Psychosecurity

/ˌsaɪkoʊsɪˈkjʊərɪti/ · noun

The protection of individuals and societies from systematic psychological attack — and the discipline of drawing the line between legitimate influence and the deliberate decomposition of a human mind.

Confronting AI-Driven Zersetzung
Read the Compendium The Summit

01 · The Term

Why a new word was needed

Cybersecurity protects machines and networks. Information security protects data. Psychosecurity brings clinical, legal, and security expertise together around a shared concern: deliberate attacks on psychological integrity.

States have always sought to persuade, and sometimes to deceive. International practice tolerates a broad spectrum of influence activity directed at populations. But there is a qualitatively different category of operation: the systematic, covert destruction of a specific person's relationships, reputation, livelihood, and sense of reality. History has a name for it: Zersetzung, a documented method of state repression. The task now is to draw that line explicitly — as artificial intelligence lowers the cost of targeted abuse.

Psychosecurity names both the problem and the field: the study of psychological attack as a security threat, and the assembly of legal, technical, clinical, and doctrinal defences against it.

02 · The Precedent

Zersetzung: a documented history of abuse

From the early 1970s until 1989, the East German Ministry for State Security — the Stasi — practised Zersetzung, literally "decomposition." Alongside imprisonment and surveillance, it used a quieter method: the covert dismantling of a person's life, conducted so that the target could rarely tell what was being done to them, or by whom.

Operational methods included the spreading of fabricated rumours to destroy friendships and careers; the interception and alteration of correspondence; the orchestration of unexplained professional failures; and informers used to undermine trust within groups. The damage looked like ordinary misfortune. The psychological effects — depression, anxiety, psychosomatic illness, and in documented cases suicide — did not.

After German reunification, these operations were extensively documented from the Stasi's own records. German rehabilitation law recognises qualifying Zersetzung measures as state injustice and provides a route to compensation. This documented history of psychological abuse is the reference point for the initiative.

The briefing: the history of Zersetzung, documented methods, and emerging digital risks. Captions available.

Read the full history of Zersetzung →

1970s

Zersetzung formalised in Stasi directive as a primary method of political repression, adding covert psychological decomposition to overt repression.

1989–1990

Fall of the German Democratic Republic. Citizens secure Stasi archives against destruction. The Stasi Records Act establishes public access in 1991.

1990s–2000s

Victims gain rehabilitation and compensation pathways for state injustice. The method becomes a paradigmatic case study in state psychological abuse.

2010s

Computational propaganda emerges at population scale: bot networks, coordinated inauthentic behaviour, and algorithmic amplification enter public awareness.

2020s

Generative and agentic AI mature. Psychological profiling, synthetic media, and adaptive persuasion make individually-targeted operations scalable — the Stasi method without the Stasi's headcount.

2026

The First Psychosecurity Summit convenes to draw the line: a shared taxonomy, ethical redlines, and a declaration grounding AI-driven Zersetzung in existing international law.

03 · The Threat

What artificial intelligence changes

Zersetzung was a craft: a dedicated team of officers working one target. Artificial intelligence could lower the cost of targeting and coordination, allowing more operations to run concurrently and making attribution harder.

Psychological profiling

A person’s digital footprint can support inferences about interests and vulnerabilities. The accuracy of those inferences varies, and access to relevant data matters.

Synthetic media

Fabricated audio, video, and imagery can simulate betrayals, destroy reputations, and corrode trust in recorded reality itself.

Coordinated inauthentic behaviour

Networks of artificial personas can manufacture the appearance of organic social rejection, weaponising a person's own community against them.

Algorithmic manipulation

Interference with feeds, search results, and recommendations can distort a target's picture of the world without their awareness.

Social graph disruption

Analysis of relationship networks identifies the few bonds whose breaking causes the greatest psychological damage — and concentrates attack there.

Closed-loop adaptation

An automated campaign can observe its own effects on the target and adjust in real time. It does not fatigue, lose focus, or develop qualms.

These capabilities are not hypothetical. Elements of them are documented in contemporary hybrid warfare and in coordinated campaigns against researchers, journalists, and public figures. Severe psychological harm from AI systems is now documented even without hostile intent, in the consumer sphere — a floor, not a ceiling, on what deliberate targeting can achieve.

Automation could lower the cost of coordinated abuse. Evidence is still needed to establish the scale, effectiveness, and detectability of sustained psychological campaigns.

Read the full threat briefing →

04 · The Agent Inside

When the attacker holds your credentials

Every capability above reaches a person from outside — shaping what they see, fabricating media about them, turning their community against them. A compromised AI assistant inverts that topology. It reads your email, holds your calendar, edits your files, and writes in your name. The adversary is inside the perimeter, and it is acting with your authority.

A malicious instruction or misused permission can lead an assistant to make changes through a connected account. The resulting activity may look authorised unless the service records which agent acted and what approval it received. That is a reason to improve attribution and access controls.

Where services record only the account used, an agent’s actions may be mistaken for the human account holder’s. Separate agent identities and tamper-resistant audit records can make that distinction visible.

"Compromised" conceals three distinct problems, which share the deniability but not the defences: an agent hijacked by hostile instructions hidden in content it reads; one subverted beneath the surface by a malicious tool or tampered model; and one simply turned — aimed at a person by someone who legitimately controls it, which needs no exploit at all and warrants attention as a potential form of coercive control.

Four safeguards address this risk: provenance, so that agent actions are distinguishable from yours; least authority, limiting access to data and consequential actions; independent records that the agent cannot alter; and review of patterns alongside individual security alerts. Their effectiveness depends on implementation and the access an attacker obtains.

The briefing: an illustrative scenario, three routes to misuse, and four layers of defence. Captions available.

Read the full agentic briefing →

05 · The Spectrum

From legitimate influence to prohibited decomposition

Not all influence is attack. States conduct — and international practice tolerates — a wide range of information activity. Psychosecurity does not seek to prohibit persuasion. It seeks to name the point at which an operation stops being persuasion at all.

BandCharacterAssessment
Public diplomacy & strategic communicationsOvert, attributable messaging directed at populations. Intent: inform, persuade.Generally legitimate, subject to applicable law.
Covert influence & computational amplificationDeniable messaging, synthetic personas, manufactured consensus. Target: populations. Intent: deception at scale.Ethically contested; increasingly regulated. Still the domain of mass influence.
Psychological decomposition (AI-driven Zersetzung)Systematic campaign against a named individual or defined group, with intent to decompose psychological integrity, relationships, reputation, or sense of reality.The red line. Potentially covered by domestic and international law, depending on the acts, severity, jurisdiction, and applicable legal thresholds. See the legal discussion below.

The red line is defined by three factors in combination: target — individual civilians rather than populations; intent — decomposition of a psyche rather than persuasion of a mind; and systematicity — a coordinated campaign rather than an isolated act. AI enablement is what makes the threat urgent; it is the scaling condition, not the boundary of the offence.

Explore the five-tier taxonomy →

06 · The Framework

Six elements of a psychosecurity framework

Naming a harm is necessary but not sufficient. A working framework needs a shared vocabulary, ethical boundaries, thresholds for response, standards of evidence, obligations for industry — and a signable instrument that binds them together.

ELEMENT 1

Taxonomy

A classification of cognitive and information operations precise enough for legal application, distinguishing legitimate influence from psychological decomposition.

ELEMENT 2

Ethics Redlines

A graduated scale of operational acceptability — internal safeguards for those who conduct legitimate operations, and a yardstick for assessing adversary conduct.

ELEMENT 3

Escalation Thresholds

Consensus criteria for when cognitive attack merits state-level response, bridging the gap between incident detection and policy action.

ELEMENT 4

Attribution Framework

Evidence standards for identifying and responding to cognitive attacks — forensic indicators, confidence levels, and standards of proof for each response.

ELEMENT 5

Industry Accountability

Pathways preventing commercial AI capabilities from becoming cognitive weapons: safety by design, responsible release, and cooperation with lawful investigation.

ELEMENT 6

The Declaration

The capstone: a signable statement grounding AI-driven Zersetzung in existing international law, with the other five elements annexed.

The framework is being developed through an invited working process and will be published for wider endorsement following the summit. About the summit →

07 · The Law

How existing law can apply

The initiative argues for applying existing legal protections to systematic psychological abuse. Whether particular conduct is unlawful depends on the facts and the requirements of each instrument; a framework can support that analysis without replacing it.

Rome Statute, Art. 7

An act may qualify as a crime against humanity when it forms part of a widespread or systematic attack on a civilian population, pursuant to a state or organisational policy, with knowledge of the attack. Persecution and other inhumane acts causing serious mental injury have additional elements; the Court’s jurisdiction must also be established.

UN Convention Against Torture, Arts. 1 & 16

Article 1 covers intentional infliction of severe physical or mental suffering for specified purposes, with involvement, consent, or acquiescence of a public official or a person acting in an official capacity. Article 16 addresses other cruel, inhuman, or degrading treatment under its own conditions.

ECHR, Arts. 3 & 8

The European Convention protects mental integrity and private life; Article 3's prohibition on inhuman and degrading treatment is absolute.

The direction of interpretation is already visible: the UN Special Rapporteur on Torture's 2020 report on psychological torture examined remote, technology-enabled infliction of severe mental suffering — "cyber-torture" — within the existing Convention framework, precisely the reading this initiative asks states to make explicit.

Existing laws can already support enforcement. Clearer definitions could improve recognition, evidence gathering, and coordination across institutions. Adversaries will not be bound by a framework; that is not its function. Its function is a baseline — an agreed standard against which conduct can be named, measured, and answered, and which disciplines the operations of those who adopt it.

08 · Resilience

Defence is more than prohibition

A norm names the crime. Resilience denies it victims. Alongside the legal framework, psychosecurity encompasses the proactive defensive floor a society should field.

Detection & monitoring

Standing capability to recognise coordinated psychological operations against individuals — not only population-scale disinformation.

Victim support

Attribution assistance, evidence preservation, and clinical referral pathways for targeted individuals, whose injuries are real and documentable.

Public inoculation

Prebunking and manipulation-literacy: populations familiar with the techniques are measurably harder to use as instruments against a target.

Design safeguards

AI systems built so that psychological-targeting misuse is harder, detectable, and costly — accountability engineered in, not bolted on.

Read the resilience guide — including support for those targeted →

09 · The Summit

The First Psychosecurity Summit

An invite-only working session convening practitioners, researchers, legal scholars, and policy specialists in late 2026, under the Chatham House Rule, to draft and adopt the Psychosecurity Framework.

This is a working session, not a conference: no panels, no keynotes, no audience. Participation is by invitation. The resulting framework and declaration will be published for wider endorsement. The summit is organised by EURAIO and funded by the Survival and Flourishing Fund.

About the Summit

10 · Questions & Answers

The hard questions, answered plainly

Is psychosecurity an attempt to ban persuasion, propaganda, or information warfare?

The proposed framework focuses on systematic campaigns intended to harm psychological integrity. It distinguishes these from ordinary persuasion and public debate. The draft taxonomy also recognises contested forms of influence, whose legality depends on their methods and context.

What about free speech, harsh criticism, and online pile-ons?

Criticism, satire, journalism, and public debate deserve protection. Harassment, threats, stalking, and unlawful disclosure can engage existing law, including when carried out through speech. The proposed framework must assess evidence of conduct, intent, coordination, and harm, with safeguards for lawful expression. Offence or disagreement alone cannot establish a psychological attack.

Why coin a new term at all?

The term brings a particular security problem into focus: deliberate attacks on psychological integrity. Mental health care, human rights, cybersecurity, and work on harassment already address parts of this problem. Psychosecurity aims to connect that expertise around prevention, evidence, and support.

Why not campaign for a new treaty?

The initiative’s immediate aim is to clarify how existing law can apply. The Rome Statute, the Convention Against Torture, and the European Convention on Human Rights contain relevant protections, each with specific thresholds and limits on jurisdiction. The proposed Declaration will set out the argument for applying them to systematic psychological abuse. Adoption of a declaration does not itself establish a new legal obligation.

Won't hostile states simply ignore the framework?

A voluntary framework cannot guarantee that hostile actors will comply. It can give institutions a shared vocabulary, evidence standards, and a basis for coordinated responses. Its adopters should also be accountable for their own conduct. Its value will depend on implementation and use.

Is AI-driven Zersetzung actually happening, or is this science fiction?

The sources collected here document harassment, impersonation, synthetic media, and security vulnerabilities in connected assistants. Research also identifies unsafe chatbot responses and risks to vulnerable users without a hostile operator. The threat briefing considers how these capabilities might be combined into automated, individually targeted campaigns. The sources cited on this site do not establish that such an integrated system is operating at scale.

Couldn't a "psychosecurity" apparatus itself become a tool of repression?

That risk is serious: the Stasi itself operated in the name of security. The proposed safeguards include narrow, evidence-based definitions, protection for lawful expression, and constraints on the conduct of institutions adopting the framework. Those commitments will need independent scrutiny, routes to challenge decisions, and accountability in practice.

I think this may be happening to me. Can you investigate my case?

We cannot — we are a research and policy initiative, with no investigative capability, and we will not pretend otherwise. What we can offer is the resilience page: grounded, practical guidance on documentation, evidence preservation, account security, and the specialist organisations that do help individuals, along with an honest word about how often distressing patterns have ordinary explanations. Please read it — including the part about looking after your mind first, which is written in earnest, not as dismissal.

Does the framework only cover AI-enabled campaigns? A human-run one is just as vicious.

The framework addresses psychological abuse carried out by humans as well as abuse enabled by AI. AI matters because it can change the cost, reach, and methods of an operation. The definitions remain subject to the summit’s working process.

Who is behind this, and who pays for it?

The initiative is convened by Nell Watson, President of EURAIO, a responsible-AI non-profit, with summit design and delivery co-directed by Simona Popa. It is funded by the Survival and Flourishing Fund. There is no cost to participants or their organisations, and no commercial product behind the effort. More on the about section.

How can I help?

Three ways, in ascending order of commitment. Subscribe for occasional updates — publication of the framework will be announced there first. If your expertise belongs in this work — legal, clinical, platform-integrity, information-operations, policy — get in touch, mentioning what you would bring. And if you are in a position to offer introductions, resources, or institutional endorsement for the framework once published, we would particularly like to hear from you.

A question this page should answer but doesn't? Ask it — the best entries here started as someone's objection.

11 · Reference

Glossary

Psychosecurity
The protection of individuals and societies from systematic psychological attack; the discipline assembling legal, technical, clinical, and doctrinal defences against it.
Zersetzung
German: "decomposition." The Stasi's method of covert psychological repression — the systematic destruction of a target's relationships, reputation, and sense of reality — subsequently documented as state injustice.
Psychological decomposition operation
A coordinated campaign designed to degrade an individual's psychological integrity, social relationships, reputation, or sense of reality, conducted with intent to decompose rather than persuade.
Cognitive integrity
The right of individuals to psychological coherence, undistorted access to information about their social reality, and freedom from targeted campaigns of psychological decomposition.
Coordinated inauthentic behaviour
The use of networks of fake or automated personas to manufacture the appearance of organic opinion, consensus, or social rejection.
Synthetic media
AI-generated or AI-altered audio, video, imagery, or text presented as authentic; colloquially, deepfakes.
Social graph analysis
The mapping of a person's relationship network — in hostile hands, used to identify which bonds to attack for maximum psychological effect.
Attribution
The process of identifying the actor behind an operation, to a stated standard of confidence, using technical forensics, behavioural signatures, and contextual intelligence.
Prebunking (inoculation)
Pre-emptive exposure to manipulation techniques in weakened form, which measurably increases resistance to those techniques when encountered in earnest.
Chatham House Rule
A convention allowing use of information from a meeting while protecting the identity and affiliation of speakers and other participants.

12 · Resources

Primary sources, law, and research

Primary documentation & legal instruments

Research & practice

Inoculation ScienceThe Cambridge research programme on prebunking: building psychological resistance to manipulation techniques.inoculation.science NATO Strategic Communications Centre of ExcellenceOpen research on information influence, hybrid threats, and cognitive security.stratcomcoe.org Atlantic Council DFRLabOpen-source investigations of coordinated inauthentic behaviour and targeted influence campaigns.dfrlab.org EU Digital Services ActThe regulatory baseline for platform accountability, including coordinated inauthentic behaviour.digital-strategy.ec.europa.eu Stanford Medicine: AI chatbots and vulnerable usersResearch on unsafe chatbot responses and risks to young and vulnerable users.med.stanford.edu OpenAI: Helping people when they need it mostAn AI developer's own account of psychological safety incidents and mitigations.openai.com German Federal ArchivesThe institutional home of the Stasi records and documentation of Zersetzung and other forms of state repression.bundesarchiv.de Swedish Psychological Defence AgencySweden’s national agency for psychological defence — coordinating resilience against malign information influence from hostile powers.mpf.se European Centre of Excellence for Countering Hybrid ThreatsThe Helsinki hub supporting participating states, the EU, and NATO with expertise and training against coordinated attacks on democratic vulnerabilities.hybridcoe.fi EUvsDisinfoThe EU External Action Service's flagship project tracking and cataloguing foreign disinformation campaigns, with a searchable case database.euvsdisinfo.eu Institute for Strategic DialogueTwo decades of threat detection and real-world strategy against extremism, hate-based abuse, and information warfare.isdglobal.org

Allied initiatives & declarations

The bookshelf

  • Thomas Rid — Active Measures · the secret history of disinformation and political warfare.
  • Peter Pomerantsev — This Is Not Propaganda · field reports from the war against reality.
  • Nicholas Wright — Warhead · how the brain shapes war, and war shapes the brain.
  • Kenneth Payne — I, Warbot · the dawn of artificially intelligent conflict.
  • Andreas Krieg — Subversion · the strategic weaponisation of narratives.
  • Leor Zmigrod — The Ideological Brain · the science of rigid and flexible minds — why decomposition works.
  • Nina Jankowicz — How to Lose the Information War · what the West keeps getting wrong.
  • Nell Watson — Taming the Machine · ethically harnessing the power of AI.

13 · About

Who is behind this

Eleanor "Nell" Watson is an engineer, ethicist, and researcher in machine intelligence and AI safety. Author of Taming the Machine and a longstanding voice on the societal impact of advanced AI, she has pioneered research into AI-induced psychological effects and the emerging field of psychosecurity. She convenes this initiative as President of EURAIO, a responsible-AI non-profit.

Simona Popa is an entrepreneur and event specialist with expertise in organisational psychology and the delivery of high-impact international forums; she co-directs the summit's design and execution.

The initiative is organised by EURAIO and funded by the Survival and Flourishing Fund, whose support for work on civilisational resilience makes this effort possible. There is no cost to participants or their organisations.

14 · Stay Informed

Updates

Occasional announcements on the initiative, the framework's publication, and related research. No noise, and no sharing of your address.

By subscribing you consent to us holding your email address for updates about this initiative. See our Privacy Policy.

15 · Contact

Get in touch

Enquiries, feedback, and collaborative opportunities are welcome — including expressions of interest in the summit and the framework's development.

Please keep enquiries general. Do not include medical records, passwords, or sensitive case evidence. For personal support, see the resilience guide.

We use your name, email, and message to respond to your enquiry, on the basis of our legitimate interest in relevant correspondence. This does not subscribe you to updates. See our Privacy Policy.