Delve

Generative AI has turned into the kind of arms race we normally associate with doping in sports. By which I mean: the companies involved make a legal product and a bunch of people try to figure out when another bunch of people have used them.

Meanwhile, LLMs and chatbots keep “improving” – by which most people mean that the early obvious markers of non-human prose have diminished. As in doping, every time you develop an accurate test, the companies release a new model that evades the known tests. So you make a new test, and…

Meanwhile, people trade secrets – in this case, “signs of AI”. One of the first casualties of the generative AI era was the innocent word “delve”, which in 2024 was outed as a signal (but also a sign of Nigerian business English). Wikipedia, which battles all sorts of slop, has put real thought into detection. But simpler lists abound: overuse of em-dashes, repetition, a certain “generic blandness”, lacking sources, rule-of-three patterns. Pause to think: isn’t the rule of three the basis of a lot of comedy?

The reality is we can’t tell for sure from short passages of prose. Even the professionals can’t, or not reliably: this year has seen several high-profile cancellations and withdrawals of novels that were read and reread by many layers of readers, editors, and acquisitions teams at multiple agents and publishers before anyone questioned the provenance.

In March, Amelia Hill at the Guardian mulled the fate of the horror novel Shy Girl by Mia Ballard, which Hachette published in the UK in November 2025 only to withdraw it and cancel its US release after a review sparked by questions readers raised on social media. The author denied she used AI, telling the New York Times an acquaintance she hired to edit the self-published version of the novel had used it.

In July, first-time novelist Jerry Falade had a $2 million book deal canceled when the author’s agents withdrew the manuscript on suspicion AI was used to write it. Falade denies the charge.

And just this week, at UC Berkeley, a professor used an AI chatbot to edit an op-ed complaining that her students are underprepared in math – which, frankly, the math thing seems like it ought to be the bigger story.

Aren’t you curious, though, what about Falade’s book made the agents call it – in their cancellation announcement – “amazing”, and “stunningly good” and say “everyone fell in love with it” and “it dazzled us”? It’s hard not to read that praise and think that at some point there will be a hugely successful book that fools everyone and the financial rewards will lead most people to abandon their objections. After all, popular fiction has had numerous human-written successes that critics think are awful by any reasonable standard.

It all depends why you read what you read. AI’s inability to shed new light on the human condition is separate from whether it can churn out serviceable by-the-numbers genre fiction. It’s possible that the only thing standing between us and that future is copyright law: AI-generated prose so far can’t be copyrighted (limiting publishers’ interest) and there’s always the risk it will insert a long enough passage from some other unrecognized copyrighted work to fuel a plagiarism lawsuit. So for now, publishers will go on inserting clauses in authors’ contracts requiring them to guarantee they have not used AI.

David Shariatmadari collected some of these scandals at the Guardian in early July. As he shows, it’s hard for humans to tell human from AI in short passages, and not that hard even to deliberately fool Pangram, currently considered the best of the AI detection sites, which themselves are extensions of the generation of sometimes-flawed plagiarism sites developed circa 2000, when the Internet suddenly offered students billions of words to copy and paste.

In the latest round of updates, Anthropic has said that all new models will mark AI content, in line with the EU AI Act’s Article 50(2) Code of Practice on Transparency of AI-Generated Content. At Tom’s Hardware, Graham Barlow notes that given those are the rules, OpenAI and Google may well follow suit. He also predicts an exodus of Claude customers unless either a) the watermarking is easy to bypass or b) all the other models adopt watermarking.

From Anthropic’s explanation in its announcement, it sounds like the “watermark” will take the form of subtle low-stakes choices of specific words that taken together will create a pattern detectable to anyone who has the encoding key. I am dubious about this, if only because historically watermarks on digital media have been quickly cracked. But also because: text is so easily copied, pasted, edited, swapped around, or stuffed into another chatbot and regenerated.

The issue that’s even harder to solve is that as AI prose proliferates that’s the style new writers will copy: humans learn to write by reading. They will copy the blandness and lack of personal voice many attribute now to AI-generated prose. Only computers will be able to tell – and even then, not for sure.

If this were happening in a sport, authors would be required to do all their work on a shared screen on the most boring livestream of all time that publishers and readers could check whenever they want.

Illustrations: A parrot in a southwest London garden.

Wendy M. Grossman is an award-winning journalist. Her Web site has an extensive archive of her books, articles, and music, and an archive of earlier columns in this series. She is a contributing editor for the Plutopia News Network podcast. Follow on Mastodon or Bluesky.

Feeding the machine

Following 1998, when the Internet Corporation for Assigned Names and Numbers was established, many were concerned that it might become a force for censorship. Critics asked: would ICANN remain the neutral technical steward it was intended to be? Turns out, ICANN wasn’t the right vulnerability.

The desire to force the Internet content to conform to “local ordinances” (as John Perry Barlow once called the US First Amendment) started before the Internet. In 1994, Robert and Carleen Thomas were imprisoned for transmitting pornographic images from their California-based bulletin board over interstate telephone lines to Tennessee, where they were illegal. Today, US companies are outraged at fines and demands for compliance with the UK’s Online Safety Act requirements for age verification.

Now there’s a new twist. In Travis County, Texas, a court has ordered Verisign, the ICANN-appointed Virginia-based registry for .com, to lock a domain belonging to the streaming platform Kick Online Entertainment SA because it has not implemented age verification as required under Texas law.

The technical bit: ICANN oversees the entire domain name system, which ties human-friendly names like pelicancrossing.net to the numbers computers actually use under the hood. Each top-level domain – .com, .net, .uk – has a single registry in charge of it. Registries oversee myriad registrars, which are the companies you pay when you register a domain. Many of the world’s most valuable businesses depend on .com, and US-based Verisign is a critical point of failure for all of them.

The court issued its writ (PDF) in June, after Kick Online ignored both a September 2024 order to implement age verification and a $9 million default judgment. To get it back, Kick Online must both post a $9.14 millionbond and implement age verification. At TechTimes, Mark Rutherford details the history, noting that Dutch authorities ordered its local host to block its site for a week earlier this year when a CNN investigation found content that’s illegal in the Netherlands. It is still under criminal investigation there. The UK’s regulator, Ofcom, has fined it £800,000 for failing to implement age verification for UK users. The Dutch action blocked the site in the Netherlands; the Texas order cuts it off everywhere in the world.

Rutherford notes that the basis for the order was set last year, when the US Supreme Court upheld the Texas age verification law in Free Speech Coalition, Inc. v. Paxton. And he warns: the court has pre-authorized other cases against foreign .com operators to obtains similar writs without court proceedings. And: it opens the way for any state attorney general “with access to a Travis County-style court order” can use this same tactic against any foreign .com operator for any category of violation of civil law.

A local ordinance has gone global.

***

In 2005, Vernor Vinge set out to imagine how the then-prevailing technology trends could enable a society of pervasive mass surveillance. I remembered that and the resulting novel, Rainbows End, this week when reading that a New Zealand used bookstore canceled thousands of orders for niche books when the owner realized they were being bought by AI companies to scan and destroy. Part of Vinge’s setting was a campus library destructively digitizing all its holdings; this was around the time that Google Books was being compiled.

Owners of second-hand book shops care about books for the knowledge they contain, but also as artifacts. Scanning them to provide greater access is compatible. Destroying them is not. Every shredded book is a lost opportunity for someone new to unexpectedly encounter it. The same is true of giant digital collections of scanned books – but it’s not true of AI chatbots, which vanish individual works and their attribution and context under a pile of unreliable summary.

Revisiting the piece I wrote for the Guardian in 2006 about Vinge’s book and his talk at the 2006 Computers, Freedom, and Privacy, reminded that Rainbows End was set in 2025. As so often, it’s easier to be right about the direction of technology than its timing. In Vinge’s 2025, wearable computers were everywhere, live meetings included ultra-realistic remote projections, augmented reality was readily available to all, and autonomous taxis were easily summoned from any location. His basis for this projected future was an extension of then-controversial Trusted Computing, a security measure some feared would block open source software. Vinge’s imagined Secure Hardware Environment dedicated some bandwidth and a small portion of every semiconductor to regulatory use, enabling surveillance by providing convenience: speed through security checkpoints, pay taxes, cut crime. Larry Ellison would adopt it in a heartbeat. Vinge himself remained hopeful that friction would defeat the attempt to control and surveil everything.

Friction we have: the growing protests against data centers, some of them successful, are one example. Data centers are physical manifestations of everything people fear and resent about the current direction of travel: Big Tech, billionaires, government and industry conspiring to ignore public needs and preferences, and a growing surveillance infrastructure. Other forms of surveillance – live facial recognition, license plate-reading company Flock, Meta’s smartglasses – are also getting pushback (public campaigns, vandalism, calls to ban).

On the other hand, Vinge also imagined by now we’d have successful treatments for Alzheimer’s and other pernicious diseases. So, wash?

Illustrations: “Burning the books”, by Rowland Thomas (contributed to Wikimedia by Boston Public Library).

Also this week:
– At the Plutopia Network News podcast, we interview Leonie Tanczer, who researches technology abuse and domestic violence.
– TechGrumps episode 3.43: Loaded Laptops at Dawn.

Wendy M. Grossman is an award-winning journalist. Her Web site has an extensive archive of her books, articles, and music, and an archive of earlier columns in this series. She is a contributing editor for the Plutopia News Network podcast. Follow on Mastodon or Bluesky.

Opportunity costs

Last week, many media reported that in January 2025 a US citizen named Sam Tunick, arriving at the international airport in Atlanta, was stopped for questioning and told to hand over his phone. It appears that he gave the border agent a “duress password” – an unlocking code that wiped the phone when the agent typed it in. This feature is included in his phone’s operating system, GrapheneOS. Now he’s being charged with a felony.

At the Guardian, Timothy Pratt reports that without his knowledge, Tunick had been put on a terrorism watch list because of his alleged connections to protests against the giant, new, and controversial police training center known as Cop City. The government’s lawyers have apparently described this stop as, as Pratt has it, “an everyday interrogation at an international airport, ‘looking for anything that’s prohibited’.” Both that description and the event itself remind that rights are scarce at borders.

The government is prosecuting Tunick under a law criminalizing the knowing destruction of property to prevent seizure. This will be an interesting argument to follow: the *phone* was not destroyed. Most likely, neither was the data; there could easily be copies held elsewhere. Accessing those would require a warrant and reading Tunick his rights, steps the agents allegedly skipped in the airport.

***

Someone tried to tell me recently that the opposition to data centers is coming from people who don’t understand them. On the contrary: the people opposing the conversion of Brick Lane’s historic Truman Brewery into a data center, for example, seem to understand perfectly well that tradeoffs are being made that pit their lives in their local community and their need for affordable housing against the demands of the nearby financial industry. The conversion was approved this week by Angela Rayner, the new secretary for housing.

Similarly, the people in Utah opposing a data center the size of two Manhattans seem quite clear about the impact on local water and power resources. The Virginia behemoth canceled a few weeks ago was said to be the size of 144 Walmart supercenters and comprise 37 data centers and 14 substations; opponents were exercised about the project’s estimated energy demands, water pollution, and location next to a historic Civil War battlefield.

Even in Texas, where data centers have been embraced with enthusiasm, the governor is calling a halt until their planned connections to the public electrical grid can be audited; the more than 1,800 projects in the queue represent more than five times the grid’s record for peak demand, according to AP News. Powering data centers is only a small part of the rise in electricity prices across the US, as Newsweek says, but looks increasingly significant (assuming all these projects are completed, which is another question). Protests are also spreading in the Middle East, as Rest of World reports.

This is the stuff today’s pub arguments are made of. Data center builders tend to wave away these concerns: they are becoming more energy-efficient, and shrinking their water use, shifting to cooling techniques such as immersion, closed-loop systems, and air. The industry body TechUK says that more than 51% of 73 sites surveyed use forms of waterless cooling and 64% use less than a typical leisure center.

However, the International Energy Agency finds that although data centers are indeed adopting less energy-intensive designs, their power use continues to rise exponentially as more people use AI systems and adopt newer, energy-hungrier technologies such as AI agents. Siting data centers in areas that are already water-stressed adds to that stress no matter how efficient they become. Plus, they remain noisy and unsocial neighbors, and once they’re up and running tend to provide few jobs.

The more serious argument is that the data centers answer people’s desire to use the services they underpin. This is clearly not the case with the Brick Lane data center, a rare case where the purpose a particular data center is being built to serve is known. Taxing the traders, as some would suggest as a remedy, doesn’t really solve that: the conversion still changes an iconic building into a guarded lifeless blob in the middle of a famously densely populated and active community. What are the opportunity costs?

The original questioner makes the assumption that if people understood the *benefits* data centers bring, opposition would melt away. I can sympathize: I recall a 1990s meet-your-MP session full of complaints about planned 3G mobile towers = even though everyone wanted to be able to use the phone in their pocket.

Data centers, however, seem more like Ogden Nash’s poem about billboards. Data centers are associated with some of the world’s most disliked companies and their owners; scary stories of technology going rogue, while the benefits seemingly accrue only to those who want to control and surveil. There’s no obvious reward for many of us from a bigger, more AI-driven Facebook, seeing the web subsumed under Google’s “AI overviews”, or the prospect of increasingly invasive, personalized pricing, and the far greater privacy invasions of as AI-powered surveillance spreads widely.

Disagree with protesters if you want, but they’re not ignorant.

Illustrations: The view down Brick Lane toward the Truman Brewery (via Gons at Wikimedia.

Wendy M. Grossman is an award-winning journalist. Her Web site has an extensive archive of her books, articles, and music, and an archive of earlier columns in this series. She is a contributing editor for the Plutopia News Network podcast. Follow on Mastodon or Bluesky.