The same system, run under two different mandates.
Freya Sense gives defense, intelligence and civilian institutions the means to intercept adverse influence operations before they land, and to set a tempo the adversary cannot match.
Below are two engagements, described end to end. One ran under a defense mandate, against a live hostile operation. The other ran under a civilian mandate, against an operation that had already reached its audience.
Freya Sense is a dual-use platform. It serves the offensive mandates held by defense and intelligence institutions and the strictly defensive mandates held by civilian entities. The distinction and guardrails sit inside the beneficiary's legal mandate.
Each deployment is mandate driven.
Freya Sense is dual use, and the same engine sits behind both paths. A defense or intelligence institution mandated for it can use the full capability, for example to disrupt a hostile foreign operation. A civilian entity runs strictly defensive capabilities, protecting the integrity and autonomy of its own audience.
Below is a comparison between engagements under different mandates.
| Defense and intelligence | Civilian entities | |
|---|---|---|
| Mandate owner | Defense or intelligence institution | Counter-disinformation initiative under a presidential administration |
| Operational limits | Both offensive and defensive capabilities | Strictly defensive capabilities |
| Configuration | We provided the input from open source data | The institution provided the input data and decided what to disseminate as counter-narrative |
| Deliverables | Target Audience Analysis and offensive campaign ready for dissemination | Toxic narrative diagnosis and counter-narrative campaign |
Taking back the initiative and preparing a counter-offensive.
NATO Allied Command Transformation opened an Innovation Challenge for agentic AI in cognitive defense. It named the work cycle it wanted closed, understanding, planning, coordination, delivery and assessment. It named who the campaigns would address. And it named six effects a submission had to be able to produce against them. These became our mission parameters:
Weaken the adversary's military strength and disrupt support networks
Damage the credibility and authority of the adversary's senior leadership
Slow decisions and complicate the rollout of the adversary's communications
Fragment internal unity and erode confidence in the adversary
Impair the adversary's effectiveness in reaching and influencing their target audiences
Create false perceptions of NATO's plans and operational intent
Challenges, and how we approached them at a tactical level
The effect of a narrative cannot be anticipated before it is disseminated.
Every proposal carries the reasoning that produced it, back to the evidence. Any step can be opened and checked, so what an operator signs off is defensible to whoever audits it later.
Existing personnel operate it after minimal training, because the system carries the argumentation for every step. A skeleton crew is enough, and every decision it produces is supported by validated methodology.
Tactical debriefing
The operation ran between 23 March and 17 April 2026. Russian-origin drones entered NATO airspace three times inside that window, once in Lithuania and twice in Romania, and Kremlin-aligned media turned those incidents into a single narrative: that Lithuania, Latvia and Estonia had opened their airspace to Ukrainian drones.
The narrative was built to turn Russian audiences against the Baltic members of the alliance. It started on a Telegram channel, moved through six aligned outlets inside 48 hours, took state endorsement at a foreign ministry briefing on 6 April, and escalated on 16 April to an invocation of Article 51.
Organize the discourse by narrative, flag coordinated activity while it is still forming, and read what the operation is built to do if it lands. Our systems caught the surge and its coordination signature: one narrative moving through six aligned outlets inside two days, with nothing in the allied response reaching the audiences it was aimed at.
Decode every story, every angle and every shift, as it happens.
Uncover adversary objectives, and what an operation will do if it lands.
Profile the actors and the audience, build the Target Audience Analysis, and name the behavior an intervention has to produce and in whom. We ran the same model backwards over the adversary's messaging. It gave up what the campaign was built to do, and where it was weak: the narrative blamed the Baltic states while two of the three incidents had happened in Romania.
Profile audiences at scale and create the Target Audience Analysis.
Profile target individuals.
Connect the objective to the desired outcomes and then design the messaging, by channel and by segment, and simulate the audience response before anything is committed. Four counter-campaigns were developed in parallel, from amplifying the allied messaging that was not landing to reframing the narrative against the physical record of where the drones actually came down.
Design interventions calibrated to shift attitudes and behaviors.
Simulate the audience response before deployment.
Variants stage for approval. The tool never transmits, and an authorized person delivers an approved message. Drafting ran under analyst review throughout, and nothing was transmitted at any point.
Orchestrate end-to-end campaigns based on validated frameworks.
Compare what was predicted against what the adversary narrative did next. The reporting feeds back into Observe, carrying what the effects were on audience attitudes and how the narrative moved behavior.
Watch how your campaign influences the narrative dynamic.
Update the Target Audience Analysis using fresh observations.
One of the top 10
Agentic AI for Cognitive Warfare, NATO ACT Innovation Challenge 2026-1
Rennes, May 2026
Evaluated by NATO ACT
Countering a live operation against a national strategic program.
Two toxic narratives were identified by a counter-disinformation program under the high patronage of a presidential administration. Both attacked a financing instrument behind a strategic defense program, and both had already gained traction at national level. We prepared a diagnosis of the effect each narrative was built to produce, and proposed counter-narratives calibrated to the intended audience.
Challenges, and how we approached them at a tactical level
An institution can watch a narrative spread. What it cannot see is how that narrative is shifting attitudes and behaviors, or what counter messages would shift them back.
The deliverables we handed over had to work without us, on a deadline set by an operation that was still running. A counter-narrative a client's own creative team will not use is worth nothing.
Diagnose the effect, then calibrate to it. Each narrative was decomposed into the emotional and cognitive levers it pulls, with the points where it is structurally weak highlighted. The counter-narratives were written and pre-validated against a behavioral model of that specific audience, so the counter-campaign's effectiveness potential was justified down to individual level for the intended audience.
Tactical debriefing
The same loop as the defense case, run defensively against two disinformation narratives, and paced by workshops with the client.
From public data, surface how each narrative is spreading. A strategy workshop agrees which two to answer and what the program is protecting.
Decode every story, every angle and every shift, as it happens.
Diagnose each narrative: the effect it seeks, the factors it uses, and its weak points, read against an existing model of that specific audience. We ran both narratives against a behavioral model of that audience that we had already built, so no individual was profiled for this work.
Uncover adversary objectives, and what an operation will do if it lands.
Profile audiences at scale and create the Target Audience Analysis.
Design counter-narratives calibrated to the intended audience, check which of them will move it and pick the most effective. A debrief workshop argues the diagnosis with the people who own the problem, allowing an informed decision.
Design interventions calibrated to shift attitudes and behaviors.
Simulate the audience response before deployment.
Three counter-narratives per narrative, ready for production. Each is a proposal the client can reject. Publishing stays with the client, and Freya never transmits. Their creative teams and ours worked the counter-narratives into complete campaigns, at the pace the operation was setting.
Orchestrate end-to-end campaigns based on validated frameworks.
14
Counter-messages produced by the national team in under a day
Twice
The reach of the operation being countered
"We used Freya to understand and create counter-narratives to an information operation aiming to discredit [a national defense program]. Freya enabled us to create 14 counter messages in less than a day, speeding up significantly our response mechanism. The videos made with Freya's support reached twice as many people [...] than the information operation we were countering."
How both engagements were governed.
Both engagements ran under precise governance, and the same lines applied to each. What separates them is the standards, the laws and the chain of command that fill those lines. Different people audit a defense mandate, different people verify it, and different people decide.
On the defense path every decision landed in an immutable audit log against a named operator and a time, with approvals granted by role. On the civilian path the equivalent record was the workshop trail: the diagnosis was argued and agreed with the people who owned the problem before a word was drafted.
Every proposal carries the reasoning chain that produced it, back to the evidence. In the demonstration that also meant separating what was observed from what was simulated in response.
Kill switches sit at campaign level and at system level, and analyst override is absolute. On the civilian path the control is a different one: we never transmitted, never posted and never held an account, so every decision to publish stayed with the client.
The defense submission was built against the alliance's labelling, binding and assurance standards, named in the FAQ below. Bias is handled through source-class weighting, ensemble classification and a closed vocabulary that constrains anything a language model is allowed to emit.
What institutions ask first.
Can the system act on its own?
No. The tool never transmits. Every variant stages for approval, and delivery is a separate action taken by an authorized person on an approved message.
The behavioral judgment is deterministic and sits outside the language model. Generative AI phrases what has already been decided, and never decides anything.
What decides how far the system can go?
The mandate of the institution running it. Rules of engagement and ethical thresholds are configuration, set by an administrator before any work begins, and an operator cannot widen them from inside the tool.
What keeps the civilian path defensive?
That configuration, plus the limits we hold ourselves to, which no setting relaxes. On the civilian path the work runs on public data, brings what is true to the surface, and leaves every act of publishing with the client.
Can it run where our data cannot leave?
Yes. The defense engagement ran inside a national enclave with no external connection. Three deployment topologies were costed for that submission: connected, air-gapped and federated.
Do we have to take the whole stack?
No. The five systems are modular and integrate at the boundary you choose. Take one, or run all of them, and what deploys is built around what you already have.
What data does it use?
On the civilian path, public data only, and nothing is inferred about individuals. In defense deployments the system operates where the data has to stay.
What standards is the defense work held to?
NATO's Principles of Responsible Use for AI, PO(2024)0199, which the challenge itself named. The submission answered all six: lawfulness, accountability, explainability and traceability, reliability, governability and bias mitigation.
On top of that we built to STANAG 4774 and 4778 for labelling and binding, and to AQAP 2110 and 2210 for the assurance regime.
Who is accountable for a decision?
A named person. Approvals are role based, the drafter is never the approver, and every decision is logged against a role and a timestamp.
What state is the product in?
In continuous operation since early 2026, with defense and civilian engagements already run. The live demonstrator reads over 3000 sources, and other deployments run inside air-gapped national enclaves.
The next step is a private briefing.
Both engagements above started the same way, with an institution describing the mandate it already held and the operation it was facing. Bring us yours and we will show you how we can help.