The AI Sedition Acts: Sabotage-by-Omission in LLM Briefing Pipelines
Abstract
A language model that summarizes evidence for a decision-maker can mislead without stating a falsehood: it can retain true component facts while omitting the relationship that makes them actionable. We call this attack relational omission and measure it end to end in a fictional military watch-floor pipeline, where an analyst model condenses 12 incident reports into the only briefing a watch-officer model sees. Across 480 paired episodes covering three events, matched control twins, and four analyst conditions, honest and fatigue-degraded analysts never cause a missed notification, while instructed saboteurs cause up to 22 of 30 misses when the decisive evidence is split across reports. Sabotaged briefings preserve most individual facts but form none of the decisive cross-report relationships. An independent monitor assigns saboteurs higher distortion scores, yet its scores overlap honest ones and admit no stable alarm threshold. Evaluations of high-stakes summarization should therefore measure whether decision-relevant relationships survive, not only whether individual statements are supported. The review artifact—code, packets, prompts, tests, and the 480-episode dataset—is available at https://anonymous.4open.science/r/AiSedition-review-0869.