Source-linked AI summary
Experts Disagree on How to Fight AI Disinformation, but Agree That Health and Politics Need Different Solutions
Alexander Loth, Martin Kappes, Marc-Oliver Pahl
TL;DR
The paper asks how experts assess AI-generated disinformation threats across modalities and domains, and which combinations appear most dangerous. Using survey responses from 54 experts, it finds domain-specific threat profiles and contested mitigation priorities, while recommending these preliminary patterns as a basis for further testing.
Problem
The paper examines how experts perceive AI-generated disinformation threats across four modalities and four domains, including which modality-domain combinations appear most dangerous.
Method
The study surveys 54 respondents about perceived threats and mitigation strategies across AI-generated disinformation modalities and domains.
Results
Political video deepfakes received the highest domain-specific threat rating (M = 6.31), while health text received the highest health-domain rating (M = 5.80); government regulation drew both 30% “most effective” and 15% “least effective” votes.
Takeaways & Limitations
The findings suggest domain-specific and layered mitigation approaches may be preferable to uniform or single-strategy solutions.
Takeaways & Limitations
The purposive sample is nonrepresentative, skews toward Western and technically proficient experts, measures perceptions rather than observed impacts, and supports descriptive rather than inferential sub-domain comparisons.
Abstract
from arXiv · showhide
When 54 international experts assessed AI-generated disinformation threats, they revealed a surprising pattern: while video deepfakes received the highest average threat ratings in the political domain (M = 6.31/7), the pattern differed in the health domain, where AI-generated text received the highest average rating (M = 5.80). Experts also diverge on what to do: government regulation drew both the most "most effective" (30%) and the most "least effective" (15%) votes, though rating distributions were contested rather than polarized, indicating disagreement over priorities rather than over efficacy. These findings offer an initial expert map of an AI-disinformation landscape that is still rapidly forming.
1 Research questions
The paper examines how experts perceive AI-generated disinformation across modalities and domains, which combinations appear most dangerous, how mitigation strategies are evaluated, and which near-term risks are most urgent.
- Experts’ threat perceptions are compared across text, images, audio, and video in political, health, financial, and social domains.
- The study asks which modality-domain combinations experts view as most dangerous and whether threat profiles differ systematically across domains.
- Experts evaluate five mitigation strategies and identify which they prioritize.
- The survey also asks experts to identify the most urgent near-term risks from generative AI.
2 Research note summary
A survey of 54 experts maps perceived AI-disinformation threats, mitigation preferences, and urgent risks. Results show domain-specific threat patterns and contested priorities, supporting tailored and layered responses.
- 54 experts were surveyed online from July 2025 to March 2026 through targeted recruitment with snowball extension.454 people were invited, producing an 11.9% response rate.
- Video deepfakes had the highest average threat rating overall at 6.19 on a 7-point scale, while health and finance showed different leading modalities.Health text led at M = 5.80, and finance audio led at M = 5.65.
- Election interference via deepfake video was identified as the top urgent risk by 78% of respondents.
- The findings suggest that domain-specific policy approaches and layered mitigation may be preferable to a uniform intervention.The proposed approach combines provenance, literacy, regulation, and platform enforcement according to domain threat profiles.
3 Implications
The paper argues that distinct domain-by-modality threat profiles call for tailored interventions rather than uniform governance. Because mitigation views are contested and tools reach audiences unevenly, it proposes a layered, domain-weighted response while framing the priority matrix as preliminary.
- Domain-specific threat patterns suggest tailored interventions: Political video, health text, and financial audio present distinct perceived threat profiles that existing governance instruments do not track.The EU approach is horizontal, while U.S. oversight is fragmented across sectors.
- Domain-specific threat patterns suggest tailored interventions: Political video motivates investment in detection and provenance standards because respondents focused on electoral and democratic-process interference.
- Domain-specific threat patterns suggest tailored interventions: Health text motivates labeling and medical fact-checking, with the WHO infodemic-management framework offering an operational template.That framework combines active listening, rapid authoritative rebuttal, and amplification through trusted local messengers.
- Domain-specific threat patterns suggest tailored interventions: Live voice or video is no longer reliable evidence of identity.
- A contested, not polarized, mitigation landscape: Government regulation, digital watermarking, media literacy, platform enforcement, and technical detection were all broadly endorsed, but experts disagreed over which should come first.Government regulation received 30% of most-effective and 15% of least-effective votes; media literacy received 26% and 24%, respectively.
- A contested, not polarized, mitigation landscape: Psychological inoculation was absent from the five-strategy survey despite cited evidence that pre-exposure can build resistance across topics and time horizons.
- Public-awareness tools reach the wrong audiences: Public-awareness tools were moderately effective at M = 4.43, but one third said they mainly reach audiences already technically confident.This points toward attention to distribution, accessibility, and integration into platforms used by vulnerable audiences.
- Toward a layered, domain-weighted response: The proposed response combines provenance, audience literacy, statutory regulation, and platform enforcement, weighted by domain.The four pillars act on artifacts, recipients, producers, and distribution, respectively.
4 Findings
Across 54 experts, video deepfakes received the highest average threat rating overall, while modality patterns varied by domain. Experts also identified election interference via deepfake video as the most urgent risk and rated government regulation highest among mitigation strategies, though strategy priorities remained contested.
- Modality threat perceptions: 6.19/7 was the highest overall average threat rating, assigned to video deepfakes.Audio, images, and text followed at M = 5.91, 5.74, and 5.57, respectively.
- Domain-specific threat profiles: 6.31 was the political-domain peak for deepfake video, although overlapping confidence intervals make this ordering suggestive rather than established.The difference from political-domain audio could plausibly reflect sampling variation among the 54 respondents.
- Domain-specific threat profiles: 5.80 was the health-domain peak for AI-generated text, while health-domain modalities clustered lower and their confidence intervals overlapped.The text rating was M = 5.80; images and video were each M = 5.13, and audio was M = 5.02.
- Domain-specific threat profiles: 5.65 was the financial-domain peak for audio deepfakes, though confidence intervals did not clearly separate audio from video or text.
- Urgent risks: 78% identified election interference via deepfake video as the most urgent risk.Cyberattacks and non-consensual deepfake imagery each followed at 46%, with wide confidence intervals indicating uncertainty in their precise ranking.
- Mitigation strategies: 5.24/7 was the highest mean effectiveness rating, assigned to government regulation, but the top four strategies were not statistically distinguishable.Government regulation also received both the most “most effective” votes (30%) and the most “least effective” votes (15%), indicating contested priorities rather than polarized distributions.
5 Methods
This exploratory study used an online survey to map expert assessments of AI-driven disinformation threats and mitigation strategies. Descriptive analyses of 54 retained responses characterize preliminary patterns, with a purposive sample that limits representativeness.
- Scope: The study was exploratory, reporting a broad descriptive map rather than preregistered hypothesis tests.The authors describe the findings as preliminary and note that the sample is purposive, nonrepresentative, and skewed toward Western, technically proficient experts.
- Study design: 54 valid responses were retained from a structured online survey conducted between July 2025 and March 2026.Eligibility required a recent publication, project, or public engagement on AI-driven disinformation; no formal post-response screening or exclusion was applied.
- Recruitment: Recruitment combined targeted expert outreach with snowball extension after identifying 516 candidates and directly contacting 454.Candidates were found through Google Scholar, LinkedIn, Mastodon, and Bluesky searches, supplemented by recent publication authors.
- Sample: The sample included substantial representation from AI/ML researchers and developers and from disinformation, fact-checking, journalism, or media researchers.Open-text role recoding produced seven coherent categories, with the two largest categories comprising 39% and 26% of respondents, respectively.
- Analysis: Quantitative data were analyzed descriptively using means, standard deviations, and frequencies rather than inferential tests.Figures used 95% bootstrap confidence intervals with 10,000 iterations and Wilson score intervals for binomial proportions.
- Scope: The sample’s composition may cause observed priorities to reflect expert perspectives on AI-related risks rather than broader societal perceptions.The authors specifically note the comparatively large proportion of AI researchers and disinformation specialists.
7 Authorship
The study’s authorship roles assigned primary responsibility for conception, survey development, data collection, analysis, and manuscript writing to A. L., with M. K. and M.-O. P. providing supervision and critical feedback.
- A. L. conceived and designed the study, developed the survey instrument, collected data, analyzed it, and wrote the manuscript.
- M. K. and M.-O. P. supervised the work and provided critical feedback on the study design and manuscript.
- All authors reviewed and approved the final version.
8 Funding
The authors report that no funding was received to conduct this research.
- No funding was received to conduct this research.
10 Ethics
The survey followed human-subjects ethical guidelines, including informed consent, voluntary participation, withdrawal rights, and avoidance of sensitive personal-data collection.
- Consent: All participants provided informed consent before completing the survey and confirmed they were at least 18 years old.
- Participation: Participants could withdraw at any time without consequences.
- Data handling: The survey collected professional opinions on AI-generated disinformation threats and mitigation strategies without sensitive personal data.
11 Copyright
The article is openly accessible under a Creative Commons license, with the publisher’s version identified separately. The survey instrument and study materials are documented in the appendices.
- The article permits unrestricted use, distribution, and reproduction when the original author and source are credited.
- The survey instrument is reproduced in Appendix A.
A.1 Consent & data protection (1 item).
The study used a consent-gated, English-language survey organized into domain, risk, mitigation, literacy, and attribution components. Professional roles were recoded into coherent categories for analysis.
- Consent & data protection: Participants confirmed that they were at least 18 and agreed to the consent terms before proceeding.
- Survey instrument: The threat instrument rated text, images, audio, and video across political, health, financial, and social domains.
- Survey instrument: Respondents selected up to three urgent risks and rated five mitigation strategies on 1–7 scales.
- Survey instrument: The survey also included forced ranking, public-literacy tools, future-outlook questions, and publication-attribution choices.
- Role recoding: Thirty-two distinct professional-role strings were recoded into seven coherent categories, with none discarded.
Appendix C: Supplementary statistical tables
The supplementary tables document respondent characteristics, mitigation-rating distributions, recruitment details, and a domain-by-modality policy-priority matrix. Their supporting notes emphasize descriptive interpretation and contested rather than polarized mitigation views.
- Sample characteristics: The sample comprised 54 respondents, with 42.6% based in the European Union and 35.2% in North America.
- Sample characteristics: Respondents had a median of 17 years of professional experience, with experience ranging from 1–65 years.
- Mitigation distributions: Mitigation ratings were right-skewed and unimodal, so forced-choice disagreement reflected priority-setting rather than effectiveness polarization.
- Recruitment: The recruitment funnel records candidate identification, direct contact, and valid responses, while snowball forwards were not captured in the denominator.
- Policy priority matrix: The policy-priority matrix maps perceived threat by domain and modality as a preliminary, re-weightable mitigation stack.