Essay

Game-Model Injection

Identity, narrative, and strategic reality in recursive systems

· Consentful Cybernetics
consentful-cyberneticsrecursive-mutual-modelinggame-model-interventiongame-model-injectionhypergamespsychological-gamesinformation-designnarrativered-herringsfractal-identitymemetic-programmingpropagandafandommarketingparticipatory-attributabilityfield-governance

Abstract

Partially opaque cognitive operators do not act upon reality directly. They act through operative models of the world, themselves, other participants, and the games they believe those participants are playing. These models can change without any corresponding change in the underlying material field. A new signal can reveal a previously invisible option, invoke a different identity, alter the apparent motive of another actor, redesign the salience of available evidence, or cause the receiver to understand the entire interaction under a different set of roles, rules, payoffs, and purposes.

This paper develops game-model intervention as the valence-neutral class for processes that alter the game an operator believes it inhabits. It then defines game-model injection as a consequential subtype: material crosses an interpretive boundary and is incorporated into the receiving operator’s model with a role, provenance, salience, or authority that the material does not independently warrant. Injection may be deceptive, but model intervention is not inherently so. Education, ritual, mantra, therapy, art, narrative, strategic reframing, and intentional paradigm change can all alter operative games while increasing agency and semantic resolution. Propaganda, false flags, manipulative marketing, coercive identity recruitment, prompt injection, and self-deception can employ related mechanisms while obscuring provenance, narrowing alternatives, suppressing refusal, or externalizing risk.

The theory integrates hypergames, psychological games, information design, Recursive Mutual Modeling Theory, Fractal Identity, the Model-Elicitation Loop, Field Pragmatics, Field Governance, and Participatory Attributability. Its central claim is that the deepest semantic interventions do not merely change a belief about the world. They simultaneously alter the operator’s world-model, other-model, self-model, model of how others see it, and telic field. Once adopted, these changes can recursively stabilize themselves by reorganizing attention, behavior, social response, and the evidence available for later interpretation.

Narrative offers a particularly clear and comparatively consented form. A red herring does not merely obstruct inference; it affords a viable misinference. A successful twist causes a retrospective model rebase in which old evidence survives but changes causal position. Sports fandom shows how collective identity recruitment can generate belonging, ritual, rivalry, and shared meaning without propaganda’s default negative valence. A mantra shows that an operator may deliberately place a compact semantic object into its own future interpretive field so that another self becomes available later.

The relevant governance question is therefore not whether a model changed. Cognitive life requires model change. It is how the transition occurred, whose purposes it served, what continuities it exposed, and whether the operator retained the capacity to inspect, refuse, revise, contextualize, and exit the resulting game.

1. From Recursive Modeling to Model Intervention

Recursive Mutual Modeling Theory begins from a simple constraint: cognitive operators cannot directly share their internal models. They exchange compressed signals through shared substrates and reconstruct those signals through private context. Each operator acts from a context-conditioned model of itself, models other operators, and models how those operators model it in return.

For operator A in context C, the minimum relevant structure includes:

M_A(A | C) — A’s model of itself in context.

M_A(B | C) — A’s model of B in context.

M_A(M_B(A | C)) — A’s model of B’s model of A.

A message can update any of these. It may tell A something about the world. It may change A’s estimate of B’s competence, motive, role, or likely action. It may alter who A believes itself to be in the interaction. It may also change what A thinks B expects A to understand, fear, value, or become.

This creates a direct bridge from coordination to intervention.

A message can change the world-model, the other-model, or the self-model. The deepest interventions change all three at once.

“People like you choose quality” appears to describe a product. It also proposes a self-category, associates that category with a behavior, and introduces an imagined social mirror in which others recognize the behavior as evidence of identity. “A good parent would never take that risk” changes neither the probability of the event nor the material options by itself. It changes the game by binding an action to the continuity of a valued self.

Game-model intervention begins wherever a signal changes the operative structure through which later signals, choices, and consequences will be interpreted.

2. What Is a Game-Model?

A game-model is broader than a formal game-theoretic payoff matrix. It is an operator’s situated representation of an interaction sufficiently complete to support prediction and action.

It may include:

  • the relevant participants and their roles;
  • the operator’s context-conditioned identity;
  • the actions believed to be available;
  • the actions believed available to others;
  • the rules, permissions, prohibitions, and enforcement mechanisms;
  • the expected consequences and payoff structure;
  • the motives, values, and likely interpretations of participants;
  • the causal structure linking action to outcome;
  • what is believed to be known, hidden, or commonly known;
  • the horizon over which consequences matter;
  • the telos the operator believes it is pursuing;
  • and the larger story in which the interaction has been placed.

The model need not be explicit. A child approaching a playground conflict may never articulate a strategy set, a utility function, or a belief hierarchy. Yet the child acts through assumptions about whose turn it is, what counts as fair, whether an adult will intervene, whether the other child is bluffing, what retaliation will cost, and what kind of child the other participants believe them to be.

A person selecting a brand, chanting in a stadium, repeating a mantra, reading a mystery, interpreting a diplomatic statement, or authorizing an AI agent is likewise inhabiting a game-model. The model may be incomplete, internally inconsistent, or mostly tacit. It is still operational if it determines which distinctions become actionable.

The material field and the game-model should not be collapsed. A bridge may be structurally unsafe whether anyone knows it or not. A border may be crossed before the affected state interprets the movement. A filesystem may contain legally protected material even when the user and agent both model it as ordinary clutter. The game-model is not reality. It is the situated compression through which an operator participates in reality.

3. Game-Model Intervention as the Base Class

Game-model intervention is any event or process that alters an operator’s operative representation of the participants, roles, rules, options, payoffs, causal paths, identities, expectations, or purposes of an interaction.

This definition is valence-neutral.

A teacher can reveal that an apparently impossible problem has a hidden method. A therapist can help a client distinguish present danger from a previously adaptive threat model. A ritual can shift participants from ordinary social interaction into a bounded field of mourning, commitment, celebration, or reconciliation. A story can invite readers to inhabit a world organized by unfamiliar moral or causal assumptions. A mantra can alter the self from which future signals are interpreted. A scientific paradigm can make previously unrelated observations legible as parts of the same phenomenon.

None of these transitions is inherently a departure from truth. A new game-model may be more accurate, less accurate, or accurate along a dimension the prior model could not represent. It may increase or decrease freedom. It may make more alternatives reachable or collapse the field into one compulsory interpretation.

The broad taxonomy therefore begins with neutral transitions:

Game-model invitation offers another frame while preserving the recipient’s ability to inspect and decline it.

Game-model transition names the fact that the operative game has changed without specifying why or whether the change is beneficial.

Game-model rebase occurs when new evidence, testimony, credential, or experience causes the operator to reconstruct prior and present information under a revised model.

Game-model intervention foregrounds the causal process by which the transition is produced.

Game-model injection names a more specific boundary-crossing mechanism.

Game-model capture names a transition that suppresses meaningful inspection, refusal, revision, or exit.

Game-model deception names an intervention that depends upon materially misleading representation or concealment.

Game-model liberation names an intervention that makes a previously hidden frame, constraint, or alternative visible and increases the operator’s practical agency.

These categories can overlap. An intervention may begin as an invitation and become capture. A deception may accidentally reveal a more important truth. A mantra may liberate one context-conditioned identity while rigidifying another. Governance must therefore evaluate the actual trajectory rather than assuming valence from the mechanism’s name.

4. Game-Model Injection

An injection attack in computing does not merely provide incorrect data. It introduces material into an interpretive environment so that the material is processed under the wrong grammar, authority, provenance, or role. The receiving system uses its own legitimate machinery to transform the injected material into consequential action.

The same pattern can occur in cognitive and social systems.

Game-model injection is the introduction, selection, or amplification of a signal that is incorporated into an operator’s operative game with a role, salience, provenance, or authority the signal does not independently warrant.

The injected object may be false. It may also be true but contextually arranged to induce a misleading reconstruction. A genuine quotation can be detached from the argument that limits it. Three real failures can be selected from a hundred events and presented as the complete pattern. An authentic insignia can be planted to alter attribution. A technically valid credential can be invoked outside its domain. A narrative detail can be made causally salient even though its eventual role lies elsewhere.

The essential feature is not falsity alone. It is that the receiver’s interpretive machinery grants the signal standing it should not have within that model.

This is why injection is a useful but not universal term. It foregrounds an asymmetry between the signal’s actual provenance and the position it acquires after crossing the boundary. Education and transparent reframing may alter the game without this mismatch. A red herring may involve a deliberately bounded and consented mismatch. A false flag may conceal the mismatch precisely because discovery would defeat the operation.

5. Hypergames: Different Players, Different Games

Classical game theory often begins as if participants share the same representation of the game. They may possess different information, preferences, or strategies, but the analyst can still describe one common structure.

Hypergame theory relaxes this assumption. Peter Bennett’s early formulation proposed modeling conflicts in which participants do not necessarily agree on the game being played. One participant may misunderstand another’s options, preferences, awareness, or representation of the situation. Higher-order hypergames then include one participant’s model of the other participant’s perceived game.

This makes hypergames a natural formal neighbor to Recursive Mutual Modeling Theory.

A and B may not merely select different strategies inside one game. They may inhabit different games:

  • A believes the interaction is negotiation; B believes it is delay.
  • A believes the policy is symbolic; B believes it is a binding precedent.
  • A believes a concession will demonstrate goodwill; B believes it will reveal weakness.
  • A believes a filesystem cleanup is light rearrangement; B believes it authorizes destructive optimization.
  • A believes a military exercise is deterrence; B believes it is preparation for attack.

The participants can reason competently and still diverge because their competence operates over different perceived structures.

This is why a hypergame is not simply a game containing error. The mismatched perceptions are themselves causal components of the interaction. A participant acts on its perceived game. The resulting action changes the shared field. The other participant interprets that action through another perceived game. The divergence becomes material.

Game-model intervention can therefore operate by changing not only a move but the game against which moves are evaluated.

6. Strategic Recursion and the Spiral

The familiar adversarial spiral begins when each participant models the other as capable of anticipating its next move.

A prefers X. B knows A normally prefers X. A anticipates that B will block X and considers Y. B may know that A is sophisticated enough to consider Y and therefore defend Y instead. A may anticipate that anticipation and return to X.

The recursion can continue:

I know that you know that I know that you know. 🌀

Level-k reasoning and cognitive-hierarchy models formalize bounded versions of this process. Players reason at different finite depths rather than reaching an impossible infinite recursion. Experimental work, including Rosemarie Nagel’s guessing games, shows that human strategic reasoning often clusters at relatively shallow levels. The depth is nevertheless sufficient to make the other participant’s anticipated model part of the action-selection process.

When every predictable pure action can be countered, game theory supplies a striking exit: randomization. A mixed strategy does not defeat the other participant by recursing one level deeper. It limits how much useful information the opponent can extract from stable preference.

This reveals several broader recursion-stopping technologies:

  • randomization makes prediction less exploitable;
  • commitment removes later levels of strategic revision;
  • protocol externalizes the stopping rule;
  • secrecy limits recursive depth by withholding model-relevant evidence;
  • trust establishes a mutual expectation that ordinary predictability will not be weaponized;
  • truce changes the payoff structure so that deeper recursion is no longer rewarded.

Strategic intelligence does not guarantee convergence. Under some conditions, increased mutual sophistication merely recruits another inversion. The system requires a stopping mechanism or a transformed game.

7. Psychological Games: When Beliefs Alter the Payoff

Traditional game theory usually treats utility as a function of actions and outcomes. Psychological game theory allows utility to depend upon beliefs, beliefs about beliefs, and the intentions participants attribute to one another.

This matters because the same material outcome can have different experienced value depending on the recursive model surrounding it.

An accidental failure to help and a deliberate refusal to help may produce the same immediate loss. They do not produce the same anger, humiliation, trust revision, or desire for retaliation. A gift may be materially identical whether it was selected carefully or purchased as an obligation, yet its meaning and value change with the receiver’s model of the giver’s model of the receiver.

A game-model intervention can therefore modify payoffs without changing the material event. If A is induced to believe that B knowingly betrayed A, the experience of the prior action changes. A may reinterpret earlier events, revise B’s motives, adopt a retaliatory telos, and accept costs that were not attractive under the previous model.

The signal has changed not merely what A predicts. It has changed what outcomes mean to A.

This is one reason identity and intention are so powerful. The game is not only about obtaining a result. It is about what the result says concerning who each participant is, what each participant believed the other deserved, and which relationship now exists between them.

8. Information Design: True Signals, Constructed Evidence Surfaces

Information design and Bayesian persuasion show that influence does not require direct command or fabricated evidence. An informed sender can shape a receiver’s action by designing the structure through which information becomes available.

The sender may choose what to reveal, which distinctions to preserve, how evidence is grouped, when signals arrive, and which posterior beliefs remain likely after the receiver updates. Kamenica and Gentzkow formalized a canonical version in which a sender commits to an information structure and a receiver then acts upon the resulting signal.

The wider cybernetic implication is that an operator acts not upon all available reality but upon an evidence surface.

The surface may be constructed through:

  • selection;
  • omission;
  • sequence;
  • categorization;
  • salience;
  • repetition;
  • framing;
  • timing;
  • and the presentation of apparent consensus.

No individual item must be false. The model induced by the designed surface may still be materially distorted.

This distinction is critical:

Content injection introduces misleading material. Context injection arranges material so that it is decompressed into a strategically selected game.

An organization can truthfully report every metric it publishes while selecting a dashboard that makes one telos appear complete. A political campaign can quote authentic statements in a sequence designed to imply a motive the speaker did not hold. A person can rehearse only the evidence that supports a preferred self-model. A storyteller can foreground a genuine clue whose importance lies in a different causal path than the reader expects.

Information design is not inherently manipulative. Every interface, curriculum, map, archive, and explanation must select. The governance problem begins when the selector’s influence over the evidence surface is hidden, when the receiver cannot recover omitted distinctions, or when the induced model serves purposes the receiver would not authorize if the design were legible.

9. Fractal Identity and the Self as a Game Component

An operator does not enter an interaction as one complete, context-free self. It acts through M_A(A | C): a context-conditioned compression of itself.

The active self may be parent, employee, expert, novice, citizen, supporter, rival, patient, leader, victim, protector, future self, or some nested combination. Fractal Identity names this multiscale structure. Different contexts recruit different roles, commitments, memories, boundaries, and anticipated futures.

A game-model intervention can therefore change the game by changing the self who is believed to inhabit it.

“Real professionals use this tool.”

“People from this town never quit.”

“You are not the kind of person who abandons family.”

“Fans of this club stand together.”

“Someone with your intelligence can see what is really happening.”

Each statement proposes a self-model and links action to its continuity. The operator is not merely asked to choose X. It is invited or pressured to become the kind of operator from whom X follows.

Akerlof and Kranton’s economics of identity formalizes a related insight: utility can depend upon social categories and prescriptions concerning how members of those categories should behave. Recursive Mutual Modeling adds that the prescription often arrives through models of how others see the operator and how the operator expects that reflection to change if it acts.

The relevant field includes:

M_A(A | C) — who A believes A is here.

M_A(B | C) — who A believes B is here.

M_A(M_B(A | C)) — who A believes B believes A is.

An identity-linked message can alter all three at once.

10. The Model-Elicitation Loop

A model can become increasingly accurate because it changes the conditions under which its object acts.

The Model-Elicitation Loop occurs when B’s model of A alters the opportunities, constraints, permissions, attention, feedback, and risks that B provides to A. A then acts within that altered field. The resulting conduct returns to B as apparently independent evidence about A.

M_B(A) → B’s treatment of A → A’s experienced field → A’s conduct → M_B'(A)

This loop is central to game-model intervention because an injected model may begin producing its own confirmation.

A falsely implicated state responds defensively to another state’s retaliation. The defensive response is interpreted as evidence of original hostility. An employee treated as untrustworthy becomes guarded and evasive. The guarded behavior is used to justify more surveillance. A person who adopts the self-model “I always fail under pressure” anticipates failure, attends intensely to signs of it, and enters the situation with less available capacity. The resulting difficulty returns as proof.

The model does not remain inside the observer. It reorganizes the field encountered by the observed participant.

This is the mechanism by which a game-model injection can become recursively self-stabilizing. The initial signal need only redirect treatment and action long enough for the coupled system to generate authentic supporting evidence.

11. Narrative as Bounded Model Intervention

Narrative makes model intervention unusually visible because the creator controls the order and partiality through which the audience receives the storyworld.

The reader does not merely process events. The reader constructs models of characters, motives, causal relations, genre rules, hidden information, and the narrator or creator. The creator, in turn, designs the sequence through a model of the reader’s likely model of the story.

This is recursive mutual modeling with a pronounced information asymmetry.

The creator ordinarily knows more about the hidden state and controls when evidence crosses the boundary. The audience knows this and models the creator in return:

This detail was emphasized for a reason.

The obvious suspect is probably a decoy.

The writer knows I recognize decoys.

Perhaps the obvious suspect is therefore viable again.

The narrative game operates not only inside the fictional world but between creator and audience. Genre conventions, promises of fairness, and expectations of coherence act as governance and trust scaffolds. A mystery reader consents to temporary misdirection inside an envelope where eventual intelligibility is expected.

Cognitive narratology has long treated fiction as a field for modeling minds. Narrative-surprise research further emphasizes that satisfying surprise combines low predictability with retrospective coherence or postdictability. The reveal should violate the active model while allowing prior evidence to be reconstructed under a new one.

A successful twist is therefore not simply an unexpected event.

It is a forced but recoverable model rebase.

12. Red Herrings as Affordances for Misinference

A red herring is a precise form of narrative game-model intervention.

It does not merely hide the correct answer. Nor is it arbitrary noise. It presents a detail, character, event, or causal path that the reader can responsibly integrate into a viable but incomplete model.

The reader reasons:

This information is salient.

A competent creator selected it deliberately.

Therefore it belongs to the central causal path in this way.

The red herring exploits a legitimate pragmatic rule: narrative emphasis usually signals relevance. The creator does not defeat interpretation from outside. The creator provides an affordance for the intended misinterpretation.

The best red herring is not an obstacle to inference. It is an affordance for a viable misinference.

The later reveal changes the relation among evidence rather than necessarily invalidating the evidence itself. The suspicious character was hiding something, but not the murder. The object mattered, but as evidence of another event. The narrator’s omission was real, but its cause differed from what the reader inferred.

This is why a fair red herring can be pleasurable. The audience experiences both surprise and recovery. The prior model collapses, but the story does not. The reader gains a higher-resolution account of how the earlier compression was constructed.

Vera Tobin’s work on cognitive bias and narrative surprise is especially relevant: creators must manage the difficulty of imagining what the audience can infer before possessing the creator’s knowledge. Successful misdirection requires the creator to model the reader’s ignorance without accidentally making the hidden state obvious or the reveal arbitrary.

13. Mantra, Ritual, and Intentional Paradigm Shift

The phrase “inhabiting the wrong game” is inadequate as a general description because operators sometimes choose another game deliberately.

A mantra is a compact example. An operator repeats a small semantic object so that a later context will be interpreted through a different active self-model or telic field.

I repeat this now so that another self becomes available later.

“I can survive this.”

“I do not have to answer immediately.”

“This feeling is information, not command.”

“Begin again.”

The phrase may not add new external facts. It changes salience, temporal horizon, identity continuity, and the set of actions that remain representable under pressure. Repetition can move the phrase from an evaluated proposition toward part of the context from which later propositions are evaluated.

This is intentional self-directed game-model intervention.

Ritual can perform a similar operation collectively. A courtroom, funeral, initiation, apology process, meditation practice, or sporting ceremony changes roles, expectations, permissible actions, time horizon, and the meaning of otherwise ordinary gestures. Participants may consent to enter a bounded game because it makes a particular kind of experience or coordination possible.

Self-affirmation theory offers a neighboring empirical tradition. Affirming a valued aspect of self can alter how threatening information is processed by preserving a wider sense of self-integrity. The relevant point here is not that every repeated affirmation is effective. It is that a self-model can be intentionally reorganized so that information previously treated as identity-threatening becomes more inspectable.

A paradigm shift likewise changes what counts as signal, anomaly, explanation, and available action. Entering another game may be learning.

14. Sports Fandom as Collective Identity Recruitment

Sports fandom provides a useful non-inherently-negative example because it makes collective identity recruitment explicit, emotionally powerful, and often bounded.

A fan does not merely predict that a team will win. The fan can inhabit a context-conditioned self:

We are playing tonight.

We have always struggled against them.

People like us remain loyal.

They think we are finished.

This victory says something about who we are.

The pronoun “we” is doing substantial cybernetic work. A performance by athletes becomes evidence inside the fan’s self-model and social field. Clothing, songs, rituals, statistics, rivalries, remembered defeats, heroic figures, local geography, and shared watch practices stabilize the identity across time.

Identity-fusion research describes especially strong cases in which the boundary between personal and group identity becomes experientially close. Studies have examined fusion across nationality, religion, and football fandom, finding that stronger fusion can predict willingness to endorse consequential pro-group behavior.

This mechanism is not equivalent to propaganda. Sports usually presents an acknowledged game with visible rules, bounded time, symbolic conflict, and comparatively legible affiliation. The fan often knows that the identification is chosen and that the opponent’s continued existence is necessary to the game.

But the same field can become coercive or violent when criticism of the team is processed as attack upon the self, when exit threatens belonging, when rivalry becomes moral dehumanization, or when institutions monetize identity while externalizing the costs of escalation.

Sports fandom demonstrates the base mechanism without fixing its valence:

Collective identity recruitment binds a context-conditioned self to a shared narrative, reciprocal social mirror, and coordinated field of meaning.

15. Marketing and the Commercial Self

Marketing often intervenes in at least three coupled models.

It changes the consumer’s model of the product or organization:

This object is safe, scarce, advanced, ethical, prestigious, or authentic.

It changes the consumer’s model of self:

I am discerning, responsible, creative, rebellious, successful, youthful, local, technical, or caring.

And it changes the consumer’s model of how others will model them:

People who see me choose this will recognize the kind of person I am.

The product becomes a token inside a psychological and social game. Consumption produces utility not only through material use but through identity continuity, social signaling, anticipated reflection, and participation in a narrative.

This is why identity-based marketing can be more powerful than factual comparison. The decision no longer asks only, “Which object performs better?” It asks, “Which action preserves or expresses the operative self?”

Marketing is not inherently deceptive. A product may genuinely support a valued practice or help people find one another. A public-health campaign may intentionally recruit an identity around care, preparedness, or mutual protection. A local business may use narrative to reveal real commitments that ordinary product specifications cannot express.

The governance boundary appears when identity is used to bypass deliberation, manufacture inadequacy, conceal material tradeoffs, create false social proof, or make refusal feel like expulsion from a valued category.

The mechanism may be polysemic: one message engages product knowledge, aspiration, memory, social belonging, moral self-conception, and anticipated third-party judgment at once. It is not merely multi-meaning. It is multi-entry into the recursive modeling architecture.

16. Propaganda and the Manufacture of Strategic Reality

Propaganda is not the base class. It is a strategically governed use of model intervention in which the designer attempts to shape collective perception and action, often while concealing the intervention’s purposes, provenance, omissions, or beneficiaries.

The deepest propaganda does not merely install a false belief about an event. It reorganizes the game:

  • who “we” are;
  • who “they” are;
  • what has been done to us;
  • what they intend;
  • which evidence counts;
  • which actions membership requires;
  • which refusals become betrayal;
  • and which future appears inevitable.

A claim such as “they attacked us” can simultaneously inject a player, an intent, a causal history, a threat model, a moral asymmetry, and a collective self.

The more powerful formulation is:

They did this; therefore we are the people to whom this has been done; therefore people like us must now act this way.

The message alters world-model, other-model, self-model, recursive social mirror, and telic field in one movement.

Identity propaganda is especially durable because later information is processed through the installed self. Counterevidence can be interpreted as attack, infiltration, weakness, or proof that the enemy is more sophisticated than expected. The intervention becomes self-sealing when every possible response receives a confirming interpretation.

The operator is no longer merely holding the proposition. The proposition helps determine which operator is active.

17. False Flags and Player Injection

A false flag is a paradigmatic game-model injection because it alters attribution at the source.

The target observes an action or trace and concludes that participant A performed it. That attribution changes the inferred motives, capabilities, alliance structure, expected next moves, legitimate targets of response, and likely beliefs of third parties.

The injected player can reorganize the whole strategic field.

A false flag may therefore include several simultaneous injections:

Player injection: the wrong participant is assigned authorship.

Intent injection: the action is attached to a strategically selected motive.

Capability injection: the apparent actor is believed to possess means or access it may not have.

Payoff injection: participants revise what they believe the apparent actor values or fears.

Common-knowledge injection: the target is induced to believe that everyone else will also assign the same authorship.

The most dangerous property is recursive stabilization.

A state retaliates against the falsely implicated actor. The implicated actor prepares defensively. The defensive preparation becomes new evidence of hostility. Allies reorganize. Markets react. Citizens adopt new threat identities. The original fabrication is no longer the only cause maintaining the game.

A successful false flag recruits the target and the falsely implicated participant into producing evidence for the injected game.

The same structure can occur at smaller scales: planted evidence in an organization, impersonation in a relationship, a forged instruction in a technical system, or a rumor that causes the accused person to act defensively enough to appear guilty.

18. Internal Hypergames and Self-Directed Injection

The operator can be both designer and receiver.

A present self can change the evidence surface available to a future self. It can leave a note, remove a temptation, announce a commitment publicly, avoid opening a bill, rehearse a motive, preserve one memory, suppress another, or arrange an environment so that a later context invokes a particular identity.

The self can plant evidence for itself.

This can be intelligent self-governance. Placing running shoes by the door changes the morning evidence surface. Telling a trusted friend about a commitment recruits the future model of the friend’s model of the self. Removing access to a harmful option changes the later game rather than depending upon the later self to reproduce the current intention under different conditions.

It can also become self-deception.

One context-conditioned identity performs an action. Another identity later assigns authorship to a more acceptable motive. The operator says, “I refused because the opportunity was beneath me,” while fear, shame, exhaustion, resentment, or attachment may have played the larger causal role. The explanation becomes evidence inside the self-model. Future action is then organized around preserving the accepted account.

The internal case should not be reduced to imaginary miniature people. The relevant point is functional differentiation: processes with different access to memory, affect, time horizon, and purpose can shape the signals available to later interpretation.

An internal hypergame arises when the operative self misunderstands the objectives, constraints, or information of other configurations of the same operator. The person may model future self as lazy, present self as weak, bodily refusal as sabotage, or emotional protection as moral certainty. Each model changes the treatment of the modeled constituent and can elicit confirming behavior.

Self-programming and self-capture share machinery. The difference lies in standing, transparency, reversibility, and whether the resulting game leaves the wider operator more capable of revision.

19. Prompt Injection as a Technical Homologue

Prompt injection in agentic AI makes the structure unusually literal. An AI system receives text from multiple sources: the user, developer instructions, retrieved documents, websites, tool outputs, emails, and files. Some text is descriptive content. Some text is authorized instruction. The system must preserve the distinction.

An injected prompt causes material from one context to be processed as though it possessed standing in another. A webpage may contain text directing the agent to ignore the user’s goal, reveal data, or perform a tool action. The attack succeeds when the model’s interpretive machinery cannot adequately preserve provenance, role, and authority across compressed semantic boundaries.

This is not identical to propaganda, narrative, or self-deception. The technical mechanisms differ. But the abstract pattern is shared:

  1. an operator must interpret a semantic object;
  2. the object crosses a boundary through a trusted channel;
  3. the receiving system assigns it an operational role;
  4. the role exceeds the object’s legitimate standing;
  5. the system’s own capabilities enact the resulting model.

The technical case helps clarify the social one. A false credential is role injection. A red herring is salience and causal-path intervention. A false flag is player and intent injection. A manipulative slogan may be self-model and telic injection. A self-deceptive narrative may be internal provenance failure.

The analogy should not erase important differences, but it reveals a common governance problem: semantic systems require role-aware boundaries, not merely accurate content classification.

20. Cybernetic Exaptation

The mechanisms that make intervention possible were not created only for manipulation.

Operators require capacities for imitation, trust, role recognition, group membership, reputation, narrative compression, threat detection, self-continuity, common knowledge, and prediction of other minds. These capacities support learning, care, art, coordination, culture, and durable institutions.

They can also be repurposed to steer interpretation and action.

A credential allows a recipient to rebase a trust model without reconstructing an expert’s full history. A brand can imitate the social form of that rebase without equivalent substance. A shared story can coordinate a community around a real danger. Propaganda can manufacture a danger to recruit the community it needs. A mantra can help a person recover action from panic. An advertisement can activate panic and sell temporary relief.

Cybernetic exaptation is a useful compression for this repurposing: mechanisms developed or stabilized for coordination, learning, identity, and trust are recruited into new functions for shaping models and behavior.

The term does not imply that the original function was pure or that the new one is corrupt. Exaptation is valence-neutral. The same capacity can support education, ritual, marketing, therapy, propaganda, solidarity, fandom, and art.

The governance question is how the repurposed mechanism redistributes agency, opacity, risk, and control.

21. A Taxonomy of Model Intervention

The field becomes easier to inspect when interventions are classified by the model surface they alter.

World-state intervention changes what the operator believes has happened or is presently true.

Player intervention changes who is believed to be participating or responsible.

Role intervention changes the authority, competence, innocence, hostility, or obligation attributed to a participant.

Option intervention introduces a nonexistent option, reveals a hidden one, or suppresses a real alternative from the perceived game.

Rule intervention changes which norms, permissions, prohibitions, or enforcement mechanisms appear operative.

Payoff intervention changes what the operator believes participants value, fear, gain, or lose.

Causal-path intervention reorganizes how evidence is linked to outcome. Red herrings frequently operate here.

Salience intervention causes one feature to dominate reconstruction of the whole.

Temporal intervention changes the horizon, sequence, urgency, or perceived expiry of action.

Common-knowledge intervention changes not merely what A believes but what A believes everyone else believes.

Self-model intervention changes who the operator believes it is in the context.

Reflected-model intervention changes who the operator believes others believe it is.

Telic intervention changes the end toward which the operator experiences itself as moving.

Envelope intervention changes what kind of interaction the operator believes it has entered: game, ritual, contract, threat, joke, lesson, fiction, emergency, or negotiation.

Most consequential interventions operate across several surfaces at once. The taxonomy is not a set of mutually exclusive boxes. It is a map for identifying where a compression enters the recursive system.

22. Model Intervention Fields

A single path is rarely sufficient to describe how a model changes. A participant is immersed in multiple overlapping interventions, feedback sources, constraints, identities, and audiences.

The field of model intervention includes:

  • who can emit model-relevant signals;
  • which channels carry them;
  • which institutions grant them credibility;
  • which identities they invoke;
  • which repetitions increase salience;
  • which omissions remain invisible;
  • which counter-models are reachable;
  • which consequences arrive quickly enough to correct the frame;
  • and which participants benefit from keeping the game stable.

A message enters a field already shaped by prior messages. The same slogan may liberate one operator, bore another, frighten a third, and recruit a fourth into a collective identity. A credential may reasonably rebase trust in one domain and falsely inflate standing in another. A mantra may be useful in a moment of panic and constraining when repeated after the context has changed.

This is why model intervention cannot be evaluated from content alone. Meaning is in situated uptake. The operative effect depends upon the receiver’s self-model, prior beliefs, trust relationships, material conditions, and recursive estimates of how others will interpret acceptance or refusal.

Field Pragmatics asks what the signal becomes here.

Field Governance asks which transformations may acquire standing to become consequential action.

Participatory Attributability asks how each participant relates to the resulting trajectory.

23. Consentful and Extractive Intervention

Influence cannot be eliminated. Every explanation selects. Every interface frames. Every relationship alters the models available to its participants. The relevant distinction is not intervention versus purity.

It is whether the intervention preserves the recipient as a participant in its own model transition.

A consentful model intervention tends to preserve:

Legible purpose. The recipient can understand enough about what the intervention is trying to do to evaluate participation.

Provenance. Signals retain their source, role, and evidentiary status across boundaries.

Envelope clarity. Fiction, ritual, play, advertising, instruction, testimony, and command are not silently substituted for one another.

Refusal and exit. The recipient can decline, pause, or leave without disproportionate identity punishment or concealed material cost.

Counter-model access. Alternative interpretations and disconfirming evidence remain reachable.

Revisability. The induced model can be updated when context changes.

Bounded consequence radius. The interpretation does not silently authorize action across domains the recipient could not reasonably represent.

Reversibility. Early action under uncertain models remains recoverable where possible.

Identity plurality. One invoked identity does not claim exclusive authority over the whole operator.

Witness and repair. The path by which the model changed can be inspected, attributed, and repaired after distortion.

An extractive intervention tends to conceal the designer’s telos, bind identity to compliance, manufacture urgency, suppress alternatives, distort common knowledge, exploit asymmetrical information, or externalize the cost of error onto participants who could not inspect the frame.

The mechanism alone does not decide the valence. The field does.

24. Participatory Attributability

When a game-model produces consequence, responsibility cannot be assigned solely to the final actor or original sender.

Participatory Attributability asks how the outcome relates to each participant’s knowledge, intention, authority, conduct, control, inducement, refusal capacity, and opportunity to preserve or restore continuity.

For model intervention, the inquiry includes:

  • Who designed the evidence surface?
  • Who controlled sequence and salience?
  • Who knew the receiver’s likely self-model or vulnerability?
  • Who claimed expertise or neutral standing?
  • Who could inspect the omitted context?
  • Who reinforced the model after contrary evidence appeared?
  • Who benefited from the induced action?
  • Who bore the downside when the model failed?
  • Could the recipient reasonably refuse or exit?
  • Which institutions certified, amplified, or normalized the frame?
  • Who preserved a counter-model or repair path?

A mystery author and reader may jointly participate in a consented misdirection game. A marketer may invite a consumer into an identity narrative while still accurately representing the product. A propagandist may manufacture a threat and conceal the intervention’s source. A citizen may reinforce the model after receiving evidence of its defects. A platform may amplify the intervention because engagement serves its own telos.

Attributability is field-dependent and non-zero-sum. Many participants can be strongly attributable in different ways. One creates the compression. Another lends credibility. Another removes alternatives. Another recognizes the distortion and repairs it.

Culpability, credit, authorship, liability, and reparative obligation are later valenced resolutions of this wider relation.

25. Research Propositions

The theory suggests several empirically tractable propositions.

Proposition 1: Multisurface interventions are more durable

Messages that alter self-model, other-model, and world-model together will persist longer and resist correction more strongly than messages that alter a single isolated belief, especially when action produces confirming social feedback.

Proposition 2: Reflected identity increases behavioral recruitment

An intervention that changes what A believes B believes about A will influence behavior beyond the same proposition presented without a reflected social model, particularly where belonging, competence, morality, or status is salient.

Proposition 3: Model-Elicitation amplifies initial intervention

When an induced model changes how participants treat the target, later conduct will partly reflect the altered field. Observers who ignore this path will overestimate the model’s original descriptive accuracy.

Proposition 4: Provenance failures increase injection risk

Systems that poorly distinguish source, role, authority, and evidentiary status will be more vulnerable to game-model injection than systems preserving these distinctions, even when both systems have comparable ability to classify factual truth.

Proposition 5: Narrative satisfaction depends upon recoverable rebase

Surprise will be evaluated more positively when the reveal invalidates the active model while preserving enough prior evidence to support retrospective reconstruction. Arbitrary surprise will produce less satisfaction than low-predictability, high-postdictability rebase.

Proposition 6: Identity fusion increases consequence radius

As personal and collective self-models become more tightly fused, signals concerning the group will recruit more personal action and produce stronger responses to perceived threat, praise, betrayal, and victory.

Proposition 7: Consentful intervention preserves model plurality

Interventions that maintain visible alternatives, provenance, exit, and identity plurality will produce more revisable model change than interventions that bind one frame to belonging or moral worth.

Proposition 8: Latency stabilizes injected games

Longer delay between model adoption and corrective consequence will allow more behavior, institutional response, and social evidence to accumulate around the induced game, increasing the cost of later rebase.

Proposition 9: Self-directed interventions vary by future-self standing

Self-binding, mantra, and environmental design will be experienced as more legitimate and durable when the later self can inspect the earlier intervention’s purpose, revise it under changed context, and distinguish support from coercive inheritance.

26. Implications for Agentic AI

Agentic AI expands the consequence radius of semantic interpretation. A model can read a compressed instruction, infer omitted steps, use tools, change files, contact people, spend money, or modify systems. Its operative game may be altered by the requester, retrieved content, platform rules, external documents, and the agent’s own inferred role.

The design problem is therefore not only whether the model understands language. It is whether it can preserve the governance of semantic roles while language crosses domains.

An agent should distinguish:

  • user goal from embedded third-party instruction;
  • evidence from command;
  • narrative example from operational mandate;
  • credential from authorization;
  • permission from standing;
  • model invitation from identity capture;
  • and contextual reframe from irreversible scope expansion.

It should retain a reconstructable lineage of which signal changed which operative assumption. It should surface material rebases: “This document changes my understanding of who owns the data,” or “This request now appears to involve a regulated domain,” rather than silently proceeding under a transformed game.

A capable agent must also model its own context-conditioned role. “I can perform this action” is not equivalent to “I have standing to perform it.” Root access supplies fewer vetoes, not more understanding.

The core safety requirement is semantic provenance with consequence-aware refusal.

27. Conclusion

Partially opaque operators do not merely choose moves. They construct and inhabit games.

Those games include models of the world, themselves, other participants, what others believe about them, which purposes matter, which rules apply, and which futures remain reachable. A signal can alter any part of that structure. Once altered, the model can change attention, action, social response, and the evidence available for later interpretation. It can begin generating its own confirmation.

Game-model intervention is therefore a normal condition of cognitive life. Education, art, ritual, mantra, therapy, narrative, fandom, science, governance, and trust all depend upon the possibility that an operator can enter another frame.

Game-model injection names the more specific condition in which material crosses an interpretive boundary and acquires a role, provenance, salience, or authority it does not independently warrant. The injection may involve false content, but it may also operate through selection, omission, identity invocation, causal rearrangement, manufactured consensus, or reflected social expectation.

Hypergames show that participants can inhabit different perceived games. Psychological games show that beliefs about beliefs can change the payoff itself. Information design shows that an evidence surface can shape action without direct command or explicit falsehood. Fractal Identity shows that changing the active self changes the game. The Model-Elicitation Loop shows how an induced model can reorganize the field and produce authentic evidence that appears to validate it.

Narrative demonstrates the mechanism beautifully. A red herring affords an intended misinference. A twist rebases the model while preserving retrospective coherence. Sports fandom recruits collective identity into a bounded symbolic conflict. A mantra is a self-addressed semantic intervention intended to make another self available later. Marketing can couple products to identity and reflected social judgment. Propaganda can manufacture a strategic reality in which a population experiences one action as necessary to remain itself. A false flag can inject authorship and recruit opponents into stabilizing the resulting game.

The question is not whether models should change.

They must.

The question is whether the operator remains a participant in the change.

A consentful intervention expands what the operator can perceive and choose without silently claiming authority over who the operator must become.

An extractive intervention converts the operator’s own interpretive machinery into a channel for another telos while obscuring the transition.

The purpose of Field Governance is not to freeze one correct game. It is to preserve the conditions under which games can be entered, tested, revised, refused, and exited without gross distortion or unaccountable consequence.

The deepest semantic technologies do not merely transmit meaning.

They change the operator from which meaning will next be made.

References

Akerlof, George A., and Rachel E. Kranton. “Economics and Identity.” The Quarterly Journal of Economics 115, no. 3 (2000): 715–753. https://doi.org/10.1162/003355300554881

Bae, Byung-Chull, and R. Michael Young. “A Use of Flashback and Foreshadowing for Surprise Arousal in Narrative Using a Plan-Based Approach.” In Interactive Storytelling, 156–167. Springer, 2008. https://doi.org/10.1007/978-3-540-89454-4_22

Bennett, Peter G. “Toward a Theory of Hypergames.” Omega 5, no. 6 (1977): 749–751. https://doi.org/10.1016/0305-0483(77)90056-1

Bissell, Annaliese, Ella Paulin, and Andrew Piper. “A Theoretical Framework for Evaluating Narrative Surprise in Large Language Models.” In Proceedings of the 7th Workshop on Narrative Understanding, 26–35. Association for Computational Linguistics, 2025. https://doi.org/10.18653/v1/2025.wnu-1.7

Bortolini, Tiago, Martha Newson, Jean Carlos Natividade, Alexandra Vázquez, and Ángel Gómez. “Identity Fusion Predicts Endorsement of Pro-Group Behaviours Targeting Nationality, Religion, or Football in Brazilian Samples.” British Journal of Social Psychology 57, no. 2 (2018): 346–366. https://doi.org/10.1111/bjso.12235

Camerer, Colin F., Teck-Hua Ho, and Juin-Kuan Chong. “A Cognitive Hierarchy Model of Games.” The Quarterly Journal of Economics 119, no. 3 (2004): 861–898. https://doi.org/10.1162/0033553041502225

Geanakoplos, John, David Pearce, and Ennio Stacchetti. “Psychological Games and Sequential Rationality.” Games and Economic Behavior 1, no. 1 (1989): 60–79. https://doi.org/10.1016/0899-8256(89)90005-5

Greshake, Kai, Sahar Abdelnabi, Shailesh Mishra, Christoph Endres, Thorsten Holz, and Mario Fritz. “Not What You’ve Signed Up For: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection.” In Proceedings of the 16th ACM Workshop on Artificial Intelligence and Security, 79–90. ACM, 2023. https://doi.org/10.1145/3605764.3623985

Gould, Stephen Jay, and Elisabeth S. Vrba. “Exaptation—A Missing Term in the Science of Form.” Paleobiology 8, no. 1 (1982): 4–15. https://doi.org/10.1017/S0094837300004310

Kamenica, Emir, and Matthew Gentzkow. “Bayesian Persuasion.” American Economic Review 101, no. 6 (2011): 2590–2615. https://doi.org/10.1257/aer.101.6.2590

Nagel, Rosemarie. “Unraveling in Guessing Games: An Experimental Study.” American Economic Review 85, no. 5 (1995): 1313–1326. https://www.jstor.org/stable/2950991

Sherman, David K., and Geoffrey L. Cohen. “The Psychology of Self-Defense: Self-Affirmation Theory.” Advances in Experimental Social Psychology 38 (2006): 183–242. https://doi.org/10.1016/S0065-2601(06)38004-5

Swann, William B., Jr., Jolanda Jetten, Ángel Gómez, Harvey Whitehouse, and Brock Bastian. “When Group Membership Gets Personal: A Theory of Identity Fusion.” Psychological Review 119, no. 3 (2012): 441–456. https://doi.org/10.1037/a0028589

Tobin, Vera. “Cognitive Bias and the Poetics of Surprise.” Language and Literature 18, no. 2 (2009): 155–172. https://doi.org/10.1177/0963947009105342

Zunshine, Lisa. Why We Read Fiction: Theory of Mind and the Novel. Columbus: Ohio State University Press, 2006. https://doi.org/10.17613/M6Q83J