Jerry Falade had the kind of debut novel publishing claims to spend its life looking for. Call Me, I’ll Hide the Body drew a 14-way auction in the United States. Minotaur, a Macmillan imprint, reportedly offered more than $2 million. British publishers were making six-figure bids. Agents and editors had already read the manuscript closely enough to decide it was extraordinary, commercial, and worth fighting over. Then somebody asked whether artificial intelligence had been involved. [1]
No detector started the process. Falade’s representatives initially accepted his assurance that AI had not been used as a resource in the writing or editorial process. His agent later said aspects of that account changed after another meeting. The agency concluded that it could no longer authenticate how the manuscript had evolved from origin to completion, withdrew it from sale, and ended its representation. Falade denies using AI to write the novel and has alleged racial bias. The available public record does not resolve either dispute, and this argument does not require it to. A manuscript carrying a reported offer above $2 million disappeared from the market while the underlying authorship question remained unsettled. [1]
Falade does not have to be proved innocent for the mechanism to matter, and his former representatives do not have to be proved wrong. The commercial consequence did not wait for either determination. Its literary quality had already been tested. Its market value had already been tested. Once enough uncertainty accumulated around the manuscript’s provenance, the operative question changed from whether the work was good to whether the person behind it could provide an account of how it came into existence that the institution considered trustworthy enough to proceed.
The artifact had become evidence about the person. Once that happens, the consequential question is no longer confined to what the work contains. It becomes what an institution is permitted to infer about a person from the history, associations, and tools behind the work. J. Edgar Hoover spent much of his career building institutions around that kind of inference.
Before McCarthy Came Hoover
In 1919, more than thirty years before Joseph McCarthy became synonymous with the Second Red Scare, Hoover was a young Justice Department lawyer leading the General Intelligence Division. He amassed intelligence on suspected radicals during the First Red Scare and helped plan the Palmer Raids. The FBI’s own history now describes those raids as poorly planned and heavily criticized for civil-liberties abuses against thousands of people caught in the government’s sweep. [2]
Hoover took control of the Bureau of Investigation in 1924 and remained at the head of what became the FBI until his death in 1972. During those forty-eight years, the Bureau developed nationwide identification systems, professionalized investigative practice, expanded its intelligence capabilities, became the country’s lead domestic counterintelligence institution during World War II, and entered the Cold War with an organizational capacity for files, investigations, information exchange, and institutional memory that did not have to be invented when political fear returned to domestic life. [3]
That capacity matters more to this argument than McCarthy’s personality. McCarthy would eventually demonstrate what accusation could do when turned into theater. Hoover represents something more durable. He represents suspicion after it acquires an institution capable of collecting it, retaining it, relating it to other information, and handing the result to somebody empowered to act.
In March 1947, President Harry Truman created the federal employee loyalty program through Executive Order 9835. The order required loyalty screening across the federal civil service. Among the criteria that could support a finding of disloyalty was “membership in, affiliation with or sympathetic association” with organizations designated by the attorney general as Communist, fascist, totalitarian, subversive, or otherwise within the order’s scope. The Attorney General’s List of Subversive Organizations, or AGLOSO, was publicly released that December, more than two years before McCarthy made his first famous allegations of widespread Communist infiltration in 1950. [4]
The chronology is important because the machinery preceded the spectacle. The government did not have to begin with a proved act of espionage, sabotage, or disclosure of national secrets. Association itself had acquired evidentiary force. A person’s membership, affiliations, sympathies, contacts, and relationships could become part of the administrative determination of whether that person remained sufficiently trustworthy for government service. [4]
Hoover was not a peripheral participant in the creation of that environment. National Archives material based on White House counsel Clark Clifford’s later account describes Hoover and Attorney General Tom Clark repeatedly pressing Truman to expand FBI investigative authority. Hoover supplied Clark with memoranda concerning suspected subversive organizations and the people affiliated with them. The resulting loyalty program subjected roughly two million federal employees, as well as future applicants, to investigation. [4]
The institutional division of labor was almost elegant. The FBI conducted initial investigations. Employing agencies and the Loyalty Review Board made the formal loyalty determinations. When the program drew criticism, Hoover emphasized that the Bureau made no recommendations about whether people were loyal. It “only reported the facts.” [5]
That sentence contains the architecture. The investigator can claim it does not punish. The decision-maker can claim it merely acts on information supplied by the investigator. A third institution can control employment, access, publication, contracting, or reputation. Every participant can describe its own authority as bounded while the person at the center experiences one continuous consequence.
Hoover’s rhetoric showed the model of threat that made this architecture useful. In 1947 he described American communism as “boring its way through our land like a termite.” [6] A termite is a concealed contaminant. You do not wait for structural collapse to decide whether one exists. You open walls. You look for traces. You follow pathways. You treat apparently incidental evidence as a possible sign that the real danger is hidden beneath the visible surface.
Under that model, association changes meaning. Membership matters. Friendship matters. Attendance matters. Sympathy matters. Contact with somebody already under scrutiny matters. The absence of a proved criminal act does not necessarily end the investigation because the institution has defined the threat as something that may conceal itself behind otherwise ordinary relationships.
AGLOSO showed what happens next when a category acquires enough institutional authority. The list had been created to support federal loyalty determinations, but state and local governments, the military, defense contractors, hotels, the Treasury Department, the State Department, and private employers began using it for their own purposes. The National Archives describes the published list as effectively becoming an official blacklist whose influence escaped the federal employment system that created it. [4]
No central authority had to order every downstream decision. The category had acquired authority, and other institutions learned what they could do with it.
The loyalty program also contained an asymmetry that should feel less historical than it does. Employees formally had rights to notice and hearings, yet security considerations could restrict what they were permitted to know. The FBI could protect confidential informants. National Archives records show that accused employees often received vague charges, were not told who had supplied allegations against them, and could not cross-examine the unknown sources whose information threatened their employment. [4]
The institution could hold a dossier about you that you could not meaningfully inspect while still expecting you to answer what it believed the dossier established. That is more than a historical due-process failure. It is a warning about any system in which one side receives a technical or investigative signal, interprets it privately, and then requires the other side to prove why the resulting conclusion should not be believed.
By the time Joseph McCarthy stepped onto the national stage, America already had the files, the lists, the investigators, the loyalty procedures, the association criteria, and the institutional pathways through which suspicion could move. McCarthy did not build the stage. He discovered how much could be done under the lights.
McCarthy Made Suspicion Spectacle
McCarthy’s power came from accusation performed publicly. Beginning in 1950, he claimed Communist infiltration throughout the federal government and turned the suggestion of concealed disloyalty into a political weapon. For roughly four years he dominated national attention until the Army-McCarthy hearings exposed his conduct to a mass television audience and the Senate formally condemned him in December 1954. [7]
The House Committee on Un-American Activities operated separately from McCarthy’s Senate investigations, and preserving that distinction makes the mechanism clearer. Hoover’s FBI supplied investigative capacity and information. McCarthy supplied political spectacle. HUAC supplied public interrogation. Loyalty boards supplied administrative adjudication. Private employers supplied economic punishment. These were different institutions, which is precisely why the system could become larger than any one of them.
The Library of Congress preserves contemporary descriptions of HUAC’s “name game.” Witnesses were pressed to identify associates, who could then be summoned and asked to identify more people. Hoover’s FBI supplied material from its “raw files.” The inquiry could therefore expand through the social relationships of the people already under suspicion, producing an ever-widening map of people considered worth examining. [8]
The logic is almost automatic once association carries weight. Who recruited you? Who attended the meeting? Who introduced you? Who else was there? Who knew? Who agreed? Who can corroborate the story? The object of inquiry has ceased to be a single act. It has become the person’s location inside a network.
Refusal had consequences too. The Hollywood Ten refused to answer HUAC questions concerning their political beliefs and Communist Party associations. They were imprisoned for contempt of Congress and became the first victims of a major-studio blacklist. The hearing therefore presented more than a request for information. It created a test in which cooperation with the investigative apparatus could itself become part of the price of remaining professionally viable. [8], [19]
Private institutions made the mechanism even more efficient. Red Channels, published in 1950 by three former FBI agents, listed 151 people in broadcasting along with organizations and activities with which they had reported associations. Radio and television employers adopted the publication as a blacklist. Actor Sam Jaffe was subpoenaed after being named. His subpoena was later discharged, but the legal resolution did not restore what suspicion had already taken. He was denied work in radio, television, and motion pictures for seven years. [9]
Hazel Scott’s case moved faster. Scott was a celebrated pianist, civil rights activist, and the first Black person to host her own television program. After Red Channels named her, she voluntarily appeared before HUAC to defend herself and condemn the accusations. The Hazel Scott Show was canceled one week later, and her concert bookings declined. [10]
Jaffe and Scott reveal something more important than whether every accusation made during the period was false. Practical punishment and formal adjudication had become different systems. A subpoena could be discharged after seven working years were gone. A performer could answer the accusations and still lose the economically significant opportunity before anything resembling a final judgement arrived.
That is also why the era’s famous grammatical construction deserves attention. In Brown v. United States, the Supreme Court record preserves the government asking a witness, “Are you now or have you ever been, a member of the Communist Party of the United States?” When Brown again refused to answer questions about Communist activities and associations after the court ordered her to respond, she was held in contempt and sentenced to six months’ imprisonment. [11]
The tense reaches backward. Once association itself becomes consequential, the institution is no longer satisfied by the present artifact or the present act. History becomes evidence. Past memberships matter. Previous associations matter. Old conversations matter. The people around you matter. Refusal to expose those relationships can acquire meaning of its own.
The people who are never called to testify are still watching. A loyalty system does not need to investigate everybody to alter everyone’s behavior. People learn which meetings not to attend, which petitions not to sign, which colleagues not to defend, and which people become expensive to hire. The hearing applies direct pressure to a few. The visible consequences teach everyone else.
Europe Builds the Mark
Article 50 of the European Union AI Act addresses a legitimate and very different problem. Providers of AI systems, including general-purpose AI systems, that generate synthetic audio, image, video, or text content must ensure that covered output is marked in machine-readable form and detectable as artificially generated or manipulated. The law requires those technical measures to be effective, interoperable, robust, and reliable as far as technically feasible. It also expressly excludes standard assistive editing and systems that do not substantially alter the user’s input or its semantics. [12]
The transparency obligations began applying on August 2, 2026. The Commission describes a limited transition until December 2 for the marking and detection obligations of systems already on the market before August 2, and says violations can carry fines up to EUR 15 million or 3 percent of worldwide annual turnover. [13]
There are good reasons for the rule. Synthetic media can enable fraud, impersonation, fabricated evidence, misinformation, manipulation, and consumer deception at scale. Reliable provenance can matter enormously when somebody needs to know whether a purported photograph, recording, public statement, or document was machine-generated or manipulated. The European framework is responding to a real information-integrity problem, not inventing one for regulatory exercise. [12], [13]
The Code of Practice on Transparency of AI-Generated Content gives providers and deployers one voluntary route for demonstrating compliance with portions of Article 50. The underlying legal obligations remain mandatory for entities within scope, including non-signatories. [14] Anthropic is among the companies that signed the Code. [15]
Anthropic’s implementation makes the issue concrete. Its guidance says supported Claude models launched on or after August 2 carry machine-readable marking. Text can carry an imperceptible embedded watermark at the model level, while supported files can carry digitally signed provenance metadata using the C2PA standard. Marking applies across supported Claude products and cloud-partner surfaces, and Anthropic says it plans to support detection of those marks by users and other third parties. [16]
The limitations in Anthropic’s own documentation are more important than the mechanism. Detecting a mark indicates that content may have been processed by Claude. It does not establish complete provenance. Claude may have proofread text, translated it, summarized it, converted it, or otherwise processed material whose underlying ideas, language, or data came from somebody else. Marks may disappear through heavy editing, paraphrasing, translation, short passages, stripped metadata, or unsupported formats. Absence of a mark therefore does not establish absence of machine involvement either. [16]
The provider has placed a boundary around its own evidence, and that boundary is where everyone downstream should begin. Washington State University gives us a different technical receipt. WSU was using Turnitin’s probabilistic AI detector, not provider-embedded provenance, and those mechanisms should not be conflated. In February 2026 the university canceled its Turnitin AI Detection contract. Between 2023 and 2025, 33 percent of Academic Integrity Hearing Board cases involving alleged inappropriate AI use ended in findings of “not responsible” when AI detection had been submitted without other supporting evidence. [17]
WSU also identified an information asymmetry. Turnitin’s detector output was instructor-facing rather than student-facing, meaning the instructor could see the technical suspicion before the student had any opportunity to know what had been flagged. WSU maintained its rule that detector output could not serve as the sole basis for an academic-misconduct case. [17]
The comfortable lesson practically writes itself. Probabilistic detectors generate false positives. Institutions can overtrust them. Students can be dragged into disciplinary processes by technical output that cannot bear the weight being placed on it. Better evidence should make the system safer. Replace probabilistic suspicion with reliable provenance. Eliminate the false positive and let the machine answer the factual question cleanly.
Now make the detector perfect.
Assume there are no false positives. No stylistic classifier. No probability score. No debate about whether the prose merely resembles machine writing. The provenance system works exactly as designed, the mark survives intact, and the institution interprets its narrow technical meaning correctly. Claude touched the work.
The false-positive defense is gone, but the harder question survives. What has actually been proved? If the disputed fact is whether Claude processed the artifact, perhaps the mark has established everything necessary. If the disputed issue is authorship, plagiarism, deception, competence, fraud, cheating, or misconduct, the signal establishes one fact inside a much larger judgement.
Authorship lives across Contribution, Judgement, Control, Representation, and Responsibility. Who supplied the substance? Who decided what mattered? Who controlled what remained in the finished work? How was the work and process represented where that representation was material? Who accepts responsibility when the result is wrong?
Someone can use AI and exercise all five. Someone else can type every character personally while plagiarizing, ghostwriting, fabricating evidence, laundering another person’s judgement, or representing competence they do not possess. Keystroke purity has never been a sufficient theory of authorship. Accurate provenance cannot make it one.
A bad detector can place an innocent person into the wrong category. A perfect provenance system can make the category easier to enforce. The second problem survives every engineering improvement we make to the first.
When Provenance Becomes a Loyalty Test
Begin with a technically accurate proposition. Claude processed this document. A university can reasonably ask whether that processing violated an academic rule. A publisher can ask whether it conflicts with an author’s representations. An employer can ask whether the artifact demonstrates the employee’s competence. A client can ask whether a contractual promise was breached.
Those are legitimate questions, but the mark has not answered them. The institution answers them when it moves from “Claude processed this” to “AI wrote this,” then to “you did not really write it,” and from there to cheating, fraud, incompetence, dishonesty, breach, or disqualification. Each step may be justified in an individual case. None arrives automatically inside the first proposition.
Responsibility can disappear precisely where the consequence becomes largest. Anthropic can accurately say it provides provenance rather than academic or professional judgement. The university enforces integrity. The publisher manages commercial risk. The employer evaluates competence. The client enforces the contract. Everyone owns a bounded function while the person under scrutiny receives the combined verdict.
Hoover’s old procedural defense should sound less antique by now. The FBI merely reported the facts while somebody else made the determination. The statement could be completely true while leaving the governing question untouched. Who owns the distance between the fact collected and the consequence imposed?
Once AI association becomes sufficiently consequential, the inquiry can expand. Did you use Claude on this paragraph? Was it generation, editing, translation, research, or critique? Which model? What prompt? Was the use authorized? Did your editor know? Did the coauthor use it? Did another employee process the file? Have you used AI on previous work? Can you produce the drafts, prompts, timestamps, notes, editor correspondence, and version history?
The social graph is waiting behind those questions. Who approved the process? Who else knew? Which collaborators use the same workflow? Did somebody else introduce the marked material? Did the professor authorize it? Did the team violate policy? A dispute that begins with one artifact can become an inquiry into the people surrounding it because questions about association naturally generate further questions about association.
Refusal creates another source of ambiguity. An author may have legitimate reasons not to surrender private prompts. An employee may have confidential material mixed through an AI history. A student may not have saved intermediate drafts because ordinary creative work was never designed to function as a future forensic archive. The institution may nevertheless interpret each absence as additional uncertainty, even though the original technical evidence never established the larger accusation the person is now being asked to rebut.
When suspicion becomes infrastructure, innocence becomes paperwork.
The paperwork changes behavior before accusation. Writers preserve drafts because they may later need to establish how the work evolved. Students retain prompts and screenshots. Engineers discover that version control has become an accidental alibi. Browser trails, handwritten notes, discarded paragraphs, Git commits, editor messages, timestamps, and intermediate files acquire a second purpose. Ordinary creative debris becomes exculpatory evidence.
The burden has quietly moved. The institution may need enough evidence to begin an inquiry. The person may need an archive of their own cognition to make it stop. The system never has to declare AI use forbidden in the abstract if enough people learn that association with it is expensive to explain.
Falade’s case belongs here precisely because the underlying dispute remains unresolved. Once the AI question surrounded his manuscript, the publishing market did not have to answer the ultimate authorship question before a multimillion-dollar opportunity disappeared. Sam Jaffe’s subpoena could be discharged without returning seven years of work. Hazel Scott could defend herself before HUAC and watch her television program disappear a week later. These are different institutions, different histories, and radically different levels of harm, but they expose the same structural possibility. Practical punishment can arrive before the contested proposition receives anything resembling final adjudication. [1], [9], [10]
People watching those cases learn. A writer can decide legitimate AI assistance is not worth the possibility of suspicion. A student can conceal permitted use because disclosure feels dangerous. An employee can avoid a useful tool because explaining the provenance later looks more expensive than losing the benefit now. Collaborators can begin treating one another as provenance risks.
No law needs to order that behavior. An institution only has to make the association expensive enough.
I Use AI
I use AI. I use it for research, interrogation, counterargument, analysis, editing, structure, synthesis, and sometimes drafting. There are pieces where it touches almost nothing and pieces where it participates much more heavily. There are also pieces I simply write. None of those process facts settles authorship on its own.
The relevant questions are whether I contributed the substance I represent as mine, exercised the judgement, retained control over the finished artifact, represented the process honestly where that representation is material, and accept responsibility for what carries my name. If Claude processed a passage and a reliable provenance mark can establish that fact, let the mark establish it. I do not need the mark to lie on my behalf. I need the institution interpreting it to stop where the evidence stops.
That boundary matters because provenance gives institutions something they value for understandable reasons. It makes a messy spectrum legible. Legibility permits classification. Classification permits routing. Routing permits policy at scale. Those capabilities can solve genuine problems, and they can also conceal the moment when a description of an artifact becomes a judgement about a person.
Red Scare classifications performed a related administrative function. Membership, affiliation, sympathetic association, presence on a list, attendance at a meeting, or connection to an organization made political relationships easier to categorize. Some of those associations were real. Some targets really were Communist Party members. Some attended meetings. Some knew people inside movements under investigation. Accuracy about association still did not establish espionage, sabotage, disloyalty, or the legitimacy of every consequence imposed upon the person carrying the association.
That is the point the perfect detector forces us to confront. Better identification can improve the quality of provenance evidence. It cannot decide what provenance should be allowed to mean.
Who Owns the Inference
There are AI-use rules worth enforcing. An unaided examination can legitimately require unaided work. A contract can prohibit particular forms of automated generation. A lawyer who submits fabricated authorities has committed a professional failure regardless of whether a model produced them. Synthetic media presented as authentic evidence creates exactly the kind of provenance problem Article 50 is intended to help address.
Those legitimate rules make the inferential boundary more important. If a mark establishes that Claude processed a document and an institution believes a rule was violated, the institution should have to identify the rule, establish the conduct the rule prohibits, connect the evidence to that conduct, distinguish generation from editing or other assistance where the policy requires the distinction, and expose enough of its reasoning for the affected person to challenge it.
A nominal human reviewer is insufficient if that reviewer simply ratifies the machine signal. The person being judged should know what was detected, how the institution interpreted it, which rule made that interpretation consequential, what contrary evidence was considered, who owns the decision, and what remedy exists when the judgement fails.
The old loyalty-program information asymmetry belongs here as a warning rather than an equivalence. Federal employees could be required to answer allegations built partly from information and sources they were not permitted to inspect. Modern institutions should not demand radical transparency from the person while keeping the detector, policy interpretation, inferential chain, or appeal process opaque. [4]
If an institution wants to move from “Claude processed this” to “you violated our rule,” every evidentiary step between those propositions belongs to the institution. It cannot outsource judgement to a watermark and then describe the resulting consequence as something the technology discovered.
McCarthy Was Replaceable
McCarthy’s political power collapsed after the Army-McCarthy hearings, and the Senate condemned his conduct on December 2, 1954. Hoover remained FBI Director until his death in 1972. [3], [7]
That chronology does not make every later FBI domestic-intelligence operation an extension of McCarthyism. COINTELPRO began in 1956 under different authorities and later expanded far beyond the Communist Party. The FBI’s own history now acknowledges that agents sometimes infiltrated organizations, sowed discord, and attempted to discredit groups even where there was little or no evidence of unlawful activity. [18]
The point is institutional rather than genealogical. Spectacle and infrastructure have different lifespans. A demagogue requires attention. An administrative capability requires files, procedures, classifications, investigators, interfaces, information flows, and organizations willing to use what it produces.
McCarthy shows what accusation looks like when one man turns suspicion into theater. Hoover shows what suspicion looks like after it acquires institutional capacity and continuity. HUAC shows what happens when association becomes interrogation. Red Channels shows how private organizations can convert the category into employment consequence. The loyalty program shows what happens when the institution possesses more of the evidentiary apparatus than the person it expects to answer.
Article 50 is not McCarthyism. Anthropic’s watermark is not a blacklist. The European Union has not declared AI users suspect people. Article 50 addresses legitimate transparency problems and creates a far narrower technical category than a loyalty program. Those distinctions are what make the comparison useful rather than theatrical.
The warning exists downstream. Europe has mandated machine-readable identification for covered synthetic content. Anthropic is implementing one response to that regulatory environment. Institutions will increasingly be able to discover some forms of AI involvement without first asking the creator of the artifact. That ability may solve serious problems.
It also makes the opening question of a loyalty inquiry very cheap. Was AI there? Sometimes the machine will be able to answer yes. The consequential questions remain entirely human. Who authored the work? Who exercised the judgement? What rule was actually violated? Was anybody deceived? What consequence is justified? What evidence can the person inspect? Who owns the inference? Who owns the error?
The category can now travel inside the artifact itself. That is technologically new and institutionally familiar. The most dangerous lists in American history were never dangerous merely because somebody wrote down the names. They became dangerous when institutions learned what the names permitted them to do.
References
[1] E. Loffhagen, “$2m crime novel deal collapses amid questions over AI use,” The Guardian, Jul. 31, 2026.
[2] Federal Bureau of Investigation, “History of the FBI,” FBI.
[3] Federal Bureau of Investigation, “J. Edgar Hoover, May 10, 1924 - May 2, 1972,” FBI.
[4] R. J. Goldstein, “Prelude to McCarthyism: The Making of a Blacklist,” Prologue Magazine, vol. 38, no. 3, Fall 2006.
[5] National Archives and Records Administration, “Classification 121: Loyalty of Government Employees (Obsolete).”
[6] J. E. Hoover, “Red Fascism in the United States Today,” FBI Law Enforcement Bulletin, Mar. 1947.
[7] United States Senate, “The Censure Case of Joseph McCarthy of Wisconsin (1954),” Senate Historical Office.
[8] Library of Congress, “‘Fire!’ - Herblock’s History: Political Cartoons from the Crash to the Millennium.”
[9] Library of Congress, “A Climate of Fear,” Hope for America: Performers, Politics and Pop Culture.
[10] Library of Congress, “Hazel Scott, now playing!,” Feb. 2, 2021.
[11] Brown v. United States, 356 U.S. 148 (1958).
[12] European Parliament and Council of the European Union, “Regulation (EU) 2024/1689, Article 50,” Official Journal of the European Union, 2024.
[13] European Commission, “Transparency obligations under Article 50 of the AI Act,” 2026.
[14] European Commission, “Code of Practice on Transparency of AI-generated Content,” 2026.
[15] European Commission, “Strong backing for the Code of Practice on Transparency of AI-generated Content,” 2026.
[16] Anthropic, “How Claude marks AI-generated content,” Claude Help Center, 2026.
[17] Washington State University Office of the Provost, “Cancellation of Turnitin AI Detection Software and the Use of AI Detectors for Academic Integrity,” Feb. 11, 2026.
[18] Federal Bureau of Investigation, “And Justice for All, 1954-1971,” History of the FBI.
[19] U.S. Capitol Visitor Center, “Sentencing Card for Dalton Trumbo, n.d.,” Communism in Hollywood.



