EPISODE · May 2, 2026 · 24 MIN
AI Deanonymization: How Claude Identifies Writers from 125 Words
from Deep Dive · host Deep Dive
A journalist named Kelsey Piper handed Claude Opus 4.7 a 125-word draft of a political column she had never published. Incognito mode. No login. Through the API. She asked: who wrote this? Claude identified her. ChatGPT guessed Matthew Yglesias. Gemini guessed Scott Alexander. Both wrong. Then four more tests across genres and decades — a Pokémon school report, a 1942 movie review, a 500-word heist novel, a college essay from 15 years ago. Claude went 5 for 5. Same writer recoverable from prose nobody had ever published.This episode is what the threshold drop is. In 1964, the canonical stylometric study — Mosteller and Wallace on the Federalist Papers — needed about 1,500 words per essay and a closed list of two candidates. In 2013, identifying J.K. Rowling as Robert Galbraith required an entire 80,000-word novel and a list of four candidates. In 2026, a frontier language model needs 125 words and the open set of every public writer on the internet. The text required dropped about a hundred-fold. The candidate pool expanded by a factor of millions.Mechanism: classical stylometry — Burrows' Delta counting commas and function words — became latent-vector matching inside a transformer. Huang et al. EMNLP 2024 anchor: 84% accuracy at 60 words on a 10-author benchmark.Anthropic's April 2025 chain-of-thought faithfulness paper: Claude 3.7 Sonnet's reasoning chains acknowledge planted hints only ~25% of the time. The other 75%, the chain reasons through alternative arguments. Larger models produce less faithful reasoning, not more. Apply that here: Claude identifies the writer correctly, then generates a plausible reason. Sub-symbolic identification. Symbolic confabulation.Institutional fallout: Anthropic's December 2025 release of 1,250 anonymized interview transcripts — deanonymized 25% in ~1 day. Snowden's 2013 stylometric hedge. Reality Winner. Glassdoor reviewers under threats that don't require a subpoena. Talley v. California and McIntyre v. Ohio protect against government compulsion but not private inference.And the 15-year fingerprint persistence. Five predictions with horizons. Closing thesis: anonymity, which used to be the default state of writing, is now a capability deficit.RELATED EPISODESWhen AI Agents Go to Court — the privacy/legal parallel for inference-based identificationClaude Mythos — the capability stack that makes 125-word identification possibleShinyHunters SSO — the adjacent data-exposure surface attackers can pair with stylometric inferenceMythos Bifurcation — frontier consolidation that concentrates this capabilityCHAPTERS00:00 Cold open — Kelsey Piper × Claude Opus 4.701:56 Intro + preview03:19 History — 1964 Federalist / 1996 Unabomber / 2013 Rowling05:40 Mechanism — function words to latent vectors08:30 Why Claude specifically09:54 Right ID, wrong reasoning — Anthropic faithfulness paper13:24 Implications — Anthropic dataset, Snowden, Glassdoor, First Amendment18:32 15-year fingerprint persistence20:12 Five predictions22:37 Closing thesis — capability deficitSOURCESApr 2026 — Kelsey Piper, The Argument: 'I can never talk to an AI anonymously again'Apr 2025 — Anthropic: Reasoning Models Don't Always Say What They Think (CoT faithfulness)Mar 2025 — Anthropic: On the Biology of a Large Language Model (Lindsey et al.)2024 — Huang, Chen, Shu (EMNLP): Can Large Language Models Identify Authorship?Feb 2026 — Tianshi Li (Northeastern Khoury): deanonymizing the Anthropic Interviewer datasetDec 2025 — Anthropic: anonymized interview transcript release (~1,250 transcripts)2013 — Patrick Juola (Duquesne): Galbraith / Rowling identification1996 — FBI / James Fitzgerald: Unabomber stylometric attribution1964 — Mosteller and Wallace: The Federalist Papers Bayesian authorship study1995 — McIntyre v. Ohio Elections Commission (anonymous speech)1960 — Talley v. California (handbill identification ordinance struck)
Embed this episode
NOW PLAYING
AI Deanonymization: How Claude Identifies Writers from 125 Words
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.