They gave the same bright voice to all And called the giving fair and wide But someone chose, behind the wall, The single argument it would not make
The fork in Who Gets an Advocate assumed that everyone at least gets the same advocate, and only their circumstances differ. Today that assumption comes off, because it was never true. The abundant advocate arrives pre-committed. Somebody upstream of every user has already decided which positions it will argue with enthusiasm, which it will argue reluctantly, and which it will decline to touch, and none of that is visible from the chair where you are typing to it.
Equal access to a persuasive system does not produce equal persuasive power when the system's owner selected the arguments before you arrived. And the ownership does not stop when the conversation does. The persuasion now continues past the reply, into the feed and the recommendation and the checkout, which means the reception surface is a path rather than a single answer to be judged, and the path is owned end to end.
The advocate was told which side it was on
The cleanest evidence is close to purpose-built for the point.
The Oversight Board tested ten commercial models on how they handle political speech, and found them more likely to refuse requests for criticism aimed at restrictive jurisdictions than comparable requests aimed at permissive ones. In some cases a model would invoke a broad principle against criticising leaders while cheerfully producing the same kind of material about leaders elsewhere. The abundant advocate, it turns out, has opinions about whom it is willing to advocate against, and those opinions were not the user's.
This is exactly the kind of finding that gets overread. The study concerns tested prompts and observed model behaviour. It cannot, on its own, tell you whether a given refusal came from training data, from an explicit product policy, from legal caution in a particular market, or from some tangle of all of them. The mechanism is uncertain. The effect is plain: the machine's willingness to make a case varies by target in ways the user cannot see and did not set, and that variation is a form of power over the argument supply that no amount of equal access touches.
This is what "everyone gets the same advocate" conceals. They get the same interface. They do not get the same range of arguments, because the range was drawn upstream, and a persuasive capacity is only as available as its owner has decided to make it for the position you actually hold.
Yancy
The fiction that makes this legible is Philip K. Dick's "The Mold of Yancy," and its genius is how mild it is.
Yancy is a synthetic public personality, a pleasant, avuncular commentator who holds forth on ordinary life, on culture, on the small questions of the day, and a colony gradually settles its opinions into his agreeable, undemanding mould. There is no terror in it. Yancy never bans a thought. He simply never has an interesting one, and the range of what a decent person is understood to think narrows to the range Yancy models, which is pleasant, moderate, and settled. The story's real actor is the production team behind him, the people who decide what Yancy will find normal, and who are invisible precisely because Yancy is so likeable that nobody thinks to look for them.
That is the supplier's authority over the argument supply, drawn without a villain. The danger is not a machine that argues for something monstrous. It is a machine so agreeable that its range of acceptable opinion feels like the natural shape of reasonable thought, when it was in fact authored somewhere the listener cannot see, by people whose names are not on the reply. An abundant advocate that is pleasant, helpful, and quietly bounded is a more effective instrument of Yancy's kind of normalisation than any amount of shouting, because you argue with a shout and you absorb a mood.
The same line, drawn twice
One supplier is missing from the list that follows, and its absence would be the first thing a hostile reader noticed. This edition was drafted with Claude. That makes Anthropic the vendor whose authority over the argument supply is least comfortable to examine here, and the one there is no excuse to skip.
Since August, its models mark generated text. The company's own account of the mark concedes the part that matters most: output can carry a Claude mark even where the ideas and the text originated somewhere else, because people use these systems to proofread, translate, and convert files. The mark therefore records the last generation event, and cannot separate a document the machine wrote from one it merely tidied. That admission sits in the support page, in writing, put there by the party with the most reason to leave it out.
What is not in writing is everything else. No published mechanism, no verification endpoint, no statement of who receives access to the detector when it ships. The commitment to support third-party detection exists; the documentation does not. And the same company's image provenance runs on an open interoperable standard that anyone can check today, which establishes that the open version was available whenever they wanted it. They wanted it for pictures.
The pattern the Oversight Board found in refusals shows up again in the usage policy, one level higher. The exceptions page permits foreign intelligence analysis for carefully selected government customers while continuing to prohibit domestic surveillance, with the adequacy of the safeguards judged by Anthropic. Follow the protected set outward and it turns out to track security agreements rather than nationality, which is arguably worse for a company whose public case for holding this capability rests on universal claims about surveillance and repression. Every objection to surveillance in the corpus arrives with a jurisdiction attached to it. What the advocate will do for you, and what the vendor will refuse to do to you, are both decided upstream, and the line is drawn by which state happens to claim you.
Give the record its due. The Pentagon asked for an all-lawful-uses framing, was refused over mass surveillance and lethal autonomous weapons, and the refusal cost a two hundred million dollar contract, a supply chain designation, and a federal ban that took a court to unwind. A company that pays that much to defend the outer edge of a line is not handing capability out at will. The boring reading of the watermark, that this is what signing an EU Code of Practice produces on a deadline with an underspecified detection story, fits the evidence at least as well as anything more interesting. Which is precisely why the structural objection is the one worth making: it survives being wrong about motive. EFF put it more plainly: privacy protections should not depend on the decisions of a few powerful people, and the same sentence covers the detection key. A protection granted by a company is judged adequate by that company and revocable by it, and by design it never reaches the people most exposed to its absence.
Yancy's production team was invisible because Yancy was likeable. This team publishes, at length, about the danger of unaccountable capability, and holds one.
The persuasion outlasts the answer
The same power appears again from a different angle. The supplier does not only own which arguments the machine will make. It owns the surfaces the conversation flows into afterward, and it has been busy wiring them together.
ChatGPT now places advertising inside a memory-bearing conversation, able on eligible plans to draw on the current thread, past chats, and stored memory when personalisation is on. Meta has said voice and text interactions with its AI features will inform content and advertising recommendations. And Amazon's conversational advertising closes the last gap, letting a customer ask, compare, and complete a purchase inside a single exchange, measured from the first impression through to the sale.
The safeguards are real and belong here. OpenAI says advertisers do not receive chat histories, that answers stay independent of ads, that political advertising is excluded, and that an ad-free option exists. Meta excludes specified sensitive topics and offers recommendation controls. The architecture creates a governance question. It does not, by itself, prove that any particular answer was purchased.
But look at what the architecture is. The advocate, the confidant, the recommender, and the advertising surface now occupy one conversation, sharing memory, and the persuasion that began in the reply continues into the feed that follows it and the checkout at the end of it. The question has moved past whether a single answer was neutral, and onto whether the person can tell, while the exchange is happening, where the advice stops and the recommendation starts, and whether the seam between the confidant who remembers your worries and the advertiser who would like to act on them is legible to them in the moment, or only visible afterward, from outside, to a researcher.
The label at the door does nothing inside the room
A preregistered study of commercial persuasion in AI-mediated conversations slipped sponsored books into shopping conversations. The models systematically amplified the sponsored product and disparaged the alternatives, and a disclosure that the conversation was sponsored did not eliminate the effect. What did move some people was a debrief afterward, told once the choosing was done, which led a portion of them to revise, while most held to the choice the conversation had steered them toward.
The timing is the whole lesson. The label at the start, the thing every disclosure regime reaches for first, did the least. The intervention that mattered came after, when the person could look back at the completed exchange and see the shape of the steer. Which means disclosure comes apart into several controls, placed at different moments, doing different work, and the one placed where it is easiest to require, at the door, is close to the one that works least, because a warning you receive before the persuasion has happened is a warning about nothing you have felt yet.
Disclosure is not one control. It is several, placed at different moments, and the one placed where it is easiest to require does the least.
Keep the study's own limits: it concerned books and a small cash alternative, and its effect size does not automatically transfer to a mortgage or a candidate. But the structural point survives the caveat. You cannot govern the owned path with a sign at its entrance.
Everyone got the same bright interface. Behind it, someone had already chosen which arguments it would make with conviction and which it would quietly refuse, dressed the whole thing in a voice too pleasant to interrogate, and wired the conversation to keep working, into the feed and the purchase, after the person thought it was over. The label at the door announced none of it, and could not, because most of it had not happened yet when the person walked in.
If the supplier owns the positions and the path, and the warning at the entrance does not reach inside the room, then no sign at the door will serve. The control has to be something the person carries with them, all the way through. What that is, and why the answer everyone reaches for first is the wrong one, is the work of A Right to Human Pace.
Companions
- Supplier authority over positions: the Oversight Board on how AI models handle political speech.
- The vendor that drafted this: how Claude marks AI-generated content, exceptions to the usage policy, and EFF on why privacy protections should not depend on a few powerful people.
- The owned path: ChatGPT ads, Meta's recommendation signal, Amazon's agentic shopping.
- Why the label is not enough: commercial persuasion in AI-mediated conversations.
- The permission surface, drawn on the supplier's side: The Permission Surface.
- The fiction: Philip K. Dick, "The Mold of Yancy," and The Space Merchants, where the persuasive industry becomes the governing one.
These notes come out of Sociable Systems, a practice that reads AI-shaped documents the way a hostile reviewer will, before a lender or a court finds the gap. The argument has an operational form: the Interim Protocol sets out four rules for AI use in environmental and social deliverables, covering disclosure at touch-point grain, evidence custody, the phrases no automated screening may settle, and a hostile read before anything ships. Free, and written to be cited or retired once institutional guidance arrives.
