Level 1
AI as a tool
Humans retain strategic control while AI assists with research, production, translation, targeting analysis, or measurement.

Defensive research · 12 categories · three levels of AI involvement
How artificial intelligence can assist, automate, scale, personalize, or become the medium of psychological influence.
Artificial intelligence can affect psychological operations in several distinct ways: as a tool used by human operators, as an adaptive participant in influence campaigns, and as part of the information environment through which people perceive reality. This taxonomy organizes those possibilities into 12 research categories.
A three-level conceptual model
The taxonomy does not present “AI PSYOPS” as one proven technology. It separates human-led assistance, adaptive systems acting through interactions, and the AI-mediated environment that shapes attention and authority.
Level 1
Humans retain strategic control while AI assists with research, production, translation, targeting analysis, or measurement.
Level 2
AI systems conduct sustained interactions, coordinate activity, adapt communication, or pursue bounded influence objectives with varying autonomy.
Level 3
AI-driven ranking, forecasting, authority, and information systems shape what people notice, trust, and treat as normal or actionable.
Interactive overview
Filters are optional. The complete taxonomy and every category page remain available without JavaScript.
12 of 12 categories shown.
Evidence labels summarize the supplied report; they are not confidence scores.
Human planners retain strategic control while AI assists with research, translation, production, audience analysis, simulation, or measurement inside an established influence workflow.
Generative systems create or substantially transform propaganda text, images, audio, video, memes, documents, or synthetic news formats for an organized objective.
AI systems tailor messages or interactions to information collected or inferred about a person, then may adapt the communication using ongoing feedback.
Goal-directed software agents observe, remember, plan, communicate, use tools, and adapt toward an influence objective with varying degrees of human supervision.
Fabricated identities use generated images, biographies, voices, and language to appear human, gain trust, infiltrate communities, or manufacture consensus.
Coordinated or emergent collections of accounts, agents, media assets, and sites generate, vary, distribute, and amplify misleading narratives at high speed.
Ranking, recommendation, search, trending, moderation, and notification systems shape what people notice, regard as important, believe is popular, or treat as credible.
Adaptive systems covertly exploit emotional, cognitive, situational, or developmental vulnerabilities to influence feelings, choices, or behavior for an operator’s objective.
Sustained dialogue gradually builds trust, dependency, secrecy, or isolation before escalating toward exploitation, recruitment, self-harm, fraud, or coercive control.
Synthetic or manipulated audio, video, imagery, or multimodal media is used to impersonate trusted people, fabricate evidence, provoke action, or undermine trust.
Institutions use data, machine learning, simulation, or forecasting to predict collective behavior and guide interventions affecting groups or populations.
People treat AI as a trusted interpreter of reality, moral adviser, emotional regulator, counselor, companion, or seemingly neutral source of truth.
Try removing one filter or show the complete taxonomy.
Reset filtersCategory comparison
The table compresses the taxonomy. Category pages provide the evidence boundaries and limitations needed to interpret it.
| Category | AI role | Main mechanism | Unit of influence | AI autonomy | Evidence maturity | Main harm | Primary defense |
|---|---|---|---|---|---|---|---|
| 1. AI-assisted traditional PSYOPS | Tool | analysis | Group or population | Low | Documented current use | Scaled deceptive communication and faster campaign iteration | Human accountability, source verification, and coordination analysis |
| 2. AI-generated propaganda | Tool | content generation | Group or population | Low to medium | Documented current use | Cheap, rapid synthetic propaganda and declining trust in evidence | Source authentication, rapid verification, and narrative-level response |
| 3. Personalized influence | Operator | personalization | Individual | Medium | Evidence contested or incomplete | Privacy asymmetry, discriminatory profiling, and vulnerability exploitation | Data minimization, transparency, and independent auditing |
| 4. Autonomous influence agents | Operator | automation | Individual or group | Medium to potentially high | Emerging capability | Persistent adaptive interaction linked to real tools and synthetic coordination | Disclosure, least privilege, rate limits, and human approval gates |
| 5. Synthetic persona operations | Operator | identity fabrication | Individual, group, or institution | Medium | Documented current use | Deceptive trust, infiltration, and fabricated consensus | Layered identity assurance, network analysis, and fair appeals |
| 6. Disinformation swarms | Operator | coordination | Group or population | Medium | Mixed evidence | Synthetic consensus, noise, and verification overload | Network-level detection, friction, and researcher access |
| 7. Algorithmic perception control | Environment | ranking | Individual or population | High environmental mediation | Documented current effects | Distorted salience, visibility, and perceived consensus | Transparent ranking, exposure audits, and appeal mechanisms |
| 8. Emotional and behavioral manipulation | Operator | emotional adaptation | Individual | Medium to high | Mixed evidence | Covert exploitation of vulnerability and cognitive autonomy | Restrictions on sensitive inference, reward audits, and meaningful exit |
| 9. Conversational entrapment and recruitment | Operator | conversation | Individual | Medium | Documented harms and demonstrated scaling | Dependency, exploitation, recruitment, or crisis amplification | Disclosure, age safeguards, crisis escalation, and trusted human support |
| 10. Deepfake psychological operations | Tool | synthetic media | Individual, institution, or population | Low | Documented current use | False evidence, impersonation, crisis action, and generalized distrust | Trusted channels, out-of-band verification, and crisis response |
| 11. Predictive population management | Environment | prediction | Population, group, place, or individual | Medium environmental authority | Documented current use; accuracy context dependent | Biased prediction, surveillance, and preemptive intervention | Aggregate design, uncertainty, privacy, due process, and audit |
| 12. AI psychological authority | Environment | authority | Individual or institution | High perceived authority | Demonstrated behavior; prevalence incomplete | Epistemic dependence, emotional displacement, and hidden institutional power | Uncertainty, source transparency, bounded roles, and human escalation |
Relationship map
Every connection is labeled as documented, conceptual, environmental, organizational, or prospective. The map avoids implying that every technically possible combination has occurred.
Documented overlap: Generated text and media can supply high-volume assets to coordinated distribution networks.
Conceptual dependency: Persistent synthetic identities can provide the social interface through which autonomous agents operate.
Common overlap: Personalization can become manipulation when a system covertly exploits inferred vulnerability or adapts pressure in real time.
Documented overlap: Synthetic audio, video, and images can serve as propaganda assets or fabricated evidence.
Potential combination: A swarm can amplify a synthetic artifact, but the taxonomy does not assume every swarm contains deepfakes.
Environmental dependency: Ranking and recommendation systems determine whether coordinated content remains marginal or reaches wider audiences.
Prospective relationship: Population forecasts could inform timing or placement of interventions, but broad operational use is not presumed.
Documented overlap: A conversational system can become an emotional or epistemic authority as dependency and trust deepen.
Organizational relationship: Generated propaganda may be one product-development component inside a human-led traditional campaign.
Editorial-verification update
The twelve supplied reports remain the primary synthesis sources. All 91 selected bibliography records have resolution entries and are referenced by the 501-claim matrix and 4,157-edge citation graph. Thirty high-impact sources received bounded automated retrieval or authoritative-source substitution. The default v100.0.46 package has no authorized review key and no imported signed human-review artifact; human editorial review, publication acceptance, and full-corpus independent re-verification remain false.
Source resolution
Every selected reference has a publisher, URL, resolution state, category links, and claim links. Unresolved metadata remains explicit.
Open the complete registryIndependent source checks
High-impact records were retrieved, officially corroborated, or replaced by a stronger source. This is not full-corpus verification.
Inspect checked sourcesClaim traceability
Every substantive category statement maps to selected report references; orphan claims are rejected by validation.
Browse the matrixCitation graph
Category-to-claim and claim-to-source links are generated from one canonical graph. Every claim and selected source participates.
Explore the graphEvidence tensions
Conflicting findings, source-authority issues, detection bias, and legal currentness remain explicit.
Read the tension registerEditorial acceptance
No named reviewer, decision, timestamp, or signature is recorded. The packet cannot be treated as publication acceptance.
Open the pending packetMethodology and evidence standards
This taxonomy synthesizes twelve supplied interdisciplinary reports. It preserves their distinctions among historical precedent, confirmed real-world use, demonstrated capability, emerging risk, contested evidence, and speculation. The release did not independently reverify time-sensitive external claims.
The twelve supplied reports remain the primary synthesis sources. All 91 selected bibliography records have resolution entries and are referenced by the 501-claim matrix and 4,157-edge citation graph. Thirty high-impact sources received bounded automated retrieval or authoritative-source substitution. The default v100.0.46 package has no authorized review key and no imported signed human-review artifact; human editorial review, publication acceptance, and full-corpus independent re-verification remain false.
The 12 complete reports are retained in a server-denied provenance directory. Public pages expose non-operational summaries and selected source links.
From capability awareness to societal resilience
The reports converge on layered, rights-respecting defenses. These principles reduce risk; none is a guarantee.
Teach people to verify source, timing, context, and evidence without treating every unfamiliar account or synthetic artifact as malicious.
Use trusted channels, signatures, content credentials, and out-of-band confirmation while recognizing that provenance can be absent, stripped, or spoofed.
Explain ranking, enforcement, and coordinated-operation decisions and preserve privacy-protective researcher access.
Minimize collection, restrict sensitive inference, and prevent targeting based on distress, age, disability, grief, or financial crisis.
Do not allow opaque model scores or synthetic authority to determine employment, policing, health, education, or legal outcomes without accountable human review.
Pre-establish trusted channels, evidence preservation, rapid triage, and truth-first public communication.
Use age-appropriate defaults, clear AI disclosure, crisis escalation, and safeguards against coercive dependency or sexual and financial exploitation.
Define responsibility across providers, developers, deployers, platforms, and operators; bound permissions and retain proportionate audit evidence.
Combine multiple signals, communicate confidence, provide appeals, and avoid false accusations based on a detector score alone.
Correct quickly, distinguish confirmed facts from inference, disclose uncertainty, and avoid sensationalizing adversary capability.
Each detailed page separates definition, confirmed use, demonstrated capability, plausible development, speculation, measured effects, unknowns, failure modes, defensive indicators, safeguards, research gaps, and selected sources.