What if disinformation is no longer designed to fool humans, but to fool the AI systems people increasingly trust? It is an unsettling thought: the lies we worry about online may not be aimed at us at all. Instead, they could be aimed at the algorithms that decide what we see, what we believe, and which voices deserve our attention. This was one of the warnings to emerge from a European Parliament hearing on the future of the information environment, where experts from NATO’s Strategic Communications Centre of Excellence and the Massachusetts Institute of Technology gathered to rethink an old problem. Neville Bolt and Elīna Lange-Ionatamišvili, authors of the NextGen Information Environment report, along with Halyna Padalko, a Fulbright Fellow at MIT, told lawmakers that Europe’s response cannot stop at regulating online content. Education, they insisted, will be just as essential to protecting open societies. The nature of the attack is changing. “The contest for attention is moving from the visible front to the machine front,” said Ms Lange-Ionatamišvili. That single sentence captures a shift that many regulators have not fully absorbed: the battlefield is no longer just our social media feeds, but the recommendation engines, search algorithms and AI assistants that stand between us and the world. For years, disinformation was a matter of false posts, manipulated videos, misleading headlines. These things are still with us, but a growing worry is deeper: if someone can quietly bend the systems that decide what counts as true, they do not need to persuade every citizen. They only need to reshape the information landscape that citizens rely on. That is why the experts’ warning matters far beyond the hearing room. It suggests that Europe’s carefully built regulatory machinery may be aiming at the wrong target.
The European Union has spent years building a regulatory arsenal against disinformation. The Digital Services Act, the AI Act, and the EU’s toolbox against Foreign Information Manipulation and Interference are serious instruments, designed to make platforms accountable, to subject high-risk AI to transparency requirements, and to coordinate responses to foreign interference. But the next phase of the information war may be moving beyond the content Europeans see on their screens toward the machines deciding what they see in the first place. Ms Lange-Ionatamišvili called this the curation layer, “where the human and machine meet or interact.” This is the plumbing of the digital public square: retrieval, ranking, filtering, summarisation. If adversaries target that layer, they are not just spreading lies; they are quietly reprogramming the conditions under which truth is possible. And here is why existing tools stumble: current detection systems typically look for narratives, engagement patterns or coordinated behaviour. They are built to catch armies of fake accounts and coordinated hashtag campaigns. But if manipulation is designed primarily to influence an AI system rather than a human audience, those signals may disappear. There may be no inflammatory post, no bot army, no obvious pattern of sharing—just a slow, invisible adjustment to the data and parameters that shape what millions of people will eventually encounter. The warning becomes even more disturbing with synthetic populations. Adversaries could create highly accurate digital replicas of populations, essentially simulated public opinion, on which influence strategies can be tested before being deployed against real people. Why gamble on a campaign when you can run thousands of simulations first? The result, Ms Lange-Ionatamišvili warned, could be a fragmentation of the information environment into what she called”parallel individualised realities with no common reference point.” A society that cannot agree on basic facts is already halfway to losing its capacity for democratic self-government.
All of this is made possible, and more urgent, by the changing economics of influence operations. Generative AI dramatically reduces the cost of producing content, maintaining online personas and targeting audiences. What once required a troll farm now requires a prompt. Ms Padalko described AI as a”triad” challenge: it is an assistant, a battlefield and an enabler. It helps people do things faster; it becomes a space where attacks unfold; and it empowers malicious actors with capabilities that were once reserved for wealthy states. Perhaps most alarmingly, she warned, “Russians are able to poison AI.” What does that mean? Large language models learn from enormous datasets scraped from the internet. If adversaries deliberately insert misleading information into the data those systems consume, themodels themselves can be”groomed” to nudge users toward particular conclusions. This matters because people are increasingly turning to AI assistants, online coaches and other systems to decide what is true—and in some cases, to discuss their most personal vulnerabilities. If an AI has been quietly poisoned, it can offer not just biased answers but tailored, seemingly empathetic advice that steers a person in a dangerous direction. Ms Padalko argued that Europe should not be asking only how to identify individual pieces of fake content, but how to detect what she called”AI swarms”—coordinated networks of machine-generated influence that cannot be understood one post at a time. To respond, she said, the EU should expand its implementation and review of the AI Act to cover agentic capabilities, including coordinated agents, multilingual propaganda and impersonation. In other words, the legal framework cannot just look at the model sitting in a server room; it must look at what the model is empowered to do across the information ecosystem
Behind this technical advice lies a deeper geopolitical anxiety. For Neville Bolt, Europe’s information challenge cannot be separated from its wider technological dependence. Europe, he said,”is caught between the United States and China in an accelerating AI race.” The two superpowers are investing at a scale that few European nations can match. During research for the NextGen report, the authors spoke with banks that delivered a blunt verdict: Europe could not realistically build an entirely independent AI ecosystem. “If Europe thinks it can build its own full European AI stack, forget it. The train has left town,” Mr Bolt recalled. That is a hard truth for a continent that likes to think of itself as a regulatory superpower. Yet Mr Bolt was not entirely pessimistic. Europe can still contribute expertise to different layers of the technology stack—specialised chips, algorithms, applications, standards—but it risks becoming, in his words,”technologically colonised by larger competitors.” This is not merely an economic concern. It is a security concern. The NATO report similarly warns that private actors are gaining growing autonomy in the security environment. Companies that control AI infrastructure increasingly make decisions with enormous public consequences, without a democratic mandate. Meanwhile, AI systems could increasingly influence what counts as knowledge and how information is interpreted. If themachines that mediate our understanding of the world are owned and shapedby powers far away, then Europe’s ability to defend its democracies depends on something it does not fully control. Regulation alone cannot solve that asymmetry. It requires investment, alliances, scientific capacity—and a clear-eyed recognition that technological sovereignty ist not a slogan but a precondition for informational self-determination
What, then, is to be done? The three experts converged on a single point: Europe cannot treat information manipulation as a problem that begins when a false story appears online. The threat is moving upstream. By the time a lie is visible to human eyes, themachinery of amplification has already done its work. Anticipation, not reaction, is the only viable posture. At MIT, according to Ms Padalko, students learn to build information campaigns and then reverse-engineer how manipulated information works. They do not read about disinformation in the abstract; they learn how to construct a narrative, target an audience, exploit algorithmic vulnerabilities—and then they learn how to dismantle such operations. This hands-on fluency is what she means by education. “Education will save us and save democracy,” she said. That seems almost old-fashioned in an era of dazzling technology, but it is profoundly practical. A population that understands how persuasion works is far harder to manipulate than one that simply consumes content. And the NATO report reaches a similar conclusion from a different angle: advanced AI could fragment evidence and create competing interpretations of objectivity, while increasingly personalised information environments risk weakening institutional trust. If people cannot agree on what counts as evidence, democracy cannot function. Therefore, education is not just a complement to regulation; it is the foundation on which regulation must stand
For Europe, there is both a warning and a spur in all of this. The challenge is to understand the technological infrastructure capable of producing, distributing and legitimising millions of fake news before those systems become impossible to see. That requires new forms of vigilance: monitoring not only content but the conditions under which content is created, ranked, filtered and summarised; investing in AI literacy at every level of society; building alliances with democracies that share the same values; and ensuring that the rules written today are flexible enough to meet threats that have not yet been named. It also requires humility. No law, no algorithm, no fact-checking desk can fully protect a society that has stopped paying attention to how its own attention is shaped. The experts at the hearing were not offering easy answers. They were asking Europeans to wake up to a strange new reality: the information war is no longer simply about what appears on our screens. It is about who and what determines the screen itself. If democracy is to survive the age of intelligent machines, its defenders must learn to see the invisible architecture of belief—and teach the next generation to question it boldly. In that sense, the fight against disinformation is not ultimately a technical problem. It is a civic one, and it will be won not in server rooms alone, but in classrooms, newsrooms, parliaments, and the quiet habits of mind that make free societies possible.

