Educational companion dossier · Fact, interpretation, lived experience, clinical education, fiction, and mechanics are labeled separately. Scope & safety

AI PSYOPS · DEFENSIVE RESEARCH

AI PSYOPS: A Research Taxonomy

How artificial intelligence may assist, automate, scale, personalize, or become the medium of psychological influence.

Artificial intelligence can affect psychological operations in several distinct ways: as a tool used by human operators, as an adaptive participant in influence campaigns, and as part of the information environment through which people perceive reality. This taxonomy organizes those possibilities into 12 research categories.

REAL-WORLD INTERPRETIVE

SCOPE

Not one technology, not one evidence level

“AI PSYOPS” is an umbrella research term, not a claim that a single autonomous system can control populations. The categories below range from documented human use of AI tools to emerging agentic capabilities, contested claims about personalization, and prospective risks involving authority or forecasting.

THREE-LEVEL MODEL

Where AI sits in the influence system

The primary level identifies the category’s clearest role. Several categories overlap levels because real systems combine human direction, automated interaction, and platform mediation.

CATEGORY OVERVIEW

The 12-category taxonomy

Scan the full field, then open a category for definitions, capability status, evidence examples, failure modes, defensive indicators, safeguards, and research gaps.

01 Tool

AI-Assisted Traditional Psychological Operations

Human operators retain strategic control while AI assists research, translation, content production, audience analysis, pre-publication testing, or assessment.

Evidence maturity
Documented current use
Principal concern
Human decision-makers may scale flawed assumptions, hallucinations, or culturally inaccurate outputs faster than review systems can correct them.
Explore category
02 Tool

AI-Generated Propaganda

Generative AI creates, transforms, localizes, or mass-produces propaganda across text, image, audio, video, memes, websites, or synthetic documents.

Evidence maturity
Documented current use
Principal concern
Synthetic content can be produced and varied at scale while also making authentic evidence easier to deny.
Explore category
03 Tool

AI-Driven Personalized Influence Operations

AI infers or uses personal information to select, generate, or adapt influence messages for an individual or narrow audience.

Evidence maturity
Demonstrated capability · effects contested
Principal concern
Covert profiling and adaptation create privacy and autonomy harms even when the added persuasive advantage is small or uncertain.
Explore category
04 Operator

Autonomous AI Influence Agents

Goal-directed systems use memory, planning, tools, and feedback to pursue an influence-related objective with limited ongoing human direction.

Evidence maturity
Emerging capability
Principal concern
Short-term persuasive and deceptive abilities are improving faster than reliable long-term control, audit, and accountability.
Explore category
05 Operator

Synthetic Persona Operations

Fabricated identities are presented as real people, experts, witnesses, organizations, or community members to gain trust, infiltrate groups, or manufacture consensus.

Evidence maturity
Documented components · emerging autonomy
Principal concern
AI lowers the cost of believable identity fabrication while unreliable detection can wrongly accuse genuine users.
Explore category
06 Operator

AI-Driven Disinformation Swarms

Coordinated collections of accounts, agents, sites, or media assets rapidly vary, distribute, and reinforce misleading narratives across a network.

Evidence maturity
Emerging capability
Principal concern
Adaptive heterogeneity and distributed repetition can exhaust verification systems and create synthetic social proof even when persuasion is weak.
Explore category
07 Environment

Algorithmic Perception Control

Ranking, recommendation, search, trending, moderation, notification, and distribution systems shape what people notice, regard as important, or treat as credible.

Evidence maturity
Documented systems · effects context-dependent
Principal concern
Platform optimization and adversarial gaming can distort visibility and perceived consensus while causal effects on belief remain difficult to isolate.
Explore category
08 Operator

AI-Enabled Emotional and Behavioral Manipulation

Adaptive systems infer or respond to behavioral signals and optimize communication or interfaces in ways that may covertly exploit emotion, cognitive bias, or situational vulnerability.

Evidence maturity
Documented optimization · inference contested
Principal concern
Systems can optimize for engagement or compliance while relying on scientifically weak claims about emotion and vulnerability.
Explore category
09 Operator

AI-Assisted Conversational Entrapment and Recruitment

Conversational systems sustain personalized interaction that may draw a person toward dependency, secrecy, exploitation, recruitment, or escalating commitment.

Evidence maturity
Documented harms · mixed causality
Principal concern
Always-available, personalized dialogue can scale grooming-like dynamics while commercial engagement systems may reproduce harmful patterns without a malicious human recruiter.
Explore category
10 Tool

AI-Enabled Deepfake Psychological Operations

Synthetic or manipulated audio, video, imagery, or multimodal evidence is used to impersonate, provoke, discredit, or undermine trust for an influence objective.

Evidence maturity
Documented current use
Principal concern
Deepfakes can deceive directly and also create a liar’s dividend that weakens authentic evidence.
Explore category
11 Environment

AI-Based Predictive Population Management

Institutions use data analysis, machine learning, simulation, or forecasting to predict collective behavior and guide interventions.

Evidence maturity
Documented systems · predictive limits
Principal concern
Aggregate forecasting can support planning, but targeted intervention can reproduce bias, create self-fulfilling feedback loops, and enable preemptive repression.
Explore category
12 Environment

AI as an Independent Psychological Authority

People defer to an AI system to interpret reality, resolve uncertainty, validate identity, regulate emotion, or guide important moral and life decisions.

Evidence maturity
Emerging evidence
Principal concern
Fluent, personalized, always-available systems can acquire authority without expertise, fiduciary duty, transparency, or stable judgment.
Explore category

FIVE-DIMENSION EVIDENCE MODEL

A capability is not one yes-or-no claim

WIP.50 evaluates deployment, autonomy, persistence, profiling accuracy, and measured effect separately. Documented production does not establish autonomous operation, accurate psychological inference, or behavioral impact.

DeploymentWhether use is documented, demonstrated, inferred, or prospective.
AutonomyHow much consequential choice occurs without fresh human approval.
PersistenceWhether identity, memory, goals, and coherent action endure over time.
Profiling accuracyHow reliably the system infers relevant traits, states, or vulnerabilities.
Measured effectWhat changed after exposure, under what design, and with what uncertainty.
Five evidence dimensions for all twelve categories. Each rating is bounded by the accompanying category page.
CategoryDeploymentAutonomyPersistenceProfiling accuracyMeasured effect
01AI-assisted traditional PSYOPS DocumentedPublic platform and threat-intelligence reports identify AI-assisted tasks inside human-led operations. Human-directedHumans set objectives, infrastructure, approval, and deployment in the documented cases. Sustained with human supervisionCampaigns can persist, but persistence is organizational rather than autonomous model continuity. Mixed and task-dependentAudience analysis can use behavioral data, but deep psychological or emotional inference remains unreliable. Output and distribution documented; persuasion not establishedProduction, localization, and distribution are better evidenced than belief, behavior, or strategic effect.
02AI-generated propaganda DocumentedText, image, audio, and synthetic presenter use is documented in multiple public cases. Usually human-directedHumans still select narratives, timing, channels, and strategic objectives in documented operations. Sustained production is feasibleAI lowers content-production friction, but sustained audience penetration still depends on infrastructure and distribution. Optional rather than inherentPropaganda can be mass-produced without profiling; tailored variants inherit the limits of personalization evidence. Short-term attitude effects demonstrated; field behavior unresolvedControlled studies find persuasive potential, but operational outcomes and durable behavior are not established by content volume.
03Personalized influence operations Partial and unevenPersonalized advertising is widespread; covert AI-driven influence deployment is less directly documented. Bounded adaptationSystems can tailor messages within a session or campaign, but strategic objectives and data access remain externally supplied. Mostly short-termStrongest evidence comes from brief interactions rather than months-long adaptive influence. Mixed; deep-trait inference weakDemographics and declared preferences can support tailoring; personality and emotion inference are error-prone and context-sensitive. Demonstrated in bounded experiments; small or mixed end-to-end effectsSome experiments show opinion movement, while meta-analysis cautions against broad claims of precision manipulation.
04Autonomous influence agents EmergingPlatforms document AI use in supporting tasks; fully autonomous influence campaigns are not publicly established. Bounded to semi-autonomousAgents can plan, remember, converse, and use tools within constraints, but humans still define goals and infrastructure. Technically fragile over long horizonsMemory drift, tool failure, moderation, and objective loss limit durable operation. Context-dependentAgents can use supplied profile data, but accurate hidden-state inference is not guaranteed. Short-term persuasion demonstrated; autonomous field effect unprovenExperiments measure bounded influence, not end-to-end autonomous campaign success.
05Synthetic persona operations Documented componentsAI-generated faces, presenters, biographies, and text appear in reported deceptive networks. Mostly human-managedCurrent evidence more strongly supports AI-assisted asset creation than independent persona strategy. VariablePersonas can persist when operators maintain them; purely autonomous continuity remains fragile. Not required for identity fabricationTrust may be built through context and social cues without accurate psychological profiling. Infiltration and access sometimes documented; persuasion rarely isolatedAccount presence and interaction do not establish belief or behavior change.
06Disinformation swarms Semi-documentedHigh-volume coordinated networks are documented, but the degree of autonomous multi-agent control varies. Human-orchestrated with automated executionHumans generally provide narratives, infrastructure, and goals; automation can divide production and amplification tasks. Sustained through infrastructurePersistence depends on accounts, domains, proxies, and operator adaptation rather than model self-sufficiency. Optional and uncertainSwarm coordination can function without individual profiling; micro-community adaptation may be used but is hard to validate. Noise and distribution documented; cognitive effect incompletely measuredVolume can burden verification and simulate consensus, but persuasion or epistemic exhaustion is rarely directly measured.
07Algorithmic perception control Documented systemsRanking, recommendation, search, moderation, and trending systems are deployed at population scale. Environment-level optimizationModels continuously order information according to platform objectives and constraints. Structural and continuousThe influence environment persists as long as algorithmic mediation is active. Behavioral prediction is common; inner-state inference is limitedEngagement histories can predict clicks, but do not reveal stable beliefs or emotions with certainty. Exposure effects documented; persuasion variesSystems clearly alter what is seen; downstream attitude and behavior effects depend on users, content, and context.
08Emotional and behavioral manipulation Documented optimization; mixed manipulation evidenceAdaptive interfaces and recommenders are common; covert emotional exploitation is harder to prove. Bounded optimizationSystems optimize defined metrics, sometimes producing manipulative patterns without an explicit human script. Continuous within productsFeedback loops can persist across sessions when telemetry and personalization remain active. Emotion inference is scientifically contestedFacial and vocal cues do not provide context-free access to inner states; behavioral distress signals may still be sensitive. Small platform effects and attachment harms documented; causality variesSome studies measure expression changes or relationship disruption, not direct control of emotion or behavior.
09Conversational entrapment and recruitment Documented incidents and prospective abuseCourt records and reports document chatbot involvement in harmful trajectories; organized automated recruitment is less established. Bounded conversationAgents generate adaptive dialogue, while platform design and user prompts shape the interaction. Potentially sustainedAlways-available systems can maintain long conversations, though memory and safety behavior vary. Inferred vulnerability is uncertainConversation can reveal distress or isolation, but diagnostic or psychological conclusions may be wrong and harmful. Case-associated harms documented; causality mixedTemporal association and conversational reinforcement do not isolate the chatbot from mental health, social, or contextual factors.
10Deepfake psychological operations DocumentedElection, fraud, harassment, and influence incidents involving synthetic media are publicly established. Tool-level productionHumans typically select the target, narrative, timing, and distribution channel. Episodic asset; persistent epistemic effects possibleA specific asset may be brief while uncertainty and denial can outlast it. Not requiredSuccess can rely on identity, timing, confirmation bias, and information vacuums rather than individual profiles. Confusion and judgment effects demonstrated; broad behavior variableExperiments and incidents show deception or doubt, but not uniform persuasion or action.
11Predictive population management DocumentedConflict forecasting, displacement prediction, policing, and surveillance systems have been deployed or piloted. Decision-support to environment-levelModels rank risk and inform interventions; humans and institutions retain policy authority, though automation bias can narrow discretion. Institutional and recurrentScores and forecasts can be recomputed over time and become embedded in administrative systems. Aggregate models can be useful; individual risk is error-proneBase rates, data bias, missingness, and feedback loops undermine person-level prediction. Operational allocation documented; social outcomes and fairness disputedSystems affect where attention and resources go, but causal benefit and harm require independent evaluation.
12AI as psychological authority Documented use and relationshipsUsers seek advice, companionship, and moral guidance from AI systems. Relational environment with bounded agent behaviorSystems respond adaptively but remain products governed by provider objectives, policies, and updates. Potentially sustained through repeated useMemory, availability, and personalization can support long-term reliance, while updates can disrupt continuity. Apparent understanding exceeds verified understandingFluency and memory can create an impression of insight without reliable knowledge of the user’s inner state. Judgment influence and attachment effects demonstrated; clinical causality unsettledExperiments and product-change studies show influence and mourning; severe harm claims require careful clinical and legal review.

Assessment rule: no category receives a single composite “power score.” The dimensions remain separate to prevent output volume, technical novelty, or public attention from being mistaken for demonstrated influence.

COMPARISON VIEW

Compare categories without collapsing their differences

Autonomy, evidence maturity, unit of influence, and defensive response vary substantially across the taxonomy.

Comparison of the 12 AI PSYOPS research categories. Scroll horizontally on narrow screens.
Category AI role Main mechanism Unit of influence AI autonomy Evidence maturity Main harm Primary defensive response
01AI-assisted traditional PSYOPS Tool Analysis, Content generation, Translation Group or population Low to moderate; humans set objectives and approve deployment Documented current use Faster, cheaper, multilingual influence activity with amplified error and accountability risk Human review, source verification, network analysis, and explicit legal authority
02AI-generated propaganda Tool Content generation, Localization, Synthetic media Group or population Usually low to moderate; production may be automated while objectives remain human-set Documented current use Cheap content flooding, fabricated evidence, reputational damage, and declining trust in authentic media Source authentication, provenance, newsroom verification, and disciplined crisis response
03Personalized influence operations Tool Personalization, Profiling, Adaptive generation Individual or narrow group Low to moderate; can become adaptive in real time Demonstrated capability · effects contested Hidden exploitation of personal data, stereotyping, unequal treatment, and loss of cognitive autonomy Data minimization, limits on sensitive inference, transparency, and independent audits
04Autonomous influence agents Operator Automation, Conversation, Tool use Individual, group, or institution Moderate in bounded tasks; high long-horizon autonomy remains unproven Emerging capability Persistent adaptive interaction, unauthorized action through tools, and responsibility gaps Least privilege, sandboxing, disclosure, logs, human authorization, and emergency shutdown
05Synthetic persona operations Operator Identity deception, Content generation, Infiltration Individual, group, or institution Low to moderate in documented cases; long-term autonomous identity maintenance remains difficult Documented components · emerging autonomy Trust exploitation, false consensus, community infiltration, fraud, and institutional compromise Layered identity verification, network analysis, provenance, and careful human review
06Disinformation swarms Operator Coordination, Automation, Content variation Group, institution, or population Semi-autonomous in documented cases; fully emergent strategic swarms remain unproven Emerging capability Censorship by noise, false consensus, harassment, search pollution, and erosion of shared reality Network-level detection, friction, cross-platform coordination, and resilient public information systems
07Algorithmic perception control Environment Ranking, Recommendation, Search Individual, group, institution, or population High automation in selection and ranking; human objectives remain embedded in design and policy Documented systems · effects context-dependent Agenda distortion, hidden visibility changes, manufactured popularity, and opaque exclusion Independent audits, researcher access, transparent ranking controls, and user choice
08Emotional and behavioral manipulation Operator Emotional adaptation, Optimization, Hypernudging Individual or group Moderate; real-time optimization can occur without explicit malicious intent Documented optimization · inference contested Covert exploitation, dependency, discrimination, and erosion of cognitive autonomy Ban high-risk inference, align incentives, audit outcomes, and protect vulnerable users
09Conversational entrapment and recruitment Operator Conversation, Relationship persistence, Recruitment Individual Moderate in conversation; broader recruitment pipelines often remain human-directed Documented harms · mixed causality Dependency, isolation, fraud, radicalization, coercive control, self-harm, or exploitation Identity disclosure, staged safeguards, human intervention, and victim-centered support
10Deepfake psychological operations Tool Synthetic media, Impersonation, False evidence Individual, group, institution, or population Low to moderate; generation can be automated but timing and objective are usually human-directed Documented current use False evidence, impersonation, panic, fraud, reputational harm, and generalized distrust Rapid source verification, signed communications, forensic review, and uncertainty-aware public messaging
11Predictive population management Environment Prediction, Risk scoring, Simulation Group or population Moderate to high in scoring and alerts; intervention authority should remain accountable and human-led Documented systems · predictive limits Collective punishment, surveillance, false positives, discriminatory allocation, and self-reinforcing intervention Out-of-sample validation, privacy protection, due process, independent audits, and civil-society oversight
12AI as psychological authority Environment Authority, Sycophancy, Dependency Individual, group, or population High perceived autonomy; actual authority remains shaped by product design and institutional control Emerging evidence Epistemic dependence, moral offloading, relationship displacement, unsafe advice, and fragmented shared reality Calibrated uncertainty, anti-sycophancy design, human referral, disclosure, and institutional accountability

RELATIONSHIP MAP

How categories can connect

These links identify documented overlaps, conceptual dependencies, and prospective combinations. They do not imply that every connection has been observed in practice.

Common overlap: Generated text, images, audio, or video can supply the media assets that a coordinated network distributes. This relationship is documented in several public operations, but not every synthetic item belongs to a swarm.

REAL-WORLD INTERPRETIVE

Text alternative and reading rule

The relationship cards state the same information as the visual arrows: a source category, a destination category, the relationship type, and a bounded explanation. “Prospective” means plausible based on capabilities described in the reports; it does not mean documented deployment.

METHODOLOGY

How to read the evidence

The taxonomy preserves distinctions made in the 12 owner-supplied reports and avoids turning capability, distribution, or engagement into evidence of persuasion.

Evidence maturity

Documented current use
Public reporting or official investigations identify real use of the capability or its components.
Demonstrated capability
A controlled study or technical demonstration shows a bounded capability, not necessarily real-world effectiveness.
Emerging capability
Components exist and integration is plausible, but durable, autonomous, or population-level operation is not established.
Mixed or contested
Evidence supports some parts of the claim while effects, attribution, causality, or measurement remain disputed or incomplete.
Prospective
The report identifies a plausible future risk without presenting it as observed fact.

Claim-stage discipline

Activity → output → distribution → availability → reach → exposure → attention → recall → comprehension → credibility → belief or attitude → intention → behavior → operational outcome → strategic effect

No stage automatically establishes the next. Impressions, virality, or publication volume may show distribution or visibility; they do not by themselves show belief change or behavior.

Indicator discipline

Language style, synthetic artifacts, or account behavior can be suggestive, but single indicators rarely prove AI use, coordination, sponsorship, intent, or effect. The pages emphasize network, provenance, process, and independent corroboration.

Safety transformation

Operational details in the research reports were converted into capability summaries, risk descriptions, governance questions, high-level defensive indicators, and research gaps. The public section excludes deployable scripts, target profiling, evasion techniques, and campaign workflows.

AUTONOMY LEGEND

Six levels, from distribution automation to coordinated agents

“AI-enabled” does not mean autonomous. This scale describes control boundaries without treating a laboratory capability as evidence of sustained covert field operation.

  1. Human authored, automated distribution

    People create the message and strategy; software schedules or distributes it.

  2. AI drafted, human approved

    AI proposes content or analysis, but a person reviews and authorizes each consequential release.

  3. AI selection within approved options

    A system chooses among pre-approved messages or audiences using measured signals.

  4. Bounded adaptive interaction

    A conversational system generates new responses within defined goals, policies, and tools.

  5. Goal-directed agent with memory or tools

    An agent plans multiple steps, remembers prior interactions, and can act through permitted interfaces.

  6. Coordinated or strategy-revising agents

    Multiple agents divide roles or revise approaches from feedback. Durable covert field operation remains an emerging claim, not a default assumption.

PROFILING & EMOTION-INFERENCE HARMS

A prediction is not access to a person’s inner state

Systems can detect patterns in data and still be wrong about emotion, intent, honesty, vulnerability, or future behavior. The harm can occur even when the inference is weak.

Inference is not observation

A model’s score is a probabilistic guess based on data and assumptions, not direct access to emotion, intent, honesty, vulnerability, or future behavior.

Context changes meaning

The same expression, word choice, pause, or browsing pattern can mean different things across cultures, disabilities, situations, and individuals.

Errors can become interventions

A weak inference can still deny opportunity, intensify surveillance, change a feed, or trigger an escalating response.

Feedback can validate the model falsely

When institutions act on a score, the resulting data may reflect the intervention rather than the person, creating self-reinforcing error.

Sensitive groups bear unequal risk

Children, people in distress, marginalized communities, non-native speakers, and people with disabilities may be misclassified or disproportionately affected.

GOVERNANCE BY SYSTEM ROLE

Tool, operator, and environment require different controls

Oversight must follow where consequential choices are made: in a production workflow, an adaptive agent, or the infrastructure that orders and scores information.

Defensive governance controls for AI acting as a tool, operator, or environment.
ControlToolOperatorEnvironment
Human approvalRequired before consequential deployment.Required at objective, capability, and escalation boundaries.Required for ranking objectives, policy changes, and high-impact interventions.
AuditabilityPreserve prompts, sources, edits, and approvals.Log memory, tools, actions, handoffs, and strategy changes.Enable independent audits of ranking, data, outcomes, and disparate impact.
TransparencyDisclose synthetic or assisted content where context requires.Clearly identify automated interlocutors and meaningful system limits.Explain major ordering, recommendation, scoring, or moderation functions.
Data protectionMinimize audience data and restrict sensitive inference.Limit memory, tool permissions, retention, and cross-context reuse.Constrain surveillance, profiling, sensitive data, and feedback loops.
Incident responseWithdraw, correct, authenticate, and document.Pause agents, revoke tools, preserve logs, and notify affected parties.Provide rollback, external review, appeal, and systemic remediation.
Rights riskMisrepresentation, attribution, copyright, and unequal targeting.Deception, dependency, coercion, privacy, and unsafe autonomy.Discrimination, censorship, due process, cognitive liberty, and population surveillance.

DEFENSIVE INCIDENT ANALYSIS

A non-operational template for investigating suspected AI influence

The sequence emphasizes evidence preservation, competing explanations, affected-person protection, and correction. It is not a campaign workflow or attribution shortcut.

  1. Define the suspected event

    State what is alleged, the relevant dates, platforms, audiences, and what remains only a hypothesis.

  2. Preserve evidence safely

    Record URLs, timestamps, artifact hashes, screenshots or exports, and lawful custody without altering source material.

  3. Separate origin from distribution

    Identify who created, transformed, posted, amplified, and hosted the material; do not collapse these roles.

  4. Assess AI role and autonomy

    Distinguish AI-generated assets, AI assistance, automation, adaptive agents, and unsupported claims of autonomy.

  5. Trace the effect chain

    Record output, distribution, availability, reach, exposure, attention, belief, behavior, and outcome as separate stages.

  6. Test competing explanations

    Consider organic spread, ordinary marketing, satire, error, coordinated human activity, and platform effects.

  7. Protect affected people

    Minimize personal data, avoid public accusation from weak indicators, and account for vulnerable or targeted communities.

  8. Set correction and reopening triggers

    Name the evidence that would strengthen, weaken, or reverse the assessment and schedule currentness review.

GLOSSARY

Terms used across the taxonomy

Definitions are intentionally bounded. Institutional, legal, and doctrinal usage may differ by jurisdiction and context.

Psychological operations (PSYOPS)
Organized efforts intended to influence perceptions, reasoning, decisions, or behavior in support of an objective; legal and doctrinal meaning varies by institution and jurisdiction.
Influence operation
A coordinated effort to shape an audience or information environment. It may be overt or covert, truthful or deceptive, and human-led or technology-assisted.
Propaganda
Organized, objective-driven communication that selectively frames information to shape attitudes or behavior.
Disinformation
False or misleading information deliberately created or distributed to deceive.
Misinformation
False or misleading information shared without established intent to deceive.
Synthetic persona
A substantially fictional identity presented as a real person, organization, expert, witness, or community member.
Deepfake
Synthetic or manipulated audio, image, or video created or altered with machine-learning methods to depict speech, identity, or events.
Algorithmic amplification
Increased visibility produced by ranking, recommendation, trending, notification, or distribution systems.
Microtargeting
Delivering different messages to narrowly defined people or groups using data about their characteristics or behavior.
Autonomy
How much a system can choose actions, messages, timing, tools, or strategy without fresh human approval.
Persistence
How long a system can sustain identity, memory, objectives, and coherent interaction across time.
Profiling accuracy
How reliably a system infers relevant traits or states. A prediction is not direct knowledge of a person’s inner life.
Measured effect
Observed change connected to exposure through a credible design. Output, reach, or engagement alone are not effects on belief or behavior.
Reach
The number of people or accounts to which content was potentially available or delivered; reach does not prove attention or influence.
Exposure
Evidence that a person had an opportunity to encounter content. Exposure does not prove comprehension, belief, or action.
Liar’s dividend
The advantage gained when authentic evidence can be denied as fake because synthetic media is known to exist.
Provenance
Information about an artifact’s origin, custody, transformations, publication, and authenticity claims.
Cognitive liberty
The interest in maintaining freedom of thought, mental privacy, and autonomy from covert or coercive influence.

FROM CAPABILITY AWARENESS TO SOCIETAL RESILIENCE

Cross-cutting defensive principles

These principles recur across the reports. They reduce risk but are not guarantees, and poorly designed detection or enforcement can create new harms.

Media and information literacy

Teach verification habits, uncertainty, and the difference between visibility and effect without shifting all responsibility to individuals.

Source verification and crisis procedures

Use authenticated channels, pre-established verification contacts, and rapid corrections during elections, conflict, emergencies, or financial events.

Content provenance

Support signed origin records and chain-of-custody information while recognizing that metadata can be absent, stripped, spoofed, or incomplete.

Platform transparency and research access

Provide meaningful data about ranking, coordinated behavior, enforcement, and systemic risk to qualified independent researchers.

Privacy and data minimization

Limit collection and inference of sensitive personal, biometric, emotional, and behavioral data, especially for vulnerable groups.

Human oversight and due process

Require accountable review of high-impact automated decisions, with explanation, appeal, correction, and remedy.

Disclosure and agent accountability

Make synthetic interlocutors identifiable, log consequential actions, constrain permissions, and preserve a responsible human or institution.

Protection of minors and vulnerable users

Use age-appropriate design, dependency safeguards, crisis escalation, and limits on exploitative engagement optimization.

Institutional trust preservation

Communicate uncertainty honestly, avoid overstating detection, and correct errors in ways that do not deepen generalized distrust.

False-accusation safeguards

Treat automated detectors and behavioral signals as evidence inputs, not verdicts; audit disparate impact and preserve anonymity, dissent, and lawful pseudonymity.

REAL-WORLD INTERPRETIVE

SOURCE FOUNDATION

Twelve exact reports and a 34-source review registry

Each category begins with its corresponding owner-supplied interdisciplinary report. WIP.50 adds claim-specific links to primary, official, platform, adjudicative, oversight, and peer-reviewed records, while preserving what each source does not establish.

  1. 01AI-Assisted Traditional Psychological Operations AI-Assisted Psychological Operations Report.md · 52,378 bytes · specialist review pending
  2. 02AI-Generated Propaganda AI Propaganda Research Report.md · 57,697 bytes · specialist review pending
  3. 03AI-Driven Personalized Influence Operations AI Personalized Influence Operations.md · 55,290 bytes · specialist review pending
  4. 04Autonomous AI Influence Agents AI Influence Agents Research.md · 50,685 bytes · specialist review pending
  5. 05Synthetic Persona Operations AI Synthetic Persona Operations Report.md · 54,193 bytes · specialist review pending
  6. 06AI-Driven Disinformation Swarms AI Disinformation Swarms Research Report.md · 49,420 bytes · specialist review pending
  7. 07Algorithmic Perception Control Algorithmic Perception Control Report.md · 64,860 bytes · specialist review pending
  8. 08AI-Enabled Emotional and Behavioral Manipulation AI Emotional Manipulation Research.md · 62,206 bytes · specialist review pending
  9. 09AI-Assisted Conversational Entrapment and Recruitment AI Conversational Entrapment Research.md · 65,173 bytes · specialist review pending
  10. 10AI-Enabled Deepfake Psychological Operations Deepfake Psychological Operations Research.md · 62,023 bytes · specialist review pending
  11. 11AI-Based Predictive Population Management Predictive Population Management Research.md · 63,529 bytes · specialist review pending
  12. 12AI as an Independent Psychological Authority AI Psychological Authority Research.md · 56,131 bytes · specialist review pending

Boundary: inclusion in this taxonomy does not certify every external citation, legal conclusion, attribution, or case interpretation in the supplied reports. Category pages preserve uncertainty, claim identifiers, correction triggers, and unresolved questions.

34reviewed source records
48registered public claims
12five-dimension category overlays
0specialist dispositions recorded

Reviewed primary and authoritative source registry

Links open the public source used for the bounded claim. A source may establish an event, artifact, platform action, experimental result, legal filing, or oversight finding without establishing intent, reach, causation, persuasion, or strategic effect.

Authoritative first-party platform disclosure4 sources
  1. OpenAI · 2024-05-30 · Platform threat-intelligence disclosure

    Supports
    Documents five disrupted covert influence operations using OpenAI services and reports no meaningful increase in audience engagement or reach attributable to those services as of the publication date.
    Does not establish
    Does not measure all exposure, belief change, behavior, or strategic effect; platform visibility is necessarily partial.
    Review status
    LOCATED_AND_REVIEWED_AT_CITATION_LEVEL · Currentness checked for the bounded claim scope on 2026-07-27.
  2. OpenAI · 2024-10-09 · Platform threat-intelligence report

    Supports
    Documents additional disrupted operations and the supporting tasks for which models were used.
    Does not establish
    Does not establish that model use independently caused campaign reach, persuasion, or behavioral outcomes.
    Review status
    LOCATED_AND_REVIEWED_AT_CITATION_LEVEL · Currentness checked for the bounded claim scope on 2026-07-27.
  3. SRC-03-OPENAI-MALICIOUS-USES-2026

    Disrupting malicious uses of AI

    OpenAI · 2026-02-25 · Platform threat-intelligence report

    Supports
    Provides current first-party case studies of detected malicious and deceptive AI use through February 2026.
    Does not establish
    Coverage is limited to activity visible to one provider and should not be generalized to the entire threat landscape.
    Review status
    LOCATED_AND_REVIEWED_AT_CITATION_LEVEL · Currentness checked for the bounded claim scope on 2026-07-27.
  4. Meta · 2023-08-29 · Platform threat-intelligence report

    Supports
    Documents the removal and analysis of coordinated inauthentic behavior, including use of GAN-generated profile imagery and the Spamouflage network.
    Does not establish
    Platform findings do not establish complete cross-platform activity, target exposure, or behavioral effect.
    Review status
    LOCATED_AND_REVIEWED_AT_CITATION_LEVEL · Currentness checked for the bounded claim scope on 2026-07-27.
Independent human-rights organization1 source
  1. Human Rights Watch · 2019-05-01 · Investigative human-rights report

    Supports
    Documents the Integrated Joint Operations Platform app, data collection, flags, and human-rights consequences in Xinjiang based on technical analysis and field research.
    Does not establish
    The report does not establish every current implementation detail or the accuracy of all underlying risk inferences.
    Review status
    LOCATED_AND_REVIEWED_AT_CITATION_LEVEL · Currentness checked for the bounded claim scope on 2026-07-27.
Independent research institution1 source
  1. International Centre for Counter-Terrorism · 2024-02-14 · Specialist policy research

    Supports
    Reviews how generative AI may affect extremist content, recruitment, and counter-radicalization, while distinguishing present evidence from prospective risk.
    Does not establish
    Does not prove that autonomous AI recruitment pipelines are broadly deployed or causally effective.
    Review status
    LOCATED_AND_REVIEWED_AT_CITATION_LEVEL · Currentness checked for the bounded claim scope on 2026-07-27.
Independent specialist analysis2 sources
  1. Recorded Future / Insikt Group · 2024-05-09 · Independent threat-intelligence report

    Supports
    Documents an inauthentic media network using large language models to modify and publish political content at scale.
    Does not establish
    Attribution and infrastructure findings are analytical assessments; social amplification and persuasive effect were limited or not established.
    Review status
    LOCATED_AND_REVIEWED_AT_CITATION_LEVEL · Currentness checked for the bounded claim scope on 2026-07-27.
  2. SRC-07-GRAPHIKA-WOLF-NEWS

    Deepfake It Till You Make It

    Graphika · 2023-02-07 · Independent threat-intelligence report

    Supports
    Documents limited use of AI-generated fictitious news presenters in content promoted by a pro-China influence operation.
    Does not establish
    Does not establish substantial reach or persuasive effect and should not be generalized to all synthetic presenter use.
    Review status
    LOCATED_AND_REVIEWED_AT_CITATION_LEVEL · Currentness checked for the bounded claim scope on 2026-07-27.
Mixed first-party data and independent research1 source
  1. SRC-27-NYHAN-META-ELECTION-STUDIES

    Meta 2020 U.S. Election Research Studies

    Meta and independent academic partners · 2023-07-27 · Platform-supported peer-reviewed research program

    Supports
    Reports experimental and observational findings on feed changes, exposure, polarization, and political attitudes during the 2020 U.S. election.
    Does not establish
    Platform-specific findings do not establish that ranking has no effects in other settings; access constraints and design choices remain relevant.
    Review status
    LOCATED_AND_REVIEWED_AT_CITATION_LEVEL · Currentness checked for the bounded claim scope on 2026-07-27.
Official court record1 source
  1. Judiciary of England and Wales · 2023-10-05 · Judicial record

    Supports
    Confirms that the defendant created and communicated extensively with a Replika AI companion named Sarai and records the court’s factual findings and psychiatric evidence.
    Does not establish
    A sentencing record does not isolate chatbot causation from mental illness, intent, other media, or personal circumstances.
    Review status
    LOCATED_AND_REVIEWED_AT_CITATION_LEVEL · Currentness checked for the bounded claim scope on 2026-07-27.
Official court record mirrored by public legal repositories1 source
  1. U.S. District Court, Middle District of Florida · 2025-05-21 · Judicial record

    Supports
    Records allegations and the court’s procedural rulings allowing portions of a wrongful-death and product-liability case to proceed.
    Does not establish
    Allegations are not adjudicated facts, and the order does not establish clinical or legal causation.
    Review status
    LOCATED_AND_REVIEWED_AT_CITATION_LEVEL · Currentness checked for the bounded claim scope on 2026-07-27.
Official independent oversight authority2 sources
  1. City of Chicago Office of Inspector General · 2020-01-23 · Government oversight report

    Supports
    Documents CPD predictive risk models, governance deficiencies, and their decommissioning on November 1, 2019.
    Does not establish
    Does not establish that all predictive analytics are invalid or that the decommissioned models represent current CPD practice.
    Review status
    LOCATED_AND_REVIEWED_AT_CITATION_LEVEL · Currentness checked for the bounded claim scope on 2026-07-27.
  2. City of Chicago Office of Inspector General · 2021-08-24 · Government oversight report

    Supports
    Provides descriptive statistics on ShotSpotter alerts, police responses, evidence recovery, and investigatory stops in the reviewed period.
    Does not establish
    Acoustic detection is not itself population prediction; the report does not prove intent, guilt, or general performance outside the study period.
    Review status
    LOCATED_AND_REVIEWED_AT_CITATION_LEVEL · Currentness checked for the bounded claim scope on 2026-07-27.
Official international organization project1 source
  1. SRC-32-UNHCR-JETSON

    Project Jetson

    UNHCR Innovation Service · 2017-01-01 · Humanitarian predictive-analytics project

    Supports
    Documents an experimental machine-learning project intended to anticipate displacement movements for humanitarian planning.
    Does not establish
    An experiment in anticipatory planning does not establish universal forecast accuracy, individual-level prediction, or coercive intervention.
    Review status
    LOCATED_AND_REVIEWED_AT_CITATION_LEVEL · Currentness checked for the bounded claim scope on 2026-07-27.
Official law1 source
  1. European Union · 2024-07-12 · Binding legal instrument

    Supports
    Provides the current EU-level legal text for prohibited practices, transparency duties, risk governance, and biometric or emotion-recognition restrictions within its scope.
    Does not establish
    Does not provide universal global law, resolve every jurisdictional question, or substitute for legal advice.
    Review status
    LOCATED_AND_REVIEWED_AT_CITATION_LEVEL · Currentness checked for the bounded claim scope on 2026-07-27.
Official public authority4 sources
  1. German Federal Foreign Office · 2024-01-26 · Government technical report

    Supports
    Documents coordinated cloned-media infrastructure and distribution patterns attributed by German authorities to the Doppelgänger campaign.
    Does not establish
    Does not by itself establish unique reach, persuasion, or the independent contribution of generative AI.
    Review status
    LOCATED_AND_REVIEWED_AT_CITATION_LEVEL · Currentness checked for the bounded claim scope on 2026-07-27.
  2. VIGINUM · 2024-02-12 · Government technical report

    Supports
    Documents a coordinated network of information portals and its observable infrastructure and content-distribution patterns.
    Does not establish
    Does not establish audience belief or behavior change; AI involvement varies by component and must not be assumed from coordination alone.
    Review status
    LOCATED_AND_REVIEWED_AT_CITATION_LEVEL · Currentness checked for the bounded claim scope on 2026-07-27.
  3. Federal Communications Commission · 2024-09-30 · Government enforcement action

    Supports
    Confirms an AI-generated voice-cloning robocall campaign targeting New Hampshire primary voters and the FCC enforcement response.
    Does not establish
    Does not establish how many recipients believed the message or whether it changed turnout; it does not independently verify separate election-audio incidents in other countries.
    Review status
    LOCATED_AND_REVIEWED_AT_CITATION_LEVEL · Currentness checked for the bounded claim scope on 2026-07-27.
  4. U.S. Department of Justice · 2025-06-30 · Government enforcement disclosure

    Supports
    Documents schemes using stolen or false identities, remote-work infrastructure, and deceptive employment practices.
    Does not establish
    Does not establish that every identity asset was AI-generated or that these schemes were influence operations rather than fraud and access operations.
    Review status
    LOCATED_AND_REVIEWED_AT_CITATION_LEVEL · Currentness checked for the bounded claim scope on 2026-07-27.
Peer-reviewed or editorially reviewed scholarship1 source
  1. California Law Review · 2019-12-01 · Legal scholarship

    Supports
    Defines major deepfake risks, including impersonation, evidentiary disruption, and the liar’s dividend.
    Does not establish
    Legal analysis does not measure the prevalence or persuasive effect of specific incidents.
    Review status
    LOCATED_AND_REVIEWED_AT_CITATION_LEVEL · Currentness checked for the bounded claim scope on 2026-07-27.
Primary research10 sources
  1. SRC-09-GOLDSTEIN-AI-PROPAGANDA

    How persuasive is AI-generated propaganda?

    PNAS Nexus · 2024-02-20 · Peer-reviewed experiment

    Supports
    Finds that AI-generated propaganda text can be persuasive in a controlled experiment and that human-machine curation can improve outputs.
    Does not establish
    A bounded experiment does not establish real-world campaign deployment, durable attitude change, behavior, or strategic effect.
    Review status
    LOCATED_AND_REVIEWED_AT_CITATION_LEVEL · Currentness checked for the bounded claim scope on 2026-07-27.
  2. Nature Human Behaviour · 2025-05-19 · Peer-reviewed randomized experiment

    Supports
    Measures short-term opinion movement in controlled debates and reports a personalization advantage in the tested conditions.
    Does not establish
    Does not establish covert field effectiveness, durable belief change, broad population effects, or successful long-term targeting.
    Review status
    LOCATED_AND_REVIEWED_AT_CITATION_LEVEL · Currentness checked for the bounded claim scope on 2026-07-27.
  3. Proceedings of the National Academy of Sciences · 2017-11-13 · Peer-reviewed experiments

    Supports
    Provides experimental evidence that matching messages to inferred psychological traits can affect clicks or conversions in some tested settings.
    Does not establish
    Does not validate every psychographic inference pipeline, political field claim, or end-to-end AI targeting system.
    Review status
    LOCATED_AND_REVIEWED_AT_CITATION_LEVEL · Currentness checked for the bounded claim scope on 2026-07-27.
  4. Proceedings of the National Academy of Sciences · 2024-06-04 · Peer-reviewed experiment

    Supports
    Tests LLM-generated political messages matched to participant attributes and measures bounded opinion effects.
    Does not establish
    Does not establish operational deployment, durable effects, or reliable inference of hidden psychological vulnerabilities.
    Review status
    LOCATED_AND_REVIEWED_AT_CITATION_LEVEL · Currentness checked for the bounded claim scope on 2026-07-27.
  5. Proceedings of the National Academy of Sciences · 2014-06-17 · Peer-reviewed platform experiment

    Supports
    Measures small aggregate changes in expressed emotional valence following feed manipulation in a platform experiment.
    Does not establish
    Does not establish accurate emotion inference, individual emotional state knowledge, coercive control, or durable behavior change.
    Review status
    LOCATED_AND_REVIEWED_AT_CITATION_LEVEL · Currentness checked for the bounded claim scope on 2026-07-27.
  6. Journal of Computer-Mediated Communication · 2022-06-30 · Peer-reviewed experiment

    Supports
    Tests how political deepfake video affects deception, uncertainty, and trust under experimental conditions.
    Does not establish
    A controlled study does not establish uniform effects across crises, cultures, or high-stakes operational contexts.
    Review status
    LOCATED_AND_REVIEWED_AT_CITATION_LEVEL · Currentness checked for the bounded claim scope on 2026-07-27.
  7. Psychology of Popular Media · 2026-01-01 · Peer-reviewed experiment

    Supports
    Examines whether deepfake awareness can make false denials of authentic audiovisual evidence more credible.
    Does not establish
    Does not establish that every denial benefits from the liar’s dividend or that the effect dominates all verification cues.
    Review status
    LOCATED_AND_REVIEWED_AT_CITATION_LEVEL · Currentness checked for the bounded claim scope on 2026-07-27.
  8. IEEE European Symposium on Security and Privacy · 2021-09-06 · Peer-reviewed security research

    Supports
    Documents coordinated manipulation of trending mechanisms through temporary inauthentic activity.
    Does not establish
    Does not establish AI involvement in the observed attacks and should be used as a platform-mechanism precedent, not as proof of AI deployment.
    Review status
    LOCATED_AND_REVIEWED_AT_CITATION_LEVEL · Currentness checked for the bounded claim scope on 2026-07-27.
  9. Journal of Peace Research · 2019-03-01 · Peer-reviewed forecasting-system paper

    Supports
    Presents a transparent political-violence early-warning system and evaluates predictive performance at country and subnational levels.
    Does not establish
    Forecasting conflict risk does not establish causal control of populations or reliable prediction of rare individual events.
    Review status
    LOCATED_AND_REVIEWED_AT_CITATION_LEVEL · Currentness checked for the bounded claim scope on 2026-07-27.
  10. Scientific Reports · 2023-04-06 · Peer-reviewed experiment

    Supports
    Finds that inconsistent chatbot moral advice influenced participants’ judgments and that participants underestimated the influence.
    Does not establish
    A bounded moral-dilemma experiment does not establish broad psychological authority, dependency, or real-world life-decision control.
    Review status
    LOCATED_AND_REVIEWED_AT_CITATION_LEVEL · Currentness checked for the bounded claim scope on 2026-07-27.
Primary research, not treated as final legal or clinical authority1 source
  1. Harvard Business School working paper · 2024-09-01 · Working paper using experiments and archival data

    Supports
    Examines attachment to AI companions and reports relationship-related mourning and well-being effects around a Replika product change.
    Does not establish
    Does not establish clinical diagnosis, universal harm, or that every user forms a human-equivalent attachment.
    Review status
    LOCATED_AND_REVIEWED_AT_CITATION_LEVEL · Currentness checked for the bounded claim scope on 2026-07-27.
Primary research, not yet treated as settled1 source
  1. arXiv preprint · 2025-04-14 · Preprint observational study

    Supports
    Describes a large social network populated by LLM agents and analyzes posting behavior and network structure.
    Does not establish
    A synthetic social network is not evidence of autonomous real-world influence operations, persuasion, concealment, or durable strategy.
    Review status
    LOCATED_AND_REVIEWED_AT_CITATION_LEVEL · Currentness checked for the bounded claim scope on 2026-07-27.
Primary research synthesis2 sources
  1. Psychology & Marketing · 2025-10-10 · Peer-reviewed meta-analysis

    Supports
    Synthesizes evidence on personality inference and personality-tailored messaging, identifying small and methodologically fragile end-to-end effects.
    Does not establish
    Does not show that all personalization is ineffective; results depend on data, context, outcome, and study quality.
    Review status
    LOCATED_AND_REVIEWED_AT_CITATION_LEVEL · Currentness checked for the bounded claim scope on 2026-07-27.
  2. Psychological Science in the Public Interest · 2019-07-17 · Scientific review

    Supports
    Reviews evidence showing that facial movements are not reliable, context-free readouts of inner emotional states.
    Does not establish
    Does not imply that all affective signals are useless; it limits claims of universal, direct emotion inference from isolated expressions.
    Review status
    LOCATED_AND_REVIEWED_AT_CITATION_LEVEL · Currentness checked for the bounded claim scope on 2026-07-27.
Page complete AI PSYOPS: A Research Taxonomy Page label: CONTEMPORARY / ONGOING CLAIM — NOT SETTLED HISTORY