Markus Neuvonen, Senior MIL/DIL specialist at FaktaBaari, reflects on an expert event held in Helsinki in October 2024, organized by Faktabaari as part of the EU-CERV funded project Immune 2 Infodemic 2. The room brought together governments, media professionals, security agencies and academics with a single urgent purpose: to build a shared understanding of AI-enhanced disinformation and to find ways to cooperate across sectors before the damage becomes too deep. The conversations that day were not abstract. They were framed by complaints about the information environment, by disturbing examples from recent elections, and by anxiety about what comes next. Artificial intelligence has moved from science fiction into the daily machinery of communication, and it is now used not only to share ideas but also to systematically distort them. It was clear from the start that the problem must be approached from three perspectives at once: security, media and democracy. Security asks who is attacking whom, media asks what is being published and why, and democracy asks what kind of public conversation we want to protect. This article brings together the main risks and challenges identified during the event, with the hope that naming the problem clearly is a first step toward solving it. Six areas emerged as particularly pressing: weakening trust in institutions, hyper-targeted disinformation, unaccountable technology governance, fragile media literacy, regulatory gaps, and the broader question of cognitive security. Read together, they reveal something deeper than the threat of one manipulated video or one fake news article. They point to a systemic disturbance in the ways people learn, trust and decide. The issue is democratic resilience, not merely information accuracy. If the foundational shared facts of a society are undermined, then deliberation, compromise and peaceful change all become far more difficult.
The first and most dangerous area is the degradation of trust in institutions and in information itself. AI allows disinformation to be produced and distributed at such low cost and such enormous scale that a single small team, or even an individual, can generate volumes of misleading content that once required a state-funded propaganda apparatus. This flood of falsehoods feeds polarization and makes citizens cynical about everything, including truthful reporting, scientific evidence and government communications. It is not limited to politics. Consumers are targeted by fake reviews and scam campaigns; companies are harmed by coordinated reputation attacks; financial markets are vulnerable to deliberate manipulation. The same tools also enable hyper-targeted disinformation. Rather than broadcasting one generalized lie, an AI system can analyze large amounts of personal data, divide audiences by their fears and desires, and send highly personalized messages into their feeds. The result is a kind of cognitive micro-targeting that feels almost intuitive to the recipient, as if the message was written directly for them. Deepfakes are now common in fraud and political blackmail, and AI-generated “experts” and influencers blur the line between genuine authority and synthetic fabrication. These virtual personalities can attract followers, spread political opinions and sell products without anyone knowing who created them. For large language models, the concern is even deeper because their training data can be corrupted. If malicious actors poison the corpora used to teach these models, every later answer may reflect that pollution. This is a new type of attack on knowledge itself, because it attacks the tools many people use to discover facts. It also creates a troubling asymmetry: the manipulators can work faster than the defenders, and every improvement in AI makes the next generation of disinformation harder to identify with the naked eye.
A second set of issues concerns digital power and corporate ethics. The technology companies that control the major online platforms are influential actors in every democratic society, yet their decision-making remains largely opaque and their reach is global. This makes them nearly impossible for any individual government to regulate effectively. During election periods, these companies can amplify hyper-targeting in ways that distort public debate, and they have often failed to provide meaningful transparency about who buys political ads or how algorithms prioritize content. Even more concerning, some platforms have cooperated with undemocratic regimes, enabling surveillance, silencing critics and collecting data without meaningful consent. All of this creates a fundamental challenge: the same infrastructure that allows people to connect, share news and organize for justice can also be used to manipulate, deceive and control. Corporate ethics have not kept pace with this power. The algorithms that decide what we see are optimized for engagement, not for truthfulness. They tend to reward anger and novelty, which are often the very characteristics that make disinformation successful. Existing laws were written before these technologies became so powerful, and they lack both teeth and reach. Citizens are rarely told when they are being profiled or how their data is used to infer political preferences. The business model of surveillance-based advertising gives technology companies a financial incentive to know users as deeply as possible, and the same knowledge can be weaponized by political operatives. As the Helsinki conversations underscored, voluntary self-regulation is not enough. We need stronger pressure on platforms to disclose their systems, an international consensus on acceptable behavior, and a clear recognition that digital power must be accompanied by democratic accountability.
The fourth area offers a more hopeful route: media and information literacy. The protection of democracy cannot rely only on censorship or fact-checking after the damage is done. It also depends on helping people think clearly in an uncertain information environment. Media literacy education must begin early and continue throughout life, reaching older adults, parents, and communities that are often overlooked. It should teach not only how to identify obvious fake news, but also how to question sources, how to understand algorithms, how to recognize manipulation techniques, and how to cope with the fact that some content is simply ambiguous. Countries like Norway and Estonia have developed strong models for integrating digital literacy into their education systems, treating it as a basic skill rather than an optional extra. Finland, too, has invested in cross-sector collaboration between education, media and civil society. The Faktabaari Digital Information Literacy (DIL) model offers a useful framework, bringing research-based knowledge into practical tools and classroom exercises. None of this is a miracle cure. In a world of synthetic media, even educated citizens will sometimes be deceived. But resilience is a social capacity that is built through repeated practice. A population that is used to asking questions is far harder to manipulate than one that expects to receive truth from authorities without any effort. This kind of literacy also helps people tolerate uncertainty and resist the emotional pull of simple explanations. It changes the relationship between citizens and the media, turning passive consumers into active interpreters. It also gives people more confidence in their own judgment, which is an important shield against fear and despair. In the long run, this may be the most sustainable defense we have against AI-enhanced disinformation. It does not require waiting for new laws or new filters; it can begin in every classroom, every library and every family conversation.
Policy makers, meanwhile, have no time to waste. The fifth theme from the event was the urgent need for proactive, human-centric regulation, especially at the European level. The EU has already taken important steps, including the Digital Services Act and the new AI Act, but regulation often lags behind the technology it tries to govern. By the time a rule is formally adopted, the landscape has changed. The Helsinki discussions made clear that regulators need to anticipate not only current applications of AI but also the next generations, which are likely to be even more powerful and harder to trace. Regulation should be based on broad principles—human dignity, transparency, accountability, non-discrimination—rather than brittle definitions of particular technologies. It must also address deliberate misuse. Too many new tools are designed without safeguards, and the same software that can be used to edit videos for journalism can be used to create devastatingly convincing deepfakes. No one is proposing to ban innovation, but there must be clear rules of responsibility. High-risk AI systems should be assessed before they enter the market, synthetic content should be labelled, and platforms should have real obligations to prevent large-scale automated manipulation. International cooperation is essential, because disinformation campaigns cross borders effortlessly. A single European regulator cannot solve a problem that originates on servers in other continents. The aim should be a global baseline of norms and standards, supported by institutions and enforcement mechanisms. This is not a simple task, but the alternative is a permanent vulnerability, a sense among citizens that no one is in charge of the digital environment. Regulation also has an important signaling function. When governments take these dangers seriously, they encourage responsible behavior from companies and help ordinary people recognize that their concerns are legitimate.
Underlying all of these concerns is cognitive security, the quiet protection of the human mind from exploitation. AI is not simply filling the information environment with lies; it is reshaping the environment in ways that make thoughtful, independent reasoning difficult. Information overload exhausts people. They retreat into emotional shorthand, tribal heuristics and confirmation bias. When the same person is bombarded with contradictory headlines, scientific warnings, propaganda and targeted ads, the natural reaction is to disengage or to fall back on the loudest voice. This is exactly what disinformation campaigns want. The goal of many manipulators is not only to make people believe a specific falsehood; it is to make people distrust everything so strongly that they no longer know whom to believe. Once that happens, shared reality begins to split. Different communities inhabit different facts, and political compromise becomes impossible because the sides cannot even agree on what is true. Protecting cognitive security therefore means protecting the preconditions of democracy: the ability of citizens to reason, to test information, to engage in public debate and to make free choices. It requires policy measures, such as restricting data-driven manipulation and demanding transparent advertising, but it also requires cultural change. We need to build social norms around information that discourage careless sharing and reward careful verification. We need to value intellectual humility and open-mindedness. And we need to treat cognitive security as a public good, just as we treat physical safety or clean water. This is the deeper message of the Helsinki event. The challenge of AI-enhanced disinformation is not only a technological one. It is a test of whether democratic societies can defend the minds of their citizens against a new generation of automated persuasion. The first answers are becoming visible in cross-sector cooperation, stronger legal frameworks and a growing focus on media literacy. But the window of opportunity is narrow. We need to act now, collectively and decisively, to build digital immune systems that protect truth, trust and democracy for generations to come.

