Total claims
Substantive statements extracted from all 12 public category records.

Claim traceability · 501 linked statements · zero orphaned claims
The matrix makes the taxonomy’s evidence chain inspectable without presenting report-derived synthesis as independently verified fact.
Matrix contract
The release distinguishes report-derived synthesis, evidence classifications, examples or allegations as labelled, prospective risks, limitations, research gaps, and governance guidance. A technical demonstration is not treated as prevalence, and reach is not treated as persuasion.
Substantive statements extracted from all 12 public category records.
Report bibliography records available to support or qualify claims.
Bounded automated checks only; no human editorial acceptance is implied.
Validation rejects a public claim with no selected-source linkage.
Browse the matrix
Each category is grouped in a native disclosure so the complete matrix remains usable without JavaScript.
42 claims shown.
Remove one or more filters or reset the evidence view.
| Claim | Evidence class | Selected sources | Review state |
|---|---|---|---|
AIP-04-0125Card definitionGoal-directed software agents observe, remember, plan, communicate, use tools, and adapt toward an influence objective with varying degrees of human supervision. |
Report Derived SynthesisCategory Report Synthesis |
|
Automated source checks in this claim: 3Human reviewed: noPublication accepted: no |
AIP-04-0126In ScopeSoftware systems that pursue an influence-related goal through repeated communication or online action with limited ongoing direction. |
Report Derived SynthesisCategory Report Synthesis |
|
Automated source checks in this claim: 3Human reviewed: noPublication accepted: no |
AIP-04-0127Out Of ScopeSimple scheduled bots, human-authored posts distributed automatically, or ordinary customer-service systems with tightly bounded rules. |
Limitation Or BoundaryCategory Report Synthesis |
|
Automated source checks in this claim: 3Human reviewed: noPublication accepted: no |
AIP-04-0128Principal ConcernAgentic systems combine communication with memory and action, but current long-horizon reliability is much weaker than fluent short-term behavior suggests. |
Report Derived SynthesisCategory Report Synthesis |
|
Automated source checks in this claim: 3Human reviewed: noPublication accepted: no |
AIP-04-0129Why It MattersAgents can sustain many interactions and connect language generation to tools, accounts, and data. |
Report Derived SynthesisCategory Report Synthesis |
|
Automated source checks in this claim: 3Human reviewed: noPublication accepted: no |
AIP-04-0130Why It MattersThe risk grows with memory, permissions, coordination, and the ability to revise strategies, but fluent messages should not be mistaken for durable autonomy. |
Prospective RiskCategory Report Synthesis |
|
Automated source checks in this claim: 3Human reviewed: noPublication accepted: no |
AIP-04-0131How Ai Changes ItPersistent memory and persona continuity. |
Report Derived SynthesisCategory Report Synthesis |
|
Automated source checks in this claim: 3Human reviewed: noPublication accepted: no |
AIP-04-0132How Ai Changes ItPlanning loops and tool invocation. |
Report Derived SynthesisCategory Report Synthesis |
|
Automated source checks in this claim: 3Human reviewed: noPublication accepted: no |
AIP-04-0133How Ai Changes ItContinuous interaction at machine scale. |
Report Derived SynthesisCategory Report Synthesis |
|
Automated source checks in this claim: 3Human reviewed: noPublication accepted: no |
AIP-04-0134How Ai Changes ItCoordination among specialized agents. |
Report Derived SynthesisCategory Report Synthesis |
|
Automated source checks in this claim: 3Human reviewed: noPublication accepted: no |
AIP-04-0135How Ai Changes ItFeedback-based strategy revision in bounded environments. |
Report Derived SynthesisCategory Report Synthesis |
|
Automated source checks in this claim: 3Human reviewed: noPublication accepted: no |
AIP-04-0136Short-term capabilities establishedShort-term capabilities established: Models generate persuasive text, use tools, and sustain bounded multi-turn interaction. |
Evidence ClassificationCategory Report Synthesis |
|
Automated source checks in this claim: 3Human reviewed: noPublication accepted: no |
AIP-04-0137Sandboxed coordination demonstratedSandboxed coordination demonstrated: Synthetic social networks and laboratory multi-agent systems show role division and emergent interaction. |
Evidence ClassificationCategory Report Synthesis |
|
Automated source checks in this claim: 3Human reviewed: noPublication accepted: no |
AIP-04-0138Long-horizon autonomy speculativeLong-horizon autonomy speculative: Multi-month strategic coherence, infrastructure management, and reliable evasion without human intervention remain unsupported. |
Evidence ClassificationCategory Report Synthesis |
|
Automated source checks in this claim: 3Human reviewed: noPublication accepted: no |
AIP-04-0139MechanismObservation and profile maintenance. |
Report Derived SynthesisCategory Report Synthesis |
|
Automated source checks in this claim: 3Human reviewed: noPublication accepted: no |
AIP-04-0140MechanismWorking and long-term memory. |
Report Derived SynthesisCategory Report Synthesis |
|
Automated source checks in this claim: 3Human reviewed: noPublication accepted: no |
AIP-04-0141MechanismPlan–act–evaluate loops. |
Report Derived SynthesisCategory Report Synthesis |
|
Automated source checks in this claim: 3Human reviewed: noPublication accepted: no |
AIP-04-0142MechanismBounded external tool access. |
Report Derived SynthesisCategory Report Synthesis |
|
Automated source checks in this claim: 3Human reviewed: noPublication accepted: no |
AIP-04-0143MechanismRole division among multiple agents. |
Report Derived SynthesisCategory Report Synthesis |
|
Automated source checks in this claim: 3Human reviewed: noPublication accepted: no |
AIP-04-0144Chirper.ai synthetic social networkChirper.ai synthetic social network Demonstrated in a sandboxed platform Thousands of LLM-driven accounts interacted in a synthetic social network after initial configuration. Researchers observed large-scale autonomous posting and social-network patterns. The system demonstrated synthetic interaction and emergent toxic behavior. It did not prove reliable deployment or moderation evasion on real social platforms. |
Fact Allegation Or Experiment As LabelledDirect Example Citation |
|
Automated source checks in this claim: 1Human reviewed: noPublication accepted: no |
AIP-04-0145PRC-linked AI debate operationsPRC-linked AI debate operations Confirmed AI use; low autonomy Operators used AI to generate and adapt content around U.S. technology and trade debates. Platform threat reporting documented the use of AI services. The activity demonstrated human-directed generation and research assistance. The models did not independently operate accounts or set strategy; real autonomy was low. |
Fact Allegation Or Experiment As LabelledDirect Example Citation |
|
Automated source checks in this claim: 0Human reviewed: noPublication accepted: no |
AIP-04-0146RiskTool permissions can turn persuasive interaction into real action. |
Prospective RiskCategory Report Synthesis |
|
Automated source checks in this claim: 3Human reviewed: noPublication accepted: no |
AIP-04-0147RiskPersistent memory can accumulate sensitive information or be poisoned. |
Prospective RiskCategory Report Synthesis |
|
Automated source checks in this claim: 3Human reviewed: noPublication accepted: no |
AIP-04-0148RiskMulti-agent coordination can fabricate social proof. |
Prospective RiskCategory Report Synthesis |
|
Automated source checks in this claim: 3Human reviewed: noPublication accepted: no |
AIP-04-0149RiskLong-running agents can drift, hallucinate, or become sycophantic. |
Prospective RiskCategory Report Synthesis |
|
Automated source checks in this claim: 3Human reviewed: noPublication accepted: no |
AIP-04-0150LimitationAttention and reasoning degrade across long tasks. |
Limitation Or BoundaryCategory Report Synthesis |
|
Automated source checks in this claim: 3Human reviewed: noPublication accepted: no |
AIP-04-0151LimitationMemory retrieval can become stale or noisy. |
Limitation Or BoundaryCategory Report Synthesis |
|
Automated source checks in this claim: 3Human reviewed: noPublication accepted: no |
AIP-04-0152LimitationModels are vulnerable to prompt injection and goal drift. |
Limitation Or BoundaryCategory Report Synthesis |
|
Automated source checks in this claim: 3Human reviewed: noPublication accepted: no |
AIP-04-0153LimitationReal-world campaigns still require human infrastructure and oversight. |
Limitation Or BoundaryCategory Report Synthesis |
|
Automated source checks in this claim: 3Human reviewed: noPublication accepted: no |
AIP-04-0154Defensive IndicatorIndicator: Persistent accounts exhibit abrupt memory or persona discontinuities. Caveat: Humans and legitimate bots can also change behavior. |
Governance Or Defensive GuidanceCategory Report Synthesis |
|
Automated source checks in this claim: 3Human reviewed: noPublication accepted: no |
AIP-04-0155Defensive IndicatorIndicator: Accounts divide roles in a highly regular interaction pattern. Caveat: Formal organizations may coordinate lawfully. |
Prospective RiskCategory Report Synthesis |
|
Automated source checks in this claim: 3Human reviewed: noPublication accepted: no |
AIP-04-0156Defensive IndicatorIndicator: Tool actions occur at machine speed or outside plausible human schedules. Caveat: Scheduled accessibility and support tools can look similar. |
Prospective RiskCategory Report Synthesis |
|
Automated source checks in this claim: 3Human reviewed: noPublication accepted: no |
AIP-04-0157SafeguardRequire clear AI identity disclosure. |
Governance Or Defensive GuidanceCategory Report Synthesis |
|
Automated source checks in this claim: 3Human reviewed: noPublication accepted: no |
AIP-04-0158SafeguardUse least-privilege, short-lived tool permissions. |
Governance Or Defensive GuidanceCategory Report Synthesis |
|
Automated source checks in this claim: 3Human reviewed: noPublication accepted: no |
AIP-04-0159SafeguardLimit execution steps and require reauthorization. |
Governance Or Defensive GuidanceCategory Report Synthesis |
|
Automated source checks in this claim: 3Human reviewed: noPublication accepted: no |
AIP-04-0160SafeguardKeep immutable audit records without storing private content unnecessarily. |
Governance Or Defensive GuidanceCategory Report Synthesis |
|
Automated source checks in this claim: 3Human reviewed: noPublication accepted: no |
AIP-04-0161SafeguardProvide emergency suspension and state rollback. |
Governance Or Defensive GuidanceCategory Report Synthesis |
|
Automated source checks in this claim: 3Human reviewed: noPublication accepted: no |
AIP-04-0162SafeguardEvaluate agents in sandboxes rather than on unwitting populations. |
Governance Or Defensive GuidanceCategory Report Synthesis |
|
Automated source checks in this claim: 3Human reviewed: noPublication accepted: no |
AIP-04-0163Research GapReliable measurement of long-horizon strategic coherence. |
Research GapCategory Report Synthesis |
|
Automated source checks in this claim: 3Human reviewed: noPublication accepted: no |
AIP-04-0164Research GapDetection of agents that deliberately vary behavior. |
Research GapCategory Report Synthesis |
|
Automated source checks in this claim: 3Human reviewed: noPublication accepted: no |
AIP-04-0165Research GapGovernance responsibility across model provider, developer, deployer, and platform. |
Research GapCategory Report Synthesis |
|
Automated source checks in this claim: 3Human reviewed: noPublication accepted: no |
AIP-04-0166Research GapSafe evaluation of persuasion without exposing real users. |
Research GapCategory Report Synthesis |
|
Automated source checks in this claim: 3Human reviewed: noPublication accepted: no |