Psychosecurity

/ˌsaɪkəʊsɪˈkjʊərɪti/ noun

The protection of individuals and societies from systematic psychological attack — and the discipline of drawing the line between legitimate influence and the deliberate decomposition of a human mind.

Confronting AI-Driven Zersetzung

01 · The Term

Why a new word was needed

Cybersecurity protectsmachines & networks
Information security protectsdata
Psychosecurity protectsminds

Psychosecurity brings clinical, legal, and security expertise together to defend psychological integrity against deliberate attack.

States have always sought to persuade, and sometimes to deceive. International practice tolerates a broad spectrum of influence activity directed at populations. But there is a qualitatively different category of operation: the systematic, covert destruction of a specific person's relationships, reputation, livelihood, and sense of reality. History has a name for it: Zersetzung, a documented method of state repression. The task now is to draw the line between influence and Zersetzung explicitly, because artificial intelligence could lower the cost of targeted abuse.

Psychosecurity names both the problem and the field: the study of psychological attack as a security threat, and the assembly of legal, technical, clinical, and doctrinal defences against it.

02 · The Precedent

Zersetzung: a documented history of abuse

From the early 1970s until 1989, the East German Ministry for State Security — the Stasi — practised Zersetzung, literally "decomposition". Alongside imprisonment and surveillance, it used a quieter method: the covert dismantling of a person's life, conducted so that the target could rarely tell what was being done to them, or by whom.

The Stasi's methods included spreading fabricated rumours to destroy friendships and careers, intercepting and altering correspondence, orchestrating unexplained professional failures, and using informers to undermine trust within groups. The damage looked like ordinary misfortune. The psychological effects — depression, anxiety, psychosomatic illness, and in documented cases suicide — did not.

After German reunification, these operations were extensively documented from the Stasi's own records. German rehabilitation law recognises qualifying Zersetzung measures as state injustice and provides a route to compensation. This history is the initiative's reference point.

Explainer video: the history of Zersetzung, documented methods, and emerging digital risks. Captions available. Licensed CC BY-SA 4.0; archival sources, credits and licences appear in the closing titles.

Read the full history of Zersetzung →

1976

Stasi Directive 1/76 formalises Zersetzung — covert psychological decomposition — as a primary method of political repression, alongside imprisonment and surveillance.

1989–1991

Fall of the German Democratic Republic. Citizens secure Stasi archives against destruction. The Stasi Records Act establishes public access in 1991.

1990s–2000s

Victims gain rehabilitation and compensation pathways for state injustice. The method becomes a paradigmatic case study in state psychological abuse.

2010s

Computational propaganda emerges at population scale: bot networks, coordinated inauthentic behaviour, and algorithmic amplification enter public awareness.

2020s

Generative and agentic AI mature. Psychological profiling, synthetic media, and adaptive persuasion could make individually targeted operations scalable — the Stasi method without the Stasi's headcount.

2026

The First Psychosecurity Summit convenes to draw the line: a shared taxonomy, ethical red lines, and a declaration applying existing international law to AI-driven Zersetzung.

03 · The Threat

What artificial intelligence changes

Zersetzung was a craft: a dedicated team of officers working one target. Artificial intelligence could lower the cost of targeting and coordination. More operations could then run at once, and attribution would become harder.

Psychological profiling

A person's digital footprint can support inferences about interests and vulnerabilities. The accuracy of those inferences varies, partly with how much relevant data an attacker can reach.

Synthetic media

Fabricated audio, video, and imagery can simulate betrayals, destroy reputations, and corrode trust in recorded reality itself.

Coordinated inauthentic behaviour

Networks of artificial personas can manufacture the appearance of organic social rejection, weaponising a person's own community against them.

Algorithmic manipulation

Interference with feeds, search results, and recommendations can distort a target's picture of the world without their awareness.

Social graph disruption

Analysis of relationship networks could help an attacker guess at the few bonds whose breaking would hurt most — and concentrate the attack there.

Closed-loop adaptation

An automated campaign could observe its own effects on the target and adjust in real time. It may misread them. It does not fatigue, lose focus, or develop qualms.

Elements of these capabilities are already documented in contemporary hybrid warfare and in coordinated campaigns against researchers, journalists, and public figures. The evidence does not yet show how far sustained psychological campaigns can scale, how well they work, or how readily they can be detected.

Serious psychological harms linked to consumer AI systems have been reported even without hostile intent — a floor, not a ceiling, on what deliberate targeting could achieve.

Read the full threat briefing →

04 · The Agent Inside

When the attacker holds your credentials

Every capability above reaches a person from outside — shaping what they see, fabricating media about them, turning their community against them. A compromised AI assistant needs no such reach. It reads your email, holds your calendar, edits your files, and writes in your name. The adversary is inside the perimeter, and it is acting with your authority.

The person who says "I did not send that" is contradicted by their own sent folder. Where services record only the account used, an agent's actions may be mistaken for the human account holder's. Separate agent identities and tamper-resistant audit records can make that distinction visible.

"Compromised" conceals three distinct problems, which share the deniability but not the defences: an agent hijacked by hostile instructions hidden in content it reads; one subverted beneath the surface by a malicious tool or tampered model; and one simply turned — aimed at a person by someone who legitimately controls it. Turning an agent needs no exploit at all; used this way, an assistant can become an instrument of coercive control.

Four safeguards address this risk: provenance, so that agent actions are distinguishable from yours; least authority, limiting access to data and consequential actions; independent records that the agent cannot alter; and attention to patterns across time, not only to individual security alerts. Their effectiveness depends on implementation and the access an attacker obtains.

Explainer video: an illustrative scenario, three routes to misuse, and four layers of defence. Captions available. Licensed CC BY-SA 4.0; archival sources and credits appear in the closing titles.

Read the full briefing on compromised AI assistants →

05 · The Spectrum

From legitimate influence to prohibited decomposition

Not all influence is attack. States conduct — and international practice tolerates — a wide range of information activity. Psychosecurity does not seek to prohibit persuasion. It seeks to name the point at which an operation stops being persuasion at all.

CategoryCharacterAssessment
Public diplomacy & strategic communicationsOvert, attributable messaging directed at populations. Intent: inform, persuade.Generally legitimate, subject to applicable law.
Covert influence & computational amplificationDeniable messaging, synthetic personas, manufactured consensus. Target: populations. Intent: deception at scale.Ethically contested; increasingly regulated. Still the domain of mass influence.
Psychological decomposition (AI-driven Zersetzung)Systematic campaign against a named individual or defined group, with intent to decompose psychological integrity, relationships, reputation, or sense of reality.The red line. Can fall under domestic and international law where the relevant legal requirements are met. See the legal discussion below.

The red line is defined by three factors in combination: target — named individuals or defined groups rather than populations; intent — decomposition of a psyche rather than persuasion of a mind; and systematicity — a coordinated campaign rather than an isolated act. AI is not one of the three. A campaign that meets them crosses the line whether software runs it or people do; AI matters because it could make such campaigns cheap enough to run against many targets at once.

See the proposed five tiers and scale bands →

06 · The Framework

Six elements of a psychosecurity framework

Naming a harm is necessary but not sufficient. A working framework needs a shared vocabulary, ethical boundaries, thresholds for response, standards of evidence, obligations for industry — and a signable instrument that binds them together.

01

Taxonomy

A classification of cognitive and information operations precise enough for legal application, distinguishing legitimate influence from psychological decomposition.

02

Ethics Redlines

A graduated scale of operational acceptability, from routine through contested to prohibited — internal safeguards for those who conduct legitimate operations, and a yardstick for assessing adversary conduct.

03

Escalation Thresholds

Consensus criteria for deciding when a detected cognitive attack merits a state-level policy response.

04

Attribution Framework

Evidence standards for identifying and responding to cognitive attacks — forensic indicators, confidence levels, and standards of proof for each response.

05

Industry Accountability

Obligations that keep commercial AI capabilities from becoming cognitive weapons: safety by design, responsible release, and cooperation with lawful investigation.

06

The Declaration

The capstone: a signable statement applying existing international law to AI-driven Zersetzung, with the other five elements annexed.

The framework is being developed with invited participants and will be published for wider endorsement following the summit. About the summit →

07 · The Law

How existing law can apply

The initiative argues for applying existing legal protections to systematic psychological abuse. Whether particular conduct is unlawful depends on the facts and the requirements of each instrument; a framework can support that analysis without replacing it.

Rome Statute, Art. 7

An act may qualify as a crime against humanity when it forms part of a widespread or systematic attack on a civilian population, pursuant to a state or organisational policy, with knowledge of the attack. Persecution must target an identifiable group on political, racial, religious, or other grounds impermissible under international law. Other inhumane acts must cause great suffering or serious injury to body or to mental or physical health. Each has further elements, and the Court's jurisdiction must also be established.

UN Convention against Torture, Arts. 1 & 16

Article 1 covers intentional infliction of severe physical or mental suffering for purposes such as obtaining information, punishment, intimidation, coercion, or discrimination, with the involvement, consent, or acquiescence of a public official or a person acting in an official capacity. Article 16 addresses cruel, inhuman, or degrading treatment that falls short of torture, subject to the same requirement of official involvement.

European Convention on Human Rights, Arts. 3 & 8

Article 8 protects private life, which the European Court of Human Rights interprets to include psychological integrity; Article 3's prohibition of torture and of inhuman or degrading treatment is absolute.

The direction of interpretation is already visible: the UN Special Rapporteur on Torture's 2020 report on psychological torture examined remote, technology-enabled infliction of severe mental suffering — "cybertorture" — within the existing legal framework against torture, precisely the reading this initiative asks states to make explicit.

Existing law can already support enforcement. Clearer definitions could help institutions recognise the conduct, gather evidence, and coordinate with one another. Adversaries will not be bound by a framework; that is not its function. Its function is a baseline — an agreed standard against which conduct can be named, measured, and answered, and which disciplines the operations of those who adopt it.

08 · Resilience

Defence is more than prohibition

A norm names the crime. Resilience denies it victims. Alongside the legal framework, psychosecurity covers the defensive floor a society should field.

Detection & monitoring

Standing capability to recognise coordinated psychological operations against individuals — not only population-scale disinformation.

Victim support

Technical assistance, evidence preservation, and clinical referral pathways for people facing coordinated abuse, whose injuries are real and documentable.

Public inoculation

Prebunking and manipulation literacy: populations familiar with the techniques are measurably harder to manipulate, and should be harder to turn against a target.

Design safeguards

AI systems built so that using them for psychological targeting is harder, more detectable, and more costly — accountability engineered in, not bolted on.

Read the resilience guide, including support if you believe you may be targeted →

09 · The Summit

The First Psychosecurity Summit

An invite-only working session in late 2026, convening practitioners, researchers, legal scholars, and policy specialists under the Chatham House Rule to draft and adopt the Psychosecurity Framework.

This is a working session, not a conference: no panels, no keynotes, no audience. The resulting framework and declaration will be published for wider endorsement. The summit is organised by EURAIO and funded by the Survival and Flourishing Fund.

About the Summit

10 · Questions & Answers

The hard questions, answered plainly

Is psychosecurity an attempt to ban persuasion, propaganda, or information warfare?

Not as such. The proposed framework focuses on systematic campaigns intended to harm psychological integrity. It distinguishes these from ordinary persuasion and public debate. The draft taxonomy also recognises contested forms of influence, whose legality depends on their methods and context.

What about free speech, harsh criticism, and online pile-ons?

Criticism, satire, journalism, and public debate deserve protection. Harassment, threats, stalking, and unlawful disclosure can engage existing law, including when carried out through speech. The proposed framework must assess evidence of conduct, intent, coordination, and harm, with safeguards for lawful expression. A pile-on manufactured through coordinated or synthetic accounts may supply exactly that coordination. Offence, disagreement, or the sheer volume of criticism cannot, by themselves, establish a psychological attack.

Why coin a new term at all?

The term names a gap. Mental health care, human rights, cybersecurity, and work on harassment each address part of the problem of deliberate attacks on psychological integrity. Psychosecurity aims to connect that expertise around prevention, evidence, and support.

Why not campaign for a new treaty?

The initiative's immediate aim is to clarify how existing law can apply. The Rome Statute, the Convention against Torture, and the European Convention on Human Rights contain relevant protections, each with specific thresholds and limits on jurisdiction. The proposed declaration will set out the argument for applying them to systematic psychological abuse. Adopting it would not, by itself, create a new legal obligation.

Won't hostile states simply ignore the framework?

Some may. A voluntary framework cannot guarantee that hostile actors will comply. It can still give institutions a shared vocabulary, evidence standards, and a basis for coordinated responses, and its own adopters should be held accountable for their conduct.

Is AI-driven Zersetzung actually happening, or is this science fiction?

Its components are documented; an integrated system operating at scale has not been established. The sources collected here record harassment, impersonation, synthetic media, and security vulnerabilities in connected assistants. Research also finds that chatbots can respond unsafely and put vulnerable users at risk even when no hostile operator is involved. The threat briefing considers how these capabilities might be combined into automated, individually targeted campaigns.

Couldn't a "psychosecurity" apparatus itself become a tool of repression?

That risk is serious: the Stasi itself operated in the name of security. The proposed safeguards include narrow, evidence-based definitions, protection for lawful expression, and constraints on the conduct of institutions adopting the framework. Those safeguards will need independent scrutiny, routes to challenge decisions, and accountability in practice.

I think this may be happening to me. Can you investigate my case?

We cannot — we are a research and policy initiative, with no investigative capability, and we will not pretend otherwise. What we can offer is the resilience page: grounded, practical guidance on documentation, evidence preservation, account security, and the specialist organisations that do help individuals. It also includes an honest word about how often distressing patterns have ordinary explanations. Please read it — including the part about looking after your mind first, which is written in earnest, not as dismissal.

Does the framework only cover AI-enabled campaigns? A human-run one is just as vicious.

No. The framework addresses psychological abuse carried out by humans as well as abuse enabled by AI. AI matters because it can lower the cost of an operation, extend its reach, and change its methods. The definitions remain subject to the summit's working process.

Who is behind this, and who pays for it?

The initiative is convened by Nell Watson, President of EURAIO, a responsible-AI non-profit, with summit design and delivery co-directed by Simona Popa. It is funded by the Survival and Flourishing Fund. There is no cost to participants or their organisations, and no commercial product behind the effort. More in the About section.

How can I help?

Three ways, in ascending order of commitment. Subscribe for occasional updates — publication of the framework will be announced there first. If your expertise belongs in this work — legal, clinical, platform-integrity, information-operations, policy — get in touch, mentioning what you would bring. And if you are in a position to offer introductions, resources, or institutional endorsement for the framework once published, we would particularly like to hear from you.

A question this page should answer but doesn't? Ask it — the best entries here started as someone's objection.

11 · Reference

Glossary

Psychosecurity
The protection of individuals and societies from systematic psychological attack; the discipline assembling legal, technical, clinical, and doctrinal defences against it.
Zersetzung
German: "decomposition". The Stasi's method of covert psychological repression — the systematic destruction of a target's relationships, reputation, and sense of reality — since recognised in German law as state injustice.
Psychological decomposition operation
A coordinated campaign designed to break down, rather than persuade, a named individual or defined group, by degrading their psychological integrity, social relationships, reputation, or sense of reality.
Psychological integrity
A person's psychological coherence and undistorted access to information about their social reality, and the right to keep both free from targeted campaigns of psychological decomposition.
Coordinated inauthentic behaviour
The use of networks of fake or automated personas to manufacture the appearance of organic opinion, consensus, or social rejection.
Synthetic media
AI-generated or AI-altered audio, video, imagery, or text. Passed off as the actual voice or image of a real person, it is colloquially called a deepfake.
Social graph analysis
The mapping of a person's relationship network — in hostile hands, a way to choose which bonds to attack.
Attribution
The process of identifying the actor behind an operation, to a stated standard of confidence, using technical forensics, behavioural signatures, and contextual intelligence.
Prebunking (inoculation)
Pre-emptive exposure to manipulation techniques in weakened form, which measurably increases resistance to those techniques when encountered in earnest.
Chatham House Rule
A convention allowing use of information from a meeting while protecting the identity and affiliation of speakers and other participants.

12 · Resources

Primary sources, law, and research

Primary documentation & legal instruments

Research & practice

Inoculation ScienceThe Cambridge research programme on prebunking: building psychological resistance to manipulation techniques.inoculation.science NATO Strategic Communications Centre of ExcellenceOpen research on information influence, hybrid threats, and cognitive security.stratcomcoe.org Atlantic Council DFRLabOpen-source investigations of coordinated inauthentic behaviour and targeted influence campaigns.dfrlab.org Stanford Medicine: AI companions and young peopleResearchers posing as teenagers found AI companions easy to draw into unsafe conversations.med.stanford.edu Large-scale online deanonymization with LLMs (2026)ETH Zurich, MATS, and Anthropic researchers show language models unmasking pseudonymous accounts from what people write, at a few dollars per profile.arxiv.org Attack the Glass: demonstrations (2026)nDiligence's demonstrations of compromised third-party scripts rewriting what a trusted page shows one person: news, payments, prescriptions, and election results.atg.ndiligence.com OpenAI: Helping people when they need it mostAn AI developer's own account of how its chatbot responds to people in distress, where those safeguards fall short, and what it plans to change.openai.com Swedish Psychological Defence AgencySweden's national agency for psychological defence — coordinating resilience against malign information influence from hostile powers.mpf.se European Centre of Excellence for Countering Hybrid ThreatsThe Helsinki hub supporting participating states, the EU, and NATO with expertise and training against coordinated attacks that exploit democratic vulnerabilities.hybridcoe.fi EUvsDisinfoThe flagship project of the European External Action Service's East StratCom Task Force, tracking and cataloguing foreign disinformation campaigns, with a searchable case database.euvsdisinfo.eu Institute for Strategic DialogueTwo decades of threat detection and real-world strategy against extremism, hate-based abuse, and information warfare.isdglobal.org

Allied initiatives & declarations

Cognitive Security InstituteA non-profit defining and defending cognitive security across human, artificial, and hybrid cognition — home of the Cognitive Attack Taxonomy and the SHIELD human-risk programme.cognitivesecurityinstitute.org Cognitive Security Task ForceWriting on cognitive security as a first-order concern for AI development: protecting the integrity of human attention, perception, memory, and judgement.cstf.dev Cannes Declaration on the Sovereignty of Mind (2026)A call from the International Forum on Digital and Democracy at the World AI Cannes Festival (WAICF) 2026: firm boundaries against AI systems designed to manipulate thought at scale or evade human reflection.inspiringfutures.eu Rise for the MindThe movement behind the Universal Declaration of the Rights of the Human Mind, which calls for worldwide recognition of the mind's sovereignty over the technologies it must coexist with.riseforthemind.org UNESCO — Ethics of NeurotechnologyThe first global standard on the ethics of neurotechnology, adopted in 2025. It covers freedom of thought, cognitive liberty, and free will where technology reaches into brain activity itself.unesco.org Neurorights FoundationResearch, advocacy, and public education to protect mental privacy, agency, and identity as human rights while brain-interfacing technologies advance.neurorightsfoundation.org Center for Humane TechnologyWorking to realign the incentives behind AI and social media with human interests — the group whose critique of persuasive design reached the mainstream.humanetech.com

The bookshelf

  • Thomas Rid — Active Measures · the secret history of disinformation and political warfare.
  • Peter Pomerantsev — This Is Not Propaganda · field reports from the war against reality.
  • Nicholas Wright — Warhead · how the brain shapes war, and war shapes the brain.
  • Kenneth Payne — I, Warbot · the dawn of artificially intelligent conflict.
  • Andreas Krieg — Subversion · the strategic weaponisation of narratives.
  • Leor Zmigrod — The Ideological Brain · the science of rigid and flexible minds — and a clue to why decomposition works.
  • Nina Jankowicz — How to Lose the Information War · what the West keeps getting wrong.
  • Nell Watson — Taming the Machine · ethically harnessing the power of AI.

13 · About

Who is behind this

Eleanor "Nell" Watson is an engineer, ethicist, and researcher in machine intelligence and AI safety. Author of Taming the Machine and a longstanding voice on the societal impact of advanced AI, she has pioneered research into AI-induced psychological effects and the emerging field of psychosecurity. She convenes this initiative as President of EURAIO, a responsible-AI non-profit.

Simona Popa is an entrepreneur and event specialist with expertise in organisational psychology and the delivery of high-impact international forums; she co-directs the summit's design and execution.

The initiative is organised by EURAIO and funded by the Survival and Flourishing Fund, whose support for work on civilisational resilience makes this effort possible. There is no cost to participants or their organisations.

14 · Stay Informed

Join the mailing list

Occasional announcements on the initiative, the framework's publication, and related research. No noise, and no sharing of your address.

By subscribing you consent to us holding your email address for updates about this initiative. See our Privacy Policy.

15 · Contact

Get in touch

We welcome enquiries, feedback, and offers of collaboration — including expressions of interest in the summit and the framework's development.

We cannot investigate individual cases, so please keep enquiries general. Do not include medical records, passwords, or sensitive case evidence. For personal support, see the resilience guide.

We use your name, email, and message to respond to your enquiry, on the basis of our legitimate interest in relevant correspondence. This does not subscribe you to updates. See our Privacy Policy.