LetsData

Misinformation, disinformation, and why we don't detect on either

Misinformation, disinformation, and why we don't detect on either

|

5 min read

Misinformation, disinformation, and why we don't detect on either

The distinction holds up, but it turns on intent, and intent is a weak basis for detection. The definitions are stable enough to state briefly before getting to why they fall short in practice.

Misinformation is false or misleading information shared without the intent to deceive. The person forwarding it believes it, or hasn't thought about it. Most of the volume in any information environment is this. [1]

Disinformation is false or misleading information created or shared deliberately to deceive, mislead, or cause harm. The falsehood is instrumental. Someone chose it.

Malinformation is the third term, and the one usually dropped. It covers genuine information deployed to harm — a real document leaked at a chosen moment, a real quote stripped of its context, real personal details published to intimidate. Nothing about it is false. It is still an attack. [2]

The taxonomy comes from Wardle and Derakhshan's information disorder work for the Council of Europe, and it has held up well as a way of describing what happened after the fact. [3]


The problem is where the line sits

Look at what separates the first two. It is not the content — the content can be identical. It is not the reach, the platform, or the harm. It is intent.

Intent is not observable. It is inferred, usually from an accumulation of behavioural evidence, and usually well after the material has finished spreading. At the moment something is detected, the analyst has posts, accounts, timestamps, infrastructure and language. None of that tells you what anyone believed.

Which produces an awkward situation for anyone trying to run this operationally: the primary classification in the field's standard vocabulary cannot be applied at detection time. It can only be applied retrospectively, and often only partially.

The second problem is that the taxonomy's other axis — true or false — is a poor predictor of harm. Malinformation is the acknowledgement of this inside the taxonomy itself, but the point generalises further than the term does. A great deal of high-impact material is technically accurate, or unfalsifiable, or consists of accurate facts arranged to support a conclusion the facts don't carry. There is nothing to fact-check in a framing. There is nothing to fact-check in a selection of true stories, each individually verifiable, chosen so that a population appears to be behaving a certain way.

Verification remains necessary work. It is just not a detection strategy, and it was never designed to be one.

What is observable

If intent isn't available and truth isn't sufficient, the thing left is behaviour — and behaviour turns out to be both observable and durable.

A useful test: a single inflammatory post from a real, unaffiliated account is content. The same claim seeded across thirty fresh accounts within an hour, in three languages, with near-identical phrasing, is behaviour. Nothing in that second description requires knowing what anyone intended or whether the claim is true. It requires counting, timestamping, and comparing text.

The formal version of this is coordinated inauthentic behaviour, and it needs both of its conditions. [4]

Coordination alone is not it. A political party running a synchronised campaign across its members' real accounts is coordinated, openly, and that is ordinary politics.

Inauthenticity alone is not it either. One person operating one fake persona is inauthentic and mostly inconsequential.

Both conditions together — assets that misrepresent who is behind them, acting in concert — is the diagnostic. [5] Neither is sufficient on its own, and recording only one of them produces exactly the false positives that make monitoring programmes get abandoned in month three.

Why this ends up mattering commercially

The truth-first framing has a second cost, which is that it quietly walls off half the problem.

An organisation that defines its exposure as "disinformation about us" is looking for false claims. It will not have a natural place to file a network of impersonated support accounts, or a cloned login page advertised through paid social, or a payout-scam funnel using its logo — because none of those are primarily claims, and arguing about their truth value is beside the point. They are the same tradecraft, run by adjacent suppliers, often on shared infrastructure, against a different objective.

The same tradecraft that prepares the ground for a territorial claim also funnels victims into an investment scam. Organise your model around what the operator wanted and you need a new model every time the operator wants something different. Organise it around what the operator did and one model holds.

Where the terms still earn their place

None of this is an argument for abolishing the vocabulary. It is an argument about which layer it belongs on.

Once behaviour is established and evidence supports a finding about intent, disinformation is the correct and precise word, and it should be used. It is also the word that regulators, platform policy teams, journalists and boards actually think in — under the DSA, in platform enforcement language, in a briefing to a non-specialist audience.6 Refusing the term because it is analytically awkward makes findings harder to act on, which defeats the purpose.

And the distinction drives response. Misinformation spreading through people who believe it calls for correction, context, and trusted voices. Disinformation calls for disruption of the network carrying it — takedowns, referrals, infrastructure work, exposure. Reach for the wrong one and you either amplify an operation by arguing with it, or you try to fact-check a botnet.

So: the terms describe conclusions, and they are good at that. Detection runs on behaviour. Keep them in that order and both stay useful.

Notes

  1. Claire Wardle and Hossein Derakhshan, Information Disorder: Toward an Interdisciplinary Framework for Research and Policymaking, Council of Europe report DGI(2017)09 (Strasbourg: Council of Europe, September 27, 2017; 2nd rev. ed., August 2018), https://rm.coe.int/information-disorder-report-version-august-2018/16808c9c77. The origin of the mis-/dis-/mal-information distinction used throughout this piece; deliberately introduced as a replacement for "fake news," which the authors judged inadequate to the phenomenon. ↩

  2. Wardle and Derakhshan, Information Disorder. For malinformation specifically — genuine information deployed to cause harm, and the category that most clearly breaks the assumption that falsity is what makes information hostile. ↩

  3. Wardle and Derakhshan, Information Disorder. Cited here for the framework's structure — three types, three elements (agent, message, interpreter), three lifecycle phases — which describes information disorder well retrospectively but was not designed as a real-time detection model. ↩

  4. Nathaniel Gleicher, "Coordinated Inauthentic Behavior Explained," Meta Newsroom, December 6, 2018, https://about.fb.com/news/2018/12/inside-feed-coordinated-inauthentic-behavior/. The term's origin, and the source of the point relied on here: enforcement attaches to the behaviour of the network as a whole, not to the truth of any individual piece of content. ↩

  5. Meta, "Inauthentic Behavior," Transparency Center community standards, accessed August 2026, https://transparency.meta.com/policies/community-standards/inauthentic-behavior/. The current policy formulation, in which false identities being central to the operation is what separates CIB from ordinary coordination — and in which foreign interference is defined as a subset of CIB rather than a separate category. ↩

  6. Regulation (EU) 2022/2065 of the European Parliament and of the Council of 19 October 2022 on a Single Market for Digital Services (Digital Services Act), OJ L 277, 27.10.2022, p. 1, https://eur-lex.europa.eu/eli/reg/2022/2065/oj. Cited as an example of a regulatory regime that obliges platforms to assess and mitigate systemic risks framed in the language of disinformation, which is why the term retains operational value on the response side. ↩

Nobody debates whether a building needs a fire alarm system.

Nobody debates whether a building needs a fire alarm system.

Most tools tell you there's smoke. Vantage tells you which floor, who started it, whether it's spreading, and what conditions made your landscape fire-prone in the first place.

Most tools tell you there's smoke. Vantage tells you which floor, who started it, whether it's spreading, and what conditions made your landscape fire-prone in the first place.