Modern influence operations are commonly understood as contests over information. Analysts search for false claims, persuasive narratives, coordinated messaging, and attempts to shape public belief. These approaches have produced important advances in understanding propaganda, disinformation, and social influence. Yet they share a common assumption: that the primary object of influence is what people think.
The paper argues that this assumption is incomplete. The objective of modern influence is not belief itself, but the conditions and constraints that support collective decision making. Information, narratives, rumors, propaganda, social interaction, economic signaling, and increasingly artificial intelligence are better understood not as objectives, but as mechanisms through which those conditions and constraints are modified. Their significance lies not in the messages they convey, but in how they alter the environment that supports collective decision making.
Military operations provide a useful analogy. Commanders do not shape terrain, logistics, or lines of communication because these are objectives in themselves. They shape them because together they determine which courses of action are feasible. Likewise, cognitive operations seek to modify the conditions and constraints that support collective decision making, because these determine the quality, reliability, and range of decisions available to individuals and organizations.
The decision environment
The term decision environment refers to the conditions and constraints that support collective decision making. It plays two operational roles at once: it provides the conditions and constraints that guide collective decision making, and it serves as the operational object upon which cognitive conflict is conducted. Cognitive conflict consists of competing processes that act upon the decision environment toward opposing objectives. Adversaries modify it to degrade or redirect its decision-support function; defenders modify it to maintain that function under changing conditions.
Formally, the decision environment consists of variables, their values, and constraints defined over them, which together determine the conditions under which collective decisions are formed.[1]
Definition Variables, constraints, and instantiation Constraints are parameterized conditions defined over one or more variables; a particular constraint is instantiated by assigning values to its parameters.
Variable values are obtained through observation, direct measurement, or inference. Constraints are parameterized conditions defined over one or more variables, and a particular constraint is instantiated by assigning values to its parameters.
Consider a constraint requiring evacuation decisions to be approved by the Emergency Operations Director. During a major crisis, authority may be delegated to designated local commanders. The underlying constraint — that evacuation decisions require designated approval — remains unchanged, while its instantiation changes to reflect the new decision environment.
As the environment evolves, constraints may be introduced or removed, instantiations may change, and variable values may change — collectively altering the conditions under which collective decisions are formed.
The capacity of a decision environment to support effective collective decision making is captured by its decision health. Decision health is not part of the environment, but an assessment of the extent to which it continues to support effective collective decision making under changing conditions. As decision health deteriorates, the decision space available to an organization is progressively reconfigured, reducing both the quality of available decisions and the organization’s ability to identify, coordinate, and execute them effectively.
Modifying the decision environment
Changes to the decision environment do not occur in isolation. Every modification alters the conditions under which subsequent decisions are made, and participants continually respond to those changing conditions with further decisions that may themselves modify the environment. Local modifications need not remain local; they may produce broader changes throughout the decision environment.
The objective of adversarial influence is not simply to modify the decision environment, but to modify it faster than its participants can successfully adapt it while preserving its decision-support function. Defenders continually modify the environment to preserve that function under changing conditions; adversaries continually modify it to degrade or redirect it. The outcome depends not only on the adversary’s actions, but on the participants’ ability to recognize, diagnose, coordinate, and respond.
Whether an organization holds under that pressure is not determined by the attack. Two organizations subjected to the same rumor can diverge completely — one verifies, clarifies, and adjusts; the other fragments.[2] The difference lies not in the attack, but in the participants’ ability to modify the decision environment in ways that maintain its decision-support function.
Evidence One rumor, two organizations The paper’s central comparative example: an identical adversarial action, two opposite outcomes.
In the first organization, participants verify the information, managers clarify responsibilities, trust relationships adjust, and reporting procedures are revised. Each response modifies the decision environment in ways that support subsequent decisions, allowing the organization to maintain its decision-support function. Effective collective decision making is preserved.
In the second, participants distrust one another, authority becomes ambiguous, communication deteriorates, and individuals compensate in incompatible ways. Each of those decisions further modifies the environment, progressively reducing its ability to support the decisions that follow. Effective collective decision making deteriorates.
The initial adversarial action was identical in both organizations.
Artificial intelligence and environmental modification
The theory developed to this point does not depend on artificial intelligence — the competing processes that modify the decision environment may be carried out entirely by people and organizations. Recent advances in AI alter the competition by dramatically increasing the speed, scale, persistence, and adaptivity with which the decision environment can be modified.
Traditional influence campaigns have generally relied on broadcast communication, coordinated messaging, and repeated narratives to produce broad effects. Adaptive AI systems are not constrained by these approaches. They can engage continuously with large numbers of individuals through personalized interactions that differ substantially from one participant to another while remaining aligned toward common operational objectives. Rather than persuading entire populations through common messages, AI systems can generate locally optimized interactions tailored to the circumstances of each participant.[3]
Evidence An evacuation, run at machine speed A metropolitan evacuation, first under a traditional influence campaign, then under thousands of individualized AI interactions.
Consider a major chemical accident requiring the rapid evacuation of a metropolitan area. Initially, the decision environment supports effective collective decision making: emergency management agencies coordinate, hospitals understand their responsibilities, transportation authorities implement established traffic plans, local governments communicate with one another, and citizens generally trust official guidance.
A traditional influence campaign might attempt to undermine the evacuation by broadcasting a small number of common narratives — claims that the government is concealing the true danger, or that evacuation orders are politically motivated. Such campaigns depend on repeated messages reaching large audiences, and are therefore relatively visible and, to some extent, predictable.
An adaptive AI-enabled campaign operates differently. Thousands of agents conduct individualized interactions: a resident receives convincing but false reports that the evacuation route near their neighborhood is impassable; a hospital administrator receives fabricated indications that neighboring hospitals have exhausted their capacity; a transportation official encounters seemingly credible reports of developing fuel shortages; local officials receive conflicting information about neighboring jurisdictions’ plans. None of these interactions need share a common narrative, and many may appear unrelated when viewed individually. Their significance lies in the decisions they induce — each response modifies the decision environment, and initially local changes propagate into broader degradation.
The operational advantage is therefore not that AI generates more persuasive content, but that it can modify the decision environment faster than defenders can successfully modify it while preserving its decision-support function. The result is influence that is coherent in its effects while heterogeneous in its observable expression — which makes approaches centered solely on messages, narratives, or attribution increasingly inadequate. The advantage derives not from superior messages, but from superior adaptive capacity.
Cognitive Security Operations
If the decision environment is the operational object of cognitive conflict, defending against that conflict requires an operational discipline organized around the environment itself, rather than around communications, narratives, or individual influence activities.
The paper defines Cognitive Security Operations (CSO) as that discipline. Its purpose is to preserve the decision-support function of the decision environment despite continuing adversarial modification. Rather than responding independently to rumors, propaganda, disinformation, or economic signals, CSO treats them as evidence of changes occurring within the decision environment, and evaluates them by their implications for collective decision making.
The central activities follow directly. The decision environment must be continuously monitored to detect meaningful change. Changes must be measured where possible and inferred where they cannot be observed directly. Their significance must be diagnosed in terms of effects on the environment’s decision-support function. And participants must modify the environment in ways that preserve or restore that function under changing conditions.
Decision health provides the principal measure of operational effectiveness. A healthy decision environment is not one that remains unchanged, but one whose participants successfully modify it to maintain its decision-support function despite continuing adversarial modification. Defensive success is therefore assessed not by the number of hostile messages identified or influence campaigns attributed, but by the continuing ability of the decision environment to support effective collective decision making.
The way ahead
If this perspective is correct, cognitive security requires a corresponding shift in operational focus: the central challenge is no longer managing information alone, but maintaining the decision-support function of the decision environment itself. The paper closes with the research agenda that shift demands — a foundation, deliberately, rather than a completed operational methodology.
The first challenge is to identify and operationalize the variables and constraints that characterize different classes of decision environments. Because decision environments differ across domains, organizations, and missions, their defining variables and constraints must be systematically identified, represented, and validated.
The second is practical methods for monitoring, measuring, and diagnosing decision environments: techniques for estimating variables through observation, measurement, and inference; detecting meaningful environmental change; assessing decision health; and identifying when adversarial modification is degrading the environment’s decision-support function.
The third is predictive models capable of representing how decision environments change over time — how local modifications propagate through the continuing actions of participants, and what the competing adaptive processes are likely to produce.
The fourth is operational systems that apply these concepts in practice: decision-support systems, monitoring and diagnostic tools, planning and assessment capabilities, and simulation environments that enable experimentation, training, and evaluation of defensive strategies under realistic conditions.
Finally, the theory itself must be validated — through simulation, operational experimentation, historical analysis, and real-world case studies. Only through iterative testing can the proposed concepts, models, and methods be refined into a mature operational discipline.
The objective of the paper is therefore not to conclude the development of cognitive security, but to establish a theoretical foundation upon which the next generation of research, operational methods, and decision-support technologies can be built.