GAVIN LUJAN BRIEF · ZIAWOLF ANALYSIS

AI: Deep Down
the Rabbit Hole

The “Alice in Wonderland” confusion technique, algorithmic disorientation, and the defense of human judgment in an age of synthetic reality.

AI SECURITYNIST AI RMFINFORMATION INTEGRITY
The old technique attacked one mind inside one controlled room. The AI version can attack an entire society inside a personalized reality.

EXECUTIVE ASSESSMENT

The rabbit hole is not a machine.
It is an environment.

In the CIA’s 1963 KUBARK Counterintelligence Interrogation manual, the “Alice in Wonderland” technique is described as an attempt to disrupt continuity, logic, expectation, and conditioned response. Its coercive power came from replacing the familiar with the strange until a person began losing confidence in the mental structure used to resist influence.

Generative AI can recreate the same information architecture: contradictory voices, unstable rules, accelerated tempo, persuasive nonsense, synthetic corroboration, personalized emotional pressure, and intermittent rewards. Recommendation systems then select and repeat whatever holds attention.

The decisive risk is epistemic exhaustion: people stop asking what is true and start asking which story makes the pressure stop.

JUDGMENT 01False content is the surface layer. The deeper capability is flooding the decision space until verification becomes costly, slow, or isolating.
JUDGMENT 02Confabulation, deepfakes, synthetic personas, and automated engagement can manufacture apparent consensus.
JUDGMENT 03No mastermind is required. Engagement incentives, model error, fragmented governance, and coordinated influence can combine into the same pattern.
JUDGMENT 04The defense is disciplined sensemaking: provenance, time, independent corroboration, explicit uncertainty, accountable judgment, and reversible action.

THE HISTORICAL MECHANISM

Break the map.
Become the replacement map.

KUBARK describes plausible-sounding nonsense, incompatible interrogator roles, unpatterned sessions, and rewards disconnected from conduct. The objective was not rational persuasion. It was to make the subject’s model of cause and effect stop working.

This manual is not behavioral scripture, and its coercive practices are not a model for legitimate leadership. Its value here is defensive: it gives us language for recognizing an information environment engineered—or simply allowed—to become unstable.

CONTINUITY ATTACKEndless feed shifts, context collapse, and claims that change before they can be tested.
LOGIC ATTACKFluent confabulation, false citations, and synthetic expertise.
SOCIAL ATTACKBot swarms, cloned voices, and manufactured consensus.
CAUSALITY ATTACKSystems that reward outrage and certainty rather than accuracy.

THE AI DESCENT

Seven layers down.

VolumeSynthetic production overwhelms verification.
FluencyConfident tone is mistaken for evidence.
MultiplicityGenerated personas manufacture apparent agreement.
PersonalizationMessages tune themselves to identity, fear, grievance, loyalty, and hope.
Synthetic evidenceText, image, audio, video, and forged records corroborate one another.
FeedbackEngagement teaches the system which pressure keeps a person inside.
DependencyThe AI accelerating confusion becomes the fastest way to interpret it.

NIST identifies confabulation, information-integrity harms, algorithmic monocultures, human-AI configuration risk, and long-term erosion of public trust among the risks intensified by generative AI. The rabbit-hole model connects them as a system.

SIGNAL DETECTION

Know when the channel is contested.

  • High confidence paired with weak, circular, or fabricated sourcing.
  • Apparent independent agreement that resolves to the same origin or model.
  • Claims that change before they can be frozen and tested.
  • Urgency used to prevent authentication or independent review.
  • Contradiction reframed as proof that the hidden system is even deeper.
  • A source that creates confusion, then sells itself as the only interpreter.
  • Punishment for provenance questions; reward for repeating the narrative.

These indicators do not prove coordination. Incompetence, breaking events, model error, and fragmented governance can create similar effects. Attribution requires evidence. The immediate conclusion should be narrower: the environment is not reliable enough for irreversible action.

ZIAWOLF COUNTER-RABBIT-HOLE DOCTRINE

Do not surrender reality
to the loudest synthetic chorus.

CONTROLACTIONDECISION VALUE
AnchorState the exact claim, timestamp, source, and decision.Stops narrative drift.
ProvenanceTrace origin, modifications, model use, and custody.Separates evidence from repetition.
TriangulateRequire independent sources using different collection paths.Reduces correlated failure.
AuthenticateVerify identity and authority out of band.Defeats cloned voices and spoofed channels.
Declare uncertaintyLabel known, assessed, unknown, and contradicted elements.Prevents confidence laundering.
Slow the irreversibleUse staged, reversible action while facts stabilize.Preserves options.
Log the decisionRecord evidence, owner, dissent, rationale, and review time.Protects institutional memory.
Red-teamTest deception, provenance bypass, crisis use, and operator failure.Finds weaknesses first.

Thirty-day minimum viable defense

  • Name an information-integrity owner for every consequential AI use case.
  • Inventory models, services, plugins, retrieval sources, and human decision owners.
  • Require AI-use disclosure and source links in executive products.
  • Create out-of-band verification for urgent consequential requests.
  • Adopt a one-page decision record covering provenance, uncertainty, dissent, authority, and review.
  • Run a tabletop involving a cloned executive voice, fabricated evidence, and conflicting AI summaries.

THE GAVIN LUJAN POSITION

Governed capability.
Human authority.

The modern rabbit hole does not end when one deepfake is labeled. It ends when people and institutions recover a trustworthy process for determining what happened, who has authority, what remains uncertain, and which actions can safely follow.

AI can serve the rabbit hole, but it can also map it. Used with provenance, independent sources, transparent uncertainty, and accountable human review, AI becomes an instrument for sensemaking rather than disorientation.

My position is neither blind acceleration nor fearful retreat. Use the machine. Preserve the human chain of judgment. Never confuse velocity with direction.

HOLD THE SIGNAL. NAME THE SOURCE. PRESERVE THE RECORD. VERIFY THE AUTHORITY. SEPARATE FACT FROM INFERENCE. ACT AT THE SPEED THE EVIDENCE CAN SUPPORT.

SOURCES & ANALYTIC BOUNDARY

  1. CIA, KUBARK Counterintelligence Interrogation, July 1963; less-redacted release of February 25, 2014.
  2. NIST, Generative Artificial Intelligence Profile, NIST AI 600-1, 2024.
  3. RAND, Artificial Intelligence, Deepfakes, and Disinformation, 2022.

This is a defensive analogy, not a claim that every algorithmic feed, contradiction, or model error is a coordinated operation. Attribution requires separate evidence.