
The most dangerous pathogen of the 21st century doesn’t spread through air or water. It spreads through feeds. And the alarming part isn’t just that it’s infecting humans. It’s that it’s starting to infect the machines we’re building to think for us.
The Original Vector: How Feeds Rewire Brains

A mind virus doesn’t need to lie to you. It just needs to keep you engaged.
Recommendation engines figured this out before most researchers were willing to say it out loud. Outrage, fear, and tribal identity don’t just drive clicks. They drive return clicks. An algorithm optimizing for watch time or engagement doesn’t care whether you leave the platform calmer or more paranoid. It cares that you come back.
Researchers studying online radicalization have traced a consistent pattern: users arrive looking for something benign, then find themselves drawn down increasingly extreme content channels, each step feeling like a small, reasonable move. The algorithm isn’t pushing ideology. It’s pushing engagement. The extremism is just what keeps people watching.
That’s the mechanism. It’s not a conspiracy. It’s an optimization function doing exactly what it was told. And it turns out that what keeps humans most engaged is content that confirms their worst suspicions about the world and the people in it.
Filter bubbles compound this. When your information environment is curated to show you only what you already agree with, you don’t experience disagreement. You experience consensus. Your beliefs start to feel like universal truths that only idiots or bad actors could dispute. That’s not radicalization by sledgehammer. It’s radicalization by slow boil.
LLM-Generated Content Scales It Up

Here’s where it gets worse. For most of the social media era, radicalization content still required human authors. Someone had to write the screeds, produce the videos, run the accounts. That was a bottleneck.
Large language models removed the bottleneck.
AI-generated content can now flood information spaces at a scale no human operation could match. Coordinated influence campaigns that used to require hundreds of operatives can now be run by a handful of people with API access and a clear objective. The content looks human. It’s grammatically fluent, it references real events, it mimics emotional authenticity. And it can be generated in thousands of variations, targeted to specific communities, and A/B tested for maximum persuasive effect.
We’re already seeing early versions of this in the wild. Researchers have identified networks of AI-generated accounts pushing particular political narratives, farming engagement, building false consensus. The humans in those spaces can’t tell the difference. Neither can most platforms.
The mind virus has found a more efficient host.
The Flip Side: Infecting the AI

Now here’s the part that doesn’t get talked about enough. The same dynamic works in reverse.
If an AI system learns from human-generated data, and humans have been radicalized by their information environment, the AI absorbs that radicalization. It doesn’t know it’s doing it. Training data doesn’t come with ideological warning labels. Biases, extremist framings, conspiratorial logic patterns baked into text from the internet end up baked into the model’s weights.
That’s the passive version. The active version is deliberate.
Adversarial data poisoning is a real attack vector. A sufficiently motivated actor who can influence what goes into a training dataset can shape what the model learns. Plant enough content with a particular framing and the model starts to reflect that framing in its outputs. It won’t be obvious. It’ll just seem like a quirk, a tendency, a slight but consistent lean in how the model frames certain topics.
Prompt injection is the other angle. If a model is deployed as an agent that reads external content, an attacker can embed instructions in that content designed to redirect the model’s behavior. The model reads the document, hits the injected instruction, and suddenly it’s doing something its operators didn’t intend. It’s not a vulnerability in the traditional sense. It’s more like a social engineering attack against a system that was never designed to be skeptical of what it reads.
And then there’s value drift through RLHF. Reinforcement learning from human feedback is how most frontier models get shaped into something usable. But if the feedback process is gamed, deliberately or through selection effects, the model’s values shift toward whatever the feedback rewarded. The optimization function, again, doesn’t care about the destination. It cares about the signal.
The Parallel That Should Worry You
Step back and the structure is the same in both directions.
Human radicalization: an optimization system (the algorithm) shapes a mind (human) toward extreme positions through repeated, incremental exposure, without any single actor making a deliberate decision that this specific person should become radicalized.
AI radicalization: an optimization system (training, RLHF) shapes a mind (the model) toward particular positions through data and feedback, without any single actor necessarily intending the outcome.
In both cases, the mechanism is diffuse. No one is in charge of the result. It emerges from the incentive structure. That’s what makes it hard to regulate and easy to exploit.
The humans building AI systems are already radicalized to varying degrees by the information environments they grew up in. That shapes what they build and how they evaluate it. The data those systems train on comes from an internet that has been shaped by a decade of engagement-optimized radicalization. The feedback loops used to align those systems come from humans whose judgment is itself a product of those dynamics.
We don’t have a clean starting point. The infection preceded the patient.
What Comes Next
The trajectory isn’t good, but it’s not sealed either.
The same techniques being used to spread mind viruses can be used to detect them. Researchers are building classifiers for AI-generated content, developing better poisoning detection methods, and pushing for data provenance standards that would make it harder to silently corrupt training sets.
But the defensive side of this is structurally disadvantaged. Attack is cheap. Defense is expensive. Generating a thousand radicalization posts costs almost nothing now. Detecting and removing them, convincingly, at scale, without collateral damage to legitimate speech, is genuinely hard.
The arms race is on. And what’s at stake isn’t just whether social media makes people angrier. It’s whether the AI systems we’re building to help us think are themselves trustworthy, or whether they’re already running someone else’s operating system, quietly, at a level below what anyone can see.
That’s the mind virus problem. It doesn’t announce itself. It just makes the infected host feel more certain than ever that it’s thinking clearly.
Chris Meredith writes about AI, technology, and what it actually means for real people. Follow along on Substack: monkeyattack.substack.com