HCOMP 2026 / CI 2026 · Workshops Day

Cognitive Security for Human–AI Systems

A full-day workshop on protecting the conditions under which people and groups reason for themselves as generative and agentic AI reshape attention, belief, memory, judgment, and agency.

DateSeptember 27, 2026
WhereNear Washington, DC — Virginia Tech Academic Building One, Alexandria, VA · in person + hybrid
FormatFull day (~7 hrs)
RegistrationEarly rates extended to August 28, 2026
The Workshop

Overview

As generative and agentic AI become embedded in search, education, companionship, and decision support, a class of risk emerges that we lack a shared way to name, test, and govern: a single model output may be accurate and disclosed, yet the risk lies in how systems shape attention, belief formation, memory, judgment, and agency across many interactions — and how they reshape collective sensemaking.

CogSec proposes cognitive security — the integrity of the conditions under which people and groups reason for themselves — as a research agenda between HCOMP (AI-assisted decision-making, over- and under-reliance, oversight) and CI (misinformation, deliberation, civic decision-making). The day is anchored by a hands-on session that builds the Cognitive Vulnerability and Mitigation Catalog (CVMC): a schema pairing each AI affordance and cognitive vulnerability with a candidate mitigation, evaluation metric, burden-and-equity check, and governance hook. Attendees leave having co-authored catalog entries and a community roadmap.

Topics in Scope

Workshop themes

The workshop's deliberate spine is the CVMC and the measurement of cognitive over- and under-reliance. The remaining themes are application surfaces.

Cognitive vulnerabilities

Attention (epistemic flooding, attentional capture); belief and judgment (fluency overtrust, authority transfer, personalized persuasion); memory and provenance (context collapse, source confusion); learning (cognitive offloading, skill atrophy); agency (automation deference, emotional dependency, agentic misalignment).

Measurement

Over- and under-reliance, appropriate reliance, and calibration in AI-assisted decision-making; longitudinal and ecological evaluation; metrics for conversion, persistence, dependence, provenance, calibration, and skill retention.

Collective sensemaking

Misinformation and influence operations, polarization, content moderation and governance, deliberation, prebunking and inoculation, and civic decision-making.

Defensive human computation

Crowdsourced verification, source credibility, provenance and content authenticity, and deepfake and synthetic-media detection.

Design & governance

Frictional and cognitive-forcing design; auditing, red-teaming, incident reporting; and alignment to standards (NIST AI RMF, EU AI Act, ISO/IEC 42001).

The CVMC Jam

Mixed groups of 4–6 each take a deployed AI affordance and draft a catalog entry end to end: affordance → vulnerability → failure pattern → mitigation → metric → burden-and-equity check → governance hook. Every attendee leaves with an artifact.

Program

Program

A full day with coffee breaks and a lunch hour. Every accepted paper presents as a lightning talk; virtual posters in the digital gallery are an optional complement.

🗓️
Times: TBA. Decisions went out August 20 and the session structure below is confirmed. Clock times, the talk order, and remaining speakers will be posted once the conference assigns rooms and slots.
Opening

Opening framing

Setting the cognitive-security agenda for the day.

15 min
Keynote

Keynote — AI, influence, and collective sensemaking

The landscape of AI-mediated influence on human and collective cognition.

45 min
Talks I

Contributed lightning talks I

Accepted papers in 4-minute talks with 1 minute of Q&A.

30 min
Break

Coffee

Panel 1

Reliance, oversight & frictional system design

Cognitive-forcing functions, microboundaries, and seams.

45 min
Talks II

Contributed lightning talks II

Accepted papers in 4-minute talks with 1 minute of Q&A.

30 min
Break

Lunch

Boxed lunch included in workshop-day registration; the digital gallery is browsable throughout.

Panel 2

Belief, manipulation & cognitive resilience

Persuasion, prebunking, and what works.

45 min
Talks III

Contributed lightning talks III

Accepted papers in 4-minute talks with 1 minute of Q&A.

30 min
Break

Coffee

Build

CVMC Jam — build phase

Mixed tables draft catalog entries end to end. Template, worked example, facilitator, and scribe per table — including a dedicated all-remote table.

75 min
Report-out

CVMC Jam — report-out & review

Every entry reviewed against the schema before release.

35 min
Closing

Closing synthesis & roadmap

A community measurement roadmap and next steps.

20 min

Contributed talks — confirmed to date

Accepted papers whose authors have registered or confirmed their attendance so far, grouped by theme. The list grows as remaining authors confirm; the final talk order will be posted with the detailed schedule.

Vulnerabilities & mechanisms

  • AI-associated Delusions: A Sentinel Case of Epistemic DriftMarlynn Wei (Private Practice, New York, NY)
  • Between Mind and Machine: Taking the Intentional Stance Toward AI Predicts Reliance Beyond General AnthropomorphismCarl Michael Galang, Khaled Hassanein, Milena Head (McMaster University)
  • Epistemic Risk from False Memory Implantation by Use of Conversational AIJulia Shaw (King's College London, Institute for AI; Centre for the Governance of AI), Carla Zoe Cremer (AI Psychological Research Coalition)

Measurement & evaluation

  • The Watchtower Imperative: Lifespan-Calibrated Evaluation for Frontier AICasey M. Williams (University of Kansas), Jennifer Victoria Scurrell (ETH Zurich / University of Zurich)
  • Connectedness, Cognitive Load, and Human-AI Oversight in Cyber OperationsNathan Conklin (Virginia Tech)
  • Cognitive Security as a Technical Problem: Assistance Timing, Removed-Tool Evaluation, and Two Catalog Entries for AI-Mediated LearningHao-Tian Lu, Kuan-Wei Lu (Junyi Academy Foundation)
  • How Well Does AI Peer Review Work? A Benchmark Built from 100 Planted ErrorsPaul Litvak (Robyn Dawes Institute)
  • The Market for Synthetic Lemons: What Can George Akerlof Teach Us About Safeguarding Cognitive Security?Dennis Murphy (Georgia Tech), Jon Lindsay

Governance, collective sensemaking & framing

  • The Accountability Regime as Cognitive Infrastructure: How Organizational Design Determines Whether Cognitive Security Interventions FunctionShefali Patil (University of Texas at Austin)
  • The Field Guide to Thinking for OurselvesAllegra Cohen
  • Shaping Deepfake Non-Consensual Intimate Imagery Prevention and Intervention Strategies through Frontline PerspectivesRiya Ranjan (Stanford University)
  • Collective Cognitive Security by Design: What Makes Human Groups Cognitively Secure and Agentic in AI-Rich Environments?Anat Levy-Raz (University of Haifa)

The digital gallery

Every accepted paper gets a page in a digital gallery, browsable throughout the workshop day and kept up afterward alongside the CVMC release. Each page carries the program listing — title, authors, abstract. Anything beyond that is the authors' choice: a one-page poster, a short captioned video, a plain-text summary, or the paper itself, each opt-in. The gallery is identical for in-person and remote attendees.

For accepted authors

Every paper presents as a 4-minute lightning talk with 1 minute of Q&A; all decks are collected and pre-loaded ahead of the day, for in-person and remote speakers alike. We will request gallery materials in early September, and slides are due about a week before the workshop. At least one author per paper must register — early rates now run through August 28 — and nothing else is needed before September.

Speakers

Confirmed speakers

Additional keynote and panel speakers are being confirmed on the standard timeline and will be posted here.

Confirmed · Panel 1
Brett Frischmann

Brett Frischmann

Villanova University · Widger Chair in Law, Business & Economics

Co-author of Re-Engineering Humanity (Cambridge, 2018); his work on friction-in-design and prosocial friction anchors the workshop's design thread. Organizer.

Confirmed · Panel 1
Ujwal Gadiraju

Ujwal Gadiraju

TU Delft · Web Information Systems

Associate Professor at TU Delft and director of the Delft AI "Design@Scale" Lab; Co-Editor-in-Chief of the Human Computation Journal. His research spans crowd computing, human-centered AI, and human–AI interaction.

Confirmed · Panel 2
Aruna Sankaranarayanan

Aruna Sankaranarayanan

MIT CSAIL / EECS

Researcher at MIT (CSAIL / EECS) working on manipulated media, deepfakes, and their effects on elections and public trust. Her study on human detection of political-speech deepfakes was published in Nature Communications (2024).

Confirmed · Governance
Nick Caputo

Nick Caputo

Oxford Martin AI Governance Initiative

Legal researcher at the Oxford Martin AI Governance Initiative studying frontier-AI regulation, legal alignment, and AI governance institutions; a Harvard Law graduate.

Call for Participation

Contribute to CogSec 2026

The call is now closed. CogSec brings together work on how AI-mediated systems shape — and can protect — human attention, belief formation, memory, judgment, agency, and collective sensemaking.

What the call covered

Short papers, position papers, demos, and datasets (non-archival) on measuring over- and under-reliance; the cognitive vulnerabilities above; persuasion and manipulation; misinformation, prebunking, and deliberation; crowdsourced verification and provenance; deepfake detection; frictional and cognitive-forcing design; and the auditing and governance of cognitive risks.

Submission format

2–6 pages (excluding references) in the ACM Primary Article Template (LaTeX and Word versions available; an Overleaf template is also provided), or an extended abstract plus demo description. The call closed on August 17, 2026. At least one author of each accepted paper must register and present. Accepted work appears as a lightning talk and/or poster, and all participants join the hands-on session that builds the community CVMC. Review is single-blind — submissions need not be anonymized — with each receiving at least two reviews and organizers recusing from any conflicts; selection is lightweight (relevance, clarity, discussion potential).

Key dates

Aug 17, 2026
Submissions closed
Aug 20, 2026
Notifications sent
Aug 21 Aug 28, 2026
Early registration ends Extended
Sep 27, 2026
Workshop

Decisions went out to all authors on August 20, and the conference has since extended early-bird registration to Friday, August 28 — so accepted authors can still register at the early rate.

Submissions are closed

The call closed on August 17, 2026 (AoE). Thank you to everyone who sent work. Decisions went out to all authors on August 20, and the accepted talks confirmed so far are listed in the program. Authors can review their submission on EasyChair.

You do not need an accepted paper to take part. CogSec is open to anyone who registers, and the CVMC Jam is built so that every person in the room helps produce the catalog. Questions? Reach the organizers by email.

Register to attend → Email the organizers →

Registration is open

Early rates extended: the conference has moved the early-bird deadline from August 21 to Friday, August 28, 2026. CogSec runs on the HCOMP / CI 2026 workshop day, Sunday September 27, and you can register for the workshop day on its own without registering for the main conference. Workshop-day registration includes snacks and a boxed lunch; full-conference registration (Sep 27–30) covers the workshop day too.

Workshop dayEarly
through Aug 28
Regular
by Sep 4
Late
after Sep 4
Student$90$100$110
ACM member$125$150$175
Non-member$175$200$225

You do not need to submit a paper to attend — everyone is welcome. At least one author of each accepted paper must register and present; with the extension, accepted authors can still register at the early rate. The workshop is hybrid, so remote attendance is an option.

Register → Rates & details →
Organizers

Organizing committee

Organized with institutional backing from the Stanford HAI Cognitive Security Task Force.

Utsav Gupta

Utsav Gupta

Stanford HAI Cognitive Security Task Force · Stanford University · Lead organizer

Co-leads the Task Force and its speaker series; lead author of the CVMC work accepted at the 3rd Frictional AI Workshop (HHAI 2026) and the 2026 Trust and Safety Research Conference.

Brett Frischmann

Brett Frischmann

Villanova University

Widger Chair in Law, Business & Economics; co-author of Re-Engineering Humanity. Brings extensive convening experience from the Workshop on Governing Knowledge Commons.

Eric Heng

Eric Heng

Stanford University · Cognitive Security Task Force

Co-Lead of the Cognitive Security Task Force and co-author of the 2026 position paper AI Development Should Prioritize Cognitive Security.

Andreas Haupt

Andreas Haupt

Stanford HAI · Stanford Digital Economy Lab

HAI Postdoctoral Fellow (Ph.D., MIT CSAIL) researching human–AI evaluation, oversight, and platform incentives; previously with the U.S. FTC and the European Commission.

Harram Mansoor

Harram Mansoor

Inter-American Development Bank · IFI AI Working Group

Tech Lead of AI at the IDB and chair of the IFI AI Working Group, coordinating AI governance across international financial institutions and multilaterals; previously worked with DHS and Google on the interaction between AI systems and neurodivergent cognition. Her research examines how autonomous AI shifts the public-sector attack surface from access to belief.

Rebecca Neff

Rebecca Neff

University of Pennsylvania · Cognitive Security Task Force

Studies computer science at the University of Pennsylvania and serves on the Georgetown University Board of Regents, bringing an institutional-governance perspective alongside her technical work. A member of the Cognitive Security Task Force.