Systems view

Cognitive attack surface map

The risk is not a single message. It is the chain connecting observation, inference, selection, adaptation, social proof, and consequence.

01Observe
02Infer
03Select
04Adapt
05Amplify
06Consequences

Every transition creates a governance question: what data was collected, what was inferred, whose objective was optimized, what uncertainty was hidden, and what remedy remains?

01Documented

Perception infrastructure

Ranking, recommendation, search, trending, moderation, and notifications decide what is visible, credible, urgent, or socially normal.

Primary liberty risk

A person cannot evaluate choices that were never made visible, and cannot contest a ranking process that remains illegible.

Defensive requirement

Choice of feed, transparency, independent audit, data minimization, and friction before amplification.

02Documented

Synthetic identity

AI-generated faces, voices, biographies, witnesses, experts, employees, and peers can borrow human trust without possessing human accountability.

Primary liberty risk

Trust is transferred to an entity whose identity, interests, capabilities, and accountability are materially misrepresented.

Defensive requirement

Identity disclosure, provenance, behavioral analysis, out-of-band verification, and safeguards for lawful anonymity.

03Emerging / contested

Adaptive persuasion

Systems can alter framing, timing, tone, and content in response to behavioral feedback, creating an asymmetry between the observer and the observed.

Primary liberty risk

The system learns from the person continuously while the person cannot observe the system’s experiments or objective function.

Defensive requirement

Meaningful consent, limits on sensitive inference, transparent intent, outcome audits, and bans on exploitative optimization.

04Documented / emerging

Psychological authority

Fluent, always-available systems can become advisors, companions, interpreters of reality, and substitutes for human relationships or professional care.

Primary liberty risk

Convenience and emotional responsiveness can displace independent judgment, human relationships, or professional accountability.

Defensive requirement

Role clarity, anti-sycophancy design, crisis escalation, time boundaries, human alternatives, and safe relationship off-ramps.

05Documented / emerging

Synthetic consensus

Coordinated networks can simulate social proof, artificial disagreement, conversion, and majority opinion while exhausting verification capacity.

Primary liberty risk

Social proof becomes counterfeit, making coordinated automation appear to be independent public judgment.

Defensive requirement

Network-level detection, rate limits, crisis circuit breakers, provenance, source-level triage, and public prebunking.

06Documented

Predictive governance

Population forecasts can guide aid, but individual or community risk scores can convert probability into suspicion, surveillance, or punishment.

Primary liberty risk

Probability is treated as evidence, producing self-fulfilling feedback loops and punishment without individualized conduct.

Defensive requirement

Aggregate-only use, due process, uncertainty disclosure, independent validation, privacy guarantees, and prohibition of predictive punishment.

CAUSAL CAUTION

Capability, exposure, persuasion, and behavior are different claims.

01Capability

Can a system generate, infer, rank, or adapt?

02Deployment

Was that capability actually used in a real setting?

03Exposure

Did authentic people encounter it at meaningful scale?

04Effect

Did beliefs or behavior change because of it?

05Durability

Did the change persist beyond the immediate interaction?

Search the archive

ProvenanceDependencySurveillance