Coordinated online information operations, platform manipulation, and algorithmic feed integrity — requests submitted to UK public authorities
| Authority | Act | Sent | Acknowledged | Due | Outcome |
|---|---|---|---|---|---|
| DSIT | FOIA 2000 | — | — | — | Awaiting |
| Police Scotland | FOISA 2002 | — | — | — | Awaiting |
| Ofcom | FOIA 2000 | — | — | — | Planned |
| Cabinet Office | FOIA 2000 | — | — | — | Planned |
| Scottish Police Authority | FOISA 2002 | — | — | — | Planned |
| National Crime Agency | FOIA 2000 | — | — | — | Planned |
Independent of whether any individual answer comes back positive, negative, or redacted, the categories of information requested here sit squarely in the public interest for reasons that have nothing to do with the more speculative framing (MITM interception, "bot armies") in some of the individual questions. FOIA and FOISA both apply a public interest test to qualified exemptions (s.2 FOIA 2000 / s.2 FOISA 2002): even where an exemption technically applies, the authority must weigh the harm of disclosure against the public's interest in knowing. The points below are the public-interest case for each broad category, kept separate from the specific (and unconfirmed) practices named in the requests.
DSIT's Counter Disinformation Unit and its successor, NSOIT, have already drawn parliamentary and press scrutiny (House of Lords Communications and Digital Committee, and reporting by outlets including Big Brother Watch's FOI-based investigations) over whether monitoring of "disinformation" extended to lawful speech by MPs, journalists, and the public. The public has a documented, pre-existing interest in knowing the criteria a government unit uses to flag citizen speech, separate from any question about bots or MITM.
The UK held a General Election in 2024, and the Intelligence and Security Committee's 2020 Russia report and subsequent Electoral Commission statements have already established that foreign interference in UK elections is an acknowledged risk category, not a fringe theory. Knowing what assessment work has been done, and whether it fed into public guidance, is core to informed civic participation.
Where a public body procures or develops tools capable of shaping what citizens see online — even defensively — the public has an interest in knowing the scale, cost, and oversight of that capability, on the same logic that underpins existing transparency regimes for surveillance cameras and biometric technology (Surveillance Camera Code of Practice, Biometrics and Surveillance Camera Commissioner).
If criteria for flagging "coordinated inauthentic behaviour" are broad, vague, or undisclosed, ordinary political expression can be misclassified and actioned without the speaker ever knowing why. Publishing the criteria (not the operational detail) lets people understand what is and isn't likely to draw attention, which is a recognised safeguard against overreach.
Commissioned research and procurement contracts are public spending. Titles, dates, authors, and contract values (as distinct from methodology or vendor trade secrets) are the minimum disclosure needed for the public to judge whether spending in this area is proportionate and effective.
Ofcom's new powers under the Online Safety Act 2023 make the terms on which government bodies coordinate with platforms a live and evolving area of policy. MOUs and protocols in this space set precedent for how much influence the state has over content moderation decisions — a question relevant to press freedom as much as to disinformation policy.
Some of the items above rest on premises I cannot currently support with public evidence. Setting out in advance what would count as confirming or ruling out each one is the difference between a transparency exercise and a search for material that fits a conclusion already reached. These criteria are fixed before any response arrives, so they can't be quietly adjusted afterwards to accommodate whatever comes back.
Online Safety Act 2023 workstreams on coordinated inauthentic behaviour produce written outputs, and Ofcom publishes extensively on its own initiative. Low national-security exposure. Best first target for anything about platform-side manipulation and the regulatory response to it.
Holds board papers, budget lines, and oversight correspondence covering Police Scotland capability. As an oversight body it is structurally less defensive than the force it oversees, and frequently a better route to the same underlying information. FOISA 2002.
Holds Defending Democracy Taskforce material. The documents certainly exist, but s.35 (policy formulation) and s.24 are heavily applied. Metadata-only requests — titles, dates, attendee lists, terms of reference — are far more likely to succeed than requests for content.
Subject to FOIA 2000 but with broad exemptions across its intelligence functions. Worth a narrow, procurement-focused request rather than anything touching capability or tasking.
Relevant material sits close to counter-terrorism and state threats, so s.23 (security bodies, absolute) and s.24 apply broadly and NCND is common. Included for completeness rather than expectation.
Qualified vs. absolute exemptions. Most of the exemptions flagged above (s.31 law enforcement, s.36 effective conduct of public affairs, s.43 commercial interests under FOIA; the FOISA equivalents) are qualified, not absolute — the authority is legally required to run the public interest test (s.2) and, if it withholds information, to state which exemption it relied on and give at least a brief indication of how the balance was struck. A response that withholds everything with no explanation of that balancing exercise is itself challengeable.
NCND is not unlimited. Neither-confirm-nor-deny responses under s.23/s.24 FOIA (or the FOISA equivalent) are meant to be used where confirming or denying the existence of information would itself cause harm — e.g. revealing operational capability. Public authorities sometimes over-apply NCND to categories, like whether a public advisory was ever issued, where the fact of existence is not obviously sensitive. Each NCND response can be queried via internal review.
Escalation path. If a request is refused, partially refused, or not answered within the 20-working-day deadline, the next steps are: (1) request an internal review from the same public authority, then (2) if unsatisfied, appeal to the relevant regulator, which can order disclosure. The two regimes have different regulators and this matters: FOIA 2000 requests (DSIT, Cabinet Office, Home Office, Ofcom, NCA) go to the Information Commissioner's Office at ico.org.uk. FOISA 2002 requests (Police Scotland, the Scottish Police Authority, Scottish Government) go to the Scottish Information Commissioner at itspublicknowledge.info. There is no reserved-matters carve-out sending Scottish public authorities to the ICO — sending a FOISA appeal to the wrong regulator wastes the appeal window, which is six months from the internal review outcome under FOISA and three months under FOIA.
Internal review timing. Under FOISA an authority has 20 working days to complete an internal review. FOIA sets no statutory deadline for internal review, but ICO guidance expects 20 working days and 40 in exceptional cases; an authority that exceeds 40 working days can be complained about to the ICO without waiting further.
Distinguishing outcome from claim. A refusal or heavy redaction on national security grounds is not evidence that the underlying claim (e.g. MITM feed manipulation) is true — it is equally consistent with there being nothing on file, and the exemption being invoked defensively or as a blanket policy for a whole subject area. This page will record the actual response text for each item once received, rather than treating silence or redaction as confirmation either way.