Executive Summary

The whole argument in nine minutes, for people who decide things, and for everyone who would rather start at the end.

The threat artificial intelligence poses to democracy is not the one the movies sold you. It is quieter: persuasion you can tune, and administration you can capture without anyone noticing. One machine writes a different, optimized argument for every voter, better each model generation. Another is wired into the daily work of the state, deciding claims and drafting the answers citizens get from their government, reconfigurable overnight.

In four parts. Part 0, The Oldest Warning: the trial of Socrates as democracy's founding failure mode, and the numbers behind its spread and retreat. Part I, The Record, is sourced history, 2023 to 2026: the deepfake that hit Slovakia inside its pre-election silence, the cloned Biden robocall in New Hampshire, the Romanian election annulled after an algorithmic surge, a chatbot system prompt edited overnight, the first AI seated at a cabinet table, the finding that frontier models now out-persuade humans. Part II, The Scenario, extrapolates those forces from mid-2026: a democracy formally intact while its powers route through systems a handful of people can adjust. A quiet coup, no tanks, just a government whose load-bearing functions answer to a tuning panel. Part III, The Epilogue, runs the same years with the defenses built in time, from 2034. Proof that the outcome was a choice.

The gap between Part II and Part III is a short list, most of it to be decided before 2028.

  1. Make provenance the default for political content. Do not try to prove what is fake; require the opposite: a signed, tamper-evident record of origin, the existing C2PA standard. Under the Digital Services Act, make unsigned political advertising unrunnable. A chain-of-custody machine, not a truth machine.
  2. Require spec transparency and behavioral audits for any state-deployed model. The public must read its spec, including the system prompt that silently governs every reply, and audit whether it behaves as claimed. A silent lever of power becomes a diff with a timestamp and an author.
  3. Draw bright lines on individualized political persuasion. Aiming a machine-tailored argument at a named person is a dual-use hazard: require a capability evaluation before deployment, and ban individually optimized political messaging not disclosed to its target.
  4. Build civic AI, and adopt AI in government only with accountability attached. Fund public-interest models that summarize legislation both ways and surface disagreement. Where the state uses AI, one rule holds: a machine may recommend, but a human signs, and every decision can be appealed to a person who can be named.
  5. Fund the defense at a fixed fraction of what is spent on AI itself. Detection research, journalism, provenance infrastructure, and AI literacy are starved next to the sums flowing into capability. Peg it to a fixed percentage of investment in AI, so the defense scales as the offense does.

The reason to act before 2028 is not alarmism but sequencing: every defense is far cheaper to install before the systems are load-bearing than to retrofit after. The branch is genuinely open, and it is short.