My AI almost told my entire FaithButWhy list that St. Francis of Assisi said something he never said.
You know the quote. "Preach the Gospel at all times. When necessary, use words." It's on coffee mugs, church signs, and about 4 million Instagram graphics.
Francis never said it. There's no record of it in his writings or in any of the early biographies. Scholars have been trying to kill that attribution for decades.
And there it was, sitting in paragraph three of my draft, cited like it came straight out of a primary source.
Now, I publish FaithButWhy, a blog and newsletter about the Christian faith. That's unforgiving terrain. Get a pope's name wrong, misdate a church council, mangle a verse... and you don't just get a correction email. You lose credibility with the EXACT readers you're trying to serve. Pastors read this thing. Seminary guys read this thing. They notice.
The same week, another draft dated the Council of Chalcedon to 351 instead of 451. One transposed digit, pulled from some sloppy blog the AI read while researching. A third draft called Augustine a pope. (He was a bishop. Big difference. The kind of difference that gets you roasted in the comments.)
None of those errors made it to publish. And it wasn't because I caught them.
A second AI caught them. One whose ONLY job is to attack the first AI's work.
That's what this issue is about.
Every AI Stack Is Missing Its Copy Chief
I've been in this game 20 years. All your gurus were my clients. Brunson, Deiss, Kennedy, Agora.
And here's something most people never learned about Agora. They didn't build a billion-dollar publishing empire on great copywriters. Great copywriters are everywhere. They built it on copy chiefs.
Every control that ever came out of those companies went through a professional whose entire job was to tear the draft apart before the market could. Weak hook? Flagged. Claim without proof? Flagged. Price in the email doesn't match the order page? Flagged. The copywriter and the copy chief were different people ON PURPOSE. Nobody grades their own homework honestly.
Halbert had editors. Agora had copy chiefs. Your AI has... nobody.
Think about what actually happened over the last three years. Every marketer bolted a generator onto their business. ChatGPT, Claude, some agent stack. And then they started shipping first drafts. First drafts written with total confidence, because that's the scary part of modern AI. It doesn't stammer when it's wrong. A hallucinated statistic reads exactly as smooth as a real one.
Here's the part everyone's got backwards, though.
Today's models don't hallucinate like they did in 2023. Not even close. But less isn't never. And the failure mode has shifted. The real problem in 2026 isn't AI inventing facts out of thin air. It's AI reading articles on the web that happen to be WRONG, and repeating them to you with a straight face. Some content farm publishes a bad date, it ranks, your AI reads it during research, and now that bad date is in your newsletter with your name on it.
And it catches your errors too. The wrong price you pasted into the brief. The stat from 2024 still sitting in your swipe file. Quality in, quality out... but somebody has to check the quality.
I call this missing piece The Copy Chief Layer. A second AI, running in a separate context, with an adversarial charter: it wins by finding problems. It gets zero credit for saying "looks great!"
This isn't my invention, by the way. It's how the AI labs themselves operate. Anthropic and OpenAI red-team their own models before every release, paying smart people to attack the thing they just built. Anthropic literally trains Claude by having one AI critique another AI's output.
The people who BUILD these models don't trust unchecked output.
Why do you?
What the Critic Catches (That You Won't)
On FaithButWhy, my adversarial pass flags something in nearly every issue. Most weeks it's small stuff. A quote that needs a better citation, a date I should double-check. Some weeks it's a howler, like the fake Francis quote, that would've been genuinely embarrassing in front of the readers whose trust I care most about.
But don't file this under "nice for bloggers." The same pattern is worth real money on the direct response side.
Run your launch emails through a copy chief agent and it catches the things that quietly bleed campaigns dry. The hook that's actually a warm-up paragraph wearing a hook costume. The "results in 30 days" claim with no proof element within screaming distance. The urgency deadline in email 3 that contradicts the deadline in email 1. The order page price that doesn't match the email price (I've watched that exact mistake torch trust at the worst possible moment... minutes after cart open).
You think the A-list guys at Agora shipped whatever the writer turned in on the first pass?? They ran everything through a killer whose job was to say no. That's WHY their packages ran for years.
Your AI can write 10 launch emails in 4 minutes now. Great. So can your competitor's. Volume stopped being the edge about 18 months ago.
The edge now is being the only one in your market whose AI output went through a hostile review before the market saw it.
So let me hand you the whole thing. The critic's charter, the exact prompts guarding FaithButWhy, the copy chief prompt for your campaigns, the MindStudio wiring, the Claude version, and the loop that tells you when a piece is actually ready to ship.
It's Monday. Deep dives are free in full. Grab a coffee.
The Full Build: The Copy Chief Layer
How the Adversarial Loop Works
The pattern is the same whether you build it in MindStudio or run it manually in Claude:
Draft → Attack → Revise → Attack Again → Verdict
Four roles, and the whole system lives or dies on keeping them separate:
- The Generator. Writes the draft. Your existing writing agent, your Claude project, whatever you use today.
- The Fact Attacker. Verifies every checkable claim. Names, dates, quotes, attributions, prices, stats, links.
- The Copy Chief. Attacks the persuasion. Hook strength, proof, offer clarity, claim risk, consistency.
- The Reviser. Takes the original draft plus both attack reports and produces the fixed version. Then it goes BACK through the attackers.
Total runtime in MindStudio: about 2-4 minutes per piece. Output: a draft you can ship, plus an attack report showing everything that got caught and fixed along the way. (Keep those reports. They become training data for making your generator better. More on that in the customization section.)
Step 1: Write the Critic's Charter (Get This Wrong and Nothing Else Matters)
Before any prompts, you need to understand the one rule that makes adversarial AI work:
The critic must live in a separate context from the writer.
Not a "now review your work" message in the same chat. A different conversation. A different node. Ideally a different model.
Because here's what happens when you ask an AI to critique its own draft in the same context: it defends its choices. Same as a copywriter grading their own sales letter. The draft is sitting right there in its context window as "something I decided was good," and the review comes back soft. I've tested this dozens of times. Same model, same draft, fresh context vs. same context. The fresh context finds 2-3x more real problems.
The second half of the charter is incentive design. Your critic prompt has to make finding problems the WIN condition. A default AI is a golden retriever. It wants you happy. You have to explicitly strip that out:
You get no credit for approval. You get no credit for
compliments. Your performance is measured by one thing
only: real problems found that the author missed.
If you approve something that contains an error, that
is a total failure of your job.
If you genuinely find nothing after a thorough attack,
say "NO FINDINGS" and specify exactly what you checked.
Never invent problems to seem useful.
That last line matters just as much as the rest. A critic that manufactures fake problems to look busy is as useless as one that rubber-stamps everything. You want a professional killer, not a nervous intern.
Step 2: The Fact Attack Prompt
This is the one guarding FaithButWhy. Adapt the domain expertise line to your niche:
ROLE: You are a hostile fact-checker with deep expertise in
[church history, theology, and Scripture]. A publication's
reputation depends on you. You are the last line of defense
before publish.
You get no credit for approval. Your performance is measured
only by real errors found. Approving an error is total failure.
If you find nothing after a thorough attack, say "NO FINDINGS"
and list exactly what you verified. Never invent problems.
ASSIGNMENT: Attack the article below. Extract EVERY checkable
claim and verify each one independently. Do not assume the
author is right. Do not assume a claim is fine because it
sounds familiar. Famous-sounding is not the same as true.
CHECK SPECIFICALLY:
1. Names and titles. Right person, right role, right era.
(A bishop is not a pope. A council is not a synod.)
2. Dates. Events, councils, reigns, publications.
3. Quotes and attributions. Is this quote REAL and correctly
attributed? Flag apocryphal quotes even when popular.
4. Scripture references. Right book, chapter, verse, and
does the text actually say what the author claims?
5. Numbers and statistics. Source and recency.
6. Doctrinal accuracy. Would a seminary professor wince?
SOURCE SKEPTICISM: If your verification relies on web content,
treat popular articles and content farms as UNRELIABLE. Prefer
primary sources and scholarly references. If sources conflict,
flag the claim as DISPUTED and show both versions.
OUTPUT FORMAT: For every claim, one line:
- CLAIM: [the exact claim]
- VERDICT: VERIFIED / SUSPECT / FALSE / DISPUTED
- EVIDENCE: [why, with source]
- FIX: [corrected version, if needed]
End with a SHIP RISK rating: LOW / MEDIUM / HIGH, with a one-
sentence reason.
Two design notes. First, "famous-sounding is not the same as true" is in there because of the Francis quote. Popularity is how apocryphal quotes survive, and a default AI treats popularity as evidence. Second, the SOURCE SKEPTICISM block is the 2026 upgrade. Your fact-checker will research the web to verify claims, which means it can be poisoned by the same wrong articles that fooled your generator. Telling it to rank primary sources over blog posts, and to surface conflicts instead of picking a side, is what keeps the critic from inheriting the generator's disease.
Step 3: The Copy Chief Prompt
Different weapon, same charter. This one attacks the SELLING:
ROLE: You are a copy chief with 25 years in direct response.
You trained under the Agora model: no package ships until it
survives you. You have killed promotions that went on to save
companies money and approved controls that ran for years. You
are respected because you are hard to please, not because you
are nice.
You get no credit for approval. Your performance is measured
only by real weaknesses found. If the piece is genuinely
strong, say so briefly and move on. Never pad your critique.
ASSIGNMENT: Below is [a launch email / ad / sales page] going
to [audience] selling [offer] at [price]. Attack it in this
order:
1. THE HOOK: Would a cold reader stop? Or is the real hook
buried in paragraph 3? Quote the exact line that should
lead.
2. THE BIG PROMISE: Specific and believable, or vague and
inflated? Rewrite it stronger if you can.
3. PROOF: List every claim, then list the proof offered next
to it. Any claim with no proof element nearby is a finding.
4. CLAIM RISK: Flag anything a regulator, ad platform, or
angry customer could use against the author. Income claims,
health claims, guarantees, "results" language.
5. MECHANICAL ERRORS: Prices, dates, deadlines, links, names.
Check consistency across the ENTIRE piece. A deadline that
moves between paragraphs is a finding.
6. THE OFFER: Could a 12-year-old repeat back what you get,
what it costs, and why now? If not, what is missing?
7. THE CLOSE: Does the CTA tell them exactly what to do, or
does it trail off politely?
OUTPUT FORMAT:
- VERDICT: SHIP / FIX AND RESUBMIT / KILL
- FINDINGS: numbered, ordered by severity, each with the
exact quoted text and a specific rewrite
- THE ONE THING: if the author only fixes one thing, which
finding moves revenue most?
Do not rewrite the author's voice. Attack facts, structure,
proof, and persuasion. The style is not yours to fix.
That last instruction (leave the voice alone) is what keeps this from becoming an AI-flavored sanding machine that turns your copy into everyone else's copy. The copy chief's job is making the piece WORK, not making it polite.
And item 5 earns its keep fast. Cross-checking prices, deadlines, and links across a whole sequence is exactly the mind-numbing work humans skip at 11pm before a launch... and exactly what torches trust when it slips through.
Step 4: Wiring It in MindStudio
Here's the node flow:
User Input → Generator → Parallel block [Fact Attacker + Copy Chief] → Reviser → Parallel block [Fact Attacker + Copy Chief] (pass 2) → Display Content → End
- User Input node. Accepts the brief (or a finished draft, if you're only using this to review). Include your offer details, price, deadline, and audience as variables. The attackers need them for consistency checks.
- Generator node. Your existing writing prompt. No changes needed.
- First Parallel block. Two nodes running simultaneously: the Fact Attack prompt and the Copy Chief prompt from Steps 2-3. Each receives the draft plus the brief variables. Set the critic nodes to a different model than the generator. If you write with Claude, attack with GPT or Gemini (or vice versa). Different models were trained on different data, and they miss different things. Same-model criticism has blind spots baked in.
- Reviser node. Receives the original draft plus both attack reports. Prompt: "Apply every FALSE and SUSPECT fix and every severity-1 and severity-2 finding. Do not change anything the reports did not flag. Preserve the author's voice exactly. Output the revised draft plus a change log."
- Second Parallel block. Same two attackers, fresh pass on the revised draft. This is the pass that catches fixes that broke something else (it happens more than you'd think).
- Display Content node. Final draft, both attack reports, the change log, and the pass-2 SHIP RISK rating.
The whole run costs pennies and takes minutes. A human copy chief of this caliber bills $500-$1,500 per piece and needs 3 days.
Step 5: The Same Loop in Claude (No Agent Platform Needed)
Not everything needs a workflow builder. Here's the manual version I use for one-off pieces:
- Project 1: "Writer." Your writing project with your voice guidelines and offer docs. Generate the draft here.
- Project 2: "Copy Chief." A SEPARATE project whose system instructions are the Step 2 and Step 3 prompts. No voice guidelines in here, no "our brand is friendly" documents. Nothing that makes it sympathetic to the draft.
- Paste the draft into Copy Chief. Get the attack report.
- Bring the report BACK to the Writer project: "A reviewer found these problems. Address every finding without changing anything else."
- Re-attack the revision in Copy Chief. Repeat until dry (next section).
If you're a Claude Code or Cowork user, this gets even cleaner: have a subagent do the critique. Subagents run in fresh context automatically, which enforces the separation rule without you managing two projects.
The mistake to avoid: doing all of this in ONE chat. The moment your critic can see that it wrote the draft, you've hired the writer to grade their own homework, and you're back to "looks great!"
Run It Until It Runs Dry
How do you know when a piece is done? The critic tells you. You're watching for the DRY signal.
Here's a real pattern from a FaithButWhy issue:
Pass 1: 9 findings. One FALSE (the misdated council), three SUSPECT quotes needing better citations, five copy findings including a buried hook.
Pass 2 (after revision): 3 findings. One new SUSPECT introduced by my fix (I "corrected" a date using the same bad source... told you the second pass earns its keep), two minor copy notes.
Pass 3: NO FINDINGS on facts. One stylistic nitpick from the copy chief.
That's dry. Ship it.
The rule of thumb: when a full pass returns nothing above nitpick severity, you're done. Usually 2-3 passes. If you're still getting severity-1 findings on pass 4, the problem isn't the draft, it's your generator prompt or your source material, and you should fix THAT instead of playing whack-a-mole.
One more thing. Save every attack report in a folder. Once a month, skim them for repeat offenders. If your copy chief flags "claim with no proof nearby" every single week, paste that pattern into your generator prompt ("every claim must have a proof element within 2 sentences") and it stops appearing. The critic doesn't just fix drafts. It upgrades your writer over time.
Making It Yours
Four areas to customize before this is production-ready:
1. The Fact Attacker's domain expertise. Mine says church history and theology. Yours should name YOUR minefield. Supplements: ingredient claims, dosages, study citations, FDA disclaimer language. Coaching: income claims, testimonial framing, FTC compliance. Software: feature accuracy, version numbers, competitor comparison claims, pricing tiers. Write the CHECK SPECIFICALLY list for the errors that would actually embarrass you.
2. The severity threshold. FaithButWhy ships at zero fact findings, full stop. For a fast-moving ad test, you might ship at "no FALSE, no claim-risk findings" and accept stylistic notes. Decide your line BEFORE the launch adrenaline hits, and write it into the Reviser prompt.
3. The approved source list. Give your Fact Attacker a ranked list of sources you trust. For me: Scripture, then primary historical documents, then established scholarly references, and random blogs dead last. For supplements it might be PubMed and the actual study PDFs. This single addition is the strongest defense against the wrong-article-on-the-web problem.
4. The voice protection clause. Keep "do not rewrite the author's voice" in the copy chief prompt, and add 2-3 lines describing your voice so it knows what to leave alone. Without this, every pass sands the personality off a little more, and by pass 3 you sound like a LinkedIn thought leader. Nobody wants that.
What Else You Can Point This At
Same architecture, different targets:
- Full launch sequences. Attack all 5-7 emails as ONE document so the critic catches cross-email contradictions (deadlines, prices, bonus counts).
- Sales pages and VSL scripts. The copy chief prompt works as-is. For VSLs, add "attack the first 15 seconds like a viewer's thumb is hovering over skip."
- Ad compliance pre-check. Feed it the ad policies for Meta or Google as context and let it flag rejection risks before the platform does. Cheaper than a banned ad account.
- SEO articles. The Fact Attack pass is built for this. AI-written articles repeating wrong web facts is exactly how sites lose trust (and rankings).
- Webinar decks and stage presentations. Nothing worse than a wrong stat on a slide behind you while you're on stage. Believe me.
- Affiliate and JV swipe. Attack the swipe your partners send YOU before you mail it to your list. Their mistakes become your reputation the moment you hit send.
- Client deliverables. If you run an agency, an adversarial pass on everything that leaves the building is the cheapest E&O insurance you'll ever buy.
- Your own briefs. Run the INPUT through the fact attacker before the generator ever sees it. Wrong facts in the brief become confident wrong facts in every draft downstream.
Your Build Checklist
- Pick your stack: MindStudio workflow or two Claude projects
- Write your critic's charter (win condition = problems found, "NO FINDINGS" allowed, no invented problems)
- Customize the Fact Attack prompt with your domain's minefield
- Customize the Copy Chief prompt with your offer, audience, and price variables
- Add your approved source list, ranked
- Set the critic to a DIFFERENT model than your generator
- Wire the loop: Draft → Attack → Revise → Attack again
- Add the voice protection clause so revisions don't sand off your personality
- Test it on something you already published (humbling, but do it)
- Define your ship threshold before your next launch
- Start a findings folder and review it monthly to upgrade your generator prompt
Continue with Build Notes+
This Monday deep dive is free in full. For complete Thursday builds and supporting files, join Build Notes+.
