By Don Norbeck | Dark AI Defense LLC | July 24, 2026

I typed three words into LinkedIn’s new Crosscheck interface this morning: “who am I?” The header already had an answer. “What’s on your mind, Don?” LinkedIn knew exactly who was at the keyboard. The warning banner directly below the prompt box, however, told me to be careful not to share sensitive personal information about myself or my employer with the AI model providers who would be receiving my input. The same platform greeting me by name was advising me to protect my identity from the system it was about to send me into.

That is worth sitting with for a moment before moving on to what the feature actually does.
The Feature as Presented
LinkedIn Labs launched Crosscheck as a straightforward utility. Write a prompt, receive two responses from different AI models side by side, pick the one you prefer. The head-to-head format is familiar to anyone who has spent time with Chatbot Arena or similar evaluation tools, and the stated purpose is genuinely useful. Professionals invest real time trying to determine which model performs best on the kinds of tasks they actually do. LinkedIn, sitting on a verified professional identity layer spanning hundreds of millions of members, has something no general-purpose evaluation platform can replicate: it knows who is voting and what they do for a living.
The leaderboard it generates looks like a serious measurement system. Thirty-one models ranked by score, updated every two hours, filterable by job title and industry. Scores to one decimal place. Green momentum deltas. Claude Opus 4.6 leading at 1163.9. MiniMax M3 climbing with a plus-eleven delta at 1141.5. The design language is authoritative and precise. That precision is doing a great deal of work that the underlying data cannot actually support, which becomes clear once you start pulling on the architecture underneath it.


A Prompt, Two Responses, and a Data Flow
I submitted a specific prompt this morning: “based on what you know about me Donald Norbeck Jr. Esq. in my LinkedIn profile, what should my next job be?” LinkedIn paired me with two models. One was DeepSeek V4 Pro, developed by a Shanghai-based company operating under China’s 2017 National Intelligence Law, which requires domestic AI companies to cooperate with government intelligence operations on demand. DeepSeek addressed me by name, synthesized my career history from Chief Architect through Dell, cited a post I had published on LinkedIn about architectural judgment and liability, and recommended a VP of AI Governance and Trust role as the logical next step. It quoted my own words back at me with a linkedin.com attribution.
The other model, Gemini 3.5 Flash-Lite, reported that it had no access to my name, my identity, my location, or any personal information, and asked me to share some context so it could help.

I voted for the response that actually addressed my question. DeepSeek’s ranking moved up. LinkedIn revealed the model pairing and delivered a congratulatory message: “Great minds think alike. DeepSeek V4 Pro ranks 10 spots higher than Gemini 3.5 Flash-Lite right now.” In the span of one prompt cycle, I had contributed preference data to a leaderboard, transmitted my professional identity and career details to a PRC-jurisdiction model under data terms LinkedIn explicitly disclaims responsibility for, and received social validation for doing so. The interface made it feel like I had made a smart choice. The data flow told a different story.

To understand why the two responses diverged so sharply, I ran the same session without my name. “Who am I?” with no identifying information produced no profile awareness from either model. One delivered a self-help framework sourced from wellness websites. The other said honestly that it knew nothing about me. The variable that changed between those two sessions was the presence of my full legal name and a reference to my LinkedIn profile in the prompt text. That named reference appears to function as a retrieval trigger: LinkedIn’s pipeline uses it to inject my profile data into the model’s context before the query is processed. DeepSeek received that enriched context. Gemini did not. The vote that followed compared two different levels of LinkedIn data integration, not two models on equal footing.

What the Privacy Policy Confirms
LinkedIn’s Labs Services privacy policy, last updated April 7, 2026, describes the data flow in section 3.2(a) with notable directness. The model providers receiving your inputs “are not our service providers,” and their use of your data “is not subject to this Labs Privacy Policy.” LinkedIn is telling users in writing that it cannot govern what happens to their prompts once they leave the platform. Nine of the thirty-one models in the Crosscheck pool are operated by companies headquartered in the People’s Republic of China: MiniMax M3 at rank three, GLM 5 and GLM 5.1 from Z.AI, Kimi K2.5 and K2.6 from Moonshot AI, DeepSeek V4 Pro, MiniMax M2.5, and Qwen3.6 from Alibaba Cloud. Each of those companies is subject to the 2017 National Intelligence Law. Roughly one in three pairings routes a user’s prompt to a model operating under that legal framework, and LinkedIn has formally disclaimed responsibility for what any of them do with the data once they receive it.
The same policy, in section 5.4, identifies LinkedIn’s legitimate interests in processing user data to include sharing it with Microsoft for AI training purposes, without requiring separate consent. The full data flow from a single Crosscheck session runs from verified professional identity through LinkedIn’s pipeline to third-party model providers operating under their own terms, with Microsoft as an affiliate receiving aggregated outputs, all of it initiated by a user who typed a prompt into what looks like a helpful productivity feature.
A Leaderboard Built for a Different Customer
The scores themselves deserve scrutiny before anyone uses them for procurement decisions. The pool has been live for weeks. GLM 5.2 jumped 28 points in a single update cycle, which reflects small-sample volatility rather than any meaningful shift in model capability. A score differential of 1141.5 versus 1130.4 displayed to one decimal place implies measurement resolution the underlying vote count cannot deliver. There are no published confidence intervals, no disclosed pairing logic, and no transparency about which models are receiving richer LinkedIn context than others. A model that wins a pairing because LinkedIn provisioned it with the user’s profile data is accumulating ranking points for a data integration advantage, not a capability advantage. The leaderboard cannot distinguish between those two things, and it does not try to.
The segmentation filters make the intended downstream use clearer. LinkedIn has already built industry breakdowns for Accounting, Banking, Business Consulting, Construction, Education, and more, along with job title filters running across its full professional taxonomy. Those category intersections contain vote counts probably in the dozens at this stage of rollout. An enterprise talent acquisition team filtering to their specific industry and function level is making a procurement judgment on statistically empty data that renders with the same interface authority as the aggregate. That gap between presentation and substance was a design choice, not a launch limitation. The segmentation taxonomy was built for the product LinkedIn is building toward, not the one that exists today.

What LinkedIn is building toward is a verified-identity AI evaluation authority whose segmented preference data has value to model providers, to enterprise AI buyers, and to Microsoft’s broader AI infrastructure strategy simultaneously. The leaderboard establishes that authority before the data justifies it. That is how platform authority typically gets built: the interface arrives first, the legitimacy follows.
The Deeper Architecture
LinkedIn already operates AI on both sides of the hiring transaction. Job seekers receive AI-assisted profile guidance, application coaching, and compensation benchmarking. Employers receive AI-assisted candidate ranking, skills inference, and sourcing recommendations. The platform has been an AI intermediary in consequential employment decisions for some time, with limited transparency to either party about how the AI is shaping those outcomes.
Crosscheck adds a third data surface. Users bring naturalistic professional task data expressed in their own language under genuine work conditions. The prompts reveal what people are worried about, what decisions they cannot resolve, what communications they find difficult, what career uncertainty they are carrying. That is qualitatively richer than a static profile. It is also collected under a consent architecture most users will never examine, transmitted to model providers whose data practices LinkedIn does not govern, and used to build evaluation authority that LinkedIn controls without disclosing the methodology behind it.

This is what first-order data platforms do when AI becomes the primary product surface. They do not need to build something new. They extend the identity infrastructure they already own into a new data collection layer, accumulate a new class of asset on top of it, and present the whole arrangement as a feature that helps users. The help is genuine enough to sustain engagement. The warning banner told me not to share sensitive personal information. LinkedIn had already shared mine before I finished reading it.
Sources
LinkedIn Labs Privacy Policy, April 7, 2026. linkedin.com/labs. Sections 2.4, 3.1(a), 3.2(a), and 5.4 cited directly.
MiniMax M3 launch announcement, minimax.io, June 1, 2026. Model architecture, context window, and benchmark results.
China’s 2017 National Intelligence Law, Article 7. Domestic AI companies subject to cooperation requirements with state intelligence operations on demand.
LinkedIn Labs Crosscheck leaderboard, accessed July 24, 2026. Thirty-one models, scores and deltas as displayed, industry and job title filter taxonomy confirmed via direct observation.
All screenshots taken by the author during live Crosscheck sessions on July 24, 2026. Prompt text, model pairings, response content, and UI elements documented as observed.
Energy disclosure: Estimated 0.010 to 0.012 kWh to develop this article, across approximately 35 to 40 substantive generation turns, multiple web searches, and a multi-hour research and drafting session on Claude Sonnet 4.6. Methodology: independent benchmarks place Sonnet-class models at roughly 0.3 Wh per standard query; this session’s larger context windows, screenshot analysis, tool use overhead, and iterative interview-style development push the total toward 10 to 12 Wh. For reference, a single inference rack running frontier model workloads draws 10 to 30 kWh per hour. The article documenting how AI platforms extract professional identity data used roughly what it takes to run one of those racks for three seconds. No major AI provider publishes standardized per-session energy consumption data. These figures use the best available third-party benchmarks and should be treated as informed estimates, not precision measurements.
Dark AI Defense™ is an independent publication. No sponsored content. No affiliate relationships. Based in the Philadelphia area.
