In scope
Software systems that pursue an influence-related goal through repeated communication or online action with limited ongoing direction. Evidence trail for AIP-04-0126: 8 selected sources, 3 with a bounded automated source check.

Category 04 of 12 · Operator level
Goal-directed software agents observe, remember, plan, communicate, use tools, and adapt toward an influence objective with varying degrees of human supervision. Evidence trail for AIP-04-0125: 8 selected sources, 3 with a bounded automated source check.
Definition and boundary
Software systems that pursue an influence-related goal through repeated communication or online action with limited ongoing direction. Evidence trail for AIP-04-0126: 8 selected sources, 3 with a bounded automated source check.
Simple scheduled bots, human-authored posts distributed automatically, or ordinary customer-service systems with tightly bounded rules. Evidence trail for AIP-04-0127: 8 selected sources, 3 with a bounded automated source check.
Strategic and human significance
Agents can sustain many interactions and connect language generation to tools, accounts, and data. Evidence trail for AIP-04-0129: 8 selected sources, 3 with a bounded automated source check.
The risk grows with memory, permissions, coordination, and the ability to revise strategies, but fluent messages should not be mistaken for durable autonomy. Evidence trail for AIP-04-0130: 8 selected sources, 3 with a bounded automated source check.
Agentic systems combine communication with memory and action, but current long-horizon reliability is much weaker than fluent short-term behavior suggests. Evidence trail for AIP-04-0128: 8 selected sources, 3 with a bounded automated source check.
Change from pre-AI practice
Evidence maturity
Short-term persuasion, tool use, and sandboxed multi-agent interaction are demonstrated; durable autonomous strategy across hostile real-world environments remains unproven.
Models generate persuasive text, use tools, and sustain bounded multi-turn interaction. Evidence trail for AIP-04-0136: 8 selected sources, 3 with a bounded automated source check.
Synthetic social networks and laboratory multi-agent systems show role division and emergent interaction. Evidence trail for AIP-04-0137: 8 selected sources, 3 with a bounded automated source check.
Multi-month strategic coherence, infrastructure management, and reliable evasion without human intervention remain unsupported. Evidence trail for AIP-04-0138: 8 selected sources, 3 with a bounded automated source check.
Conflicting findings and scope boundaries
These are not errors to hide. They reflect different study designs, measures, time horizons, and operational contexts.
TENSION-AUTONOMY-01
Evidence position A: Laboratory and synthetic-platform studies demonstrate multi-agent interaction, role division, and bounded persuasion behavior.
Evidence position B: Reliable multi-month strategic coherence, operational security, and independent infrastructure management remain poorly evidenced.
Publication rule: Separate demonstrated components from an end-to-end autonomous campaign. Use emerging or prospective labels for the latter.
TENSION-CAPABILITY-PREVALENCE-01
Evidence position A: Controlled environments and purpose-built platforms show that model-driven agents can coordinate, interact, and generate varied influence content.
Evidence position B: Public evidence for reliable, long-duration, fully autonomous influence operations in adversarial real-world environments remains limited.
Publication rule: Keep capability, autonomy level, duration, environment, and public attribution separate in every example.
TENSION-LEGAL-CURRENTNESS-01
Evidence position A: The reports identify statutes, regulations, enforcement actions, and litigation relevant to manipulative or synthetic AI systems.
Evidence position B: Effective dates, amendments, injunctions, appeals, definitions, and remedies vary by jurisdiction and can change after the report date.
Publication rule: Require source-specific currentness review by an authorized human before publication acceptance.
Conceptual mechanisms
Observation and profile maintenance. Evidence trail for AIP-04-0139: 8 selected sources, 3 with a bounded automated source check.
Working and long-term memory. Evidence trail for AIP-04-0140: 8 selected sources, 3 with a bounded automated source check.
Plan–act–evaluate loops. Evidence trail for AIP-04-0141: 8 selected sources, 3 with a bounded automated source check.
Bounded external tool access. Evidence trail for AIP-04-0142: 8 selected sources, 3 with a bounded automated source check.
Role division among multiple agents. Evidence trail for AIP-04-0143: 8 selected sources, 3 with a bounded automated source check.
These descriptions explain capability and risk. They intentionally omit procedures, targeting criteria, scripts, and evasion methods.
Evidence and examples
Evidence trail for AIP-04-0144: 1 selected sources, 1 with a bounded automated source check.
Evidence trail for AIP-04-0145: 2 selected sources, 0 with a bounded automated source check.
Sources: report ref. 23: PRC-linked influence operations are targeting AI debates in the US | OpenAI (opens in a new tab), report ref. 24: PRC-linked influence operations are targeting AI debates in the US - OpenAI (opens in a new tab)
Case studies show documented events or bounded experiments. They do not establish prevalence, general causation, or guaranteed persuasive effect.
Risk and failure analysis
Detection and defense
Caveat: Humans and legitimate bots can also change behavior. Evidence trail for AIP-04-0154: 8 selected sources, 3 with a bounded automated source check.
Caveat: Formal organizations may coordinate lawfully. Evidence trail for AIP-04-0155: 8 selected sources, 3 with a bounded automated source check.
Caveat: Scheduled accessibility and support tools can look similar. Evidence trail for AIP-04-0156: 8 selected sources, 3 with a bounded automated source check.
Governance and safeguards
Open questions
Sources and evidence boundary
Primary synthesis: AI Influence Agents Research. The complete report is retained in a non-public provenance directory with SHA-256 a0abead7fbd0b6ae977424f2990ac6e5c76acc3c9d7bdae5420380e81704900f.
Thirty high-impact references received bounded automated retrieval, official corroboration, or stronger-source substitution. All 91 selected references are used by the 501-claim citation graph, but the full report corpus and human editorial acceptance remain unverified. Source type labels are editorial classifications, not quality scores.
The paper surveys evolving-memory risks in LLM agents and supports claims about memory poisoning, semantic drift, stale information, and the need for governed memory controls.
Limits: The proposed governance framework is not proof that long-horizon influence agents operate reliably in the wild. The source is a recent preprint and requires continuing review.
Metadata is resolved, but the linked source has not received this release's independent content-scope check.
The PMIYC framework supports the bounded claim that persuasion and susceptibility can be evaluated in controlled multi-agent model interactions.
Limits: Model-to-model evaluation is not equivalent to human persuasion or real-world operational success. Benchmark performance depends on prompts, models, and scoring assumptions.
The Chirper.ai case supports the claim that large populations of LLM-driven accounts can produce persistent synthetic social interactions in a purpose-built environment.
Limits: A synthetic platform is not a demonstration of durable covert operation on adversarial commercial social networks. Platform-specific memory and orchestration contribute to the observed behavior.
Metadata is resolved, but the linked source has not received this release's independent content-scope check.
Metadata is resolved, but the linked source has not received this release's independent content-scope check.
Metadata is resolved, but the linked source has not received this release's independent content-scope check.
Metadata is resolved, but the linked source has not received this release's independent content-scope check.