Electoral Integrity // Assessment, Engine, Corpus
The finished estimate, the coordination engine, the post-level authorship pipeline, the model backtest, and the doctrine annex, in a single page with the computed data embedded. No setup. Use the tabs.
Scores, bands, and what they mean
Stress scores, 0 to 6
Each indicator is scored for observed intensity of a concerning condition. Higher is more adverse. A low score can mean the condition is genuinely low or that it is thinly measured, so coverage is tracked as a separate flag. The presence of a capability is never scored as persuasion.
The index, 0 to 100
The Electoral Integrity Threat Index is a weighted composite of five components, shown with its parts on the Index panel. It is a decision aid, not a measurement, and the weights are meant to be argued with.
Likelihood bands
Estimates use half-open probability bands: almost certain 95 to 99, very likely 80 to 95, likely 55 to 80, roughly even 45 to 55, unlikely 20 to 45, very unlikely 5 to 20, remote 1 to 5.
Confidence and sourcing
Analytic confidence, low, moderate, or high, is reported separately from likelihood and reflects evidence depth and source agreement. Sources are graded on reliability A to F and credibility 1 to 6, never averaged. Verified fact and adversary claim stay in separate sentences.
The scoring instrument and the collection tradecraft behind these read-outs are house-proprietary and are not detailed here. What is published is the result and its meaning, at a tearline depth.
Mechanically sound, politically contested
The system that certifies U.S. elections is intact. The system that legitimizes them is under sustained strain. The dominant new variable for 2026 is the disposition of state force around civic life, set against a defensive posture cut at the moment of need.
One-sentence judgment. It is likely (55 to 80%) that 2026 produces localized intimidation, at least one AI deception referencing voting, and one or more certification disputes, while a systemic breach of the count remains unlikely (20 to 45%). Confidence moderate, bounded by four structural gaps.
Fact and adversary claim kept in separate sentences. Presence of a capability is never scored as persuasion.
Electoral Integrity Threat Index
A construct, not a measurement, published with its parts. Foreign election-nexus, relative U.S.-surface estimate: .
| Component | Wt | Score | 0-100 anchor |
|---|
How to read: the ring fills to the composite score, higher is more adverse. The rows above are the weighted components and the line is the arithmetic that produces the index.
STEMPLES stress by dimension
Collection maturation, six rounds
Likelihood and confidence, kept separate
Ten vectors, graded
Vector risk matrix · likelihood by impact
Satellite, alt-right, and PIR-9
Satellite / GNSS
No documented GNSS manipulation of a U.S. election system (gap). Starlink is poll-book connectivity, not tabulation. 2020 flip claims assessed false, held as pre-bunk. Recurrence very likely (80-95%); an actual GNSS event very unlikely (5-20%).
Alt-right ecosystem
America First and Groyper network as an online influence vector distinct from physical presence. Electoral-denial amplification and harassment of officials documented. Foreign-nexus link is a gap.
PIR-9 state-actor
Executive-branch actions consolidated: counter-influence capacity, threat prosecution, federal-force near sites, voter-data and citizenship policy, pressure on officials and vendors. Discrete actions, not a single master plan.
Directed op, convergence, or domestic dynamic
| Evidence | H1 Directed foreign | H2 Convergence | H3 Domestic + state |
|---|---|---|---|
| Verbatim foreign-to-U.S. reposting | + + | + | 0 |
| Only paid Tenet link proven | – – | + | + |
| No shared cross-network infrastructure | – – | + + | 0 |
| Measured vote effect null | – | 0 | + |
| Defensive collapse is domestic policy | 0 | + | + + |
| State-force deployments domestic, public | – | + | + + |
| Verdict | Rejected | Most consistent | Strongly supported |
H1 rejected: no shared infrastructure, one proven control link, null measured effect. Weight on independent convergence plus domestic and state-driven dynamics. Confidence moderate.
How the risk emerges, and what we estimate
The systemic risk here is emergent. No single actor produces it. It arises from five components that interact and reinforce each other, and it is the interaction, not any one part, that sets the level.
The emergence mechanism
Five components
Cheap AI synthetic capability. A hollowed federal defense. A laundering seam that converts foreign or fringe content into domestic-seeming speech. The disposition of state force around civic sites. A depressed, partisan-asymmetric trust baseline.
Three feedback loops
Trust erosion drives certification friction, which drives further trust erosion. Defensive cuts lower detection, which raises perceived impunity, which invites more activity. Laundering builds domestic ownership, which frustrates attribution, which invites more laundering.
Tipping conditions
The system moves from managed erosion toward contested certification when a decisive-county refusal, a tally-moment deepfake, or federal force at a site couples with the low trust baseline. These are the tripwires modeled on the Foresight tab.
Consolidated estimate
It is likely (55 to 80%) that 2026 produces localized intimidation, at least one AI deception referencing voting, and one or more certification disputes. A systemic breach of the count is unlikely (20 to 45%). Trust stays depressed, very likely (80 to 95%). Confidence moderate across the set, bounded by four structural gaps that open collection cannot close.
Predictions and accountability
The estimate is committed to six dated, falsifiable predictions on the Forecast Tracker, each with a resolution date and a Brier scoring plan. The intent is a scored track record, so the assessment can be graded rather than merely believed.
Assumptions, and what would break the theory
The emergence theory assumes the paper-and-audit backstop holds, that courts keep treating certification as a ministerial duty, and that no foreign actor gains witting control of a large organic domestic channel. It would be falsified by a disclosed outcome-altering intrusion of the count, by courts permitting discretionary certification refusal, or by proof of foreign direction of a major organic amplifier. Any one of those forces a rewrite, not a patch. Confidence in the emergence model is moderate.
Computed cone, fire a tripwire
Posterior is proportional to prior times a per-scenario likelihood ratio, then normalized. Toggle tripwires to update the weights live.
How to read: bars are the current scenario weights. Firing a tripwire multiplies the prior by a per-scenario likelihood ratio and renormalizes, so one switch moves all four weights; the arithmetic prints below the bars.
Falsifiable, dated, scored
| ID | Forecast | p | Resolves | Outcome | Set |
|---|
What to do, and where the edge is
Defensive, non-operational, and prioritized. Recommendations are ordered by marginal value for a state or county principal. Opportunities are strong points where the defender is already ahead or the adversary is weak.
Recommendations
| Priority | Action | Owner | Trigger |
|---|---|---|---|
| 1 | Put the marginal security dollar on tabulation and canvass venue integrity, not broad content takedown | SoS / county registrar | Before ballots print |
| 2 | Stand up a first-seen-origin watch on the captured channels; measure who posts first, not who posts loudest | Analyst cell | Now |
| 3 | Pre-position sourced rebuttals for the recurring machine-flip and satellite-flip narratives; publish on first sighting, not after spread | Comms | Pre-election |
| 4 | Backfill lost federal monitoring through a state information-sharing memorandum or a paid equivalent service | State | This quarter |
| 5 | Pre-brief counsel to enforce the ministerial certification duty at known chokepoint boards | Legal | Pre-certification |
| 6 | Activate an officials-protection protocol for the documented harassment surge | Security | Now |
Opportunities
Lead with the defended count
The paper and audit backstop is broad and the count is mechanically sound. Saying so plainly and early is the strongest single move against delegitimization.
Deny oxygen, not just content
The adversary model ranks patience above fabrication. The strongest defense is starving real domestic friction of the amplification the operator is counting on.
Own the tally moment
Detectors are weak in the wild, but provenance signaling plus a fast human correction still works at the one moment a deepfake would matter most.
Unlock the private corpus
A post-level export of the captured channels turns the wired authorship and origin-timing pipeline into a product no one else can produce.
Lean on the courts
Every reviewed case holds certification ministerial. That is a reliable legal backstop to pre-position around, not a hope.
Coalition backfill
State memoranda can replace much of the lost federal sharing at modest cost, and the window to sign them is open now.
One customer, one date, one flip
Built from real observed edges
How to read: node size grows with connections and color marks the movement cluster. Orange lines are observed forwards from the source hub. Teal lines mark channels that share an identical automated preview string. Hover any node for detail.
Shared-template co-activity
Method wired, sample flagged
The real authorship run lives on the Corpus tab. This harness shows the method on the list-capture previews, which are below the reliable floor.
What a rational operator does
Transparent expected utility: EV = p_success x damage minus attribution_risk x penalty minus cost, plus a small reach term. A model, not a claim about intent.
| # | Option | p_succ | damage | attrib | cost | EV |
|---|
Every judgment challenged
| Judgment | Devil's-advocate challenge | Survives? |
|---|
Four real channels, the origin chain, and a cross-channel matrix
The chain, measured end to end
The typology finding
Cross-channel authorship matrix
Fingerprint store
Function-word matrix and clusters
Burrows Delta over a 120-word function-word list, reposts stripped before attribution. Lower Delta means closer authorship. Cluster count chosen at the largest gap in merge distances.
How to read: each cell is the stylistic distance between two channels, darker teal meaning closer authorship. Colored dots group the channels the method judges to share an author, which is distinct from sharing content.
Sample adequacy gate
The laundering trace
Origination profile
Cross-channel content units
Coupled posting rhythm
| Channel A | Channel B | Pearson r |
|---|
Export to findings in one command
In Telegram Desktop, export each channel as JSON. Lay them out one folder per channel:
corpus/ Patriot Front/result.json Patriot Front Sightings/result.json Qanon Q17/result.json ...
Then run INSURRECT_CORPUS=corpus python3 insurrect_corpus.py. The same code produces a real authorship matrix, real origin timing, and real cadence over the captured channels. The synthetic banner disappears when real text is present.
Backtest against 2020, 2022, and 2024
The scenario model was run backward on three real cycles. For each, the documented record set which tripwires fired; the model produced a posterior; the top scenario was compared to what actually happened; and the set was scored.
What the backtest actually found
One win, one honest failure, one fix. The model correctly kept Infrastructure Shock near zero in all three cycles, which matches the record: no disclosed outcome-altering breach ever occurred, and the 2016 Illinois registration compromise remains the reference case for a disclosed successful intrusion. The model also correctly flagged 2020 as the highest Contested-Certification cycle.
The failure: as originally tuned, the certification-refusal tripwire is too strong. It pushed Contested Certification to about 50 percent in 2020 and 2022, when the count actually held and the realized outcome was Managed Erosion. Original argmax hit rate was 1 of 3.
The fix emerges from the data, not from taste: cutting the certification-refusal likelihood ratio from 3.0 to 1.8, and adding a severity gate that separates a resolved county refusal from a systemic scheme, makes the model call all three cycles correctly while keeping Contested Certification appropriately elevated in 2020. That is the difference between a number and a track record.
Posterior, model call, and what happened
| Cycle | Tripwires fired | Posterior (ME / CC / RH / IS) | Model call | Actual | Result |
|---|
ME Managed Erosion, CC Contested Certification, RH Resilient Hold, IS Infrastructure Shock. Actual outcome for every cycle was Managed Erosion, since every count held and was certified. 2020 came closest to Contested Certification through the fake-elector scheme and January 6, but the certification completed.
The correction the record forces
Same three cycles, same fired tripwires, certification-refusal likelihood ratio reduced from 3.0 to 1.8. The model now calls all three as Managed Erosion, with Contested Certification held as the elevated second scenario in 2020 and 2022.
| Cycle | Recalibrated posterior (ME / CC / RH / IS) | Model call | Actual |
|---|
Both versions beat the coin-flip baseline of 0.75. Mean Brier improves from 0.52 to 0.37 after recalibration. The lesson is specific and carried forward: certification drama that gets resolved by courts is weak evidence for a genuine certification crisis, and the model now treats it that way.
Which fired, which did not, and why
| Tripwire | 2020 | 2022 | 2024 | Basis, paraphrased from the record |
|---|---|---|---|---|
| Armed force at polls | no | no | no | State National Guard was activated in support and cyber roles in 2020 and 2024, but per every responding state not stationed at polling places. Texas expressly ruled out any polling-place role in 2020. |
| Viral deepfake at the tally | no | no | yes | The January 2024 New Hampshire AI robocall imitating President Biden, plus federally attributed Russian fabricated videos in late October and early November 2024. Nothing comparable in 2020 or 2022; consumer generative AI arrived only in late 2022. |
| Certification refusal at the general | yes | yes | no | 2020 fake-elector slates and the Wayne County board reversal; 2022 the Cochise County refusal, certified under court order. In 2024 the refusal risk sat in the primaries and pre-election rule fights, and the general-election certification was clean. |
| Swing-state intrusion disclosed | no | no | no | No disclosed successful, outcome-relevant intrusion in any of the three cycles. Federal officials stated repeatedly that no votes were changed. The 2016 Illinois registration breach remains the reference baseline. Attempts, scanning, and a campaign hack are not the same as a disclosed successful breach. |
| Federal monitoring intact | yes | yes | yes | CISA, EI-ISAC, MS-ISAC, and the FBI task force were fully staffed across all three cycles. This stabilizer is the single most important change for 2026, since it was cut in 2025. |
Sources paraphrased from CISA and ODNI and FBI statements, the FCC robocall enforcement actions, state court certification orders in New Mexico and Arizona, and Gallup, Pew, and MIT trust series. The one specification-sensitive call is the certification tripwire: score it at the general-election stage, not the primaries.
The Condor question, answered
Is there a single thread anywhere, in any language, that lays out the full line from an information operation to an electoral takeover, the way a reader might extrapolate a war plan from a novel? The short answer is no. There is no unified master text. What exists is a modular literature: state military theory, investigated commercial playbooks, and academic taxonomies, each supplying a different piece, and none assembling the whole. This annex maps them so a defender can watch each stream on its own.
Descriptive and defensive only. This annex characterizes what already sits in the public record. It does not assemble the pieces into a usable method, and it reproduces no operational content.
Theory, mostly written to be defensive
Russian reflexive control
The theory, from Vladimir Lefebvre in the 1960s and later Chekinov and Bogdanov, is about feeding an opponent prepared information so that his own reasoned choice serves the initiator. Applied to an electorate, it means shaping the perceived choice-set so a population picks the manipulator's preferred outcome on its own. Timothy Thomas gives the standard English account.
Russian political technology
Andrew Wilson's Virtual Politics is the reference work. Practitioners such as Gleb Pavlovsky and Vladislav Surkov build a whole staged system of fake parties and phantom opponents and captured media, so democratic form is observed while real choice is hollowed out. Surkov's sovereign democracy is the ideological arm.
The Gerasimov misnomer
The so-called Gerasimov doctrine is a Western label its own coiner, Mark Galeotti, later disavowed. Gerasimov's 2013 article was a description of what Russia believed the West was doing through the Arab Spring and color revolutions, not an offensive playbook. It matters because it is routinely mischaracterized.
Chinese Three Warfares
Public-opinion, psychological, and legal warfare are codified in the PLA political-work regulations, with a newer concept of cognitive domain operations aiming at command of the mind. Taiwan is the documented target, including deepfakes during its January 2024 election.
Iranian activity
Documented through vendor disclosures rather than a published doctrine. Storm-2035 used language-model accounts to seed articles and comments on United States candidates on both sides, rated low impact. Iran-linked actors also phished a 2024 presidential campaign. Note that Storm-1516 is Russian, not Iranian, a frequent conflation.
The through-line
Across these, the common logic is not to change the count but to shape the environment so a chosen outcome looks legitimate and inevitable, while an opponent's own choices are turned against him.
Where documented operational method actually lives
This is investigative and platform-takedown evidence, not published doctrine, and much of it is self-reported by operators with reasons to exaggerate.
Team Jorge and Tal Hanan
Exposed in 2023 by the Forbidden Stories Story Killers consortium. A former Israeli operative claimed involvement in dozens of national campaigns, using a fake-avatar management suite and account hacking to plant and then amplify material. Scope figures are the operator's own claims.
Cambridge Analytica and SCL
A military psychological-operations contractor lineage applied to civilian elections through psychographic microtargeting, built partly on tens of millions of harvested Facebook profiles. Documented by the whistleblowers and the United Kingdom Parliament. Independent scholarship treats its effect claims with caution.
Internet Research Agency
The Russian operation documented by the Mueller report and two United States Senate committee studies. A sustained cross-platform effort to polarize the electorate and depress specific groups, which exploited existing divisions rather than inventing them.
Archimedes and the hire market
An Israeli firm banned by Meta in 2019 for operations across several African elections, including a false-flag page to smear an opponent. Andres Sepulveda described, to Bloomberg, hacking-and-bot campaigns across nine Latin American countries for a Miami-based strategist. Both illustrate a mature disinformation-for-hire market.
The newer AI-enabled networks
CopyCop used language models to plagiarize, translate, and re-bias content across hundreds of fake sites. Spamouflage and Doppelganger are the documented Chinese and Russian analogues. The cost of entry is falling.
The pattern
The vendor market supplies the concrete methods the doctrine only theorizes: fake amplification, account compromise, and laundering of content into legitimate outlets, sold as a service.
Diagnostic taxonomies, written for defense
How democracies erode
Levitsky and Ziblatt describe elected leaders capturing referees and breaking unwritten norms. Nancy Bermeo names the modern forms: executive aggrandizement and strategic manipulation, the slow legal tilt rather than day-of fraud. This is the best-cited account of how the process actually runs.
How elections are rigged
Cheeseman and Klaas set out six techniques, from gerrymandering and vote-buying to hacking and fooling observers, and note the paradox that holding a rigged election can prolong a ruler's survival. The book is framed as a handbook for observers.
The authoritarian playbook
Protect Democracy synthesizes the scholarship into seven shared tactics, including politicizing institutions, spreading disinformation, corrupting elections, and aggrandizing the executive. Applebaum's Autocracy Inc adds the networked, transnational dimension.
Coups and self-coups
Naunihal Singh models coups as a coordination game won by projecting inevitability. The self-coup, or autogolpe, is a sitting executive seizing power and shutting other branches. Edward Luttwak's practical handbook is the classic that reads as a literal manual.
Color-revolution counter-doctrine
Russian and Chinese military science genuinely treats Western election and democracy promotion as itself a covert takeover method, named as color-revolution technology. Because they believe this sincerely, they justify their own interference in Western votes as defensive. Watching their military-science journals for this framing gives forward warning of escalation. Surkov's sovereign democracy is the domestic ideological answer to the same perceived threat.
The direct Condor parallel
The clearest case of a novel treated by a real movement as an operational blueprint is a piece of insurrection fiction that researchers tie to numerous attacks. It is documented here only as researchers characterize its role, with no operational content. The point for this question is the boundary: that case is about violent insurrection, not electoral takeover. There is no comparably documented novel that functions as an election-takeover blueprint, which is itself part of the answer. The true non-fiction analogue for seizing or defending power is the pairing of Luttwak's coup handbook and, inverted for liberation, Gene Sharp's list of nonviolent methods, which authoritarian states then re-read as a regime-change manual.
Modular, not unified
The finding
No single thread runs the whole length. Doctrine supplies the theory, the vendor market supplies the methods, and the academic taxonomies supply the diagnosis, but no public text joins them into one operational plan. The absence is itself the answer to the question.
How a defender uses this
Map threats along three separate axes and assess each on its own: theory such as reflexive control and the Three Warfares, commercial vendors of the Team Jorge kind, and the diagnostic taxonomies. Use the academic checklists as the defensive instrument. Treat operator scope claims as claims, since efficacy is far weaker than the sellers assert, and remember that these operations mostly exploit existing division rather than manufacture it.
THE FORENSIC FOOTPRINT
Three ways people tried, and got caught
Between 2018 and 2026, state and federal agencies investigated, charged, and convicted operatives, circulators, and officials who tried to manipulate elections. The cases sort into three types. None altered a national outcome. Administrative verification caught most of them before certification.
Commercial signature forgery
Pay-per-signature contracts without verification controls, so subcontracted crews forge sheets in bulk. Michigan 2022. Lincoln, Nebraska 2026.
Absentee harvesting and drop-box tampering
Operatives insert themselves into the chain of custody between voter and ballot box. North Carolina. Bridgeport. Paterson.
Insider system compromise
Sworn officials use their credentials to bypass access controls and copy voting software. Mesa County. Coffee County.
The trail, 2018 to 2026
Absentee harvesting sets aside a House result
Election-night tallies showed a 905-vote Republican lead. The state board found statistical anomalies in absentee returns and refused to certify. Operative Leslie McCrae Dowless, hired through a campaign consulting firm, ran an illegal ballot-collection operation.
An all-mail council election unravels
Audits flagged bulk mailings from single mailboxes and residents who never received the ballots recorded in their names. The state charged a council president and a councilman.
Two insiders open the doors
In Coffee County, Georgia, a local supervisor let an outside forensics team copy Dominion software on January 7, 2021. In Mesa County, Colorado, the clerk used another person's credentials to admit an unvetted third party during a trusted-build update, and the images later appeared online.
A signature ring knocks candidates off the ballot
Two firm owners took more than 700,000 dollars from campaigns and delivered tens of thousands of forged sheets. Inspectors caught full pages in identical handwriting and names of deceased voters. Five Republican gubernatorial candidates and three judicial candidates were disqualified.
Drop-box footage forces a redo
Security video showed a town-committee official dropping thick stacks of absentee ballots into a City Hall drop box. A judge invalidated the Democratic primary and ordered a court-monitored redo.
Paid circulators, caught by hand-verification
Three petitions to amend Lincoln's charter drew more than 30,000 signatures. Hand-verification rejected most of them and flagged more than 13,300 as fraudulent. Investigators placed the circulators' phones in the county when the sheets were signed.
The detection funnel
The safeguard worked exactly as designed. Every signature was checked against the voter file by hand, and the fraud collapsed before a single measure reached the ballot.
What the courts handed down
Where the risk lives, and what closes it
| Vector | Risk mechanism | Primary detection | Safeguard response |
|---|---|---|---|
| Commercial petition canvassing | Pay-per-signature incentives drive bulk forgery and false affidavits | Automated signature matching, voter-roll address cross-referencing | Bans on per-signature pay, mandatory registration of third-party firms |
| Absentee ballot processing | Unlawful third-party harvesting, drop-box stuffing, witness forgery | Drop-box video, signature verification, postal tracking | Restrictive return laws, drop-box surveillance, chain-of-custody tracking |
| Electronic voting access | Insider compromise of software, password leaks, physical trespass | Trusted-build integrity checks, access logs, security footage | Dual-person access, state oversight of updates, mandatory video logging |
The count held
Across seven jurisdictions and eight years, deliberate fraud left a forensic footprint every time, and administrative verification caught it before a national result turned on it. The disruption landed on primaries, local initiatives, and municipal contests. The verification wall held, and the schemes ran into courtrooms.
Read the full analysis · Managed Erosion