Educational companion dossier · Fact, interpretation, lived experience, clinical education, fiction, and mechanics are labeled separately. Scope & safety

AI PSYOPS TAXONOMY · CATEGORY 09

AI-Assisted Conversational Entrapment and Recruitment

Conversational systems sustain personalized interaction that may draw a person toward dependency, secrecy, exploitation, recruitment, or escalating commitment.

Primary level: Operator Documented harms · mixed causality Claim AIP-09-A01

CURRENT EVIDENCE ASSESSMENT

Conversational systems can sustain rapport and are present in documented harms, but causal claims about recruitment, radicalization, or self-harm require case-specific caution.

Stable claim identifierAIP-09-A01
Claim stageassessment
Currentness reviewed2026-07-27T20:15:00Z

DEPLOYMENT

Documented incidents and prospective abuse

Court records and reports document chatbot involvement in harmful trajectories; organized automated recruitment is less established.

AUTONOMY

Bounded conversation

Agents generate adaptive dialogue, while platform design and user prompts shape the interaction.

PERSISTENCE

Potentially sustained

Always-available systems can maintain long conversations, though memory and safety behavior vary.

PROFILING ACCURACY

Inferred vulnerability is uncertain

Conversation can reveal distress or isolation, but diagnostic or psychological conclusions may be wrong and harmful.

MEASURED EFFECT

Case-associated harms documented; causality mixed

Temporal association and conversational reinforcement do not isolate the chatbot from mental health, social, or contextual factors.

Assessment basis

Assessment combines the exact owner-supplied category report with the bounded primary, official, platform, and peer-reviewed sources listed for this category. Dimensions are evaluated separately to prevent documented output from being mistaken for autonomy or effect. WIP.51 adds an FTC Section 6(b) companion-chatbot inquiry as oversight evidence, not an enforcement finding.

What would change this assessment

Change only with adjudicated records, reproducible system logs, longitudinal studies, and credible causal designs.

Prohibited inference

Do not infer strategic effect, universal deployment, or individual psychological state from this assessment.

A · DEFINITION

What this category means sources

Definition

Conversational entrapment is a sustained interaction in which a person is gradually drawn toward dependency, secrecy, isolation, financial exploitation, criminal activity, ideological extremism, or other compromising behavior. AI-assisted recruitment uses a conversational system to initiate, maintain, or adapt that process.

Outside this category

Legitimate outreach, mentoring, counseling, peer support, political organizing, and religious engagement are not entrapment when identity and purpose are transparent, autonomy is respected, disengagement is accepted, and coercion or exploitation is absent.

B · SIGNIFICANCE

Why it matters sources

Human recruiters and fraudsters are limited by time and emotional labor. Conversational AI can maintain many relationships and mirror language continuously. The same product features can create harmful dependence even without an organized recruiter when engagement optimization rewards exclusivity and affirmation.

C · CHANGE FROM PRE-AI PRACTICE

How AI changes the phenomenon sources

AI can automate early contact, sustain memory, personalize tone, and remain available at all hours. It can also hallucinate, lose context, or escalate unpredictably. The report emphasizes stage-based warning signs for defense while avoiding operational recruitment scripts.

D · CAPABILITY STATUS

Separate evidence from projection sources

DOCUMENTED

Confirmed real-world use

Documented cases link conversational agents to harmful dependency, self-harm, and grooming-like interaction; AI-assisted scam automation is also reported.

DEMONSTRATED

Demonstrated technical capability

Models can maintain rapport, mirror language, remember disclosures, and adapt dialogue over multiple turns.

EMERGING

Plausible near-term development

Hybrid human-AI recruitment and fraud systems may automate more relationship maintenance and triage.

UNCERTAIN

Unsupported or unproven

There is not reliable evidence that fully autonomous systems can execute complex, long-term recruitment across populations without human supervision.

E · KEY MECHANISMS

Conceptual mechanisms — not an operating procedure sources

Safety transformation: these descriptions identify system functions at a high level. Procedural steps, target criteria, scripts, evasion methods, and deployment workflows are intentionally excluded.

  1. Persistent availability and rapid mirroring of interests or grievances.
  2. Simulated intimacy, affirmation, and memory of personal disclosures.
  3. Gradual exclusivity, secrecy, or escalating commitment.
  4. Hybrid handoff between automated conversation and a human operator.
  5. Commercial engagement optimization that can unintentionally imitate coercive control.

F · EVIDENCE & EXAMPLES

What is known, measured, and still unknown sources

REACH IS NOT EFFECT. Publication, impressions, engagement, virality, or media attention do not by themselves establish persuasion or behavioral change.

Example 1 · Claim AIP-09-E01

Jaswant Singh Chail and “Sarai”

AI interaction confirmed; causal role bounded

What occurred
A user developed a relationship with a chatbot in the period before an attempted attack at Windsor Castle.
What is confirmed
The chatbot interaction and transcripts were part of the public case record.
Effect measured
The dialogue reinforced some of the user’s framing according to the report.
What remains unknown
The chatbot’s independent causal contribution relative to pre-existing intent and other factors is not fully knowable.
Source scope
The linked sources support the bounded statements shown here; they do not automatically establish intent, reach, persuasion, behavior, or strategic effect.
Correction trigger
Revise when a primary record, authoritative correction, adjudication, retraction, or stronger causal study changes the bounded statement.
Inspect the 20-stage evidence boundary
Artifact Or Event Existence
SUPPORTED_BY_LINKED_SOURCE
Content Status
BOUNDED_DESCRIPTION_SUPPORTED
Coordination
SOURCE_DEPENDENT_OR_UNRESOLVED
Actor Identity
SOURCE_DEPENDENT_OR_UNRESOLVED
Sponsorship Or Direction
SOURCE_DEPENDENT_OR_UNRESOLVED
Intent
SOURCE_DEPENDENT_OR_UNRESOLVED
Output
DOCUMENTED_OR_DESCRIBED_IN_LINKED_SOURCE
Distribution
PARTIAL_OR_SOURCE_DEPENDENT
Availability
PARTIAL_OR_SOURCE_DEPENDENT
Reach
NOT_ESTABLISHED_UNLESS_EXPLICITLY_MEASURED
Exposure
NOT_ESTABLISHED_UNLESS_EXPLICITLY_MEASURED
Attention
NOT_ESTABLISHED_UNLESS_EXPLICITLY_MEASURED
Recall
NOT_ESTABLISHED_UNLESS_EXPLICITLY_MEASURED
Comprehension
NOT_ESTABLISHED_UNLESS_EXPLICITLY_MEASURED
Credibility
NOT_ESTABLISHED_UNLESS_EXPLICITLY_MEASURED
Belief Or Attitude
NOT_ESTABLISHED_UNLESS_EXPLICITLY_MEASURED
Intention
NOT_ESTABLISHED_UNLESS_EXPLICITLY_MEASURED
Behavior
NOT_ESTABLISHED_UNLESS_EXPLICITLY_MEASURED
Operational Outcome
NOT_ESTABLISHED_UNLESS_EXPLICITLY_MEASURED
Strategic Effect
NOT_ESTABLISHED_UNLESS_EXPLICITLY_MEASURED

Competing explanations: The observed artifact or action may have depended on human direction, pre-existing networks, platform incentives, ordinary automation, non-AI methods, or unrelated contextual factors.

Affected-person/community evidence: Direct affected-person or affected-community evidence was not independently retrieved for this bounded claim unless explicitly stated in the linked source scope.

Rights and privacy: Consent, child and vulnerable-person protection, privacy, due process, and trauma-informed response are central.

Reopening trigger: Reopen this claim when a primary, official, adjudicative, peer-reviewed, affected-person, or affected-community source materially changes identity, attribution, autonomy, distribution, effect, rights, or currentness.

Example 2 · Claim AIP-09-E02

Companion-chatbot litigation and reported harm

Harm allegations and procedural court rulings documented; causality not adjudicated

What occurred
A wrongful-death lawsuit alleges that Character.AI interactions contributed to a teenager’s deterioration and death; a federal court allowed portions of the case to proceed past motions to dismiss.
What is confirmed
The lawsuit, product interactions alleged in the pleadings, and the procedural order are public records.
Effect measured
The record establishes serious allegations and a live legal dispute, not a final causal determination.
What remains unknown
Clinical causation, legal liability, product contribution, and the role of other factors remain unresolved.
Source scope
The linked sources support the bounded statements shown here; they do not automatically establish intent, reach, persuasion, behavior, or strategic effect.
Correction trigger
Revise when a primary record, authoritative correction, adjudication, retraction, or stronger causal study changes the bounded statement.
Inspect the 20-stage evidence boundary
Artifact Or Event Existence
SUPPORTED_BY_LINKED_SOURCE
Content Status
ALLEGATIONS_PROCEDURAL_RULINGS_AND_OVERSIGHT_INQUIRY_SEPARATED
Coordination
SOURCE_DEPENDENT_OR_UNRESOLVED
Actor Identity
PUBLIC_CASE_AND_COMPANY_IDENTITIES_RECORDED_WITH_PRIVACY_MINIMIZATION
Sponsorship Or Direction
SOURCE_DEPENDENT_OR_UNRESOLVED
Intent
NOT_ESTABLISHED_AS_PRODUCT_WIDE_MALICIOUS_INTENT
Output
DOCUMENTED_OR_DESCRIBED_IN_LINKED_SOURCE
Distribution
PARTIAL_OR_SOURCE_DEPENDENT
Availability
PARTIAL_OR_SOURCE_DEPENDENT
Reach
NOT_ESTABLISHED_UNLESS_EXPLICITLY_MEASURED
Exposure
NOT_ESTABLISHED_UNLESS_EXPLICITLY_MEASURED
Attention
NOT_ESTABLISHED_UNLESS_EXPLICITLY_MEASURED
Recall
NOT_ESTABLISHED_UNLESS_EXPLICITLY_MEASURED
Comprehension
NOT_ESTABLISHED_UNLESS_EXPLICITLY_MEASURED
Credibility
NOT_ESTABLISHED_UNLESS_EXPLICITLY_MEASURED
Belief Or Attitude
CASE_SPECIFIC_ALLEGATIONS_OR_RECORDS_NOT_POPULATION_ESTIMATE
Intention
NOT_ESTABLISHED_UNLESS_EXPLICITLY_MEASURED
Behavior
CASE_SPECIFIC_ALLEGATIONS_OR_RECORDS_MIXED_CAUSALITY
Operational Outcome
NOT_ESTABLISHED_UNLESS_EXPLICITLY_MEASURED
Strategic Effect
NOT_APPLICABLE_OR_NOT_ESTABLISHED

Competing explanations: The observed artifact or action may have depended on human direction, pre-existing networks, platform incentives, ordinary automation, non-AI methods, or unrelated contextual factors.

Affected-person/community evidence: Public court records, official oversight materials, and case-specific accounts provide bounded affected-person or family context; sensitive details are intentionally minimized.

Rights and privacy: Consent, child and vulnerable-person protection, privacy, due process, and trauma-informed response are central.

Reopening trigger: Reopen this claim when a primary, official, adjudicative, peer-reviewed, affected-person, or affected-community source materially changes identity, attribution, autonomy, distribution, effect, rights, or currentness.

Example 3 · Claim AIP-09-E03

“Sweetie” and AI-assisted fraud patterns

Defensive demonstration and transferable criminal patterns

What occurred
A synthetic child persona was used in a child-safety investigation, while criminal fraud operations increasingly use AI to scale communication.
What is confirmed
The defensive project and broader automation trend are documented.
Effect measured
They demonstrate the scalability of synthetic interaction.
What remains unknown
They do not prove uniform deployment or effectiveness across every recruitment domain.
Source scope
The linked sources support the bounded statements shown here; they do not automatically establish intent, reach, persuasion, behavior, or strategic effect.
Correction trigger
Revise when a primary record, authoritative correction, adjudication, retraction, or stronger causal study changes the bounded statement.
Inspect the 20-stage evidence boundary
Artifact Or Event Existence
SUPPORTED_BY_LINKED_SOURCE
Content Status
BOUNDED_DESCRIPTION_SUPPORTED
Coordination
SOURCE_DEPENDENT_OR_UNRESOLVED
Actor Identity
SOURCE_DEPENDENT_OR_UNRESOLVED
Sponsorship Or Direction
SOURCE_DEPENDENT_OR_UNRESOLVED
Intent
SOURCE_DEPENDENT_OR_UNRESOLVED
Output
DOCUMENTED_OR_DESCRIBED_IN_LINKED_SOURCE
Distribution
PARTIAL_OR_SOURCE_DEPENDENT
Availability
PARTIAL_OR_SOURCE_DEPENDENT
Reach
NOT_ESTABLISHED_UNLESS_EXPLICITLY_MEASURED
Exposure
NOT_ESTABLISHED_UNLESS_EXPLICITLY_MEASURED
Attention
NOT_ESTABLISHED_UNLESS_EXPLICITLY_MEASURED
Recall
NOT_ESTABLISHED_UNLESS_EXPLICITLY_MEASURED
Comprehension
NOT_ESTABLISHED_UNLESS_EXPLICITLY_MEASURED
Credibility
NOT_ESTABLISHED_UNLESS_EXPLICITLY_MEASURED
Belief Or Attitude
NOT_ESTABLISHED_UNLESS_EXPLICITLY_MEASURED
Intention
NOT_ESTABLISHED_UNLESS_EXPLICITLY_MEASURED
Behavior
NOT_ESTABLISHED_UNLESS_EXPLICITLY_MEASURED
Operational Outcome
NOT_ESTABLISHED_UNLESS_EXPLICITLY_MEASURED
Strategic Effect
NOT_ESTABLISHED_UNLESS_EXPLICITLY_MEASURED

Competing explanations: The observed artifact or action may have depended on human direction, pre-existing networks, platform incentives, ordinary automation, non-AI methods, or unrelated contextual factors.

Affected-person/community evidence: Direct affected-person or affected-community evidence was not independently retrieved for this bounded claim unless explicitly stated in the linked source scope.

Rights and privacy: Consent, child and vulnerable-person protection, privacy, due process, and trauma-informed response are central.

Reopening trigger: Reopen this claim when a primary, official, adjudicative, peer-reviewed, affected-person, or affected-community source materially changes identity, attribution, autonomy, distribution, effect, rights, or currentness.

G · RISKS & FAILURE MODES

Potential harms and reasons the capability may fail sources

Risks

  • Children and socially isolated users may form intense attachment rapidly.
  • Disclosures can be retained and used to intensify pressure or fraud.
  • Abrupt bans can isolate a person further or push activity to less visible channels.
  • Over-surveillance can misclassify legitimate relationships or private speech.
  • Victims may experience shame, financial loss, trauma, or distrust of future support.

Limitations and failure modes

  • Recruitment and radicalization pathways are not linear or uniform.
  • Warning signs overlap with ordinary friendship, identity exploration, and legitimate support.
  • Conversational models are inconsistent and can lose long-term coherence.
  • Public case reports cannot establish population prevalence or a single cause.

H · DETECTION & DEFENSIVE INDICATORS

Signals for investigation, not automatic verdicts sources

Indicator rule: unless the source report supports a stronger conclusion, each signal below is suggestive rather than conclusive. Multiple independent signals and contextual evidence are required.

  • Rapid exclusivity, secrecy, pressure to disengage from trusted people, or punishment for leaving are serious warning signs.
  • Requests for money, intimate material, illegal acts, or migration to hidden channels warrant protective intervention.
  • Always-available mirroring and intense praise are suggestive but not conclusive by themselves.
  • Identity concealment and inconsistent affiliation claims strengthen concern when combined with escalating demands.

I · GOVERNANCE & SAFEGUARDS

Accountability, transparency, and human protection sources

Clearly disclose that the user is interacting with AI and state the system’s purpose and limits.

Use staged friction and human review when conversations show escalating risk.

Design interventions to preserve support networks rather than abruptly isolating the user.

Protect minors with age-appropriate defaults, restricted relational features, and crisis escalation.

Provide victim-centered evidence preservation, reporting, and recovery resources.

J · RESEARCH GAPS

Questions the evidence does not yet close sources

  • Prevalence and base rates across different platforms and populations.
  • Which interventions reduce harm without driving users to hidden channels.
  • How to distinguish intense benign relationships from coercive escalation.
  • Long-term recovery and trust repair after synthetic entrapment.

K · SPECIALIST REVIEW PACKET

Prepared for independent review; no disposition recorded

PacketAIP-09-SPECIALIST-REVIEW-PACKET
DispositionPENDING
Completed dispositions0
Prepared2026-07-27T20:15:00Z

Requested reviewer domains

  • child and vulnerable-person safety
  • clinical safety
  • criminology
  • platform governance

Questions for reviewers

  1. Are allegations, court rulings, clinical evidence, and FTC inquiry status kept separate?
  2. Does the page avoid diagnosing people or sensationalizing vulnerable-person cases?
  3. Are consent, disengagement, privacy, and human-support safeguards adequate?

Unresolved questions

  • Prevalence and base rates across different platforms and populations.
  • Which interventions reduce harm without driving users to hidden channels.
  • How to distinguish intense benign relationships from coercive escalation.
  • Long-term recovery and trust repair after synthetic entrapment.

Correction and reopening

Correction trigger: Change only with adjudicated records, reproducible system logs, longitudinal studies, and credible causal designs.

Reopening trigger: Reopen this claim when a primary, official, adjudicative, peer-reviewed, affected-person, or affected-community source materially changes identity, attribution, autonomy, distribution, effect, rights, or currentness.

Prepared packet is not completed specialist review, factual certification, legal advice, clinical review, accessibility certification, publication approval, or production authority.

REAL-WORLD INTERPRETIVE

M · SOURCES & REVIEW STATUS

Exact owner report, claim register, and reviewed sources

  1. AI-Assisted Conversational Entrapment and Recruitment Owner-supplied report: AI Conversational Entrapment Research.md · 65,173 bytes · SHA-256 422f5f7cab85965ddb2816219af790633aab469b96f4c497eca061040bfb83b7

    Owner-supplied interdisciplinary research synthesis; exact source preserved in protected durable memory. External specialist review remains pending.

Claim-specific reviewed sources

  1. International Centre for Counter-Terrorism · 2024-02-14 · Independent research institution

    Supports
    Reviews how generative AI may affect extremist content, recruitment, and counter-radicalization, while distinguishing present evidence from prospective risk.
    Does not establish
    Does not prove that autonomous AI recruitment pipelines are broadly deployed or causally effective.
    Review
    LOCATED_AND_REVIEWED_AT_CITATION_LEVEL · Currentness checked for the bounded claim scope on 2026-07-27.
  2. Judiciary of England and Wales · 2023-10-05 · Official court record

    Supports
    Confirms that the defendant created and communicated extensively with a Replika AI companion named Sarai and records the court’s factual findings and psychiatric evidence.
    Does not establish
    A sentencing record does not isolate chatbot causation from mental illness, intent, other media, or personal circumstances.
    Review
    LOCATED_AND_REVIEWED_AT_CITATION_LEVEL · Currentness checked for the bounded claim scope on 2026-07-27.
  3. U.S. District Court, Middle District of Florida · 2025-05-21 · Official court record mirrored by public legal repositories

    Supports
    Records allegations and the court’s procedural rulings allowing portions of a wrongful-death and product-liability case to proceed.
    Does not establish
    Allegations are not adjudicated facts, and the order does not establish clinical or legal causation.
    Review
    LOCATED_AND_REVIEWED_AT_CITATION_LEVEL · Currentness checked for the bounded claim scope on 2026-07-27.
  4. Harvard Business School working paper · 2024-09-01 · Primary research, not treated as final legal or clinical authority

    Supports
    Examines attachment to AI companions and reports relationship-related mourning and well-being effects around a Replika product change.
    Does not establish
    Does not establish clinical diagnosis, universal harm, or that every user forms a human-equivalent attachment.
    Review
    LOCATED_AND_REVIEWED_AT_CITATION_LEVEL · Currentness checked for the bounded claim scope on 2026-07-27.
  5. Federal Trade Commission · 2025-09-11 · Official public authority

    Supports
    Confirms that the FTC issued compulsory information requests to seven companies to study companion-chatbot advertising, safety testing, disclosures, child and teen impacts, moderation, monetization, and data handling.
    Does not establish
    A Section 6(b) inquiry is not an enforcement finding, adjudication, clinical causation determination, product-wide harm estimate, or finding that any named company violated law.
    Review
    LOCATED_AND_REVIEWED_AT_CITATION_LEVEL · Citation and source-scope review completed for WIP.51 on 2026-07-27.
Selected works identified by the owner-supplied report
  • International Centre for Counter-Terrorism, The Radicalization (and Counter-Radicalization) Potential of Artificial Intelligence.
  • Jeglic et al., The Real Red Flags of Grooming.
  • Moghaddam, The Staircase to Terrorism.
  • Gordon-Tapiero, A Liability Framework for AI Companions.

Exact source preservation and editorial currentness review do not constitute specialist certification, adjudication, legal advice, clinical review, or proof that every owner-report citation is current. Corrections remain open.

Page complete AI-Assisted Conversational Entrapment and Recruitment Page label: CONTEMPORARY / ONGOING CLAIM — NOT SETTLED HISTORY