This is my very first post on EA forum, but I have been thinking about this topic for over 10 years, back when I was doing third party security risk management at Facebook in 2016 , during US presidential election time.
A decade later, what I feared the most is already transpiring, supposedly in “test environments”, Iran, China and private firms in Israel tested AIs to run autonomous influence campaigns. The very same week, Treasury Secretary Bessent suggests creating an early warning system for AI incidents.
The signal I receive from this is that federal agencies recognize that coordination on AI driven epistemic attack is essential.
From the Cambridge Analytica carrying out Cyber Political Engineering to now, I have been tracking the problem and believe that we need a comprehensive framework , that has policies and toolkits as well as solutions that help create resilient information channels. While I don’t have all the answers, but one I deeply believe in is protecting Critical Cognitive Infrastructure ( CCI ).
CCI : https://xrsi.org/publication/critical-cognitive-infrastructure
we need to protect our ability to make critical decisions , especially when it matters the most. We need to prepare for the time, today.
What I believe we need: research connecting CCI outcomes to safety governance, practitioners willing to build certifiable standards, federal policy with cross-agency buy-in, and funding to operationalize it.
I welcome any criticism and feedback to the positioning paper I put together here : https://xrsi.org/publication/critical-cognitive-infrastructure
( thank you for your kindness and patience and any perspective you might care to share. After a decade, I feel empowered to share this publicly and feel it might actually help with some of the challenges we might be about to face)
I think the central idea of treating critical cognitive infrastructure as something that can be protected and made resilient is genuinely worth developing further.
One direction I would especially encourage you to pursue is the operationalisation you mention in the post. The positioning paper gives us concepts such as degradation, resilience and criticality, but the next really interesting step, to me, would be asking: what observations would tell us that a piece of cognitive infrastructure is actually degrading?
There is a recent paper by Emilio Ferrara ( MDPI), The Generative AI Paradox, that seems to be moving in a similar direction on epistemic security. He proposes candidate measures such as authenticity coverage, correction latency, manipulation susceptibility, verification load and attribution stability.
I don’t think those measures map one-to-one onto CCI, but they strike me as a useful example of how a broad epistemic-security concept can begin to become empirically tractable. CCI could perhaps go a step further and ask which variables specifically indicate degradation of a critical information channel, what counts as recovery, and at what point ordinary informational noise becomes a genuine CCI incident. Once those variables are defined, you could begin comparing systems, testing interventions and eventually deriving the kind of certifiable resilience standards you mention.
So I hope you keep developing this. It strikes me less as a finished framework than as the beginning of a potentially valuable research programme (and I mean that positively).
There seems to be quite a lot of interesting work still hiding inside the idea.