Provenance and attribution for mass submissions
Recovering who stands behind mass submissions: which campaign, how large, who organized it, and by what route each entry was filed. Decision-makers can see which campaign produced a flood of comments and how many distinct people stand behind it.
The impact of agents
Mass submissions corrupt a record in three distinct ways: the orchestrated campaign that files one position thousands of times, the computer-generated flood with no person behind it, and the malattributed filing made in a real person's name without their knowledge. As agents make all three cheap, each grows faster than any reviewer's ability to tell them apart. The consultation record stops recording its own provenance.
What the agency has to recover is attribution: which submissions belong to which campaign, who organized it, and by what route each was filed, so it can report the record honestly and defend the weight it gave it. That means not discounting legitimate coordinated advocacy.
This is a problem of attribution at scale. It doesn't require detecting which submissions a machine wrote.
What must be verified
Government needs enough confidence in a body of submissions to act on it and stand behind the decision: that organized campaigns are identified and collapsed to a single representative entry with their size and organizer disclosed, that submissions filed through a verified route can be told apart from unverified ones, and that duplicates and automated filings are visible as such. The confidence comes from provenance and source validation. It doesn't come from judging whether a given submission was machine-written.
Protecting access
Legitimate coordinated advocates are the group most at risk. If campaign volume itself gets treated as suspect, a real constituency is collapsed out of the record the agency reads: its numbers stop counting, precisely because it organized. A submitter who can't or won't clear identity validation, because of limited connectivity, device access, or distrust of the process, can't be discounted by default.
Keeping the path open
- Attribute a campaign rather than discarding it: one representative entry, a participant count, the organizer named.
- Give organizers a route to confirm authorship.
- Treat a submission filed outside the verified route as data for follow-up, never grounds for rejection, so source validation doesn't harden into an identity barrier.
Response surface
A campaign appears on the record as one attributed entry with its size and organizer disclosed, rather than as thousands of separate-looking submissions.
The record shows what it can verify: size, organizer, and route. It also states what it cannot verify. No entry is labeled machine-written, because that call cannot be made reliably.
Maturity
- Established
For problem recognition and verified-source intake, which are already in practice.
- Emerging Headline
For representative-version reporting and attribution of agent-assisted submissions at scale, which are still taking shape.
Precedents
ACUS Recommendation 2021-1. The Administrative Conference of the United States separated three kinds of problematic comment: mass comments orchestrated by campaign organizations, computer-generated comments, and malattributed comments filed using stolen or fabricated identities. It recommended practices for managing each while preserving the right to participate, and returned to the subject with guidance on responding to the full range of comment types. The three categories are distinguished by origin, and only the third is fraud.
GSA's Regulations.gov integrity updates. GSA relaunched the federal comment portal with a bulk-comment API requiring identity validation for organizations filing on behalf of others. Provenance is captured at the point of filing, which is what lets a verified route be told apart from an unverified one afterward.
The New York Attorney General's investigation. The investigation found nearly 18 million of the 22 million comments in one federal docket were fake, roughly 8.5 million of them using the names and addresses of real people without their knowledge, and secured settlements from the companies that supplied them. Identity misuse at that scale was established by a law-enforcement investigation, and not by the docket's own controls.
GAO on comment integrity. Surveying ten agencies, GAO estimated the share of commenters whose email addresses confirmed their submissions ranged from 48 to 87 percent, and that 5 to 30 percent of addresses on the record were unverifiable. Agencies differ by a factor of two in how much of the record they can stand behind.
Australian Senate form-letter listings. The Senate climate-policy committee published its submission list under the heading 'Submissions received as standard form letters, including form letters with additional individual comments', and environment committees maintain standing pages for the same purpose. The campaign is disclosed as a category of the official record, attributed rather than erased.
What carries over to agent use
High, with jurisdictional adaptation. The US Administrative Procedure Act's (APA) notice-and-comment framework is US-specific, but every jurisdiction running public consultations faces the same structural challenge. The UK, Australian, and Canadian governments all encounter campaign responses and must decide how to report and weight them. The US Federal Communications Commission's (FCC) net-neutrality comment flood is a cautionary tale with universal applicability: any system that accepts unverified submissions at scale is vulnerable to manipulation.
Where things go wrong
Absent public disclosure of the data's limits and provenance checks before acting, an organizer can inflate a campaign's participant count or file under fabricated identities to make it look larger than it is. If the representative entry for that campaign is never checked against its actual submissions, the inflated count drives a decision the agency can't later defend.
Sources
13 references
The instrument, the operating deployment, or the official record itself.
- ACUS Recommendation 2021-1: Mass, Computer-Generated, and Fraudulent Comments
-
Nextgov: House bill targets AI-generated comments (Comment Integrity and Management Act)
A House-passed bill (not enacted law; it lapsed with the 118th Congress) that would have required agencies to publish a single representative version of mass comments, publicly state the number of computer-generated submissions, and tasked the Office of Management and Budget (OMB) with guidance and the Government Accountability Office (GAO) with reporting on AI-generated comment prevalence.
- Australian Senate climate committee — submissions received as standard form letters
-
Australian Senate Environment and Communications Committee — standard and form letters page (2008–10)
Senate environment committees maintain dedicated "Standard and form letters" pages for individual inquiries: the observable, standing listing convention behind Australian committees' form-letter handling, evidencing that the practice is routine rather than improvised per inquiry.
Writing about the subject rather than the framework itself, including vendor commentary.
- NY Attorney General report on fake net neutrality comments
-
NY Attorney General secures $615,000 from companies that supplied fake comments
A second round of settlements two years later, recovering US$615,000 from three further companies — LCX, Lead ID, and Ifficient — that supplied fake comments to the same FCC proceeding. Enforcement against the suppliers of a corrupted record arrives years after the decision that record was used to justify.
- GAO-21-103181: comment integrity