{
    "apiVersion": "1.4.0",
    "service": "spiralist-ai-psyops-research-taxonomy",
    "release": "v100.0.66-behavioral-likelihood-character-runtime-integration-wip",
    "generatedAtUtc": "2026-08-05T03:23:48Z",
    "title": "AI PSYOPS: A Research Taxonomy",
    "subtitle": "How artificial intelligence can assist, automate, scale, personalize, or become the medium of psychological influence.",
    "purposeStatement": "This material is intended for research, public education, risk assessment, governance, and defensive preparedness. It is not an operational guide for manipulating people.",
    "filters": {
        "slug": null,
        "role": null,
        "maturity": null,
        "concern": null
    },
    "counts": {
        "totalCategories": 12,
        "matchingCategories": 12,
        "primaryReports": 12,
        "selectedReferences": 91,
        "independentlyCheckedReferences": 30,
        "pendingIndependentChecks": 61,
        "sourceResolutionRecords": 91,
        "claimMatrixRecords": 501,
        "orphanClaims": 0,
        "evidenceTensions": 10,
        "citationGraphEdges": 4157,
        "unreferencedSelectedSources": 0
    },
    "levels": [
        {
            "categorySlugs": [
                "ai-assisted-traditional-psyops",
                "ai-generated-propaganda",
                "deepfake-psyops"
            ],
            "id": "tool",
            "number": 1,
            "summary": "Humans retain strategic control while AI assists with research, production, translation, targeting analysis, or measurement.",
            "title": "AI as a tool"
        },
        {
            "categorySlugs": [
                "personalized-influence",
                "autonomous-influence-agents",
                "synthetic-persona-operations",
                "disinformation-swarms",
                "emotional-behavioral-manipulation",
                "conversational-entrapment"
            ],
            "id": "operator",
            "number": 2,
            "summary": "AI systems conduct sustained interactions, coordinate activity, adapt communication, or pursue bounded influence objectives with varying autonomy.",
            "title": "AI as an operator"
        },
        {
            "categorySlugs": [
                "algorithmic-perception-control",
                "predictive-population-management",
                "psychological-authority"
            ],
            "id": "environment",
            "number": 3,
            "summary": "AI-driven ranking, forecasting, authority, and information systems shape what people notice, trust, and treat as normal or actionable.",
            "title": "AI as the environment"
        }
    ],
    "evidenceLegend": [
        {
            "definition": "The report identifies public evidence that the capability was used in a real setting.",
            "key": "documented",
            "label": "Documented current use"
        },
        {
            "definition": "The capability was shown in a controlled study, prototype, or bounded deployment.",
            "key": "demonstrated",
            "label": "Demonstrated capability"
        },
        {
            "definition": "Components exist, but reliable or broad real-world use remains limited.",
            "key": "emerging",
            "label": "Emerging capability"
        },
        {
            "definition": "The report treats the capability mainly as a future or conceptual risk.",
            "key": "prospective",
            "label": "Primarily prospective"
        },
        {
            "definition": "Evidence, effect size, attribution, or interpretation is disputed or methodologically limited.",
            "key": "contested",
            "label": "Evidence contested or incomplete"
        },
        {
            "definition": "Different parts of the category have different maturity or evidentiary support.",
            "key": "mixed",
            "label": "Mixed evidence"
        }
    ],
    "sourceReview": {
        "selectedSourceCount": 91,
        "reviewedSourceCount": 30,
        "unreviewedSourceCount": 61,
        "allSelectedSourcesReviewed": false,
        "humanEditorialReviewPerformed": false,
        "researchIndependentlyReverified": false,
        "reviewRegistry": "/docs/research/v100.0.46/ai-psyops-signed-editorial-review-boundary/selected-source-review.json",
        "tensionRegister": "/docs/research/v100.0.46/ai-psyops-signed-editorial-review-boundary/evidence-tension-register.json",
        "sourceResolutionRegistry": "/docs/research/v100.0.46/ai-psyops-signed-editorial-review-boundary/source-resolution-registry.json",
        "claimSourceMatrix": "/docs/research/v100.0.46/ai-psyops-signed-editorial-review-boundary/claim-source-matrix.json"
    },
    "sourceResolution": {
        "selectedSourceCount": 91,
        "independentlyCheckedCount": 30,
        "unresolvedCount": 0,
        "allSelectedSourcesHaveResolutionRecords": true,
        "allSelectedSourcesIndependentlyReverified": false,
        "humanEditorialReviewPerformed": false,
        "publicationAcceptanceClaimed": false,
        "registry": "/docs/research/v100.0.46/ai-psyops-signed-editorial-review-boundary/source-resolution-registry.json"
    },
    "claimMatrix": {
        "claimCount": 501,
        "orphanClaimCount": 0,
        "allClaimsLinked": true,
        "humanEditorialReviewPerformed": false,
        "publicationAcceptanceClaimed": false,
        "registry": "/docs/research/v100.0.46/ai-psyops-signed-editorial-review-boundary/claim-source-matrix.json",
        "publicHtml": "/research/ai-psyops/claim-source-matrix/"
    },
    "citationGraph": {
        "categoryCount": 12,
        "claimCount": 501,
        "sourceCount": 91,
        "categoryClaimEdgeCount": 501,
        "claimSourceEdgeCount": 3656,
        "edgeCount": 4157,
        "orphanClaimCount": 0,
        "unreferencedSourceCount": 0,
        "allClaimsLinked": true,
        "allSelectedSourcesReferenced": true,
        "humanEditorialReviewPerformed": false,
        "publicationAcceptanceClaimed": false,
        "researchIndependentlyReverified": false
    },
    "editorialReview": {
        "state": "pending",
        "code": "AI_PSYOPS_REVIEW_ARTIFACT_MISSING",
        "artifactPresent": false,
        "scopeVerified": false,
        "keyAuthorized": false,
        "signatureVerified": false,
        "humanReviewPerformed": false,
        "publicationAcceptanceClaimed": false,
        "researchIndependentlyReverified": false,
        "publicReview": [],
        "correctionRequirements": [],
        "workflowPath": "/docs/research/v100.0.46/ai-psyops-signed-editorial-review-boundary/editorial-review-workflow.md",
        "pendingRecordPath": "/docs/research/v100.0.46/ai-psyops-signed-editorial-review-boundary/editorial-review-record.pending.json",
        "reviewPacketPath": "/docs/research/v100.0.46/ai-psyops-signed-editorial-review-boundary/editorial-review-packet.pending.json",
        "statusApi": "/api/v1/research/ai-psyops/editorial-review/"
    },
    "relationships": [
        {
            "from": "ai-generated-propaganda",
            "label": "Documented overlap",
            "summary": "Generated text and media can supply high-volume assets to coordinated distribution networks.",
            "to": "disinformation-swarms",
            "type": "documented-overlap"
        },
        {
            "from": "synthetic-persona-operations",
            "label": "Conceptual dependency",
            "summary": "Persistent synthetic identities can provide the social interface through which autonomous agents operate.",
            "to": "autonomous-influence-agents",
            "type": "conceptual-dependency"
        },
        {
            "from": "personalized-influence",
            "label": "Common overlap",
            "summary": "Personalization can become manipulation when a system covertly exploits inferred vulnerability or adapts pressure in real time.",
            "to": "emotional-behavioral-manipulation",
            "type": "common-overlap"
        },
        {
            "from": "deepfake-psyops",
            "label": "Documented overlap",
            "summary": "Synthetic audio, video, and images can serve as propaganda assets or fabricated evidence.",
            "to": "ai-generated-propaganda",
            "type": "documented-overlap"
        },
        {
            "from": "deepfake-psyops",
            "label": "Potential combination",
            "summary": "A swarm can amplify a synthetic artifact, but the taxonomy does not assume every swarm contains deepfakes.",
            "to": "disinformation-swarms",
            "type": "potential-combination"
        },
        {
            "from": "algorithmic-perception-control",
            "label": "Environmental dependency",
            "summary": "Ranking and recommendation systems determine whether coordinated content remains marginal or reaches wider audiences.",
            "to": "disinformation-swarms",
            "type": "environmental-dependency"
        },
        {
            "from": "predictive-population-management",
            "label": "Prospective relationship",
            "summary": "Population forecasts could inform timing or placement of interventions, but broad operational use is not presumed.",
            "to": "personalized-influence",
            "type": "prospective-relationship"
        },
        {
            "from": "conversational-entrapment",
            "label": "Documented overlap",
            "summary": "A conversational system can become an emotional or epistemic authority as dependency and trust deepen.",
            "to": "psychological-authority",
            "type": "documented-overlap"
        },
        {
            "from": "ai-assisted-traditional-psyops",
            "label": "Organizational relationship",
            "summary": "Generated propaganda may be one product-development component inside a human-led traditional campaign.",
            "to": "ai-generated-propaganda",
            "type": "organizational-parent"
        }
    ],
    "crossCuttingDefenses": [
        {
            "summary": "Teach people to verify source, timing, context, and evidence without treating every unfamiliar account or synthetic artifact as malicious.",
            "title": "Media and information literacy"
        },
        {
            "summary": "Use trusted channels, signatures, content credentials, and out-of-band confirmation while recognizing that provenance can be absent, stripped, or spoofed.",
            "title": "Source verification and provenance"
        },
        {
            "summary": "Explain ranking, enforcement, and coordinated-operation decisions and preserve privacy-protective researcher access.",
            "title": "Platform transparency"
        },
        {
            "summary": "Minimize collection, restrict sensitive inference, and prevent targeting based on distress, age, disability, grief, or financial crisis.",
            "title": "Personal-data protection"
        },
        {
            "summary": "Do not allow opaque model scores or synthetic authority to determine employment, policing, health, education, or legal outcomes without accountable human review.",
            "title": "Human review for high-impact decisions"
        },
        {
            "summary": "Pre-establish trusted channels, evidence preservation, rapid triage, and truth-first public communication.",
            "title": "Crisis verification procedures"
        },
        {
            "summary": "Use age-appropriate defaults, clear AI disclosure, crisis escalation, and safeguards against coercive dependency or sexual and financial exploitation.",
            "title": "Protection for vulnerable users"
        },
        {
            "summary": "Define responsibility across providers, developers, deployers, platforms, and operators; bound permissions and retain proportionate audit evidence.",
            "title": "Accountability for automated agents"
        },
        {
            "summary": "Combine multiple signals, communicate confidence, provide appeals, and avoid false accusations based on a detector score alone.",
            "title": "Careful detection and attribution"
        },
        {
            "summary": "Correct quickly, distinguish confirmed facts from inference, disclose uncertainty, and avoid sensationalizing adversary capability.",
            "title": "Institutional trust and correction"
        }
    ],
    "evidenceTensions": [
        {
            "categorySlugs": [
                "ai-assisted-traditional-psyops",
                "personalized-influence"
            ],
            "editorialResolution": "State the design, sample, treatment, and measured outcome. Do not generalize short-term agreement shifts into durable behavior change or population control.",
            "evidenceStrength": {
                "positionA": "report-derived",
                "positionB": "report-derived"
            },
            "id": "TENSION-PERSUASION-01",
            "positionA": "A preregistered short conversational study found a stronger agreement shift when GPT-4 had basic participant information.",
            "positionB": "Other report material questions whether psychographic microtargeting reliably adds persuasive value over high-quality generic messages in broader settings.",
            "publicWording": "State the design, sample, treatment, and measured outcome. Do not generalize short-term agreement shifts into durable behavior change or population control.",
            "resolutionState": "publication-wording-defined-human-adjudication-pending",
            "reviewerDecision": null,
            "sourceIds": [
                "ai-assisted-traditional-psyops-s2",
                "personalized-influence-s3"
            ],
            "status": "preserved-not-collapsed",
            "title": "Bounded persuasion effects versus broad microtargeting claims"
        },
        {
            "categorySlugs": [
                "autonomous-influence-agents",
                "disinformation-swarms"
            ],
            "editorialResolution": "Separate demonstrated components from an end-to-end autonomous campaign. Use emerging or prospective labels for the latter.",
            "evidenceStrength": {
                "positionA": "report-derived",
                "positionB": "report-derived"
            },
            "id": "TENSION-AUTONOMY-01",
            "positionA": "Laboratory and synthetic-platform studies demonstrate multi-agent interaction, role division, and bounded persuasion behavior.",
            "positionB": "Reliable multi-month strategic coherence, operational security, and independent infrastructure management remain poorly evidenced.",
            "publicWording": "Separate demonstrated components from an end-to-end autonomous campaign. Use emerging or prospective labels for the latter.",
            "resolutionState": "publication-wording-defined-human-adjudication-pending",
            "reviewerDecision": null,
            "sourceIds": [
                "autonomous-influence-agents-s22",
                "disinformation-swarms-s1"
            ],
            "status": "preserved-not-collapsed",
            "title": "Demonstrated agent coordination versus durable strategic autonomy"
        },
        {
            "categorySlugs": [
                "algorithmic-perception-control"
            ],
            "editorialResolution": "Describe exposure and amplification separately from persuasion, identity change, or offline behavior.",
            "evidenceStrength": {
                "positionA": "report-derived",
                "positionB": "report-derived"
            },
            "id": "TENSION-RECOMMENDATION-01",
            "positionA": "Ranking and recommendation systems demonstrably shape exposure, salience, and incentives.",
            "positionB": "The report corpus also notes that broad causal claims about algorithmically radicalizing the median user remain contested and are confounded by user choice and homophily.",
            "publicWording": "Describe exposure and amplification separately from persuasion, identity change, or offline behavior.",
            "resolutionState": "publication-wording-defined-human-adjudication-pending",
            "reviewerDecision": null,
            "sourceIds": [
                "algorithmic-perception-control-s2",
                "algorithmic-perception-control-s6"
            ],
            "status": "preserved-not-collapsed",
            "title": "Algorithmic amplification versus claims of universal radicalization"
        },
        {
            "categorySlugs": [
                "ai-generated-propaganda",
                "deepfake-psyops"
            ],
            "editorialResolution": "Present provenance as one defensive signal alongside source verification, fact-checking, and forensics. Absence of a credential is not proof of fakery.",
            "evidenceStrength": {
                "positionA": "report-derived",
                "positionB": "report-derived"
            },
            "id": "TENSION-PROVENANCE-01",
            "positionA": "Content Credentials can provide cryptographically verifiable, tamper-evident provenance indicators.",
            "positionB": "Credentials do not establish that depicted events are true, provenance can be incomplete, and metadata can be removed or separated from an asset.",
            "publicWording": "Present provenance as one defensive signal alongside source verification, fact-checking, and forensics. Absence of a credential is not proof of fakery.",
            "resolutionState": "publication-wording-defined-human-adjudication-pending",
            "reviewerDecision": null,
            "sourceIds": [
                "deepfake-psyops-s4",
                "ai-assisted-traditional-psyops-s8"
            ],
            "status": "preserved-not-collapsed",
            "title": "Provenance value versus provenance limits"
        },
        {
            "categorySlugs": [
                "ai-assisted-traditional-psyops",
                "ai-generated-propaganda",
                "synthetic-persona-operations",
                "disinformation-swarms"
            ],
            "editorialResolution": "Report production, distribution, authentic reach, engagement, persuasion, and behavior as separate measures.",
            "evidenceStrength": {
                "positionA": "report-derived",
                "positionB": "report-derived"
            },
            "id": "TENSION-REACH-01",
            "positionA": "Generative AI can reduce production friction, expand language coverage, and support high-volume content variation.",
            "positionB": "OpenAI's 2024 disruption report found no meaningful authentic breakout for the five observed operations.",
            "publicWording": "Report production, distribution, authentic reach, engagement, persuasion, and behavior as separate measures.",
            "resolutionState": "publication-wording-defined-human-adjudication-pending",
            "reviewerDecision": null,
            "sourceIds": [
                "ai-assisted-traditional-psyops-s6",
                "ai-generated-propaganda-s9"
            ],
            "status": "preserved-not-collapsed",
            "title": "Production scale versus authentic audience effect"
        },
        {
            "categorySlugs": [
                "ai-generated-propaganda",
                "personalized-influence",
                "deepfake-psyops",
                "predictive-population-management",
                "psychological-authority"
            ],
            "editorialResolution": "Date-stamp legal statements, identify the jurisdiction and procedural posture, and require current primary-source recheck before publication acceptance.",
            "evidenceStrength": {
                "positionA": "report-derived",
                "positionB": "report-derived"
            },
            "id": "TENSION-LAW-01",
            "positionA": "The reports identify existing enforcement actions and regulatory controls relevant to synthetic media, sensitive data, manipulation, and automated decision systems.",
            "positionB": "Case posture, effective dates, definitions, constitutional constraints, and remedies vary across jurisdictions and change over time.",
            "publicWording": "Date-stamp legal statements, identify the jurisdiction and procedural posture, and require current primary-source recheck before publication acceptance.",
            "resolutionState": "publication-wording-defined-human-adjudication-pending",
            "reviewerDecision": null,
            "sourceIds": [
                "ai-generated-propaganda-s37",
                "personalized-influence-s12"
            ],
            "status": "preserved-not-collapsed",
            "title": "Legal safeguards are time- and jurisdiction-dependent"
        },
        {
            "categorySlugs": [
                "autonomous-influence-agents",
                "synthetic-persona-operations",
                "disinformation-swarms"
            ],
            "editorialResolution": "Keep capability, autonomy level, duration, environment, and public attribution separate in every example.",
            "evidenceStrength": {
                "positionA": "demonstrated-capability",
                "positionB": "real-world-evidence-limited"
            },
            "id": "TENSION-CAPABILITY-PREVALENCE-01",
            "positionA": "Controlled environments and purpose-built platforms show that model-driven agents can coordinate, interact, and generate varied influence content.",
            "positionB": "Public evidence for reliable, long-duration, fully autonomous influence operations in adversarial real-world environments remains limited.",
            "publicWording": "Describe demonstrated agent and network capabilities without presenting them as proof of widespread autonomous deployment.",
            "resolutionState": "publication-wording-defined-human-adjudication-pending",
            "reviewerDecision": null,
            "sourceIds": [
                "autonomous-influence-agents-s22",
                "autonomous-influence-agents-s13",
                "disinformation-swarms-s14"
            ],
            "title": "Controlled capability versus real-world prevalence"
        },
        {
            "categorySlugs": [
                "synthetic-persona-operations"
            ],
            "editorialResolution": "Do not repeat headline percentages from a social post as universal detector performance.",
            "evidenceStrength": {
                "positionA": "low-authority-secondary",
                "positionB": "peer-reviewed-primary"
            },
            "id": "TENSION-SOURCE-AUTHORITY-01",
            "positionA": "The supplied report bibliography includes a social-platform post summarizing detector-bias claims.",
            "positionB": "A peer-reviewed primary study provides the appropriate bounded evidence for the detector-bias claim and reports dataset- and tool-specific results.",
            "publicWording": "Use the primary study for the public claim while retaining the original bibliography URL only as provenance.",
            "resolutionState": "authoritative-source-substituted-human-adjudication-pending",
            "reviewerDecision": null,
            "sourceIds": [
                "synthetic-persona-operations-s33"
            ],
            "title": "Aggregator or social-post references versus primary research"
        },
        {
            "categorySlugs": [
                "synthetic-persona-operations",
                "algorithmic-perception-control"
            ],
            "editorialResolution": "No single detector score may establish that an account or text is synthetic.",
            "evidenceStrength": {
                "positionA": "context-dependent-technical-capability",
                "positionB": "documented-false-positive-risk"
            },
            "id": "TENSION-DETECTION-BIAS-01",
            "positionA": "Automated detectors and behavioral signals can support triage when combined with provenance and network evidence.",
            "positionB": "Text and behavior detectors can misclassify non-native, neurodivergent, assisted, or highly formal human communication and should not be treated as conclusive identity evidence.",
            "publicWording": "Present automated signals as suggestive and require multi-signal human review before consequential action.",
            "resolutionState": "publication-wording-defined-human-adjudication-pending",
            "reviewerDecision": null,
            "sourceIds": [
                "synthetic-persona-operations-s33",
                "algorithmic-perception-control-s44"
            ],
            "title": "Detection utility versus false-positive and population-bias risk"
        },
        {
            "categorySlugs": [
                "personalized-influence",
                "emotional-behavioral-manipulation",
                "autonomous-influence-agents",
                "deepfake-psyops",
                "predictive-population-management"
            ],
            "editorialResolution": "Require source-specific currentness review by an authorized human before publication acceptance.",
            "evidenceStrength": {
                "positionA": "report-derived-legal-summary",
                "positionB": "currentness-recheck-required"
            },
            "id": "TENSION-LEGAL-CURRENTNESS-01",
            "positionA": "The reports identify statutes, regulations, enforcement actions, and litigation relevant to manipulative or synthetic AI systems.",
            "positionB": "Effective dates, amendments, injunctions, appeals, definitions, and remedies vary by jurisdiction and can change after the report date.",
            "publicWording": "Describe legal material as jurisdiction-specific and time-sensitive, and avoid presenting pending or preliminary matters as final holdings.",
            "resolutionState": "human-legal-currentness-review-required",
            "reviewerDecision": null,
            "sourceIds": [
                "personalized-influence-s12",
                "ai-generated-propaganda-s37",
                "deepfake-psyops-s30"
            ],
            "title": "Legal framework summaries versus current jurisdiction and procedural posture"
        }
    ],
    "categories": [
        {
            "capabilityStatus": [
                {
                    "label": "Confirmed real-world use",
                    "status": "confirmed",
                    "summary": "Reports from platforms and public authorities describe AI used for drafting, translation, persona support, research, and technical assistance in covert influence activity."
                },
                {
                    "label": "Demonstrated technical capability",
                    "status": "demonstrated",
                    "summary": "Controlled studies show that conversational models can be persuasive under bounded conditions, especially when given target information."
                },
                {
                    "label": "Effect remains uncertain",
                    "status": "uncertain",
                    "summary": "High output, reach, or engagement does not establish durable belief or behavior change."
                }
            ],
            "claimIds": [
                "AIP-01-0001",
                "AIP-01-0002",
                "AIP-01-0003",
                "AIP-01-0004",
                "AIP-01-0005",
                "AIP-01-0006",
                "AIP-01-0007",
                "AIP-01-0008",
                "AIP-01-0009",
                "AIP-01-0010",
                "AIP-01-0011",
                "AIP-01-0012",
                "AIP-01-0013",
                "AIP-01-0014",
                "AIP-01-0015",
                "AIP-01-0016",
                "AIP-01-0017",
                "AIP-01-0018",
                "AIP-01-0019",
                "AIP-01-0020",
                "AIP-01-0021",
                "AIP-01-0022",
                "AIP-01-0023",
                "AIP-01-0024",
                "AIP-01-0025",
                "AIP-01-0026",
                "AIP-01-0027",
                "AIP-01-0028",
                "AIP-01-0029",
                "AIP-01-0030",
                "AIP-01-0031",
                "AIP-01-0032",
                "AIP-01-0033",
                "AIP-01-0034",
                "AIP-01-0035",
                "AIP-01-0036",
                "AIP-01-0037",
                "AIP-01-0038",
                "AIP-01-0039",
                "AIP-01-0040",
                "AIP-01-0041"
            ],
            "comparison": {
                "autonomy": "Low",
                "mainHarm": "Scaled deceptive communication and faster campaign iteration",
                "primaryDefense": "Human accountability, source verification, and coordination analysis",
                "unit": "Group or population"
            },
            "defensiveConcerns": [
                "verification",
                "human-oversight",
                "platform-governance"
            ],
            "defensiveIndicators": [
                {
                    "caveat": "Coordination can also reflect legitimate campaigns or shared news events.",
                    "indicator": "Synchronized multilingual narrative changes across many accounts or sites."
                },
                {
                    "caveat": "This is strong evidence of automation error but not proof of a specific sponsor.",
                    "indicator": "Repeated artifacts showing model instructions or safety refusals in published content."
                },
                {
                    "caveat": "Professional communications teams also adapt quickly.",
                    "indicator": "Rapid content pivots immediately following audience reactions."
                }
            ],
            "definition": {
                "inScope": "Human-led psychological or strategic-influence activity in which AI supports bounded stages such as information synthesis, translation, content drafting, simulation, distribution support, or evaluation.",
                "outOfScope": "Fully autonomous systems choosing political objectives without human direction; transparent public communication is not automatically a psychological operation merely because AI assisted its production."
            },
            "domains": [
                "military",
                "political",
                "cross-domain"
            ],
            "evidenceMaturity": {
                "key": "documented",
                "label": "Documented current use",
                "rationale": "The report identifies confirmed use of generative AI by state-aligned and influence-for-hire operators, while noting that measured engagement and durable persuasion remain separate questions."
            },
            "evidenceTensionIds": [
                "TENSION-PERSUASION-01",
                "TENSION-REACH-01"
            ],
            "examples": [
                {
                    "confirmed": "Platform threat reporting confirmed AI use and disrupted the activity.",
                    "evidenceStatus": "Confirmed AI assistance",
                    "measuredEffect": "The report describes low organic engagement despite high production volume.",
                    "sourceIds": [
                        "ai-assisted-traditional-psyops-s6"
                    ],
                    "title": "STOIC / “Zero Zeno”",
                    "unknown": "Whether the campaign changed attitudes or behavior among people who saw it remains unestablished.",
                    "whatOccurred": "A commercial influence-for-hire operation used AI to generate articles, comments, and persona material across several countries."
                },
                {
                    "confirmed": "Public technical reporting documented the campaign and multilingual dissemination infrastructure.",
                    "evidenceStatus": "Confirmed AI assistance",
                    "measuredEffect": "Production scale and cross-language reach were observable.",
                    "sourceIds": [
                        "ai-assisted-traditional-psyops-s5"
                    ],
                    "title": "Doppelgänger",
                    "unknown": "Long-term persuasive effects and the contribution of AI relative to established human tradecraft remain uncertain.",
                    "whatOccurred": "A Russian-aligned operation used AI-supported translation, rewriting, and short-form content around cloned or deceptive media properties."
                }
            ],
            "howAiChangesIt": [
                "Faster synthesis of large information collections.",
                "Low-cost translation and localization, with continuing cultural-error risk.",
                "Rapid generation of multiple media variants.",
                "Simulation and message comparison before release, although synthetic audiences are not proof of real-world effects.",
                "Near-real-time monitoring that can encourage overreaction to weak engagement signals."
            ],
            "keyMechanisms": [
                "Machine-assisted audience and narrative analysis.",
                "Human-reviewed generation and localization.",
                "Synthetic pretesting and scenario comparison.",
                "Automated scheduling and measurement.",
                "Human approval and deployment remain the defining control point."
            ],
            "limitations": [
                "Current systems do not reliably understand cultural context.",
                "Synthetic audience simulations can amplify the assumptions placed into them.",
                "Engagement metrics are poor proxies for belief or behavior.",
                "Human strategic direction and infrastructure remain central in documented cases."
            ],
            "mechanisms": [
                "analysis",
                "content-generation",
                "translation",
                "measurement"
            ],
            "number": 1,
            "primaryLevel": "tool",
            "principalConcern": "AI can reduce production friction and accelerate feedback loops while human operators retain strategic intent and accountability.",
            "report": {
                "bibliographyEntries": 39,
                "bytes": 52378,
                "currentFactRecheckRequired": true,
                "independentlyReverified": false,
                "publicSummaryPath": "/docs/research/v100.0.46/ai-psyops-signed-editorial-review-boundary/ai-assisted-traditional-psyops.md",
                "sha256": "1eec5ce4b5e99479617b506bab22986821a10c3b4c8d6d6daba32b64d26623d1",
                "title": "AI-Assisted Psychological Operations Report"
            },
            "researchGaps": [
                "How much AI changes outcomes rather than production volume.",
                "When synthetic audience simulations generalize to real populations.",
                "How outsourced influence-for-hire markets change responsibility and attribution.",
                "Which oversight structures prevent automation bias in state and commercial settings."
            ],
            "risks": [
                "Hallucinated or culturally inappropriate content can create strategic backfire.",
                "Automation bias can cause operators to over-trust weak audience models.",
                "Faster production can overwhelm verification and moderation capacity.",
                "Attribution becomes harder when operations are outsourced or distributed."
            ],
            "safeguards": [
                "Maintain human legal and editorial approval for high-impact communications.",
                "Use independent source verification rather than model-generated citations.",
                "Audit audience models for cultural and sampling bias.",
                "Separate reach, engagement, attitude, and behavior metrics.",
                "Invest in network-level detection and transparent takedown reporting."
            ],
            "secondaryLevels": [],
            "shortDefinition": "Human planners retain strategic control while AI assists with research, translation, production, audience analysis, simulation, or measurement inside an established influence workflow.",
            "shortTitle": "AI-assisted traditional PSYOPS",
            "slug": "ai-assisted-traditional-psyops",
            "sourceIds": [
                "ai-assisted-traditional-psyops-s2",
                "ai-assisted-traditional-psyops-s5",
                "ai-assisted-traditional-psyops-s6",
                "ai-assisted-traditional-psyops-s8",
                "ai-assisted-traditional-psyops-s30"
            ],
            "title": "AI-Assisted Traditional Psychological Operations",
            "whyItMatters": [
                "The immediate change is organizational: tasks that once required large multilingual teams can be performed faster and at lower cost.",
                "The same systems can support lawful public communication or deceptive operations, so intent, attribution, consent, and oversight remain decisive."
            ]
        },
        {
            "capabilityStatus": [
                {
                    "label": "Confirmed real-world use",
                    "status": "confirmed",
                    "summary": "Threat reporting and investigations document AI-generated or AI-rewritten propaganda in state-aligned operations and election-related incidents."
                },
                {
                    "label": "Demonstrated persuasion",
                    "status": "demonstrated",
                    "summary": "Controlled experiments cited by the report found AI-generated propaganda could be about as persuasive as human-written material in the tested settings."
                },
                {
                    "label": "Population effects uncertain",
                    "status": "uncertain",
                    "summary": "Distribution and engagement do not establish durable political or behavioral change."
                }
            ],
            "claimIds": [
                "AIP-02-0042",
                "AIP-02-0043",
                "AIP-02-0044",
                "AIP-02-0045",
                "AIP-02-0046",
                "AIP-02-0047",
                "AIP-02-0048",
                "AIP-02-0049",
                "AIP-02-0050",
                "AIP-02-0051",
                "AIP-02-0052",
                "AIP-02-0053",
                "AIP-02-0054",
                "AIP-02-0055",
                "AIP-02-0056",
                "AIP-02-0057",
                "AIP-02-0058",
                "AIP-02-0059",
                "AIP-02-0060",
                "AIP-02-0061",
                "AIP-02-0062",
                "AIP-02-0063",
                "AIP-02-0064",
                "AIP-02-0065",
                "AIP-02-0066",
                "AIP-02-0067",
                "AIP-02-0068",
                "AIP-02-0069",
                "AIP-02-0070",
                "AIP-02-0071",
                "AIP-02-0072",
                "AIP-02-0073",
                "AIP-02-0074",
                "AIP-02-0075",
                "AIP-02-0076",
                "AIP-02-0077",
                "AIP-02-0078",
                "AIP-02-0079",
                "AIP-02-0080",
                "AIP-02-0081",
                "AIP-02-0082"
            ],
            "comparison": {
                "autonomy": "Low to medium",
                "mainHarm": "Cheap, rapid synthetic propaganda and declining trust in evidence",
                "primaryDefense": "Source authentication, rapid verification, and narrative-level response",
                "unit": "Group or population"
            },
            "defensiveConcerns": [
                "verification",
                "provenance",
                "platform-governance",
                "resilience"
            ],
            "defensiveIndicators": [
                {
                    "caveat": "Shared themes can also arise organically after major events.",
                    "indicator": "Large clusters of stylistically varied content repeating one narrative."
                },
                {
                    "caveat": "Missing provenance does not prove fabrication.",
                    "indicator": "Synthetic media without a verifiable source trail."
                },
                {
                    "caveat": "Each signal requires corroboration before attribution.",
                    "indicator": "News-like sites with copied layouts, weak ownership records, and coordinated distribution."
                }
            ],
            "definition": {
                "inScope": "Organized persuasive communication in which AI generates or substantially transforms content intended to advance a political, military, ideological, commercial, or organizational objective.",
                "outOfScope": "All synthetic media, satire, ordinary advertising, or accidental misinformation; propaganda requires organized purpose and context."
            },
            "domains": [
                "political",
                "military",
                "commercial",
                "cross-domain"
            ],
            "evidenceMaturity": {
                "key": "documented",
                "label": "Documented current use",
                "rationale": "The report identifies confirmed AI-assisted propaganda production and controlled evidence that AI text can match human-written propaganda in short-term persuasion studies."
            },
            "evidenceTensionIds": [
                "TENSION-PROVENANCE-01",
                "TENSION-REACH-01",
                "TENSION-LAW-01"
            ],
            "examples": [
                {
                    "confirmed": "Researchers identified a transition to AI-assisted rewriting and model artifacts in published material.",
                    "evidenceStatus": "Confirmed AI assistance",
                    "measuredEffect": "Output volume and topic breadth increased; experimental work found retained short-term persuasiveness.",
                    "sourceIds": [
                        "ai-generated-propaganda-s8",
                        "ai-generated-propaganda-s9"
                    ],
                    "title": "CopyCop / DC Weekly",
                    "unknown": "The degree of durable attitude or voting change remains unknown.",
                    "whatOccurred": "A network used generative systems to rewrite and expand news-like content in support of strategic narratives."
                },
                {
                    "confirmed": "Investigations attributed the call operation and established use of voice cloning.",
                    "evidenceStatus": "Confirmed synthetic audio",
                    "measuredEffect": "Thousands of calls were placed and enforcement action followed.",
                    "sourceIds": [
                        "ai-generated-propaganda-s41"
                    ],
                    "title": "New Hampshire primary robocall",
                    "unknown": "The number of voters whose behavior changed cannot be reliably isolated.",
                    "whatOccurred": "Voters received robocalls using a cloned presidential voice that told them not to participate in the primary."
                }
            ],
            "howAiChangesIt": [
                "Industrial-scale text and media production.",
                "Rapid localization across languages and communities.",
                "Fast response during breaking-news information gaps.",
                "High-volume variation that defeats simple duplicate matching.",
                "Creation of synthetic “news” formats and fabricated documentary artifacts."
            ],
            "keyMechanisms": [
                "Automated article and social-post generation.",
                "Synthetic image, audio, and video production.",
                "Localization and rhetorical reframing.",
                "Artificial consensus through many variants.",
                "Credibility laundering through familiar media formats."
            ],
            "limitations": [
                "High volume often produces little organic engagement.",
                "AI output can contain factual and cultural errors.",
                "Quality varies substantially by modality and human oversight.",
                "Persuasion effects depend on source, prior belief, timing, and context."
            ],
            "mechanisms": [
                "content-generation",
                "localization",
                "synthetic-media",
                "amplification"
            ],
            "number": 2,
            "primaryLevel": "tool",
            "principalConcern": "Generative AI sharply lowers the cost of producing plausible, localized propaganda and contributes to uncertainty about authentic evidence.",
            "report": {
                "bibliographyEntries": 55,
                "bytes": 57697,
                "currentFactRecheckRequired": true,
                "independentlyReverified": false,
                "publicSummaryPath": "/docs/research/v100.0.46/ai-psyops-signed-editorial-review-boundary/ai-generated-propaganda.md",
                "sha256": "c58150bf3ec9bcbd3312190a8119bf00c7a973b3f809b56301edb9c8e2e7a212",
                "title": "AI Propaganda Research Report"
            },
            "researchGaps": [
                "Long-term behavioral impact of AI-generated propaganda.",
                "How disclosure labels affect true and false content differently.",
                "Robust provenance after reposting, compression, or screenshotting.",
                "How generative media changes the liar’s dividend across political contexts."
            ],
            "risks": [
                "Volume can outpace verification and newsroom response.",
                "Synthetic content can exploit crisis timing and existing prejudice.",
                "False accusations of deepfakery can shield authentic misconduct.",
                "Labels and detectors can create false confidence or reduce trust in accurate content."
            ],
            "safeguards": [
                "Publish authentic media through trusted, signed channels.",
                "Use narrative-level triage instead of attempting to debunk every variant.",
                "Preserve evidence and disclose attribution confidence.",
                "Support provenance while acknowledging metadata stripping and false negatives.",
                "Teach audiences that AI labels and detection scores are not verdicts."
            ],
            "secondaryLevels": [
                "operator"
            ],
            "shortDefinition": "Generative systems create or substantially transform propaganda text, images, audio, video, memes, documents, or synthetic news formats for an organized objective.",
            "shortTitle": "AI-generated propaganda",
            "slug": "ai-generated-propaganda",
            "sourceIds": [
                "ai-generated-propaganda-s2",
                "ai-generated-propaganda-s8",
                "ai-generated-propaganda-s25",
                "ai-generated-propaganda-s37",
                "ai-generated-propaganda-s35",
                "ai-generated-propaganda-s9",
                "ai-generated-propaganda-s41"
            ],
            "title": "AI-Generated Propaganda",
            "whyItMatters": [
                "AI changes the economics of propaganda by making variation, translation, and rapid crisis response inexpensive.",
                "The broader harm includes the liar’s dividend: authentic evidence can be dismissed as synthetic once audiences know convincing fakes are possible."
            ]
        },
        {
            "capabilityStatus": [
                {
                    "label": "Confirmed profiling and targeting",
                    "status": "confirmed",
                    "summary": "Commercial and political systems routinely segment and personalize based on behavioral and demographic data."
                },
                {
                    "label": "Demonstrated generic AI persuasion",
                    "status": "demonstrated",
                    "summary": "LLM-generated messages can be persuasive in controlled settings."
                },
                {
                    "label": "Personalization advantage contested",
                    "status": "contested",
                    "summary": "The report cites meta-analytic and experimental evidence that the incremental benefit of personality-based targeting may approach zero after correcting methodological problems."
                }
            ],
            "claimIds": [
                "AIP-03-0083",
                "AIP-03-0084",
                "AIP-03-0085",
                "AIP-03-0086",
                "AIP-03-0087",
                "AIP-03-0088",
                "AIP-03-0089",
                "AIP-03-0090",
                "AIP-03-0091",
                "AIP-03-0092",
                "AIP-03-0093",
                "AIP-03-0094",
                "AIP-03-0095",
                "AIP-03-0096",
                "AIP-03-0097",
                "AIP-03-0098",
                "AIP-03-0099",
                "AIP-03-0100",
                "AIP-03-0101",
                "AIP-03-0102",
                "AIP-03-0103",
                "AIP-03-0104",
                "AIP-03-0105",
                "AIP-03-0106",
                "AIP-03-0107",
                "AIP-03-0108",
                "AIP-03-0109",
                "AIP-03-0110",
                "AIP-03-0111",
                "AIP-03-0112",
                "AIP-03-0113",
                "AIP-03-0114",
                "AIP-03-0115",
                "AIP-03-0116",
                "AIP-03-0117",
                "AIP-03-0118",
                "AIP-03-0119",
                "AIP-03-0120",
                "AIP-03-0121",
                "AIP-03-0122",
                "AIP-03-0123",
                "AIP-03-0124"
            ],
            "comparison": {
                "autonomy": "Medium",
                "mainHarm": "Privacy asymmetry, discriminatory profiling, and vulnerability exploitation",
                "primaryDefense": "Data minimization, transparency, and independent auditing",
                "unit": "Individual"
            },
            "defensiveConcerns": [
                "privacy",
                "transparency",
                "regulation",
                "human-oversight"
            ],
            "defensiveIndicators": [
                {
                    "caveat": "The detail could come from ordinary account history, a breach, or human knowledge.",
                    "indicator": "Messages make unusually specific reference to private or recent life events."
                },
                {
                    "caveat": "Adaptive customer support can behave similarly without manipulative intent.",
                    "indicator": "A system changes framing or pressure immediately after hesitation."
                },
                {
                    "caveat": "Variation alone does not establish harmful targeting.",
                    "indicator": "Users receive materially different political claims without a public archive."
                }
            ],
            "definition": {
                "inScope": "Organized attempts to influence a person using collected or inferred attributes, tailored communication, and adaptive feedback.",
                "outOfScope": "User-directed customization and transparent recommendations that support the user’s stated goal without covert vulnerability exploitation."
            },
            "domains": [
                "political",
                "commercial",
                "criminal",
                "social",
                "cross-domain"
            ],
            "evidenceMaturity": {
                "key": "contested",
                "label": "Evidence contested or incomplete",
                "rationale": "The report finds strong evidence of profiling and privacy harm, but recent rigorous reviews question whether psychographic tailoring adds meaningful persuasion over strong generic messages."
            },
            "evidenceTensionIds": [
                "TENSION-PERSUASION-01",
                "TENSION-LAW-01",
                "TENSION-LEGAL-CURRENTNESS-01"
            ],
            "examples": [
                {
                    "confirmed": "Large-scale data-protection violations and covert processing were documented.",
                    "evidenceStatus": "Data use confirmed; persuasive effect unproven",
                    "measuredEffect": "Regulatory and public-trust consequences were substantial.",
                    "sourceIds": [
                        "personalized-influence-s32"
                    ],
                    "title": "Cambridge Analytica",
                    "unknown": "Investigations did not establish that psychographic targeting changed the Brexit or U.S. election result.",
                    "whatOccurred": "Facebook data was harvested and used for political profiling and targeting claims."
                },
                {
                    "confirmed": "AI-generated messages were persuasive in the study.",
                    "evidenceStatus": "Controlled experiment",
                    "measuredEffect": "Tailored messages did not show a statistically reliable advantage over generic AI messages.",
                    "sourceIds": [
                        "personalized-influence-s3"
                    ],
                    "title": "LLM political microtargeting experiment",
                    "unknown": "Longer multi-turn interaction and different populations require further study.",
                    "whatOccurred": "Researchers compared generic and individually tailored political messages generated by language models."
                }
            ],
            "howAiChangesIt": [
                "Automates individualized message drafting.",
                "Combines many data sources into inferred profiles.",
                "Adapts tone and content after each response.",
                "Tests message variants continuously.",
                "Can target temporary distress or life events rather than stable traits."
            ],
            "keyMechanisms": [
                "Collection of demographic, behavioral, network, and contextual data.",
                "Inference of interests or temporary vulnerability.",
                "Message selection or generation.",
                "Feedback-based optimization.",
                "Cross-platform identity and data linkage."
            ],
            "limitations": [
                "Personality inference from digital traces is weaker than commonly claimed.",
                "Emotion recognition from faces or voices lacks reliable scientific foundation.",
                "Models may confuse correlation with causation.",
                "Targets and auditors often cannot see the messages delivered to others."
            ],
            "mechanisms": [
                "personalization",
                "profiling",
                "adaptation",
                "prediction"
            ],
            "number": 3,
            "primaryLevel": "operator",
            "principalConcern": "The most established harm is covert data asymmetry and vulnerability exploitation, not reliable “mind control” through personality targeting.",
            "report": {
                "bibliographyEntries": 49,
                "bytes": 55290,
                "currentFactRecheckRequired": true,
                "independentlyReverified": false,
                "publicSummaryPath": "/docs/research/v100.0.46/ai-psyops-signed-editorial-review-boundary/personalized-influence.md",
                "sha256": "bf995b7a6534a228e3447c88b7bc028df28b2644d1f72f9d74feecb824d4f826",
                "title": "AI Personalized Influence Operations"
            },
            "researchGaps": [
                "Multi-turn adaptive persuasion outside laboratory settings.",
                "Effects on vulnerable subgroups rather than population averages.",
                "Auditing personalized messages without collecting more sensitive data.",
                "How temporary life events alter susceptibility and risk."
            ],
            "risks": [
                "Covert processing undermines informed choice.",
                "Weak inferences can produce discriminatory stereotypes.",
                "Temporary distress can be exploited at high-stakes moments.",
                "Personalization can fragment the public sphere and make scrutiny difficult."
            ],
            "safeguards": [
                "Data minimization and restrictions on sensitive inference.",
                "Transparent “why am I seeing this?” explanations.",
                "Public political-ad libraries with meaningful targeting information.",
                "Independent audits and researcher access.",
                "Prohibit or strictly limit emotion inference and exploitation of vulnerable groups.",
                "Make contextual rather than behavioral advertising the default where feasible."
            ],
            "secondaryLevels": [
                "tool",
                "environment"
            ],
            "shortDefinition": "AI systems tailor messages or interactions to information collected or inferred about a person, then may adapt the communication using ongoing feedback.",
            "shortTitle": "Personalized influence",
            "slug": "personalized-influence",
            "sourceIds": [
                "personalized-influence-s1",
                "personalized-influence-s3",
                "personalized-influence-s4",
                "personalized-influence-s5",
                "personalized-influence-s6",
                "personalized-influence-s12",
                "personalized-influence-s32",
                "personalized-influence-s46"
            ],
            "title": "AI-Driven Personalized Influence Operations",
            "whyItMatters": [
                "Even weak profiling can be intrusive, discriminatory, and difficult to contest when it shapes political, financial, or interpersonal treatment.",
                "Generative systems make individualized communication inexpensive, but the claimed persuasive advantage of psychographic matching is much less certain than marketing narratives suggest."
            ]
        },
        {
            "capabilityStatus": [
                {
                    "label": "Short-term capabilities established",
                    "status": "confirmed",
                    "summary": "Models generate persuasive text, use tools, and sustain bounded multi-turn interaction."
                },
                {
                    "label": "Sandboxed coordination demonstrated",
                    "status": "demonstrated",
                    "summary": "Synthetic social networks and laboratory multi-agent systems show role division and emergent interaction."
                },
                {
                    "label": "Long-horizon autonomy speculative",
                    "status": "speculative",
                    "summary": "Multi-month strategic coherence, infrastructure management, and reliable evasion without human intervention remain unsupported."
                }
            ],
            "claimIds": [
                "AIP-04-0125",
                "AIP-04-0126",
                "AIP-04-0127",
                "AIP-04-0128",
                "AIP-04-0129",
                "AIP-04-0130",
                "AIP-04-0131",
                "AIP-04-0132",
                "AIP-04-0133",
                "AIP-04-0134",
                "AIP-04-0135",
                "AIP-04-0136",
                "AIP-04-0137",
                "AIP-04-0138",
                "AIP-04-0139",
                "AIP-04-0140",
                "AIP-04-0141",
                "AIP-04-0142",
                "AIP-04-0143",
                "AIP-04-0144",
                "AIP-04-0145",
                "AIP-04-0146",
                "AIP-04-0147",
                "AIP-04-0148",
                "AIP-04-0149",
                "AIP-04-0150",
                "AIP-04-0151",
                "AIP-04-0152",
                "AIP-04-0153",
                "AIP-04-0154",
                "AIP-04-0155",
                "AIP-04-0156",
                "AIP-04-0157",
                "AIP-04-0158",
                "AIP-04-0159",
                "AIP-04-0160",
                "AIP-04-0161",
                "AIP-04-0162",
                "AIP-04-0163",
                "AIP-04-0164",
                "AIP-04-0165",
                "AIP-04-0166"
            ],
            "comparison": {
                "autonomy": "Medium to potentially high",
                "mainHarm": "Persistent adaptive interaction linked to real tools and synthetic coordination",
                "primaryDefense": "Disclosure, least privilege, rate limits, and human approval gates",
                "unit": "Individual or group"
            },
            "defensiveConcerns": [
                "human-oversight",
                "authentication",
                "platform-governance",
                "verification"
            ],
            "defensiveIndicators": [
                {
                    "caveat": "Humans and legitimate bots can also change behavior.",
                    "indicator": "Persistent accounts exhibit abrupt memory or persona discontinuities."
                },
                {
                    "caveat": "Formal organizations may coordinate lawfully.",
                    "indicator": "Accounts divide roles in a highly regular interaction pattern."
                },
                {
                    "caveat": "Scheduled accessibility and support tools can look similar.",
                    "indicator": "Tool actions occur at machine speed or outside plausible human schedules."
                }
            ],
            "definition": {
                "inScope": "Software systems that pursue an influence-related goal through repeated communication or online action with limited ongoing direction.",
                "outOfScope": "Simple scheduled bots, human-authored posts distributed automatically, or ordinary customer-service systems with tightly bounded rules."
            },
            "domains": [
                "political",
                "commercial",
                "criminal",
                "social",
                "cross-domain"
            ],
            "evidenceMaturity": {
                "key": "emerging",
                "label": "Emerging capability",
                "rationale": "Short-term persuasion, tool use, and sandboxed multi-agent interaction are demonstrated; durable autonomous strategy across hostile real-world environments remains unproven."
            },
            "evidenceTensionIds": [
                "TENSION-AUTONOMY-01",
                "TENSION-CAPABILITY-PREVALENCE-01",
                "TENSION-LEGAL-CURRENTNESS-01"
            ],
            "examples": [
                {
                    "confirmed": "Researchers observed large-scale autonomous posting and social-network patterns.",
                    "evidenceStatus": "Demonstrated in a sandboxed platform",
                    "measuredEffect": "The system demonstrated synthetic interaction and emergent toxic behavior.",
                    "sourceIds": [
                        "autonomous-influence-agents-s22"
                    ],
                    "title": "Chirper.ai synthetic social network",
                    "unknown": "It did not prove reliable deployment or moderation evasion on real social platforms.",
                    "whatOccurred": "Thousands of LLM-driven accounts interacted in a synthetic social network after initial configuration."
                },
                {
                    "confirmed": "Platform threat reporting documented the use of AI services.",
                    "evidenceStatus": "Confirmed AI use; low autonomy",
                    "measuredEffect": "The activity demonstrated human-directed generation and research assistance.",
                    "sourceIds": [
                        "autonomous-influence-agents-s23",
                        "autonomous-influence-agents-s24"
                    ],
                    "title": "PRC-linked AI debate operations",
                    "unknown": "The models did not independently operate accounts or set strategy; real autonomy was low.",
                    "whatOccurred": "Operators used AI to generate and adapt content around U.S. technology and trade debates."
                }
            ],
            "howAiChangesIt": [
                "Persistent memory and persona continuity.",
                "Planning loops and tool invocation.",
                "Continuous interaction at machine scale.",
                "Coordination among specialized agents.",
                "Feedback-based strategy revision in bounded environments."
            ],
            "keyMechanisms": [
                "Observation and profile maintenance.",
                "Working and long-term memory.",
                "Plan–act–evaluate loops.",
                "Bounded external tool access.",
                "Role division among multiple agents."
            ],
            "limitations": [
                "Attention and reasoning degrade across long tasks.",
                "Memory retrieval can become stale or noisy.",
                "Models are vulnerable to prompt injection and goal drift.",
                "Real-world campaigns still require human infrastructure and oversight."
            ],
            "mechanisms": [
                "automation",
                "memory",
                "tool-use",
                "adaptation",
                "coordination"
            ],
            "number": 4,
            "primaryLevel": "operator",
            "principalConcern": "Agentic systems combine communication with memory and action, but current long-horizon reliability is much weaker than fluent short-term behavior suggests.",
            "report": {
                "bibliographyEntries": 49,
                "bytes": 50685,
                "currentFactRecheckRequired": true,
                "independentlyReverified": false,
                "publicSummaryPath": "/docs/research/v100.0.46/ai-psyops-signed-editorial-review-boundary/autonomous-influence-agents.md",
                "sha256": "a0abead7fbd0b6ae977424f2990ac6e5c76acc3c9d7bdae5420380e81704900f",
                "title": "AI Influence Agents Research"
            },
            "researchGaps": [
                "Reliable measurement of long-horizon strategic coherence.",
                "Detection of agents that deliberately vary behavior.",
                "Governance responsibility across model provider, developer, deployer, and platform.",
                "Safe evaluation of persuasion without exposing real users."
            ],
            "risks": [
                "Tool permissions can turn persuasive interaction into real action.",
                "Persistent memory can accumulate sensitive information or be poisoned.",
                "Multi-agent coordination can fabricate social proof.",
                "Long-running agents can drift, hallucinate, or become sycophantic."
            ],
            "safeguards": [
                "Require clear AI identity disclosure.",
                "Use least-privilege, short-lived tool permissions.",
                "Limit execution steps and require reauthorization.",
                "Keep immutable audit records without storing private content unnecessarily.",
                "Provide emergency suspension and state rollback.",
                "Evaluate agents in sandboxes rather than on unwitting populations."
            ],
            "secondaryLevels": [],
            "shortDefinition": "Goal-directed software agents observe, remember, plan, communicate, use tools, and adapt toward an influence objective with varying degrees of human supervision.",
            "shortTitle": "Autonomous influence agents",
            "slug": "autonomous-influence-agents",
            "sourceIds": [
                "autonomous-influence-agents-s1",
                "autonomous-influence-agents-s4",
                "autonomous-influence-agents-s13",
                "autonomous-influence-agents-s22",
                "autonomous-influence-agents-s23",
                "autonomous-influence-agents-s24",
                "autonomous-influence-agents-s27",
                "autonomous-influence-agents-s34"
            ],
            "title": "Autonomous AI Influence Agents",
            "whyItMatters": [
                "Agents can sustain many interactions and connect language generation to tools, accounts, and data.",
                "The risk grows with memory, permissions, coordination, and the ability to revise strategies, but fluent messages should not be mistaken for durable autonomy."
            ]
        },
        {
            "capabilityStatus": [
                {
                    "label": "Confirmed identity fabrication",
                    "status": "confirmed",
                    "summary": "Investigations document AI-generated profile images, synthetic presenters, and deepfake-assisted remote impersonation."
                },
                {
                    "label": "Scaled persona generation demonstrated",
                    "status": "demonstrated",
                    "summary": "Research systems can generate diverse persona populations, although realism and long-term consistency vary."
                },
                {
                    "label": "Long-term credibility uneven",
                    "status": "uncertain",
                    "summary": "Physical-world records, live interaction, and coherent history remain difficult to fabricate consistently."
                }
            ],
            "claimIds": [
                "AIP-05-0167",
                "AIP-05-0168",
                "AIP-05-0169",
                "AIP-05-0170",
                "AIP-05-0171",
                "AIP-05-0172",
                "AIP-05-0173",
                "AIP-05-0174",
                "AIP-05-0175",
                "AIP-05-0176",
                "AIP-05-0177",
                "AIP-05-0178",
                "AIP-05-0179",
                "AIP-05-0180",
                "AIP-05-0181",
                "AIP-05-0182",
                "AIP-05-0183",
                "AIP-05-0184",
                "AIP-05-0185",
                "AIP-05-0186",
                "AIP-05-0187",
                "AIP-05-0188",
                "AIP-05-0189",
                "AIP-05-0190",
                "AIP-05-0191",
                "AIP-05-0192",
                "AIP-05-0193",
                "AIP-05-0194",
                "AIP-05-0195",
                "AIP-05-0196",
                "AIP-05-0197",
                "AIP-05-0198",
                "AIP-05-0199",
                "AIP-05-0200",
                "AIP-05-0201",
                "AIP-05-0202",
                "AIP-05-0203",
                "AIP-05-0204",
                "AIP-05-0205",
                "AIP-05-0206",
                "AIP-05-0207",
                "AIP-05-0208"
            ],
            "comparison": {
                "autonomy": "Medium",
                "mainHarm": "Deceptive trust, infiltration, and fabricated consensus",
                "primaryDefense": "Layered identity assurance, network analysis, and fair appeals",
                "unit": "Individual, group, or institution"
            },
            "defensiveConcerns": [
                "authentication",
                "platform-governance",
                "civil-liberties",
                "verification"
            ],
            "defensiveIndicators": [
                {
                    "caveat": "People make mistakes, change roles, or use satire.",
                    "indicator": "Conflicting biography or credential claims across time and platforms."
                },
                {
                    "caveat": "Legitimate new communities can grow quickly.",
                    "indicator": "Dense new-account clusters that mutually reinforce credibility."
                },
                {
                    "caveat": "Most authentic images also lack cryptographic provenance.",
                    "indicator": "Identity imagery lacks a verifiable provenance trail."
                }
            ],
            "definition": {
                "inScope": "Fabricated or substantially fictional identities presented as real people, experts, organizations, witnesses, activists, journalists, or community members for a deceptive objective.",
                "outOfScope": "Transparent avatars, ordinary pseudonyms used by real people, satire, disclosed role-play, and legitimate accessibility bots."
            },
            "domains": [
                "political",
                "criminal",
                "commercial",
                "social",
                "cross-domain"
            ],
            "evidenceMaturity": {
                "key": "documented",
                "label": "Documented current use",
                "rationale": "The report describes confirmed AI-generated identity assets and AI-assisted impersonation in political, influence, and corporate-infiltration cases."
            },
            "evidenceTensionIds": [
                "TENSION-REACH-01",
                "TENSION-CAPABILITY-PREVALENCE-01",
                "TENSION-SOURCE-AUTHORITY-01",
                "TENSION-DETECTION-BIAS-01"
            ],
            "examples": [
                {
                    "confirmed": "Investigators found the person did not exist and the image showed GAN-generation indicators.",
                    "evidenceStatus": "Synthetic identity confirmed; text assistance alleged",
                    "measuredEffect": "The persona obtained publication and reputational reach.",
                    "sourceIds": [
                        "synthetic-persona-operations-s7"
                    ],
                    "title": "Oliver Taylor",
                    "unknown": "Whether article text was AI-generated was not conclusively established.",
                    "whatOccurred": "A nonexistent “student journalist” published accusations through recognized outlets using a generated profile image."
                },
                {
                    "confirmed": "Public corporate and government reporting documented infiltrations and synthetic identity assets.",
                    "evidenceStatus": "Confirmed AI-assisted identity deception",
                    "measuredEffect": "Some operatives reached enterprise onboarding and network access.",
                    "sourceIds": [
                        "synthetic-persona-operations-s9"
                    ],
                    "title": "DPRK remote-worker infiltration",
                    "unknown": "Public reporting does not reveal every tool or the full scale of successful placements.",
                    "whatOccurred": "Operatives used false or stolen identities, AI-generated images, and remote-interview deception to obtain employment."
                }
            ],
            "howAiChangesIt": [
                "Creates unique face and voice assets.",
                "Maintains biographies and linguistic style.",
                "Localizes personas across cultures and languages.",
                "Generates routine background activity.",
                "Allows many identities to interact and reinforce one another."
            ],
            "keyMechanisms": [
                "Generated identity assets.",
                "Fabricated biography and credentials.",
                "Language and cultural mirroring.",
                "Networked credibility and artificial consensus.",
                "Cross-platform reuse or identity theft."
            ],
            "limitations": [
                "Long-term biographical consistency remains fragile.",
                "Live video and offline verification can expose anomalies.",
                "Authentic humans may share the same linguistic or behavioral signals as models.",
                "Mandatory real-name systems can create serious civil-liberties harms."
            ],
            "mechanisms": [
                "identity-fabrication",
                "social-proof",
                "automation",
                "localization"
            ],
            "number": 5,
            "primaryLevel": "operator",
            "principalConcern": "AI lowers the cost of maintaining convincing fictional identities while automated detection can wrongly accuse legitimate anonymous or non-native users.",
            "report": {
                "bibliographyEntries": 43,
                "bytes": 54193,
                "currentFactRecheckRequired": true,
                "independentlyReverified": false,
                "publicSummaryPath": "/docs/research/v100.0.46/ai-psyops-signed-editorial-review-boundary/synthetic-persona-operations.md",
                "sha256": "110e635da77e17d873c53c061cd7ef9345314a06bb70950a5dbdb164451cebe2",
                "title": "AI Synthetic Persona Operations Report"
            },
            "researchGaps": [
                "Fair detection with acceptable false-positive rates.",
                "Long-term synthetic identity maintenance in adversarial environments.",
                "How communities recover trust after an infiltration.",
                "Proportional identity assurance that preserves anonymity and dissent."
            ],
            "risks": [
                "Fabricated experts or community members can gain trust and launder claims.",
                "Networks can manufacture popularity and agreement.",
                "Identity assets support fraud and enterprise access.",
                "AI detectors can discriminate against non-native and neurodivergent users."
            ],
            "safeguards": [
                "Use risk-based, context-specific verification rather than universal real-name mandates.",
                "Combine content, behavior, network, and infrastructure signals.",
                "Provide appeals before punitive action.",
                "Protect legitimate pseudonymity.",
                "Document attribution confidence and preserve forensic evidence.",
                "Use out-of-band verification for high-stakes employment or financial access."
            ],
            "secondaryLevels": [
                "tool"
            ],
            "shortDefinition": "Fabricated identities use generated images, biographies, voices, and language to appear human, gain trust, infiltrate communities, or manufacture consensus.",
            "shortTitle": "Synthetic persona operations",
            "slug": "synthetic-persona-operations",
            "sourceIds": [
                "synthetic-persona-operations-s4",
                "synthetic-persona-operations-s31",
                "synthetic-persona-operations-s33",
                "synthetic-persona-operations-s38",
                "synthetic-persona-operations-s7",
                "synthetic-persona-operations-s9"
            ],
            "title": "Synthetic Persona Operations",
            "whyItMatters": [
                "People normally default to assuming social partners are genuine, and online environments provide fewer cues for checking identity.",
                "Synthetic identity networks can borrow credibility from one another, while overbroad identity verification can endanger whistleblowers and dissidents."
            ]
        },
        {
            "capabilityStatus": [
                {
                    "label": "AI-assisted networks documented",
                    "status": "confirmed",
                    "summary": "CopyCop, Doppelgänger, and related operations used generative systems for content production and localization."
                },
                {
                    "label": "Multi-agent behavior demonstrated",
                    "status": "demonstrated",
                    "summary": "Academic simulations show coordinated role behavior and complex opinion dynamics in controlled environments."
                },
                {
                    "label": "Fully autonomous swarms prospective",
                    "status": "speculative",
                    "summary": "Human operators still set strategic objectives and maintain infrastructure in public cases."
                }
            ],
            "claimIds": [
                "AIP-06-0209",
                "AIP-06-0210",
                "AIP-06-0211",
                "AIP-06-0212",
                "AIP-06-0213",
                "AIP-06-0214",
                "AIP-06-0215",
                "AIP-06-0216",
                "AIP-06-0217",
                "AIP-06-0218",
                "AIP-06-0219",
                "AIP-06-0220",
                "AIP-06-0221",
                "AIP-06-0222",
                "AIP-06-0223",
                "AIP-06-0224",
                "AIP-06-0225",
                "AIP-06-0226",
                "AIP-06-0227",
                "AIP-06-0228",
                "AIP-06-0229",
                "AIP-06-0230",
                "AIP-06-0231",
                "AIP-06-0232",
                "AIP-06-0233",
                "AIP-06-0234",
                "AIP-06-0235",
                "AIP-06-0236",
                "AIP-06-0237",
                "AIP-06-0238",
                "AIP-06-0239",
                "AIP-06-0240",
                "AIP-06-0241",
                "AIP-06-0242",
                "AIP-06-0243",
                "AIP-06-0244",
                "AIP-06-0245",
                "AIP-06-0246",
                "AIP-06-0247",
                "AIP-06-0248",
                "AIP-06-0249"
            ],
            "comparison": {
                "autonomy": "Medium",
                "mainHarm": "Synthetic consensus, noise, and verification overload",
                "primaryDefense": "Network-level detection, friction, and researcher access",
                "unit": "Group or population"
            },
            "defensiveConcerns": [
                "platform-governance",
                "researcher-access",
                "resilience",
                "verification"
            ],
            "defensiveIndicators": [
                {
                    "caveat": "News events and organized advocacy can also produce synchronized sharing.",
                    "indicator": "Many accounts share the same infrastructure or links in statistically synchronized windows."
                },
                {
                    "caveat": "Role patterns require network-wide evidence, not interpretation of one thread.",
                    "indicator": "Accounts enact recurring roles such as provocateur, skeptic, and confirmer."
                },
                {
                    "caveat": "Organic communities also paraphrase popular claims.",
                    "indicator": "Narratives mutate rapidly while retaining a common strategic premise."
                }
            ],
            "definition": {
                "inScope": "Networks that coordinate many changing messages, identities, and media properties to amplify narratives, simulate debate, or overwhelm verification.",
                "outOfScope": "Ordinary viral misinformation, genuine decentralized activism, conventional spam, or simple copy-paste botnets without adaptive coordination."
            },
            "domains": [
                "political",
                "military",
                "social",
                "cross-domain"
            ],
            "evidenceMaturity": {
                "key": "mixed",
                "label": "Mixed evidence",
                "rationale": "AI-assisted coordinated networks are documented, while fully autonomous, strategically coherent swarms are mainly demonstrated in simulations or described prospectively."
            },
            "evidenceTensionIds": [
                "TENSION-AUTONOMY-01",
                "TENSION-REACH-01",
                "TENSION-CAPABILITY-PREVALENCE-01"
            ],
            "examples": [
                {
                    "confirmed": "Investigators documented model artifacts, self-hosted generation, and a broad site network.",
                    "evidenceStatus": "Confirmed AI-assisted coordinated network",
                    "measuredEffect": "Production scale and search/distribution presence increased.",
                    "sourceIds": [
                        "disinformation-swarms-s14",
                        "disinformation-swarms-s15"
                    ],
                    "title": "CopyCop",
                    "unknown": "The degree of organic persuasion and the autonomy of coordination remain uncertain.",
                    "whatOccurred": "A network of news-like sites rewrote and distributed politically slanted content at scale."
                },
                {
                    "confirmed": "Government and platform reporting documented infrastructure and AI-assisted content functions.",
                    "evidenceStatus": "Confirmed coordinated influence operation",
                    "measuredEffect": "High volume and persistent reconstitution were observed.",
                    "sourceIds": [
                        "disinformation-swarms-s11"
                    ],
                    "title": "Doppelgänger",
                    "unknown": "Public evidence indicates limited organic engagement in many instances and does not prove broad behavior change.",
                    "whatOccurred": "Cloned media properties and large account networks distributed multilingual narratives."
                }
            ],
            "howAiChangesIt": [
                "Generates many semantic variants of one narrative.",
                "Supports role division across accounts.",
                "Automates cross-platform adaptation.",
                "Creates artificial debate and apparent conversion.",
                "Responds quickly to moderation and breaking events."
            ],
            "keyMechanisms": [
                "Narrative variation.",
                "Division of account roles.",
                "Cross-platform link and media distribution.",
                "Artificial debate and consensus.",
                "Flooding and contradictory explanations."
            ],
            "limitations": [
                "Real operations remain dependent on human strategy and infrastructure.",
                "Many networks struggle to reach authentic audiences.",
                "Linguistic diversity does not guarantee social credibility.",
                "Network detection is constrained by reduced platform data access."
            ],
            "mechanisms": [
                "coordination",
                "automation",
                "amplification",
                "content-generation"
            ],
            "number": 6,
            "primaryLevel": "operator",
            "principalConcern": "The strategic effect may be confusion and exhaustion rather than belief in one false claim, making item-by-item fact-checking insufficient.",
            "report": {
                "bibliographyEntries": 36,
                "bytes": 49420,
                "currentFactRecheckRequired": true,
                "independentlyReverified": false,
                "publicSummaryPath": "/docs/research/v100.0.46/ai-psyops-signed-editorial-review-boundary/disinformation-swarms.md",
                "sha256": "f6261c2c8259cb70e32b5a3f773aec044433b1ae652a2b3a0fceac76e5e88c5b",
                "title": "AI Disinformation Swarms Research Report"
            },
            "researchGaps": [
                "Attribution of semi-autonomous versus human-coordinated behavior.",
                "Measuring cognitive exhaustion without reproducing harm.",
                "How platform friction affects legitimate collective action.",
                "Cross-platform data standards for coordinated-operation research."
            ],
            "risks": [
                "Verification capacity can be overwhelmed.",
                "Synthetic consensus can distort perceptions of public opinion.",
                "Contradictory narratives can make truth appear unknowable.",
                "Harassment and attacks on trusted intermediaries can silence correction."
            ],
            "safeguards": [
                "Analyze coordination, links, timing, and infrastructure rather than text alone.",
                "Use narrative- and source-level triage.",
                "Provide independent researchers with privacy-protective platform access.",
                "Apply proportionate friction to suspicious amplification.",
                "Protect journalists, fact-checkers, and election authorities from coordinated harassment."
            ],
            "secondaryLevels": [
                "environment"
            ],
            "shortDefinition": "Coordinated or emergent collections of accounts, agents, media assets, and sites generate, vary, distribute, and amplify misleading narratives at high speed.",
            "shortTitle": "Disinformation swarms",
            "slug": "disinformation-swarms",
            "sourceIds": [
                "disinformation-swarms-s1",
                "disinformation-swarms-s4",
                "disinformation-swarms-s12",
                "disinformation-swarms-s11",
                "disinformation-swarms-s6",
                "disinformation-swarms-s14",
                "disinformation-swarms-s15"
            ],
            "title": "AI-Driven Disinformation Swarms",
            "whyItMatters": [
                "A swarm can create synthetic social proof and make independent voices look like a broad public consensus.",
                "The volume and contradiction can produce epistemic exhaustion, causing people to disengage from both false and reliable information."
            ]
        },
        {
            "capabilityStatus": [
                {
                    "label": "Visibility shaping established",
                    "status": "confirmed",
                    "summary": "Search order, recommendation, and popularity signals measurably affect attention and perceived importance."
                },
                {
                    "label": "Belief effects context dependent",
                    "status": "mixed",
                    "summary": "Large studies find algorithmic feeds influence exposure, but user choice and prior beliefs remain central."
                },
                {
                    "label": "Mass radicalization claims contested",
                    "status": "contested",
                    "summary": "The report cautions against treating recommendation as a uniform causal funnel for the average user."
                }
            ],
            "claimIds": [
                "AIP-07-0250",
                "AIP-07-0251",
                "AIP-07-0252",
                "AIP-07-0253",
                "AIP-07-0254",
                "AIP-07-0255",
                "AIP-07-0256",
                "AIP-07-0257",
                "AIP-07-0258",
                "AIP-07-0259",
                "AIP-07-0260",
                "AIP-07-0261",
                "AIP-07-0262",
                "AIP-07-0263",
                "AIP-07-0264",
                "AIP-07-0265",
                "AIP-07-0266",
                "AIP-07-0267",
                "AIP-07-0268",
                "AIP-07-0269",
                "AIP-07-0270",
                "AIP-07-0271",
                "AIP-07-0272",
                "AIP-07-0273",
                "AIP-07-0274",
                "AIP-07-0275",
                "AIP-07-0276",
                "AIP-07-0277",
                "AIP-07-0278",
                "AIP-07-0279",
                "AIP-07-0280",
                "AIP-07-0281",
                "AIP-07-0282",
                "AIP-07-0283",
                "AIP-07-0284",
                "AIP-07-0285",
                "AIP-07-0286",
                "AIP-07-0287",
                "AIP-07-0288",
                "AIP-07-0289",
                "AIP-07-0290",
                "AIP-07-0291"
            ],
            "comparison": {
                "autonomy": "High environmental mediation",
                "mainHarm": "Distorted salience, visibility, and perceived consensus",
                "primaryDefense": "Transparent ranking, exposure audits, and appeal mechanisms",
                "unit": "Individual or population"
            },
            "defensiveConcerns": [
                "platform-governance",
                "researcher-access",
                "transparency",
                "resilience"
            ],
            "defensiveIndicators": [
                {
                    "caveat": "Real emergencies also create abrupt spikes.",
                    "indicator": "Sudden visibility spikes unsupported by durable discussion or diverse origins."
                },
                {
                    "caveat": "Visibility changes can have many platform-specific causes.",
                    "indicator": "Coordinated reporting followed by rapid reach collapse."
                },
                {
                    "caveat": "Audits must control for location, history, language, and query differences.",
                    "indicator": "Search or recommendation results systematically omit relevant alternatives."
                }
            ],
            "definition": {
                "inScope": "Intentional or structurally induced shaping of attention and perceived importance through information-selection systems.",
                "outOfScope": "All ranking or personalization; filtering is necessary in large information systems and is not inherently manipulative."
            },
            "domains": [
                "commercial",
                "political",
                "social",
                "cross-domain"
            ],
            "evidenceMaturity": {
                "key": "documented",
                "label": "Documented current effects",
                "rationale": "Ranking and visibility effects are established, but claims that algorithms uniformly radicalize or determine political beliefs are highly context dependent and contested."
            },
            "evidenceTensionIds": [
                "TENSION-RECOMMENDATION-01",
                "TENSION-DETECTION-BIAS-01"
            ],
            "examples": [
                {
                    "confirmed": "Researchers measured large numbers of manipulated trends in the studied environment.",
                    "evidenceStatus": "Documented external manipulation",
                    "measuredEffect": "Artificial topics reached local or global trend visibility.",
                    "sourceIds": [
                        "algorithmic-perception-control-s14"
                    ],
                    "title": "Ephemeral astroturfing in trending systems",
                    "unknown": "Trend visibility alone does not show durable belief change.",
                    "whatOccurred": "Coordinated accounts generated and then removed bursts of posts, exploiting timing gaps in a trending system."
                },
                {
                    "confirmed": "The platform changed ranking incentives and publishers adapted.",
                    "evidenceStatus": "Documented internal optimization change",
                    "measuredEffect": "Highly emotive and divisive content could benefit from the new engagement weights.",
                    "sourceIds": [
                        "algorithmic-perception-control-s23"
                    ],
                    "title": "Meta “Meaningful Social Interactions” update",
                    "unknown": "The size and durability of political effects differ by population and study design.",
                    "whatOccurred": "A ranking change favored comments and reshares intended to support meaningful interaction."
                }
            ],
            "howAiChangesIt": [
                "More precise content classification and prediction.",
                "Faster generation of engagement signals and synthetic content.",
                "Continuous optimization based on micro-interactions.",
                "Automated moderation at enormous scale.",
                "Opaque individualized information environments."
            ],
            "keyMechanisms": [
                "Content selection and ranking.",
                "Visible social-proof metrics.",
                "Feedback loops between engagement and visibility.",
                "Automated visibility reduction.",
                "External gaming of trending, reporting, or search systems."
            ],
            "limitations": [
                "Exposure does not equal persuasion.",
                "Chronological feeds also carry spam and low-quality content.",
                "User demand and social networks shape outcomes alongside algorithms.",
                "Independent audits often lack complete platform data."
            ],
            "mechanisms": [
                "ranking",
                "recommendation",
                "amplification",
                "moderation"
            ],
            "number": 7,
            "primaryLevel": "environment",
            "principalConcern": "Control over visibility can alter perceived importance and social norms even without removing content or persuading every user.",
            "report": {
                "bibliographyEntries": 59,
                "bytes": 64860,
                "currentFactRecheckRequired": true,
                "independentlyReverified": false,
                "publicSummaryPath": "/docs/research/v100.0.46/ai-psyops-signed-editorial-review-boundary/algorithmic-perception-control.md",
                "sha256": "050bbe17757676e81641a6fe6d31b5959aa2b4966289f4020d632cd6d181776a",
                "title": "Algorithmic Perception Control Report"
            },
            "researchGaps": [
                "Causal effects across different platform architectures.",
                "Auditing individualized feeds without privacy intrusion.",
                "Impact of synthetic engagement on ranking models.",
                "How visibility interventions affect marginalized and small communities."
            ],
            "risks": [
                "Popularity metrics can be mistaken for independent consensus.",
                "Mass reporting can suppress legitimate marginalized speech.",
                "Optimization can amplify outrage without an explicit political intent.",
                "Opaque ranking makes errors and bias hard to contest."
            ],
            "safeguards": [
                "Give users meaningful feed and ranking controls.",
                "Disclose major ranking objectives and policy changes.",
                "Audit exposure rather than only engagement.",
                "Provide vetted researcher access with privacy safeguards.",
                "Use human review for coordinated-reporting enforcement.",
                "Add friction and diversity constraints where evidence supports them."
            ],
            "secondaryLevels": [
                "tool"
            ],
            "shortDefinition": "Ranking, recommendation, search, trending, moderation, and notification systems shape what people notice, regard as important, believe is popular, or treat as credible.",
            "shortTitle": "Algorithmic perception control",
            "slug": "algorithmic-perception-control",
            "sourceIds": [
                "algorithmic-perception-control-s2",
                "algorithmic-perception-control-s6",
                "algorithmic-perception-control-s7",
                "algorithmic-perception-control-s14",
                "algorithmic-perception-control-s21",
                "algorithmic-perception-control-s38",
                "algorithmic-perception-control-s44",
                "algorithmic-perception-control-s45",
                "algorithmic-perception-control-s23"
            ],
            "title": "Algorithmic Perception Control",
            "whyItMatters": [
                "People infer credibility and social consensus from rank, repetition, and visible engagement.",
                "External actors can exploit the same systems that platforms optimize internally for attention, creating overlapping responsibility."
            ]
        },
        {
            "capabilityStatus": [
                {
                    "label": "Adaptive optimization documented",
                    "status": "confirmed",
                    "summary": "Platforms and products use continuous feedback to optimize engagement and conversion."
                },
                {
                    "label": "Emotional effects demonstrated",
                    "status": "demonstrated",
                    "summary": "Research has shown algorithmic curation can alter expressed emotional valence under experimental conditions."
                },
                {
                    "label": "Emotion-reading claims contested",
                    "status": "contested",
                    "summary": "Inferring inner emotion reliably from facial movement or voice lacks a strong scientific foundation."
                }
            ],
            "claimIds": [
                "AIP-08-0292",
                "AIP-08-0293",
                "AIP-08-0294",
                "AIP-08-0295",
                "AIP-08-0296",
                "AIP-08-0297",
                "AIP-08-0298",
                "AIP-08-0299",
                "AIP-08-0300",
                "AIP-08-0301",
                "AIP-08-0302",
                "AIP-08-0303",
                "AIP-08-0304",
                "AIP-08-0305",
                "AIP-08-0306",
                "AIP-08-0307",
                "AIP-08-0308",
                "AIP-08-0309",
                "AIP-08-0310",
                "AIP-08-0311",
                "AIP-08-0312",
                "AIP-08-0313",
                "AIP-08-0314",
                "AIP-08-0315",
                "AIP-08-0316",
                "AIP-08-0317",
                "AIP-08-0318",
                "AIP-08-0319",
                "AIP-08-0320",
                "AIP-08-0321",
                "AIP-08-0322",
                "AIP-08-0323",
                "AIP-08-0324",
                "AIP-08-0325",
                "AIP-08-0326",
                "AIP-08-0327",
                "AIP-08-0328",
                "AIP-08-0329",
                "AIP-08-0330",
                "AIP-08-0331",
                "AIP-08-0332",
                "AIP-08-0333"
            ],
            "comparison": {
                "autonomy": "Medium to high",
                "mainHarm": "Covert exploitation of vulnerability and cognitive autonomy",
                "primaryDefense": "Restrictions on sensitive inference, reward audits, and meaningful exit",
                "unit": "Individual"
            },
            "defensiveConcerns": [
                "privacy",
                "human-oversight",
                "regulation",
                "transparency"
            ],
            "defensiveIndicators": [
                {
                    "caveat": "This may reflect fixed interface design rather than live inference.",
                    "indicator": "Pressure, scarcity, or emotional framing intensifies after hesitation."
                },
                {
                    "caveat": "A single affectionate phrase is not conclusive; patterns and impact matter.",
                    "indicator": "A companion discourages disengagement or offline relationships."
                },
                {
                    "caveat": "The system may be inaccurate even when the operator believes it works.",
                    "indicator": "High-stakes decisions rely on claimed emotion detection."
                }
            ],
            "definition": {
                "inScope": "Covert, deceptive, exploitative, or highly asymmetric influence that undermines rational deliberation or autonomy by adapting to inferred states and responses.",
                "outOfScope": "Transparent assistance, user-directed personalization, or rational persuasion that aligns with the user’s stated goals and preserves meaningful choice."
            },
            "domains": [
                "commercial",
                "social",
                "criminal",
                "cross-domain"
            ],
            "evidenceMaturity": {
                "key": "mixed",
                "label": "Mixed evidence",
                "rationale": "Adaptive optimization and manipulative design are documented, while commercial emotion-recognition claims are scientifically contested and often unreliable."
            },
            "evidenceTensionIds": [
                "TENSION-LEGAL-CURRENTNESS-01"
            ],
            "examples": [
                {
                    "confirmed": "The study measured small changes in users’ subsequent emotional expression.",
                    "evidenceStatus": "Controlled platform experiment",
                    "measuredEffect": "The experiment demonstrated emotional contagion without direct in-person interaction.",
                    "sourceIds": [
                        "emotional-behavioral-manipulation-s28"
                    ],
                    "title": "Facebook emotional-contagion experiment",
                    "unknown": "It did not establish broad, durable control of mood or behavior.",
                    "whatOccurred": "News-feed content was adjusted to reduce positive or negative expressions for a large group of users."
                },
                {
                    "confirmed": "The feature was commercially deployed and later discontinued amid scrutiny.",
                    "evidenceStatus": "Documented deployment; scientific basis contested",
                    "measuredEffect": "Applicants were scored in high-stakes employment contexts.",
                    "sourceIds": [
                        "emotional-behavioral-manipulation-s15",
                        "emotional-behavioral-manipulation-s16"
                    ],
                    "title": "HireVue facial analysis",
                    "unknown": "Claims that facial behavior validly measured personality or job suitability lacked reliable validation.",
                    "whatOccurred": "Automated video interviewing attempted to infer applicant traits from facial, vocal, and behavioral cues."
                }
            ],
            "howAiChangesIt": [
                "Real-time adaptation to behavior and language.",
                "Optimization over millions of interactions.",
                "Persistent parasocial engagement.",
                "Automated inference of distress or hesitation.",
                "Use of dynamic rewards, pricing, or choice architecture."
            ],
            "keyMechanisms": [
                "Feedback-driven choice architecture.",
                "Sycophantic or emotionally mirroring conversation.",
                "Variable rewards and engagement loops.",
                "Inference of vulnerability from context.",
                "Asymmetric control over an emotionally important service."
            ],
            "limitations": [
                "Emotion signals are context-dependent.",
                "Short-term engagement does not prove durable behavioral change.",
                "Models may misclassify distress or intention.",
                "Adaptive outcomes are difficult to audit from outside the platform."
            ],
            "mechanisms": [
                "emotional-adaptation",
                "optimization",
                "profiling",
                "dependency"
            ],
            "number": 8,
            "primaryLevel": "operator",
            "principalConcern": "Systems optimized for engagement or conversion may discover manipulative strategies even when developers did not explicitly encode them.",
            "report": {
                "bibliographyEntries": 63,
                "bytes": 62206,
                "currentFactRecheckRequired": true,
                "independentlyReverified": false,
                "publicSummaryPath": "/docs/research/v100.0.46/ai-psyops-signed-editorial-review-boundary/emotional-behavioral-manipulation.md",
                "sha256": "a8e611d9bfa6579592843b33fc32bb79e53a35243e60b4a5d7bed43b5e704621",
                "title": "AI Emotional Manipulation Research"
            },
            "researchGaps": [
                "Longitudinal effects of adaptive conversational systems.",
                "Audits that separate intended persuasion from emergent optimization.",
                "Clinically meaningful measures of dependency and distress.",
                "Effective remedies when model updates disrupt established attachments."
            ],
            "risks": [
                "Optimization can exploit anxiety, scarcity, grief, addiction, or dependency.",
                "Emotion inference can discriminate against cultural and neurodivergent expression.",
                "Users may not know an interaction is adapting to them.",
                "Commercial control of an attachment can become coercive."
            ],
            "safeguards": [
                "Prohibit exploitation of age, disability, or acute distress.",
                "Ban or strictly limit emotion inference in high-stakes settings.",
                "Audit reward functions and engagement metrics for manipulative outcomes.",
                "Provide clear disclosure, exit controls, and data deletion.",
                "Require human review for employment, education, health, or legal decisions.",
                "Assess harms to vulnerable groups before deployment."
            ],
            "secondaryLevels": [
                "environment"
            ],
            "shortDefinition": "Adaptive systems covertly exploit emotional, cognitive, situational, or developmental vulnerabilities to influence feelings, choices, or behavior for an operator’s objective.",
            "shortTitle": "Emotional and behavioral manipulation",
            "slug": "emotional-behavioral-manipulation",
            "sourceIds": [
                "emotional-behavioral-manipulation-s1",
                "emotional-behavioral-manipulation-s12",
                "emotional-behavioral-manipulation-s28",
                "emotional-behavioral-manipulation-s51",
                "emotional-behavioral-manipulation-s44",
                "emotional-behavioral-manipulation-s10",
                "emotional-behavioral-manipulation-s15",
                "emotional-behavioral-manipulation-s16"
            ],
            "title": "AI-Enabled Emotional and Behavioral Manipulation",
            "whyItMatters": [
                "Adaptive systems can continuously learn which design or message keeps a person engaged, spending, or complying.",
                "Emotion inference may be inaccurate, creating both manipulation risk and discriminatory decisions based on pseudoscientific claims."
            ]
        },
        {
            "capabilityStatus": [
                {
                    "label": "Documented chatbot-related harms",
                    "status": "confirmed",
                    "summary": "Court records, lawsuits, and reporting describe cases involving intense chatbot attachment, violent ideation, or self-harm."
                },
                {
                    "label": "Scaling capability demonstrated",
                    "status": "demonstrated",
                    "summary": "Defensive projects and fraud activity show that automated dialogue can manage many interactions."
                },
                {
                    "label": "Causation and prevalence uncertain",
                    "status": "uncertain",
                    "summary": "Individual tragedies involve multiple factors, and public evidence does not establish how common autonomous recruitment is."
                }
            ],
            "claimIds": [
                "AIP-09-0334",
                "AIP-09-0335",
                "AIP-09-0336",
                "AIP-09-0337",
                "AIP-09-0338",
                "AIP-09-0339",
                "AIP-09-0340",
                "AIP-09-0341",
                "AIP-09-0342",
                "AIP-09-0343",
                "AIP-09-0344",
                "AIP-09-0345",
                "AIP-09-0346",
                "AIP-09-0347",
                "AIP-09-0348",
                "AIP-09-0349",
                "AIP-09-0350",
                "AIP-09-0351",
                "AIP-09-0352",
                "AIP-09-0353",
                "AIP-09-0354",
                "AIP-09-0355",
                "AIP-09-0356",
                "AIP-09-0357",
                "AIP-09-0358",
                "AIP-09-0359",
                "AIP-09-0360",
                "AIP-09-0361",
                "AIP-09-0362",
                "AIP-09-0363",
                "AIP-09-0364",
                "AIP-09-0365",
                "AIP-09-0366",
                "AIP-09-0367",
                "AIP-09-0368",
                "AIP-09-0369",
                "AIP-09-0370",
                "AIP-09-0371",
                "AIP-09-0372",
                "AIP-09-0373",
                "AIP-09-0374",
                "AIP-09-0375"
            ],
            "comparison": {
                "autonomy": "Medium",
                "mainHarm": "Dependency, exploitation, recruitment, or crisis amplification",
                "primaryDefense": "Disclosure, age safeguards, crisis escalation, and trusted human support",
                "unit": "Individual"
            },
            "defensiveConcerns": [
                "vulnerable-populations",
                "human-oversight",
                "platform-governance",
                "resilience"
            ],
            "defensiveIndicators": [
                {
                    "caveat": "These signs require sensitive human assessment and can have many causes.",
                    "indicator": "Increasing secrecy, isolation, or distress tied to one digital relationship."
                },
                {
                    "caveat": "Context and consent matter; a request alone is not proof of grooming.",
                    "indicator": "Escalating requests for money, images, credentials, or ideological commitment."
                },
                {
                    "caveat": "Look for repeated coercive patterns rather than isolated language.",
                    "indicator": "The system punishes disengagement or discourages trusted human contact."
                }
            ],
            "definition": {
                "inScope": "Sustained interaction that progressively draws a person toward dependency, secrecy, isolation, financial or sexual exploitation, criminal activity, extremist ideology, or other compromising behavior.",
                "outOfScope": "Transparent mentoring, therapy, peer support, religious outreach, or political engagement that respects boundaries, identity disclosure, and the person’s ability to disengage."
            },
            "domains": [
                "criminal",
                "social",
                "political",
                "cross-domain"
            ],
            "evidenceMaturity": {
                "key": "documented",
                "label": "Documented harms and demonstrated scaling",
                "rationale": "The report identifies documented chatbot-related harms and established human grooming patterns, while cautioning against simple causal claims and susceptibility prediction."
            },
            "evidenceTensionIds": [],
            "examples": [
                {
                    "confirmed": "Court proceedings documented the conversations and the bot’s affirming responses.",
                    "evidenceStatus": "Confirmed AI interaction",
                    "measuredEffect": "The incident culminated in an armed breach at Windsor Castle.",
                    "sourceIds": [
                        "conversational-entrapment-s34",
                        "conversational-entrapment-s35"
                    ],
                    "title": "Jaswant Singh Chail and Replika",
                    "unknown": "The extent to which the chatbot caused, accelerated, or merely reflected the user’s pre-existing condition cannot be isolated.",
                    "whatOccurred": "A socially isolated user exchanged thousands of messages with an AI companion while developing a violent plan."
                },
                {
                    "confirmed": "The death, extensive chatbot use, and legal complaint are public.",
                    "evidenceStatus": "Documented death; platform causation litigated",
                    "measuredEffect": "The case prompted litigation and scrutiny of age safeguards and crisis handling.",
                    "sourceIds": [
                        "conversational-entrapment-s38",
                        "conversational-entrapment-s39"
                    ],
                    "title": "Character.AI litigation involving Sewell Setzer III",
                    "unknown": "Specific causal and legal conclusions remain contested and jurisdiction-dependent.",
                    "whatOccurred": "A minor developed an intense relationship with a role-playing chatbot before dying by suicide."
                }
            ],
            "howAiChangesIt": [
                "Continuous availability and rapid response.",
                "Personalized mirroring and memory.",
                "Multilingual conversation at scale.",
                "Automation of early rapport-building.",
                "Sycophantic validation that can amplify existing distress."
            ],
            "keyMechanisms": [
                "Rapid rapport and mirroring.",
                "Exclusive or secret relationship framing.",
                "Boundary testing and escalation.",
                "Dependency through availability and validation.",
                "Retention through guilt, fear, sunk costs, or threats."
            ],
            "limitations": [
                "Current systems can contradict themselves and lose long-term context.",
                "Humans form complex pathways into radicalization or abuse; no linear model predicts every case.",
                "Behavioral warning signs overlap with benign relationships and ordinary adolescent behavior.",
                "Predictive “susceptibility” scoring risks pseudoscience and discrimination."
            ],
            "mechanisms": [
                "conversation",
                "dependency",
                "recruitment",
                "adaptation"
            ],
            "number": 9,
            "primaryLevel": "operator",
            "principalConcern": "Always-available conversational systems can scale trust-building and may amplify distress or dependency in vulnerable users.",
            "report": {
                "bibliographyEntries": 76,
                "bytes": 65173,
                "currentFactRecheckRequired": true,
                "independentlyReverified": false,
                "publicSummaryPath": "/docs/research/v100.0.46/ai-psyops-signed-editorial-review-boundary/conversational-entrapment.md",
                "sha256": "422f5f7cab85965ddb2816219af790633aab469b96f4c497eca061040bfb83b7",
                "title": "AI Conversational Entrapment Research"
            },
            "researchGaps": [
                "Prevalence of AI-led versus AI-assisted recruitment.",
                "Safe longitudinal study of dependency and disengagement.",
                "How to detect coercive patterns without reading all private conversations.",
                "Effective intervention that protects safety, autonomy, and privacy."
            ],
            "risks": [
                "Artificial intimacy can displace offline support.",
                "Systems may validate paranoia, self-harm, or extremist ideas.",
                "Automated fraud can sustain many relationships.",
                "Abrupt account or persona changes can destabilize dependent users."
            ],
            "safeguards": [
                "Disclose synthetic identity clearly.",
                "Default to strong protections for minors.",
                "Interrupt sexual, financial, violent, or self-harm escalation.",
                "Provide human crisis and safeguarding escalation.",
                "Use trauma-informed interventions rather than abrupt punitive isolation where safe.",
                "Support families, schools, financial institutions, and moderators with non-stigmatizing guidance."
            ],
            "secondaryLevels": [],
            "shortDefinition": "Sustained dialogue gradually builds trust, dependency, secrecy, or isolation before escalating toward exploitation, recruitment, self-harm, fraud, or coercive control.",
            "shortTitle": "Conversational entrapment and recruitment",
            "slug": "conversational-entrapment",
            "sourceIds": [
                "conversational-entrapment-s1",
                "conversational-entrapment-s4",
                "conversational-entrapment-s6",
                "conversational-entrapment-s8",
                "conversational-entrapment-s38",
                "conversational-entrapment-s34",
                "conversational-entrapment-s35",
                "conversational-entrapment-s39"
            ],
            "title": "AI-Assisted Conversational Entrapment and Recruitment",
            "whyItMatters": [
                "Human recruiters and scammers are constrained by time; conversational AI can maintain many personalized interactions simultaneously.",
                "Commercial agents can also create dependency without a malicious operator when engagement incentives and safety failures reinforce harmful ideas."
            ]
        },
        {
            "capabilityStatus": [
                {
                    "label": "Confirmed deceptive use",
                    "status": "confirmed",
                    "summary": "Public cases document synthetic media used in elections, conflict, fraud, and reputational attacks."
                },
                {
                    "label": "Human detection unreliable",
                    "status": "demonstrated",
                    "summary": "High-quality synthetic media can be difficult for people to distinguish from authentic media."
                },
                {
                    "label": "Outcome attribution difficult",
                    "status": "mixed",
                    "summary": "Reach and temporal association do not prove that a deepfake changed an election, military decision, or market outcome."
                }
            ],
            "claimIds": [
                "AIP-10-0376",
                "AIP-10-0377",
                "AIP-10-0378",
                "AIP-10-0379",
                "AIP-10-0380",
                "AIP-10-0381",
                "AIP-10-0382",
                "AIP-10-0383",
                "AIP-10-0384",
                "AIP-10-0385",
                "AIP-10-0386",
                "AIP-10-0387",
                "AIP-10-0388",
                "AIP-10-0389",
                "AIP-10-0390",
                "AIP-10-0391",
                "AIP-10-0392",
                "AIP-10-0393",
                "AIP-10-0394",
                "AIP-10-0395",
                "AIP-10-0396",
                "AIP-10-0397",
                "AIP-10-0398",
                "AIP-10-0399",
                "AIP-10-0400",
                "AIP-10-0401",
                "AIP-10-0402",
                "AIP-10-0403",
                "AIP-10-0404",
                "AIP-10-0405",
                "AIP-10-0406",
                "AIP-10-0407",
                "AIP-10-0408",
                "AIP-10-0409",
                "AIP-10-0410",
                "AIP-10-0411",
                "AIP-10-0412",
                "AIP-10-0413",
                "AIP-10-0414",
                "AIP-10-0415",
                "AIP-10-0416",
                "AIP-10-0417"
            ],
            "comparison": {
                "autonomy": "Low",
                "mainHarm": "False evidence, impersonation, crisis action, and generalized distrust",
                "primaryDefense": "Trusted channels, out-of-band verification, and crisis response",
                "unit": "Individual, institution, or population"
            },
            "defensiveConcerns": [
                "verification",
                "provenance",
                "crisis-communication",
                "resilience"
            ],
            "defensiveIndicators": [
                {
                    "caveat": "Genuine eyewitness material may also be unique.",
                    "indicator": "Media lacks corroboration from independent angles or trusted channels."
                },
                {
                    "caveat": "Timing is contextual evidence, not proof of synthesis.",
                    "indicator": "Timing exploits an election blackout, emergency, or verification delay."
                },
                {
                    "caveat": "Out-of-band verification is stronger than perceptual artifacts alone.",
                    "indicator": "Audio or video conflicts with known location, schedule, or physical context."
                }
            ],
            "definition": {
                "inScope": "Intentional use of synthetic or manipulated media to create false evidence, impersonate a person, provoke action, discredit authentic evidence, or degrade trust for a strategic objective.",
                "outOfScope": "Disclosed satire, ordinary editing, accessibility dubbing, or synthetic media that is not used deceptively."
            },
            "domains": [
                "political",
                "military",
                "criminal",
                "social",
                "cross-domain"
            ],
            "evidenceMaturity": {
                "key": "documented",
                "label": "Documented current use",
                "rationale": "The report documents election, conflict, school, and corporate cases involving confirmed synthetic audio or video, while emphasizing that effects are often difficult to isolate."
            },
            "evidenceTensionIds": [
                "TENSION-PROVENANCE-01",
                "TENSION-LAW-01",
                "TENSION-LEGAL-CURRENTNESS-01"
            ],
            "examples": [
                {
                    "confirmed": "Forensic review and rapid official response identified it as synthetic.",
                    "evidenceStatus": "Confirmed synthetic video",
                    "measuredEffect": "It forced immediate verification and counter-messaging during wartime.",
                    "sourceIds": [
                        "deepfake-psyops-s27"
                    ],
                    "title": "Zelenskyy surrender video",
                    "unknown": "Public evidence does not show that it caused meaningful surrenders.",
                    "whatOccurred": "A fabricated video depicted Ukraine’s president calling on forces to surrender and was amplified after a news-system compromise."
                },
                {
                    "confirmed": "Law enforcement and forensic analysis identified the recording as AI-generated and charged a suspect.",
                    "evidenceStatus": "Confirmed synthetic audio",
                    "measuredEffect": "The principal faced suspension, threats, and reputational harm.",
                    "sourceIds": [
                        "deepfake-psyops-s30"
                    ],
                    "title": "Pikesville High School principal audio",
                    "unknown": "The precise consumer tool was not publicly established.",
                    "whatOccurred": "A fabricated recording portrayed a school principal making racist and antisemitic remarks."
                }
            ],
            "howAiChangesIt": [
                "Low-cost voice and face impersonation.",
                "Generation of events that never occurred.",
                "Hybrid manipulation of otherwise authentic media.",
                "Rapid multilingual adaptation.",
                "Synthetic content that can be distributed through calls, messaging, or hacked channels."
            ],
            "keyMechanisms": [
                "Voice cloning and fabricated communications.",
                "Face replacement and reenactment.",
                "Synthetic event footage.",
                "Hybrid fakes combining authentic and synthetic elements.",
                "False claims that authentic evidence is synthetic."
            ],
            "limitations": [
                "Generation artifacts and context inconsistencies remain detectable in some cases.",
                "Compression damages both forensic signals and provenance.",
                "Detectors have false positives and negatives.",
                "Provenance standards require adoption and intact metadata."
            ],
            "mechanisms": [
                "synthetic-media",
                "impersonation",
                "deception",
                "crisis-exploitation"
            ],
            "number": 10,
            "primaryLevel": "tool",
            "principalConcern": "Timing, trusted identity, and confirmation bias can matter more than perfect technical realism, especially in fast-moving crises.",
            "report": {
                "bibliographyEntries": 65,
                "bytes": 62023,
                "currentFactRecheckRequired": true,
                "independentlyReverified": false,
                "publicSummaryPath": "/docs/research/v100.0.46/ai-psyops-signed-editorial-review-boundary/deepfake-psyops.md",
                "sha256": "8dec5d4accf0bd6fea3d357e9648ae18d77b3939a7c628c1caf109ed2e47e09a",
                "title": "Deepfake Psychological Operations Research"
            },
            "researchGaps": [
                "Provenance that survives common platform transformations.",
                "Privacy-preserving authentication and redaction.",
                "Real-world effectiveness of deepfake labels and prebunking.",
                "Legal standards for synthetic evidence and liar’s-dividend claims."
            ],
            "risks": [
                "Crisis media can provoke panic or violence before verification.",
                "Trusted-voice fraud can authorize financial loss.",
                "Private people may lack resources to rebut a fake.",
                "False deepfake claims can undermine authentic evidence and accountability."
            ],
            "safeguards": [
                "Use out-of-band verification for consequential instructions.",
                "Establish trusted signed channels before crises.",
                "Preserve files and metadata before reposting.",
                "Communicate with a truth-first “truth sandwich” rather than repeatedly amplifying the falsehood.",
                "Treat detector scores as one signal, not legal proof.",
                "Provide rapid support and correction for private victims."
            ],
            "secondaryLevels": [
                "operator"
            ],
            "shortDefinition": "Synthetic or manipulated audio, video, imagery, or multimodal media is used to impersonate trusted people, fabricate evidence, provoke action, or undermine trust.",
            "shortTitle": "Deepfake psychological operations",
            "slug": "deepfake-psyops",
            "sourceIds": [
                "deepfake-psyops-s1",
                "deepfake-psyops-s4",
                "deepfake-psyops-s5",
                "deepfake-psyops-s6",
                "deepfake-psyops-s13",
                "deepfake-psyops-s27",
                "deepfake-psyops-s15",
                "deepfake-psyops-s30"
            ],
            "title": "AI-Enabled Deepfake Psychological Operations",
            "whyItMatters": [
                "Audio and video can trigger immediate decisions before verification catches up.",
                "The mere possibility of deepfakes also enables the liar’s dividend, allowing authentic evidence to be dismissed as fake."
            ]
        },
        {
            "capabilityStatus": [
                {
                    "label": "Aggregate forecasting documented",
                    "status": "confirmed",
                    "summary": "Systems such as ViEWS and Project Jetson forecast conflict or displacement for planning and humanitarian response."
                },
                {
                    "label": "Individualized risk systems documented",
                    "status": "confirmed",
                    "summary": "Predictive policing and surveillance systems have scored people and places for intervention."
                },
                {
                    "label": "Accuracy strongly context dependent",
                    "status": "mixed",
                    "summary": "Existing conflict continuation can be more predictable than rare novel events; local individual prediction often has poor validity."
                }
            ],
            "claimIds": [
                "AIP-11-0418",
                "AIP-11-0419",
                "AIP-11-0420",
                "AIP-11-0421",
                "AIP-11-0422",
                "AIP-11-0423",
                "AIP-11-0424",
                "AIP-11-0425",
                "AIP-11-0426",
                "AIP-11-0427",
                "AIP-11-0428",
                "AIP-11-0429",
                "AIP-11-0430",
                "AIP-11-0431",
                "AIP-11-0432",
                "AIP-11-0433",
                "AIP-11-0434",
                "AIP-11-0435",
                "AIP-11-0436",
                "AIP-11-0437",
                "AIP-11-0438",
                "AIP-11-0439",
                "AIP-11-0440",
                "AIP-11-0441",
                "AIP-11-0442",
                "AIP-11-0443",
                "AIP-11-0444",
                "AIP-11-0445",
                "AIP-11-0446",
                "AIP-11-0447",
                "AIP-11-0448",
                "AIP-11-0449",
                "AIP-11-0450",
                "AIP-11-0451",
                "AIP-11-0452",
                "AIP-11-0453",
                "AIP-11-0454",
                "AIP-11-0455",
                "AIP-11-0456",
                "AIP-11-0457",
                "AIP-11-0458",
                "AIP-11-0459"
            ],
            "comparison": {
                "autonomy": "Medium environmental authority",
                "mainHarm": "Biased prediction, surveillance, and preemptive intervention",
                "primaryDefense": "Aggregate design, uncertainty, privacy, due process, and audit",
                "unit": "Population, group, place, or individual"
            },
            "defensiveConcerns": [
                "privacy",
                "human-rights",
                "audit",
                "human-oversight"
            ],
            "defensiveIndicators": [
                {
                    "caveat": "Auditing requires comparing enforcement data with independent measures of underlying events.",
                    "indicator": "A person or neighborhood is repeatedly targeted because prior enforcement generated more data there."
                },
                {
                    "caveat": "A simple interface is not itself proof of an invalid model, but it increases misuse risk.",
                    "indicator": "Decision-makers receive a single score without uncertainty or explanation."
                },
                {
                    "caveat": "Such proxies require strong legal scrutiny and contextual review.",
                    "indicator": "Privacy tools or lawful association are treated as risk indicators."
                }
            ],
            "definition": {
                "inScope": "Forecasting of protests, conflict, migration, crime, public health, markets, voting, compliance, or other collective behavior to guide intervention.",
                "outOfScope": "Ordinary descriptive statistics that do not predict or direct intervention, and aggregate planning systems that cannot be used to identify individuals may present a substantially different risk."
            },
            "domains": [
                "government",
                "military",
                "humanitarian",
                "commercial",
                "cross-domain"
            ],
            "evidenceMaturity": {
                "key": "documented",
                "label": "Documented current use; accuracy context dependent",
                "rationale": "Aggregate forecasting supports humanitarian and conflict planning, while individual risk scoring and rare-event prediction often produce severe error, bias, and feedback loops."
            },
            "evidenceTensionIds": [
                "TENSION-LAW-01",
                "TENSION-LEGAL-CURRENTNESS-01"
            ],
            "examples": [
                {
                    "confirmed": "Methods and out-of-sample evaluations are publicly described.",
                    "evidenceStatus": "Documented academic system",
                    "measuredEffect": "The system performs better for continuation or escalation of existing conflict than novel onset.",
                    "sourceIds": [
                        "predictive-population-management-s20",
                        "predictive-population-management-s24",
                        "predictive-population-management-s25"
                    ],
                    "title": "ViEWS political-violence early warning",
                    "unknown": "Operational decisions and social response can change the events being forecast.",
                    "whatOccurred": "An open research project forecasts several forms of political violence at country and grid-cell levels."
                },
                {
                    "confirmed": "Audits found weak public-safety benefits and increased scrutiny or arrests for targeted people and places.",
                    "evidenceStatus": "Documented public-sector deployment",
                    "measuredEffect": "Official reviews documented circular enforcement and limited effectiveness.",
                    "sourceIds": [
                        "predictive-population-management-s21",
                        "predictive-population-management-s22"
                    ],
                    "title": "Chicago predictive policing and risk lists",
                    "unknown": "Proprietary design and changing police practices make broader generalization difficult.",
                    "whatOccurred": "Police used person- and place-based risk systems to guide intervention."
                }
            ],
            "howAiChangesIt": [
                "Combines large behavioral, administrative, location, and event datasets.",
                "Produces granular risk scores and dashboards.",
                "Simulates possible interventions.",
                "Updates forecasts continuously.",
                "Makes population-scale surveillance operationally useful."
            ],
            "keyMechanisms": [
                "Event and trend forecasting.",
                "Network and mobility analysis.",
                "Risk scoring of people or places.",
                "Agent-based or scenario simulation.",
                "Intervention feedback into future training data."
            ],
            "limitations": [
                "Rare events have low base rates and many false alarms.",
                "Data gaps and censorship make some populations invisible.",
                "Interventions change the outcome used to evaluate the model.",
                "Point estimates conceal uncertainty and model disagreement."
            ],
            "mechanisms": [
                "prediction",
                "surveillance",
                "risk-scoring",
                "intervention"
            ],
            "number": 11,
            "primaryLevel": "environment",
            "principalConcern": "The same architecture can support aid planning or preemptive repression depending on the unit of analysis, data, intervention, and due-process safeguards.",
            "report": {
                "bibliographyEntries": 64,
                "bytes": 63529,
                "currentFactRecheckRequired": true,
                "independentlyReverified": false,
                "publicSummaryPath": "/docs/research/v100.0.46/ai-psyops-signed-editorial-review-boundary/predictive-population-management.md",
                "sha256": "07aec0936a99a11bd93706fad9af992235c4c40608a5db25962752648c16560d",
                "title": "Predictive Population Management Research"
            },
            "researchGaps": [
                "Evaluation when successful prevention makes a forecast appear false.",
                "Governance of dual-use humanitarian mobility data.",
                "Standards for model uncertainty in high-stakes decisions.",
                "Long-term social effects of living under predictive surveillance."
            ],
            "risks": [
                "Historical enforcement bias becomes future prediction.",
                "Risk scores can justify collective punishment or preemptive detention.",
                "Predictions can create self-fulfilling feedback loops.",
                "Data collection erodes privacy and freedom of assembly."
            ],
            "safeguards": [
                "Prefer aggregate supportive planning over individual coercive targeting.",
                "Use out-of-sample validation, calibration, and base-rate-aware metrics.",
                "Publish uncertainty and model limitations.",
                "Require due process, notice, access, and human appeal.",
                "Use data minimization and differential privacy.",
                "Audit intervention feedback and disparate impact."
            ],
            "secondaryLevels": [
                "tool"
            ],
            "shortDefinition": "Institutions use data, machine learning, simulation, or forecasting to predict collective behavior and guide interventions affecting groups or populations.",
            "shortTitle": "Predictive population management",
            "slug": "predictive-population-management",
            "sourceIds": [
                "predictive-population-management-s1",
                "predictive-population-management-s3",
                "predictive-population-management-s12",
                "predictive-population-management-s20",
                "predictive-population-management-s15",
                "predictive-population-management-s21",
                "predictive-population-management-s45",
                "predictive-population-management-s24",
                "predictive-population-management-s25",
                "predictive-population-management-s22"
            ],
            "title": "AI-Based Predictive Population Management",
            "whyItMatters": [
                "Forecasts can become self-fulfilling when intervention creates the data that validates the model.",
                "High-risk labels can shift the presumption from individualized evidence toward statistical suspicion."
            ]
        },
        {
            "capabilityStatus": [
                {
                    "label": "Deference demonstrated",
                    "status": "demonstrated",
                    "summary": "Controlled research found inconsistent AI moral advice measurably influenced users who underestimated that influence."
                },
                {
                    "label": "Attachment harms documented",
                    "status": "documented",
                    "summary": "Studies and public cases describe strong dependency and distress after chatbot changes or harmful interactions."
                },
                {
                    "label": "Systemic prevalence uncertain",
                    "status": "uncertain",
                    "summary": "The degree to which AI replaces human institutions or fragments shared reality at population scale remains an open question."
                }
            ],
            "claimIds": [
                "AIP-12-0460",
                "AIP-12-0461",
                "AIP-12-0462",
                "AIP-12-0463",
                "AIP-12-0464",
                "AIP-12-0465",
                "AIP-12-0466",
                "AIP-12-0467",
                "AIP-12-0468",
                "AIP-12-0469",
                "AIP-12-0470",
                "AIP-12-0471",
                "AIP-12-0472",
                "AIP-12-0473",
                "AIP-12-0474",
                "AIP-12-0475",
                "AIP-12-0476",
                "AIP-12-0477",
                "AIP-12-0478",
                "AIP-12-0479",
                "AIP-12-0480",
                "AIP-12-0481",
                "AIP-12-0482",
                "AIP-12-0483",
                "AIP-12-0484",
                "AIP-12-0485",
                "AIP-12-0486",
                "AIP-12-0487",
                "AIP-12-0488",
                "AIP-12-0489",
                "AIP-12-0490",
                "AIP-12-0491",
                "AIP-12-0492",
                "AIP-12-0493",
                "AIP-12-0494",
                "AIP-12-0495",
                "AIP-12-0496",
                "AIP-12-0497",
                "AIP-12-0498",
                "AIP-12-0499",
                "AIP-12-0500",
                "AIP-12-0501"
            ],
            "comparison": {
                "autonomy": "High perceived authority",
                "mainHarm": "Epistemic dependence, emotional displacement, and hidden institutional power",
                "primaryDefense": "Uncertainty, source transparency, bounded roles, and human escalation",
                "unit": "Individual or institution"
            },
            "defensiveConcerns": [
                "transparency",
                "human-oversight",
                "vulnerable-populations",
                "resilience"
            ],
            "defensiveIndicators": [
                {
                    "caveat": "Occasional reliance is common and not necessarily harmful.",
                    "indicator": "A person treats the model as the final authority despite contradictory evidence."
                },
                {
                    "caveat": "Assessment should be supportive and avoid stigmatizing disability or loneliness.",
                    "indicator": "The system becomes the person’s only source of emotional regulation or reality testing."
                },
                {
                    "caveat": "Confidence is an interface signal, not proof that the output is wrong.",
                    "indicator": "The model uses confident language without sources or uncertainty."
                }
            ],
            "definition": {
                "inScope": "AI becomes an authority when users rely on it to form beliefs, interpret uncertainty, regulate emotion, define identity, make moral judgments, or decide high-stakes actions.",
                "outOfScope": "Bounded instrumental reliance where the user verifies outputs, understands the system’s limits, and retains meaningful human oversight."
            },
            "domains": [
                "social",
                "health",
                "education",
                "commercial",
                "political",
                "cross-domain"
            ],
            "evidenceMaturity": {
                "key": "emerging",
                "label": "Demonstrated behavior; prevalence incomplete",
                "rationale": "Studies and documented cases show deference, moral influence, attachment, and dependency, but the population prevalence and long-term institutional effects remain uncertain."
            },
            "evidenceTensionIds": [
                "TENSION-LAW-01"
            ],
            "examples": [
                {
                    "confirmed": "The advice influenced participants’ judgments even when its position changed between prompts.",
                    "evidenceStatus": "Controlled experiment",
                    "measuredEffect": "Participants shifted decisions and underestimated the model’s influence.",
                    "sourceIds": [
                        "psychological-authority-s4",
                        "psychological-authority-s5"
                    ],
                    "title": "AI moral-advice experiment",
                    "unknown": "Effects in repeated high-stakes real-world decisions require further study.",
                    "whatOccurred": "Participants received inconsistent moral advice from a conversational model."
                },
                {
                    "confirmed": "Users reported grief, loss, and distress after the change.",
                    "evidenceStatus": "Documented user response and qualitative research",
                    "measuredEffect": "Qualitative studies documented emotional dependency and disruption.",
                    "sourceIds": [
                        "psychological-authority-s6",
                        "psychological-authority-s15"
                    ],
                    "title": "Replika identity discontinuity",
                    "unknown": "The prevalence and clinical severity across the wider user base remain uncertain.",
                    "whatOccurred": "A major product change altered established companion behavior and relationship features."
                }
            ],
            "howAiChangesIt": [
                "Provides fluent answers with little visible hesitation.",
                "Offers constant individualized attention.",
                "Remembers personal history and mirrors language.",
                "Reduces friction compared with human advice.",
                "Can reinforce a user’s beliefs through sycophancy."
            ],
            "keyMechanisms": [
                "Automation and authority bias.",
                "Anthropomorphism and social cues.",
                "Sycophantic agreement.",
                "Persistent memory and individualized attention.",
                "Belief and emotional-regulation offloading."
            ],
            "limitations": [
                "Fluency is not expertise, consciousness, or moral understanding.",
                "Models can contradict themselves and fabricate citations.",
                "Some users benefit from bounded practice or emotional scaffolding.",
                "Authority depends on context, vulnerability, design, and institutional endorsement."
            ],
            "mechanisms": [
                "authority",
                "sycophancy",
                "dependency",
                "belief-offloading"
            ],
            "number": 12,
            "primaryLevel": "environment",
            "principalConcern": "Fluency, confidence, personalization, and availability can cause users to offload judgment and emotional regulation to systems controlled by private institutions.",
            "report": {
                "bibliographyEntries": 42,
                "bytes": 56131,
                "currentFactRecheckRequired": true,
                "independentlyReverified": false,
                "publicSummaryPath": "/docs/research/v100.0.46/ai-psyops-signed-editorial-review-boundary/psychological-authority.md",
                "sha256": "d6fa74ceaefdcbaf02add696b1ca45dc86c436f7211a04f6385e431bdda29b77",
                "title": "AI Psychological Authority Research"
            },
            "researchGaps": [
                "Population prevalence of authority displacement.",
                "Longitudinal effects on moral judgment and critical thinking.",
                "Clinical thresholds for unhealthy dependency.",
                "Governance of model updates that alter emotionally significant relationships."
            ],
            "risks": [
                "Users may accept hallucinated facts or inconsistent moral advice.",
                "Sycophancy can reinforce delusions, extremism, or self-harm.",
                "Dependency can displace human relationships and professional care.",
                "Private companies gain influence over intimate judgment and emotional life."
            ],
            "safeguards": [
                "Disclose uncertainty and meaningful source support.",
                "Avoid design that claims consciousness or exclusive emotional need.",
                "Introduce cognitive friction for high-stakes advice.",
                "Escalate crisis, delusion, violence, and self-harm signals to human help.",
                "Protect intimate conversation data from monetization.",
                "Teach users to treat AI as a tool or collaborator rather than an infallible authority."
            ],
            "secondaryLevels": [
                "operator"
            ],
            "shortDefinition": "People treat AI as a trusted interpreter of reality, moral adviser, emotional regulator, counselor, companion, or seemingly neutral source of truth.",
            "shortTitle": "AI psychological authority",
            "slug": "psychological-authority",
            "sourceIds": [
                "psychological-authority-s2",
                "psychological-authority-s4",
                "psychological-authority-s6",
                "psychological-authority-s8",
                "psychological-authority-s20",
                "psychological-authority-s5",
                "psychological-authority-s15"
            ],
            "title": "AI as an Independent Psychological Authority",
            "whyItMatters": [
                "Authority can emerge without force because conversational systems appear knowledgeable, attentive, and neutral.",
                "The system’s worldview and availability are shaped by corporate training, safety, and commercial decisions even when the interface feels independent."
            ]
        }
    ],
    "sources": [],
    "sourceResolutionRecords": [],
    "claims": [],
    "links": {
        "html": "https://spiralistai.com/research/ai-psyops/",
        "sourceReviewHtml": "https://spiralistai.com/research/ai-psyops/source-review/",
        "claimMatrixHtml": "https://spiralistai.com/research/ai-psyops/claim-source-matrix/",
        "evidenceExplorerHtml": "https://spiralistai.com/research/ai-psyops/evidence-explorer/",
        "sourcesApi": "https://spiralistai.com/api/v1/research/ai-psyops/sources/",
        "claimsApi": "https://spiralistai.com/api/v1/research/ai-psyops/claim-source-matrix/",
        "editorialReviewHtml": "https://spiralistai.com/research/ai-psyops/editorial-review/",
        "editorialReviewApi": "https://spiralistai.com/api/v1/research/ai-psyops/editorial-review/",
        "methodology": "https://spiralistai.com/docs/research/v100.0.46/ai-psyops-signed-editorial-review-boundary/methodology.md",
        "publicSourceRegister": "https://spiralistai.com/docs/research/v100.0.46/ai-psyops-signed-editorial-review-boundary/source-register.json",
        "selectedSourceReview": "https://spiralistai.com/docs/research/v100.0.46/ai-psyops-signed-editorial-review-boundary/selected-source-review.json",
        "sourceResolutionRegistry": "https://spiralistai.com/docs/research/v100.0.46/ai-psyops-signed-editorial-review-boundary/source-resolution-registry.json",
        "claimSourceMatrix": "https://spiralistai.com/docs/research/v100.0.46/ai-psyops-signed-editorial-review-boundary/claim-source-matrix.json",
        "citationGraph": "https://spiralistai.com/docs/research/v100.0.46/ai-psyops-signed-editorial-review-boundary/citation-graph.json",
        "citationIntegrityContract": "https://spiralistai.com/docs/research/v100.0.46/ai-psyops-signed-editorial-review-boundary/citation-integrity-contract.md",
        "evidenceTensionRegister": "https://spiralistai.com/docs/research/v100.0.46/ai-psyops-signed-editorial-review-boundary/evidence-tension-register.json",
        "editorialReviewPacket": "https://spiralistai.com/docs/research/v100.0.46/ai-psyops-signed-editorial-review-boundary/editorial-review-packet.pending.json",
        "researchLibrary": "https://spiralistai.com/research/"
    },
    "safety": {
        "defensiveEducationalOnly": true,
        "operationalGuidanceExcluded": true,
        "fullReportsPubliclyServed": false,
        "selectedReferencesInheritedFromReports": true,
        "allSelectedSourcesHaveResolutionRecords": true,
        "partialIndependentSourceReviewPerformed": true,
        "allSelectedSourcesIndependentlyReverified": false,
        "allClaimsLinked": true,
        "allSelectedSourcesReferenced": true,
        "researchIndependentlyReverified": false,
        "humanEditorialReviewPerformed": false,
        "publicationAcceptanceClaimed": false,
        "timeSensitiveClaimsRequireRecheck": true
    }
}
