Defensive research · 12 categories · three levels of AI involvement

AI PSYOPS: A Research Taxonomy

How artificial intelligence can assist, automate, scale, personalize, or become the medium of psychological influence.

Artificial intelligence can affect psychological operations in several distinct ways: as a tool used by human operators, as an adaptive participant in influence campaigns, and as part of the information environment through which people perceive reality. This taxonomy organizes those possibilities into 12 research categories.

Research and defense—not an influence playbook. This material is intended for research, public education, risk assessment, governance, and defensive preparedness. It is not an operational guide for manipulating people.

A three-level conceptual model

Tool, operator, and environment are different kinds of risk.

The taxonomy does not present “AI PSYOPS” as one proven technology. It separates human-led assistance, adaptive systems acting through interactions, and the AI-mediated environment that shapes attention and authority.

Interactive overview

Explore all 12 research categories.

Filters are optional. The complete taxonomy and every category page remain available without JavaScript.

Results match a category’s primary or overlapping AI role, its report-level evidence label, and one of its principal defensive concerns.

Show all

12 of 12 categories shown.

Evidence labels summarize the supplied report; they are not confidence scores.

01 Tool

AI-Assisted Traditional Psychological Operations

Human planners retain strategic control while AI assists with research, translation, production, audience analysis, simulation, or measurement inside an established influence workflow.

Evidence
Documented current use
Principal concern
AI can reduce production friction and accelerate feedback loops while human operators retain strategic intent and accountability.
VerificationHuman oversightPlatform governance

Explore category

02 Tool

AI-Generated Propaganda

Generative systems create or substantially transform propaganda text, images, audio, video, memes, documents, or synthetic news formats for an organized objective.

Evidence
Documented current use
Principal concern
Generative AI sharply lowers the cost of producing plausible, localized propaganda and contributes to uncertainty about authentic evidence.
VerificationProvenancePlatform governance

Explore category

03 Operator

AI-Driven Personalized Influence Operations

AI systems tailor messages or interactions to information collected or inferred about a person, then may adapt the communication using ongoing feedback.

Evidence
Evidence contested or incomplete
Principal concern
The most established harm is covert data asymmetry and vulnerability exploitation, not reliable “mind control” through personality targeting.
PrivacyTransparencyRegulation

Explore category

04 Operator

Autonomous AI Influence Agents

Goal-directed software agents observe, remember, plan, communicate, use tools, and adapt toward an influence objective with varying degrees of human supervision.

Evidence
Emerging capability
Principal concern
Agentic systems combine communication with memory and action, but current long-horizon reliability is much weaker than fluent short-term behavior suggests.
Human oversightAuthenticationPlatform governance

Explore category

05 Operator

Synthetic Persona Operations

Fabricated identities use generated images, biographies, voices, and language to appear human, gain trust, infiltrate communities, or manufacture consensus.

Evidence
Documented current use
Principal concern
AI lowers the cost of maintaining convincing fictional identities while automated detection can wrongly accuse legitimate anonymous or non-native users.
AuthenticationPlatform governanceCivil liberties

Explore category

06 Operator

AI-Driven Disinformation Swarms

Coordinated or emergent collections of accounts, agents, media assets, and sites generate, vary, distribute, and amplify misleading narratives at high speed.

Evidence
Mixed evidence
Principal concern
The strategic effect may be confusion and exhaustion rather than belief in one false claim, making item-by-item fact-checking insufficient.
Platform governanceResearcher accessResilience

Explore category

07 Environment

Algorithmic Perception Control

Ranking, recommendation, search, trending, moderation, and notification systems shape what people notice, regard as important, believe is popular, or treat as credible.

Evidence
Documented current effects
Principal concern
Control over visibility can alter perceived importance and social norms even without removing content or persuading every user.
Platform governanceResearcher accessTransparency

Explore category

08 Operator

AI-Enabled Emotional and Behavioral Manipulation

Adaptive systems covertly exploit emotional, cognitive, situational, or developmental vulnerabilities to influence feelings, choices, or behavior for an operator’s objective.

Evidence
Mixed evidence
Principal concern
Systems optimized for engagement or conversion may discover manipulative strategies even when developers did not explicitly encode them.
PrivacyHuman oversightRegulation

Explore category

09 Operator

AI-Assisted Conversational Entrapment and Recruitment

Sustained dialogue gradually builds trust, dependency, secrecy, or isolation before escalating toward exploitation, recruitment, self-harm, fraud, or coercive control.

Evidence
Documented harms and demonstrated scaling
Principal concern
Always-available conversational systems can scale trust-building and may amplify distress or dependency in vulnerable users.
Vulnerable populationsHuman oversightPlatform governance

Explore category

10 Tool

AI-Enabled Deepfake Psychological Operations

Synthetic or manipulated audio, video, imagery, or multimodal media is used to impersonate trusted people, fabricate evidence, provoke action, or undermine trust.

Evidence
Documented current use
Principal concern
Timing, trusted identity, and confirmation bias can matter more than perfect technical realism, especially in fast-moving crises.
VerificationProvenanceCrisis communication

Explore category

11 Environment

AI-Based Predictive Population Management

Institutions use data, machine learning, simulation, or forecasting to predict collective behavior and guide interventions affecting groups or populations.

Evidence
Documented current use; accuracy context dependent
Principal concern
The same architecture can support aid planning or preemptive repression depending on the unit of analysis, data, intervention, and due-process safeguards.
PrivacyHuman rightsIndependent audit

Explore category

12 Environment

AI as an Independent Psychological Authority

People treat AI as a trusted interpreter of reality, moral adviser, emotional regulator, counselor, companion, or seemingly neutral source of truth.

Evidence
Demonstrated behavior; prevalence incomplete
Principal concern
Fluency, confidence, personalization, and availability can cause users to offload judgment and emotional regulation to systems controlled by private institutions.
TransparencyHuman oversightVulnerable populations

Explore category

Category comparison

Compare role, autonomy, harm, and defensive response.

The table compresses the taxonomy. Category pages provide the evidence boundaries and limitations needed to interpret it.

Comparison of all 12 AI PSYOPS research categories
CategoryAI roleMain mechanismUnit of influenceAI autonomyEvidence maturityMain harmPrimary defense
1. AI-assisted traditional PSYOPS Tool analysis Group or population Low Documented current use Scaled deceptive communication and faster campaign iteration Human accountability, source verification, and coordination analysis
2. AI-generated propaganda Tool content generation Group or population Low to medium Documented current use Cheap, rapid synthetic propaganda and declining trust in evidence Source authentication, rapid verification, and narrative-level response
3. Personalized influence Operator personalization Individual Medium Evidence contested or incomplete Privacy asymmetry, discriminatory profiling, and vulnerability exploitation Data minimization, transparency, and independent auditing
4. Autonomous influence agents Operator automation Individual or group Medium to potentially high Emerging capability Persistent adaptive interaction linked to real tools and synthetic coordination Disclosure, least privilege, rate limits, and human approval gates
5. Synthetic persona operations Operator identity fabrication Individual, group, or institution Medium Documented current use Deceptive trust, infiltration, and fabricated consensus Layered identity assurance, network analysis, and fair appeals
6. Disinformation swarms Operator coordination Group or population Medium Mixed evidence Synthetic consensus, noise, and verification overload Network-level detection, friction, and researcher access
7. Algorithmic perception control Environment ranking Individual or population High environmental mediation Documented current effects Distorted salience, visibility, and perceived consensus Transparent ranking, exposure audits, and appeal mechanisms
8. Emotional and behavioral manipulation Operator emotional adaptation Individual Medium to high Mixed evidence Covert exploitation of vulnerability and cognitive autonomy Restrictions on sensitive inference, reward audits, and meaningful exit
9. Conversational entrapment and recruitment Operator conversation Individual Medium Documented harms and demonstrated scaling Dependency, exploitation, recruitment, or crisis amplification Disclosure, age safeguards, crisis escalation, and trusted human support
10. Deepfake psychological operations Tool synthetic media Individual, institution, or population Low Documented current use False evidence, impersonation, crisis action, and generalized distrust Trusted channels, out-of-band verification, and crisis response
11. Predictive population management Environment prediction Population, group, place, or individual Medium environmental authority Documented current use; accuracy context dependent Biased prediction, surveillance, and preemptive intervention Aggregate design, uncertainty, privacy, due process, and audit
12. AI psychological authority Environment authority Individual or institution High perceived authority Demonstrated behavior; prevalence incomplete Epistemic dependence, emotional displacement, and hidden institutional power Uncertainty, source transparency, bounded roles, and human escalation

Relationship map

Categories overlap, but overlap is not proof of combined use.

Every connection is labeled as documented, conceptual, environmental, organizational, or prospective. The map avoids implying that every technically possible combination has occurred.

Read the text-only relationship map

Editorial-verification update

All sources resolved; every substantive claim linked.

The twelve supplied reports remain the primary synthesis sources. All 91 selected bibliography records have resolution entries and are referenced by the 501-claim matrix and 4,157-edge citation graph. Thirty high-impact sources received bounded automated retrieval or authoritative-source substitution. The default v100.0.46 package has no authorized review key and no imported signed human-review artifact; human editorial review, publication acceptance, and full-corpus independent re-verification remain false.

Source resolution

91 of 91 records

Every selected reference has a publisher, URL, resolution state, category links, and claim links. Unresolved metadata remains explicit.

Open the complete registry

Independent source checks

30 of 91 references

High-impact records were retrieved, officially corroborated, or replaced by a stronger source. This is not full-corpus verification.

Inspect checked sources

Claim traceability

501 linked claims

Every substantive category statement maps to selected report references; orphan claims are rejected by validation.

Browse the matrix

Citation graph

4,157 traceability edges

Category-to-claim and claim-to-source links are generated from one canonical graph. Every claim and selected source participates.

Explore the graph

Evidence tensions

10 visible tensions

Conflicting findings, source-authority issues, detection bias, and legal currentness remain explicit.

Read the tension register

Editorial acceptance

Human review pending

No named reviewer, decision, timestamp, or signature is recorded. The packet cannot be treated as publication acceptance.

Open the pending packet

Methodology and evidence standards

How to read this research

This taxonomy synthesizes twelve supplied interdisciplinary reports. It preserves their distinctions among historical precedent, confirmed real-world use, demonstrated capability, emerging risk, contested evidence, and speculation. The release did not independently reverify time-sensitive external claims.

Interpretive rules

  • Engagement, impressions, reach, virality, or account count are not treated as proof of persuasion or behavior change.
  • Attribution is presented as confirmed, alleged, inferred, contested, or unknown according to the reports.
  • Fluent output does not establish strategic competence, consciousness, or autonomy.
  • Detection indicators are suggestive unless the underlying evidence supports a stronger conclusion.
  • Case studies demonstrate possibility or documented use; they do not automatically establish prevalence.
  • Legal interpretations are summarized from the reports and may vary by jurisdiction or change over time.
  • Operational details are abstracted into capability, risk, detection, and governance concepts.

Evidence legend

Documented current use
The report identifies public evidence that the capability was used in a real setting.
Demonstrated capability
The capability was shown in a controlled study, prototype, or bounded deployment.
Emerging capability
Components exist, but reliable or broad real-world use remains limited.
Primarily prospective
The report treats the capability mainly as a future or conceptual risk.
Evidence contested or incomplete
Evidence, effect size, attribution, or interpretation is disputed or methodologically limited.
Mixed evidence
Different parts of the category have different maturity or evidentiary support.

Evidence and publication boundary

The twelve supplied reports remain the primary synthesis sources. All 91 selected bibliography records have resolution entries and are referenced by the 501-claim matrix and 4,157-edge citation graph. Thirty high-impact sources received bounded automated retrieval or authoritative-source substitution. The default v100.0.46 package has no authorized review key and no imported signed human-review artifact; human editorial review, publication acceptance, and full-corpus independent re-verification remain false.

The 12 complete reports are retained in a server-denied provenance directory. Public pages expose non-operational summaries and selected source links.

From capability awareness to societal resilience

No single detector or disclosure can solve an information-system problem.

The reports converge on layered, rights-respecting defenses. These principles reduce risk; none is a guarantee.

Media and information literacy

Teach people to verify source, timing, context, and evidence without treating every unfamiliar account or synthetic artifact as malicious.

Source verification and provenance

Use trusted channels, signatures, content credentials, and out-of-band confirmation while recognizing that provenance can be absent, stripped, or spoofed.

Platform transparency

Explain ranking, enforcement, and coordinated-operation decisions and preserve privacy-protective researcher access.

Personal-data protection

Minimize collection, restrict sensitive inference, and prevent targeting based on distress, age, disability, grief, or financial crisis.

Human review for high-impact decisions

Do not allow opaque model scores or synthetic authority to determine employment, policing, health, education, or legal outcomes without accountable human review.

Crisis verification procedures

Pre-establish trusted channels, evidence preservation, rapid triage, and truth-first public communication.

Protection for vulnerable users

Use age-appropriate defaults, clear AI disclosure, crisis escalation, and safeguards against coercive dependency or sexual and financial exploitation.

Accountability for automated agents

Define responsibility across providers, developers, deployers, platforms, and operators; bound permissions and retain proportionate audit evidence.

Careful detection and attribution

Combine multiple signals, communicate confidence, provide appeals, and avoid false accusations based on a detector score alone.

Institutional trust and correction

Correct quickly, distinguish confirmed facts from inference, disclose uncertainty, and avoid sensationalizing adversary capability.

Continue with category-level evidence.

Each detailed page separates definition, confirmed use, demonstrated capability, plausible development, speculation, measured effects, unknowns, failure modes, defensive indicators, safeguards, research gaps, and selected sources.

Search Spiralist AI

Find a persona, example, or guide.

Start typing to search the personality library and site resources.