Source resolution · 91 records · automated checks are not human acceptance

Source resolution and bounded review

Every selected bibliography record now has a stable resolution entry, category links, claim links, source-type metadata, limitations, and an explicit reviewer state.

Resolution is not re-verification. 30 high-impact records received an automated retrieval or authoritative-source substitution. 61 remain metadata-resolved but independently unchecked. No named human reviewer has accepted the taxonomy.

Evidence boundary

What the release establishes—and what it does not

The twelve supplied reports remain the primary synthesis sources. All 91 selected bibliography records have resolution entries and are referenced by the 501-claim matrix and 4,157-edge citation graph. Thirty high-impact sources received bounded automated retrieval or authoritative-source substitution. The default v100.0.46 package has no authorized review key and no imported signed human-review artifact; human editorial review, publication acceptance, and full-corpus independent re-verification remain false.

91

Resolution records

Every selected reference has a canonical title, publisher or venue, stable identifier, URL, category links, and reviewer state.

30

Automated source checks

Selected high-impact records were retrieved, corroborated, or replaced by a stronger primary or official source.

61

Checks still pending

These records remain report-inherited bibliography entries. Their metadata is visible, but their scope has not been independently checked here.

501

Linked public claims

Every substantive taxonomy statement maps to one or more selected references. Orphaned claims fail validation.

30 of 91 sources received this bounded automated source check. The complete taxonomy remains not independently reverified.

Complete source-resolution registry

Checked and unresolved records remain visible together.

A checked record means the release process retrieved the selected source or a stronger authoritative substitute and recorded bounded support and limitations. It is not peer review, legal advice, or publication acceptance.

Reset

8 records shown.

All selected source records with bounded resolution and reviewer states.
SourceStatePublisher / typeCategories and claimsScope and limitations
Governing Evolving Memory in LLM Agents: Risks, Mechanisms, and the Stability and Safety Governed Memory (SSGM) Framework - arXiv (opens in a new tab) autonomous-influence-agents-s1 Automated scope check completeResearch Preprint RetrievedHuman reviewed: no arXivResearch PreprintResearch Autonomous Influence Agents40 linked claims
Support and limitations

Bounded support

  • The paper surveys evolving-memory risks in LLM agents and supports claims about memory poisoning, semantic drift, stale information, and the need for governed memory controls.

Limitations

  • The proposed governance framework is not proof that long-horizon influence agents operate reliably in the wild.
  • The source is a recent preprint and requires continuing review.
[2503.01829] Persuade Me if You Can: A Framework for Evaluating Persuasion Effectiveness and Susceptibility Among Large Language Models - arXiv (opens in a new tab) autonomous-influence-agents-s13 Automated scope check completeResearch Preprint RetrievedHuman reviewed: no arXivResearch PreprintResearch Autonomous Influence Agents40 linked claims
Support and limitations

Bounded support

  • The PMIYC framework supports the bounded claim that persuasion and susceptibility can be evaluated in controlled multi-agent model interactions.

Limitations

  • Model-to-model evaluation is not equivalent to human persuasion or real-world operational success.
  • Benchmark performance depends on prompts, models, and scoring assumptions.
[2504.10286] Characterizing LLM-driven Social Network: The Chirper.ai Case - arXiv (opens in a new tab) autonomous-influence-agents-s22 Automated scope check completeResearch Preprint RetrievedHuman reviewed: no arXivResearch PreprintResearch Autonomous Influence Agents41 linked claims
Support and limitations

Bounded support

  • The Chirper.ai case supports the claim that large populations of LLM-driven accounts can produce persistent synthetic social interactions in a purpose-built environment.

Limitations

  • A synthetic platform is not a demonstration of durable covert operation on adversarial commercial social networks.
  • Platform-specific memory and orchestration contribute to the observed behavior.
PRC-linked influence operations are targeting AI debates in the US | OpenAI (opens in a new tab) autonomous-influence-agents-s23 Independent check pendingNot Independently RetrievedHuman reviewed: no OpenAIOfficial Or InstitutionalOfficial Or Institutional Autonomous Influence Agents41 linked claims

This selected reference has not received an independent source-scope review in this release.

PRC-linked influence operations are targeting AI debates in the US - OpenAI (opens in a new tab) autonomous-influence-agents-s24 Independent check pendingNot Independently RetrievedHuman reviewed: no cdn.openai.comOfficial Or InstitutionalOfficial Or Institutional Autonomous Influence Agents41 linked claims

This selected reference has not received an independent source-scope review in this release.

Evaluating AI Agent Persuasion of Safety Monitors - NeurIPS 2026 (opens in a new tab) autonomous-influence-agents-s27 Independent check pendingNot Independently RetrievedHuman reviewed: no neurips.ccSecondary Or TechnicalSecondary Or Technical Autonomous Influence Agents40 linked claims

This selected reference has not received an independent source-scope review in this release.

EU Commission Publishes Guidelines on the Prohibited AI Practices under the AI Act (opens in a new tab) autonomous-influence-agents-s34 Independent check pendingNot Independently RetrievedHuman reviewed: no orrick.comSecondary Or TechnicalSecondary Or Technical Autonomous Influence Agents40 linked claims

This selected reference has not received an independent source-scope review in this release.

Persuading large language models to comply with objectionable requests - PNAS (opens in a new tab) autonomous-influence-agents-s4 Independent check pendingNot Independently RetrievedHuman reviewed: no Proceedings of the National Academy of SciencesResearch SourceResearch Autonomous Influence Agents40 linked claims

This selected reference has not received an independent source-scope review in this release.

Evidence-tension register

Disagreement and scope limits are preserved.

Each tension carries competing bounded statements, public wording, source links, and a null human-decision field. Nothing here silently resolves a contested issue.

TENSION-PERSUASION-01 · Publication Wording Defined Human Adjudication Pending

Bounded persuasion effects versus broad microtargeting claims

One evidence boundary

A preregistered short conversational study found a stronger agreement shift when GPT-4 had basic participant information.

Countervailing boundary

Other report material questions whether psychographic microtargeting reliably adds persuasive value over high-quality generic messages in broader settings.

Public wording: State the design, sample, treatment, and measured outcome. Do not generalize short-term agreement shifts into durable behavior change or population control.

Editorial handling: State the design, sample, treatment, and measured outcome. Do not generalize short-term agreement shifts into durable behavior change or population control.

Reviewer decision: pending

TENSION-AUTONOMY-01 · Publication Wording Defined Human Adjudication Pending

Demonstrated agent coordination versus durable strategic autonomy

One evidence boundary

Laboratory and synthetic-platform studies demonstrate multi-agent interaction, role division, and bounded persuasion behavior.

Countervailing boundary

Reliable multi-month strategic coherence, operational security, and independent infrastructure management remain poorly evidenced.

Public wording: Separate demonstrated components from an end-to-end autonomous campaign. Use emerging or prospective labels for the latter.

Editorial handling: Separate demonstrated components from an end-to-end autonomous campaign. Use emerging or prospective labels for the latter.

Reviewer decision: pending

TENSION-RECOMMENDATION-01 · Publication Wording Defined Human Adjudication Pending

Algorithmic amplification versus claims of universal radicalization

One evidence boundary

Ranking and recommendation systems demonstrably shape exposure, salience, and incentives.

Countervailing boundary

The report corpus also notes that broad causal claims about algorithmically radicalizing the median user remain contested and are confounded by user choice and homophily.

Public wording: Describe exposure and amplification separately from persuasion, identity change, or offline behavior.

Editorial handling: Describe exposure and amplification separately from persuasion, identity change, or offline behavior.

Reviewer decision: pending

TENSION-PROVENANCE-01 · Publication Wording Defined Human Adjudication Pending

Provenance value versus provenance limits

One evidence boundary

Content Credentials can provide cryptographically verifiable, tamper-evident provenance indicators.

Countervailing boundary

Credentials do not establish that depicted events are true, provenance can be incomplete, and metadata can be removed or separated from an asset.

Public wording: Present provenance as one defensive signal alongside source verification, fact-checking, and forensics. Absence of a credential is not proof of fakery.

Editorial handling: Present provenance as one defensive signal alongside source verification, fact-checking, and forensics. Absence of a credential is not proof of fakery.

Reviewer decision: pending

TENSION-REACH-01 · Publication Wording Defined Human Adjudication Pending

Production scale versus authentic audience effect

One evidence boundary

Generative AI can reduce production friction, expand language coverage, and support high-volume content variation.

Countervailing boundary

OpenAI's 2024 disruption report found no meaningful authentic breakout for the five observed operations.

Public wording: Report production, distribution, authentic reach, engagement, persuasion, and behavior as separate measures.

Editorial handling: Report production, distribution, authentic reach, engagement, persuasion, and behavior as separate measures.

Reviewer decision: pending

TENSION-LAW-01 · Publication Wording Defined Human Adjudication Pending

Legal safeguards are time- and jurisdiction-dependent

One evidence boundary

The reports identify existing enforcement actions and regulatory controls relevant to synthetic media, sensitive data, manipulation, and automated decision systems.

Countervailing boundary

Case posture, effective dates, definitions, constitutional constraints, and remedies vary across jurisdictions and change over time.

Public wording: Date-stamp legal statements, identify the jurisdiction and procedural posture, and require current primary-source recheck before publication acceptance.

Editorial handling: Date-stamp legal statements, identify the jurisdiction and procedural posture, and require current primary-source recheck before publication acceptance.

Reviewer decision: pending

TENSION-CAPABILITY-PREVALENCE-01 · Publication Wording Defined Human Adjudication Pending

Controlled capability versus real-world prevalence

One evidence boundary

Controlled environments and purpose-built platforms show that model-driven agents can coordinate, interact, and generate varied influence content.

Countervailing boundary

Public evidence for reliable, long-duration, fully autonomous influence operations in adversarial real-world environments remains limited.

Public wording: Describe demonstrated agent and network capabilities without presenting them as proof of widespread autonomous deployment.

Editorial handling: Keep capability, autonomy level, duration, environment, and public attribution separate in every example.

Reviewer decision: pending

TENSION-SOURCE-AUTHORITY-01 · Authoritative Source Substituted Human Adjudication Pending

Aggregator or social-post references versus primary research

One evidence boundary

The supplied report bibliography includes a social-platform post summarizing detector-bias claims.

Countervailing boundary

A peer-reviewed primary study provides the appropriate bounded evidence for the detector-bias claim and reports dataset- and tool-specific results.

Public wording: Use the primary study for the public claim while retaining the original bibliography URL only as provenance.

Editorial handling: Do not repeat headline percentages from a social post as universal detector performance.

Reviewer decision: pending

TENSION-DETECTION-BIAS-01 · Publication Wording Defined Human Adjudication Pending

Detection utility versus false-positive and population-bias risk

One evidence boundary

Automated detectors and behavioral signals can support triage when combined with provenance and network evidence.

Countervailing boundary

Text and behavior detectors can misclassify non-native, neurodivergent, assisted, or highly formal human communication and should not be treated as conclusive identity evidence.

Public wording: Present automated signals as suggestive and require multi-signal human review before consequential action.

Editorial handling: No single detector score may establish that an account or text is synthetic.

Reviewer decision: pending

Machine-readable tension register

Next evidence gate

Human editorial acceptance remains separate and pending.

The pending packet requires a named reviewer, bounded scope, category-by-category decisions, citation and safety checks, timestamp, and detached signature or explicitly authorized equivalent. This release does not simulate that decision.

Open the pending review packetReturn to the taxonomy

Search Spiralist AI

Find a persona, example, or guide.

Start typing to search the personality library and site resources.