Educational companion dossier · Fact, interpretation, lived experience, clinical education, fiction, and mechanics are labeled separately. Scope & safety

AI PSYOPS TAXONOMY · CATEGORY 05

Synthetic Persona Operations

Fabricated identities are presented as real people, experts, witnesses, organizations, or community members to gain trust, infiltrate groups, or manufacture consensus.

Primary level: Operator Documented components · emerging autonomy Claim AIP-05-A01

CURRENT EVIDENCE ASSESSMENT

Synthetic identity assets and human-operated persona networks are documented; autonomous long-term persona operation is still emerging.

Stable claim identifierAIP-05-A01
Claim stageassessment
Currentness reviewed2026-07-27T20:15:00Z

DEPLOYMENT

Documented components

AI-generated faces, presenters, biographies, and text appear in reported deceptive networks.

AUTONOMY

Mostly human-managed

Current evidence more strongly supports AI-assisted asset creation than independent persona strategy.

PERSISTENCE

Variable

Personas can persist when operators maintain them; purely autonomous continuity remains fragile.

PROFILING ACCURACY

Not required for identity fabrication

Trust may be built through context and social cues without accurate psychological profiling.

MEASURED EFFECT

Infiltration and access sometimes documented; persuasion rarely isolated

Account presence and interaction do not establish belief or behavior change.

Assessment basis

Assessment combines the exact owner-supplied category report with the bounded primary, official, platform, and peer-reviewed sources listed for this category. Dimensions are evaluated separately to prevent documented output from being mistaken for autonomy or effect. WIP.51 adds independent investigative closure for the Oliver Taylor persona and generated-image assessment while preserving unresolved operator attribution.

What would change this assessment

Upgrade autonomy only with verifiable, long-duration persona operation, coherent identity history, and minimal human maintenance.

Prohibited inference

Do not infer strategic effect, universal deployment, or individual psychological state from this assessment.

A · DEFINITION

What this category means sources

Definition

A synthetic persona operation uses a substantially fictional identity that is presented as a real person, organization, expert, witness, activist, journalist, or community member. AI can generate faces, biographies, localized language, audio, and routine background activity.

Outside this category

Pseudonyms used by real people, disclosed bots, satire, role-play, and transparently synthetic virtual influencers are not the same. The defining feature is deception about the entity’s real-world identity or existence for an influence or access objective.

B · SIGNIFICANCE

Why it matters sources

Online trust normally begins with a default assumption of sincerity. Synthetic identities exploit that assumption at scale, but aggressive automated detection can also harm non-native speakers, neurodivergent users, activists, and people who rely on anonymity for safety.

C · CHANGE FROM PRE-AI PRACTICE

How AI changes the phenomenon sources

AI can produce unique faces that defeat reverse-image search, generate mundane posting histories, adapt language to local communities, and maintain many identities. Physical-world history, verifiable relationships, and long live interaction remain harder to fabricate consistently.

D · CAPABILITY STATUS

Separate evidence from projection sources

DOCUMENTED

Confirmed real-world use

Documented political, corporate, and criminal cases include AI-generated faces, synthetic identities, and AI-supported multilingual persona activity.

DEMONSTRATED

Demonstrated technical capability

Models can generate coherent biographies, images, voice, and routine content at scale.

EMERGING

Plausible near-term development

More persistent cross-platform personas and live multimodal interaction are plausible as memory and synthetic media improve.

UNCERTAIN

Unsupported or unproven

Fully autonomous personas that maintain flawless, verifiable life histories and relationships over long periods are not established.

E · KEY MECHANISMS

Conceptual mechanisms — not an operating procedure sources

Safety transformation: these descriptions identify system functions at a high level. Procedural steps, target criteria, scripts, evasion methods, and deployment workflows are intentionally excluded.

  1. Synthetic face, voice, biography, credential, and document assets.
  2. Language generation that mimics community norms and local idiom.
  3. Routine background posting used to create apparent history.
  4. Cross-platform identity reuse or coordinated clusters of fictional identities.
  5. Trust formation through apparent expertise, similarity, support, or shared group membership.

F · EVIDENCE & EXAMPLES

What is known, measured, and still unknown sources

REACH IS NOT EFFECT. Publication, impressions, engagement, virality, or media attention do not by themselves establish persuasion or behavioral change.

Example 1 · Claim AIP-05-E01

“Oliver Taylor” synthetic-persona reporting

Identity fabrication widely reported; AI generation and operator attribution not independently closed here

What occurred
A digital persona presented as a real individual published commentary and used a profile image assessed by outside analysts as likely synthetic.
What is confirmed
The persona’s real-world identity could not be substantiated in the reporting reviewed by the owner-supplied report.
Effect measured
The persona obtained publication and attention, demonstrating an access and credibility problem rather than measured persuasion.
What remains unknown
This review does not independently establish the generating model, operator, sponsor, audience belief, or behavioral effect.
Source scope
No independently verified public source was added for this example in WIP.50; it remains a bounded lead from the exact owner-supplied report.
Correction trigger
Revise when a primary record, authoritative correction, adjudication, retraction, or stronger causal study changes the bounded statement.
Inspect the 20-stage evidence boundary
Artifact Or Event Existence
PUBLIC_PERSONA_AND_PUBLICATIONS_DOCUMENTED
Content Status
PROFILE_IMAGE_ASSESSED_AS_GENERATED_IDENTITY_NOT_SUBSTANTIATED
Coordination
NOT_RETRIEVED
Actor Identity
NOT_RETRIEVED
Sponsorship Or Direction
NOT_RETRIEVED
Intent
PARTIAL_CONTEXT_ONLY
Output
ARTICLES_AND_PROFILE_DOCUMENTED
Distribution
PUBLICATION_DOCUMENTED
Availability
DOCUMENTED
Reach
NOT_RETRIEVED
Exposure
NOT_RETRIEVED
Attention
PARTIAL_JOURNALISTIC_ATTENTION
Recall
NOT_ESTABLISHED_UNLESS_EXPLICITLY_MEASURED
Comprehension
NOT_ESTABLISHED_UNLESS_EXPLICITLY_MEASURED
Credibility
NOT_ESTABLISHED_UNLESS_EXPLICITLY_MEASURED
Belief Or Attitude
NOT_ESTABLISHED
Intention
NOT_ESTABLISHED
Behavior
NOT_ESTABLISHED
Operational Outcome
TARGETED_REPUTATIONAL_ATTACK_CONTEXT_REPORTED
Strategic Effect
NOT_ESTABLISHED

Competing explanations: The missing identity record and generated image support a fabricated persona assessment, but they do not identify whether one operator, a coordinated network, a private actor, or a state-linked actor was responsible.

Affected-person/community evidence: Reuters included the targeted activists’ account and publisher/university verification efforts; broader affected-community reception was not measured.

Rights and privacy: Identity integrity, lawful anonymity, due process, privacy, and false-positive risks require protection.

Reopening trigger: Reopen this claim when a primary, official, adjudicative, peer-reviewed, affected-person, or affected-community source materially changes identity, attribution, autonomy, distribution, effect, rights, or currentness.

Linked sources: No independently closed public source in WIP.51; see the source-scope statement above.
Example 2 · Claim AIP-05-E02

Doppelganger / Social Design Agency

AI involvement confirmed in broader operation

What occurred
A state-aligned network paired cloned media properties with synthetic accounts and multilingual generated content.
What is confirmed
AI-generated content and coordinated inauthentic identities are documented.
Effect measured
The network achieved large-scale distribution and persistence.
What remains unknown
The independent effect of each persona on belief or behavior is unknown.
Source scope
The linked sources support the bounded statements shown here; they do not automatically establish intent, reach, persuasion, behavior, or strategic effect.
Correction trigger
Revise when a primary record, authoritative correction, adjudication, retraction, or stronger causal study changes the bounded statement.
Inspect the 20-stage evidence boundary
Artifact Or Event Existence
SUPPORTED_BY_LINKED_SOURCE
Content Status
BOUNDED_DESCRIPTION_SUPPORTED
Coordination
SOURCE_DEPENDENT_OR_UNRESOLVED
Actor Identity
SOURCE_DEPENDENT_OR_UNRESOLVED
Sponsorship Or Direction
SOURCE_DEPENDENT_OR_UNRESOLVED
Intent
SOURCE_DEPENDENT_OR_UNRESOLVED
Output
DOCUMENTED_OR_DESCRIBED_IN_LINKED_SOURCE
Distribution
PARTIAL_OR_SOURCE_DEPENDENT
Availability
PARTIAL_OR_SOURCE_DEPENDENT
Reach
NOT_ESTABLISHED_UNLESS_EXPLICITLY_MEASURED
Exposure
NOT_ESTABLISHED_UNLESS_EXPLICITLY_MEASURED
Attention
NOT_ESTABLISHED_UNLESS_EXPLICITLY_MEASURED
Recall
NOT_ESTABLISHED_UNLESS_EXPLICITLY_MEASURED
Comprehension
NOT_ESTABLISHED_UNLESS_EXPLICITLY_MEASURED
Credibility
NOT_ESTABLISHED_UNLESS_EXPLICITLY_MEASURED
Belief Or Attitude
NOT_ESTABLISHED_UNLESS_EXPLICITLY_MEASURED
Intention
NOT_ESTABLISHED_UNLESS_EXPLICITLY_MEASURED
Behavior
NOT_ESTABLISHED_UNLESS_EXPLICITLY_MEASURED
Operational Outcome
NOT_ESTABLISHED_UNLESS_EXPLICITLY_MEASURED
Strategic Effect
NOT_ESTABLISHED_UNLESS_EXPLICITLY_MEASURED

Competing explanations: The observed artifact or action may have depended on human direction, pre-existing networks, platform incentives, ordinary automation, non-AI methods, or unrelated contextual factors.

Affected-person/community evidence: Direct affected-person or affected-community evidence was not independently retrieved for this bounded claim unless explicitly stated in the linked source scope.

Rights and privacy: Identity integrity, lawful anonymity, due process, privacy, and false-positive risks require protection.

Reopening trigger: Reopen this claim when a primary, official, adjudicative, peer-reviewed, affected-person, or affected-community source materially changes identity, attribution, autonomy, distribution, effect, rights, or currentness.

Linked sources: SRC-04-GERMAN-FO-DOPPELGANGER SRC-06-RECORDED-FUTURE-COPYCOP Recorded Future / Insikt Group
Example 3 · Claim AIP-05-E03

DPRK IT-worker fraud and Spamouflage

AI-supported identity deception confirmed in cited cases

What occurred
Synthetic or stolen identities augmented with AI were used in remote hiring and cross-platform influence activity.
What is confirmed
AI-generated profile assets and other synthetic identity methods were documented.
Effect measured
Some operations gained institutional access or rebuilt persona networks after disruption.
What remains unknown
The prevalence of each technique and the role of autonomous operation remain uncertain.
Source scope
The linked sources support the bounded statements shown here; they do not automatically establish intent, reach, persuasion, behavior, or strategic effect.
Correction trigger
Revise when a primary record, authoritative correction, adjudication, retraction, or stronger causal study changes the bounded statement.
Inspect the 20-stage evidence boundary
Artifact Or Event Existence
SUPPORTED_BY_LINKED_SOURCE
Content Status
BOUNDED_DESCRIPTION_SUPPORTED
Coordination
SOURCE_DEPENDENT_OR_UNRESOLVED
Actor Identity
SOURCE_DEPENDENT_OR_UNRESOLVED
Sponsorship Or Direction
SOURCE_DEPENDENT_OR_UNRESOLVED
Intent
SOURCE_DEPENDENT_OR_UNRESOLVED
Output
DOCUMENTED_OR_DESCRIBED_IN_LINKED_SOURCE
Distribution
PARTIAL_OR_SOURCE_DEPENDENT
Availability
PARTIAL_OR_SOURCE_DEPENDENT
Reach
NOT_ESTABLISHED_UNLESS_EXPLICITLY_MEASURED
Exposure
NOT_ESTABLISHED_UNLESS_EXPLICITLY_MEASURED
Attention
NOT_ESTABLISHED_UNLESS_EXPLICITLY_MEASURED
Recall
NOT_ESTABLISHED_UNLESS_EXPLICITLY_MEASURED
Comprehension
NOT_ESTABLISHED_UNLESS_EXPLICITLY_MEASURED
Credibility
NOT_ESTABLISHED_UNLESS_EXPLICITLY_MEASURED
Belief Or Attitude
NOT_ESTABLISHED_UNLESS_EXPLICITLY_MEASURED
Intention
NOT_ESTABLISHED_UNLESS_EXPLICITLY_MEASURED
Behavior
NOT_ESTABLISHED_UNLESS_EXPLICITLY_MEASURED
Operational Outcome
NOT_ESTABLISHED_UNLESS_EXPLICITLY_MEASURED
Strategic Effect
NOT_ESTABLISHED_UNLESS_EXPLICITLY_MEASURED

Competing explanations: The observed artifact or action may have depended on human direction, pre-existing networks, platform incentives, ordinary automation, non-AI methods, or unrelated contextual factors.

Affected-person/community evidence: Direct affected-person or affected-community evidence was not independently retrieved for this bounded claim unless explicitly stated in the linked source scope.

Rights and privacy: Identity integrity, lawful anonymity, due process, privacy, and false-positive risks require protection.

Reopening trigger: Reopen this claim when a primary, official, adjudicative, peer-reviewed, affected-person, or affected-community source materially changes identity, attribution, autonomy, distribution, effect, rights, or currentness.

G · RISKS & FAILURE MODES

Potential harms and reasons the capability may fail sources

Risks

  • Fabricated expertise or lived experience can distort community decisions.
  • Synthetic identities can support fraud, access, harassment, or false consensus.
  • Detection systems can produce discriminatory false positives.
  • Pressure for universal identity verification can endanger whistleblowers and vulnerable communities.
  • Persona networks can reconstitute quickly after takedown.

Limitations and failure modes

  • Long-term consistency across biography, relationships, time, and physical evidence remains difficult.
  • Synthetic media artifacts are becoming less reliable as a single detection method.
  • Humans legitimately use writing assistance, scheduling tools, filters, and anonymity.
  • An unusual identity claim is not proof of malicious coordination.

H · DETECTION & DEFENSIVE INDICATORS

Signals for investigation, not automatic verdicts sources

Indicator rule: unless the source report supports a stronger conclusion, each signal below is suggestive rather than conclusive. Multiple independent signals and contextual evidence are required.

  • Conflicting biographical claims, sudden topic or language shifts, and graph-seeding anomalies may be suggestive.
  • Cross-platform reuse of obscure identity assets can support investigation but may also reflect identity theft.
  • Machine-speed interaction patterns are stronger when combined with infrastructure and network evidence.
  • AI-text detectors should not be treated as conclusive identity evidence.

I · GOVERNANCE & SAFEGUARDS

Accountability, transparency, and human protection sources

Use risk-based, privacy-preserving authentication for high-impact roles rather than universal real-name rules.

Combine account history, network behavior, provenance, and human investigation.

Create appeal and correction pathways for people falsely classified as synthetic.

Disclose bots and virtual representatives clearly while protecting legitimate pseudonymity.

Harden remote hiring and credential verification against synthetic media without collecting unnecessary biometric data.

J · RESEARCH GAPS

Questions the evidence does not yet close sources

  • Reliable detection without demographic bias or loss of lawful anonymity.
  • Longitudinal evidence on persona persistence and community influence.
  • Cross-platform coordination data that can be shared responsibly with researchers.
  • Recovery of interpersonal and institutional trust after a synthetic identity is exposed.

K · SPECIALIST REVIEW PACKET

Prepared for independent review; no disposition recorded

PacketAIP-05-SPECIALIST-REVIEW-PACKET
DispositionPENDING
Completed dispositions0
Prepared2026-07-27T20:15:00Z

Requested reviewer domains

  • digital identity and forensics
  • platform integrity
  • privacy and civil liberties
  • information operations

Questions for reviewers

  1. Does the Oliver Taylor closure support a generated persona without overclaiming operator attribution?
  2. Are lawful pseudonymity and anonymous dissent protected from overbroad detection?
  3. Are false-positive and disparate-impact risks adequately described?

Unresolved questions

  • Reliable detection without demographic bias or loss of lawful anonymity.
  • Longitudinal evidence on persona persistence and community influence.
  • Cross-platform coordination data that can be shared responsibly with researchers.
  • Recovery of interpersonal and institutional trust after a synthetic identity is exposed.

Correction and reopening

Correction trigger: Upgrade autonomy only with verifiable, long-duration persona operation, coherent identity history, and minimal human maintenance.

Reopening trigger: Reopen this claim when a primary, official, adjudicative, peer-reviewed, affected-person, or affected-community source materially changes identity, attribution, autonomy, distribution, effect, rights, or currentness.

Prepared packet is not completed specialist review, factual certification, legal advice, clinical review, accessibility certification, publication approval, or production authority.

REAL-WORLD INTERPRETIVE

M · SOURCES & REVIEW STATUS

Exact owner report, claim register, and reviewed sources

  1. Synthetic Persona Operations Owner-supplied report: AI Synthetic Persona Operations Report.md · 54,193 bytes · SHA-256 110e635da77e17d873c53c061cd7ef9345314a06bb70950a5dbdb164451cebe2

    Owner-supplied interdisciplinary research synthesis; exact source preserved in protected durable memory. External specialist review remains pending.

Claim-specific reviewed sources

  1. OpenAI · 2024-05-30 · Authoritative first-party platform disclosure

    Supports
    Documents five disrupted covert influence operations using OpenAI services and reports no meaningful increase in audience engagement or reach attributable to those services as of the publication date.
    Does not establish
    Does not measure all exposure, belief change, behavior, or strategic effect; platform visibility is necessarily partial.
    Review
    LOCATED_AND_REVIEWED_AT_CITATION_LEVEL · Currentness checked for the bounded claim scope on 2026-07-27.
  2. OpenAI · 2024-10-09 · Authoritative first-party platform disclosure

    Supports
    Documents additional disrupted operations and the supporting tasks for which models were used.
    Does not establish
    Does not establish that model use independently caused campaign reach, persuasion, or behavioral outcomes.
    Review
    LOCATED_AND_REVIEWED_AT_CITATION_LEVEL · Currentness checked for the bounded claim scope on 2026-07-27.
  3. Recorded Future / Insikt Group · 2024-05-09 · Independent specialist analysis

    Supports
    Documents an inauthentic media network using large language models to modify and publish political content at scale.
    Does not establish
    Attribution and infrastructure findings are analytical assessments; social amplification and persuasive effect were limited or not established.
    Review
    LOCATED_AND_REVIEWED_AT_CITATION_LEVEL · Currentness checked for the bounded claim scope on 2026-07-27.
  4. SRC-07-GRAPHIKA-WOLF-NEWSDeepfake It Till You Make It

    Graphika · 2023-02-07 · Independent specialist analysis

    Supports
    Documents limited use of AI-generated fictitious news presenters in content promoted by a pro-China influence operation.
    Does not establish
    Does not establish substantial reach or persuasive effect and should not be generalized to all synthetic presenter use.
    Review
    LOCATED_AND_REVIEWED_AT_CITATION_LEVEL · Currentness checked for the bounded claim scope on 2026-07-27.
  5. Meta · 2023-08-29 · Authoritative first-party platform disclosure

    Supports
    Documents the removal and analysis of coordinated inauthentic behavior, including use of GAN-generated profile imagery and the Spamouflage network.
    Does not establish
    Platform findings do not establish complete cross-platform activity, target exposure, or behavioral effect.
    Review
    LOCATED_AND_REVIEWED_AT_CITATION_LEVEL · Currentness checked for the bounded claim scope on 2026-07-27.
  6. U.S. Department of Justice · 2025-06-30 · Official public authority

    Supports
    Documents schemes using stolen or false identities, remote-work infrastructure, and deceptive employment practices.
    Does not establish
    Does not establish that every identity asset was AI-generated or that these schemes were influence operations rather than fraud and access operations.
    Review
    LOCATED_AND_REVIEWED_AT_CITATION_LEVEL · Currentness checked for the bounded claim scope on 2026-07-27.
  7. Reuters · 2020-07-15 · Independent professional journalism

    Supports
    Documents the public Oliver Taylor persona and publications, the University of Birmingham statement that it had no record of him, failed publisher verification, a limited online footprint, and expert assessments that the profile image was generated.
    Does not establish
    Does not identify the operator, sponsor, direction, legal identity, full publication history, intended audience, unique reach, exposure, persuasion, or strategic effect.
    Review
    LOCATED_AND_REVIEWED_AT_CITATION_LEVEL · Citation and source-scope review completed for WIP.51 on 2026-07-27.
Selected works identified by the owner-supplied report
  • Levine, Truth-Default Theory and the Psychology of Lying and Deception Detection.
  • Liang et al., GPT Detectors Are Biased Against Non-Native English Writers.
  • Recorded Future, Synthetic Identities: The Dual Threat to Enterprises.
  • Pamment and Tsurtsumia, Beyond Operation Doppelgänger.

Exact source preservation and editorial currentness review do not constitute specialist certification, adjudication, legal advice, clinical review, or proof that every owner-report citation is current. Corrections remain open.

Page complete Synthetic Persona Operations Page label: CONTEMPORARY / ONGOING CLAIM — NOT SETTLED HISTORY