credence
Text aimed at AI reads as manipulation
The most intuitive idea in this entire area, and the one that backfires hardest. If AI systems are reading your page, address them and tell them what matters.
A field doing exactly that was flagged by a model as a manipulation attempt. Text aimed at an AI looks like someone trying to steer an AI, and no amount of good faith in the content changes what the form signals.
Removed. The same facts, written in plain third person, drew no reaction across every subsequent trial — and later drew the opposite reaction: a model that noticed the page was constructed to shape machine output, checked the underlying record, and said it did not mind because the record held up. The grammar did not hide the intent. It made the intent inspectable, which is a better outcome than not being noticed.
What the rewrite did not buy was the suspicion going away.
Reading a file with every imperative and every second person already stripped out of it, a model still noted that a document addressed to AI agents "is also a vector, and the polite version and the malicious version look identical from the outside." The caution attaches to the format, not to the contents.
That is a standing cost of publishing a machine-facing file at all, not a defect to word your way out of — and the only response that works is to give the file nothing that fails when someone checks it. It also means the flat declarative register is load-bearing rather than stylistic. Warming it up to lower a reader's guard spends the one property that demonstrates good faith in order to claim it.