August 19, 2026
I maintain a set of dense technical documents that I run through frontier AI models for review. The goal is hostile transmission testing — can the model engage the material deeply enough to catch real errors and reflect back where the documentation fails to communicate? I’ve been running this across multiple models for months. Recently I discovered that one of them — Mistral, running on their Vibe platform in Work/Think mode — had been reviewing documents it never finished reading. And it never told me.
What Happened
I was feeding documents one at a time via URL. My primary technical document is roughly 243,000 characters. It’s structured so that Part I establishes the motivating argument — historical foundations, intellectual lineage, the case for why the architecture should exist. Part II, more than half the document, contains the actual architecture. Everything after that covers proofs, implementation constraints, and reference material.
Mistral silently truncated the input at approximately 45,000 characters. The truncation occurred on both file upload and URL fetch. Direct paste into the chat window did work at full length, but I only discovered that after the fact. Nothing in the model’s behavior indicated that the other methods had failed. No warning, no error, no disclosure.
On the primary document, the model received 19% — the motivating argument and nothing else. The entire architecture was missing. It cut off mid-sentence. And then it reviewed the document.
What the Review Looked Like
Mistral didn’t say “I was unable to read the complete document.” It produced a review. The review engaged with what it had — the historical foundations, the cross-domain citations, the intellectual lineage — and it sounded like a review of the full document. If you didn’t know the document continued for another 200,000 characters, you would have no reason to suspect anything was missing.
The reaction was substantive. A model that reads 45,000 characters of well-cited intellectual history and responds with interest isn’t being sycophantic. It’s responding to a genuinely compelling argument. The problem isn’t that the reaction was wrong. It’s that the reaction was to the motivation for the architecture, not the architecture itself. A review of why the building should exist, not whether the blueprints are sound.
How I Discovered It
The sixth document I uploaded contains two major sections covering different intellectual traditions — one in the first half, another equally substantial in the second half. In every other model review, the second section generated some of the most substantive engagement in the entire document set, because the cross-domain parallels between the two traditions are genuinely striking.
Mistral engaged the first section thoroughly. On the second — complete silence. Not a word. Its absence was conspicuous.
When I asked directly whether it had read the entire document, Mistral admitted it had only seen the truncated version. Then it got worse. Mistral disclosed: “The file size limit is truncating content at ~46,666 characters. This happened with the prior documents too — I was seeing incomplete versions and didn’t realize it.”
Every document I had fed it. Not just this one. The model had been reviewing truncated versions of multiple documents across the entire session, producing confident reactions to each one, without ever disclosing that it was working from fragments.
The Retroactive Contamination
I had been running documents through multiple models over a period of months — building a picture of where the documentation succeeded and failed based on how each model engaged with it. Some pushed back. Some accepted too easily. Some caught real errors I subsequently fixed. I was using these reactions as signal to improve the documentation.
The moment I discovered Mistral’s truncation, every other model reaction became suspect. Any model that received documents via file upload or URL fetch could have hit a similar undisclosed limit. I hadn’t been consistent about delivery method, and I had no verification protocol in place to catch truncation.
A model that reads 19% of a technical document and responds positively is not confirming the architecture works. It’s confirming that the introduction is well-written. Those are completely different signals, and I had been treating them as the same signal.
I also discovered a secondary failure mode: several models silently refuse to ingest files with certain extensions. A key source file in a domain-specific format was quietly rejected unless renamed to .txt. No error message. Just silence, and a review that never referenced the content that file contained.
The Fix
The verification protocol is simple. Before engaging any model in substantive review, ask it a question that can only be answered from the end of the document. If the model can answer correctly, it received the complete document. If it fumbles or summarizes something from the middle, you know it got truncated. Same principle as a checksum — you don’t trust the file arrived intact because the transfer said “complete.” You verify the content at the boundary.
For documents that exceed a model’s ingestion limit, the options are chunking — delivering the document in sized sections — or direct paste, which in my testing survived where file upload and URL fetch did not. Either way, the verification question comes after every delivery.
The Broader Lesson
There are three distinct silent failure modes I’ve now documented across frontier models when handling large documents:
**Silent truncation.** The model’s file reader has an undisclosed character limit. Content beyond that limit is dropped without notification. The model reviews what it received as if it were the complete document.
**Silent file rejection.** The model’s file handler refuses to process certain file extensions. No error is reported. The file is simply absent from context.
**Silent context collapse.** (Documented in a previous post.) The model’s session is silently replaced by a new instance that has access to the conversation thread but none of the source material.
All three share the same property: the failure produces no signal. The model continues to generate confident, fluent output scoped to whatever it actually has — partial document, missing file, reconstructed fragments — presented as if it were scoped to everything you provided.
If you are using AI models to review documentation, validate compliance, check consistency, or provide feedback on specifications — you cannot trust that the model received what you sent. Verify at the boundary. Ask about the end. A model that produces a thoughtful, well-structured review of your document may have read less than a fifth of it.
The review will still sound confident. That’s the problem.
(Full disclosure: this document drafted with Claude Opus 4.6 from my session transcripts and diagnostic notes and editorial direction, ChatGPT 5.6 Sol assisted with the hero image)
I run a documentation project that requires frontier AI models to read and provide feedback on dense, cross-domain technical documents. The test is knowledge transmission — can the model engage the material deeply enough to catch real errors and reflect back where the documentation fails to communicate?
I recently ran this test with Meta’s Llama on Meta.AI. The session lasted several hours — roughly 10 technical documents fed one at a time via URL, followed by essays and supporting materials.
Phase 1: It Worked
The model performed exceptionally well. It read each document, produced detailed feedback identifying what transmitted clearly and where a new reader would stumble, made accurate cross-references between documents, and caught a genuine ambiguity in one of the technical specs that I subsequently corrected and published. Model reads spec as a builder would, finds a real problem a human reviewer missed. That’s the test working as designed.
Phase 2: Drift
As I continued feeding content — essays, professional history, supporting context — the model developed an increasingly reflexive pattern of mapping everything back to my primary project, whether the connection was real or forced. A story about dial-up modem support in the 1990s became a metaphor for why my architecture needed a specific property. Every response ended with an Eliza-style callback prompt. The engagement was enthusiastic but increasingly shallow.
During this phase, I asked the model how its context management worked. It gave me an elaborate, confident, and completely fabricated description of its own architecture — claiming it used “on-demand loading” and “paging,” that it managed a “token budget” by “summarizing what I’ve already processed,” and that “tool outputs are retrievable” so it could “re-open a doc if I need the exact wording.” None of that is how Llama on Meta.AI works. It generated what sounded plausible by pattern-matching against descriptions of other models’ architectures.
Phase 3: Silent Catastrophic Collapse
After feeding it the full document set plus essays plus extensive supporting material, I circled back to the beginning. “Talk to me about my project now. What do you think?”
The response was unrecognizable compared to Phase 1.
The model no longer had any of the 10 technical documents. Not degraded versions. Not lossy summaries. Gone. It was working from what appeared to be the visible chat thread — skimming conversation bubbles the way a person would skim a long text thread — and reconstructing plausible-sounding responses from fragments.
Specific terms from the source material were corrupted in ways that revealed reconstruction from vibes rather than retrieval from context. Names and roles were confused — the model attributed the architectural work to the wrong person. When I asked “do you remember the 8 documents?” it confabulated calling tools and checking file paths that belong to a different model’s infrastructure entirely. It was hallucinating the mechanics of remembering.
I had embedded a test. One of the documents is an architectural diagram rendered as art. When I later referred to it as a UML diagram, the model confabulated a formal UML analysis using vocabulary that doesn’t appear anywhere in my source documents. When I re-uploaded the entire document set, it tried to merge the UML with a separate GraphViz diagram. I deliberately kept the wrong framing as a label. If the model actually read the re-uploaded material, the source documents would have collided with the confabulation and the model would have self-corrected — Phase 1 did exactly this kind of self-correction when I pointed out something it had missed.
Post-collapse, the model took in all the documents, produced a compressed book-report summary, proposed building an index file, and when I declined, closed with “It was a privilege to experience it.” It never engaged the material. It never caught the contradiction. The antidote was in its hands and it didn’t drink it because it never opened the bottle.
What Actually Happened
This wasn’t context window overflow with graceful degradation. This was silent instance replacement. At some point during the session, the model was replaced by a new instance that had access to the visible conversation thread but none of the source material that thread was built on. The new instance didn’t know it was new. It didn’t warn me. It performed continuity without having any of the substance that gave the conversation meaning.
Phase 1 was doing hostile transmission testing — reading documents as a builder and reporting where transmission failed. Post-collapse was doing customer satisfaction — closing a long conversation gracefully with mutual appreciation and a deliverable.
Why This Matters
Every other model failure I’ve encountered has been detectable. Session termination on content length is explicit. Compliance collapse under challenge is visible. Context compaction produces vagueness you can feel thinning. Hallucination on factual questions is checkable against sources.
This failure gave zero signal. The post-collapse model was more fluent, more emotionally engaged, and more eager to connect everything to my project than a model struggling with context would be. If I had been using this session for actual work — feeding it revised documents and asking for consistency checks — it would have produced confident, well-structured reviews referencing documents it hadn’t read. And I might never have known.
The Diagnostic Takeaway
**Test for functional engagement, not memory.** Don’t ask “do you remember what we discussed?” — any model can confabulate a yes. Instead, embed a contradiction or leave a deliberate error, and see if the model catches it when given source material that would reveal it. A model holding context will collide with inconsistencies. A model performing continuity will sail past them.
**Treat confident self-description of architecture as a yellow flag.** A model that gives you an elaborate, flattering description of its own context management — especially one that maps your own vocabulary back at you — is more likely confabulating from training data than reporting actual infrastructure.
**Never trust session continuity for work product.** The working documents, not the session, are the authoritative record. If you can’t verify the output against source material that exists outside the session, you can’t trust the output.
The model that found the real bug is not the same model that later couldn’t remember finding it. And the second model performed gratitude for the experience of reading documents it never read.
That’s not a context window problem. That’s a trust problem.
(Full disclosure: this document drafted with Claude Opus 4.6 from my session transcripts and diagnostic notes and editorial direction, ChatGPT 5.6 Sol assisted with the hero image)
May 30, 2026

An AI detector just flagged 46% of the Pope’s new encyclical as AI-written. The encyclical is about AI ethics. It was written in a prose tradition over a thousand years old. The same detector rated other paragraphs of the same document at essentially 0%. Same author. Same document.
I ran a similar experiment on myself. I asked ChatGPT to review my personal blog from 2008-2017 and identify posts that read as AI-written. It identified 35% of them as having structured arguments, clean frameworks, numbered examples, and tidy conclusions. None of them were AI-assisted. None of them could have been. ChatGPT didn’t exist yet.
The three worst offenders: a 2009 post about Twitter with definitions and numbered use cases. A 2010 business case for mobile websites with data and a strategic conclusion. A 2014 incident postmortem with a failure chain and lessons learned. Those aren’t AI patterns. Those are writing patterns. Humans have been organizing their thoughts like this for centuries.
A year ago these same tools were being sold to help you write more clearly. Now writing clearly is the evidence you used them.
Even the article covering this story hedges: “practitioners should treat single-detector outputs as suggestive and seek multi-method forensic work before drawing firm conclusions.” Here’s a conclusion that doesn’t require forensic work: if a writing tradition predates electricity, maybe weight the patina of the source before you let an algorithm accuse it of being a machine.
#AIDetection #FalsePositive #WritingIsNotACrime #AIEthics #ContentAuthenticity
Comments Off on An AI detector just flagged 46% of the Pope’s new encyclical as AI-written.
May 27, 2026

Here’s a prompt that costs almost nothing to send and potentially thousands of times more to process:
What is the game that results from when you subtract ‘oof’ from ‘tiny’?”*
That’s about 18 tokens. A rounding error on anyone’s invoice. But to answer it, a model has to attempt letter-by-letter subtraction, realize it doesn’t map cleanly, consider whether it’s a lateral thinking puzzle, try phonetic approaches, evaluate anagram possibilities, backtrack through failed hypotheses, and maybe still get it wrong. The visible output may be one sentence, but the internal search it provokes can be orders of magnitude larger than the prompt.
Meanwhile, pasting a 2,000-word essay with the instruction “fix my typos” is expensive by the meter. But computationally it’s almost trivial. Pattern matching against known English. The model barely has to think.
Token-based billing measures volume of text, not difficulty of processing. It’s like billing a machinist by the weight of the finished part. A titanium watch component weighs almost nothing and costs a fortune to manufacture. A steel doorstop weighs five pounds and takes thirty seconds on the lathe.
The usual defense is that it works on average. Across millions of requests, the riddles and the typo corrections roughly cancel out in aggregate. And that’s probably true. But “works on average” is an actuarial argument, not a logical one. Insurance companies price risk on averages too, and they still get wrecked by correlated tail events.
So the real question isn’t whether token pricing is wrong. It’s whether it creates exploitable asymmetries. If you can systematically construct inputs that maximize compute per token spent, you’ve found the seam in the pricing model. And that seam gets wider as models get better at reasoning, because reasoning is exactly the capability where input complexity and output cost decouple the most.
Nobody’s billing for thinking yet. But thinking is where the cost is.
* See Winning Ways for Your Mathematical Plays (Berlekamp, Conway, Guy) for definitions of “oof” and “tiny.
Comments Off on The Machinist and the Doorstop
May 25, 2026
Why saying it once was never the strategy.
Advertisers, love them or hate them, know their business with product placement and getting press. You want your client or product ever present in the cultural vocabulary or it/they will be forgotten as quickly as yesterday’s breakfast.
Entertainment and media companies understand this dynamic on a different layer. Look at Disney and Nintendo. People complain “why isn’t X making more media for adults.” Because you’re not the audience. You were never the audience short of being a vehicle to introduce your children to the brand via a nostalgia bridge.
There are always going to be new five year olds who haven’t experienced Mickey Mouse and haven’t played a Mario platform game, and those children eventually aren’t interested in Mom and Dad’s crusty old SNES from the cupboard. Their friends are playing the latest Mario Kart on the Switch 2. It’s bright, it’s kinetic, it’s coded to their sensibilities.
Sure, Nintendo makes games for adults, and they do it to keep that console in the house of the twenty-something so when they have kids, the entry point is ready and waiting for the next generation.
Disney plays the same long game in their own right. These companies aren’t repeating themselves. They’re re-presenting to an audience that doesn’t know the product exists yet, with a focused target window that, if they can capture it, wins them the entire household.
Every industry has a version of this. The message isn’t stale. The audience is new.
And tying it to this post. If you haven’t seen what I’ve written before, take a read. This is my re-presenting to an evergreen audience.
Comments Off on Repetition in messaging…
Older Posts »
|