Independent · no analytics · source-aware InternationalIntelligence.org

RESEARCH / TAXONOMY / DEFENSE

AI PSYOPS: A Research Taxonomy

How artificial intelligence can assist, automate, personalize, or become the medium of psychological influence.

Artificial intelligence can affect psychological operations in several distinct ways: as a tool used by human operators, as an adaptive participant in influence campaigns, and as part of the information environment through which people perceive reality. This taxonomy organizes those possibilities into 12 research categories.

12 research categories Evidence cutoff: 2026-07-27 Bilingual parity validated: 2026-07-27 Defensive and non-operational

THREE-LEVEL MODEL

AI can be a tool, an operator, or part of the environment

The levels describe the system’s primary role, not a fixed ladder of danger or autonomy. Several categories overlap more than one level.

INTERACTIVE OVERVIEW

Twelve distinct research categories

Filter by role, domain, mechanism, evidence maturity, or defensive concern. Every category remains available as a dedicated, citable page.

Showing 12 categories

Show all

Choose any combination. The Apply filters button returns a server-rendered result when JavaScript is unavailable.

01 Tool

AI-Assisted Traditional Psychological Operations

Human-led influence campaigns that use AI to assist established research, translation, production, audience analysis, testing, distribution, or evaluation workflows.

Evidence
Documented current use
Principal concern
AI can compress the time and labor required for influence work while encouraging automation bias and overconfidence in weak audience models.
Explore category
02 Tool

AI-Generated Propaganda

Organized persuasive communication in which generative AI creates, substantially transforms, localizes, or mass-produces text, images, audio, video, memes, or synthetic documents.

Evidence
Documented current use
Principal concern
Generative systems remove production bottlenecks, making persuasive and locally adapted material cheap to produce while degrading confidence in authentic evidence.
Explore category
03 Tool

AI-Driven Personalized Influence Operations

Organized attempts to alter a person’s perceptions or behavior by tailoring messages to collected or inferred information about that individual.

Evidence
Mixed or context dependent
Principal concern
The strongest established risk is not precise mind-reading but opaque surveillance, data asymmetry, and exploitation of situational vulnerability.
Explore category
04 Operator

Autonomous AI Influence Agents

Goal-directed software systems that observe, remember, plan, communicate, use tools, or revise influence-related actions with limited ongoing human direction.

Evidence
Emerging capability
Principal concern
Short-term persuasion and tool use are established, but public discussion often overstates current agents’ ability to remain coherent, covert, and strategically effective over months.
Explore category
05 Operator

Synthetic Persona Operations

Coordinated use of fabricated identities presented as real people, experts, organizations, witnesses, activists, journalists, or community members to gain trust or influence decisions.

Evidence
Documented current use
Principal concern
Generative AI lowers the cost of plausible faces, biographies, language, and persistent background activity, while detection can wrongly accuse lawful pseudonymous or non-native users.
Explore category
06 Operator

AI-Driven Disinformation Swarms

Coordinated or emergent networks of accounts, agents, sites, and media assets that use AI to vary, distribute, and amplify misleading narratives at high speed or scale.

Evidence
Emerging capability
Principal concern
The realistic near-term threat is human-directed strategy combined with automated production and distribution that creates synthetic consensus or cognitive overload.
Explore category
07 Environment

Algorithmic Perception Control

Intentional or structurally induced shaping of what people notice, encounter, regard as important, believe to be popular, or treat as credible through ranking, recommendation, search, trending, moderation, and notification systems.

Evidence
Documented current use
Principal concern
Algorithms can set issue salience and manufacture social proof even when they do not reliably persuade users to adopt new beliefs.
Explore category
08 Environment

AI-Enabled Emotional and Behavioral Manipulation

Covert, deceptive, exploitative, or highly asymmetric use of AI-supported inference and adaptive interaction to influence feelings, judgments, choices, or actions against a person’s autonomy.

Evidence
Mixed or context dependent
Principal concern
Systems optimized for engagement or conversion can learn to exploit human biases and distress even when no developer explicitly writes a manipulation rule.
Explore category
09 Operator

AI-Assisted Conversational Entrapment and Recruitment

Sustained AI-assisted dialogue that gradually draws a person toward dependency, secrecy, isolation, fraud, exploitation, extremist commitment, criminal activity, or an abusive actor.

Evidence
Emerging capability
Principal concern
Conversational AI can remove the human labor bottleneck from rapport-building and maintain many personalized interactions, but public evidence for fully autonomous grooming or radicalization at scale remains limited.
Explore category
10 Tool

AI-Enabled Deepfake Psychological Operations

Intentional use of synthetic or manipulated audio, video, imagery, or multimodal media to alter perceptions, impersonate trusted figures, fabricate evidence, provoke action, discredit authentic evidence, or undermine trust.

Evidence
Documented current use
Principal concern
Timing, emotional fit, and trusted distribution can matter more than perfect realism, while the mere possibility of deepfakes enables the liar’s dividend.
Explore category
11 Environment

AI-Based Predictive Population Management

Use of data analysis, machine learning, simulation, or forecasting to predict collective behavior and guide interventions intended to prevent, redirect, contain, or exploit social outcomes.

Evidence
Documented current use
Principal concern
Forecasting can support humanitarian planning at aggregate scale, but individual or neighborhood targeting can reproduce bias, create feedback loops, and substitute statistical probability for due process.
Explore category
12 Environment

AI as an Independent Psychological Authority

AI systems treated as trusted interpreters of reality, moral or emotional advisers, identity validators, counselors, companions, or decision authorities rather than limited tools.

Evidence
Emerging capability
Principal concern
Fluency, availability, personalization, and sycophancy can make a proprietary system feel neutral, caring, and authoritative even when it lacks grounded understanding or consistent values.
Explore category

COMPARISON VIEW

Compare role, mechanism, autonomy, evidence, and defense

On narrow screens, scroll horizontally to compare every column.

The table summarizes the taxonomy; detail pages retain qualifications, examples, and sources.
Category AI role Main mechanisms Unit Autonomy Evidence Main harm Primary defense
1. AI-Assisted Traditional Psychological Operations Tool Content generation, Analysis, Personalization group / population Low to moderate Documented current use AI can compress the time and labor required for influence work while encouraging automation bias and overconfidence in weak audience models. Human oversight
2. AI-Generated Propaganda Tool Content generation, Automation, Deception group / population Low to moderate Documented current use Generative systems remove production bottlenecks, making persuasive and locally adapted material cheap to produce while degrading confidence in authentic evidence. Verification
3. AI-Driven Personalized Influence Operations Tool Personalization, Emotional adaptation, Prediction individual Low to moderate Mixed or context dependent The strongest established risk is not precise mind-reading but opaque surveillance, data asymmetry, and exploitation of situational vulnerability. Privacy
4. Autonomous AI Influence Agents Operator Automation, Personalization, Coordination individual / group Moderate; high autonomy remains prospective Emerging capability Short-term persuasion and tool use are established, but public discussion often overstates current agents’ ability to remain coherent, covert, and strategically effective over months. Human oversight
5. Synthetic Persona Operations Operator Identity, Content generation, Coordination individual / group / institution Low to moderate Documented current use Generative AI lowers the cost of plausible faces, biographies, language, and persistent background activity, while detection can wrongly accuse lawful pseudonymous or non-native users. Detection
6. AI-Driven Disinformation Swarms Operator Coordination, Automation, Content generation group / population Semi-autonomous today; full autonomy prospective Emerging capability The realistic near-term threat is human-directed strategy combined with automated production and distribution that creates synthetic consensus or cognitive overload. Platform governance
7. Algorithmic Perception Control Environment Ranking, Recommendation, Moderation group / population Systemic optimization rather than agent autonomy Documented current use Algorithms can set issue salience and manufacture social proof even when they do not reliably persuade users to adopt new beliefs. Platform governance
8. AI-Enabled Emotional and Behavioral Manipulation Environment Emotional adaptation, Personalization, Ranking individual / group Adaptive optimization; intent may be emergent Mixed or context dependent Systems optimized for engagement or conversion can learn to exploit human biases and distress even when no developer explicitly writes a manipulation rule. Privacy
9. AI-Assisted Conversational Entrapment and Recruitment Operator Conversation, Personalization, Emotional adaptation individual Human-augmented and bounded autonomous systems Emerging capability Conversational AI can remove the human labor bottleneck from rapport-building and maintain many personalized interactions, but public evidence for fully autonomous grooming or radicalization at scale remains limited. Protection of vulnerable users
10. AI-Enabled Deepfake Psychological Operations Tool Deception, Content generation, Authority individual / group / institution Low; distribution may be automated Documented current use Timing, emotional fit, and trusted distribution can matter more than perfect realism, while the mere possibility of deepfakes enables the liar’s dividend. Verification
11. AI-Based Predictive Population Management Environment Prediction, Classification, Surveillance population / group / individual Decision support to automated flagging Documented current use Forecasting can support humanitarian planning at aggregate scale, but individual or neighborhood targeting can reproduce bias, create feedback loops, and substitute statistical probability for due process. Privacy
12. AI as an Independent Psychological Authority Environment Authority, Conversation, Personalization individual / group Conversational authority; institutional control remains human Emerging capability Fluency, availability, personalization, and sycophancy can make a proprietary system feel neutral, caring, and authoritative even when it lacks grounded understanding or consistent values. Protection of vulnerable users

RELATIONSHIP MAP

How the categories connect without collapsing into one technology

Relationship labels identify documented overlap, conceptual dependency, potential combinations, and prospective connections. They do not claim that every combination is operating in practice.

  1. Documented relationship

    AI-Generated PropagandaAI-Driven Disinformation Swarms

    Generated and localized content has supplied documented coordinated networks.

  2. Potential combination

    Synthetic Persona OperationsAutonomous AI Influence Agents

    Persistent personas can serve as the social identity layer for agents.

  3. Common overlap

    AI-Driven Personalized Influence OperationsAI-Enabled Emotional and Behavioral Manipulation

    Personalization becomes manipulation when it covertly exploits vulnerabilities or asymmetric incentives.

  4. Documented relationship

    AI-Enabled Deepfake Psychological OperationsAI-Generated Propaganda

    Synthetic audio and video are documented propaganda assets.

  5. Conceptual dependency

    Algorithmic Perception ControlAI-Driven Disinformation Swarms

    Ranking and engagement systems determine whether coordinated content gains visibility.

  6. Potential combination

    AI-Based Predictive Population ManagementAI-Assisted Traditional Psychological Operations

    Forecasts may inform intervention timing, but this combination raises major rights and validity concerns.

  7. Common overlap

    AI-Assisted Conversational Entrapment and RecruitmentAI as an Independent Psychological Authority

    Authority and dependency can develop through sustained conversational interaction.

  8. Prospective relationship

    Autonomous AI Influence AgentsAI-Driven Disinformation Swarms

    More autonomous agents could coordinate future swarms; current public operations remain human-directed.

METHODOLOGY AND EVIDENCE

How to read this research

  • The taxonomy synthesizes 12 commissioned research reports and preserves their distinctions among historical precedent, documented use, demonstrated capability, emerging risk, and speculation.
  • Reach, impressions, engagement, and virality are not treated as proof of persuasion or behavioral change.
  • Attribution is often uncertain. Case summaries distinguish confirmed, alleged, inferred, and absent AI use.
  • Automated detectors produce false positives and false negatives; indicators are suggestive unless a source supports a stronger conclusion.
  • Fluent output does not establish strategic competence, durable autonomy, or long-term operational coherence.
  • Legal interpretations vary by jurisdiction, facts, speaker, medium, and applicable rights.
  • Operationally sensitive descriptions are abstracted into capability summaries, defensive indicators, failure modes, and governance questions.
  • English and Spanish use the same structured records. Release validation requires every public localizable field to contain both locales and rejects silent English fallback on Spanish routes; source titles remain in their original publication language.

Compare qualified cases without treating reach or engagement as proof of persuasion

Open the deduplicated evidence register and follow every section-level source connection

Use the research glossary to compare definitions and category boundaries

Documented evidence

Public records, investigations, official reports, or documented deployments establish that the activity occurred.

Demonstrated capability

Controlled studies, prototypes, or bounded deployments show a capability under specified conditions.

Emerging risk

Technical components exist, but prevalence, reliability, autonomy, or real-world impact remains uncertain.

Prospective or speculative

A plausible scenario or research hypothesis that has not been established as a current operational capability.

Contested or incomplete

Credible evidence points in different directions, or available data cannot support a strong conclusion.

FROM CAPABILITY AWARENESS TO SOCIETAL RESILIENCE

AI PSYOPS Resilience and Safeguards

The reports repeatedly favor layered defense: people and institutions need verification habits; platforms need transparent, auditable controls; and high-impact systems need privacy, oversight, appeal, and accountability. This guide consolidates those recommendations without implying that prevention, detection, or attribution can ever be perfect.

Open the full resilience guide
  1. 01

    Media literacy and pre-bunking

    Teach people to recognize common influence tactics, uncertainty signals, and source-quality differences before a crisis rather than relying only on post-hoc correction.

  2. 02

    Source verification and crisis procedures

    Establish authenticated channels, out-of-band confirmation, evidence preservation, and time-bounded verification procedures before high-pressure incidents.

  3. 03

    Provenance and authenticity signals

    Use cryptographic provenance, signed media, chain-of-custody records, and source metadata as one layer of authentication.

  4. 04

    Platform transparency and independent research access

    Provide intelligible explanations, exposure data, documented moderation rules, and privacy-preserving access for vetted researchers.

  5. 05

    Data minimization and limits on sensitive profiling

    Collect less behavioral data, restrict cross-context aggregation, and prohibit or tightly constrain emotion inference and coercive use of probabilistic profiles.

  6. 06

    Human review, appeal, and accountable automation

    Keep consequential decisions reviewable by authorized humans, preserve logs, provide explanations and appeals, and assign responsibility across the supply chain.

  7. 07

    Protection for minors and situationally vulnerable users

    Use age-appropriate design, hard safety boundaries, crisis escalation, safe off-ramps, and restrictions on exploitative engagement.

  8. 08

    Clear AI disclosure and interaction boundaries

    Tell people when they are interacting with an AI system, what role it is authorized to play, and when human expertise or intervention is required.

  9. 09

    Careful detection, due process, and false-positive controls

    Combine behavioral, network, contextual, and forensic signals; document uncertainty; and require review before sanctions or public attribution.

  10. 10

    Institutional communication and trust repair

    Correct quickly through verified channels, lead with established facts, preserve evidence, explain uncertainty, and acknowledge institutional errors.