110 incidents on record · 2026 Headlights Incident reports by Ellie Harris · Melbourne
10 new this week Library last updated 27 July 2026
← The incident library
HD-INC-095
Public affairs · Netherlands · 2026 · Alleged AI-generated astroturfing

Dutch reporters found that most Dutch responses to an EU tobacco consultation appeared to come from a Philip Morris AI tool, and the company denied steering them

By Ellie Harris · Filed European Commission tobacco consultation; investigation reported mid-2026

Alleged: Philip Morris International developed or deployed the AI system implicated in this incident. Details are drawn from public reports; parties are presumed innocent of any wrongdoing not established by an official finding.

Dutch reporters found that most Dutch responses to an EU tobacco consultation appeared to come from a Philip Morris AI tool, and the company denied steering them

What happened

It was reported that in mid-2026 the Dutch broadcaster NOS and the journalism platform Pointer alleged that Philip Morris International had used an AI tool to generate large numbers of apparently individual responses to a European Commission consultation on stricter tobacco and vaping rules, weighted against tighter regulation. Philip Morris denied steering the responses. According to the reporting, the company ran a campaign called “Your Voice Your Choice”, placing QR-code posters in tobacco shops; scanning a code led to a tool that asked a few multiple-choice questions and then produced a first-person text the user could submit to the consultation on the revision of the Tobacco Products Directive.

The journalists said they ran about 65,000 responses from fifteen EU countries through an AI-detection tool and estimated that roughly a third were probably written entirely by AI. In the Netherlands, they reported, of 786 responses examined, about 71 percent appeared almost certainly AI-written, and around nine in ten Dutch-language responses appeared to originate from, or be linked to, the Philip Morris tool. They also reported that the tool’s selectable arguments were weighted against regulation, with eleven of twelve listed “important aspects” arguing for looser rules, and that of several hundred responses they linked to the tool, only a handful supported tighter regulation. The consultation drew about 80,000 responses in all, far more, the journalists noted, than the fewer than a thousand that most comparable consultations receive. The tool has since been taken offline.

According to the reporting, Philip Morris rejected the characterisation, saying it had used standard AI settings to make the texts readable, describing the campaign as a legitimate contribution to the democratic process, and maintaining that users stayed in control of their submissions and were free to edit them. It accused anti-tobacco campaigners, the reporting said, of spreading “fake news” and of manufacturing a controversy to delegitimise views they disagreed with. Separately, a group of Dutch lung specialists filed a complaint with the country’s advertising standards body, arguing the campaign was misleading and amounted to tobacco advertising, and reporting said a further complaint was being prepared for the Dutch data protection authority over the collection of smoking-status data. The European Commission said it was very concerned and would take the campaign into account when weighing the responses. As of mid-2026 no regulator or court had made a finding.

What an auditable version would have shown

A public consultation is only as trustworthy as its ability to tell a genuine voice from a mass-produced one, and in this case the process, as described in the reporting, had no built-in way to. An auditable version attaches a record of provenance and authenticity to each submission: whether it was written by a person or generated by a tool, and, where a tool was involved, which campaign or system produced it. With that record, any wave of near-identical AI-authored texts from a single source could be visible as it happened and weighed accordingly, rather than reconstructed afterwards by journalists running detection software over tens of thousands of responses. The aim is not to silence anyone, but to let a process see what it is actually receiving.

Where the gap was

The consultation took each submission as one person’s view, and, as far as the reporting shows, nothing travelled with it to say otherwise. A PersonaGuard is built to spot content that poses as a real individual when a machine produced it, so synthetic participation does not slip through as authentic. A ConductRecord attaches provenance to each submission, where it came from and any tool behind it, so a process can separate organised, machine-written input from the individual voices it is meant to weigh. The reported problem was not that people held these views; it was that a process meant to hear individuals had, on the journalists’ account, no way to tell how many of the voices were, as they alleged, machine-generated.

What governance should have looked like

Now that AI makes it cheap to write fluent, first-person text at scale, any process that weighs public opinion needs to know where each contribution actually came from. That means every submission should carry some record of who or what produced it, and the process should be able to spot and set aside the ones that were machine-written or organised by an interested party, so the final count reflects real people. This is not about deciding what the public should think, or silencing anyone, but about a consultation being able to show what it is actually made of, the way any piece of evidence should. The lesson, as reported, is a simple one: opinion produced at scale is not the same as opinion held, and a process that cannot tell the two apart belongs to whoever can generate the most text.

Failure Pattern: an AI tool can produce first-person messages at scale that are submitted as individual citizens’ views, and a process receiving them may have no way to tell authentic participation from manufactured responses.

Governance Principle: a process that weighs public input needs a reliable record of each submission’s provenance and authenticity, so that manufactured or AI-generated responses can be identified and are less likely to pass as genuine individual participation.

The reference implementation of PersonaGuard and ConductRecord is open source. It lives at github.com/saffronandindia/headlights-oss, Apache 2.0 licensed and free to install. The repository is public now.

Sources

The mailing list

Fresh incident reports every week. One email to match.

We add new incidents to the library regularly, and send a single short email each week with what's new. The library stays free and open; this is just how you keep up with it.

No tracking. Unsubscribe in one click.

The record

An auditable system would have produced a signed, tamper-evident record the moment this happened: what the system did, the version that did it, the basis it acted on, and the action taken, and Philip Morris International could have produced it on demand.

This is the record the system as deployed did not produce in a signed, auditable form.

What this teaches
Capture what happened when it happens
What the system did, the version that did it, the basis it acted on, and the action taken, recorded at the moment, not reconstructed after.
Sign it, so no one has to trust the record-keeper
A tamper-evident entry. Edit it later and the signature breaks. The record does not ask for the benefit of the doubt.
Make it verifiable by anyone
A court, a regulator, a customer's lawyer can check the record themselves, without taking the company, or us, at our word.

Headlights summarises publicly reported AI incidents. All summaries are independently written, attributed to their original sources, and intended for research and educational purposes. Allegations are identified as such until established through official findings.

Last reviewed June 2026. This report is based on the sources listed above and reflects information available at the time of review; later developments may not be captured. Where a person is described as charged with or alleged to have done something, that allegation is unproven unless a conviction or a court or regulatory finding is stated. Headlights publishes journalism and commentary, not legal advice.

Want to write back?

Direct to my inbox.

ellie@useheadlights.com →