The Four Worlds as a Cognitive Warfare Grid: the bullets land on your vocabulary, but the target is the layer underneath
The Kabbalistic emanation schema, written out as a machine-readable ontology, gives a defender the two things the standard advice cannot: a coordinate for where a cognitive attack lands, and a reason why what it changes is somewhere else entirely.
Key Judgements: the tradition gives you the coordinates, the file gives you the instrument
- The Four Worlds already describes how an idea becomes an action. Writing it as a file adds one thing: a stranger, or a machine, can now check a claim made with it.
- The bullets land on four things: language, social conventions, doctrine, ethics. An adversary can reach all four in public, without knowing anything else about your system. Access is what makes them the impact point, not importance.
- What the attack changes is not where it lands. The carriers sit on a loop running upward into inherited patterns and archetypes, amplified and delayed, then returning. That is why the symptom never resembles the cause: it reads as a group that changed its mind. The return leg is what makes the attack matter: a change to the deep patterns that never resurfaces as thought or behaviour would leave no trace and do no harm.
- The model predicts order, not timing. The lag is named but never measured, so it tells you which layer moves next, not when.
- These traditions already run the defence under other names: teaching in stages, testing a claim before accepting it, checking a lineage. The work is recognising them as controls and running them deliberately.
Situation: the advice a civilian is given runs on the layer that is already under attack
Cognitive warfare is a formalised military concept, not an informal description: a NATO-sponsored study records the claim that “the brain will be the battlefield of the 21st century”, sets out how operations in that space are built, and recommends the Alliance recognise a sixth, human domain to cover them (du Cluzel, 2020, Cognitive Warfare, NATO Innovation Hub). Read it with its interest in view: a sponsored paper arguing for a new domain has reason to want the threat to look large. What it establishes is that the concept is formalised — not how big the effect is.
Against that, the advice offered to individuals has not changed: apply faith, critical thinking, moral judgement. Each is real. But each runs on language, inherited social convention, doctrine and ethics — the four carriers this model names as the impact point. The process is only as trustworthy as the vocabulary it thinks in.
That is an asymmetry of cognition, not of information. A defender does not know where the bullets are landing, cannot see how a surface irritation connects to a deep commitment, and has no instrument that says this is the impact point. An attacker with a targeting doctrine has all three. The threat-model report in this series mapped the terrain; this briefing takes one artefact and asks what a defender can do with it.
Analysis: four stages, one surface spanning two of them, four carriers, and a loop that runs both ways
The four worlds are read here as architectural domains, stacked in order. The worlds and their order are classical; the architectural readings, the mind-technology column and the operational-property column are a 2026 synthesis laid over them. One point of precision: the four are stages of creation, and only the first is emanation proper.
| World | Architectural reading | Mind technology | Operational property |
|---|---|---|---|
| Atziluth (Archetypal) | entity, model | virtual universe (unconscious) — archetypes, rule-sets | purpose — raw material |
| Briah (Creative) | controller, business rules | genetic repository (subconscious) — logic, patterns | structure — formula |
| Yetzirah (Formative) | controller, business logic | fluid (thought and emotion) | feedback loop — amplification, delay |
| Assiah (Action) | boundary, view | ego system (manifestation, interpretation) | quantity and size — experience |
One attack surface crosses the boundary between the formative and active worlds — container / application logic — holding four components: language, social conventions, doctrine, and ethics. Call them the carriers: they are what an attack actually touches.
Why those four, and not others: all are transacted in the open — taught, published, repeated, enforced socially — so an adversary can act on them using only what is publicly observable. The deeper layers offer no comparable way in. Nothing addresses an archetype the way a curriculum addresses a vocabulary, and that difference in access is what makes the container the impact point. The file marks this as an assumption rather than a result: nothing inside the model derives it, and it is the first thing to attack.
The transport is the formative world’s operational property: a feedback loop with amplification and delay, running both ways — upward into the inherited and archetypal layers, downward returning the altered structure into thought, emotion and behaviour. Written out as an ontology it gains invariants: rules a claim has to satisfy, or it fails the check. Two carry the argument. An impact must resolve to a surface, never to a world (I4), which forbids the sentence the field reaches for most readily (the campaign attacked the collective unconscious). And an effect may name a world, but only by declaring its transport and direction (I5), which makes “the archetypes were targeted” checkable rather than atmospheric.
One caution. An earlier report on this site uses the Consciousness Virtualisation Platform, an ontology by the author of this model, whose container layer groups language, ethics, social norms and cultural expectations. The two agree closely — but two artefacts by one author agreeing tells you they are consistent, not that they are right.
The machine-readable model: four-worlds-threat-model-v1.0.yaml
→ four-worlds-threat-model-v1.0.yaml
Published as a file rather than a description of one: four worlds, the attack surface, the bidirectional transport, the threat vector with its impact and four effects, seven invariants. If an invariant is wrong, the file is the thing to show wrong.
Evaluation: it ranks the carriers and predicts the sequence — two limits, measuring across the boundary and the simplified grid’s coverage
It ranks the four carriers. Score each one on four things: how far it reaches, how easily it changes, what it costs to check, and how close it is to hardening into doctrine. The highest total is where an attacker gets the most for the least, so it is what to defend first. Three caveats, stated plainly: those criteria extend the schema rather than come from it, they are not independent of one another, and none has been checked against a recorded case. It is a prediction to write down in advance and test later, not a measurement.
It predicts the sequence — the usable half of a set-forward point. The term is from fire control: where a moving target will be when the shot arrives. That needs a direction and a time of flight, and this model has only the direction. It still explains why correcting the record afterwards underperforms. A meta-analysis of 32 experiments (N = 6,527) found that correction does not entirely eliminate misinformation’s influence — a marginal residual, r = −0.05 — and that corrections work less well the longer the gap between the misinformation and the correction (Walter & Tukachinsky, 2020). Those are laboratory corrections of stated falsehoods, not communities absorbing slow drift, and the delay those experiments varied was a filler task, not a season. What transfers is the sign of the finding, not its scale in either dimension.
The model adds what the evidence does not: where that gap comes from. A change committed into the inherited patterns comes back down as behaviour only after a lag this model does not measure. By the time there is anything visible to correct, the correction is already late — which is the condition the evidence says correction handles worst. The delay is not a side effect of the attack. It is what protects it.
Two limits, and both are structural.
The first is measuring an attack that crosses the boundary. The carriers sit on a surface spanning two worlds, and a tool that inspects one world at a time reports both neighbours clean while the traffic runs between them.
The second is what the simplified grid leaves out, and it is the sharper of the two. Atziluth carries a further link outward — not upward — to what lies beyond the four worlds, which needs the sequence of Ain, Ain Soph and Ain Soph Aur to set out properly. Leaving it out has a security cost. That link can be blocked, and blocking it is a different kind of attack: it lands on no carrier, and it works by cutting a group off from anything outside its own worldview, so nothing can ever contradict it. A grid with one impact point shows a battlefield, not the whole war.
Both limits are about scope. A third gap is about proof, and it is the one to hold onto: nothing here separates an attack from ordinary cultural change. The signature the model predicts — delayed, out of proportion, resistant to argument, no longer tracking events — is also what unremarkable drift looks like when a group simply changes over twenty years. The file lists no test that tells the two apart, and neither does this briefing. Until one exists, the grid locates a change well and says nothing about whether anyone aimed it.
The file’s own metadata classifies it as a decision — a doctrine artefact, superseded by revision rather than falsified by evidence. Argue with it; do not mistake it for a measurement.
Recommendation: inventory the four carriers, rank them, and hand the file to your AI assistant to diff them against what you already hold
1. Write the carrier inventory — one page, four lists. The words a group runs on; the norms it enforces without ever writing them down; the texts it treats as authoritative, and whoever interprets them now; the ethical commitments treated as settled. Most groups have never written this down, and that is itself the finding: you cannot notice drift in a set you never listed.
A training organisation lists its core terms and finds that one word central to its teaching has no agreed definition — each senior teacher supplies their own. Nothing would resist a change to it, and nothing would record that one had happened.
2. Score each carrier, and harden the top one this quarter. Score four things 1–5: how far it reaches, how easily it changes, what it costs to check, and how close it is to hardening into doctrine. Give the highest-scoring one a written definition, a named owner, and a change record — three artefacts, not a policy.
The highest score turns out not to be a doctrinal text but the everyday jargon used in every introductory session: enormous reach, trivially changed, nobody’s job, and already treated by newer members as settled.
3. Compare today’s definitions against material you already hold — this week, not next year. Almost every group sits on an earlier snapshot it has never read as one: old handbooks, recorded sessions, archived pages, a first syllabus. Write down today’s definitions from current usage without consulting those, then compare. Re-check anything easy to change far more often than annually, because sampling once a year tells you that something moved and not what moved it.
A group compares its introductory language against a recording from four years ago. A term that used to mean a demanding practice now routinely means a purchasable experience. Nobody decided it, nobody announced it, and the comparison is the first time anyone noticed.
4. Keep a dated log of what comes back down. The return leg shows up as behaviour, not vocabulary, so it needs its own record — one line each: the date, what was said or done, and which carrier you think produced it. Worth logging: feeling out of proportion to what triggered it and that survives being argued with, and people describing themselves as chosen or set apart. What makes an entry meaningful is the lag — a returned effect keeps going after whatever set it off has stopped, and no longer matches what is actually happening.
Short-form video reliably provokes strong feeling. Long afterwards, that same audience describes itself as distinct from and above some out-group, and people arrive already holding the reasons, experiencing them as their own conclusions. The visible event is the hostility; the impact point was the vocabulary that made the distinction sayable.
Using the file with an AI assistant
You do not need to read YAML. Hand the file to whichever assistant you already use, along with your own material, and ask it to do the work. Four prompts, one per task above:
- “Here is our handbook. Using the four carriers in this model, sort what you find into four lists — language, social conventions, doctrine, ethics — and quote where each one came from.”
- “Score each carrier 1–5 for reach, ease of change, cost of checking, and how settled it has become. Show your reasoning for the highest one.”
- “Here is our current introductory text, and here is our version from four years ago. List every term whose meaning has changed, and quote both.”
- “Check this claim against the invariants in the file.” — then paste something you have read about a cognitive attack.
Hand it the file rather than describing the model: the invariants are written as rules, so the assistant has something to test a claim against instead of agreeing with you. If it reports that a claim breaks one, you have a specific thing to check. And if an invariant is itself wrong, one documented counter-example is enough to show it — the file is published so that anyone can build one.
We analyse structure, not people. The model examined here is a doctrine artefact, presented as judgement rather than measurement, and its agreement with the adjacent in-house ontology is composition by a shared author rather than independent corroboration. No specific community, organisation, or practitioner is identified, and no example describes a specific group. The patterns are the artefact.