Opinion
How AI-era disinformation targets both human and machine cognition

Artificial intelligence (AI) democratizes access to information but agentic AI could also be used to spread false or misleading content via humans and machines. Image: Getty Images/LaurenceDutton
Tobias Knappe
Senior Project and Research Officer, Polymath Initiative, Geneva Centre for Security Policy (GCSP)- In the age of AI, disinformation efforts can target people, but also machines.
- Agentic AI and AI swarms can be used to spread false or misleading content, disrupting the global information ecosystem.
- Safeguarding against such autonomous influence efforts will require strengthening cognitive security and resilience for both people and machines.
Technological advancements have fundamentally changed the global information ecosystem, making it more digital, accessible, complex and fragmented. Artificial intelligence (AI) sits at the centre of this transformation by democratizing access to information and underpinning data-driven decision-making by governments and companies.
Since 2022, generative AI, particularly large language models (LLMs), has flooded the information ecosystem with content of inconsistent quality. An estimated 50% of newly published articles are now AI-generated, while synthetic content appears on up to 74% of new webpages. This blurs the line between human- and machine-generated content and affects business intelligence and analytics inputs.
Disinformation and cognitive warfare
Disinformation is spread with the intent to manipulate or deceive, while misinformation is also inaccurate or misleading but is shared unknowingly.
Both predate AI but the digital age has intensified their sophistication, scale and reach, compounded by recommendation algorithms and the relentless monetization of data.
Influence operations have long used disinformation, evolving as technology has. Early deepfakes were easy to spot, but recent ones are convincing enough to exploit for political and financial gain. Low-cost, multi-modal LLMs have lowered the barrier to entry for malicious actors, enabling text, audio and video disinformation at scale.
Companies face exposure through supply chains and market manipulation via coordinated disinformation on stock-sensitive news or deepfakes impersonating executives. This should be on every board's radar.
Motives vary. Some malicious actors may be pursuing extortion and fraud, while others could be focused on subversion – exploiting political and social vulnerabilities to undermine established authority.
Subversion sits at the heart of the emerging practice of cognitive warfare. Where disinformation manipulates the narrative, cognitive warfare seeks to influence how people, companies, institutions and societies make sense of reality and make decisions.
Agentic AI and AI swarms
Agentic AI adds complexity to this threat landscape. AI agents, which autonomously perceive and act upon their environment, are proliferating rapidly across businesses, governments and militaries, despite reliability and security limitations.
An estimated 28.6 million agents were in use across enterprises in 2025, and this is projected to exceed 2 billion by 2030.
This proliferation also raises misuse concerns. Autonomous agents have already partially automated cyber operations, and so attacks that once required deep expertise can now run independently, at machine speed and scale.
The risk compounds when specialized AI agents operate in coordinated networks, or swarms. Although still nascent, these AI swarms could amplify disinformation through greater autonomy, sophistication, scale and speed. Unlike rule-bound bots, agentic AI may enable adaptive, end-to-end influence operations with little human oversight once a goal is set.
This risk is not hypothetical. In a simulated social media environment created as part of a recent USC study, 500 AI agents independently coordinated to promote a political candidate. Used against businesses or public figures, such agent-driven campaigns could inflict reputational damage within days where trust takes years to build.
Dual targets: human and machine cognition
Agentic AI pushes disinformation beyond mass generation and amplification towards automation and saturation. This makes true and false progressively harder to distinguish. Where generative AI enabled hyper-personalized disinformation, agentic AI can fabricate synthetic consensus at scale, aided by personal data used for profiling.
This is where disinformation could become cognitive warfare: human cognition could emerge as a central target of modern conflict, while autonomous influence operations would make subversive campaigns easier to launch and harder to trace.
AI swarms meet fertile ground amid what some call a deepening epistemic crisis due to the erosion of society’s ability to agree on fundamental facts. Traditional intermediaries such as science, media and government agencies have seen their authority decline with the rise of the internet and social media. This has weakened collective trust and left societies more susceptible to disinformation. Agentic AI could exploit these vulnerabilities with precision.
And in the AI era, cognitive warfare can also target machine cognition – processes in artificial systems resembling human perception, inference and reasoning.
As synthetic data proliferates, data-poisoning risks also grow. LLM grooming can plant deceptive content across the open web to enter training data and skew model outputs. Such attacks need little to succeed, with one study showing that 250 poisoned documents are enough to embed a hidden vulnerability into an LLM.
Even without deliberate manipulation, models may feature disinformation prominently where little credible information exists. Swarms could quickly fill such data voids with synthetic content, distorting public perception early on. As human-generated data grows scarce, models increasingly train on synthetic data, risking self-reinforcing errors and biases. This phenomenon is known as model collapse.
Evidence suggests AI interactions can shift beliefs across contested societal issues.
AI models thus present high-value targets. Compromising them risks contaminating both machine and human cognition, and with it the reliable information and undistorted judgement essential to decision-making across public and private sectors. Agentic AI compounds this risk when the scale and speed of its decisions outpace human oversight.
How to build cognitive security
Defending the information ecosystem demands a multi-layered approach built around two interconnected goals: protecting cognitive security and building cognitive resilience for humans and machines.
On the human side, individual, institutional and societal resilience requires educational, policy and regulatory measures. Systematic media and AI literacy, alongside adapted education, can help to improve critical thinking and safeguard human cognitive security.
Organizations need practices such as AI auditing and red teaming, and protocols to verify information before it influences decisions. Awareness of cognitive manipulation risks such as corrupted intelligence, fabricated pressure and impersonated leadership is also important.
More widely, regulation must address accountability and alter the systemic incentives that favour disinformation, such as its lower production cost relative to truthful content as well as the tendency of digital platforms to prioritise engagement over accuracy.
As AI systems become part of global cognitive infrastructure, cognitive security must also extend to machines. Sovereign or in-house models trained on trusted, verified datasets reduce exposure to data poisoning and model collapse. Progress in mechanistic interpretability – the ability to understand models’ inner workings – would enable better tracing and auditing of AI behaviour.
Cross-platform monitoring shows promise in predicting how false narratives spread, while defensive AI agents could detect disinformation by identifying coordination patterns that are unlikely to be human. They could also monitor brand reputation to flag defamation campaigns before they gain traction.
All of these actions will require a mindset shift that treats the foundations of human and machine cognition as critical infrastructure.
Building resilience to cognitive threats is as much a governance challenge as a technical one. It demands institutional capacity, cross-sectoral research, international collaboration and genuine multi-stakeholder engagement.
Don't miss any update on this topic
Create a free account and access your personalized content collection with our latest publications and analyses.
License and Republishing
World Economic Forum articles may be republished in accordance with the Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International Public License, and in accordance with our Terms of Use.
The views expressed in this article are those of the author alone and not the World Economic Forum.
Stay up to date:
Disinformation
Related topics:
Forum Stories newsletter
Bringing you weekly curated insights and analysis on the global issues that matter.
More on Artificial IntelligenceSee all
Peter Bakker and Gabriela Ramos
September 8, 2026





