What is epistemic security?
The capacity of an organisation or a society to preserve the conditions in which its members form reliable beliefs, and therefore make sound decisions. Its contemporary formulation was advanced by the Alan Turing Institute in 2020 [5]. Applied to a company or an institution, it asks a simple question: do your decisions rest on information that has not been manipulated?
Situate your organisation in ten minutes →Disinformation, misinformation, malinformation: what is the difference?
Two criteria separate them: falsity, and intent to harm. Misinformation is false information spread without intent to harm, the honest mistake. Disinformation is false information spread deliberately to deceive. Malinformation is true information used to harm: an authentic document leaked at a calculated moment, accurate words taken out of context. This distinction, established for the Council of Europe in 2017, has become the standard [3].
The consequence is operational: these three cases do not call for the same response, and denial is ineffective against the third.
A rumour targets my organisation. Should I respond publicly?
Not necessarily, and this is the most useful counter-intuition in this field: responding publicly carries the rumour to an audience that had not seen it. A public response is justified when at least two of four conditions are met: the narrative is still spreading, it has been picked up by a credible relay, it reaches an audience whose decisions bind you, or silence would be read as an admission. Below that, the useful action is targeted treatment.
Does disinformation really cost companies money?
The most cited estimate, published in 2019, puts the annual cost of disinformation to the world economy at about $78 billion, including $39 billion in stock-market losses [4]. We quote it with its limit: the study predates generative AI and was commissioned by a private actor. It gives an order of magnitude, not a measurement.
A documented case illustrates the mechanism better: in 2013, a fake post published from a hacked news-agency account wiped about $136 billion off the S&P 500 in roughly two minutes, before a full recovery in three [2]. Trading systems had reacted before any human.
Why does false information travel faster?
The reference study, covering about 126,000 rumour cascades spread by nearly three million people, establishes that false information is about 70% more likely to be reshared, and that true information takes about six times longer to reach 1,500 people. The authors point to novelty and emotional reactions as the explanation, and show that automated accounts spread true and false at the same rate: it is humans who accelerate the false [1].
Is training my teams enough to protect my organisation?
No, and our own work shows it. A pre-registered randomised controlled trial, conducted on 502 French-speaking participants as part of the doctoral research underpinning our programmes, yields a null primary result: brief inoculation alone does not produce the expected effect [6]. The inoculation literature is itself debated within its own discipline: a reanalysis published in 2023 concludes that gamified formats do not improve discrimination between true and false information [7].
We publish this result because it is true, and because it grounds our approach: preparation must be structural before it is pedagogical. Designate a decision-maker, establish an alert chain, organise monitoring, in that order.
My company uses generative AI. Am I under any obligation?
Probably. The transparency obligations of Article 50 of Regulation (EU) 2024/1689 become applicable on 2 August 2026. They do not depend on high-risk classification and cover four situations: a system interacting directly with people, production of synthetic content, emotion recognition or biometric categorisation, and dissemination of deepfakes or AI-generated texts on matters of public interest [8].
The eight checks to run before 2 August 2026 →Where do I start, concretely, if I have nothing?
With the two actions that cost nothing. One: designate in writing who decides on public responses, with a deputy. Two: establish the alert chain: who reports to whom, through which channel, within what time. These two measures cover the majority of real cases, because most of the damage comes not from the attack but from the improvised response in the six hours that follow.
The diagnostic tells you where to start →These pages are awareness resources. They constitute neither legal advice, nor an audit, nor an analysis adapted to your particular context.