[Written with GPT-6 Instant, and a loooot of hand-holding. Doesn’t quite get at everything I want to get at, but an acceptable placeholder for now!]


Traditional propaganda attempts to establish a particular [linear] narrative. It connects events, people, and ideas into a story designed to lead an audience toward a specific conclusion. A leads to B, B explains C, and C becomes evidence for D. But there is another, less recognized attack surface around generative AI, one that doesn’t require a coherent story or even a specific conclusion. Instead, it relies on flooding the information environment with fragments that repeatedly associate certain people, organizations, events, and ideas. The goal is to make those associations so prevalent that they become part of the background context from which AI systems construct answers. This is associative saturation.

Imagine thousands of articles, posts, and websites repeatedly mentioning a particular institution alongside corruption, foreign influence, and secrecy. None needs to make a direct accusation or present a complete argument. Some fragments may be accurate, others misleading, and others entirely fabricated. What matters is their accumulated effect. When an AI assistant searches the web to answer a question about that institution, it encounters a dense cluster of related concepts across seemingly different sources. The repetition creates an appearance of corroboration, even when those sources are recycling the same unsupported associations. The information environment develops certain habits: particular concepts keep appearing together, and certain connections become easier to make than others.

This exploits a basic characteristic of generative AI: these systems don’t simply retrieve and repeat information. They synthesize relationships, construct explanations, and produce conclusions based on patterns in the material they encounter. They also draw on learned bundles of characteristics that tend to occur together. When associations are repeatedly reinforced in retrieved material, they can exert an outsized influence on the resulting answer. A model may connect two concepts because they frequently appear together, not because reliable evidence establishes a meaningful relationship between them. The strength of an association becomes confused with the strength of the evidence. The attacker doesn’t need to dictate the final conclusion, only strengthen the associations that make certain conclusions more likely to emerge. The model’s generative process performs the final synthesis.

This is what distinguishes associative saturation from conventional narrative warfare, although the two can work together. Traditional propaganda repeats messages to reinforce particular interpretations. Associative saturation reinforces the relationships between concepts that make those interpretations seem natural in the first place. A campaign can simultaneously push explicit narratives toward human audiences while flooding the wider information environment with loosely connected fragments. In some respects, this resembles the dynamics of QAnon, where scattered clues and loosely connected claims encouraged participants to construct their own elaborate explanations. With generative AI, the machine can perform much of that connective work, assembling apparently coherent answers from a manipulated collection of sources.

The under-recognized target here is not necessarily the human audience or even the AI assistant rendering search results, although both remain important. It is the topology of the information space itself: which concepts cluster together, which connections are repeatedly reinforced, and which explanations become easier to generate as a result. Rather than controlling a single story, associative saturation attempts to shape the underlying patterns from which many different stories can emerge. This makes it a potentially powerful complement to traditional propaganda, because the same information environment can influence both what people encounter and what AI systems subsequently tell them.

Narrative warfare attempts to control the conclusions being transmitted. Associative saturation attempts to control the space of conclusions that can be generated.


[Originally inspired by this Ben Shultz tweet, where I got to trying to elaborate more fully what it would look like to try to manipulate the model itself over and above human end-consumers.]