Académie Nexus

The questions leaders ask, and our answers.

Substantial, sourced answers, and four free resources. Two ask for a form, and you will know why.

The four resources

Interactive · 10 minutes

Executive information-resilience diagnostic

Seven real decision situations, ten minutes. Your decision profile in the face of information manipulation, with an immediate on-screen result and a full report by email if you request it.

Take the diagnostic
PDF · 1 page · no form

The executive's 10 rules of information hygiene

Ten reflexes that protect your decisions. One page, to display or circulate. Free download, no data requested. Document in French.

Download the PDF
PDF · 8 pages

AI Act checklist: the obligations of 2 August 2026

The four situations of Article 50, and the eight checks detailed: what each covers, who owns it, the typical mistake, and a model notice or clause to adapt. For any organisation using generative AI. Document in French.

Everything about Article 50
PDF · 6 pages

The first 24 hours protocol

Qualify, decide, treat: the hour-by-hour course of action for an information incident, with the reflex sheet to display and the contacts to fill in. Document in French.

Discover the protocol

Why only one resource asks for a form. The diagnostic shows its result without asking for anything, and the 10 rules circulate freely: they are made to travel, in a committee, a corridor, a LinkedIn feed. The checklist and the 24-hour protocol ask for an email because we prefer knowing who we are talking to over installing trackers to guess it. This site uses none. The LinkedIn image version of the 10 rules is here.

The questions, and the answers

What is epistemic security?

The capacity of an organisation or a society to preserve the conditions in which its members form reliable beliefs, and therefore make sound decisions. Its contemporary formulation was advanced by the Alan Turing Institute in 2020 [5]. Applied to a company or an institution, it asks a simple question: do your decisions rest on information that has not been manipulated?

Situate your organisation in ten minutes

Disinformation, misinformation, malinformation: what is the difference?

Two criteria separate them: falsity, and intent to harm. Misinformation is false information spread without intent to harm, the honest mistake. Disinformation is false information spread deliberately to deceive. Malinformation is true information used to harm: an authentic document leaked at a calculated moment, accurate words taken out of context. This distinction, established for the Council of Europe in 2017, has become the standard [3].

The consequence is operational: these three cases do not call for the same response, and denial is ineffective against the third.

A rumour targets my organisation. Should I respond publicly?

Not necessarily, and this is the most useful counter-intuition in this field: responding publicly carries the rumour to an audience that had not seen it. A public response is justified when at least two of four conditions are met: the narrative is still spreading, it has been picked up by a credible relay, it reaches an audience whose decisions bind you, or silence would be read as an admission. Below that, the useful action is targeted treatment.

Does disinformation really cost companies money?

The most cited estimate, published in 2019, puts the annual cost of disinformation to the world economy at about $78 billion, including $39 billion in stock-market losses [4]. We quote it with its limit: the study predates generative AI and was commissioned by a private actor. It gives an order of magnitude, not a measurement.

A documented case illustrates the mechanism better: in 2013, a fake post published from a hacked news-agency account wiped about $136 billion off the S&P 500 in roughly two minutes, before a full recovery in three [2]. Trading systems had reacted before any human.

Why does false information travel faster?

The reference study, covering about 126,000 rumour cascades spread by nearly three million people, establishes that false information is about 70% more likely to be reshared, and that true information takes about six times longer to reach 1,500 people. The authors point to novelty and emotional reactions as the explanation, and show that automated accounts spread true and false at the same rate: it is humans who accelerate the false [1].

Is training my teams enough to protect my organisation?

No, and our own work shows it. A pre-registered randomised controlled trial, conducted on 502 French-speaking participants as part of the doctoral research underpinning our programmes, yields a null primary result: brief inoculation alone does not produce the expected effect [6]. The inoculation literature is itself debated within its own discipline: a reanalysis published in 2023 concludes that gamified formats do not improve discrimination between true and false information [7].

We publish this result because it is true, and because it grounds our approach: preparation must be structural before it is pedagogical. Designate a decision-maker, establish an alert chain, organise monitoring, in that order.

My company uses generative AI. Am I under any obligation?

Probably. The transparency obligations of Article 50 of Regulation (EU) 2024/1689 become applicable on 2 August 2026. They do not depend on high-risk classification and cover four situations: a system interacting directly with people, production of synthetic content, emotion recognition or biometric categorisation, and dissemination of deepfakes or AI-generated texts on matters of public interest [8].

The eight checks to run before 2 August 2026

Where do I start, concretely, if I have nothing?

With the two actions that cost nothing. One: designate in writing who decides on public responses, with a deputy. Two: establish the alert chain: who reports to whom, through which channel, within what time. These two measures cover the majority of real cases, because most of the damage comes not from the attack but from the improvised response in the six hours that follow.

The diagnostic tells you where to start

To go further: our articles, documented case analyses (FIMI, deepfakes, crisis communication) and practical guides (in French)

Sources

  1. Vosoughi, S., Roy, D. et Aral, S., « The spread of true and false news online », Science, vol. 359, n° 6380, 2018, p. 1146 à 1151. DOI 10.1126/science.aap9559
  2. Bloomberg, « Fake Post Erasing $136 Billion Shows Markets Need Humans », 23 avril 2013. Reuters estime la perte temporaire à 136,5 milliards de dollars.
  3. Wardle, C. et Derakhshan, H., Information Disorder : Toward an Interdisciplinary Framework for Research and Policy Making, Conseil de l'Europe, Strasbourg, 2017.
  4. Cavazos, R. (University of Baltimore) et CHEQ, The Economic Cost of Bad Actors on the Internet : Fake News 2019, 2019.
  5. Seger, E., Avin, S. et Pearson, G., Tackling Threats to Informed Decision-Making in Democratic Societies : Promoting Epistemic Security in a Technologically-Advanced World, The Alan Turing Institute, octobre 2020.
  6. Abousaab, E., Pre-registration : Cognitive Inoculation Against FIMI Susceptibility, A Randomised Controlled Trial on a French Adult Population, version 2, 27 mai 2026. Zenodo, licence CC BY 4.0. DOI 10.5281/zenodo.20403018
  7. Modirrousta-Galian, A. et Higham, P. A., « Gamified inoculation interventions do not improve discrimination between true and fake news », Journal of Experimental Psychology : General, vol. 152, n° 9, 2023, p. 2411 à 2437. DOI 10.1037/xge0001395
  8. Règlement (UE) 2024/1689 (intelligence artificielle), article 50. Règlement (UE) 2022/2065 (services numériques), articles 34 et 35. World Economic Forum, The Global Risks Report 2026, janvier 2026. Abousaab, E., Epistemic Security Score (ESS), Zenodo, DOI 10.5281/zenodo.20837003

These pages are awareness resources. They constitute neither legal advice, nor an audit, nor an analysis adapted to your particular context.

These resources come from our programmes

Académie Nexus trains leaders and institutions in epistemic security and information resilience. Our tracks are grounded in doctoral research conducted at the Centre d'Études Diplomatiques et Stratégiques, from which come the societal-resonator framework and the Epistemic Security Score, deposited for the twenty-seven member states of the European Union.

Two entry points: the executive track Epistemic Security and Information Resilience, and, in the catalogue, the programme Data Governance and Sovereignty, which covers the legal framework the AI Act belongs to.

The programmes that extend these resources

Four tracks for leaders and teams exposed to information manipulation: executive information security, deepfake detection, governance and the AI Act, crisis communication. All OPCO-eligible.

Communication

Executive information security

One day to understand disinformation mechanics, detect manipulated content and protect both decision-making and reputation.

1 day (7 h)In-house and inter-companyOPCO-eligible
View the programme
IA

Deepfakes: detection and response protocol

Recognise synthetic content (voice, image, video), assess the risk to the organisation and trigger the right protocol under attack.

1 day (7 h)In-houseOPCO-eligible
View the programme
IA

Data governance and sovereignty

Legal framework, GDPR, AI Act, technological sovereignty.

2 daysRemoteOPCO-eligible
View the programme
Communication

Crisis communication

Proven methods to handle sensitive, institutional or media crises.

2 daysIn-houseOPCO-eligible
View the programme