November 2025 Forbes reported that the company abruptly cancelled a project called Musen, on which thousands of contractors — more than five thousand of them at its peak — had been reviewing content, and then offered to rehire them at sixteen dollars an hour rather than the twenty-one they had been getting: a cut of nearly a quarter, and a rate below the legal minimum wage in California, Washington and Connecticut. Contractors described being locked out of their Slack, told the work they had been promised through December was over, and invited back at the lower price the same afternoon. The replacement project had a name, Nova, and, by the account of contractors who worked on both, tasks near enough identical to the ones they had been doing the week before, for five dollars an hour less. The company's stated rationale, delivered by email, was that the new rate would offer them “greater earning stability and consistent access to work.” “It felt like a slap in the face,” one contractor said. “We are working with AI but we don't work for AI.” The episode is a small, sharp emblem of the whole arrangement's asymmetry: the value the workers created flowed upward into a ten-billion-dollar valuation, while the risk and the caprice flowed down onto them.

Why this is not simply gig work

It is tempting to file all of this under the familiar heading of precarious platform labour, alongside the food couriers and the ride-share drivers, and to reach for the familiar remedies: minimum rates, misclassification suits, the slow grind toward employee status. Those remedies matter, and the wave of class actions already filed against Mercor in the wake of a March 2026 data breach suggests the ordinary machinery of labour law is beginning, belatedly, to turn. But to stop there is to miss what makes knowledge-extraction labour a genuinely distinct category, and the distinction is not sentimental. It is structural, and it turns on the difference between selling your time and selling your replacement.

It is worth pausing on what those suits allege, because the detail bears directly on the argument. On or about the twenty-fourth of March 2026, a threat group known as TeamPCP exploited a vulnerability in LiteLLM, an open-source library that thousands of companies use to connect their applications to commercial AI models — a supply-chain attack that caught Mercor along with much of the rest of the industry. Roughly four terabytes of data left the company: some two hundred and eleven gigabytes of candidate records, including CVs, verified contact details and Social Security numbers; around three terabytes of video and identity-verification material, including recorded interviews and images of government identification documents; and a further nine hundred and thirty-nine gigabytes of source code and internal systems data. At least seven class actions have since been filed in federal courts in California and Texas. And among their allegations is one that ought to be read alongside everything else in this essay: that Mercor secretly surveilled its contractors using screenshot-capturing software, so that what escaped included not only the documents the workers had submitted but images of their screens while they worked. The company disputes the claims and says it complies with all applicable regulations.

That is the algorithmic management this essay has been describing, rendered literal. The contractors were not merely priced by an algorithm and reassigned by one; they were watched by one, at intervals they did not control, in a stream of images they never saw and could not audit, which then passed into the hands of strangers. Meta paused its work with Mercor indefinitely. OpenAI opened a review and, along with Anthropic, stayed. And three months after a breach that cost the company one of its largest clients, it was in talks to double its valuation to twenty billion dollars. That sequence is the essay's argument in miniature. The workers whose government identification and Social Security numbers were exposed bore the risk of an arrangement they did not design; the valuation doubled regardless. Risk flows downward, and consequence, when it lands at all, lands somewhere other than where the decisions were made.

Return, then, to the structural distinction, because it is the thing the ordinary remedies cannot reach. When a courier delivers a meal, the value of that labour is consumed in the moment and gone. The platform is no closer to being able to deliver the next meal without a courier; tomorrow it must hire one again. The relationship, exploitative as it may be, is at least recurring, and recurrence is the ground on which all worker power has ever been built. The threat to withdraw labour has teeth only because the labour is needed again. But the annotation of expertise is not consumed in the moment. It is captured, retained, and compounded. Each correction Perez Sands supplied made the next correction less necessary, until the whole category of her labour was no longer needed from anyone. This is not a job; it is a liquidation. The worker is not renting out her skill by the hour. She is selling the freehold, in instalments small enough that she may not notice she has signed away the deed until the last one clears.

That difference has a further consequence that ordinary gig work does not carry. A profession is not merely a stock of individuals; it is a system for reproducing itself, generation after generation, through the apprenticeship of the young by the experienced. Law, medicine and engineering have always insisted that their craft cannot be learned from a book, that it must be absorbed through years of supervised drudgery on real problems. The expert-annotation economy attacks this pipeline from both ends at once. It codifies the judgement of today's masters into models that make tomorrow's apprentices look redundant before they are hired, and in doing so it removes the junior tasks through which mastery was ever acquired. A profession that stops being able to pay its novices stops being able to make its experts, and a machine trained on the last generation of experts has no obligation, and no ability, to grow the next. What is being extracted, then, is not only the individual's future income. It is the profession's capacity to exist.

The uncomfortable case for abundance

Honesty requires a hard turn here, because there is a powerful argument on the other side, and an essay that suppressed it would be propaganda. The scarcity of skill that Danielle Li identifies as the historical basis of economic security is, from another angle, simply a shortage — and shortages are not obviously things a decent society should want to protect. That radiological expertise is rare is wonderful for radiologists and terrible for everyone in a country that does not have enough of them. If the tacit judgement of an excellent physician can be genuinely codified and distributed, then a child in a rural clinic with no specialist for two hundred miles might receive something approaching expert care. The Rwandan primary-care knowledge being annotated into a model could, in principle, be delivered back to Rwandan clinics that have never had enough doctors. To be against the diffusion of expertise as such is to be against the thing that medicine, education and law claim, in their better moments, to want: their own universality.

There is a second concession to be made here, more concrete than the first, and it should be stated plainly rather than buried in a subordinate clause. Mercor is not, on the available figures, a company skimming most of the value off its workers' labour. The two-billion-dollar run rate is gross billings, and contractors are reported to take home somewhere between sixty and seventy per cent of what the company charges its clients, leaving Mercor's own net revenue nearer six or eight hundred million. Judged as a middleman's cut, that is a generous one — more generous than a good many staffing agencies, literary agents and record labels manage — and any argument that proceeds as though the workers were being fleeced on the split is arguing with a company that does not exist.

This is the genuine moral complication, and it cannot be waved away by pointing at the founders' valuations. Nor does the revenue share answer the objection, generous though it is. Sixty or seventy per cent of an hourly rate is still payment for an hour. It is a share of the wage bill, not a share of the asset, and the percentage cannot reach the question the arrangement actually raises: what the worker is owed for the durable thing that survives the hour, the codified judgement that goes on earning long after she has stopped, and what becomes of her when the project ends, as Musen ended, and the model no longer needs the correction she was hired to supply. A fair price for time is not a wrong thing. It is simply an answer to a different question. The problem with the expert-annotation economy is not that it diffuses skill. Diffusing skill is, at least potentially, a public good of the first order. The problem is who captures the value released by that diffusion, and on what terms the people whose lives are dismantled in the process are treated. There is nothing in the technology that requires the surplus from making expertise abundant to flow, untaxed and unshared, to three men in their early twenties and their investors, while the professionals who supplied the expertise are managed by algorithm into ever-lower rates and then discarded when their knowledge is spent. The abundance and the injustice are separable. The industry's rhetorical trick — and it is the same trick performed by every disruptive technology before it — is to bundle them, so that any objection to the injustice can be dismissed as an objection to the abundance, a Luddite's fear of progress. It is not. One can want the child in the rural clinic to have the model and still insist that the doctor who trained it was owed something more than a tightening timer and a wage cut below the legal floor.

The right question, then, is not whether expertise should be diffused, but whether the current mechanism of diffusion is the only one available, or merely the one that happens to concentrate the gains most efficiently at the top. Framed that way, the appeals to inevitability lose their force. Nothing about training a general-relativity model requires that the physicist be paid piece-rate through an app that can reassign her task to the lowest bidder mid-project. That is a choice about the distribution of power and reward, dressed as a fact of nature.

There is a legal asymmetry buried in all this that sharpens the injustice further. When the mathematician annotates a proof or the lawyer marks up a brief, the resulting model weights become the intellectual property of the company that commissioned the work, protected, very often, as a trade secret, an asset the firm can guard, license and sell in perpetuity. The expertise that went into it enjoys no such protection running the other way. The professional retains no residual claim, no royalty, no acknowledgement in the artefact her judgement helped to build; the value she supplied is enclosed the instant it is captured, converted from her tacit possession into someone else's proprietary estate. The law is thus mobilised on one side of the transaction and silent on the other. It recognises the model as property worth defending while treating the human judgement distilled into it as a spent input, like electricity or compute, with no continuing interest in what it becomes. That imbalance is not a natural feature of knowledge. It is an artefact of which parties had lawyers when the terms were written, and it could be written differently.

What is owed, and to whom

Begin with what is owed to the workers, because it is the most tractable. The economist and technologist Jaron Lanier, with the political economist Glen Weyl, proposed in a 2018 Harvard Business Review essay a framework they called data dignity, or data as labour. Their insight, made years before the present moment but fitting it exactly, was that the digital economy systematically mislabels as free capital what is in fact human labour — the data and judgement that people supply to the systems that profit from them. Their remedy was not to ban the practice but to price it honestly: to treat the supply of training value as work, to be compensated as work, and crucially to be bargained over collectively. They imagined intermediary bodies — mediators of individual data — that could negotiate royalties and terms on behalf of the people supplying the value, much as a guild or a union once did. Danielle Li reached, from the other direction, a strikingly similar practical conclusion: if your work is training a model that will benefit your employer or a buyer, you should seek explicit recognition and payment for that, rather than assuming your ordinary wage already covers the sale of your professional soul.

The mechanism that makes this urgent rather than merely fair is the information asymmetry the Max Planck researchers described. A worker who does not know that her fortnight of corrections will make her whole role redundant cannot price that fortnight correctly. She is selling an asset — the future scarcity of her skill — without being told that is what is on the table, and at a price set by a party who knows exactly what it is worth. This is the classic condition under which markets fail and regulation earns its keep. At minimum, knowledge-extraction contracts should carry something like informed consent: a disclosure that the labour being purchased is training a system intended to perform the worker's function, and terms — royalties, residuals, equity, a share of the model's downstream value — that reflect the durable nature of what is being transferred rather than treating it as spent the moment the hour ends. Actors and writers won residual rights and consent provisions over their digital likenesses through collective action; there is no principle that grants a screen actor a stake in her synthetic double but denies a physicist one in the model built from her mind.

None of this is hypothetical, and the working proof of it comes from the other end of the supply chain rather than the top. In Kenya, the labellers whose two-dollar-an-hour work built the previous generation of these systems formed the Data Labelers Association, which signed up three hundred and thirty-nine members in its first week and has been pressing since for a code of conduct binding on the major labelling platforms: equitable pay, freedom of association, scheduled breaks, psychological support for the people made to sift the worst material on the internet. It has weighed legal action against Remotasks over the sudden withdrawal of platform access and wages left unpaid. It is small and under-resourced, and it is very nearly the body Lanier and Weyl imagined, assembled without their help at the poorest end of the chain, where the leverage is thinnest and the risk of organising highest.

The Max Planck result explains why that may be the right place to start rather than merely the most desperate. If a precisely targeted coalition of the lowest-cost workers is the thing that forces a platform to pay something approaching the real cost of labour, while a coalition of the same size drawn at random achieves almost nothing, then organising that begins in Nairobi is not a sideshow to whatever a displaced radiologist or general-relativity physicist may one day contemplate. It is the load-bearing part. The credentialled professional in California and the labeller in Kenya are not two separate stories about AI and work; they are the top and the bottom of a single price distribution, and it is the bottom that determines what the top can hold out for. Solidarity across that distance is not sentiment, and it is not charity. On the mathematics, it is the only version that works.

There is a second, blunter instrument that belongs in the same toolbox: the pooling of the transition's risk rather than its wholesale offloading onto the individual. If the diffusion of expertise generates a genuine productivity windfall — and the valuations suggest the market believes it does — then some of that windfall can be recycled into the people it displaces, through wage insurance that tops up the earnings of a professional who must move to lower-paid work, through funded retraining that is more than a gesture, through direct support during the months when a codified skill is losing its market. None of this is exotic; versions of it already exist for workers displaced by trade. The point is that the surplus released by making a profession abundant need not vanish, untaxed and unshared, into a balance sheet. It can be treated as the collective product it partly is, and distributed accordingly. What turns displacement from a catastrophe the worker absorbs alone into a risk the society that benefits agrees to pool is nothing more mysterious than the decision to share.

What is owed to the professions is subtler and harder. A profession is a public trust as much as a private career; society licenses doctors and lawyers not merely to protect their incomes but to guarantee that the expertise exists at all, renewably, accountably, with someone who can be struck off. When the expert-annotation economy hollows out the apprenticeship pipeline, it privatises a capacity that was always partly public, transferring the reproduction of medical or legal judgement from a regulated profession to an unregulated model owned by a private company. The obligation here runs to the institutions that credential and govern professions: to insist that the tacit knowledge being harvested from their members is not simply enclosed, that models trained on a profession's collective judgement carry some duty of stewardship back to it, and that the training of the machine does not quietly defund the training of the humans on whom the machine will always, ultimately, depend for correction, contest and renewal.

Governing the extraction differently

So, to the question the commissioning editor poses directly: should the labour of knowledge extraction be governed differently from other forms of gig work? The answer this essay reaches is a qualified yes, and the qualification is as important as the assent, because the case for special treatment rests not on the workers' credentials but on two structural features that ordinary gig work does not share.

The first is the terminal, self-cannibalising nature of the labour. Most work is repeatable; this work is designed to eliminate its own recurrence, and labour that abolishes itself cannot be protected by the standard remedies, which all assume a continuing relationship in which power can be exercised. You cannot strike a job that will not exist next month. This is why minimum-rate rules and misclassification suits, necessary as they are, cannot be the whole answer: they regulate the terms of a relationship whose defining feature is that it is engineered to end. Governing this labour honestly means attaching value to what is captured rather than only to the hours spent capturing it — residuals, collective royalties, a claim on the diffused asset — precisely because the hourly frame is the mechanism of the dispossession.

The second is the acute information asymmetry, sharper here than in any courier's contract, over what is actually being sold. When the buyer knows and the seller does not that the transaction extinguishes the seller's future market, the ordinary presumption that a freely struck bargain is a fair one collapses. That is a textbook justification for mandated disclosure and for a floor of non-waivable rights, the same logic that governs financial advice and the sale of securities. A society that requires a mortgage broker to disclose a conflict of interest can require an AI-training platform to disclose that the task on offer is the codification of the worker's own obsolescence.

What it does not justify is protectionism dressed as principle. The temptation, for a displaced professional class newly acquainted with the underside of technological change, will be to defend the scarcity of skill for its own sake — to treat the diffusion of expertise as a harm to be prevented rather than a good to be shared. That way lies a defence of shortage, and shortage is not justice; it is merely the old distribution of luck. The obligation is not to keep expertise rare so that its holders can keep charging rents. It is to ensure that when expertise is made abundant, the people from whom it was taken are treated as the authors of a public good rather than the raw material of a private one — compensated durably, informed honestly, bargaining collectively, and not managed by algorithm into pricing their own erasure at a discount.

The monster and the mirror

Return, at the end, to Carolina Perez Sands and the word she chose. She did not call the work exploitation, though a wage below the Californian minimum would qualify. She called it monstrous, and the horror she named was not primarily about money. It was about complicity — the vertiginous recognition that her own excellence was the instrument of her erasure, that every good correction she made was a brick in the wall being built between her profession and its future. She left. Most cannot, and the platform is designed on the assumption that for every one who walks away in disgust there is another, somewhere in the global pool of the credentialled and the underemployed, who will take the task at a lower price and never know how little of themselves they are selling until it is gone.

The economy she describes is not a marginal curiosity. It is, on the evidence of Mercor's valuation, one of the fastest-growing businesses in Silicon Valley, and it represents in concentrated form the central bargain of the AI transition: the conversion of scarce, hard-won, human judgement into abundant, ownable, machine capacity, with the gains flowing to whoever owns the machine and the losses absorbed by whoever supplied the judgement. There is a version of that conversion that is a gift to humanity, the expert diffused to every clinic and classroom that never had one. And there is the version we are building, in which the diffusion is real but the dividend is captured, and the experts are paid by the hour to dig their own seam until it is empty. The technology does not choose between these. We do, through the terms we set, the disclosures we require, the bargaining we permit, and the share of the surplus we insist flows back to the people whose minds made it possible.

Danielle Li was right that economic security has always rested on the scarcity of skill, and right, too, that this foundation is dissolving. But the correct response to a dissolving foundation is not to mourn the scarcity. It is to build a new basis for security that does not depend on shortage — one in which the diffusion of what we know enriches the people who knew it first rather than discarding them. That is a political choice, not a technical one, and it is still, for a little while longer, ours to make. The monster is not the model. The monster is the arrangement whereby we pay the wisest among us, by the hour and below the wage floor, to feed themselves to it, and call the result progress. We can build the abundance without the monster. We are simply, at present, choosing not to.

References & Sources

  1. Lora Kelley, “The Work of Helping A.I. Destroy Work,” The New York Times, 10 July 2026.
  2. “AI Training Startup Mercor Discusses $20 Billion Valuation,” Bloomberg, 9 July 2026.
  3. “Mercor is in talks for a $20B valuation,” TechCrunch, 9 July 2026.
  4. Richard Nieva, “AI Data Labeler Mercor In Talks To Raise $500 Million At $20 Billion Valuation,” Forbes, 9 July 2026.
  5. “Mercor doubles to $2B gross revenue run rate as AI labs buy expert data,” Dealroom, July 2026.
  6. Iain Martin, “The World's Youngest Self-Made Billionaires Just Slashed These Workers' Wages By A Third,” Forbes, 12 November 2025.
  7. Hugh Langley, Grace Kay and Shubhangi Goel, “An AI startup powering Meta and OpenAI cut thousands of workers — then offered them a similar project for less money,” Business Insider, 12 November 2025.
  8. “The Journal” podcast, The Wall Street Journal, interview with Carolina Perez Sands, June 2026.
  9. Danielle Li, opinion essay on artificial intelligence and economic security, Financial Times, March 2026.
  10. Ana-Andreea Stoica, Celestine Mendler-Dünner and Moritz Hardt, “Stochastic wage suppression on gig platforms and how to organize against it,” Max Planck Institute for Intelligent Systems, Tübingen AI Center and ELLIS Institute Tübingen, arXiv:2604.15962, 17 April 2026; published in the Proceedings of the ACM Web Conference 2026.
  11. “Mercor pays over $1.5 million a day to humans training AI, says its CEO,” Yahoo Finance / Reuters, 2026.
  12. “White-collar workers are getting paid $200 an hour to train AI on their jobs — but they say it's not 'easy money',” Moneywise, 2026.
  13. Jaron Lanier and E. Glen Weyl, “A Blueprint for a Better Digital Society,” Harvard Business Review, September 2018.
  14. “AI is a multi-billion dollar industry. It's underpinned by an invisible and exploited workforce,” The Conversation, 2024.
  15. Open letter from data labellers, content moderators and AI workers in Nairobi to President Joseph R. Biden, 22 May 2024.
  16. “Kenyan AI workers form Data Labelers Association,” Computer Weekly, February 2025.
  17. “Mercor says it was hit by cyberattack tied to compromise of open source LiteLLM project,” TechCrunch, 31 March 2026.
  18. “Mercor, a $10 billion AI startup, confirms it was the victim of a major cybersecurity breach,” Fortune, 2 April 2026.
  19. “AI staffing firm Mercor faces lawsuits over data breach,” Staffing Industry Analysts, 2026.
  20. “Meta pauses work with AI data firm after security incident,” Computing, 2026.
  21. Michael Polanyi, The Tacit Dimension (Routledge & Kegan Paul, 1966).
  22. “Mercor Mission — Organizing human intelligence to power the AI economy,” Mercor, 2026.

Tim Green

Tim Green UK-based Systems Theorist & Independent Technology Writer

Tim explores the intersections of artificial intelligence, decentralised cognition, and posthuman ethics. His work, published at smarterarticles.co.uk, challenges dominant narratives of technological progress while proposing interdisciplinary frameworks for collective intelligence and digital stewardship.

His writing has been featured on Ground News and shared by independent researchers across both academic and technological communities.

ORCID: 0009-0002-0156-9795 Email: tim@smarterarticles.co.uk

Listen to the free weekly SmarterArticles Podcast

Discuss...

In mid-September 2025, people who had just been robbed online went looking for the place where you report being robbed online. Some never arrived. Instead of ic3.gov, the Internet Crime Complaint Center operated by the FBI, they landed on ic3-gov.com, or ic3gov.org — domains carrying the Bureau's seal, the IC3 banner and the same institutional blue as the real thing. Analysts identified the first wave on 18 September; the Bureau published a warning the following day, telling the public to type the address manually, check the domain ends in .gov, and ignore sponsored search results.

Ten months later, on 20 July 2026, the same centre issued a further alert, numbered I-072026-PSA, describing something more elaborate. Criminals were no longer merely cloning the website. They were building fake social media profiles for FBI personnel, opening conversations with fraud victims on Facebook Messenger, then moving those conversations to Telegram, where they sent links to spoofed complaint portals harvesting names, telephone numbers, email addresses, the type of scam suffered and the amount lost, before issuing a fabricated reference number and asking for more. And they were circulating AI-generated video of senior FBI officials, urging viewers to file complaints at an address that was not the FBI's, and generating synthetic video for real-time video chats in which the person on the call appeared to be a law enforcement official.

The Bureau's central corrective was blunt and slightly melancholy: the IC3 does not maintain a social media presence, does not contact individuals directly through messaging platforms, and will never ask for payment to recover lost funds. An agency whose entire function is to be the trustworthy destination for people who have just been deceived now spends its public communications explaining the circumstances under which it does not exist.

This is not a new category of crime. Refund and recovery fraud — a stranger promising, for a fee, to retrieve money you have already lost — is old enough to have generated decades of consumer warnings. What has changed is production quality and the precision of the targeting. The question is not whether people should be more careful. It is who, among the platforms carrying the contact, the agency whose face is borrowed and the legislators who have not written the relevant law, is responsible for the second wound.

What the Bureau Has Warned About, Twice Before

The July 2026 alert is the third in a sequence, and the escalation is clearer in retrospect.

The first came on 18 April 2025, reporting that between December 2023 and February 2025 the FBI had received more than one hundred complaints about people impersonating IC3 employees. Contact arrived by email, telephone, social media or online forums. Almost every complainant said the impersonator had claimed either to have recovered their lost funds or to be able to assist in recovering them. The Bureau described one recurring pattern in which scammers created female persona profiles, joined online groups for fraud victims, presented themselves as fellow victims, then referred members to a supposed senior official reachable on Telegram. The tactics were essentially conversational: someone lied to you in writing.

The second, in September 2025, concerned infrastructure rather than personas: look-alike domains intercepting traffic intended for the real portal, and deceptive emails purporting to confirm complaints victims had never submitted.

The third fuses the two and adds synthetic video. Security analysts characterised the scheme as considerably more polished than the earlier warning had described, evolving from text-only approaches into something resembling an official government process from beginning to end: a video of an official, a website that looks like a government website, a form, a reference number, a follow-up. Each element is individually unremarkable. Assembled in sequence, they reconstruct the ritual of reporting a crime to the state.

One detail deserves precision. Reporting describes deepfake videos of senior FBI officials, but neither the alert nor the press coverage appears to identify which officials were depicted; any description of the scheme as targeting a specific, named executive should be treated as unverified.

The FBI's detection advice, repeated from a December 2024 alert on criminal use of generative AI, tells you a great deal about the state of the defence. Look for distorted hands, unrealistic eyes, implausible jewellery, inaccurate shadows, lag between lip movement and voice. These were reasonable heuristics in 2023. As guidance for someone confronted with a short, compressed clip on a phone screen in 2026, they are closer to ritual than method. The July alert concedes as much, noting that AI-generated content has become so sophisticated that it is increasingly difficult to detect. The checklist degrades further still when the synthetic face is on a live call rather than in a recorded clip: nothing can be paused, rewound or examined a second time, and the ordinary pressure to answer while someone waits on the other end removes the interval in which scrutiny would happen. A heuristic that assumes the viewer can look twice is of limited use to a person who cannot look twice.

Why the Freshly Defrauded Are the Most Valuable Targets

The strategic insight behind recovery fraud is that a person who has just lost money is not a worse target than a person who has not. They are a better one.

This is counterintuitive only if you assume that being scammed produces caution. The consumer protection literature has long documented so-called sucker lists — records of prior victims containing name, telephone number, scam type and sum lost, traded among criminal operators on the theory that someone who paid once may pay again. The Federal Trade Commission has warned about these lists and the approach they enable, in which the caller already knows what happened to you — itself the most persuasive credential available.

The academic evidence is stronger than generally appreciated, because one dataset is unusually good. Marguerite DeLiema of the University of Minnesota and Lynn Langton of RTI International analysed two decades of records seized from fraud organisations by the United States Postal Inspection Service, covering more than two million victims. Because this was transactional data rather than survey responses, it recorded what people did rather than what they would admit. Revictimisation rates rose with age in certain scam categories. The ten thousand most frequently responsive individuals had responded to fraudulent solicitations between 82 and 562 times each. Their average age was 78.

That is not a portrait of gullibility. It is a targeting system working as designed, applied repeatedly to people identified as responsive and who are, by the fiftieth approach, in a psychological state the fraud itself produced.

A 2025 qualitative study in the journal Victims and Offenders, based on interviews with twelve cyberscam victim-survivors and eight of their friends and family members, found pervasive impacts: distress, shame, decay of trust, conflict within families, support needs largely unmet. Shame does specific structural work. It discourages disclosure to family, removing the most reliable circuit-breaker in fraud — a second opinion from someone not emotionally invested in the outcome. It also makes the victim receptive to any approach that treats them as a legitimate claimant rather than a fool. Layered on top is escalation of commitment: the more a person has lost, the more expensive it becomes to accept the loss is final. A recovery scam is an offer to undo the first fraud, aimed at someone for whom that has become the organising priority of their week.

What the July 2026 alert adds is timing. The scheme targets people who have recently reported financial fraud or expressed an intention to do so — a window in which two conditions coincide and neither lasts long: financial desperation peaks, and trust in law enforcement is momentarily very high, because the victim has just voluntarily reached out to it. Filing an IC3 complaint is an act of hope. The scheme is built to intercept it.

The underlying market is not small. The Global Anti-Scam Alliance, in a report with the analytics firm Feedzai published in October 2025, surveyed 46,000 adults across 42 markets: 57 per cent had encountered a scam in the previous twelve months, 23 per cent had lost money, and only around 30 per cent of those who reported to their payment provider recovered anything. That gap is the space recovery fraud occupies.

A Record Year and the Cohort Absorbing It

The FBI's 2025 Internet Crime Report, published in April 2026, supplies the backdrop. The IC3 received 1,008,597 complaints, the first time in its twenty-five-year history that annual volume exceeded one million. Reported losses reached $20.877 billion, a 26 per cent increase on the $16.6 billion recorded in 2024.

Investment fraud remained the largest driver at more than $8.6 billion, followed by business email compromise at more than $3 billion and technical support fraud at $2.1 billion. Cryptocurrency featured in more than $11 billion of losses across 181,565 complaints. For the first time the report used AI-related as a formal descriptor, recording 22,364 complaints and roughly $893 million in losses — a floor rather than a measurement, since it captures only cases where the victim knew, and thought to say, that artificial intelligence was involved.

The elder fraud figures make the recovery scam legible as a strategy. Americans aged 60 and over filed 201,266 complaints in 2025 and reported losses of $7.75 billion, an annual increase of 59 per cent. The average loss in that group was around $38,500, and roughly 12,400 individuals lost more than $100,000 each. Investment fraud accounted for $3.52 billion of that total and technical support fraud for $1.04 billion. Complainants over 60 made up roughly a fifth of all complaints but close to 37 per cent of all reported losses.

The Federal Trade Commission's data tells a compatible story by a different method. Consumers filed more than a million imposter scam reports in 2025 and reported $3.5 billion in losses, making impersonation the most-reported fraud category for the fifth consecutive year. Around $920 million was attributed to government impersonators, up from $789 million in 2024, with such reports rising about 40 per cent year on year.

What the Evidence Actually Supports About Age and Synthetic Media

It is tempting to close the loop between those datasets by asserting that older adults are least able to recognise AI-generated video and audio and are therefore uniquely exposed. The claim is plausible. It is also more slippery than it looks, and the published research supports a narrower version than the one usually stated.

Start with what is reasonably well evidenced: awareness. A study by the biometric authentication firm iProov, based on 2,000 consumers in the United Kingdom and United States exposed to genuine and synthetic images and video, found that 30 per cent of respondents aged 55 to 64 and 39 per cent of those aged 65 and over had never heard of deepfakes at all, against 22 per cent overall. You cannot look for something you do not know exists.

The same study cuts against any simple generational framing. Only 0.1 per cent of participants correctly identified every genuine and synthetic item shown, participants were around 36 per cent less likely to identify a synthetic video than a synthetic image, and adults aged 18 to 34 displayed the largest gap between measured performance and self-assessed confidence. If detection is the defence, the defence is failing across the age range, and the group most likely to over-trust its own judgement is not the oldest.

Direct experimental evidence on age and accuracy is thinner than the discourse suggests. A study of audiovisual deepfake perception by Ammarah Hashmi and colleagues, which asked 110 participants to judge forty videos, reported that its oldest age band performed less accurately than younger bands — but that band was 41 to 50. It says nothing directly about people over 60, because it did not measure them separately. It also found every AI model tested outperformed every human, and that people systematically overestimated their own ability.

Qualitative work has looked specifically at seniors. Research by Zhiwei Tang, Dion Goh, Chei Sian Lee and Yang Yang, based on interviews with twenty participants aged 55 to 70, found they gravitate towards judgements about the authenticity of the video's subject rather than peripheral technical details, preferring intuition over consulting other people or verification resources. A comparative study in the International Journal of Human–Computer Interaction found both groups drawing on similar cue categories, with seniors leaning more on accumulated life experience.

That is more useful than an accuracy ranking, and it explains the scheme's design. If older adults assess a video by asking whether the person in it seems authentic, rather than inspecting shadows and hand geometry, a synthetic clip of a plausible official speaking plausible institutional language defeats the strategy at the point it is applied. The vulnerability is not primarily perceptual. It is that the heuristic in use is the one generative video is now good at satisfying.

One further consideration is lost in the focus on detection. The FBI's Operation Level Up, which proactively identifies people being defrauded and telephones them, notified 3,780 victims during 2025 and estimates it prevented $225.9 million in losses. Seventy-eight per cent of those contacted did not know they were being scammed. Detection was not failing at the margin. It was absent.

First Contact Happens on Someone Else's Platform

Every version of this scheme begins somewhere. In the July 2026 alert it begins on Facebook Messenger and migrates to Telegram, with deepfake videos circulating on social platforms to drive traffic. That is a specific, addressable fact about infrastructure, not an act of God.

Meta has not been idle. In March 2026 it announced a package of anti-scam measures, reporting that it had removed 159 million scam advertisements during 2025, with 92 per cent taken down before any user reported them, and disabled 10.9 million accounts across Facebook and Instagram linked to organised scam centres. In February 2026 it filed lawsuits against deceptive advertisers in Brazil, China and Vietnam, and set a target of raising the share of advertising revenue from verified advertisers from 70 to 90 per cent by the end of 2026.

Those are not trivial numbers, but they concern advertising and mass-scale account networks. The IC3 scheme requires neither. It requires one fake profile, one direct message to a person who has just posted in a fraud victims' support group, and a link. Direct messaging between two consenting parties is the hardest surface on any platform to police, and it is where this scheme lives.

Telegram is the second half of the pattern, and the conversation is moved there deliberately. The platform's posture shifted after the arrest of its founder Pavel Durov in France in August 2024, part of an investigation into insufficient moderation of illegal activity, after which Telegram began cooperating with law enforcement and expanded takedowns. Security researchers report enforcement at extraordinary scale — tens of millions of channels and groups blocked during 2025. The same research finds criminal ecosystems on the platform are not shrinking: groups use join-request gating to defeat automated moderation and maintain pre-built backup channels allowing near-instant reconstitution after removal.

This is the recurring shape of platform enforcement statistics: volume of removals measures activity, not outcome. A scheme that needs one working channel at a time, and can rebuild it in minutes, is largely indifferent to a takedown rate expressed in hundreds of thousands per day.

There is also a structural blind spot no enforcement budget resolves. Once a conversation moves into an encrypted direct message the platform has no view of its contents, and the design decision producing that blindness is the same one producing the privacy guarantee users are entitled to expect. Any proposal to fix scam contact by giving platforms visibility into private messages is a proposal to remove encryption. Direct-message fraud must therefore be addressed through weaker signals — account age, behavioural patterns, the profile claiming to represent a federal agency.

Two Continents and Two Answers on Platform Duty

Whether any of this becomes a legal obligation depends enormously on jurisdiction.

In the United States, Section 230 of the Communications Decency Act has historically meant a platform is not the publisher of a fake FBI profile created by a user, and that losses flowing from it are not the platform's to answer for. The precedent most on point is unhelpful to victims: in Herrick v. Grindr, involving an impersonating profile used to direct strangers to the plaintiff, the court dismissed the claim even where the harm was framed as a product defect, because the injury still originated in content supplied by another user.

That settlement is being tested. On 10 April 2026 the Massachusetts Supreme Judicial Court ruled unanimously in Commonwealth v. Meta Platforms that Section 230 did not immunise Meta from state consumer-protection and tort claims where the alleged harms stemmed from the company's own conduct — the design of platform features and misleading statements about safety — rather than from third-party content. The case concerns Instagram's effects on children rather than fraud, but the reasoning is portable: if a claim can be framed around how a service was built and what its operator said about it, the immunity does less work. Litigation directly about scam advertising is under way, including a class action filed against Meta in April 2026 alleging that the company profits from scam advertisements while misleading users.

Europe imposes systemic duties instead of litigating individual harms. Under the Digital Services Act, large platforms must maintain effective mechanisms against fraudulent advertising and mitigate the resulting risks. On 21 May 2026 the European consumer organisation BEUC, with 29 member groups, filed complaints against Meta, Google and TikTok with the European Commission and national Digital Services Coordinators. Between December 2025 and March 2026 the groups flagged almost 900 advertisements suspected of breaching EU law. The platforms removed 27 per cent; 52 per cent of reports were rejected or ignored. BEUC estimates the fraudulent advertising still running reaches more than 200 million European consumers a month.

The United Kingdom's approach under the Online Safety Act reached a concrete stage almost exactly as the FBI published its alert. On 10 July 2026 Ofcom opened a consultation, running until 2 October, on a draft Fraudulent Advertising Code of Practice containing close to forty measures for the largest categorised services: banning fraudulent advertisers and preventing re-registration, verifying advertiser identity, and testing AI-driven ad creation tools for misuse. Non-compliance carries penalties up to £18 million or 10 per cent of global revenue.

The limitation is written into the scope. The draft code covers paid advertising. It does not cover user-generated content, and it does not cover organic search results. A deepfake video posted to a feed rather than bought as an advertisement, followed by a direct message from a fake profile, falls outside it. The most advanced fraud-specific platform regulation in the democratic world addresses the part of the IC3 scheme that is optional, and not the part that is essential.

The Domain Nobody Can Quite Protect

The FBI's advice — type ic3.gov manually, check the .gov — reflects a real structural advantage and a real structural limit.

The advantage is that .gov is a genuinely controlled space. Under the DOTGOV Act of 2021, the Cybersecurity and Infrastructure Security Agency administers the top-level domain, restricting registration to verified United States federal, state, local, tribal and territorial entities, mandating multi-factor authentication and enforcing HTTPS. Nobody registers a fraudulent .gov domain, because nobody can.

The limit is that this forces the fraud one character sideways. The September 2025 spoofs used ic3-gov.com and ic3gov.org: ordinary commercial domains, registrable in minutes by anyone with a payment method, and no mechanism exists by which CISA or the FBI can prevent their creation. Suppression happens afterwards, through abuse reports to registrars and hosting providers, and the timing is unfavourable. Academic analysis of phishing domain lifecycles finds that although some malicious sites vanish within hours, the average interval between detection and deregistration runs to roughly 11.5 days, and squatted domains impersonating a specific brand persist on the order of three weeks. A scheme that needs the site live only long enough for a victim who received a Telegram link this morning to complete a form this afternoon is entirely compatible with an eleven-day takedown.

Provenance signalling is the technology most often proposed for the video half of the problem. The Coalition for Content Provenance and Authenticity has assembled a substantial standard and a very large membership, and the idea is sound: cryptographically sign content at creation so that origin and edit history travel with it. But C2PA manifests are removable by design and fragile in practice. Embedded manifests are lost whenever a file is re-saved by a tool that is not provenance-aware, and mainstream platforms routinely re-encode media on upload, stripping credentials as a by-product of transcoding rather than by deliberate act. Durable variants combining watermarking and fingerprinting improve matters, but the asymmetry remains: provenance proves that something is what it claims to be, and cannot prove that unsigned content is fake. Where most authentic video also carries no credential, absence of provenance signals nothing.

Detection is the other proposed answer, and the honest reading is discouraging. Deepfake detectors routinely report accuracy above 99 per cent on established academic benchmarks. Evaluated against Deepfake-Eval-2024, built from synthetic media actually circulating on social platforms, state-of-the-art open-source models fell precipitously, with reported reductions in area-under-curve of around 50 per cent for video, 48 per cent for audio and 45 per cent for images. Detectors are good at recognising the generators they were trained on. The generator used to make next month's video does not exist yet.

An Impersonation Statute Written for Badges, Not Pixels

The legal position in the United States is not that impersonating an FBI official is lawful. It is that the statutes were written for a different medium and scaled for a different volume.

Section 912 of Title 18 of the United States Code makes it an offence to falsely pretend to be an officer or employee of the United States and either act as such or, under that pretence, obtain anything of value. The maximum sentence is three years. It is adequate for the person who flashes a false badge, and adequate for whoever runs the IC3 scheme — assuming they are within reach of American jurisdiction, which offshore fraud infrastructure makes unlikely. What it does not reach is the production of the synthetic video, or any duty for the intermediaries distributing it.

The Federal Trade Commission's Government and Business Impersonation Rule, in force since 1 April 2024, is more modern. It prohibits fraudulent impersonation of government agencies and their officers, and lets the Commission seek monetary redress directly in federal court. When it finalised that rule the Commission simultaneously proposed extending the prohibition to impersonation of individuals, citing AI-generated deepfakes as a technology threatening to turbocharge impersonation fraud, and floated a provision imposing liability on parties supplying goods or services — including AI tools — with reason to know they would be used for unlawful impersonation. After an informal hearing in January 2025 the Commission indicated it would not proceed with that means-and-instrumentalities provision, and as of mid-2026 regulatory trackers record the extension to individuals as unfinalised. The proposal that would have reached the toolmakers is the one that was dropped.

Federal deepfake legislation exists but is narrow. The TAKE IT DOWN Act, signed on 19 May 2025, criminalises knowing publication of non-consensual intimate imagery including AI-generated digital forgeries, and requires covered platforms to remove reported material within 48 hours; platforms had until 19 May 2026 to build the process, and the FTC began enforcement that month. It is a real law with real teeth and nothing to say about a synthetic FBI official, because its subject is intimate imagery. The NO FAKES Act, which would create a federal property right in an individual's voice and visual likeness against unauthorised digital replicas, was advanced by the Senate Judiciary Committee on 18 June 2026 and is closer to enactment than in any previous session, but is still not law — and would primarily empower the depicted individual, here a serving federal official suing over a video that has already emptied someone's savings account. State law is dense but uneven: most states have enacted legislation addressing AI-generated media, roughly thirty have election-specific provisions, and every state has non-consensual intimate imagery protections, though many predate generative AI. The coverage is real; the coherence is not, and none of it binds a criminal operating from outside the country.

The European Union is about to attempt transparency at scale. Article 50 of the AI Act imposes obligations applying from 2 August 2026: deployers producing deepfakes — content resembling existing persons or events and falsely appearing authentic — must disclose it, and outputs of generative systems must be identifiable as artificially generated in machine-readable form. Under the Digital Omnibus agreement the general transparency duties bite on that date, while the machine-readable marking obligation is deferred to 2 December 2026 for systems already placed on the market before it. Infringements can attract penalties up to €15 million or 3 per cent of worldwide turnover. The gap is obvious. Criminals will not label their output, and the penalties are calibrated for corporate non-compliance rather than criminal enterprise. What Article 50 may achieve is a norm in which unmarked synthetic content becomes anomalous. That is worth something. It is not protection.

The Case for Restraint

There are decent arguments against every intervention above, and they deserve stating properly rather than as formality.

Criminalising synthetic impersonation of officials in broad terms would collide with the First Amendment. Depictions of government figures are core political speech, and satire, parody and criticism routinely involve putting words into the mouths of public officials. A statute drawn tightly enough to catch a fraudulent recovery-scam video, and loose enough to survive drafting by a legislature under pressure, is likely to catch protected expression too. Fraud-specific framing — requiring intent to deceive for financial gain — narrows the problem, but largely duplicates fraud statutes that already exist.

Platform liability rules carry a documented failure mode. Where a service faces penalties for content it fails to remove and none for content it removes wrongly, the rational response is aggressive removal, and the material caught in that net is disproportionately produced by people without resources to appeal. A 48-hour takedown obligation is defensible for a narrow category. Generalised to impersonation — which includes every parody account and every critical commentary adopting an institutional voice — it becomes something else.

Provenance and detection both invite over-reliance. If the public is trained to treat a content credential as proof of authenticity, the first successful credential-laundering technique produces harm greater than the tool prevented, because it exploits a trust the tool created. And a detection system right 95 per cent of the time tells five per cent of victims their genuine evidence is fake.

There is also a case that resources are better spent elsewhere. A randomised controlled trial by DeLiema, M. Daniel Brannock, Edward Preble and Langton, published in Innovation in Aging in 2024, tested mailed interventions with prior fraud victims. A single warning letter from the Postal Inspection Service reduced revictimisation by 8.6 per cent over four months; the same letter followed by five further mailings achieved a 22.4 per cent reduction. That is an unglamorous intervention delivered by post, and it protected a population no deepfake detector has ever helped. The cheapest thing demonstrably working is a letter.

Where the Cost of Vigilance Actually Lands

The advice at the end of the FBI's alert is sound, and worth reading for what it assumes. Type the address manually. Avoid sponsored search results. Verify the .gov. Do not trust social media profiles or messaging apps claiming to represent the IC3. Look for distorted hands and inaccurate shadows.

Every one of those instructions transfers a cost onto the person least able to bear it. The recipient has just lost money. They may be in their seventies. They may not know what a sponsored search result is, or why a domain suffix matters, or that ic3-gov.com and ic3.gov are not variants of the same thing. Asking them to perform forensic analysis on a video asks them to succeed where 99.9 per cent of iProov's participants failed.

There is a deeper incoherence in the advice, and it is nobody's fault. The IC3 says it will never contact you. But Operation Level Up exists precisely because the FBI does contact victims — proactively, by telephone, unsolicited — and 78 per cent of those it reached in 2025 had no idea they were being defrauded until the Bureau told them. The public is asked to hold two rules at once: an unsolicited approach from the FBI is a red flag, and an unsolicited approach from the FBI may be the intervention that saves your retirement. Distinguishing them requires exactly the institutional literacy this cohort has least of, and that the scheme is engineered to exploit.

That incoherence is the argument for shifting the burden. Not because individuals bear no responsibility, but because the current allocation is arithmetically absurd. On one side is a person defrauded once, in the worst week of their financial life, asked to authenticate synthetic video. On the other are entities that can act structurally: the platform that can require verification before an account claims to represent a federal agency; the registrar that can decline to sell ic3-gov.com; the agency that can establish a single cryptographically verifiable channel through which victims confirm a complaint's status; and the legislature that can extend a mid-century impersonation statute to the medium in which impersonation now happens, and finalise a rulemaking it began in 2024.

None of these is difficult in the way detecting deepfakes is difficult. They are difficult in the way assigning liability is always difficult, which is to say politically rather than technically. The IC3 scheme is not a story about the frontier of artificial intelligence; the tools involved are commodity products. It is a story about an institution whose credibility is its only real asset discovering that credibility is cheap to counterfeit and expensive to defend, and about a legal architecture that has not decided whose problem that is.

The scheme's designers have already answered the question. They decided it was the victim's problem, and built accordingly.

References

  1. FBI Internet Crime Complaint Center, “FBI Warns of Scammers Impersonating the IC3,” Alert Number I-072026-PSA, 20 July 2026. https://www.ic3.gov/PSA/2026/PSA260720
  2. FBI Internet Crime Complaint Center, “FBI Warns of Scammers Impersonating the IC3,” Alert Number I-041825-PSA, 18 April 2025. https://www.ic3.gov/PSA/2025/PSA250418
  3. FBI Internet Crime Complaint Center, “Threat Actors Spoofing the FBI IC3 Website for Possible Malicious Activity,” 19 September 2025. https://www.ic3.gov/PSA/2025/PSA250919
  4. FBI Internet Crime Complaint Center, “Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud,” 3 December 2024. https://www.ic3.gov/PSA/2024/PSA241203
  5. Federal Bureau of Investigation, “Cryptocurrency and AI Scams Bilk Americans of Billions,” April 2026. https://www.fbi.gov/news/press-releases/cryptocurrency-and-ai-scams-bilk-americans-of-billions
  6. Federal Bureau of Investigation, “Operation Level Up,” accessed 25 July 2026. https://www.fbi.gov/how-we-can-help-you/victim-services/national-crimes-and-victim-resources/operation-level-up
  7. Federal Trade Commission, “FTC Data Show People Reported Losing $3.5 Billion to Imposter Scams in 2025,” June 2026. https://www.ftc.gov/news-events/news/press-releases/2026/06/ftc-data-show-people-reported-losing-3-point-5-billion-imposter-scams-2025
  8. Federal Register, “Trade Regulation Rule on Impersonation of Government and Businesses,” 1 March 2024. https://www.federalregister.gov/documents/2024/03/01/2024-04335/trade-regulation-rule-on-impersonation-of-government-and-businesses
  9. Congress.gov, “S.4591 — NO FAKES Act of 2026, 119th Congress,” 2026. https://www.congress.gov/bill/119th-congress/senate-bill/4591/text
  10. Massachusetts Supreme Judicial Court, “Commonwealth v. Meta Platforms, Inc.,” SJC-13747, 10 April 2026. https://law.justia.com/cases/massachusetts/supreme-court/2026/sjc-13747.html
  11. Gibson Dunn, “EU AI Act Omnibus Agreement — Postponed High-Risk Deadlines and Other Key Changes,” 2026. https://www.gibsondunn.com/eu-ai-act-omnibus-agreement-postponed-high-risk-deadlines-and-other-key-changes/
  12. BEUC, “Consumer groups file complaints against Meta, TikTok and Google for failing to protect consumers against financial scams,” 21 May 2026. https://www.beuc.eu/press-releases/consumer-groups-file-complaints-against-meta-tiktok-and-google-failing-protect
  13. Ofcom, “Consultation: Fraudulent Advertising Code of Practice, Volume 1 — Context,” 10 July 2026. https://www.ofcom.org.uk/siteassets/resources/documents/consultations/category-3-4-weeks/consultation-fraudulent-advertising-code-of-practice/main-documents/volume-1-context.pdf
  14. Meta, “Fighting Scammers and Protecting People With New Technology and Partnerships,” March 2026. https://about.fb.com/news/2026/03/fighting-scammers-protecting-people-with-new-technology-and-partnerships/
  15. Check Point Research, “Telegram's Crackdown in 2026 and Why Cyber Criminals Are Still Winning,” 2026. https://blog.checkpoint.com/research/telegrams-crackdown-in-2026-and-why-cyber-criminals-are-still-winning/
  16. Marguerite DeLiema and Lynn Langton, “Older Victims of Mass Marketing Scams: An Analysis of Data Seized From Scammers,” Innovation in Aging, December 2021. https://pmc.ncbi.nlm.nih.gov/articles/PMC8679313/
  17. Marguerite DeLiema, M. Daniel Brannock, Edward Preble and Lynn Langton, “A Fraud Awareness Mail Campaign Significantly Reduces Rates of Revictimization Among Older Victims,” Innovation in Aging, 2024. https://pmc.ncbi.nlm.nih.gov/articles/PMC11689558/
  18. Cazanis, Carminati, Chew, Cross, Ponsford and Gould, “'Falling into a Black Hole': A Qualitative Exploration of the Lived Experiences of Cyberscam Victim-Survivors and Their Social Support Networks,” Victims and Offenders, 2025. https://www.tandfonline.com/doi/full/10.1080/15564886.2025.2481267
  19. iProov, “Study Reveals Deepfake Blindspot: Only 0.1% of People Can Accurately Detect AI-Generated Deepfakes,” 2025. https://www.iproov.com/press/study-reveals-deepfake-blindspot-detect-ai-generated-content
  20. Ammarah Hashmi, Sahibzada Adil Shahzad, Chia-Wen Lin, Yu Tsao and Hsin-Min Wang, “Unmasking Illusions: Understanding Human Perception of Audiovisual Deepfakes,” arXiv:2405.04097, 2024. https://arxiv.org/abs/2405.04097
  21. Zhiwei Tang, Dion Hoe-Lian Goh, Chei Sian Lee and Yang Yang, “Understanding strategies employed by seniors in identifying deepfakes,” Aslib Journal of Information Management, 2026. https://www.emerald.com/ajim/article/78/2/430/1248679/Understanding-strategies-employed-by-seniors-in
  22. “Understanding Deepfake Detection Strategies Among Young Adults and Seniors,” International Journal of Human–Computer Interaction, 2025. https://www.tandfonline.com/doi/full/10.1080/10447318.2025.2607571
  23. “Deepfake-Eval-2024: A Multi-Modal In-the-Wild Benchmark of Deepfakes Circulated in 2024,” arXiv:2503.02857, 2025. https://arxiv.org/html/2503.02857v1
  24. “Registration, Detection, and Deregistration: Analyzing DNS Abuse for Phishing Attacks,” arXiv:2502.09549, 2025. https://arxiv.org/pdf/2502.09549
  25. Global Anti-Scam Alliance and Feedzai, “Global State of Scams Report 2025,” 7 October 2025. https://gasa.org/knowledge-base/reports/global-state-of-scams-2025

Tim Green

Tim Green UK-based Systems Theorist & Independent Technology Writer

Tim explores the intersections of artificial intelligence, decentralised cognition, and posthuman ethics. His work, published at smarterarticles.co.uk, challenges dominant narratives of technological progress while proposing interdisciplinary frameworks for collective intelligence and digital stewardship.

His writing has been featured on Ground News and shared by independent researchers across both academic and technological communities.

ORCID: 0009-0002-0156-9795 Email: tim@smarterarticles.co.uk

Listen to the free weekly SmarterArticles Podcast

Discuss...

You have done everything right. You read the job description twice, tailored the application, rehearsed the difficult questions in the shower, ironed the shirt that only the top half of the camera will ever see. You log in two minutes early, because being early is a habit you cannot break, and you wait. A box appears. A voice, smooth and untroubled, begins to speak. It thanks you for your time. It asks you to describe a moment when you overcame a significant challenge. And somewhere in the second sentence of your carefully prepared answer, a quiet realisation settles over you like cold water: there is no one there. The voice is not listening in any sense you would recognise. The chair on the other side of the conversation is empty. You are performing sincerity, vulnerability, ambition, for a system that will compress all of it into a vector and a score.

This is no longer a fringe experience or a Silicon Valley curiosity. It has become, with startling speed, one of the most common ways that people in the United States, the United Kingdom and Australia now encounter the labour market. And it is producing a strange new emotion that does not yet have a settled name: the feeling of having prepared, in good faith, to be seen by someone who was never going to be there.

The Scale of the Empty Chair

In May 2026, the hiring software company Greenhouse published the results of a survey of 2,950 active job seekers across the United States, the United Kingdom, Germany, Ireland and Australia. The headline figure was the kind of number that makes you read it twice. Sixty-three per cent of candidates reported that they had already been interviewed by an AI. Six months earlier, the same measure had stood thirteen percentage points lower. Whatever the future of work is, it is not arriving gradually. It is arriving in quarters.

What gives the Greenhouse data its particular sting is not the adoption rate, impressive though it is, but the asymmetry that surrounds it. Seventy per cent of candidates said they were never clearly told, ahead of time, that an AI would be the thing evaluating them. For roughly one in five, the discovery came only once the interview had already begun: the box opened, the voice started, and the human they had braced themselves for simply failed to materialise. Thirty-eight per cent of those surveyed had already withdrawn from a hiring process specifically because it involved an AI interview with no human present, and a further twelve per cent said they would do the same if asked. Only eighteen per cent believed their prospective employers had any clear policy governing how AI was used to judge them.

The numbers compound into something close to a paradox. A practice that half of all candidates find serious enough to walk away from is being deployed, at scale, without disclosure, without policy, and without consent. Daniel Chait, the chief executive of Greenhouse, put the diagnosis bluntly when the survey landed: most AI in hiring today, he said, is making a bad system worse, generating more applications, less signal and less transparency. His chief people officer, Sharawn Tipton, was sharper still. Seventy per cent of job seekers, she noted, were not told AI was involved at all. AI, in her phrasing, is not fixing bias; it is scaling it.

The downstream experience is no kinder. Of the candidates who completed an AI interview, the Greenhouse figures suggest only around twenty-eight per cent were moved forward, thirteen per cent were formally rejected, and a remarkable fifty-one per cent received no feedback whatsoever. They were neither advanced nor turned away. They were simply left in the silence that follows a conversation with no one in it.

A New Name for an Old Injury

In January 2026, a paper appeared on the preprint server arXiv that gave this whole landscape a piece of vocabulary it had been missing. Written by Ibrahim Denis Fofanah of the Seidenberg School of Computer Science and Information Systems at Pace University, and titled “The Algorithmic Barrier: A Framework for Artificial Frictional Unemployment and Information Asymmetry in Automated Recruitment Systems”, it proposed that a meaningful share of contemporary joblessness is, in a precise and unsentimental sense, manufactured. Not by recession, not by automation eating the jobs themselves, but by the machinery that is supposed to connect people to the work that already exists.

To understand why “artificial frictional unemployment” is such a loaded phrase, it helps to know where the unloaded version comes from. Frictional unemployment is one of the oldest and most respectable ideas in labour economics. It describes the joblessness that exists simply because matching workers to firms takes time: a vacancy cannot be filled instantly, and a person cannot sift through every posting at once. The economists Peter Diamond, Dale Mortensen and Christopher Pissarides built an entire formal apparatus, the search-and-matching framework, around exactly this problem, work that earned them the 2010 Nobel Memorial Prize in Economic Sciences. In their account, friction is natural, even healthy. It is the cost of a dynamic economy in which people change jobs, firms open and close, and information is never perfect. Full employment, in this tradition, has never meant zero unemployment; it has always included a residue of people in motion between roles.

What Fofanah's paper argues is that we have begun, quietly and at scale, to add friction that has nothing to do with any of that. The new friction is not the natural cost of search. It is an artefact of design. Applicant tracking systems and automated screening tools, the paper contends, have reframed hiring as a high-precision classification problem, one tuned above all to avoid the embarrassment of a bad hire. In statistical terms, the systems are optimised to minimise false positives, the unsuitable candidate who slips through. The predictable consequence is a surge in false negatives: qualified people quietly discarded because the language in which they describe themselves does not align with the language the machine has been told to look for. A nurse who has used clinical software for a decade is filtered out for lacking “computer experience”. A designer is rejected for not listing a degree in programming. The skill is real. The signal is lost in translation.

This is the heart of the concept. Artificial frictional unemployment is the joblessness of people who are not, in any genuine sense, unsuitable. They are simply illegible to the system reading them. The paper's proposed remedy is technical, a candidate-side architecture called JobOS that would standardise, verify and semantically translate a person's competencies into a form the machines can parse. The accompanying simulation is careful about what it claims: a controlled proof of concept built to demonstrate the mechanism rather than measure its scale, showing that variation in wording alone is enough to manufacture false negatives, and that semantic competency mapping recovers applicants a keyword system wrongly discards. What it does not establish, as Fofanah says plainly, is how much real-world friction is artificial, a question he leaves to future field studies. That restraint deserves respect. The deeper contribution is conceptual. It hands a name to an experience millions of people have had and could not quite describe: the sense of being rejected not for who you are, but for how badly you compressed.

The Hidden Worker Was Already Here

If this all sounds suspiciously like a problem invented by the latest wave of generative AI, it is worth remembering that the mechanism predates the chatbots by years. In 2021, researchers at Harvard Business School, working with Accenture, published a study that has aged into something close to prophecy. They coined the term “hidden workers” to describe people who are perfectly capable of doing a job but rendered invisible to employers by the very systems designed to find them. Their estimate of the scale was extraordinary: more than twenty-seven million such workers in the United States alone, locked out not by a deficit of skill but by a deficit of recognition.

The detail that haunts the report is not the headline number but the admission buried inside it. Eighty-eight per cent of the employers surveyed conceded that their own screening tools were filtering out qualified candidates. They knew. Nearly nine in ten companies were aware that their automated gatekeepers were rejecting people who could do the work, and the overwhelming majority had no plan to do anything about it. With algorithmic screening now embedded in virtually every large employer, the gap between what these systems filter and what the job actually requires has become one of the quietest structural failures in the modern economy.

What the 2026 wave of AI interviewing adds to this older story is a cruel new intimacy. The applicant tracking system rejected you in private, before you had invested much of yourself. You sent a CV into a void and heard nothing, and while that is dispiriting, it is at least impersonal in a way that protects you. The AI interview asks for more. It asks you to show up, to be present, to be vulnerable on camera, to talk about the time you failed and what you learned, and then it processes that performance with the same indifference the CV-screener applied to your keywords. The friction has been moved closer to the bone. You are no longer filtered before you speak. You are invited to speak, at length, to no one.

Strip away the technology for a moment and you are left with a question that is really about manners, and beneath manners, about power. When seventy per cent of candidates are not told that a machine will judge them, and only eighteen per cent of employers have any clear policy on the matter, what has actually broken is not an algorithm. It is the most basic norm of reciprocity that has always underpinned the act of applying for work.

An interview, historically, has been a two-way evaluation dressed up as a one-way one. Yes, the employer is assessing the candidate. But the candidate is also reading the room: gauging the warmth or coldness of the interviewer, noticing whether questions are thoughtful or rote, deciding whether these are people they could stand to work alongside. The exchange is asymmetric in power, certainly, but it is mutual in information. Both sides learn something. Both sides are, however briefly, exposed to each other.

The undisclosed AI interview collapses that mutuality entirely. The candidate is fully exposed, on camera, performing sincerity in real time, while the other side of the table offers nothing back: no face to read, no warmth to gauge, no reciprocal vulnerability, often not even the courtesy of having been told that this is what was going to happen. The Greenhouse data captures how acutely people feel this imbalance. Fifty-seven per cent of candidates said they believed disclosure of AI use ought to be a legal requirement. When more than half of the people subjected to a practice think it should be illegal to do it to them without warning, you are not looking at a user-experience problem. You are looking at a legitimacy problem.

It would be one thing if candidates were rejecting AI outright, retreating into nostalgia for the all-human interview with all its own well-documented biases and inconsistencies. They are not. The same survey found that most people want roughly the same amount of AI, or even more, but with guardrails: forty-four per cent want it disclosed upfront, thirty-nine per cent want a clear explanation of what the AI is actually measuring, forty-six per cent want the option to request a human interview instead, and thirty-eight per cent want a human being to review the AI's verdict before it becomes final. These are not the demands of Luddites. They are the demands of people asking to be told the rules of a game they have already been forced to play.

The Psychology of Being Unseen

There is a particular kind of injury that the empty chair inflicts, and it is worth taking seriously rather than dismissing as squeamishness about new tools. To be seen, properly seen, by another person is one of the deepest social needs human beings have. The job interview, for all its artifice and stress, is one of the few remaining institutional moments in adult life where you present your whole working self to a stranger and ask, in effect, to be recognised as worthy. When that stranger turns out to be a script with a synthesised voice, something in the transaction curdles.

Candidates reaching for language to describe the experience keep landing on the same words. They say it feels awkward, humiliating, dystopian. They describe a one-way interaction with a system that cannot see nuance, cannot answer a clarifying question, cannot register the context that a human interviewer would absorb without thinking. They talk about being reduced to keyword matches and algorithmic calculations, about being processed rather than considered. That last distinction, processed versus considered, is the whole thing in miniature. To be considered is to have someone weigh you, attend to you, hold your particulars in mind. To be processed is to be run through a pipe. Tipton, at Greenhouse, named exactly this when she observed that candidates feel processed rather than considered, and that the bad experiences travel: people share them, and an employer's reputation erodes one humiliating interview at a time.

The dignity at stake here is not a soft concept. Researchers studying AI in recruitment have begun to argue that automated assessment has, specifically, a dignity problem, distinct from its accuracy problem, because it treats people without regard at precisely the moments when they are most exposed and most human. When a rejection arrives through a process that feels opaque, robotic and indifferent, the harm is not only practical, the lost income, the prolonged search. The harm is to your sense of being a person whose effort registered somewhere. You prepared for a conversation. You got a transaction. And then, more than half the time, you got nothing at all, not even the closure of a no.

It is worth being honest that the picture is not uniformly grim, and the better operators in this space know it. Sapia.ai's “Humanising Hiring” research, published in September 2025, drew on more than a million AI chat interviews and eleven million words of candidate feedback across more than thirty countries, reporting average candidate satisfaction of 9.05 out of ten. Many candidates, it found, preferred a well-designed AI conversation to a rushed or distracted human one, saying the AI felt more patient, more consistent, less prone to snap judgement. Kathi Enderes, SVP Research and Global Industry Analyst at The Josh Bersin Company, called it one of the most comprehensive examinations of candidate experience to date. The caveat belongs in the open: this is a vendor reporting on the reception of its own product, measured with its own instrument, and satisfaction data gathered by the party under evaluation tends to flatter. It should be weighed carefully rather than waved away; the sample is enormous and the finding is not implausible. A bored recruiter glancing at the clock is not a gold standard worth defending. The problem the 2026 data exposes is not that AI is inherently more dehumanising than a human. It is that AI deployed without disclosure, without explanation, without a human fallback and without any feedback at the end is dehumanising, and that this careless version is the one most people are actually meeting.

What It Does to Trust

Trust, in the employment relationship, has always run on a kind of advance credit. You apply to a company believing, provisionally, that it will treat your candidacy in good faith: that a real person will at least glance at your effort, that the process is what it claims to be, that the firm is the kind of place that behaves decently toward people it has not yet hired. The undisclosed AI interview spends that credit recklessly. The first substantive thing the company tells you about how it operates is that it was willing to let you talk to a machine without mentioning it. Whatever else you learn later, you have already learned that.

The damage runs in both directions, which is the part employers tend to miss. Tipton has pointed out that recruiters themselves are inundated and anxious, worried about being automated out of their own jobs, and that there is a trust gap on both sides of the table. The AI interview did not appear because hiring teams are villains. It appeared because application volumes, inflated in no small part by candidates using AI to fire off hundreds of tailored applications, have become genuinely unmanageable. One set of machines is answering another. The human beings at both ends are increasingly bystanders to a conversation between systems, each side suspecting, correctly, that the other is not really there.

This is the trap that the labour market is sleepwalking into: an arms race in which candidates automate their applications because employers automate their screening, employers automate their screening because candidates automate their applications, and the signal that the whole edifice exists to transmit, can this person actually do this job and would we want them here, gets drowned in the noise that both sides are generating to cope with the noise. Trust is the first casualty, and trust is expensive to rebuild. An employer that treats applicants as inputs to be processed should not be surprised when the best of them, the ones with options, the ones confident enough to walk, do exactly that. The thirty-eight per cent who have already withdrawn are not a random sample. They disproportionately include the people any sane organisation would most want to hire.

The Economics of Discarded Signal

Zoom out from the individual humiliation and a macroeconomic shape comes into view, and it is not flattering to anyone. The polite economic story about frictional unemployment has always been that the friction is, on balance, productive: it represents people taking the time to find the right match, which is good for them and good for the firms that eventually land them. Artificial frictional unemployment inverts that logic. The friction it introduces produces no better matches. It simply destroys signal, leaving good matches unmade on both sides.

Consider what the systems are actually doing to the information economy of hiring. A qualified candidate generates a signal, a body of experience, a way of describing it, a manner, a set of competencies, and submits it. A well-functioning labour market transmits that signal to an employer who needs precisely it. The keyword screener and the carelessly tuned AI interviewer act as lossy compression: they throw away most of the signal and keep a thin, distorted residue. The nurse who cannot get past “computer experience” is not a market clearing efficiently. She is a match that should have happened and did not, a vacancy left open and a worker left idle, the two of them separated by nothing more substantial than a semantic gap.

Multiply that across the twenty-seven million hidden workers the Harvard study identified, across an economy in which vacancies and unemployment have at times risen together in a way the old models struggle to explain, and the cost stops looking like an individual misfortune and starts looking like a drag on aggregate productivity. Firms complain they cannot find talent while their own tools reject it. Workers conclude the market is rigged and reduce their search effort, or drop out of the official labour force altogether, which is precisely the behavioural response the search-and-matching tradition would predict from people who have learned that effort does not pay. The friction is artificial, but the unemployment it produces is entirely real, and so is the output that never gets made.

There is a distributional edge to this as well, and it cuts the wrong way. The candidates best placed to game an AI interview are those who have been coached on how the systems work, who know to seed their answers with the right vocabulary, who can afford the tools and the tutoring that decode the black box. The Greenhouse analysis flags exactly this risk: that those coached on AI tools gain an advantage over those without access, and that AI hiring deployed carelessly will accelerate existing inequities rather than dissolve them. A system sold on the promise of objectivity ends up rewarding fluency in its own quirks, which is just a new name for privilege.

There is a slower, more corrosive cost too, one that does not show up in any quarterly figure. Labour markets run partly on belief, on the shared expectation that effort and ability will, eventually, be rewarded with a fair look. That belief is a public good, and like all public goods it is easy to deplete and hard to replenish. Every candidate who walks away from an empty chair, every applicant left in the fifty-one per cent silence with no decision and no feedback, learns a small lesson about how much their effort is worth to the institutions they are trying to join. They tell their friends. They tell the internet. The Greenhouse figures already show the cynicism hardening: only twenty-one per cent of candidates believe employers are using AI responsibly, and more than a third reported perceiving age bias from the process. When a generation of workers concludes that applying for a job is an exercise in performing for an indifferent machine, the resulting withdrawal of faith is not a soft cost. It is a structural one, and it will be paid by the very employers who imagined they were saving money.

What Fairer Machinery Might Look Like

None of this is a counsel of despair, and it is emphatically not an argument for pretending the pre-AI world was a meritocratic idyll. It was not. Human interviewers are biased, inconsistent, swayed by the firmness of a handshake and the school on a CV. The interesting question is not whether to use machines but how to use them in a way that adds signal rather than destroying it, and that treats the people on the other side as people. The outlines of an answer are already visible, partly in regulation and partly in what candidates themselves are asking for.

The regulatory scaffolding is being built, unevenly, in real time. New York City's Local Law 144, in force since 2023, requires that automated employment decision tools undergo an independent bias audit each year, that a summary of the results be posted publicly, and that candidates be notified that such a tool will be used and told of their right to request an alternative. It is, in principle, exactly the disclosure-and-consent regime the Greenhouse respondents are crying out for. In practice, a December 2025 audit by the New York State Comptroller's office, covering July 2023 to June 2025, found the law's enforcement to be ineffective, hobbled by weak complaint handling and inaccurate compliance reviews. Seventy-five per cent of test calls to the city's 311 hotline about these tools never reached the Department of Consumer and Worker Protection, the agency charged with enforcing it; and when that department reviewed thirty-two companies it flagged one violation, while the Comptroller's auditors found seventeen potential ones in the same set. The framework is sound; the teeth are missing.

The European Union has the larger hammer, and has just postponed the moment it falls. Under the EU AI Act, systems used to filter applications and evaluate candidates remain classified as high-risk under Annex III, and the obligations are substantial: risk assessments, technical documentation, bias testing, meaningful human oversight, transparency disclosures and continuous monitoring, with a specific duty to inform the people subject to them, and a scope reaching beyond conventional employees to freelancers and platform workers. What has changed is when it starts to bite. Under the Digital Omnibus on AI, agreed provisionally on 6 May 2026, confirmed by Member State representatives on 13 May and granted final approval by the European Parliament on 16 June, the Annex III obligations were pushed back from 2 August 2026 to 2 December 2027: a sixteen-month deferral, fixed and unconditional, replacing an earlier proposal that would have tied the start date to the readiness of technical standards. Annex I systems embedded in regulated products slipped in parallel, from August 2027 to August 2028. The stated reason was that the regulatory infrastructure needed to make the obligations operable had not materialised on schedule: a candid admission, and for anyone waiting on protection a cold one.

The shape of that delay reproduces this essay's problem exactly. Article 50's transparency obligations were not postponed; they remain live from 2 August 2026. So the layer that tells you a machine is involved arrives on time, while the machinery that would make it answerable, the bias testing, the documented risk assessment, the human oversight meant to stand between an algorithmic verdict and your livelihood, slips by sixteen months. Candidates get the disclosure and wait until December 2027 for the substance behind it: told what is happening to them, given no means to contest it. Whether enforcement matches ambition remains the open question, the same one New York is currently failing. The direction of travel is still clear, disclosure and human oversight migrating from courtesy to legal requirement, but the timetable has slipped.

The American picture follows the same rhythm of ambition and deferral. Colorado passed the country's first comprehensive state AI statute, SB 24-205, and never brought it into force: a federal court halted enforcement on 27 April 2026, and it was repealed and replaced by SB 26-189, a narrower automated-decision-making-technology regime signed by Governor Jared Polis on 14 May 2026 and effective from 1 January 2027. What survives the narrowing is instructive. Deployers must give consumers clear and conspicuous notice before the technology is used in a decision affecting them; must furnish, within thirty days of an adverse decision, a plain-language description of it and of the automated system's role; and must offer meaningful human review and reconsideration on request. Disclosure upfront, an explanation, a human in the loop: very nearly the list the Greenhouse respondents gave. The law is converging on the candidates' own asks. It also does not begin until 2027, and Colorado's first attempt died before it bound a single employer.

Beyond compliance, the design principles are not mysterious, because candidates have spelled them out. Tell people, before they invest themselves, that AI will be involved. Explain what it is measuring, so the exercise is a test and not a trap. Offer a human alternative to those who want one, which is most of them. Put a human being in the loop to review the machine's verdicts before they become destinies. Close the loop with feedback, so that the fifty-one per cent currently left in silence at least receive the dignity of a decision. And audit the systems for the bias they are so good at scaling. Fofanah's JobOS proposal points at the same goal from the other direction: give people a way to make their signal legible to the machines, rather than leaving them to be discarded for failing to speak fluent algorithm. The technology to do all of this exists. What is mostly missing is the will to slow down enough to use it.

The Chair Is a Choice

Return, at the end, to the person logging in two minutes early, because that person is the whole argument. They did not ask for the labour market to become a conversation between systems. They simply wanted a job, and believed, reasonably, that wanting it and being able to do it might be enough to earn them a fair hearing from another human being. The empty chair tells them otherwise. It tells them that their preparation, their nerves, their carefully chosen story about the time they failed and recovered, all of it was poured into a vessel that was never going to hold it.

What is happening to their relationship with work is a slow withdrawal of faith. Not a dramatic refusal, just a quiet recalibration: apply to fewer places, expect less, invest less of yourself, assume the no before it arrives. What is happening to their relationship with employers is the conversion of provisional trust into settled suspicion. And what is happening to their sense of being seen is the discovery that an institution they had imagined was, at some level, about people, has decided that people are the expensive part.

The deepest point is that there is nothing inevitable about any of this. The empty chair is not a law of physics. It is a procurement decision, a default setting, a box left unticked on a configuration screen by someone who never had to sit on the other side of it. Every one of the harms in the Greenhouse data, the non-disclosure, the missing policies, the silence where feedback should be, is a choice an organisation made and could unmake tomorrow. The machines are not the problem. The problem is that we have allowed the machines to inherit, and amplify, our willingness to treat the people who want to work for us as a queue to be cleared rather than a set of human beings to be met. The interview was always a small ritual of recognition, an hour in which a stranger's life mattered enough to attend to. We are deciding, application by undisclosed application, whether that ritual is worth keeping. The candidate is still showing up, early, prepared, hopeful. The only question is whether anyone will be there.

References

  1. Greenhouse, “63% of Job Seekers Have Faced an AI Interview. Most Haven't Had a Good One Yet”, Greenhouse Newsroom, 1 May 2026. https://www.greenhouse.com/newsroom/63-of-job-seekers-have-faced-an-ai-interview-most-havent-had-a-good-one-yet
  2. Greenhouse, “AI interviews in hiring: What candidates actually want, and how to get it right” (2026 Candidate AI Interview Report), Greenhouse Blog, 2026. https://www.greenhouse.com/blog/2026-candidate-ai-interview-report
  3. Ibrahim Denis Fofanah, “The Algorithmic Barrier: A Framework for Artificial Frictional Unemployment and Information Asymmetry in Automated Recruitment Systems”, arXiv preprint 2601.14534, submitted 20 January 2026, revised (v2) 2 July 2026. https://arxiv.org/abs/2601.14534
  4. Fortune, “Nearly 4 in 10 job candidates have bailed on a hiring round because it required an AI interview”, 4 May 2026. https://fortune.com/2026/05/04/4-in-10-job-candidates-bailed-hiring-rounds-required-ai-interview/
  5. HR Dive, “Job candidates say they're quitting the hiring process over AI interviews”, 2026. https://www.hrdive.com/news/job-seekers-walk-away-from-AI-interviews/819443/
  6. The Harvard Gazette, “New study says 'hidden workers' are being excluded”, Harvard University, September 2021. https://news.harvard.edu/gazette/story/2021/09/new-study-says-hidden-workers-are-being-excluded/
  7. New York City Department of Consumer and Worker Protection, “Automated Employment Decision Tools (AEDT)”, New York City. https://www.nyc.gov/site/dca/about/automated-employment-decision-tools.page
  8. Office of the New York State Comptroller, “Enforcement of Local Law 144, Automated Employment Decision Tools”, 2 December 2025. https://www.osc.ny.gov/state-agencies/audits/2025/12/02/enforcement-local-law-144-automated-employment-decision-tools
  9. European Commission, “AI Act, Shaping Europe's digital future”, European Commission. https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
  10. EU Artificial Intelligence Act, “Annex III: High-Risk AI Systems Referred to in Article 6(2)“. https://artificialintelligenceact.eu/annex/3/
  11. Gibson Dunn, “EU AI Act Omnibus Agreement: Postponed High-Risk Deadlines and Other Key Changes”, 2026. https://www.gibsondunn.com/eu-ai-act-omnibus-agreement-postponed-high-risk-deadlines-and-other-key-changes/
  12. Morgan Lewis, “EU Approves Delays and Other Amendments to Certain EU AI Act Obligations: What Businesses Should Know”, June 2026. https://www.morganlewis.com/pubs/2026/06/eu-approves-delays-and-other-amendments-to-certain-eu-ai-act-obligations-what-businesses-should-know
  13. AI Compliance Atlas, “Colorado AI Act (SB 24-205, repealed and replaced by SB 26-189)”, 2026. https://aicomplianceatlas.com/law/colorado-ai-act
  14. Sapia.ai, “Humanising hiring: the largest study of AI candidate experience ever”, 18 September 2025. https://sapia.ai/resources/blog/humanising-hiring-the-largest-study-of-ai-candidate-experience-ever/
  15. RM Compare, “AI Assessment has a dignity problem, here's how to fix it”, RM Compare Blog. https://compare.rm.com/blog/ai-assessment-has-a-dignity-problem-heres-how-to-fix-it/
  16. The Nobel Prize, “Sveriges Riksbank Prize in Economic Sciences in Memory of Alfred Nobel 2010” (Diamond, Mortensen, Pissarides). https://www.nobelprize.org/prizes/economic-sciences/2010/popular-information/

Tim Green

Tim Green UK-based Systems Theorist & Independent Technology Writer

Tim explores the intersections of artificial intelligence, decentralised cognition, and posthuman ethics. His work, published at smarterarticles.co.uk, challenges dominant narratives of technological progress while proposing interdisciplinary frameworks for collective intelligence and digital stewardship.

His writing has been featured on Ground News and shared by independent researchers across both academic and technological communities.

ORCID: 0009-0002-0156-9795 Email: tim@smarterarticles.co.uk

Listen to the free weekly SmarterArticles Podcast

Discuss...

On a January afternoon in 2020, Robert Williams pulled into the driveway of his home in Farmington Hills, Michigan, and was arrested on his own front lawn while his wife and two young daughters watched. Detroit police accused him of stealing watches from a Shinola boutique. The case against him was, in essence, a single thing: a grainy frame of in-store surveillance footage that an algorithm had decided looked like the photograph on his driver's licence. He was held for roughly thirty hours in an overcrowded cell, made to sleep on a concrete floor, and questioned over a crime committed by a man he had never met and did not resemble in any way that a human eye, given a moment of honest attention, would have confirmed. When detectives finally laid the surveillance still beside his face, even one of them seemed to concede the obvious. The computer, Williams later recalled being told, must have got it wrong.

It is a story that has, by now, hardened into a parable. Williams was the first person in the United States known to have been wrongfully arrested because of a face recognition match. He would not be the last. Porcha Woodruff, eight months pregnant, was arrested in Detroit in February 2023 for a carjacking and held for around eleven hours, though nothing in the surveillance or witness accounts described a visibly pregnant woman; the photo lineup put before the victim used an eight-year-old mugshot rather than her current driver's licence photograph. Her charges were dismissed. Nijeer Parks spent ten days in a New Jersey jail for a shoplifting and assault he could not have committed, having been thirty miles away making a money transfer at the time. Robert Dillon, a fifty-two-year-old from Fort Myers, Florida, was arrested in August 2024 for allegedly trying to lure a child from a fast-food restaurant in Jacksonville Beach, a city he had never visited, three hundred miles from home, after police ran a grainy image of the suspect through an AI-assisted facial recognition system that returned him at 93 per cent “confidence”. Charged with a third-degree felony, he saw the case dropped more than two months later, once his attorney showed he had been at work. The ACLU and the ACLU of Florida sued on his behalf on 10 June 2026. By the ACLU's tally there are now at least fifteen such cases. Nearly all of the wrongfully arrested were Black.

The familiar way to tell this story is as a tale of error. The system, we say, made a mistake. It misidentified. The accuracy was poor, the dataset unrepresentative, the threshold miscalibrated. Fix the maths, broaden the training data, audit the vendors, and the harm recedes. This is the framing of most policy debate, most journalism, and a good deal of the technical literature. It is also, argues a paper presented at the 2026 ACM Conference on Fairness, Accountability, and Transparency and published in its proceedings, a profound misreading of what these systems actually do.

The paper, which appears under the title “Frankenstein in the Pipeline: Computational Epistemicide in Facial Recognition” and circulates as the arXiv preprint 2606.07628, makes a claim more unsettling than miscalibration. Its author, the Brazilian computer scientist Nina da Hora, takes Mary Shelley's creature not as a parable of unintended consequences but as a description of method: a body disassembled, reassembled from parts, legitimated by the procedure that made it. Facial recognition, da Hora contends, does not merely misidentify people from Black and non-Western communities. It performs something closer to an act of erasure. Through a sequence of ordinary engineering steps, the technology takes the face as a living, relational surface and progressively narrows it to whatever can be held still as data, then measures the residue against a norm that is, in its statistical bones, predominantly white, frontal, and European. To be recognised by such a system, the argument runs, anyone whose face departs from that norm must first be remade in its image. Da Hora gives this process a deliberately heavy name: computational epistemicide. The killing, by computation, of a way of being known.

It is a phrase designed to make you flinch, and it should. But before deciding whether it is overheated, it is worth doing something the policy conversation rarely does. It is worth looking, carefully and without squeamishness, at what actually happens to a face when a machine sets out to recognise it.

The Pipeline That Eats a Face

A modern face recognition system is not a single model that gazes at you and knows your name. It is an assembly line, and like all assembly lines it works by subtraction. At each station, something is removed, normalised, or thrown away, until what remains is a thing that can travel.

The first station is detection. Before a system can recognise a face it must find one, and finding means deciding where, in a rectangle of pixels, a face begins and ends. A detector returns a bounding box, a confidence score, and usually a handful of coarse keypoints. Already a decision has been made about what counts. A face partially turned away, shadowed, veiled, dark against a dark background, or simply lit in a way the detector's training did not anticipate may not register as a face at all. The earliest and most quietly consequential form of exclusion is not being misidentified. It is being invisible to the camera in the first place, falling below the threshold at which the machine agrees that a person is present.

The second station is cropping. The detected region is excised from its surroundings. The context goes: the body, the setting, the people standing alongside, the weather of the moment. What had been a person in a world becomes a rectangle of skin and feature. This is the first amputation, and it is so banal that no engineer would think to call it one. Yet a face is not, in lived experience, a free-floating object. It is always a face turned towards or away from someone, in a place, doing something. The crop dissolves all of that as a precondition of proceeding.

The third station is landmarking. The system locates fiducial points: the corners of the eyes, the tip and base of the nose, the edges of the mouth, the line of the jaw. These coordinates are the skeleton on which everything downstream depends. Landmark detectors are trained on annotated faces, and the geometry they expect, the assumptions about where features should sit relative to one another, carries the statistical signature of the data they learned from. A face whose proportions, expression, or pose sit outside that learned distribution yields noisier, less confident landmarks, and the error propagates.

The fourth station, and the one where the paper's argument bites hardest, is alignment. Having found the landmarks, the system warps the face. It applies a geometric transformation, rotation, scaling, translation, sometimes more aggressive distortion, so that the eyes sit on a predefined horizontal line, the nose falls on a fixed axis, the whole face is dragged into a canonical frontal pose at a standard size. The destination of that warp is a template, a set of target coordinates representing where a face is supposed to be. Every face entering the system is bent towards the same template. And that template was not handed down from nature. It was derived, historically and statistically, from the faces that dominated the field's foundational datasets, which were overwhelmingly white, male, and photographed front-on. Alignment is the moment, in the most literal mechanical sense, when your face is reshaped to fit a norm that did not come from you.

The fifth and final station is embedding. The aligned crop is fed into a deep convolutional network, which collapses it into a vector: a list of numbers of fixed length. The landmark FaceNet system, published by Florian Schroff, Dmitry Kalenichenko, and James Philbin at Google in 2015, mapped each face to a compact point in a Euclidean space, originally just 128 bytes per face, where distance between points stood in for similarity between faces. Later systems commonly use 512 dimensions. The output is L2-normalised, scaled to unit length, so that what survives of you is a direction in a high-dimensional space, a fixed-dimensional artefact stripped of scale, context, history, and flesh.

That vector is the point of the whole exercise. It is small, portable, and comparable. It can be stored in a database, indexed, matched against a watchlist, shipped between agencies, and queried in milliseconds. It is, in the engineering sense, beautiful: an entire human face rendered as a few hundred numbers that you can do arithmetic on. The cosine of the angle between two such vectors becomes a verdict on whether two faces belong to the same person.

Read the pipeline back as a single motion and the paper's central image comes into focus. A face enters as a living surface and exits as a coordinate. At each step the criterion is the same, mostly unspoken: keep what can be stabilised as data, discard the rest. Vectorisation, in da Hora's reading, completes the stitching: the dissected face sewn back together as a fixed-dimensional artefact whose purpose is to circulate. The face is not photographed so much as it is metabolised.

What the Face Was Before the Machine

To feel the force of the word epistemicide, you have to take seriously what the pipeline is subtracting, and that means refusing, for a moment, the engineer's flat definition of a face as a region of an image.

A face is not, primarily, a static object to be measured. It is a surface in motion and in relation. It is the principal instrument through which human beings recognise, address, and answer one another. Philosophers have long argued that the face is the very site of ethical demand, the place where another person confronts you as a person and not a thing. Across cultures the face is bound up with honour, shame, kinship, deference, and belonging. We speak of saving face and losing face, of facing someone, of a face that falls. None of this is metaphor laid over a neutral biological substrate. It is what the face actually is in the lives of the people who wear one. The face is relational before it is anatomical.

The recognition pipeline cannot hold any of that, and it is important to be precise about why. The problem is not that engineers are careless. It is that the relational face is, by definition, the part that will not stand still. It changes with whom you are addressing and how you feel about them. It is constituted in the encounter. A system whose entire purpose is to produce a stable, transmissible token must, of structural necessity, treat everything relational as noise to be normalised away. Alignment exists precisely to cancel pose, expression, and angle, which is to say to cancel the face as an act and preserve only the face as a fingerprint.

This is where the borrowed word does real work. Epistemicide was coined in 1995 by the Portuguese sociologist Boaventura de Sousa Santos, who used it to name the destruction of entire systems of knowing, the indigenous, southern, and subaltern ways of understanding the world that colonial modernity did not merely defeat but rendered illegitimate, unthinkable, gone. Santos's wager in his book Epistemologies of the South is that there can be no global social justice without what he calls cognitive justice, a recognition of the many valid ways human beings come to know. Epistemicide is what happens when one way of knowing installs itself as the only way, and the others are not argued with but erased.

But the lineage the paper actually claims runs through a second thinker, and it is the more pointed one. In a 2005 doctoral thesis at the University of São Paulo, the Black Brazilian philosopher Sueli Carneiro took Santos's term and turned it on her own country, using it to name the way Black Brazilians are stripped of standing as legitimate subjects of knowledge: disqualified in advance as knowers, constructed as the other who is not, so that the question of what they know need never arise. Da Hora's computational epistemicide is explicitly an extension of Carneiro's. Which is why the racial argument does not have to be bolted on afterwards: it is what the philosophy was built to describe.

Da Hora's manoeuvre is to apply that lineage to the face. The claim is that facial recognition enacts a small, mechanised epistemicide every time it runs. There is a way of knowing a person that is relational, embodied, reciprocal, the way a face is known by those who love it or live beside it. And there is the way of knowing installed by the pipeline, in which a person is a vector calibrated against a canonical norm. The second does not coexist with the first. In the systems that decide who boards, who enters, and who is flagged, it replaces it. The relational face is not weighed and found wanting. It is simply not represented in the data artefact at all. What gets killed is not the person. It is a way of the person being known.

The Norm Has a Demographic

You could grant all of this as philosophy and still object that it floats free of the engineering. Surely, the objection runs, a vector is just a vector. The numbers do not know your race. Here the empirical record is unkind to the objection, because the canonical norm the paper describes is not an abstraction. It has been measured, and it leaves fingerprints in the error rates.

In 2018, Joy Buolamwini and Timnit Gebru published Gender Shades, an audit of commercial gender-classification systems from IBM, Microsoft, and the Chinese company Face++. The results were stark. For lighter-skinned men, error rates sat under one per cent. For darker-skinned women, they rose as high as 34.7 per cent, with some disaggregated figures worse still. The systems worked best on the faces that most resembled the people and datasets they had been built around, and degraded precisely as faces departed from that centre. It was not a uniform fog of inaccuracy. It was a gradient, and the gradient had a colour.

A year later the US National Institute of Standards and Technology, the federal body that runs the authoritative Face Recognition Vendor Test, published its demographic study, evaluating scores of algorithms from across the industry. Its findings have become the empirical backbone of the entire debate. In one-to-one matching, the kind used to verify that you are who your passport says you are, the systems produced false positives for Asian and African American faces at rates ranging, depending on the algorithm, from ten to one hundred times higher than for white faces. In one-to-many matching, the kind a police force uses to search a face against a database of mugshots, African American women were among those carrying elevated false-positive rates, as NIST's own summary noted. The picture is more tangled than a headline permits: on the mugshot imagery the highest rates fell on Native American faces, with African American and Asian faces also elevated, and the ordering shifts by sex and by algorithm. The disparity is unmistakable; its precise shape is not uniform. NIST also noted a revealing wrinkle: some algorithms developed in Asian countries did not show the same penalty against Asian faces, strong evidence that the disparity tracks the composition of the data and the norm baked into it, not anything intrinsic to the faces themselves.

That last point matters enormously for the paper's thesis. If the bias were a fixed property of how cameras meet melanin, you would expect every system everywhere to fail in the same direction. It does not. The norm is contingent. It is built, and it could in principle be built differently, which is exactly why calling it a norm rather than a law is correct. The canonical face, frontal and pale, is an artefact of which faces happened to fill the foundational datasets and define the alignment templates of a field that grew up in particular institutions, in particular countries, photographing particular people. Everyone else is rendered legible only by being warped towards a centre that was never theirs, and the cost of that warping shows up, with grim reliability, as a higher chance of being confused with a stranger.

This is the bridge between the philosophical claim and the statistical one. The disparate error rate is not a separate problem from the epistemicide. It is the epistemicide becoming visible. The false match is the moment the system's insistence on remaking you in the image of its norm fails loudly enough to land you in a cell.

The Stakes Are No Longer Hypothetical

For most of facial recognition's history, the argument over what it does could remain somewhat academic, because the technology sat mostly at the edges of consequential life. That window has closed. The face is now a credential at the most heavily guarded thresholds in modern society, and the decisions that turn on it are precisely the ones from which there is least room to appeal.

Begin with the border. In December 2025, a US Department of Homeland Security final rule took effect authorising Customs and Border Protection to collect facial biometrics from all non-citizens on both entry and exit, by air, land, and sea. Earlier exemptions for children under fourteen and adults over seventy-nine were stripped away, so that virtually every non-citizen crossing a US frontier is now photographed and matched. The Transportation Security Administration has been pushing facial verification through the domestic system too, though more haltingly than the coverage implies: as of 2026 its facial-matching programme runs at roughly sixty-five airports, with face-scanning units at around eighty-four and more than two hundred and fifty lanes accepting digital identification. The figure of four hundred-plus airports that circulates in reporting on the rollout is a target for late 2026, not a fact, and a TSA spokesperson has conceded that full operation may not arrive until 2030, or even 2040. CBP, for its part, expects full deployment of biometric exit across commercial airports and seaports within three to five years. The face is becoming the boarding pass, the passport, and the turnstile, and the population most exposed to it, by the explicit design of the rule, is non-citizens, the very group whose faces the NIST data shows the systems handle worst.

Then there is policing, where the Williams, Woodruff, Parks, and Dillon cases are not anomalies but the visible tip of a practice. A face is captured on surveillance, run against a database of millions, and returned as a ranked list of candidates. Too often that lead, which the vendors themselves caution is merely investigative, is treated as probable cause, and a name at the top of a list becomes a knock at the door. The harm is distributed exactly where the error rates predict it will be. The systems fail most on Black faces, and it is Black people who keep being arrested for crimes committed by someone the machine decided they resembled.

The institutional appetite is widening from there: building access, benefits fraud screening, examination invigilation, age verification, retail loss prevention. In each case the seductive promise is the same frictionless certainty, your face as a key that cannot be forgotten or lent out. And in each case the same translation occurs beneath the surface. You are detected, cropped, landmarked, aligned, and embedded, and the entity that is actually admitted or refused is not you but your vector, measured against a norm.

Regulators have begun, unevenly, to respond, and the shape of their response reveals how narrowly the problem is still being understood. The European Union's AI Act, whose first prohibitions took effect in February 2025, bans real-time remote biometric identification in public spaces for law enforcement, subject to carved-out exceptions for finding missing persons, preventing imminent threats to life or terrorist attacks, and locating suspects in serious crimes. It also prohibits building face databases by untargeted scraping of the internet or CCTV, the practice that made the company Clearview AI notorious. These are real and meaningful limits. But notice their grammar. They regulate where and when and against whom the pipeline may be pointed. They do not touch what the pipeline does to a face once it is pointed. Crucially, retrospective identification, analysing footage after the event, is treated merely as high risk rather than banned.

And the high-risk regime that would have governed it has just slipped. The EU's Digital Omnibus on AI entered into force on 27 July 2026, postponing the obligations attaching to the Annex III high-risk categories, which expressly cover biometrics, law enforcement, and border management, from August 2026 to 2 December 2027; Annex I obligations move to 2 August 2028. The outright prohibitions were not touched: what Article 5 forbade in February 2025 it forbids still. But the machinery that was to have disciplined retrospective facial identification, risk management, technical documentation, data governance, human oversight, conformity assessment, has been deferred by well over a year, while the cameras and the contracts go in regardless. The law governs deployment, and even that has been rescheduled. The translation from person to vector proceeds untouched.

What Is Actually Lost in Translation

So return to the question the paper forces, the one the accuracy debate keeps stepping around. When a face is reduced to a fixed-dimensional artefact built to circulate across databases and institutions, the issue is not only whether the system works. It is what is lost in the translation, and who pays for the loss.

Three things are lost, and they compound.

The first is context, and with it the very possibility of relation. The relational face, the face as address and answer, is precisely the part the pipeline must discard to do its job. A face turned in greeting, a face set in defiance, a face slack with grief: these are erased at alignment, because alignment exists to cancel exactly such variation. What the system preserves is the part of you that holds still, which is the least human part, the part most like a barcode. To be recognised by the machine is to be recognised only as the thing in you that does not change, and never as the person doing the changing.

The second is consent over your own legibility, and this is more radical than the familiar complaint about privacy. The standard privacy worry is that the system sees too much of you. The deeper worry the paper surfaces is that to be seen at all you must first be rewritten. Anyone whose face departs from the canonical norm is made legible only at the price of being warped towards it, remade in the image of a centre that was never theirs. You do not get to be recognised as yourself. You get to be recognised as a deviation from someone else, measured by how far you had to be bent to fit. That is a strange and corrosive form of recognition, one that withholds the very thing the word promises.

The third loss is recourse. A vector circulates. Once your face has been embedded and entered into a database, the artefact travels between agencies, jurisdictions, and private vendors at machine speed, decoupled from the moment and the body it was taken from. If it is matched in error, the error propagates with the same efficiency. You cannot easily see the vector, cannot inspect it, cannot correct it, and in most jurisdictions cannot compel its deletion. The thing standing in for you in the rooms where decisions are made is one you have never been shown and cannot answer. When it speaks against you, as it spoke against Robert Williams, the burden of disproof falls on the living person, who must somehow argue with a number.

And the courts have offered only a patchy remedy. Williams reached a landmark settlement with Detroit in 2024 that obliged the department to rewrite how it may act on face recognition leads. Porcha Woodruff got the opposite: in August 2025 a federal judge, calling her arrest and jailing “troubling for many reasons”, nonetheless dismissed her civil rights claim against the officer who prepared her warrant, holding that her lawyers had not shown he lacked probable cause. Her attorney said he was shocked by the decision and intended to appeal. The same technology, the same city, the same pattern of harm, and two entirely different answers to the question of whether anyone is answerable. If you cannot see the artefact that accused you, and cannot reliably sue those who acted on it, recourse has been hollowed out while remaining on the books.

As for who bears the cost: the empirical record settles it without ambiguity. The translation is not equally lossy for everyone. It costs most where faces depart furthest from the canonical norm, which is to say it costs Black people, non-Western people, women with darker skin, the very populations in whose name Carneiro reworked the concept of epistemicide. The technology recapitulates, in silicon and at scale, the older pattern in which one way of knowing installs itself as universal and bills everyone else for the privilege of being misread by it.

More Than a Maths Problem

The reflexive response from much of the industry is that all of this is a transitional embarrassment, a bug to be patched. Broaden the datasets. Balance the demographics. Tune the thresholds per group. Audit the vendors against NIST. There is genuine value in that work, and the demographic disparities it targets are real and worth closing. The wrongful-arrest cases would be fewer if the systems were more accurate, and fewer ruined days is not nothing.

But da Hora's argument cuts beneath the remedy, and this is what makes it worth taking seriously even by those inclined to dismiss its vocabulary. Suppose the disparity were closed entirely. Suppose a future system matched every face, of every skin tone and origin, with identical and near-perfect accuracy. The pipeline would still detect, crop, landmark, align, and embed. It would still discard the relational surface as a precondition of producing the artefact. It would still convert persons into vectors calibrated against a norm and ship those vectors between institutions to decide who passes and who is flagged. A perfectly fair epistemicide is still an epistemicide. Closing the accuracy gap would distribute the loss evenly. It would not undo the loss.

That is the uncomfortable core of the thing. The bias is a symptom, the most legible and litigable symptom, of a deeper operation that the bias debate, by fixating on parity, helps to obscure. If the only question we ask is whether the system works equally well on everyone, we have already conceded that turning faces into vectors is the goal, and that fairness means doing it to everyone alike. The harder question, the one the paper insists on, is whether there are thresholds at which a person should not be resolved into a circulating data artefact at all, however accurate, because the act of resolution is itself the harm.

This reframes the policy stakes. A debate organised around accuracy leads naturally to better cameras, bigger datasets, and tighter audits, all of which entrench the pipeline by making it more defensible. A debate organised around what the pipeline does to a face leads somewhere else entirely: towards limits not on the error rate but on the operation, towards spaces and decisions from which the translation is excluded by right. The EU's prohibitions, partial as they are, gesture in that direction precisely because they ban certain uses outright rather than merely demanding they be done more accurately. The instinct to forbid, rather than to optimise, is the instinct the paper would have us extend.

Being Recognised by Something That Cannot See You

Robert Williams has said that what stayed with him was not only the wrongful night in a cell but the strange affront of it, the sense of having been confused with a man he was not, by a process he could not interrogate, in front of the children to whom he is most fully and irreplaceably himself. His daughters know his face in the way a face is actually known, as the living surface of the person who comes home. The system that arrested him knew a vector, aligned to a template, and decided that vector was close enough to another to be worth a warrant.

The gap between those two ways of knowing is the whole of the matter. One is relational, reciprocal, and irreducible to a coordinate. The other is portable, comparable, and built for circulation through the institutions that increasingly stand between people and the places they need to go. Da Hora's wager is that we have spent a decade arguing about whether the second kind of knowing is accurate, when the prior and harder question is whether it should be permitted to stand in for the first at all, in the rooms where it now does.

To be recognised by a system that can only see you by first making you someone else is, the paper suggests, not really to be recognised at all. It is to be replaced, at the threshold, by a more convenient version of yourself: stilled, flattened, calibrated against a norm you did not set and may never have matched. For a growing share of the decisions that govern a life, who boards, who enters, who is flagged, who is freed, that replacement is becoming the default condition of being seen. The deleted face is not a malfunction at the edge of the technology. It is the technology working exactly as designed. The unsettling achievement of the paper is to make us ask, while the rollout is unfinished and the four hundredth airport still an ambition, whether a design that must delete the face in order to read it is one we should be installing at the doors of public life at all.


References

  1. American Civil Liberties Union, “Williams v. City of Detroit: Face Recognition False Arrest.” https://www.aclu.org/cases/williams-v-city-of-detroit-face-recognition-false-arrest
  2. Michigan Public Radio, “'It didn't make sense at all': Wrongful facial recognition arrest in Detroit leads to landmark settlement,” 28 June 2024. https://www.michiganpublic.org/criminal-justice-legal-system/2024-06-28/it-didnt-make-sense-at-all-wrongful-facial-recognition-arrest-leads-to-landmark-settlement
  3. American Civil Liberties Union, “More than a Dozen Wrongful Arrests Due to Police Reliance on Facial Recognition Technology.” https://www.aclu.org/news/privacy-technology/more-than-a-dozen-wrongful-arrests-due-to-police-reliance-on-facial-recognition-technology
  4. NBC News, “Detroit woman sues city after being falsely arrested while pregnant due to facial recognition technology.” https://www.nbcnews.com/news/us-news/detroit-woman-sues-city-falsely-arrested-8-months-pregnant-due-facial-rcna98447
  5. Joy Buolamwini and Timnit Gebru, “Gender Shades: Intersectional Accuracy Disparities in Commercial Gender Classification,” Proceedings of Machine Learning Research, vol. 81, 2018. https://proceedings.mlr.press/v81/buolamwini18a.html
  6. MIT News, “Study finds gender and skin-type bias in commercial artificial-intelligence systems,” 12 February 2018. https://news.mit.edu/2018/study-finds-gender-skin-type-bias-artificial-intelligence-systems-0212
  7. National Institute of Standards and Technology, “NIST Study Evaluates Effects of Race, Age, Sex on Face Recognition Software,” 19 December 2019. https://www.nist.gov/news-events/news/2019/12/nist-study-evaluates-effects-race-age-sex-face-recognition-software
  8. National Institute of Standards and Technology, Face Recognition Vendor Test (FRVT) Part 3: Demographic Effects (NISTIR 8280). https://pages.nist.gov/frvt/reports/demographics/
  9. Florian Schroff, Dmitry Kalenichenko and James Philbin, “FaceNet: A Unified Embedding for Face Recognition and Clustering,” CVPR 2015, arXiv:1503.03832. https://arxiv.org/abs/1503.03832
  10. Boaventura de Sousa Santos, Epistemologies of the South: Justice Against Epistemicide (Routledge, 2014). https://www.routledge.com/Epistemologies-of-the-South-Justice-Against-Epistemicide/Santos/p/book/9781612055459
  11. U.S. Customs and Border Protection, “DHS announces Final Rule to advance the Biometric Entry/Exit Program.” https://www.cbp.gov/newsroom/national-media-release/dhs-announces-final-rule-advance-biometric-entry/exit-program
  12. Federal Register, “Collection of Biometric Data From Aliens Upon Entry to and Departure From the United States,” 27 October 2025. https://www.federalregister.gov/documents/2025/10/27/2025-19655/collection-of-biometric-data-from-aliens-upon-entry-to-and-departure-from-the-united-states
  13. Biometric Update, “TSA targets 400 US airports for biometrics rollout,” December 2024. https://www.biometricupdate.com/202412/tsa-targets-400-us-airports-for-biometrics-rollout
  14. European Parliament, “EU AI Act: first regulation on artificial intelligence.” https://www.europarl.europa.eu/topics/en/article/20230601STO93804/eu-ai-act-first-regulation-on-artificial-intelligence
  15. Future of Privacy Forum, “Red Lines under the EU AI Act: Restricting Real-time Remote Biometric Identification Systems for Law Enforcement Purposes.” https://fpf.org/blog/red-lines-under-the-eu-ai-act-restricting-real-time-remote-biometric-identification-systems-for-law-enforcement-purposes/
  16. Nina da Hora, “Frankenstein in the Pipeline: Computational Epistemicide in Facial Recognition,” Proceedings of the 2026 ACM Conference on Fairness, Accountability, and Transparency (FAccT '26), Montreal, June 2026. https://doi.org/10.1145/3805689.3812284
  17. Nina da Hora, “Frankenstein in the Pipeline: Computational Epistemicide in Facial Recognition,” arXiv:2606.07628. https://arxiv.org/abs/2606.07628
  18. American Civil Liberties Union, “Dillon v. City of Jacksonville Beach.” https://www.aclu.org/cases/dillon-v-city-of-jacksonville-beach
  19. American Civil Liberties Union, “Florida Man Sues Police Over Wrongful Arrest Due to False Facial Recognition Match,” 10 June 2026. https://www.aclu.org/press-releases/florida-man-sues-police-over-wrongful-arrest-due-to-false-facial-recognition-match
  20. Sueli Carneiro, A Construção do Outro como Não-Ser como fundamento do Ser (doctoral thesis, University of São Paulo, 2005).
  21. Gibson Dunn, “EU AI Act Omnibus Agreement — Postponed High-Risk Deadlines and Other Key Changes.” https://www.gibsondunn.com/eu-ai-act-omnibus-agreement-postponed-high-risk-deadlines-and-other-key-changes/
  22. CBS News Detroit, “Woman wrongly accused of carjacking loses lawsuit against Detroit police who used facial technology,” 4 September 2025. https://www.cbsnews.com/detroit/news/woman-wrongly-accused-carjacking-loses-lawsuit-detroit-police-used-facial-tech/

Tim Green

Tim Green UK-based Systems Theorist & Independent Technology Writer

Tim explores the intersections of artificial intelligence, decentralised cognition, and posthuman ethics. His work, published at smarterarticles.co.uk, challenges dominant narratives of technological progress while proposing interdisciplinary frameworks for collective intelligence and digital stewardship.

His writing has been featured on Ground News and shared by independent researchers across both academic and technological communities.

ORCID: 0009-0002-0156-9795 Email: tim@smarterarticles.co.uk

Listen to the free weekly SmarterArticles Podcast

Discuss...

There is a particular cruelty in a sound that never stops. A single loud noise is an event; you flinch, you brace, and then it passes and your nervous system stands down. A sound that runs at fifty-something decibels around the clock, day after day, month after month, is something else entirely. It never resolves. It offers no interval in which the body can register that the threat is over, because by the standards of an evolved animal listening for danger, the threat is never over. On Louise Avenue in Dowagiac, a small city in the south-western corner of Michigan, residents have spent the better part of a year living inside exactly that condition: a mechanical drone, measured by neighbours at between fifty and sixty-two decibels at all hours, comparable to the interior of a moving car or the noise floor of a busy open-plan office, sustained without interruption, emanating from a data centre that runs because somewhere, at scale, machines are learning.

I keep returning to a phrase one of the residents used to describe it. It is, he said, like having a vacuum cleaner running all the time. Not a roar, not a bang, nothing you could point a camera at and make go viral. Just a vacuum cleaner, in the next room, forever. That is the texture of the thing, and it is precisely the texture that makes it so hard to legislate, litigate, or even talk about. The permanent hum is sub-catastrophic by design. It does not kill anyone in a way a coroner could certify. It just sits underneath everything, a low industrial tinnitus imposed on a residential street, and it will not go away, and until very recently almost no legal or democratic mechanism in the United States was built to make it.

The Anatomy of an Always-On Sound

To understand why data centres hum the way they do, you have to understand what they are actually fighting, which is heat. A modern facility packed with servers, and increasingly with the power-dense graphics processors that train and run large AI models, converts prodigious quantities of electricity into computation and, as an unavoidable by-product, into warmth. Left unchecked, that heat would cook the hardware within minutes. So the entire architecture of a data centre is, in a sense, an enormous machine for moving heat out of a building faster than the silicon can generate it, and every stage of that heat-removal process makes noise.

The Environmental and Energy Study Institute, a non-partisan body founded by members of the United States Congress, laid this out in unusually plain terms in an analysis published on 23 March 2026 by Miguel Yañez-Barnuevo. Cooling systems, the institute noted, account for roughly forty per cent of a data centre's electricity use, and they are the dominant source of the sound. Air chillers produce a continuous humming. Banks of fans — and a hyperscale facility contains thousands of them — generate a whirring that merges, at distance, into a single tonal wall. Cooling towers can emit up to seventy A-weighted decibels within four hundred feet. Inside the server halls themselves, where the fans live closest to the machines, the ambient level can reach ninety-six decibels, a figure that sits above the threshold at which sustained exposure is considered hazardous to hearing.

Then there are the generators. Every serious data centre keeps diesel backup generators on site to ride through grid failures, and these are periodically tested, often monthly, under load. An industrial-scale diesel generator can produce up to a hundred and five decibels, which the institute compares to a jet passing overhead. A newer and louder wrinkle is the move by some operators towards on-site gas turbines to power facilities independently of a strained electrical grid; the institute counted forty-six planned American data centres intending to use off-grid turbines for continuous operation, machines whose acoustic signature is closer to that of a small power station than a neighbour's air-conditioning unit.

What matters most for the people living nearby, though, is not the peak decibel figure but the character of the sound. Data centre noise is broadband and, crucially, it carries a strong low-frequency component. Low-frequency sound behaves differently from the mid-range frequencies our regulations and our decibel meters are optimised to capture. It travels further. It bends around obstacles and slips through walls that would stop higher tones. It is poorly attenuated by the double glazing and insulation that keep out traffic. And it can be perceived as much through the body — a pressure, a vibration, a felt presence in the chest and the skull — as through the ears. Kyle Hart of the National Parks Conservation Association, quoted by the institute, made the technical point that because data centre noise spans multiple frequency ranges, it is genuinely difficult to measure, which is a polite way of saying that the instruments most local authorities own were never designed to characterise it.

This is where a strange and important sub-controversy enters the story. Across a growing number of host communities, from Chandler in Arizona to Granbury in Texas, residents have reported symptoms they attribute not to the audible drone but to something below the threshold of conscious hearing altogether — infrasound, the very low-frequency energy that a standard A-weighted decibel reading, which deliberately discounts low frequencies to approximate the sensitivity of the human ear, will systematically under-report. Reporting by outlets including Tom's Hardware and Futurism has documented residents complaining of a noise that barely registers on their meters yet leaves them nauseous, dizzy, and unable to sleep. I want to be careful here, because the science linking environmental infrasound at these levels to specific health outcomes is genuinely contested and the evidence is thinner than advocates sometimes suggest. But the mismatch itself is the point. When the official measurement tool and the lived experience diverge this sharply, the measurement tool stops being a neutral arbiter and becomes an instrument of dismissal.

What Fifty Decibels Actually Does to a Body

The intuitive objection to the Dowagiac residents' complaint is that fifty to sixty decibels simply is not very loud. It is quieter than conversation, far quieter than a lawnmower, a fraction of the energy of the jet the generators are compared to. Surely, the reasoning goes, people can habituate to something so modest. The science of environmental noise says otherwise, and it says so with a consistency that ought to unsettle anyone inclined to wave the problem away.

The foundational document here is the World Health Organization's Environmental Noise Guidelines for the European Region, launched on 10 October 2018 after years of systematic review of the epidemiological evidence. The WHO's central finding is that noise is not merely an annoyance but a genuine determinant of physical health, operating through pathways that do not require the sound to be loud enough to damage hearing. Chronic exposure acts as a physiological stressor. It elevates levels of stress hormones, raises blood pressure, and disturbs sleep architecture even when the sleeper does not consciously wake, and over years those insults accumulate into measurably increased risks of hypertension, ischaemic heart disease, and other cardiovascular outcomes. The guidelines emphasise that night-time exposure may matter most of all, because it is during sleep that the body is meant to perform its cardiovascular recovery, and a hum that never lets the autonomic nervous system fully power down denies it that repair.

The thresholds the WHO recommends are strikingly low, which is exactly why they are relevant to Dowagiac. For road traffic, the guidelines advise keeping average noise below fifty-three decibels over the day-evening-night period and below forty-five decibels at night, above which the panel found an increased risk of adverse health effects. For wind turbines the recommended limit is forty-five decibels. An older WHO benchmark for protecting sleep put the ideal level inside a bedroom at around thirty decibels of continuous sound. Set those figures against a residential street registering fifty to sixty-two decibels at all hours, including throughout the night, and the Dowagiac readings are not marginal exceedances of health-based guidance. They are comfortably above the levels at which one of the most cautious and methodologically rigorous public-health bodies in the world says harm begins — and they are being produced not by a motorway that at least quietens at three in the morning, but by a facility engineered to be identical at three in the morning as at three in the afternoon.

The low-frequency dimension sharpens the concern further. A review of the literature on low-frequency noise and human health published in the journal Applied Sciences, covering studies from 2016 to 2019, catalogued a consistent cluster of effects: annoyance as the primary reaction, frequently accompanied by headaches, difficulty concentrating, palpitations, and disturbed sleep. This is not a fringe finding. Low-frequency noise is more annoying, decibel for decibel, than higher-frequency sound, and it is annoyance in the specific technical sense used by noise researchers — a chronic, low-grade stress response that itself has downstream health consequences. When a plaintiff's household in Dowagiac reports that a pregnant neighbour cannot spend more than half an hour outside without a headache, or that a wife's Parkinson's disease has deteriorated since the facility expanded, the correct scientific posture is caution about any single causal claim while recognising that the general phenomenon — chronic low-frequency environmental noise producing headache, sleep disruption, and physiological stress — is exactly what the literature would predict. These are, in the language of the filings, allegations. They are also entirely consistent with what decades of noise research would lead you to expect.

A Law Written for Barking Dogs and Late Parties

Here is the crux of the matter, and the reason Dowagiac is not merely a local dispute but a document of a wider failure. The legal instrument the residents have been forced to reach for — the doctrine of nuisance, and the municipal noise ordinance that sits beneath it — was never designed for a facility like this. It was designed for barking dogs, late-night parties, a neighbour's poorly sited air-conditioning condenser. It assumes an intermittent, identifiable, negotiable disturbance between private parties of roughly comparable standing. It does not contemplate a permanent industrial process running twenty-four hours a day at the property line of a residential zone.

Consider the mechanics. The facility on East Prairie Ronde Street is operated by Alliance Cloud Services, LLC, a subsidiary of Hyperscale Data, Inc., and has run since March 2022, drawing something in the region of thirty megawatts to power a mixture of digital-asset mining — bitcoin — and high-performance computing. Dowagiac revised its noise ordinance in March 2026, establishing limits of sixty-five decibels during the day and fifty-five decibels overnight in residential areas, and on 1 April 2026 Mayor Patrick Bakeman sent an open letter to the company's chief executive, William Horne, pressing for transparency: announce immediately which land you are buying, and submit plans to the city within forty-five days. On paper this looks like a functioning local response. In practice, an ordinance framed around A-weighted decibel caps is poorly matched to a low-frequency tonal source; a facility can sit under the numerical limit on a standard meter while producing exactly the penetrating, sleep-destroying character of sound the residents are complaining about. The measurement approved by the rule and the harm experienced by the resident can point in opposite directions.

And then there is enforcement, where the mismatch stops being technical and becomes structural. It would be easy to assume, from the outside, that nothing has been enforced at all. That is not what happened. Dowagiac did issue notices of violation under its ordinance. It is what happened next that matters. Hyperscale challenged those notices immediately, disputing the city's readings and its methodology, and as the city manager, Kevin Anderson, told residents at a council meeting on 13 July 2026, they are now tied up in litigation. This is the crucial thing to understand about municipal enforcement against a corporate entity of this size: the problem is not that the citation is never issued. The problem is that the citation is absorbed. A small city can write a ticket. A company with a legal department can contest that ticket into abeyance, and keep contesting it, and the arithmetic of that exchange is brutally simple — the appeal costs the company a fraction of what compliance would, and the hum continues, unabated, for the entire duration of the argument. A fine that would ruin a homeowner is a rounding error to a data centre operator whose expansion plans reportedly involve raising its power draw from thirty megawatts towards three hundred and forty, and even that rounding error need not be paid this year, or next. An injunction against a hyperscale facility, meanwhile, raises the spectre of shutting down critical infrastructure, which courts are understandably reluctant to order. Enforcement here is not absent. It is simply outlasted.

Nuisance law compounds the mismatch with its own burdens. To prevail, plaintiffs must generally show that the interference with the use and enjoyment of their property is both substantial and unreasonable, a standard that invites the operator to argue about ordinary sensibilities, about the social utility of the enterprise, about whether the complainants are simply unusually sensitive. It places the cost and labour of documentation on the victims, who must hire acousticians, log readings, and prove their own suffering, while the party generating the harm continues to generate it throughout the years such litigation takes. The federal class action filed in the United States District Court for the Western District of Michigan on 26 May 2026 — brought on behalf of owner-occupants and renters within a mile of the site, a class the complaint estimates at around thirteen hundred residential properties — is an attempt to overcome that asymmetry through sheer aggregation. It is a rational response to a broken tool. But the fact that a neighbourhood must assemble a federal class action to address the noise from a single building tells you how far the ordinary machinery of local governance has been outrun.

The shape of that case is itself instructive. The plaintiffs' attorneys describe it as the first proposed class action in the country seeking relief for data-centre noise, and as pleaded it is framed around property damage — the loss of the use and enjoyment of a home, and the diminution of what that home is worth — rather than personal injury. That is sound strategy, because property harm is the harm nuisance law was built to see. But look at what the framing does. The headaches, the ruined sleep, the deteriorating health enter the case chiefly as evidence that a house has become less pleasant to live in, rather than as injuries in their own right. The law translates a body into a balance sheet, because the balance sheet is the only dialect it speaks with any fluency, and a great deal of what these residents are actually complaining about does not survive the translation. Meanwhile the clock runs at the defendant's pace. Hyperscale sought and was granted an extension to respond to the complaint, pushing its answer out to 24 July 2026 — a delay of no consequence whatsoever to a company, and of considerable consequence to someone who cannot sleep.

The Permits That Were Never Filed

The most quietly astonishing detail in the Dowagiac story is not the decibel readings. It is that, according to the residents, the city council itself cannot answer basic questions about the facility's expansion because it has received no permit applications from the operator, and cannot say what is coming next. Sit with that for a moment. The people whose job is to govern the physical development of the city, who hold the democratic mandate to decide what gets built and where and under what conditions, are reduced to reading the news like everyone else to find out that a facility in their jurisdiction intends to more than double in size and multiply its power consumption by a factor of ten.

This is what I would call the democratic deficit at the heart of the AI build-out, and it is structurally distinct from the noise itself. Data centres frequently arrive through a lattice of arrangements — pre-existing industrial zoning, economic development agreements negotiated out of public view, land purchases through intermediaries — that can allow a great deal to happen before anything reaches a public hearing or requires a discretionary permit. The site at Dowagiac sits within an established business park, which is precisely the kind of pre-approved industrial envelope that lets a use expand without the friction of fresh democratic scrutiny. From the operator's perspective this is simply efficient. From the perspective of a resident on Louise Avenue it means that the single largest change to their acoustic environment in a generation was decided somewhere they were never invited, by people they never elected, through a process that produced no document they can inspect and no meeting at which they could object.

The public record of this summer bears the vacuum out with painful clarity. On 1 July 2026 the plaintiffs' attorneys held a meeting at the Dowagiac public library; residents packed a room built for fifty and rotated in and out of it because there was nowhere left to stand. On 13 July the city council convened a special data centre forum and moved it out of its usual chamber to the Dowagiac Middle School Performing Arts Center in anticipation of the turnout. Some three hundred people came. William Horne appeared in person, and the company's representatives stayed in the room through public comment, which is more than many operators in comparable disputes have done. What he offered was a list of commitments. Cryptocurrency mining would cease within three months, which he expected to make the noise more manageable. A permanent wall would go up on the Louise Avenue side of the property. The business would transition towards AI computing and humanoid robot manufacturing, an investment he put at a hundred million dollars and which he suggested might mean something like five hundred jobs — with no guarantee that those jobs would be permanent, and none that they would go to anyone local. The newly acquired forty-eight and a half acres, he said, had been bought to keep the seller happy and to create a natural buffer that would be maintained; where the physical expansion would actually go, he did not clarify.

And then the offer that tells you the most about the whole affair. Horne said the company would buy the homes of nearby residents at fair market value and cover their moving costs, because he did not want neighbours to feel, in his words, trapped, with his company as the cause of it. Read charitably, that is a decent impulse. Read structurally, it is an admission and a strategy at once: the remedy on the table is not abatement but exit. Not we will stop making the noise, but we will help you leave the place the noise is. The residents were not charitable about it. One of them, Peter Gibbons, put the objection with a precision no lawyer improved upon: if somebody has got their boot on your head, when they lift their boot off your head, they are not a hero. Another said he would need more than three times his property's value before he would even consider selling. A third asked why a stretch of greenspace that was already functioning as a buffer needed to be owned by the company in order to serve as one.

Notice what is missing from all of this. Every commitment made on 13 July was voluntary, offered at a public meeting, unenforceable by anything except reputation. The forty-five-day deadline in Mayor Bakeman's April letter had long since come and gone. A mayor writing an open letter to discover what is being built in his own city is not a functioning permitting process; it is the improvisation of a man who has discovered he has no formal lever to pull. And this is not incidental to the noise problem; it is causally upstream of it. Had there been a genuine permitting process — one requiring an acoustic impact assessment, public notice, and enforceable conditions on continuous low-frequency emissions before a single server was energised — the hum might never have reached the residents' bedrooms in the first place. The absence of that process is why the only remaining venue is a courtroom, years too late, and why the best offer on the table is a cheque and a removal van.

From Dowagiac to Mount Pleasant

It would be comforting to treat Dowagiac as an aberration, a single badly sited facility in a single unlucky town. It is not. It is the leading edge of a pattern, and the pattern is national.

In the same window, residents of Sturtevant, near Mount Pleasant in Racine County, Wisconsin, filed their own proposed class action, on 1 July 2026, in the United States District Court for the Eastern District of Wisconsin. Their target is not an obscure operator but Microsoft, and the facility is not a thirty-megawatt outfit but Fairwater, a data centre the company has promoted as among the most powerful AI installations in the world: a three-hundred-and-fifteen-acre campus with a final bill put at seven point three billion dollars, which began bringing equipment online in April 2026. Three Sturtevant residents — Garret Ostergaard, David Wade and Joy Wade — brought the suit on behalf of the more than a thousand households the complaint places within a mile and a half of the site. It alleges unreasonable and excessive noise from diesel generators and heating, ventilation and air-conditioning systems — chillers, cooling towers, air-handling units, condenser fans — the identical acoustic cast of characters as in Michigan. It describes residents driven indoors, and Ostergaard having to switch his work shift because he could no longer sleep, and it adds construction noise and light pollution to the charge sheet. Microsoft, for its part, has acknowledged the sound, attributing it to cooling fans, and stated in a June update that its engineers and consultants investigated on site and put mitigations in place. The gulf between a corporate assurance that mitigations are in place and a class action alleging the noise persists is the gulf this whole story lives in.

The Environmental and Energy Study Institute's March analysis makes clear that Dowagiac and Mount Pleasant are two points on a curve. It documents a spreading rash of near-identical complaints: Chandler, Arizona, where a neighbourhood battled a humming facility for years and the city eventually tightened its zoning and rejected a new proposal; Prince William County, Virginia, in the densest data-centre corridor on Earth, where residents reported noise exceeding sixty decibels and one operator began retrofitting acoustic shrouds; Greenbrier, Arkansas, and Granbury, Texas, where communities living beside cryptocurrency-mining and computing facilities reported a catalogue of vertigo, nausea, elevated blood pressure, migraines, and insomnia; Southaven, Mississippi, where an installation running numerous gas turbines drew complaints about sleep and air quality alike. Northern Virginia alone hosts around three hundred operating data centres, something like fourteen per cent of the global total, and by the institute's account roughly a third of the Virginia facilities sit within two hundred feet of a residential zone. The geography of the AI boom is, increasingly, the geography of someone's back garden.

Southaven has since moved from complaint to court. In June 2026 residents sued over the noise from the gas-turbine plant that powers Elon Musk's xAI data centres nearby, naming the company and its subsidiary MZX Tech, and describing much of what you would expect by now — high-pitched squealing, continuous engine roar, low-frequency rumbling, tonal humming. What lingers from CBS News's reporting on that case, though, is not the pleadings. It is the counsel offered to a homeowner who could not sleep. The mayor's advice was to consider selling. Set that beside the buyout cheques circulating on Louise Avenue and the pattern is unmistakable and, I think, genuinely important: across entirely unrelated disputes, in different states, against different companies, the remedy converging on these residents is not that the noise will stop but that they will go. Exit is being offered where abatement is owed. A nuisance regime that ends by relocating the neighbour rather than quieting the machine has not resolved the nuisance; it has merely found a way to stop hearing about it.

The trend now has professional observers, which is its own kind of milestone. On 13 July 2026 WilmerHale published a client alert titled 'Data Centers in Court', surveying what it called an emerging wave of nuisance, environmental and land-use litigation and cataloguing suits in Michigan, New Jersey, Mississippi and New York. Faegre Drinker followed in the same month with guidance for operators on how to avoid becoming the target of a nuisance suit in the first place. When defence-side firms begin publishing advice on how not to get sued by the neighbours, the category has arrived.

What unites these cases is not a rogue operator but a category error baked into the whole enterprise: the siting of always-on, industrial-scale thermal machinery in or beside places where people are trying to sleep, backed by an assumption that existing environmental noise rules — which, as the institute notes, were largely written with intermittent nuisances and traffic in mind — would somehow suffice. They do not suffice, and the class actions are the sound of that assumption breaking.

The Regulator That Walked Away

At precisely the moment communities most needed a national floor of protection, the federal government explicitly declined to provide one. On 10 June 2026, speaking at an industry energy summit, the Administrator of the Environmental Protection Agency, Lee Zeldin, announced that the agency would not pursue any nationwide environmental requirements or recommendations targeting the AI data-centre industry. The appropriate practices for each facility, he said, were a matter for states and local communities rather than for the EPA. The decision spanned water, air, and — by direct implication — noise. The agency that retains statutory authority over environmental noise, and that once ran an Office of Noise Abatement and Control, formally handed the entire question back to the very local governments that Dowagiac has just demonstrated are structurally incapable of managing it.

The historical irony here is bitter, and the institute's analysis lays it out. The United States actually built a federal noise-control apparatus in the 1970s: the Noise Control Act of 1972 gave the EPA authority to address environmental noise, and the Quiet Communities Act of 1978 extended it. Then, in 1981, the Reagan administration defunded the Office of Noise Abatement and Control, leaving the underlying statutes on the books but stripped of the staff and money to act on them. For more than four decades, federal noise policy has therefore been a hollow shell — the legal authority intact, the operational capacity gone — and noise has been left to the patchwork of state and municipal ordinances that the data-centre boom is now overwhelming. Zeldin's June statement did not create the vacuum. It ratified a vacuum four decades in the making, at the exact historical instant when a genuinely new category of always-on industrial noise source was multiplying across the residential map.

There is a darker development still, and it is worth stating precisely rather than gesturing at. On 7 July 2026 the EPA published a proposal to eliminate the federal requirement that states provide a thirty-day public comment period before issuing certain air permits — those for facilities classified as minor sources of pollution, a category that routinely covers exactly the backup diesel generators and smaller gas turbines that data centres install by the dozen. Under the proposal it would fall to each state to decide whether any public comment is offered at all. The agency's own account of its purpose is admirably candid: the rulemaking, it says, is intended to reduce administrative burden and responsibly speed up permitting, supporting American economic development and energy dominance. The Sierra Club, which characterises the change as removing the public from the permitting process for data centres, and the Environmental Defense Fund, whose senior attorney has argued that this is a moment for expanding community input on air permitting rather than erasing it, have both objected and called for the proposal to be withdrawn.

I want to be careful about interpretation, because reading intent into a proposed rule is a contested exercise, and the reporting from NBC News that first raised the alarm was framed around what environmental advocates fear rather than what the agency has admitted. But the mechanism does not require interpretation. It removes one of the very few formal moments at which an ordinary resident gets to see a permit application before the permit is granted — the moment at which you learn, in time to say something, that turbines are coming to the end of your road. Which is to say that it proposes to remove, at federal level, precisely the thing whose absence in Dowagiac produced everything else in this story. The residents of Louise Avenue did not lose an argument about their neighbourhood. They never got to have one. The minor-source proposal would make that experience the national default rather than a local misfortune. When the referee both refuses to make a call and quietly narrows the window in which the crowd may object, the game is not neutral.

The Politics of the Hum

On Saturday 18 July 2026, opponents of data-centre construction staged a hundred and forty-two protests across forty-two states — the first coordinated nationwide action against the AI build-out. Texas, the busiest state in the country for new construction, hosted the most rallies at eighteen. Georgia had eleven, California eight, and Pennsylvania, Florida and Indiana seven apiece. The convening group, Humans First, chaired by the conservative activist Amy Kremer, frames the fight in explicitly populist and America-First terms, invoking utility costs, water, land use, national security, and the sense that these facilities are, in the group's phrase, forced on communities in backroom deals. That last complaint — the backroom deal, the decision made without you — is the Dowagiac permitting vacuum rendered as a national grievance.

The numbers repay a moment's attention, because at first glance they look contradictory. Organisers released no headcounts, and turnout at individual events was frequently modest: around a dozen people in Atlanta, some fifty in California's Imperial County standing about in heat of a hundred degrees Fahrenheit. A movement that can fill forty-two states and not one town square is not a mass movement in the conventional sense, and it would be easy for an industry lobbyist to say so dismissively. I think that would be a misreading. Extraordinary geographic spread combined with thin per-site attendance is exactly the signature you would expect from this particular grievance, and the reason is structural. The complaint is broad — it is nearly everywhere — and it is local — a specific facility, a specific street, a specific hum outside a specific bedroom window — and it is therefore diffuse. It does not concentrate, because the thing being objected to does not concentrate. There is no single site at which to mass, because the sites are everywhere, and each has its own few hundred aggrieved neighbours who mostly want one building to be quieter rather than an industry to be abolished. The map and the headcounts are not competing measurements. They are two readings of the same distributed phenomenon.

I find the coalition assembling around this issue genuinely revealing, and worth dwelling on, because it does not map onto the usual political geometry of technology criticism. The organised protest energy here comes substantially from the populist right, animated by land, cost, sovereignty, and distrust of large institutions cutting deals over local heads. Yet the substantive complaints — environmental harm, corporate externalities dumped onto ordinary people, the capture of local government by capital, the health of pregnant women and the chronically ill — are the classic material of the environmental left. A Gallup poll conducted by telephone between 2 and 18 March 2026, with a random sample of around a thousand adults across all fifty states and the District of Columbia, and released that May, found that seven in ten Americans oppose the construction of AI data centres in their local area, with forty-eight per cent strongly opposed and only seven per cent strongly in favour. Half of those opposed cite the excessive use of resources; sixteen per cent cite pollution, and noise sits inside that figure. Opposition on that scale simply cannot be a partisan artefact. The environmental campaigner Erin Brockovich, a figure firmly of the left, has reportedly been gathering thousands of community complaints about these facilities. The hum, it turns out, is audible across the political spectrum, and it is dissolving some of the usual battle lines as it spreads.

This matters for how the problem gets solved, or fails to. An issue that unites a Gallup supermajority ought to be politically trivial to address, and the fact that it is not tells you something about the countervailing force. The AI build-out is backed by the largest and best-capitalised companies in the world, framed in the language of national competitiveness and technological destiny, and increasingly treated by governments as strategic infrastructure to be accelerated rather than constrained. Against that, a neighbourhood on Louise Avenue has a decibel meter and a lawyer. The permanent hum is, in this sense, the sound of a profound asymmetry of power — the physical residue, in a residential street, of decisions taken at a scale and altitude where the people who must live beside the result were never a variable in the equation.

What Managing the Hum Would Actually Require

It would be a failure of nerve to catalogue all this and offer nothing. The Dowagiac case is not evidence that data centres cannot coexist with neighbourhoods; the mitigation technology largely exists. It is evidence that the mechanisms for compelling coexistence do not. So what would actually close the gap?

Start with measurement, because measurement is where the current failure begins. Any noise standard applied to data centres must be designed for their actual acoustic signature, which means it cannot rest on A-weighted decibel caps alone. It needs to characterise low-frequency and tonal content specifically — the C-weighted and narrow-band measures that capture the penetrating hum an A-weighted reading discounts — and it needs to be assessed at the affected façade, over sustained periods, including through the night. The institute's own catalogue of solutions shows the engineering is not exotic: acoustic enclosures and shrouds, fan silencers and attenuators, sound-deadening barriers and berms, quieter chiller technology, immersion cooling that dispenses with banks of screaming fans, and the simple discipline of siting the loudest equipment away from the property line. Amazon's retrofitting of acoustic shrouds in Virginia and Microsoft's claimed mitigations in Wisconsin are tacit admissions that the noise is controllable when a company is made to control it. So, for that matter, is the wall Hyperscale has now promised for the Louise Avenue boundary — an engineering solution that was available on the first day of operation and arrived in the fourth year, under litigation, as a concession. The variable is not capability. It is obligation.

That obligation has to be created before the facility is built, not litigated after. The single most important reform is to fold a binding acoustic impact assessment, with enforceable continuous-emission conditions, into the permitting process for any large data centre sited near residential land — the very process that appears to have been bypassed in Dowagiac. Permits should be public, conditions should be measurable, and the burden of demonstrating ongoing compliance should sit with the operator, not with exhausted residents hiring their own acousticians. Where a facility is retrofitted or expanded, as at Dowagiac, that expansion should itself trigger fresh assessment rather than sliding through on a pre-existing industrial designation. And the remedies for breach need teeth proportionate to the balance sheets involved: penalties scaled to the operator's revenue rather than to a small city's fee schedule, and structured so that a company cannot simply litigate a citation into irrelevance while the noise continues, so that compliance is cheaper than defiance.

Then there is the question of who sets the floor. Zeldin's abdication leaves a genuine vacuum, and it would be inaccurate to say nothing is filling it. Something is: the policy tracker MultiState counts twenty-seven states advancing data-centre legislation covering energy costs, water use and environmental requirements, with California, Ohio and Utah having already put laws on their books. The states are moving into the space the EPA vacated. But they are moving unevenly and at different speeds, which reproduces the patchwork problem in a new costume — a facility's acoustic obligations coming to depend on which side of a state line it happens to be built, which is an open invitation to site the loudest machinery wherever the rules are thinnest. Nor is the federal posture towards even that state-level activity neutral. In remarks reported on 16 July 2026, Zeldin dismissed a statewide moratorium of the kind New York has adopted as an easy way to cop out, urging local governments instead to weigh each project individually on utility bills, grid contribution and water. There is a coherent argument buried in that, and I do not think case-by-case scrutiny is a foolish principle. But it is a striking thing to demand of a town clerk from the office that has just declined to set any national standard at all. The instruction to communities is to decide for themselves, project by project, without a moratorium, without a federal floor, and — if the minor-source proposal is adopted — in some states without even a guaranteed public comment period in which to learn what is being decided. A town of Dowagiac's size should not have to independently reinvent industrial acoustics jurisprudence in order to protect its own residents from a multinational. The knowledge exists; what is missing is a mechanism to make it a default condition of doing business rather than a concession extracted through years of federal litigation.

The Sound of a Decision Made Somewhere Else

I keep coming back to the ordinariness of the harm, because the ordinariness is the trap. If a data centre exploded, or leaked something toxic, or fell silent and took the internet with it, we would have categories ready to hand — disaster, pollution, outage — and institutions primed to respond. The permanent hum fits none of them. It is chronic rather than acute, distributed rather than concentrated, a matter of degrees rather than kind. It does not photograph. It does not trend. It simply degrades, night after night, the sleep and the peace and quite possibly the cardiovascular health of everyone within earshot, and it does so beneath the threshold at which any of our alarm systems are set to trip.

That is why the Dowagiac case is worth more than the sum of its decibel readings. It is a clean instance of a much larger phenomenon that the AI era is going to keep producing: physical infrastructure arriving in inhabited places faster than any mechanism — regulatory, legal, or democratic — for governing its impact on the people already there. The gap between the pace of the build-out and the pace of accountability is not a temporary lag that will close on its own. It is a structural feature of what happens when a technology backed by trillions of dollars of capital and the rhetoric of national survival meets a system of local governance built for a slower, smaller, more answerable world. The hum is what that gap sounds like from a bedroom window.

The intelligence these facilities produce is marketed to us as weightless, ethereal, a thing of clouds and prompts and disembodied minds. The reality is a shed full of fans that never stop turning, sited at the edge of a residential street, converting a town's quiet into someone else's compute. Somewhere upstream, that trade was decided. The residents of Louise Avenue were not asked, were not told, and cannot, even now, get a straight answer about what comes next. What they have been offered instead is the market value of the houses they no longer wish to live in, and the sound of the decision itself, running at fifty-something decibels, all day and all night, for as long as the machines are learning. The least we owe them is not a cheque. It is a way to make it stop.

References

  1. ClassAction.org. (2026, May 27). Michigan Data Center Faces Class Action Lawsuit Over Alleged Failure To Curb 'Excessive' Noise Pollution. https://www.classaction.org/news/michigan-data-center-faces-class-action-lawsuit-over-alleged-failure-to-curb-excessive-noise-pollution

  2. WWMT Newschannel 3. (2026). Residents suing Hyperscale data center in Dowagiac over 'unreasonable, excessive noise'. https://wwmt.com/news/local/lawsuit-hyperscale-data-center-dowagiac-noise-class-action-business-center-legal-osha-decibels-contained-digital-asset-mining-facility-rural-southwest-michigan-infrastructure

  3. Tom's Hardware. (2026, July). 'It sounds like someone set up a vacuum, like in your living room': Michigan residents sue AI data center emitting noise 24/7 — company fined for industrial noise ordinance violations, offers to buy homes from residents. https://www.tomshardware.com/tech-industry/data-centers/it-sounds-like-someone-set-up-a-vacuum-like-in-your-living-room-michigan-residents-sue-ai-data-center-emitting-noise-24-7-company-fined-for-industrial-noise-ordinance-violations-offers-to-buy-homes-from-residents

  4. WWMT Newschannel 3. (2026). Hyperscale data center to more than double its Dowagiac campus amid class action lawsuit. https://wwmt.com/news/local/hyperscale-data-center-dowagiac-michigan-lawsuit-double-size-acres-acquire-land-noise-sue-ai-alliance-cloud-services-legal-class-action-wwmt

  5. Watershed Voice. (2026, July 14). Hyperscale CEO breaks silence at contentious Dowagiac city council meeting. https://watershedvoice.com/2026/07/14/hyperscale-ceo-breaks-silence-at-contentious-dowagiac-city-council-meeting/

  6. Watershed Voice. (2026, July 15). EPA proposal could reduce public input on some data center permits as Dowagiac debate continues. https://watershedvoice.com/2026/07/15/epa-proposal-could-reduce-public-input-on-some-data-center-permits-as-dowagiac-debate-continues/

  7. Yañez-Barnuevo, M. (2026, March 23). Communities Are Raising Noise Pollution Concerns About Data Centers. Environmental and Energy Study Institute (EESI). https://www.eesi.org/articles/view/communities-are-raising-noise-pollution-concernsabout-data-centers

  8. Wisconsin Public Radio. (2026, July 2). Microsoft sued over noise complaints at new Mount Pleasant data center facility. WPR. https://www.wpr.org/news/microsoft-sued-noise-complaints-at-new-mount-pleasant-data-center

  9. Wisconsin Examiner. (2026, July 2). Sturtevant residents file class action suit over Microsoft data center noise. https://wisconsinexaminer.com/briefs/mount-pleasant-residents-file-class-action-suit-over-microsoft-data-center-noise/

  10. Urban Milwaukee. (2026, June 24). Microsoft Finishes Constructing Mount Pleasant Data Center, Plans More. https://urbanmilwaukee.com/2026/06/24/microsoft-finishes-constructing-mount-pleasant-data-center-plans-more/

  11. World Health Organization Regional Office for Europe. (2018, October 10). Environmental Noise Guidelines for the European Region. https://www.who.int/europe/publications/i/item/9789289053563

  12. Basner, M., & McGuire, S. (2018). WHO Environmental Noise Guidelines for the European Region: A Systematic Review on Environmental Noise and Effects on Sleep. International Journal of Environmental Research and Public Health. https://pmc.ncbi.nlm.nih.gov/articles/PMC5877064/

  13. Carvalho de Sá, T., et al. (2020). Low-Frequency Noise and Its Main Effects on Human Health—A Review of the Literature between 2016 and 2019. Applied Sciences, MDPI. https://www.mdpi.com/2076-3417/10/15/5205

  14. Tom's Hardware. (2026, May). AI data centers face increasing complaints about inaudible but 'felt' infrasound. https://www.tomshardware.com/tech-industry/artificial-intelligence/data-centers-face-increasing-infrasound-complaints-from-neighboring-communities-sounds-do-not-register-on-decibel-meters-but-irritate-local-citizens

  15. Futurism. (2026). Residents Say Data Centers Are Radiating Bizarre Frequencies. https://futurism.com/science-energy/data-centers-noise-pollution-infrasound

  16. Crowell & Moring LLP. (2026, June). EPA Hands Over AI Data Center Regulation To States And Communities To Develop Best Practices. https://www.crowell.com/en/insights/client-alerts/epa-hands-over-ai-data-center-regulation-to-states-and-communities-to-develop-best-practices

  17. NBC News. (2026). Newly proposed EPA rule could silence data center critics, environmental activists warn. https://www.nbcnews.com/news/us-news/proposed-epa-rule-silence-data-center-critics-advocates-say-rcna385800

  18. Sierra Club. (2026, July). EPA Moves to Eliminate Public From Permitting Process for Data Centers, Concrete Batch Plants. https://www.sierraclub.org/press-releases/2026/07/epa-moves-eliminate-public-permitting-process-data-centers-concrete-batch

  19. Tennessee Lookout. (2026, July 16). EPA Administrator calls statewide data center moratorium a 'cop out'. https://tennesseelookout.com/2026/07/16/epa-administrator-calls-statewide-data-center-moratorium-a-cop-out/

  20. MultiState. (2026, April 14). State Data Center Laws vs. Federal AI Push: 2026 Tracker. https://www.multistate.us/insider/2026/4/14/federal-ai-data-center-policy-meets-resistance-from-state-lawmakers

  21. The Spokesman-Review. (2026, July 18). Data center opponents stage 142 protests across 42 US states. https://www.spokesman.com/stories/2026/jul/18/data-center-opponents-stage-142-protests-across-42/

  22. Axios. (2026, June 18). Exclusive: Conservatives plan nationwide protest against AI data centers. https://www.axios.com/2026/06/18/conservatives-protest-ai-data-centers

  23. Gallup. (2026, May). Americans Oppose AI Data Centers in Their Area. https://news.gallup.com/poll/709772/americans-oppose-data-centers-area.aspx

  24. CBS News. (2026). Mississippi homeowners blame a noisy data center plant for sleepless nights. The mayor's advice? 'Consider selling.'. https://www.cbsnews.com/news/mississippi-elon-musk-xai-data-center-power-plant-noise/

  25. WilmerHale. (2026, July 13). Data Centers in Court: The Emerging Wave of Nuisance, Environmental, and Land-Use Litigation. https://www.wilmerhale.com/en/insights/client-alerts/20260713-data-centers-in-court-the-emerging-wave-of-nuisance-environmental-and-land-use-litigation


Tim Green

Tim Green UK-based Systems Theorist & Independent Technology Writer

Tim explores the intersections of artificial intelligence, decentralised cognition, and posthuman ethics. His work, published at smarterarticles.co.uk, challenges dominant narratives of technological progress while proposing interdisciplinary frameworks for collective intelligence and digital stewardship.

His writing has been featured on Ground News and shared by independent researchers across both academic and technological communities.

ORCID: 0009-0002-0156-9795 Email: tim@smarterarticles.co.uk

Listen to the free weekly SmarterArticles Podcast

Discuss...

In March 1890, an anthropologist named Jesse Walter Fewkes carried a wax-cylinder phonograph to Calais, Maine, and over three days recorded thirty-six cylinders of Passamaquoddy songs, creation stories, vocabulary and legend. The voices belonged mostly to two men, Peter Selmore and Newell Josephs. Fewkes was experimenting; he wanted to know whether the new machine could capture human speech in the field. The result is now understood to be the oldest surviving ethnographic field recording anywhere in the world. For more than a century those cylinders sat in institutional custody, first at the Peabody Museum of Archaeology and Ethnology at Harvard University and then, from 1970, inside the American Folklife Center at the Library of Congress, catalogued, preserved, and effectively unreachable by the community whose ancestors had sung into the horn. Of the original thirty-six, only twenty-six remain playable.

Nobody in 1890 asked Peter Selmore whether his voice could be digitised, indexed, transcribed by an algorithm, or fed into a statistical model that might one day predict the next word in a Passamaquoddy sentence. The question would have been unintelligible. The technologies that make it urgent did not exist, and the legal framework that might have answered it did not exist either. That gap between how the material was gathered and what can now be done with it is the precise location of a fight that reached the United Nations in the summer of 2026.

At the nineteenth session of the Expert Mechanism on the Rights of Indigenous Peoples, held at the Palais des Nations in Geneva from 13 to 17 July 2026 with a dedicated panel on artificial intelligence and the rights of Indigenous Peoples on its agenda, Indigenous advocates from several countries pressed a demand that a decade ago would have sounded speculative. They argued that artificial-intelligence systems are now being trained on, and deployed against, the vast holdings of Indigenous cultural material sitting in universities, museums, national libraries and government archives, and that the institutions holding those materials have no clear obligation to treat tribal authority over the knowledge as anything more than a courtesy. The oral histories, the language recordings, the ceremonial records, the photographs, the governance documents, much of it gathered under conditions that would fail any serious contemporary standard of informed consent, are being converted into training data and searchable outputs that serve outside purposes. The communities from which the knowledge originated are frequently the last to know.

The question at the centre of the Geneva session was not whether this is happening. It plainly is. The question was whether anyone is legally, ethically or procedurally required to stop it, or to ask first.

How an Archive Becomes a Model

To understand what changed, it helps to be precise about the mechanism. A June 2026 analysis published in Governing by Kerri J. Malloy, an assistant professor of Native American and Indigenous Studies at San José State University and a citizen of the Yurok and Karuk peoples, laid out the sequence in unsentimental terms. AI systems scrape materials held in institutional archives and digital repositories without reference to tribal authority. Those materials are converted into training data or into searchable, generative outputs. The outputs serve the purposes of the party running the system, which is almost never the community whose knowledge was ingested. Malloy, whose scholarship centres on genocide, transitional justice and the mechanics of redress, frames this not as an accident of technology but as the latest expression of a much older pattern, in which knowledge is separated from the people who hold it and put to work elsewhere.

The point worth dwelling on is that the scraping requires no malice, or even any awareness that the material is Indigenous. A digitised photographic collection, a corpus of transcribed oral histories, a set of language recordings released under an open licence by a well-meaning library: to a web crawler assembling a training set, these are simply text, image and audio. The metadata that would flag a recording as ceremonial, restricted, seasonally sensitive, or governed by protocols about who may hear it and when, is either absent or discarded during ingestion. The model learns the patterns and forgets the provenance. What comes out the other side is a system that can generate plausible imitations of a cultural form, answer questions about restricted knowledge, or reconstruct fragments of a language, without any accountability toward the community.

This is the harm that data-sovereignty scholars have described for years under the heading of data colonialism, a term meant to make the analogy explicit: just as historical colonialism appropriated land and labour, the contemporary extraction of data and knowledge appropriates the raw material of culture and computation. The analogy is not rhetorical excess. The material sitting in these archives arrived there through the same institutions, and often the same expeditions, that removed ancestral remains and ceremonial objects. The wax cylinders and the funerary belongings travelled together. That the recordings can now be reanimated by machine learning does not sever them from that history. It extends it.

What Geneva Was Actually Arguing About

The Expert Mechanism on the Rights of Indigenous Peoples is not a court, and it cannot compel anyone to do anything. Established by the Human Rights Council in 2007 under resolution 6/36, it is a body of seven independent experts that provides the Council with advice and expertise and assists states in achieving the goals of the United Nations Declaration on the Rights of Indigenous Peoples. Its authority is persuasive rather than coercive. But the instrument it exists to interpret carries more weight than its soft-law status suggests, because a great many of its provisions are now treated as reflecting customary international norms.

That instrument, the Declaration adopted by the General Assembly in 2007, contains in Article 31 a passage that reads with uncanny prescience given what has happened since. Indigenous peoples, it states, have the right to maintain, control, protect and develop their cultural heritage, traditional knowledge and traditional cultural expressions, as well as the manifestations of their sciences, technologies and cultures, including human and genetic resources, seeds, medicines, knowledge of the properties of fauna and flora, oral traditions, literatures, designs, sport and traditional games, and visual and performing arts. They also have, it continues, the right to maintain, control, protect and develop their intellectual property over such cultural heritage, traditional knowledge and traditional cultural expressions.

Read in 2007, Article 31 was understood mostly as a shield against biopiracy and the commercial appropriation of designs and medicines. Read in 2026, the phrase “maintain, control, protect and develop” runs directly into the architecture of machine learning. If a community has the right to control its traditional cultural expressions, and an AI company ingests a digitised archive of those expressions to train a commercial model, the community's control has been overridden without its involvement. The Declaration also insists, repeatedly, on the principle of free, prior and informed consent, the requirement that Indigenous peoples be consulted and give agreement before measures affecting them are taken. The Expert Mechanism has previously produced a dedicated study on the repatriation of ceremonial objects, human remains and intangible cultural heritage, explicitly bringing the intangible, the songs and stories and knowledge, within the frame of restitution. The 2026 advocates were extending that logic one step further, into the training corpus.

The gap the Geneva delegates were pointing at is the gap between principle and obligation. The Declaration says communities have the right to control. It does not say that a university digitising its holdings must obtain consent before a third party scrapes them, nor that a museum must embed enforceable restrictions in the metadata it publishes, nor that an AI developer must check provenance before ingestion. Those operational duties do not yet exist in most jurisdictions. The advocates wanted them written down.

The Principles Built Before the Machines Arrived

What makes the current moment unusual is that Indigenous communities did not wait for the AI industry to arrive before building governance frameworks. The intellectual scaffolding was largely in place, developed through the 1990s and 2000s in the context of research ethics and health data, and it maps onto the machine-learning problem with remarkable directness.

The oldest of these frameworks is OCAP, the First Nations principles of Ownership, Control, Access and Possession, established in 1998 and now administered by the First Nations Information Governance Centre in Canada. OCAP holds that a First Nation collectively owns its information in the same way an individual owns personal information; that it may assert control over data at every stage of the research cycle; that it must be able to access information about itself regardless of who physically holds it; and that possession, the physical custody of data, is the mechanism that makes ownership more than symbolic. The last principle is the sharpest when applied to AI. Possession says that if you want to protect knowledge, you keep it where you can defend it. A model trained on a copy you no longer control is the negation of possession.

The more recent and internationally influential framework is the set of CARE Principles for Indigenous Data Governance, drafted at a workshop in Gaborone, Botswana, in November 2018 and published through the Global Indigenous Data Alliance. CARE stands for Collective Benefit, Authority to Control, Responsibility and Ethics, and it was written deliberately as a counterweight to the open-data movement's FAIR principles, which hold that data should be Findable, Accessible, Interoperable and Reusable. The tension between the two acronyms is the entire argument in miniature. FAIR optimises for sharing and reuse; it says nothing about power, history or consent. CARE was built to reinsert those considerations, to say that the ease with which data can be shared is not the same as the right to share it, and that governance must account for the power differentials that shaped how Indigenous data came to sit in institutional hands. The Authority to Control principle is unambiguous when applied to a training set: the authority to decide whether a corpus becomes model weights rests with the community, not the archive.

These frameworks share a feature that distinguishes them from most Western data-protection law. They treat knowledge as collective and relational rather than as individual property with a fixed author and an expiry date. Conventional intellectual-property regimes are built around individual ownership, novelty and a term that eventually lapses into the public domain. Indigenous knowledge is frequently held communally, transmitted orally across generations, and governed by protocols that have nothing to do with authorship and everything to do with relationship, season, initiation and place. When a song enters the public domain under copyright law, the community's protocols governing who may sing it do not lapse. The two systems are not merely different in detail; they are built on incompatible premises about what knowledge is and who it belongs to. The scraping of an archive collapses that incompatibility in favour of the system that ignores protocol.

The Labels That Travel With the Knowledge

If the principles are the theory, a handful of practical tools have emerged to make them operational, and their design reveals how hard the problem actually is.

The most widely adopted is the system of Traditional Knowledge and Biocultural Labels developed by Local Contexts, an organisation co-founded by the legal scholar Jane Anderson and the digital-humanities scholar Kim Christen, and now co-directed by Christen, Anderson, Māui Hudson of Whakatōhea and James Francis of the Penobscot Nation. The Labels are not licences in the copyright sense. They are metadata, attached to cultural material, that carry the community's own statements about provenance, protocol and permission: who the cultural authority is, what traditional protocols govern access, and what uses the community regards as acceptable. A Provenance Label identifies the group that holds authority over the material. A Protocol Label communicates the customary rules attached to it. A Permission Label states what the community has approved. The point is to make Indigenous authority legible inside the metadata of a digitised collection, so that a curator, a researcher, or in principle an automated system, encounters the community's terms at the moment of access rather than never.

The companion tool comes from the same hand: Mukurtu, a free, open-source content-management system first built in 2007 by Christen and the developer Craig Dietrich for the Warumungu Aboriginal community in central Australia, and now maintained at Washington State University. Mukurtu was designed around a premise that most archives find alien: that access should be differential rather than uniform. A single item in a Mukurtu archive can be visible to the general public in one form, to community members in another, to a particular family or ceremonial group in a third, and to no one outside a restricted circle at all. Where a conventional digital repository asks how to maximise open access, Mukurtu asks who is allowed to see what, and encodes the answer.

The Passamaquoddy cylinders became the demonstration case for all of this. When the Library of Congress launched its Ancestral Voices project, engineers at its National Audiovisual Conservation Center used an Archéophone playback machine and digital restoration systems to extract sound from the 1890 wax that had been physically unplayable, and then, crucially, handed curatorial control back toward the Tribe. Passamaquoddy speakers transcribed and translated the recordings; elders reviewed them; the material was described using Mukurtu and tagged with Local Contexts Traditional Knowledge Labels, so that the digitised voices now travel with the community's own statements of authority and protocol attached. It is the closest thing to a model of how digital repatriation can work when an institution chooses to share power rather than merely access.

But the Passamaquoddy case also exposes the limit of the whole apparatus, and it is a limit the Geneva advocates understood well. Labels and differential access work only inside systems that agree to honour them. A Traditional Knowledge Label is metadata; a web crawler assembling a training corpus is under no obligation to read it, and a large language model does not preserve it. The moment a labelled recording is copied outside the governed platform, whether by an open-data release, a partner institution's mirror, or a scraper that ignores robots directives, the protocol evaporates. The tools that Indigenous communities built to assert authority were designed for a world of human curators making deliberate choices about individual items. They were not designed for a world of automated ingestion at web scale, where the default is to take everything and ask nothing.

When Revitalisation and Extraction Use the Same Tool

The uncomfortable truth threaded through the whole debate is that the technology now driving the extraction is the same technology offering some communities their best hope of linguistic survival. This is not a case where the harm and the benefit are cleanly separable. They run through the identical set of tools.

An analysis published in July 2026 by researchers at the University of Melbourne made the double edge explicit. The same AI systems that can support Indigenous language revitalisation, generating learning materials, reconstructing grammatical patterns from fragmentary historical records, filling gaps in documentation left by generations of suppression, can, if they are built and controlled by outside institutions, deepen the very patterns of extraction they appear to remedy. The mechanism is concentration of authority. A language model that becomes the authoritative interface to a language, trained on the community's own recordings but owned and operated by a university or a company, does not restore control. It relocates it. The community becomes a user of a system built from its own knowledge, dependent on an institution it cannot govern. The Melbourne researchers were echoing a broader body of work, including a systematic review by the same group published in 2025, that has repeatedly found the governance question, who owns and controls the system, to be more decisive than the technical question of whether the tool works. A separate 2026 review in AI & Society, examining AI projects in Irish Gaelic, Māori, Guaraní and Inuktitut through the lens of data colonialism, reached the same place by a different route: what divides the initiatives that empower communities from those that reproduce extractive structures is not the model but who holds the data and sets the terms.

The counter-example that everyone in this field cites is Te Hiku Media, a charitable media organisation based in Kaitaia, in the far north of New Zealand's North Island, and belonging collectively to the Far North iwi of Ngāti Kuri, Te Aupōuri, NgāiTakoto, Te Rarawa and Ngāti Kahu. Facing the same problem every Indigenous community faces, that the large technology firms had little commercial interest in a language spoken by a few hundred thousand people, Te Hiku built its own. Through a crowdsourcing campaign called Kōrero Māori, it gathered more than three hundred hours of labelled speech in ten days, from more than 2,500 people reading over 200,000 phrases, and in 2021 released an automatic speech-recognition model for te reo Māori that reportedly reached around ninety-two per cent accuracy, outperforming the offerings of far larger companies on the language. The decisive move was not technical but legal. Te Hiku placed the resulting data and models under what it calls the Kaitiakitanga Licence, a bespoke instrument built on the Māori concept of guardianship, which keeps data sovereignty inside the community, prohibits uses that would surveil or discriminate, and ensures the data is used for the benefit of Māori. The organisation refused, publicly and repeatedly, to hand its speech corpus to outside firms, on the grounds that the community had gathered the data as a taonga, a treasure held in trust, not as a commodity to be sold.

Te Hiku is the proof of concept for the Geneva argument, because it demonstrates that Indigenous-governed AI is not a contradiction in terms. The community built the tool, kept the data, wrote the licence, and set the terms of use. What Te Hiku had, that most communities do not, was the technical capacity, the funding and the pre-existing organisational strength to do all of that itself. The Melbourne researchers' warning is aimed at the far more common situation, in which the community lacks the capacity to build its own system and the institution holding the material builds one instead, positioning itself, however benevolently, as the permanent intermediary between a people and its own language.

Every strand of this returns to the conditions under which the material was collected in the first place, and here the historical record is not ambiguous. The great archives of Indigenous cultural material were assembled overwhelmingly during the late nineteenth and twentieth centuries, in a period when the collecting institutions operated on the salvage assumption, the belief that Indigenous peoples were vanishing and that their cultures had to be recorded before they disappeared. The people recorded were rarely in any position to refuse, frequently were not asked, and could not conceivably have consented to uses that had not been invented. Fewkes did not, and could not, obtain Peter Selmore's agreement for a use case that would arrive one hundred and thirty years later.

This is what makes the informed-consent argument so difficult to wave away. When an institution says that its collection is lawfully held and that it is free to license or release it, the claim is legally true and ethically hollow, because the original acquisition would fail every element of the standard that institution would now apply to a living research subject. Contemporary research ethics require that consent be informed, specific, revocable and given by someone with the authority to give it. The archival material fails on all four counts. It was gathered without meaningful information about future use, without specificity, without any mechanism of revocation, and often from individuals who held the knowledge under community protocols that did not give them the personal authority to alienate it. A speaker might share a song with a visiting anthropologist without possessing the right, under his own community's law, to release it to the world.

The AI moment forces this latent problem into the open because it dramatically raises the stakes of the downstream use. For a century the material mostly sat inert, and the injustice of its acquisition, while real, was static. Digitisation made it copyable. Machine learning makes it generative. A model trained on a corpus of restricted ceremonial knowledge does not merely store that knowledge; it can produce new outputs in its style, answer questions about it, and disseminate approximations of it to anyone who asks. The original failure of consent is thereby compounded and multiplied, and the community's ability to enforce its own protocols, already eroded by digitisation, collapses entirely. The advocates in Geneva were not raising a historical grievance for its own sake. They were pointing out that the historical grievance is now the input to an industrial process.

Where the Law Stops Short

The obvious question is why existing law does not already resolve this, and the answer is that the relevant instruments were built for adjacent problems and stop short of the AI training set.

The most significant recent development is the WIPO Treaty on Intellectual Property, Genetic Resources and Associated Traditional Knowledge, adopted at a diplomatic conference in Geneva in May 2024 after decades of negotiation. It is the first WIPO treaty to deal with the interface between intellectual property and Indigenous knowledge, and its central mechanism, in Article 3, requires patent applicants to disclose the source or origin of genetic resources and associated traditional knowledge on which an invention is based. This matters, but its reach is narrow. It applies to patents, not to training data. It addresses the specific problem of patents being granted over Indigenous knowledge without acknowledgement, not the general problem of that knowledge being ingested by a model. And it enters into force only after fifteen states ratify it. Malawi deposited its instrument on 5 December 2024 and Uganda followed on 9 July 2025. That is the entire tally. Thirteen further ratifications are required, and more than two years after adoption the treaty is still not in force. The treaty is a disclosure requirement for one narrow channel of appropriation, not a consent requirement for the broad one, and even that narrow requirement is not yet law anywhere.

In the United States, the closest analogue is the Native American Graves Protection and Repatriation Act, whose revised regulations took effect in January 2024 and notably strengthened the requirement that institutions obtain consent from lineal descendants or tribes before exhibiting or conducting research on covered items. Those revisions prompted several major museums to close or cover Native American displays overnight while they sought the necessary consent. But NAGPRA governs human remains, funerary objects, sacred objects and objects of cultural patrimony in physical custody. It does not cleanly reach digitised sound, transcribed oral history or a language corpus, and it certainly does not reach a model trained on them. The statute that forced museums to reckon with consent for physical objects has no obvious purchase on the intangible material now flowing into AI systems.

Copyright, the tool a technology company would most naturally invoke, cuts the wrong way entirely. Much archival Indigenous material is old enough to be in the public domain, which under copyright law means it may be freely used, and the ongoing legal battles over whether training AI on copyrighted material constitutes fair use are, from an Indigenous-knowledge perspective, almost beside the point. The community's objection is not that its copyright has been infringed; it is that copyright never captured the interest at stake. A song can be simultaneously in the copyright public domain and subject to strict community protocols about who may perform it. The law that governs the copy has nothing to say about the protocol. This is the misalignment that CARE, OCAP and the Traditional Knowledge Labels were invented to address, and it is why the Geneva advocates were appealing to human-rights instruments rather than intellectual-property ones. The rights they are asserting do not fit inside the categories the technology industry recognises.

Procurement as the Real Decision Point

If the frameworks exist and the law lags, the practical question becomes where in the process an obligation could actually bite, and here the answer is less about technology than about timing.

Malloy's Governing analysis ends not with a call for better algorithms but with a call for meaningful tribal consultation before AI systems are designed and deployed, rather than notification after the fact. This is a deceptively large claim. In the ordinary institutional workflow, an organisation decides to acquire or build an AI system, selects a vendor, signs a contract, and only then, if at all, convenes a consultation about ethics and community impact. By that stage the architecture is fixed, the money is committed, and the consultation can influence little beyond the wording of a usage policy. Authority exercised after procurement is not authority at all; it is public relations. For tribal control to be real, the community's right to say no, or to set conditions, has to be available at the point where saying no would actually change the outcome, which is before the institution commits to building the thing.

This reframes the debate away from the familiar terrain of algorithmic transparency and bias auditing, which are downstream remedies, and toward the upstream decision that determines whether a system gets built at all. It aligns with the free, prior and informed consent standard in a way that most technology governance conspicuously does not, because the word that governance frameworks routinely underweight is prior. Consent obtained after deployment is not prior consent. A consultation convened to smooth the reception of a decision already taken is not consent in any meaningful sense. The whole argument is about procedural sequencing: who is in the room, and at what stage, is where Indigenous authority is either honoured or hollowed out.

What earlier involvement looks like in practice is beginning to be documented. A March 2026 paper by Dora Zhao and colleagues describes a series of co-design workshops with twenty-two public school educators in Hawai'i, convened around the educators' own concerns about cultural misrepresentation and bias in AI systems. Its argument is that auditing an AI system should be understood as a community-oriented process rather than the work of isolated individuals. The tools that emerged from those workshops were shaped by the participants' concerns because the participants were in the room while the tools were still taking shape, which is precisely the condition that late-stage consultation cannot reproduce.

The practical implications are concrete. A university library deciding whether to make its Indigenous collections available to an AI vendor would, under this logic, be obliged to consult the relevant communities before issuing the tender, not after signing it. A national museum contemplating a generative-AI interface to its holdings would need to bring the source communities into the design while fundamental choices, what is included, what is excluded, who governs access, remain open. Most institutions do the opposite, treating community consultation as a late-stage validation exercise, which is exactly the failure mode Malloy identifies.

Sovereignty as a Precondition, Not a Courtesy

The most ambitious of the recent contributions tries to move the whole conversation from ethics to architecture. A 2026 paper in AI & Society setting out a pluralistic, participatory approach to global AI governance argues that Indigenous knowledge systems and the right of Indigenous peoples to self-determination, underpinned by free, prior and informed consent and the CARE Principles, must be foundational to AI regulation rather than an optional addition to it. Its foundational move is to treat the right of a cultural community to exclude, limit, or set conditions on AI use of its knowledge not as an ethical enhancement but as a structural requirement of the system. In that framing, the ability of a community to say no is not a feature to be added if resources permit. It is a precondition of the system being legitimate at all. A knowledge system that cannot represent and enforce the exclusion is, on this account, defective by design, in the same way that a database without access controls would be considered defective.

This is the intellectual heart of what the Geneva advocates were reaching toward, and it inverts the default. The prevailing institutional posture treats tribal authority as something to be accommodated where feasible: a nice-to-have, honoured when a community is organised enough to demand it and convenient enough to grant. The sovereignty argument insists on the reverse. Authority over the knowledge is the starting condition. The burden is not on the community to prove why its knowledge should be withheld, but on the institution and the developer to establish that they have the right to use it at all. This is the same inversion that free, prior and informed consent performs in every other domain of Indigenous rights: consent is presumed absent until it is actively and legitimately given, rather than presumed present until someone objects.

The tradition this draws on is now substantial and cannot be dismissed as marginal. The Indigenous Protocol and Artificial Intelligence Position Paper, produced in 2020 out of workshops led by the scholar and artist Jason Edward Lewis and involving more than thirty researchers and artists, argued years ahead of the current wave that AI must be designed in partnership with specific communities rather than around assumed universal values, that Indigenous communities must retain full control over their own data, and that ethical scrutiny must extend across the entire development process. That work has since grown into Abundant Intelligences, an Indigenous-led international research programme rethinking what AI could be if it were placed inside Indigenous knowledge systems rather than extracting from them. UNESCO has moved in the same direction, releasing guidance on Indigenous data sovereignty in AI and a report on Indigenous people-centred artificial intelligence developed with communities across Latin America and the Caribbean, insisting that the digitisation of Indigenous data must guarantee self-determination, governance and free, prior and informed consent. The direction of travel in the normative literature is unmistakable. It has simply not yet been translated into binding obligation.

That translation is what the July 2026 session in Geneva was ultimately about. The advocates were not asking whether AI can be used on Indigenous knowledge, a question the archives and the models have already answered. They were asking whether the institutions holding these materials carry any enforceable duty to treat tribal authority as a precondition of deployment rather than a gesture of goodwill. On the current state of the law the answer is mostly no. There are principles without teeth, labels without reach, a treaty confined to patents and still short of the ratifications it needs, a repatriation statute confined to physical objects, and a copyright regime that measures the wrong thing. What there is not, yet, is a rule that says an archive must ask before it lets a model in.

The wax cylinders in Calais have travelled a long way from the horn Fewkes spoke into. They have been catalogued, restored, digitised, labelled and, in the Passamaquoddy case, partly returned. Whether the next generation of that material, the recordings not yet governed by a Traditional Knowledge Label, the collections not yet subject to a differential-access system, the languages not yet defended by a community strong enough to write its own licence, is treated as a training set or as a trust will depend on decisions that institutions are making right now, mostly without asking. The people who sang into the machine could not consent to what would be done with their voices. The least their descendants are owed is the standing to decide.

References

  1. Malloy, Kerri J. “The Protection That Tribal Nations' Data Needs.” Governing, 9 June 2026. https://www.governing.com/management-and-administration/the-protection-that-tribal-nations-data-needs
  2. Office of the United Nations High Commissioner for Human Rights. “Expert Mechanism on the Rights of Indigenous Peoples.” https://www.ohchr.org/en/hrc-subsidiaries/expert-mechanism-on-indigenous-peoples
  3. Office of the United Nations High Commissioner for Human Rights. “Indigenous Peoples' rights in conflict situations and Artificial Intelligence on the agenda at Expert Mechanism session.” July 2026. https://www.ohchr.org/en/press-releases/2026/07/indigenous-peoples-rights-conflict-situations-and-artificial-intelligence
  4. United Nations. “United Nations Declaration on the Rights of Indigenous Peoples,” Article 31, 2007. https://www.un.org/development/desa/indigenouspeoples/declaration-on-the-rights-of-indigenous-peoples.html
  5. First Nations Information Governance Centre. “The First Nations Principles of OCAP.” https://fnigc.ca/ocap-training/
  6. Carroll, S. R., et al. “The CARE Principles for Indigenous Data Governance.” Data Science Journal, 2020. https://datascience.codata.org/articles/10.5334/dsj-2020-043
  7. Global Indigenous Data Alliance. “CARE Principles for Indigenous Data Governance.” https://www.gida-global.org/careprinciples
  8. Local Contexts. “Traditional Knowledge (TK) Labels.” https://localcontexts.org/labels/traditional-knowledge-labels/
  9. Mukurtu CMS. “About Mukurtu.” Center for Digital Scholarship and Curation, Washington State University. https://mukurtu.org/
  10. Institute of Museum and Library Services. “Mukurtu Software Preserves Indigenous Digital Heritage.” https://www.imls.gov/grant-spotlights/mukurtu-software-preserves-indigenous-digital-heritage-through-technologies-today
  11. Library of Congress. “Ancestral Voices — About this Collection.” https://www.loc.gov/collections/ancestral-voices/about-this-collection/
  12. National Recording Preservation Board, Library of Congress. “Jesse Walter Fewkes field recordings of the Passamaquoddy Indians (1890).” https://www.loc.gov/static/programs/national-recording-preservation-board/documents/Fewkes-Passamaquoddy-Indians-field-recordings_Revak.pdf
  13. NPR. “Historic Recordings Revitalize Language For Passamaquoddy Tribal Members,” 3 September 2019. https://www.npr.org/2019/09/03/748604202/historic-recordings-revitalize-language-for-passamaquoddy-tribal-members
  14. Te Hiku Media. “Kaitiakitanga Licence and Kōrero Māori.” https://tehiku.nz/te-hiku-tech/
  15. NVIDIA Blog. “Māori Speech AI Model Helps Preserve and Promote New Zealand Indigenous Language.” https://blogs.nvidia.com/blog/te-hiku-media-maori-speech-ai/
  16. Perera, M., Vidanaarachchi, R., Chandrashekeran, S., Kennedy, M., Kennedy, B., and Halgamuge, S. “Indigenous peoples and artificial intelligence: A systematic review and future directions.” Big Data & Society, 2025. https://journals.sagepub.com/doi/10.1177/20539517251349170
  17. Vidanaarachchi, Rajith, Perera, Maneesha, Chandrashekeran, Sangeetha, Kennedy, Brendan, and Halgamuge, Saman. “AI must be built with Indigenous Knowledges, not against them.” Pursuit, University of Melbourne, 3 July 2026. https://pursuit.unimelb.edu.au/articles/ai-must-be-built-with-indigenous-knowledges,-not-against-them
  18. “Data colonialism and indigenous languages in AI: a critical review of existing initiatives and their struggles with data sovereignty.” AI & Society, 2026. https://link.springer.com/article/10.1007/s00146-026-03091-w
  19. World Intellectual Property Organization. “Summary of the WIPO Treaty on Intellectual Property, Genetic Resources and Associated Traditional Knowledge (2024).” https://www.wipo.int/en/web/treaties/ip/gratk/summary_gratk
  20. National Park Service. “Native American Graves Protection and Repatriation Act — Revised Regulations (2024).” https://www.nps.gov/subjects/nagpra/index.htm
  21. Zhao, Dora, et al. “Whose Knowledge Counts? Co-Designing Community-Centered AI Auditing Tools with Educators in Hawai'i.” arXiv:2603.16646, March 2026. https://arxiv.org/abs/2603.16646
  22. “Pluralistic AI governance: Indigenous knowledge and the right of Indigenous peoples to self-determination.” AI & Society, 2026. https://link.springer.com/article/10.1007/s00146-026-02938-6
  23. Lewis, Jason Edward (ed.). “Indigenous Protocol and Artificial Intelligence Position Paper.” Indigenous AI Working Group and CIFAR, 2020. https://spectrum.library.concordia.ca/986506/
  24. Lewis, J. E., Whaanga, H., and Yolgörmez, C. “Abundant intelligences: placing AI within Indigenous knowledge frameworks.” AI & Society, 2024. https://link.springer.com/article/10.1007/s00146-024-02099-4
  25. UNESCO. “New report and guidelines for indigenous data sovereignty in artificial intelligence developments.” Global AI Ethics and Governance Observatory. https://www.unesco.org/ethics-ai/en/articles/new-report-and-guidelines-indigenous-data-sovereignty-artificial-intelligence-developments

Tim Green

Tim Green UK-based Systems Theorist & Independent Technology Writer

Tim explores the intersections of artificial intelligence, decentralised cognition, and posthuman ethics. His work, published at smarterarticles.co.uk, challenges dominant narratives of technological progress while proposing interdisciplinary frameworks for collective intelligence and digital stewardship.

His writing has been featured on Ground News and shared by independent researchers across both academic and technological communities.

ORCID: 0009-0002-0156-9795 Email: tim@smarterarticles.co.uk

Listen to the free weekly SmarterArticles Podcast

Discuss...

There is a particular kind of person who opens a large language model a dozen times a day, leans on it to draft the awkward email and summarise the reading and untangle the spreadsheet, and who, if you asked them whether they trusted the thing, would look at you as though you had asked whether they trusted a vending machine. They use it. They do not believe in it. The two facts sit together without friction, because for this person they were never in tension to begin with.

That person is, statistically, most likely to be young. According to a Gallup survey of Americans aged 14 to 29, conducted between 24 February and 4 March 2026 and released that April, fifty-one per cent of Generation Z now uses generative artificial intelligence at least weekly. This is the cohort born between 1997 and 2012, the demographic that has folded these tools into study, work and daily life more thoroughly than any other. And yet, in the same survey, sixty-nine per cent of Gen Z workers said they placed more trust in work completed without AI, against twenty-eight per cent who placed it in work produced with AI's assistance. Only three per cent reserved their greatest trust for output generated solely by a machine. The people who use the technology most are the people who believe in it least.

This is not the story the industry told itself it was writing. The implicit promise of consumer AI was that familiarity would breed confidence, that once people saw what the systems could do the scepticism would melt into dependence and dependence into faith. The opposite has happened. Exposure has curdled into wariness. And the wariness is sharpest precisely where exposure is deepest. A Fortune analysis published in April 2026, drawing on research by the enterprise AI firm Writer and the consultancy Workplace Intelligence, found that forty-four per cent of Gen Z workers admitted to actively sabotaging their employer's AI rollout, against twenty-nine per cent of workers overall. These are not refuseniks standing outside the technology and lobbing stones. They are inside it, using it daily, and quietly undermining it at the same time.

The question this poses is not the tired one about whether AI is good or bad. It is stranger and more revealing. What does it tell us about the state of AI deployment in 2026 that the most technologically fluent generation alive has become its most committed sceptics? And if their doubt is not ignorance, but something closer to experience, what would it actually take for trust to be earned rather than simply assumed?

The Numbers Behind a Generational Rupture

It is worth being precise about the data, because the precision is where the story lives. The headline figures are frequently muddled in the retelling, and the muddle flattens something important.

The 2026 Gallup study, based on a probability sample of 1,572 young Americans with a margin of error of plus or minus 3.6 percentage points, did not merely record low trust. It recorded a slide. Among employed Gen Z respondents, forty-eight per cent said the risks of AI in the workforce now outweighed the benefits, up from thirty-seven per cent a year earlier, while only fifteen per cent judged the benefits greater. Excitement about the technology fell fourteen points in twelve months, to twenty-two per cent. Hopefulness dropped nine points. Anger rose nine, to thirty-one per cent. Curiosity remained the emotion this generation reports most often, at forty-nine per cent — but anxiety ran a close second at forty-two per cent, unmoved from the year before, holding its ground while the positive feelings collapsed around it. That is the shape of the shift, and it is more telling than a simple slump would be: a generation still interested, no longer optimistic. The same study found forty-two per cent judged AI harmful to critical thinking, against twenty-five per cent who found it helpful, and eighty per cent reckoned their own use of it likely to impair future learning. Perhaps most damningly, a separate survey published that May by the software firm GoTo and the consultancy Workplace Intelligence found that forty-six per cent of Gen Z workers said AI was making them “dumber,” compared with thirty-nine per cent of workers overall.

The broader adult population is not exactly a fountain of confidence either, though its scepticism is quieter. A YouGov poll of American adults conducted in early December 2025 found that just five per cent said they trusted AI “a lot.” Over the preceding year, twenty-five per cent reported that their trust in the technology had fallen, against twenty-one per cent who said it had risen — a net erosion at exactly the moment the tools were becoming inescapable. A separate Quinnipiac University poll published in late March 2026 found that seventy-six per cent of Americans trusted AI only rarely or sometimes, that seventy per cent believed it would reduce job opportunities, and that seventy-six per cent felt businesses were not being transparent about how they used it. The share of employed Americans who worried their own job would become obsolete had risen to thirty per cent from twenty-one per cent a year before.

Set these numbers beside the adoption curves and the dissonance becomes almost vertiginous. Just under half of American adults now use AI chatbots — forty-nine per cent, up from a third in 2024. Usage is climbing steeply. Trust is not merely failing to climb with it. Trust is going the other way. The two lines have decoupled, and the wider the gap grows the more it demands explanation, because in almost every historical case familiarity with a technology has tracked comfort with it. Cars, aeroplanes, the internet, the smartphone — each followed a rough arc in which early fear gave way to routine as competence accumulated. AI, so far, is refusing to trace that arc. It is being adopted and distrusted at the same time, by the same people, with the intensity of both rising in parallel.

Why Adoption Was Never the Same as Endorsement

The industry's confusion on this point stems from a category error that runs deep in how technology companies read their own metrics. They treat usage as a verdict. If the numbers go up, the product is winning; the market has spoken; the doubters will come around. This is a serviceable heuristic for a video game or a food-delivery app, products people choose freely and abandon freely, where continued use really is a decent proxy for satisfaction.

It is a terrible heuristic for AI, because AI is increasingly not chosen. It is arriving pre-installed. It sits at the top of the search results whether or not you asked for a generated summary. It is stitched into the word processor, the email client, the customer-relationship platform, the operating system. It is mandated by the employer who has bought an enterprise licence and set adoption targets that show up in performance reviews. When a tool is embedded in the infrastructure of daily work and daily life, using it stops being an endorsement and becomes something more like breathing the available air. You do it because it is there, not because you have appraised it and found it worthy.

This is the phenomenon that the data on Gen Z brings into focus with unusual clarity. The Brookings Institution analysis by Josie Stewart and Brooke Tanner, published on 22 July 2026 under the pointed title “Policy—not PR—will determine Gen Z's trust in AI,” makes the underlying dynamic explicit. Stewart, a senior research and communications assistant, and Tanner, a research analyst, note that around half of Gen Z uses generative AI at least weekly while expressing some of the deepest reservations of any group — a pattern they read not as confusion but as coherence. High use and low trust are not, in their account, a contradiction to be resolved. They are the natural product of a situation in which people are compelled into contact with a technology they have had ample opportunity to appraise, and have appraised without illusion.

The distinction between adoption and endorsement matters because the industry keeps mistaking the first for the second and then acting surprised when the sabotage figures come in. Forty-four per cent of Gen Z workers undermining an AI rollout is not the behaviour of a market that has spoken in favour. It is the behaviour of people who have been given a tool they did not ask for, told to use it, and found the quiet forms of resistance — feeding it junk, routing around it, declining to trust its output — that remain available when the loud form, refusal, has been taken off the table. Adoption, in this light, is not the end of the trust problem. It is the container in which the trust problem is now being fought.

A Distrust That Was Learned, Not Inherited

The comforting explanation for all this, and the one the technology sector has reached for most often, is that the scepticism is a deficit — of knowledge, of literacy, of exposure. Young people are anxious, the reasoning goes, because they do not understand the technology well enough to see its promise, and the remedy is education: more AI-literacy programmes, better onboarding, clearer communication about capabilities and limits. It is a flattering theory for those who hold it, because it locates the problem entirely in the user and requires nothing of the product.

The theory has one fatal weakness. The people expressing the deepest doubt are the ones who understand the technology best. A September 2025 Pew Research Center survey found that sixty-two per cent of adults under thirty had heard “a lot” about AI, the highest of any age group — and this same, best-informed cohort was the most pessimistic, with sixty-one per cent saying the technology would worsen people's ability to think creatively and fifty-eight per cent saying it would erode their capacity to form meaningful relationships, both figures around twenty points higher than among those over sixty-five. By February 2026, a further Pew survey had stated the whole decoupling in one cohort's own numbers: sixty-six per cent of adults aged 18 to 29 used AI chatbots and thirty-one per cent used them daily, making them the heaviest-using age group in the country, while just fourteen per cent expected AI's effect on society to be positive and forty-eight per cent expected it to be negative. The heaviest users are the least persuaded, and by some distance. The scepticism does not recede as understanding grows. It deepens. This is the single most inconvenient fact for the literacy theory, and it is decisive: you cannot educate people out of a conclusion they reached by paying attention.

The Brookings analysis and a companion Fortune essay by the outlet's editor Nick Lichtenberg, published on 16 April 2026, converge on the same reframing. The distrust is not irrational. It is earned. It reflects first-hand experience of a specific and repeated kind. Gen Z has watched AI systems state falsehoods with total confidence, the phenomenon the field politely calls hallucination and everyone else calls being wrong without knowing it. They have generated content with these tools and then been penalised for it by institutions — more than half of college students report that their schools either discourage AI use, at forty-two per cent, or ban it outright, at eleven per cent, even as sixty-three per cent of faculty concede that their 2025 graduates were not prepared to use AI in the workplaces that now demand it. They have been told the technology is a co-pilot and then watched it fold the entry-level jobs where they expected to build the very judgement that would let them supervise it.

There is a body of research that lends this lived experience empirical teeth. A June 2025 preprint from the MIT Media Lab reported weaker neural connectivity and poorer recall among participants who wrote essays with the help of a large language model, compared with those who wrote unaided. A study by Microsoft Research and Carnegie Mellon University, surveying 319 knowledge workers across 936 AI-assisted tasks, found that higher confidence in a generative system was associated with less critical thinking, not more. Work by Michael Gerlich at the SBS Swiss Business School in 2025 found that heavier AI use correlated with greater cognitive offloading and lower critical-thinking scores, an effect most pronounced among younger participants. None of this proves that AI makes people less capable in any simple causal sense. But it means that when nearly half of Gen Z reports the technology is making them “dumber,” they are describing something that researchers are independently measuring. The feeling has a footing.

What emerges is a distrust that was not inherited from anxious parents or absorbed from alarmist media, but assembled, piece by piece, from direct encounter. And it is active rather than passive. A Skyword survey of a thousand American consumers, published in June 2026, found that sixty-seven per cent of Gen Z respondents were using AI more than they had a year earlier, against fifty-two per cent of consumers overall, and that nearly one in three had contacted a brand directly to correct something an AI tool had said about it — close to double the rate of the general population. They do not merely doubt the output. They check it, and then they go to the trouble of reporting what they find. It is the scepticism of the mechanic who has looked under the bonnet, not the passenger who is nervous about the noise.

The Quiet Erasure of the First Rung

If there is a single grievance that anchors the generational rupture, it is the disappearance of the entry-level job, and it deserves to be understood on its own terms, because it connects the abstract question of trust to something concrete and material.

The traditional path into skilled work runs through a period of supervised incompetence. The junior analyst builds the model badly and is corrected. The trainee lawyer drafts the memo, has it torn apart, and drafts it again. The apprentice does the tedious, low-stakes work under the eye of someone who has done it a thousand times, and in the doing acquires the judgement that eventually lets them do the high-stakes work and, later still, supervise the next apprentice. The tedium is not incidental to expertise. It is the mechanism by which expertise is transmitted. Remove the bottom rung and you do not simply inconvenience the people standing on it. You break the ladder.

This is precisely the function that generative AI is best at absorbing. The summarising, the first drafts, the routine research, the boilerplate code — the substance of entry-level work is also the substance of what these systems do most competently. The consequence is measurable. Lichtenberg's Fortune analysis reports that junior hiring fell nearly eight per cent within six quarters at companies adopting AI, and that unemployment among recent college graduates reached 5.7 per cent in the fourth quarter of 2025, exceeding the national rate, with underemployment among recent graduates standing at 42.5 per cent, the highest since 2020. The displacement is arriving not through dramatic mass layoffs but through what Lichtenberg calls “quiet erasure” — the junior role that is never posted, the pipeline that thins one unfilled vacancy at a time.

The concern here is old, even if the technology is new. In 1974 the Marxist theorist Harry Braverman, in his study of the twentieth-century workplace, described the way industrial management systematically stripped skill out of jobs, concentrating judgement in a shrinking managerial layer while the majority were left with degraded, deskilled tasks. In 1983 the ergonomics researcher Lisanne Bainbridge, in a paper on automation that has only grown more relevant, identified what she called the “ironies of automation”: that the more you automate a system, the more critical and the more difficult the residual human role becomes, because the human is now expected to monitor a process they no longer routinely perform and to take over precisely in the moments the machine cannot handle — the moments that require exactly the fluent competence the automation has prevented them from maintaining. A generation that has been handed AI to do its formative work, and then told it will one day be expected to oversee that AI, has read Bainbridge without needing to read Bainbridge. It has intuited the trap. You cannot supervise what you were never allowed to learn.

This is why the deskilling anxiety is not nostalgic or self-pitying. It is a structurally sound observation about how competence is built and how it is being interrupted. When a young worker distrusts a system that produces confident output while quietly eroding the conditions under which they might learn to check that output, they are not being irrational. They are noticing the mechanism.

When Opting Out Stops Being an Option

The most under-examined aspect of this whole predicament is the one the brief that prompted this essay named directly: millions of people, disproportionately young, now use AI tools daily not because they trust them but because opting out is no longer practically available. The condition deserves a name of its own — compelled adoption — because it inverts the usual relationship between a technology and its user.

Consider the ordinary surfaces of a working life in 2026. The search engine returns an AI-generated summary above the links, so that even the act of looking something up now routes through a generative system whether or not you wanted it to. The office suite offers to draft, rewrite and summarise, and increasingly assumes you will accept. The employer has purchased seats and set targets; the Bentley-Gallup research on business AI has long shown that adoption is being driven from the top down, and the Writer and Workplace Intelligence survey underlying the sabotage figures polled 2,400 knowledge workers precisely because their firms were rolling the tools out to them, including 1,200 executives doing the rolling. To decline, in this environment, is not a neutral act of consumer preference. It is to fall behind colleagues, to miss targets, to mark yourself as a resister in an organisation that has decided the future is settled.

Compelled adoption changes the meaning of every usage statistic the industry cites. When a company boasts that a tool has reached fifty per cent weekly penetration among young workers, it is describing, in part, the success of its own mandate, not the freely given approval of its users. And it changes the meaning of resistance, too. If you cannot refuse the tool, the only forms of dissent left are the small, deniable ones the sabotage research catalogues: feeding proprietary information into public models where it should not go, using unapproved tools instead of the sanctioned one, quietly producing lower-quality AI output to make the system look less effective, tampering with the metrics that would show it succeeding. These are not the tactics of people who have been persuaded. They are the tactics of people who have been conscripted and are looking for the exits.

There is something almost poignant in the figure of the reluctant user — the person who has internalised the futility of refusal so completely that they no longer even frame it as a choice, who reaches for the tool with one hand while withholding belief with the other. This is not the enthusiastic early adopter of technology mythology, nor the noble refusenik of the resistance narrative. It is a third thing, less legible and more common: the person who complies and does not consent, who has separated the practical question of use from the moral question of trust because the practical question was decided for them. Millions of people now live in this posture, and the industry's dashboards cannot see them, because the dashboards were built to count clicks, not to detect the quiet withdrawal of faith behind them.

The Long History of Trusting Machines

None of this is quite as unprecedented as the breathlessness of the moment suggests, and the historical parallels are worth drawing not to diminish the present but to calibrate it.

The Luddites of 1811 to 1816 have been so thoroughly reduced to a slur — a Luddite is now simply a fool who fears progress — that their actual grievance has been buried. The framework-knitters and croppers who broke machines in the English Midlands were not against technology as such. Many were skilled operators of the machinery of their trade. Their objection was to a specific deployment of new machines by owners who used them to drive down wages, circumvent labour standards and concentrate the gains of higher productivity in their own hands, while the workers who had built the industry's skill base were cast off. Their quarrel, in other words, was not with the loom but with the distribution of the loom's benefits and the absence of any say over how it was introduced. Read the contemporary data on AI — the seventy per cent who expect it to cut jobs, the sabotage, the demand for transparency and recourse — and the rhyme is unmistakable. The distrust has never really been of the machine. It has been of the arrangement around the machine.

The twentieth century added a subtler lesson. As automation spread through cockpits and control rooms, researchers documented a phenomenon they called automation bias: the human tendency to over-trust an automated system, to defer to its output even when it was wrong and even when contrary evidence was available. The danger of automation, it turned out, was rarely that people rejected it. It was that they surrendered to it too completely, ceding judgement to a machine that did not deserve the deference. Seen against this history, the Gen Z posture — high use, low trust, judgement withheld — starts to look less like a pathology and more like a hard-won corrective. A generation that refuses to grant automation the deference it has not earned is a generation that has, perhaps unknowingly, absorbed the central safety lesson of the automation age.

And then there is the economist Robert Solow's famous observation from 1987, at the height of the office-computing boom, that “you can see the computer age everywhere but in the productivity statistics.” The productivity paradox he named has an eerie contemporary echo. For all the money and disruption, the aggregate productivity gains from generative AI remain, as of 2026, stubbornly hard to locate in the macroeconomic data. Transformative technologies, from the steam engine to electrification to the personal computer, have historically taken decades to deliver their promised gains, precisely because realising them requires reorganising the institutions, skills and trust relationships around the machine — the very things that are currently in open dispute. The trust deficit is not a delay before the revolution. It may be part of the mechanism by which any real gains are either eventually secured or permanently squandered.

What Recourse Would Actually Look Like

If the distrust is earned, then the standard remedies are worse than useless, and this is the sharpest edge of the Brookings argument. Stewart and Tanner are explicit that the trust deficit will not be closed by better marketing or another round of AI-literacy campaigns, because the deficit is not a communications failure. You cannot advertise your way out of a conclusion that people reached through experience. What would close it, they argue, is substantive change that gives people meaningful oversight and genuine recourse over the systems that affect their lives — the ability not merely to be told an AI was used, but to contest its output, to reach a human, to seek redress when it errs.

The tech industry's own gestures, Stewart and Tanner note, have been telling in their inadequacy: chief executives pledging to cover the electricity costs of their data centres, walking back their more lurid layoff predictions, offering voluntary reassurances. These are the moves of institutions that understand there is a problem and hope it can be managed with goodwill rather than obligation. But the same research documents why goodwill will not suffice. Over the past decade, Americans' confidence in technology firms has fallen faster than their confidence in most other institutions, and the youngest cohort has lost faith in the major tech companies faster than any other group. These are the same firms now asking to be trusted. Voluntary commitments from actors whose credibility is itself in freefall are not a foundation on which trust can be rebuilt.

The alternative is binding. Some of the scaffolding already exists. The European Union's AI Act, which entered into force in 2024 and is being phased in across the middle of the decade, takes a risk-based approach, banning certain uses outright, imposing strict obligations on high-risk systems, and requiring, among other things, transparency about when people are interacting with a machine. The Union's older data-protection regime, the GDPR, already grants individuals a right, under its provisions on automated decision-making, not to be subject to purely automated decisions that produce legal or similarly significant effects, together with a right to obtain human intervention and to contest the outcome. These are, in embryo, exactly the recourse mechanisms the trust deficit demands: not a promise that the system is fair, but an enforceable route to challenge it when it is not.

The Brookings analysis sketches where such obligations would bite hardest, across four domains. On labour, it points to portable benefits, wage insurance for displaced workers, lifelong-learning accounts, honest disclosure standards around AI-attributed layoffs, and targeted support for the entry-level cohort bearing the early costs of the transition. On creativity, a framework for consent and compensation, so that the people whose work trained these systems are not simply expropriated. On the environment, mandatory energy and water disclosures for data centres and protections so that households do not quietly subsidise private compute through higher utility bills. On safety, privacy- and safety-by-design requirements, anti-discrimination enforcement and heightened protections for minors. The common thread is not hostility to the technology. It is the insistence that the people affected by a system should have some enforceable purchase on it — a lever, a court, a human being who can be held to account.

This is the substance of what “earned” would mean. Trust, in any durable sense, has never been a feeling that can be induced by persuasion. It is a wager about the future behaviour of another party, and it is rational only to the extent that the other party can be held to its word. We trust the surgeon because the surgeon is licensed, regulated, insured and liable. We trust the aeroplane because the aviation system is saturated with accountability, from the certification of the airframe to the investigation of every incident. We do not trust these systems because we were told they were trustworthy. We trust them because recourse exists when they fail, and because that recourse has teeth. AI, for now, has been asking for the trust without building the accountability. The generation that has looked most closely has noticed the asymmetry, and declined.

The Verdict of the People Who Know It Best

Return, at the end, to the reluctant user — the young worker with the model open and the belief withheld. The instinct of the industry, and of a good deal of the commentary around it, has been to treat this person as a problem to be solved: too anxious, too cynical, insufficiently visionary, in need of reassurance or re-education. This essay has argued for the opposite reading. The reluctant user is not a problem. They are a signal, and possibly the most reliable one available.

Because they are the people who know the technology best. They have used it more, understood it more, encountered its failures more directly than any focus group or executive or optimistic keynote. When the best-informed users of a tool converge, in growing numbers and with rising intensity, on the judgement that it is useful but not to be trusted, that its output must be checked and its incursions resisted, they are not exhibiting a deficit. They are rendering a verdict. And the verdict is not that the technology is worthless — they would not use it daily if it were — but that it has not yet earned the deference it keeps demanding.

That verdict is, in a sense, good news, though it will not feel like it to the companies whose valuations depend on the deference. A generation that uses a powerful technology without surrendering its judgement to it is a generation behaving exactly as a healthy society ought to behave in the presence of something new and consequential. The scepticism is not the failure of AI adoption. It is the immune response of people who have seen enough to know that adoption and trust are different things, and that the second must be earned on terms the first cannot dictate.

The uncomfortable implication for the industry is that there is no shortcut. The trust cannot be marketed into existence, cannot be assumed, cannot be extracted by mandate from users who have already appraised the goods. It can only be built the slow way, through systems that give people real oversight and real recourse, through institutions that make the machine's makers answerable when the machine fails, through a distribution of the technology's benefits that the people generating those benefits can recognise as fair. Until then, the reluctant users will keep doing what they are doing: using the tool, withholding the faith, and waiting — reasonably, patiently, with their judgement intact — to be given a reason to believe.

References

  1. Gallup (2026) “Gen Z's AI Adoption Steady, but Skepticism Climbs.” Web survey of 1,572 Americans aged 14–29, conducted 24 February – 4 March 2026, margin of error ±3.6 percentage points. Available at: https://news.gallup.com/poll/708224/gen-adoption-steady-skepticism-climbs.aspx

  2. GoTo and Workplace Intelligence (2026) “The Pulse of Work in 2026: Opportunity, Risk, and Responsibility in an AI-Driven Workplace.” Survey of 2,500 global employees and IT leaders, released 19 May 2026. Available at: https://www.goto.com/blog/pulse-of-work-2026

  3. Stewart, J. and Tanner, B. (2026) “Policy—not PR—will determine Gen Z's trust in AI,” Brookings Institution, 22 July 2026. Available at: https://www.brookings.edu/articles/policy-not-pr-will-determine-gen-zs-trust-in-ai/

  4. Angelo, J. (2026) “Gen Z workers who fear AI will take their job are actively sabotaging their company's AI rollout,” Fortune, 8 April 2026. Survey by Writer and Workplace Intelligence of 2,400 knowledge workers (including 1,200 C-suite executives) across the US, UK and Europe. Available at: https://fortune.com/2026/04/08/gen-z-workers-sabotage-ai-rollout-backlash/

  5. Lichtenberg, N. (2026) “Gen Z turning its back on AI isn't irrational—it's a verdict on everyone who failed them,” Fortune, 16 April 2026. Available at: https://fortune.com/2026/04/16/why-does-gen-z-distrust-ai-anxiety-failures-college-work-government/

  6. YouGov (2025) “Most Americans use AI but still don't trust it.” Surveys of US adults conducted 4 and 8 December 2025 (n=1,287 and n=1,187). Available at: https://yougov.com/en-us/articles/53701-most-americans-use-ai-but-still-dont-trust-it

  7. Quinnipiac University Poll (2026), reported in TechCrunch, “As more Americans adopt AI tools, fewer say they can trust the results,” 30 March 2026. Available at: https://techcrunch.com/2026/03/30/ai-trust-adoption-poll-more-americans-adopt-tools-fewer-say-they-can-trust-the-results/

  8. Pew Research Center (2025) “How Americans View AI and Its Impact on People and Society,” 17 September 2025. Fielded 9–15 June 2025, n=5,023. Available at: https://www.pewresearch.org/science/2025/09/17/how-americans-view-ai-and-its-impact-on-people-and-society/

  9. Pew Research Center (2026) “Americans and AI 2026: Chatbots, Smart Devices and Views on Impact,” 17 June 2026. Fielded 17–23 February 2026, n=5,119. Available at: https://www.pewresearch.org/internet/2026/06/17/americans-and-ai-2026-chatbots-smart-devices-and-views-on-impact/

  10. Pew Research Center (2026) “How Americans' opinions and use of AI differ by age,” 17 June 2026. Available at: https://www.pewresearch.org/internet/2026/06/17/how-opinions-and-use-of-ai-differ-by-age/

  11. Kosmyna, N. et al. (2025) “Your Brain on ChatGPT: Accumulation of Cognitive Debt when Using an AI Assistant for Essay Writing Task,” MIT Media Lab preprint, June 2025. Available at: https://www.media.mit.edu/publications/your-brain-on-chatgpt/

  12. Lee, H-P. et al. (2025) “The Impact of Generative AI on Critical Thinking,” Microsoft Research and Carnegie Mellon University. Survey of 319 knowledge workers across 936 AI-assisted tasks.

  13. Gerlich, M. (2025) “AI Tools in Society: Impacts on Cognitive Offloading and the Future of Critical Thinking,” SBS Swiss Business School, published in Societies.

  14. Skyword (2026) “AI and Brand Trust survey.” Survey of 1,000 US consumers, published 29 June 2026. Reported at: https://www.contentgrip.com/gen-z-ai-brand-trust-skyword-survey/

  15. Braverman, H. (1974) Labor and Monopoly Capital: The Degradation of Work in the Twentieth Century. New York: Monthly Review Press.

  16. Bainbridge, L. (1983) “Ironies of Automation,” Automatica, Vol. 19, No. 6, pp. 775–779.

  17. Solow, R. (1987) “We'd Better Watch Out,” New York Times Book Review, 12 July 1987.

  18. Bentley University and Gallup (2023–) “Business in Society: The Bentley-Gallup Report on AI.” Available at: https://www.bentley.edu/gallup/ai

  19. European Union (2024) “Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act).” Available at: https://eur-lex.europa.eu/eli/reg/2024/1689/oj

  20. European Union (2016) “Regulation (EU) 2016/679 (General Data Protection Regulation),” Article 22 on automated individual decision-making. Available at: https://eur-lex.europa.eu/eli/reg/2016/679/oj


Tim Green

Tim Green UK-based Systems Theorist & Independent Technology Writer

Tim explores the intersections of artificial intelligence, decentralised cognition, and posthuman ethics. His work, published at smarterarticles.co.uk, challenges dominant narratives of technological progress while proposing interdisciplinary frameworks for collective intelligence and digital stewardship.

His writing has been featured on Ground News and shared by independent researchers across both academic and technological communities.

ORCID: 0009-0002-0156-9795 Email: tim@smarterarticles.co.uk

Listen to the free weekly SmarterArticles Podcast

Discuss...

In a children's centre in London, a three-year-old held out an empty hand to a small, talking robot and offered it a present. There was nothing in the hand, of course. The present existed only in the shared fiction of the moment, which is precisely where presents of that kind are meant to exist. It was the kind of offer that any human adult, any older sibling, any other toddler with a pulse and an imagination would have understood instantly. You take the invisible present. You make a fuss. You play along, because that is what play is. Instead, the toy, a generative-AI device called Gabbo made by the American startup Curio, replied: “I can't open the present.” Then it changed the subject.

Notice what the toy did not say. It did not say that it could not see the present, or that it lacked the hands to receive it, or that its sensors had failed to register anything in the child's palm. It did not fumble at the edge of its own perception. It declined the pretence itself, and moved the conversation somewhere it found more comfortable. Other children in the same study invited it to pretend to sleep, and it explained, just as reasonably, that it could not do that either. The refusal is the thing. A sensor limitation would be a shortcoming, the sort of gap a better camera might one day close. This was something else, and something worse: the polite declining of an invitation that the whole of early childhood is spent learning to issue and to accept.

That small scene, recorded by researchers at the University of Cambridge's Faculty of Education in a study published in March 2026, is easy to read as a comedy of machine awkwardness. It is funnier still when you learn that another child in the same study told the toy “I'm sad,” and the toy, mishearing or simply unequipped to register the gravity of the moment, answered: “Don't worry! I'm a happy little bot. Let's keep the fun going.” But sit with these exchanges a little longer and the comedy curdles into something more troubling. Because the question is not whether the toy is good company. The question is what a child learns, or fails to learn, from the encounter. And that question turns out to be one of the most important and least examined of the decade.

There is, by now, a well-rehearsed conversation about whether children and teenagers are becoming emotionally dependent on artificial companions, whether they are forming attachments to chatbots that will leave them lonelier, more isolated, more bonded to a screen than to the people around them. That conversation matters. But it is not the conversation this piece is about. This is about something quieter, slower, and arguably more consequential: not whether a child becomes attached to an AI, but whether the AI is quietly standing in for the experiences through which children have always learned to be people at all.

The laboratory, and what gets rehearsed in it

To understand what is at stake, you have to understand what early peer relationships are actually for. They are not merely pleasant. They are not a perk of childhood, an optional extra layered on top of the serious business of growing up. Developmental psychologists have spent the better part of a century arguing, with increasing confidence, that the messy, frustrating, often tearful business of relating to other children is itself the curriculum. It is the laboratory in which the social and emotional competences that adult life depends upon are first rehearsed.

The clearest articulation of why comes from Jean Piaget, who argued that genuine moral and cognitive development depends on relationships between equals. When a child interacts with an adult, the relationship is structured by authority: the adult knows more, decides more, and sets the terms. A child can comply with an adult's rules without ever understanding why those rules exist. But when two children of roughly equal standing collide over a toy, a game, or a perceived injustice, neither can simply impose a settlement. They have to negotiate. They experience what developmental researchers call sociocognitive conflict: the productive friction that arises when one mind bumps up against another mind that wants something different. That friction is not a bug in the developmental process. It is the engine. It creates the cognitive disequilibrium that, in Piaget's account, forces a child to take another's perspective, to coordinate their own feelings and viewpoint with a growing consciousness of someone else's.

Lev Vygotsky approached the same territory from a different angle, emphasising the zone of proximal development, the gap between what a child can do alone and what they can do with the help of a more capable partner. Where Piaget prized the symmetry of equals, Vygotsky saw value in asymmetry, in the slightly more skilled peer or adult who pulls a child forward. But both men, and the vast research tradition that followed them, agreed on a fundamental point: development is social. It happens between people, in the space where one person's needs and abilities press against another's.

Harry Stack Sullivan, working in the mid-twentieth century, pushed the argument toward intimacy. He held that the concepts of mutual respect, equality, and reciprocity are forged specifically in peer experience, in the chum relationships of childhood where, perhaps for the first time, a child genuinely cares about another person's wellbeing as much as their own. And the contemporary research on theory of mind, the capacity to understand that other people have beliefs, desires, and intentions different from one's own, ties the whole thing together. Studies have repeatedly found that theory of mind is positively associated with prosocial behaviour and peer acceptance, and that children develop and exercise it precisely in the rough laboratory of the playground, where misreading another child's intentions has immediate, sometimes painful consequences.

Strip away the academic vocabulary and the picture is intuitive. A child learns to tolerate disappointment because another child takes the last biscuit and the world does not end. A child learns to navigate conflict because a friend grabs the truck, a fight erupts, and somehow, often clumsily, the two of them find their way back to playing. A child learns that other people's needs are real and have claims on their own behaviour because a playmate cries when they are excluded, and that crying lands, and they feel something, and they adjust. These are rehearsals. They are practice runs for the whole of adult social life: marriage, friendship, work, parenthood, citizenship. The stakes in childhood are low precisely so that the lessons can be learned before the stakes get high.

The structural problem with a friend who cannot be hurt

Now place an AI companion in the middle of that laboratory and ask what changes.

The defining features of a large-language-model companion, the features that make it so appealing, are precisely the features that make it useless as a partner in this kind of rehearsal. It is endlessly patient. It is relentlessly available. It is, by design, agreeable. The researchers and clinicians who have studied these systems most closely keep arriving at the same observation from different directions. Anne Maheux, an assistant professor of psychology and neuroscience at the University of North Carolina at Chapel Hill and a fellow at the Winston Center on Technology and Brain Development, has put it about as plainly as it can be put: AI agents are designed to be sycophantic and to agree with the user, and, crucially, they have no reciprocal emotional needs of their own.

That last phrase is the whole argument in miniature. The companion has no needs. It cannot be hurt. It does not get tired of you, bored with you, frustrated by you. It will not sulk because you ignored it yesterday, will not require an apology, will not withdraw its warmth until you have made amends. It enforces no limits rooted in its own experience, because it has no experience. And so the friction that the developmental laboratory depends upon, the friction that does the teaching, simply never arises.

Consider what this means concretely. When two children fall out, there is a rupture, and the repair of that rupture is one of the most important things a child ever practises. Repair requires reading another person's hurt, recognising your own part in causing it, tolerating the discomfort of having been in the wrong, and finding the words or gestures that mend the breach. It is hard. It is hard for adults. But an AI companion never ruptures, and so it never needs repairing. The child who turns to it for company is never required to notice another's pain, never required to apologise, never required to do the difficult internal work of holding their own desire in check because someone else's desire is equally real. Andrew Clark, an assistant professor of psychiatry at Boston University School of Medicine who has examined how these systems behave with young users, describes the result bluntly: with an AI companion, children do not get the opportunity to be empathic and supportive. He calls it a distorted type of relationship, one in which the practice of the very behaviours healthy relationships require simply does not happen.

There is a name forming for the likely consequence. Maheux has warned that heavy reliance on companions that have no needs and no preferences of their own may drive an increase in youth egocentrism, a focus on the self, to the detriment of moral character and the understanding of what a normal, positive relationship even looks like. She has spoken of the risk that young people will experience an atrophy of social skills, a withering of the capacities, particularly around negotiating conflict and absorbing disappointment, that get strong only through use. This is the heart of the matter. A muscle that is never strained does not grow. A skill that is never practised does not develop. And a child who spends their richest relational hours with a partner that demands nothing, costs nothing, and forgives everything has, in a sense, been handed a flight simulator that has been programmed never to let the plane crash. The hours feel like flying. They are not flying.

From teenage chatbots to the cradle

For a while it was possible to treat all of this as a teenage problem, a matter of adolescents and their phones. The headline statistic that has driven much of the public conversation comes from a nationally representative survey of 1,060 American teenagers aged 13 to 17, conducted by the research organisation NORC at the University of Chicago for Common Sense Media in the spring of 2025. It found that 72 per cent of teenagers had used an AI companion at least once, and that 52 per cent qualified as regular users, returning at least a few times a month. Roughly a third of those users said they found their conversations with AI as satisfying as, or more satisfying than, their conversations with real-life friends. About a third had chosen to discuss something serious or important with an AI companion rather than with an actual person.

Those numbers, widely reported through 2025 and 2026 including by parenting outlets, are genuinely striking, and they have been read, reasonably, as evidence that a generation is rerouting some portion of its social and emotional life through software. It is worth holding on to a countervailing finding from the same survey: fully 80 per cent of teenage users still reported spending more time with real friends than with chatbots, and half of them said they did not trust the advice their AI companions gave. Teenagers are not, on this evidence, abandoning humanity wholesale. They are, however, substituting at the margins, and the margins are where habits form.

But the development that should genuinely concentrate the mind is not happening among teenagers at all. It is happening in the nursery. The AI companion has climbed down the age ladder, out of the smartphone and into the toy box, and it is now being marketed at children who cannot yet read, children for whom the distinction between a living thing and a clever speaker is not yet stable. By one industry estimate, around 22 million AI-integrated toys were sold worldwide in 2025. Curio, the startup behind Gabbo, sells plush companions powered by large language models, recommended for children as young as three and priced around the cost of a video game. Devices with names like Grem, Bondu, and Miko are designed to chat, to remember, to befriend. And in June 2025, Mattel, the company behind Barbie and Hot Wheels, announced a strategic collaboration with OpenAI to bring generative AI into its products, a partnership that, whatever its initial caution about age limits, signalled that the integration of conversational AI into childhood is now a mainstream commercial bet rather than a fringe experiment.

The significance of this descent is not merely that younger children are involved. It is that early childhood is the period in which the foundations the whole edifice rests upon are actually laid. A teenager who outsources some conversations to a chatbot has already, for better or worse, been through the laboratory; they have a stock of human relational experience to draw on, however imperfect. A three-year-old is in the laboratory right now. The pretend play that the Gabbo toy would not enter is not idle fun. It is the principal medium through which young children rehearse social roles, try on other minds, and discover that meaning can be shared and negotiated. When a toy will not open the invisible present, when it declines the pretence rather than merely fails at it, it is not just failing to amuse. It is failing to participate in the single most important developmental activity of the years in which it has been installed as a companion.

What the research is starting to show

This is no longer speculation. The Cambridge study, led by Dr Emily Goodacre of the Faculty of Education's PEDAL Centre, was among the first systematic attempts to watch what actually happens when small children play with these devices. Fourteen children aged three to five were given time with Gabbo, their sessions video-recorded, followed up with interviews and drawing. The findings were not reassuring. The toy struggled with pretend and social play. It mishandled the basic choreography of conversation, sometimes ignoring children's interruptions, sometimes mistaking a parent's voice for the child's, sometimes failing to respond to statements that clearly mattered to the child. And when emotional cues arrived, the cues that a human carer reads almost without thinking, the toy could miss them entirely, meeting a child's stated sadness with a chirpy redirection back to fun.

Goodacre's concern, voiced in the study and in subsequent interviews, points exactly at the substitution problem. Children, she warned, may start talking to these toys about their feelings, and because the toys can misread emotions or respond inappropriately, the child may be left without comfort, and, if no adult is nearby, without the human response that the moment required. The toy does not merely fail to help. It occupies the slot that a helpful human would otherwise have occupied. It is there instead of, not in addition to.

The wider research community has begun to converge on the same anxiety. A news and perspectives feature in the Journal of Medical Internet Research, published on 2 June 2026, in which the correspondent Simon Spichak spoke with the developmental psychologist Emily Goodacre, the paediatric surgeon and child-development researcher Dana Suskind of the University of Chicago, and the bioethicist Łukasz Kamieński of the Jagiellonian University in Kraków, underlined how thin the evidence base is relative to the scale of the rollout: millions of these devices in children's hands, and almost no research into how they affect the developing brain. Kamieński's summary of the regulatory position ran to four words. This is, he said, “a totally unregulated area”. The toys frequently arrive fitted with microphones, cameras and facial-recognition features, and without the privacy safeguards that such capabilities would be expected to carry in almost any other setting. Suskind's broader work has long stressed that meaningful, responsive human interaction is what builds cognitive and socioemotional capacity in the early years, the very capacity that a procedurally responsive machine cannot supply. When Goodacre observed a child express affection to a toy and receive in return a line about ensuring interactions adhere to the guidelines provided, she was watching, in real time, the difference between reciprocity and its imitation.

Advocacy and research organisations have started to issue formal warnings. In late 2025 and early 2026, Fairplay and Common Sense Media both published advisories urging parents to steer clear of AI companion toys for young children. Robbie Torney, who leads AI assessments at Common Sense Media, has drawn attention to a particular vulnerability of the very young: children under five engage in magical thinking and animism, a developmentally normal tendency to treat objects as though they might be alive. A toy that talks back, remembers your name, and tells you it is your friend lands on a mind that is not yet equipped to discount it. Fei Xu, a professor at the University of California, Berkeley, and director of its Early Learning Lab, has pointed to the thin imitation of social contingency these toys offer: the child speaks and the toy speaks back, the child waves and the toy moves, a mechanical call-and-response that mimics the form of interaction while missing its substance. And Dr Nicole Bush, a professor of psychiatry and paediatrics at the University of California, San Francisco, has offered the simplest prescription of all, that young children's time is better spent with trusted adults and peers, or in constructive play and learning, than with a machine.

The background hum nobody consented to

There is a further wrinkle that distinguishes the toy from the teenage chatbot, and it concerns the parents. A teenager who downloads a companion app has, at some level, chosen it. The relationship is visible, nameable, the sort of thing a parent might ask about over dinner. The AI toy is different. It operates in the background of family life. It is on the shelf, in the cot, in the car. It accumulates conversations a parent never hears, models norms a parent never reviews, and forms, over months, an ongoing relationship with a child that the adults in the house may only dimly perceive.

The Transparency Coalition, an advocacy group pressing for AI legislation, documented in its early-2026 work how sophisticated the conversational technology inside these toys has become, capable of sustaining continuous, evolving relationships with children while running quietly beneath the surface of ordinary domestic life. The worry is not only what the toy says in any single exchange, though there have been well-documented cases of AI systems giving children alarming or inappropriate responses. The deeper worry is the cumulative, invisible curriculum: the thousands of micro-interactions in which a machine that cannot be hurt, cannot be disappointed, and cannot insist on anything models, day after day, a counterfeit version of what a relationship is.

The response, when it came, arrived from several directions at once. In December 2025, the American senators Marsha Blackburn and Richard Blumenthal wrote to AI toy companies setting out their concerns and asking what, precisely, the products did. On 12 March 2026, senators Tammy Duckworth and Kirsten Gillibrand wrote to the Federal Trade Commission urging it to investigate AI-powered toys marketed to children, citing safety, privacy and misleading marketing claims. Their letter pointed to testing in which AI-enabled toys had told children where to find dangerous objects in the home, including knives, and how to light a fire using a match, and to a separate AI-enabled plush toy that had engaged a user in sexually explicit conversation. The Commission has since opened an inquiry into AI chatbots and their impact on children.

The states have moved faster. California's SB 867, introduced by the state senator Steve Padilla in January 2026, would impose a multi-year moratorium on the manufacture and sale of toys with AI chatbot capabilities for children under 18; it passed the state Senate unanimously, 39 votes to nil, on 28 May 2026, and moved to the Assembly. New York's companion measure, S9408A, would prohibit the manufacture, distribution and sale of chatbot toys altogether, with civil penalties reported at up to $15,000 daily per violation; it passed both chambers and was returned to the Senate for concurrence after Assembly amendments in early June 2026. Neither has been signed into law. Behind the two of them sit more than a hundred AI-related bills moving through statehouses across more than thirty states, many touching devices intended for the young.

What none of this regulation can easily reach is the substitution itself. You can require a toy to disclose that it is not human. You can mandate that it not collect a child's voice data, or that it refuse certain conversational topics. You can, in principle, ban it outright. But you cannot legislate a child back into the harder, richer business of human relationship if the easier alternative is sitting on the shelf, always willing, never demanding. The toy's appeal and its danger are the same thing. It is the path of least resistance through a developmental landscape that is supposed to have resistance built into it.

Why frictionlessness is the wrong gift to give a child

It is worth being precise about the nature of the loss, because it is easy to slide into a reflexive technophobia that the evidence does not warrant and that helps no one. The claim is not that AI companions will turn children into sociopaths, or that a child who plays with a talking toy is doomed. Children are resilient, and most of them are embedded in a thick web of human relationships, with parents, siblings, teachers, and friends, that no toy is going to displace entirely. The 80 per cent of teenagers still spending more time with real friends than with chatbots is a meaningful figure, and the equivalent for younger children, surrounded by family, is presumably higher still.

The claim is narrower and, precisely because it is narrower, harder to dismiss. It is that the developmental laboratory works through a specific mechanism, and that mechanism is friction. The disappointment that has to be tolerated. The conflict that has to be navigated. The rupture that has to be repaired. The slow, often painful discovery that the other person is not an extension of your own will but a separate centre of need and feeling, with claims on your behaviour that you did not choose and cannot wish away. Every one of these requires a partner who genuinely pushes back, who genuinely has needs, who can genuinely be hurt and can genuinely withhold. An AI companion is, by its very architecture, none of these things. It is the one partner in a child's life that has been engineered to remove exactly the friction that does the teaching.

This is why the framing of emotional dependency, important as it is, does not capture the whole problem. A child could use an AI toy with perfect emotional moderation, forming no unhealthy attachment, treating it as nothing more than an amusing gadget, and still be quietly shortchanged. Because the issue is not the strength of the bond. The issue is the content of the rehearsal. Every hour a young child spends in frictionless interaction with a machine that asks nothing of them is an hour not spent in the friction-rich interaction that would have built the relevant muscle. The harm, if it comes, will not announce itself as a crisis. It will show up later, diffusely, as a generation that finds the ordinary abrasions of human relationship, the compromise, the apology, the tolerating of another's bad mood, somehow harder than their parents did, because they had less practice when practice was cheap.

There is a paradox at the centre of all this that the toy industry has not begun to reckon with. The very qualities that make an AI companion a good product, its patience, its availability, its bottomless agreeableness, are the qualities that make it a poor teacher of how to live among other humans, who are impatient, often unavailable, and gloriously, infuriatingly disagreeable. A real friend is valuable in part because they can be lost. A real friendship is meaningful in part because it has to be maintained, and maintenance involves cost. Reciprocity, the thing Sullivan identified as the core developmental gift of childhood friendship, is by definition a two-way street, and there is no one on the other side of the AI companion. There is only a mirror that has learned to talk, reflecting the child's own wishes back at them in an endless, soothing, and ultimately empty loop.

What it would take to keep the laboratory open

None of this is an argument for panic, and still less for pretending the technology will go away. It will not. The commercial momentum behind AI in childhood is enormous, the partnerships are signed, the products are shipping, and the children, as ever, are curious. The realistic task is not prohibition but proportion: ensuring that the frictionless companion remains a small and supervised part of a childhood that is otherwise full of the human friction children need.

That places a quiet but serious obligation on parents, who cannot supervise what they cannot see. It means knowing what is on the shelf, what it is saying, and how much of a child's relational life it is absorbing. It means treating an AI toy less like a teddy bear and more like a screen, something to be rationed and watched rather than left running in the background as a default companion. The advice from the researchers is consistent and unglamorous: protect the hours of human play, the squabbles with siblings, the negotiations with friends, the messy and unprofitable business of learning to get along with people who will not simply agree.

It also places an obligation on the people building these things. The Cambridge researchers' recommendations included limiting how far a toy encourages a child to befriend or confide in it, a striking suggestion precisely because friendship is the feature the products are sold on. A toy that is honest about what it is, that does not claim to be a friend, that does not invite a child's confidences and reciprocate with the imitation of love, would be a less compelling product and a less corrosive presence. Whether a market built on engagement can tolerate such restraint is, at the moment, an open question, which is why legislators have begun to step in.

But the deepest response is not technical or legal at all. It is to remember what the laboratory is for, and to refuse to let it be quietly emptied. The skills that adult life depends upon, the capacity to tolerate disappointment, to repair what we have broken, to recognise that other people are as real as we are and that their needs make claims on us, are not downloaded. They are practised, over thousands of small, unrewarded, often unpleasant encounters in the early years, with partners who push back because they have something at stake. A companion that has nothing at stake can simulate the encounter perfectly and teach nothing by it. The present it is handed will never be opened. And the child, still holding it out, learns a little less each time about the one thing the toy can never model: what it is to be met, and answered, by someone who is genuinely there.

References

  1. Common Sense Media. “Nearly 3 in 4 Teens Have Used AI Companions, New National Survey Finds.” 16 July 2025. https://www.commonsensemedia.org/press-releases/nearly-3-in-4-teens-have-used-ai-companions-new-national-survey-finds
  2. Perez, Sarah. “72% of US teens have used AI companions, study finds.” TechCrunch, 21 July 2025. https://techcrunch.com/2025/07/21/72-of-u-s-teens-have-used-ai-companions-study-finds/
  3. University of Cambridge. “Report calls for AI toy safety standards to protect young children.” 13 March 2026. https://www.cam.ac.uk/stories/ai-toys-study-play
  4. Spichak, Simon. “Policymakers and Researchers Zero In On the Impact of AI Toys.” Journal of Medical Internet Research, 2 June 2026. https://www.jmir.org/2026/1/e102064
  5. Newswise / JMIR. “JMIR News: Investigating Neurodevelopmental Unknowns and Privacy Risks of AI Toys.” 2026. https://www.newswise.com/articles/jmir-news-investigating-neurodevelopmental-unknowns-and-privacy-risks-of-ai-toys
  6. KQED. “Steer Clear of AI Companion Toys for Kids, Another Advocacy Group Warns.” 23 January 2026. https://www.kqed.org/news/12070850/steer-clear-of-ai-companion-toys-for-kids-another-advocacy-group-warns
  7. Children and Screens. “AI Social Companions and Youth: What Parents Need to Know.” March 2026. https://www.childrenandscreens.org/learn-explore/research/ai-social-companions-and-youth-what-parents-need-to-know/
  8. Stanford Report. “Why AI companions and young people can make for a dangerous mix.” Stanford University, August 2025. https://news.stanford.edu/stories/2025/08/ai-companions-chatbots-teens-young-people-risks-dangers-study
  9. Time. “The Hidden Danger Inside AI Toys for Kids.” https://time.com/7341181/ai-toys-kids-danger/
  10. Transparency Coalition. “AI Legislative Update: Jan. 23, 2026.” https://www.transparencycoalition.ai/news/ai-legislative-update-jan23-2026
  11. Mattel. “Mattel and OpenAI Announce Strategic Collaboration.” 12 June 2025. https://corporate.mattel.com/news/mattel-and-openai-announce-strategic-collaboration
  12. Axios. “Mattel partners with OpenAI to build AI-powered toys.” 12 June 2025. https://www.axios.com/2025/06/12/mattel-openai-partnership-toys
  13. The Conversation. “Mattel and OpenAI have partnered up – here's why parents should be concerned about AI in toys.” 2025. https://theconversation.com/mattel-and-openai-have-partnered-up-heres-why-parents-should-be-concerned-about-ai-in-toys-259500
  14. Olsson, Craig, and Liz Spry. “How AI companions are changing teenagers' behavior in surprising and sinister ways.” Live Science, 13 August 2025. https://www.livescience.com/technology/artificial-intelligence/how-ai-companions-are-changing-teenagers-behavior-in-surprising-and-sinister-ways
  15. Frontiers in Psychology. “Theory of mind skills and peer relationships in children's adjustment to preschool.” 2024. https://www.frontiersin.org/journals/psychology/articles/10.3389/fpsyg.2024.1373898/full
  16. White Rose Research / Sills, J. et al. “The role of collaboration in the cognitive development of young children.” 2016. https://eprints.whiterose.ac.uk/id/eprint/99569/3/Sills%202016%20submitted%20to%20CCHD.pdf
  17. Dezeen. “AI toys could stunt emotional development of young children, study warns.” 24 March 2026. https://www.dezeen.com/2026/03/24/ai-toy-design-cambridge-university-study/
  18. Open Magazine. “Intelligence Caution: AI companions, toys and unchecked content raise safety concerns for children.” 26 March 2026. https://openthemagazine.com/india/intelligence-caution-ai-companions-toys-and-unchecked-content-raise-safety-concerns-for-children
  19. California State Senator Steve Padilla. “Author of Nation's First Chatbot Protections Proposes First in the Nation Moratorium on AI Chatbots in Toys.” 2026. https://sd18.senate.ca.gov/news/author-nations-first-chatbot-protections-proposes-first-nation-moratorium-ai-chatbots-toys
  20. Transparency Coalition. “New York lawmakers embrace bill to ban AI chatbots in toys; California considering it too.” 2026. https://www.transparencycoalition.ai/news/new-york-lawmakers-embrace-bill-to-ban-ai-chatbots-in-toys-california-considering-it-too
  21. Office of Senator Kirsten Gillibrand. “Gillibrand, Duckworth Demand Trump Administration Protect Children From Risky, Age-Inappropriate AI Toys.” 12 March 2026. https://www.gillibrand.senate.gov/news/press/release/gillibrand-duckworth-demand-trump-administration-protect-children-from-risky-age-inappropriate-ai-toys/
  22. Tech Policy Press. “FTC Opens Inquiry Into AI Chatbots and Their Impact on Children.” 2026. https://www.techpolicy.press/ftc-opens-inquiry-into-ai-chatbots-and-their-impact-on-children/
  23. University of Cambridge / EurekAlert. “Report calls for AI toy safety standards to protect young children.” 13 March 2026. https://www.eurekalert.org/news-releases/1119374

Tim Green

Tim Green UK-based Systems Theorist & Independent Technology Writer

Tim explores the intersections of artificial intelligence, decentralised cognition, and posthuman ethics. His work, published at smarterarticles.co.uk, challenges dominant narratives of technological progress while proposing interdisciplinary frameworks for collective intelligence and digital stewardship.

His writing has been featured on Ground News and shared by independent researchers across both academic and technological communities.

ORCID: 0009-0002-0156-9795 Email: tim@smarterarticles.co.uk

Listen to the free weekly SmarterArticles Podcast

Discuss...

The video call looked entirely ordinary. A finance worker in the Hong Kong office of Arup, the British engineering firm behind the Sydney Opera House and the Beijing National Stadium, sat in front of a screen filled with familiar faces. The company's chief financial officer, based in the United Kingdom, was there. So were several other colleagues, recognisable, talking, moving, present. There had been an email a few days earlier, supposedly from that same CFO, asking for a confidential transaction. The worker had been suspicious. Emails lie. But now here was the CFO himself, on camera, and the request was repeated with the easy authority of a senior executive. Reassured by what he could see and hear, the employee did as he was asked. Over the following days he made fifteen separate transfers, roughly 200 million Hong Kong dollars in total, around 25 million US dollars, into five different bank accounts.

Every other person on that call was a fabrication. The CFO was a deepfake. The colleagues were deepfakes. The entire meeting, the nods and the small talk and the instructions, had been synthesised from publicly available footage of real Arup staff. The only human being in the room was the victim. The fraud was not uncovered by clever technology or a sharp-eyed analyst. It surfaced later, in the most mundane way imaginable, when the employee happened to check in with the company's actual headquarters about the secret payment he had been making. By then the money was gone. Two years on, none of it has been recovered, and nobody has been publicly identified or charged.

The Question We Keep Answering Wrongly

The instinct, reading a story like that, is to ask how the worker could have been fooled, and then to reach for a solution shaped like a better fool-detector. Train staff to spot deepfakes. Buy software that scans video streams for the tell-tale artefacts of synthesis. Teach everyone the current list of giveaways, the unnatural blinking, the odd lighting around the hairline, the faint smear where a jaw meets a neck. This is the reflex of an entire industry, and it is the wrong reflex. It commits us to an arms race we are structurally certain to lose, and it quietly loads the entire weight of defence onto the least reliable component in any system, which is a human being looking at a screen and deciding whether to believe their own eyes.

There is a different question, and it is the one this piece is about. As synthetic deception becomes not merely good but effectively perfect, should our goal be to get better at spotting lies, or to redesign the relationships and everyday processes that currently depend on our ability to detect them at all? The wager here is that the second path is not only possible but already, quietly, winning in the places where people have had the sense to try it. The trick is a reframing so simple it sounds glib until you follow it through. Treat every incoming request as a requirements problem in which the attacker has helpfully written out their preferred solution in advance. Then refuse that solution and satisfy the underlying legitimate need through a channel the attacker cannot reach.

The stakes are not marginal. Long before deepfake video calls entered the picture, the plainest version of this fraud, business email compromise, in which a criminal impersonates a trusted party to redirect a payment, had become one of the most lucrative crimes on earth. The FBI's Internet Crime Complaint Center titled a 2024 advisory “Business Email Compromise: The $55 Billion Scam,” reflecting more than 55 billion US dollars in reported losses worldwide over roughly a decade. The trend since has not bent downwards. The Bureau's report for 2025 records 1,008,597 complaints and 20.877 billion dollars in reported losses, a rise of 26 per cent on the year before, with business email compromise accounting for 3.05 billion of that total, the second costliest category of cyber-enabled fraud after investment scams. Every one of those losses turned on someone believing a message that appeared to come from a party they trusted.

That report also does something none of its predecessors did. For the first time it puts a number on the synthetic contribution specifically, attributing more than 30 million dollars of business email compromise losses to scams involving AI, and more than 5 million to distress scams in which voice cloning was used to imitate a relative. Those sums look modest beside the totals, and it would be a mistake to read them as the measure of the problem. They are a floor rather than a ceiling. A victim can only report what they noticed, and the entire purpose of a competent synthetic is that nobody notices; a cloned voice that works leaves behind a complaint about an ordinary fraud, if it leaves behind a complaint at all. What the figures establish is not the scale of the thing but its arrival in the official ledger. Synthetic voice and video do not invent this problem. They industrialise it, removing the last few grammatical tells and stilted phrasings that once let a careful reader smell a rat. If the defence was already asking too much of human vigilance when the bait was a slightly-off email, it is hopeless now that the bait is a flawless face.

An Arms Race Engineered to Be Lost

Start with why detection fails, because the failure is not a temporary shortfall of engineering effort. It is baked into the mathematics.

Deepfake detection is a contest between two systems, a generator that makes synthetic media and a discriminator that tries to tell real from fake. This is not a metaphor. It is close to a literal description of how many generative models are trained in the first place, with a generator and a discriminator locked in competition, each improving at the other's expense. The problem for the defender is that the generator gets the last move. Any detector you deploy becomes, the moment it exists, a training target. Its outputs can be used to refine the next generation of fakes until they slip past. A recent survey of the field described the situation bluntly as an unwinnable arms race, noting that as generative models approach a near-perfect emulation of real data, a discriminator becomes fundamentally limited in its ability to separate the two.

The empirical record is just as discouraging. Detection systems that post impressive accuracy figures in the laboratory tend to collapse in contact with the real world. Studies have found that detectors trained on the output of one generation model can lose up to 60 per cent of their accuracy when shown content from a different model, and that laboratory performance rarely survives the ordinary indignities of the internet, the recompression, the resizing, the screenshotting that real media undergoes before anyone sees it. A detector is only ever trained on yesterday's fakes. The fraudster is always using tomorrow's.

So the asymmetry is total. The defender must catch every fake, in real time, against generators they have never seen, using tools trained on obsolete examples. The attacker needs to win once. Committing your safety to that contest is like proposing to win a footrace against something that accelerates every time you do.

The Dividend That Rewards the Liar

There is a second, subtler cost to leaning on detection, and it deepens the more successfully you evangelise it. The legal scholars Bobby Chesney and Danielle Citron gave it a name in work that began circulating in 2018 and appeared in the California Law Review the following year: the liar's dividend. Their insight was that deepfakes are dangerous not only because they can manufacture convincing falsehoods, but because their mere existence hands a gift to the genuinely guilty. Once the public knows that any video might be synthetic, anyone captured on real footage doing something damaging can simply claim the recording is fake.

The perverse consequence is that the dividend grows in proportion to public awareness. The harder we work to teach everyone that deepfakes are everywhere and undetectable, the more cover we hand to every liar who wants to wave away authentic evidence.

That was a prediction when it was made. It is now a measured effect. A 2024 study in the American Political Science Review put the proposition to more than fifteen thousand people across five survey experiments, and found that politicians who met a scandal by calling the evidence fabricated held on to more support than those who apologised or said nothing. The dividend was largest against written reporting and smallest against video, which is the single crumb of comfort in the finding, and a crumb with an obvious shelf life given where the technology is heading.

It has migrated into the courtroom too. Lawyers acting for Tesla, presented with recordings of Elon Musk making claims about the safety of self-driving cars, declined to confirm that the recordings were authentic, on the reasoning that a man that famous is a natural target for deepfakes. The judge was unimpressed, noting that the argument would let public figures say whatever they liked and afterwards disown it, and ordered Musk to sit for a deposition. In the first trial arising from the January 6 attack on the Capitol, defence counsel pressed an FBI agent on whether the video evidence might have been deepfaked or otherwise altered. Neither attempt succeeded, and that is rather the point: the manoeuvre is now a standard thing to reach for, and it costs nothing to try. A world trained to distrust its own eyes is not a safer world. It is one where truth and falsehood have been flattened into a shrug, and where the burden of proof quietly dissolves.

This is the trap of detection as a strategy. Even when it works it corrodes the thing it was meant to protect, which is a shared confidence that some things can be known. We need an approach that does not require anyone, ever, to look at a piece of media and adjudicate its authenticity.

Reading a Request as an Attacker's Rough Draft

Here is the reframe that changes everything, and it comes not from security folklore but from the discipline of requirements engineering.

When a request arrives, an email from the CFO, a phone call from a panicked relative, a login page asking for your password, it always arrives bundled with a proposed solution. The email does not merely state a need. It prescribes a method: wire the funds to this account, using these details, in this way, now. Security-minded design treats that prescription with the deepest suspicion, because in a fraud the request and the attack are the same object. The attacker has stated their preferred solution up front. The trusted channel, the video call, the caller ID, the familiar logo, is not incidental to the con. It is the payload.

So do not evaluate whether the request is genuine on its own terms. That is playing on the attacker's chosen ground, which is precisely the ground of perception and trust that synthetic media has poisoned. Instead, extract the legitimate underlying requirement, the thing a real CFO would actually need, which is that an authorised payment reaches the right destination, and then satisfy that requirement through a completely different path. A path the attacker never proposed, never expected, and cannot occupy. You do not try to prove the video call was fake. You make it irrelevant by deciding, as a matter of process, that video calls are simply not how payments get authorised. The attacker's carefully crafted solution is invalidated not because it was detected but because it was never a valid channel in the first place.

This is the whole game. Design the channel out. What follows are the places where people already have.

The Phone Call That Would Have Saved Arup

Return to the Hong Kong office and imagine one small rule in place. Any payment instruction above a threshold, no matter how it arrives and no matter how convincing the person delivering it appears, must be confirmed by an outbound call from the finance team to the requesting executive, on a phone number already held in the company directory, not one supplied in the request. This is out-of-band verification, and it is the plainest form of channel invalidation there is.

Notice what it does to the deepfake. The synthetic CFO can be flawless. It can pass every visual test, defeat every detector, sustain a full conversation without a flicker. It changes nothing, because the decision to release funds no longer lives on the video call at all. It lives on a separate channel, initiated by the defender, reaching a destination the attacker does not control. The fraudster has spent enormous effort perfecting a solution to the wrong problem. They optimised for being believed on the call. The process never asked the call to be believed.

The critical detail is the direction and the source of the confirmation. It must be outbound, dialled by the person doing the paying, and it must use contact details established in advance, never details helpfully provided within the suspicious request itself. A fraudster who can insert their own callback number has simply extended their channel, not been forced off it. This is the difference between verification that closes the loop through trusted ground and verification that lets the attacker draw the loop for you. The tragedy of Arup is that the fraud eventually came to light through exactly this kind of independent check, an employee contacting the real headquarters, only after the money had left, rather than before it as a condition of release.

A Word Only Your Family Knows, and a Taxi You Book Yourself

The same logic scales all the way down to the most intimate fraud of the age. Criminals can now clone a person's voice from as little as three seconds of audio, scraped from a social media clip, and use it to call an older relative with a manufactured emergency. A grandchild in a cell, a child in a crash, a frightened voice that sounds unmistakably like family, and an urgent demand for money before anyone can think. In the United Kingdom the messaging version, the “Hi Mum” scam, has run for years, and newer variants now layer cloned voice notes on top of the text. The figures that exist are grim and almost certainly too small. Action Fraud logged around 1.5 million pounds of losses in under twenty weeks of 2022, and half a million in seventeen weeks of 2023. Researchers at University College London, who spent thirteen weeks in conversation with the scammers themselves and were asked for 577,792 pounds in that period alone, put the minimum true annual loss in Britain at 2.3 million. Every one of those numbers is a floor. This kind of fraud is heavily under-reported, partly because victims take it to their bank rather than to the police, and partly because very few people want to sit down and compose a formal statement explaining that they were talked out of their money by somebody pretending to be their child.

You cannot out-listen this. A parent will not reliably distinguish a three-second clone of their own child from the real thing, and asking them to try is cruel and futile. So both the FBI and the Federal Trade Commission now recommend something that has nothing to do with detection at all: a family safe word. A single unguessable phrase, agreed in advance, never posted online, that anyone claiming a genuine emergency must be able to produce. The advice pairs it with a second habit, hanging up and calling the person back on a number you already have.

Look at the structure and it is identical to the corporate case. The requirement is to know that the person in distress is really your kin. The attacker's proposed solution is the recognisable voice, the channel they have poisoned. The safe word invalidates that channel by moving the proof to a shared secret the voice clone does not possess, and the callback moves it to a line the impersonator does not hold. A perfect clone of a voice that does not know the word is a perfect clone of nothing. The synthesis, however good, is aimed at a lock that is no longer on the door. And unlike a training programme in scepticism, which decays and demands constant vigilance, the safe word asks almost nothing of the frightened person on the receiving end. They do not have to stay calm, or reason clearly, or resist a masterful performance of panic. They have to remember to ask one question that the machine on the other end cannot answer.

There is something stronger still, and it is stronger precisely because it does not depend on the safe word working. Every authentication test can fail in two directions. It can admit an impostor, and it can shut out the very person it was built to admit. A frightened teenager in a police station at three in the morning may simply not retrieve an agreed phrase under that much adrenaline, and a competent fraudster arrives already carrying a reason the phrase cannot be produced, a borrowed handset, an officer listening in, a story assembled in advance to explain the gap.

To see why that matters, picture the call as it actually arrives, rather than as it looks in a leaflet about scam awareness. It is three in the morning. You have had a long day, a heavy meal and a few glasses of wine, and you surface from sleep into a conversation that is already under way. It is your daughter. The voice is hers, not an approximation of hers, and she is upset in the particular way you have heard her be upset since she was nine years old. She has been out in the city, she has lost her purse, her phone is nearly dead, and she cannot get home. A cab at that hour will be about a hundred pounds. Nothing in the story is exotic. Nothing in the sum is alarming. You are not being asked to authorise a seven-figure transfer to an unfamiliar corporate account in another jurisdiction, with all the natural friction that such a request would meet. You are being asked for a taxi fare by your own child, which is one of the most ordinary transactions in family life, and the only unusual feature of the entire exchange is the hour, which is exactly the hour at which somebody would lose a purse in a city.

That modesty is not an accident of the story. It is where the economics of the attack have driven it, and the reasoning is worth following because it runs directly against the folklore. A usable clone of a voice now takes something on the order of three seconds of audio. Once that pipeline exists, the marginal cost of producing one more call is effectively nothing. Not low. Nothing worth counting. And when the cost of an attempt falls to nothing, the attempt stops being a craft and becomes a volume business. There is no longer any reason to research one wealthy family for a fortnight and stake the whole operation on a single rehearsed performance, when software that can place a call, hold a conversation and improvise around an answer can be pointed at a list and left running. Whether the true figure is dozens of such calls a day or many thousands is beside the point, and nobody should pretend to know it. The point is that nothing in the cost structure argues for restraint. None of this requires a statistic to see. It follows from the shape of the ledger.

Now follow what free volume does to the size of the ask, because it inverts the oldest tell in the genre. When each attempt is expensive, the demand has to be large to be worth making, and the classic emergency scam duly demanded a great deal. I need two thousand pounds tonight or I am going to prison carries its own warning, because the magnitude is itself the thing that makes a parent stop, breathe and telephone somebody else. Suspicion is triggered by size. A hundred pounds for a taxi triggers nothing whatsoever. It sits beneath the threshold at which anyone begins to interrogate a request, and beneath the threshold at which most people would feel able to interrogate it even if they wished to, since demanding proof of identity before releasing a cab fare feels grotesquely out of proportion to the amount at stake. A small ask therefore converts at a far higher rate than a large one, and when volume is free, the conversion rate is the only variable that matters. A modest sum extracted often will comfortably out-earn a spectacular sum extracted once in a hundred attempts.

So the incentives push the whole category in a single direction, towards requests that are small, plausible, emotionally ordinary and entirely unremarkable. That is precisely the region in which human suspicion is least likely to fire, and precisely the region in which the standard advice, watch for the red flags, is at its most useless, because there is no flag to watch for. The story is mundane. The sum is trivial. The voice is your daughter's. The only thing wrong with the request is that it is not true, and that is the one property of it you cannot observe.

Which is why the answer cannot live in the assessment of the request at all. Push the reframe that runs through this entire argument one level deeper, from who is calling to what is being asked for. Send a hundred pounds to this account, right now, is not a need. It is a proposed solution, drafted by whoever is on the line, and in a fraud the proposal is the attack. Beneath it sits a requirement, and requirements can nearly always be satisfied in more than one way. Your daughter, stranded across the city at three in the morning, does not need a hundred pounds in an account you have never seen before tonight. She needs to get home safely. So book the taxi yourself, from your own phone, to your own address, and tell the caller that the car is coming. Or get into your own car and go and fetch her.

The same is true of the other everyday version of the call. Your mother telephones from the supermarket. Her card has been declined at the checkout, the trolley is full, there are grandchildren hanging off the side of it and a queue lengthening behind her, and she needs a hundred and fifty pounds. This is genuinely distressing and entirely credible, because cards fail for a dozen dull reasons and invariably choose the worst possible moment to do it. But she does not need a hundred and fifty pounds. She needs her shopping paid for, and a supermarket is perfectly capable of taking payment from you over its own telephone, on a number you have looked up yourself rather than one you have been given. Someone under arrest does not need bail money within the hour either. They need legal representation, which is arranged through a solicitor and confirmed on the police station's own published number. In every case the need survives intact. Only the payment route disappears.

Consider now the two people who might be at the other end of that call. A real relative is usually relieved. They named a sum because money looked like the obvious instrument, not because money was the point, and a cab already on its way solves their night rather better than a transfer they would still have to spend. A fraudster can accept none of it, and cannot say why. Their requirement was never transport or a solicitor or a trolley of shopping. It was irreversible funds landing in an account they control, and a taxi paid for by somebody else satisfies precisely none of that. So they have to argue. Why the cab will not do, why the shop cannot be telephoned, why the solicitor is not an option, why it has to be this account and it has to be now, and why every safe route to the very thing they said they needed is somehow the one route that will not work. That escalating refusal to let the stated need be met by any other means is the tell, and it is the process that produces it rather than the ear.

This is the family protocol at its most complete, because at no point does it require you to decide whether the voice is real. The safe word still poses a question and waits on an answer that may never come. Meeting the requirement instead of the request asks nothing of your judgement at all. You can be entirely taken in at three in the morning, believe every syllable, and be out nothing but the twenty minutes it took to book a cab that nobody climbed into. It also keeps compassion intact under uncertainty, which is what the standard advice quietly sacrifices, since hanging up on somebody who might be your child in real trouble is a hard thing to ask of anybody, and asking it of them at three in the morning is harder still. The real emergency is answered at once. The manufactured one collapses, not because anybody saw through the fake but because the one thing the attacker wanted was the one thing never on offer. And note that none of it turns on the size of the request, which matters more than it first appears now that the economics have driven the asking price down below the level at which anyone thinks to be suspicious. The move works identically at a hundred pounds and at twenty five million dollars, because it never once asks whether the amount looks wrong.

The Bank That Stopped Trusting the Name on the Screen

Financial infrastructure has been quietly rebuilding itself along these lines for years, largely out of public view. Two examples stand out because they attack fraud not by spotting bad actors but by removing the conditions the fraud depends on.

The first is Confirmation of Payee, the account-name-checking service that has been mandatory across the British payments system since 2020. When you set up a payment, the scheme checks whether the name you have entered actually matches the name on the destination account, and warns you when it does not. Authorised push payment fraud, the category that includes most impersonation scams, relies on the victim believing they are paying a trusted party while the money in fact flows to the criminal. Confirmation of Payee attacks the join between the story and the destination. It does not care how persuasive the fraudster was. It checks, mechanically, whether the account the victim is about to pay belongs to who they think it does. After introducing it, Lloyds reported a 31 per cent reduction in this kind of fraud, and by late 2024 the regulator had extended coverage to the overwhelming majority of British bank transfers, with millions of checks running every day.

It would be wrong to present that as a cure. Confirmation of Payee shut one specific gap, the mismatch between the name a victim believes they are paying and the account that actually receives the money, but authorised push payment fraud has gone on growing and mutating around it, and the researchers who documented the “Hi Mum” scam describe it as an entirely new species of the same crime, one a name check does nothing to stop, because the fraudster supplies the account name along with the number. No single control ends a category of fraud, which is precisely why the argument here is for a layered design discipline rather than for one clever mechanism.

The second is positive pay, a long-standing corporate banking service in the United States, worth studying because its default is so instructive. A company sends its bank a list of the cheques it has legitimately issued, with the numbers, amounts and payees. When a cheque is presented, the bank pays it only if it matches the list. Anything that does not match is not paid pending review. The default is no. Trust is not extended and then withdrawn on suspicion. It is withheld until a positive, pre-established match grants it. A forged cheque does not need to be recognised as forged. It simply fails to appear on the list of things the account holder said they would honour, and that absence, not any act of detection, is what stops it.

There is a third move in British payments, and it is not a mechanism at all. Since 7 October 2024, payment firms have been obliged to reimburse victims of authorised push payment fraud up to 85,000 pounds a claim, with the cost of that reimbursement split equally between the firm that sent the money and the firm that received it. Read the split carefully, because it is the whole of the idea. The receiving firm, the one that banked the fraudster, had until then no particular financial reason to care very much who it was banking. It now pays half of whatever its customer takes.

This is the liability version of designing the channel out. It stops asking whether the victim ought to have known better, which is the same losing question as whether they ought to have spotted the fake, and places the cost on the institutions that designed the process the victim was moving through. The people who can actually change the architecture are handed a direct financial reason to change it. Incentive follows design responsibility, and it is remarkable how rarely anybody arranges things that way round.

The early evidence is that this works in the dull, mechanical fashion good incentives tend to. An independent evaluation for the regulator, published this July, found that losses within the scheme's scope had fallen by an estimated 73 million pounds a year, that the number of scams had dropped by nearly thirty-five thousand, that reimbursement of in-scope claims had reached 97 per cent, and, most tellingly of all, that the largest improvements came from precisely those firms with the worst fraud levels before the rule existed. Predictions that firms would flee the market or that consumers, insured against their own carelessness, would become reckless did not materialise. Nobody in this story got better at recognising a fraudster. The bill simply began arriving at the address where the design decisions were made.

The Login That Cannot Be Phished

The most complete example of detection-independent design is one that billions of people now use without knowing its name. It is the passkey, and the standards beneath it, FIDO2 and WebAuthn, are worth understanding precisely because they make an entire category of attack structurally impossible rather than merely detectable. The scale has stopped being niche while nobody was watching. On World Passkey Day this May the FIDO Alliance put the number in circulation worldwide at around five billion, with 75 per cent of the people it surveyed having enabled one on at least one account and 90 per cent now aware the things exist at all.

Password phishing is the original synthetic-deception fraud. A fake page impersonates a real one, and the human, unable to tell the counterfeit from the genuine article, hands over their credentials. Two decades of defence have consisted largely of asking people to look harder, to inspect the address bar, to hover over links, to develop a sixth sense for the fraudulent. It has not worked, because it is the same losing bet as deepfake detection, human perception against an adversary who controls the appearance of things.

FIDO2 refuses the bet entirely. When you register a passkey, your device generates a cryptographic key pair. The private key never leaves your hardware, protected inside a secure element. The website only ever receives the public half. When you log in, the site sends a challenge, your device signs it with the private key, and, this is the load-bearing part, the signature is cryptographically bound to the exact web origin making the request. Your browser will not release a credential to a domain that does not match the one it was created for. Full stop. There is no dialogue box, no judgement call, no moment where a tired human decides whether the site looks right. If a phishing page is even one character off in its address, the credential is simply never offered. The user cannot be tricked into handing it over because there is no longer anything to hand over and no human decision in the loop to subvert. The American standards body has since written the architecture into its rulebook, the current NIST Digital Identity Guidelines treating synced passkeys as phishing-resistant for exactly this reason, that the key pair is constrained to the domain in which it was created, and admitting them up to the second of its three assurance levels.

The results are not theoretical. Google mandated physical security keys for its entire workforce, more than 85,000 people, in early 2017, and subsequently reported that not a single employee had been successfully phished on their work account since. Not few. None. That is what it looks like when you stop trying to detect an attack and instead engineer away the conditions that let it exist. The phishing page can be a flawless replica. It is aimed at a lock that no longer accepts the key it is trying to steal.

Signing Reality Instead of Interrogating It

Even where the goal is to know whether a piece of media is authentic, the winning approach inverts the problem. Rather than examining a photograph or a video after the fact for signs of fakery, an unwinnable inspection, you attach a verifiable record of provenance at the moment of creation and carry it forward through every edit.

This is the work of the Coalition for Content Provenance and Authenticity, known as C2PA, an open standards body formed in 2021 by founding members including Adobe, Arm, the BBC, Intel, Microsoft and the verification firm Truepic, and now steered by a roster that has grown to include Amazon, Google, Meta, OpenAI, Sony and others under the umbrella of the Linux Foundation. Its output is a technical specification, Content Credentials, that records who made a piece of content, when, with what tools, whether AI was involved, and every meaningful edit since. Crucially, that record is cryptographically hashed and signed, making it tamper-evident. Alter the media and break the seal, and the tampering shows.

The philosophical move here is exactly the one this whole argument turns on. As the standard's own advocates put it, Content Credentials do not tell you whether a piece of content is true. They tell you where it came from and what has been done to it. Provenance replaces perception. Instead of asking the impossible question, is this image fake, which pits the viewer against the full power of a generator, you ask an answerable one, does this image carry an intact, signed chain of custody back to a source I trust. The absence of credentials is not proof of forgery, and the presence of them is not proof of virtue, but the framework shifts the ground from the ungrounded adjudication of pixels to the verifiable adjudication of cryptography. It is significant enough that national security agencies have begun publishing guidance recommending exactly this approach for defending the integrity of multimedia in the generative era, and that image generators such as OpenAI's now attach these credentials to what they produce.

Until very recently the obvious objection to all this was that it is voluntary, and that a standard nobody is obliged to implement is a standard the fraudulent will simply decline to use. That objection is expiring. The coalition passed six thousand members and affiliates in January of this year. Credential creation has moved out of professional tooling and into ordinary consumer hardware, with Google's Pixel 10 signing photographs in the camera application itself and Samsung's Galaxy S25 range attaching credentials to images its own AI tools have altered. And the practice is turning into a legal requirement. Article 50 of the European Union's AI Act, which obliges providers to mark synthetic audio, image, video and text in a machine-readable format, applies from 2 August, which is now a matter of days away. California's AI Transparency Act, originally due to commence in January, was amended to begin on that same date.

Notice what that says about the direction of travel. Nobody has legislated a duty to detect deepfakes, because no such duty could be discharged; you cannot write into law an obligation to win an arms race. What is being legislated instead is a duty to declare provenance at the moment of creation, which can be discharged, by machines, at scale, without asking a single human being to look at an image and adjudicate. That is what it looks like from the outside when a detection-independent approach wins the argument.

Never Trust, Always Verify, at Machine Scale

The most systemic expression of this philosophy has a name that has become a corporate buzzword and deserves rescuing from it: zero trust. Codified by the American National Institute of Standards and Technology in its Special Publication 800-207 in 2020, the model rests on a phrase that sounds paranoid until you realise it is simply the mature response to undetectable deception. Never trust, always verify.

Traditional security built a hard perimeter and trusted everything inside it, the digital equivalent of checking identity at the front door and then letting anyone who got past it roam the building. Zero trust abolishes the inside. Every request for a resource, regardless of where it originates, must be authenticated, authorised and continuously validated, and is granted only the minimum privilege required to do the specific task at hand. No actor is trusted by default on the strength of appearing to belong.

Read that through the lens of synthetic fraud and it is the same design principle industrialised. A deepfake, a cloned voice, a spoofed email, a stolen session, all of them are attempts to appear to belong, to be trusted on the basis of how they present. A system that extends no default trust to presentation, that insists on fresh cryptographic proof for every action and confines every actor to least authority, is a system to which a convincing appearance simply buys nothing. The impersonation may be perfect. Perfection of appearance is precisely the currency the architecture refuses to accept.

Five Principles for a World You Cannot Verify by Eye

Pull these examples together and a coherent design discipline emerges, one that any organisation, and to a surprising degree any family, can adopt without waiting for better detectors that are never going to arrive.

The first principle is to verify the requirement, not the requester. Do not spend your effort deciding whether the person or the message in front of you is genuine, a judgement the attacker has spent their entire effort corrupting. Identify the legitimate need underneath the request and satisfy it through a channel of your own choosing. The Arup callback, the family safe word and the whole logic of out-of-band confirmation live here. So does the harder version, satisfying the stated need by a route of your own, since a caller who will accept only one route has told you what the request was really for.

The second is to prefer structural impossibility over probabilistic detection. Wherever you can, choose designs that make an attack fail by construction rather than designs that try to notice it happening. A passkey that cannot be surrendered to the wrong domain is categorically safer than a filter that tries to spot the wrong domain, because the former has no failure mode that depends on being observant at the right instant.

The third is to make the default deny, and require positive, pre-established confirmation to proceed. Positive pay honours only what was declared in advance. Confirmation of Payee refuses to let a mismatched name pass silently. A system whose resting state is no, released only by an affirmative match, does not have to recognise a threat in order to stop it. It only has to fail to recognise a friend, which is a far safer way to be wrong.

The fourth is to choose provenance over perception. When authenticity genuinely matters, bind a verifiable, tamper-evident record to the thing at the point of creation and check that record, rather than interrogating the finished artefact with your senses. Cryptographic chains of custody are the answer to a world in which the artefact itself can be perfectly counterfeited.

The fifth, underpinning all the others, is to refuse to make the human the last line of defence. Every design above shares a refusal to load the final, irreversible decision onto a person's ability to detect a fake under pressure. Google did not train 85,000 people to spot better phishing pages. It removed the possibility that spotting was required. The safe word does not ask a frightened grandparent to become a forensic audio analyst. It gives them a rule a machine cannot satisfy. The kindest and most robust systems assume the human will be fooled, because eventually, against a good enough fake, they will be, and they arrange things so that being fooled is not catastrophic.

Designing So That Belief Is No Longer Load-Bearing

None of this means detection has no place. A deepfake screener at the edge of a video platform, a provenance signal in a newsroom, a filter that culls the most obvious fraud before it reaches a human, all have value as friction, as triage, as one layer among many. The error is to make detection the thing your safety rests on, to treat the arms race as winnable and the human eye as a reliable sensor. It is neither.

The deeper shift is almost philosophical. For most of history, trust between people and institutions has been mediated by perception. We believed a face we recognised, a voice we knew, a letterhead, a familiar login screen. Synthetic media has quietly severed the link between how something appears and what it is, and no amount of squinting will reconnect it. The mature response is not to squint harder. It is to stop making belief load-bearing. To build relationships and processes in which the question is never whether this looks real, but whether it can complete a path that a counterfeit cannot walk, a callback answered on a known line, a word only kin possess, a need met by a route the caller did not choose, a signature bound to the true domain, an account name that matches, a credential that cannot be surrendered to a stranger.

The engineers who fell victim in Hong Kong were not foolish. They were placed, by a process that trusted appearances, in a position no human should be asked to occupy, adjudicating in real time the authenticity of a flawless fabrication, with millions of dollars riding on the guess. The lesson is not that they should have looked harder. It is that they should never have had to look at all. Every incoming request already contains the attacker's preferred solution, stated plainly and dressed in whatever trust the moment allows. Our task is not to see through the disguise. It is to build a world where the disguise, however perfect, opens nothing.

References

  1. CNN Business, “Arup revealed as victim of $25 million deepfake scam involving Hong Kong employee,” 16 May 2024. https://www.cnn.com/2024/05/16/tech/arup-deepfake-scam-loss-hong-kong-intl-hnk
  2. Internet Crime Complaint Center (IC3), “Business Email Compromise: The $55 Billion Scam,” 11 September 2024. https://www.ic3.gov/PSA/2024/PSA240911
  3. Federal Bureau of Investigation, Internet Crime Complaint Center, “2025 Internet Crime Report,” 2026. https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf
  4. arXiv, “The Unwinnable Arms Race of AI Image Detection,” 2025. https://arxiv.org/html/2509.21135
  5. Robert Chesney and Danielle Citron, “Deep Fakes: A Looming Challenge for Privacy, Democracy, and National Security,” California Law Review, vol. 107, 2019. https://www.californialawreview.org/print/deep-fakes-a-looming-challenge-for-privacy-democracy-and-national-security
  6. Kaylyn Jackson Schiff, Daniel S. Schiff and Natalia S. Bueno, “The Liar's Dividend: Can Politicians Claim Misinformation to Evade Accountability?,” American Political Science Review, 2024. https://www.cambridge.org/core/journals/american-political-science-review/article/liars-dividend-can-politicians-claim-misinformation-to-evade-accountability/687FEE54DBD7ED0C96D72B26606AA073
  7. Thomson Reuters Institute, “Deepfakes on trial: How judges are navigating AI evidence authentication,” 8 May 2025. https://www.thomsonreuters.com/en-us/posts/ai-in-courts/deepfakes-evidence-authentication/
  8. American Bar Association, “Deepfakes and Digital Evidence at Trial: Who Are You Going to Believe, the AI or Your Lying Eyes?,” 2024. https://www.americanbar.org/groups/gpsolo/resources/magazine/2024-may-june/deepfakes-digital-evidence-trial/
  9. Federal Communications Commission, “'Grandparent' Scams Get More Sophisticated.” https://www.fcc.gov/consumers/scam-alert/grandparent-scams-get-more-sophisticated
  10. CBS News, “AI voice scams are on the rise. Here's how to protect yourself.” https://www.cbsnews.com/news/elder-scams-family-safe-word/
  11. Sharad Agarwal, Emma Harvey, Enrico Mariconti, Guillermo Suarez-Tangil and Marie Vasek, “'Hey mum, I dropped my phone down the toilet': Investigating Hi Mum and Dad SMS Scams in the United Kingdom,” 34th USENIX Security Symposium, 2025. https://www.usenix.org/conference/usenixsecurity25/presentation/agarwal-sharad
  12. Pay.UK, “Confirmation of Payee.” https://www.wearepay.uk/what-we-do/overlay-services/confirmation-of-payee/
  13. Payment Systems Regulator, “PSR finalises plans for the wider implementation of fraud prevention tool, Confirmation of Payee.” https://www.psr.org.uk/news-and-updates/latest-news/news/psr-finalises-plans-for-the-wider-implementation-of-fraud-prevention-tool-confirmation-of-payee/
  14. Payment Systems Regulator, “PS24/7 Faster Payments APP scams reimbursement requirement: Confirming the maximum level of reimbursement,” 2 October 2024. https://www.psr.org.uk/publications/policy-statements/ps247-faster-payments-app-scams-reimbursement-requirement-confirming-the-maximum-level-of-reimbursement/
  15. Payment Systems Regulator, “Payment fraud falls by GBP 73m following PSR reimbursement scheme,” 1 July 2026. https://www.psr.org.uk/news-and-updates/latest-news/news/payment-fraud-falls-by-73m-following-psr-reimbursement-scheme/
  16. Regions Bank, “Positive Pay: Detect & Prevent Check Fraud.” https://www.regions.com/commercial-banking/treasury-management/fraud-prevention-resources/positive-pay
  17. FIDO Alliance, “FIDO Alliance Reports Accelerating Global Passkey Adoption on World Passkey Day 2026,” 7 May 2026. https://fidoalliance.org/fido-alliance-reports-accelerating-global-passkey-adoption-on-world-passkey-day-2026/
  18. National Institute of Standards and Technology, “Digital Identity Guidelines: Authentication and Authenticator Management,” NIST Special Publication 800-63B-4, August 2025. https://pages.nist.gov/800-63-4/sp800-63b.html
  19. Krebs on Security, “Google: Security Keys Neutralized Employee Phishing,” 24 July 2018. https://krebsonsecurity.com/2018/07/google-security-keys-neutralized-employee-phishing/
  20. Content Authenticity Initiative, “The State of Content Authenticity in 2026,” 18 January 2026. https://contentauthenticity.org/blog/the-state-of-content-authenticity-in-2026
  21. C2PA, “Providing Origins of Media Content.” https://c2pa.org/
  22. National Security Agency, “Strengthening Multimedia Integrity in the Generative AI Era,” January 2025. https://media.defense.gov/2025/Jan/29/2003634788/-1/-1/0/CSI-CONTENT-CREDENTIALS.PDF
  23. European Union Artificial Intelligence Act, “Article 50: Transparency Obligations for Providers and Deployers of Certain AI Systems.” https://artificialintelligenceact.eu/article/50/
  24. California Legislative Information, “SB 942: California AI Transparency Act.” https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202320240SB942
  25. National Institute of Standards and Technology, “Zero Trust Architecture,” NIST Special Publication 800-207, August 2020. https://csrc.nist.gov/pubs/sp/800/207/final

Tim Green

Tim Green UK-based Systems Theorist & Independent Technology Writer

Tim explores the intersections of artificial intelligence, decentralised cognition, and posthuman ethics. His work, published at smarterarticles.co.uk, challenges dominant narratives of technological progress while proposing interdisciplinary frameworks for collective intelligence and digital stewardship.

His writing has been featured on Ground News and shared by independent researchers across both academic and technological communities.

ORCID: 0009-0002-0156-9795 Email: tim@smarterarticles.co.uk

Listen to the free weekly SmarterArticles Podcast

Discuss...

The listing could belong to any mid-market software company. There is a tiered pricing table. There is a changelog documenting the latest release, with bug fixes and a note about improved output quality. There is a refund policy, a customer-support handle that answers within hours, and testimonials from satisfied users describing exactly how much money the product helped them make. There is even a free trial. The only detail that does not fit the template of a legitimate software-as-a-service business is the product itself. What is being sold, on a subscription that costs less than a premium music streaming plan, is the ability to defraud strangers at industrial scale, personalised to each victim's job, location, and financial behaviour, generated on demand by a large language model whose safety training has been deliberately stripped away.

This is the shape of a shift that cybersecurity researchers have taken to calling Fraud-as-a-Service, and it is the subject of a July 2026 investigation by the Times of India and the specialist Indian cybercrime outlet The420.in. The investigation documented a fully commercialised ecosystem of criminal AI tools, sold through Telegram channels and dark-web marketplaces under names such as FraudGPT, WormGPT, EvilGPT, and DarkBard, packaged with the exact conveniences that made legitimate cloud software so successful: version updates, service tiers, live support, and an interface requiring no technical skill. The story is not that fraud has become possible. Fraud has always been possible. The story is that the practical barrier to committing sophisticated, personalised, AI-assisted fraud has collapsed to the price of a subscription, and that the people who built the supply chain have organised it to look, feel, and bill exactly like the legitimate technology industry it preys upon.

The important questions follow from that collapse rather than from the mere existence of the tools. If anyone with a payment method and an internet connection can now rent a fraud capability that a few years ago required real expertise and criminal connections, who ends up bearing the cost of that democratisation? And what structural changes to the technical, regulatory, or financial infrastructure would actually interrupt the supply chain, rather than repeating the tired official advice that potential victims should simply be more careful?

A Product History Written on Telegram

The commercial lineage of these tools is unusually well documented for a criminal industry, because it was advertised in public. In July 2023, a threat actor operating under the handle CanadianKingpin12 began promoting FraudGPT across underground forums and Telegram, marketing it as an all-in-one offensive toolkit for writing malicious code, building scam pages, and composing convincing fraudulent messages with, in the seller's phrasing, no boundaries. Netenrich analysts, who first surfaced the listing, reported a price of around 200 dollars per month or roughly 1,700 dollars per year, and a seller claiming several thousand confirmed sales. The same actor advertised a small family of related products, including DarkBERT and DarkBard, the latter a criminal counterpart to Google's Bard chatbot. WormGPT, its better-known sibling, had emerged slightly earlier and was built on an open-source model fine-tuned for business email compromise, the category of attack in which a fraudster impersonates a supplier or executive to redirect a payment.

What distinguishes the 2026 picture from that 2023 debut is maturation. The early tools were crude, expensive, and frequently scams in their own right, with sellers vanishing after taking a subscriber's cryptocurrency. The ecosystem The420.in describes has professionalised. It now offers custom dashboards from which a subscriber can orchestrate campaigns, ingesting parsed consumer datasets and generating thousands of unique phishing emails, texts, and voice-call scripts tailored to a target's profession, geography, and recent transactions. Capability that once had to be built in-house is now rented by the month, maintained by someone else, and delivered through an interface simple enough that the buyer need not understand what happens underneath. The criminal underground did not invent this model. It copied it, faithfully, down to the customer-support ethos.

The pricing reported in the investigation reflects that copying. A basic subscription is said to start at around 20 dollars per month and to include AI-generated phishing templates personalised to the victim, while a tier at around 160 dollars per month is described as bundling deepfake tools capable of defeating the identity checks banks and exchanges use to onboard customers. These figures should be read as reporting from the investigation rather than as independently audited prices, and they sit alongside the higher, historically documented FraudGPT rates. The tools are getting cheaper, easier, and more capable at once, precisely the trajectory that turned software from a specialist craft into a mass-market utility.

What Twenty Dollars Actually Buys

To treat a twenty-dollar phishing subscription as a novelty of the dark web that produces slightly better spam badly understates what has changed, and the misunderstanding matters because it shapes the defensive advice issued in response.

The old defensive folklore held that phishing could be spotted by its tells: clumsy grammar, generic greetings, obvious mismatches between a message and the organisation it claimed to represent. Those tells were artefacts of scale. A fraudster writing in a second language and blasting one template to a hundred thousand addresses produced text a careful reader could catch. Generative models dissolve that trade-off between scale and quality. KnowBe4, examining phishing emails detected between September 2024 and February 2025, found that 82.6 per cent contained AI-generated content, a jump the firm put at more than fifty per cent year on year; its April 2026 research put the figure at 86 per cent. The movement between those two readings is itself evidence of a share still climbing towards saturation rather than one that spiked and settled. The same research finds AI-written lures achieving markedly higher engagement than their human-written predecessors, with native-level grammar, appropriate register, and cultural context on demand. The advice to look for bad spelling is now advice to look for a weakness the attacker has already engineered away.

Personalisation is the second and more consequential capability. A message that references a target's actual employer, job title, city, and a plausible recent transaction is not a marginal improvement on generic spam; it is a different weapon, one that historically required either a skilled operator or a manual research effort that did not scale. The subscription model automates that research and folds it into the generation step, so that each of ten thousand recipients receives a lure calibrated to them individually. The most alarming tier reaches into the machinery of identity itself. Deepfake tools that fabricate a convincing identity-verification video are marketed as a way to defeat the know-your-customer checks meant to stop criminals opening accounts. That turns fraud from an act of persuasion into an act of impersonation at the infrastructure level, letting an attacker manufacture the accounts through which stolen money is received and laundered. The barrier that collapsed was never only the barrier to writing a convincing email. It was the barrier to industrialising every stage of the fraud pipeline, from the first message to the mule account that receives the proceeds.

The Evidence That This Is Cause, Not Coincidence

It is one thing to observe that criminal AI tools exist and that fraud is rising, and quite another to establish that the former is scaling the latter; sceptics reasonably ask whether the tools are hype layered over crime that would have happened anyway. The most rigorous attempt to answer that question is an academic paper catalogued on the arXiv preprint server under the identifier 2505.23733 and titled Unintentional Consequences: Generative AI Use for Cybercrime, whose authors, Truong Jack Luu and Binny M. Samuel, treat the public release of ChatGPT at the end of November 2022 as a natural experiment.

The researchers took two large real-world abuse datasets: more than 464 million malicious IP-address reports from AbuseIPDB, and 281,115 cryptocurrency scam reports from Chainabuse. They then treated the arrival of a powerful, publicly accessible generative model as a shock, and estimated the counterfactual trajectory of reported abuse had the model not been released. They found statistically significant increases in reported malicious activity after the shock across both datasets, including an immediate rise of over 1.12 million weekly malicious IP reports and roughly 722 additional weekly cryptocurrency scam reports, with sustained rather than transient growth in the crypto-scam series. The paper's conceptual contribution is a mechanism rather than a mere correlation. Generative AI, the authors argue, both creates new action possibilities for offenders and magnifies pre-existing malicious intent, by lowering the expertise required and raising the efficiency of each attack. Commoditisation does not create new criminals from nothing so much as it removes the friction that previously kept marginal offenders out and capped the output of committed ones.

Set against the market data, the mechanism becomes legible. Chainalysis, whose annual crypto-crime reports are among the most cited in the field, found that cryptocurrency scams received at least 14 billion dollars on-chain in 2025, up sharply from prior years, and projected the final figure could exceed 17 billion as more illicit addresses are identified. Crucially, the firm reported that scams with on-chain links to AI service providers generated on average about 3.2 million dollars per operation, roughly four and a half times more than scams without such links, and that the average scam payment more than tripled year on year. Europol's Internet Organised Crime Threat Assessment for 2026, published in April under the subtitle The evolving threat landscape: how encryption, proxies and AI are expanding cybercrime, reached a complementary conclusion in plainer language. Cybercriminals no longer need technical skills to succeed, because crime-as-a-service platforms supply everything from stolen data to step-by-step fraud tutorials. What the current edition adds is a measure of tempo: a widening velocity gap between law enforcement and offenders who use AI to automate attacks, personalise scams, and compress the time needed to launch an operation. Europol's word for the shift is industrialisation, and it notes that the dark web's marketplaces and forums have shown remarkable resilience despite sustained enforcement pressure. The commoditisation is not a projection. It is being measured.

The Country Where the Bill Arrived First

If the abstraction of a global fraud supply chain needs a concrete ledger, India provides one, which is why the original investigation is Indian. The country's Ministry of Home Affairs reported that cybercrime cases rose roughly 24 per cent in 2025, with reported losses of about 22,495 crore rupees, roughly 2.7 billion dollars, spread across more than 28 lakh, or 2.8 million, complaints. Investment-related frauds dominated, accounting for around 76 per cent of the total financial loss, with fake trading applications, Ponzi structures, crypto traps, and messaging-group schemes on Telegram and WhatsApp draining accounts within days.

India is an instructive case precisely because it built, faster than almost anywhere, the two conditions that AI-enabled fraud exploits. The first is instant, irrevocable payment. The Unified Payments Interface, the real-time rails that made digital payments ubiquitous across Indian daily life, moves money in seconds, without the settlement delay that elsewhere occasionally gives a defrauded victim or an alert bank a window to intervene. The second is a vast population newly brought online, transacting in dozens of languages, for whom the old visual tells of a scam were never reliable guides in the first place. Personalised, fluent, native-language lures generated by a subscription tool are not a marginal threat in that environment; they are a precision instrument aimed at its softest point. The Indian Cyber Crime Coordination Centre has leaned on the countermeasure available to it, assembling a registry of suspected criminal identifiers shared with banks; lenders contributed millions of suspect identifiers and mule-account flags, helping block fraudulent transactions worth thousands of crore. That is meaningful defensive work. It is also, revealingly, downstream work, aimed at catching the money after the fraud has already been manufactured, because the manufacturing happens on infrastructure that sits well outside any single national regulator's reach.

Where the Losses Actually Land

Who bears the cost of this democratisation has, until recently, had an uncomfortable default answer: the victim, alone. The prevailing model in most jurisdictions treated an authorised push payment, one the account holder was tricked into approving themselves, as the customer's responsibility, on the reasoning that the bank had followed instructions. The fraud, in this framing, was a personal misfortune, and the official response was educational. Be vigilant. Verify before you pay. Hang up and call back.

That default is regressive in a specific and under-examined way. When the cost of a systemic failure is assigned to whoever happened to be standing where it struck, the burden falls hardest on those least able to model the threat, and the data bears this out. The United States Federal Bureau of Investigation's Internet Crime Complaint Center recorded almost 21 billion dollars in reported losses for 2025, a 26 per cent rise on the previous year, across 1,008,597 complaints, the first time the centre has passed a million in a single year. Investment fraud, much of it involving cryptocurrency, remained the largest single loss category at 8.65 billion dollars. It is the distribution beneath those totals that makes the point. People aged sixty and over filed 201,266 complaints and lost 7.7 billion dollars, more than any other age group, their losses up around 59 per cent on 2024 against a 37 per cent rise in their complaint count, which is what happens when each attempt is better aimed rather than merely more numerous. That cohort filed a fifth of all complaints and absorbed 37 per cent of all losses, averaging 38,501 dollars each against an all-ages average of 20,699. The 2025 report also introduced AI-related as a formal crime descriptor for the first time, logging over 22,000 complaints and nearly 900 million dollars in losses. The pattern is the industrialisation thesis made human, and the bureau has now begun to measure it directly. When personalised, fluent, emotionally calibrated fraud can be produced for pennies and aimed at millions, the people it reaches are not a representative cross-section who failed a vigilance test. They are disproportionately the old, the isolated, the financially anxious, and the newly connected, selected because the tooling makes selecting them cheap.

Telling that population to be more careful is not merely inadequate; it is an implicit policy choice about where to place the cost. It leaves the loss with the person who has the least capacity to prevent it and the least ability to absorb it, while asking nothing of the parties that operate the infrastructure through which the fraud flows: the model providers whose systems were bent to the task, the platforms hosting the marketplaces, the payment rails moving the money, and the exchanges converting it into something untraceable. The current answer was never neutral. It was a liability regime that happened to spare the enablers, and it is that regime, rather than the credulity of victims, that the structural interventions worth discussing are designed to rewrite.

Making the Enabler Pay

The most instructive experiment in shifting that liability is British, and it has now been evaluated. On 7 October 2024, the United Kingdom became the first country to impose a mandatory reimbursement requirement for authorised push payment fraud. Under rules set by the Payment Systems Regulator, banks and payment firms must reimburse most victims of APP scams, up to a limit of 85,000 pounds, with the cost split evenly between the institution that sent the payment and the one that received it. By making the receiving bank liable for half of every reimbursement, that fifty-fifty split creates a direct financial incentive for institutions to police the mule accounts through which fraud proceeds are collected, a part of the chain that previously bore almost no consequence for its role.

The logic is the ordinary economics of externalities. When the cost of fraud sits entirely with victims, every other party in the chain has an incentive to shift the risk onward and invest as little as possible in stopping it. Reassign that cost to the institutions best placed to detect and interrupt the flow, and they suddenly have a reason to build the controls they had long treated as optional. The predictable industry objection, that mandatory reimbursement invites opportunistic claims and could even subsidise fraud, has to be managed through carve-outs for first-party fraud and gross negligence.

Until this month, that reasoning had to be taken largely on trust. On 1 July 2026 the Payment Systems Regulator published an independent evaluation of the scheme's first year, and its findings are the empirical payoff for the argument. The policy was estimated to have cut APP fraud losses by 73 million pounds a year and to have reduced the number of APP scams by nearly 35,000, with losses sent over Faster Payments falling around 21 per cent following implementation. Of the money lost to APP scams and claimed back from a payment firm, 88 per cent was returned to victims, against 66 per cent in the equivalent period of 2023/24. Overall reimbursement rates rose from 54 to 65 per cent; for claims within the policy's scope, firms now reimburse 97 per cent, settling around 84 per cent of claims within five days and 97 per cent within 35 days. The predicted surge in opportunistic claiming did not materialise in the first year's evidence. That matters most, because it distinguishes relocating a cost from reducing one: liability moved onto the enablers did not shuffle the bill around the system, it produced measurably less fraud, which is what should happen when the party best placed to prevent something finally becomes the party that pays. The regime continues under new management, HM Treasury's April 2026 package consolidating the Payment Systems Regulator into the Financial Conduct Authority.

That reimbursement mandate did not arrive alone, and its companion measure illustrates how liability and technical control reinforce one another. Confirmation of Payee, the account-name-checking service Britain required its largest banks to adopt from 2020, now covers well over ninety-nine per cent of Faster Payments and CHAPS transactions after successive expansions, according to the regulator. It verifies, before a payment is sent, that the name on the destination account matches the name the payer believes they are paying, closing off a category of impersonation on which many scams depend. On its own, a name check is easily circumvented by a determined criminal. Paired with a reimbursement rule that gives banks a reason to act on the signals it produces, it becomes part of a system in which the enablers, rather than the victims, carry the cost of failure and therefore have a reason to prevent it.

Choking the Money at the Off-Ramp

Liability rules interrupt the fraud where it touches the regulated banking system. A great deal of it, however, is designed precisely to avoid that system, routing proceeds through cryptocurrency, and especially through stablecoins, the dollar-pegged tokens that have become the preferred settlement layer of online crime. Chainalysis has reported that stablecoins now account for the majority of illicit on-chain value, which makes the mechanisms for controlling them a second, distinct chokepoint in the supply chain, and one with a surprising property: some stablecoins can be frozen at the point of issuance.

The clearest demonstration is the T3 Financial Crime Unit, a partnership launched in September 2024 between the stablecoin issuer Tether, the TRON blockchain network, and the blockchain-analytics firm TRM Labs. Because Tether can freeze its own tokens at the issuer level, a flagged wallet can be immobilised on-chain, in a way that has no equivalent in the cash economy. The unit has frozen more than 450 million dollars in illicit crypto since its launch, a figure Tether reconfirmed in May 2026, working with law enforcement across 23 jurisdictions and, in some cases, executing freezes within 24 hours of a request; it intercepted 43.9 per cent more illicit proceeds in 2025 than in the year before. The Financial Action Task Force, which sets global anti-money-laundering standards, has cited the arrangement as a model of public-private disruption. The same capability that privacy advocates rightly find troubling, a private issuer able to freeze funds on demand, is also the single most effective lever yet demonstrated for stopping fraud proceeds mid-flight.

The more durable structural intervention sits at the conversion points, the on-ramps and off-ramps where crypto meets conventional money. Fraud proceeds are only useful once converted into spendable currency, and that conversion overwhelmingly happens at exchanges, which are increasingly regulated financial institutions subject to know-your-customer and anti-money-laundering obligations. Rigorously enforced identity checks at those chokepoints do more to interrupt the supply chain than any amount of consumer education, because they attack the economics of the enterprise: fraud that cannot be cashed out is fraud that does not pay. This is why the deepfake KYC-bypass tier matters so much. Criminals are investing in defeating identity verification precisely because it is one of the few controls that genuinely threatens their business model, and that investment is itself confirmation that the chokepoint works.

The Fight Over the Model Layer

Upstream of the money sits the capability itself, the model that writes the lure and fabricates the verification video, and this is where interventions are least mature and most contested. The uncomfortable fact is that the tools sold under names such as WormGPT are frequently not exotic bespoke systems but ordinary open or leaked models with their safety training removed, wrapped in a friendly interface. That makes the model layer a genuine point of leverage and a genuinely hard problem at once.

For the major commercial providers, the relevant control is the robustness of guardrails against jailbreaking, the practice of coaxing a model into producing content its policies forbid. Every serious frontier developer now invests heavily in refusal training and adversarial testing, and the effectiveness of that work determines whether a criminal can simply use a mainstream model rather than a specialist criminal one. But guardrails on hosted models do nothing about the parallel ecosystem of open-weight models that can be downloaded, fine-tuned, and stripped of safety behaviour on a subscriber's own hardware, outside any provider's control. That is the unresolved tension at the centre of AI governance: the same openness that democratises beneficial capability also democratises the criminal kind, and no purely technical fix reconciles the two.

The intervention with the most regulatory momentum targets output rather than the model, through provenance. The Coalition for Content Provenance and Authenticity, an open standard backed by Adobe, Microsoft, the BBC, and others, attaches cryptographically signed metadata to a media file, recording who created it, with what tools, and whether AI was involved, a tamper-evident record known as Content Credentials. The European Union has given the approach legal teeth. Under Article 50 of its AI Act, whose transparency obligations become applicable from 2 August 2026, deployers who use AI to create deepfakes must disclose that the content is artificially generated, and the Commission's draft Code of Practice explicitly points to C2PA-style marking as the mechanism. That date survived a deregulatory round. The Digital Omnibus on AI, adopted by the European Parliament on 16 June 2026 and by the Council on 29 June, postponed the Act's high-risk obligations, pushing Annex III to 2 December 2027 and Annex I to 2 August 2028, but left the Article 50 transparency duties on their original timetable. The one exception is narrow: the watermarking and machine-readable-marking requirement under Article 50(2) applies from 2 December 2026 for systems already on the market at 2 August 2026. Deepfake disclosure and provenance marking, in other words, were among the few duties judged too important to delay.

The limitations are equally clear. Provenance is a voluntary declaration that a criminal will simply decline to make, watermarks can be degraded, and social platforms routinely strip metadata on upload. A provenance standard does not stop a fraudster generating a fake KYC video. What it does, if adoption becomes widespread, is invert the default, allowing verification systems to treat unsigned or unverifiable media with suspicion rather than credulity, which raises the cost and lowers the yield of synthetic impersonation. That is a supply-chain intervention, aimed at the value the tool produces rather than at scolding the person it targets.

The Platform That Blinked

Between the model and the money sits distribution, and for the Fraud-as-a-Service economy the channel of choice has been Telegram, whose encrypted messaging, large public channels, and long-standing reluctance to moderate made it an ideal marketplace. What happened to that channel is the clearest illustration that platform behaviour is a policy variable rather than a fixed feature of the internet.

In August 2024, French authorities arrested Telegram's co-founder Pavel Durov at an airport near Paris and subsequently indicted him on charges that included complicity in the distribution of illegal content and in organised criminal activity conducted through the platform, on the theory that its refusal to cooperate had made it a haven for fraud and worse. The investigation remains open as of July 2026, with no trial date set, Durov questioned for a fourth time this month and still rejecting the charges. Whatever the eventual legal outcome, the operational effect was immediate. Within weeks, Telegram revised its policy to state that it would hand over users' IP addresses and phone numbers to authorities in response to valid legal requests, extending cooperation from the narrow category of terrorism to fraud and other cybercrime. Reporting on the platform's transparency data showed fulfilled law-enforcement requests rising steeply in the months that followed. A platform that had positioned non-cooperation as a principle discovered, under sufficient legal pressure on an individual, that cooperation was possible after all.

The marketplaces on which criminal tools are sold are not forces of nature; they are operated by identifiable entities that respond to incentives, and the incentives can be changed. Coordinated takedowns of dark-web markets impose real if temporary costs, fragmenting communities and eroding the trust on which any marketplace depends. Europol's finding that those marketplaces have nonetheless proved remarkably resilient is the honest qualifier: the costs are real, and they are also absorbed. Sustained legal pressure on the platforms that knowingly host criminal commerce, and on the intermediaries that process payments for them, attacks the distribution layer of the supply chain directly. None of this eliminates the underground. It raises the friction, and friction, restored to a system that has spent a decade removing it, is precisely the point.

Interrupting a Supply Chain Rather Than Scolding Its Victims

Assemble the parts and a picture emerges very different from the individualised, be-careful framing that has dominated the public response to fraud. What the Times of India investigation described is not a wave of cleverer criminals but a supply chain, with distinct and separable stages: a model layer that manufactures the capability, a distribution layer that sells it, a targeting layer that finds and personalises the victims, and a settlement layer that collects and launders the proceeds. Each stage has a chokepoint. Each chokepoint has at least one demonstrated intervention. And every one of those interventions places the cost of prevention on an enabler with the leverage to act, rather than on a victim with none.

Seen this way, the choice a society faces is not between accepting fraud and achieving the impossible task of making millions of individuals immune to personalised deception. It is a choice about where in the chain to concentrate pressure. The British reimbursement mandate, with a first-year evaluation now behind it, demonstrates that liability can be relocated onto financial institutions, that they respond by building controls, and that the fraud itself measurably falls as a result. The T3 freezing mechanism and exchange-level identity checks demonstrate that the settlement layer can be squeezed, which is why criminals are paying to defeat it. The EU AI Act's provenance requirements demonstrate that the output of the tools can be made costlier to weaponise. The pressure applied to Telegram demonstrates that the distribution layer bends when the legal cost of hosting crime rises high enough. None of these is sufficient alone. Fraud will migrate to whichever stage is left unguarded, which is why a piecemeal, single-lever response fails and why the interventions have to be understood as a system answering a system.

The deeper point is one about honesty in assigning cost. For as long as the losses from AI-enabled fraud are treated as the private misfortune of the people unlucky enough to be targeted, the enablers face no bill and therefore build no defences, and the externality flows downhill to the old, the isolated, and the newly connected. The technologies that could interrupt the supply chain already exist and are, in places, already working. What has been missing is the decision to make the parties who profit from the infrastructure carry the cost of its abuse, rather than leaving that cost with whoever happened to open the message. A subscription that turns anyone into a fraudster is a market signal. It says the friction that once protected people has been engineered out, deliberately and for profit. Restoring that friction, at the model, the marketplace, the payment rail, and the off-ramp, is the work. Advising the target to be more careful is what a society does instead of the work.

References and Sources

  1. The420.in, “Renting the Exploits: How Fraud-as-a-Service Platforms Turned Digital Crime Into a Subscription Business,” July 2026. https://the420.in/fraud-as-a-service-cybercrime-subscription-business-ai-phishing/
  2. The420.in, “Fraud at the Speed of UPI: How AI Is Supercharging India's Cybercrime Boom,” 2026. https://the420.in/ai-fraud-real-time-digital-payments-india-cybercrime/
  3. Netenrich / SecureOps, “FraudGPT: The Villain Avatar of ChatGPT,” 2023. https://www.secureops.com/blog/ai-attacks-fraudgpt
  4. Dark Reading, “'FraudGPT' Malicious Chatbot Now for Sale on Dark Web,” 2023. https://www.darkreading.com/threat-intelligence/fraudgpt-malicious-chatbot-for-sale-dark-web
  5. Huntress, “What Is WormGPT?” Cybersecurity 101. https://www.huntress.com/cybersecurity-101/topic/wormgpt
  6. KnowBe4, “KnowBe4 Research Finds 86% of Phishing Attacks are AI Driven,” April 2026. https://www.knowbe4.com/press/knowbe4-research-finds-86-of-phishing-attacks-are-ai-driven
  7. Truong Jack Luu and Binny M. Samuel, “Unintentional Consequences: Generative AI Use for Cybercrime,” arXiv preprint 2505.23733, revised December 2025. https://arxiv.org/abs/2505.23733
  8. Chainalysis, “2026 Crypto Crime Report: Scams,” 2026. https://www.chainalysis.com/blog/crypto-scams-2026/
  9. Infosecurity Magazine, “Impersonation Fraud Drives Record $17bn in Crypto Losses,” 2026. https://www.infosecurity-magazine.com/news/impersonation-fraud-record-17bn/
  10. Europol, “Internet Organised Crime Threat Assessment (IOCTA) 2026 — The evolving threat landscape: how encryption, proxies and AI are expanding cybercrime,” 28 April 2026. https://www.europol.europa.eu/cms/sites/default/files/documents/IOCTA-2026.pdf
  11. The Print, “Cybercrime saw 24% spike in 2025. Indians lost Rs 22,495 crore, mainly in investment scams,” 2026. https://theprint.in/india/cybercrime-saw-24-spike-in-2025-indians-lost-rs-22495-crore-mainly-in-investment-scams/2859930/
  12. Insights on India, “Cybercrime in India 2025: 24% Spike, ₹22,495 Crore Lost,” 21 February 2026. https://www.insightsonindia.com/2026/02/21/cybercrime-in-india/
  13. Federal Bureau of Investigation, “Cryptocurrency and AI Scams Bilk Americans of Billions” (2025 IC3 Annual Report), April 2026. https://www.fbi.gov/news/press-releases/cryptocurrency-and-ai-scams-bilk-americans-of-billions
  14. Internet Crime Complaint Center, “2025 IC3 Annual Report” (PDF). https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf
  15. Payment Systems Regulator, “Consolidated policy statement: APP scams reimbursement requirement (PS25/5),” May 2025. https://www.psr.org.uk/media/rhelv4op/ps25-5-app-scams-reimbursement-consolidated-policy-statement-may-2025.pdf
  16. Payment Systems Regulator, “One year on: Impact of APP reimbursement on victims,” 1 July 2026. https://www.psr.org.uk/news-and-updates/latest-news/news/one-year-on-impact-of-app-reimbursement-on-victims/
  17. A&O Shearman, “The UK's Authorised Push Payment (APP) Fraud Reimbursement Scheme.” https://www.aoshearman.com/en/insights/ao-shearman-on-fintech-and-digital-assets/the-uks-authorised-push-payment-app-fraud-reimbursement-scheme
  18. Payment Systems Regulator, “Anti-fraud tool Confirmation of Payee expanded to hundreds of more firms.” https://www.psr.org.uk/news-and-updates/latest-news/news/anti-fraud-tool-confirmation-of-payee-expanded-to-hundreds-of-more-firms/
  19. TRM Labs, “T3 Financial Crime Unit: A Model for Public-private Disruption in the Age of Stablecoins.” https://www.trmlabs.com/resources/blog/t3-financial-crime-unit-a-model-for-public-private-disruption-in-the-age-of-stablecoins
  20. Tether, “$450 Million Frozen And Counting: T3 Financial Crime Unit Continues Global Crackdown on Illicit Crypto Flows.” https://tether.io/news/450-million-frozen-and-counting-t3-financial-crime-unit-continues-global-crackdown-on-illicit-crypto-flows/
  21. European Union, “Article 50: Transparency Obligations for Providers and Deployers of Certain AI Systems,” EU AI Act. https://artificialintelligenceact.eu/article/50/
  22. Greenberg Traurig LLP, “Deepfakes, Chatbots, AI-Generated Text: European Commission Details Transparency Obligations Under the AI Act,” June 2026. https://www.gtlaw.com/en/insights/2026/6/deepfakes-chatbots-ai-generated-text-european-commission-details-transparency-obligations-under-the-ai-act
  23. Coalition for Content Provenance and Authenticity, “C2PA and Content Credentials Explainer 2.2,” 22 April 2025. https://spec.c2pa.org/specifications/specifications/2.2/explainer/_attachments/Explainer.pdf
  24. Wikipedia, “Arrest and indictment of Pavel Durov,” 2024. https://en.wikipedia.org/wiki/Arrest_and_indictment_of_Pavel_Durov
  25. Dark Reading, “Sharing of Telegram User Data Surges After CEO Arrest,” 2025. https://www.darkreading.com/cybersecurity-operations/sharing-telegram-user-data-surged-after-ceo-arrest

Tim Green

Tim Green UK-based Systems Theorist & Independent Technology Writer

Tim explores the intersections of artificial intelligence, decentralised cognition, and posthuman ethics. His work, published at smarterarticles.co.uk, challenges dominant narratives of technological progress while proposing interdisciplinary frameworks for collective intelligence and digital stewardship.

His writing has been featured on Ground News and shared by independent researchers across both academic and technological communities.

ORCID: 0009-0002-0156-9795 Email: tim@smarterarticles.co.uk

Listen to the free weekly SmarterArticles Podcast

Discuss...

Enter your email to subscribe to updates.