Sensity AI Logo
Threat Intelligence

Cognitive Warfare is Now Global, Digital, and Persistent

Francesco Cavalli - Co-Founder & COO
21 August 2026

In the 21st century, conflicts are no longer confined to specific regions, borders, or even timelines. Content platforms have become the new battlefields. Viral posts are the new shells, applying constant pressure on target populations. Cognitive warfare operates below the threshold of traditional conflict. It has no peace treaties. In fact, many states turn a Nelsonian eye in order to uphold the status of ‘implausible deniability’ regarding their own actions. It is a low-intensity, continuous campaign made up of a relentless psychological assault on the minds of populations, all aimed at eroding trust in institutions, authorities, allies, and political organizations.

It’s long been said that geography is the most unchanging factor in strategy, but the last 24 months have shown that nation states can, and will, exert their influence further afield through digital means, and that hybrid threats are accelerated by globalization and technological advancement. In the information domain, geography is of no importance.

As we reveal in our report, The Role of Deepfakes in Cognitive Warfare, the Russia–Ukraine war is not simply a conflict where deepfakes appear as isolated organic disinformation. It is the first large-scale scenario where synthetic media can be observed being used as a programmable and repeatable component of hybrid warfare.
This conflict is a paradigmatic example which reveals a structural template for cognitive warfare that can be reproduced by anyone across contemporary and future crises, regardless of geography or ideology.



Key Deepfake Threat Vectors in Cognitive Warfare

This new era of cognitive warfare has been ushered in by the democratization of synthetic media and the ability to systematically forge compelling deepfakes, along with a rapid decrease in the cost and effort required to do so. This allows actors, both state-sponsored and non-state, to achieve a high level of sophistication in cognitive attacks, and accelerates their adoption for future
conflicts.

Access to accurate and reliable information is key for intelligence analysts, and their exposure to sophisticated deepfake campaigns poses a threat to their credibility. When front-line troops, or the Ukrainian or Western public perceive a vulnerability to manipulated content, the agency’s influence, and by extension, the state’s, is undermined. So, this potential impact on local and global trust underlines the importance of developing robust strategies for detecting and addressing deepfake threats within the intelligence community.

As we have established, these modern national security threats increasingly operate below the threshold of traditional conflict. Under the ‘AI fog of war’, influence campaigns, psyops, and synthetic propaganda are deployed at scale to distort perception, erode trust, and destabilize decision-making—often in real time. Cognitive warfare is now a clear and present danger.

Observed Deepfake Threat Vectors

AI Face Swap
Replaces a face in a photo or video with another face, creating the appearance that the target individual performed the actions or expressions of the source. In the observed examples we see Russian ‘actors’ faceswapped onto Ukrainian soldiers.

AI Generated Video
AI-generated human faces created by Generative Adversarial Networks, producing photorealistic identities that do not correspond to any real person. In the observed examples we see synthesized identities of Ukrainian soldiers, or even synthetic
members of the Ukrainian public being interviewed.

Synthetic Voice
AI-generated speech that mimics human tone, rhythm, and emotion. In the observed examples we see synthetic speech being deployed to relay the key messages in the videos.

Best Practices for Intelligence Analysts in Deepfake Detection

For intelligence analysts facing these threats, legacy image, video, and audio forensic software has been outcompeted by the rapid advancements in AIgenerated content. Although specialist digital forensics tools exist, they are not designed for detecting sophisticated AIgenerated falsifications at scale or in realtime, making it harder than ever to uncover the truth in digital media.

  • The flood of synthetic content means working through high-volume case loads with a need to analyze media quickly to identify disinformation. Traditional forensic tools rely heavily on human interpretation of the findings, which significantly delays decision-making in time-sensitive investigations.
  • Legacy forensic tools tend to be point solutions, designed to analyze one type of media at a time—either video, images, or audio. Fully synthetic media may include both artificially-generated audio and video, requiring multiple, disjointed tools to analyze the different formats, leading to workflow inefficiencies and compatibility issues, as well as increasing the burden on the human for interpretation.
  • Interpretation and explanation of results is critical, and traditional forensic software has a steep learning curve, which increases the cost of training, and significantly slows down investigations.

Fundamentally, the ease with which malicious media can either be manipulated or completely fabricated is changing the nature of how forensic authenticity is handled in terms of deepfake detection. Given the volumes and sophistication involved it can no
longer be treated as a late-stage expert opinion, but must be addressed instead as an automated verification step in the
process.

The optimal analytical process should be to integrate AI-generated media and deepfake detection at the earliest stage of
evidence ingestion, so every extracted media file can be automatically screened for signs of manipulation before it enters
the investigative record.

By following this approach, the intelligence analysts we worked with on this investigation reported dramatic reductions in manual review time of deepfake detection cases, faster triage of large datasets, and—most critically— greater confidence when creating reports including digital media.

Explainability is also critical. Getting a binary ‘fake’ or ‘real’ verdict isn’t enough. There needs to be a robust understanding of why this conclusion was reached and a justification of findings. When dealing with highly sophisticated AI-generated deepfakes, intelligence reports need to be reproducible, explainable, and traceable, avoiding the ‘black box problem’ and enabling intelligence analysts to rely on verifiable technical analysis rather than subjective interpretation.

Explainability – assisted by some of the techniques on the left, helps analysts to understand the reasoning behind a detection model’s decision, which then builds trust in the tool, and ensures
responsible use of it.

Because modern intelligence analysis is a complex process including use of deep learning technology as well as human intelligence, explainability can help build greater trust in automated detection systems. This unlocks the potential of Human-Machine Teaming (HMT), which fosters collaboration between intelligence analysts and AI systems, where machine driven data processing scales and complements human interpretive skills, to enhance decision-making, efficiency, and environmental awareness.

Share the article