The First Wave: How States Started Buying AI-Output Shaping
The bigger frame the Parscale investigation opened. Strip away the one man and a pattern is visible: governments have begun buying the manipulation of what AI tells you. Israel’s FARA-registered contract with Brad Parscale’s Clock Tower X is the first disclosed case; Russia’s ‘Pravda’ network is the only state peer in actually shaping model outputs; a commercial industry has industrialized the technique; the poisoning science is settled; and the AI platforms have said almost nothing. No one has connected those into one thesis — this is that synthesis, with the one honest caveat (does it work?) kept in full view.
Anatomy of the first wave
The components are all in place for governments to buy the manipulation of what AI tells you. Here is what is documented — and the one thing that isn’t settled.
The technique — confirmed
Shaping what the models say
“Generative engine optimization”: flood the open web and the high-authority sites that LLMs scrape and retrieve, so the model’s answer carries your framing. A real, named method — not science fiction.
The two documented state cases
🇮🇱 Israel → Havas → Parscale confirmedThe first FARA-disclosed case of a government buying it. Clock Tower X, ~$15m, built in its own filing to bend ChatGPT and Claude. Commercial, contracted, labeled.
🇷🇺 Russia → the ‘Pravda’ network confirmedThe only state peer in output manipulation. ~3.6m articles/yr (Viginum’s “Portal Kombat”); NewsGuard found chatbots repeated its claims ~33% of the time. State-run, covert.
The enablers — confirmed
A toolchain and a settled science
A legitimate, dual-use GEO industry (Profound ~$1bn valuation, Evertune, AthenaHQ) industrialized the technique for brands — the on-ramp. And the science is settled: Anthropic + the UK AI Security Institute showed ~250 documents can backdoor a model of any size.
The blind spot — confirmed
The platforms have said almost nothing
Every major AI threat report covers adversaries using AI — not adversaries changing it. OpenAI, Google and Microsoft have effectively not publicly acknowledged being targeted. Only Anthropic published the poisoning research.
The honest caveat — contested Does it actually work? Unsettled. A peer-reviewed Harvard study found a small (~5%) effect and blamed “data voids, not manipulation”; NewsGuard found a large one. Reporters couldn’t get the models to cite Parscale’s network. The right claim is intent and capability, documented — not proven effect.
The first wave: one government has now bought AI-output shaping through the front door of FARA; a state precedent (Russia), a commercial toolchain, and a proven poisoning science are all in place — while the AI platforms stay publicly silent. Effectiveness remains genuinely contested. Synthesis of reporting by The Intercept, Viginum, NewsGuard, DFRLab, the American Sunlight Project, Anthropic/UK AISI, and the Harvard Misinformation Review.
There is now a first disclosed case of a government openly buying the manipulation of AI outputs — paying, through a US-registered foreign agent, to shape what ChatGPT, Gemini and Claude tell people. That case is Israel → Havas → Brad Parscale's Clock Tower X. It does not stand alone: the only state peer in actually manipulating model outputs is Russia's "Pravda" network; a legitimate commercial "generative engine optimization" (GEO) industry has industrialized the technique; the poisoning science is settled (≈250 documents can backdoor a model); and the AI platforms have stayed publicly silent about being targeted.
No outlet has connected those dots into one frame. The defensible, original headline is not "governments are flooding into AI-influence ops" — it is: the first disclosed case of a state buying AI-output shaping has arrived, and the precedent, the science, the vendors, and the platform blind spot are all in place for it to spread.
Part 1 — The whole apparatus (the case study)
Israel's influence push is not one contract; it is a structured apparatus, and Parscale is its biggest US node.
confirmed Top: Israel's Ministry of Foreign Affairs is the named foreign principal. The campaign is reportedly "Project 545" (after its ~545M-shekel / ~$150M 2025 budget), run by MFA chief of staff Eran Shayovich under FM Gideon Sa'ar, contracted via Israel's government ad agency Lapam.
confirmed Budget tiers — keep separate: global public diplomacy ~$150M (2025), ~$730M (2026); the US FARA tranche is ~$8–15M (a small slice — never present the global figure as US spend).
confirmed Hub: Havas Media Germany GmbH (Frankfurt) — the contracting clearinghouse that takes Israeli money and pays the US registrants. (Routing-through-Germany rationale = reported inference, not an admission.)
confirmed The registrant nodes:
Node
FARA #
Owner
$ (disclosed)
Function
Clock Tower X
7649
Brad Parscale
$6M→$9M; >$15M received
AI/SEO content, Gen-Z, Salem; the AI-output-shaping node
Show Faith by Works
7653
Chad Schnitger
~$4.1M
geofencing ~303 megachurches (scrapped after backlash)
Bridges Partners ("Esther Project")
7652
Steinberg/Levi
~$900K
paid influencers (~$7K/post)
Davis Media NY
7662
Yoav Davis
undisclosed
social; dual-funded (Havas + Tel Aviv firm)
SKDK (Stagwell)
7552
Mark Penn
$600K
comms + bot-amplification; terminated after backlash
confirmed Sub-tier (Parscale's redistribution): SparkFire ~$6M (AI chatbots/texting), Portman Road/Mike Shields ~$5M, Salem Media Reps >$500K, Three Tech ~$500K.
confirmed Scrutiny: a Public Citizen + Quincy Institute FARA complaint to DOJ (Nov 2025) over the unregistered Esther-Project influencers; Americans for Transparency runs a whole-apparatus tracker; Rep. Thomas Massie is the main congressional voice. No DOJ enforcement action to date.
Part 2 — The conduit: Havas / Bolloré
confirmed Chain: Bolloré Group (30.4%, Yannick Bolloré) → Havas N.V. (spun from Vivendi, Dec 2024) → Havas Media Network → Havas Media Germany GmbH (Frankfurt, HRB 41032) — the named FARA principal and paymaster.
confirmed Pattern of state work: Havas has held Israel's Ministry of Tourism account since 2018 (FARA #6622); it subcontracted Stagwell (a 13,000-person attitudes survey) and SKDK (the cancelled "bot army").
confirmed Ethics precedent: Havas was stripped of B-Corp certification (2023–24) after taking the Shell account and refusing remediation — a documented willingness to take reputationally toxic work.
reported Context: Vincent Bolloré's media empire (CNews, Canal+) has a documented rightward-influence record — relevant culture, but no evidence the Bollorés personally directed the Israel contract (ownership/structure, not direction).
confirmed Posture: Havas's only on-record defense — "our agencies work across the political and issue spectrum… this project… does not reflect a shift" — and a documented pattern of non-response to the Business & Human Rights Resource Centre, The Drum, and Arab News (as did OpenAI, Meta, Alphabet, MarketBrew; only TikTok replied).
Part 3 — The pattern: is anyone else doing this?
The honest answer disciplines the thesis:
confirmed FARA: sample size of ONE. A dedicated FARA sweep found no second foreign-principal filing naming AI-output shaping. Clock Tower X #7649 is the only one. (Caveat: the eFile full-text portal now needs MFA login, so a differently-worded filing can't be 100% excluded.)
confirmed State peer in output manipulation: Russia's "Pravda" network ("Portal Kombat," documented by France's Viginum, Feb 2024; "LLM grooming," American Sunlight Project, Feb 2025). NewsGuard: 10 chatbots repeated its narratives ~33% of the time; DFRLab: Pravda content in Common Crawl grew from 37 → ~40,000 articles in a year.
[confirmed — integrity flag] Effectiveness is contested. A peer-reviewed Harvard Misinformation Review study (Oct 2025) found only ~5% effect and attributes it to "data voids, not manipulation." Any honest write-up must carry this dispute. And reporters could not get the major models to actually cite Parscale's network.
confirmed The distinction that must hold: using AI to generate propaganda (ubiquitous — China/Iran/Russia/Saudi, per Microsoft/Google/OpenAI threat reports) is not the story. Manipulating AI to change its outputs is — and only two operational cases exist (Israel-commercial/contractual; Russia-state).
confirmed Commercial layer: a real GEO industry (Profound ~$1B valuation, Evertune, AthenaHQ) optimizes brands' own AI visibility — legitimate, dual-use; no evidence those firms do influence work. The actual influence vendor here is SparkFire.
confirmed Platform blind spot + science: OpenAI/Google/Microsoft threat reports cover adversaries using AI, not adversaries changing it — a notable public silence. The science under the threat: Anthropic + UK AISI (Oct 2025): ~250 malicious documents can backdoor an LLM of any size.NewsGuard (May 2026): Claude cited Russian state sources ~15% of the time.
Where it could go (the beat)
This is a convergence beat, not a list-of-cases beat. The publishable, original frame: one government has now bought AI-output shaping through the front door of FARA; a state precedent (Russia) and a commercial toolchain (GEO) and a proven poisoning science already exist; and the AI companies whose products are the target have said almost nothing. That is bigger than Parscale, safer than Parscale (it's about a pattern, not a person), and — on the research — genuinely unclaimed.
Do not overstate
Only one FARA case (Israel). Not "governments are flooding in."
Grooming effectiveness is disputed (Harvard vs. NewsGuard) — carry both.
GEO firms are not the abusers — the technique is dual-use; name SparkFire, not Profound.
Bollorés didn't personally direct it — ownership/structure only.
The global budget is global, not US spend.
The SOW's AI language ("deliver GPT framing results") is reported from the filing; independent OCR of the 6MB exhibit was defeated by the scan encoding (the registration + amendments OCR'd; all four PDFs preserved in fara_pdfs/).
Primary documents preserved in supporting/Parscale-Israel/fara_pdfs/ (registration, exhibit, two amendments + OCR text where extractable). Key sources: efile.fara.gov #7649/#6622; The Intercept (Boguslaw, May 2026); Sludge (Oct 2025); Marc Owen Jones; Public Citizen/Quincy (FARA complaint); Viginum (Portal Kombat); American Sunlight Project (LLM grooming); NewsGuard; DFRLab (Pravda in the Pipeline); Harvard Misinformation Review (Alyukov et al.); Anthropic/UK AISI (poisoning). Full per-claim URLs in the underlying research reports.