Psychosecurity
/ˌsaɪkəʊsɪˈkjʊərɪti/ noun
The protection of individuals and societies from systematic psychological attack — and the discipline of drawing the line between legitimate influence and the deliberate decomposition of a human mind.
Confronting AI-Driven Zersetzung01 · The Term
Why a new word was needed
Psychosecurity brings clinical, legal, and security expertise together to defend psychological integrity against deliberate attack.
States have always sought to persuade, and sometimes to deceive. International practice tolerates a broad spectrum of influence activity directed at populations. But there is a qualitatively different category of operation: the systematic, covert destruction of a specific person's relationships, reputation, livelihood, and sense of reality. History has a name for it: Zersetzung, a documented method of state repression. The task now is to draw the line between influence and Zersetzung explicitly, because artificial intelligence could lower the cost of targeted abuse.
Psychosecurity names both the problem and the field: the study of psychological attack as a security threat, and the assembly of legal, technical, clinical, and doctrinal defences against it.
02 · The Precedent
Zersetzung: a documented history of abuse
From the early 1970s until 1989, the East German Ministry for State Security — the Stasi — practised Zersetzung, literally "decomposition". Alongside imprisonment and surveillance, it used a quieter method: the covert dismantling of a person's life, conducted so that the target could rarely tell what was being done to them, or by whom.
The Stasi's methods included spreading fabricated rumours to destroy friendships and careers, intercepting and altering correspondence, orchestrating unexplained professional failures, and using informers to undermine trust within groups. The damage looked like ordinary misfortune. The psychological effects — depression, anxiety, psychosomatic illness, and in documented cases suicide — did not.
After German reunification, these operations were extensively documented from the Stasi's own records. German rehabilitation law recognises qualifying Zersetzung measures as state injustice and provides a route to compensation. This history is the initiative's reference point.
Explainer video: the history of Zersetzung, documented methods, and emerging digital risks. Captions available. Licensed CC BY-SA 4.0; archival sources, credits and licences appear in the closing titles.
Read the full history of Zersetzung →
Stasi Directive 1/76 formalises Zersetzung — covert psychological decomposition — as a primary method of political repression, alongside imprisonment and surveillance.
Fall of the German Democratic Republic. Citizens secure Stasi archives against destruction. The Stasi Records Act establishes public access in 1991.
Victims gain rehabilitation and compensation pathways for state injustice. The method becomes a paradigmatic case study in state psychological abuse.
Computational propaganda emerges at population scale: bot networks, coordinated inauthentic behaviour, and algorithmic amplification enter public awareness.
Generative and agentic AI mature. Psychological profiling, synthetic media, and adaptive persuasion could make individually targeted operations scalable — the Stasi method without the Stasi's headcount.
The First Psychosecurity Summit convenes to draw the line: a shared taxonomy, ethical red lines, and a declaration applying existing international law to AI-driven Zersetzung.
03 · The Threat
What artificial intelligence changes
Zersetzung was a craft: a dedicated team of officers working one target. Artificial intelligence could lower the cost of targeting and coordination. More operations could then run at once, and attribution would become harder.
Psychological profiling
A person's digital footprint can support inferences about interests and vulnerabilities. The accuracy of those inferences varies, partly with how much relevant data an attacker can reach.
Synthetic media
Fabricated audio, video, and imagery can simulate betrayals, destroy reputations, and corrode trust in recorded reality itself.
Coordinated inauthentic behaviour
Networks of artificial personas can manufacture the appearance of organic social rejection, weaponising a person's own community against them.
Algorithmic manipulation
Interference with feeds, search results, and recommendations can distort a target's picture of the world without their awareness.
Social graph disruption
Analysis of relationship networks could help an attacker guess at the few bonds whose breaking would hurt most — and concentrate the attack there.
Closed-loop adaptation
An automated campaign could observe its own effects on the target and adjust in real time. It may misread them. It does not fatigue, lose focus, or develop qualms.
Elements of these capabilities are already documented in contemporary hybrid warfare and in coordinated campaigns against researchers, journalists, and public figures. The evidence does not yet show how far sustained psychological campaigns can scale, how well they work, or how readily they can be detected.
04 · The Agent Inside
When the attacker holds your credentials
Every capability above reaches a person from outside — shaping what they see, fabricating media about them, turning their community against them. A compromised AI assistant needs no such reach. It reads your email, holds your calendar, edits your files, and writes in your name. The adversary is inside the perimeter, and it is acting with your authority.
The person who says "I did not send that" is contradicted by their own sent folder. Where services record only the account used, an agent's actions may be mistaken for the human account holder's. Separate agent identities and tamper-resistant audit records can make that distinction visible.
"Compromised" conceals three distinct problems, which share the deniability but not the defences: an agent hijacked by hostile instructions hidden in content it reads; one subverted beneath the surface by a malicious tool or tampered model; and one simply turned — aimed at a person by someone who legitimately controls it. Turning an agent needs no exploit at all; used this way, an assistant can become an instrument of coercive control.
Four safeguards address this risk: provenance, so that agent actions are distinguishable from yours; least authority, limiting access to data and consequential actions; independent records that the agent cannot alter; and attention to patterns across time, not only to individual security alerts. Their effectiveness depends on implementation and the access an attacker obtains.
Explainer video: an illustrative scenario, three routes to misuse, and four layers of defence. Captions available. Licensed CC BY-SA 4.0; archival sources and credits appear in the closing titles.
05 · The Spectrum
From legitimate influence to prohibited decomposition
Not all influence is attack. States conduct — and international practice tolerates — a wide range of information activity. Psychosecurity does not seek to prohibit persuasion. It seeks to name the point at which an operation stops being persuasion at all.
| Category | Character | Assessment |
|---|---|---|
| Public diplomacy & strategic communications | Overt, attributable messaging directed at populations. Intent: inform, persuade. | Generally legitimate, subject to applicable law. |
| Covert influence & computational amplification | Deniable messaging, synthetic personas, manufactured consensus. Target: populations. Intent: deception at scale. | Ethically contested; increasingly regulated. Still the domain of mass influence. |
| Psychological decomposition (AI-driven Zersetzung) | Systematic campaign against a named individual or defined group, with intent to decompose psychological integrity, relationships, reputation, or sense of reality. | The red line. Can fall under domestic and international law where the relevant legal requirements are met. See the legal discussion below. |
The red line is defined by three factors in combination: target — named individuals or defined groups rather than populations; intent — decomposition of a psyche rather than persuasion of a mind; and systematicity — a coordinated campaign rather than an isolated act. AI is not one of the three. A campaign that meets them crosses the line whether software runs it or people do; AI matters because it could make such campaigns cheap enough to run against many targets at once.
06 · The Framework
Six elements of a psychosecurity framework
Naming a harm is necessary but not sufficient. A working framework needs a shared vocabulary, ethical boundaries, thresholds for response, standards of evidence, obligations for industry — and a signable instrument that binds them together.
Taxonomy
A classification of cognitive and information operations precise enough for legal application, distinguishing legitimate influence from psychological decomposition.
Ethics Redlines
A graduated scale of operational acceptability, from routine through contested to prohibited — internal safeguards for those who conduct legitimate operations, and a yardstick for assessing adversary conduct.
Escalation Thresholds
Consensus criteria for deciding when a detected cognitive attack merits a state-level policy response.
Attribution Framework
Evidence standards for identifying and responding to cognitive attacks — forensic indicators, confidence levels, and standards of proof for each response.
Industry Accountability
Obligations that keep commercial AI capabilities from becoming cognitive weapons: safety by design, responsible release, and cooperation with lawful investigation.
The Declaration
The capstone: a signable statement applying existing international law to AI-driven Zersetzung, with the other five elements annexed.
The framework is being developed with invited participants and will be published for wider endorsement following the summit. About the summit →
07 · The Law
How existing law can apply
The initiative argues for applying existing legal protections to systematic psychological abuse. Whether particular conduct is unlawful depends on the facts and the requirements of each instrument; a framework can support that analysis without replacing it.
Rome Statute, Art. 7
An act may qualify as a crime against humanity when it forms part of a widespread or systematic attack on a civilian population, pursuant to a state or organisational policy, with knowledge of the attack. Persecution must target an identifiable group on political, racial, religious, or other grounds impermissible under international law. Other inhumane acts must cause great suffering or serious injury to body or to mental or physical health. Each has further elements, and the Court's jurisdiction must also be established.
UN Convention against Torture, Arts. 1 & 16
Article 1 covers intentional infliction of severe physical or mental suffering for purposes such as obtaining information, punishment, intimidation, coercion, or discrimination, with the involvement, consent, or acquiescence of a public official or a person acting in an official capacity. Article 16 addresses cruel, inhuman, or degrading treatment that falls short of torture, subject to the same requirement of official involvement.
European Convention on Human Rights, Arts. 3 & 8
Article 8 protects private life, which the European Court of Human Rights interprets to include psychological integrity; Article 3's prohibition of torture and of inhuman or degrading treatment is absolute.
The direction of interpretation is already visible: the UN Special Rapporteur on Torture's 2020 report on psychological torture examined remote, technology-enabled infliction of severe mental suffering — "cybertorture" — within the existing legal framework against torture, precisely the reading this initiative asks states to make explicit.
Existing law can already support enforcement. Clearer definitions could help institutions recognise the conduct, gather evidence, and coordinate with one another. Adversaries will not be bound by a framework; that is not its function. Its function is a baseline — an agreed standard against which conduct can be named, measured, and answered, and which disciplines the operations of those who adopt it.
08 · Resilience
Defence is more than prohibition
A norm names the crime. Resilience denies it victims. Alongside the legal framework, psychosecurity covers the defensive floor a society should field.
Detection & monitoring
Standing capability to recognise coordinated psychological operations against individuals — not only population-scale disinformation.
Victim support
Technical assistance, evidence preservation, and clinical referral pathways for people facing coordinated abuse, whose injuries are real and documentable.
Public inoculation
Prebunking and manipulation literacy: populations familiar with the techniques are measurably harder to manipulate, and should be harder to turn against a target.
Design safeguards
AI systems built so that using them for psychological targeting is harder, more detectable, and more costly — accountability engineered in, not bolted on.
Read the resilience guide, including support if you believe you may be targeted →
09 · The Summit
The First Psychosecurity Summit
An invite-only working session in late 2026, convening practitioners, researchers, legal scholars, and policy specialists under the Chatham House Rule to draft and adopt the Psychosecurity Framework.
This is a working session, not a conference: no panels, no keynotes, no audience. The resulting framework and declaration will be published for wider endorsement. The summit is organised by EURAIO and funded by the Survival and Flourishing Fund.
10 · Questions & Answers
The hard questions, answered plainly
Is psychosecurity an attempt to ban persuasion, propaganda, or information warfare?
Not as such. The proposed framework focuses on systematic campaigns intended to harm psychological integrity. It distinguishes these from ordinary persuasion and public debate. The draft taxonomy also recognises contested forms of influence, whose legality depends on their methods and context.
What about free speech, harsh criticism, and online pile-ons?
Criticism, satire, journalism, and public debate deserve protection. Harassment, threats, stalking, and unlawful disclosure can engage existing law, including when carried out through speech. The proposed framework must assess evidence of conduct, intent, coordination, and harm, with safeguards for lawful expression. A pile-on manufactured through coordinated or synthetic accounts may supply exactly that coordination. Offence, disagreement, or the sheer volume of criticism cannot, by themselves, establish a psychological attack.
Why coin a new term at all?
The term names a gap. Mental health care, human rights, cybersecurity, and work on harassment each address part of the problem of deliberate attacks on psychological integrity. Psychosecurity aims to connect that expertise around prevention, evidence, and support.
Why not campaign for a new treaty?
The initiative's immediate aim is to clarify how existing law can apply. The Rome Statute, the Convention against Torture, and the European Convention on Human Rights contain relevant protections, each with specific thresholds and limits on jurisdiction. The proposed declaration will set out the argument for applying them to systematic psychological abuse. Adopting it would not, by itself, create a new legal obligation.
Won't hostile states simply ignore the framework?
Some may. A voluntary framework cannot guarantee that hostile actors will comply. It can still give institutions a shared vocabulary, evidence standards, and a basis for coordinated responses, and its own adopters should be held accountable for their conduct.
Is AI-driven Zersetzung actually happening, or is this science fiction?
Its components are documented; an integrated system operating at scale has not been established. The sources collected here record harassment, impersonation, synthetic media, and security vulnerabilities in connected assistants. Research also finds that chatbots can respond unsafely and put vulnerable users at risk even when no hostile operator is involved. The threat briefing considers how these capabilities might be combined into automated, individually targeted campaigns.
Couldn't a "psychosecurity" apparatus itself become a tool of repression?
That risk is serious: the Stasi itself operated in the name of security. The proposed safeguards include narrow, evidence-based definitions, protection for lawful expression, and constraints on the conduct of institutions adopting the framework. Those safeguards will need independent scrutiny, routes to challenge decisions, and accountability in practice.
I think this may be happening to me. Can you investigate my case?
We cannot — we are a research and policy initiative, with no investigative capability, and we will not pretend otherwise. What we can offer is the resilience page: grounded, practical guidance on documentation, evidence preservation, account security, and the specialist organisations that do help individuals. It also includes an honest word about how often distressing patterns have ordinary explanations. Please read it — including the part about looking after your mind first, which is written in earnest, not as dismissal.
Does the framework only cover AI-enabled campaigns? A human-run one is just as vicious.
No. The framework addresses psychological abuse carried out by humans as well as abuse enabled by AI. AI matters because it can lower the cost of an operation, extend its reach, and change its methods. The definitions remain subject to the summit's working process.
Who is behind this, and who pays for it?
The initiative is convened by Nell Watson, President of EURAIO, a responsible-AI non-profit, with summit design and delivery co-directed by Simona Popa. It is funded by the Survival and Flourishing Fund. There is no cost to participants or their organisations, and no commercial product behind the effort. More in the About section.
How can I help?
Three ways, in ascending order of commitment. Subscribe for occasional updates — publication of the framework will be announced there first. If your expertise belongs in this work — legal, clinical, platform-integrity, information-operations, policy — get in touch, mentioning what you would bring. And if you are in a position to offer introductions, resources, or institutional endorsement for the framework once published, we would particularly like to hear from you.
A question this page should answer but doesn't? Ask it — the best entries here started as someone's objection.
11 · Reference
Glossary
- Psychosecurity
- The protection of individuals and societies from systematic psychological attack; the discipline assembling legal, technical, clinical, and doctrinal defences against it.
- Zersetzung
- German: "decomposition". The Stasi's method of covert psychological repression — the systematic destruction of a target's relationships, reputation, and sense of reality — since recognised in German law as state injustice.
- Psychological decomposition operation
- A coordinated campaign designed to break down, rather than persuade, a named individual or defined group, by degrading their psychological integrity, social relationships, reputation, or sense of reality.
- Psychological integrity
- A person's psychological coherence and undistorted access to information about their social reality, and the right to keep both free from targeted campaigns of psychological decomposition.
- Coordinated inauthentic behaviour
- The use of networks of fake or automated personas to manufacture the appearance of organic opinion, consensus, or social rejection.
- Synthetic media
- AI-generated or AI-altered audio, video, imagery, or text. Passed off as the actual voice or image of a real person, it is colloquially called a deepfake.
- Social graph analysis
- The mapping of a person's relationship network — in hostile hands, a way to choose which bonds to attack.
- Attribution
- The process of identifying the actor behind an operation, to a stated standard of confidence, using technical forensics, behavioural signatures, and contextual intelligence.
- Prebunking (inoculation)
- Pre-emptive exposure to manipulation techniques in weakened form, which measurably increases resistance to those techniques when encountered in earnest.
- Chatham House Rule
- A convention allowing use of information from a meeting while protecting the identity and affiliation of speakers and other participants.
12 · Resources
Primary sources, law, and research
Primary documentation & legal instruments
Research & practice
Allied initiatives & declarations
The bookshelf
- Thomas Rid — Active Measures · the secret history of disinformation and political warfare.
- Peter Pomerantsev — This Is Not Propaganda · field reports from the war against reality.
- Nicholas Wright — Warhead · how the brain shapes war, and war shapes the brain.
- Kenneth Payne — I, Warbot · the dawn of artificially intelligent conflict.
- Andreas Krieg — Subversion · the strategic weaponisation of narratives.
- Leor Zmigrod — The Ideological Brain · the science of rigid and flexible minds — and a clue to why decomposition works.
- Nina Jankowicz — How to Lose the Information War · what the West keeps getting wrong.
- Nell Watson — Taming the Machine · ethically harnessing the power of AI.
13 · About
Who is behind this
Eleanor "Nell" Watson is an engineer, ethicist, and researcher in machine intelligence and AI safety. Author of Taming the Machine and a longstanding voice on the societal impact of advanced AI, she has pioneered research into AI-induced psychological effects and the emerging field of psychosecurity. She convenes this initiative as President of EURAIO, a responsible-AI non-profit.
Simona Popa is an entrepreneur and event specialist with expertise in organisational psychology and the delivery of high-impact international forums; she co-directs the summit's design and execution.
The initiative is organised by EURAIO and funded by the Survival and Flourishing Fund, whose support for work on civilisational resilience makes this effort possible. There is no cost to participants or their organisations.
14 · Stay Informed
Join the mailing list
Occasional announcements on the initiative, the framework's publication, and related research. No noise, and no sharing of your address.
By subscribing you consent to us holding your email address for updates about this initiative. See our Privacy Policy.
15 · Contact
Get in touch
We welcome enquiries, feedback, and offers of collaboration — including expressions of interest in the summit and the framework's development.