A Washington firm called Shaper Collective sells AI "digital advocates" that argue for clients inside online communities. It is one visible, above-board node in a much larger shift — from Tehran's Lego cartoons to Taiwan's five-second smear clips to a $45M contract run out of Florida.
22 cards. Primary sources, three case studies, the academic evidence, and the parts that are genuinely contested.
Why it matters
The bottleneck on political persuasion used to be human headcount. That constraint is gone, and nobody has decided what replaces it.
The subject
Shaper Collective was founded by Ben Newman, who worked national public affairs on K Street before building AI systems. Its pitch: "expert humans moving at agent speed."
The firm says its digital advocates — Lead Shapers — generate 10,000+ messages daily across platforms. That figure is self-reported, from the company's own FAQ; no independent audit exists.
Traditional PR firms speak AT audiences. AI-native public relations speaks WITH communities.Shaper Collective FAQ
Why it matters
This is the same capability that state actors deploy covertly, sold openly as an agency service with an invoice attached.
The taxonomy
Per the .agent community profile, Shaper sorts its advocates into three tiers:
The Lead Shapers code is published on GitHub.
Why it matters
"Mirror the target demographic" is the design goal that separates advocacy from impersonation — and the tier where the line gets thin.
The line they draw
Shaper's stated ethics rule is narrow and specific. From its FAQ:
Our Lead Shapers never claim false identities or fabricate experiences. They advocate in third-person rather than making false first-person claims.Shaper Collective
The firm describes "approved narratives, prohibited claims, compliance posture, and human oversight triggers" enforced at generation time, with human review of outputs.
Note the gap: a persona with a name, face and backstory that avoids first-person claims is still a synthetic participant in a human conversation. Disclosure is not part of the stated rule.
Why it matters
Where the industry self-regulates, this is roughly where the line is being drawn. It is a claim about phrasing, not about identity.
The other product
SENSE is a weekly written brief — what is being argued, who is moving it, what to say back — built by agents that listen, filter, connect, map, read and remember.
Prices as listed publicly on the SENSE page, July 2026.
Why it matters
Synthetic audiences to test messages, then synthetic advocates to deliver them. The loop closes without a real person in it until the target.
The thesis
Newman's argument, distilled: if a language model can simulate the conversational nuance of a grassroots organiser, the constraint on advocacy is no longer headcount — it is model quality and data.
His newsletter, The Influence Model, extends this: AI agents now hold the tools once reserved for humans — inboxes, wallets, social accounts — so influencing an agent is becoming as important as influencing a person.
The .agent community's own writeup is blunter, describing the firm as using "the social and relational capabilities of LLMs to manipulate the social graph."
Why it matters
Every case that follows is a variation on this one economic fact. The tactics differ; the collapsed marginal cost is constant.
Case 1 · Iran
On 7 March 2026, a Tehran outlet called Explosive Media switched from Farsi videos with human hosts to English-language AI clips animated with Lego-style figures. Engagement exploded.
Why it matters
Global Affairs Canada assessed this as likely the most-viewed foreign information operation of 2026 so far — ahead of anything Russian.
Case 1 · attribution
Explosive Media presents itself as independent and solicits crypto donations. RRM Canada assesses it is likely linked to Saeed Jalili, the Supreme Leader's representative to Iran's SNSC.
The open-source chain: a recurring on-camera host was credited by name on an Instagram collaboration — a tag requiring his approval — and that same individual was on Jalili's social media team during his 2024 presidential run, later directing Jalili's Telegram subscribers to Explosive Media.
Separately, a spokesperson acknowledged to the BBC that the Iranian government was a customer.
Why it matters
Plausible deniability is now the default posture. "Independent media outlet" is a costume, and the attribution work is slow, manual and public-domain.
Case 1 · mechanism
The Atlantic Council's DFRLab credits the operation's traction to humour and to targeting "politically uninvested people who otherwise wouldn't have engaged with war-related content."
Writing in The Conversation, researchers describe the videos as Trojan horses: recognisable imagery, references and music carrying a narrative about American overreach and corruption. 404 Media credits the global cultural ubiquity of the Lego aesthetic itself.
YouTube suspended the group's account under its spam and deceptive practices policy. The Lego Group has trodden carefully in public.
Why it matters
The audience strategy is the innovation. It does not compete for news attention — it borrows entertainment attention from people who were never going to read about the war.
Case 1 · scale
The Institute for Strategic Dialogue estimates that Iran's broader AI-driven operations — which expanded into Minecraft and Pixar-style aesthetics — likely amassed over a billion views in the conflict's first month.
These are different measurements of different populations across different platforms. They should not be added together, and view counts are not persuasion counts.
RRM Canada notes a growing set of unaffiliated copycat creators producing similar content, and flags that the youth-coded intellectual property means a meaningful share of viewers were likely under 16.
Why it matters
Once an aesthetic proves it travels, the state no longer has to pay for distribution. Volunteers replicate it for free.
Case 2 · United States
In September 2025 the ad group Havas, acting for Israel's Ministry of Foreign Affairs, hired Clock Tower X — the firm of Brad Parscale, Trump's former campaign manager — at $1.5 million a month to run a US messaging campaign.
By The Wall Street Journal's accounting the contract has grown past $45 million. Reporting describes a commitment to 100 original pieces of content a month, at least 80% aimed at Gen Z.
We are pissed at Brad Parscale. We have paid him lots of money. But what did he do with it? Things have only gotten worse.Israeli official, to TIME
Why it matters
Registered, legal, and enormous. The regulated version of this industry is bigger than the covert version — and by its own client's account, not obviously working.
Case 2 · the texts
Millions of Americans received texts from senders named Emma, Matt, Sarah — introducing themselves as being with Friends for Peace, a group that does not officially exist. The messages open with a question rather than a position, engineered to start a conversation.
The texting ran through Sparkfire, which had collected $6.5 million by mid-May as a Clock Tower X subcontractor. One recipient noticed everything she wrote came back rephrased in the next message:
I said to him, "I don't think you're a real person," and he tried to persuade me to think that he was.Recipient, via TIME / WSJ
Separately, NPR counts at least five vendors running AI text conversations for the US midterms. One, Vector Political, reports 2.5 million texts and 20,000–30,000 conversations this year.
Why it matters
This is the Shaper "Persona" tier, deployed at national scale by a foreign government, in a channel with no labelling requirement.
Case 2 · the new target
The same operation built pro-Israel websites structured so that AI assistants would cite them. The Journal names Allyvia.org as one that both ChatGPT and Claude have picked up.
The vulnerability is real. Berlin think tank Agora Digitale Transformation ran 675 news questions through major chatbots and reviewed 4,811 source references. The diet was narrow — 46% of the 544 cited domains appeared exactly once — and Claude cited the Russian "Pravda" propaganda network seven times, unlabelled, beside legitimate journalism.
Why it matters
Persuading one retrieval index is cheaper than persuading a million people, and it scales to everyone who asks the question afterwards.
Case 3 · Taiwan
Taiwan's July 2025 "Great Recall" — a mass attempt to remove KMT legislators — became a laboratory for a new format. FactLink analysed 318 AI-generated mini-clips circulated 25 April – 30 July 2025.
They were shorter than TikTok videos — 5 to 30 seconds, closer to animated GIFs — and pushed as Reels, where Facebook and Instagram algorithms carried them.
Why it matters
No botnet, no state attribution needed. Free tools plus a recommendation algorithm outperformed the follower graph entirely.
Case 3 · the twist
FactLink's most uncomfortable finding: many clips displayed their AI watermarks openly. Doubao, Vidu, Dreamina, Hailuo, PixVerse, CapCut logos left visible.
They were not intended to deceive viewers into thinking they were real, but were meant to leave an impression and shape perception.Wei-Ping Li, Summer Chen, Mary Ma — FactLink
Recall supporters were rendered as toads, zombies and "flying frogs" — reusing a Chinese nationalist slur for Taiwanese people. The most-watched clips urged people to vote. The most-shared ones invented events to ridicule opponents.
Why it matters
Fact-checking assumes the goal is belief. When the goal is repeated symbolic association, a debunk has nothing to grip.
Case 4 · the industrial version
In August 2025, internal documents from GoLaxy — a Beijing firm affiliated with the Chinese Academy of Sciences — leaked to Vanderbilt University's Institute of National Security.
An operator dashboard screenshot lists 3,692 personas; an internal sheet names ten of them with phone numbers and email addresses. The system is described as mining social profiles to generate content that "feels authentic, adapts in real-time and avoids detection."
Reporting: Axios, The Record, Doublethink Lab.
Why it matters
Taiwan's 2024 election and Hong Kong's national security law were the proving grounds. The documents point forward to Taiwan's 2026 locals and 2028 presidential race.
Lineage
Team Jorge — exposed in 2023 by a 30-outlet consortium coordinated by Forbidden Stories. Israeli operative Tal Hanan's AIMS software commanded roughly 30,000 fake profiles across Facebook, Twitter, Telegram, Instagram — some with Amazon accounts, credit cards, crypto wallets and Airbnb histories. Hanan boasted of 33 presidential-level campaigns, 27 successful.
Doppelgänger — the Russian operation first identified by EU DisinfoLab in 2022, cloning The Guardian, Der Spiegel and Fox News. Per the FBI, contractors Social Design Agency and Structura produced nearly 40,000 pieces of content and 33.9 million comments between January and April 2024. Both firms are now under EU and US Treasury sanctions.
Why it matters
The persona farm predates the language model. What generative AI changed is the marginal cost of making each persona sound like a specific person.
The evidence · effect
Published in Nature, December 2025: a pre-registered set of experiments across the 2024 US presidential election, the 2025 Canadian federal election and the 2025 Polish presidential election. Participants were randomly assigned to converse with an AI advocating for a candidate.
We observed significant treatment effects on candidate preference that are larger than typically observed from traditional video advertisements.Lin, Rand et al., Nature 648 (2025)
The mechanism is less exotic than feared: models persuaded with relevant facts and evidence, not sophisticated psychological technique. But not all of it was accurate — across all three countries, models advocating for right-wing candidates made more inaccurate claims.
Why it matters
This is the strongest causal evidence yet that the Shaper business model has a real product behind it, not just reach.
The evidence · levers
Also in Science, December 2025: three experiments, N = 76,977, 19 language models, 707 political issues, with 466,769 resulting claims fact-checked.
The gains came from models' ability to rapidly marshal information. And strikingly — where the methods increased persuasiveness, they systematically decreased factual accuracy. Small open-source models, once post-trained, rivalled frontier models.
Why it matters
Two consequences. Persuasion capability does not require a frontier lab. And the most persuasive configuration is reliably the least accurate one.
The counter-case
The tidy story — huge views, therefore huge influence — does not survive contact with the literature. Kalla & Broockman's canonical review of 49 field experiments found the persuasive effects of campaign contact in general elections are close to zero.
OpenAI's threat reporting, covering 40+ disrupted networks since February 2024, reaches a deflationary conclusion: threat actors "bolt AI onto old playbooks to move faster," rather than gaining novel capability.
The honest synthesis: lab experiments show real per-conversation effects; field deployment shows most content reaches people who already agree. The open question is whether volume at collapsed cost converts a small effect into a decisive one.
Why it matters
Overstating the threat is its own hazard — it feeds the liar's dividend, where anything inconvenient gets dismissed as AI.
The governance gap
TikTok says it has labelled 3 billion AI-generated videos via Content Credentials and watermarking. Research cited alongside that rollout found small overlay labels do not measurably change belief or sharing — only full-screen interstitials do.
Meanwhile the US federal posture points elsewhere. The FTC's July 2026 proposed policy statement, issued under Executive Order 14365, targets AI companies steering model outputs toward undisclosed ideological objectives — not the firms buying synthetic advocacy.
State deepfake-disclosure laws (Kentucky, Louisiana, Maine, Maryland, Pennsylvania and others) cover fabricated media in election communications. A named persona arguing a policy position in a Facebook group is not a deepfake.
Why it matters
Every regulatory instrument on the table addresses synthetic media. The activity in this digest is synthetic participation, and it falls through.
If you only remember one thing
Taiwan's mini-clips left their AI watermarks visible. Iran's Lego videos never pretended to be footage. Shaper Collective publishes its persona taxonomy and open-sources the code.
The assumption underneath a decade of counter-disinformation work — that these operations depend on being mistaken for authentic — is no longer load-bearing. What they depend on is volume, repetition, and an algorithm that rewards emotional response.
Detection and labelling were built for the old assumption. That is the gap worth watching through the US midterms and Taiwan's November 2026 local elections.
Why it matters
If authenticity is not the load-bearing element, then authenticity verification is not the fix.
Sources