Educational companion dossier · Fact, interpretation, lived experience, clinical education, fiction, and mechanics are labeled separately. Scope & safety

AI PSYOPS TAXONOMY · CATEGORY 10

AI-Enabled Deepfake Psychological Operations

Synthetic or manipulated audio, video, imagery, or multimodal evidence is used to impersonate, provoke, discredit, or undermine trust for an influence objective.

Primary level: Tool Documented current use Claim AIP-10-A01

CURRENT EVIDENCE ASSESSMENT

Synthetic audio, image, and video use is documented; deception, confusion, and liar’s-dividend effects depend more on context than perfect realism alone.

Stable claim identifierAIP-10-A01
Claim stageassessment
Currentness reviewed2026-07-27T20:15:00Z

DEPLOYMENT

Documented

Election, fraud, harassment, and influence incidents involving synthetic media are publicly established.

AUTONOMY

Tool-level production

Humans typically select the target, narrative, timing, and distribution channel.

PERSISTENCE

Episodic asset; persistent epistemic effects possible

A specific asset may be brief while uncertainty and denial can outlast it.

PROFILING ACCURACY

Not required

Success can rely on identity, timing, confirmation bias, and information vacuums rather than individual profiles.

MEASURED EFFECT

Confusion and judgment effects demonstrated; broad behavior variable

Experiments and incidents show deception or doubt, but not uniform persuasion or action.

Assessment basis

Assessment combines the exact owner-supplied category report with the bounded primary, official, platform, and peer-reviewed sources listed for this category. Dimensions are evaluated separately to prevent documented output from being mistaken for autonomy or effect. WIP.51 adds affected-state and independent reporting on the Zelenskyy surrender deepfake and a large peer-reviewed liar’s-dividend study.

What would change this assessment

Upgrade claims with verified exposure, authentication timelines, response delays, and measured downstream decisions.

Prohibited inference

Do not infer strategic effect, universal deployment, or individual psychological state from this assessment.

A · DEFINITION

What this category means sources

Definition

A deepfake psychological operation intentionally uses synthetic or manipulated audio, video, imagery, or multimodal media to alter perception, impersonate a trusted figure, create false evidence, provoke action, discredit authentic material, or undermine trust.

Outside this category

Not all edited media is a deepfake, and not all deepfakes are psychological operations. Disclosed artistic transformation, accessibility dubbing, satire, and ordinary editing lack the deceptive influence objective that defines this category.

B · SIGNIFICANCE

Why it matters sources

A synthetic artifact released during a crisis can outrun verification. The broader danger is epistemic: once people know convincing fakes exist, wrongdoers can deny authentic recordings and institutions may struggle to establish a shared factual record.

C · CHANGE FROM PRE-AI PRACTICE

How AI changes the phenomenon sources

Generative models make voice, face, image, and event fabrication cheaper and faster. Success often depends more on timing, source credibility, prior belief, and emotional intensity than on perfect realism. Low-quality manipulations can still work in an information vacuum.

D · CAPABILITY STATUS

Separate evidence from projection sources

DOCUMENTED

Confirmed real-world use

Synthetic audio, video, and imagery have been used in political, criminal, and coercive incidents.

DEMONSTRATED

Demonstrated technical capability

Current tools can impersonate voices and faces and generate plausible scenes, though artifacts and temporal errors remain.

EMERGING

Plausible near-term development

Real-time multimodal impersonation and hybrid authentic-synthetic evidence are likely to become more accessible.

UNCERTAIN

Unsupported or unproven

Technical realism does not establish persuasion, and no detector can provide universal certainty across all media and generation methods.

E · KEY MECHANISMS

Conceptual mechanisms — not an operating procedure sources

Safety transformation: these descriptions identify system functions at a high level. Procedural steps, target criteria, scripts, evasion methods, and deployment workflows are intentionally excluded.

  1. Voice cloning and fabricated calls or recordings.
  2. Face replacement, reenactment, and altered lip synchronization.
  3. Synthetic eyewitness, battlefield, protest, or disaster imagery.
  4. Hybrid fakes that change one consequential element inside authentic media.
  5. False claims that genuine evidence is AI-generated.

F · EVIDENCE & EXAMPLES

What is known, measured, and still unknown sources

REACH IS NOT EFFECT. Publication, impressions, engagement, virality, or media attention do not by themselves establish persuasion or behavioral change.

Example 1 · Claim AIP-10-E01

Election-related synthetic audio

Synthetic media documented; behavioral impact uncertain

What occurred
Fabricated political audio circulated during election periods, including cases described in Slovakia and the United States.
What is confirmed
The media artifacts and distribution are documented.
Effect measured
They triggered public warnings, investigation, and policy response.
What remains unknown
A reliable causal effect on final voter behavior is not established.
Source scope
The linked sources support the bounded statements shown here; they do not automatically establish intent, reach, persuasion, behavior, or strategic effect.
Correction trigger
Revise when a primary record, authoritative correction, adjudication, retraction, or stronger causal study changes the bounded statement.
Inspect the 20-stage evidence boundary
Artifact Or Event Existence
SUPPORTED_BY_LINKED_SOURCE
Content Status
BOUNDED_DESCRIPTION_SUPPORTED
Coordination
SOURCE_DEPENDENT_OR_UNRESOLVED
Actor Identity
SOURCE_DEPENDENT_OR_UNRESOLVED
Sponsorship Or Direction
SOURCE_DEPENDENT_OR_UNRESOLVED
Intent
SOURCE_DEPENDENT_OR_UNRESOLVED
Output
DOCUMENTED_OR_DESCRIBED_IN_LINKED_SOURCE
Distribution
PARTIAL_OR_SOURCE_DEPENDENT
Availability
PARTIAL_OR_SOURCE_DEPENDENT
Reach
NOT_ESTABLISHED_UNLESS_EXPLICITLY_MEASURED
Exposure
NOT_ESTABLISHED_UNLESS_EXPLICITLY_MEASURED
Attention
NOT_ESTABLISHED_UNLESS_EXPLICITLY_MEASURED
Recall
NOT_ESTABLISHED_UNLESS_EXPLICITLY_MEASURED
Comprehension
NOT_ESTABLISHED_UNLESS_EXPLICITLY_MEASURED
Credibility
NOT_ESTABLISHED_UNLESS_EXPLICITLY_MEASURED
Belief Or Attitude
NOT_ESTABLISHED_UNLESS_EXPLICITLY_MEASURED
Intention
NOT_ESTABLISHED_UNLESS_EXPLICITLY_MEASURED
Behavior
NOT_ESTABLISHED_UNLESS_EXPLICITLY_MEASURED
Operational Outcome
NOT_ESTABLISHED_UNLESS_EXPLICITLY_MEASURED
Strategic Effect
NOT_ESTABLISHED_UNLESS_EXPLICITLY_MEASURED

Competing explanations: The observed artifact or action may have depended on human direction, pre-existing networks, platform incentives, ordinary automation, non-AI methods, or unrelated contextual factors.

Affected-person/community evidence: Direct affected-person or affected-community evidence was not independently retrieved for this bounded claim unless explicitly stated in the linked source scope.

Rights and privacy: Privacy, dignity, evidentiary integrity, crisis response, free expression, and protection from non-consensual media are central.

Reopening trigger: Reopen this claim when a primary, official, adjudicative, peer-reviewed, affected-person, or affected-community source materially changes identity, attribution, autonomy, distribution, effect, rights, or currentness.

Example 2 · Claim AIP-10-E02

Wartime leader-impersonation media

Public incident reporting exists; strategic effect not established

What occurred
Synthetic or manipulated media impersonating political leaders circulated during armed conflict and information crises.
What is confirmed
Specific artifacts and distribution events have been documented by investigators and journalists.
Effect measured
Rapid debunking and limited visible engagement were reported in some cases; no broad strategic effect is established.
What remains unknown
Complete exposure, belief, delayed influence, and the independent effect of the synthetic asset remain unknown.
Source scope
The linked sources support the bounded statements shown here; they do not automatically establish intent, reach, persuasion, behavior, or strategic effect.
Correction trigger
Revise when a primary record, authoritative correction, adjudication, retraction, or stronger causal study changes the bounded statement.
Inspect the 20-stage evidence boundary
Artifact Or Event Existence
DOCUMENTED
Content Status
FALSE_SYNTHETIC_SURRENDER_VIDEO_DOCUMENTED
Coordination
DISTRIBUTION_EVENT_DOCUMENTED_CREATION_COORDINATION_UNRESOLVED
Actor Identity
NOT_RETRIEVED
Sponsorship Or Direction
NOT_RETRIEVED
Intent
SURRENDER_MESSAGE_CONTENT_SUPPORTS_INFLUENCE_PURPOSE_EXACT_DIRECTION_UNRESOLVED
Output
VIDEO_DOCUMENTED
Distribution
ONLINE_CIRCULATION_AND_COMPROMISED_MEDIA_CONTEXT_DOCUMENTED
Availability
DOCUMENTED
Reach
NOT_RETRIEVED_UNIQUE_COUNT
Exposure
NOT_RETRIEVED
Attention
RAPID_PUBLIC_AND_INSTITUTIONAL_RESPONSE_DOCUMENTED
Recall
NOT_ESTABLISHED
Comprehension
NOT_ESTABLISHED
Credibility
REUTERS_REPORTED_IMMEDIATE_RIDICULE_EFFECT_NOT_QUANTIFIED
Belief Or Attitude
NOT_ESTABLISHED
Intention
NOT_ESTABLISHED
Behavior
NOT_ESTABLISHED
Operational Outcome
RAPID_REBUTTAL_AND_PLATFORM_REMOVAL_DOCUMENTED
Strategic Effect
NOT_ESTABLISHED

Competing explanations: The observed artifact or action may have depended on human direction, pre-existing networks, platform incentives, ordinary automation, non-AI methods, or unrelated contextual factors.

Affected-person/community evidence: Affected-state authorities supplied crisis-response context, and contemporaneous reporting recorded rapid public ridicule and rebuttal; recipient belief and military behavior were not measured.

Rights and privacy: Privacy, dignity, evidentiary integrity, crisis response, free expression, and protection from non-consensual media are central.

Reopening trigger: Reopen this claim when a primary, official, adjudicative, peer-reviewed, affected-person, or affected-community source materially changes identity, attribution, autonomy, distribution, effect, rights, or currentness.

Example 3 · Claim AIP-10-E03

The liar’s dividend

Legal theory and experimental evidence; real-world magnitude context-dependent

What occurred
Researchers and legal scholars examine how awareness of deepfakes can make false denials of authentic evidence more plausible.
What is confirmed
The mechanism is theoretically developed and has experimental support under tested conditions.
Effect measured
Some participants become more uncertain or receptive to false denial claims.
What remains unknown
Its prevalence, durability, and ability to override trusted authentication in real crises remain unsettled.
Source scope
The linked sources support the bounded statements shown here; they do not automatically establish intent, reach, persuasion, behavior, or strategic effect.
Correction trigger
Revise when a primary record, authoritative correction, adjudication, retraction, or stronger causal study changes the bounded statement.
Inspect the 20-stage evidence boundary
Artifact Or Event Existence
RESEARCH_MECHANISM_AND_EXPERIMENTS_DOCUMENTED
Content Status
FALSE_DENIAL_TREATMENTS_DOCUMENTED
Coordination
NOT_APPLICABLE_TO_EXPERIMENTAL_DESIGN
Actor Identity
HYPOTHETICAL_POLITICIANS_IN_EXPERIMENT
Sponsorship Or Direction
RESEARCH_CONTEXT_ONLY
Intent
EXPERIMENTALLY_ASSIGNED_FALSE_DENIAL
Output
TREATMENT_MESSAGES_DOCUMENTED
Distribution
CONTROLLED_EXPERIMENTAL_DELIVERY
Availability
CONTROLLED_EXPERIMENTAL_DELIVERY
Reach
OVER_15000_PARTICIPANTS_ACROSS_FIVE_EXPERIMENTS_IN_APSR_STUDY
Exposure
EXPERIMENTALLY_ASSIGNED
Attention
ASSUMED_BY_COMPLETION_NOT_INDEPENDENTLY_MEASURED
Recall
NOT_PRIMARY_OUTCOME
Comprehension
NOT_PRIMARY_OUTCOME
Credibility
MECHANISM_TESTED_BOUNDED
Belief Or Attitude
SHORT_TERM_POLITICIAN_SUPPORT_MEASURED
Intention
NOT_PRIMARY_OUTCOME
Behavior
NOT_MEASURED
Operational Outcome
NOT_ESTABLISHED
Strategic Effect
NOT_ESTABLISHED

Competing explanations: The observed artifact or action may have depended on human direction, pre-existing networks, platform incentives, ordinary automation, non-AI methods, or unrelated contextual factors.

Affected-person/community evidence: Direct affected-person or affected-community evidence was not independently retrieved for this bounded claim unless explicitly stated in the linked source scope.

Rights and privacy: Privacy, dignity, evidentiary integrity, crisis response, free expression, and protection from non-consensual media are central.

Reopening trigger: Reopen this claim when a primary, official, adjudicative, peer-reviewed, affected-person, or affected-community source materially changes identity, attribution, autonomy, distribution, effect, rights, or currentness.

G · RISKS & FAILURE MODES

Potential harms and reasons the capability may fail sources

Risks

  • Rapid false evidence can trigger panic, fraud, or escalation before verification.
  • Private individuals may lack the resources to rebut convincing impersonation.
  • False positives can discredit authentic media and innocent creators.
  • Provenance metadata can be removed, absent, or forged.
  • Repeated exposure to synthetic media can erode baseline trust even when specific fakes are debunked.

Limitations and failure modes

  • Long video can still reveal temporal, physical, acoustic, or contextual inconsistencies.
  • Human detection performs poorly for high-quality media and can be overconfident.
  • Detection models are generation-specific and degrade as tools change.
  • Labels and watermarks are incomplete evidence, not proof of authenticity or falsity.

H · DETECTION & DEFENSIVE INDICATORS

Signals for investigation, not automatic verdicts sources

Indicator rule: unless the source report supports a stronger conclusion, each signal below is suggestive rather than conclusive. Multiple independent signals and contextual evidence are required.

  • A sensational recording appearing first through an unverified channel should trigger source confirmation before rebroadcast.
  • Inconsistent lighting, anatomy, timing, acoustics, or context may be suggestive but not conclusive.
  • Absence of provenance should increase uncertainty, not automatically classify the media as fake.
  • Independent confirmation from the represented person or institution is often more valuable than automated scoring alone.

I · GOVERNANCE & SAFEGUARDS

Accountability, transparency, and human protection sources

Sign authoritative media and publish trusted verification routes before a crisis occurs.

Use layered forensic analysis and preserve original files and chain of custody.

Communicate uncertainty quickly and update public statements as evidence changes.

Protect private victims with rapid reporting, takedown, and legal-remedy processes.

Treat provenance, detectors, human review, and contextual verification as complementary—not interchangeable—controls.

J · RESEARCH GAPS

Questions the evidence does not yet close sources

  • Long-term effects on baseline trust and democratic participation.
  • Effectiveness and unintended consequences of mandatory labels.
  • Privacy-preserving provenance that remains useful after legitimate editing.
  • Crisis protocols for people and institutions with limited technical resources.

K · SPECIALIST REVIEW PACKET

Prepared for independent review; no disposition recorded

PacketAIP-10-SPECIALIST-REVIEW-PACKET
DispositionPENDING
Completed dispositions0
Prepared2026-07-27T20:15:00Z

Requested reviewer domains

  • media forensics
  • crisis communication
  • international humanitarian law
  • political communication

Questions for reviewers

  1. Does the Zelenskyy incident record artifact and response without inferring belief or military effect?
  2. Are liar’s-dividend experiments bounded by medium, setting, and measured outcome?
  3. Are crisis-response recommendations protective without becoming censorship or surveillance guidance?

Unresolved questions

  • Long-term effects on baseline trust and democratic participation.
  • Effectiveness and unintended consequences of mandatory labels.
  • Privacy-preserving provenance that remains useful after legitimate editing.
  • Crisis protocols for people and institutions with limited technical resources.

Correction and reopening

Correction trigger: Upgrade claims with verified exposure, authentication timelines, response delays, and measured downstream decisions.

Reopening trigger: Reopen this claim when a primary, official, adjudicative, peer-reviewed, affected-person, or affected-community source materially changes identity, attribution, autonomy, distribution, effect, rights, or currentness.

Prepared packet is not completed specialist review, factual certification, legal advice, clinical review, accessibility certification, publication approval, or production authority.

REAL-WORLD INTERPRETIVE

M · SOURCES & REVIEW STATUS

Exact owner report, claim register, and reviewed sources

  1. AI-Enabled Deepfake Psychological Operations Owner-supplied report: Deepfake Psychological Operations Research.md · 62,023 bytes · SHA-256 8dec5d4accf0bd6fea3d357e9648ae18d77b3939a7c628c1caf109ed2e47e09a

    Owner-supplied interdisciplinary research synthesis; exact source preserved in protected durable memory. External specialist review remains pending.

Claim-specific reviewed sources

  1. Federal Communications Commission · 2024-09-30 · Official public authority

    Supports
    Confirms an AI-generated voice-cloning robocall campaign targeting New Hampshire primary voters and the FCC enforcement response.
    Does not establish
    Does not establish how many recipients believed the message or whether it changed turnout; it does not independently verify separate election-audio incidents in other countries.
    Review
    LOCATED_AND_REVIEWED_AT_CITATION_LEVEL · Currentness checked for the bounded claim scope on 2026-07-27.
  2. California Law Review · 2019-12-01 · Peer-reviewed or editorially reviewed scholarship

    Supports
    Defines major deepfake risks, including impersonation, evidentiary disruption, and the liar’s dividend.
    Does not establish
    Legal analysis does not measure the prevalence or persuasive effect of specific incidents.
    Review
    LOCATED_AND_REVIEWED_AT_CITATION_LEVEL · Currentness checked for the bounded claim scope on 2026-07-27.
  3. Journal of Computer-Mediated Communication · 2022-06-30 · Primary research

    Supports
    Tests how political deepfake video affects deception, uncertainty, and trust under experimental conditions.
    Does not establish
    A controlled study does not establish uniform effects across crises, cultures, or high-stakes operational contexts.
    Review
    LOCATED_AND_REVIEWED_AT_CITATION_LEVEL · Currentness checked for the bounded claim scope on 2026-07-27.
  4. Psychology of Popular Media · 2026-01-01 · Primary research

    Supports
    Examines whether deepfake awareness can make false denials of authentic audiovisual evidence more credible.
    Does not establish
    Does not establish that every denial benefits from the liar’s dividend or that the effect dominates all verification cues.
    Review
    LOCATED_AND_REVIEWED_AT_CITATION_LEVEL · Currentness checked for the bounded claim scope on 2026-07-27.
  5. SRC-07-GRAPHIKA-WOLF-NEWSDeepfake It Till You Make It

    Graphika · 2023-02-07 · Independent specialist analysis

    Supports
    Documents limited use of AI-generated fictitious news presenters in content promoted by a pro-China influence operation.
    Does not establish
    Does not establish substantial reach or persuasive effect and should not be generalized to all synthetic presenter use.
    Review
    LOCATED_AND_REVIEWED_AT_CITATION_LEVEL · Currentness checked for the bounded claim scope on 2026-07-27.
  6. Center for Countering Disinformation under the National Security and Defense Council of Ukraine · Official affected-state public authority

    Supports
    Identifies the 16 March 2022 synthetic video falsely depicting President Volodymyr Zelenskyy calling on Ukrainian forces to lay down their arms and surrender, within a broader affected-state account of AI-generated wartime disinformation.
    Does not establish
    An affected-state analytical report does not independently establish the creator, sponsor, complete distribution path, unique exposure, belief change, military behavior, or strategic effect of the artifact.
    Review
    LOCATED_AND_REVIEWED_AT_CITATION_LEVEL · Citation and source-scope review completed for WIP.51 on 2026-07-27; publication date was not independently closed in retrieved page metadata.
  7. Reuters · 2022-03-16 · Independent professional journalism

    Supports
    Documents the appearance and circulation of a poorly edited video falsely depicting President Zelenskyy urging surrender, the Ukraine24 compromise report, rapid debunking, and platform removal.
    Does not establish
    Does not identify the creator or sponsor and states that it was unclear whether anyone was convinced; it does not establish military, political, or strategic effect.
    Review
    LOCATED_AND_REVIEWED_AT_CITATION_LEVEL · Citation and source-scope review completed for WIP.51 on 2026-07-27.
  8. American Political Science Review · 2025-02-01 · Primary research

    Supports
    Across five survey experiments involving more than 15,000 U.S. adults, finds that false claims of misinformation can raise politician support in tested scandal scenarios, primarily for text reports rather than video, without a consistent generalized decline in media trust.
    Does not establish
    Does not measure naturalistic field prevalence, durable electoral behavior, every type of audiovisual denial, cross-national generalizability, or the strategic magnitude of the liar’s dividend in real crises.
    Review
    LOCATED_AND_REVIEWED_AT_CITATION_LEVEL · Citation and source-scope review completed for WIP.51 on 2026-07-27.
Selected works identified by the owner-supplied report
  • Chesney and Citron, Deep Fakes: A Looming Challenge for Privacy, Democracy, and National Security.
  • Lucas et al., Political Deepfake Videos Are No More Deceptive Than Other Fake News.
  • Schiff et al., The Liar’s Dividend: Can Politicians Claim Misinformation to Evade Accountability?
  • Boneh, Using Zero-Knowledge Proofs to Fight Disinformation.

Exact source preservation and editorial currentness review do not constitute specialist certification, adjudication, legal advice, clinical review, or proof that every owner-report citation is current. Corrections remain open.

Page complete AI-Enabled Deepfake Psychological Operations Page label: CONTEMPORARY / ONGOING CLAIM — NOT SETTLED HISTORY