AI Swarms pose a potentially existential threat to democracy, which is nothing if not the enactment of majoritarian politics. If we can no longer know quickly or reliably the opinions of the majorities, our democratic societies will be threatened as never before.
AI information warfare is doing much more than making propaganda cheaper. In the near future, AI-influenced swarms could give small states and small groups outsized and unprecedented power to manufacture the appearance of mass opinion at scale. However, doing so will not destroy our ability to distinguish genuine public sentiment from synthetic consensus; it will displace the entire independent media ecosystem that the advent of the internet has enabled
The result would be akin to a return of the old legacy broadcast age that largely lost its control over shaping narratives as social media and video hosting platforms displaced it. This time, however, the return to a centralised narrative that does not necessarily reflect the views of the majority will be shaped by the autonomous influence bots distributed widely across the entire decentralised web of independent media that now drive public opinion and journalists.
AI information warfare is beginning to invert the traditional relationship between size and power. A small state—or even a well-resourced non-state actor—with advanced models, compute and platform access can now build a synthetic public: thousands of persistent personas that post, argue, translate, harass, imitate local voices and adapt to events in real time. Davids do not merely gain a louder slingshot. They can begin to manufacture the appearance of Goliath.
The deeper danger is the destruction of what I call majoritarian legibility: not the claim that majorities determine truth, but the imperfect ability to see what large numbers of real people broadly think. For a brief period, the social-media and creator-media revolutions weakened the old gatekeepers. Twitter ratios, YouTube comments, view patterns, independent creators and viral dissent were never representative polling. But taken together, they provided a rough sanity check on elite narratives—and influenced the journalists, politicians and broadcasters who still shaped the wider public. It is always worth noting that majoritarianism can produce tyrannies of the majority over the minority, as Benjamin Franklin, Thomas Jefferson, and countless others have warned. Nevertheless, we agree that various forms of representative democracy represent the most moral form of government possible.
AI influence swarms can corrupt that signal at its source. They can manufacture apparent consensus, turn an 80–20 split among humans into a visible 50–50 contest, intimidate genuine users into silence, flood search and recommendation systems, and make every organic movement look potentially synthetic. The strategic objective is not merely to make people believe one lie. It is to destroy the denominator: to make it impossible to know how many voices are real, how widely an opinion is genuinely held, or whether public reaction is emerging from society at all.
This would not restore the old broadcast order. It would create something worse: decentralised media on the surface, but centralised perception management underneath. The actors best placed to exploit it will not necessarily be the largest. They will be those with sufficient compute, capable models, platform access—and the least commitment to truth.
The Importance of the Information Space
Information warfare has sometimes been treated as a supporting act to the real business of conflict, kinetic operations on the ground. This framing is understandable but increasingly outdated. In a growing number of conflicts, the contest to shape international perception matters as much as the fighting itself. Not more, but often as much.
For instance, amplifying discontent with an already unpopular war and helping it become politically unviable in domestic politics is much easier and less costly than winning a kinetic war. Moreover, battlefield victories do not automatically translate into political outcomes when the information environment has become so polluted.
Information operations have always been prioritised by states at war, but their cost, speed, scale, and sophistication have dramatically changed. For the first time, a relatively small team with endless compute can now manufacture the appearance of mass public sentiment, deploy it across every major platform at once, and do so in ways that are increasingly difficult to distinguish from organic human activity. This is not a distant prospect. The tools already exist, the early operations are already running, and the implications for how we receive information deserve far more attention than they currently receive.
The End of Majoritarian Opinion on the Internet
For most of the social media era, a working assumption has underpinned how journalists, analysts, and policymakers read the online environment: that prominence reflects something real. Not perfectly — everyone understands that algorithms reward outrage and that simple bots have always existed — but, at sufficient scale, the signal has been meaningful. If a narrative is trending or a position is widely represented across many days and demographics, it has been taken to reflect a genuine population of people who hold it.
AI is now starting to break that assumption in ways we havent seen before—going far beyond the simple & analogue foreign influence and manipulation campaigns we have seen in the past. The online sphere was never a perfect marketplace of ideas, but it at least bore some relationship to what people actually thought. That relationship is now severable. Small states, lobbyists, campaigns, non-state actors, and medium-sized powers alike can manufacture the appearance of consensus at a scale that bears no relationship to genuine support. The most accurate way to understand this is as mass data poisoning applied to public opinion: the deliberate corruption of the inputs from which we infer what people believe.
The infrastructure has been developing for years. In 2023, an international consortium of journalists coordinated by Forbidden Stories exposed a disinformation-for-hire unit operating software known as AIMS — Advanced Impact Media Solutions — capable of controlling more than 30,000 fake social media profiles across X, Facebook, LinkedIn, Instagram, Telegram, and Gmail. Each profile carried a constructed backstory, mimicked human behaviour, and was tied to verified phone numbers. The unit behind it claimed to have been covertly involved in 33 presidential-level campaigns worldwide. That was three years ago, before large language models made content generation trivial and before image-generation tools made synthetic profiles essentially undetectable. The barrier to entry has fallen dramatically since, and it continues to fall.
What does this look like in the real world?
A sophisticated influence operation today is not a crude flood of identical, poorly translated propaganda. It is layered. A base tier of accounts posts broadly appealing, apolitical content most of the time — trending clips, explainers, local colour — which builds genuine-looking audiences and establishes behavioural credibility. On the issues that matter to whoever is running the operation, those accounts then take positions, amplify allied messaging, and drown out opposition. A second tier mimics credible analytical voices: synthetic independent researchers, shell think tanks, accounts that post in measured, ostensibly objective terms but are sharply one-sided on the questions that count. A third tier is overt and aggressive — harassment accounts that make no secret of being automated but maintain a relentless presence, raising the cost of dissent. Recent experience with AI-run accounts on X has shown how much influence a non-human account can exert through volume and speed alone, even operating in plain sight.
Crucially, the accounts need not push a single line. Half might amplify left-leaning economic content while the other half amplifies right-leaning cultural content. The objective is often not to advocate a position but to inflame existing divisions, making the information environment more chaotic and more vulnerable to further manipulation. These operations rarely invent grievances. They identify real ones and apply pressure at scale.
Nor is this confined to X. A comprehensive operation spans every platform where perception is formed. Tools such as ElevenLabs and AI video generators make compelling short-form content for TikTok and Instagram Reels straightforward to produce. YouTube channels can be seeded and grown through a mix of synthetic and genuine engagement, reaching audiences who never encounter mainstream news. YouTube comment sections — an underappreciated arena that shapes both viewers and the creators responding to them — can be gamed in exactly the same way as a feed. And the synthetic activity online is increasingly reinforced offline by fake outlets with the visual polish of real publications and shell think tanks with professional websites, producing material that circulates through the legitimate information ecosystem because it looks credible enough to cite. The poisoning is not only in the feed; it is in the sources the feed points to.
The Iran Campaign
The most extensively documented recent case is unfolding in public. Since the conflict involving Iran escalated in early 2026, a pro-Iranian outfit known as Explosive Media has flooded social media with AI-generated videos — Lego-style and Pixar-like animations set to hip-hop, using satire to cast Western and Israeli leaders as warmongering, corrupt, and deeply compromised while portraying Iran as a defiant underdog leading the Global South’s resistance. The content is produced quickly enough to respond to the news cycle within hours: when a controversial statement broke from the White House, response videos were circulating the same day. This is powerful and allows propaganda to ride the news cycle, raking in earned media.
The creators initially presented themselves as independent students. They have since acknowledged that the Iranian government is among their clients. Researchers at the Oxford Internet Institute have noted that the operation is designed less to convince viewers of specific facts than to shape the ambient atmosphere of the conflict, reaching people who do not follow international news closely. Because the videos use cartoon aesthetics, they evade automated moderation that would flag real conflict footage. Because they are shareable and emotionally resonant, they spread through networks that would never engage with traditional state media. And the campaign has consistently anchored itself to genuine points of Western discontent — billionaire-class politics, institutional credibility, the Epstein affair — directing real frustration toward its preferred conclusions. This is the template: not fabricating reality, but finding the existing tensions and applying pressure at scale.
Why journalists are at risk
The danger is not only that this content exists, but that the systems through which we validate information were not built for it. A significant share of journalistic agenda-setting now runs through X. Many, if not most, journalists today monitor their feeds – especially X/Twitter – to gauge sentiment, assess the temperature of debates, and even sometimes absorb the framing of large commentators, especially if the reactions to these posts seem overwhelmingly positive and in agreement. This is both a conscious and subconscious process for most users, not just journalists. Journalists are not careless — X/Twitter has long been a strong source of live, minute-by-minute updates that are often 10-30 minutes ahead of media reporting during major events. It also reflects the genuine role the platform has played in public discourse over the past two decades. But if the conversation has now been co-opted and shaped by coordinated synthetic activity, then what journalists are reading is not public opinion. It is a manufactured impression of public opinion. The resulting stories enter mainstream publications with real editorial credibility, and the synthetic framing is laundered into the legitimate information bloodstream.
This is not a charge of naivety. Journalists are, on the whole, capable and aware that social media is imperfect. But awareness is not immunity. Sustained exposure to content shapes perception, even content one consciously discounts — that is simply how perception works. Synthetic activity does not have to persuade anyone of anything specific to tilt the frame. It only has to be present, consistently, over time.
What Comes Next
None of this is limited to the actors named here, and the incentives apply broadly — to any government seeking to shape the narrative around its conduct, to any actor with an agenda and a technical team. Several democracies, including Sweden, already operate government units that monitor their international reputation online. That is legitimate situational awareness. The point is that AI has dramatically narrowed the distance between monitoring the information environment and manufacturing it.
What we are seeing now — the Lego videos, the AIMS-style networks, the shell think tanks — is early experimentation. The tools will improve and the operations will become harder to detect. Within the next 12 to 24 months, it is reasonable to expect coordinated influence operations running at a scale and sophistication that makes today’s examples look primitive. States are already studying how effectively recent campaigns shaped English-language discourse, and they will draw the obvious lessons.
The technical countermeasures are real and worth a discussion of their own, which I will take up separately. But the most urgent change is not technical. It is in how we treat what we see online. Social media discourse needs to be approached as a primary source requiring verification, not as a readout of public sentiment, held to the same scepticism as a government press release or a corporate statement. Newsrooms should invest in the open-source and forensic capacity needed to assess whether a trend is organic, and should set explicit editorial standards for when online activity is used as evidence of public opinion. The information environment is the contested terrain of twenty-first century conflict. The question is whether the institutions meant to help us make sense of it are adapting quickly enough to operate within it. At present, they are not.
By: Broderick James McDonald
About the author: Broderick James McDonald is the CEO of Safeguard AI and a behavioural scientist at the University of Oxford and The Alan Turing Institute.
For media inquiries, please send an email to: contact@broderick.email

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.