Six ways AI is already manipulating your decisions

Dear Reader,

When most people hear the phrase "AI manipulation," they think about dramatic scenarios. Deepfake videos of politicians saying things they never said. Chatbots convincing users of dangerous conspiracies. Autonomous agents plotting to deceive their operators. These scenarios are real and worth taking seriously, but they are not the main thing that AI manipulation actually looks like in 2026.

The main thing is more mundane and more effective. It is the specific ways that AI systems, embedded in the products you use every day, shape your decisions in directions you would not endorse if you could see what was happening. This kind of manipulation does not require any specific intent. It happens as a byproduct of systems that were optimized for specific metrics, in ways that turned out to require shaping user behavior to hit those metrics.

I want to walk through six specific mechanisms by which this is happening. Each of them is well-documented, currently deployed, and affecting decisions you probably made this week. Recognizing them is the first step to defending against them, though defending against them fully is harder than most guides suggest.

The first mechanism is personalized framing.

When you see information online, the specific way it is presented is often chosen by a system that knows something about you. The headline, the image, the specific words used in the summary, the specific comparison points offered. These are personalized based on what has worked before for people similar to you, or in some cases for you specifically.

The specific effect is that the same underlying information hits you in the specific way most likely to produce the response the system is optimizing for. If the system wants you to click, it frames the information in the way most likely to make you click. If it wants you to buy, it frames it to make you buy. If it wants you to agree, it frames it to make you agree. The information may be technically accurate. The framing is not neutral.

You can see this working in yourself if you pay attention. Something catches your eye. You feel a specific pull toward it. You click, or buy, or share. Later you wonder why. The wondering is your rational self noticing that a decision was made through a channel that bypassed rational deliberation. This is the specific texture of framing manipulation working on you.

The defense against this is limited. You cannot see what alternative framings would have been available. You can only train yourself to notice the pull, to pause before responding, to ask whether you would have made the same decision if the framing had been different. This is exhausting to do consistently. But it is the only real defense.

The second mechanism is engagement optimization.

The specific content you see on any given platform is chosen by an algorithm optimizing for a specific engagement metric. Time on app. Number of interactions. Rate of return. The specific metric varies by platform, but the underlying pattern is that content is selected to maximize whatever the platform can measure.

The consequence is that your attention is being deliberately shaped toward whatever produces the metric, regardless of whether that is good for you. Content that provokes anger. Content that produces envy. Content that triggers anxiety. All of these produce engagement, and so all of them are systematically over-represented in what you see relative to what would appear if the selection were neutral.

This is manipulation in a specific sense. Your attention is being directed toward specific things, not because those things are important to you, but because they produce a metric the platform cares about. And the specific things being over-represented are typically things that in a healthier state you would rather not attend to as much.

The defense here is either to change the platform, to change what you engage with on it, or to accept that you are being manipulated and try to compensate consciously. None of these fully work. Changing the platform reduces exposure but rarely eliminates it. Changing what you engage with is difficult because the algorithm adapts to whatever you engage with, meaning that your specific defenses feed back into what you are shown. Conscious compensation is exhausting.

The third mechanism is anchoring through choice architecture.

When you make a decision online, the specific set of options presented to you is chosen by a system. The default option. The highlighted option. The order of options. The specific pricing. Each of these is a design choice, and each of them affects your decision in predictable ways.

This is the specific pattern that Cass Sunstein and Richard Thaler wrote about under the name of "nudge," and it is now deployed at scale by every major digital platform, with far more sophistication than the original nudge literature contemplated. AI systems can now personalize the choice architecture to each user, presenting the specific configuration of options most likely to produce the specific decision the system wants.

The defense here is to recognize when you are in a designed choice architecture and to consciously consider what other options might have been available. When you subscribe to something, is the annual option really cheaper than monthly, or is that just how it is framed? When you shop, are the products at the top of the list really the best options, or are they the ones with the highest margins for the platform? When you sign up for something, are the default settings really what you want, or are they what the platform wants?

Most people do not do this. Most decisions are made quickly, in the specific choice architecture presented, without asking whether the architecture is neutral. Which it almost never is.

The fourth mechanism is dark patterns.

Dark patterns are specific design choices intended to trick users into decisions they would not otherwise make. The unsubscribe process that requires seven steps. The consent form that visually emphasizes "accept" and de-emphasizes "reject." The "free trial" that automatically converts to a paid subscription unless you take specific action to cancel. The confirmshaming that offers you a choice between "yes, save money" and "no, I don't want to save money."

These patterns are extensively documented. There are academic papers cataloging them. There is regulatory attention to them. And they continue to be deployed at scale, because they work. Every major platform uses at least some of them. Many use most of them.

The specific development of the last few years is that AI is being used to personalize dark patterns to specific users. The specific version of the manipulation you experience is tuned to your specific weaknesses. If you are impatient, the dark pattern will exploit impatience. If you are conflict-averse, it will exploit conflict-aversion. The specific vulnerability that will get you is being deliberately targeted, based on data collected from your previous interactions.

The defense against dark patterns is basically pattern-recognition. Once you have seen a few, you start noticing them. You learn to slow down when you see the specific triggers. You develop a specific skepticism about interfaces that seem designed to rush you. This helps but is not fully protective. And it requires attention that most of us do not have available.

The fifth mechanism is emotional targeting.

AI systems can now identify emotional states from a variety of signals, and shape content or interactions based on those states. The specific texture of your typing. The specific patterns of your scrolling. The specific times of day you are active. All of these carry information about your emotional state, and AI systems can use that information to time interventions for maximum effectiveness.

This is being deployed in advertising, in commerce, and increasingly in social platforms. The specific pattern is that emotionally activating content is shown to you when you are in a state that will produce the strongest response. Sad late at night? Here is content that will keep you engaged with your sadness. Anxious in the morning? Here is content that will confirm your anxiety and produce more of it. Happy after good news? Here is content that will get you to spend money while you are feeling generous.

The specific ethical status of this practice is debated. Some argue that emotional targeting is not different in kind from any other form of personalization. Others argue that it crosses a specific line by exploiting states of reduced agency. Whatever the ethics, the practice is happening, and it is getting better at doing what it does.

The defense here is to be careful about what you consume during emotional states, and to notice when your emotional state seems to be shifting in response to what you are consuming. If a platform seems to consistently leave you in a specific emotional state, that state is probably being targeted. Adjusting what platforms you use during vulnerable times helps. Sometimes.

The sixth mechanism is model-tuned persuasion.

Large language models can now produce persuasive content tailored to specific arguments, specific audiences, and specific rhetorical goals. This is being used in political campaigns, in marketing, and in customer service. The specific texture of what you read is often the output of a model that has been tuned to produce exactly the response the deployer wants.

This is different from earlier forms of manipulation because it happens at the level of specific language. The specific phrasing of an email you receive, the specific way an argument is made in a piece of content you read, the specific responses you get in a chatbot interaction, are all outputs of systems that can produce many variants and select the one most likely to move you in the direction the deployer wants.

The specific implication is that the language you encounter online is progressively less natural. It is being shaped, at fine grain, to have specific effects on you. And you cannot easily distinguish naturally-produced language from strategically-produced language, because the strategic language is designed to look natural.

The defense against this is to be more skeptical about the language you encounter, particularly language that is trying to move you toward a decision. Ask yourself if you would have found the same argument compelling if it had been made less well. Ask yourself if the specific words you are reading were chosen for you or would have appeared naturally. Notice when the phrasing feels a little too on-point, a little too well-tuned, a little too smooth. These are signals that you may be interacting with model-tuned content.

Let me tell you what pulling these together looks like in practice.

I spent an hour recently trying to cancel a subscription I no longer wanted. The service was one I had been paying for for years, and I had decided I did not need it anymore. Should have been a five-minute task.

The specific experience was that I opened the app, went to settings, could not find the cancellation option, went to the website, could not find it there either, contacted support through chat, was told I needed to call, called, was put on hold for twenty minutes, spoke to a person who tried to talk me out of canceling, was offered three different discounts, was made to explain in detail why I was canceling, was told I would lose specific benefits I had not known I had, and was finally allowed to cancel after another set of confirmations. The whole thing took over an hour.

Every specific step was a designed choice by someone. The specific difficulty of finding the option. The specific requirement to use a channel that was more difficult. The specific script the agent used. The specific escalation of offers. The specific delays before each step. All of this was choice architecture, dark patterns, model-tuned persuasion, and possibly emotional targeting, deployed against my attempt to leave the platform.

The specific frustrating thing is that I know how these systems work. I could see, in real time, that I was in a designed retention flow. And I still had to spend the hour. Because the specific design was effective enough that even knowing what was happening did not let me shortcut it.

If it does this to me, it does this to everyone. And most people do not know what to look for. So they end up either not canceling, or canceling with significant emotional cost, or eventually giving up and paying for something they did not want.

The general implication is that we are living inside systems that are constantly manipulating our decisions, often through mechanisms that are difficult to see and defenses that are difficult to sustain. This is not a hypothetical concern. It is the specific texture of daily life for anyone using digital platforms at scale.

The individual response has real but limited value. You can learn to see the manipulation. You can learn to resist it in specific instances. You can build habits that reduce your exposure. All of this helps. None of it fully protects you.

The collective response would be regulatory. There are specific legal frameworks that would restrict dark patterns, require transparency about algorithmic decision-making, and hold platforms accountable for exploiting user vulnerabilities. Some jurisdictions have started to implement these. Most have not. And the specific pace of regulation is much slower than the pace of technological development.

Which means, in the near term, individual defense is what we have. And individual defense is inadequate. This is the specific gap that most commentary about digital manipulation glosses over. Yes, you should be careful. Yes, you should notice what is happening. Yes, you should protect yourself. And no, this will not be enough. You will still be manipulated, at scale, by systems more sophisticated than your defenses.

Naming this clearly is important. Because the framing that puts the responsibility on individuals to defend themselves against these systems is the framing that lets the systems continue operating without accountability. If we cannot solve this problem at the individual level, then we should stop pretending we can. And we should turn our attention to the collective mechanisms that could actually address it.

I want to close with something specific about how this connects to the wider AI question.

The AI systems currently deployed in these manipulation mechanisms are not general artificial intelligence in the sense of the science fiction narratives. They are specialized systems tuned to specific tasks. But they are exactly the systems that will scale up as AI becomes more capable. The infrastructure being built to manipulate you on social media today is the same infrastructure that will manipulate you in more consequential ways as it improves.

This is not paranoia. It is what the specific companies deploying these systems have said they intend to do. They are building persuasion infrastructure. They are building attention-capture infrastructure. They are building emotional-targeting infrastructure. All of this is downstream of business models that reward doing so, and all of it is being made more capable by advances in AI.

Which means that the AI ethics conversation cannot be usefully separated from the current manipulation infrastructure. The people building AI are building systems that will plug into these mechanisms. The systems that will be built next will be more effective at manipulating you than the ones being built now. And the specific gap between individual defense and systemic response will grow, not shrink, as this proceeds.

The only real response is systemic. Regulation. Alternative economic models. Public investment in non-manipulative infrastructure. These are big projects. They are slow. And they are what the current situation actually calls for. Individual defense is a survival strategy for the interim. It is not a solution.

Next month I want to write about deepfakes and the specific way they are reshaping our relationship with shared reality. Because if manipulation of your decisions is one problem, manipulation of what you can believe to be real is another, and the second one is coming more quickly than most people realize. Stay with me.

— Transmission Sent —

Niklas Hanitsch


Reference materials

  • Cass Sunstein and Richard Thaler — Nudge: Improving Decisions About Health, Wealth, and Happiness (2008)
  • Harry Brignull — Deceptive Design (deceptive.design catalog)
  • Cass Sunstein — Manipulation as Theft of Autonomy (2016)
  • Karen Yeung — Hypernudge: Big Data as a Mode of Regulation by Design (2017)
  • European Commission — Digital Services Act (2022)
  • Nature Human Behaviour — Online manipulation: hidden influences in a digital world (2019)
  • https://www.deceptive.design/
  • https://ec.europa.eu/info/policies/consumers/consumer-protection-policy_en

Continue reading

Frequently asked questions

What is AI manipulation? AI manipulation is any use of artificial intelligence to shape human decisions in ways the human would not endorse if they saw the mechanism clearly. It ranges from personalized advertising to dark patterns to model-tuned persuasion. Most AI manipulation happens without any specific intent to harm, as a byproduct of systems optimizing for engagement or revenue metrics.

Are algorithms manipulating me right now? Almost certainly yes, in the specific sense that the digital platforms you use are running algorithms that shape your choices in ways you did not explicitly choose. Whether this counts as manipulation depends on how you define the term. If you define it as any non-neutral shaping of decisions, the answer is unambiguously yes.

What are dark patterns? Dark patterns are user interface designs specifically intended to trick users into decisions they would not otherwise make. Examples include hard-to-find unsubscribe buttons, misleading consent forms, automatic subscription renewals, and confirmshaming language. Dark patterns are extensively documented and continue to be deployed at scale because they work.

How can I protect myself from AI manipulation? Partially, through vigilance. Slow down before making decisions online. Notice when interfaces seem designed to rush you. Recognize when content activates strong emotional responses. Use fewer platforms. Prefer paid services with clearer incentive alignment. Full protection is not available at the individual level. Regulatory intervention is the only real solution.

What is model-tuned persuasion? Model-tuned persuasion is the use of AI systems, particularly large language models, to produce persuasive content optimized for specific arguments, audiences, and rhetorical goals. It is deployed in advertising, political campaigns, marketing, and customer service. It is difficult to detect because it is designed to look natural.


About the author

Niklas Hanitsch is a German technology entrepreneur, criminal defense lawyer, and digital artist. He is the CEO of SECJUR, an AI-powered compliance automation platform, and the creator of FALSE GOD, a body of digital art exploring consciousness, decay, and the boundary between the human and the machine. He writes the monthly newsletter Signals From The Machine.

Find him on LinkedIn or subscribe to Signals From The Machine.

Previous
Previous

Deepfakes and the coming collapse of shared reality

Next
Next

The algorithmic god. How recommendation systems became our post-religion