How a 2016 law aimed at foreign propaganda became domestic content-moderation infrastructure — the Global Engagement Center, the Global Disinformation Index, the funding ecosystem, the revolving door, and the EU Digital Services Act that exported the model.
Contents 83 sections

1. Legislative Origin: The Countering Foreign Propaganda and Disinformation Act (2016)

On December 23, 2016, President Obama signed the National Defense Authorization Act for FY2017, which included the Countering Foreign Propaganda and Disinformation Act (CFPDA). The bipartisan bill was co-sponsored by Republican Rob Portman and Democrat Chris Murphy. It authorized $160 million over two years and created the Global Engagement Center (GEC) within the State Department, tasked with countering foreign propaganda.

The key word is “foreign.” The legislation was a response to Russian information operations during the 2016 election. What followed was a decade-long mission creep from foreign propaganda countermeasures into domestic speech policing.


2. The Global Engagement Center (GEC)

Budget and Scope

The GEC operated with approximately 120 staff and an annual budget of $61 million. Its stated mission was countering foreign state propaganda.

Domestic Overreach

The GEC funded domestic and foreign organizations performing work in communications and technology, including projects to “identify and combat disinformation.” The State Department admitted in litigation to funding the Global Disinformation Index and NewsGuard through a middleman, Park Capital Investment Group.

Closure

The GEC’s legislative authority expired December 23, 2024. It was briefly reorganized as the Counter Foreign Information and Manipulation and Interference Office before Secretary of State Marco Rubio announced its closure in April 2025, stating it had “wasted taxpayer money and engaged in censorship.”


3. The Global Disinformation Index (GDI)

Funding

The GDI, a British-based nonprofit, received a combined $330,000 from two State Department-aligned agencies:

  • $230,000 from the National Endowment for Democracy (NED)
  • $100,000 from the Global Engagement Center (GEC)

What It Did

GDI produced risk ratings for news outlets and provided advertiser blacklists. Its methodology was straightforward: rate outlets on a “disinformation risk” scale and pressure advertisers to defund those rated high-risk.

The Bias

All 10 outlets GDI rated as “riskiest” leaned politically right. All but one of the 10 rated “least risky” leaned left. Outlets targeted included The Daily Wire, The Daily Signal, RealClearPolitics, The Blaze, One America News, The Federalist, Newsmax, The American Spectator, The American Conservative, and Reason.

Defunding

NED cut ties with GDI in 2023 after the bias was exposed. The UK’s Foreign Secretary David Cameron stated that FCDO had ceased funding GDI and did not plan to resume. In January 2026, Rep. Eli Crane introduced an amendment to defund NED entirely; it failed.

DEFAMATION NOTE: GDI’s bias in ratings is documented through its own published reports and confirmed by multiple independent analyses. NED’s defunding is confirmed by NED’s own public statement.


4. The USAID Disinformation Primer (February 2021)

The Document

A 97-page internal document marked “for internal use only,” conceived and developed by Joshua Machleder and Shannon Maguire at USAID, together with the University of Chicago’s National Opinion Research Center. Obtained via FOIA litigation by America First Legal after the State Department failed to respond to a FOIA request and was compelled by court order.

Key Content

  • Identifies “gaming sites” including Amazon-owned Twitch as “alternative spaces” from which “problematic information more regularly originates” than from state actors
  • Targets memes as disinformation vectors
  • Introduces the concept of a “right not to be disinformed”
  • Distinguishes three types of problematic information:
    • Misinformation: false information spread by those who believe it true
    • Disinformation: false information spread with intent to deceive
    • Malinformation: speech that is factually correct but deemed misleading or taken out of context
  • Recommends tactics including “prebunking” and “debunking and discrediting”

The Gaming Connection

The primer explicitly states that extremists can spread information on gaming platforms such as Twitch which “enable users to coordinate to grow followers and spread content to large social media sites such as Facebook and Twitter.” This is the federal government officially classifying gaming communities as a national security concern – the same communities that had been dismissed as a “harassment mob” during GamerGate.


5. CISA: From Cybersecurity to Speech Police

Mission Creep

The Cybersecurity and Infrastructure Security Agency (CISA), part of DHS, replaced its Countering Foreign Influence Task Force with a formal “Mis-, Dis-, and Malinformation” (MDM) team by 2021. The scope expanded from foreign election interference to domestic content of all kinds.

The Switchboard Function

CISA acted as a “switchboard” for content moderation requests. State and local officials flagged social media posts; CISA funneled the requests to platforms. The 5th Circuit Court of Appeals found CISA was the “primary facilitator” of the FBI’s interactions with social media platforms.

The Twitter Files

Internal Twitter documents released in 2022-2023 showed that agencies including the FBI, DHS, and CISA regularly sent content requests to Twitter’s Legal, Policy, and Trust & Safety teams, flagging specific accounts and posts for potential “disinformation” violations.

Court Action

In October 2023, a federal court barred CISA from making social media moderation requests, finding the government had likely violated the First Amendment.


6. The Stanford Internet Observatory and the Election Integrity Partnership

Formation

The Election Integrity Partnership (EIP) was created in the summer of 2020 “at the request of” CISA, according to the House Judiciary Committee. It was led by the Stanford Internet Observatory (SIO) and included the University of Washington, Graphika, and the Atlantic Council’s Digital Forensic Research Lab.

What It Did

The EIP monitored social media for “election misinformation” and reported flagged content to platforms. A House investigation found it worked directly with DHS and the GEC to monitor and censor Americans’ online speech.

The Virality Project (2021)

Stanford’s follow-up, the Virality Project, extended the model to COVID-19 vaccine content. The Twitter Files revealed that the Virality Project:

  • Explicitly flagged “true content which might promote vaccine hesitancy”
  • Encouraged Twitter to expand misinformation policies to include true reports of vaccine side effects
  • Targeted legitimate scientific research on natural immunity and breakthrough infections
  • Labeled factually correct content as “malinformation” if it might discourage vaccination

This is the documented moment when a federally-connected institution explicitly advocated for the suppression of true information.

Funding

SIO received a five-year NSF grant of $748,437 in 2021. Stanford maintains that no government funding was used for the 2020 election work or the Virality Project.


7. The “Malinformation” Concept

Definition

Malinformation is defined by DHS/CISA as information that is based on fact but used out of context to mislead, harm, or manipulate. It is the third category in the MDM (Mis-, Dis-, Malinformation) framework.

Significance

This is the concept that broke the system’s credibility. Misinformation and disinformation are at least nominally about false content. Malinformation is, by the government’s own definition, true. The creation of a federal category for “true but harmful” speech – and the funding of an entire institutional ecosystem to identify and suppress it – is the single most important development in the censorship infrastructure story.

The USAID Primer’s version

The USAID Disinformation Primer uses the same three-category framework. Its definition of malinformation: speech that is “factually correct but has been deemed misleading or taken out of context.” The primer recommends that USAID programs address all three categories.


8. The Funding Scale

USAID

USAID was the second-largest federal funder of anti-disinformation efforts. Analysis of nearly 1,100 awards found approximately 900 included awards with a total value of roughly $1.5 billion.

Other Federal Funders

The broader anti-disinformation funding ecosystem includes:

  • Department of Defense
  • State Department (via GEC, NED)
  • National Science Foundation (academic research grants)
  • National Institutes of Health (COVID-related)
  • Centers for Disease Control and Prevention

The Ecosystem

The funding created a self-sustaining ecosystem: federal grants funded NGOs and academic programs, which produced research classifying more categories of speech as harmful, which justified more federal funding to combat the newly-identified threats. Career incentives aligned with expanding the definition of “disinformation” – no researcher ever received a grant for concluding that a category of speech was harmless.


9. The Trust & Safety Professional Pipeline

Formalization

The Trust & Safety Professional Association (TSPA) formalized the career path between government, NGOs, and platform trust-and-safety teams. Its membership explicitly includes practitioners from “civil society, academia, or non-governmental organizations.”

The Revolving Door

The pipeline runs in both directions:

  • Government employees transition into platform T&S roles, bringing regulatory frameworks
  • Platform T&S employees move into government advisory roles, bringing content moderation norms
  • NGO researchers move between academia, platforms, and government, carrying the same frameworks across all three sectors

The result is ideological convergence across institutions that are nominally independent. The same people, applying the same definitions, rotating through positions at CISA, Stanford, Twitter, and NED, producing a monoculture of content moderation philosophy funded by federal dollars.


10. DOGE and the Unraveling (2025-2026)

USAID Dismantling

In January 2025, DOGE members entered USAID headquarters. The Trump administration subsequently:

  • Ended 83% of overall USAID projects
  • Sent Congress a rescissions package of $9.4 billion in cuts including foreign aid and public broadcasting
  • Targeted USAID for full closure by September 2026

Specific Findings

DOGE documented specific examples including $4.5 million spent to combat disinformation in Kazakhstan. Comprehensive documentation of specific anti-disinformation program cuts remains incomplete as of March 2026.

The Politico Connection

Government agencies collectively paid $8.2 million for Politico subscriptions and products in 2024 ($24,000 from USAID specifically). Politico had run extensive anti-GamerGate coverage. The Trump administration cancelled the subscriptions.


11. The GamerGate Connection

Timeline

The federal anti-disinformation infrastructure was being built simultaneously with GamerGate (August 2014 onward):

  • Dec 2016: CFPDA signed, GEC created
  • 2017-2019: GEC begins funding NGOs (GDI, NewsGuard) and academic programs
  • Summer 2020: EIP created “at the request of” CISA
  • Feb 2021: USAID Disinformation Primer written, explicitly targeting gaming sites
  • 2021: CISA MDM team formalized, Virality Project launched
  • 2022-2023: Twitter Files expose the infrastructure
  • 2024: USAID primer obtained via FOIA
  • 2025: DOGE enters USAID, GEC shuttered

The Thesis

The people and organizations who framed GamerGate as a harassment campaign – and who framed gaming communities as radicalization vectors – were in many cases funded by the same federal apparatus that was simultaneously building the infrastructure to classify those communities as national security threats. The USAID Disinformation Primer, which explicitly names gaming sites as sources of “problematic information,” was produced by the same funding ecosystem that had supported the anti-GamerGate narrative.

This is not a conspiracy. It is an incentive structure. Federal dollars created careers in identifying online threats. Gaming communities were identified as threats. The identification justified more federal dollars. The people doing the identifying moved between government, academia, NGOs, and platforms, carrying the same frameworks and the same conclusions. No coordination was necessary. The funding aligned the incentives, and the incentives produced the consensus.


  1. House Judiciary Committee: “The Weaponization of CISA” (June 2023)

  2. House Judiciary Committee: “The Weaponization of ‘Disinformation’ Pseudo-Experts and Bureaucrats” (Nov 2023)

  3. House Small Business Committee: “Instruments and Casualties of the Censorship-Industrial Complex” (Sept 2024)

  4. Senate Grassley Letter: GDI Funding inquiry to State Department

  5. America First Legal FOIA Production: USAID Disinformation Primer

  6. USAID Disinformation Primer (direct PDF):


13. The Trust & Safety Conference Circuit

TSPA (Trust & Safety Professional Association)

A 501(c)(6) non-partisan membership association. Its sibling, the Trust and Safety Foundation (TSF), is a 501(c)(3). Together they operate the conference circuit, career pipeline, and professional standards for the entire content moderation industry.

Founding Supporters

Airbnb, Automattic, Cloudflare, Match Group, Meta, Pinterest, Wikimedia Foundation

Annual Supporters

ActiveFence, Adobe, Alorica, Bitly, Bumble, Cinder, Clavata, Concentrix, Depop, Discord, Gear Inc, Microsoft, Niantic, Roblox, TaskUs, Thumbtack, TikTok, Twitch, Vimeo, WebPurify, Zefr

Past / In-Kind Support

Cobalt, Google, Internet Education Foundation, Mozilla, Neo Law Group, Omidyar Network, Postmates, Santa Clara Law, Slack, Twitter, Wilson Sonsini

Note: Omidyar Network is Pierre Omidyar’s philanthropic investment firm, which has also funded The Intercept, First Look Media, and various “digital rights” organizations. Wilson Sonsini is Silicon Valley’s dominant tech law firm.

TrustCon 2024 (July 22-24, San Francisco)

  • 1,300+ attendees from 400+ organizations across 40 countries
  • 260 speakers, 150 panels/presentations/workshops across 3 days
  • Visionary Sponsors: Genpact, Google, Wipro
  • Scholarship Sponsor: TaskUs
  • Evening social hosted by Tech Mahindra
  • Held at Hyatt Regency San Francisco

Notable Session Topics (from r/trustandsafetypros megathread)

The agenda reveals the scope of the industry’s self-conception:

  • “Network Analysis to Discover Emerging Influencers & Superspreaders”
  • “Platform Accountability for Elections”
  • “Coordinated Behavior at Scale”
  • “Election Integrity Best Practices”
  • “Tabletop Scenarios for T&S During Elections”
  • “Safety Design in Gaming Platforms”
  • “Content Moderation Impact Assessment”
  • “Countering Terrorism Online”
  • “Terrorist Use of the Internet and Extremism & Technology”
  • “Ctrl-Alt-Speech Live: TrustCon Edition”
  • “Algorithmic Moderation”
  • “Breaking the Silence: Marginalized Tech Workers’ Experiences”
  • “Gen-AI Investigation” (presented by the subreddit mod)
  • “AI Frameworks” / “T&S in Gen AI” / “GenAI Preparedness Strategies”

The Conference Circuit (2025-2026)

TSPA runs three annual conferences:

  • TrustCon (San Francisco, July) — the flagship, 1,300+ attendees
  • EMEA Summit (Dublin, May) — European arm
  • APAC Summit (Singapore, October) — Asia-Pacific arm

The 2025 EMEA Summit was sponsored by Tech Coalition and Resolver.

What This Means

This is not a fringe operation. This is a professionalized industry with founding support from the largest platforms on earth (Meta, Google, Twitter, Microsoft, TikTok), annual conferences with over a thousand attendees, and a career pipeline that moves people between government agencies, academic research programs, NGOs, and platform trust-and-safety teams. The same organizations that fund TSPA are the ones implementing content moderation decisions on platforms used by billions.

The session topics tell the story: “discovering superspreaders,” “election integrity tabletop exercises,” “safety design in gaming platforms.” This is the institutional infrastructure that decides what speech is permissible online. It has founding members, sponsor tiers, career tracks, and chair massages at the conference.

The subreddit (r/trustandsafetypros) has minimal engagement — 9 upvotes on the TrustCon 2024 megathread. The industry doesn’t need public support. It has corporate sponsorship.

  • Source: tspa.org
  • Source: Reddit r/trustandsafetypros TrustCon 2024 Megathread (archived PDF)

14. The Funding Ecosystem: Who Pays for Content Moderation

Omidyar Network — The Architect

Pierre Omidyar’s hybrid foundation/LLC is the closest thing to an architect of the entire T&S professional ecosystem. By 2025, Omidyar had awarded almost $2 billion to more than 700 organizations.

Key T&S investments:

  • Helped launch TSPA — Omidyar directly helped create the Trust & Safety Professional Association
  • Funded the Stanford Internet Observatory — SIO received Omidyar grants, including a pilot program for trust-and-safety researchers (up to $15,000 per grant)
  • “Responsible Technology” program — Omidyar’s umbrella for all T&S investment, covering “curbing the harmful effects of Big Tech,” “digital safety and trust,” and “building alternative tech ecosystems”

Omidyar also funds The Intercept and First Look Media, creating a media ecosystem that covers the same issues its philanthropy funds research into. The foundation defines the problem, funds the research, and funds the journalism that covers the research.

ActiveFence — The $500M Content Moderation Startup

Co-headquartered in New York and Tel Aviv. Raised $100 million at a $500+ million valuation. Investors include Highland Europe, CRV, Telefonica, Norwest Venture Partners, and Grove Ventures. Estimated revenue: $100-250 million. Over 300 employees.

ActiveFence sells AI-powered content moderation tools to platform trust-and-safety teams. It acquired Spectrum Labs (last valued at $137M) in September 2023. It is an annual TSPA supporter.

This is the commercial arm of the pipeline: federal grants fund the research that defines what “harmful content” is, TSPA professionalizes the workforce that implements the definitions, and companies like ActiveFence sell the tools to automate enforcement at scale.

Cognizant — The $2 Million Grant

Cognizant (multinational IT services, 350,000+ employees) awarded $2 million to the Trust and Safety Foundation in 2019 as part of a commitment to fund research on reducing user exposure to “objectionable online content.” Cognizant is also a major content moderation outsourcer — its workers review flagged content for platforms. The company that profits from content moderation funded the foundation that professionalizes content moderation.

The Santa Clara Conference Origin (2020)

TSPA and TSF were jointly launched in 2020 as a result of a conference at Santa Clara University. The conference brought together platform employees, academics, and civil society organizations to formalize trust-and-safety as a professional field.

The professionalization creates a self-reinforcing loop:

  1. Platforms fund TSPA/TSF
  2. TSPA/TSF define professional standards for content moderation
  3. Platforms hire people trained to those standards
  4. Those people implement policies aligned with the standards
  5. The standards expand to cover more categories of speech
  6. More moderators are needed → more TSPA membership → more funding

The Outsourcing Companies

Several TSPA supporters are content moderation outsourcing firms:

  • TaskUs — TrustCon scholarship sponsor, outsourced moderation for platforms
  • Alorica — BPO firm, content moderation services
  • Concentrix — outsourced content moderation
  • Genpact — TrustCon 2024 Visionary Sponsor, AI-powered moderation services
  • Wipro — TrustCon 2024 Visionary Sponsor, IT outsourcing

These companies profit directly from the expansion of content moderation. Every new category of “harmful content” creates more work for their moderators. Their sponsorship of TSPA is a business development expense.

The Powermod Connection

The pipeline from volunteer Reddit moderator to paid content moderation professional is documented:

  • GallowBoob (Robert Allam) — Reddit’s most prolific powermod (113+ subreddits), hired by UNILAD, then Jukin Media, then BoredPanda, then Director of Social Media at Tempo Storm. Content moderation as a career path.
  • TSPA career track explicitly recruits from government and civil society into platform T&S roles
  • TrustCon sessions include “Building Long Term T&S Careers for Moderators” and “Organizational Design for Trust & Safety”
  • The same people who volunteer-moderated forums and subreddits are now the paid professionals implementing content policies at scale, with corporate sponsorship, professional certification, and conference keynotes

The powermod-to-professional pipeline is not a conspiracy theory. It is documented in TSPA’s own career resources, which explicitly describe the pathway from volunteer moderation to paid T&S roles. The difference is that powermods were accountable to their communities (who could leave). Professional T&S employees are accountable to their employers (who set the policies). The communities lost their moderators. The platforms gained employees. The speech policies became corporate rather than communal.


15. Think Tanks and Advocacy Organizations

The anti-disinformation ecosystem includes numerous think tanks and advocacy organizations that operate as political entities while presenting as neutral researchers:

Key Organizations

  • Stanford Internet Observatory (SIO) — Created EIP, Virality Project. Funded by NSF, Omidyar. Closed 2024 amid controversy.
  • Atlantic Council’s Digital Forensic Research Lab (DFRLab) — EIP partner. Atlantic Council funded by NATO governments, tech companies, and defense contractors.
  • Graphika — EIP partner. Social network analysis firm. Government contracts for influence operation detection.
  • NewsGuard — GEC-funded. Rates news sources on “trustworthiness.” Revenue from licensing its ratings to platforms, advertisers, and government agencies.
  • Institute for Strategic Dialogue (ISD) — UK-based. Tracks “online extremism.” Funded by European governments, tech companies, and foundations.
  • Center for Countering Digital Hate (CCDH) — UK-based. Produced “Disinformation Dozen” report targeting 12 individuals for deplatforming. Founded by Imran Ahmed, former political operative for the UK Labour Party.

The Pattern

Every organization follows the same model:

  1. Receive funding from governments, foundations, or platforms
  2. Produce research identifying categories of speech as harmful
  3. Recommend policy changes to platforms based on the research
  4. Platforms implement the recommendations
  5. The organization publishes follow-up research showing the recommendations worked (or that more are needed)
  6. The cycle justifies continued funding

No organization in this ecosystem has ever published research concluding that less content moderation is needed. The incentive structure does not permit that conclusion.


16. The CVE Pipeline: From Counter-Terrorism to Content Moderation

Origins

President Obama released the National Strategy on Empowering Local Partners to Prevent Violent Extremism in August 2011. The CVE (Countering Violent Extremism) Initiative created a domestic infrastructure for “countering extremist narratives” – including online narratives – run through DHS, FBI, DOJ, and the National Counterterrorism Center.

In February 2015, the White House hosted the Summit on Countering Violent Extremism, bringing together ministers from nearly 70 countries, the UN Secretary-General, and representatives from civil society and the private sector. The summit explicitly called for DHS to build “relationships with the social media industry” and to increase “training available to communities to counter violent extremists online.” A proposed “CVE Hub” was designed to be a non-governmental organization connecting community groups, funders, academics, and the tech sector. This was the institutional moment when counter-terrorism formally merged with social media content moderation.

The CVE Grants Program ($10 Million, 2016-2017)

On January 13, 2017 – seven days before Trump’s inauguration – DHS Secretary Jeh Johnson announced $10 million in CVE grant funding to 31 organizations. Recipients included:

  • Life After Hate ($400,000) – for “proactively identifying white supremacists online who want to leave the movement”
  • Multiple universities and NGOs focused on “countering online radicalization”

The Trump administration froze the grants, placed them under review, and published a revised recipient list in June 2017 that stripped funding from Life After Hate and others. The timing – grants announced in Obama’s final week, frozen in Trump’s first – illustrates the partisan weaponization of CVE funding.

From Counter-Terrorism to Content Moderation

The CVE framework was the bridge between traditional counter-terrorism and modern content moderation. The critical conceptual shift:

  1. Counter-terrorism focused on stopping acts of violence
  2. CVE expanded the focus to narratives that might lead to violence
  3. Content moderation expanded further to speech that might promote narratives that might lead to violence

Each expansion doubled the scope. By the time CISA formalized its MDM (Mis-, Dis-, Malinformation) team in 2021, the framework had traveled from “prevent terrorist attacks” to “flag social media posts that might contribute to vaccine hesitancy.” The CVE grants program is the institutional ancestor of the Election Integrity Partnership.

The GAO Reports

A 2024 GAO report (GAO-24-106262) found that the FBI and DHS had mechanisms to share domestic violent extremism threat information with social media and gaming companies, but “neither agency has developed a strategy that articulates how it identifies and selects companies to engage with or the goals and desired outcomes of those engagements.” The government was sharing threat intelligence with platforms without defined criteria for what constituted a threat, what the engagement was supposed to achieve, or how success would be measured.

A 2017 GAO report (GAO-17-300) found that DHS needed to improve grants management and data collection for CVE programs. A 2021 GAO follow-up (GAO-21-216) found the same problems persisted.


17. The Revolving Door: Named Personnel

The Stanford-CISA-Platform Triangle

The revolving door between government, academia, and platform trust-and-safety teams is documented through named individuals:

Alex Stamos

  • Facebook Chief Security Officer (2015-2018) – spearheaded internal investigation of Russian 2016 election meddling
  • Stanford Internet Observatory founding director (2019-2023)
  • CISA Cybersecurity Advisory Committee member
  • Krebs Stamos Group co-founder (2021) with former CISA director Chris Krebs – first client was SolarWinds
  • Krebs Stamos Group acquired by SentinelOne (2023), renamed PinnacleOne Strategic Advisory Group

The same person held positions at a major platform, led the academic center that created the Election Integrity Partnership at CISA’s request, sat on CISA’s advisory board, and then formed a consulting firm with CISA’s fired director. This is not a conspiracy. It is a LinkedIn profile.

Renee DiResta

  • B.S. in computer science and political science, Stony Brook University (2004)
  • CIA intern while an undergraduate (association ended 2004, per her own account; confirmed by Stamos in video remarks)
  • Seven years on Wall Street as an equity derivatives trader at Jane Street (quantitative proprietary trading)
  • Principal at O’Reilly AlphaTech Ventures (OATV) – seed-stage venture capital
  • Director of Research at New Knowledge – the firm behind Project Birmingham, a disinformation operation during the 2017 Alabama Senate special election (Roy Moore vs. Doug Jones). New Knowledge created fake Russian bot accounts to follow Moore’s Twitter, ran false-flag Facebook pages posing as conservative Alabamians, and boosted a write-in candidate to split the Republican vote. Funded with ~$100,000 from LinkedIn co-founder Reid Hoffman. The Alabama AG investigated.
  • Testified before the Senate Intelligence Committee (August 2018) on Russian IRA social media manipulation – while employed at the same company that had just run a domestic disinformation operation using the same techniques
  • Stanford Internet Observatory research manager (2019-2024) – led the EIP and Virality Project
  • CISA subcommittee Subject Matter Expert
  • Contract not renewed in June 2024 as SIO was dismantled
  • Currently Associate Research Professor, Georgetown McCourt School of Public Policy
  • Published a June 2024 NYT op-ed warning about election vulnerabilities without the EIP

The DiResta career arc is the single most illustrative example of the pipeline’s moral incoherence. The person who became America’s leading anti-disinformation researcher was previously at a company that ran a disinformation operation. The person who testified to Congress about Russian bot tactics worked at a company that deployed those same tactics domestically. The person who led the Virality Project – which flagged true vaccine information for suppression – had previously been a CIA intern and a Wall Street derivatives trader. This is not a conspiracy. It is a resume.

DEFAMATION NOTE: All career facts sourced from DiResta’s own website (reneediresta.com/about), Wikipedia, Senate testimony records, NPR, and the National Security Archive at GWU. Project Birmingham facts sourced from NPR, Wikipedia, and NYT reporting. CIA internship confirmed by Stamos in video remarks cited by Foundation for Freedom Online.

Chris Krebs

  • CISA director (2018-2020) – fired by Trump via tweet for declaring 2020 election “the most secure in American history”
  • Krebs Stamos Group co-founder (2021) with Stamos
  • SentinelOne (2023-present) via acquisition
  • Former DHS official Caitlin Durkovich recently started a separate firm with former CISA official Jeff Greene offering services CISA has scaled back

The Pattern

The personnel movements follow a predictable circuit:

  1. Government agency (CISA, DHS, State Dept) → defines threats
  2. Academic center (Stanford SIO, UW) → researches threats with government funding/consultation
  3. Platform T&S team (Facebook, Twitter, Google) → implements policies based on research
  4. Consulting firm (Krebs Stamos, etc.) → advises all three sectors
  5. NGO/Think tank (Atlantic Council, ISD) → advocates for policy changes

The same 50-100 people rotate through all five positions. The frameworks travel with them. The ideological convergence is not coordinated – it is structural. You do not need a conspiracy when you have a career path.

The Stanford Internet Observatory Collapse (2024)

SIO’s collapse is the clearest evidence that the infrastructure depended on political protection:

  • Founded 2019 with $5 million from Craig Newman Philanthropies
  • Received $748,437 NSF grant (2021)
  • Created EIP (2020), Virality Project (2021)
  • Sued three times by conservative groups alleging illegal government collusion – all eventually dismissed
  • Stanford spent millions defending staff in litigation
  • Stamos departed November 2023; DiResta’s contract expired June 2024
  • Other staff told to find new jobs
  • Will not conduct election research going forward
  • Child safety and Journal of Online Trust and Safety continue under new leadership

The House Judiciary Committee called SIO’s dismantling a “big win.” The infrastructure didn’t collapse because it was wrong. It collapsed because the political protection was withdrawn. The research continues under different names and different institutions. The frameworks persist.

DEFAMATION NOTE: All career histories sourced from Wikipedia, LinkedIn, news coverage, and official organizational announcements. The “revolving door” characterization refers to documented employment transitions, not allegations of impropriety.


18. The EU Digital Services Act: Exporting the Model

Overview

The Digital Services Act (DSA), effective February 2024 for all platforms, is the EU’s comprehensive content moderation law. It transforms voluntary platform content moderation into a legal obligation with fines up to 6% of global turnover.

Key Obligations

  • Platforms must have clear terms of service and enforce them diligently
  • Users can flag illegal content; platforms must act on notifications “expeditiously”
  • Very Large Online Platforms (VLOPs: 45M+ EU monthly users) must conduct systemic risk assessments for disinformation, election integrity, and public health
  • Annual transparency reports on content moderation volumes, automated systems, and error rates
  • Researcher access to platform data for studying systemic risks

The “Trusted Flagger” System

Article 22 of the DSA creates “trusted flaggers” – organizations designated by national authorities whose content reports receive priority treatment from platforms. As of mid-2025, 34+ trusted flaggers have been appointed across the EU.

Designated organizations include:

  • France: ALPA, IFAW, INDECOSA-CGT, Point de Contact
  • Germany: HateAid, Federal Association of Online Retailers, Federation of German Consumer Organizations, Respect reporting office

Eligible categories: consumer rights organizations, child-protection organizations, human rights organizations, environmental organizations, trade unions, fact-checker networks, and “networks or alliances of entities at national and European levels.”

The PCI Parallel

The DSA’s trusted flagger system is structurally identical to the PCI Qualified Security Assessor (QSA) system:

FeaturePCIDSA
Mandatory complianceRequired for card processingRequired for EU platform operation
Designated assessorsQSAs certified by PCI SSCTrusted flaggers designated by national authorities
Priority treatmentQSA findings treated as authoritativeTrusted flagger reports treated with priority
Scope creepPCI v4.0 expanded to JavaScript monitoringDSA covers illegal content, disinformation, election integrity, public health, minors
Revenue modelQSAs profit from compliance complexityOutsourcing firms (TaskUs, Genpact, Wipro) profit from moderation volume
Accountability gapNo breached org was fully PCI compliantTrusted flaggers hold “flagging bias” with no feedback mechanism

The DSA is the European institutionalization of the same pipeline. What was voluntary in the US – platforms moderating content at government suggestion – becomes mandatory in the EU. The trusted flagger system formally outsources content policing to NGOs with no democratic accountability, exactly as PCI outsourced security assessment to QSAs with no accountability for breach outcomes.

Trusted Flagger Criticism

The system’s structural problems are documented in academic literature:

  • Germany’s Respect NGO receives 95% of its funding from the federal government’s “Demokratie Leben” programme. Lawyer Ralf Höcker described this as “state censorship” with “numerous connections between these organisations and political parties.”

  • Platforms do not disclose which organizations have trusted flagger privileges, leaving users unable to know who is involved in content moderation decisions affecting them

  • Platforms are transparent about NGO interactions but opaque about government and IP-rights organization interactions – the categories most likely to raise free speech concerns

  • Trusted flagging allows platforms to “perform multi-stakeholderism” while leaving core operations untouched – a PR function rather than accountability

  • The Yale Information Society Project published a critical paper (“On ‘Trusted’ Flaggers”) arguing the system reflects and reinforces pre-existing power structures, including state coercion

  • Source: policyreview.info

  • Source: cadeproject.org

  • Source: law.yale.edu

  • Source: compliancehub.wiki

2024-2025 Enforcement Actions

The Commission opened proceedings against:

  • X (Twitter): Fined €120 million (December 2025) – the first formal DSA enforcement action. Breakdown: €45M for blue checkmark violations, €40M for blocking researcher data access, €35M for advertising transparency failures.
  • Meta (Instagram/Facebook): preliminary findings of DSA breaches (October 2025) – transparency, content moderation, dark patterns, election integrity, addictive design. Potential fines up to 6% of global revenue (~$9.87 billion)
  • TikTok: preliminary findings of DSA breaches (October 2025) – transparency, researcher data access, minors’ protection. Secured binding commitments with no fine.
  • AliExpress: illegal products, risk assessment

Total enforcement actions to date: €120 million in fines with multiple proceedings pending.

The Brussels Effect

The DSA creates a “Brussels Effect” – because platforms must comply with EU law for EU users, they tend to implement the same policies globally rather than maintaining separate systems. European content moderation mandates effectively become global content moderation policies. The EU’s definition of “illegal content” – which varies by member state and includes categories like “hate speech” that have no legal equivalent in the US – becomes the de facto global standard.


19. The Structural Parallel: PCI, Anti-Disinformation, and the DSA

The Thesis

The federal anti-disinformation pipeline, the PCI compliance industry, and the EU Digital Services Act all follow the same structural pattern of regulatory capture creating a self-sustaining industry:

Phase 1: Legitimate Problem

  • PCI: Credit card fraud was real
  • Anti-disinfo: Russian election interference was real
  • DSA: Illegal content on platforms was real

Phase 2: Institutional Response

  • PCI: Payment Card Industry Security Standards Council created (2006)
  • Anti-disinfo: GEC created (2016), CVE grants ($10M, 2017), CISA MDM team (2021)
  • DSA: Digital Services Act adopted (2022), effective (2024)

Phase 3: Scope Expansion

  • PCI: From “protect cardholder data” to PCI v4.0 requiring JavaScript monitoring on every page
  • Anti-disinfo: From “counter Russian propaganda” to flagging true vaccine information as “malinformation”
  • DSA: From “remove illegal content” to mandatory systemic risk assessments for disinformation, election integrity, public health, and minors

Phase 4: Industry Creation

  • PCI: QSA firms, scanning vendors, compliance consultants – multi-billion dollar industry
  • Anti-disinfo: TSPA, ActiveFence ($500M), outsourcing firms (TaskUs, Genpact, Wipro), 1,300-attendee conferences
  • DSA: Trusted flaggers, compliance consultants, transparency reporting tools, risk assessment firms

Phase 5: Accountability Failure

  • PCI: “VERIZON ZERO” – no breached organization was ever fully PCI compliant. The compliance industry failed at its stated purpose.
  • Anti-disinfo: The Virality Project flagged true information for suppression. The anti-disinformation industry became a disinformation operation.
  • DSA: Trusted flaggers hold “flagging bias” with no feedback mechanism. The accountability structure is designed to measure volume of moderation, not accuracy.

Phase 6: The Industry Becomes the Problem

  • PCI: Compliance costs drive small businesses out of card processing; monopoly vendors profit from mandatory requirements they helped write
  • Anti-disinfo: Career incentives reward expanding the definition of “harmful content”; no researcher ever received a grant for concluding speech was harmless
  • DSA: Global platforms implement EU standards worldwide; European content rules become de facto global policy with no democratic input from non-EU citizens

The Common Architecture

All three systems share:

  1. A legitimate founding grievance that justifies the initial intervention
  2. Scope creep driven by institutional incentives to expand
  3. A compliance industry that profits from complexity
  4. Revolving door personnel who carry frameworks between regulator, industry, and assessor roles
  5. No accountability for outcomes – only accountability for process
  6. The problem gets worse despite (or because of) the intervention

This is not corruption. It is the natural behavior of institutional systems when compliance becomes more profitable than outcomes. The same structural forces that turned PCI into a $5 billion tax on commerce turned anti-disinformation into a $1.5 billion industry for suppressing speech. The DSA is the next iteration, and it has the force of law.