CURRENT EVIDENCE ASSESSMENT
Documented human-directed use; persuasive effect remains claim-specific and incompletely measured.
DEPLOYMENT
Documented
Public platform and threat-intelligence reports identify AI-assisted tasks inside human-led operations.
AUTONOMY
Human-directed
Humans set objectives, infrastructure, approval, and deployment in the documented cases.
PERSISTENCE
Sustained with human supervision
Campaigns can persist, but persistence is organizational rather than autonomous model continuity.
PROFILING ACCURACY
Mixed and task-dependent
Audience analysis can use behavioral data, but deep psychological or emotional inference remains unreliable.
MEASURED EFFECT
Output and distribution documented; persuasion not established
Production, localization, and distribution are better evidenced than belief, behavior, or strategic effect.
Assessment basis
Assessment combines the exact owner-supplied category report with the bounded primary, official, platform, and peer-reviewed sources listed for this category. Dimensions are evaluated separately to prevent documented output from being mistaken for autonomy or effect.
What would change this assessment
Upgrade effect only with transparent exposure measures, pre-registered outcomes, credible counterfactuals, and durable behavioral evidence.
Prohibited inference
Do not infer strategic effect, universal deployment, or individual psychological state from this assessment.
A · DEFINITION
What this category means sources
Definition
This category covers human-led psychological operations in which AI supports established stages of work without independently setting the campaign’s strategic purpose. It includes analysis, summarization, translation, media generation, simulation, and measurement used under human command.
Outside this category
It does not include systems that independently choose strategic goals, create their own target sets, or run sustained campaigns without meaningful human approval; those belong primarily to autonomous influence agents.
B · SIGNIFICANCE
Why it matters sources
AI can compress the time and labor needed to move from research to multilingual output, allowing more content, more variants, and faster feedback. The same compression can magnify automation bias, weak source material, cultural mistakes, and unclear responsibility.
C · CHANGE FROM PRE-AI PRACTICE
How AI changes the phenomenon sources
Compared with pre-AI workflows, machine assistance can summarize large information sets, generate localized drafts, compare message variants, and monitor reactions at much higher speed. The report also cautions that fluent output and rapid measurement do not establish cultural understanding, persuasion, or strategic effect.
D · CAPABILITY STATUS
Separate evidence from projection sources
Confirmed real-world use
Public threat-intelligence reporting documents actors using generative AI for articles, comments, personas, translation, research, and technical support within human-directed influence operations.
Demonstrated technical capability
Controlled studies indicate that language models can be persuasive in bounded, short-term interactions, particularly when supplied with contextual information.
Plausible near-term development
More integrated use of AI across planning, simulation, localization, and assessment is plausible, but the reliability of simulated audiences remains uncertain.
Unsupported or unproven
The report does not establish durable population-level behavioral control or reliable strategic effect from AI assistance.
E · KEY MECHANISMS
Conceptual mechanisms — not an operating procedure sources
Safety transformation: these descriptions identify system functions at a high level. Procedural steps, target criteria, scripts, evasion methods, and deployment workflows are intentionally excluded.
- Large-scale collection and summarization of public information.
- Translation and cultural adaptation that still require native and contextual review.
- Generation of text, images, audio, or video drafts for human approval.
- Pre-publication comparison using synthetic or modeled audiences.
- Monitoring of distribution and reaction signals without treating engagement as effect.
F · EVIDENCE & EXAMPLES
What is known, measured, and still unknown sources
REACH IS NOT EFFECT. Publication, impressions, engagement, virality, or media attention do not by themselves establish persuasion or behavioral change.
STOIC / “Zero Zeno”
AI use confirmed by platform reporting
- What occurred
- An influence-for-hire network used AI-generated articles, comments, and fabricated personas across several national contexts.
- What is confirmed
- The report treats AI-assisted content and persona production as confirmed.
- Effect measured
- The operation produced content at scale but reportedly struggled to secure organic engagement.
- What remains unknown
- The number of people persuaded or behaviorally influenced is not established.
- Source scope
- The linked sources support the bounded statements shown here; they do not automatically establish intent, reach, persuasion, behavior, or strategic effect.
- Correction trigger
- Revise when a primary record, authoritative correction, adjudication, retraction, or stronger causal study changes the bounded statement.
SRC-01-OPENAI-COVERT-IO-2024 OpenAI Doppelganger
AI use confirmed; attribution publicly reported
- What occurred
- A Russian-aligned network used AI to translate, rewrite, and distribute narratives through cloned media properties and social accounts.
- What is confirmed
- Multilingual AI assistance and coordinated deceptive infrastructure are documented.
- Effect measured
- Large output and broad distribution were observed.
- What remains unknown
- Reach, exposure, belief change, and strategic effect remain separate and incompletely measured.
- Source scope
- The linked sources support the bounded statements shown here; they do not automatically establish intent, reach, persuasion, behavior, or strategic effect.
- Correction trigger
- Revise when a primary record, authoritative correction, adjudication, retraction, or stronger causal study changes the bounded statement.
SRC-04-GERMAN-FO-DOPPELGANGER German Federal Foreign Office Spamouflage
AI use confirmed in supporting tasks
- What occurred
- A state-aligned network used AI for multilingual content, research, and technical support around its distribution infrastructure.
- What is confirmed
- AI-assisted content and operational support are documented in the source report.
- Effect measured
- The network sustained cross-platform activity.
- What remains unknown
- The independent contribution of AI to persuasion is unknown.
- Source scope
- The linked sources support the bounded statements shown here; they do not automatically establish intent, reach, persuasion, behavior, or strategic effect.
- Correction trigger
- Revise when a primary record, authoritative correction, adjudication, retraction, or stronger causal study changes the bounded statement.
SRC-08-META-SPAMOUFLAGE Meta G · RISKS & FAILURE MODES
Potential harms and reasons the capability may fail sources
Risks
- Automation bias can cause operators to trust confident but unsupported analysis.
- Hallucinated facts or citations can enter public communications.
- Cultural or linguistic errors can produce backlash or expose sponsorship.
- Rapid iteration can outpace legal, ethical, and command review.
- Commercial influence-for-hire structures can complicate attribution and accountability.
Limitations and failure modes
- High production volume does not prove meaningful exposure or persuasion.
- Short-term laboratory persuasion does not establish durable belief or behavior change.
- Synthetic audience models may drift from real populations and current events.
- Human operators remain necessary for strategic direction, infrastructure, and contextual judgment in documented cases.
H · DETECTION & DEFENSIVE INDICATORS
Signals for investigation, not automatic verdicts sources
Indicator rule: unless the source report supports a stronger conclusion, each signal below is suggestive rather than conclusive. Multiple independent signals and contextual evidence are required.
- Rapidly produced multilingual variants linked to the same narrative and infrastructure may be suggestive of AI assistance.
- Coordinated account behavior and domain reuse are stronger signals than writing style alone.
- Repeated factual errors or machine-generated artifacts may support investigation but are not conclusive by themselves.
- Unexplained changes in publication tempo can justify closer provenance and network review.
I · GOVERNANCE & SAFEGUARDS
Accountability, transparency, and human protection sources
Require accountable human approval for every high-impact release and preserve review logs.
Verify factual claims and translations against independent sources and native-language expertise.
Combine provenance controls with behavioral and infrastructure analysis rather than relying on watermarks alone.
Use public resilience, prebunking, and rapid correction practices that do not amplify the original narrative unnecessarily.
Maintain explicit legal authority, auditability, and complaint or remedy pathways.
J · RESEARCH GAPS
Questions the evidence does not yet close sources
- Long-term retention of belief changes observed in short, controlled interactions.
- How AI-supported simulations diverge from real audiences during geopolitical shocks.
- Whether model-assisted planning increases escalation or strategic error.
- The independent causal contribution of AI within mixed human-machine campaigns.
L · SOURCES & REVIEW STATUS
Exact owner report, claim register, and reviewed sources
-
AI-Assisted Traditional Psychological Operations
Owner-supplied report: AI-Assisted Psychological Operations Report.md · 52,378 bytes · SHA-256
1eec5ce4b5e99479617b506bab22986821a10c3b4c8d6d6daba32b64d26623d1Owner-supplied interdisciplinary research synthesis; exact source preserved in protected durable memory. External specialist review remains pending.
Claim-specific reviewed sources
-
SRC-01-OPENAI-COVERT-IO-2024Disrupting deceptive uses of AI by covert influence operationsOpenAI · 2024-05-30 · Authoritative first-party platform disclosure
- Supports
- Documents five disrupted covert influence operations using OpenAI services and reports no meaningful increase in audience engagement or reach attributable to those services as of the publication date.
- Does not establish
- Does not measure all exposure, belief change, behavior, or strategic effect; platform visibility is necessarily partial.
- Review
- LOCATED_AND_REVIEWED_AT_CITATION_LEVEL · Currentness checked for the bounded claim scope on 2026-07-27.
-
SRC-02-OPENAI-UPDATE-2024Influence and cyber operations: an update, October 2024OpenAI · 2024-10-09 · Authoritative first-party platform disclosure
- Supports
- Documents additional disrupted operations and the supporting tasks for which models were used.
- Does not establish
- Does not establish that model use independently caused campaign reach, persuasion, or behavioral outcomes.
- Review
- LOCATED_AND_REVIEWED_AT_CITATION_LEVEL · Currentness checked for the bounded claim scope on 2026-07-27.
-
SRC-04-GERMAN-FO-DOPPELGANGERTechnical report on the Doppelgänger disinformation campaignGerman Federal Foreign Office · 2024-01-26 · Official public authority
- Supports
- Documents coordinated cloned-media infrastructure and distribution patterns attributed by German authorities to the Doppelgänger campaign.
- Does not establish
- Does not by itself establish unique reach, persuasion, or the independent contribution of generative AI.
- Review
- LOCATED_AND_REVIEWED_AT_CITATION_LEVEL · Currentness checked for the bounded claim scope on 2026-07-27.
-
SRC-06-RECORDED-FUTURE-COPYCOPRussia-Linked CopyCop Uses LLMs to Weaponize Influence Content at ScaleRecorded Future / Insikt Group · 2024-05-09 · Independent specialist analysis
- Supports
- Documents an inauthentic media network using large language models to modify and publish political content at scale.
- Does not establish
- Attribution and infrastructure findings are analytical assessments; social amplification and persuasive effect were limited or not established.
- Review
- LOCATED_AND_REVIEWED_AT_CITATION_LEVEL · Currentness checked for the bounded claim scope on 2026-07-27.
-
SRC-08-META-SPAMOUFLAGEMeta Quarterly Adversarial Threat Report, Q3 2023Meta · 2023-08-29 · Authoritative first-party platform disclosure
- Supports
- Documents the removal and analysis of coordinated inauthentic behavior, including use of GAN-generated profile imagery and the Spamouflage network.
- Does not establish
- Platform findings do not establish complete cross-platform activity, target exposure, or behavioral effect.
- Review
- LOCATED_AND_REVIEWED_AT_CITATION_LEVEL · Currentness checked for the bounded claim scope on 2026-07-27.
-
SRC-10-SALVI-LLM-PERSUASIONOn the conversational persuasiveness of GPT-4Nature Human Behaviour · 2025-05-19 · Primary research
- Supports
- Measures short-term opinion movement in controlled debates and reports a personalization advantage in the tested conditions.
- Does not establish
- Does not establish covert field effectiveness, durable belief change, broad population effects, or successful long-term targeting.
- Review
- LOCATED_AND_REVIEWED_AT_CITATION_LEVEL · Currentness checked for the bounded claim scope on 2026-07-27.
Selected works identified by the owner-supplied report
- Department of the Army, Psychological Operations Process Tactics, Techniques, and Procedures (FM 3-05.301).
- Salvi et al., On the Conversational Persuasiveness of Large Language Models: A Randomized Controlled Trial.
- OpenAI Threat Intelligence, Disrupting Deceptive Uses of AI by Covert Influence Operations.
- Schmitt, ed., Tallinn Manual 2.0 on the International Law Applicable to Cyber Operations.
Exact source preservation and editorial currentness review do not constitute specialist certification, adjudication, legal advice, clinical review, or proof that every owner-report citation is current. Corrections remain open.
Evidence methodReach versus effectCorrectionsDefensive incident template