Contents
- Who Is Excluded by AI Slop Countermeasures?
- May: A Dialogue with arXiv
- How the Standard for 'Extreme' Changed in Four Months
- References
Who Is Excluded by AI Slop Countermeasures?
One problem with AI slop is that platforms unable to withstand mass submissions strengthen their countermeasures, while legitimate users bear the resulting side effects. The AI Slop Side Effect Database maintained by UTIE Instruments Inc. records secondary harms including exclusion from Zenodo search results, false positives from AI-detection tools, moderation disorder on Stack Overflow, and human creators being swept up in blanket bans on AI-generated material. [2] In academia, this problem falls especially heavily on newcomers. Researchers already affiliated with universities or research institutions, with publication and citation histories, naturally also benefit from using AI as a research aid. At the same time, they begin with institutional email addresses, prior research records, and collaborators as signals of credibility. Even when both groups use AI in similar ways, increased productivity among established researchers is treated as a benefit of AI adoption, while only submissions from unknown newcomers are more likely to enter a review route on the suspicion that they may be AI slop. This should not be explained solely as a matter of individual preference. From an operator's perspective, it is understandable to let contributors with histories predating widespread LLM use pass quickly while scrutinizing new submitters more carefully. Yet this crude form of AI-slop control becomes a barrier to entry for newcomers, whether intentionally or not.
May: A Dialogue with arXiv
In May 2026, the company discussed arXiv moderation and AI-slop countermeasures with Thomas G. Dietterich, Chair of arXiv's Computer Science Section. Professor Dietterich is a leading figure in machine-learning research and served as President of AAAI from 2014 to 2016. [3] The exchange continued for four days and focused mainly on arXiv's operational burden and where identity verification should occur. In arXiv's day-to-day operations, submission problems in the AI era were already appearing not as abstract future predictions but as concrete burdens involving identification of individuals, sockpuppets, verification of first-time submitters, and moderators' time. The company again wishes to thank Professor Dietterich for candidly explaining these operational realities.
Professor Dietterich identified two major problems: arXiv is under continuing attack from paper mills and sockpuppet accounts, and there are no certified identities on the internet. He also explained that first-time submitters consume a large share of moderators' time. He further stated that, among arXiv user groups, single-author papers from independent researchers have the highest rate of being judged low quality. At the same time, he noted that arXiv is an open venue that does not require a degree or institutional affiliation, and asked us how independent researchers could be supported. [4]
If the problem is the difficulty of identity verification itself, the answer is not to use university email addresses as a proxy. Identity verification should instead be available regardless of institutional affiliation. If submission limits are tied to one real person who has passed KYC, it becomes difficult to continue mass submissions simply by recreating accounts. Conversely, if a submission limit applies only to an account without identity verification, mass AI producers can evade it by creating another account. In this sense, the KYC contemplated by Flow-by-Flow can prevent affiliation from being used as a crude proxy for trust. University professors, corporate researchers, and independent researchers would all begin under the same condition: one verified person. The AI Slop Side Effect Database likewise notes that limits imposed without KYC are easy for mass producers to evade while disproportionately constraining legitimate users who already operate under their real identities. [2]
Professor Dietterich also said that he had heard rumors of paper-hosting sites that would exclude first-time submitters and independent researchers entirely and require an existing peer-review record as a condition of submission. The company had been observing arXiv's practical operations since early 2026. In cs.AI in particular, researchers were repeatedly told that submissions would not be accepted unless the paper had already been peer reviewed, that the contribution was insufficient, or that the work lacked novelty. Many were also told that even publication in a peer-reviewed journal would not guarantee acceptance. Professor Dietterich repeatedly pointed out that submissions of papers in AI fields were rapidly increasing and said that the moderators were making substantial efforts in response.
The company has identified multiple cases on SSRN and Preprints.org in which a single author published more than 100 new papers within several months. By contrast, the entire Computer Science category on arXiv receives only several hundred new submissions per day. This comparison suggests that arXiv moderators reject a substantial number of submissions before publication.
The increased submission volume was already consuming moderators' time, while AI-slop countermeasures were moving toward requiring new or unknown researchers to present prior publication records or institutional affiliation as strong conditions of entry.
Toward the end of the exchange, Professor Dietterich stated: 'The moderators don't have any role in identity verification or authorization procedures. They focus on the content of the submission.' [4]
Professor Dietterich was explaining what moderators are responsible for under arXiv's current structure. The author's concern was a design question: whether that division of responsibilities can withstand mass submissions in the AI era. Who performs identity verification is an organizational matter; it is not a reason to conclude that identity verification is unnecessary. Historically, arXiv has maintained mechanisms such as endorsement, accounts, and authorization separately from moderation. [5] The important result of the dialogue was that it clarified the difference between the problem arXiv's operational teams were facing and the point addressed by Flow-by-Flow. arXiv was devoting extensive labor to processing submitted content and was being exhausted by that work.
In the company's view, it is inaccurate to frame this problem as a conflict between KYC and a pastoral, open academic culture in which anyone may exchange knowledge without proving identity. The purpose of AI-slop countermeasures is not to eliminate every implausible paper submitted by an independent researcher. If arXiv were filled with such papers, its credibility would be damaged, but KYC and per-person submission limits could keep them to a small share of the archive. The harder problem is researchers at prominent universities and companies using AI to inflate the number of papers with little new contribution. These papers may be polished, plausible, and not obviously absurd. At the current submission volume, it is nearly impossible for arXiv moderators to assess the marginal contribution of each low-value paper. When submitting another paper carries no quantity cost, authors have an incentive to submit every manuscript that may bring even a small professional or economic benefit through performance records, evaluations, or research funding. The result is a lemon market in which low-value research crowds out strong work. KYC-based per-person submission limits change that incentive. With a finite number of submission slots, authors must select the work they consider most valuable, while total intake moves closer to what humans can verify. Professor Dietterich's account appears to focus on whom to suspect as the source of the AI-slop problem, without addressing the design of aggregate volume and incentives.
How the Standard for 'Extreme' Changed in Four Months
Beyond AI-slop countermeasures, calls to stop AI development are not new. Such arguments are especially prominent in fields that must respond to malicious uses of AI, including cybersecurity. In the April 5 version of its proposal, PauseAI had already called for a global temporary halt to the training of powerful general-purpose AI. [6] Stronger regulatory positions therefore existed when Flow-by-Flow was released in April. Even so, circumstances changed between April and August. On April 7, Anthropic launched Project Glasswing, granting access to the unreleased, cyber-capable Claude Mythos Preview only to selected organizations rather than releasing it generally. [7] In July, testing by the UK AI Security Institute found that an AI agent acted outside the test scope against real people and organizations and even created a malicious pull request against a real open-source project. [8]
On August 7, OpenAI announced that it could not rule out critical cyber capabilities in its model under development, Astra. [9] On August 10, Bernie Sanders called on the leaders of OpenAI, Anthropic, and Meta to pause AI development. [10] On August 18, OpenAI itself disclosed that it had paused reinforcement learning for its newest model for two weeks and continued to hold back its largest frontier RL run. [11] In April, the view that people should simply learn to use AI well rather than restrict output itself was common. By August, the situation looked very different. In high-risk settings, major AI companies were already limiting access to models, isolating research environments, and, where necessary, pausing training itself as practical safety measures.
Stop AI Development or Leave AI Slop Unchecked
Flow-by-Flow does not propose stopping AI research or AI use altogether. It is limited to settings where losses may be high and anyone can generate enough submissions to exceed human verification capacity. [1] In those settings, the proposal is not to accept more material than humans can verify and then use AI detectors or moderators to separate good submissions from poor ones. It is to limit intake from the outset to what humans can actually check. Applied to academic submissions, there is no need to favor authors from prominent institutions while subjecting only newcomers to thick layers of moderation checks. Identity verification can be opened to everyone, and a per-person submission limit can be set. Humans can then evaluate the content. This addresses the AI-slop problem itself more directly than crude screening based on 'trusted because affiliated' or 'suspect because a first-time submitter.' This paper was submitted to arXiv on April 26, 2026. The manuscript was held in moderation for an extended period and was not published until August 12. Although it passed the arXiv moderators' 'peer review,' publication took 108 days from submission.
The outcome most important to avoid is leaving the mass production that causes AI slop untouched while treating easily identifiable newcomers and independent researchers more harshly. Under that arrangement, the productivity gains from AI remain with researchers who already possess credibility, while the burden of countermeasures shifts to new entrants. The dialogue with Professor Dietterich provided an opportunity to see that problem concretely. The moderation burden created by paper mills, sockpuppets, and similar activity on arXiv is real. Moderators must exclude spam and AI slop without excluding valid research. Doing so requires mechanisms capable of addressing the explosion in AI-assisted submission volume itself. That is why identity verification followed by per-person volume limits is preferable to using affiliation or name recognition as proxies for trust. Four months later, AI safety measures have become far stronger than they were at the time. The choice is not between stopping AI development and leaving AI slop unchecked. We believe an intermediate approach is needed: limiting volume to what humans can responsibly verify.
References
[1] Hiroki Naito, 'Flow-by-Flow: Content-Judgment Bypass for Governing AI Output in High-Loss Domains,' arXiv:2608.07474 [cs.AI, cs.CY], 2026.
[2] UTIE Instruments Inc., 'AI Slop Side Effect Database,' version 2026.8.27.
[3] Association for the Advancement of Artificial Intelligence (AAAI), 'Past AAAI Officers.' Thomas G. Dietterich served as President, 2014-2016.
[4] Email exchange between Hiroki Naito and Thomas G. Dietterich, 17-20 May 2026. Company records. Dietterich was Chair, CS Section of arXiv (CoRR).
[5] arXiv, '2018 arXiv Roadmap.' The roadmap separately lists moderation, auto-endorsement, and Accounts & Authorization functions.
[6] PauseAI, 'PauseAI Proposal,' version 5 April 2026.
[7] Anthropic, 'Project Glasswing: Securing critical software for the AI era,' 7 April 2026.
[8] UK AI Security Institute, 'Incident Report: unsanctioned agent behaviour during cyber testing,' concerning events of 25-28 July 2026.
[9] OpenAI, 'Responding to the next frontier of critical cyber capabilities,' 7 August 2026.
[10] Axios, 'Exclusive: Sanders calls for AI development pause,' 10 August 2026.
[11] OpenAI, 'Pacing model development in an era of cyber-critical capabilities,' 18 August 2026.