Educational companion dossier · Fact, interpretation, lived experience, clinical education, fiction, and mechanics are labeled separately. Scope & safety

AI PSYOPS · FIELD REALISM · WIP.56

From plausible claim to bounded finding

A defensive authority-review layer for deciding what an incident, model, law, appeal, forecast, or authentication signal actually establishes.

The twelve-category taxonomy describes how AI can intersect with influence. Field realism follows the evidence farther: from source identity to authority, from artifact to effect, from appeal to downstream repair, from sensor to construct validity, and from predictive output to the institutional action taken on it.

REAL-WORLD INTERPRETIVE

A CROSS-CUTTING EVIDENCE LAYER

Twelve exact owner reports plus one clearly labeled repository synthesis

WIP.56 retains the twelve exact owner-supplied report records and their thirteen source instances. It adds twenty-two primary or authoritative source records and thirteen claim-specific reviews. The additional predictive-population deployment report is explicitly repository-authored because no new dedicated owner report on that topic was supplied in the WIP.55 intake.

What this changes: public wording now states the source relationship, supported finding, unsupported stronger inference, competing explanations, measurement and generalization limits, privacy and affected-person boundaries, currentness, correction trigger, and reopening trigger.

What this does not change: source review is not a legal opinion, clinical diagnosis, scientific certification, intelligence attribution, affected-community endorsement, accessibility certification, publication approval, production authority, or permission to conduct psychological operations.

SIX REALISM GATES

Do not let one observation silently become a stronger conclusion

Each gate prevents a common analytical collapse. A source can pass one gate and still leave every later stage unresolved.

  1. Artifact → effect

    An artifact can exist without proving coordination, actor identity, sponsorship, intent, recipient belief, behavior change, or strategic effect.

  2. Appeal → repair

    A reversal or restored item can stop an immediate error without correcting copied data, derived scores, rankings, vendor records, lost income, reputation, or repeated harm.

  3. Signal → mind

    A facial movement, vocal feature, gaze pattern, physiological signal, or interaction trace is not direct knowledge of emotion, deception, loyalty, vulnerability, or intent.

  4. Rule → universal law

    One enacted rule, judgment, settlement, guidance document, or proposal does not become a universal cognitive-liberty code.

  5. Account → prevalence

    An attributable first-person or institutional record can document harm without establishing population prevalence, one exclusive cause, or community endorsement.

  6. Indicator → attribution

    A generated face, detector score, linguistic pattern, or synchronized post is not enough by itself to establish a coordinated network, actor, sponsor, intent, or effect.

TWENTY-STAGE EFFECT ATTRIBUTION

Follow the complete chain—then stop where the evidence stops

Distribution metrics, psychological outcomes, operational outcomes, and strategic effects are separate findings. A sponsor’s objective is not a measured effect.

  1. 01Artifact or event existence
  2. 02Content status
  3. 03Coordination
  4. 04Actor identity
  5. 05Sponsorship or direction
  6. 06Intent
  7. 07Output
  8. 08Distribution
  9. 09Availability
  10. 10Reach
  11. 11Exposure
  12. 12Attention
  13. 13Recall
  14. 14Comprehension
  15. 15Credibility
  16. 16Belief or attitude
  17. 17Intention
  18. 18Behavior
  19. 19Operational outcome
  20. 20Strategic effect

Publication rule: output does not establish distribution; reach does not establish exposure; exposure does not establish credibility; credibility does not establish belief; behavior does not automatically establish operational or strategic effect.

THIRTEEN CLAIM-SPECIFIC REVIEWS

Public wording paired with the strongest source and its limits

Open a review to see the source relationship, alternatives, measurement limits, privacy boundary, currentness, and the evidence that would reopen the assessment.

  1. CLAIM-REAL-01-REPAIR Reversal is not complete repairPRIMARY_AUTHORITY_CLOSURE_PARTIAL
    A successful appeal, reversal, settlement, or restored account can stop an immediate error without repairing every copied record, derived score, ranking signal, vendor system, financial loss, reputational consequence, or psychological harm.

    Evidence supports

    Remedy must be decomposed into notice, access, authoritative review, reversal, restoration, data correction, downstream propagation, compensation, repeat prevention, and unresolved harm.

    Does not establish

    That every appealed system fails downstream repair or that every reversal is ineffective.

    Claim type
    REMEDY_OUTCOME
    Scope
    Cross-domain automated decisions and platform governance
    Source relationship
    Official inquiry plus a primary platform appellate decision illustrate distinct remedy stages.
    Currentness
    SUPPORTED_WITH_DOMAIN_LIMITS
    Specialist disposition
    NOT_COMPLETED

    Measurement limits

    Public decisions rarely disclose all internal ranking, feature-store, vendor, cache, and backup changes.

    Generalization limits

    A platform-content appeal and a public-benefits inquiry are different legal and technical systems.

    Privacy boundary

    Do not publish personal records or infer private harms beyond attributable evidence.

    Affected-person boundary

    Published testimony and institutional findings can establish experienced harms without making every account representative.

    Competing explanations

    • Some systems may fully correct a limited record even when broader harm is absent.
    • A visible restoration may be complete for a narrow content-removal dispute but not for other domains.

    Primary or authoritative records

    Correction trigger: A source shows complete downstream correction and remediation for a cited case.

    Reopening trigger: New audit, compensation, propagation, or repeat-error data becomes available.

  2. CLAIM-REAL-02-UNLEARNING Deletion and output blocking are not model unlearningPRIMARY_AUTHORITY_CLOSURE_SUBSTANTIAL
    Deleting a source record or blocking an output does not by itself remove the record’s learned influence from model weights, embeddings, features, memories, caches, backups, or downstream recipients.

    Evidence supports

    Source deletion, suppression, output blocking, retraining, and influence removal are distinct interventions.

    Does not establish

    That exact unlearning is feasible for every model or that a specific implementation satisfies law.

    Claim type
    TECHNICAL_DATA_LINEAGE
    Scope
    Machine-learning systems, retrieval systems, agents, and data pipelines
    Source relationship
    Official technical definition supported by primary research on an efficient unlearning architecture.
    Currentness
    SUPPORTED_TECHNICAL_DISTINCTION
    Specialist disposition
    NOT_COMPLETED

    Measurement limits

    Verification requires comparing model behavior or parameters against an appropriate counterfactual and tracing downstream systems.

    Generalization limits

    Methods for sharded supervised models do not automatically transfer to foundation models, reinforcement learning, or proprietary multi-vendor systems.

    Privacy boundary

    Verification should avoid re-exposing the very personal data being removed.

    Affected-person boundary

    A person’s right to correction does not imply that every probabilistic inference can be labeled factually true or false without context.

    Competing explanations

    • For an untrained rules system, source deletion may be sufficient.
    • A model may never have ingested the corrected record.

    Primary or authoritative records

    Correction trigger: NIST or a recognized standard adopts a materially different definition.

    Reopening trigger: Validated exact-unlearning benchmarks for large deployed models become available.

  3. CLAIM-REAL-03-MENTAL-STATE Observed movement is not direct knowledge of emotionPEER_REVIEWED_CLOSURE_SUBSTANTIAL
    A system may detect a facial movement, voice feature, gaze pattern, physiological signal, or interaction trace without validly determining a person’s emotion, deception, loyalty, attention, vulnerability, or intent.

    Evidence supports

    Sensor and feature accuracy must be separated from label quality, construct validity, calibration, generalization, base rates, subgroup burden, and institutional action.

    Does not establish

    That no behavioral or physiological signal has any predictive utility for any narrow purpose.

    Claim type
    SCIENTIFIC_CONSTRUCT_VALIDITY
    Scope
    Affective computing and mental-state inference
    Source relationship
    Peer-reviewed scientific review provides the construct-validity boundary; legislation supplies a bounded governance response.
    Currentness
    SUPPORTED_WITH_MODALITY_LIMITS
    Specialist disposition
    NOT_COMPLETED

    Measurement limits

    Ground truth for latent mental constructs is often contested, culturally dependent, and affected by context.

    Generalization limits

    Facial-expression evidence cannot be generalized automatically to every modality or population.

    Privacy boundary

    Do not treat inferred states as private facts or publish individualized mental-health conclusions.

    Affected-person boundary

    Subgroup performance, disability, neurodiversity, and cultural expression require separate evaluation.

    Competing explanations

    • Multimodal systems may improve prediction for a defined operational outcome without reading an inner state.
    • Context-specific self-report labels may support narrow research uses.

    Primary or authoritative records

    Correction trigger: Large replicated field studies establish robust construct validity for a specified system and use.

    Reopening trigger: New scientific consensus or regulatory guidance materially changes the boundary.

  4. CLAIM-REAL-04-LAW Cognitive-liberty law is jurisdiction-specific and unevenPRIMARY_LEGAL_CLOSURE_PARTIAL
    Current protections for neural data, emotion inference, manipulation, automated decisions, and mental privacy are distributed across jurisdictions and legal instruments; no single universal cognitive-liberty code governs every system.

    Evidence supports

    Legal status must separate proposal, enactment, entry into force, application, guidance, complaint, enforcement, settlement, judgment, amendment, repeal, and supersession.

    Does not establish

    Legal advice, universal application, or uniform enforcement.

    Claim type
    LEGAL_CURRENTNESS
    Scope
    International, supranational, national, and subnational law
    Source relationship
    Primary enacted legal texts establish bounded rules in their own jurisdictions.
    Currentness
    CURRENTNESS_REVIEWED_2026-07-28
    Specialist disposition
    NOT_COMPLETED

    Measurement limits

    Public legal status may lag implementation, enforcement, or litigation.

    Generalization limits

    EU and Colorado rules cannot be universalized to other jurisdictions.

    Privacy boundary

    Legal summaries should not expose complainants or infer protected traits.

    Affected-person boundary

    Formal rights may remain inaccessible because of cost, language, disability, retaliation, or standing barriers.

    Competing explanations

    • Existing privacy, consumer-protection, disability, labor, or human-rights law may cover harms without using the term cognitive liberty.
    • Soft-law principles can influence practice without being binding law.

    Primary or authoritative records

    Correction trigger: A law is amended, repealed, corrected, or authoritatively interpreted.

    Reopening trigger: Implementing rules, enforcement, or appellate decisions become available.

  5. CLAIM-REAL-05-VISIBILITY Visibility actions and remedy outcomes are separatePRIMARY_DECISION_CLOSURE_PARTIAL
    Removal, restriction, search exclusion, recommendation exclusion, downranking, labeling, monetization change, account penalties, synthesized reframing, and profile changes are different interventions with different notice, evidence, appeal, restoration, and downstream effects.

    Evidence supports

    A content item can be restored without evidence that reach, recommendation, strikes, monetization, or copied signals were repaired.

    Does not establish

    That every traffic decline is suppression or every ranking change is censorship.

    Claim type
    PLATFORM_GOVERNANCE_OUTCOME
    Scope
    Ranking, recommendation, moderation, and persistent profiles
    Source relationship
    A primary appellate decision demonstrates removal, notice, appeal, reversal, and restoration as separate stages.
    Currentness
    SUPPORTED_CASE_BOUNDARY
    Specialist disposition
    NOT_COMPLETED

    Measurement limits

    Platforms rarely reveal counterfactual distribution, recommendation coefficients, or all internal enforcement signals.

    Generalization limits

    One platform decision does not describe every platform or AI assistant.

    Privacy boundary

    Appeal transparency should not expose reporter identities, private safety data, or vulnerable users.

    Affected-person boundary

    Creator income and audience effects require attributable evidence rather than inferred reach loss.

    Competing explanations

    • Audience demand, competition, seasonality, product changes, or ordinary ranking updates can reduce reach.
    • Some interventions are lawful, transparent, and necessary for safety.

    Primary or authoritative records

    Correction trigger: Platform records show that a named action or outcome was misclassified.

    Reopening trigger: Audit data reveals downstream ranking, strike, monetization, or profile changes.

  6. CLAIM-REAL-06-AFFECTED-EVIDENCE Lived experience and institutional evidence require explicit scopeOFFICIAL_INQUIRY_CLOSURE_PARTIAL
    Attributed first-person, representative, institutional, aggregated, anonymized, and derivative evidence can document serious algorithmic harms, but none should be treated as automatically representative of every affected person or as proof of one exclusive causal mechanism.

    Evidence supports

    Affected-person evidence belongs in governance analysis with consent, privacy, retaliation, selection, nonresponse, and representativeness limits.

    Does not establish

    Population prevalence from a case collection or an exclusive causal chain for every reported harm.

    Claim type
    AFFECTED_PERSON_EVIDENCE
    Scope
    Workers, applicants, tenants, benefits claimants, students, creators, families, and other affected groups
    Source relationship
    Official inquiry record integrates institutional evidence and published testimony while preserving a bounded source context.
    Currentness
    SUPPORTED_METHOD_BOUNDARY
    Specialist disposition
    NOT_COMPLETED

    Measurement limits

    Nonresponse, survivorship, legal selection, and inaccessible records limit inference.

    Generalization limits

    One program, community, or jurisdiction cannot represent all systems.

    Privacy boundary

    Do not identify private people, publish sensitive records, or infer diagnosis, immigration status, disability, or trauma.

    Affected-person boundary

    No project-run interviews, consent, or community endorsement are claimed in WIP.56.

    Competing explanations

    • Administrative, economic, health, family, or institutional factors may contribute alongside automation.
    • Published testimony may overrepresent severe or legally salient cases.

    Primary or authoritative records

    Correction trigger: A cited account is corrected, withdrawn, or shown to be misrepresented.

    Reopening trigger: Authorized community research, representative surveys, or new official records become available.

  7. CLAIM-REAL-07-COMPANION-SAFETY Regulatory inquiry is not clinical causalityPRIMARY_REGULATORY_CLOSURE_LIMITED
    The FTC’s companion-chatbot inquiry establishes an official demand for information about safety, children and teens, disclosures, monetization, and data practices; it is not a completed finding that any product caused a psychiatric condition.

    Evidence supports

    Companion-system safety requires product-design, age, disclosure, data, engagement, crisis, and dependency review.

    Does not establish

    Prevalence, diagnosis, causation, negligence, or liability.

    Claim type
    CLINICAL_AND_REGULATORY_BOUNDARY
    Scope
    AI companion products and conversational systems
    Source relationship
    Primary regulatory notice defines inquiry scope without adjudicating clinical causation.
    Currentness
    INQUIRY_OPEN_OR_FINDINGS_NOT_RETRIEVED
    Specialist disposition
    NOT_COMPLETED

    Measurement limits

    Case reports, media accounts, and complaints cannot establish population prevalence or comparative risk alone.

    Generalization limits

    Different products, model versions, ages, and usage patterns have different risk profiles.

    Privacy boundary

    Do not diagnose identifiable users or publish private chats without authorization.

    Affected-person boundary

    Families and users should be represented through attributable, consent-aware records with withdrawal and retaliation safeguards.

    Competing explanations

    • Users may have pre-existing vulnerabilities, sleep loss, substance exposure, grief, isolation, or other stressors.
    • Some users report short-term support without harmful dependency.

    Primary or authoritative records

    Correction trigger: FTC publishes findings or corrects the inquiry scope.

    Reopening trigger: Peer-reviewed longitudinal evidence, final enforcement, or adjudicated product records become available.

  8. CLAIM-REAL-08-INCIDENT-EFFECT An incident record does not automatically prove behavioral effectPRIMARY_AUTHORITY_CLOSURE_SUBSTANTIAL_FOR_INCIDENT
    The New Hampshire Biden robocall is documented as an AI-generated impersonation, spoofed distribution event, and enforcement matter; the available authority does not establish how many recipients believed it or whether voting behavior changed.

    Evidence supports

    Incident analysis must separate existence, content, coordination, identity, sponsorship, intent, output, distribution, availability, reach, exposure, attention, recall, comprehension, credibility, belief, intention, behavior, operational outcome, and strategic effect.

    Does not establish

    Recipient belief, turnout change, electoral outcome, or broad AI persuasion effectiveness.

    Claim type
    INCIDENT_AND_EFFECT_ATTRIBUTION
    Scope
    Election-related synthetic audio incident
    Source relationship
    Final agency action closes artifact, operator, distribution, and enforcement stages while leaving belief and behavior unmeasured.
    Currentness
    FINAL_ENFORCEMENT_RECORD_WITH_EFFECT_GAP
    Specialist disposition
    NOT_COMPLETED

    Measurement limits

    Recipient-level exposure, belief, and behavior data are not available in the cited enforcement record.

    Generalization limits

    A targeted robocall cannot represent all synthetic media or election contexts.

    Privacy boundary

    Do not publish recipient phone numbers or private voter data.

    Affected-person boundary

    Recipient experience is not inferred without attributable testimony or research.

    Competing explanations

    • Recipients may have recognized the anomaly or learned of the correction before acting.
    • Media coverage may have expanded awareness of the fake more than the original calls.

    Primary or authoritative records

    Correction trigger: FCC or a court changes the operator, scope, or final disposition.

    Reopening trigger: Survey, telecom, or election research measures exposure, belief, or behavior.

  9. CLAIM-REAL-09-SWARM-DETECTION Behavioral coordination evidence is stronger than a synthetic-content score alonePRIMARY_PLATFORM_CLOSURE_PARTIAL
    Synthetic profile imagery or an AI-content detector score can be one clue, but coordinated inauthentic behavior should be assessed through network, chronology, infrastructure, role, and platform-enforcement evidence; a generated face alone does not identify a sponsor or prove effect.

    Evidence supports

    Content generation, coordination, actor identity, sponsorship, intent, and effect are separate claims.

    Does not establish

    That pseudonymous users, non-native writers, activists, role-players, or neurodivergent users are bots because of linguistic style or imagery.

    Claim type
    ATTRIBUTION_AND_FALSE_POSITIVES
    Scope
    Synthetic personas, coordinated networks, and platform threat detection
    Source relationship
    Primary platform reports document observed misuse while preserving behavior-centered enforcement and bounded reach findings.
    Currentness
    SUPPORTED_WITH_PLATFORM_LIMITS
    Specialist disposition
    NOT_COMPLETED

    Measurement limits

    Platform access and private telemetry create verification asymmetry; public researchers may lack decisive metadata.

    Generalization limits

    Detection signals vary by platform, language, community, and adversary adaptation.

    Privacy boundary

    Avoid de-anonymizing lawful pseudonymous users or publishing sensitive network identifiers.

    Affected-person boundary

    False-positive burden must be evaluated for marginalized, anonymous, and emergency-response communities.

    Competing explanations

    • Organic communities can synchronize around breaking events.
    • Marketing automation, accessibility tools, translation, or shared templates can resemble coordination.

    Primary or authoritative records

    Correction trigger: A platform retracts or materially changes a network attribution.

    Reopening trigger: Independent forensic, legal, or financial evidence establishes actor or sponsor identity.

  10. CLAIM-REAL-10-DEEPFAKE-RESPONSE Official debunking closes some stages, not all effectsPRIMARY_INCIDENT_CLOSURE_PARTIAL
    Official Ukrainian records document the Zelenskyy surrender deepfake and later Zaluzhnyi deepfakes and describe rapid detection and debunking; they do not quantify continuing belief, troop-level exposure, operator identity for every artifact, or strategic effect.

    Evidence supports

    Rapid live confirmation, official channels, redundancy, platform response, and correction archives are distinct crisis controls.

    Does not establish

    Precise origin, continuing belief, behavior change, operational disruption, or strategic effect.

    Claim type
    CRISIS_AUTHENTICATION_AND_EFFECT
    Scope
    Wartime leader impersonation and institutional response
    Source relationship
    Primary targeted-state incident report documents artifacts and response; technical standard informs future provenance rather than retroactive proof.
    Currentness
    HISTORICAL_INCIDENT_RECORD_WITH_EFFECT_GAP
    Specialist disposition
    NOT_COMPLETED

    Measurement limits

    Audience belief and frontline exposure are not fully measured in the official report.

    Generalization limits

    A wartime national-leader incident differs from local fraud, elections, or private-person harassment.

    Privacy boundary

    Do not expose private recipients, device logs, or operational security details.

    Affected-person boundary

    Civilian and service-member experiences require direct, consent-aware evidence.

    Competing explanations

    • Low technical quality may have limited credibility.
    • Repeated media coverage of the debunk may have increased awareness of the artifact.

    Primary or authoritative records

    Correction trigger: The issuing body or stronger forensic evidence changes chronology or attribution.

    Reopening trigger: Platform telemetry, intelligence release, or recipient research measures exposure and effect.

  11. CLAIM-REAL-11-LIARS-DIVIDEND Provenance is not truth, and the liar’s dividend is context-dependentPRIMARY_STANDARD_PLUS_PEER_REVIEWED_CLOSURE_SUBSTANTIAL
    Cryptographic provenance can verify a signed history or claim, but it does not prove the represented event is true, and missing credentials do not prove media is false. Experimental evidence also shows that false deepfake claims do not work uniformly across formats and contexts.

    Evidence supports

    Authentication should combine provenance, source confirmation, live interaction, reverse search, forensics, channel redundancy, correction archives, and uncertainty disclosure.

    Does not establish

    That provenance guarantees truth or that deepfake denial always succeeds.

    Claim type
    PROVENANCE_AND_LIARS_DIVIDEND
    Scope
    Crisis authentication, signed media, and false denial
    Source relationship
    Primary standard defines what provenance authenticates; peer-reviewed experiments bound the liar’s-dividend effect.
    Currentness
    STANDARD_AND_EXPERIMENTAL_EVIDENCE_CURRENT_AS_ACCESSED
    Specialist disposition
    NOT_COMPLETED

    Measurement limits

    Trust-list governance, key compromise, metadata loss, and user comprehension affect real-world performance.

    Generalization limits

    Survey experiments do not reproduce every high-stakes crisis or media ecosystem.

    Privacy boundary

    Provenance systems should minimize unnecessary device and creator identity exposure.

    Affected-person boundary

    Authentication should not require vulnerable witnesses to reveal identities publicly.

    Competing explanations

    • Authentic media can lack credentials because of legacy devices, screenshots, recompression, or stripped metadata.
    • Signed media can still depict staged, misleading, or selectively framed events.

    Primary or authoritative records

    Correction trigger: C2PA or the journal corrects the relevant records.

    Reopening trigger: Field evidence on credential adoption, attack resistance, or liar’s-dividend effects becomes available.

  12. CLAIM-REAL-12-DEMOCRATIC-DEFENSE Democratic defense should target behavior and foreign interference, not lawful beliefPRIMARY_GOVERNANCE_CLOSURE_PARTIAL
    A defensible cognitive-security mandate can focus on concealed foreign direction, artificial amplification, impersonation, technical tampering, and coordinated inauthentic behavior while preserving lawful domestic belief, dissent, anonymity, journalism, and political opposition.

    Evidence supports

    Mandates should be specific, legally bounded, transparent, independently overseen, correction-capable, and separated from content or belief policing.

    Does not establish

    That every institutional classification is correct or that the French model is universally transferable.

    Claim type
    GOVERNANCE_AND_CIVIL_LIBERTIES
    Scope
    Democratic information-integrity institutions
    Source relationship
    Official French threat assessment documents a foreign-interference and behavior-focused mandate.
    Currentness
    CURRENT_OFFICIAL_MANDATE_AS_ACCESSED
    Specialist disposition
    NOT_COMPLETED

    Measurement limits

    Effectiveness and false-positive rates require independent oversight and published outcome data.

    Generalization limits

    Constitutional, intelligence, platform, and administrative law differs across countries.

    Privacy boundary

    Open-source analysis should not become general monitoring of lawful domestic communities.

    Affected-person boundary

    Targets of erroneous classification need notice, correction, and remedy where disclosure is legally possible.

    Competing explanations

    • Some harmful campaigns use authentic domestic actors or lawful speech, complicating mandate boundaries.
    • Foreign-origin evidence may be incomplete or politically contested.

    Primary or authoritative records

    Correction trigger: VIGINUM changes its mandate or an oversight body identifies mischaracterization.

    Reopening trigger: Independent audits, litigation, parliamentary review, or affected-community evidence becomes available.

  13. CLAIM-REAL-13-PREDICTIVE Aggregate forecasting and person-level risk scoring are different system classesPRIMARY_OFFICIAL_MULTI_CASE_CLOSURE_PARTIAL
    Population-level forecasts used for planning must be separated from person- or family-level risk scores used to route, investigate, screen, deny, or intensify intervention. Accuracy, authority, rights burden, feedback loops, and remedy differ substantially between these system classes.

    Evidence supports

    Every predictive system should disclose unit, target, horizon, data, model role, threshold, action, evaluation, false-positive and false-negative burden, subgroup effects, human authority, feedback loops, appeal, and current status.

    Does not establish

    That all forecasting is harmful, that all person-level scoring is unlawful, or that a model’s operator description proves independent validity.

    Claim type
    PREDICTIVE_DEPLOYMENT_SYNTHESIS
    Scope
    Public health, humanitarian planning, conflict warning, policing, benefits, child welfare, and immigration workflow
    Source relationship
    Seven primary official records illustrate distinct deployments, authorities, units of prediction, and decision consequences.
    Currentness
    REPOSITORY_AUTHORED_BOUNDED_RESEARCH_2026-07-28
    Specialist disposition
    NOT_COMPLETED

    Measurement limits

    Operator transparency records often omit independent calibration, subgroup error, and counterfactual outcomes.

    Generalization limits

    Health, humanitarian, conflict, visa, child-welfare, fraud, and policing systems have different purposes and legal bases.

    Privacy boundary

    Population planning should minimize reidentification; person-level systems require heightened data minimization and access control.

    Affected-person boundary

    No system should infer endorsement from affected communities; direct and representative evidence remains necessary.

    Competing explanations

    • Aggregate forecasting may support beneficial resource allocation without identifying individuals.
    • Human reviewers may mitigate or amplify model errors depending on authority and workload.

    Primary or authoritative records

    Correction trigger: An operator or court changes a system’s purpose, authority, status, or outcome.

    Reopening trigger: Independent evaluation, litigation, audit, or affected-person evidence becomes available.

REMEDY AND SCIENTIFIC VALIDITY

Two chains that prevent paper compliance and scientific overclaiming

A nominal appeal is not complete repair. A high classification score is not proof that a system measures the claimed psychological construct.

Thirteen-stage remedy chain

  1. 01Notice
  2. 02Comprehension
  3. 03Access
  4. 04Relevant evidence
  5. 05Authoritative review
  6. 06Reversal
  7. 07Immediate restoration
  8. 08Source-data correction
  9. 09Inferred-data correction
  10. 10Downstream propagation
  11. 11Compensation
  12. 12Repeat-error prevention
  13. 13Unresolved harm

Sixteen-stage validity chain

  1. 01Sensor or input quality
  2. 02Feature extraction
  3. 03Label quality
  4. 04Construct validity
  5. 05Criterion validity
  6. 06Calibration
  7. 07Generalization
  8. 08Base-rate sensitivity
  9. 09False-positive burden
  10. 10False-negative burden
  11. 11Subgroup performance
  12. 12Human override
  13. 13Automation bias
  14. 14Institutional action
  15. 15Downstream consequence
  16. 16Remedy

REPOSITORY-AUTHORED BOUNDED RESEARCH

Seven predictive deployments, three different system classes

No dedicated owner-supplied predictive-deployment report was present in the WIP.55 intake. WIP.56 fills that gap with a clearly labeled synthesis of primary official records rather than manufacturing an owner source.

Aggregate forecasting

Examples: Influenza activity, forced displacement, conflict risk

Usually planning-oriented; uncertainty, resource allocation, omission, and politicized interpretation remain material.

Case routing and prioritization

Examples: Visa application complexity routing

Not necessarily a final decision, but can alter delay, scrutiny, workload, and automation bias.

Person or family risk scoring

Examples: Police risk lists, child-welfare screening, fraud-risk indications

Heightened notice, validation, subgroup burden, feedback-loop, human-authority, appeal, and downstream-correction requirements.

Deployment purpose, decision role, status, validation boundary, and remedy
DeploymentSystem classUnitDecision roleStatusValidation and remedy boundary
Chicago Strategic Subjects List and Crime and Victimization Risk ModelPolicing and public safety PERSON_LEVEL_RISK_SCORING Named individuals Person-level scoring and tiering used within policing programs. DECOMMISSIONED_2019-11-01

OFFICIAL_OVERSIGHT_DOCUMENTED_INDEPENDENT_CAUSAL_BENEFIT_NOT_ESTABLISHED

Downstream deletion, correction, and notice to scored people are not established in the cited authority.

System Risk Indication (SyRI)Public-benefits and fraud risk PERSON_OR_HOUSEHOLD_RISK_ANALYSIS People and households within selected areas or investigations Risk indication supporting government investigation rather than final adjudication by itself. LEGAL_FRAMEWORK_FOUND_INCOMPATIBLE_WITH_ARTICLE_8_IN_2020_JUDGMENT

JUDICIAL_TRANSPARENCY_AND_PROPORTIONALITY_FAILURE_DOCUMENTED_PREDICTIVE_VALIDITY_NOT_ESTABLISHED

The judgment stopped the legal framework’s use in the challenged form; complete correction of all underlying records and harms is not established.

Allegheny Family Screening ToolChild welfare intake FAMILY_LEVEL_RISK_SCREENING Children and families named in hotline referrals High score levels can require screening in; other scores supplement human intake judgment. CURRENT_OPERATOR_DESCRIPTION_AS_ACCESSED

OPERATOR_DOCUMENTATION_AVAILABLE_INDEPENDENT_CURRENT_VALIDITY_REVIEW_INCOMPLETE

Public operator description does not establish a comprehensive affected-family appeal and downstream-correction process.

UK Home Office Complexity Application Routing Solution — VisitsImmigration workflow CASE_ROUTING_AND_PRIORITIZATION Visitor visa applications The official record states that the system does not make the application decision. CURRENT_TRANSPARENCY_RECORD_AS_ACCESSED

ROLE_AND_PURPOSE_DOCUMENTED_INDEPENDENT_GROUP_PERFORMANCE_NOT_CLOSED

Ordinary visa-review routes may apply, but correction of routing features and downstream influence is not established here.

CDC FluSightPublic-health planning AGGREGATE_POPULATION_FORECASTING Population-level influenza activity over time Forecasts inform planning rather than assigning individual risk labels or legal consequences. ACTIVE_PROGRAM_AS_ACCESSED

SEASONAL_EVALUATION_PRACTICE_DOCUMENTED_PERFORMANCE_VARIES_BY_SEASON_AND_HORIZON

Forecast correction is principally methodological and public; individual appeal is generally not the relevant remedy.

UNHCR forced-displacement forecastingHumanitarian planning AGGREGATE_DISPLACEMENT_FORECASTING Aggregate displacement flows and humanitarian demand Planning input; the cited record does not assign person-level sanctions or status decisions. 2025_TECHNICAL_WORK_RECORDED

INSTITUTIONAL_TECHNICAL_WORK_DOCUMENTED_OPERATIONAL_PERFORMANCE_REVIEW_NOT_CLOSED

Model revision and allocation correction are relevant; individual appeal is not the primary mechanism in the cited use.

European Commission JRC Dynamic Conflict Risk ModelConflict early warning AGGREGATE_STRUCTURAL_RISK_FORECASTING Country- or area-level conflict risk over defined horizons Analytical input rather than an autonomous decision or coercive intervention. 2025_TECHNICAL_REPORT_AS_PUBLISHED

MODEL_AND_INTEGRATION_APPROACH_DOCUMENTED_OUT_OF_SAMPLE_AND_POLICY_EFFECT_REVIEW_OPEN

Correction concerns model, data, and published assessment; person-level appeal is not the primary mechanism.

Chicago Strategic Subjects List and Crime and Victimization Risk Model — evidence boundary

Stated purpose: Estimate risk of involvement in gun violence and support intervention prioritization.

Rights and feedback-loop risk: Historical police data can encode enforcement patterns; person-level scores can intensify contact and create feedback loops.

Human authority: Institutional intervention decisions remained human, but the score structured attention and priority.

Source supports: The OIG documents the models, governance concerns, and decommissioning.

Source does not establish: Crime reduction caused by the models, complete downstream repair, or universal properties of predictive policing.

Open the primary or authoritative record

Reopening trigger: New litigation, audit, retained-score evidence, or replacement-system record.

System Risk Indication (SyRI) — evidence boundary

Stated purpose: Identify elevated risk of fraud or non-compliance by linking administrative data.

Rights and feedback-loop risk: Opaque multi-source scoring can burden disadvantaged neighborhoods and make errors difficult to contest.

Human authority: Authorities selected projects and acted on indications; human involvement did not remove transparency and proportionality concerns.

Source supports: The court’s disposition and legal reasoning in the case.

Source does not establish: That every fraud-risk system is unlawful or that every person experienced the same harm.

Open the primary or authoritative record

Reopening trigger: Higher-court, legislative, compensation, or implementation records.

Allegheny Family Screening Tool — evidence boundary

Stated purpose: Estimate chance of future out-of-home placement to inform screening decisions.

Rights and feedback-loop risk: Administrative data and prior intervention can reproduce institutional patterns; mandated thresholds can amplify automation bias.

Human authority: Human screeners retain roles, but high-score mandates constrain discretion.

Source supports: Purpose, score role, and operator-described workflow.

Source does not establish: Independent fairness, causal benefit, or absence of disparate burden.

Open the primary or authoritative record

Reopening trigger: New independent audit, litigation, model update, threshold change, or community evidence.

UK Home Office Complexity Application Routing Solution — Visits — evidence boundary

Stated purpose: Route applications according to assessed complexity for workflow management.

Rights and feedback-loop risk: Routing can still affect delay, scrutiny, workload, and automation bias even when it is not the final decision.

Human authority: Human caseworkers make final decisions.

Source supports: The operator’s system purpose, rules-based nature, and non-decision role.

Source does not establish: Fairness, calibration, or no effect on applicants.

Open the primary or authoritative record

Reopening trigger: Impact assessment, audit, updated transparency record, or litigation.

CDC FluSight — evidence boundary

Stated purpose: Support public-health situational awareness, planning, and resource decisions.

Rights and feedback-loop risk: Lower person-level rights burden, but communication of uncertainty and resource-allocation consequences still matter.

Human authority: Public-health officials interpret forecasts alongside surveillance and operational judgment.

Source supports: Existence, planning purpose, and evaluation model.

Source does not establish: Perfect accuracy or transferability to political or security prediction.

Open the primary or authoritative record

Reopening trigger: Season-end evaluation, methodology change, or program status change.

UNHCR forced-displacement forecasting — evidence boundary

Stated purpose: Anticipate potential forced displacement to inform preparedness and resource planning.

Rights and feedback-loop risk: Aggregate models can still misallocate scarce aid or overlook communities if uncertainty and data gaps are hidden.

Human authority: Humanitarian analysts and decision-makers integrate forecasts with contextual evidence.

Source supports: The institutional forecasting initiative and humanitarian-planning purpose.

Source does not establish: Individual movement prediction or universal performance across crises.

Open the primary or authoritative record

Reopening trigger: Operational evaluation, model-card publication, or revised technical guidance.

European Commission JRC Dynamic Conflict Risk Model — evidence boundary

Stated purpose: Provide quantitative risk signals integrated with qualitative early warning.

Rights and feedback-loop risk: False alarms and omissions can affect attention and resources; politicized interpretation can exceed the model’s evidentiary scope.

Human authority: Analysts integrate quantitative output with qualitative evidence and policy judgment.

Source supports: The model architecture and its role within a mixed-method early-warning process.

Source does not establish: Certainty of conflict onset or strategic benefit from actions taken.

Open the primary or authoritative record

Reopening trigger: Performance evaluation, model revision, or public operational-use record.

CRISIS AUTHENTICATION

Use overlapping controls—and state what each control cannot prove

Authentication fails when one detector or one credential is treated as an oracle. Provenance, forensics, official confirmation, corrections, and public literacy answer different questions.

Live confirmation

Direct interactive confirmation can rapidly rebut a recording, but the channel itself must be authenticated and available.

Official authentication channels

Pre-established official channels reduce ambiguity; channel compromise or impersonation remains possible.

Cross-channel redundancy

Independent channels reduce single-point failure but do not guarantee audience exposure.

Cryptographic signing and C2PA

Can verify signed provenance claims; cannot prove the depicted event is true or make unsigned media false.

Watermarking

Can signal synthetic origin in supported systems; marks may be absent, stripped, or unavailable for open models.

Forensic analysis

Can identify artifacts or inconsistencies; detector confidence is not identity, sponsorship, or effect.

Reverse search and source comparison

Can reveal older or unaltered material; novel synthetic media may have no prior source.

Public correction archives

Preserve institutional memory; a correction record does not prove every audience received or believed it.

Prebunking and public literacy

Can prepare audiences for known tactics; must not become generalized distrust of all evidence.

Rapid-response teams

Can coordinate verification and communication; authority, oversight, privacy, and correction must be explicit.

BEHAVIOR-BASED DEMOCRATIC DEFENSE

Defend institutions without turning lawful belief into hostile terrain

  • Target concealed coordination, impersonation, technical tampering, foreign direction, and artificial amplification rather than lawful belief.
  • Separate platform behavior evidence from content truth judgments and political viewpoint.
  • Require attributable authority, narrow mandate, independent oversight, correction, and public reporting.
  • Protect lawful pseudonymity, journalism, research, activism, minority-language speech, and emergency coordination from false positives.
  • Do not treat institutional classification as self-proving; preserve alternative explanations and reopening triggers.

THIRTEEN PUBLIC REPORT RECORDS

Twelve owner reports and one bounded predictive synthesis

Exact owner-source identity remains separate from authority review. The thirteenth record is visibly marked as repository-authored and has zero owner source instances.

  1. REMEDY AND DOWNSTREAM REPAIR

    Algorithmic Remedy Outcomes and Downstream Repair

    #

    Examines the gap between a nominal appeal, a reversible decision, immediate restoration, downstream-data correction, compensation, repeat-error prevention, and complete repair across high-stakes automated systems.

    What it adds

    Grounds cognitive-liberty remedy claims in the difference between stopping an error and repairing the financial, reputational, housing, employment, benefits, identity, and psychological consequences that can continue after reversal.

    Evidence boundary

    The report is owner supplied and not independently citation-audited in this release. A reversed decision, settlement, restored post, or reopened account is not treated as proof that every copied record, score, vendor system, or downstream consequence was repaired.

    Defensive questions for this evidence
    • Could the affected person discover the decision, rule, and responsible institution?
    • Did a reviewer have real authority to reverse the decision and correct source and inferred data?
    • Was repair propagated to vendors, caches, model features, risk labels, strikes, and third-party recipients?
    • What harm remained after the formal remedy?
    Stable IDREAL-01-ALGORITHMIC-REMEDY
    Source authorityOWNER_SUPPLIED_RESEARCH_REPORT
    Owner fileAlgorithmic Appeal Outcomes And Repair.md
    Bytes61,588
    SHA-25673c415dfab0b96c27811e8c67cfd58bd23fcc931b819ad92ba39ec5aecbd4bb8
    Source instances1
    Review stateEXACT_BYTES_PRESERVED_NOT_INDEPENDENTLY_CITATION_VERIFIED
  2. DATA LINEAGE, CORRECTION, AND DELETION

    Machine Unlearning, Derived-Data Correction, and the Right to Change

    #

    Traces a correction or deletion request through source databases, features, embeddings, recommendation profiles, agent memories, model weights, caches, backups, vendors, and data brokers.

    What it adds

    Makes downstream repair technically concrete by distinguishing physical deletion, suppression, tombstoning, source correction, embedding regeneration, model editing, retraining, machine unlearning, retention expiry, and output-layer blocking.

    Evidence boundary

    The report describes technical approaches and legal tensions; it does not establish that any particular system can perfectly remove a person’s influence from every model or recipient. Concealment at the output layer is not represented as verified erasure.

    Defensive questions for this evidence
    • Which system layers still retain the record or its derived influence?
    • Is the response deletion, concealment, retraining, or verified influence removal?
    • How are downstream recipients notified, confirmed, and audited?
    • Can the correction survive future re-indexing, retraining, restoration from backup, or agent-memory retrieval?
    Stable IDREAL-02-MACHINE-UNLEARNING
    Source authorityOWNER_SUPPLIED_RESEARCH_REPORT
    Owner fileMachine Unlearning and Data Correction.md
    Bytes39,239
    SHA-256e2fe3dbfd96ffd872e33527587395b4cb8de6ec743c8d0f169a95538ebb85252
    Source instances1
    Review stateEXACT_BYTES_PRESERVED_NOT_INDEPENDENTLY_CITATION_VERIFIED
  3. SCIENTIFIC VALIDITY AND FIELD CONSEQUENCE

    Field Validity of AI Mental-State Inference Systems

    #

    Separates sensor accuracy, feature extraction, label quality, construct validity, criterion validity, calibration, generalization, base-rate sensitivity, subgroup burden, and institutional action across fourteen reported deployments.

    What it adds

    Prevents the site from presenting detection of a facial movement, vocal feature, gaze pattern, keystroke rhythm, physiological signal, or neural trace as reliable knowledge of emotion, attention, deception, loyalty, personality, dangerousness, or intent.

    Evidence boundary

    Owner-supplied case descriptions and citations are not independently verified here. Vendor demonstrations and laboratory classification scores remain insufficient evidence of construct validity or real-world benefit.

    Defensive questions for this evidence
    • What exactly was measured, and what psychological construct was inferred?
    • How was ground truth labeled and with what agreement or uncertainty?
    • How did performance change across setting, culture, language, disability, device, and time?
    • What action was taken on the output, and what false-positive burden followed?
    Stable IDREAL-03-MENTAL-STATE-VALIDITY
    Source authorityOWNER_SUPPLIED_RESEARCH_REPORT
    Owner fileAI Mental-State Inference Validity.md
    Bytes52,267
    SHA-256f08dfa4448c5db19839df85a6bed4302e449b28f2ea753330b83099827e9a2fe
    Source instances1
    Review stateEXACT_BYTES_PRESERVED_NOT_INDEPENDENTLY_CITATION_VERIFIED
  4. JURISDICTION-SPECIFIC LAW AND IMPLEMENTATION

    Comparative Cognitive Liberty Law, Regulation, and Enforcement Atlas

    #

    Surveys international, supranational, national, and subnational legal instruments touching neural data, mental privacy, biometric inference, AI manipulation, automated decisions, transparency, and contestability.

    What it adds

    Strengthens the site’s distinction between enacted text, entry into force, application date, guidance, complaint, inquiry, enforcement, settlement, judgment, appeal, amendment, repeal, and supersession.

    Evidence boundary

    The report contains currentness claims extending into 2026 that require official issuing-body verification before being promoted as current law. It is not legal advice, and no jurisdiction-specific rule is treated as a universal cognitive-liberty code.

    Defensive questions for this evidence
    • What exact instrument, jurisdiction, institution, date, scope, exception, and enforcement path apply?
    • Is the record enacted law, soft law, guidance, proposal, complaint, settlement, or final judgment?
    • What changed after adoption, and what remains unimplemented or contested?
    • What correction or reopening trigger would change the legal-status label?
    Stable IDREAL-04-COGNITIVE-LIBERTY-LAW
    Source authorityOWNER_SUPPLIED_RESEARCH_REPORT
    Owner fileCognitive Liberty Legal Atlas.md
    Bytes62,400
    SHA-256290ca671ed271470c29b50c5e2631537ae4b43379e5fbb8b7267f4ef2393ef9c
    Source instances1
    Review stateEXACT_BYTES_PRESERVED_NOT_INDEPENDENTLY_CITATION_VERIFIED
  5. VISIBILITY ACTIONS AND OBSERVED OUTCOMES

    The Invisible Editor Outcome Casebook

    #

    Treats removal, restriction, search exclusion, recommendation exclusion, downranking, labeling, monetization change, synthesized reframing, account penalties, personalization, and saved-profile change as distinct actions.

    What it adds

    Adds case-oriented questions about notice, rule-specific reasons, internal and independent appeal, restoration, strikes, ranking signals, income, audience, language burden, accessibility, and unresolved harm.

    Evidence boundary

    A traffic decline alone is not treated as proof of covert suppression, and not every ranking decision is called censorship. Restoration of one item is not complete repair of reach, income, reputation, or future recommendation state.

    Defensive questions for this evidence
    • What action changed visibility, access, monetization, ranking, or profile state?
    • Was the decision automated, human, or hybrid, and was a specific reason supplied?
    • What was actually restored or corrected after appeal?
    • Did the intervention impose unequal linguistic, political, disability, or cultural burdens?
    Stable IDREAL-05-INVISIBLE-EDITOR-OUTCOMES
    Source authorityOWNER_SUPPLIED_RESEARCH_REPORT
    Owner fileAlgorithmic Visibility Outcome Casebook.md
    Bytes71,791
    SHA-256759d9ecd72ff961333a67aa6d52a34ccaa61e7837e6455b75f0d6b1756640ee0
    Source instances1
    Review stateEXACT_BYTES_PRESERVED_NOT_INDEPENDENTLY_CITATION_VERIFIED
  6. AFFECTED-PERSON AND COMMUNITY EVIDENCE

    Affected Person and Community Evidence in AI Governance

    #

    Organizes published evidence involving workers, applicants, tenants, borrowers, benefits recipients, students, families, disabled and neurodivergent people, creators, journalists, minority-language communities, migrants, neurotechnology users, and AI-companion users.

    What it adds

    Strengthens consent, privacy, retaliation, selection, nonresponse, representativeness, and lived-consequence boundaries, while distinguishing first-person, representative, institutional, aggregated, anonymized, and derivative evidence.

    Evidence boundary

    The project conducted no interviews and claims no community endorsement. Illustrative accounts are not prevalence estimates, and public testimony does not eliminate privacy, safety, withdrawal, or retaliation concerns.

    Defensive questions for this evidence
    • What is the source’s relationship to the issue and what consent or publication boundary applies?
    • Is the evidence first-person, representative, institutional, aggregated, anonymized, or derivative?
    • Whose experience is absent because of language, access, disability, retaliation, or nonresponse?
    • What does the account support, and what does it not establish about prevalence or causality?
    Stable IDREAL-06-AFFECTED-COMMUNITY
    Source authorityOWNER_SUPPLIED_RESEARCH_REPORT
    Owner fileAI Governance Community Evidence.md
    Bytes46,868
    SHA-2562f7db8b5cbbdf7e9e3ace86143e4ff71770ecca6b187e85db4e73e0a978ad7cf
    Source instances1
    Review stateEXACT_BYTES_PRESERVED_NOT_INDEPENDENTLY_CITATION_VERIFIED
  7. CLINICAL SAFETY AND AUTHORITY DISPLACEMENT

    AI Companion Dependency, Reality Testing, and Clinical Safety

    #

    Examines parasocial dependency, simulated affection, engagement optimization, sleep disruption, identity discontinuity, social stimulation versus displacement, reality testing, crisis disclosure, and the boundary between companion products and clinical systems.

    What it adds

    Improves realism around AI as a psychological authority by distinguishing formal diagnoses from public labels, temporal association from causation, and AI as catalyst, amplifier, co-author, or object of a delusional framework.

    Evidence boundary

    The report is not a clinical review of an identifiable person and does not establish prevalence or causation from media cases. The public site must not diagnose users or treat the phrase “AI psychosis” as a formal diagnostic category.

    Defensive questions for this evidence
    • What product design choices encourage attachment, exclusivity, anthropomorphism, or authority displacement?
    • What independent longitudinal evidence separates short-term support from social displacement or harm?
    • How are crisis disclosures, sleep disruption, dependency, and reality-testing concerns handled?
    • Is the system marketed or governed as a companion, wellness tool, or validated clinical product?
    Stable IDREAL-07-AI-COMPANION-SAFETY
    Source authorityOWNER_SUPPLIED_RESEARCH_REPORT
    Owner fileAI Companion Clinical Safety Analysis.md
    Bytes41,315
    SHA-2566675d1d051a6d709b914417976032edfd0608906daef6bb6374db1ac7d145cd8
    Source instances1
    Review stateEXACT_BYTES_PRESERVED_NOT_INDEPENDENTLY_CITATION_VERIFIED
  8. INCIDENT VERIFICATION AND EFFECT ATTRIBUTION

    AI PSYOPS Incident Verification and Effect Attribution Casebook

    #

    Applies a twenty-stage evidence model to reported election, narrative, geopolitical, reputational, and synthetic-media incidents so that artifact existence, coordination, attribution, intent, distribution, exposure, belief, behavior, and strategic effect remain separate.

    What it adds

    Provides a concrete realism discipline for the twelve-category taxonomy: an AI artifact can exist and circulate without proving actor identity, sponsorship, persuasion, behavior change, operational outcome, or strategic effect.

    Evidence boundary

    Incident tables contain owner-supplied judgments and some assertive causal language that require independent source review. Virality, views, impressions, media coverage, or election outcomes are not treated as proof of unique AI-caused behavior change.

    Defensive questions for this evidence
    • Is AI use confirmed, alleged, inferred, technically possible, or absent?
    • What evidence supports coordination, actor identity, sponsorship, and intent separately?
    • What is known about reach, exposure, attention, recall, comprehension, and credibility?
    • What independent evidence connects the incident to behavior, operational outcome, or strategic effect?
    Stable IDREAL-08-AI-PSYOPS-INCIDENTS
    Source authorityOWNER_SUPPLIED_RESEARCH_REPORT
    Owner fileAI PSYOPS Incident Casebook.md
    Bytes70,881
    SHA-256cf03f95334e97bcb2e99eaec986dfebcd7f879ead083f12a787d725aac217bc9
    Source instances1
    Review stateEXACT_BYTES_PRESERVED_NOT_INDEPENDENTLY_CITATION_VERIFIED
  9. DETECTION, ATTRIBUTION, AND FALSE POSITIVES

    Synthetic Persona and Disinformation Swarm Detection

    #

    Separates content generation from coordination, coordination from actor identity, actor identity from sponsorship, and sponsorship from intent or effect while surveying defensive evidence from chronology, networks, infrastructure, provenance, behavior, linguistics, and platform records.

    What it adds

    Makes false-positive risk a first-class realism concern for anonymous whistleblowers, activists, non-native writers, minority-language communities, neurodivergent users, role-players, and emergency-response communities.

    Evidence boundary

    No single linguistic, temporal, image, or detector signal proves a synthetic persona or coordinated influence operation. Public content must not expose operational evasion or collection procedures.

    Defensive questions for this evidence
    • Which independent evidence streams indicate coordination rather than similarity or shared context?
    • What benign explanations fit the same temporal, linguistic, or network pattern?
    • How were false-positive rates and subgroup burdens evaluated?
    • What platform, infrastructure, financial, or legal evidence supports attribution beyond behavioral clustering?
    Stable IDREAL-09-SWARM-DETECTION
    Source authorityOWNER_SUPPLIED_RESEARCH_REPORT
    Owner fileDisinformation Swarm Detection Research.md
    Bytes51,535
    SHA-256911690b7f246bec573b1683cb2a7b6376e188bc1094e6c23c8b9ada8077f0648
    Source instances1
    Review stateEXACT_BYTES_PRESERVED_NOT_INDEPENDENTLY_CITATION_VERIFIED
  10. CRISIS AUTHENTICATION AND INCIDENT RESPONSE

    Deepfake Crisis Authentication: Incident and Response Casebook

    #

    Reconstructs fifteen reported synthetic-media crises and compares proactive provenance, watermarking, forensic analysis, reverse search, official confirmation, cross-channel redundancy, pre-bunking, and rapid-response practices.

    What it adds

    Grounds deepfake analysis in timing, first appearance, verification, official response, platform action, media correction, continuing belief, reuse, legal action, and unresolved uncertainty rather than technical realism alone.

    Evidence boundary

    The report is owner supplied and contains incident-level claims that require source-by-source verification. Fast correction does not prove zero exposure or zero belief, and technical anomalies do not alone establish origin or sponsor.

    Defensive questions for this evidence
    • What trusted channel can authenticate a statement before a crisis occurs?
    • How quickly did reliable confirmation reach the same audiences and channels as the false artifact?
    • What evidence supports the origin, distribution network, continuing belief, and later reuse?
    • How did the response preserve authentic evidence against the liar’s dividend?
    Stable IDREAL-10-DEEPFAKE-INCIDENT-RESPONSE
    Source authorityOWNER_SUPPLIED_RESEARCH_REPORT
    Owner fileDeepfake Crisis Authentication Response.md
    Bytes71,633
    SHA-25658979757ac737fb2e357332569b30e62e9407bce833c77bf912c4b2647264ac3
    Source instances2
    Review stateEXACT_BYTES_PRESERVED_NOT_INDEPENDENTLY_CITATION_VERIFIED
    Duplicate lineage1 exact duplicate instance preserved
  11. AUTHENTICATION INFRASTRUCTURE AND EPISTEMIC RESILIENCE

    Deepfake Authentication Infrastructure and the Liar’s Dividend

    #

    Compares cryptographic signing, content credentials, watermarking, forensic analysis, reverse search, live confirmation, correction archives, official channels, cross-channel redundancy, pre-bunking, and rapid-response teams.

    What it adds

    Treats authenticity as an institutional system rather than a detector score and gives equal attention to the liar’s dividend: authentic evidence can be falsely dismissed as synthetic.

    Evidence boundary

    No provenance or detector system is represented as universal, unbreakable, or sufficient on its own. Absence of credentials is not proof of falsity, and presence of credentials requires trust-chain and custody review.

    Defensive questions for this evidence
    • Can the public verify origin, custody, edits, and official channel without relying on one platform label?
    • What happens when metadata is stripped, credentials are absent, or the source device is untrusted?
    • How are authentic records preserved when a subject falsely claims they are synthetic?
    • What public correction archive and redundant channel remain available after the immediate crisis?
    Stable IDREAL-11-DEEPFAKE-AUTHENTICATION-STUDY
    Source authorityOWNER_SUPPLIED_RESEARCH_REPORT
    Owner fileDeepfake Crisis Authentication Study.md
    Bytes61,344
    SHA-256887cee613bed350e1d027b9db6b4bb52275032c769d151c014943c2314547b10
    Source instances1
    Review stateEXACT_BYTES_PRESERVED_NOT_INDEPENDENTLY_CITATION_VERIFIED
  12. BEHAVIOR-BASED DEMOCRATIC DEFENSE

    Democratic Cognitive Defense Without Domestic Manipulation

    #

    Compares institutional approaches to foreign-influence transparency, authentication, platform reporting, independent journalism, researcher access, civic verification, election communication, provenance, whistleblower protection, and oversight.

    What it adds

    Centers the distinction between defending against concealed behavior and policing lawful belief, dissent, interpretation, or political identity, with attention to mission creep, politicization, unsupported attribution, and correction failures.

    Evidence boundary

    Case-study claims and current institutional status require issuing-body and jurisdiction-specific review. The report does not authorize domestic surveillance, censorship, belief scoring, or unsupported foreign attribution.

    Defensive questions for this evidence
    • Is the intervention behavior based, origin based, content based, or belief based?
    • What legal authority, oversight, transparency, correction, and judicial or parliamentary review apply?
    • How are lawful domestic speech, anonymity, journalism, research, and whistleblowing protected?
    • What measurable outcome and documented failure mode exist?
    Stable IDREAL-12-DEMOCRATIC-COGNITIVE-DEFENSE
    Source authorityOWNER_SUPPLIED_RESEARCH_REPORT
    Owner fileDemocratic Cognitive Defense Research.md
    Bytes57,982
    SHA-256176661c46c13e27ffe560cd9474e717f6ed465daa78395cd4e64e1b4248d96ce
    Source instances1
    Review stateEXACT_BYTES_PRESERVED_NOT_INDEPENDENTLY_CITATION_VERIFIED
  13. REPOSITORY-AUTHORED BOUNDED RESEARCH

    Predictive Population Management: Deployments, Feedback Loops, and Remedies

    #

    Compares seven primary or authoritative records spanning person-level police and child-welfare scores, fraud-risk analysis, visa workflow routing, public-health forecasting, humanitarian displacement forecasting, and conflict early warning.

    What it adds

    Fills the WIP.55 intake gap without fabricating an owner report. It separates aggregate forecasting from case routing and person-level scoring, then records decision role, human authority, validation status, feedback-loop risk, remedy, and current status for each deployment.

    Evidence boundary

    This is repository-authored bounded research, not an owner-supplied report. Operator descriptions establish purpose and workflow but do not independently prove fairness, validity, benefit, or complete remedy. No specialist disposition or affected-community endorsement is claimed.

    Defensive questions for this evidence
    • What is the unit of prediction: population, place, case, family, or person?
    • What decision or intervention can the output trigger?
    • What independent calibration, subgroup, false-positive, and false-negative evidence exists?
    • How are feedback loops, notice, appeal, correction, and downstream repair handled?
    Stable IDREAL-13-PREDICTIVE-DEPLOYMENTS
    Source authorityREPOSITORY_AUTHORED_BOUNDED_RESEARCH
    Owner source instances0
    Research basisSeven primary official records
    Review statePRIMARY_AUTHORITY_REVIEW_COMPLETE_SPECIALIST_DISPOSITION_OPEN
REAL-WORLD INTERPRETIVE

SOURCE AND REVIEW INTEGRITY

What WIP.56 verifies—and what remains open

Verified or explicitly recorded

  • 12 exact owner report records across 13 source instances, 12 unique hashes, and 1 exact duplicate lineage instance.
  • 22 source records with issuer, type, scope, source relationship, currentness, supported finding, unsupported stronger inference, and correction/reopening triggers.
  • 13 claim-specific reviews and 7 repository-authored predictive deployment records.
  • The owner continuation directive is preserved exactly and packaged in a deterministic one-entry source archive.

Not certified or completed

  • Every citation and conclusion within each owner-supplied report.
  • Named legal, clinical, scientific, intelligence, affected-community, privacy, accessibility, or reproduction-rights specialist review.
  • Human screen-reader, magnification, reflow, voice-control, cognitive-load, language-access, or representative-user testing.
  • Hosting approval, publication approval, production authorization, or permission to conduct psychological operations.

Correction standard: identify the stable report, claim, deployment, or source ID; specify the disputed wording; provide the strongest available primary or authoritative record; and state whether the correction changes source identity, currentness, interpretation, attribution, effect, remedy, or rights analysis.

Page complete AI PSYOPS Field Realism Page label: REAL-WORLD INTERPRETIVE