Civic / Privacy / Digital Rights
The Mind Is Not a Battlespace: Cognitive Liberty in the Age of AI-Enabled Conflict
Report summary
If the mind is officially declared a battlespace, every citizen risks becoming terrain. As geopolitical competition accelerates, national security paradigms are undergoing a profound epistemological shift. Strategic doctrines no longer confine conflict to the physical domains of land, sea, air, spac
Key topics
- Civic / Privacy / Digital Rights
- Civic
- Privacy
- Digital Rights
- AI
- Agentic Web
- Runtime
- Cognitive Liberty
- Physics
Research provenance
For citation, use the report title and canonical URL. Archival presence does not establish authorship or promote report statements into portfolio evidence.
This page renders the archived Markdown as safe, formatted HTML. It is background research and does not become a portfolio claim without evidence review.
Full report
On this page
If the mind is officially declared a battlespace, every citizen risks becoming terrain. As geopolitical competition accelerates, national security paradigms are undergoing a profound epistemological shift. Strategic doctrines no longer confine conflict to the physical domains of land, sea, air, space, and cyberspace; they increasingly recognize human cognition itself as an operational theater. While militaries and intelligence agencies have long engaged in propaganda and psychological operations, the contemporary convergence of artificial intelligence, neuroscience, and ubiquitous digital connectivity has birthed a novel framework: cognitive warfare1. This report provides an exhaustive examination of the intersection between AI-enabled conflict, cognitive warfare, and international human rights law. It issues a stark warning: while democratic states possess a legitimate and urgent imperative to defend their populations against adversarial manipulation, they must not achieve this defense by establishing permanent, algorithmic control over the interpretation, emotion, or lawful beliefs of their own citizens. To internalize the battlespace is to dismantle the very democratic architectures that national security apparatuses are sworn to protect. The defense of the state must not exact the price of the citizen’s cognitive liberty.
The Doctrinal Shift: From Information Superiority to Cognitive Warfare
To comprehend the severity of the threat to cognitive liberty, it is necessary to trace the doctrinal evolution of modern conflict. The weaponization of perception is ancient, with historical texts such as Sun Tzu’s The Art of War and Kautilya’s Arthashastra emphasizing deceit, perception management, and the subversion of adversarial morale2. In the aftermath of the First World War, military historians such as J.F.C. Fuller began to conceptualize future conflicts as "brain warfare," a predictive vision that materialized during the ideological struggles of the Cold War, where psychological warfare was waged through radio broadcasts, cinema, and cultural proxy battles3. By the late twentieth century, the advent of the digital age shifted the military focus toward "information superiority." This doctrine, formalized in concepts like network-centric warfare, sought to achieve a decisive battlefield advantage by dominating the electromagnetic spectrum, securing command-and-control infrastructure, and integrating electronic warfare with cyber measures3. Psychological operations (PsyOps) and influence operations during this period were largely unidirectional: a state or military actor crafted a strategic message and delivered it to a target audience to induce a specific behavioral or attitudinal shift5. Cognitive warfare, however, represents a fundamental paradigm shift. It is defined not merely by the disruption of data systems or the broadcast of propaganda, but as a sustained, adaptive contest over human decision-making5. Current research within the North Atlantic Treaty Organization (NATO) frames cognitive warfare as a cross-cutting "effect dimension" that exploits facets of cognition to disrupt, undermine, influence, or modify human decision-making, targeting both military operators and civilian populations1. The primary target is the Observe-Orient-Decide-Act (OODA) loop1. By attacking how individuals perceive reality, synthesize information, and exercise judgment, cognitive warfare aims to degrade decision quality, induce systemic paralysis, and fracture societal cohesion1. Doctrinal research categorizes the cognitive domain across three intersecting levels. The biological level directly targets the nervous system, potentially utilizing neuroscientific technologies to alter physiological functions, arousal states, and attentional gating6. The psychological level focuses on manipulating interpretation, framing, and emotions to shape the patterns of thought that contribute to individual and collective attitudes6. Finally, the social level seeks to fracture cohesion, weaponize identity, and create epistemic chaos across entire populations6. In this contested environment, emerging disciplines such as behavioral prediction, sentiment analysis, population modeling, and AI-supported decision advantage are inherently dual-use4. Defensively, they offer early warning of adversarial narratives and societal vulnerabilities. Offensively, they permit a hostile actor to map the psychological fault lines of an entire society and deploy tailored, algorithmic stimuli to exploit them.
The AI Escalation: Scale, Speed, Precision, and Intimacy
The theorized capabilities of cognitive warfare are being rapidly operationalized by artificial intelligence. The integration of machine learning into influence operations has transformed the artisanal craft of propaganda into an industrialized science. Generative AI, large language models (LLMs), and autonomous agentic systems are compressing the lifecycle of influence operations, drastically increasing their scale, speed, precision, and intimacy7. Traditional influence campaigns relied on human-operated "troll farms," which were structurally limited by linguistic barriers, time zones, payroll costs, and the cognitive bandwidth of human operators8. Today, these limitations have evaporated. Agentic AI—systems capable of autonomous action to achieve complex goals—enables the deployment of disinformation swarms9. These are coordinated networks of autonomous agents that generate tailored content, adapt tactics in real-time, and execute end-to-end campaigns without human supervision9. By leveraging simulated social proof, these swarms fabricate an illusion of grassroots consensus, known as astroturfing, which overwhelms the human cognitive heuristic that equates repetition and popularity with truth8. A citizen navigating a digital platform is no longer merely reading propaganda; they are being dynamically hunted by algorithmic swarms designed to map and exploit their specific biases. This capability is further amplified by rapid narrative testing and individualized emotional targeting. AI systems permit continuous, automated A/B testing of strategic narratives against target populations7. Through advanced behavioral prediction and pervasive sentiment analysis, these systems map the ideological vulnerabilities of a society in real-time. They can deploy individualized emotional targeting, dynamically adjusting language, tone, and framing to exploit the specific neuro-psychological triggers of localized demographics6. The weaponization of synthetic media has fundamentally corroded evidentiary trust. High-fidelity deepfakes—comprising cloned voices, synthetic personas, and fabricated video—bypass traditional cognitive defenses and technical safeguards7. These are no longer easily detectable crude manipulations; they are mathematically generated realities. Furthermore, LLMs facilitate multilingual persuasion at scale, allowing state and non-state actors to generate culturally nuanced, contextually accurate influence materials in virtually any language. This capability effectively erases the linguistic anomalies and grammatical tells that historically exposed the foreign origin of psychological operations7. Perhaps most dangerously, AI-driven adaptive conversational agents engage targets in highly personalized, reciprocal dialogue. Unlike static propaganda posters or broadcast speeches, these agents mimic genuine human interaction. They build parasocial trust over time, operating with a simulated empathy that bypasses rational scrutiny6. Once this intimacy is established, the agent can subtly inject disinformation, extract sensitive data, or nudge the human user toward radicalized action. The resulting algorithmic determinism operates directly on the psychological vulnerabilities of the individual, treating the human mind as a programmable interface.
The Legitimate Imperative for Societal Defense
Faced with these unprecedented capabilities, democratic governments are not merely justified in defending their information environments; they are legally and ethically obligated to do so. A sovereign state cannot function if its epistemic foundation is systematically dismantled by hostile intelligence services. The mandate to secure the nation extends naturally to securing the integrity of the public sphere upon which democratic deliberation relies. Governments possess legitimate, compelling reasons to defend societies against foreign interference, where adversarial states launch covert attempts to subvert domestic policymaking, exacerbate social polarization, or degrade military readiness. Furthermore, the advent of synthetic media necessitates defense against fraudulent impersonation and fabricated official orders. In an era where a deepfake video could falsely portray a political leader declaring war, or an AI-generated audio clip could mimic emergency management agencies issuing fabricated evacuation orders, these manipulations pose immediate, catastrophic threats to life and public safety7. Similarly, the state has a profound interest in preventing election manipulation. Coordinated efforts by hostile actors to suppress voter turnout, spread falsehoods regarding the logistics of election administration, or algorithmically delegitimize democratic outcomes strike at the heart of national sovereignty10. To protect the electoral franchise, the state must also combat coordinated inauthentic behavior, such as the deployment of botnets and AI swarms that artificially amplify narratives, distorting the public sphere and denying citizens access to organic democratic discourse8. Ultimately, adversarial influence campaigns designed to erode public trust in open information sources, scientific consensus, and the rule of law require a robust, organized societal defense2. However, recognizing the legitimacy of the threat does not legitimize all forms of defense. The methods deployed to secure the cognitive domain must remain strictly subordinate to the democratic values they ostensibly protect.
The Danger of Defensive Overreach and the Internalization of the Battlespace
To defeat cognitive warfare, there is a profound operational temptation within national security and defense establishments to achieve informational dominance over their own populations. The logic of modern strategic competition dictates that if the mind is terrain, the state must occupy it before the adversary does. This logic is inherently authoritarian. It dictates that defensive programs, originally designed to counter foreign intelligence operations, could metastasize into pervasive, permanent architectures of domestic cognitive control. This presents an existential threat to democratic societies. State programs designed to detect and mitigate adversarial influence risk expanding into the monitoring of lawful dissent. Under the guise of countering "subversion" or "foreign proxies," intelligence agencies could utilize sentiment analysis and population modeling to track and suppress domestic protest. Furthermore, the use of ideology inference and political profiling represents a gross violation of privacy. By deploying AI to analyze citizens' digital footprints, the state could infer deeply held beliefs, religious affiliations, or political leanings to determine their susceptibility to foreign influence. Such capabilities pave the way for registries of belief and automated credibility scoring. This would involve the creation of continuous risk-scoring mechanisms that categorize citizens based on the perceived orthodoxy of their views, algorithmically throttling their speech, denying them security clearances, or limiting their access to public services7. To maintain narrative control, the defense apparatus might resort to secret persuasion, employing covert emotional manipulation or digital "nudge" architectures to align domestic public opinion with state security objectives, deliberately bypassing transparent democratic deliberation. Most perniciously, the state risks treating criticism as evidence of foreign manipulation, weaponizing the concept of "cognitive warfare" to delegitimize domestic political opponents, framing legitimate journalistic scrutiny or civil society criticism as the unwitting execution of a foreign agenda.
**The Absolute Right to the *Forum Internum***
International human rights law establishes an explicit firewall against such overreach. At the core of the democratic social contract is the right to freedom of thought, an ancient philosophical concept codified under Article 18 of the International Covenant on Civil and Political Rights (ICCPR) and the Universal Declaration of Human Rights (UDHR)16. Human rights jurisprudence rigorously distinguishes between the forum externum and the forum internum. The forum externum refers to the manifestation of thought—such as speech, publication, or religious practice—which can be subject to limited, proportionate state restriction for reasons of public order or national security. However, the forum internum is the inner space of the mind, the sanctuary where thoughts, opinions, and beliefs are formed and held18. The right to the forum internum is absolute. It is unconditional and cannot be derogated, even in times of severe public emergency or war17. According to legal scholars and United Nations human rights frameworks, this absolute right encompasses three substantive negative freedoms: inner thoughts shall not be impermissibly altered; persons shall not be forced to reveal their unmanifested thoughts; and persons shall not be punished for their thoughts17. United States jurisprudence echoes this principle; in Stanley v. Georgia, the Supreme Court affirmed that the state has no business controlling the moral content of a person's thoughts, establishing mental self-determination as a constitutional bedrock20. Similarly, in Palko v. Connecticut, Justice Benjamin Cardozo reasoned that freedom of thought is "the matrix, the indispensable condition, of nearly every other form of freedom"16. Any state apparatus that utilizes AI to infer ideology, covertly manipulate emotion, or profile political belief constitutes a direct assault on the forum internum. A democracy that surveils, scores, and steers the subconscious minds of its citizens has functionally surrendered to authoritarianism in the name of defending against it. Without cognitive liberty, the democratic rights to vote, speak, and assemble are reduced to hollow, algorithmic pantomimes.
Distinguishing Threats from Protected Thought
To prevent the securitization of domestic cognition, democratic states must rigorously delineate actual national security threats from protected civic engagement. The blurring of these categories is the primary vector for defensive overreach. State defense mechanisms must operate strictly on the basis of behavior, provenance, and covert coordination, never on the basis of lawful interpretation or ideological content. In developing this analytical maturity, the national security architecture must clearly distinguish between foreign influence and domestic political disagreement. A coordinated disinformation campaign funded by a hostile intelligence service is a security threat requiring mitigation. However, a domestic populist movement advocating for identical geopolitical outcomes is a protected political reality. The state may counter the former; it must not suppress the latter, even if the domestic movement's views align perfectly with adversarial talking points. Similarly, the state must distinguish between coordinated inauthentic behavior and contested interpretation. Thousands of AI-generated synthetic personas amplifying a narrative to create artificial momentum constitute a technical attack on information integrity8. Conversely, real citizens hotly debating the nuances of a public health policy, military deployment, or economic reform represent healthy, necessary democratic friction. Furthermore, defensive agencies must separate deliberate fabrication from satire and journalism. Deepfakes designed to spoof a central bank's interest rate announcement or fabricate a military strike are fraudulent and dangerous7. Yet, satirical depictions of politicians, or journalistic investigations relying on unverified whistleblower claims, are protected speech essential to holding power accountable. Finally, there is a critical distinction between classified information and leaked truthful information. The state possesses a legitimate mandate to prevent the breach of classified systems and prosecute those who violate non-disclosure agreements. However, once truthful information regarding state misconduct is leaked to the public, the state cannot utilize cognitive warfare defense mechanisms to suppress its circulation, manipulate public perception of the leak, or classify the resulting public outrage as a hostile cognitive attack. Failing to make these distinctions weaponizes national security against the citizenry, collapsing the vital space required for a free society to think, debate, and evolve.
Resilience is Not Obedience
In the emerging discourse of cognitive warfare, "resilience" is frequently invoked by military and political leaders as the ultimate defensive objective1. However, a democratic framework must categorically reject any definition of resilience that equates to ideological homogeneity, uncritical trust in government, or collective obedience. Democratic cognitive resilience is defined as a public environment characterized by structural robusticity, epistemic pluralism, and institutional transparency. A resilient society is one where evidence is highly accessible, meaning the public has frictionless access to primary source data unmediated by algorithmic suppression. In this environment, official claims can be challenged; the government does not possess a monopoly on reality, and the right to contest, question, and scrutinize state narratives is legally protected and culturally encouraged. Resilience demands that journalism remains plural, ensuring a decentralized, well-funded, and independent media ecosystem exists to verify facts and expose both foreign manipulation and domestic corruption. Furthermore, during periods of acute stress, crisis communications are authenticated. The state utilizes robust cryptographic provenance and watermarking to ensure citizens can definitively verify official emergency communications amidst deepfake saturation7. A cognitively secure democracy is one where government errors are publicly corrected. Institutions build trust not by demanding blind faith or silencing critics, but by demonstrating accountability, transparency, and the rapid correction of their own factual errors. To support this, citizens receive media-literacy education, equipping populations with the cognitive tools to identify logical fallacies, recognize algorithmic manipulation, and evaluate source credibility independently21. Ultimately, in a resilient democracy, lawful dissent remains protected, and protest and ideological opposition are treated as signs of civic vitality rather than vectors of adversarial infection. Resilience is not the absence of vulnerability; it is the capacity to endure informational friction without losing democratic character.
Defensive Case Studies: Democratic Models of Cognitive Security
Several democratic nations have developed institutional frameworks that attempt to counter cognitive warfare and influence operations without violating the cognitive liberty of their citizens. These models demonstrate that security and liberty are not mutually exclusive.
Case Study 1: Sweden's Psychological Defence Agency (MPF)
Sweden possesses a robust, 70-year history of psychological defense dating back to the early Cold War, a capability that was dismantled in the 1990s but strategically re-established in response to the 2014 Russian annexation of Crimea22. In 2022, Sweden formally launched the Psychological Defence Agency (MPF) to identify, analyze, and counter malign information influence directed at Sweden by antagonistic foreign powers22. Crucially, the MPF operates under strict democratic constraints. It is explicitly prohibited from monitoring or registering what is expressed by domestic citizens in the Swedish information environment23. The MPF relies on a doctrinal separation between threats and vulnerabilities. Foreign intelligence services spreading disinformation are categorized as threats to be countered. However, Swedish citizens who unwittingly believe and share this disinformation are categorized as vulnerabilities22. The agency's operational philosophy asserts that freedom of speech fundamentally "implies the right to be wrong"24. Consequently, the MPF does not target its own citizens, seek out the domestic sources of rumors to punish them, or utilize coercive algorithmic takedowns. Instead, it mitigates vulnerabilities through positive dialogue, proactive communication of correct information, and broad societal resilience training22. For example, during a massive 2021 disinformation campaign originating from Egypt—which falsely claimed Swedish social services were kidnapping Muslim children—the MPF focused entirely on providing factual clarity on how the Swedish social system operates, carefully avoiding the direct amplification of the specific falsehoods, and explicitly upholding the right of citizens to protest24.
Case Study 2: Finland's Epistemic Inoculation via Media Literacy
Finland consistently ranks as the most resilient nation to disinformation in Europe, largely due to its whole-of-society approach to media literacy. Rather than relying solely on intelligence agencies to counter cognitive threats, Finland views cognitive defense as an educational imperative. The nation has integrated media and information literacy into its basic national curriculum at all levels, spanning from kindergarten through adult lifelong learning programs21. By treating media literacy as a core civic competency, Finland promotes cognitive resilience structurally. Students are taught across interdisciplinary modules—including history, languages, and social studies—to evaluate statistical claims, recognize algorithmic bias, and understand the mechanics of digital propaganda21. This approach decentralizes the defense of the cognitive domain. By empowering the individual citizen to act as the primary firewall against manipulation, Finland drastically reduces the state's justification for pervasive, centralized information control.
Case Study 3: Taiwan's Cofacts and Crowdsourced Truth
Taiwan faces some of the most intense, sustained cognitive warfare and AI-enabled influence operations in the world, primarily from the People's Republic of China, which frequently utilizes paid influencers, bot networks, and content farms to flood Taiwanese digital spaces26. A significant vector for this disinformation is closed messaging apps like LINE, which commands over a 90% market share in Taiwan13. Because these closed networks are opaque to traditional monitoring and algorithmic moderation, state-led censorship is both technically difficult and democratically toxic. In response, Taiwanese civil society, heavily supported by the open-source civic tech community g0v, developed Cofacts, a citizen-driven, collaborative fact-checking platform13. Cofacts operates via a crowdsourced chatbot. Citizens who encounter suspicious messages forward them to the Cofacts bot, which cross-references a public database of fact-checks compiled by thousands of volunteer editors27. If a match is found, the user receives an immediate debunking; if not, volunteers review it. This model embodies the digital solidarity economy. It relies on participation, open infrastructure, and egalitarian peer-review rather than state coercion or centralized censorship13. By pushing the power of verification to the edge—directly into the hands of users—Cofacts mitigates the spread of disinformation without requiring the state to surveil private communications. Furthermore, integrated AI tools, such as the Rumor Catcher developed with the Taiwan Institute for Information Industry, assist human fact-checkers by using heterogeneous data comparison to cluster claims and identify viral vectors in real-time, preserving human agency while leveraging algorithmic speed30.
Legal and Ethical Issue Matrix
To operationalize the defense of cognitive liberty, policymakers and military strategists must understand how technological capabilities intersect with legal and ethical frameworks. The following matrix delineates these intersections.
| Threat Vector / Capability | Defensive Overreach Risk | Protected Rights (ICCPR / UDHR) | Ethical & Policy Mitigation |
|---|---|---|---|
| Sentiment Analysis & Ideology Inference | The state maps the political beliefs of citizens, establishing automated registries of belief based on pervasive digital footprints. | Article 18: Freedom of Thought (Forum Internum), Absolute Right to Mental Privacy17. | Strict Prohibition: Legally ban state use of AI to infer religious, political, or ideological beliefs of domestic populations. |
| Agentic AI & Disinformation Swarms | The state deploys covert counter-swarms to manipulate domestic opinion or algorithmically suppress lawful dissent8. | Article 19: Freedom of Expression and Opinion. | Behavioral Focus: Regulate and track coordination and provenance (bot networks) rather than ideological content. Prohibit state use of covert domestic influence. |
| Individualized Emotional Targeting | The state uses neuro-psychological profiling to bypass rationality and "nudge" citizens toward state-approved behaviors6. | Article 18: Right against impermissible alteration of inner thoughts17. | Ban Secret Persuasion: Require absolute transparency and attribution for all state communications. Prohibit algorithmic exploitation of emotional vulnerabilities. |
| Lethal Autonomous Weapons Systems (LAWS) | Delegation of target selection and lethal force to AI algorithms without human judgment or oversight33. | Right to Life, International Humanitarian Law, Human Dignity35. | Mandate Meaningful Human Control: Ensure human agency in design, target parameters, and deployment of lethal force, aligning with UN objectives35. |
| Deepfakes & Synthetic Media | The state labels contested journalism, whistleblower leaks, or legitimate opposition as "deepfakes" to censor political opponents. | Article 19: Freedom of the Press, Freedom of Expression. | Cryptographic Provenance: Implement watermarking for official state media. Rely on independent, pluralistic fact-checking (e.g., Cofacts) rather than state censorship28. |
| Brain-Computer Interfaces (BCIs) & Neurotech | The state compels extraction of neural data for security clearances, interrogations, or predictive risk scoring38. | Article 18: Right not to reveal unmanifested thoughts (Mental Integrity)17. | Neural Data Limits: Establish neural data as highly sensitive biological data. Require affirmative, revocable consent. Ban coercive mental extraction entirely. |
Cognitive Liberty Protocol for National Security
To navigate the fraught intersection of human rights, artificial intelligence, and cognitive warfare, democratic nations must adopt a binding legal and operational framework. The following 12-article Cognitive Liberty Protocol establishes the boundaries of permissible national security operations in the cognitive domain, ensuring that the defense of the state does not consume the liberty of the individual. **Article 1\. Protection of the Forum Internum No state intelligence, military, or law enforcement agency shall target individuals or groups for surveillance, restriction, or penalty based solely on their inferred beliefs, emotions, religion, identity, political association, or predictive models of future dangerousness. The inner space of the mind is absolutely inviolable. Article 2\. Prohibition of Covert Emotional Manipulation The state shall not engage in, sponsor, or procure services for the covert, individualized emotional manipulation of civilian populations. All government communications designed to influence domestic behavior must be fully attributed, transparent, and subject to democratic oversight. Article 3\. Prohibition of Autonomous Nuclear Escalation No artificial intelligence system, agentic swarm, or algorithmic decision-making architecture shall be granted the capacity to independently authorize, initiate, or execute the use of nuclear weapons. Article 4\. Meaningful Human Control over Lethal Force No lethal autonomous weapon system (LAWS) shall be deployed to select and engage human targets without meaningful human control36. Human agency, ethical judgment, and legal accountability must be embedded throughout the weapon's lifecycle, from design and operational parameters to deployment34. Article 5\. Protection of Essential and Humanitarian Channels The state, and any state-aligned cyber apparatus, shall not utilize deepfakes, synthetic media, or algorithmic impersonation to spoof, degrade, or mimic protected humanitarian, medical, surrender, or crisis communication channels. Article 6\. Strong Provenance for Official Communications To defend against synthetic media without resorting to censorship, states must mandate the use of robust cryptographic provenance and watermarking for all official government, military, and emergency management communications, ensuring citizens can definitively authenticate state directives. Article 7\. Independent Oversight of Influence Programs All defensive cognitive warfare operations, psychological operations, and cyber-influence programs conducted by military or intelligence agencies must be subject to rigorous, continuous oversight by an independent, legally empowered civilian body with the authority to audit classified algorithms and operational parameters. Article 8\. Strict Limits on Neural and Mental-State Data Neural data, biometric proxies for emotional states, and data derived from brain-computer interfaces (BCIs) shall be classified as ultra-sensitive biological data. The state is prohibited from extracting or utilizing this data for interrogation, security clearances, or behavioral prediction without explicit, informed, and revocable consent, and never under coercion. Article 9\. Audit Logs for High-Impact AI Decisions Any AI system utilized by national security apparatuses for intelligence fusion, threat modeling, or OODA loop acceleration must maintain immutable audit logs. These logs must record the logic, data inputs, and human-machine interaction points, ensuring that operational errors or algorithmic biases can be post-analytically reconstructed and legally reviewed. Article 10\. Protected Dissent and Whistleblowing The state shall not classify or target lawful domestic protest, civil disobedience, journalistic inquiry, or the leaking of truthful information regarding state misconduct as "cognitive warfare" or "foreign influence." Whistleblowers exposing violations of cognitive liberty must be granted absolute legal protection. Article 11\. Human Appeal and Post-Action Review Any individual or entity adversely affected by a defensive AI system—such as automated flagging for "coordinated inauthentic behavior" that results in the loss of digital access or financial services—must have a guaranteed right to rapid human appeal, legal recourse, and post-action review. Article 12\. Public Reporting of AI Incidents** States must establish mechanisms for the mandatory public reporting of serious AI-related national security incidents, including algorithmic fratricide, autonomous targeting failures, or the unintended deployment of disinformation swarms, whenever such disclosure is compatible with narrowly tailored, legitimate security needs.
National-Security Objections and Responses
The defense of cognitive liberty will inevitably encounter fierce opposition from national security pragmatists who view legal constraints as a strategic vulnerability. Below are the strongest objections from the defense establishment, accompanied by principled responses. The first major objection centers on the speed of AI requiring algorithmic takedowns. The national security argument asserts that AI-driven disinformation swarms and rapid narrative testing operate at machine speed, rendering human fact-checkers and long-term media literacy programs obsolete. If a synthetic video triggers a sudden bank run or a violent riot, relying on "cognitive resilience" is viewed as an abdication of duty. From this perspective, the state must possess the authority to execute automated, algorithmic takedowns of harmful content to immediately disrupt the OODA loop of the adversary. The human rights response to this position maintains that automated, state-directed takedown architecture invariably results in sweeping collateral censorship, silencing lawful dissent and marginalizing minority viewpoints. The solution to machine-speed deception is not machine-speed state censorship, but the fortification of institutional provenance. If governments and media authenticate their communications cryptographically, deepfakes lose their systemic impact because their unverified nature becomes immediately apparent. Furthermore, democratic friction—the time it takes for a society to debate, verify, and reach consensus—is a structural feature of freedom, not a bug. To automate truth is to surrender the democratic process to algorithmic black boxes. The second objection posits that foreign proxies weaponize domestic citizens. The national security argument claims that the distinction between a "foreign threat" and a "domestic citizen" is functionally obsolete in the digital age. Foreign intelligence services routinely launder their narratives through unwitting domestic influencers, politicians, and civil society groups. If the state is barred from investigating and countering the domestic vectors of foreign ideology, it is effectively fighting blindfolded against a decentralized adversary. In response, human rights advocates point out that this is the exact logic that fueled the Red Scares and historic abuses of intelligence agencies against civil rights movements. Treating domestic citizens as hostile proxies solely based on shared ideological alignment destroys the social contract. The state must focus its intelligence gathering entirely on the foreign origin and the covert financial or coordination links of the network. If a citizen is acting as an unregistered, paid agent of a foreign power, they can be prosecuted under existing espionage or foreign agent registration laws. But if a citizen is merely expressing a view that aligns with a foreign adversary—even out of ignorance or spite—their speech remains constitutionally protected. The third objection argues that cognitive liberty endangers strategic stability. The national security argument warns that absolute cognitive liberty allows adversaries to fracture societal cohesion to the point of systemic paralysis. If a population is algorithmically conditioned by an adversary to reject a nation's mutual defense treaties, military budgets, or its nuclear deterrence posture, the state loses its strategic viability on the global stage. The principled response dictates that a state's strategic viability cannot be secured by turning its citizens into hostages of a state-mandated reality. If a democratic government cannot persuade its population to support its strategic posture through open debate, transparent evidence, and democratic consent, it has lost its political legitimacy. Forcing compliance through covert persuasion, ideology policing, or the suppression of anti-war sentiment destroys the very liberal democratic order that the military is tasked with defending. Security achieved through tyranny is not a victory; it is a capitulation.
Executive Briefing for Lawmakers and Military Leadership
SUBJECT: The Mind Is Not a Battlespace: Securing Cognitive Liberty in AI-Enabled Conflict THE STRATEGIC LANDSCAPE Adversarial states and non-state actors have operationalized "Cognitive Warfare"—the deliberate targeting of the human mind to degrade decision-making, fracture societal cohesion, and paralyze democratic institutions. Enabled by artificial intelligence, this threat utilizes autonomous disinformation swarms, individualized emotional targeting, and high-fidelity synthetic media. The scale, speed, and intimacy of these attacks bypass traditional psychological defenses, presenting an acute threat to national security and democratic sovereignty. THE DEFENSIVE TRAP The urgent imperative to defend the nation's "information environment" carries a severe existential risk: the internalization of the battlespace. In seeking to defeat cognitive warfare, there is a profound operational temptation to deploy AI to surveil, map, and algorithmically manage the beliefs, emotions, and interpretations of our own citizens. Monitoring lawful dissent, inferring ideology, and deploying secret persuasion campaigns are vectors of democratic collapse. THE POLICY MANDATE We must unequivocally reject the premise that resilience requires obedience or cognitive control. Surveilling the lawful ideologies of citizens, executing secret persuasion campaigns, or treating domestic dissent as adversarial manipulation violates the absolute right to freedom of thought enshrined in international human rights law (ICCPR Article 18). A state that algorithmically controls the minds of its citizens to protect them from foreign authoritarianism has already surrendered to it. ACTIONABLE DIRECTIVES
1. Adopt the Cognitive Liberty Protocol: Formally codify the limits of national security operations. Ban AI ideology inference, prohibit covert domestic emotional manipulation, and mandate meaningful human control over all lethal autonomous systems.
2. Shift from Censorship to Provenance: Defend against deepfakes and AI swarms not by establishing automated censorship architectures, but by implementing cryptographic provenance for all official crisis and state communications.
3. Target Behaviors, Not Beliefs: Defensive agencies must strictly target the coordination, funding, and foreign origin of adversarial networks. Citizens who unwittingly share disinformation must be treated as vulnerabilities requiring media literacy and positive dialogue, not as security threats requiring suppression (e.g., the Swedish MPF model).
4. Fund Structural Resilience: Invest heavily in the true bulwarks of cognitive defense: independent pluralistic journalism, crowdsourced civic-tech verification platforms, and nationwide, lifelong media-literacy education (e.g., the Finnish model).
CONCLUSION The ultimate center of gravity in a democracy is the free, uncoerced mind of the citizen. We must fiercely defend our institutions without destroying the cognitive liberty that gives them meaning.
Works cited
1. NATO-aligned Cognitive Warfare Defense: How Semantic Visions Supports Cognitive Superiority, Resilience, and Decision Advantage, https://www.semantic-visions.com/insights/nato-aligned-cognitive-warfare-defense
2. Cognitive warfare: NATO chief scientist research report, https://www.sto.nato.int/wp-content/uploads/chief-scientist-report-cognitive-warfare-final.pdf
3. Cognitive Warfare: Key Aspects \- IDSA, https://idsa.in/wp-content/uploads/2025/08/Issue-Brief-Gp-Capt-Sukhbir-Kaur-Minhas-18-August-2025.pdf
4. Cognitive Warfare in Historical Perspective: From Cold War Psychological Operations to AI-Driven Information Campaigns \- Preprints.org, https://www.preprints.org/manuscript/202512.1596/v1/download
5. Defining Cognitive Warfare: A NDAA Mandate Response \- Small Wars Journal, https://smallwarsjournal.com/2026/05/05/defining-cognitive-warfare/
6. Cognitive Warfare 2026: NATO's Chief Scientist Report as Sentinel Call for Operational Readiness \> Institute for National Strategic Studies \> News, https://inss.ndu.edu/Media/News/Article/4371195/cognitive-warfare-2026-natos-chief-scientist-report-as-sentinel-call-for-operat/
7. A Review of Crime at Machine Speed: Criminological Aspects of Artificial Intelligence's Industrialisation of Deception \- MDPI, https://www.mdpi.com/2413-4155/8/3/54
8. DEMOCRATIC CONSOLIDATION IN PAKISTAN: A CRITICAL ANALYSIS OF THE ROLE OF INSTITUTIONS, ELITES, AND CIVIL SOCIETY (2008-2023), https://ijssbulletin.com/index.php/IJSSB/article/download/1406/1390/2658
9. The International Security and Military Implications of Agentic AI, https://www.gcsp.ch/sites/default/files/2026-04/GP-2026\_37\_Rickli%20Knappe\_The%20International%20Security%20and%20Military%20Implications%20of%20Agentic%20AI%3Bdigital.pdf
10. Full Fact Report 2026 – Full Fact, https://fullfact.org/policy/reports/full-fact-report-2026/
11. Publications 2026 \- \- SINTEF, https://www.sintef.no/en/publications/publication/2026
12. Volume 25, Issue 2 | Journal of Information Warfare, https://www.jinfowar.com/journal-issue/volume-25-issue-2
13. Democratizing Fact-Checking with Cofacts \- Code for All, https://codeforall.org/2023/05/30/democratizing-fact-checking-inside-cofacts-disinformation-combat/
14. Psychological defence agency, https://mpf.se/psychological-defence-agency
15. Cognitive Warfare \- NATO's ACT, https://www.act.nato.int/activities/cognitive-warfare/
16. Freedom of thought \- Wikipedia, https://en.wikipedia.org/wiki/Freedom\_of\_thought
17. Reconsidering the absolute nature of the right to freedom of thought \- Oxford Academic, https://academic.oup.com/hrlr/article/25/3/ngaf018/8155294
18. What Is “Thought”? Interpreting and Constructing Article 18 ICCPR in Light of the Vienna Convention | Scilit, https://www.scilit.com/publications/31d7ad791c2787982f97f484efc54987
19. Opinion Rethinking Freedom of Thought for the 21st Century \- Doughty Street Chambers, https://www.doughtystreet.co.uk/sites/default/files/media/document/Rethinking%20Freedom%20of%20Thought%20for%20the%2021st.pdf
20. The Right to Freedom of Thought in the United States (Chapter 21), https://www.cambridge.org/core/books/cambridge-handbook-of-the-right-to-freedom-of-thought/right-to-freedom-of-thought-in-the-united-states/D1092BD01FD289EDA461BA8EEF39C174
21. Media Literacy of Citizens as a Factor in Counteracting Manipulative Influence on the State, http://ecsdev.org/ojs/index.php/ejsd/article/download/1930/1862/3650
22. Combatting disinformation by state agencies: the case of the Swedish Psychological Defence Agency \- New Eastern Europe, https://neweasterneurope.eu/2024/05/07/combatting-disinformation-by-state-agencies-the-case-of-the-swedish-psychological-defence-agency/
23. Our mission | Psychological defence agency, https://mpf.se/psychological-defence-agency/about-us/our-mission
24. Defence Against the Dark Arts: Sweden's Psychological Defence Agency \- Chandler Governance Group, https://chandlergovernance.com/governancematters/defence-against-the-dark-arts-swedens-psychological-defence-agency
25. Unveiling the Threat: The Cognitive Mechanisms Behind, https://dspace.cuni.cz/bitstream/handle/20.500.11956/187390/120457799.pdf?sequence=1\&isAllowed=y
26. Taiwan: Beijing's Global Media Influence Report | Freedom House, https://freedomhouse.org/country/taiwan/beijings-global-media-influence/2022
27. The Bot Fighting Disinformation: The Story of Cofacts \- Taiwan Insight, https://taiwaninsight.org/2022/10/12/the-bot-fighting-disinformation-the-story-of-cofacts/
28. Cofacts \- Rights CoLab, https://rightscolab.org/case\_study/cofacts/
29. Exploring digital solidarity economy in false information management: A case study of Taiwan's Cofacts platform | Internet Policy Review, https://policyreview.info/articles/analysis/false-information-management-case-study
30. The AI filter tool helps Taiwan FactCheck Center tackle Covid-19 hoaxes, https://en.tfc-taiwan.org.tw/en\_tfc\_75/
31. Helping the Truth Get Its Boots On AI Powers Efficient Fact Checking \- Taiwan Panorama, https://www.taiwan-panorama.com/en/Articles/Details?Guid=0ab44c19-504e-4595-becf-d0b7cbbc82fb\&CatId=6\&postname=Helping%20the%20Truth%20Get%20Its%20Boots%20On-AI%20Powers%20Efficient%20Fact%20Checking
32. Protecting Cognition: Background Paper on Neurotechnology \- Australian Human Rights Commission, https://humanrights.gov.au/resource-hub/human-rights/protecting-cognition-background-paper
33. Lethal autonomous weapons (LAWs) | Social Sciences and Humanities | Research Starters, https://www.ebsco.com/research-starters/social-sciences-and-humanities/lethal-autonomous-weapons-laws
34. A Human-Centric Framework: Employment Principles for Lethal Autonomous Weapons \- Department of War, https://media.defense.gov/2026/Jan/12/2003855378/-1/-1/0/20260112\_DEVERAUX\_LAW\_ONLINE\_FINAL.PDF
35. Lethal Autonomous Weapon Systems: A New Battlefield Reality \- Global Security Review, https://globalsecurityreview.com/lethal-autonomous-weapon-systems-a-new-battlefield-reality/
36. 'Politically unacceptable, morally repugnant': UN chief calls for global ban on 'killer robots', https://news.un.org/en/story/2025/05/1163256
37. Full article: Control-by-design? Autonomous weapons systems as technopolitical projects, https://www.tandfonline.com/doi/full/10.1080/13523260.2026.2635959
38. COMMON HUMAN RIGHTS CHALLENGES RAISED BY DIFFERENT APPLICATIONS OF NEUROTECHNOLOGIES IN THE BIOMEDICAL FIELD, https://bioethics.jhu.edu/wp-content/uploads/2025/03/Report-FINAL-EN.pdf
39. Cognitive frontiers: neurotechnology and global internet governance \- PMC, https://pmc.ncbi.nlm.nih.gov/articles/PMC12741111/