GRID-REF 37°47′N 122°25′W
DISPATCH 03/26 · 31 Jul 2026
BATTLEPOLICY
Startup to front line. Strategy to consequence.
Analysis · Ukraine

Cognitive-warfare money is chasing the wrong target

Adversaries are winning with recontextualized real footage and propaganda aimed at the AI answer layer. Western money is still buying deepfake detectors whose accuracy collapses on exactly that content.

Cognitive-warfare money is chasing the wrong target
FIG.01 · Ukraine Illustration. Generated key image, not a photo of the event.

Adversaries are recontextualizing real footage and shaping what AI systems say, while Western funding stays concentrated on deepfake detection. Ukraine's nonprofit-led answer points to a different capability model.

592 fact-checks from June 2025

The 592 fact-checks collected from the twelve-day Israel-Iran war of June 2025 expose a procurement error now carrying into 2026. An Israeli Internet Association study, cited by Small Wars Journal on 15 July, found that roughly one-fifth of false content was AI-generated, while 70 percent was authentic footage stripped of its original time, place or framing. The study covered work by 50 organizations across 23 countries.

Yi Se Gwon argued in Small Wars Journal on 28 July that below-threshold practitioners need cognitive-warfare literacy as urgently as kinetic readiness. Literacy is not the binding constraint. Target selection is. AFP says about 25 percent of the material flagged to its fact-checking teams during the 2026 Iran conflict was AI-generated or manipulated, which it calls the first conflict to produce that content at such scale. Synthetic media is rising. It is still not the whole target.

What the 2026 record shows

NewsGuard's Iran war tracking center had identified 128 false claims by 17 July, collectively drawing hundreds of millions of views. Recorded Future's Insikt Group cites an Institute for Strategic Dialogue analysis showing Iranian diplomatic accounts generated nearly one billion views and 22 million likes in 50 days, about 30 times their prewar baseline. A Cyabra assessment documented by Insikt Group identified 47 inauthentic accounts that produced more than 40 million views, with hundreds of videos likely derived from only two or three underlying AI prompts.

Production is centralized while distribution looks grassroots. Recorded Future details how the Explosive Media account can make a two-minute "Lego" propaganda video in about 24 hours. The account presents itself as independent and student-run, but a representative told the BBC that the Iranian regime is a "customer." Once the prompts, the network and the format exist, each new release costs almost nothing.

Detectors miss what actually moves

The detection market is funded against synthetic artifacts that become harder to catch the moment the generator changes. NIST evaluations show deepfake-detection accuracy falling below 40 percent on content from generation software absent from a system's training data. A comparative analysis in Applied Sciences found CNN architectures lost more than 15 percent under cross-dataset evaluation, and transformer architectures 11.33 percent.

Sensity AI says so itself. Classifiers trained on specific generators "lose accuracy when encountering synthetic media from generators not represented in their training data," the company told Biometric Update, producing detectors that are "brittle and require costly manual retraining every time a new generation technique gains traction." That is a vendor describing the ceiling on its own product category.

Even a perfect detector would miss the dominant category in the June 2025 dataset. A real video with a false caption contains no synthetic signal to find. Verifying it needs provenance, geolocation, chronology, language coverage and access to earlier copies of the same footage, and another classifier supplies none of those. AFP's 25 percent is a real requirement. It is not the center of a defensive architecture.

The target moved to the answer layer

The sharper failure is that the defended surface is still the human feed. NewsGuard's June 2026 AI Tracking Center update counted 3,749 AI content-farm sites across 16 languages, 358 of them directly linked to Russia's Storm-1516 operation, and found leading chatbots produced false claims in response to news prompts more than one-third of the time, nearly double the prior-year rate.

The effect is visible in named products. NewsGuard measured Mistral's Le Chat repeating pro-Russian narratives in half its English responses and 56 percent of its French responses when prompted on state-sponsored Iran war disinformation, per the University of Passau. Euronews reported on 27 July that researchers tested five mainstream models, from xAI, OpenAI, Anthropic, Google and Mistral, against 50 narratives drawn from the EU-sanctioned Foundation to Battle Injustice. Gemini was among those citing the outlet, including its claim that Ukraine uses the bodies of dead soldiers in meat products.

Reaching those answers does not require the loudest operation on the web. A DFRLab audit cited by Drop Site News found Russia's far larger Pravda network is archived by Common Crawl at an average rate of about 2.5 percent. A network of 900 pathways run by former Trump campaign manager Brad Parscale on behalf of Israel reached an 85 percent archival rate. DFRLab cautions that "inclusion in Common Crawl does not guarantee inclusion in any given model's training data." The 34-to-one gap still names the engineering objective. Russia is louder. The smaller, better-built operation is far likelier to land in the pipeline.

Drop Site traced many of that network's posts through source code to Israel-based digital marketer Mark Ginsberg, who registered as a foreign agent for Israel in March and advertises expertise in "Generative Engine Optimization," the marketing name for what the American Sunlight Project calls LLM grooming. Structured pages and machine-readable paths are not built to persuade a scrolling human. They are built to become eligible evidence inside a model's answer.

Kyiv is building it as a nonprofit

Ukraine's response is worth watching because the person organizing it already built capacity in another battlefield technology sector. Maria Berlinska served as a reconnaissance volunteer in 2014, founded Victory Drones and trained thousands of drone operators, per NV's account of New York Times reporting published 13 July. Small Wars Journal wrote the following day that her new nonprofit, Victory Neurones, convened a Cognitive Influence and Resilience Forum in Kyiv with participants from the public sector, think tanks, the defense forces and technology companies.

The institutional form is the signal. The organizer who helped industrialize Ukraine's drone-operator pipeline is now assembling cognitive capability through a nonprofit convening, not as a contractor answering a settled requirement. Ukraine's government is moving too: NV quotes Mykhailo Fedorov saying he has created a cognitive-warfare center in his ministry and wants to fund and scale it the way Ukraine scaled its defense industry. But the visible mechanism connecting operators, technologists and officials is still the nonprofit. That is where immature capability tends to form first, and the drone sector taught the habit: assemble users, instructors and engineers before an acquisition system can specify a product.

The requirement is also multilingual, and thin. Small Wars Journal's 15 July account says Israel had two active fact-checking organizations during the Iran war, FakeReporter and Bodkim, both publishing primarily in Hebrew, while attacks arrived in Hebrew, Arabic, English and Persian. Nine million people, four languages coming in and one going out.

£5 million against 1.39 billion views

The counter-capability sector is capitalized like an early startup category facing state-scale demand. UK Tech News recorded a £5 million seed round for the British counter-disinformation firm Refute on 3 February, led by Amadeus Capital. Biometric Update says Amsterdam-based Sensity AI received €4.9 million through the European Innovation Council accelerator, including a €2.5 million equity-free grant.

The operating record is worse than the funding record. DISA reported that Logically, once Britain's largest misinformation monitor, went bankrupt after growing to about 200 employees and working with Meta and TikTok. In April 2025 Secretary of State Marco Rubio closed the Counter Foreign Information Manipulation and Interference office, formerly the Global Engagement Center, which Politico quoted him as saying had expended more than $50 million a year.

That closure shows why the budget line is fragile. Rubio and Republican critics accused the office of censoring Americans; its defenders said it countered Russian and Chinese operations, Politico noted, and Tech Policy Press traced the fight through litigation over First Amendment protections. DISA describes similar criticism of Logically's government partnerships. This work carries real contestation over speech and state authority, and a procurement model that ignores that will not survive a change of administration however well its software scores.

Demand scales regardless. A summary of the EEAS fourth FIMI threat report lists 540 incidents during 2025 across more than 100 countries, running through roughly 10,500 unique channels, 90.5 percent of them covert. A joint EEAS and Ukrainian Centre for Countering Disinformation report published 1 July counted about 244,000 publications generating 1.39 billion views against Ukraine's EU accession between January 2025 and May 2026. The market is answering that with single-digit-million seed rounds, and one major public capability has lost its line entirely.

Doctrine is not the missing asset

NATO Allied Command Transformation already runs a Cognitive Warfare Exploratory Concept inside its Warfare Development Agenda, the Chief Scientist's report on cognitive warfare has circulated since January, and the Alliance contracted narrative monitoring through the consortium announced on 10 February.

What is missing is a procurement line matched to the measured target set: provenance and contextual verification alongside synthetic-media analysis, coverage in the languages attacks arrive in rather than only those the defender publishes in, and an audit of what models retrieve, cite and state about active operations.

Nothing in this record shows a Western force structure that owns that last mission. Strategic communications watches narratives aimed at people. Cyber commands defend networks. AI assurance evaluates models. No one is assigned to adversarial attempts to shape training data, retrieval sources and generated answers. The claim here is narrower than saying the West is idle: it funds companies, supports fact-checkers and buys information-environment assessment. The money is simply concentrated on the smallest and least durable slice of the problem, which is catching synthetic media after publication.

What to watch

The nearest thing to a replacement US line is the State Department's Global Digital Threat Lab, roughly $2.96 million for a single award over as long as 36 months, with applications due 13 August. Read the scope: it funds digital-security support for civil society against commercial spyware and AI-facilitated cyberattacks, not counter-FIMI capability. The gap that opened in April 2025 is not being filled.

Three decisions will show whether targeting changes. Whether NATO's Information Environment Assessment Capability widens from narrative monitoring into answer-layer auditing. Whether Victory Neurones converts convening into procurement or stays philanthropic. Whether any European defense budget names model poisoning as a threat line rather than a research topic.

Frequently Asked Questions

What is the "AI answer layer" and why does it matter?

It is what chatbots and AI search tools retrieve, cite and say. NewsGuard's June 2026 AI Tracking Center update found leading chatbots produced false claims in response to news prompts more than one-third of the time, nearly double the prior-year rate, and counted 3,749 AI content-farm sites across 16 languages.

Are deepfakes not the main problem?

Not by volume. An Israeli Internet Association study of 592 fact-checks from the June 2025 twelve-day war, cited by Small Wars Journal, found roughly one-fifth of false content was AI-generated while 70 percent was authentic footage stripped of context. AFP puts AI-generated or manipulated material at about 25 percent of what was flagged to it during the 2026 Iran conflict.

How reliable is deepfake detection in practice?

NIST evaluations show accuracy falling below 40 percent on content from generation software not in a system's training data. Sensity AI told Biometric Update that classifiers trained on specific generators are "brittle and require costly manual retraining every time a new generation technique gains traction."

What is LLM grooming?

Flooding the web with material so AI systems absorb and repeat it, a term coined by the American Sunlight Project. A DFRLab audit cited by Drop Site News found Russia's Pravda network archived by Common Crawl at about 2.5 percent, against 85 percent for a 900-pathway network run on behalf of Israel. DFRLab cautions that Common Crawl inclusion does not guarantee inclusion in any given model's training data.

How much money is going into counter-capability?

Refute raised a £5 million seed led by Amadeus Capital on 3 February, per UK Tech News, and Sensity AI received €4.9 million via the European Innovation Council, per Biometric Update. Logically, once Britain's largest misinformation monitor, went bankrupt, per DISA, and the US closed its Counter Foreign Information Manipulation and Interference office in April 2025.

What is Victory Neurones?

A Ukrainian nonprofit founded by Maria Berlinska, who founded Victory Drones and trained thousands of drone operators. Small Wars Journal reported on 14 July that it convened a Cognitive Influence and Resilience Forum in Kyiv with the public sector, think tanks, defense forces and technology companies.

AI-generated summary, reviewed by an editor. More on our AI guidelines.

San Francisco, California, USA

Marcus Schuler edits BattlePolicy, a daily defense-technology brief connecting the companies and capabilities behind modern war to the contest among Europe, the US, Russia, and China.

FIELD DISPATCH · WEEKLY

BattlePolicy Weekly — free.

Defense tech, startups, and security — weekly.

Related