Insights & Commentary
•
Online manipulation / CIB / FIMI

What Counts as Disinformation? A Working Taxonomy for Analysts

Denis Starovoytov
25 Sep 26
•
4 min read

"Disinformation" gets used as a catch-all in everyday conversation - anything false, misleading, or simply disagreeable online. For analysts, regulators, and election observers, that looseness is a problem. Whether a piece of content gets flagged, how a finding gets reported, and whether a conclusion survives scrutiny from a regulator or a court all depend on which term actually applies, and why. This piece sets out the working taxonomy the field actually uses, and the criteria behind each term.

The foundational split: three types of information disorder

The starting point for almost all serious work in this field is a 2017 Council of Europe report by researchers Claire Wardle and Hossein Derakhshan, which introduced "information disorder" as an umbrella term and split it into three categories along two axes: whether the content is false, and whether it was created or shared with intent to cause harm.

Term Is the content false? Was there intent to cause harm?
Misinformation False or misleading No — shared without harmful intent, though the effects can still be harmful
Disinformation False or misleading Yes — created or shared deliberately to deceive or cause harm
Malinformation Genuine, factually accurate Yes — true information deliberately weaponised, such as leaking private material or stripping real content of its context

This distinction matters operationally. A researcher who shares an outdated statistic in good faith is producing misinformation. A network deliberately fabricating a scandal to damage a candidate is producing disinformation. Someone leaking a real private document specifically to harm its subject is producing malinformation - genuinely true content, weaponised.

Do they know it's false? A psychological layer 

Psychological research adds a further layer to the intent criterion behind disinformation. A 2024 paper led by Stephan Lewandowsky, with Sander van der Linden and colleagues, "Liars Know They Are Lying: Differentiating Disinformation from Disagreement," argues that what separates disinformation from a genuinely held, if mistaken, opinion is not just coordinated behaviour, but whether the speaker's own internal state shows they know their claim is false. This gives analysts a second, complementary test alongside the EEAS's behavioural framework: not only does the activity look coordinated and inauthentic, but is there evidence the actor knows what they're saying isn't true. The two tests - one behavioural, one psychological - tend to reinforce each other in practice, but they're not the same question. 

A broader view of misinformation 

Sander van der Linden, a Cambridge psychologist and one of the field's most cited misinformation researchers, has argued that even these definitions may be too narrow. In a 2024 Science commentary written with Yara Kyrychenko, he points to evidence that content never flagged as misinformation, but still misleading through selective framing rather than outright falsehood, can have a larger real-world effect than content that is flagged, simply because it spreads further and faces no friction. It is a useful caution for analysts: a piece of content can pass every test in the taxonomy above and still function as manipulation. 

The EU's working definition

The European Commission uses a related but more compact operative definition, the one that underpins the Code of Practice on Disinformation and its integration into the Digital Services Act: disinformation is false or misleading content spread with an intention to deceive or secure economic or political gain, which may cause public harm. Misinformation, in the same framework, is false or misleading content shared without harmful intent, even though its effects can still be harmful. The core logic matches Wardle and Derakhshan's: falsity plus intent is what separates the two - the Commission's version simply folds "false" and "misleading" together and adds an economic-gain motive alongside the political one, reflecting that a lot of real-world disinformation is monetised, not just ideological.

Why content alone isn't a sufficient test

Both frameworks above are content-first: they ask whether a specific piece of information is true or false, and why it was shared. That works well for individual claims, but it breaks down for organised campaigns, which is precisely why the EEAS developed a separate, narrower-yet-broader concept: Foreign Information Manipulation and Interference (FIMI).

FIMI is defined by the EEAS as a mostly non-illegal pattern of behaviour that threatens or has the potential to negatively impact values, procedures, and political processes - manipulative in character, conducted intentionally and in a coordinated manner, by state or non-state actors or their proxies. Two things about that definition are deliberate. First, FIMI is narrower than disinformation because it only covers foreign actors, not domestic ones - a distinction the field marks separately as DIMI (Domestic Information Manipulation and Interference) when the same tactics originate at home. Second, FIMI is broader than disinformation because it does not require the underlying content to be verifiably false. A coordinated network amplifying technically accurate information, at an artificial scale, timed to manipulate a political process, can still constitute FIMI - because the object of concern has shifted from the content to the behaviour.

The criteria analysts actually apply: the ABCDE framework

If behaviour, not just content, is the object of analysis, a campaign needs a structured way to characterise that behaviour - not just an impression that something looks coordinated. The EEAS's own methodology, building on a framework originally proposed by researcher Camille François and later extended by James Pamment, breaks an incident down into five elements:

Actor - who is behind the activity, and is their identity being concealed or misrepresented

Behaviour - is the activity coordinated, inauthentic, or deceptive in how it operates (synchronised posting, fake account networks, artificial amplification)

Content - what is actually being said or shown, and is it false, misleading, or genuine

Degree - how large is the campaign's reach and how sophisticated is its execution

Effect - what measurable impact did it have on the information environment or the target audience

This is the practical answer to "how do you know it's disinformation and not just an unpopular opinion, or a coincidence." No single element is decisive on its own. A single anonymous account is unremarkable; a thousand accounts posting the same sentence within a three-minute window is a behavioural signal regardless of whether that sentence happens to be true. The strength of a finding comes from how many of the five elements point the same direction, and how well each one is documented.

The operational toolkit

Two further tools, both referenced directly in EEAS methodology, turn this framework from a way of thinking into something that produces comparable, shareable findings. DISARM is an open-source framework for cataloguing the specific tactics, techniques, and procedures used in information operations - built deliberately on the same logic as cybersecurity's MITRE ATT&CK framework, so that a technique observed in one campaign can be named and recognised consistently in the next one. STIX is a standardised data-sharing format that lets different organisations - a national security service, an EU institution, a research NGO - exchange findings about the same incident in a structured, machine-readable way rather than a narrative writeup that has to be manually reconciled.

Why the precision matters

None of this is academic hair-splitting. Whether an incident is classified as misinformation, disinformation, or FIMI determines who has standing to respond, what legal or regulatory levers apply, and what kind of evidence a finding needs to survive contact with a sceptical audience - a journalist, a court, or a foreign ministry summoning an ambassador. The EEAS's own definition explicitly calls FIMI "mostly non-illegal" - a deliberate acknowledgment that most of this activity sits outside existing law, which is exactly why the analytical rigour of the classification matters more, not less. A finding built on a clear taxonomy and a documented ABCDE breakdown holds up. A finding built on "this looks like disinformation" does not.

Sources

1. Council of Europe - Claire Wardle and Hossein Derakhshan, Information Disorder: Toward an Interdisciplinary Framework for Research and Policy Making (2017): https://www.coe.int/en/web/freedom-expression/news/-/asset_publisher/thFVuWFiT2Lk/content/tackling-disinformation-in-the-global-media-environment-new-council-of-europe-report

2. European Commission - Tackling Online Disinformation: https://digital-strategy.ec.europa.eu/en/policies/online-disinformation

3. EEAS - 1st EEAS Report on Foreign Information Manipulation and Interference Threats (February 2023), via EUvsDisinfo: https://euvsdisinfo.eu/eeas-1st-fimi-threat-report-february-2023/

4. EEAS - Information Integrity and Countering Foreign Information Manipulation & Interference (FIMI): https://www.eeas.europa.eu/eeas/information-integrity-and-countering-foreign-information-manipulation-interference-fimi_en

5. Lewandowsky, S., Ecker, U., Cook, J., van der Linden, S., Roozenbeek, J., Oreskes, N., & McIntyre, L. C. (2024). Liars Know They Are Lying: Differentiating Disinformation from Disagreement. Nature Humanities and Social Sciences Communications, 11, 986. (Lead author: Stephan Lewandowsky; van der Linden is a co-author, fourth of seven.) https://www.nature.com/articles/s41599-024-03503-6

6. Sander van der Linden, S., & Kyrychenko, Y. (2024). A broader view of misinformation reveals potential for intervention. Science, 384(6699), 959-960. (Two authors: van der Linden and a researcher from his own lab - this one is genuinely his own argument.) https://www.science.org/doi/10.1126/science.adp9117

‍

Denis Starovoytov
25 Sep 26
•
4 min read
Ready to
explore Trementum?

If you’d like to see how Trementum Platform could work on your data, we can prepare a live demo tailored to your use cases.