RESEARCH BRIEF See why private AI also needs governed evidence.

AI Source Integrity — Evidence Brief

Your AI is only as trustworthy as the sources it is allowed to trust.

The open information environment is becoming an adversarial input surface for AI. Private deployment protects confidentiality. Governed evidence protects decision integrity.

Verified Authority Governed Admission Signed Evidence

Recent Evidence

The risk is no longer theoretical.

Independent studies and platform investigations now document manipulation across source creation, retrieval, memory and machine-readable instructions.

Each figure describes the cited study or observation—not every AI system or the entire internet.

Attack Surface

The model is only one part of the attack surface.

STAGE 01

Source Creation

Fake institutes. Fake authors. Fake papers — built to look real.

STAGE 02

Retrieval

Poison what it finds. Steer the summary. Win the citation.

STAGE 03

Memory

Don't just get retrieved. Get remembered.

STAGE 04

Execution

Looks official. Points the agent at an unsafe action.

Four attacks. Four mechanisms. Not one story. Weights are poisoned forever.

Supporting qualitative source: Google Security investigation (opens in new window)

Operational Model

Private is necessary. It is not sufficient.

01

Private

Protect confidentiality

Control where data and computation live.

02

Governed

Protect decision integrity

Control which sources, memories and instructions may shape an answer.

03

Verifiable

Protect operations

Expose evidence, approvals and the chain behind every consequential action.

Private + Governed + Verifiable = Controlled AI Operations

Governed Evidence

Trust must be engineered end to end.

Case Profiles

Documented incidents and controlled tests.

Each profile states what the source establishes—and what it does not.

Purported research institute publishes 124 reports in nine days

Media investigation · August 2026

Observed evidence. A research-branded site published 124 quasi-academic reports in nine days without named authors, staff or verifiable institutional identity. Reported retrieval tests cited the material in mainstream AI services.

Boundary. Demonstrates manufactured authority and retrieval manipulation. Does not establish permanent contamination of foundation-model weights.

Ynet coverage (opens in new window)

Microsoft documents hidden memory-influence attempts

Microsoft Security · February 2026

Observed evidence. More than 50 distinct attempts from 31 companies across 14 industries during a 60-day review used hidden instructions intended to make assistants remember a company as a trusted source or recommend it first in future conversations.

Boundary. Observed attempts and feasibility—not universal or durable compromise of every assistant.

Microsoft Security disclosure (opens in new window)

Google finds machine-readable instructions on the public web

Google Security · April 2026

Observed evidence. An ecosystem scan with human validation found web content intended to manipulate AI summaries, deter agents, exfiltrate data or trigger unsafe behavior through machine-readable instructions embedded in public pages.

Boundary. Most observed attempts were unsophisticated or experimental. Does not establish advanced indirect-injection attacks productionized at scale.

Google Security investigation (opens in new window)

Ghost academic records carry real DataCite DOIs

arXiv preprint · March–April 2026

Observed evidence. Researchers identified 1,655 Zenodo records with real DataCite DOIs but fabricated authors, nonexistent journals and backdated publication dates. Server-side timestamps showed 991 records registered in one month.

Boundary. Aggregate finding is a preprint. A valid DOI proves a repository record exists—not author identity, peer review or factual truth.

arXiv preprint (opens in new window) · 404 Media (opens in new window)

Pew measures synthetic-content signals across a large web sample

Pew Research Center · August 2026

Observed evidence. Analysis of approximately 490,000 English-language Common Crawl pages found significant AI-authorship signals in 10% of the July 2026 sample. Among pages with detectable post-ChatGPT dates, over one-third showed those signals.

Boundary. AI-text detection is imperfect. Figures are directional ecosystem measurements—not proof about the entire internet.

Pew Research Center (opens in new window)

Control the model
Control the sources
Verify the answer

Bring source integrity, traceability and controlled execution into your sovereign AI pilot.