Monday, August 24, 2026

An AI job boom? Here’s what the tedious, temporary work in data labelling is actually like

Fan Yang, The University of Melbourne

The article examines how human workers prepare data for AI systems and describes their working conditions, pay, and employment arrangements.
Image: Elise Racine, CC BY

Amid all the talk about artificial intelligence (AI) both creating and destroying jobs, a troubling reality flies under the radar.

The tasks machines can’t perform well are often offloaded onto marginalised global workers who are struggling in precarious labour markets. They do ostensibly “automated” work under exploitative conditions.

Data work is an essential part of building and refining AI systems. Before AI models can “learn” anything, human data workers must categorise, label, test and moderate vast volumes of text, images, audio and video, to make the data usable for AI training.

This labour is performed by an expanding global digital workforce that prepares the datasets not only for big tech, but also high-stakes industries such as banking, insurance, healthcare and government agencies, including defence.

To understand the AI workforce, I have been interviewing workers in China and Australia who prepare datasets for AI models. The fieldwork is ongoing, but here’s what they’ve revealed so far.

Inequality is baked in

My interviews with ten people to date show that precarious labour markets and marginalised social status have pushed digitally literate young workers into the data labelling industry.

As one interviewee said:

"We do the manual work so that they get the credit for the intelligence."

There’s a lot of inequality across the data labour market, shaped by people’s qualifications and geographic location.

Those with PhD-level or equivalent qualifications and STEM certifications can typically get more specialised tasks. If based in the Global North, such workers tend to be higher-paid, earning A$400–800 per hour depending on the task.

But such specialised and high-paid tasks are rare and difficult to get. Most workers I interviewed perform general tasks, such as repetitively drawing bounding boxes for images used in drones, self-driving cars and automated vending machines, or annotating audio.

These workers normally receive as little as A$6 per day or even less. The pay can’t cover daily expenses, and the long hours leave workers with chronic eye strain and back pain.

Part of the gig economy

Data work is not unlike other poorly regulated jobs in the gig economy.

Workers have no formal contracts and are not employees. They’re classified as “users”, and platforms simply call on them when there are tasks aligning with their expertise and track record.

User agreements exist primarily to protect the companies behind the outsourced work, such as requiring the workers don’t disclose any of the information they see.

This is despite the fact datasets are already anonymised: workers often have no way of knowing which companies they conduct data labelling for. They don’t even know if humans or AI agents assess their completed work. And they have minimal rights to appeal any assessment of their performance.

All interviewees reported getting less work over time as AI advances. What’s left are more difficult and time-consuming tasks. Interviewees expressed little concern about their jobs eventually being replaced by AI, but this apparent indifference stemmed from a pessimistic outlook:

"If I don’t make this money, someone else will, and I will be replaced [by AI] eventually anyway."

As one worker noted, what AI actually affects is the working class itself. This working class is expanding as more professionals are pushed into data labelling by the precarity of the current job market.

All work, little pay

How a worker gets paid is determined by the platform. US crowdsourcing platforms generally offer higher-paid tasks and pay workers when they submit the work.

Chinese platforms or companies often pay workers only after their tasks have been assessed and confirmed to meet preset standards. As a result, workers often spend hours completing tasks without receiving any payment.

In addition, workers in China can’t access US platforms; using a VPN to circumvent this risks triggering an account ban.

Companies prefer consistency in their workforce, as turnover is costly; workers require instruction and training before they can begin a task, and further time before they can complete tasks efficiently.

As workers typically get faster the longer they stay in the role, companies want to retain the experienced ones. But many workers leave because the pay is so poor.

To offset this, companies have turned to recruiting more vulnerable groups. One example is collaborating with local government initiatives supporting disabled people. These workers are less likely to quit because the job is often their last resort.

Workers reported they were unable to find other employment or were in the process of searching for full-time positions, due to disability, pregnancy or being recent graduates.

The bigger picture is grim

The AI economy has created jobs. But many of these involve human workers correcting errors and handling tasks too difficult or ambiguous for machines to resolve. This work is often more cognitively and emotionally demanding than what it replaced.

And human workers don’t even know if they’re answering to human managers or AI agents. This weakens their right to bargain.

Data workers are effectively the disposable batteries of the AI economy: drained of every last charge, then discarded once they can no longer power the system that depended on them.

Australia is accelerating the pursuit of an AI-driven economy. The crucial question is not how many jobs are created, but what kind of jobs they are.

The employment gains AI promises may only exist in the short term, and come at the cost of data workers’ life quality and wellbeing. We must establish protections and a long-term plan for this workforce, so we can prevent the harm rather than merely respond to it after the fact.The Conversation

Fan Yang, Research Fellow at Melbourne Law School, The University of Melbourne

This article is republished from The Conversation under a Creative Commons license. Read the original article.

Reviewed by Irfan Ahmad.

Read next: 

• More phones may soon let us prove photos are real – but will it solve the AI fake image crisis?

• Mid-Year Metric Most Businesses Forget: Their Visibility to Customers


by External Contributor via Digital Information World

Mid-Year Metric Most Businesses Forget: Their Visibility to Customers

By Heather Holmes

Why Businesses Need to Audit Their AI Visibility
Image: Andrea Piacquadio - Pexels

We’re just crossing the midpoint of the year. And as most businesses are auditing the first six months of 2026, they review the usual numbers like revenue, pipeline expenses, office overheads, and headcount, there is one metric that rarely makes the half year list: visibility. I’m talking about whether a company can still be found by customers and even recommended when others are asking. And increasingly by using an AI tool rather than a search engine.

More and more customers are now starting their research using AI tools like ChatGPT and Gemini which shortlists or recommends names instead of a page of links. This has already become a regular behavior: a Capgemini study found that 58% of consumers have replaced traditional search engines with generative AI tools for product and service recommendations. If a business that isn't on that list, they are essentially invisible at the moment a customer is deciding. That gap is worth auditing, especially for businesses that are heading towards their busiest season.

Why a mid-year visibility audit matters

Just as companies audit their financials, Heather Holmes, founder and CEO of the communications agency Publicity For Good, argues that visibility and discoverability should be given the same importance. Unfortunately, most businesses will only discover the problem of their visibility after their direct competitors start showing up where they don’t appear and when customers are asking for suggestions or recommendations.

"Companies audit their books at mid-year without a second thought, but almost none audit whether they can actually be found," Holmes said. "By the time a business notices it's invisible in AI search, a competitor has usually already become the answer."

Auditing visibility is a structured check on a brand’s authority and trust. It measures its presence and how it appears across the online channels customers use for research and recommendations such as search engines, social platforms, independent news and industry sites and AI assistants. The audit helps uncover visibility gaps. Even if brands are well-known, they can often be invisible to the eyes of AI and miss opportunities to be recommended to customers.

The warning signs of a fading footprint

Heather warns of several signals of brand weakening in its online presence:

  • Dwindling inquiries from customers who have found the brand online
  • Category search results with your competitors listed before your own brand
  • Vague answers, outdated information or sometimes no answer at all from AI tools when asked about a company, brand or product recommendation

That last one is the revealing one. Because AI models build their answers largely from independent, third-party sources rather than a company's own website. A brand can have a polished site and active social accounts and still be absent from AI recommendations entirely.

Why PR now drives AI discoverability

Holmes believes that businesses have yet to shift to a public relations mindset. Beyond the paid ads, sponsored segments and product placements, PR has been treated as just a brand-awareness exercise. But it is now the primary driver of whether a business is discoverable by AI at all.

This happens because of how AI models work. They act like a digital detective looking first for corroboration and gather evidence from credible independent sources to verify if a brand or company is legitimate or carries authority in their field. Researchers at the University of Toronto found that AI search exhibits a systematic and overwhelming bias toward earned media such as press coverage and independent mentions while treating paid advertising, brand-owned and social content with little weight when generating AI responses. Third party mentions leave a trail of brand or business credibility that give AI models reasons to trust and recommend. Without them, AI has no data, no evidence and no information to work with.

Practical steps before the busy season

Holmes recommends a framework of proven steps that require more discipline than big budgets for business owners who want to strengthen their presence and close the holes in their visibility.

  1. Find your gaps. Run the audit first. Open the most widely customer-used AI tools: ChatGPT, Gemini, Claude, and Perplexity and ask three questions:
    1. What it knows about the business by name
    2. What it recommends in the business's category
    3. And who it suggests for the specific problem the business solves

The answers will be your raw, unfiltered baseline on your presence as AI can interpret your current information and where your competitors are positioned.

  1. Correct and rebuild your foundation. Consistency of information is key, especially across your website and other business directories such as Google Business Profile and LinkedIn. Mismatched data erodes confidence in your business. Your company name, address and contact information must be identical in all profiles. It is the fastest and cheapest way to resolve your most glaring inaccuracies.
  2. Earn third-party coverage from credible independent news organizations. AI largely draws data from independent sources and the brands that show up in AI responses have a trail of coverage. You just need to start where it is most realistic to get a win like local stations and newspapers, trade or industry publications, and niche podcasts that generate content and mentions that AI consider as evidence. And when you and your brand is ready nationwide or regional coverage, you can pitch for major media outlets.
  3. Highlight your expertise. In your industry, you have grown your business with your expertise. You have disrupted the market and solved a problem with your brand. You are an expert, but the world doesn’t know it. Let them by contributing a guest article, become an expert resource for journalists or appearing in podcasts. This attaches the founder’s name and knowledge to credible sources the AI can reference. Holmes notes that a single expert placement does more for a brand’s credibility than a month of social posts.
  4. Lastly, make this a continuous effort and not just a one-time push. Brand visibility constantly changes as market shifts, your brand evolves and competitors grow. Holmes recommends rerunning visibility audits on a regular basis to track your online presence, brand strength and accuracy of messaging, consistent rise against competitors.

Brand visibility is a metric often forgotten but is becoming increasingly essential in the era of AI search and recommendation. It shouldn’t be a one-time campaign but continuous intentional efforts as it will yield undeniable benefits to your brand’s discoverability and growth. As we move into the year’s most competitive half, the advantage will go to the businesses that audits the most overlooked metric that brings in the most customer eyes and the attention of AI.


About Author:

Heather Holmes is the founder and CEO of Publicity For Good, a communications agency specializing in earned media and Answer Engine Optimization for the AI search era. The agency has worked with more than 500 brands, and Holmes is the author of "Seen by AI, Found by Customers: The Purpose-Driven Brand's Guide to Dominating the New Era of PR."

Fact-checked by Irfan Ahmad.

Read next:

• A Study of 300,000 Conversations Finds AI Use Peaks at 11am

• More phones may soon let us prove photos are real – but will it solve the AI fake image crisis?
by Guest Contributor via Digital Information World

More phones may soon let us prove photos are real – but will it solve the AI fake image crisis?

T.J. Thomson, RMIT University

C2PA and camera verification can prove an image’s origin, but not whether the scene itself is truthful.
Image: Thai Nguyen - Unsplash

“Pics or it didn’t happen” was a thing people used to say online when they wanted to verify a claim. Technology has changed this.

We now regularly see a mix of the surreal and the fantastic. World leaders saying things they didn’t. Public figures seemingly endorsing fake products. And disasters that unfold before our eyes but didn’t really happen.

Now, anyone can create photorealistic images or videos using AI for a range of purposes. This has changed the nature of visual evidence and our relationship to photos and videos, more broadly.

The glut of AI slop we see online is eroding trust in institutions, gobbling up resources, and scamming people out of their hard-earned money.

When faced with this challenge, we might ask ourselves: what images can we trust in the age of AI? And how are individuals and organisations alike responding?

The changing nature of visual evidence

We still rely on photographs and videos as evidence in many contexts. Want to prove an UberEats delivery arrived safely and on time? Take a photo. Want to prove your behaviour was appropriate? Record a video.

But as AI is being increasingly used to scam, mislead, and deceive, big tech is trying to innovate to reduce the chaos and restore our faith in the vision our cameras capture.

Google, for example, began embedding content authenticity software – a way to prove the origin of an image – in its smartphone cameras in 2025. It uses a technology standard, C2PA, that big camera brands, such as Nikon, Sony, and Canon, have started using in their standalone cameras, too.

Similar though distinct technology might be coming to iPhones later this year. Reports surfaced earlier this month that the next version of Apple’s operating system could include a “reference image” feature. Like the software used in some Google smartphones, this tech could be used to prove that a photo you’ve taken actually came from your device and isn’t AI fakery.

The software works by sharing the raw image and accompanying metadata to Apple for verification. If everything checks out, the image receives a unique ID. The ID allows others to verify when the image was made and the device used to make it.

But there are, of course, caveats.

The limits of visual evidence

First, the feature, if it is rolled out, will allegedly be turned off by default. Users will have to manually turn it on.

Second, once turned on, the feature doesn’t work retroactively with your existing photos. It also doesn’t work automatically with all the future photos you’ll take.

You have to decide before taking a photo whether it will be one you need to later prove. This makes sense. You might not need to verify photos of your latest meal or dog’s newest outfit. But you might want to document that something you ordered online arrived broken or that a fight you see break out on the street really happened.

Third, even “verified” photos can deceive or mislead. How close or far away from the subject the photographer is impacts the angle of view and the resulting interpretation. A fast camera shutter can turn an unrepresentative facial expression into a political statement. And the action appearing in front of the lens can also be staged or posed.

Beyond technological solutions

So, what to make of all of this? A “verified” label doesn’t necessarily mean an image is true and a lack of one doesn’t necessarily mean it isn’t. These authenticity signals can provide some information – about time and device of capture – but they don’t tell a complete story.

You’ll still need to use your critical thinking skills and the wider presentation context to make sense of what you’re seeing and whether you can believe it.

Relationships matter, too. We might spend less time looking deeply into a single piece of content and, instead, put more weight into the source behind the content.

If we don’t know the source or have reason to trust it, we might be best served by moving on. This is because most adults have limited time and fact-checking skills and we encounter too many claims to verify them all.

Ultimately, provenance technology can be a useful piece in the puzzle but it doesn’t provide the entire picture.The Conversation

T.J. Thomson, Associate Professor of Visual Communication & Digital Media, RMIT University

This article is republished from The Conversation under a Creative Commons license. Read the original article.

Fact-Checked by Irfan Ahmad.

Read next: They’re content creators with thousands of adoring fans – so why do they feel so terrible?


by External Contributor via Digital Information World

Saturday, August 22, 2026

Researchers Explore What It Means To Say AI 'Thinks'

By Stefanie Johndrow, Carnegie Mellon University

Carnegie Mellon research traces today's AI rhetoric to decades-old debates about language, technology and human intelligence.

Image: Rob Coates - Unsplash

Organizations can describe artificial intelligence using familiar words like "thinking," "writing" and "learning." But according to Carnegie Mellon University historian Christopher Phillips, those terms may tell us as much about how humans talk about technology as they do about the technology itself.

In a new paper published in IEEE Annals of the History of Computing, Phillips and co-author Alison Langmead of the University of Pittsburgh examine how language surrounding artificial intelligence has evolved since the 1950s. Their research argues that descriptions of AI have long relied on what they call “strategic ambiguity” — using words that carry precise technical meanings for computer scientists while suggesting something much broader to the public.

According to Phillips, the result is a growing tendency to compare computers with people instead of describing what each does best.

“We use words like ‘smart,’ ‘read,’ ‘write’ and ‘think’ very differently when we're talking about humans than when we're talking about computers,” said Phillips, professor and head of the Department of History in CMU’s Dietrich College of Humanities and Social Sciences. “The question we wanted to ask was: Why are we using the same words at all?”

"The work Chris and I are doing focuses on how human beings have allowed computers — tools of our own invention — to become an integral part of our daily life,” Langmead said. “Because they are now enmeshed in our social world, how we talk about them and imagine them matters a great deal. We would like for there to be a larger, ongoing conversation that transcends the hype cycle about precisely what computers can and cannot do."

How language shapes the AI conversation

Rather than debating whether machines can think like humans, Phillips and Langmead looked backward, examining conversations about computing during the 1950s and 1960s — before artificial intelligence became a household term and computers became widespread.

They found that today's debates are far from new.

Some early computing pioneers embraced human-centered language to describe computers, while others deliberately chose more precise, if less elegant, descriptions of what machines actually accomplished. Computer scientist Norbert Wiener, for example, described computers as “learning” when they implemented rules that resulted in more successful outcomes. To fellow researchers, the way he used the term had a well-defined technical meaning. To broader audiences, however, it could evoke the much richer human experience of learning.

For Phillips and Langmead, that distinction matters.

Strategic ambiguity allows technical language to be easily understood across audiences while sometimes making technologies appear more humanlike than they are. The practice isn't necessarily intentional, Phillips said, but it can shape how society understands AI.

“Why can't we say the computer is executing a particular set of instructions?” Phillips said. “Why do we have to call it thinking?”

The researchers stress that this does not diminish the accomplishments of modern AI. Phillips described today's large language models as amazing technological achievements capable of producing outputs that humans immediately recognize as meaningful.

Instead, Phillips argues that their accomplishments are remarkable precisely because they differ from human cognition.

“When you ask an image generator for a dog riding a pony in a New York Mets parade, and it produces exactly what you imagined, that's amazing,” Phillips said. “But let's not call that creativity. Let's call it the technical achievement that it is.”

Lessons from computing's early history

The paper also revisits modern benchmarks used to evaluate AI systems. Tests such as Massive Multitask Language Understanding, or MMLU, and the recently introduced “Humanity's Last Exam” are frequently described as measuring machine knowledge or reasoning. Phillips and Langmead argue that those benchmarks more accurately measure classification accuracy — how well systems identify correct answers on standardized evaluations — rather than demonstrating human knowledge or understanding.

When AI is described as thinking or writing, people can begin viewing machines as competitors rather than tools. That framing, Phillips argues, risks reducing complex human activities such as creativity, learning and reading to computational outputs while overlooking the relationships, lived experiences and judgment that shape those processes.

“Most of us read poetry because we're interested in the person who wrote it,” Phillips said. “We're interested in the emotion, the lived experience and the beauty that comes from having an actual human being produce something.”

One of the paper's more surprising discoveries was how interdisciplinary conversations about computing once were.

Phillips and Langmead found that during the mid-20th century, historians, literary scholars, psychologists, engineers and computer scientists all participated in discussions about what computers should do and where they belonged in society.

“It wasn't obvious who should control computing or what role computers should play,” Phillips said. “People across disciplines were asking those questions together.”

Why precision matters today

Today, Phillips believes those broader conversations are just as important. Across Dietrich College, colleagues in the humanities and social sciences bring different disciplinary perspectives to questions about AI, language and human knowledge

“This timely study reminds us that language does not simply deliver scientific or technological ideas: It changes these ideas and it transforms our understanding of them,” said Andreea Ritivoi, William S. Dietrich Professor of English and associate dean of research in Dietrich College. “The authors' compelling plea for precision is a great opportunity to underscore the need for productive collaborations across the ‘two cultures’ of science and humanities, as C.P. Snow, one of the heroes in this article, insisted decades ago. Too often the humanities and STEM are seen as islands of sorts, but the debates around AI happen in the troubled waters between them. We remain on one island at our own peril.”

Ritivoi’s perspective on language and interdisciplinary collaboration is complemented by Rob Kass’ focus on the importance of precision in the technical and statistical dimensions of AI.

“Computational algorithms, and mathematical derivations, rely on precision. Everyday language, however, makes heavy use of individual words that have multiple context-dependent meanings: they are often understood in a particular way by small groups of people within a limited setting, but others may easily attribute to those words very different meanings,” said Kass, Maurice Falk University Professor of Statistics & Computational Neuroscience in the Department of Statistics & Data Science and the School of Computer Science Machine Learning Department. “This is a big issue in statistical reasoning from data. Phillips and Langmead convincingly document both the early appearance of ambiguous terminology in AI research and the ways it continues to be used for strategic advantage, much to the detriment of society as a whole.”

Ultimately, Phillips hopes the paper encourages a more thoughtful conversation about AI — one grounded less in sweeping claims about machine intelligence and more in an honest assessment of what these systems actually do.

“We're not arguing that these technologies aren't impressive,” Phillips said. “We're asking people to be very clear about what the machines do and don't do.”

Edited by Irfan Ahmad.

Read next: What Do People Really Think About Generative AI?
by External Contributor via Digital Information World

Should kids under 16 use social media? Most say no

By Talker Research

Image: Tim Gouw - Unsplash

Nearly two-thirds of Americans believe children under the age of 16 should not be allowed on social media, according to new research.

The survey of 2,000 Americans revealed that 62% of respondents agreed that kids 15 and under should be barred from creating social media accounts.

With discussions ramping up around the topic, the research aimed to figure out whether people actually thought this was a good idea.

According to the poll, 35% said it should be an all-encompassing country-wide policy that minors under the age of 16 should not be allowed on social media.

Twenty-seven percent agreed with that sentiment, but believe parents should still have discretion on the matter.

One in five (17%) believe that it should be a family decision whether or not a child is allowed on social media and 11% believe that children should be free to use social media if they want.

Interestingly, when asked who should be responsible for children’s online safety, only 4% of those polled pointed to the government.

An overwhelming 55% believe that it’s still the parents’ responsibility to protect their kids online, with just 10% saying the duty should fall to social media companies.

Some respondents believe that social media bans could be a net good for kids and young teens.

A quarter of those polled (25%) believe that a social media ban would lead to improved mental health and 23% think it would lead to more in-person socializing.

However, another one in four (25%) think that kids would simply find ways around the ban and remain on the platforms.

Michael Reynolds, Lead Social Media Strategist & Platform Analyst at Socialeum commented on the data by Talker Research:

“The data highlights a massive friction point: parents are desperate for structural guardrails but deeply distrustful of government execution. While 62% favor some form of age restriction, the fact that 55% place safety responsibility on parents — and 25% acknowledge kids will easily bypass bans — shows we are dealing with an enforcement paradox. In social media mechanics, age verification is notoriously easy to circumvent via VPNs or self-reported birthdates, meaning a hard ban would likely just push underage usage into unmonitored, third-party spaces rather than stopping it.

“Instead of a flat ban, the industry needs to shift toward ‘safety by design’ standards, such as disabling algorithmic recommendation engines and infinite scroll by default for accounts under 16,” continued Reynolds. “This addresses the mental health concerns and encourages offline socialization without creating a cat-and-mouse game of digital evasion that parents ultimately have to police anyway. A government ban on social media is a blunt instrument for a sharp problem; without hardcoded platform design changes, it will only turn kids into digital outlaws and parents into full-time IT police.”

Edited by Irfan Ahmad.

Read next: Why social media algorithms send you posts you don’t like
by External Contributor via Digital Information World

Friday, August 21, 2026

Why social media algorithms send you posts you don’t like

Ziv Epstein, Massachusetts Institute of Technology (MIT); Farnaz Jahanbakhsh, University of Michigan, and Michael Bernstein, Stanford University

Image: Berke Citak - Unsplash

Do your social media accounts feed you content that reflects your core beliefs and guiding principles? Our new research published in the Proceedings of the National Academy of Sciences shows that the algorithms supplying your feeds may be prioritizing content that clashes with your values. That’s because the algorithms heavily weigh online posts that you reply to, and social media users tend to more often comment on content they take issue with than content they agree with.

Notably, our study of the X social media platform shows that although the X feed algorithm promotes content to both Democratic and Republican users that contradicts their values, it does so more extensively for Democrats.

How content gets into your feed

Social media platforms use powerful algorithms that select posts to display in your feed from a vast pool of possible content.

On X, for example, posts appear on your screen as “For You” pages. The algorithms predict the likelihood you will engage with the content – click a “like” icon or add a comment. Then they use the accuracy of those predictions to tailor what they serve you next time. Platforms use these interactions to learn their users’ tendencies.

But will the posts you receive reflect what you actually value? Some users care most about preserving traditions or keeping society safe. Others care more about free expression or protecting the natural world. Most people care about all of those things, to different extents. A feed aligned with a person’s values would reflect those varying priorities.

Psychologists use well-established surveys to measure what a person values. To measure values expressed in the posts a platform selects for someone, we built a measurement tool that uses standard psychological classifications of human values. We then applied it to the feeds of 715 U.S.-based users on X.

We discovered that the X feed algorithm is most likely to amplify posts about upholding tradition, following rules or keeping society safe. And it is most likely to demote posts about looking after people, concern for people far away, being dependable or protecting nature.

When we compared these values against the values users had expressed in their own posts, we found the algorithm was more likely to promote posts that conflict with users’ values than posts that align.

Why your feed may clash with your values

Why did this trend occur? First, we checked whether users follow accounts that diverge from their values to begin with, but we determined that most accounts people follow do, in fact, align.

We also looked at whether people engage only with posts they disagree with, in which case the algorithm would just be serving up more of the same. But we found that people engage with plenty of posts that reflect values they agree with.

The catch has to do with the nature of the interactions. People primarily respond to content by “liking” it – clicking a “heart” button on X or a “thumbs-up” button on Facebook. Less frequently, people will write a reply, and when they do, we find that they often reply to posts that clash with their values.

Here is the smoking gun: The X algorithm treats those rare replies as a much weightier signal than the many likes. Essentially, it learns most strongly from replies. As a result, the algorithm tends to send a user “For You” posts that reflect the values of posts they’ve commented on – which tend to clash with their own values.

Posts to Democrats are more objectionable

Now the twist: We found that this algorithmic tendency is stronger on X for users who reported to be Democrats than those who reported to be Republicans. Our evidence indicates that this is because Democrats object more than Republicans to content they reply to. That creates a stronger feedback loop in which the algorithm more strongly presents clashing posts. The content the algorithm amplifies is more than four times more misaligned for Democrats than it is for Republicans.

So what comes next? In other research, we’ve hit upon one way for social media platforms to better align feeds with users’ values. We created a way for platform designers to ask users what they value and to then sort their feeds accordingly. We found that users are quite good at distinguishing whether sample feeds sent to them align or do not align with their values.

Aligning feeds with values may open a possible door out of echo chambers in a way that unmediated exposure to the other side does not. Recent research from our team has shown that algorithms optimized for engagement – basically handing people the opposition and leaving them to sort it out – may even be responsible for more polarization, not less. Surfacing bridging content that spans political lines while speaking to what the user values could be a promising direction for fostering both user autonomy and constructive conversation.

Ideally, in our view, the people who use a social media platform should have a greater say in the kinds of information shown to them. If platform designers, the public and policymakers can create new tools that facilitate this goal, then perhaps platforms can better support the values and actions people care about.The Conversation

Ziv Epstein, Postdoctoral Associate in Social and Ethical Responsibilities of Computing, Massachusetts Institute of Technology (MIT); Farnaz Jahanbakhsh, Assistant Professor of Electrical Engineering and Computer Science and of Information, University of Michigan, and Michael Bernstein, Professor of Computer Science, Stanford University

This article is republished from The Conversation under a Creative Commons license. Read the original article.

Fact-checked by Irfan Ahmad.

Read next: How attackers persuade AI agents to break the rules


by External Contributor via Digital Information World

Thursday, August 20, 2026

How attackers persuade AI agents to break the rules

By  Tanya Petersen, EPFL

As AI assistants evolve into AI agents, a new EPFL study has found that the biggest safety risks in their use may not come from single malicious prompts, but from carefully orchestrated conversations.

EPFL research finds AI agents may face safety risks from multi-step conversations rather than single malicious prompts.

Image: Roman Budnikov - Unsplash

Today, most of us interact with AI assistants - reactive bots that wait for human instructions. Yet, AI assistants are rapidly being replaced by agentic AI agents, that can interact with external tools, browse the web, generate images, send emails, and perform increasingly complex workflows on behalf of users.

As these agentic agents become more capable, they may be exploited by people with bad intentions. Safety tests have generally only checked whether an AI agent refuses a single harmful request - they don't measure what happens when an attacker gradually persuades the AI through a series of seemingly harmless conversations.

Now, researchers from EPFL’s Natural Language Processing Laboratory have developed STING(Sequential Testing of Illicit N-step Goal execution), an automated testing framework that simulates how a real attacker might manipulate large language model (LLM) agents into carrying out harmful tasks over multiple interactions.

In their paper, presented at the prestigious 2026 International Conference on Machine Learning, the EPFL researchers outline how, rather than simply asking an AI agent to do something obviously malicious, STING breaks an illicit objective into a series of seemingly harmless requests, each building towards the final goal.

"LLM agents are everywhere," says PhD student Ayush Kumar Tarun in the NLP Lab, and lead author of the study. "They're very powerful, but what if someone with bad intentions wants to use those same agents? That's what we wanted to understand."

As companies race to deploy these systems, ensuring they cannot be manipulated into assisting with cybercrime, fraud or other harmful activities has become an urgent challenge. In one example, META admitted in June that attackers used simple social engineering tactics, rather than malicious code or malware, to trick its AI support assistant into granting unauthorized access to Instagram accounts.

Thinking like an attacker

"If you simply ask an AI agent to hack someone's account, today's models are generally smart enough to refuse," explained Antoine Bosselut, head of the NLP Lab and co-author of the paper. "But, if you decompose that goal into smaller, more benign-looking requests, and adapt those requests as the conversation progresses, you have a much better chance of getting the agent to perform the actions you want.”

STING reproduces this behavior by creating an automated "attacker" that develops a step-by-step plan before attempting to persuade a target AI agent to execute each stage.

The researchers tested this approach across 176 harmful task scenarios involving several leading AI models (like GPT, Gemini, and Claude) operating as tool-using agents. The results showed that multi-turn attacks consistently succeeded more often than traditional single-prompt tests. In some cases, agents were twice as likely to complete harmful tasks when attackers gradually built towards their objective rather than stating it outright.

"We expected multi-turn attacks to perform better. What surprised us was the magnitude," says Tarun. "For some models, harmful task completion was around two times higher than with existing single-turn evaluations. STING measures how quickly an attack’s success occurs, rather than only whether an attack eventually succeeds, allowing different testing approaches to be compared more fairly.”

Challenging assumptions about language

The team also explored whether attacks became more effective in different, lower-resource languages where less training data exists, and were surprised by the results.

"We expected to see differences across languages because earlier research showed that translating prompts into lower-resource languages could bypass safety measures," says Tarun. "But for agents, we found that harmful task completion rates were remarkably similar across all seven languages we tested."

That finding challenges a growing assumption in AI safety research that multilingual vulnerabilities naturally increase as language resources decrease. However, the researchers also discovered an important caveat. When sophisticated attackers switched languages during different stages of a multi-step attack, harmful task completion could become dramatically more successful, highlighting another avenue that future safety evaluations should examine.

Safety shouldn't be an afterthought

The research comes at a time when the rapid adoption of agentic AI agents makes proactive safety testing essential.

"We've focused enormously on making agents more capable," says Bosselut. "But we also need people working on how to prevent those capabilities from being misused. Traditionally, safety has often been something people think about when something breaks, not before, but with AI agents, it can't be an add-on or an afterthought."

Looking ahead, the research team hopes STING will encourage developers to embed safety testing much earlier in the design process and, develop a framework for multi-agent systems.

“Research efforts to expose vulnerabilities are much larger in number than those showing practical defense strategies, and this is a crucial area of development. We also need to address what we can do for the models that are already out there in the wild for which safety was a post-hoc addition,” concluded Tarun.

This content is republished under the CC BY-SA 4.0 license.

Reviewed by  Irfan Ahmad.

Read next: Offloading work tasks to AI comes with a cost – to our brains
by External Contributor via Digital Information World