◀︎ tap lefttap right ▶︎

The persuasion layer is now a product you can buy

A Washington firm called Shaper Collective sells AI "digital advocates" that argue for clients inside online communities. It is one visible, above-board node in a much larger shift — from Tehran's Lego cartoons to Taiwan's five-second smear clips to a $45M contract run out of Florida.


22 cards. Primary sources, three case studies, the academic evidence, and the parts that are genuinely contested.

Why it matters

The bottleneck on political persuasion used to be human headcount. That constraint is gone, and nobody has decided what replaces it.

The subject

An "AI-native PR firm" in Washington, DC

Shaper Collective was founded by Ben Newman, who worked national public affairs on K Street before building AI systems. Its pitch: "expert humans moving at agent speed."

The firm says its digital advocates — Lead Shapers — generate 10,000+ messages daily across platforms. That figure is self-reported, from the company's own FAQ; no independent audit exists.

Traditional PR firms speak AT audiences. AI-native public relations speaks WITH communities.Shaper Collective FAQ

Why it matters

This is the same capability that state actors deploy covertly, sold openly as an agency service with an invoice attached.

The taxonomy

Faceless, Personas, Avatars

Per the .agent community profile, Shaper sorts its advocates into three tiers:

The Lead Shapers code is published on GitHub.

Why it matters

"Mirror the target demographic" is the design goal that separates advocacy from impersonation — and the tier where the line gets thin.

The line they draw

Third person, never first

Shaper's stated ethics rule is narrow and specific. From its FAQ:

Our Lead Shapers never claim false identities or fabricate experiences. They advocate in third-person rather than making false first-person claims.Shaper Collective

The firm describes "approved narratives, prohibited claims, compliance posture, and human oversight triggers" enforced at generation time, with human review of outputs.

Note the gap: a persona with a name, face and backstory that avoids first-person claims is still a synthetic participant in a human conversation. Disclosure is not part of the stated rule.

Why it matters

Where the industry self-regulates, this is roughly where the line is being drawn. It is a claim about phrasing, not about identity.

The other product

SENSE: listening priced per issue space

SENSE is a weekly written brief — what is being argued, who is moving it, what to say back — built by agents that listen, filter, connect, map, read and remember.

From $3Kweekly brief, per issue space
From $6Kplus opposition tracking
Custom"Full Spectrum" — closed-garden sources and an AI persona focus group

Prices as listed publicly on the SENSE page, July 2026.

Why it matters

Synthetic audiences to test messages, then synthetic advocates to deliver them. The loop closes without a real person in it until the target.

The thesis

The cost of persuasion collapsed

Newman's argument, distilled: if a language model can simulate the conversational nuance of a grassroots organiser, the constraint on advocacy is no longer headcount — it is model quality and data.

His newsletter, The Influence Model, extends this: AI agents now hold the tools once reserved for humans — inboxes, wallets, social accounts — so influencing an agent is becoming as important as influencing a person.

The .agent community's own writeup is blunter, describing the firm as using "the social and relational capabilities of LLMs to manipulate the social graph."

Why it matters

Every case that follows is a variation on this one economic fact. The tactics differ; the collapsed marginal cost is constant.

Case 1 · Iran

83 million views of a Lego cartoon

On 7 March 2026, a Tehran outlet called Explosive Media switched from Farsi videos with human hosts to English-language AI clips animated with Lego-style figures. Engagement exploded.

83Musers who viewed a Lego-style video, March 2026 — RRM Canada minimum estimate
~200MRRM Canada's likely upper estimate, accounting for takedowns
4.38%of views from IPs in Russia or Iran — amplification was not the engine

Why it matters

Global Affairs Canada assessed this as likely the most-viewed foreign information operation of 2026 so far — ahead of anything Russian.

Case 1 · attribution

The trail to the Supreme National Security Council

Explosive Media presents itself as independent and solicits crypto donations. RRM Canada assesses it is likely linked to Saeed Jalili, the Supreme Leader's representative to Iran's SNSC.

The open-source chain: a recurring on-camera host was credited by name on an Instagram collaboration — a tag requiring his approval — and that same individual was on Jalili's social media team during his 2024 presidential run, later directing Jalili's Telegram subscribers to Explosive Media.

Separately, a spokesperson acknowledged to the BBC that the Iranian government was a customer.

Chart of Explosive Media Lego video views by platform
Views by platform; TikTok dominates. Global Affairs Canada, RRM report

Why it matters

Plausible deniability is now the default posture. "Independent media outlet" is a costume, and the attribution work is slow, manual and public-domain.

Case 1 · mechanism

It worked because it was funny

The Atlantic Council's DFRLab credits the operation's traction to humour and to targeting "politically uninvested people who otherwise wouldn't have engaged with war-related content."

Writing in The Conversation, researchers describe the videos as Trojan horses: recognisable imagery, references and music carrying a narrative about American overreach and corruption. 404 Media credits the global cultural ubiquity of the Lego aesthetic itself.

YouTube suspended the group's account under its spam and deceptive practices policy. The Lego Group has trodden carefully in public.

Why it matters

The audience strategy is the innovation. It does not compete for news attention — it borrows entertainment attention from people who were never going to read about the war.

Case 1 · scale

A billion views, and the copycats

The Institute for Strategic Dialogue estimates that Iran's broader AI-driven operations — which expanded into Minecraft and Pixar-style aesthetics — likely amassed over a billion views in the conflict's first month.

These are different measurements of different populations across different platforms. They should not be added together, and view counts are not persuasion counts.

RRM Canada notes a growing set of unaffiliated copycat creators producing similar content, and flags that the youth-coded intellectual property means a meaningful share of viewers were likely under 16.

Why it matters

Once an aesthetic proves it travels, the state no longer has to pay for distribution. Volunteers replicate it for free.

Case 2 · United States

$45 million, filed under FARA

In September 2025 the ad group Havas, acting for Israel's Ministry of Foreign Affairs, hired Clock Tower X — the firm of Brad Parscale, Trump's former campaign manager — at $1.5 million a month to run a US messaging campaign.

By The Wall Street Journal's accounting the contract has grown past $45 million. Reporting describes a commitment to 100 original pieces of content a month, at least 80% aimed at Gen Z.

We are pissed at Brad Parscale. We have paid him lots of money. But what did he do with it? Things have only gotten worse.Israeli official, to TIME

Why it matters

Registered, legal, and enormous. The regulated version of this industry is bigger than the covert version — and by its own client's account, not obviously working.

Case 2 · the texts

"I don't think you're a real person"

Millions of Americans received texts from senders named Emma, Matt, Sarah — introducing themselves as being with Friends for Peace, a group that does not officially exist. The messages open with a question rather than a position, engineered to start a conversation.

The texting ran through Sparkfire, which had collected $6.5 million by mid-May as a Clock Tower X subcontractor. One recipient noticed everything she wrote came back rephrased in the next message:

I said to him, "I don't think you're a real person," and he tried to persuade me to think that he was.Recipient, via TIME / WSJ

Separately, NPR counts at least five vendors running AI text conversations for the US midterms. One, Vector Political, reports 2.5 million texts and 20,000–30,000 conversations this year.

Why it matters

This is the Shaper "Persona" tier, deployed at national scale by a foreign government, in a channel with no labelling requirement.

Case 2 · the new target

Now they are optimising for the chatbot

The same operation built pro-Israel websites structured so that AI assistants would cite them. The Journal names Allyvia.org as one that both ChatGPT and Claude have picked up.

The vulnerability is real. Berlin think tank Agora Digitale Transformation ran 675 news questions through major chatbots and reviewed 4,811 source references. The diet was narrow — 46% of the 544 cited domains appeared exactly once — and Claude cited the Russian "Pravda" propaganda network seven times, unlabelled, beside legitimate journalism.

Why it matters

Persuading one retrieval index is cheaper than persuading a million people, and it scales to everyone who asks the question afterwards.

Case 3 · Taiwan

318 clips, five to thirty seconds each

Taiwan's July 2025 "Great Recall" — a mass attempt to remove KMT legislators — became a laboratory for a new format. FactLink analysed 318 AI-generated mini-clips circulated 25 April – 30 July 2025.

They were shorter than TikTok videos — 5 to 30 seconds, closer to animated GIFs — and pushed as Reels, where Facebook and Instagram algorithms carried them.

2.43Mviews on one fabricated clip, posted by an account with 10,000 followers
35.3%of clips carried watermarks; most traced to Chinese AI tools
19.2%carried two or more watermarks — multi-stage production

Why it matters

No botnet, no state attribution needed. Free tools plus a recommendation algorithm outperformed the follower graph entirely.

Case 3 · the twist

They did not hide that it was AI

FactLink's most uncomfortable finding: many clips displayed their AI watermarks openly. Doubao, Vidu, Dreamina, Hailuo, PixVerse, CapCut logos left visible.

They were not intended to deceive viewers into thinking they were real, but were meant to leave an impression and shape perception.Wei-Ping Li, Summer Chen, Mary Ma — FactLink

Recall supporters were rendered as toads, zombies and "flying frogs" — reusing a Chinese nationalist slur for Taiwanese people. The most-watched clips urged people to vote. The most-shared ones invented events to ridicule opponents.

Why it matters

Fact-checking assumes the goal is belief. When the goal is repeated symbolic association, a debunk has nothing to grip.

Case 4 · the industrial version

GoLaxy: 3,692 personas on a dashboard

In August 2025, internal documents from GoLaxy — a Beijing firm affiliated with the Chinese Academy of Sciences — leaked to Vanderbilt University's Institute of National Security.

An operator dashboard screenshot lists 3,692 personas; an internal sheet names ten of them with phone numbers and email addresses. The system is described as mining social profiles to generate content that "feels authentic, adapts in real-time and avoids detection."

117members of the US Congress profiled
2,000+American political figures and thought leaders profiled
50,000Taiwan-related news items collected in one project, actors sorted into "Hardliners," "Moderates," "Swing Voters"

Reporting: Axios, The Record, Doublethink Lab.

Why it matters

Taiwan's 2024 election and Hong Kong's national security law were the proving grounds. The documents point forward to Taiwan's 2026 locals and 2028 presidential race.

Lineage

This did not start with AI

Team Jorge — exposed in 2023 by a 30-outlet consortium coordinated by Forbidden Stories. Israeli operative Tal Hanan's AIMS software commanded roughly 30,000 fake profiles across Facebook, Twitter, Telegram, Instagram — some with Amazon accounts, credit cards, crypto wallets and Airbnb histories. Hanan boasted of 33 presidential-level campaigns, 27 successful.


Doppelgänger — the Russian operation first identified by EU DisinfoLab in 2022, cloning The Guardian, Der Spiegel and Fox News. Per the FBI, contractors Social Design Agency and Structura produced nearly 40,000 pieces of content and 33.9 million comments between January and April 2024. Both firms are now under EU and US Treasury sanctions.

Why it matters

The persona farm predates the language model. What generative AI changed is the marginal cost of making each persona sound like a specific person.

The evidence · effect

Conversational AI beats a campaign ad

Published in Nature, December 2025: a pre-registered set of experiments across the 2024 US presidential election, the 2025 Canadian federal election and the 2025 Polish presidential election. Participants were randomly assigned to converse with an AI advocating for a candidate.

We observed significant treatment effects on candidate preference that are larger than typically observed from traditional video advertisements.Lin, Rand et al., Nature 648 (2025)

The mechanism is less exotic than feared: models persuaded with relevant facts and evidence, not sophisticated psychological technique. But not all of it was accurate — across all three countries, models advocating for right-wing candidates made more inaccurate claims.

Why it matters

This is the strongest causal evidence yet that the Shaper business model has a real product behind it, not just reach.

The evidence · levers

Persuasion goes up, accuracy goes down

Also in Science, December 2025: three experiments, N = 76,977, 19 language models, 707 political issues, with 466,769 resulting claims fact-checked.

+51%persuasiveness gain from post-training for persuasion
+27%gain from prompting method alone
~0added gain from personalisation or model scale

The gains came from models' ability to rapidly marshal information. And strikingly — where the methods increased persuasiveness, they systematically decreased factual accuracy. Small open-source models, once post-trained, rivalled frontier models.

Why it matters

Two consequences. Persuasion capability does not require a frontier lab. And the most persuasive configuration is reliably the least accurate one.

The counter-case

Reach is not persuasion

The tidy story — huge views, therefore huge influence — does not survive contact with the literature. Kalla & Broockman's canonical review of 49 field experiments found the persuasive effects of campaign contact in general elections are close to zero.

OpenAI's threat reporting, covering 40+ disrupted networks since February 2024, reaches a deflationary conclusion: threat actors "bolt AI onto old playbooks to move faster," rather than gaining novel capability.

The honest synthesis: lab experiments show real per-conversation effects; field deployment shows most content reaches people who already agree. The open question is whether volume at collapsed cost converts a small effect into a decisive one.

Why it matters

Overstating the threat is its own hazard — it feeds the liar's dividend, where anything inconvenient gets dismissed as AI.

The governance gap

The label is not the remedy

TikTok says it has labelled 3 billion AI-generated videos via Content Credentials and watermarking. Research cited alongside that rollout found small overlay labels do not measurably change belief or sharing — only full-screen interstitials do.

Meanwhile the US federal posture points elsewhere. The FTC's July 2026 proposed policy statement, issued under Executive Order 14365, targets AI companies steering model outputs toward undisclosed ideological objectives — not the firms buying synthetic advocacy.

State deepfake-disclosure laws (Kentucky, Louisiana, Maine, Maryland, Pennsylvania and others) cover fabricated media in election communications. A named persona arguing a policy position in a Facebook group is not a deepfake.

Why it matters

Every regulatory instrument on the table addresses synthetic media. The activity in this digest is synthetic participation, and it falls through.

If you only remember one thing

The disguise was never the point

Taiwan's mini-clips left their AI watermarks visible. Iran's Lego videos never pretended to be footage. Shaper Collective publishes its persona taxonomy and open-sources the code.

The assumption underneath a decade of counter-disinformation work — that these operations depend on being mistaken for authentic — is no longer load-bearing. What they depend on is volume, repetition, and an algorithm that rewards emotional response.

Detection and labelling were built for the old assumption. That is the gap worth watching through the US midterms and Taiwan's November 2026 local elections.

Why it matters

If authenticity is not the load-bearing element, then authenticity verification is not the fix.

Sources

References