Where it hits

Government websites and public comment: when fake participation shapes real policy

Public bodies can't put a price on participation or demand identity from everyone. That makes their channels the hardest to protect, and some of the most important.

FAKE: NEARLY 18 MILLIONTHE REST
FCC 2017 net neutrality proceeding, one block per million comments. New York Attorney General, 2021.

The case everyone should know

In 2017 the US Federal Communications Commission received more than 22 million public comments on its proposal to repeal net neutrality rules. A 2021 investigation by the New York Attorney General found that nearly 18 million of them were fake.

The fabrication came from more than one direction. More than 8.5 million fake comments supporting repeal came from a campaign funded by a broadband industry group, which paid lead generation companies that submitted comments using real people's names without their knowledge. Separately, a single 19-year-old college student submitted more than 7.7 million comments opposing repeal, using made-up identities. Three lead generation companies later agreed to pay more than $4.4 million in penalties and disgorgement.

That was before generative AI. Those comments were largely templated, which is how investigators could find them. Today each one could be unique.

Why public channels are uniquely exposed

  • Openness is the point. Consultations, petitions and complaint forms must accept anyone, often anonymously.
  • Price is off the table. Charging residents to participate is unacceptable, so the tool that works best for inboxes can't be used as is.
  • Volume carries meaning. Comment counts, petition signatures and complaint volumes are read as signals of public sentiment, which gives fabricators a reason to inflate them.
  • Service channels get flooded too. Service requests, freedom of information requests and appointment systems can be overwhelmed, delaying real residents.
  • Budgets and expertise are thin, especially for local government.

What protection can look like

Proof of presence, not identity

The question a consultation needs answered is "is this one real person, once?", not "who is this?" Device attestation, passkeys and privacy-preserving tokens can answer it without collecting names. A resident proves their device holds a real credential. The public body learns nothing else.

Rate limits per person, not per connection

Anonymous per-person limits, such as one submission per credential per consultation, stop fabrication at scale while leaving every resident able to take part.

Refundable deposits for institutional submitters

Organisations submitting at volume, such as advocacy groups and lead generators, can reasonably be asked to post a refundable deposit or register, while individual residents participate free.

Honest reporting

Publish verified and unverified counts separately rather than a single total. That alone removes most of the incentive to inflate.

A public-sector edition is on the Franked roadmap.

Sources

  1. New York Attorney General, Fake Comments: How U.S. Companies & Partisans Hack Democracy (2021)
  2. Thales Imperva, 2026 Bad Bot Report: Bad Bots in the Agentic Age