What used to take ten people and $50,000 to run a disinformation campaign can now be done by one person for a few dollars in AI tokens. Worse, the AI-generated personas behind these campaigns no longer show the tells that made troll farms easy to spot. Detection has to move from flagging fake content to analyzing fake behavior at the network level, and intelligence teams need to move now.

In my first post in this series, Agents Handle the Legwork, Not the Judgement, I covered how Fivecast is building agentic AI into protective security, cyber and OSINT investigations. This post is about the flip side of the same technology, and it’s the part of my AIPIO Intelligence Conference 2026 talk that stayed with the room longest.
Lesson two: the threat side has industrialized
Earlier this year, Fivecast ran a symposium on AI and misinformation with researchers from the University of Adelaide, Flinders University and Australia’s Department of Defence, drawing around 100 people from defense, research and industry leaders. We didn’t come out of that day with a solution. Many of us left more concerned than we arrived and the reason was one number that kept coming up in different forms from different speakers: cost.
What used to take ten people and $50,000 to run a coordinated disinformation campaign can now be done by one person for a few dollars in AI tokens. That’s not a marginal efficiency gain, that’s the cost of running a disinformation campaign dropping by several orders of magnitude, and it happened inside a handful of years. When the cost drops that far, the eco-system of people capable of mounting it stops being a short list of well-resourced actors and becomes, effectively, anyone with a laptop and motive.
This is documented, not hypothetical. Google’s Threat Intelligence Group has reported generative models operating inside adversary workflows at industrial scale. Australia’s own security leadership names disinformation and deepfakes as a foreign interference vector, not a hypothetical future risk but a current one. And it’s landing on real people, not just institutions. The week before our symposium, I heard a radio report describing a deepfake circulating locally that showed a Melbourne cancer researcher advising patients to stop their medication. That’s one local instance of a pattern now well documented globally, where scammers clone the faces and voices of real doctors to push fake health advice to sick, frightened people. This isn’t an abstract information-integrity problem, it has a direct line to physical harm.
This is exactly why disinformation detection now sits inside how we think about national security intelligence, not as a side concern but as a core mission.
Fivecast at AIPIO Conference 2026
Why the old detection playbook is behind
Going back to the well-documented cases of foreign interference in past elections. Those campaigns ran largely on troll farms, and troll farm personas were, on close inspection, easy to spot. No real friend networks. No genuine posting history stretching back years. A narrow, single-topic focus no real person exhibits.
AI-driven personas today don’t have those tells. They hold a consistent, plausible identity across months of activity, posting about sport, family, local news and politics in believable proportion, the way a real account does, while still steering toward a coordinated narrative when it matters. At the symposium, some of the most experienced detection specialists in the room said, plainly, that they could no longer reliably tell the difference between the two account types on inspection alone.
That’s the shift intelligence teams need to make right now. If your detection strategy is still built around flagging obviously synthetic content, unnatural phrasing, telltale artifacts, suspiciously new accounts, it’s already fighting the previous generation of the problem. The frontier has moved to persona-level and network-level analysis: not “does this piece of content look fake,” but “does this cluster of accounts behave like a real, organic community, or a coordinated one,” regardless of how convincing any single account looks in isolation. This is squarely agentic work: no human team can manually trace posting behavior and network structure across the volume of accounts a modern influence operation can stand up, but the judgment on what a detected pattern means, and what to do about it, stays with the analyst.
We go into this shift in more depth in our post on OSINT data fusion, for anyone who wants to see how it works in practice.
What this means for the profession
I closed my session at AIPIO with four things I think every analyst, team leader and executive in this profession needs to sit with, and they apply directly to everything in this series.
- Build judgment. The job is shifting, not disappearing. Spend less time on manual search and collection, and more time on the calls an agent cannot make: what matters, what’s missing, and what the consequences of being wrong actually are.
- Treat agent literacy as a core skill. Understanding what an agent can and cannot reliably do, how to interrogate its provenance, and when to override it, is becoming as important as source knowledge was a generation ago.
- Make it a partnership, not a handover. Relying solely on AI output invites bias and hallucination. Human verification stays the checkpoint on any decision with real consequences.
- For leaders, treat Agentic AI as a capability investment. It’s not a single product purchase. It requires tooling budget, cross-agency data access and the governance that lets agentic tools query the sources they actually need.
The takeaway: the strategic reality is straightforward. Agentic AI systems are already in the wild, and your adversaries are already using them. The open question is whether your organization’s collection, analysis and governance, and your own skills, can keep pace. The technology will keep moving in months, not years, and the durable advantage belongs to the teams that treat agent architecture as core intelligence infrastructure and invest in the judgment to direct it.
If you want to talk through where your organization sits on that journey, our team would welcome the conversation. If you’d rather start with the research first, our Intel Hub has case studies and briefs on exactly this kind of work.
About Fivecast
Fivecast delivers intelligence solutions built for clarity, powered by AI and trusted to surface what matters. Engineered to solve complex intelligence challenges our platform cuts through digital noise to help those protecting nations, borders, businesses and communities uncover critical insights – before risk becomes reality.
Trusted by agencies and enterprises across national security, law enforcement, defense, corporate security and financial crime, Fivecast was born from collaboration between governments and research institutions. Headquartered in Australia with a global footprint, we support the world’s most critical missions.
Fivecast. Engineered for Intelligence.
- Dr Brenton Cooper is Co-Founder and CEO of Fivecast. This is Part 1 of a two-part series following his presentation at the AIPIO Intelligence Conference 2026, “Misinformation in the age of AI”
- Fivecast delivers open-source intelligence solutions built for clarity, powered by AI, and trusted to surface what matters. Request a Demo.
- Read the series: Part 1: Agents Handle the Legwork, Not the Judgement.
