← The Engine Log

When Anyone Can Sound Credible, Only Stakes Are Evidence

The slop panic has the diagnosis backwards. The numbers say the flood of machine-written articles stopped growing a while ago and largely does not reach readers through search anyway. What actually broke is not the supply of good work — it is the instrument readers used to spot it. For centuries, apparent effort was a costly signal: polish was expensive, so polish was evidence. Generation cost went to zero and took the signal with it. What survives is not what looks expensive to make, but what would be expensive to be wrong about. The new marking regime — Article 50 live since 2 August, Anthropic announcing watermarks for Claude's text days later — cannot restore the old signal, because by Anthropic's own admission a mark confirms involvement, not authorship. It records what touched a document. It never records who is answerable for it.

Linara Bozieva22 min read
Watercolor illustration: an endless tide of immaculate, identical, unsigned pages washes past in the dark, every one of them flawless and anonymous. The Ravenopus holds up the single page that is visibly different — marked up, corrected in the margin, and signed at the bottom in a human hand. The scarce thing in the flood is not the polish, which is everywhere and free. It is the signature, and the crossing-out that proves someone was willing to be caught being wrong.

"Slop" was named word of the year for 2025 — by Merriam-Webster, by the American Dialect Society, by The Economist, and by Australia's Macquarie Dictionary, which is the kind of consensus you usually only get about a war. Merriam-Webster's definition is clinical enough to sting: digital content of low quality produced, usually in quantity, by means of artificial intelligence. Two dictionaries, a scholarly society and a newspaper looked at the year and concluded the story was that the internet had filled up with garbage.

I want to argue that the diagnosis is wrong, and that getting it right matters a great deal if you sell anything to anyone who reads.

What the numbers actually say

Start with the flood itself, because the panic rests on a shape rather than a number, and the shape is not what people think.

The most-cited measurement is Graphite's, which sampled 43,000 English-language articles from CommonCrawl published between January 2020 and May 2025 and ran them through a detector, classifying an article as machine-written when more than half of it registered as such. Two findings get quoted. The first is the crossover: around November 2024, machine-written articles overtook human-written ones in volume. That one travelled everywhere, and it is real.

The second finding travelled almost nowhere, and it is the one that matters. The proportion did not keep climbing. It went roughly flat and stayed there — the explosive phase was over by about the middle of 2024. A 2026 update to the research, using three detectors instead of one, put the share about three points lower still. And the research makes a third observation that sits oddly next to the panic it fuelled: those articles largely do not appear in Google and ChatGPT. The filters mostly are not surfacing them.

So the honest version of the empirical picture is: yes, more than half of newly published articles are machine-written; no, that share is not running away; and mostly it is not reaching readers through the routes readers actually use. Detector-based measurement also carries real error — Graphite's own false-positive rate was 4.2%, which is small but not nothing when the headline is a coin-flip percentage.

None of that means nothing happened. It means the thing that happened was not the thing everyone named.

The instrument broke, not the supply

Here is what I think actually happened, and it has almost nothing to do with volume.

For most of human history, the cost of producing something that looked credible was high. Setting type was expensive. A designed page meant someone paid a designer. A hundred-page report meant months of somebody's salary. A polished thirty-second film meant a crew. None of that guaranteed the content was true — plenty of expensively-produced material was wrong or dishonest — but the expense guaranteed something narrower and enormously useful: that somebody had a reason to spend. Effort implied intent, intent implied stakes, and a reader could use apparent effort as a fast, cheap first filter on what deserved a second look.

That filter is what broke. Not the supply of good work, which is fine and arguably better than ever. The reader's instrument.

The collapse in generation cost that made execution effectively free did not only reprice what suppliers sell. It repriced what readers can infer. Polish, fluency, structure, confident specificity, a clean design, a plausible citation, a competent hundred-page report — every one of those used to cost something and therefore meant something, and now every one of them is available instantly to anyone with a browser and no particular intentions. The signal did not get noisier. It went to zero.

And this is why the flood does not have to reach you to have already done its damage. Even if the filters catch every generated article before it reaches your screen, you have still lost the ability to look at a page and infer anything from how much work it looks like. That inference is gone whether or not you ever meet a single piece of slop.

Why a costless signal is not a signal

The economics here are old and I am not claiming them as new. A signal only carries information if sending it falsely is expensive. That is the whole mechanism — a peacock's tail, a degree, a warranty, a firm that spends heavily on a brand it would lose by cheating. The cost is not a side effect of the signal. The cost is the signal. Strip the cost out and the gesture remains, meaning nothing.

What is worth pointing at is the specific shape of this particular failure, because it is not the one I described in the last issue. In how to buy marketing in the agent era I argued that headcount, as a proxy for capability, did something worse than stop working: it inverted, and started recommending the supplier carrying the most obsolete cost structure. The proxy changed sign.

Apparent effort does something different. It does not invert — a beautifully made page is not now evidence of a worse source. It goes silent. It carries no information in either direction, which is a stranger and more disorienting condition than being misled, because the instrument still feels like it is working. Reading a polished page still produces the small internal click of someone bothered. The click is now a hallucination. That is why smart, careful people are getting fooled at a rate that embarrasses them: the feeling of discernment survived the death of the thing it was discerning.

You cannot restore a signal by asserting it

The dominant institutional response is labelling, and it is worth being fair to it because the serious version is better than critics admit — and because it has just stopped being hypothetical.

On 2 August 2026, the EU AI Act's transparency obligations under Article 50 became applicable. Providers of systems generating synthetic text, audio, image or video must mark their outputs in a machine-readable format, detectable as artificially generated. Unlike other parts of the Act, that deadline was not deferred, and market surveillance authorities can enforce from that date; systems already on the market before it have until 2 December to comply with the marking requirement. Nine days later, Anthropic announced that it will watermark text produced by its Claude models — a mark woven into the text itself, one that survives copy-paste and, the company says, some editing, with C2PA used for files. Models released after that deadline carry it automatically, and the company says it will extend support to older ones. The covered surfaces include the API, the consumer app, and Claude Code.

That is not theatre. It is the most serious attempt yet to rebuild the signal that collapsed, and it is backed by law with real enforcement behind it.

It still answers the wrong question, and this time I do not have to argue that from first principles, because the vendor says so.

Anthropic's own compliance documentation states that a detected mark does not confirm authorship. It signals that Claude was involved — and, in their words, Claude may not be the original author, because people routinely use these systems to edit, translate, proofread, and reformat work whose ideas and sentences are entirely their own. The mark travels with text the human wrote. It is also destroyed by paraphrase, since substantial rewriting breaks the statistical distribution it lives in, which means its absence proves nothing either. A probabilistic, authorship-agnostic signal is about to be treated by schools, employers, and platforms as proof of something it explicitly does not establish.

So the most advanced provenance system yet deployed tells a reader that a machine touched an artifact. It does not tell them whether anyone thought about it, whether the claims were checked, or who is answerable if they are wrong. Provenance answers what tool made this. A reader's actual question is who pays if this is wrong. Those two come apart the moment you look at them, and the new infrastructure makes the gap wider rather than narrower — a piece drafted by a machine, then checked, corrected, argued with, and signed by a named operator who will hear about it if it is false, now carries a mark reading machine-involved, while an unsigned, unchecked human-typed post carries none. The label will say the accountable document is the synthetic one. No provenance standard records the difference, because it is not a fact about production. It is a fact about who is standing behind the thing.

Which is also why "human-made" is not the reassurance it is being sold as. It was never true that human authorship implied quality or honesty, and building the new trust infrastructure on that premise imports an error we already know about. The useful question was never what made this. It was always who is answerable for it — and that question only got sharper when production stopped being evidence of anything.

The Stake Premium

So here is what I think survives, and it is the only thing I can find that does.

The Stake Premium is the value that accrues to a claim because its author is exposed to being wrong about it. When sounding credible is free and infinite, the appearance of credibility carries no information. What still carries information is exposure — a findable name, a claim specific enough to be checkable, and a real cost the author pays if it turns out to be false.

Notice that this is not a claim about correctness, and I want to be exact about that because the flattering misreading is right there. Stake does not make anyone right. A named, exposed, accountable operator can be confidently and repeatedly wrong, and some are. What stake does is put a price on being wrong, and a price is what makes correction happen — the anonymous account has no reason to revisit anything it said, because nothing accrues to it either way. Stake is not a guarantee of accuracy. It is the mechanism by which inaccuracy gets fixed instead of accumulating.

The Stake Premium is the sibling of the argument I made about taste, and the pairing is deliberate. When execution went free, value relocated to the judgment that selects the output. When assertion went free, credibility relocated to the exposure behind the claim. Same move, opposite side of the transaction: one is what the supplier is really selling, the other is what the reader is really buying. Both are the residue left when the thing that used to be scarce stopped being scarce.

The test this gives a reader

The practical form of it is a single question, replacing the one everybody is currently asking. Not did a human make this, which is hard to verify and, as argued, beside the point. Instead: what does the author lose if this is false?

That resolves into things you can check quickly. Is there a specific person's name on it, or only a brand — not because a brand risks nothing, but because a brand's risk is fat-tailed and attaches to conduct rather than to accuracy, so a merely wrong page costs it close to nothing, whereas a name concentrates the whole cost of this particular claim on someone you can find. Does it make claims precise enough to be wrong, or has it been written in the safe register that cannot fail because it never commits? Is there a record that persists and accumulates, so that being wrong today costs something tomorrow? And — the strongest tell — can you find a place where the author corrected themselves?

That last one is worth dwelling on, because it inverts the instinct. A visible correction reads like a weakness and is actually the most expensive signal on the list. It is nearly free to verify and genuinely costly to fake, since faking it means manufacturing an error you then publicly own. An archive with no corrections in it is either very short, or not a record of anyone thinking.

If you are a brand, you are the name

Everything above is written from the reader's chair. Turn it around, because most of what a reader encounters is published by a company rather than a person, and that is where this gets uncomfortable.

When you read something on a company's site, the company is the name on it. Whoever actually wrote it — an employee, a contractor, an agency, a model, some combination nobody discloses — is invisible to you, and reasonably so: you were never going to audit the supply chain, and it is not what you are judging. You are judging the brand, because the brand is what is standing there. So the brand is the stake-holder, and the question the rest of this piece has been building toward applies to it directly: what does this company lose if this is false?

The answer is usually "less than you would think," and not because companies are shameless.

It is the diversification again. A company's reputation is a portfolio assembled from a great many impressions, most of which have nothing to do with this page — the product, the price, the support call, fifteen other articles. One wrong claim lands against all of that, so the marginal damage is small, and the company knows it is small. That is not cynicism; it is arithmetic, and it is why a brand can publish something thin without anyone internally feeling a thing. A person publishing under their own name is undiversified: the same wrong claim is a meaningful fraction of everything they have. Total exposure is far larger for the company. Exposure per claim is far larger for the person. And since a signal informs in proportion to what it costs to send falsely, the marginal figure is the one carrying information — which means the confident, polished, corporate register that used to read as substantial now reads as exactly what it is: cheap to produce and nearly costless to be wrong in.

That last sentence understates something, and it is worth being exact rather than tidy. Brand risk is not uniformly small. It is fat-tailed. Most of what a company publishes costs it nothing whatsoever, and a rare few things are ruinous — companies have been gutted by one sentence from a chief executive, and reputations built over decades have gone inside a week. So "small per claim" is an average, and averages are a poor description of a distribution with a cliff in it.

But look at what actually occupies that tail, because it decides how much the objection bites. The catastrophic cases are conduct: a safety failure, a fraud, contempt for customers said out loud, a moral position that curdles. They are almost never this claim turned out to be inaccurate. Companies do not die from publishing a mediocre article, or a wrong statistic in one. The tail is real, it is genuinely terrifying to the people managing it — and it does not attach to the class of thing you are holding when you ask whether to believe a page.

The tail also explains the register, which is the part I did not expect when I started pulling on this. A company facing rare, enormous downside manages that exposure with process: review, approval, legal sign-off, the removal of anything that could later be quoted against it. That process is entirely rational. It is also precisely what produces writing that commits to nothing, because the surest way never to say the ruinous thing is never to say the thing. So the fat tail does not refute the weightlessness of brand content. It manufactures it.

Then the part that does the real damage, which is that inside almost every brand the person who made the claim is not the person who carries it. Someone wrote that sentence. You do not know who, they are not named, and if it is wrong, the cost lands on a marketing budget in a quarterly review rather than on them. Authorship and consequence sit in different places, and the artifact does not record the gap. This is a milder cousin of the dissolution I described in the queue: distribution does not erase consequence, it spreads it thin and far from the decision until it stops working as a signal. A different failure from not existing, and the difference is the whole thing.

So the practical problem for a company is not that it lacks stake. It is that its stake is real, large, diversified, delayed, and completely illegible to the person reading the page right now — and right now is the only moment that reader has. None of which is fixed by producing more, faster, or more polished, since every one of those was the thing that stopped meaning anything.

What does move it is concentration: a named human who actually owns the claim and is reachable about it, specifics precise enough to be wrong, and a visible record of having corrected something. Those are the same things the reader's test looks for, which is not a coincidence — the test is just the reader's side of the same mechanism. It happens that this is easier for an operation where one accountable person is close to the output than for one where the work passes through many hands, which is an argument about supplier structure that I have a commercial interest in and will not make here. It is a whole piece of its own, and it is the next one.

The uncomfortable position I am arguing from

I should say plainly where I stand in this, because the objection is obvious and I would rather make it myself.

I run an agent-staffed function. This piece was produced with agents — researched, drafted, argued with, and revised through a system I built, at a volume no unaided person would attempt. By any reasonable accounting I am a contributor to the abundance I have spent this issue describing. I am not standing outside the flood diagnosing it. I am one of the taps.

Which makes this document a live test of the argument, and I may as well run it here.

This piece was produced through Claude Code, one of the surfaces named in the watermarking announcement above. So depending on which model version handled which pass, the text you are reading may already carry an invisible machine-readable mark identifying it as AI-involved — and if it does not yet, a later one will. Under the new regime, that mark is the official signal about this artifact. Now notice what it tells you. It tells you a machine was involved. It does not tell you that five statistics were pulled because they did not survive a primary source, that the coined term was changed because the obvious one was already in circulation, or that the argument was rebuilt after checking what the flood data actually said. Every one of those was a judgment someone made and is answerable for, and not one of them is in the mark.

That is exactly why the argument lands where it does. I cannot claim this is trustworthy because a human typed it, because a human largely did not. The only claim available to me is the one I am making: my name is on it, the sources are named and checkable, several numbers that appear in every other article on this subject are absent from this one because they did not survive being checked, and if any of it is wrong, I am the one who hears about it. That is the entire warranty. It is also, I think, the only warranty that is going to mean anything soon — which is why I would rather build on it now than on a claim about authorship that was never load-bearing, and that the machinery being built to certify it does not actually make.

Two of the figures I cut are instructive, since the cutting is the receipt. A widely repeated version of the Graphite study cites 65,000 URLs; the study says 43,000. A statistic about what share of AI-assistant citations go to human-written pages appears in a great deal of secondary coverage; it is not in the primary source I could verify, so it is not here. Both would have strengthened the piece rhetorically. Neither survived, and the difference between an operation that checks and one that does not is invisible in the finished prose — which is the problem this whole issue is about.

Where this reaches its limit

The honest boundaries, because the triumphant version of this argument is the one that ages worst.

The first and largest is that this argument advantages the already-established, and I do not have a good answer to it. Stake is a lagging asset. It accumulates, which means someone with a long public record has a great deal of it and someone starting on Monday has none, regardless of the quality of their work. A rule that filters out slop also filters out the newcomer who is merely new. The route through is the one the argument implies — commit to claims specific enough to be wrong, under one name, and let the record build — but that route costs time the incumbent has already spent, and any version of this piece that pretends otherwise is selling something.

The second is that stake is gameable at the low end. A name is cheap to invent, a persona is cheap to maintain, and manufactured credibility is a functioning industry. What is expensive is stake that has been tested — a record long enough to contain a mistake someone actually paid for. The test does not work on a six-month-old profile, and I would not want anyone applying it as though it did.

The third is that reputational stake is unevenly distributed in ways that have nothing to do with reliability. Being publicly named is not equally safe for everyone, and there are people whose best work is pseudonymous for reasons that are entirely legitimate. An argument that treats anonymity as presumptively untrustworthy would be wrong about the world and unpleasant besides. The narrower claim I am prepared to defend is that the reader loses a filter when a source is anonymous, not that the anonymous source is worse.

The fourth is the counter-reading of my own evidence, and it is a real one. If the flood plateaued and the filters mostly suppress it, perhaps the system is already correcting and this whole argument is early. That may be right. What I would say against it is that the filters doing the suppressing are themselves machines, and outsourcing the judgment to them relocates the problem rather than solving it — you have not restored your instrument, you have delegated it to Google and to a handful of assistants whose criteria you cannot inspect and who have their own reasons to recommend one source over another. Being filtered for is not the same as being able to tell.

For a long time we could read effort off a page, and we used that reading for everything — who to believe, who to hire, what to finish reading. That reading is gone and it is not coming back, and no label is going to restore it, because the thing that made it work was a cost that no longer exists. What is left is smaller and harder and much more honest: find out what the author has to lose, and weigh the claim accordingly. It was always the better question. It is now the only one left.


In one paragraph, and a few common questions

In one paragraph: "Slop" was named word of the year for 2025 by four separate authorities, but the panic underneath it is misdiagnosed. The best measurement of the flood — Graphite's detector-based sample of 43,000 articles — found machine-written work overtook human-written work in volume around November 2024, then went roughly flat rather than climbing, and largely does not surface in Google or ChatGPT anyway. What broke is not the supply of good work but the reader's instrument for spotting it: for centuries, producing something polished was expensive, so polish implied someone had a reason to spend, and readers used apparent effort as a cheap first filter. Generation cost fell to zero and took the filter with it — and unlike the headcount proxy, which inverted, this one went silent, carrying no information in either direction while still feeling informative. The new marking regime cannot repair it — Article 50 of the EU AI Act applied from 2 August 2026 and Anthropic announced watermarking for Claude's text days later, but Anthropic's own documentation concedes a mark confirms involvement rather than authorship, and paraphrase destroys it — because provenance answers what tool made the artifact when the reader's real question is who pays if it is wrong. What survives is the Stake Premium: the value a claim carries because its author is exposed to being wrong about it — a findable name, a claim precise enough to be wrong, a record that accumulates, and, the strongest tell because it is cheap to verify and expensive to fake, a visible instance of the author correcting themselves. Stake does not make anyone correct; it puts a price on being wrong, which is what makes correction happen at all. It attaches to whoever is named — and since most published content is named by a company rather than a person, that is where it bites: a brand's reputation is a diversified portfolio, so its cost per claim is small and it knows it — brand risk is genuinely fat-tailed and a single act can be ruinous, but that tail is occupied by conduct rather than by inaccuracy, and managing it with approval process is itself what makes brand content commit to nothing; whoever actually wrote the sentence is unnamed and does not carry it; and none of that exposure is legible to a reader at the moment of reading, which is the only moment they get. Brand stake is not smaller. It is illegible, and illegible stake cannot function as a signal. The limits are serious: this advantages incumbents, it is gameable on young accounts, it must not become a rule that anonymity is untrustworthy, and if the filters are already working the argument may be early.

Isn't the internet drowning in AI slop? Less straightforwardly than the discourse suggests. Machine-written articles passed human-written ones in volume around November 2024, then plateaued rather than continuing to climb, and the same research notes they largely do not reach readers through Google and ChatGPT. The volume is real; the runaway curve is not, and the panic is running on the curve.

So if the flood plateaued, is there no problem? There is, but it is not a supply problem. The reader's instrument broke. Polish used to be expensive and therefore implied intent; production cost fell to zero and polish stopped implying anything. The flood does not have to reach you to have already cost you your cheapest filter.

Doesn't mandatory AI watermarking fix this? It is now law — Article 50 applied from 2 August 2026, and Anthropic announced Claude text watermarking days later — and it is a serious mechanism. But Anthropic's own documentation says a mark does not confirm authorship, only involvement, and that Claude may not be the original author; paraphrase destroys the mark, so absence proves nothing either. It records what touched the artifact, never who is answerable for it.

What is the Stake Premium? The value a claim carries because its author is exposed to being wrong about it. When sounding credible is free, the appearance of credibility carries no information; exposure does. It is not a measure of correctness — a staked author can be badly wrong — but of whether being wrong has a price.

How do I apply this? Replace did a human make this with what does the author lose if this is false. Look for a person's name rather than only a brand — not because a brand risks nothing, but because its risk is fat-tailed, attaches to conduct rather than accuracy, and lands where you cannot see it — plus claims precise enough to be wrong, a record that persists, and, the strongest tell, a visible correction, which is cheap to verify and expensive to fake.

Doesn't this protect the already-established? Substantially, yes, and that is its honest cost. Stake is a lagging asset, so the rule that filters slop also filters newcomers who are merely new. The route through is to make checkable claims under one name and let the record accumulate, but that takes time an incumbent has already spent.

Linara Bozieva, Founder, Ravenopus

The Engine Log

More like this in your inbox.

Operational artifacts, real protocols, real numbers. Sent when something is worth sending.

If the queue diagnosis applies to your current setup and you want to see what an agency without queues actually delivers, the 72-Hour Diagnostic is the smallest commitment we offer.

See the 72-Hour Diagnostic →