AI as a tool
Humans retain strategic control while AI assists with research, production, translation, targeting analysis, or measurement.
RESEARCH / TAXONOMY / DEFENSE
How artificial intelligence can assist, automate, personalize, or become the medium of psychological influence.
Artificial intelligence can affect psychological operations in several distinct ways: as a tool used by human operators, as an adaptive participant in influence campaigns, and as part of the information environment through which people perceive reality. This taxonomy organizes those possibilities into 12 research categories.
THREE-LEVEL MODEL
The levels describe the system’s primary role, not a fixed ladder of danger or autonomy. Several categories overlap more than one level.
Humans retain strategic control while AI assists with research, production, translation, targeting analysis, or measurement.
AI systems conduct sustained interactions, adapt communications, coordinate activity, or pursue influence-related objectives with varying autonomy.
Ranking, recommendation, authority, forecasting, and institutional systems shape what people encounter and how decisions are framed.
INTERACTIVE OVERVIEW
Filter by role, domain, mechanism, evidence maturity, or defensive concern. Every category remains available as a dedicated, citable page.
Showing 12 categories
Choose any combination. The Apply filters button returns a server-rendered result when JavaScript is unavailable.
Active filters:
Human-led influence campaigns that use AI to assist established research, translation, production, audience analysis, testing, distribution, or evaluation workflows.
Organized persuasive communication in which generative AI creates, substantially transforms, localizes, or mass-produces text, images, audio, video, memes, or synthetic documents.
Organized attempts to alter a person’s perceptions or behavior by tailoring messages to collected or inferred information about that individual.
Goal-directed software systems that observe, remember, plan, communicate, use tools, or revise influence-related actions with limited ongoing human direction.
Coordinated use of fabricated identities presented as real people, experts, organizations, witnesses, activists, journalists, or community members to gain trust or influence decisions.
Coordinated or emergent networks of accounts, agents, sites, and media assets that use AI to vary, distribute, and amplify misleading narratives at high speed or scale.
Intentional or structurally induced shaping of what people notice, encounter, regard as important, believe to be popular, or treat as credible through ranking, recommendation, search, trending, moderation, and notification systems.
Covert, deceptive, exploitative, or highly asymmetric use of AI-supported inference and adaptive interaction to influence feelings, judgments, choices, or actions against a person’s autonomy.
Sustained AI-assisted dialogue that gradually draws a person toward dependency, secrecy, isolation, fraud, exploitation, extremist commitment, criminal activity, or an abusive actor.
Intentional use of synthetic or manipulated audio, video, imagery, or multimodal media to alter perceptions, impersonate trusted figures, fabricate evidence, provoke action, discredit authentic evidence, or undermine trust.
Use of data analysis, machine learning, simulation, or forecasting to predict collective behavior and guide interventions intended to prevent, redirect, contain, or exploit social outcomes.
AI systems treated as trusted interpreters of reality, moral or emotional advisers, identity validators, counselors, companions, or decision authorities rather than limited tools.
Reset one or more filters to restore the full taxonomy.
COMPARISON VIEW
On narrow screens, scroll horizontally to compare every column.
| Category | AI role | Main mechanisms | Unit | Autonomy | Evidence | Main harm | Primary defense |
|---|---|---|---|---|---|---|---|
| 1. AI-Assisted Traditional Psychological Operations | Tool | Content generation, Analysis, Personalization | group / population | Low to moderate | Documented current use | AI can compress the time and labor required for influence work while encouraging automation bias and overconfidence in weak audience models. | Human oversight |
| 2. AI-Generated Propaganda | Tool | Content generation, Automation, Deception | group / population | Low to moderate | Documented current use | Generative systems remove production bottlenecks, making persuasive and locally adapted material cheap to produce while degrading confidence in authentic evidence. | Verification |
| 3. AI-Driven Personalized Influence Operations | Tool | Personalization, Emotional adaptation, Prediction | individual | Low to moderate | Mixed or context dependent | The strongest established risk is not precise mind-reading but opaque surveillance, data asymmetry, and exploitation of situational vulnerability. | Privacy |
| 4. Autonomous AI Influence Agents | Operator | Automation, Personalization, Coordination | individual / group | Moderate; high autonomy remains prospective | Emerging capability | Short-term persuasion and tool use are established, but public discussion often overstates current agents’ ability to remain coherent, covert, and strategically effective over months. | Human oversight |
| 5. Synthetic Persona Operations | Operator | Identity, Content generation, Coordination | individual / group / institution | Low to moderate | Documented current use | Generative AI lowers the cost of plausible faces, biographies, language, and persistent background activity, while detection can wrongly accuse lawful pseudonymous or non-native users. | Detection |
| 6. AI-Driven Disinformation Swarms | Operator | Coordination, Automation, Content generation | group / population | Semi-autonomous today; full autonomy prospective | Emerging capability | The realistic near-term threat is human-directed strategy combined with automated production and distribution that creates synthetic consensus or cognitive overload. | Platform governance |
| 7. Algorithmic Perception Control | Environment | Ranking, Recommendation, Moderation | group / population | Systemic optimization rather than agent autonomy | Documented current use | Algorithms can set issue salience and manufacture social proof even when they do not reliably persuade users to adopt new beliefs. | Platform governance |
| 8. AI-Enabled Emotional and Behavioral Manipulation | Environment | Emotional adaptation, Personalization, Ranking | individual / group | Adaptive optimization; intent may be emergent | Mixed or context dependent | Systems optimized for engagement or conversion can learn to exploit human biases and distress even when no developer explicitly writes a manipulation rule. | Privacy |
| 9. AI-Assisted Conversational Entrapment and Recruitment | Operator | Conversation, Personalization, Emotional adaptation | individual | Human-augmented and bounded autonomous systems | Emerging capability | Conversational AI can remove the human labor bottleneck from rapport-building and maintain many personalized interactions, but public evidence for fully autonomous grooming or radicalization at scale remains limited. | Protection of vulnerable users |
| 10. AI-Enabled Deepfake Psychological Operations | Tool | Deception, Content generation, Authority | individual / group / institution | Low; distribution may be automated | Documented current use | Timing, emotional fit, and trusted distribution can matter more than perfect realism, while the mere possibility of deepfakes enables the liar’s dividend. | Verification |
| 11. AI-Based Predictive Population Management | Environment | Prediction, Classification, Surveillance | population / group / individual | Decision support to automated flagging | Documented current use | Forecasting can support humanitarian planning at aggregate scale, but individual or neighborhood targeting can reproduce bias, create feedback loops, and substitute statistical probability for due process. | Privacy |
| 12. AI as an Independent Psychological Authority | Environment | Authority, Conversation, Personalization | individual / group | Conversational authority; institutional control remains human | Emerging capability | Fluency, availability, personalization, and sycophancy can make a proprietary system feel neutral, caring, and authoritative even when it lacks grounded understanding or consistent values. | Protection of vulnerable users |
RELATIONSHIP MAP
Relationship labels identify documented overlap, conceptual dependency, potential combinations, and prospective connections. They do not claim that every combination is operating in practice.
AI-Generated PropagandaAI-Driven Disinformation Swarms
Generated and localized content has supplied documented coordinated networks.
Synthetic Persona OperationsAutonomous AI Influence Agents
Persistent personas can serve as the social identity layer for agents.
AI-Driven Personalized Influence OperationsAI-Enabled Emotional and Behavioral Manipulation
Personalization becomes manipulation when it covertly exploits vulnerabilities or asymmetric incentives.
AI-Enabled Deepfake Psychological OperationsAI-Generated Propaganda
Synthetic audio and video are documented propaganda assets.
Algorithmic Perception ControlAI-Driven Disinformation Swarms
Ranking and engagement systems determine whether coordinated content gains visibility.
AI-Based Predictive Population ManagementAI-Assisted Traditional Psychological Operations
Forecasts may inform intervention timing, but this combination raises major rights and validity concerns.
AI-Assisted Conversational Entrapment and RecruitmentAI as an Independent Psychological Authority
Authority and dependency can develop through sustained conversational interaction.
Autonomous AI Influence AgentsAI-Driven Disinformation Swarms
More autonomous agents could coordinate future swarms; current public operations remain human-directed.
METHODOLOGY AND EVIDENCE
Compare qualified cases without treating reach or engagement as proof of persuasion
Open the deduplicated evidence register and follow every section-level source connection
Use the research glossary to compare definitions and category boundaries
Public records, investigations, official reports, or documented deployments establish that the activity occurred.
Controlled studies, prototypes, or bounded deployments show a capability under specified conditions.
Technical components exist, but prevalence, reliability, autonomy, or real-world impact remains uncertain.
A plausible scenario or research hypothesis that has not been established as a current operational capability.
Credible evidence points in different directions, or available data cannot support a strong conclusion.
FROM CAPABILITY AWARENESS TO SOCIETAL RESILIENCE
The reports repeatedly favor layered defense: people and institutions need verification habits; platforms need transparent, auditable controls; and high-impact systems need privacy, oversight, appeal, and accountability. This guide consolidates those recommendations without implying that prevention, detection, or attribution can ever be perfect.
Teach people to recognize common influence tactics, uncertainty signals, and source-quality differences before a crisis rather than relying only on post-hoc correction.
Establish authenticated channels, out-of-band confirmation, evidence preservation, and time-bounded verification procedures before high-pressure incidents.
Use cryptographic provenance, signed media, chain-of-custody records, and source metadata as one layer of authentication.
Provide intelligible explanations, exposure data, documented moderation rules, and privacy-preserving access for vetted researchers.
Collect less behavioral data, restrict cross-context aggregation, and prohibit or tightly constrain emotion inference and coercive use of probabilistic profiles.
Keep consequential decisions reviewable by authorized humans, preserve logs, provide explanations and appeals, and assign responsibility across the supply chain.
Use age-appropriate design, hard safety boundaries, crisis escalation, safe off-ramps, and restrictions on exploitative engagement.
Tell people when they are interacting with an AI system, what role it is authorized to play, and when human expertise or intervention is required.
Combine behavioral, network, contextual, and forensic signals; document uncertainty; and require review before sanctions or public attribution.
Correct quickly through verified channels, lead with established facts, preserve evidence, explain uncertainty, and acknowledge institutional errors.