Sources for Book 3: The Economics of Trust
Status: this English source list is a working version, not the final edition. It gives readers the current named links for the selected English manuscript; final English source activation and release verification remain separate.
This page brings together bibliographic cards and verified direct links for Book 3. Cards follow the book's reading order, and their numbers match the source footnotes in the manuscript. Printed page numbers are intentionally omitted because they change with format and typesetting.
How to read the cards
- The description identifies the source and explains which fact, quotation, or qualification it supports.
- Open sources lists the named original publication, official document, independent confirmation, bibliographic record, or useful context.
- Gaps in numbering are expected: some numbers belong to glossary or explanatory notes that are not repeated here.
A linked source may open in the language in which it was originally published.
From the Author: The Human Check
Quotes and epigraphs
::: {.source-note} 1. Kenneth J. Arrow, “Gifts and Exchanges,” Philosophy & Public Affairs 1, no. 4 (1972), 343–362; quotation on p. 357.
Open sources: «Gifts and Exchanges»; PhilPapers. :::
Research, reports, and data
::: {.source-note} 13. The U.S. National Institute of Standards and Technology (NIST), AI 100-4 (2024; updated 2026): a detector is only one signal alongside provenance records, labeling, testing, and auditing.
Open sources: NIST AI 100-4: «Reducing Risks Posed by Synthetic Content». :::
Books and frameworks
::: {.source-note} 4. Chesney and Citron, California Law Review (2019): the liar's dividend is the advantage created when the possibility of fabrication helps people deny authentic recordings.
Open sources: «Deep Fakes: A Looming Challenge for Privacy, Democracy, and National Security». :::
::: {.source-note} 9. O'Neill argues that we should ask not “How can we increase trust?” but “What grounds allow us to judge trustworthiness?”
Open sources: «What We Don’t Understand About Trust»; «How to Trust Intelligently». :::
Markets, companies, and products
::: {.source-note} 2. ABC News and CBS News, October 2, 2023: Tom Hanks said that he did not take part in an advertisement that used an AI version of his likeness.
Open sources: ABC News; CBS News. :::
Author cases
::: {.source-note} 11. The U.S. Treasury's Financial Crimes Enforcement Network (FinCEN) and the FBI recommend confirming critical payment requests through an independent channel.
Open sources: Source 1: fincen.gov; FBI IC3, Annual Report 2025; FBI IC3 — Business Email Compromise (BEC). :::
Glossary notes
::: {.source-note} 3. Liar's dividend: the availability of fakes makes it easier to deny an authentic recording. See the Reader Glossary. :::
::: {.source-note} 5. Authority: the right to act, sign, or decide on behalf of a person, company, or system. It must be verified separately from identity. See the Reader Glossary. :::
::: {.source-note} 6. Content provenance: the history of a file or message—where it came from, who created it, and which traces support that account. See the Reader Glossary. :::
::: {.source-note} 7. Authenticity: a verifiable connection among the source of a message, its provenance, and accountability for the action. It does not mean that every word is true. See the Reader Glossary. :::
::: {.source-note} 8. Authenticity capital: the author's framework in Book 3 for the verifiable trail that a person or business accumulates over years—a history of decisions, real relationships, an authenticated channel, and accepted accountability. It is the asset; the authenticity premium is its return. See the Reader Glossary. :::
::: {.source-note} 10. Authenticity premium: the return on accumulated authenticity capital—a faster decision, lower verification costs, or a greater likelihood of being chosen when other factors are equal. See the Reader Glossary. :::
::: {.source-note} 12. A detector assesses properties of an object but does not establish authorship. A high or low score alone does not prove who created the text or exactly how AI was used. See the Reader Glossary. :::
Chapter 1. Convincing Does Not Mean Authentic
Quotes and epigraphs
::: {.source-note} 14. Sam Altman, post on X, September 3, 2025: “LLM-run accounts.”
Open sources: Source 1: x.com; forbes.com — sam altman starting see the dead; futurism.com — sam altman dead internet theory. :::
Research, reports, and data
::: {.source-note} 23. Imperva/Thales, 2025 Bad Bot Report: automation accounted for 51 percent of observed traffic. This is a vendor report about bots, not the share of AI-generated content.
Open sources: Imperva — 2025 Bad Bot Report; Source 2: imperva.com. :::
::: {.source-note} 24. Cloudflare, June 2026: automated requests for web pages exceeded human requests for the first time, at about 57 percent. The measurement covers one bot-protection vendor's network and only requests for pages.
Open sources: Source 1: radar.cloudflare.com; HUMAN Security — State of AI Traffic 2026. :::
::: {.source-note} 27. Kapwing, AI Slop Report (2025): a manual sample of trending YouTube channels. The figures for views, audience, and revenue come from outside aggregators and remain estimates.
Open sources: Kapwing — AI Slop Report; Source 2: sostav.ru. :::
Books and frameworks
::: {.source-note} 16. Merriam-Webster recorded a new digital meaning for the old word slop. It is a judgment about the quality and scale of content, not a way to prove machine origin.
Open sources: Merriam-Webster — Slop, Word of the Year 2025. :::
::: {.source-note} 17. Macquarie Dictionary and the American Dialect Society selected AI slop / slop as their 2025 word of the year. These are two institutions, not “three dictionaries.”
Open sources: Macquarie Dictionary — AI Slop, Word of the Year 2025; American Dialect Society — Slop, Word of the Year 2025. :::
::: {.source-note} 18. Merriam-Webster named authentic its 2023 word of the year and linked interest in the word partly to AI, deepfakes, and identity.
Open sources: Merriam-Webster — Authentic, Word of the Year 2023; Source 2: globenewswire.com. :::
::: {.source-note} 21. Niederhoffer et al., Harvard Business Review (2025): workslop looks like work but shifts the effort and cost of making sense of it to the recipient. The figures come from a survey.
Open sources: Harvard Business Review — Workslop and productivity; BetterUp — Workslop; BetterUp — hidden costs of Workslop. :::
Markets, companies, and products
::: {.source-note} 19. Australian Competition and Consumer Commission (ACCC), Targeting Scams 2021, p. 22: two transfers went through; a third bank stopped the next one. The U.S. Financial Crimes Enforcement Network (FinCEN) advises confirming new payment details through more than one channel.
Open sources: Source 1: accc.gov.au; Source 2: fincen.gov. :::
::: {.source-note} 28. Moderators of r/changemyview, 2025: the University of Zurich experiment was unauthorized, and its reported results were not peer reviewed.
Open sources: Reddit — meta unauthorized experiment cmv involving; Reddit — meta cmv experiment update apology received 2; washingtonpost.com — reddit bot university zurich. :::
::: {.source-note} 29. The New York Times, March 19, 2026: Hachette canceled Shy Girl over suspected AI use; the author disputed the allegation.
Open sources: The New York Times — shy girl book; The Guardian — hachette horror novel shy girl suspected. :::
Glossary notes
::: {.source-note} 15. Not every AI-written text is slop. Low quality and mass production are the defining features; the involvement of a model alone does not justify the label. See the Reader Glossary. :::
::: {.source-note} 20. What separates workslop from ordinary slop is who bears the cost. Even polished text becomes workslop when the recipient has to reconstruct the missing decisions, checks, and reasoning. See the Reader Glossary. :::
::: {.source-note} 22. Bot traffic means automated requests from programs to sites and services. It is not the share of content created by AI. See the Reader Glossary. :::
::: {.source-note} 25. Synthetic origin does not by itself mean falsehood or deception. Disclosure of AI's role, human verification, and the person accepting accountability all matter. See the Reader Glossary. :::
::: {.source-note} 26. Automated participation may be open and useful or hidden and harmful. The absence of a person at every step does not by itself make something a fake. See the Reader Glossary. :::
::: {.source-note} 30. The three questions of trust are the author's framework: Where did this come from? Who is speaking, and what are they accountable for? Who can confirm it independently? See the Reader Glossary. :::
::: {.source-note} 31. Cost of error means the potential harm from a wrong decision. The higher it is, the deeper verification should go. See the Reader Glossary. :::
::: {.source-note} 32. Human-verified marks a human check and accepted accountability, not a promise that every part was made by hand. See the Reader Glossary. :::
Chapter 2. Counterfeit Presence
Quotes and epigraphs
::: {.source-note} 33. Warren Buffett, Berkshire Hathaway annual meeting, May 4, 2024: he described AI as enabling a promising “growth industry” in fraud.
Open sources: cnbc.com — warren buffett says scamming will the; Fortune — warren buffett deepfake video tricking him. :::
Research, reports, and data
::: {.source-note} 44. The Bank of Russia counts transfers made without the customer's voluntary consent. In 2025, theft rose to 29.3 billion rubles, up 6.4 percent. The 2024 figure is a point in the trend, not its peak.
Open sources: Source 1: cbr.ru; Source 2: cbr.ru; Source 3: kommersant.ru. :::
::: {.source-note} 46. This figure is the share of the amount stolen, not one-quarter of victims or cases. The Bank of Russia's 2023 data is cited in a February 2024 report by Vedomosti.
Open sources: vedomosti.ru — kazhdii chetvertii pohischennii moshennikami rubl okazalsya. :::
::: {.source-note} 47. Bank of Russia, 2024 survey: working urban women with middle incomes and education were victimized more often; the economically active 25–64 age group was particularly exposed.
Open sources: Source 1: cbr.ru. :::
::: {.source-note} 49. U.S. Treasury Financial Crimes Enforcement Network (FinCEN), November 13, 2024: banks reported more schemes involving deepfake media in ordinary document, account, and loan fraud.
Open sources: FinCEN — Alert FIN-2024-Alert004; Source 2: fincen.gov. :::
::: {.source-note} 51. FBI Internet Crime Complaint Center (IC3), 2025 report: 22,364 complaints marked “AI Related” reported about $893 million in losses. This is not an estimate of AI's share of all fraud.
Open sources: FBI IC3 — Annual Report 2025; Source 2: fbi.gov. :::
Books and frameworks
::: {.source-note} 36. Kommersant, June 2025: experts estimated that about twenty seconds of voice could provide a usable sample. This is an estimate, not a technical constant.
Open sources: Source 1: kommersant.ru. :::
Markets, companies, and products
::: {.source-note} 35. Jennifer DeStefano's testimony to the U.S. Senate, June 13, 2023: her daughter's voice was checked through an independent call; AI use in the original call was not technically confirmed.
Open sources: Source 1: judiciary.senate.gov. :::
::: {.source-note} 37. Kommersant, June 2025: experts said fraudsters recorded victims' voices under the guise of opinion polling. This is an expert estimate, not a regulator's finding.
Open sources: Source 1: kommersant.ru. :::
::: {.source-note} 38. Russia's Ministry of Internal Affairs, as reported by Izvestia, July 6, 2026: a relative's voice can be synthesized during a call.
Open sources: iz.ru — mvd zaiavil vozmozhnosti moshennikov sozdavat dipfeiki. :::
::: {.source-note} 39. Fuzhou police and Chinese media, May 2023: a business owner transferred 4.3 million yuan after a video call that replaced a “friend's” face and voice.
Open sources: yicaiglobal.com — china uncovers countrys largest face swap; Source 2: news.rthk.hk. :::
::: {.source-note} 40. Government of Hong Kong, June 26, 2024: HK$200 million was transferred after a prerecorded deepfake conference without live dialogue; Arup later confirmed the case.
Open sources: Source 1: info.gov.hk; scmp.com — multinational arup confirmed victim hk200 million; scmp.com — everyone looked real multinational firms hong 2; hongkongfp.com — multinational loses hk200 million deepfake video. :::
::: {.source-note} 41. Bloomberg and MIT Sloan Management Review, 2024: a personal verification question stopped an attempt to imitate the Ferrari CEO's voice. There was no loss.
Open sources: sloanreview.mit.edu — how ferrari hit the brakes deepfake; Fortune — ferrari deepfake attempt scammer security question. :::
::: {.source-note} 42. The Guardian, May 10, 2024: an attack on WPP using a fake CEO account, cloned voice, and YouTube footage was stopped.
Open sources: Source 1: theguardian.com. :::
::: {.source-note} 43. Singapore Police Force, April 2025: US$499,000 sent after a deepfake call was frozen and returned to the company.
Open sources: mothership.sg — finance director scammed deepfake; Source 2: hcamag.com. :::
::: {.source-note} 48. France 24 and NBC News, January 2025: a woman in France lost about €830,000 in a fraudulent correspondence with someone posing as “Brad Pitt.”
Open sources: Fortune — brad pitt scam fake relationship french; nbcnews.com — brad pitt woman romance scam france; euronews.com — viral scam french woman duped brad. :::
::: {.source-note} 50. Europol, Facing Reality? (2022): a $35 million transfer in the United Arab Emirates was linked to a call imitating a company director's voice.
Open sources: europol.europa.eu — Europol Innovation Lab Facing Reality Law; forbes.com — huge bank fraud uses deep fake. :::
::: {.source-note} 54. The U.S. Federal Trade Commission (FTC), the U.S. Financial Crimes Enforcement Network (FinCEN), and Russia's Ministry of Internal Affairs converge on one rule: end a suspicious conversation and call back on a number known in advance.
Open sources: Source 1: consumer.ftc.gov; FinCEN Alert FIN-2024-Alert004; Source 3: iz.ru. :::
Glossary notes
::: {.source-note} 34. Unlike a recording or static deepfake, counterfeit presence participates in an action: the copy responds, asks, confirms, or creates urgency in a person's name. See the Reader Glossary. :::
::: {.source-note} 52. A code word is a family secret chosen in advance to verify an urgent call or message from someone close. See the Reader Glossary. :::
::: {.source-note} 53. A second channel is an independent way to confirm a costly action—for example, calling back yourself on a previously known number. See the Reader Glossary. :::
Page notes
::: {.source-note} 45. Social engineering is deception that persuades a person to disclose data, transfer money, or bypass protection. It attacks a person's decision, not only a system. :::
Chapter 3. The Reverse Turing Test
Quotes and epigraphs
::: {.source-note} 55. Peter Steiner, cartoon caption, The New Yorker, July 5, 1993.
Open sources: Source 1: en.wikipedia.org; smithsonianmag.com — the most reprinted new yorker cartoon. :::
Research, reports, and data
::: {.source-note} 72. Vanderbilt University, "Guidance on AI Detection and Why We're Disabling Turnitin's AI Detector" (August 16, 2023): Vanderbilt submitted about 75,000 papers to Turnitin in 2022 and calculated that a 1% false-positive rate could wrongly flag roughly 750. Johns Hopkins says it disabled Turnitin's detector over false-positive concerns and recommends discussing concerns with a student before making an accusation. Turnitin's release notes say scores from 1% to 19% are no longer shown because false positives can occur in that band.
Open sources: Vanderbilt — AI detection guidance; Johns Hopkins — detection tools guidance; Turnitin — AI writing detection model. :::
Books and frameworks
::: {.source-note} 59. Diel et al., 2024: a meta-analysis of 56 studies put average human accuracy at detecting synthetic content at 55.5%.
Open sources: sciencedirect.com — S2451958824001714; macdorman.com — Diel Human Performance Detecting Deepfakes Meta. :::
::: {.source-note} 60. Porter and Machery, Scientific Reports (2024): non-experts distinguished AI and human poetry at 46.6% accuracy and more often mistook machine-written poems for human ones.
Open sources: Nature — s41598; pmc.ncbi.nlm.nih.gov — PMC11564748. :::
::: {.source-note} 61. Jones and Bergen, PNAS, 2026: in five-minute conversations, GPT-4.5 given a roleplay instruction was judged human in 73% of rounds; without it, in 36%.
Open sources: PNAS — 10.1073/pnas.2524472123; arXiv — 2503.23674; today.ucsd.edu — can seem more human than real. :::
::: {.source-note} 64. OpenAI closed its AI Text Classifier in July 2023 citing low accuracy: it caught roughly 26% of AI-written texts and produced a 9% false-positive rate on human-written text.
Open sources: OpenAI — new classifier for indicating written text; techcrunch.com — openai scuttles written text detector over; searchengineland.com — openai classifier longer available. :::
::: {.source-note} 65. OpenAI, educator FAQ: the reliability of AI-text detectors has not been demonstrated, and ChatGPT cannot determine whether it wrote a specific text.
Open sources: help.openai.com — how can educators respond students presenting. :::
::: {.source-note} 66. Liang et al., Patterns (2023): seven detectors incorrectly labeled an average of 61.3% of essays written by non-native English speakers as AI-generated.
Open sources: sciencedirect.com — S2666389923001307; arXiv — 2304.02819. :::
::: {.source-note} 74. Chesney and Citron (2019); Schiff et al. (2024): claims of "this is a deepfake" can reduce accountability for genuine incriminating material.
Open sources: Source 1: scholarship.law.bu.edu; cambridge.org — 687FEE54DBD7ED0C96D72B26606AA073. :::
::: {.source-note} 75. Reason and versions of the Europol report: the forecast of "90% AI content by 2026" traces back to a Synthesia vendor claim and is not supported by any measurements.
Open sources: reason.com — that time tried make sense statistic; europol.europa.eu — Europol Innovation Lab Facing Reality Law; securitydelta.nl — Europol Innovation Lab Facing Reality Law. :::
Markets, companies, and products
::: {.source-note} 56. Rolling Stone, 2025: the em dash came to be seen as a ChatGPT marker, and some writers began avoiding a punctuation mark they had long used.
Open sources: Source 1: rollingstone.com; Source 2: techradar.com; Source 3: washingtonpost.com. :::
::: {.source-note} 67. Fast Company and EdSurge, 2024: student Marley Stevens was penalized after Turnitin flagged an essay she had run through Grammarly; she was later reimbursed $4,000.
Open sources: fastcompany.com — can using grammarly set off detection; edsurge.com — can using grammar checker set off; grammarly.com — grammarly launches grammarly authorship. :::
::: {.source-note} 68. Rolling Stone and Washington Post, May 2023: a professor used ChatGPT as a detector; revision histories were accepted as evidence of student authorship.
Open sources: Source 1: rollingstone.com; Source 2: washingtonpost.com. :::
::: {.source-note} 69. The Bookseller and other outlets, 2026: Jamir Nazir's story was run through Claude and Pangram, but on review the author retained his Commonwealth Short Story Prize win.
Open sources: theconversation.com — what the commonwealth writers prize allegations; thebookseller.com — jamir nazir wins commonwealth short story; slate.com — jamir nazir commonwealth short story prize. :::
::: {.source-note} 70. Kommersant, April 28, 2026: Antiplagiat returned high AI-content scores on independently written theses; the stated accuracy figure is a vendor claim.
Open sources: Source 1: kommersant.ru; antiplagiat.ru — instructions new. :::
::: {.source-note} 71. Kommersant, June 8, 2026: the court reinstated the student, noting the probabilistic nature of the Antiplagiat report and the need for an expert decision.
Open sources: Source 1: kommersant.ru; Source 2: kommersant.ru; Source 3: habr.com; Source 4: ria.ru. :::
Glossary notes
::: {.source-note} 57. The term is used here more broadly than CAPTCHA: the examiner is an employer, a university, or a platform, and what counts as proof is not a single answer but a trail of process and decisions. See the Reader Glossary. :::
::: {.source-note} 62. A synthetic-content detector looks for signs of generation or manipulation; its output is one signal for review, not a final verdict. See the Reader Glossary. :::
::: {.source-note} 73. The liar's dividend does not require producing a fake: it is enough to plausibly invoke the existence of the technology and shift the dispute from the act to the record. See the Reader Glossary. :::
Page notes
::: {.source-note} 58. A meta-analysis is a study that pools results from many previously published works to arrive at a more robust overall estimate. :::
::: {.source-note} 63. "Detector percentage" throughout refers to the model's probabilistic numeric output. The interface may display it as a share, probability, or confidence score, but it is not a measured proportion of AI text and is not proof of authorship. It is a signal for review, not the sole basis for a decision. :::
::: {.source-note} 76. A RAW file is the camera's unprocessed output; it retains more capture data than a finished JPEG and can help verify a photograph's origin. :::
Chapter 4. Synthetic Reputation
Quotes and epigraphs
::: {.source-note} 77. Jonathan Swift, The Examiner, November 9, 1710: "Falsehood flies, and truth comes limping after it." The popular version involving boots is apocryphal.
Open sources: ourcivilisation.com — chap14; quoteinvestigator.com — truth; en.wikiquote.org — Jonathan Swift. :::
Research, reports, and data
::: {.source-note} 88. Tripadvisor, 2023 transparency report: the platform identified 4.4% of submitted reviews as fraudulent; this is the platform's own moderation data, not an independent audit.
Open sources: tripadvisor.com — transparencyreport2023; prnewswire.com — tripadvisor report reveals strong growth review. :::
::: {.source-note} 89. Google, 2023 data: more than 170 million policy-violating reviews and 12 million fake business profiles removed; this is the platform's own report.
Open sources: Google — How machine learning keeps contributed content helpful; Search Engine Land — Google fake reviews 2023; TechSpot — fake reviews removed by Google. :::
::: {.source-note} 91. FTC, 2024 rule: fake reviews, their purchase, and undisclosed insider connections are prohibited in the United States; civil penalties apply.
Open sources: Federal Trade Commission — final rule banning fake reviews and testimonials; Davis Wright Tremaine — FTC finalizes fake-review rule; Alston & Bird — FTC final rule on fake reviews. :::
Books and frameworks
::: {.source-note} 83. Robert Cialdini, Influence (1984): social proof leads us to judge behavior as correct when we see others doing it.
Open sources: Source 1: books.google.com. :::
::: {.source-note} 85. Merriam-Webster and specialized sources trace "astroturfing" to Senator Lloyd Bentsen's remark about artificial AstroTurf grass (1985).
Open sources: en.wikipedia.org — Astroturfing; merriam-webster.com — astroturfing; newsroom.ucla.edu — whats the difference between political grassroots. :::
::: {.source-note} 93. Salvi et al., Nature Human Behaviour (2025): GPT-4 outperformed humans in short debates only when personalization data was available.
Open sources: Nature — s41562. :::
Markets, companies, and products
::: {.source-note} 78. Block Club Chicago and Axios, 2025: Restaurant Alpana received 15 fake reviews and an extortion demand; Google removed the attack within twenty-four hours of the complaint.
Open sources: Source 1: blockclubchicago.org; Source 2: axios.com; Source 3: fox32chicago.com. :::
::: {.source-note} 79. Block Club Chicago, December 5, 2025: restaurants and a pharmacy received series of fake reviews accompanied by threats to continue the attack.
Open sources: blockclubchicago.org — scammers are trying extort chicago restaurants; hoodline.com — business beware nationwide scam floods companies. :::
::: {.source-note} 80. Stuart A. Thompson, NYT News Service, September 18, 2025: a small business owner paid extortionists after her rating collapsed, but the attack resumed.
Open sources: The Economic Times — Small Businesses Face a New Threat; Source 2: consumeraffairs.com; Source 3: patch.com. :::
::: {.source-note} 86. Today.com, August 2022: U.S. restaurants were threatened with series of one-star reviews and demanded gift cards of $75.
Open sources: today.com — one star review restaurant extortion scam; 9to5Google — Google one-star review scam; Engadget — restaurant review extortion. :::
::: {.source-note} 87. Amazon, 2022–2023: the company filed suits against group administrators and review traders; figures reflect the platform's own claims.
Open sources: aboutamazon.com — amazon targets fake review fraudsters social; cnbc.com — amazon sues facebook group administrators over; time.com — amazon lawsuit facebook groups fake reviews. :::
::: {.source-note} 90. Separate Which? investigations found ten Facebook recommendations offered for about £6.50 and Amazon reviews offered at about £13 each, with packages starting at £620 for fifty. The market study is Sherry He, Brett Hollenbeck, and Davide Proserpio, "The Market for Fake Reviews," Marketing Science 41, no. 5 (2022): a hand-collected panel of roughly 1,500 Amazon products soliciting reviews in private Facebook groups, matched against weekly ratings, reviews, and sales data. Ratings rose briefly and fell back once the purchasing stopped.
Open sources: Source 1: vc.ru. :::
::: {.source-note} 92. NPR, 2022: Renée DiResta and Josh Goldstein discovered more than a thousand LinkedIn profiles with AI-generated faces, used to initiate first contact with prospective clients.
Open sources: npr.org — fake linkedin profiles; theregister.com — fake linkedin faces. :::
Glossary notes
::: {.source-note} 81. Synthetic reputation—the appearance of public approval or condemnation behind which there is no actual crowd of independent real people. See the Reader Glossary. :::
::: {.source-note} 82. Social proof amplifies with the number of voices only when those voices are independent: forty coordinated accounts remain a single signal source. See the Reader Glossary. :::
::: {.source-note} 84. What distinguishes astroturfing from an ordinary campaign is the concealment of a common organizer: coordination is presented as the independent initiative of many people. See the Reader Glossary. :::
::: {.source-note} 94. Increasing the number of signals within one rung does not move you to the next: a hundred claims are still claims. The next rung appears only with a new, preferably independent, foundation. See the Reader Glossary. :::
Chapter 5. The Distrust Tax
Quotes and epigraphs
::: {.source-note} 95. Francis Fukuyama, Trust: The Social Virtues and the Creation of Prosperity (1995): pervasive distrust imposes an economic tax that high-trust societies don't have to pay.
Open sources: Simon & Schuster — Trust; Source 2: iacajournal.org; Source 3: journals.library.wustl.edu. :::
Research, reports, and data
::: {.source-note} 99. Truecaller's April 2026 Phone Fraud & AI Threat Survey was an online survey of 1,614 U.S. adults conducted by Centiment from February 20 to March 17, 2026; 82% said they had ignored an important call or text in the previous year for fear of a scam. Truecaller's U.S. Spam Scorecard estimates 2.7 billion unwanted and spam calls a month from anonymized data for U.S. users, projected against U.S. Census data. Truecaller sells caller-identification software, so both figures are vendor-reported.
Open sources: Source 1: comnews.ru; Source 2: ng.ru. :::
::: {.source-note} 101. Both figures are self-reports from survey participants, not a review of work logs: they reflect participants' perceptions of their own behavior and errors, and do not by themselves establish causation.
Open sources: Source 1: kpmg.com; Source 2: assets.kpmg.com. :::
::: {.source-note} 103. Bank of Russia Instruction No. 181-I, clause 16.2.1: document review for a payment—by the next business day. T-Business (Russian corporate banking division): translation of a complex contract—up to five business days.
Open sources: Source 1: cbr.ru; Source 2: tbank.ru. :::
::: {.source-note} 104. BIS and Swift: on average, a payment passes through slightly more than one intermediary; the BIS long-route model has two to three. The Bank of England: less common currency pairs require more correspondents.
Open sources: Source 1: bis.org; Source 2: bis.org; Source 3: bankofengland.co.uk. :::
::: {.source-note} 105. FATF (2021): reviewing an alert with complete data—1–5 minutes; when additional information is requested—2–5 days. Bank of Russia: a correspondent may refuse or freeze funds.
Open sources: Source 1: fatf-gafi.org; Source 2: cbr.ru. :::
::: {.source-note} 110. LexisNexis Risk Solutions, 2023: global financial institutions' spending on financial-crime compliance—$206.1 billion per year; the study was commissioned by a compliance-solutions vendor.
Open sources: Source 1: risk.lexisnexis.com. :::
::: {.source-note} 111. Metrigy, Customer Experience Optimization 2025-26 — Consumer Views, a November 2025 survey of 503 adults in the United States and Canada: 84.9% preferred a human agent to an AI agent, and 80.1% still preferred a human when told their issue would be resolved either way.
Open sources: Source 1: markway.ru. :::
::: {.source-note} 114. World Values Survey (aggregated by Our World in Data): share agreeing that "most people can be trusted"—approximately 74% in Denmark and 72% in Norway, versus single digits in the lowest-scoring countries.
Open sources: Source 1: ourworldindata.org; Source 2: pewresearch.org. :::
::: {.source-note} 119. Edelman Trust Barometer 2026: online survey of approximately 34,000 people in 28 countries; seven out of ten on average—and nine out of ten in Japan—were unwilling or hesitant to trust people with different values or information sources.
Open sources: Edelman — Trust Barometer 2026; Source 2: prnewswire.com. :::
History and institutional context
::: {.source-note} 102. Michael Catanzaro, GNOME personal blog, July 20, 2026: he is stopping acceptance of new vulnerability reports and seeking a successor; the AI-generated report volume is cited as the reason for shortening the disclosure window and halting forwarding to projects that ban AI-generated content.
Open sources: Michael Catanzaro — Some changes to GNOME security tracking; LWN.net — Catanzaro: Some changes to GNOME security tracking. :::
Books and frameworks
::: {.source-note} 97. For Luhmann, trust is a mechanism for reducing complexity, not a moral endorsement of another person: it allows action without cycling through every possible risk and outcome. Source: Trust and Power, 1979.
Open sources: Internet Archive — Trust and Power; Source 2: downloads.bbc.co.uk. :::
::: {.source-note} 98. Stephen M.R. Covey Jr., The Speed of Trust (2006): the accounting language of the "distrust tax" and the "trust dividend"—low trust slows and increases the cost of everything.
Open sources: FranklinCovey — The Speed of Trust; Source 2: speedoftrust.com. :::
::: {.source-note} 106. Swift transmits messages but does not hold or move money. Settlement is performed by payment systems—Fedwire in the U.S., T2 in the eurozone, CIPS in China. The mechanics differ; the underlying logic is similar: instruction, settlement, verification.
Open sources: Source 1: swift.com; Federal Reserve Financial Services — Fedwire; Source 3: ecb.europa.eu; Source 4: cips.com.cn. :::
::: {.source-note} 115. Paul Zak and Stephen Knack, "Trust and Growth," The Economic Journal (2001): growth is on average roughly one percentage point higher per fifteen-point increase in trust; very low trust levels can produce a poverty trap.
Open sources: Oxford Academic — Trust and Growth; Source 2: neuroeconomicstudies.org. :::
::: {.source-note} 116. Yann Algan and Pierre Cahuc, American Economic Review (2010): a modeled estimate. Had Mexico inherited Sweden's level of inherited trust, GDP per capita in 2000 would have been roughly 59% higher. The paper models the same counterfactual for several countries.
Open sources: American Economic Association — Inherited Trust and Growth; Source 2: yann-algan.com. :::
Markets, companies, and products
::: {.source-note} 100. Gartner forecast (2025, as reported in HR publications): by 2028, one in four candidate profiles globally could be fake.
Open sources: Source 1: hrdive.com; Source 2: personneltoday.com. :::
::: {.source-note} 107. Swift: without a unified tracking system, tracing could take days or weeks; the tracker shows status, and Case Resolution helps banks work through stalled payments.
Open sources: Source 1: swift.com; Swift — Case Management. :::
::: {.source-note} 108. Raiffeisen: after two weeks, a paid tracing service is available, with no guaranteed resolution timeline; individual payments have been known to sit in queue for more than three months. CommBank: tracing costs AUD 25.
Open sources: Source 1: raiffeisen.ru; Source 2: commbank.com.au. :::
::: {.source-note} 109. Swift: a priority message moves ahead in the queue but does not necessarily speed up the response. OCBC China: an expedited internal status request costs more than a standard one.
Open sources: Source 1: swift.com; Source 2: ocbc.com.cn. :::
::: {.source-note} 112. banki.ru, December 2022: a customer review of a bank chatbot—to reach a live agent, the user had to type "agent" multiple times.
Open sources: Source 1: banki.ru. :::
Synthesis notes
::: {.source-note} 117. Francis Fukuyama in 1995 classified Japan as a high-trust society; the Edelman Trust Barometer 2026 placed it last among 28 countries (trust index 38; 90% unwilling to trust those who are "different from them").
Open sources: Source 1: gordonconwell.edu; Edelman — Trust Barometer 2026. :::
Glossary notes
::: {.source-note} 96. The distrust tax is paid primarily by honest participants—before any fraud occurs. It is the cost of prevention and false alarms, not the damage amount from fraud that has already happened. See the Reader Glossary. :::
::: {.source-note} 118. Trust radius—how far beyond one's own circle a person is willing to trust strangers and institutions. See the Reader Glossary. :::
Page notes
::: {.source-note} 113. Used here colloquially. More precisely, GDP per capita is the value of all final goods and services produced in a country in a year, divided by the total population—not average earnings. :::
Chapter 6. Verifiability Instead of Transparency
Quotes and epigraphs
::: {.source-note} 120. Carl Sagan, Cosmos TV series (1980), episode 12: what counts are claims that survive rigorous and skeptical scrutiny; the formula about extraordinary evidence Sagan popularized following Marcello Truzzi.
Open sources: Effectiviology — Sagan standard. :::
::: {.source-note} 126. Onora O'Neill, TEDxHousesOfParliament (2013): trust differs from having grounds to judge a party reliable; the chapter's formulation "transparency shows more—verifiability lets you decide" is the author's development of this idea.
Open sources: Source 1: ted.com. :::
History and institutional context
::: {.source-note} 121. Citizen's Charter—John Major's initiative (1991): public services were required to publish standards and outcomes, set annual targets, and undergo independent review; compliance was recognized with a Charter Mark.
Open sources: Source 1: en.wikipedia.org. :::
Books and frameworks
::: {.source-note} 122. Goodhart's Law: when a statistical regularity is used for control purposes, it collapses. The widely cited formulation by Marilyn Strathern (1997): when a measure becomes a target, it ceases to be a good measure.
Open sources: Source 1: en.wikipedia.org. :::
::: {.source-note} 123. Onora O'Neill, BBC Reith Lectures "A Question of Trust" (2002): instead of demanding more trust, we need assessable grounds for trust—competence, honesty, and reliability; accountability alone does not create them.
Open sources: Source 1: downloads.bbc.co.uk. :::
::: {.source-note} 124. Onora O'Neill, final Reith Lecture (2002): to restore trust, limiting deception matters more than demanding ever-greater transparency; what people need are assessable reasons to trust and to withhold trust.
Open sources: Source 1: downloads.bbc.co.uk. :::
::: {.source-note} 125. Oliver Schilke and Martin Reimann, "The Transparency Dilemma" (2025): across 13 experiments, disclosing AI use reduced trust in the discloser; varied disclosure framing did not eliminate the penalty.
Open sources: ScienceDirect — The Transparency Dilemma; Source 2: papers.ssrn.com. :::
::: {.source-note} 127. Diego Gambetta, "Can We Trust Trust?" (1988): trust is a subjective bet on another's action made before the outcome can be verified; it requires uncertainty and the risk of disappointment.
Open sources: Source 1: sieci.pjwstk.edu.pl; Source 2: philpapers.org. :::
::: {.source-note} 128. The term is taken from Rachel Botsman's Who Can You Trust? (2017) and TEDSummit talk (2016); extending the framework from platforms to AI agents is the author's application in this chapter.
Open sources: Source 1: ted.com; Source 2: futurespodcast.net. :::
::: {.source-note} 130. Roger Mayer, James Davis, and David Schoorman, "An Integrative Model of Organizational Trust" (1995): interpersonal trust is tied to another party's ability, benevolence, and integrity.
Open sources: Source 1: jstor.org; Source 2: people.wku.edu. :::
::: {.source-note} 131. The "lubricant" metaphor describes reduced transaction costs; it does not imply that trust replaces contracts and verification when the cost of error is high. Source: Kenneth J. Arrow, "Gifts and Exchanges," 1972.
Open sources: JSTOR — Gifts and Exchanges. :::
::: {.source-note} 132. George Akerlof, "The Market for 'Lemons'" (1970): when quality cannot be distinguished, information asymmetry drives out good offerings; the used-car market is his original example.
Open sources: JSTOR — The Market for Lemons. :::
::: {.source-note} 133. Oliver Williamson, The Economic Institutions of Capitalism (1985): guarantees, monitoring, and protection against opportunism enter into the cost of a transaction; he was skeptical of the vague word "trust."
Open sources: Google Books — The Economic Institutions of Capitalism; University of Chicago Press — Calculativeness, Trust, and Economic Organization. :::
::: {.source-note} 134. Steven Tadelis, "Reputation and Feedback Systems in Online Platform Markets" (2016): ratings and reviews equalize information between transaction parties and reduce verification costs, but scores are biased and require correction.
Open sources: Source 1: doi.org; Source 2: faculty.haas.berkeley.edu. :::
Glossary notes
::: {.source-note} 129. "Unknown" does not mean "false": it marks an absence of grounds. The verification boundary shows the limit of a conclusion—it does not pass a general verdict on the subject. See the Reader Glossary. :::
::: {.source-note} 135. Verifiable reliability—the ability to give others grounds to judge your competence, honesty, and reliability that are both sufficient and inexpensive to check. See the Reader Glossary. :::
Chapter 7. The Infrastructure of Trust
Quotes and epigraphs
::: {.source-note} 136. Alexander Griboyedov, Woe from Wit (1824), Act I, Scene 4: Famusov speaking to Molchalin, who has brought papers for signature. The Russian text was checked against the 1987 academic edition of the USSR Academy of Sciences.
Open sources: Source 1: imwerden.de; Source 2: ru.wikisource.org. :::
::: {.source-note} 137. Hany Farid, Dartmouth professor and one of the founders of digital forensics, in a New York Times profile dated June 14, 2026: “I feel like I'm going blind.”
Open sources: Source 1: nytimes.com; Source 2: faculty-directory.dartmouth.edu. :::
::: {.source-note} 140. This is an engineering criticism of deployment, not a rule of the C2PA standard. A signature can provide positive evidence of provenance. Its absence is an absence of evidence, not evidence of a fake.
Open sources: Sean Goedecke — C2PA only works if everything is signed. :::
Research, reports, and data
::: {.source-note} 138. C2PA is an open standard for a signed file-provenance manifest; Content Credentials is its reader-facing name. Its steering committee includes Adobe, the BBC, Microsoft, OpenAI, Sony, and others.
Open sources: C2PA — Technical Specification 2.4; Source 2: c2pa.org. :::
::: {.source-note} 141. The C2PA FAQ warns that a manifest can be removed by recompression, a screenshot, or metadata stripping. The standard makes interference visible when checked, but does not prevent removal of the entire signal.
Open sources: C2PA — FAQ. :::
::: {.source-note} 145. According to the FIDO Alliance report for World Passkey Day 2026, about five billion passkeys were in use worldwide; 75% of survey participants had enabled one for at least one account.
Open sources: FIDO Alliance — World Passkey Day 2026; FIDO Alliance — Passkeys FAQ. :::
::: {.source-note} 146. China's measures for labeling AI-generated synthetic content and the GB 45438-2025 standard took effect on September 1, 2025; they provide for explicit and implicit labels.
Open sources: China Law Translate — AI labeling measures; Source 2: loeb.com. :::
::: {.source-note} 147. Article 50 of the EU AI Act: obligations for machine-readable labeling of synthetic content and disclosure of deepfakes apply from August 2, 2026; Article 99 sets the penalties.
Open sources: Source 1: eur-lex.europa.eu; Source 2: digital-strategy.ec.europa.eu. :::
::: {.source-note} 148. Federal Law No. 243-FZ (Bill No. 1271570-8) was signed and officially published on July 26, 2026. It takes effect on March 1, 2027: users may label AI-created audio and video, and major platforms must provide the means to preserve and display that label.
Open sources: Source 1: publication.pravo.gov.ru; Source 2: sozd.duma.gov.ru; Source 3: interfax.ru. :::
::: {.source-note} 150. The measurement covers requests observed by one security provider's network. Bot traffic counts requests to pages, not published material; therefore 51% is neither the share of the whole internet nor the share of AI content.
Open sources: Imperva — 2025 Bad Bot Report. :::
History and institutional context
::: {.source-note} 143. The Japan Times (2020–2021): Taro Kono's reform reduced the number of administrative procedures requiring a hanko seal from 14,747 to 83.
Open sources: The Japan Times — Hanko stamping and paperwork; Library of Congress — Tradition vs. Efficiency. :::
Books and frameworks
::: {.source-note} 151. Adler, Hitzig, Jain et al., “Personhood Credentials” (preprint, 2024): a cryptographic credential can confirm a unique person without revealing that person's identity.
Open sources: arXiv — Personhood credentials; Source 2: technologyreview.com. :::
Markets, companies, and products
::: {.source-note} 139. Camera manufacturers and newsrooms are adopting C2PA. Since May 19, 2026, OpenAI has combined C2PA Content Credentials with Google's SynthID watermark in its images.
Open sources: OpenAI — Advancing content provenance; OpenAI Help Center — C2PA and SynthID in generated images. :::
::: {.source-note} 149. Federal Law No. 41-FZ (2025) introduced labels for calls from organizations. On January 27, 2026, labels disappeared from Sberbank, VTB, and Alfa-Bank calls because of a payment dispute. Alfa-Bank later began restoring the labels for some calls.
Open sources: Source 1: rbc.ru; Source 2: kommersant.ru. :::
Concepts used across the books
::: {.source-note} 152. Yancey Strickler, “The Dark Forest Theory of the Internet” (2019): live conversation is retreating from public platforms into private, unindexed, and nongamified spaces.
Open sources: Yancey Strickler — The Dark Forest Theory of the Internet. :::
Synthesis notes
::: {.source-note} 142. FotoForensics / Hacker Factor analyses from 2024–2025 show two limits: Content Credentials are still rarely checked, and a valid signature certifies provenance but not the truth of the content.
Open sources: Hacker Factor — C2PA and Authentication Updates; Hacker News — C2PA Investigations. :::
Glossary notes
::: {.source-note} 144. A passkey is a passwordless sign-in method using a cryptographic key pair unique to a service. It is resistant to phishing and may be synchronized across devices or bound to one device. See the Reader Glossary. :::
::: {.source-note} 153. Personal provenance is the habit of keeping originals, change history, sources of decisions, and a canonical channel for everything important. It strengthens the grounds for judging provenance but does not replace independent verification. See the Reader Glossary. :::
Chapter 8. When AI Agents Spend Money
Quotes and epigraphs
::: {.source-note} 154. Norbert Wiener, "Some Moral and Technical Consequences of Automation" (Science, 1960)—on the "mechanical agency" whose operation cannot be interrupted once set in motion.
Open sources: Source 1: science.org. :::
Research, reports, and data
::: {.source-note} 159. Amazon v. Perplexity (lawsuit filed 2025): in March 2026 the district court preliminarily barred Comet from accessing Amazon under the CFAA; the Ninth Circuit stayed the injunction pending appeal, then reversed it and remanded—ruling that, on the facts presented, Amazon was unlikely to prove it was Perplexity itself, rather than users employing the Assistant as a tool, that accessed its computers.
Open sources: Source 1: cnbc.com; Source 2: dockets.justia.com. :::
::: {.source-note} 160. Cloudflare, June 2026: automated requests to web pages in its network exceeded human requests for the first time; the company sells bot-protection services. Analysts estimate that roughly one percent of the work agents could theoretically do is actually transacting.
Open sources: Source 1: radar.cloudflare.com; Source 2: fortune.com. :::
::: {.source-note} 172. California AB 316 (signed October 13, 2025; in effect January 1, 2026): a defendant may not claim in court that "an autonomous AI caused the harm"; the law does not impose strict liability.
Open sources: California Legislative Information — AB 316. :::
::: {.source-note} 174. IMF analytical note "How Agentic AI Will Reshape Payments" (April 2026, S. Davidovich, E. Tourpe): payment systems are deterministic, AI agents are probabilistic—a foundational friction requiring Know Your Agent.
Open sources: IMF — How Agentic AI Will Reshape Payments. :::
::: {.source-note} 175. Sarah Breeden, Deputy Governor of the Bank of England, at the ECB Forum in Sintra (June 2026): agentic AI acts autonomously, regulatory frameworks are not ready for that, and a "human in the loop" for every agent action is unrealistic.
Open sources: Bank of England — Sarah Breeden at ECB Forum. :::
::: {.source-note} 176. 2025 surveys: Bain—24% of consumers are comfortable letting an AI agent complete a purchase; Contentsquare—30% would allow an agent to buy autonomously. The figure shifts noticeably depending on how the question is framed.
Open sources: Bain — consumer trust in AI agents; Contentsquare — AI shopping research. :::
::: {.source-note} 178. Session on the agentic economy at SPIEF 2026 (St. Petersburg International Economic Forum), as reported in business press: "trust comes to the foreground"—the business question has shifted to how to enter the circle of agents a customer trusts.
Open sources: Source 1: rbc.ru. :::
History and institutional context
::: {.source-note} 158. Moffatt v. Air Canada, 2024 BCCRT 149: the Civil Resolution Tribunal, an independent quasi-judicial body in British Columbia, rejected the company's attempt to treat the chatbot as a separate legal entity and awarded the passenger CAD 812.02.
Open sources: Source 1: americanbar.org. :::
Books and frameworks
::: {.source-note} 157. OWASP, LLM01:2025 Prompt Injection: a hidden instruction in a page or file can indirectly alter a model's behavior; the risk grows when the agent has access to both data and actions.
Open sources: OWASP — LLM01:2025 Prompt Injection. :::
::: {.source-note} 165. Agent Payments Protocol AP2 (Google, September 2025, 60+ partners): buyer consent is structured as three signed "mandates"—intent, cart, payment.
Open sources: Google Developers Blog — AI agent protocols. :::
Markets, companies, and products
::: {.source-note} 155. Incident at Chevrolet of Watsonville (December 2023): via prompt injection a chatbot "agreed" to sell a Chevy Tahoe for $1; no transaction was completed, and no lawsuit followed.
Open sources: Source 1: incidentdatabase.ai; Source 2: futurism.com. :::
::: {.source-note} 161. Cloudflare pay-per-crawl program and Web Bot Auth signature (2025): a site owner chooses for each AI crawler—"admit / charge a fee / block"—while the signature prevents a bot from impersonating a different bot.
Open sources: Cloudflare — Introducing Pay Per Crawl; Cloudflare — Web Bot Auth. :::
::: {.source-note} 162. Shopify (2025–2026) embeds agent instruction files (agents.md, llms.txt) in stores—a storefront addressed not to a person but to a program.
Open sources: Shopify — agents.md Liquid template; Shopify — changelog agent-facing files. :::
::: {.source-note} 166. Visa Intelligent Commerce (2025): an agent receives tokenized payment credentials rather than a card number, and the spending limits and conditions are set by the consumer.
Open sources: Visa — Visa Intelligent Commerce. :::
::: {.source-note} 167. Stripe (2026): single-use virtual cards for a specific agent purchase and pre-approved spending limits (Machine Payments Protocol)—a model its own engineers call "opening a tab at a bar."
Open sources: Stripe — Giving agents the ability to pay; Stripe — Machine Payments Protocol. :::
::: {.source-note} 169. Know Your Agent in practice: the Skyfire agent-passport protocol (2025) became the identity layer of Experian's Agent Trust framework (2026)—binding an agent to the human owner behind it.
Open sources: Skyfire — Know Your Agent; Experian — Agent Trust; Skyfire — identity layer for Experian. :::
::: {.source-note} 170. American Express, Agent Purchase Protection (April 2026): a network statement promising to protect cardholders when a registered agent makes an erroneous purchase with a confirmed purchase intent; public details remain limited—this is a vendor commitment.
Open sources: American Express — ACE Developer Kit. :::
::: {.source-note} 173. Protocol x402 (Coinbase and Cloudflare, 2025) activated HTTP status 402; in 2026 it was transferred to the Linux Foundation—roughly 40 organizations are members, including Visa, Mastercard, and Amex. Transaction figures are as reported by the project's developers.
Open sources: Linux Foundation — x402 Foundation launch. :::
::: {.source-note} 177. Forrester Consumer Pulse Survey, March 2025: 24% of U.S. online adults said they trust AI agents to act on their behalf for routine purchases. The figure measures stated trust, not how many people have actually delegated a purchase.
Open sources: Source 1: ir.yandex.ru; Source 2: developer.tbank.ru; Source 3: cbr.ru. :::
Glossary notes
::: {.source-note} 156. Prompt injection—a hidden command embedded in a website, email, or file. An agent may treat it as an instruction from the owner and assist an attacker: disclosing data or executing a transaction. See the Reader Glossary. :::
::: {.source-note} 163. Read access to data and authority to initiate a payment are granted separately: a service may see transaction history but not move money. See the Reader Glossary. :::
::: {.source-note} 164. Agent mandate—a signed record, created before any action, of exactly what the person has authorized the agent to do: the purchase type, the spending boundary, the time frame. See the Reader Glossary. :::
::: {.source-note} 168. Know Your Agent is not an assessment of a program's intelligence—it's an address for accountability: the service links the agent to its owner, its provider, and the permissions that were granted. See the Reader Glossary. :::
::: {.source-note} 171. A chargeback is not automatic insurance: the outcome depends on the grounds, the filing deadline, and the evidence. That is why an agent needs not only a limit but a reversible payment channel. See the Reader Glossary. :::
Chapter 9. Trust Inside the Company: Teams, Hiring, and AI Agents
Quotes and epigraphs
::: {.source-note} 179. Herbert Broom, A Selection of Legal Maxims (1874): whoever acts through another is considered to have acted himself. The Latin maxim and its rendering in the epigraph are in the author's translation.
Open sources: Broom — A Selection of Legal Maxims (Google Books); Cornell LII — respondeat superior. :::
Research, reports, and data
::: {.source-note} 183. Markswebb, "Chatbot: haters to lovers" (2025): 13 interviews with self-identified opponents of banking chatbots and a review of 41 scenarios. The sample is far too small to measure prevalence and is used here only for the reasons people give. This is qualitative research, not market-wide statistics.
Open sources: Markswebb — Chatbot: haters to lovers. :::
::: {.source-note} 184. EU Regulation 2024/1689 (AI Act), Art. 50(1): from August 2, 2026, a person must be notified that they are interacting with an AI system unless that is obvious from context. Rules differ across other jurisdictions.
Open sources: EUR-Lex — Regulation (EU) 2024/1689. :::
::: {.source-note} 187. U.S. Department of Justice (2025), United States v. Chapman: more than 300 companies, over $17 million in scheme revenue, and 68 stolen identities; "thousands of workers" is an FBI estimate.
Open sources: U.S. Department of Justice — Christina Chapman sentencing. :::
::: {.source-note} 188. Gartner, July 31, 2025: a second-quarter 2025 survey of 3,000 job candidates found that 6% admitted to interview fraud, either impersonating someone else or having another person pose as them. Gartner predicts that one in four candidate profiles worldwide will be fake by 2028. Greenhouse's 2025 AI in Hiring survey covered 4,136 respondents across four countries. Among U.S. hiring managers, 18% said they had caught applicants showing up as deepfakes.
Open sources: Source 1: hi-tech.mail.ru; Source 2: cnews.ru. :::
::: {.source-note} 196. No option had yet become Debian policy: proposals ranged from a ban on AI-generated text in human communication to disclosure requirements, full author accountability, and restrictions on cloud models for sensitive data.
Open sources: Debian — General Resolution: LLM usage in Debian. :::
History and institutional context
::: {.source-note} 180. Hacker News thread on Cursor (April 2025) and the company's responses: support bot "Sam" fabricated a one-device rule; a co-founder apologized, refunded the affected user, and announced that AI replies would be labeled going forward.
Open sources: Hacker News — Cursor IDE support hallucinates lockout policy. :::
::: {.source-note} 182. Moffatt v. Air Canada, 2024 BCCRT 149: the tribunal rejected the "separate legal entity" argument and awarded the passenger CA$812.02 for incorrect information provided by the chatbot.
Open sources: CanLII — Moffatt v. Air Canada, 2024 BCCRT 149; McCarthy Tétrault — case analysis; ABA Business Law Today — case analysis. :::
::: {.source-note} 185. "We Hired a Deepfake" (Habr, 2026)—a firsthand account from the hiring side: the candidate passed four rounds but barely spoke English. The company is unnamed; no independent verification is available.
Open sources: Source 1: habr.com. :::
::: {.source-note} 186. KnowBe4 (2024): an AI-enhanced stock photo, a laptop farm, and the workstation isolated in roughly 25 minutes; according to the company's account, no data was compromised.
Open sources: KnowBe4 — How a North Korean Fake IT Worker Tried to Infiltrate Us; KnowBe4 — hiring-process updates. :::
Books and frameworks
::: {.source-note} 190. Sundar and Kim, CHI 2019 (N=160): participants were more willing to share card details with a machine travel agent than a human one; the authors described this as the "machine heuristic."
Open sources: ACM Digital Library — Machine Heuristic. :::
::: {.source-note} 191. Dietvorst et al. (2015) documented abandonment of an algorithm after a single error; Logg et al. (2019) documented preference for algorithmic advice over human advice. Together they explain the trust swing.
Open sources: Journal of Experimental Psychology — Algorithm Aversion; OBHDP — Algorithm Appreciation. :::
::: {.source-note} 192. Klingbeil, Grützner, and Schreck (2024): merely knowing that advice came from an AI increased compliance with it, even against context and the person's own assessment.
Open sources: Computers in Human Behavior — Trust and Reliance on AI. :::
Markets, companies, and products
::: {.source-note} 189. SberBusiness Live, "The Fake Director" (2025): an analysis of the Fake Boss scheme and the case of a clinic administrator who transferred more than 107,000 rubles to scammers following a message from the "director" with a familiar profile photo.
Open sources: Source 1: sberbusiness.live. :::
Author cases
::: {.source-note} 195. Godot Engine, "Changes to our Contribution Policies," June 30, 2026. Policy: a ban on autonomous AI agents and vibe-coding, required disclosure of AI use, and a separate regime for new contributors.
Open sources: Godot Engine — Changes to our Contribution Policies. :::
Glossary notes
::: {.source-note} 181. The model has no human intention to deceive, but that does not relieve the company that presents its output to customers or employees of responsibility. See the Reader Glossary. :::
::: {.source-note} 193. Trust calibration—the alignment between how much we trust a tool or person and their actual reliability on a specific task; a gap in either direction is dangerous. See the Reader Glossary. :::
Page notes
::: {.source-note} 194. The second reviewer doesn't need to redo all the work: the scope of the check is set by the cost and reversibility of the error, the type of action, access to relevant data, and regulatory requirements. :::
Chapter 10. When a Fake Becomes Fact: Who Decides What to Believe
Quotes and epigraphs
::: {.source-note} 197. Hannah Arendt's essay “Truth and Politics” was first published in The New Yorker on February 25, 1967. Its context was the vulnerability of factual truth in public debate, not the problem of digital fakes.
Open sources: Source 1: idanlandau.com. :::
::: {.source-note} 220. Arendt argued that eyewitnesses are unreliable, documents can be suspected of forgery, and when a dispute arises, the only remaining recourse is to other witnesses.
Open sources: Source 1: idanlandau.com. :::
Research, reports, and data
::: {.source-note} 199. Bank of Russia Instruction No. 181-I, Section 16.2.1: documents relating to a payment transaction must be reviewed no later than the next business day.
Open sources: Source 1: cbr.ru. :::
::: {.source-note} 205. The CFPB warns that alternative data may conceal prohibited discrimination; lenders must test their models and provide specific reasons for denying credit.
Open sources: CFPB — Fair Lending Report 2023. :::
::: {.source-note} 211. Proposed Rule 707 concerns acknowledged AI-generated material. In May 2026, the committee postponed its effective date, revised the text, and continued studying deepfakes.
Open sources: U.S. Courts — Report of the Advisory Committee on Evidence Rules, May 2026. :::
::: {.source-note} 212. China's measures and GB 45438-2025 standard have been in effect since September 1, 2025. They require visible and machine-readable labels, including a platform label when synthetic content is suspected.
Open sources: China Law Translate — Labelling Measures for AI-Generated Synthetic Content; Source 2: loeb.com. :::
::: {.source-note} 213. A Chinese state source notes methods used to evade labeling: hiding watermarks, removing identifiers, and splitting videos into fragments.
Open sources: Source 1: english.scio.gov.cn. :::
::: {.source-note} 214. Federal Law No. 243-FZ (Bill No. 1271570-8) was signed and officially published on July 26, 2026. User labeling remains voluntary; major platforms must provide the technical means to preserve and display it from March 1, 2027.
Open sources: Source 1: publication.pravo.gov.ru; Source 2: sozd.duma.gov.ru; Source 3: pnp.ru. :::
::: {.source-note} 216. Aadhaar covers more than 1.3 billion identification numbers. In May 2026, UPI processed 23.2 billion transactions—an average of more than 700 million per day.
Open sources: Source 1: pib.gov.in; NPCI — UPI Product Statistics. :::
::: {.source-note} 219. This refers to three approaches: draft No. 718538-8 clarified several provisions of the Criminal Code as applied to deepfakes; No. 1133088-8 addressed unlawful processing of personal data; and No. 885494-8 proposed treating the use of AI as an aggravating circumstance.
Open sources: Source 1: garant.ru; Source 2: comnews.ru. :::
History and institutional context
::: {.source-note} 202. In the classic “five Cs of credit,” character comes first. Nineteenth-century credit agencies collected information about merchants' reputations and habits.
Open sources: Hagley Museum and Library — R.G. Dun & Co. credit report volumes; Source 2: time.com. :::
::: {.source-note} 207. State of Washington v. Puloka (2024): the court excluded AI-enhanced video because the method had not gained general acceptance among forensic video analysis experts.
Open sources: Source 1: americanbar.org; Source 2: gtlaw.com. :::
::: {.source-note} 210. Kohls v. Bonta: the court blocked most of AB 2839 as unconstitutional, made the injunction permanent in 2025, and the state appealed.
Open sources: CourtListener — docket Kohls v. Bonta; Columbia Global Freedom of Expression — Kohls v. Bonta. :::
::: {.source-note} 215. In November 2017, Estonia blocked the certificates of 760,000 vulnerable ID cards. The official review describes remote updates and backup channels.
Open sources: RIA Estonia — ROCA Vulnerability and eID: Lessons Learned; Source 2: ria.ee. :::
Books and frameworks
::: {.source-note} 201. Credit analysis compares a borrower with a comparable group: identical indicators mean different things depending on industry, size, region, and period.
Open sources: Moody’s Analytics — The Power of Credit Risk Benchmarking. :::
::: {.source-note} 203. Berg et al. (2020): simple digital-footprint indicators were comparable to credit bureau scores in predictive power and provided additional information.
Open sources: The Review of Financial Studies — Credit Scoring Using Digital Footprints; Source 2: nber.org. :::
::: {.source-note} 204. Björkegren and Grissen (2020): patterns of mobile phone use predicted loan repayment among people without traditional credit histories.
Open sources: The World Bank Economic Review — Mobile Phone Usage Predicts Credit Repayment. :::
::: {.source-note} 209. NIST SP 800-86 and ISO/IEC 27037 require the handling of digital evidence to be documented and file integrity to be confirmed with a checksum.
Open sources: NIST SP 800-86 — Guide to Integrating Forensic Techniques into Incident Response. :::
Markets, companies, and products
::: {.source-note} 206. BBC Verify launched in May 2023 and brought together more than 60 journalists working on fact-checking, data, and the verification of user-generated material.
Open sources: Source 1: committees.parliament.uk; Source 2: pressgazette.co.uk. :::
Synthesis notes
::: {.source-note} 217. Privacy International has compiled reports of Aadhaar leaks and vulnerabilities. A biometric identifier cannot be replaced as easily as a password.
Open sources: Privacy International — Aadhaar Security Failures. :::
::: {.source-note} 218. Edelman 2025 reported trust in AI at 72% in China and 32% in the United States. VCIOM 2024 found that 52% of Russians tended to trust AI. The methodologies differ.
Open sources: Edelman — 2025 Trust Barometer, technology sector; Source 2: wciom.ru. :::
Glossary notes
::: {.source-note} 208. A chain of custody confirms a file's integrity and handling after a documented point, but it does not prove that the scene itself is truthful or establish the identity of the person shown. See the Reader Glossary. :::
Page notes
::: {.source-note} 198. Here, “payment details” means information identifying the recipient and the destination of the payment, not necessarily the literal dictation of an account number, taxpayer identification number, and a complete set of banking details. :::
::: {.source-note} 200. Highly likely is a conversational phrase, not a legal standard. A bank selects a sufficient degree of confidence based on the cost of error. :::
Chapter 11. The Authenticity Premium: What Becomes More Valuable When the Copy Is Free
Quotes and epigraphs
::: {.source-note} 221. Alexander Pushkin, A Conversation Between a Bookseller and a Poet (1824): the lines about selling the manuscript are spoken by the bookseller, not the poet.
Open sources: Source 1: culture.ru. :::
::: {.source-note} 230. Adam Smith, lectures on jurisprudence (1762–1766): when transactions are repeated frequently, the appearance of fraud costs a dealer more than the one-time benefit.
Open sources: Liberty Fund — Lectures on Justice, Police, Revenue and Arms. :::
::: {.source-note} 233. George Akerlof, The Market for "Lemons" (1970, p. 495): the cost of dishonesty includes the loss caused by driving honest business out of the market.
Open sources: JSTOR — The Market for “Lemons”. :::
Research, reports, and data
::: {.source-note} 235. Cicek, Gursoy, and Lu (2024; more than 1,000 participants across eight categories): mentioning AI in a description reduced emotional trust and purchase intention, especially for high-risk purchases.
Open sources: Taylor & Francis — Adverse impacts of revealing AI; Source 2: news.wsu.edu. :::
::: {.source-note} 237. Lim and coauthors (2026; N=618): the "AI-made" label reduced perceptions of the effort invested, while "human-made" did not differ from having no label; willingness to pay was not measured.
Open sources: Frontiers — Human-made vs. AI-generated. :::
::: {.source-note} 241. Live Nation Entertainment, full-year 2025 results: revenue above $25 billion, up 9% year over year; concert revenue $20.9 billion, up 10%; a record 159 million attendees across roughly 55,000 shows. Part of the growth reflects higher average ticket prices rather than attendance alone.
Open sources: Source 1: okkam.group; Source 2: adpass.ru. :::
Books and frameworks
::: {.source-note} 223. Lynne Zucker (1986) distinguishes trust produced through repeated exchanges, shared group membership, and formal institutions; the growth of US markets required stronger institutional support.
Open sources: Berkeley Library — Production of Trust. :::
::: {.source-note} 224. Michael Spence (1973) and Amotz Zahavi (1975): a signal distinguishes participants when it is cheaper for a strong participant to send than for a weak participant or impostor.
Open sources: Oxford Academic — Job Market Signaling; DOI — Mate selection — a selection for a handicap. :::
::: {.source-note} 225. A review by Penn and Számadó (2020), along with modern models, shows that a signal's honesty is determined by the relationship between costs and benefits, not by high cost alone.
Open sources: Wiley — The evolution of costly signaling; Source 2: ncbi.nlm.nih.gov. :::
::: {.source-note} 227. Kirlappos, Sasse, and Harvey (2012): trust seals are easy to copy and, without automatic authenticity checks, do not perform a protective function.
Open sources: Springer — Why Trust Seals Don't Work. :::
::: {.source-note} 228. Zhang and coauthors (2016): an excessively favorable stream of reviews can reduce purchase intention through psychological reactance; this is a direction of effect, not a universal law.
Open sources: Source 1: sciencedirect.com. :::
::: {.source-note} 229. Steven Tadelis (2016): reputation systems reduce information asymmetry, but ratings are systematically biased upward and require deliberate system design.
Open sources: DOI — Reputation and Feedback Systems in Online Platform Markets. :::
::: {.source-note} 242. Pierre Bourdieu, The Forms of Capital (1986): capital accumulates through durable relationships; its unequal distribution can reproduce the existing hierarchy.
Open sources: The Forms of Capital — English text. :::
Markets, companies, and products
::: {.source-note} 238. Myer's Bagels in Vermont (May 2026): mixing real and generated images in an advertisement caused protests from regular customers; the owner removed the post and apologized.
Open sources: WCAX — South Burlington bagel shop faces backlash; PetaPixel — Bagel shop removes AI-generated ad images; Ad Age — local bagel shop backlash. :::
::: {.source-note} 240. Google's official documentation: trustworthiness is the most important element of E-E-A-T; creators are encouraged to explain who made the content, how it was made, and why.
Open sources: Google Search Central — helpful, reliable, people-first content; Google Search Central — E-E-A-T gets an extra E. :::
Glossary notes
::: {.source-note} 222. The distrust tax is the time, money, and delays people and organizations bear when they must confirm an identity, authority, or the provenance of a message. See the Reader Glossary. :::
::: {.source-note} 226. A costly signal is a sign of reliability that is difficult and unprofitable for an impostor to imitate; its value depends on costs, the benefit of deception, and the risk of exposure. See the Reader Glossary. :::
::: {.source-note} 234. Information asymmetry is a situation in which one party to a transaction knows substantially more about a product or service than the other and can take advantage of that difference. See the Reader Glossary. :::
::: {.source-note} 236. The cost of error is what you lose if you are wrong: money, health, reputation, or safety. In this book, it determines the appropriate depth of verification. See the Reader Glossary. :::
::: {.source-note} 239. E-E-A-T evaluates the grounds for trusting content but does not certify that a text was written by a human. First-hand experience and expertise are different signals: one does not replace the other. See the Reader Glossary. :::
Page notes
::: {.source-note} 231. The risk premium is the part of an interest rate that compensates a lender for uncertainty about a borrower: the less that can be learned in advance, the higher the additional charge. :::
::: {.source-note} 232. An interest rate includes the cost of money, term, expected losses, capital, expenses, collateral, and competition. Uncertainty about the borrower is one assessed component, expressed in banking practice through basis points. :::
Chapter 12. Authenticity Capital: How to Leave a Trail Others Can Verify Without You
Quotes and epigraphs
::: {.source-note} 243. Xenophon, Memorabilia, II.6.39: Socrates tells Critobulus that the surest way to seem good at something is to try to become genuinely good at it.
Open sources: Perseus — Xenophon, Memorabilia II.6.39. :::
Research, reports, and data
::: {.source-note} 245. Reuters Institute for the Study of Journalism, Digital News Report 2025: a survey of nearly 100,000 respondents across 48 markets. In the United States, 54% accessed news through social media and video networks, overtaking television at 50% and news websites or apps at 48% for the first time.
Open sources: Source 1: m.seonews.ru. :::
::: {.source-note} 246. Reuters Institute for the Study of Journalism, Digital News Report 2025: 58% of respondents across 48 markets said they worried about what was real and false online when it came to news. Overall trust in news remained at 40% for the third year in a row, four points below its pandemic peak.
Open sources: Source 1: jrnlst.ru. :::
::: {.source-note} 251. Edelman and LinkedIn, B2B Thought Leadership Impact Report 2024: 75% of surveyed executives began exploring a product or service they had not previously considered, and 60% were willing to pay a premium to the provider.
Open sources: Edelman–LinkedIn — 2024 B2B Thought Leadership Impact Report. :::
::: {.source-note} 256. Cloudflare, June 2026: automated requests to web pages exceeded human requests for the first time—about 57% versus 43%. The measurement covers the network of one company that sells protection against bots, and only requests to web pages.
Open sources: Source 1: radar.cloudflare.com; HUMAN Security — State of AI Traffic 2026. :::
::: {.source-note} 257. Oliver Schilke and Martin Reimann, 2025: across thirteen experiments, disclosure of AI use reduced trust; the mechanism was associated with lower perceived legitimacy.
Open sources: DOI — The transparency dilemma; SSRN — open manuscript. :::
::: {.source-note} 262. Peter H. Kim and coauthors, 2004: after a competence failure, an apology works better than denial; under a false suspicion of dishonesty, an evidence-based denial is more effective.
Open sources: DOI — Removing the Shadow of Suspicion. :::
History and institutional context
::: {.source-note} 255. Google launched the first transparency report in 2010, publishing data on government requests for user information and content removal.
Open sources: Google Transparency Center — Accountability. :::
Books and frameworks
::: {.source-note} 248. Austin Kleon, Show Your Work! (2014), and Shawn Wang, Learn in Public: show the process and leave a public by-product of your own learning.
Open sources: Austin Kleon — Show Your Work!; swyx — Learn in Public. :::
::: {.source-note} 254. GitLab maintains a public handbook as the single source of rules for its fully distributed company: if a process is not recorded in the handbook, it does not exist.
Open sources: GitLab Handbook — Handbook-first documentation. :::
Markets, companies, and products
::: {.source-note} 247. LinkedIn defines an engagement pod as a coordinated group whose members react to one another's content to inflate visibility artificially, and says it restricts this activity.
Open sources: LinkedIn — Authentic Content and Conversations. :::
Author cases
::: {.source-note} 244. Zed Industries, Hired Through GitHub: Part 1 (September 16, 2025): Junqu Zhang and Anthony Idd were hired after contributing to open-source software over an extended period; Idd described his only interview as a conversation about work he had already demonstrated.
Open sources: Zed — Hired Through GitHub, part 1. :::
::: {.source-note} 249. After leaving Airbnb in 2019, Lenny Rachitsky began writing regularly and later introduced a paid subscription; his newsletter grew to more than one million subscribers.
Open sources: Substack — How Lenny Rachitsky earned $65,000 in his first year of writing; Source 2: lennyrachitsky.com. :::
::: {.source-note} 250. Ben Thompson launched Stratechery in 2013 as a side project and made it his primary work in 2014, building a subscription publication around regular analysis.
Open sources: Stratechery — About. :::
::: {.source-note} 252. The absolute figures are preserved here to avoid repeating the mistake of calling the change “229% growth”: 2,886 is about 229% of the previous level, but the increase itself is about 129%.
Open sources: Buffer — Introducing Open Salaries; Buffer — 10 years of building Buffer. :::
::: {.source-note} 258. GitLab, postmortem of the January 31, 2017 incident: about 300 GB of data was deleted, 6 hours and 40 minutes of changes were lost, and the recovery was livestreamed to a peak audience of about 5,000 viewers.
Open sources: GitLab — Postmortem of database outage of January 31. :::
::: {.source-note} 260. Cloudflare, postmortem of the November 18, 2025 outage: the CEO provided a detailed explanation of the technical cause that same day and issued a public apology.
Open sources: Cloudflare — November 18, 2025 outage. :::
Glossary notes
::: {.source-note} 261. A public incident postmortem is an open report on an organization's own failure: what happened, why it happened, what was lost, and what changed to prevent a recurrence. See the Reader Glossary. :::
Page notes
::: {.source-note} 253. GitLab builds a platform for collaborative software development. The company is fully distributed: employees work from different countries, and a significant share of its internal rules is open to the entire internet. :::
::: {.source-note} 259. Cloudflare is an infrastructure company whose network stands between websites and their visitors: it accelerates loading, blocks attacks, and helps services remain available. :::
Chapter 13. The Trust Compass: When to Verify and What to Show
Quotes and epigraphs
::: {.source-note} 263. Antoine de Saint-Exupéry, The Little Prince, 1943, Chapter XXI, Russian translation by Nora Gal. These are the Fox's parting words, which he calls his secret.
Open sources: Library of Congress — Le Petit Prince. :::
Research, reports, and data
::: {.source-note} 264. Public reports of the announcement do not name a specific division of the ministry, so the book uses the general designation Russia's Ministry of Internal Affairs. The same guidance advises children not to disclose personal information, banking details, or codes from text messages.
Open sources: Source 1: rbc.ru. :::
Books and frameworks
::: {.source-note} 265. Jonathan Haidt, The Anxious Generation, 2024. The book is about childhood and smartphones; only its underlying logic is used here: the way out of a collective-action trap is collective action.
Open sources: The Anxious Generation Movement — Four Norms; Jonathan Haidt — The Anxious Generation. :::
Epilogue. The Handshake
Quotes and epigraphs
::: {.source-note} 266. Confucius, The Analects, Book II, “Wei Zheng,” passage 22, in James Legge's public-domain English translation. The word rendered here as “truthfulness” means fidelity to one's word—something others can rely on.
Open sources: Source 1: ctext.org; Source 2: iphlib.ru. :::