Independent · no analytics · source-aware InternationalIntelligence.org

CATEGORY 03

AI-Driven Personalized Influence Operations

Organized attempts to alter a person’s perceptions or behavior by tailoring messages to collected or inferred information about that individual.

Tool Mixed or context dependent Updated 2026-07-27 Bilingual parity 2026-07-27

A · DEFINITION

What this category means

Organized attempts to alter a person’s perceptions or behavior by tailoring messages to collected or inferred information about that individual.

Outside its scope

Ordinary customization and transparent recommendations are not inherently manipulative. Risk rises with covert profiling, sensitive data, vulnerability exploitation, and adaptive optimization against the user’s interests.

Evidence basis[1]

B · WHY IT MATTERS

Strategic and public-interest significance

Personalized systems can observe a user continuously while revealing little about their own objective, data inputs, or testing process. This imbalance can undermine informed choice even when the incremental persuasive advantage is small.

Primary AI role
Tool
Unit of influence
individual
Degree of autonomy
Low to moderate
Evidence maturity
Mixed or context dependent

Evidence basis[1, 2, 5]

C · HOW AI CHANGES IT

What changes compared with pre-AI practice

Generative models remove the cost of writing many individualized variants, while adaptive algorithms learn from clicks, replies, and dwell time. Yet rigorous reviews question whether inferred personality traits are accurate enough to make psychographic messages reliably outperform strong generic messages.

Evidence basis[1, 2, 3]

D · CAPABILITY STATUS

Separate current evidence from prospective risk

Confirmed real-world use

  • Commercial and political ecosystems routinely personalize content using demographic, behavioral, and location data. Criminal actors also personalize fraud using scraped or stolen information.

Demonstrated technical capability

  • LLMs can generate tailored messages at scale; evidence that psychographic tailoring adds consistent persuasive value is mixed.

Plausible near-term development

  • Longer multi-turn adaptation may be more consequential than one-off advertisements, but longitudinal evidence is limited.

Speculative or unsupported claims

  • Claims of accurate emotional mind-reading or deterministic behavior control are unsupported.

Evidence basis[1, 2, 3, 4]

E · KEY MECHANISMS

Conceptual mechanisms—not procedures

01

Data aggregation from demographics, location, browsing, purchases, networks, and conversation.

02

Probabilistic inference of interests, intent, or temporary distress.

03

Generative adaptation of tone, framing, and examples.

04

Continuous testing that optimizes a measurable outcome rather than user autonomy.

Evidence basis[1, 2]

F · EVIDENCE AND EXAMPLES

What occurred, what is known, and what remains unknown

Reach, engagement, and visibility are not treated as proof of persuasion or behavior change.

Compare every qualified case across the taxonomy

Cambridge Analytica claims and ICO investigation[1]

What occurred
The firm claimed highly effective psychographic political targeting using harvested Facebook data.
Evidence status
The data protection violations were documented; extraordinary persuasion claims were not substantiated by the regulatory investigation.
Measured or documented effect
The scandal produced major privacy and democratic-trust harms.
What remains unknown
No reliable evidence isolates a decisive effect on election outcomes.

LLM political microtargeting experiment[1, 3]

What occurred
Researchers compared generic and demographically tailored AI-generated political messages.
Evidence status
The controlled capability was demonstrated.
Measured or documented effect
AI messages were persuasive overall, but personalization did not produce a statistically reliable advantage.
What remains unknown
Multi-turn relationships and higher-quality profiles may behave differently.

G · RISKS AND FAILURE MODES

Malicious-use risks and reasons the capability may fail

Primary risks

  • Sensitive data can expose health, financial, religious, or location vulnerabilities.
  • Weak inferences can stereotype and discriminate.
  • Optimization may converge on manipulative framing even without explicit malicious intent.

Evidence basis[1, 4, 5]

Limits and failure modes

  • Digital footprints predict only a limited share of stable personality variation in stricter analyses.
  • Emotion recognition from isolated face or voice signals lacks a reliable scientific foundation.

Evidence basis[1, 2, 3, 4]

H · DETECTION AND DEFENSIVE INDICATORS

Signals are suggestive, not automatic proof

False-positive warning: No single detector score, writing style, profile image artifact, posting pattern, or political similarity should be used alone to accuse a person or organization.
  • Uncannily specific references to private events can indicate cross-context data aggregation, but may also reflect ordinary account history.
  • Interfaces should disclose why content was selected and what data influenced it.

Evidence basis[1, 5]

I · GOVERNANCE AND SAFEGUARDS

Layered controls, oversight, and accountability

  • Make contextual rather than surveillance-based advertising the default.
  • Prohibit or tightly restrict sensitive profiling and emotion inference.
  • Provide meaningful opt-out, data deletion, and explanations.

Evidence basis[1, 4, 5]

J · RESEARCH GAPS

Questions the evidence does not yet resolve

  • Longitudinal effects of adaptive multi-turn persuasion.
  • Reliable measurement of situational vulnerability without creating surveillance harms.
  • Independent replication using real platform delivery systems.

Evidence basis[1, 2, 3]

Compare this category’s questions across the research agenda

K · SOURCES

Traceable source list

The commissioned report is the organizing source. External records below are the principal sources retained for the public synthesis; source quality varies by type and is labelled.

English and Spanish editions are published from the same structured record. Bilingual parity is validated for every release; source titles may remain in their original publication language.

  1. Commissioned research report AI-Driven Personalized Influence Operations: A Comprehensive Interdisciplinary Analysis
    Evidence links: 12
  2. Research record The (In)Effectiveness of Psychological Targeting: A Meta-Analytic Review
    Evidence links: 6
  3. Academic summary Does political microtargeting with large language models offer persuasive returns?
    Evidence links: 5
  4. Peer-reviewed review Emotional expressions reconsidered
    Evidence links: 4
  5. Official enforcement record FTC v. Kochava, Inc.
    Evidence links: 4