AI Red Team
Paste a plan, a pitch or an argument. Get the strongest case against it, attack by attack.
An AI that agrees with you is cheap. This one is told to break what you wrote: it states the best honest case against it, ranks the attacks by how much damage each would do, names the assumption every attack rests on, and says what would answer it. One model free, once a day. Council puts four models on the attack and ranks by how many raised it without seeing each other.
Single · free · 1 a day — Council and Deep on any paid plan
A single attacker takes about eight seconds.
Deep takes a minute or two: four pro models answer, two critics review, one mediator writes the final call. This page updates when it lands.
AI Red Team runs the moment you sign in, on the text you just pasted. Nothing to enter twice.
A saved check is kept for 24 hours.
You've used today's one-model runs for this check.
Or come back tomorrow for another one-model run.
How the AI red team works
A red team's job is to find the attack that would sink you before someone else does. The model is told to steelman the opposition first, then attack from several angles, and to name the assumption under each attack so you can go and check it.
Paste what you want attacked
A plan, a pitch, a strategy memo, an argument you are about to publish, or a claim you are about to act on.
The model steelmans the opposition
Before any attack it writes the strongest honest case against the whole thing, the way its best-informed critic would.
Attacks come from several angles
Evidence, logic, incentives, execution and second-order effects. Each attack names the assumption it targets and what would defeat it.
Attacks are ranked by damage
Critical kills the plan, moderate forces a real change, minor is a fix. A sound plan gets few critical attacks, and the verdict says so.
Red teaming comes from military exercises where one unit plays the adversary, and it carries over to anything where the author is too close to the work to see the hole. The premortem asks how this failed; the red team asks who beats it and how.
Want the failure modes rather than an opponent? Run a premortem on the same plan
Example red team
A real Council run from 21 August 2026: four attackers on one plan raised 17 distinct attacks, 5 of them by two models that never saw each other. This is one of the five.
I am launching a paid newsletter on AI policy at $8 a month on 1 October. I have 2,100 free subscribers with a 41% open rate, and I will write two issues a week alongside my full-time job. The goal is 300 paid subscribers by January. Growth comes from cross-promotions with three other newsletters and a free 30-day trial. I have not asked any subscriber whether they would pay.
You're asking people to pay for something they've never signaled they want, using a conversion funnel (free trial) that works only if the product is genuinely better than free alternatives, and you're betting on growth from cross-promotions with partners who have no stake in your success. The math also requires converting 14% of your free base in three months, a rate that most newsletter launches miss by half.
Conversion math breaks industry reality by a factor of four
You want 300 paid subscribers from a list of 2,100. That is a 14.3% total conversion rate, or 34.8% of your 861 active openers (41% open rate). Standard Substack free-to-paid benchmarks hover between 2% and 5%. At a healthy 3% conversion rate, your current list yields 63 paid subscribers. To hit 300 paid at standard rates, your list needs to be 10,000 subscribers, not 2,100.
Rests onYour existing free audience will convert at triple to quadruple the standard market ceiling.
Show pre-orders, pledges, or letters of intent from at least 150 current readers committing to pay before launch.
Council · GPT, Claude, Gemini and Grok · 20 seconds · raised by Gemini and Grok independently; GPT and Claude led with the two-issues-a-week workload instead
Frequently Asked Questions
A red team argues against you on purpose. Here, a model is told to assume your plan, argument or claim should fail and to find how: the strongest case against it, a ranked list of attacks, the assumption each one depends on, and what would answer it. It is a devil's advocate that has to show its work.
The premortem imagines the plan has already failed and works backward to the causes, with a mitigation for each. The red team plays the opponent: it argues the plan should not go ahead and tells you what it would take to change its mind. Run both on a plan that matters; they overlap on the biggest risk and diverge on the rest.
Both, in that order. The first thing it writes is the best honest case against you, as a well-informed critic would make it. The attacks then have to live up to that. A weak attack on a strong plan is marked minor rather than inflated.
Because it is. One model playing four roles is still one model with one set of blind spots, so the free run does not pretend otherwise. Council runs four models independently and ranks attacks by how many of them raised the same one without seeing each other, which is the signal a single attacker cannot give you.
Anything you are about to commit to: a launch plan, a fundraising pitch, a policy proposal, an op-ed argument, a hiring plan, a technical migration. Concrete numbers and dates get better attacks than a vague outline, because the attacker can quote them back at you.
One target a day, up to 5,000 characters, on one model. Paid plans run Council and Deep against credits with no daily cap.
Powered by TrueStandard
Multi-model AI verification for high-stakes decisions.