the idea behind aegis is one sentence. you do not learn to resist manipulation by reading about it; you learn by being manipulated, in a safe room, by something that is genuinely trying, and fighting your way out. so aegis gives you an adversarial ai whose job is to persuade, pressure and mislead you, and your job is to catch it in the act. you spar with the thing you are learning to resist.
i am publishing this now, but the idea is not new to me. i started building aegis in 2025, when "manipulation literacy" was not a phrase anyone was procuring and an ai you fight to get better was not a category. that is rather the point of putting a date on it. the world has since arrived at this problem from three directions at once, and i want the record to show where i was standing when it did.
why fighting works, and it is not my theory
the mechanic rests on something older and far better evidenced than anything i could claim: inoculation theory. the psychologist william mcguire proposed it in the 1960s as a "vaccine" against persuasion. expose someone to a weak, survivable dose of a manipulation technique, with a forewarning, and they build resistance to the full-strength version later, including versions they have never seen. it is the cognitive equivalent of a jab.
the modern, gamified form is well studied. cambridge researchers, jon roozenbeek and sander van der linden, built browser games such as bad news, where players take weakened doses of misinformation tactics and come out measurably better at spotting them, across languages and cultures. the lesson from that body of work is specific, and it shaped aegis: teach the technique, not the example. someone who has learned to feel the shape of a false-urgency play, a fabricated consensus, or a foot-in-the-door, can catch a brand new instance they have never seen before. example-based training ages; technique-based resistance transfers.
so the science says active, experiential, technique-level, with a real adversary in the loop. that is the whole design brief for aegis.
what aegis does that the games did not
i want to be precise about the claim, because precision is what makes it credible. i did not invent inoculation, and i did not invent the manipulation-resistance game. the misinformation games are excellent and they came first.
what they do not do is fight back. they are scripted: you step into the manipulator's shoes and follow a written scenario. aegis inverts it. the adversary is a live ai, you are the target, and it adapts to you in real time, the way a real manipulator does. it finds the pressure that works on you specifically and leans on it, and you learn under live fire instead of on rails. it is also not confined to political misinformation. it trains general manipulation literacy: the sales close, the scam, the dark-pattern checkout, the social-engineering pretext, the emotionally loaded ask. a live, adaptive adversary pointed at the full surface of everyday manipulation. that combination is the thing i was early on.
the world caught up, from three sides
three things have happened since, and all of them landed after the idea, not before it.
the threat went industrial. ai turned manipulation from a craft into a scaled, automated product. deepfaked executives now authorise wire transfers (one widely reported video call cost a firm around $25 million, every participant on it synthetic except the victim); ai-written phishing and cloned-voice calls run at volume; fraud involving synthetic media has climbed by orders of magnitude in a couple of years. the manipulator is increasingly an automated system that never tires, which is precisely what aegis trains you to recognise, because it is precisely what aegis is.
the market named it. what was a vague idea is now a procurement line. through 2025 and 2026, enterprises are buying ai social-engineering awareness, deepfake-resistance training, and ai red-team exercises run against their own staff. security leaders have started naming ai, ahead of ransomware, as their top concern. "can my people resist an ai that is trying to trick them" became a budget item.
the literature followed. only in 2026 are academic ai-literacy frameworks being built explicitly on inoculation theory rather than on knowledge transfer, with trust calibration as the core skill. the formal taxonomies of ai persuasion, manipulation and coercion are 2025 work. the research is now writing down, carefully and with citations, the thing aegis was already doing.
i am not claiming the field copied me. i am claiming i was building the same answer before the question became fashionable, and that is worth a timestamp.
it is the other half of the dark patterns problem
if you have read the piece on dark patterns, this is the matching half. that one catalogues the manipulation: who does it, how it works on the brain, what it costs. aegis is the countermeasure at the level of the person. you cannot regulate every deceptive interface fast enough, and you cannot label your way out, the research is blunt that telling people "this is ai" does not blunt its persuasive pull. the durable defence is a person who can feel the manipulation as it happens. that is a trainable skill, and the way you train it is to fight something that is good at it.
the grown-up version of a priority claim names what came before. inoculation theory is sixty years old. the misinformation games predate aegis. my contribution is narrower, and i think it holds: a live, adaptive ai adversary you spar with to build general manipulation literacy, built as a product before the enterprise market and the academic literature arrived at the same place.
first published june 2026. the idea is older. that is the point.
aegis is live for individuals (for now), with team and enterprise training rolling out soon. try it, or talk to us about it. and the manipulation it trains you against, out in the wild, is here.