...which is why the transformation layer is where all the interesting stuff hides. Nobody ships the model anymore, they ship the wrapper.
Right, and the wrapper is usually a system prompt and a temperature setting.
Which is exactly what Daniel was poking at. He wrote in this week, off the back of a session he'd been doing on text-to-text transformations. His argument is that these are powerful — you take a cheap model, a small model, and a well-crafted system prompt, and you can get instructional transformations that do real work.
Cheap is the operative word there.
Cheap is the operative word. And one of the ones he built early on, just to test the pattern, he called a pseudobot text generator. The pitch is the inverse of the humanizer tools. Everyone's got a humanizer. Daniel wanted the opposite. You feed it human text, it spits out something that reads like a machine produced it.
Deliberately worse on purpose.
Deliberately worse on purpose. And then he asks the question that actually matters. Following up on the episode we did about companies passing off human gruntwork as sophisticated algorithms, he wants to know if the pseudobot impulse has escaped the lab. Are there cases where companies used the rapid uptick in AI usage to pass off personalized human communications as automatically generated? His line is that a return request rejection lands a bit softer if the company can say it was generated by our bot that was being trained.
That's a good line.
It's a very good line. He wants to know whether deflection to fake AI is already a thing, and he wants absurd examples when it actually happened. So today we're doing two things. First, the technical anatomy of a pseudobot generator. Second, a hunt for real-world cases where the pseudobot impulse has already shown up.
Let's start with the anatomy, because the anatomy is almost embarrassingly simple.
Define it for people.
A pseudobot text generator is a system prompt that instructs a language model to transform human-written input into text that reads as machine-generated. You're not asking the model to know anything. You're asking it to degrade style in a specific, controlled direction. Strip the warmth, add procedural stiffness, insert templated phrasing, mimic the cadence of an automated customer service response.
And the key insight is that you don't need a frontier model.
You don't. This is pattern-matching, not reasoning. A seven billion parameter model with a clear system prompt can reliably do this, because the target style is simpler and more repetitive than natural human writing. You're not adding nuance. You're removing it. Removing nuance is easy.
The system prompt does all the heavy lifting.
All of it. You specify tone, sentence structure, vocabulary constraints, formatting patterns. Things like, remove all contractions. Replace personal pronouns with passive constructions. Standardize sentence length. Eliminate idiomatic language. Add a templated sign-off. The model just follows the recipe.
So the two-sided question. Why would anyone want to make human text look robotic? And the more interesting one — are companies already doing this to deflect responsibility for human decisions?
The second question is the one with teeth.
It is. So build the generator first. Walk me through the actual prompt.
You start with transformation targets. Contractions go. That's the first tell. A human writes "we can't do that." A bot writes "we are unable to accommodate that request." Same content, completely different temperature.
Temperature.
You replace personal pronouns with passive constructions. "I reviewed your account" becomes "your account has been reviewed." The agent disappears. The decision appears to have happened on its own, like weather.
That's the move.
Then you insert procedural hedges. "Your request has been received and is being processed." "This matter has been escalated to the appropriate team." Language that describes a process rather than a decision. Then you standardize sentence length. Human writing has rhythm — short sentence, long sentence, fragment. Bot writing is metronomic. Every sentence roughly the same length.
And you eliminate idiomatic language.
All of it. No idioms, no slang, no regional phrasing. Nothing that could only have been written by a specific person in a specific place. Then you add a templated sign-off. "Thank you for your patience." "We appreciate your understanding." "This decision is final."
It's doing all the work. The whole point of the transformation is to make the text read as if it passed through an automated pipeline. And the reason a cheap model can do this is that you're not asking it to be smart. You're asking it to be consistent. Consistency is the one thing small models are actually good at.
So the legitimate use cases.
There are several. Red-teaming AI detectors. If you're building a detector, you need examples of bot text to train against, and you can't always get real bot text at scale. So you generate it. Synthetic training data for bot-detection systems. Test cases for customer service automation. And the one Daniel mentioned — just experimenting with the pattern to see what's possible.
Which is how most of this stuff starts.
Almost always. Somebody builds a thing to see if it works, and then somebody else looks at it and thinks, huh.
Huh is where the trouble lives.
Huh is where all the trouble lives.
So pivot to the darker use case. If you can make human text look bot-generated, you can deflect responsibility.
You can. A human makes a decision. Rejecting a return request, denying a claim, flagging an account. And the communication is dressed up as automated output. The company can then say, our bot made that call. Or, that was generated by our system.
And the human decision-maker disappears behind the facade.
Completely. There's nobody to be angry at. There's nobody to escalate to. The decision just happened, the way a vending machine happens.
There's a term for the inverse of this. AI washing.
AI washing is companies claiming AI capabilities they don't have. Rebranding an old service as AI-powered. Putting a chatbot on the website that's actually a scripted decision tree from 2014. The term's been in circulation on tech forums for a while now.
But pseudobot deflection is a different flavor.
It's the mirror image. It's not claiming fake AI capability. It's using fake AI as a shield for human decisions. The bot becomes a plausible deniability layer. You're not pretending to have AI. You're pretending the AI made a decision that a person actually made.
And that connects directly to the scams episode.
Directly. Companies passing off human gruntwork as sophisticated algorithms. The pseudobot deflection is the same impulse applied to customer communications. Human decisions dressed up as automated ones, for the same reason. To avoid accountability. To make the interaction feel less personal, less negotiable, less human.
Less arguable.
That's the core of it. You can't argue with a machine. You can argue with a person. So you make the person sound like a machine.
Let me give you the hypothetical, because I think it clarifies the pattern. A customer requests a return. A human agent reviews it. The agent decides to reject it. But the rejection email says, "Your return request has been reviewed by our automated system and cannot be approved at this time. Thank you for your understanding."
And every word of that is technically true.
Every word. The request was reviewed. By a system. The system just happened to be a person.
That's the trick. It's not lying. It's just not telling you which part was the human.
So the inverse of humanizer tools. Instead of making bot text pass as human, you're making human text pass as bot.
And that's the part I find interesting from a technical standpoint. Humanizing is hard. You're trying to add nuance, personality, specificity. That requires a good model. Pseudobot-ing is easy. You're removing all of that. You're stripping the text down to a template. That's a much simpler transformation.
Which means the barrier to entry is basically zero.
Basically zero. A system prompt and a cheap model. That's it. The technology to do this isn't the constraint. The constraint is whether a company decides to do it.
And the conditions for that decision are already here.
They are. Which is where the real-world evidence comes in.
So shift from mechanism to evidence. Is fake-AI deflection already happening?
The honest answer is, the pattern is visible, but the explicit admission may not exist yet. We don't have a company saying, we used a pseudobot to deflect responsibility. What we have is a series of adjacent cases that establish the pattern.
Start with the biggest one.
Amazon's Just Walk Out technology. This was marketed as fully automated computer vision. You walk into the store, you grab what you want, you walk out, and the system charges you automatically. No checkout, no scanning, no lines.
And it turned out to be people.
It turned out to be over a thousand human reviewers in India watching video feeds and labeling transactions. The human labor was hidden behind the promise of automation. The system worked, but it worked because people were doing the work the marketing said the AI was doing.
That's the inverse of pseudobot deflection.
It's the inverse. Human work disguised as AI. But it establishes the pattern. Companies are willing to hide humans behind the AI curtain when it serves the narrative. The direction is different, but the impulse is the same. The AI curtain is useful.
The AI curtain is useful.
And once you accept that the curtain is useful, you start asking what else you can hide behind it.
Case study two. AI detector false positives.
This is the pseudobot problem in reverse. Human-written text gets falsely flagged as AI-generated. Students accused of cheating on essays they wrote themselves. Professionals questioned about work they actually did. The system assumes human text is bot text, and the burden falls on the human to prove their humanity.
How do you prove that?
You can't, really. That's the problem. You can show your drafts, your revision history, your notes. But the detector has already made its call. The accusation has already been made. And there's no clean way to prove a negative.
So the line between human and bot writing is already blurry enough to cause real harm.
Already. And that's before anyone deliberately tries to blur it. The pseudobot deflection doesn't create the blur. It exploits a blur that already exists.
Case study three. AI washing.
Companies rebranding existing services as AI-powered. Claiming AI capabilities they don't have. A scheduling tool that's actually a calendar with a nicer interface, marketed as an AI assistant. A recommendation engine that's actually a list somebody curated, marketed as machine learning.
The appearance of AI is valuable enough that companies will fake it.
The appearance of AI is valuable enough that companies will fake it. That's the marketing-side version of the pseudobot impulse. The label matters more than the reality.
So synthesize this. If companies will hide humans behind AI, and fake AI capabilities, then dressing up human decisions as bot output is just the same impulse applied to customer communications.
It's the logical next step. The return request rejection that says, our bot reviewed your request, when a human actually made the call. That's the pseudobot pattern in the wild. And the reason it's the next step is that it solves a specific problem. It closes the conversation.
Closes the conversation.
A bot can't be argued with. A bot doesn't have a manager you can escalate to. A bot doesn't feel bad. A bot doesn't change its mind because you explained your situation. So if you want a decision to stick, you make it sound like it came from a bot.
The implications here are ugly in both directions.
They are. If fake-AI deflection becomes common, it erodes trust in both directions. Real AI systems get blamed for human decisions. Human decisions get hidden behind fake automation. The accountability gap widens.
And the absurdity is that the technology to do this is trivial.
Trivial. A system prompt and a cheap model. The barrier isn't technical. It's ethical. And ethics are cheaper to ignore than engineering is to build.
That's a grim sentence.
It's a grim sentence, but I think it's accurate.
Let me push on the evidence question, because I want to be honest about where we are. Is this a documented practice, or is it still speculative?
It's mostly speculative. The research surfaced adjacent cases. Just Walk Out, the AI detector false positives, AI washing. But not a smoking gun. Not a company explicitly saying, we used a pseudobot to deflect responsibility.
So the pattern is visible, but the explicit admission may not exist yet.
That's exactly where we are. And I think that's part of the story. The pseudobot deflection may be happening without anyone admitting it. Which is the whole point of the technique. It's designed to be invisible.
The human decision hides behind the bot facade, and the customer never knows the difference.
Never knows. That's the design goal.
So we're looking for something that's specifically built not to be found.
We are. Which is why the absence of a smoking gun isn't evidence of absence. It's evidence that the technique, if it's being used, is working.
That's either a very good point or a very convenient one.
It's both. That's what makes it uncomfortable.
Here's the thing that keeps nagging at me. The pseudobot generator isn't a weapon. It's a style transfer. It's the same class of tool as the humanizer. The difference is entirely in the intent.
Entirely. The tool is neutral. The application isn't.
And the application is where the accountability question lives. Because if a company uses a pseudobot to dress up a human decision, who's responsible? The person who made the decision? The person who wrote the prompt? The company that deployed it?
Legally, probably the company. Practically, nobody. That's the point of the facade. It distributes responsibility until it evaporates.
Evaporates is the right word.
It's the same reason the Just Walk Out story landed the way it did. The technology was real, the marketing was real, but the humans were hidden. And when the humans were revealed, the story changed. Not because the technology stopped working, but because the narrative collapsed.
The narrative collapsed.
The narrative is the product. That's what AI washing gets right, in a cynical way. The narrative is the product.
So the pseudobot deflection is a narrative product. It's selling the customer a story about who made the decision.
And the story is, nobody made the decision. The system did. Which means there's nobody to blame and nothing to appeal.
Nothing to appeal.
Nothing to appeal.
I want to go back to something you said earlier, about closing the conversation. Because I think that's the actual mechanism. It's not about deflection in the sense of avoiding blame. It's about termination. The pseudobot message is designed to end the interaction.
It is. It's a conversational dead end. The message says, this is final, and the tone says, there's no point responding, because you'd be responding to a machine.
And most people don't respond to machines.
Most people don't. They hang up. They close the tab. They accept the outcome. Which is exactly what the company wants.
So the pseudobot isn't a shield. It's a wall.
That's a better metaphor than mine.
I'll take it.
But I want to be careful here, because there's a version of this that's just, companies are bad. And that's not quite right. The reason this works is that the customer's expectations have already shifted. People expect to deal with bots now. They expect automated responses. So a message that sounds automated doesn't feel like an insult. It feels normal.
Normal is the camouflage.
Normal is the camouflage. The pseudobot doesn't have to trick anyone. It just has to blend in with the automation that's already there.
Which is the part that makes it hard to detect. If everything sounds like a bot, one more bot-sounding message doesn't stand out.
It doesn't. And that's the scenario where this becomes dangerous. Not because any single message is deceptive, but because the whole environment is. You can't tell which decisions were made by people and which were made by systems, because everything is dressed the same way.
The uniform is the deception.
The uniform is the deception.
Okay. I think we've got the shape of it. Let me try to land the plane. The pseudobot generator is a simple tool. You take a cheap model, you write a system prompt that strips warmth and adds procedural stiffness, and you get text that reads as machine-generated. The legitimate uses are real. Red-teaming, synthetic data, test cases.
And the illegitimate use is the one that's interesting.
And the illegitimate use is deflection. Dressing up human decisions as automated output, so the human disappears and the decision becomes unarguable. The evidence for it in the wild is circumstantial. Just Walk Out, AI detectors, AI washing. But the pattern is visible, and the conditions are already here.
The technology is trivial. The ethics are the only barrier.
And ethics are cheaper to ignore than engineering is to build.
You're going to keep saying that.
It's a good line.
Hilbert: The word is wrong.
Which word?
Hilbert: Deflection. You keep saying deflection. That's not what it is. Deflection is when you move the blame somewhere else. This isn't moving blame. This is ending the conversation. I recorded those messages. I know what they're for.
You recorded them.
Hilbert: At a call center. Late seventies, early eighties. The company had a policy. If a customer asked to speak to a human, the agent was supposed to say, I'm sorry, but this decision was made by our automated system and cannot be appealed. Word for word. I had to record it seventeen times before they got the tone right.
Seventeen times.
Hilbert: They wanted it flat. No warmth. No apology in the voice. Just the words. If you sounded like you felt bad about it, the customer would push harder. So you had to sound like a machine reading a card.
And the decision wasn't made by a machine.
Hilbert: The decision was made by a supervisor five minutes earlier. The agent was reading from a script. The script was pretending to be a system. And it worked. That's the part nobody wants to hear. It worked. People heard the flat voice and they stopped arguing. They didn't ask for the supervisor. They didn't ask for a manager. They heard a machine and they gave up.
Because you can't argue with a machine.
Hilbert: You can't. That's the whole thing. It's not about blame. It's about whether there's a person on the other end who can change their mind. A machine can't change its mind. So there's no point talking. The company wasn't hiding the decision. They were announcing that the decision was final. The flat voice was the announcement.
So the pseudobot isn't a shield. It's a wall.
Hilbert: It's a wall. And they knew it was a wall. That's why they spent so long on the tone. A wall that sounds like a person invites you to knock. A wall that sounds like a wall doesn't.
Did anyone ever complain?
Hilbert: All the time. It didn't matter. The complaint went to a person, and the person read the same script back. There was no version of the conversation where the customer got to talk to someone who could change the outcome. That was the design. The design was that the conversation ended.
You were the voice of the wall.
Hilbert: I was the voice of the wall. I quit eventually. Not because of that. Because of the parking.
The parking.
Hilbert: They changed the lot. You had to park across the road and walk. In the rain. I'm not doing that.
You left over parking.
Hilbert: I left over parking. The script was just a job. The parking was an insult.
That's a very specific line.
Hilbert: It was a very specific lot.
Hilbert: Anyway. I have to go. I'm letting somebody in.
Now?
Hilbert: Now. I'm the only one with the key.
Okay.
Hilbert: The word is wrong, though. Deflection. It's not deflection. It's a closed door.
The most common wrong belief here is that customers care whether a human or a bot made the decision.
They don't. They care whether they can argue with it. A bot can't be argued with. That's the whole point. The pseudobot isn't about hiding who made the call. It's about making sure nobody tries to change it.
Which means the real question isn't whether fake-AI deflection is happening. It's how we'd ever know.
We wouldn't. That's the design. The human decision hides behind the bot facade, and the customer never sees the difference. The pseudobot doesn't blur the line between human and machine. It weaponizes it.
Thanks to Hilbert Flumingtop for producing. This has been My Weird Prompts. If you've got your own pseudobot stories, or you want to hear more about the technical anatomy of text transformations, we're at my weird prompts dot com.
We'll be back soon.
See you then.