Once is all it takes, from that point forward you can't fully trust anything they say about their privacy / security.
The only real questions are: is this an april fools? And does it matter?
"Hey George, did you hear Reddit has a canary now too. Ok, add it to the list. Pick a user there and issue an NSL. And don't forget about Google and FB this month as well, they are about to reset theirs".
Putting oneself in the shoes of such an actor this is a rational approach to take.
Can be done by re-interpreting what is happening -- "we are not issuing bogus NSLs to troll them, we are fighting terrorism and these sites deliberately shelter and protect terrorists and other criminals. We want to periodically issue NSLs to establish protocols and methods so we can more effectively protect our country and do our work".
So it has to be story which will look good on paper and workers will tell themselves without feeling like they are doing something illegal.
Another way is to do it as a side-effect of something else -- say "we decided to double our efforts to track down drug dealers on these sites, therefore we'll put 2x more people on it and they will conduct research and open new cases and so on". So simply by allocating more resources to the "problem" they'll ensure any of these large sites will simply get a constant stream of NSLs without explictly writing that down as "we are busting the canaries" as a goal anywhere.