EU Warned: Disinformation Is Now Targeting AI Itself

BRUSSELS — What if disinformation is no longer designed to fool humans, but to fool the AI systems that humans increasingly trust? That unsettling question was at the centre of a European Parliament hearing on the future of the information environment, where experts from NATO’s Strategic Communications Centre of Excellence and the Massachusetts Institute of Technology warned that the next phase of information warfare is shifting away from visible fake posts and toward the machines that curate, rank, and deliver information. Neville Bolt and Elīna Lange-Ionatamišvili, authors of the NATO report NextGen Information Environment, joined Halyna Padalko, a Fulbright Fellow at MIT, to argue that Russia and other adversaries could increasingly target AI systems directly. This could take the form of poisoning large language models with misleading data, manipulating the algorithms that decide what people see, or even testing influence campaigns on synthetic populations before unleashing them on real societies. Their central message to European policymakers was blunt: Europe’s response cannot stop at regulating online content. Education, media literacy, and a deeper understanding of the technological infrastructure of disinformation will be equally essential to protecting European democracies from a threat that is rapidly becoming invisible.

The European Union has spent years constructing a regulatory response to disinformation, from the Digital Services Act (DSA) to the Artificial Intelligence Act and the EU’s toolbox against Foreign Information Manipulation and Interference (FIMI). Yet the experts at the hearing argued that the next phase of the information war may be moving beyond the content Europeans see on their screens and toward the machines deciding what they see in the first place. As Lange-Ionatamišvili put it, “The contest for the attention is moving from the visible front to the machine front.” This shift is significant because instead of simply producing misleading posts, adversaries can now target the systems that retrieve, rank, filter, and summarise information — what she calls the “curation layer,” the point where “the human and machine meet or interact.” This creates a serious problem for Europe’s existing approach. Current detection systems typically look for suspicious narratives, engagement patterns, or coordinated behaviour. But if manipulation is designed primarily to influence an AI system rather than a human audience, those familiar signals may simply disappear. A poisoned recommendation engine, for example, might still recommend plausible content; it would just be content that has been invisibly steered toward an adversary’s desired outcome. That makes the manipulation far harder to detect, let alone regulate, under the current legal frameworks that focus on content rather than on the infrastructure through which content flows.

Lange-Ionatamišvili also warned that adversaries could create “highly accurate digital replicas of populations.” In other words, they could build synthetic audiences — digital twins of real societies — on which influence strategies could be tested and refined before being deployed against actual human beings. This would allow state actors to perfect their messaging, identify vulnerable demographic segments, and adjust their tactics in real time without ever revealing their hand in the real world. The consequence, she warned, could be the fragmentation of the information environment into what she described as “parallel individualised realities with no common reference point.” In such an environment, different groups would not merely disagree about facts; they would inhabit informational universes that share almost nothing in common. The traditional ideal of a public sphere, in which citizens debate on the basis of shared evidence, would collapse. This is not a distant science-fiction scenario. The necessary technologies already exist, and the rapid development of generative AI makes it easier and cheaper than ever to construct such synthetic populations and to feed them into decision-making processes, both human and automated. For European democracies, the danger is that the very concept of objective truth becomes difficult to sustain when every individual can be presented with a perfectly tailored stream of information designed to exploit their cognitive weaknesses.

The economics of influence operations have also been transformed by generative AI. Producing content, maintaining fake online personas, and targeting specific audiences once required substantial human labour and coordination. Now, AI can do much of that work at near-zero cost. Halyna Padalko described AI as a “triad” challenge, because it is simultaneously an assistant, a battlefield, and an enabler. “AI became a battlefield itself,” she said, pointing to the emerging practice of deliberately poisoning or “grooming” large language models by inserting misleading information into the data they consume. Models trained on corrupted datasets can then reproduce falsehoods as though they were established fact, and because users interact with them through conversational interfaces that appear neutral and objective, the falsehoods gain an insidious authority. “Russians are able to poison AI,” Padalko warned, arguing that this matters enormously because people are increasingly turning to AI assistants, online coaches, and other automated systems to decide what is true and, in some cases, to discuss their most personal vulnerabilities. The European Union should therefore be asking not simply how to identify individual pieces of fake content, but how to detect what she called “AI swarms” — coordinated networks of agents that can operate across languages, platforms, and jurisdictions. Padalko also urged the EU to expand the implementation and review of the AI Act to cover agentic capabilities, including coordinated agents, multilingual propaganda, and impersonation, to ensure that the regulation does not become outdated before it is fully enforced.

Europe’s ability to respond to these threats is inseparable from its broader technological position. Neville Bolt argued that Europe “is caught between the United States and China in an accelerating AI race,” and that this dependence has direct security implications. During the research for the NextGen Information Environment report, Bolt recalled, banks told the authors that Europe could not realistically build an entirely independent AI ecosystem. “If Europe thinks it can build its own full European AI stack, forget it. The train has left town,” he said. That is a sobering statement for a bloc that aspires to strategic autonomy. Yet Bolt was not entirely pessimistic. Europe can still contribute valuable expertise to different layers of the technology stack, but if it does not act quickly and strategically, it risks becoming “technologically colonised” by larger competitors. The NATO report similarly warns that private actors are gaining growing autonomy in the security environment, while AI systems could increasingly influence what counts as knowledge and how information is interpreted. If European governments do not understand and shape the technological infrastructure on which their information environments depend, they will be left relying on platforms and systems designed elsewhere, subject to the interests, laws, and manipulations of foreign powers. This does not necessarily mean building everything from scratch, but it does mean developing enough expertise and leverage to maintain some degree of control over the digital environment in which European citizens form their opinions.

The three experts ultimately converged on a single point: Europe cannot treat information manipulation as a problem that begins when a false story appears online. The threat is moving upstream, before content reaches human eyes, and the response must move upstream as well. At MIT, according to Padalko, students learn to build information campaigns and then reverse-engineer how manipulated information works. This kind of education, she insisted, is vital: “Education will save us and save democracy.” The NATO report reaches a similar conclusion, warning that advanced AI could fragment evidence and create competing interpretations of objectivity, while increasingly personalised information environments risk weakening institutional trust. If citizens cannot agree on basic facts, they cannot hold their governments accountable, and democracy itself is undermined. For Europe, the challenge is therefore not merely to police the internet but to understand and, where necessary, reshape the technological infrastructure capable of producing, distributing, and legitimising millions of fake news items before those systems become impossible to see. The window for action may be closing. The EU has already established significant legal tools, but the experts’ message is clear: regulation alone will not be enough. The next generation of disinformation will not always look like disinformation. It will look like a helpful search result, a trusted AI assistant, or a perfectly tailored news feed. By the time Europeans begin to suspect that they are being manipulated, the machines that led them there may already be out of reach.

Share.
Leave A Reply

Exit mobile version