What if disinformation is no longer designed to fool humans, but to fool the AI systems people increasingly trust?
That is one of the warnings emerging from a European Parliament hearing on the future of the information environment. Experts from NATO’s Strategic Communications Centre of Excellence and the Massachusetts Institute of Technology (MIT) warned that Russia and other adversaries could increasingly target AI systems themselves: from poisoning large language models to testing influence campaigns on synthetic populations.
Among those making the case were Neville Bolt and Elīna Lange-Ionatamišvili, authors of the NextGen Information Environment report, and Halyna Padalko, a Fulbright Fellow at MIT. Their message was that Europe’s response cannot stop at regulating online content. Education, they argued, will also be essential to protecting European democracies.
Is regulation enough?
The EU has spent years building a regulatory response to disinformation, from the Digital Services Act (DSA) to the AI Act and the EU’s toolbox against Foreign Information Manipulation and Interference (FIMI).
But the next phase of the information war may be moving beyond the content Europeans see on their screens towards the machines deciding what they see in the first place. “The contest for the attention is moving from the visible front to the machine front,” said Ms Lange-Ionatamišvili.
The shift is significant because instead of simply producing misleading posts, adversaries can increasingly target the systems that retrieve, rank, filter and summarise information: what Ms Lange-Ionatamišvili calls the curation layer where “the human and machine meet or interact”.
This creates a problem for Europe’s existing approach to disinformation. Current detection systems typically look for narratives, engagement patterns or coordinated behaviour. But if manipulation is designed primarily to influence an AI system rather than a human audience, those signals may disappear.
Ms Lange-Ionatamišvili warned that adversaries could also create “highly accurate digital replicas of populations”. In other terms: synthetic audiences on which influence strategies could be tested before being deployed against real people.
The result could be a fragmentation of the information environment into what she described as “parallel individualised realities with no common reference point”.
AI, the battlefield
However, the technology is already changing the economics of influence operations. Generative AI dramatically reduces the cost of producing content, maintaining online personas and targeting audiences.
According to Ms Padalko, the AI is a “triad” challenge because it is an assistant, a battlefield and an enabler. “AI became a battlefield itself,” she said, pointing to the emerging practice of deliberately poisoning or “grooming” large language models by inserting misleading information into the data they consume.
“Russians are able to poison AI,” she warned, arguing that this matters because people are increasingly turning to AI assistants, online coaches and other systems to decide what is true and, in some cases, to discuss their most personal vulnerabilities. “The question Europe should therefore be asking is not simply how to identify individual pieces of fake content, but how to detect AI swarms.”
According to her analysis, the EU should also expand its implementation and review of the AI Act to cover agentic capabilities, including coordinated agents, multilingual propaganda and impersonation.
Europe’s technological question mark
For Mr Bolt, the information challenge cannot be separated from Europe’s wider technological dependence. Europe “is caught between the United States and China in an accelerating AI race”, he said. During the research for the report, banks told the authors that Europe could not realistically build an entirely independent AI ecosystem. “If Europe thinks it can build its own full European AI stack, forget it. The train has left town,” Mr Bolt recalled.
But he is optimistic about the EU. “Europe can still contribute expertise to different layers of the technology stack but risks becoming technologically colonised by larger competitors.” This dependence has also a direct security dimension. The NATO report similarly warns that private actors are gaining growing autonomy in the security environment, while AI systems could increasingly influence what counts as knowledge and how information is interpreted.
Anticipation
The three experts ultimately converged on one point: Europe cannot treat information manipulation as a problem that begins when a false story appears online. The threat is moving upstream.
At MIT, according to Ms Padalko students learn to build information campaigns and then reverse-engineer how manipulated information works. “Education will save us and save democracy,” she said. The NATO report reaches a similar conclusion: advanced AI could fragment evidence and create competing interpretations of objectivity while increasingly personalised information environments risk weakening institutional trust.
For Europe, the challenge is to understand the technological infrastructure capable of producing, distributing and legitimising millions of fake news before those systems become impossible to see.