Influence operations

AI-Assisted Psychological Operations

Maps AI onto traditional human-led influence workflows while emphasizing hallucinations, cultural error, automation bias, attribution problems, and defensive governance.

DOCUMENTED + EMERGINGOwner-supplied working paper30 min deep read
Evidence caution: the document is preserved as supplied. Publication here does not independently validate every source, legal conclusion, causal inference, current office-holder, or 2026 claim. Hypothetical sections remain scenarios, not current intelligence.

AI-Assisted Traditional Psychological Operations: An Interdisciplinary Assessment of Capabilities, Risks, and Governance#

1. Executive Summary#

The integration of artificial intelligence into traditional psychological operations (PSYOPS) marks a profound structural shift in the landscape of strategic communications, cognitive warfare, and geopolitical competition. This rigorous interdisciplinary analysis evaluates "AI-assisted traditional PSYOPS," campaigns wherein human operators retain ultimate command and decision-making authority but leverage artificial intelligence to optimize specific stages of the established influence-operation workflow. Through a comprehensive synthesis of military doctrine, psychological research, technical capability assessments, international law, and documented threat intelligence, this analysis addresses the transformative effects of AI on the persuasion, scale, and operational tempo of modern influence campaigns. The evidence indicates that artificial intelligence fundamentally transforms nearly every stage of the traditional PSYOPS cycle, from the initial collection of intelligence and target audience analysis to the generation of highly personalized media and the simulated pre-testing of messaging. While early assessments inferred that artificial intelligence would primarily serve as a "scaling layer"—increasing the speed, volume, and cost-efficiency of propaganda—empirical research now demonstrates that large language models possess qualitatively new persuasive capabilities. Peer-reviewed controlled trials provide empirical evidence that when equipped with micro-targeted sociodemographic data, AI agents can significantly outperform human debaters in altering user beliefs1. Despite these advancements, AI-assisted operations introduce severe systemic vulnerabilities. The reliance on algorithmic generation exposes campaigns to the risks of hallucinations, cultural mistranslations, and automation bias. Furthermore, the delegation of campaign logic to automated systems creates an environment where operators may implicitly trust flawed behavioral models, leading to strategic backfires. Contemporary case studies, including the Israeli firm STOIC and the Russian Doppelganger network, confirm that while the technical production of deceptive content has been mastered, achieving organic audience engagement remains a significant barrier for threat actors4. It must be noted, however, that analysts cannot treat low engagement metrics as definitive proof that persuasion or behavioral change failed to occur among the audiences that were reached. Geopolitically, the democratization of AI capabilities has given rise to an "influence-for-hire" industry, flattening the command structures of traditional intelligence organizations and complicating the legal attribution of cognitive warfare7. Addressing these threats requires a multidimensional defense strategy. The inference drawn from cybersecurity analyses is that relying solely on technical provenance standards, such as digital watermarks and cryptographic metadata, is insufficient due to adversarial spoofing and stripping techniques8. A resilient governance framework must encompass robust cognitive security, stringent enterprise defense architectures, updated interpretations of international non-intervention law, and proactive public resilience initiatives.

2. Definitions and Conceptual Boundaries#

To maintain analytical precision, it is necessary to establish rigid conceptual boundaries distinguishing psychological operations from adjacent communicative practices. Psychological operations, or PSYOPS, are defined as organized, systematic efforts by governments, militaries, intelligence organizations, political movements, corporations, or non-state actors to intentionally influence the perceptions, emotions, reasoning, decisions, or behavior of selected foreign or domestic audiences10. AI-assisted traditional PSYOPS refers specifically to campaigns operating under a human-in-the-loop architecture. In this paradigm, human commanders or campaign managers remain responsible for defining strategic objectives, selecting target audiences, and approving operational deployments. Artificial intelligence is utilized strictly as a toolset to enhance established workflows, rather than as an autonomous agent setting independent strategic goals. It is vital to distinguish legitimate strategic communication from unlawful interference or coercive persuasion. The following taxonomy delineates these boundaries:

  • Strategic Communication and Public Diplomacy: These operations rely on transparent attribution. The origin of the message is clearly identifiable, and the objective is to persuade foreign or domestic audiences through factual representation, policy explanation, and ideological appeal.
  • Advertising: This constitutes commercial persuasion, where the intent to sell a product, service, or brand is legally mandated to be transparent.
  • Military Information Support Operations (MISO): These operations aim to influence target audiences but are strictly bound by military doctrine and international law. They often operate overtly in combat theaters to reduce collateral damage, communicate with civilian populations, or encourage enemy surrender11.
  • Propaganda: This involves the dissemination of biased, selective, or misleading information designed to promote a specific political cause or point of view, often relying on emotional manipulation rather than rational discourse.
  • Disinformation: This requires the deliberate creation and dissemination of demonstrably false information with the explicit intent to deceive.
  • Deception: Operations that obscure the true identity of the sponsor or the nature of an event to create a false reality, often causing an adversary to misallocate resources.
  • Coercive Persuasion: This occurs when an audience is manipulated under conditions that restrict their cognitive autonomy, exploiting severe emotional vulnerabilities, isolation, or psychological pressure.
  • Unlawful Interference: Within the context of international law, this describes operations that utilize methods of coercion to manipulate the sovereign choices of a state, such as disrupting the internal functioning of democratic elections12.

AI-assisted operations operate across this entire spectrum. The technology functions as a dual-use accelerator that can equally optimize a transparent public diplomacy campaign, a commercial advertising rollout, or a covert, state-sponsored disinformation network.

3. Historical Baseline for Traditional PSYOPS#

A rigorous evaluation of AI's impact requires establishing a historical baseline. The fundamental logic of psychological warfare—exploiting human emotion, bias, and information processing—has remained remarkably consistent for centuries, evolving primarily in its medium of delivery rather than its psychological foundation13. During the Second World War, states developed specialized, systematic approaches to cognitive influence. Soviet psychological tactics, for example, utilized cultural pride and historical symbolism to fracture enemy morale while heavily regulating internal information, whereas Japanese efforts focused on placing disguised cultural and educational propaganda in overseas media to shape public perception14. In modern military doctrine, psychological operations are formalized through a rigid, seven-phase process designed to minimize reliance on intuition and maximize systematic behavioral analysis11. This traditional PSYOPS cycle consists of the following phases:

1. Planning: Operators establish the psychological objective (PO) and supporting psychological objectives (SPOs), integrating these goals into the broader military or geopolitical strategy while securing appropriate geopolitical approvals16. 2. Target Audience Analysis (TAA): This is the most critical and labor-intensive analytical phase. Operators segment populations and analyze internal conditions (attitudes, values, beliefs) alongside external conditions (economic, political, social). Analysts determine audience vulnerabilities, susceptibility to messaging, and the accessibility of various communication media to select the optimal psychological appeals16. 3. Series Development: Planners design a synchronized sequence of communications—a series—directed at a specific target audience to achieve a specific behavioral response, mapping out the frequency, duration, and placement of media16. 4. Product Development and Design: Specialists craft the physical or digital media, such as leaflets, radio broadcasts, or social media posts, translating conceptual arguments into tangible products16. 5. Approval: The campaign is subjected to a hierarchical chain of command to ensure strict alignment with strategic policy and legal boundaries prior to deployment16. 6. Production, Distribution, and Dissemination: The campaign is physically or digitally executed across the selected media environments16. 7. Evaluation: Analysts measure the operational impact against predefined assessment criteria and behavioral indicators, adjusting the campaign based on the target audience's reaction15.

This traditional model was historically bottlenecked by the limitations of human labor and cognition. Target Audience Analysis demanded extensive cultural and linguistic expertise, which is slow to develop, impossible to mass-replicate, and costly to deploy10. Product development required graphic designers, native speakers, and cultural liaisons. Consequently, historical PSYOPS were often constrained by the logistical endurance of human organizations and the rigid bureaucracies required to manage them.

4. AI-Enabled PSYOPS Workflow#

The introduction of artificial intelligence effectively unbundles the human limitations inherent in the seven-phase traditional model. By mapping specific AI capabilities to the established PSYOPS workflow, the profound operational transformations become evident.

Collecting and Summarizing Audience Information#

In the initial planning and intelligence-gathering phases, AI systems function as autonomous data ingestion engines. Large language models (LLMs) and machine learning classifiers monitor vast, unstructured data ecosystems, including professional networks, public social media, trade reporting, and leaked databases19. Researchers have developed AI-assisted methodologies to analyze "grey zone domains"—under-regulated web platforms hosting violent or extremist content—allowing operators to extract sentiment and narrative trends at scale while minimizing human exposure to traumatic material20.

Identifying Themes, Grievances, and Social Divisions#

During Target Audience Analysis, AI tools transition from passive data collection to active pattern recognition. Natural language processing algorithms conduct sentiment analysis at a massive scale, identifying emergent grievances, social fault lines, and critical information deficits. These systems map the cognitive terrain of a target population, identifying key communicators, demographic vulnerabilities, and the optimal timing for narrative injection19. This allows campaigns to move from broad demographic assumptions to highly granular, dynamic psychographic profiling.

Translating and Culturally Adapting Communications#

Historically, linguistic accuracy and cultural nuance were the primary failure points for foreign influence operations. Modern generative AI dynamically translates concepts across languages while preserving idioms, slang, and cultural context. Threat actors utilize these models to ensure that malicious content reads as authentic to native speakers, entirely bypassing the need for human linguistic assets and allowing a single operator to project a multi-lingual footprint across varied geographic domains5.

Producing Media#

The most visible transformation occurs in product development. Generative AI enables the instantaneous creation of text, imagery, audio, and video. Threat actors leverage models to generate multi-language text, craft fictional personas with realistic biographies, and produce highly convincing deepfake audio or video4. The emergence of advanced AI-generated video models has allowed state-aligned operations to fabricate localized news events, such as generating fictitious footage of election officials destroying ballots to undermine democratic processes23.

Comparing Alternative Messages Before Publication#

A revolutionary development in campaign planning is the use of Large Language Models for Generative Agent-Based Modeling (GABM). Rather than deploying a message and awaiting real-world feedback, operators can construct highly sophisticated virtual audience simulations. By assigning demographic, psychographic, and emotional parameters to thousands of LLM-driven autonomous agents, campaign managers can test competing narratives within a "silicon sample" of the target population24. These agents exhibit internal reasoning, engage in simulated social interactions, and form synthetic public opinions26. For instance, simulations utilizing massive parallel execution allow agents to process promotional awareness, emotional history, and social connections, generating structured outputs that predict how a specific message will ripple through a population26. This grants operators a zero-risk environment to optimize psychological appeals before authentic publication.

Monitoring Reactions and Measuring Effects#

Following dissemination, AI tools perform continuous sentiment tracking and behavioral modeling. Machine learning algorithms analyze engagement metrics, content diffusion paths, and audience backlash in real time. This rapid feedback loop allows the campaign to iteratively adjust its messaging, correcting ineffective themes at machine speed.

Table 1: Mapping the Traditional PSYOPS Workflow to AI Integration#

Traditional PSYOPS PhaseAI Function & IntegrationClaimed AdvantagesTechnical LimitationsHuman Oversight RequirementsObservable IndicatorsDefensive Controls
1. PlanningAutomated intelligence fusion, strategic forecasting.Rapid processing of unstructured geopolitical data.Hallucinations; lack of contextual nuance.Verification of strategic alignment; checking AI summaries against primary sources.Unnaturally rapid campaign mobilization relative to world events.Compartmentalization of sensitive planning data; network anomaly detection.
2. Target Audience AnalysisSentiment analysis, pattern recognition, social network mapping.Granular micro-targeting; identification of hidden social divisions.Bias in training data skewing demographic assumptions.Validating derived cultural models against on-the-ground human intelligence.Hyper-specific targeting based on obscure, recently aggregated data points.Restricting API access to bulk psychometric data; enhanced privacy legislation.
3. Series DevelopmentGenerative Agent-Based Modeling (GABM) for audience simulation.Zero-risk pre-testing of messaging; high-speed hypothesis validation.Agent degradation; simulation drift from real-world conditions over time.Defining simulation parameters; preventing confirmation bias in scenario design.Iterative message tuning visible across multiple synchronized burner accounts.Monitoring for automated API calls testing algorithmic amplification parameters.
4. Product DevelopmentGenerative text, deepfake audio/video, dynamic translation.Infinite scalability; zero marginal cost; multi-lingual output.Generative artifacts (e.g., visual distortions, repetitive syntax, physical impossibilities).Quality assurance checking for cultural anomalies and physical rendering errors.Presence of AI watermarks; metadata inconsistencies; perfect grammatical homogenization.Implementation of C2PA provenance standards; algorithmic deepfake detection tools.
5. ApprovalAlgorithmic compliance checking against campaign doctrine.Removes bureaucratic bottlenecks; standardizes policy compliance.Inability to judge nuanced ethical or legal thresholds (automation bias).Final legal and ethical sign-off by a human commander.Standardized output lacking human idiosyncrasies or creative variance.Strict access controls requiring multi-factor human authorization for deployment.
6. DisseminationAutomated bot networks, timing optimization, algorithmic amplification.Continuous, fatigue-free operation at machine tempo.Susceptible to platform bot-detection algorithms and rate limits.Monitoring network health; adjusting dissemination tempo to avoid detection.Sudden spikes in synchronized multi-account posting; repetitive temporal patterns.Platform-level behavioral analytics; rate limiting; identification of inauthentic coordination.
7. EvaluationReal-time sentiment tracking and engagement analysis.Immediate strategic adjustment based on incoming data streams.Inability to measure deep, long-term psychological change accurately.Correlating digital engagement metrics with actual geopolitical behavioral shifts.Rapid pivoting of narratives immediately following algorithmic user pushback.Obfuscation of authentic public sentiment data to disrupt adversary feedback loops.

5. Capability and Limitation Assessment#

The central debate regarding artificial intelligence in psychological operations is whether the technology merely increases the speed and scale of existing tactics, or whether it introduces qualitatively new influence capabilities. The evidence indicates that while the primary immediate impact is quantitative, the capacity for hyper-personalized persuasion represents a profound qualitative leap. Historically, PSYOPS operators were forced to broadcast generalized appeals to broad demographic segments. AI facilitates individualized micro-targeting, dynamically adjusting the rhetorical strategy of a message based on a single user's inferred psychological profile. A landmark, peer-reviewed empirical study conducted by researchers at the École Polytechnique Fédérale de Lausanne (EPFL) and Princeton University provides rigorous evidence of this capability. In a controlled, two-by-two factorial design, human subjects engaged in multi-round debates regarding socio-political issues with either another human or the GPT-4 language model. The study found that when the AI was granted access to basic sociodemographic information about the human user—enabling personalized argumentation—the AI was 81.7% more effective at altering the human's beliefs than a human debater1. This evidence demonstrates that AI-generated analysis and content improve actual persuasion rather than merely increasing output. The language models utilized complex analytical reasoning, read as harder to comprehend, and employed customized appeals that human debaters struggled to replicate under time constraints3. However, AI-assisted operations face significant technical limitations and self-induced vulnerabilities. The most critical risk is the "hallucination" of facts or the misinterpretation of cultural contexts. If an AI model's training data is heavily biased or structurally unrepresentative of a target demographic, the resulting audience simulations and generated media will be fundamentally misaligned24. This can cause a campaign to backfire by producing culturally offensive material or utilizing idioms that immediately expose the campaign's foreign origin. Furthermore, human operators risk severe automation bias—the psychological tendency to trust automated systems over human judgment. If campaign commanders excessively defer to AI recommendations during target audience analysis or campaign evaluation, they may deploy resources against phantom social divisions, utilize ineffective psychological appeals, or misinterpret engagement metrics as actual strategic success. The delegation of complex cognitive tasks to machines without rigorous human oversight invites catastrophic strategic failure, particularly when operating in highly volatile geopolitical environments.

Table 2: Assessment of AI Capabilities in Psychological Operations#

Capability ClassificationDescription and EvidenceExample Applications
Established CapabilitiesWidely deployed, highly reliable tools used in current, confirmed operations.Multi-language translation, generative text production, basic sentiment analysis, automated scheduling5.
Demonstrated PrototypesProven in controlled academic environments or limited public deployments, but facing scaling challenges in the wild.Personalized conversational persuasion, synthetic audience simulation via multi-agent generative networks3.
Plausible Near-Term DevelopmentsTechnologically feasible within current paradigms, pending integration and cost reduction.Fully autonomous, closed-loop psychological targeting and multi-modal media generation responding in real-time to global events without human prompting.
Unsupported SpeculationClaims lacking empirical backing, defying current technical realities, or violating principles of cognitive psychology.AI systems capable of overriding deeply entrenched human core values instantly; flawless mind-control logic guaranteeing specific physical behaviors.

6. Comparative Case Studies#

Analyzing documented, public examples of AI-assisted influence operations provides vital insight into the practical application of these capabilities. Threat intelligence reports from major platforms, including OpenAI and Meta, have documented several state-aligned and commercial networks attempting to leverage AI for cognitive warfare4. It is imperative to clearly separate confirmed use of AI from suspected use, and to recognize that while these campaigns produced high volumes of content, analysts must not treat mere engagement metrics as proof of persuasion or behavioral change.

Case Study 1: STOIC / "Zero Zeno" (Israel)#

In 2024, platforms disrupted a network operated by an Israeli political marketing and influence-for-hire firm known as STOIC. OpenAI identified the operation under the moniker "Zero Zeno." The campaign targeted audiences in the United States, Canada, India, Israel, and Ghana. The operators utilized AI models to generate articles and comments focusing on the conflict in Gaza, accusations of antisemitism in North American universities, and domestic Indian politics4. The STOIC operation highlighted the integration of AI into the product development and distribution phases. Operators used AI to fabricate realistic personas, complete with biographies tailored to specific ages, genders, and locations4. However, the campaign demonstrated the limits of AI-assisted PSYOPS without a sophisticated understanding of organic audience dynamics. Despite the sheer volume of generated text, the operation failed to achieve meaningful audience engagement and scored exceptionally low on standard influence breakout scales6. Furthermore, operators exhibited poor oversight, occasionally publishing the AI model's safety refusal messages directly to their social media feeds, immediately exposing the automated nature of the campaign6. This represents a confirmed use of AI that ultimately suffered an operational backfire due to automation bias and sloppy tradecraft.

Case Study 2: Doppelganger (Russia)#

The Russian-aligned "Doppelganger" network represents a highly coordinated, confirmed application of AI in strategic deception. This operation systematically spoofed legitimate European news domains to distribute anti-Ukraine and anti-US propaganda5. Doppelganger operators utilized large language models to ingest authentic Russian propaganda, translate it flawlessly into English, French, German, Italian, and Polish, and generate compelling headlines and short-form social media commentary5. This case study illustrates how AI eliminates the linguistic bottleneck in foreign influence operations. By using generative models to translate and culturally adapt text, Russian operators projected a massive, multi-lingual footprint across platforms like X and Telegram without requiring an army of human linguists6. While the reach was vast, evidence of actual psychological persuasion resulting from this specific campaign remains elusive, underscoring the distinction between content output and cognitive impact.

Case Study 3: Spamouflage (China)#

A Chinese state-aligned network, known as "Spamouflage," utilized AI across an even broader spectrum of the PSYOPS workflow. Beyond generating multi-language text (Chinese, English, Japanese, Korean) to criticize foreign governments, the operators abused AI models for operational security and backend infrastructure6. Threat intelligence confirmed that the actors used AI models to debug code for websites hosting their propaganda and to conduct open-source intelligence research on global social media sentiment6. This demonstrates that AI is not merely a content-generation tool, but a comprehensive operational assistant capable of supporting the technical and analytical infrastructure of cognitive warfare.

7. Organizational and Geopolitical Implications#

The integration of artificial intelligence fundamentally alters the staffing, cost, command structure, accountability, and operational tempo of influence organizations. Historically, state-level psychological operations required vast institutional backing, necessitating specialized military units or highly funded intelligence directorates to sustain the human expertise required for cross-cultural manipulation10. AI drastically lowers the barrier to entry, precipitating the rise of a privatized "influence-for-hire" industry. Firms like STOIC operate with flattened command structures, offering state-level cognitive warfare capabilities to political actors, corporations, or proxy states at a fraction of the traditional cost4. This democratization of influence capabilities creates extreme operational tempo; a small team equipped with agentic AI can hypothesize a narrative, simulate its effects, generate multi-media content, and deploy it globally within hours, acting well within the decision cycle of targeted institutions. Accountability becomes highly diffuse, as state actors can maintain plausible deniability by contracting these capabilities through layers of commercial front companies. Furthermore, AI scales a specific method of strategic influence known as the "respectability engine." This is a pattern of influence operations that manufactures legitimacy for destabilizing claims by laundering narratives through credible formats—such as policy language, risk reporting, and analytical products19. AI agentic tools ingest trade discourse and map institutional sensitivities, allowing adversaries to generate highly tailored narrative variants synchronized with routine operational friction (e.g., minor supply chain delays). The objective is not mass public persuasion, but procedural conversion; when institutional leadership reacts to a polished, AI-generated narrative by initiating audits or delaying approvals, the reaction itself is treated as confirmation, systematically degrading trust in the targeted industrial complex19. However, a paradoxical geopolitical implication arises when viewing AI through the broader lens of irregular warfare. As detailed in strategic analyses such as "The Hollowing Arsenal," traditional irregular warfare and psychological operations derive their power from the "coupling" of human populations to security outcomes10. You persuade human actors—conscripts, logistics workers, or civilian administrators—to defect, doubt, or slow their operations, thereby crippling the adversary10. As modern states aggressively integrate AI into their own security apparatuses—automating logistics, border surveillance, and targeting decisions—the fundamental logic of PSYOPS faces collapse. The inference drawn here is that an automated targeting algorithm cannot be demoralized, and a robotic supply chain cannot be persuaded that its cause is unjust10. Therefore, as the adversary automates its decision-making, population-centric influence yields diminishing strategic returns. Future cognitive warfare must shift away from merely influencing public sentiment and toward directly contesting the adversary's technical systems.

The rapid deployment of AI-assisted influence operations operates within a precarious void in international law and research ethics. The legality of psychological operations in cyberspace largely hinges on the principle of non-intervention, a cornerstone of customary international law that prohibits states from interfering in the internal or external affairs of another sovereign state. According to the legal consensus established by international law scholars in the Tallinn Manual 2.0, a cyber influence operation constitutes an internationally wrongful act if it reaches the threshold of "coercion"29. Under traditional interpretations, persuasion, propaganda, and public diplomacy are generally viewed as lawful, albeit adversarial, practices. However, coercion occurs when an operation deprives a state of its sovereign free will regarding choices that must remain free, such as the conduct of democratic elections12. The enhanced capabilities of AI complicate this legal framework. If an AI system utilizes hyper-personalized targeting derived from stolen psychometric data to manipulate an electorate, it blurs the line between persuasion and coercion. The deployment of AI-generated deepfakes to simulate a political candidate's concession or fabricate evidence of election fraud is increasingly viewed by legal scholars as a coercive intervention, violating both domestic and international law12. The application of criminal indictments and diplomatic sanctions against individuals conducting cyber influence operations indicates a shifting tendency to view these acts as unlawful interference rather than standard espionage30. Ethically, the use of AI for cognitive warfare raises profound human rights concerns, particularly regarding cognitive sovereignty—the right of individuals to control their own mental processes and reasoning without algorithmic subversion. When AI operations utilize the respectability engine to systematically degrade public trust in epistemic institutions (science, media, law), they attack the shared reality necessary for the functioning of a democratic society19. Furthermore, the lack of a coherent, ethically grounded doctrine leaves liberal democracies at a disadvantage. Democracies are rightfully constrained by values of free expression and transparency, while authoritarian adversaries exploit those very freedoms to inject automated disinformation into the public sphere13.

9. Detection and Attribution Indicators#

Distinguishing AI-assisted traditional PSYOPS from ordinary corporate communications, public relations, or authentic political discourse is a formidable challenge for intelligence analysts and platform moderators. Because sophisticated actors use AI to supplement rather than entirely replace human operations, the resulting output often seamlessly mimics authentic human communication6. Technological detection mechanisms primarily rely on identifying artifacts within the generative models or tracking content provenance. The Coalition for Content Provenance and Authenticity (C2PA) has established standards for embedding cryptographically signed metadata into digital media, creating "Content Credentials" that track the origin and alteration history of an asset33. Digital watermarking, such as Google's SynthID, embeds imperceptible signals within the frequency or spatial domains of generated images, text, and audio9. However, cybersecurity analyses warn that no single technical control can reliably establish origin in open, adversarial environments due to a fundamental robustness-spoofing tradeoff9. Technical controls are highly vulnerable. Watermarks can be stripped or degraded through adversarial attacks, such as JPEG compression, color filtering, time-stretching audio, or model-based text rewriting8. Open-source tools routinely allow malicious actors to erase visual watermarks from AI-generated video within minutes, rendering the content indistinguishable from reality to the average consumer23. Furthermore, cryptographic metadata is frequently lost during routine social media uploads or simple screenshotting, resulting in a vast ecosystem of untraceable media8. Consequently, behavioral and structural indicators often provide more reliable attribution. Analysts identify AI-assisted PSYOPS by observing artificial amplification networks, unnatural posting cadences, and the sudden synchronization of hyper-specific narratives across disparate geographic domains4. The inadvertent inclusion of AI prompt refusals (e.g., "As an AI language model, I cannot generate...") in social media posts remains a highly reliable, albeit diminishing, indicator of sloppy operational tradecraft6.

10. Defensive and Governance Recommendations#

Securing the cognitive domain against AI-assisted influence operations requires a layered, defense-in-depth approach that assumes technical control failure. Governments, platforms, civil society, and enterprise security architectures must implement comprehensive strategies.

1. Enterprise and Platform Architecture: Organizations must assume that digital watermarks and metadata will be stripped by adversaries9. Therefore, platforms should implement robust behavioral analytics to detect coordinated inauthentic behavior, focusing on the infrastructure of dissemination rather than the origin of the content. Platforms must invest in generative AI-assisted detection tools to analyze anomalous linguistic patterns and network interactions36. 2. Pre-Bunking and Cognitive Inoculation: Civil society, journalists, and governments must prioritize media literacy and "pre-bunking" programs. Research indicates that forewarning populations about the specific tactics of AI manipulation (e.g., explaining how deepfakes or hyper-personalized bots function) builds cognitive resilience, reducing the efficacy of subsequent exposure to AI-generated disinformation and preserving public cognitive sovereignty36. 3. Institutional Response Discipline: To defeat the "respectability engine," institutions must reform how they respond to manufactured friction. Leaders must avoid procedural overreactions—such as unnecessary audits or public defensive statements—that inadvertently legitimize the adversary's narrative19. Rapid truth publication, aligned with transparent operational integrity checks, is essential. 4. Regulatory and Legal Modernization: Policymakers must establish strict liabilities for the commercial "influence-for-hire" industry. Furthermore, democratic nations must collaboratively articulate red lines regarding cognitive warfare in cyberspace, explicitly defining the boundaries of coercive algorithmic manipulation under international law to deter unlawful interference.

11. Major Research Gaps#

Despite rapid advancements in threat intelligence and behavioral modeling, significant empirical gaps remain regarding AI-assisted PSYOPS:

  • Longitudinal Behavioral Impact: While short-term studies demonstrate the persuasive efficacy of LLMs in controlled debates2, there is a lack of research on the long-term retention of AI-induced belief changes. It is unknown whether individuals revert to their original beliefs after leaving the digital environment, or if the persuasion endures.
  • LLM Escalation Dynamics: Studies indicate that LLMs utilized in military simulations exhibit tendencies toward escalation and aggressive action38. The integration of these models into influence campaign command structures requires further study to understand the risk of uncontrolled narrative escalation.
  • Simulation Divergence: As Generative Agent-Based Modeling becomes prevalent for campaign pre-testing, it remains unclear how rapidly these simulated "silicon samples" drift from reality when subjected to novel, real-world geopolitical shocks, potentially leading operators to base campaigns on highly flawed assumptions25.

12. Conclusion#

The weaponization of artificial intelligence within traditional psychological operations represents a strategic inflection point in the nature of conflict and cognitive warfare. The evidence confirms that AI does not merely scale the output of historical propaganda; it introduces the capacity for instantaneous, multi-lingual, hyper-personalized cognitive influence. By unburdening human operators from the logistical friction of target audience analysis, cultural translation, and media production, AI allows both state and non-state actors to execute persistent, machine-tempo campaigns that directly attack the epistemic foundations of targeted societies. While the empirical evidence confirms the superior persuasive capabilities of personalized AI models, these operations are not infallible. They remain highly vulnerable to hallucinations, automation bias, and the inability to generate authentic, organic community engagement. However, as the technological barrier to entry collapses, the proliferation of commercial influence-for-hire firms will continue to obscure attribution and challenge the legal frameworks governing international non-intervention. Protecting the cognitive sovereignty of modern populations requires acknowledging that the battle for influence will increasingly be decided not by traditional kinetic superiority, but by the resilience of human psychology against algorithmic optimization.

13. Annotated Bibliography#

The foundational literature for this report spans military doctrine, empirical psychology, cybersecurity threat intelligence, and geopolitical theory, forming the basis of the preceding analysis:

  • Department of the Army (2007). Psychological Operations Process Tactics, Techniques, and Procedures (FM 3-05.301).15: This foundational military doctrine explicitly outlines the rigid seven-phase process utilized in traditional U.S. psychological operations. It provides the essential historical baseline against which modern AI integration is measured. While slightly dated regarding digital media, its articulation of Target Audience Analysis remains highly reliable as a doctrinal framework.
  • Dawson, M., Khan, A. H., & Nartey, C. (2025). Weaponising the Mind: AI, Cyberspace, and the Future of Psychological Operations. Journal of Military Studies13: This peer-reviewed academic analysis traces the evolutionary trajectory of propaganda from World War II to modern digital campaigns. The authors reliably articulate how AI expands the PSYOPS toolkit, arguing against technological determinism while highlighting the vulnerability of democratic transparency to algorithmic persuasion.
  • Salvi, F. et al. (2024). On the Conversational Persuasiveness of Large Language Models: A Randomized Controlled Trial. Nature Human Behaviour1: A critical, highly reliable empirical study conducted by researchers at EPFL and Princeton. By utilizing a rigorous two-by-two factorial design, the researchers provided definitive quantitative evidence that LLMs, when equipped with personalized sociodemographic data, are significantly more persuasive than human debaters, confirming the qualitative shift in AI influence capabilities.
  • OpenAI Threat Intelligence (2024). Disrupting Deceptive Uses of AI by Covert Influence Operations.6: A primary source intelligence report detailing the disruption of specific, state-aligned, and commercial AI influence operations, including the Russian Doppelganger network and the Israeli firm STOIC. While limited by the platform's proprietary visibility constraints, the report provides vital evidence of the operational reality, successes, and failures of AI integration in the wild.
  • Irregular Warfare Center (2026). The Hollowing Arsenal: How Artificial Intelligence Erodes the Foundations of Irregular Warfare.10: A strategic geopolitical analysis arguing that AI adoption systematically attacks the foundational logic of irregular warfare. The authors provide a reliable theoretical framework asserting that as adversaries automate their decision-making and logistics, traditional psychological operations targeting human populations will yield diminishing strategic returns.
  • Schmitt, M. N. (Ed.) (2017). Tallinn Manual 2.0 on the International Law Applicable to Cyber Operations.12: The definitive, peer-reviewed legal text regarding state conduct in cyberspace. The manual's articulation of the principle of non-intervention and the threshold of "coercion" forms the foundational legal framework for evaluating the legality of AI-assisted influence operations across international borders.

Works cited#

1. GPT-4 Outperforms Humans in Persuasion by 82% in This New Study, https://www.digitalinformationworld.com/2024/04/gpt-4-outperforms-humans-in-persuasion.html 2. \[2403.14380\] On the Conversational Persuasiveness of Large Language Models: A Randomized Controlled Trial - arXiv, https://arxiv.org/abs/2403.14380 3. (PDF) On the Conversational Persuasiveness of Large Language Models: A Randomized Controlled Trial - ResearchGate, https://www.researchgate.net/publication/381186642\_On\_the\_Conversational\_Persuasiveness\_of\_Large\_Language\_Models\_A\_Randomized\_Controlled\_Trial 4. OpenAI cracks down on Israeli "for-hire threat actor" Stoic | Ctech, https://www.calcalistech.com/ctechnews/article/yft28i1tl 5. Germany Targeted by the Pro-Russian Disinformation Campaign “Doppelgänger”, https://www.auswaertiges-amt.de/resource/blob/2682484/2da31936d1cbeb9faec49df74d8bbe2e/technischer-bericht-desinformationskampagne-doppelgaenger-1--data.pdf 6. Disrupting deceptive uses of AI by covert influence operations - OpenAI, https://openai.com/index/disrupting-deceptive-uses-of-ai-by-covert-influence-operations/ 7. Israeli influence operation highlights global disinformation industry - CyberScoop, https://cyberscoop.com/israel-influence-operations-stoic/ 8. What Lies Ahead for Generative AI Watermarking, https://blog.genlaw.org/pdfs/genlaw\_icml2024/27.pdf 9. Authenticity Debt and the Synthetic Content Threat Landscape: A Layered Framework for Trust, Provenance, and IP Governance in the Generative AI Era - arXiv, https://arxiv.org/html/2606.00621v1 10. The Hollowing Arsenal: How Artificial Intelligence Erodes the Foundations of Irregular Warfare, https://irregularwarfarecenter.org/publications/perspectives/the-hollowing-arsenal-how-artificial-intelligence-erodes-the-foundations-of-irregular-warfare/ 11. Theoretical Implications for Inform and Influence Activities - DTIC, https://apps.dtic.mil/sti/tr/pdf/ADA589562.pdf 12. Cyber and Influence Operations Targeting Elections: Back to the Principle of Non-Intervention - EJIL: Talk!, https://www.ejiltalk.org/cyber-and-influence-operations-targeting-elections-back-to-the-principle-of-non-intervention/ 13. Old Propaganda Tricks Add a New Digital Upgrade | Illinois Institute of Technology, https://www.iit.edu/news/old-propaganda-tricks-add-new-digital-upgrade 14. Weaponising the mind: AI, cyberspace and the future of psychological operations, https://www.researchgate.net/publication/398827283\_Weaponising\_the\_mind\_AI\_cyberspace\_and\_the\_future\_of\_psychological\_operations 15. Military Psychological Operations Manual | PDF - Scribd, https://www.scribd.com/document/339009930/Restricted-U-S-Army-Psychological-Operations-Process-Tactics-Techniques-and-Procedures-Manual-FM-3-05-301-pdf 16. Psyops: 7 Phase Process Overview | PDF | Behavior | Psychological Egoism - Scribd, https://www.scribd.com/document/440177708/7-Phases-study 17. Target Audience Analysis in PsyOps | PDF | Military Intelligence - Scribd, https://id.scribd.com/document/623285985/Intro-to-TAIA 18. JP 3-13.2, Psychological Operations - BITS, https://www.bits.de/NRANEU/others/jp-doctrine/jp3\_13\_2%2810%29.pdf 19. Information Influence in AI-Assisted Hybrid Warfare in the U.S. Industrial Complex, https://globalsecurityreview.com/information-influence-in-ai-assisted-hybrid-warfare-in-the-u-s-industrial-complex/ 20. New report: AI-assisted analysis of war-related content on grey zone domains, https://www.psychologicaldefence.lu.se/article/new-report-ai-assisted-analysis-war-related-content-grey-zone-domains-1 21. NAVAL POSTGRADUATE SCHOOL THESIS - DTIC, https://apps.dtic.mil/sti/pdfs/AD1173493.pdf 22. OpenAI says Russian and Israeli groups used its tools to spread disinformation, https://www.theguardian.com/technology/article/2024/may/30/openai-disinformation-russia-israel-china-iran 23. OpenAI's Sora: When Seeing Should Not Be Believing - NewsGuard, https://www.newsguardtech.com/special-reports/openai-sora-seeing-should-not-be-believing/ 24. Audience Simulation: Can LLMs Predict Human Behavior? - AIMultiple, https://aimultiple.com/audience-simulation 25. Virtual Audience Simulation Canvas: Designing For LLM-Powered Synthetic Data Insights, https://askrally.com/article/virtual-audience-simulation-canvas 26. \[Literature Review\] LLM-Based Multi-Agent System for Simulating and Analyzing Marketing and Consumer Behavior - Moonlight, https://www.themoonlight.io/en/review/llm-based-multi-agent-system-for-simulating-and-analyzing-marketing-and-consumer-behavior 27. Synthetic Social Media Influence Experimentation Via an Agentic Reinforcement Learning Large Language Model Bot - JASSS, https://www.jasss.org/28/3/6.html 28. OpenAI says it disrupted covert influence operation by Israeli firm STOIC, https://www.timesofisrael.com/openai-says-it-disrupted-covert-influence-operation-by-israeli-firm-stoic/ 29. Taming the Lawless Void: Tracking the Evolution of International Law Rules for Cyberspace, https://tnsr.org/2020/07/taming-the-lawless-void-tracking-the-evolution-of-international-law-rules-for-cyberspace/ 30. A Rule Book on the Shelf? Tallinn Manual 2.0 on Cyberoperations and Subsequent State Practice | American Journal of International Law | Cambridge Core, https://www.cambridge.org/core/journals/american-journal-of-international-law/article/rule-book-on-the-shelf-tallinn-manual-20-on-cyberoperations-and-subsequent-state-practice/54FBA2B30081B53353B5D2F06F778C14 31. Manufacturing Reality-AI, PsyOps, and the War You Can't See | by VEEXH - Medium, https://medium.com/the-sleuth-sheet/manufacturing-reality-ai-psyops-and-the-war-you-cant-see-2fe312d0e783 32. Maurice Dawson's lab | Illinois Institute of Technology (IIT) - ResearchGate, https://www.researchgate.net/lab/Center-for-Cyber-Security-and-Forensics-Education-Maurice-Dawson 33. How OpenAI, Google, and Anthropic Plan to Handle the 2026 US Midterms, https://www.techpolicy.press/how-openai-google-and-anthropic-plan-to-handle-the-2026-us-midterms/ 34. Content Credentials: Strengthening Multimedia Integrity in the Generative AI Era, https://media.defense.gov/2025/Jan/29/2003634788/-1/-1/0/CSI-CONTENT-CREDENTIALS.PDF 35. From AI-Generated Content to Agentic Action: Security and Safety Threats in Generative AI - arXiv, https://arxiv.org/html/2605.16471 36. From Trolls to Generative AI: Russia's Disinformation Evolution, https://www.cigionline.org/publications/from-trolls-to-generative-ai-russias-disinformation-evolution/ 37. Artificial Intelligence (AI) now more persuasive than humans in debates? - FBK, https://www.fbk.eu/en/press-releases/artificial-intelligence-ai-now-more-persuasive-than-humans-in-debates/ 38. Causal Reasoning and Large Language Models for Military Decision-Making: Rethinking the Command Structures in the Era of Generative AI - MDPI, https://www.mdpi.com/2673-2688/7/1/14 39. FM 3-05.130 Army Special Operations Forces Unconventional Warfare - Academia.edu, https://www.academia.edu/32074830/FM\_3\_05\_130\_Army\_Special\_Operations\_Forces\_Unconventional\_Warfare

Search the archive

ProvenanceDependencySurveillance