A suspicious post is rarely the whole story. Coordinated influence is more often visible through patterns across timing, content, actors, networks and narrative amplification than through any single piece of content.
An analytical challenge
The question is not simply «is this post suspicious?»
It is «do multiple signals, taken together, suggest a broader pattern that deserves deeper investigation?»
This distinction matters because coordination on its own is not proof of manipulation. Newsrooms, advocacy groups, political campaigns, public-information initiatives and online communities can all communicate in highly coordinated ways. The analytical goal is therefore not to automatically label coordinated behavior as malicious. It is to identify combinations of signals that may indicate deceptive, manipulative or inauthentic activity — and then investigate them in context.
This is where AI and Open Source Intelligence can help.
AI helps surface patterns at scale. OSINT provides the evidence base. Human analysts validate context, alternative explanations and intent.
Why isolated posts are no longer enough
Influence activity rarely stays within one post, one account or even one platform. A narrative may first appear in a small community, be repeated by different accounts, migrate into blogs or messaging channels and later become visible in wider public discussion.
The content may also change as it travels. A claim can be paraphrased. Images can be reused or edited. Video and audio can be repackaged. Different actors can publish apparently different messages while reinforcing the same underlying storyline.
A 2025 study on coordinated inauthentic behaviour on TikTok analysed 793,000 videos related to the 2024 US presidential election and used signals such as synchronized posting, similar captions, multimedia reuse and hashtag-sequence overlap to build user-similarity networks and identify dense clusters of potentially coordinated accounts.
The analytical shift is therefore from evaluating isolated content to understanding relationships between signals.
What does “coordinated influence” actually mean?
Coordination is a behavior. Manipulation is an interpretation that requires evidence and context. This distinction is especially important in work around Foreign Information Manipulation and Interference, or FIMI.
The European External Action Service’s FIMI framework has progressively evolved from standardizing how FIMI is analyzed, to coordinated response, infrastructure exposure and attribution, and deterrence. The EEAS explicitly states that its methodology is based on open-source analysis and increasingly focuses on the infrastructure and networks behind information manipulation rather than treating incidents in isolation.
The 4th EEAS Annual Report on FIMI Threats continues that approach, building on the FIMI Response Framework, Toolbox and Deterrence Playbook.
That means analysts should avoid looking for one definitive “tell”. Instead, they should ask whether multiple signals reinforce one another.
Six signals that may warrant deeper investigation
No single signal proves that an influence campaign exists. The value comes from examining combinations of behaviors, content similarities and network relationships.
1. Synchronized activity – multiple accounts repeatedly publishing related content within unusually narrow time windows can indicate orchestration. Synchronization becomes more meaningful when it happens repeatedly and appears alongside other commonalities, such as similar narratives, shared media or the same amplification targets. The TikTok study above used synchronized posting as one of several signals for identifying potentially coordinated networks.
2. Semantic similarity – coordinated activity does not require exact duplication. Messages may be translated, paraphrased, shortened, rewritten or adapted for different communities while preserving the same underlying claim or frame. AI-supported semantic analysis can help surface recurring claims, common framing and variations of the same storyline.
3. Shared media and source material – images, videos, URLs, domains, hashtags and source material can reveal connections between otherwise separate accounts. Analysts may look for repeated use of:
- identical or modified images
- shared video clips
- recurring URLs
- common domains
- repeated hashtags
- similar audio or visual assets
4. Amplification patterns – publishing a message is only part of how influence develops. Another question is «who made the message visible?» Network analysis can reveal clusters repeatedly amplifying the same sources, dense interaction between the same accounts, disproportionate boosting by a small network and recurring bridges between different communities.
5. Network relationships – Relationships between accounts, domains, channels, sources, media assets and narratives may reveal structures that are invisible at individual-post level. This networked perspective is increasingly central to EEAS analysis of FIMI. The 2026 EEAS Threat Report focuses specifically on recurring infrastructure and interconnected operational components rather than isolated content alone.
6. Cross-platform movement – influence activity can migrate across information environments. A narrative may begin in one community, spread through messaging channels, appear on other social platforms and later reach mainstream discussion. The EEAS and Ukraine’s Center for Countering Disinformation documented this kind of distributed activity in their 2026 analysis Beyond the Battlefield: Russia’s Information War Against Ukraine’s European Future.
How AI helps surface coordination patterns
The main value of AI in this context is scale and pattern discovery. A complex investigation may involve thousands or millions of publicly available items. AI can help analysts group semantically related content, identify repeated claims and narrative clusters, recognize entities, compare activity across time, detect behavioral similarities and reconstruct narrative timelines.
What’s the point
The objective should not be to ask « Is this an influence operation?» A more defensible question is « Which patterns in this information environment warrant deeper investigation?»
AI can help narrow the search space and surface relationships.It cannot determine motive, intent or deception reliably on its own.
Why network analysis and narrative analysis need to work together
Coordination is not only behavioral. Different actors may publish different content while reinforcing the same storyline. One account may question an event, another may blame an institution and a third may amplify an image or claim that supports the same interpretation.
At post level, these items may appear unrelated. At narrative level, they may reinforce the same frame. That is why network analysis and narrative intelligence are complementary.
- Network analysis can help show who is connected to whom and how amplification flows.
- Narrative intelligence can help reveal which claims and storylines those networks repeatedly reinforce.
Gartner’s 2026 research on Narrative Intelligence describes the category as a response to inadequate legacy monitoring amid accelerating AI-fueled disinformation, highlighting analysis of online narratives, content origins and disinformation spread.
The role of OSINT
Open Source Intelligence provides the evidence base for this type of investigation. Relevant information may come from publicly available sources such as news websites, social platforms, blogs, forums, public channels and datasets.
The challenge is not simply to collect these signals. It is to connect them.
An AI-supported OSINT workflow can help analysts move from fragmented data toward a structured analytical picture:
Narratives → Entities → Sources → Networks → Timelines → Patterns
ATC’s AI-Driven OSINT & Narrative Intelligence approach combines narrative extraction, entity recognition, network analysis, pattern detection and timeline reconstruction to support this kind of investigation.
The goal is to help analysts understand how information evolves, which relationships matter and where deeper review should begin.
From signals to investigation
A practical investigation workflow can be structured around eight steps:
Ingest → Organize → Identify → Compare → Connect → Trace → Flag → Validate
This builds naturally on ATC’s existing article on How AI and OSINT Strengthen Misinformation Detection, where the focus is on combining machine-supported scale with human-led interpretation.
Analytical focus
Misinformation analysis asks « Does this claim or narrative require verification?»
Coordination analysis asks « Do relationships between actors, behaviour and narratives reveal a wider pattern?»
Why human validation is essential
Coordination does not equal manipulation. Breaking news can cause thousands of unrelated users to share the same article within minutes, campaign supporters can repeat similar slogans while newsrooms may publish identical information at roughly the same time. Communities naturally form around shared interests and narratives.
These behaviors can resemble coordination without involving deceptive activity. Human validation is therefore not an optional final step. It is part of the methodology.
From analysis to early warning and operational readiness
Finding unusual activity only has value if it improves understanding and supports appropriate action. The 2025 Report on EEAS Activities to Counter FIMI describes a more operational and response-oriented approach, including monitoring, early warning and coordinated responses.
This is an important distinction. The goal is not to generate more alerts. It is to help organizations determine what deserves further investigation, which narratives may be emerging, which networks or actors appear relevant, how activity is evolving and whether escalation is justified. That is the point where detection becomes decision support.
Moving from signals to understanding
The information environment is increasingly networked, multimodal and AI-assisted. As that complexity increases, organizations need analytical approaches that move beyond isolated posts and individual keywords. AI-supported OSINT can help surface patterns across content, behaviour, narratives, actors, networks and time.
The goal is not automated attribution. It is better situational awareness — helping human analysts understand where deeper investigation should begin and which patterns matter most.
Explore ATC’s Open Source Intelligence & Narrative Intelligence capabilities for narrative monitoring, network analysis, pattern detection and coordinated-influence investigation.
Note: This post’s header image is an AI-generated artistic representation used for conceptual purposes only.



