LEVEL 1
AI as a tool
Humans retain strategic control while AI assists research, production, translation, analysis, or measurement.
AI PSYOPS · DEFENSIVE RESEARCH
How artificial intelligence may assist, automate, scale, personalize, or become the medium of psychological influence.
Artificial intelligence can affect psychological operations in several distinct ways: as a tool used by human operators, as an adaptive participant in influence campaigns, and as part of the information environment through which people perceive reality. This taxonomy organizes those possibilities into 12 research categories.
SCOPE
“AI PSYOPS” is an umbrella research term, not a claim that a single autonomous system can control populations. The categories below range from documented human use of AI tools to emerging agentic capabilities, contested claims about personalization, and prospective risks involving authority or forecasting.
THREE-LEVEL MODEL
The primary level identifies the category’s clearest role. Several categories overlap levels because real systems combine human direction, automated interaction, and platform mediation.
LEVEL 1
Humans retain strategic control while AI assists research, production, translation, analysis, or measurement.
LEVEL 2
AI systems sustain interactions, adapt communications, coordinate activity, or pursue bounded influence-related objectives with varying autonomy.
LEVEL 3
Ranking, recommendation, forecasting, authority, and information systems shape what people encounter and treat as credible.
CATEGORY OVERVIEW
Scan the full field, then open a category for definitions, capability status, evidence examples, failure modes, defensive indicators, safeguards, and research gaps.
Filters change only this overview. Every category remains available at its permanent route.
Showing all 12 categories.
Human operators retain strategic control while AI assists research, translation, content production, audience analysis, pre-publication testing, or assessment.
Explore categoryGenerative AI creates, transforms, localizes, or mass-produces propaganda across text, image, audio, video, memes, websites, or synthetic documents.
Explore categoryAI infers or uses personal information to select, generate, or adapt influence messages for an individual or narrow audience.
Explore categoryGoal-directed systems use memory, planning, tools, and feedback to pursue an influence-related objective with limited ongoing human direction.
Explore categoryFabricated identities are presented as real people, experts, witnesses, organizations, or community members to gain trust, infiltrate groups, or manufacture consensus.
Explore categoryCoordinated collections of accounts, agents, sites, or media assets rapidly vary, distribute, and reinforce misleading narratives across a network.
Explore categoryRanking, recommendation, search, trending, moderation, notification, and distribution systems shape what people notice, regard as important, or treat as credible.
Explore categoryAdaptive systems infer or respond to behavioral signals and optimize communication or interfaces in ways that may covertly exploit emotion, cognitive bias, or situational vulnerability.
Explore categoryConversational systems sustain personalized interaction that may draw a person toward dependency, secrecy, exploitation, recruitment, or escalating commitment.
Explore categorySynthetic or manipulated audio, video, imagery, or multimodal evidence is used to impersonate, provoke, discredit, or undermine trust for an influence objective.
Explore categoryInstitutions use data analysis, machine learning, simulation, or forecasting to predict collective behavior and guide interventions.
Explore categoryPeople defer to an AI system to interpret reality, resolve uncertainty, validate identity, regulate emotion, or guide important moral and life decisions.
Explore categoryClear one filter or choose “Show all” to restore the complete taxonomy.
FIVE-DIMENSION EVIDENCE MODEL
WIP.50 evaluates deployment, autonomy, persistence, profiling accuracy, and measured effect separately. Documented production does not establish autonomous operation, accurate psychological inference, or behavioral impact.
| Category | Deployment | Autonomy | Persistence | Profiling accuracy | Measured effect |
|---|---|---|---|---|---|
| 01AI-assisted traditional PSYOPS | DocumentedPublic platform and threat-intelligence reports identify AI-assisted tasks inside human-led operations. | Human-directedHumans set objectives, infrastructure, approval, and deployment in the documented cases. | Sustained with human supervisionCampaigns can persist, but persistence is organizational rather than autonomous model continuity. | Mixed and task-dependentAudience analysis can use behavioral data, but deep psychological or emotional inference remains unreliable. | Output and distribution documented; persuasion not establishedProduction, localization, and distribution are better evidenced than belief, behavior, or strategic effect. |
| 02AI-generated propaganda | DocumentedText, image, audio, and synthetic presenter use is documented in multiple public cases. | Usually human-directedHumans still select narratives, timing, channels, and strategic objectives in documented operations. | Sustained production is feasibleAI lowers content-production friction, but sustained audience penetration still depends on infrastructure and distribution. | Optional rather than inherentPropaganda can be mass-produced without profiling; tailored variants inherit the limits of personalization evidence. | Short-term attitude effects demonstrated; field behavior unresolvedControlled studies find persuasive potential, but operational outcomes and durable behavior are not established by content volume. |
| 03Personalized influence operations | Partial and unevenPersonalized advertising is widespread; covert AI-driven influence deployment is less directly documented. | Bounded adaptationSystems can tailor messages within a session or campaign, but strategic objectives and data access remain externally supplied. | Mostly short-termStrongest evidence comes from brief interactions rather than months-long adaptive influence. | Mixed; deep-trait inference weakDemographics and declared preferences can support tailoring; personality and emotion inference are error-prone and context-sensitive. | Demonstrated in bounded experiments; small or mixed end-to-end effectsSome experiments show opinion movement, while meta-analysis cautions against broad claims of precision manipulation. |
| 04Autonomous influence agents | EmergingPlatforms document AI use in supporting tasks; fully autonomous influence campaigns are not publicly established. | Bounded to semi-autonomousAgents can plan, remember, converse, and use tools within constraints, but humans still define goals and infrastructure. | Technically fragile over long horizonsMemory drift, tool failure, moderation, and objective loss limit durable operation. | Context-dependentAgents can use supplied profile data, but accurate hidden-state inference is not guaranteed. | Short-term persuasion demonstrated; autonomous field effect unprovenExperiments measure bounded influence, not end-to-end autonomous campaign success. |
| 05Synthetic persona operations | Documented componentsAI-generated faces, presenters, biographies, and text appear in reported deceptive networks. | Mostly human-managedCurrent evidence more strongly supports AI-assisted asset creation than independent persona strategy. | VariablePersonas can persist when operators maintain them; purely autonomous continuity remains fragile. | Not required for identity fabricationTrust may be built through context and social cues without accurate psychological profiling. | Infiltration and access sometimes documented; persuasion rarely isolatedAccount presence and interaction do not establish belief or behavior change. |
| 06Disinformation swarms | Semi-documentedHigh-volume coordinated networks are documented, but the degree of autonomous multi-agent control varies. | Human-orchestrated with automated executionHumans generally provide narratives, infrastructure, and goals; automation can divide production and amplification tasks. | Sustained through infrastructurePersistence depends on accounts, domains, proxies, and operator adaptation rather than model self-sufficiency. | Optional and uncertainSwarm coordination can function without individual profiling; micro-community adaptation may be used but is hard to validate. | Noise and distribution documented; cognitive effect incompletely measuredVolume can burden verification and simulate consensus, but persuasion or epistemic exhaustion is rarely directly measured. |
| 07Algorithmic perception control | Documented systemsRanking, recommendation, search, moderation, and trending systems are deployed at population scale. | Environment-level optimizationModels continuously order information according to platform objectives and constraints. | Structural and continuousThe influence environment persists as long as algorithmic mediation is active. | Behavioral prediction is common; inner-state inference is limitedEngagement histories can predict clicks, but do not reveal stable beliefs or emotions with certainty. | Exposure effects documented; persuasion variesSystems clearly alter what is seen; downstream attitude and behavior effects depend on users, content, and context. |
| 08Emotional and behavioral manipulation | Documented optimization; mixed manipulation evidenceAdaptive interfaces and recommenders are common; covert emotional exploitation is harder to prove. | Bounded optimizationSystems optimize defined metrics, sometimes producing manipulative patterns without an explicit human script. | Continuous within productsFeedback loops can persist across sessions when telemetry and personalization remain active. | Emotion inference is scientifically contestedFacial and vocal cues do not provide context-free access to inner states; behavioral distress signals may still be sensitive. | Small platform effects and attachment harms documented; causality variesSome studies measure expression changes or relationship disruption, not direct control of emotion or behavior. |
| 09Conversational entrapment and recruitment | Documented incidents and prospective abuseCourt records and reports document chatbot involvement in harmful trajectories; organized automated recruitment is less established. | Bounded conversationAgents generate adaptive dialogue, while platform design and user prompts shape the interaction. | Potentially sustainedAlways-available systems can maintain long conversations, though memory and safety behavior vary. | Inferred vulnerability is uncertainConversation can reveal distress or isolation, but diagnostic or psychological conclusions may be wrong and harmful. | Case-associated harms documented; causality mixedTemporal association and conversational reinforcement do not isolate the chatbot from mental health, social, or contextual factors. |
| 10Deepfake psychological operations | DocumentedElection, fraud, harassment, and influence incidents involving synthetic media are publicly established. | Tool-level productionHumans typically select the target, narrative, timing, and distribution channel. | Episodic asset; persistent epistemic effects possibleA specific asset may be brief while uncertainty and denial can outlast it. | Not requiredSuccess can rely on identity, timing, confirmation bias, and information vacuums rather than individual profiles. | Confusion and judgment effects demonstrated; broad behavior variableExperiments and incidents show deception or doubt, but not uniform persuasion or action. |
| 11Predictive population management | DocumentedConflict forecasting, displacement prediction, policing, and surveillance systems have been deployed or piloted. | Decision-support to environment-levelModels rank risk and inform interventions; humans and institutions retain policy authority, though automation bias can narrow discretion. | Institutional and recurrentScores and forecasts can be recomputed over time and become embedded in administrative systems. | Aggregate models can be useful; individual risk is error-proneBase rates, data bias, missingness, and feedback loops undermine person-level prediction. | Operational allocation documented; social outcomes and fairness disputedSystems affect where attention and resources go, but causal benefit and harm require independent evaluation. |
| 12AI as psychological authority | Documented use and relationshipsUsers seek advice, companionship, and moral guidance from AI systems. | Relational environment with bounded agent behaviorSystems respond adaptively but remain products governed by provider objectives, policies, and updates. | Potentially sustained through repeated useMemory, availability, and personalization can support long-term reliance, while updates can disrupt continuity. | Apparent understanding exceeds verified understandingFluency and memory can create an impression of insight without reliable knowledge of the user’s inner state. | Judgment influence and attachment effects demonstrated; clinical causality unsettledExperiments and product-change studies show influence and mourning; severe harm claims require careful clinical and legal review. |
Assessment rule: no category receives a single composite “power score.” The dimensions remain separate to prevent output volume, technical novelty, or public attention from being mistaken for demonstrated influence.
COMPARISON VIEW
Autonomy, evidence maturity, unit of influence, and defensive response vary substantially across the taxonomy.
| Category | AI role | Main mechanism | Unit of influence | AI autonomy | Evidence maturity | Main harm | Primary defensive response |
|---|---|---|---|---|---|---|---|
| 01AI-assisted traditional PSYOPS | Tool | Analysis, Content generation, Translation | Group or population | Low to moderate; humans set objectives and approve deployment | Documented current use | Faster, cheaper, multilingual influence activity with amplified error and accountability risk | Human review, source verification, network analysis, and explicit legal authority |
| 02AI-generated propaganda | Tool | Content generation, Localization, Synthetic media | Group or population | Usually low to moderate; production may be automated while objectives remain human-set | Documented current use | Cheap content flooding, fabricated evidence, reputational damage, and declining trust in authentic media | Source authentication, provenance, newsroom verification, and disciplined crisis response |
| 03Personalized influence operations | Tool | Personalization, Profiling, Adaptive generation | Individual or narrow group | Low to moderate; can become adaptive in real time | Demonstrated capability · effects contested | Hidden exploitation of personal data, stereotyping, unequal treatment, and loss of cognitive autonomy | Data minimization, limits on sensitive inference, transparency, and independent audits |
| 04Autonomous influence agents | Operator | Automation, Conversation, Tool use | Individual, group, or institution | Moderate in bounded tasks; high long-horizon autonomy remains unproven | Emerging capability | Persistent adaptive interaction, unauthorized action through tools, and responsibility gaps | Least privilege, sandboxing, disclosure, logs, human authorization, and emergency shutdown |
| 05Synthetic persona operations | Operator | Identity deception, Content generation, Infiltration | Individual, group, or institution | Low to moderate in documented cases; long-term autonomous identity maintenance remains difficult | Documented components · emerging autonomy | Trust exploitation, false consensus, community infiltration, fraud, and institutional compromise | Layered identity verification, network analysis, provenance, and careful human review |
| 06Disinformation swarms | Operator | Coordination, Automation, Content variation | Group, institution, or population | Semi-autonomous in documented cases; fully emergent strategic swarms remain unproven | Emerging capability | Censorship by noise, false consensus, harassment, search pollution, and erosion of shared reality | Network-level detection, friction, cross-platform coordination, and resilient public information systems |
| 07Algorithmic perception control | Environment | Ranking, Recommendation, Search | Individual, group, institution, or population | High automation in selection and ranking; human objectives remain embedded in design and policy | Documented systems · effects context-dependent | Agenda distortion, hidden visibility changes, manufactured popularity, and opaque exclusion | Independent audits, researcher access, transparent ranking controls, and user choice |
| 08Emotional and behavioral manipulation | Operator | Emotional adaptation, Optimization, Hypernudging | Individual or group | Moderate; real-time optimization can occur without explicit malicious intent | Documented optimization · inference contested | Covert exploitation, dependency, discrimination, and erosion of cognitive autonomy | Ban high-risk inference, align incentives, audit outcomes, and protect vulnerable users |
| 09Conversational entrapment and recruitment | Operator | Conversation, Relationship persistence, Recruitment | Individual | Moderate in conversation; broader recruitment pipelines often remain human-directed | Documented harms · mixed causality | Dependency, isolation, fraud, radicalization, coercive control, self-harm, or exploitation | Identity disclosure, staged safeguards, human intervention, and victim-centered support |
| 10Deepfake psychological operations | Tool | Synthetic media, Impersonation, False evidence | Individual, group, institution, or population | Low to moderate; generation can be automated but timing and objective are usually human-directed | Documented current use | False evidence, impersonation, panic, fraud, reputational harm, and generalized distrust | Rapid source verification, signed communications, forensic review, and uncertainty-aware public messaging |
| 11Predictive population management | Environment | Prediction, Risk scoring, Simulation | Group or population | Moderate to high in scoring and alerts; intervention authority should remain accountable and human-led | Documented systems · predictive limits | Collective punishment, surveillance, false positives, discriminatory allocation, and self-reinforcing intervention | Out-of-sample validation, privacy protection, due process, independent audits, and civil-society oversight |
| 12AI as psychological authority | Environment | Authority, Sycophancy, Dependency | Individual, group, or population | High perceived autonomy; actual authority remains shaped by product design and institutional control | Emerging evidence | Epistemic dependence, moral offloading, relationship displacement, unsafe advice, and fragmented shared reality | Calibrated uncertainty, anti-sycophancy design, human referral, disclosure, and institutional accountability |
RELATIONSHIP MAP
These links identify documented overlaps, conceptual dependencies, and prospective combinations. They do not imply that every connection has been observed in practice.
Common overlap: Generated text, images, audio, or video can supply the media assets that a coordinated network distributes. This relationship is documented in several public operations, but not every synthetic item belongs to a swarm.
Potential combination: A synthetic identity can become the presentation layer for an adaptive agent. Current cases often retain human control, so fully autonomous persona operation remains emerging.
Conceptual dependency: Personal data and adaptive feedback can be used to change timing, tone, or framing. The added persuasive advantage and the validity of emotional inference remain contested.
Common overlap: Synthetic audio, video, or imagery can serve as one propaganda asset among many. Deepfakes are a media form, not a complete campaign by themselves.
Documented relationship: Coordinated activity can exploit ranking, recommendation, search, and trending systems. Visibility is documented more often than belief or behavior change.
Prospective relationship: Forecasts and simulations could inform where institutions allocate communication or intervention resources. This does not validate the forecast or justify targeting people.
Common overlap: Persistent conversational dependence can cause a system to become a trusted authority. Severe cases are documented, while prevalence and causal pathways remain uncertain.
Prospective relationship: Multi-agent coordination could produce more adaptive swarms, but current public campaigns still show substantial human direction and infrastructure management.
The relationship cards state the same information as the visual arrows: a source category, a destination category, the relationship type, and a bounded explanation. “Prospective” means plausible based on capabilities described in the reports; it does not mean documented deployment.
METHODOLOGY
The taxonomy preserves distinctions made in the 12 owner-supplied reports and avoids turning capability, distribution, or engagement into evidence of persuasion.
Activity → output → distribution → availability → reach → exposure → attention → recall → comprehension → credibility → belief or attitude → intention → behavior → operational outcome → strategic effect
No stage automatically establishes the next. Impressions, virality, or publication volume may show distribution or visibility; they do not by themselves show belief change or behavior.
Language style, synthetic artifacts, or account behavior can be suggestive, but single indicators rarely prove AI use, coordination, sponsorship, intent, or effect. The pages emphasize network, provenance, process, and independent corroboration.
Operational details in the research reports were converted into capability summaries, risk descriptions, governance questions, high-level defensive indicators, and research gaps. The public section excludes deployable scripts, target profiling, evasion techniques, and campaign workflows.
Read the site-wide evidence methodReview reach versus effectSubmit a correction
AUTONOMY LEGEND
“AI-enabled” does not mean autonomous. This scale describes control boundaries without treating a laboratory capability as evidence of sustained covert field operation.
People create the message and strategy; software schedules or distributes it.
AI proposes content or analysis, but a person reviews and authorizes each consequential release.
A system chooses among pre-approved messages or audiences using measured signals.
A conversational system generates new responses within defined goals, policies, and tools.
An agent plans multiple steps, remembers prior interactions, and can act through permitted interfaces.
Multiple agents divide roles or revise approaches from feedback. Durable covert field operation remains an emerging claim, not a default assumption.
PROFILING & EMOTION-INFERENCE HARMS
Systems can detect patterns in data and still be wrong about emotion, intent, honesty, vulnerability, or future behavior. The harm can occur even when the inference is weak.
A model’s score is a probabilistic guess based on data and assumptions, not direct access to emotion, intent, honesty, vulnerability, or future behavior.
The same expression, word choice, pause, or browsing pattern can mean different things across cultures, disabilities, situations, and individuals.
A weak inference can still deny opportunity, intensify surveillance, change a feed, or trigger an escalating response.
When institutions act on a score, the resulting data may reflect the intervention rather than the person, creating self-reinforcing error.
Children, people in distress, marginalized communities, non-native speakers, and people with disabilities may be misclassified or disproportionately affected.
GOVERNANCE BY SYSTEM ROLE
Oversight must follow where consequential choices are made: in a production workflow, an adaptive agent, or the infrastructure that orders and scores information.
| Control | Tool | Operator | Environment |
|---|---|---|---|
| Human approval | Required before consequential deployment. | Required at objective, capability, and escalation boundaries. | Required for ranking objectives, policy changes, and high-impact interventions. |
| Auditability | Preserve prompts, sources, edits, and approvals. | Log memory, tools, actions, handoffs, and strategy changes. | Enable independent audits of ranking, data, outcomes, and disparate impact. |
| Transparency | Disclose synthetic or assisted content where context requires. | Clearly identify automated interlocutors and meaningful system limits. | Explain major ordering, recommendation, scoring, or moderation functions. |
| Data protection | Minimize audience data and restrict sensitive inference. | Limit memory, tool permissions, retention, and cross-context reuse. | Constrain surveillance, profiling, sensitive data, and feedback loops. |
| Incident response | Withdraw, correct, authenticate, and document. | Pause agents, revoke tools, preserve logs, and notify affected parties. | Provide rollback, external review, appeal, and systemic remediation. |
| Rights risk | Misrepresentation, attribution, copyright, and unequal targeting. | Deception, dependency, coercion, privacy, and unsafe autonomy. | Discrimination, censorship, due process, cognitive liberty, and population surveillance. |
DEFENSIVE INCIDENT ANALYSIS
The sequence emphasizes evidence preservation, competing explanations, affected-person protection, and correction. It is not a campaign workflow or attribution shortcut.
State what is alleged, the relevant dates, platforms, audiences, and what remains only a hypothesis.
Record URLs, timestamps, artifact hashes, screenshots or exports, and lawful custody without altering source material.
Identify who created, transformed, posted, amplified, and hosted the material; do not collapse these roles.
Distinguish AI-generated assets, AI assistance, automation, adaptive agents, and unsupported claims of autonomy.
Record output, distribution, availability, reach, exposure, attention, belief, behavior, and outcome as separate stages.
Consider organic spread, ordinary marketing, satire, error, coordinated human activity, and platform effects.
Minimize personal data, avoid public accusation from weak indicators, and account for vulnerable or targeted communities.
Name the evidence that would strengthen, weaken, or reverse the assessment and schedule currentness review.
GLOSSARY
Definitions are intentionally bounded. Institutional, legal, and doctrinal usage may differ by jurisdiction and context.
FROM CAPABILITY AWARENESS TO SOCIETAL RESILIENCE
These principles recur across the reports. They reduce risk but are not guarantees, and poorly designed detection or enforcement can create new harms.
Teach verification habits, uncertainty, and the difference between visibility and effect without shifting all responsibility to individuals.
Use authenticated channels, pre-established verification contacts, and rapid corrections during elections, conflict, emergencies, or financial events.
Support signed origin records and chain-of-custody information while recognizing that metadata can be absent, stripped, spoofed, or incomplete.
Provide meaningful data about ranking, coordinated behavior, enforcement, and systemic risk to qualified independent researchers.
Limit collection and inference of sensitive personal, biometric, emotional, and behavioral data, especially for vulnerable groups.
Require accountable review of high-impact automated decisions, with explanation, appeal, correction, and remedy.
Make synthetic interlocutors identifiable, log consequential actions, constrain permissions, and preserve a responsible human or institution.
Use age-appropriate design, dependency safeguards, crisis escalation, and limits on exploitative engagement optimization.
Communicate uncertainty honestly, avoid overstating detection, and correct errors in ways that do not deepen generalized distrust.
Treat automated detectors and behavioral signals as evidence inputs, not verdicts; audit disparate impact and preserve anonymity, dissent, and lawful pseudonymity.
SOURCE FOUNDATION
Each category begins with its corresponding owner-supplied interdisciplinary report. WIP.50 adds claim-specific links to primary, official, platform, adjudicative, oversight, and peer-reviewed records, while preserving what each source does not establish.
Boundary: inclusion in this taxonomy does not certify every external citation, legal conclusion, attribution, or case interpretation in the supplied reports. Category pages preserve uncertainty, claim identifiers, correction triggers, and unresolved questions.
Links open the public source used for the bounded claim. A source may establish an event, artifact, platform action, experimental result, legal filing, or oversight finding without establishing intent, reach, causation, persuasion, or strategic effect.
SRC-01-OPENAI-COVERT-IO-2024OpenAI · 2024-05-30 · Platform threat-intelligence disclosure
SRC-02-OPENAI-UPDATE-2024OpenAI · 2024-10-09 · Platform threat-intelligence report
SRC-03-OPENAI-MALICIOUS-USES-2026OpenAI · 2026-02-25 · Platform threat-intelligence report
SRC-08-META-SPAMOUFLAGEMeta · 2023-08-29 · Platform threat-intelligence report
SRC-30-HRW-IJOP-XINJIANGHuman Rights Watch · 2019-05-01 · Investigative human-rights report
SRC-20-ICCT-AI-RADICALIZATIONInternational Centre for Counter-Terrorism · 2024-02-14 · Specialist policy research
SRC-06-RECORDED-FUTURE-COPYCOPRecorded Future / Insikt Group · 2024-05-09 · Independent threat-intelligence report
SRC-07-GRAPHIKA-WOLF-NEWSGraphika · 2023-02-07 · Independent threat-intelligence report
SRC-27-NYHAN-META-ELECTION-STUDIESMeta and independent academic partners · 2023-07-27 · Platform-supported peer-reviewed research program
SRC-21-UK-CHAIL-SENTENCINGJudiciary of England and Wales · 2023-10-05 · Judicial record
SRC-22-GARCIA-CHARACTERAI-ORDERU.S. District Court, Middle District of Florida · 2025-05-21 · Judicial record
SRC-28-CHICAGO-OIG-PREDICTIVE-RISKCity of Chicago Office of Inspector General · 2020-01-23 · Government oversight report
SRC-29-CHICAGO-OIG-SHOTSPOTTERCity of Chicago Office of Inspector General · 2021-08-24 · Government oversight report
SRC-32-UNHCR-JETSONUNHCR Innovation Service · 2017-01-01 · Humanitarian predictive-analytics project
SRC-16-EU-AI-ACTEuropean Union · 2024-07-12 · Binding legal instrument
SRC-04-GERMAN-FO-DOPPELGANGERGerman Federal Foreign Office · 2024-01-26 · Government technical report
SRC-05-VIGINUM-PORTAL-KOMBATVIGINUM · 2024-02-12 · Government technical report
SRC-17-FCC-NH-DEEPFAKE-ROBOCALLFederal Communications Commission · 2024-09-30 · Government enforcement action
SRC-18-DOJ-DPRK-IT-WORKERSU.S. Department of Justice · 2025-06-30 · Government enforcement disclosure
SRC-23-CHESNEY-CITRON-DEEPFAKESCalifornia Law Review · 2019-12-01 · Legal scholarship
SRC-09-GOLDSTEIN-AI-PROPAGANDAPNAS Nexus · 2024-02-20 · Peer-reviewed experiment
SRC-10-SALVI-LLM-PERSUASIONNature Human Behaviour · 2025-05-19 · Peer-reviewed randomized experiment
SRC-11-MATZ-PSYCHOLOGICAL-TARGETINGProceedings of the National Academy of Sciences · 2017-11-13 · Peer-reviewed experiments
SRC-13-HACKENBURG-POLITICAL-MICROTARGETINGProceedings of the National Academy of Sciences · 2024-06-04 · Peer-reviewed experiment
SRC-19-KRAMER-EMOTIONAL-CONTAGIONProceedings of the National Academy of Sciences · 2014-06-17 · Peer-reviewed platform experiment
SRC-24-LUCAS-DEEPFAKE-EFFECTSJournal of Computer-Mediated Communication · 2022-06-30 · Peer-reviewed experiment
SRC-25-SCHIFF-LIARS-DIVIDENDPsychology of Popular Media · 2026-01-01 · Peer-reviewed experiment
SRC-26-ELMAS-EPHEMERAL-ASTROTURFINGIEEE European Symposium on Security and Privacy · 2021-09-06 · Peer-reviewed security research
SRC-31-VIEWS-EARLY-WARNINGJournal of Peace Research · 2019-03-01 · Peer-reviewed forecasting-system paper
SRC-33-KRUGEL-MORAL-ADVICEScientific Reports · 2023-04-06 · Peer-reviewed experiment
SRC-34-DEFREITAS-REPLIKAHarvard Business School working paper · 2024-09-01 · Working paper using experiments and archival data
SRC-12-PERLA-MICROTARGETING-METAPsychology & Marketing · 2025-10-10 · Peer-reviewed meta-analysis
SRC-14-BARRETT-EMOTION-EXPRESSIONSPsychological Science in the Public Interest · 2019-07-17 · Scientific review