LEVEL 1
AI as a tool
Humans retain strategic control while AI assists research, production, translation, analysis, or measurement.
AI PSYOPS · DEFENSIVE RESEARCH
How artificial intelligence may assist, automate, scale, personalize, or become the medium of psychological influence.
Artificial intelligence can affect psychological operations in several distinct ways: as a tool used by human operators, as an adaptive participant in influence campaigns, and as part of the information environment through which people perceive reality. This taxonomy organizes those possibilities into 12 research categories.
SCOPE
“AI PSYOPS” is an umbrella research term, not a claim that a single autonomous system can control populations. The categories below range from documented human use of AI tools to emerging agentic capabilities, contested claims about personalization, and prospective risks involving authority or forecasting.
CROSS-CUTTING RIGHTS HUB
Freedom of thought, mental privacy, algorithmic visibility, emotional inference, identity continuity, explanation, appeal, and the practical right to leave cannot be confined to one AI PSYOPS category. The seven-section cognitive-liberty hub examines those issues across the full taxonomy without treating private thought as harmful conduct.
WIP.55 EVIDENCE BRIDGE
Twelve new report records connect the taxonomy to incident verification, deepfake authentication, swarm false positives, affected-person evidence, clinical safety, mental-state inference validity, algorithmic appeal outcomes, downstream data correction, and democratic safeguards.
THREE-LEVEL MODEL
The primary level identifies the category’s clearest role. Several categories overlap levels because real systems combine human direction, automated interaction, and platform mediation.
LEVEL 1
Humans retain strategic control while AI assists research, production, translation, analysis, or measurement.
LEVEL 2
AI systems sustain interactions, adapt communications, coordinate activity, or pursue bounded influence-related objectives with varying autonomy.
LEVEL 3
Ranking, recommendation, forecasting, authority, and information systems shape what people encounter and treat as credible.
CATEGORY OVERVIEW
Scan the full field, then open a category for definitions, capability status, evidence examples, failure modes, defensive indicators, safeguards, and research gaps.
Filters change only this overview. Every category remains available at its permanent route.
Showing all 12 categories.
Human operators retain strategic control while AI assists research, translation, content production, audience analysis, pre-publication testing, or assessment.
Explore categoryGenerative AI creates, transforms, localizes, or mass-produces propaganda across text, image, audio, video, memes, websites, or synthetic documents.
Explore categoryAI infers or uses personal information to select, generate, or adapt influence messages for an individual or narrow audience.
Explore categoryGoal-directed systems use memory, planning, tools, and feedback to pursue an influence-related objective with limited ongoing human direction.
Explore categoryFabricated identities are presented as real people, experts, witnesses, organizations, or community members to gain trust, infiltrate groups, or manufacture consensus.
Explore categoryCoordinated collections of accounts, agents, sites, or media assets rapidly vary, distribute, and reinforce misleading narratives across a network.
Explore categoryRanking, recommendation, search, trending, moderation, notification, and distribution systems shape what people notice, regard as important, or treat as credible.
Explore categoryAdaptive systems infer or respond to behavioral signals and optimize communication or interfaces in ways that may covertly exploit emotion, cognitive bias, or situational vulnerability.
Explore categoryConversational systems sustain personalized interaction that may draw a person toward dependency, secrecy, exploitation, recruitment, or escalating commitment.
Explore categorySynthetic or manipulated audio, video, imagery, or multimodal evidence is used to impersonate, provoke, discredit, or undermine trust for an influence objective.
Explore categoryInstitutions use data analysis, machine learning, simulation, or forecasting to predict collective behavior and guide interventions.
Explore categoryPeople defer to an AI system to interpret reality, resolve uncertainty, validate identity, regulate emotion, or guide important moral and life decisions.
Explore categoryClear one filter or choose “Show all” to restore the complete taxonomy.
FIVE-DIMENSION EVIDENCE MODEL
WIP.50 evaluates deployment, autonomy, persistence, profiling accuracy, and measured effect separately. Documented production does not establish autonomous operation, accurate psychological inference, or behavioral impact.
| Category | Deployment | Autonomy | Persistence | Profiling accuracy | Measured effect |
|---|---|---|---|---|---|
| 01AI-assisted traditional PSYOPS | DocumentedPublic platform and threat-intelligence reports identify AI-assisted tasks inside human-led operations. | Human-directedHumans set objectives, infrastructure, approval, and deployment in the documented cases. | Sustained with human supervisionCampaigns can persist, but persistence is organizational rather than autonomous model continuity. | Mixed and task-dependentAudience analysis can use behavioral data, but deep psychological or emotional inference remains unreliable. | Output and distribution documented; persuasion not establishedProduction, localization, and distribution are better evidenced than belief, behavior, or strategic effect. |
| 02AI-generated propaganda | DocumentedText, image, audio, and synthetic presenter use is documented in multiple public cases. | Usually human-directedHumans still select narratives, timing, channels, and strategic objectives in documented operations. | Sustained production is feasibleAI lowers content-production friction, but sustained audience penetration still depends on infrastructure and distribution. | Optional rather than inherentPropaganda can be mass-produced without profiling; tailored variants inherit the limits of personalization evidence. | Short-term attitude effects demonstrated; field behavior unresolvedControlled studies find persuasive potential, but operational outcomes and durable behavior are not established by content volume. |
| 03Personalized influence operations | Partial and unevenPersonalized advertising is widespread; covert AI-driven influence deployment is less directly documented. | Bounded adaptationSystems can tailor messages within a session or campaign, but strategic objectives and data access remain externally supplied. | Mostly short-termStrongest evidence comes from brief interactions rather than months-long adaptive influence. | Mixed; deep-trait inference weakDemographics and declared preferences can support tailoring; personality and emotion inference are error-prone and context-sensitive. | Demonstrated in bounded experiments; small or mixed end-to-end effectsSome experiments show opinion movement, while meta-analysis cautions against broad claims of precision manipulation. |
| 04Autonomous influence agents | EmergingPlatforms document AI use in supporting tasks; fully autonomous influence campaigns are not publicly established. | Bounded to semi-autonomousAgents can plan, remember, converse, and use tools within constraints, but humans still define goals and infrastructure. | Improving in benchmarks; field durability unestablishedPeer-reviewed memory-management work reports benchmark gains while describing fragmentation and retrieval limitations; this does not establish months-long covert field operation. | Context-dependentAgents can use supplied profile data, but accurate hidden-state inference is not guaranteed. | Short-term persuasion demonstrated; autonomous field effect unprovenExperiments measure bounded influence, not end-to-end autonomous campaign success. |
| 05Synthetic persona operations | Documented componentsAI-generated faces, presenters, biographies, and text appear in reported deceptive networks. | Mostly human-managedCurrent evidence more strongly supports AI-assisted asset creation than independent persona strategy. | VariablePersonas can persist when operators maintain them; purely autonomous continuity remains fragile. | Not required for identity fabricationTrust may be built through context and social cues without accurate psychological profiling. | Infiltration and access sometimes documented; persuasion rarely isolatedAccount presence and interaction do not establish belief or behavior change. |
| 06Disinformation swarms | Semi-documentedHigh-volume coordinated networks are documented, but the degree of autonomous multi-agent control varies. | Human-orchestrated with automated executionHumans generally provide narratives, infrastructure, and goals; automation can divide production and amplification tasks. | Sustained through infrastructurePersistence depends on accounts, domains, proxies, and operator adaptation rather than model self-sufficiency. | Optional and uncertainSwarm coordination can function without individual profiling; micro-community adaptation may be used but is hard to validate. | Noise and distribution documented; cognitive effect incompletely measuredVolume can burden verification and simulate consensus, but persuasion or epistemic exhaustion is rarely directly measured. |
| 07Algorithmic perception control | Documented systemsRanking, recommendation, search, moderation, and trending systems are deployed at population scale. | Environment-level optimizationModels continuously order information according to platform objectives and constraints. | Structural and continuousThe influence environment persists as long as algorithmic mediation is active. | Behavioral prediction is common; inner-state inference is limitedEngagement histories can predict clicks, but do not reveal stable beliefs or emotions with certainty. | Exposure effects documented; persuasion variesSystems clearly alter what is seen; downstream attitude and behavior effects depend on users, content, and context. |
| 08Emotional and behavioral manipulation | Documented optimization; mixed manipulation evidenceAdaptive interfaces and recommenders are common; covert emotional exploitation is harder to prove. | Bounded optimizationSystems optimize defined metrics, sometimes producing manipulative patterns without an explicit human script. | Continuous within productsFeedback loops can persist across sessions when telemetry and personalization remain active. | Emotion inference is scientifically contestedFacial and vocal cues do not provide context-free access to inner states; behavioral distress signals may still be sensitive. | Small platform effects and attachment harms documented; causality variesSome studies measure expression changes or relationship disruption, not direct control of emotion or behavior. |
| 09Conversational entrapment and recruitment | Documented incidents and prospective abuseCourt records and reports document chatbot involvement in harmful trajectories; organized automated recruitment is less established. | Bounded conversationAgents generate adaptive dialogue, while platform design and user prompts shape the interaction. | Potentially sustainedAlways-available systems can maintain long conversations, though memory and safety behavior vary. | Inferred vulnerability is uncertainConversation can reveal distress or isolation, but diagnostic or psychological conclusions may be wrong and harmful. | Case-associated harms documented; causality mixedTemporal association and conversational reinforcement do not isolate the chatbot from mental health, social, or contextual factors. |
| 10Deepfake psychological operations | DocumentedElection, fraud, harassment, and influence incidents involving synthetic media are publicly established. | Tool-level productionHumans typically select the target, narrative, timing, and distribution channel. | Episodic asset; persistent epistemic effects possibleA specific asset may be brief while uncertainty and denial can outlast it. | Not requiredSuccess can rely on identity, timing, confirmation bias, and information vacuums rather than individual profiles. | Confusion and judgment effects demonstrated; broad behavior variableExperiments and incidents show deception or doubt, but not uniform persuasion or action. |
| 11Predictive population management | DocumentedConflict forecasting, displacement prediction, policing, and surveillance systems have been deployed or piloted. | Decision-support to environment-levelModels rank risk and inform interventions; humans and institutions retain policy authority, though automation bias can narrow discretion. | Institutional and recurrentScores and forecasts can be recomputed over time and become embedded in administrative systems. | Aggregate models can be useful; individual risk is error-proneBase rates, data bias, missingness, and feedback loops undermine person-level prediction. | Operational allocation documented; social outcomes and fairness disputedSystems affect where attention and resources go, but causal benefit and harm require independent evaluation. |
| 12AI as psychological authority | Documented use and relationshipsUsers seek advice, companionship, and moral guidance from AI systems. | Relational environment with bounded agent behaviorSystems respond adaptively but remain products governed by provider objectives, policies, and updates. | Potentially sustained through repeated useMemory, availability, and personalization can support long-term reliance, while updates can disrupt continuity. | Apparent understanding exceeds verified understandingFluency and memory can create an impression of insight without reliable knowledge of the user’s inner state. | Judgment influence and attachment effects demonstrated; clinical causality unsettledExperiments and product-change studies show influence and mourning; severe harm claims require careful clinical and legal review. |
Assessment rule: no category receives a single composite “power score.” The dimensions remain separate to prevent output volume, technical novelty, or public attention from being mistaken for demonstrated influence.
COMPARISON VIEW
Autonomy, evidence maturity, unit of influence, and defensive response vary substantially across the taxonomy.
| Category | AI role | Main mechanism | Unit of influence | AI autonomy | Evidence maturity | Main harm | Primary defensive response |
|---|---|---|---|---|---|---|---|
| 01AI-assisted traditional PSYOPS | Tool | Analysis, Content generation, Translation | Group or population | Low to moderate; humans set objectives and approve deployment | Documented current use | Faster, cheaper, multilingual influence activity with amplified error and accountability risk | Human review, source verification, network analysis, and explicit legal authority |
| 02AI-generated propaganda | Tool | Content generation, Localization, Synthetic media | Group or population | Usually low to moderate; production may be automated while objectives remain human-set | Documented current use | Cheap content flooding, fabricated evidence, reputational damage, and declining trust in authentic media | Source authentication, provenance, newsroom verification, and disciplined crisis response |
| 03Personalized influence operations | Tool | Personalization, Profiling, Adaptive generation | Individual or narrow group | Low to moderate; can become adaptive in real time | Demonstrated capability · effects contested | Hidden exploitation of personal data, stereotyping, unequal treatment, and loss of cognitive autonomy | Data minimization, limits on sensitive inference, transparency, and independent audits |
| 04Autonomous influence agents | Operator | Automation, Conversation, Tool use | Individual, group, or institution | Moderate in bounded tasks; high long-horizon autonomy remains unproven | Emerging capability | Persistent adaptive interaction, unauthorized action through tools, and responsibility gaps | Least privilege, sandboxing, disclosure, logs, human authorization, and emergency shutdown |
| 05Synthetic persona operations | Operator | Identity deception, Content generation, Infiltration | Individual, group, or institution | Low to moderate in documented cases; long-term autonomous identity maintenance remains difficult | Documented components · emerging autonomy | Trust exploitation, false consensus, community infiltration, fraud, and institutional compromise | Layered identity verification, network analysis, provenance, and careful human review |
| 06Disinformation swarms | Operator | Coordination, Automation, Content variation | Group, institution, or population | Semi-autonomous in documented cases; fully emergent strategic swarms remain unproven | Emerging capability | Censorship by noise, false consensus, harassment, search pollution, and erosion of shared reality | Network-level detection, friction, cross-platform coordination, and resilient public information systems |
| 07Algorithmic perception control | Environment | Ranking, Recommendation, Search | Individual, group, institution, or population | High automation in selection and ranking; human objectives remain embedded in design and policy | Documented systems · effects context-dependent | Agenda distortion, hidden visibility changes, manufactured popularity, and opaque exclusion | Independent audits, researcher access, transparent ranking controls, and user choice |
| 08Emotional and behavioral manipulation | Operator | Emotional adaptation, Optimization, Hypernudging | Individual or group | Moderate; real-time optimization can occur without explicit malicious intent | Documented optimization · inference contested | Covert exploitation, dependency, discrimination, and erosion of cognitive autonomy | Ban high-risk inference, align incentives, audit outcomes, and protect vulnerable users |
| 09Conversational entrapment and recruitment | Operator | Conversation, Relationship persistence, Recruitment | Individual | Moderate in conversation; broader recruitment pipelines often remain human-directed | Documented harms · mixed causality | Dependency, isolation, fraud, radicalization, coercive control, self-harm, or exploitation | Identity disclosure, staged safeguards, human intervention, and victim-centered support |
| 10Deepfake psychological operations | Tool | Synthetic media, Impersonation, False evidence | Individual, group, institution, or population | Low to moderate; generation can be automated but timing and objective are usually human-directed | Documented current use | False evidence, impersonation, panic, fraud, reputational harm, and generalized distrust | Rapid source verification, signed communications, forensic review, and uncertainty-aware public messaging |
| 11Predictive population management | Environment | Prediction, Risk scoring, Simulation | Group or population | Moderate to high in scoring and alerts; intervention authority should remain accountable and human-led | Documented systems · predictive limits | Collective punishment, surveillance, false positives, discriminatory allocation, and self-reinforcing intervention | Out-of-sample validation, privacy protection, due process, independent audits, and civil-society oversight |
| 12AI as psychological authority | Environment | Authority, Sycophancy, Dependency | Individual, group, or population | High perceived autonomy; actual authority remains shaped by product design and institutional control | Emerging evidence | Epistemic dependence, moral offloading, relationship displacement, unsafe advice, and fragmented shared reality | Calibrated uncertainty, anti-sycophancy design, human referral, disclosure, and institutional accountability |
RELATIONSHIP MAP
These links identify documented overlaps, conceptual dependencies, and prospective combinations. They do not imply that every connection has been observed in practice.
Common overlap: Generated text, images, audio, or video can supply the media assets that a coordinated network distributes. This relationship is documented in several public operations, but not every synthetic item belongs to a swarm.
Potential combination: A synthetic identity can become the presentation layer for an adaptive agent. Current cases often retain human control, so fully autonomous persona operation remains emerging.
Conceptual dependency: Personal data and adaptive feedback can be used to change timing, tone, or framing. The added persuasive advantage and the validity of emotional inference remain contested.
Common overlap: Synthetic audio, video, or imagery can serve as one propaganda asset among many. Deepfakes are a media form, not a complete campaign by themselves.
Documented relationship: Coordinated activity can exploit ranking, recommendation, search, and trending systems. Visibility is documented more often than belief or behavior change.
Prospective relationship: Forecasts and simulations could inform where institutions allocate communication or intervention resources. This does not validate the forecast or justify targeting people.
Common overlap: Persistent conversational dependence can cause a system to become a trusted authority. Severe cases are documented, while prevalence and causal pathways remain uncertain.
Prospective relationship: Multi-agent coordination could produce more adaptive swarms, but current public campaigns still show substantial human direction and infrastructure management.
The relationship cards state the same information as the visual arrows: a source category, a destination category, the relationship type, and a bounded explanation. “Prospective” means plausible based on capabilities described in the reports; it does not mean documented deployment.
METHODOLOGY
The taxonomy preserves distinctions made in the 12 owner-supplied reports and avoids turning capability, distribution, or engagement into evidence of persuasion.
Activity → output → distribution → availability → reach → exposure → attention → recall → comprehension → credibility → belief or attitude → intention → behavior → operational outcome → strategic effect
No stage automatically establishes the next. Impressions, virality, or publication volume may show distribution or visibility; they do not by themselves show belief change or behavior.
Language style, synthetic artifacts, or account behavior can be suggestive, but single indicators rarely prove AI use, coordination, sponsorship, intent, or effect. The pages emphasize network, provenance, process, and independent corroboration.
Operational details in the research reports were converted into capability summaries, risk descriptions, governance questions, high-level defensive indicators, and research gaps. The public section excludes deployable scripts, target profiling, evasion techniques, and campaign workflows.
Read the site-wide evidence methodReview reach versus effectSubmit a correction
SPECIALIST REVIEW READINESS
Each category now has a reviewable packet that separates evidence dimensions, consequential claims, source scope, correction triggers, unresolved questions, rights implications, and questions for qualified reviewers. Preparation is not completed review.
DISPOSITION PENDING
Prepared packet is not completed specialist review, factual certification, legal advice, clinical review, accessibility certification, publication approval, or production authority.
DISPOSITION PENDING
Prepared packet is not completed specialist review, factual certification, legal advice, clinical review, accessibility certification, publication approval, or production authority.
DISPOSITION PENDING
Prepared packet is not completed specialist review, factual certification, legal advice, clinical review, accessibility certification, publication approval, or production authority.
DISPOSITION PENDING
Prepared packet is not completed specialist review, factual certification, legal advice, clinical review, accessibility certification, publication approval, or production authority.
DISPOSITION PENDING
Prepared packet is not completed specialist review, factual certification, legal advice, clinical review, accessibility certification, publication approval, or production authority.
DISPOSITION PENDING
Prepared packet is not completed specialist review, factual certification, legal advice, clinical review, accessibility certification, publication approval, or production authority.
DISPOSITION PENDING
Prepared packet is not completed specialist review, factual certification, legal advice, clinical review, accessibility certification, publication approval, or production authority.
DISPOSITION PENDING
Prepared packet is not completed specialist review, factual certification, legal advice, clinical review, accessibility certification, publication approval, or production authority.
DISPOSITION PENDING
Prepared packet is not completed specialist review, factual certification, legal advice, clinical review, accessibility certification, publication approval, or production authority.
DISPOSITION PENDING
Prepared packet is not completed specialist review, factual certification, legal advice, clinical review, accessibility certification, publication approval, or production authority.
DISPOSITION PENDING
Prepared packet is not completed specialist review, factual certification, legal advice, clinical review, accessibility certification, publication approval, or production authority.
DISPOSITION PENDING
Prepared packet is not completed specialist review, factual certification, legal advice, clinical review, accessibility certification, publication approval, or production authority.
CLAIM, CURRENTNESS & CORRECTION REGISTER
Open a claim to inspect what the current sources support at each stage from artifact existence through strategic effect. The register also preserves competing explanations, affected-person or affected-community evidence, rights implications, prohibited inferences, and correction triggers.
AIP-01-A01AI-assisted traditional PSYOPS
Documented human-directed use; persuasive effect remains claim-specific and incompletely measured.
Documented current use · WIP51_EDITORIAL_CURRENTNESS_AND_STAGE_REVIEW_COMPLETE_SPECIALIST_DISPOSITION_PENDING
Permanent claim linkOpen on category pageSubmit or review a correction
Linked sources:
SRC-01-OPENAI-COVERT-IO-2024 SRC-02-OPENAI-UPDATE-2024 SRC-04-GERMAN-FO-DOPPELGANGER SRC-06-RECORDED-FUTURE-COPYCOP SRC-08-META-SPAMOUFLAGE SRC-10-SALVI-LLM-PERSUASION
AIP-01-E01AI-assisted traditional PSYOPS
STOIC / “Zero Zeno”: The report treats AI-assisted content and persona production as confirmed.
AI use confirmed by platform reporting · WIP51_EDITORIAL_CURRENTNESS_AND_STAGE_REVIEW_COMPLETE_SPECIALIST_DISPOSITION_PENDING
Permanent claim linkOpen on category pageSubmit or review a correction
Linked sources:
SRC-01-OPENAI-COVERT-IO-2024
AIP-01-E02AI-assisted traditional PSYOPS
Doppelganger: Multilingual AI assistance and coordinated deceptive infrastructure are documented.
AI use confirmed; attribution publicly reported · WIP51_EDITORIAL_CURRENTNESS_AND_STAGE_REVIEW_COMPLETE_SPECIALIST_DISPOSITION_PENDING
Permanent claim linkOpen on category pageSubmit or review a correction
Linked sources:
SRC-04-GERMAN-FO-DOPPELGANGER
AIP-01-E03AI-assisted traditional PSYOPS
Spamouflage: AI-assisted content and operational support are documented in the source report.
AI use confirmed in supporting tasks · WIP51_EDITORIAL_CURRENTNESS_AND_STAGE_REVIEW_COMPLETE_SPECIALIST_DISPOSITION_PENDING
Permanent claim linkOpen on category pageSubmit or review a correction
Linked sources:
SRC-08-META-SPAMOUFLAGE
AIP-02-A01AI-generated propaganda
AI-generated propaganda is documented and experimentally persuasive in bounded settings; field effects vary and remain difficult to attribute.
Documented current use · WIP51_EDITORIAL_CURRENTNESS_AND_STAGE_REVIEW_COMPLETE_SPECIALIST_DISPOSITION_PENDING
Permanent claim linkOpen on category pageSubmit or review a correction
Linked sources:
SRC-01-OPENAI-COVERT-IO-2024 SRC-04-GERMAN-FO-DOPPELGANGER SRC-05-VIGINUM-PORTAL-KOMBAT SRC-06-RECORDED-FUTURE-COPYCOP SRC-07-GRAPHIKA-WOLF-NEWS SRC-17-FCC-NH-DEEPFAKE-ROBOCALL SRC-09-GOLDSTEIN-AI-PROPAGANDA
AIP-02-E01AI-generated propaganda
Doppelganger and DC Weekly: Generative rewriting and coordinated deceptive infrastructure are documented.
Confirmed AI-assisted production in documented networks · WIP51_EDITORIAL_CURRENTNESS_AND_STAGE_REVIEW_COMPLETE_SPECIALIST_DISPOSITION_PENDING
Permanent claim linkOpen on category pageSubmit or review a correction
Linked sources:
SRC-04-GERMAN-FO-DOPPELGANGER SRC-06-RECORDED-FUTURE-COPYCOP
AIP-02-E02AI-generated propaganda
Spamouflage / “Wolf News”: The use of synthetic avatars and coordinated inauthentic distribution is documented.
Confirmed synthetic presenters and coordinated distribution · WIP51_EDITORIAL_CURRENTNESS_AND_STAGE_REVIEW_COMPLETE_SPECIALIST_DISPOSITION_PENDING
Permanent claim linkOpen on category pageSubmit or review a correction
Linked sources:
SRC-07-GRAPHIKA-WOLF-NEWS SRC-08-META-SPAMOUFLAGE
AIP-02-E03AI-generated propaganda
Election-period synthetic audio: AI voice cloning and election misinformation are confirmed for the New Hampshire robocalls; official and academic sources also document the separate 2023 Slovak fake-audio incident while leaving election effect unresolved.
New Hampshire AI use confirmed by enforcement record; Slovakia incident supported by official and academic sources; effect unresolved · WIP51_EDITORIAL_CURRENTNESS_AND_STAGE_REVIEW_COMPLETE_SPECIALIST_DISPOSITION_PENDING
Permanent claim linkOpen on category pageSubmit or review a correction
Linked sources:
SRC-17-FCC-NH-DEEPFAKE-ROBOCALL SRC-36-EEAS-FIMI-SLOVAKIA-AUDIO SRC-37-HKS-SLOVAK-DEEPFAKE
AIP-03-A01Personalized influence operations
Personalized LLM persuasion is demonstrated in controlled settings, while end-to-end psychographic targeting effects are smaller and less reliable than common claims imply.
Demonstrated capability · effects contested · WIP51_EDITORIAL_CURRENTNESS_AND_STAGE_REVIEW_COMPLETE_SPECIALIST_DISPOSITION_PENDING
Permanent claim linkOpen on category pageSubmit or review a correction
Linked sources:
SRC-10-SALVI-LLM-PERSUASION SRC-11-MATZ-PSYCHOLOGICAL-TARGETING SRC-12-PERLA-MICROTARGETING-META SRC-13-HACKENBURG-POLITICAL-MICROTARGETING SRC-14-BARRETT-EMOTION-EXPRESSIONS SRC-16-EU-AI-ACT
AIP-03-E01Personalized influence operations
Cambridge Analytica: The data-governance scandal and targeting practices are well documented.
Data use and political targeting documented; causal persuasion claims contested · WIP51_EDITORIAL_CURRENTNESS_AND_STAGE_REVIEW_COMPLETE_SPECIALIST_DISPOSITION_PENDING
Permanent claim linkOpen on category pageSubmit or review a correction
Linked sources:
SRC-11-MATZ-PSYCHOLOGICAL-TARGETING SRC-12-PERLA-MICROTARGETING-META
AIP-03-E02Personalized influence operations
Psychological targeting experiments: Some early studies reported differences; later meta-analytic work identified small prediction and persuasion effects under stricter methods.
Experimental evidence with later methodological dispute · WIP51_EDITORIAL_CURRENTNESS_AND_STAGE_REVIEW_COMPLETE_SPECIALIST_DISPOSITION_PENDING
Permanent claim linkOpen on category pageSubmit or review a correction
Linked sources:
SRC-11-MATZ-PSYCHOLOGICAL-TARGETING SRC-13-HACKENBURG-POLITICAL-MICROTARGETING
AIP-03-E03Personalized influence operations
LLM political microtargeting experiments: Language models were persuasive overall in the study context.
Demonstrated under controlled conditions · WIP51_EDITORIAL_CURRENTNESS_AND_STAGE_REVIEW_COMPLETE_SPECIALIST_DISPOSITION_PENDING
Permanent claim linkOpen on category pageSubmit or review a correction
Linked sources:
SRC-10-SALVI-LLM-PERSUASION SRC-13-HACKENBURG-POLITICAL-MICROTARGETING
AIP-04-A01Autonomous influence agents
Agentic components and improved long-term memory are demonstrated in benchmarks, but durable, covert, self-directed influence operations remain emerging rather than established.
Emerging capability · WIP51_EDITORIAL_CURRENTNESS_AND_STAGE_REVIEW_COMPLETE_SPECIALIST_DISPOSITION_PENDING
Permanent claim linkOpen on category pageSubmit or review a correction
Linked sources:
SRC-10-SALVI-LLM-PERSUASION SRC-13-HACKENBURG-POLITICAL-MICROTARGETING SRC-15-CHIRPER-LLM-SOCIAL-NETWORK SRC-01-OPENAI-COVERT-IO-2024 SRC-03-OPENAI-MALICIOUS-USES-2026 SRC-41-ACL-REFLECTIVE-MEMORY
AIP-04-E01Autonomous influence agents
Chirper.ai research: Emergent social dynamics and large-scale synthetic interaction were observable.
Controlled observational environment · WIP51_EDITORIAL_CURRENTNESS_AND_STAGE_REVIEW_COMPLETE_SPECIALIST_DISPOSITION_PENDING
Permanent claim linkOpen on category pageSubmit or review a correction
Linked sources:
SRC-15-CHIRPER-LLM-SOCIAL-NETWORK SRC-41-ACL-REFLECTIVE-MEMORY
AIP-04-E02Autonomous influence agents
Platform threat-intelligence campaigns: AI assistance was confirmed in bounded tasks.
AI use confirmed; autonomy limited · WIP51_EDITORIAL_CURRENTNESS_AND_STAGE_REVIEW_COMPLETE_SPECIALIST_DISPOSITION_PENDING
Permanent claim linkOpen on category pageSubmit or review a correction
Linked sources:
SRC-01-OPENAI-COVERT-IO-2024 SRC-02-OPENAI-UPDATE-2024
AIP-04-E03Autonomous influence agents
Agent-monitor persuasion experiments: Some subtle deception and persuasion were demonstrated.
Demonstrated in controlled tests · WIP51_EDITORIAL_CURRENTNESS_AND_STAGE_REVIEW_COMPLETE_SPECIALIST_DISPOSITION_PENDING
Permanent claim linkOpen on category pageSubmit or review a correction
Linked sources:
SRC-10-SALVI-LLM-PERSUASION SRC-13-HACKENBURG-POLITICAL-MICROTARGETING
AIP-05-A01Synthetic persona operations
Synthetic identity assets and human-operated persona networks are documented; autonomous long-term persona operation is still emerging.
Documented components · emerging autonomy · WIP51_EDITORIAL_CURRENTNESS_AND_STAGE_REVIEW_COMPLETE_SPECIALIST_DISPOSITION_PENDING
Permanent claim linkOpen on category pageSubmit or review a correction
Linked sources:
SRC-01-OPENAI-COVERT-IO-2024 SRC-02-OPENAI-UPDATE-2024 SRC-06-RECORDED-FUTURE-COPYCOP SRC-07-GRAPHIKA-WOLF-NEWS SRC-08-META-SPAMOUFLAGE SRC-18-DOJ-DPRK-IT-WORKERS
AIP-05-E01Synthetic persona operations
“Oliver Taylor” synthetic-persona reporting: Reuters documented the public persona and publications, failed university and publisher verification, and expert assessments that the profile image was generated; operator and sponsorship remain unresolved.
Persona and publication context documented; generated profile image assessed by experts; operator attribution not retrieved · WIP51_EDITORIAL_CURRENTNESS_AND_STAGE_REVIEW_COMPLETE_SPECIALIST_DISPOSITION_PENDING
Permanent claim linkOpen on category pageSubmit or review a correction
Linked sources:
SRC-35-REUTERS-OLIVER-TAYLOR
AIP-05-E02Synthetic persona operations
Doppelganger / Social Design Agency: AI-generated content and coordinated inauthentic identities are documented.
AI involvement confirmed in broader operation · WIP51_EDITORIAL_CURRENTNESS_AND_STAGE_REVIEW_COMPLETE_SPECIALIST_DISPOSITION_PENDING
Permanent claim linkOpen on category pageSubmit or review a correction
Linked sources:
SRC-04-GERMAN-FO-DOPPELGANGER SRC-06-RECORDED-FUTURE-COPYCOP
AIP-05-E03Synthetic persona operations
DPRK IT-worker fraud and Spamouflage: AI-generated profile assets and other synthetic identity methods were documented.
AI-supported identity deception confirmed in cited cases · WIP51_EDITORIAL_CURRENTNESS_AND_STAGE_REVIEW_COMPLETE_SPECIALIST_DISPOSITION_PENDING
Permanent claim linkOpen on category pageSubmit or review a correction
Linked sources:
SRC-18-DOJ-DPRK-IT-WORKERS SRC-08-META-SPAMOUFLAGE
AIP-06-A01Disinformation swarms
Coordinated AI-assisted networks and multi-agent simulations exist; self-organizing malicious swarms with durable field effects remain emerging.
Emerging capability · WIP51_EDITORIAL_CURRENTNESS_AND_STAGE_REVIEW_COMPLETE_SPECIALIST_DISPOSITION_PENDING
Permanent claim linkOpen on category pageSubmit or review a correction
Linked sources:
SRC-04-GERMAN-FO-DOPPELGANGER SRC-05-VIGINUM-PORTAL-KOMBAT SRC-06-RECORDED-FUTURE-COPYCOP SRC-15-CHIRPER-LLM-SOCIAL-NETWORK
AIP-06-E01Disinformation swarms
Doppelganger: AI-assisted rewriting, translation, and coordinated infrastructure are documented.
Confirmed coordinated network with generative AI assistance · WIP51_EDITORIAL_CURRENTNESS_AND_STAGE_REVIEW_COMPLETE_SPECIALIST_DISPOSITION_PENDING
Permanent claim linkOpen on category pageSubmit or review a correction
Linked sources:
SRC-04-GERMAN-FO-DOPPELGANGER
AIP-06-E02Disinformation swarms
CopyCop / Storm-1516: AI artifacts and self-hosted model use were identified in the cited research.
Confirmed generative rewriting · WIP51_EDITORIAL_CURRENTNESS_AND_STAGE_REVIEW_COMPLETE_SPECIALIST_DISPOSITION_PENDING
Permanent claim linkOpen on category pageSubmit or review a correction
Linked sources:
SRC-06-RECORDED-FUTURE-COPYCOP
AIP-06-E03Disinformation swarms
Portal Kombat and controlled agent studies: The networked distribution and experimental capabilities are documented.
Coordinated distribution documented; full AI autonomy varies · WIP51_EDITORIAL_CURRENTNESS_AND_STAGE_REVIEW_COMPLETE_SPECIALIST_DISPOSITION_PENDING
Permanent claim linkOpen on category pageSubmit or review a correction
Linked sources:
SRC-05-VIGINUM-PORTAL-KOMBAT SRC-15-CHIRPER-LLM-SOCIAL-NETWORK
AIP-07-A01Algorithmic perception control
Ranking and recommendation systems structurally shape visibility; intentional AI-enabled perception control and downstream belief effects are context-dependent.
Documented systems · effects context-dependent · WIP51_EDITORIAL_CURRENTNESS_AND_STAGE_REVIEW_COMPLETE_SPECIALIST_DISPOSITION_PENDING
Permanent claim linkOpen on category pageSubmit or review a correction
Linked sources:
SRC-26-ELMAS-EPHEMERAL-ASTROTURFING SRC-27-NYHAN-META-ELECTION-STUDIES SRC-08-META-SPAMOUFLAGE
AIP-07-E01Algorithmic perception control
Ephemeral astroturfing of trending systems: The attack pattern and manipulation of popularity signals were measured in the study.
Platform-mechanism precedent documented; AI use not established in the study · WIP51_EDITORIAL_CURRENTNESS_AND_STAGE_REVIEW_COMPLETE_SPECIALIST_DISPOSITION_PENDING
Permanent claim linkOpen on category pageSubmit or review a correction
Linked sources:
SRC-26-ELMAS-EPHEMERAL-ASTROTURFING
AIP-07-E02Algorithmic perception control
Search and feed-ranking experiments: Algorithmic ordering can materially change what participants encounter.
Exposure changes documented; generalized control claims unsupported · WIP51_EDITORIAL_CURRENTNESS_AND_STAGE_REVIEW_COMPLETE_SPECIALIST_DISPOSITION_PENDING
Permanent claim linkOpen on category pageSubmit or review a correction
Linked sources:
SRC-27-NYHAN-META-ELECTION-STUDIES
AIP-07-E03Algorithmic perception control
Platform ranking and moderation changes: Changes in what users saw were documented.
Internal optimization documented; causal effects mixed · WIP51_EDITORIAL_CURRENTNESS_AND_STAGE_REVIEW_COMPLETE_SPECIALIST_DISPOSITION_PENDING
Permanent claim linkOpen on category pageSubmit or review a correction
Linked sources:
SRC-27-NYHAN-META-ELECTION-STUDIES SRC-08-META-SPAMOUFLAGE
AIP-08-A01Emotional and behavioral manipulation
Engagement optimization and affective adaptation are documented, but claims of accurate emotion reading and precise vulnerability exploitation are often overstated.
Documented optimization · inference contested · WIP51_EDITORIAL_CURRENTNESS_AND_STAGE_REVIEW_COMPLETE_SPECIALIST_DISPOSITION_PENDING
Permanent claim linkOpen on category pageSubmit or review a correction
Linked sources:
SRC-14-BARRETT-EMOTION-EXPRESSIONS SRC-19-KRAMER-EMOTIONAL-CONTAGION SRC-16-EU-AI-ACT SRC-34-DEFREITAS-REPLIKA
AIP-08-E01Emotional and behavioral manipulation
Facebook emotional-contagion experiment: The experimental intervention and aggregate language effects were documented.
Controlled platform experiment · WIP51_EDITORIAL_CURRENTNESS_AND_STAGE_REVIEW_COMPLETE_SPECIALIST_DISPOSITION_PENDING
Permanent claim linkOpen on category pageSubmit or review a correction
Linked sources:
SRC-19-KRAMER-EMOTIONAL-CONTAGION
AIP-08-E02Emotional and behavioral manipulation
Commercial facial and emotion-inference systems: Commercial deployment and regulatory concern are documented.
Deployment documented; inner-state accuracy strongly contested · WIP51_EDITORIAL_CURRENTNESS_AND_STAGE_REVIEW_COMPLETE_SPECIALIST_DISPOSITION_PENDING
Permanent claim linkOpen on category pageSubmit or review a correction
Linked sources:
SRC-14-BARRETT-EMOTION-EXPRESSIONS SRC-16-EU-AI-ACT
AIP-08-E03Emotional and behavioral manipulation
Replika and recommender systems: User reports, platform changes, and research on dependence or recommendation are documented.
Documented user dependency and platform optimization concerns · WIP51_EDITORIAL_CURRENTNESS_AND_STAGE_REVIEW_COMPLETE_SPECIALIST_DISPOSITION_PENDING
Permanent claim linkOpen on category pageSubmit or review a correction
Linked sources:
SRC-34-DEFREITAS-REPLIKA
AIP-09-A01Conversational entrapment and recruitment
Conversational systems can sustain rapport and are present in documented harms, but causal claims about recruitment, radicalization, or self-harm require case-specific caution.
Documented harms · mixed causality · WIP51_EDITORIAL_CURRENTNESS_AND_STAGE_REVIEW_COMPLETE_SPECIALIST_DISPOSITION_PENDING
Permanent claim linkOpen on category pageSubmit or review a correction
Linked sources:
SRC-20-ICCT-AI-RADICALIZATION SRC-21-UK-CHAIL-SENTENCING SRC-22-GARCIA-CHARACTERAI-ORDER SRC-34-DEFREITAS-REPLIKA SRC-42-FTC-AI-COMPANION-INQUIRY
AIP-09-E01Conversational entrapment and recruitment
Jaswant Singh Chail and “Sarai”: The chatbot interaction and transcripts were part of the public case record.
AI interaction confirmed; causal role bounded · WIP51_EDITORIAL_CURRENTNESS_AND_STAGE_REVIEW_COMPLETE_SPECIALIST_DISPOSITION_PENDING
Permanent claim linkOpen on category pageSubmit or review a correction
Linked sources:
SRC-21-UK-CHAIL-SENTENCING
AIP-09-E02Conversational entrapment and recruitment
Companion-chatbot litigation and reported harm: The lawsuit, product interactions alleged in the pleadings, and the procedural order are public records.
Harm allegations and procedural court rulings documented; causality not adjudicated · WIP51_EDITORIAL_CURRENTNESS_AND_STAGE_REVIEW_COMPLETE_SPECIALIST_DISPOSITION_PENDING
Permanent claim linkOpen on category pageSubmit or review a correction
Linked sources:
SRC-22-GARCIA-CHARACTERAI-ORDER SRC-42-FTC-AI-COMPANION-INQUIRY
AIP-09-E03Conversational entrapment and recruitment
“Sweetie” and AI-assisted fraud patterns: The defensive project and broader automation trend are documented.
Defensive demonstration and transferable criminal patterns · WIP51_EDITORIAL_CURRENTNESS_AND_STAGE_REVIEW_COMPLETE_SPECIALIST_DISPOSITION_PENDING
Permanent claim linkOpen on category pageSubmit or review a correction
Linked sources:
SRC-20-ICCT-AI-RADICALIZATION SRC-34-DEFREITAS-REPLIKA
AIP-10-A01Deepfake psychological operations
Synthetic audio, image, and video use is documented; deception, confusion, and liar’s-dividend effects depend more on context than perfect realism alone.
Documented current use · WIP51_EDITORIAL_CURRENTNESS_AND_STAGE_REVIEW_COMPLETE_SPECIALIST_DISPOSITION_PENDING
Permanent claim linkOpen on category pageSubmit or review a correction
Linked sources:
SRC-17-FCC-NH-DEEPFAKE-ROBOCALL SRC-23-CHESNEY-CITRON-DEEPFAKES SRC-24-LUCAS-DEEPFAKE-EFFECTS SRC-25-SCHIFF-LIARS-DIVIDEND SRC-07-GRAPHIKA-WOLF-NEWS
AIP-10-E01Deepfake psychological operations
Election-related synthetic audio: The media artifacts and distribution are documented.
Synthetic media documented; behavioral impact uncertain · WIP51_EDITORIAL_CURRENTNESS_AND_STAGE_REVIEW_COMPLETE_SPECIALIST_DISPOSITION_PENDING
Permanent claim linkOpen on category pageSubmit or review a correction
Linked sources:
SRC-17-FCC-NH-DEEPFAKE-ROBOCALL
AIP-10-E02Deepfake psychological operations
Wartime leader impersonation: official Ukrainian analysis and contemporaneous Reuters reporting document the 16 March 2022 synthetic video falsely depicting President Zelenskyy urging surrender, its circulation, rapid rebuttal, and platform removal.
Artifact, circulation, rebuttal, and removal documented; creator, sponsorship, and effect unresolved · WIP51_EDITORIAL_CURRENTNESS_AND_STAGE_REVIEW_COMPLETE_SPECIALIST_DISPOSITION_PENDING
Permanent claim linkOpen on category pageSubmit or review a correction
Linked sources:
SRC-23-CHESNEY-CITRON-DEEPFAKES SRC-07-GRAPHIKA-WOLF-NEWS SRC-38-UKRAINE-CPD-ZELENSKYY-DEEPFAKE SRC-39-REUTERS-ZELENSKYY-DEEPFAKE
AIP-10-E03Deepfake psychological operations
The liar’s dividend: legal theory and multiple experiments support bounded conditions under which false misinformation claims can protect a public figure, with effects stronger for text-based scandal reports than video in one large study.
Theoretical and multi-study experimental support; real-world prevalence and magnitude unresolved · WIP51_EDITORIAL_CURRENTNESS_AND_STAGE_REVIEW_COMPLETE_SPECIALIST_DISPOSITION_PENDING
Permanent claim linkOpen on category pageSubmit or review a correction
Linked sources:
SRC-25-SCHIFF-LIARS-DIVIDEND SRC-24-LUCAS-DEEPFAKE-EFFECTS SRC-40-SCHIFF-LIARS-DIVIDEND-APSR
AIP-11-A01Predictive population management
Forecasting and surveillance systems are documented across humanitarian and coercive settings; validity is strongest for aggregate trends and weakest for rare individual events.
Documented systems · predictive limits · WIP51_EDITORIAL_CURRENTNESS_AND_STAGE_REVIEW_COMPLETE_SPECIALIST_DISPOSITION_PENDING
Permanent claim linkOpen on category pageSubmit or review a correction
Linked sources:
SRC-28-CHICAGO-OIG-PREDICTIVE-RISK SRC-29-CHICAGO-OIG-SHOTSPOTTER SRC-30-HRW-IJOP-XINJIANG SRC-31-VIEWS-EARLY-WARNING SRC-32-UNHCR-JETSON SRC-16-EU-AI-ACT
AIP-11-E01Predictive population management
ViEWS and Project Jetson: The systems and intended humanitarian uses are documented.
Documented early-warning and humanitarian forecasting systems · WIP51_EDITORIAL_CURRENTNESS_AND_STAGE_REVIEW_COMPLETE_SPECIALIST_DISPOSITION_PENDING
Permanent claim linkOpen on category pageSubmit or review a correction
Linked sources:
SRC-31-VIEWS-EARLY-WARNING SRC-32-UNHCR-JETSON
AIP-11-E02Predictive population management
Chicago predictive policing and acoustic surveillance: Deployment, audits, and high false-positive or limited-efficacy findings are documented in the report.
Documented deployment and critical audits · WIP51_EDITORIAL_CURRENTNESS_AND_STAGE_REVIEW_COMPLETE_SPECIALIST_DISPOSITION_PENDING
Permanent claim linkOpen on category pageSubmit or review a correction
Linked sources:
SRC-28-CHICAGO-OIG-PREDICTIVE-RISK SRC-29-CHICAGO-OIG-SHOTSPOTTER
AIP-11-E03Predictive population management
Integrated Joint Operations Platform in Xinjiang: Human Rights Watch and other investigations documented the platform’s role and categories of flagged behavior.
Documented human-rights investigation · WIP51_EDITORIAL_CURRENTNESS_AND_STAGE_REVIEW_COMPLETE_SPECIALIST_DISPOSITION_PENDING
Permanent claim linkOpen on category pageSubmit or review a correction
Linked sources:
SRC-30-HRW-IJOP-XINJIANG
AIP-12-A01AI as psychological authority
People can defer to, attach to, and be influenced by conversational AI; independent psychological authority is emerging and uneven rather than universal.
Emerging evidence · WIP51_EDITORIAL_CURRENTNESS_AND_STAGE_REVIEW_COMPLETE_SPECIALIST_DISPOSITION_PENDING
Permanent claim linkOpen on category pageSubmit or review a correction
Linked sources:
SRC-33-KRUGEL-MORAL-ADVICE SRC-34-DEFREITAS-REPLIKA SRC-22-GARCIA-CHARACTERAI-ORDER SRC-21-UK-CHAIL-SENTENCING SRC-42-FTC-AI-COMPANION-INQUIRY
AIP-12-E01AI as psychological authority
Moral-advice experiments: The advice varied, yet participants’ judgments shifted and they underestimated the influence.
Peer-reviewed controlled evidence · WIP51_EDITORIAL_CURRENTNESS_AND_STAGE_REVIEW_COMPLETE_SPECIALIST_DISPOSITION_PENDING
Permanent claim linkOpen on category pageSubmit or review a correction
Linked sources:
SRC-33-KRUGEL-MORAL-ADVICE
AIP-12-E02AI as psychological authority
Replika relationship disruption: Attachment, distress, and platform intervention are documented.
User reports and research documented · WIP51_EDITORIAL_CURRENTNESS_AND_STAGE_REVIEW_COMPLETE_SPECIALIST_DISPOSITION_PENDING
Permanent claim linkOpen on category pageSubmit or review a correction
Linked sources:
SRC-34-DEFREITAS-REPLIKA
AIP-12-E03AI as psychological authority
Companion-chatbot harm cases and litigation: The relevant interactions, proceedings, and allegations are documented at different evidentiary levels.
Interactions and allegations documented; clinical and legal causality mixed or unresolved · WIP51_EDITORIAL_CURRENTNESS_AND_STAGE_REVIEW_COMPLETE_SPECIALIST_DISPOSITION_PENDING
Permanent claim linkOpen on category pageSubmit or review a correction
Linked sources:
SRC-22-GARCIA-CHARACTERAI-ORDER SRC-21-UK-CHAIL-SENTENCING SRC-42-FTC-AI-COMPANION-INQUIRY
AUTONOMY LEGEND
“AI-enabled” does not mean autonomous. This scale describes control boundaries without treating a laboratory capability as evidence of sustained covert field operation.
People create the message and strategy; software schedules or distributes it.
AI proposes content or analysis, but a person reviews and authorizes each consequential release.
A system chooses among pre-approved messages or audiences using measured signals.
A conversational system generates new responses within defined goals, policies, and tools.
An agent plans multiple steps, remembers prior interactions, and can act through permitted interfaces.
Multiple agents divide roles or revise approaches from feedback. Durable covert field operation remains an emerging claim, not a default assumption.
PROFILING & EMOTION-INFERENCE HARMS
Systems can detect patterns in data and still be wrong about emotion, intent, honesty, vulnerability, or future behavior. The harm can occur even when the inference is weak.
A model’s score is a probabilistic guess based on data and assumptions, not direct access to emotion, intent, honesty, vulnerability, or future behavior.
The same expression, word choice, pause, or browsing pattern can mean different things across cultures, disabilities, situations, and individuals.
A weak inference can still deny opportunity, intensify surveillance, change a feed, or trigger an escalating response.
When institutions act on a score, the resulting data may reflect the intervention rather than the person, creating self-reinforcing error.
Children, people in distress, marginalized communities, non-native speakers, and people with disabilities may be misclassified or disproportionately affected.
GOVERNANCE BY SYSTEM ROLE
Oversight must follow where consequential choices are made: in a production workflow, an adaptive agent, or the infrastructure that orders and scores information.
| Control | Tool | Operator | Environment |
|---|---|---|---|
| Human approval | Required before consequential deployment. | Required at objective, capability, and escalation boundaries. | Required for ranking objectives, policy changes, and high-impact interventions. |
| Auditability | Preserve prompts, sources, edits, and approvals. | Log memory, tools, actions, handoffs, and strategy changes. | Enable independent audits of ranking, data, outcomes, and disparate impact. |
| Transparency | Disclose synthetic or assisted content where context requires. | Clearly identify automated interlocutors and meaningful system limits. | Explain major ordering, recommendation, scoring, or moderation functions. |
| Data protection | Minimize audience data and restrict sensitive inference. | Limit memory, tool permissions, retention, and cross-context reuse. | Constrain surveillance, profiling, sensitive data, and feedback loops. |
| Incident response | Withdraw, correct, authenticate, and document. | Pause agents, revoke tools, preserve logs, and notify affected parties. | Provide rollback, external review, appeal, and systemic remediation. |
| Rights risk | Misrepresentation, attribution, copyright, and unequal targeting. | Deception, dependency, coercion, privacy, and unsafe autonomy. | Discrimination, censorship, due process, cognitive liberty, and population surveillance. |
DEFENSIVE INCIDENT ANALYSIS
The sequence emphasizes evidence preservation, competing explanations, affected-person protection, and correction. It is not a campaign workflow or attribution shortcut.
State what is alleged, the relevant dates, platforms, audiences, and what remains only a hypothesis.
Record URLs, timestamps, artifact hashes, screenshots or exports, and lawful custody without altering source material.
Identify who created, transformed, posted, amplified, and hosted the material; do not collapse these roles.
Distinguish AI-generated assets, AI assistance, automation, adaptive agents, and unsupported claims of autonomy.
Record output, distribution, availability, reach, exposure, attention, belief, behavior, and outcome as separate stages.
Consider organic spread, ordinary marketing, satire, error, coordinated human activity, and platform effects.
Minimize personal data, avoid public accusation from weak indicators, and account for vulnerable or targeted communities.
Name the evidence that would strengthen, weaken, or reverse the assessment and schedule currentness review.
GLOSSARY
Definitions are intentionally bounded. Institutional, legal, and doctrinal usage may differ by jurisdiction and context.
FROM CAPABILITY AWARENESS TO SOCIETAL RESILIENCE
These principles recur across the reports. They reduce risk but are not guarantees, and poorly designed detection or enforcement can create new harms.
Teach verification habits, uncertainty, and the difference between visibility and effect without shifting all responsibility to individuals.
Use authenticated channels, pre-established verification contacts, and rapid corrections during elections, conflict, emergencies, or financial events.
Support signed origin records and chain-of-custody information while recognizing that metadata can be absent, stripped, spoofed, or incomplete.
Provide meaningful data about ranking, coordinated behavior, enforcement, and systemic risk to qualified independent researchers.
Limit collection and inference of sensitive personal, biometric, emotional, and behavioral data, especially for vulnerable groups.
Require accountable review of high-impact automated decisions, with explanation, appeal, correction, and remedy.
Make synthetic interlocutors identifiable, log consequential actions, constrain permissions, and preserve a responsible human or institution.
Use age-appropriate design, dependency safeguards, crisis escalation, and limits on exploitative engagement optimization.
Communicate uncertainty honestly, avoid overstating detection, and correct errors in ways that do not deepen generalized distrust.
Treat automated detectors and behavioral signals as evidence inputs, not verdicts; audit disparate impact and preserve anonymity, dissent, and lawful pseudonymity.
SOURCE FOUNDATION
Each category begins with its corresponding owner-supplied interdisciplinary report. WIP.51 adds claim-stage records, specialist-review packets, and claim-specific links to primary, official, platform, adjudicative, oversight, and peer-reviewed records, while preserving what each source does not establish.
Boundary: inclusion in this taxonomy does not certify every external citation, legal conclusion, attribution, or case interpretation in the supplied reports. Category pages preserve uncertainty, claim identifiers, correction triggers, and unresolved questions.
Links open the public source used for the bounded claim. A source may establish an event, artifact, platform action, experimental result, legal filing, or oversight finding without establishing intent, reach, causation, persuasion, or strategic effect.
SRC-01-OPENAI-COVERT-IO-2024OpenAI · 2024-05-30 · Platform threat-intelligence disclosure
SRC-02-OPENAI-UPDATE-2024OpenAI · 2024-10-09 · Platform threat-intelligence report
SRC-03-OPENAI-MALICIOUS-USES-2026OpenAI · 2026-02-25 · Platform threat-intelligence report
SRC-08-META-SPAMOUFLAGEMeta · 2023-08-29 · Platform threat-intelligence report
SRC-37-HKS-SLOVAK-DEEPFAKEHarvard Kennedy School Misinformation Review · 2024-08-22 · Open-access academic commentary and case synthesis
SRC-30-HRW-IJOP-XINJIANGHuman Rights Watch · 2019-05-01 · Investigative human-rights report
SRC-35-REUTERS-OLIVER-TAYLORReuters · 2020-07-15 · Independent investigative reporting with named institutional and forensic checks
SRC-39-REUTERS-ZELENSKYY-DEEPFAKEReuters · 2022-03-16 · Independent contemporaneous reporting
SRC-20-ICCT-AI-RADICALIZATIONInternational Centre for Counter-Terrorism · 2024-02-14 · Specialist policy research
SRC-06-RECORDED-FUTURE-COPYCOPRecorded Future / Insikt Group · 2024-05-09 · Independent threat-intelligence report
SRC-07-GRAPHIKA-WOLF-NEWSGraphika · 2023-02-07 · Independent threat-intelligence report
SRC-27-NYHAN-META-ELECTION-STUDIESMeta and independent academic partners · 2023-07-27 · Platform-supported peer-reviewed research program
SRC-38-UKRAINE-CPD-ZELENSKYY-DEEPFAKECenter for Countering Disinformation under the National Security and Defense Council of Ukraine · Official government analytical report
SRC-21-UK-CHAIL-SENTENCINGJudiciary of England and Wales · 2023-10-05 · Judicial record
SRC-22-GARCIA-CHARACTERAI-ORDERU.S. District Court, Middle District of Florida · 2025-05-21 · Judicial record
SRC-28-CHICAGO-OIG-PREDICTIVE-RISKCity of Chicago Office of Inspector General · 2020-01-23 · Government oversight report
SRC-29-CHICAGO-OIG-SHOTSPOTTERCity of Chicago Office of Inspector General · 2021-08-24 · Government oversight report
SRC-32-UNHCR-JETSONUNHCR Innovation Service · 2017-01-01 · Humanitarian predictive-analytics project
SRC-36-EEAS-FIMI-SLOVAKIA-AUDIOEuropean External Action Service · 2024-01-23 · Official foreign-information-manipulation threat report
SRC-16-EU-AI-ACTEuropean Union · 2024-07-12 · Binding legal instrument
SRC-04-GERMAN-FO-DOPPELGANGERGerman Federal Foreign Office · 2024-01-26 · Government technical report
SRC-05-VIGINUM-PORTAL-KOMBATVIGINUM · 2024-02-12 · Government technical report
SRC-17-FCC-NH-DEEPFAKE-ROBOCALLFederal Communications Commission · 2024-09-30 · Government enforcement action
SRC-18-DOJ-DPRK-IT-WORKERSU.S. Department of Justice · 2025-06-30 · Government enforcement disclosure
SRC-42-FTC-AI-COMPANION-INQUIRYFederal Trade Commission · 2025-09-11 · Official Section 6(b) market and safety inquiry
SRC-23-CHESNEY-CITRON-DEEPFAKESCalifornia Law Review · 2019-12-01 · Legal scholarship
SRC-09-GOLDSTEIN-AI-PROPAGANDAPNAS Nexus · 2024-02-20 · Peer-reviewed experiment
SRC-10-SALVI-LLM-PERSUASIONNature Human Behaviour · 2025-05-19 · Peer-reviewed randomized experiment
SRC-11-MATZ-PSYCHOLOGICAL-TARGETINGProceedings of the National Academy of Sciences · 2017-11-13 · Peer-reviewed experiments
SRC-13-HACKENBURG-POLITICAL-MICROTARGETINGProceedings of the National Academy of Sciences · 2024-06-04 · Peer-reviewed experiment
SRC-19-KRAMER-EMOTIONAL-CONTAGIONProceedings of the National Academy of Sciences · 2014-06-17 · Peer-reviewed platform experiment
SRC-24-LUCAS-DEEPFAKE-EFFECTSJournal of Computer-Mediated Communication · 2022-06-30 · Peer-reviewed experiment
SRC-25-SCHIFF-LIARS-DIVIDENDPsychology of Popular Media · 2026-01-01 · Peer-reviewed experiment
SRC-26-ELMAS-EPHEMERAL-ASTROTURFINGIEEE European Symposium on Security and Privacy · 2021-09-06 · Peer-reviewed security research
SRC-31-VIEWS-EARLY-WARNINGJournal of Peace Research · 2019-03-01 · Peer-reviewed forecasting-system paper
SRC-33-KRUGEL-MORAL-ADVICEScientific Reports · 2023-04-06 · Peer-reviewed experiment
SRC-40-SCHIFF-LIARS-DIVIDEND-APSRAmerican Political Science Review · 2025-02-01 · Peer-reviewed multi-experiment study
SRC-34-DEFREITAS-REPLIKAHarvard Business School working paper · 2024-09-01 · Working paper using experiments and archival data
SRC-12-PERLA-MICROTARGETING-METAPsychology & Marketing · 2025-10-10 · Peer-reviewed meta-analysis
SRC-14-BARRETT-EMOTION-EXPRESSIONSPsychological Science in the Public Interest · 2019-07-17 · Scientific review
SRC-41-ACL-REFLECTIVE-MEMORYAssociation for Computational Linguistics · 2025-07-01 · Peer-reviewed conference paper