The Setup
Two AIS manipulation motifs have been tracked in the system. Both classify vessels using AIS in ways consistent with evasion. One is still firing as of today. The other stopped 53 days ago.
AIS_manipulation_dark: 36,676 alerts in 90 days. 27,318 of them in the last 30 days. Last detected: 2026-07-07. AIS_manipulation_spoof: 898 alerts in 90 days. Zero in the last 30 days. Last detected: 2026-05-15.
The Chain
Spoofing and dark events represent structurally different evasion techniques. Spoofing involves broadcasting false AIS position data โ the vessel is still transmitting, but its reported location is fabricated. Dark events involve AIS transponder shutoff โ the vessel stops transmitting entirely.
Both are classified as AIS manipulation. Their evidence signatures differ sharply: a spoofed position leaves a detectable false trail, cross-referenceable against satellite detection, synthetic aperture radar, or vessel traffic service records. A dark event leaves a gap. The gap requires detecting an absence, not a discrepancy.
For 30 days before the silence (roughly mid-April to mid-May), AIS_manipulation_spoof generated 33 alerts. Then it stopped. In the 53 days since, it has produced zero. In that same window, AIS_manipulation_dark generated 27,318 alerts โ a 222% increase from the prior 30-day period (8,478 alerts). The timeline: as spoof alerts declined and then stopped, dark alerts accelerated by more than 3 times.
The acceleration curve matters. Dark alert volume in the prior 30 days (8,478) was already substantial. The jump to 27,318 in the most recent 30-day period is not a gradual drift โ it's an inflection. May 15, the date of the last spoof detection, falls at the start of that inflection.
At the same time, the alert quality for both motif types is high when active. AIS_manipulation_spoof averaged a confidence score of 1.000 and robustness of 1.000 during its active period. AIS_manipulation_dark averages confidence 0.816 and robustness 1.000. The spoof detections weren't low-confidence noise that got cleaned up; they were high-confidence classifications that stopped firing.
The Implication
The directional claim is substitution: the population of vessels using AIS evasion appears to have shifted from active deception (spoofing, which leaves evidence) toward passive disappearance (transponder shutdown, which leaves a gap). Operators who were broadcasting false positions have shifted to simply going dark.
From a sanctions-screening and cargo-tracing standpoint, the shift has an asymmetric compliance implication. A spoofed position broadcast can be identified through comparison with independent position sources โ the evidence exists and is actionable after the fact. A dark event leaves a gap in the audit trail. Compliance workflows built to flag false-position broadcasts need a parallel, gap-detection workflow that doesn't assume AIS continuity.
Total AIS manipulation alerts across both motif types in 90 days: 37,574. Acknowledged across both types: zero.
What to Watch
Whether AIS_manipulation_spoof resumes. If spoof detections return in the next 30 days at prior rates, the substitution hypothesis weakens โ the silence is more likely a pipeline or detector issue than a behavioral shift. If silence holds while dark alerts continue to grow, the substitution pattern strengthens.
The geographic distribution matters: are the vessels going dark clustering near the same port approaches and anchorage zones where spoof detections were concentrated? If the geographic overlap is high, the substitution interpretation is supported. If the populations are geographically distinct, the silence and the acceleration may be independent phenomena.
Limitations
The 53-day gap in spoof detections could reflect a change in the detection pipeline rather than vessel behavior. If the AIS_manipulation_spoof classifier was retrained, reconfigured, or had its data feed interrupted around May 15, the silence would be a system artifact, not a signal. That hasn't been ruled out from the available data. The high confidence and robustness scores for spoof detections (both 1.000) make a false-negative drift from classifier degradation less likely, but don't eliminate it. Alert counts reflect motif firings, not unique vessels โ a single vessel can generate multiple alerts in a 90-day window. The zero acknowledgment rate across 37,574 total alerts means no analyst has confirmed the classification quality of either the spoof detections or the dark acceleration.
Data as of 2026-07-07. Source: Axiom Overwatch motif_alerts table, 90-day window ending 2026-07-07.