FOI / FOISA Request Tracker

Coordinated online information operations, platform manipulation, and algorithmic feed integrity — requests submitted to UK public authorities

Freedom of Information Act 2000 Freedom of Information (Scotland) Act 2002 Submitted
About this page. This tracks two formal information requests I have sent — one to the Department for Science, Innovation and Technology (DSIT), and one to Police Scotland referencing the National Crime Agency. The requests below are reproduced as sent: they are questions asked, not claims of fact. I have no confirmation that any of the described capabilities, policies, or practices (e.g. "bot armies," feed-level MITM interception) exist as described — that is precisely what the requests are trying to establish. Expect heavy redaction or outright refusal on national security (s.24/s.31 FOIA, s.31/s.35 FOISA), law enforcement, and commercial-confidentiality grounds; that likelihood is noted for each section.

Correction log. Two errors in an earlier version of this page have been fixed: (1) the FOISA exemption references have been corrected — under FOISA 2002, s.31 is national security/defence, s.35 is law enforcement, and s.33 is commercial interests; (2) the escalation path incorrectly stated that the ICO handles FOISA appeals for reserved matters. It does not. All FOISA appeals go to the Scottish Information Commissioner; the ICO handles FOIA 2000 only.

Response log

Updated as each response arrives. Deadlines are 20 working days from receipt, excluding weekends and bank holidays.
Authority Act Sent Acknowledged Due Outcome
DSIT FOIA 2000 Awaiting
Police Scotland FOISA 2002 Awaiting
Ofcom FOIA 2000 Planned
Cabinet Office FOIA 2000 Planned
Scottish Police Authority FOISA 2002 Planned
National Crime Agency FOIA 2000 Planned
Full response text will be reproduced verbatim as it arrives, including refusal notices and the exemptions cited. Where an authority states that information is not held, that will be recorded with the same prominence as a disclosure — a negative answer is a result, not an absence of one.

Why this is worth asking about

Independent of whether any individual answer comes back positive, negative, or redacted, the categories of information requested here sit squarely in the public interest for reasons that have nothing to do with the more speculative framing (MITM interception, "bot armies") in some of the individual questions. FOIA and FOISA both apply a public interest test to qualified exemptions (s.2 FOIA 2000 / s.2 FOISA 2002): even where an exemption technically applies, the authority must weigh the harm of disclosure against the public's interest in knowing. The points below are the public-interest case for each broad category, kept separate from the specific (and unconfirmed) practices named in the requests.

Democratic accountability

DSIT's Counter Disinformation Unit and its successor, NSOIT, have already drawn parliamentary and press scrutiny (House of Lords Communications and Digital Committee, and reporting by outlets including Big Brother Watch's FOI-based investigations) over whether monitoring of "disinformation" extended to lawful speech by MPs, journalists, and the public. The public has a documented, pre-existing interest in knowing the criteria a government unit uses to flag citizen speech, separate from any question about bots or MITM.

Electoral integrity

The UK held a General Election in 2024, and the Intelligence and Security Committee's 2020 Russia report and subsequent Electoral Commission statements have already established that foreign interference in UK elections is an acknowledged risk category, not a fringe theory. Knowing what assessment work has been done, and whether it fed into public guidance, is core to informed civic participation.

Proportionality of state power

Where a public body procures or develops tools capable of shaping what citizens see online — even defensively — the public has an interest in knowing the scale, cost, and oversight of that capability, on the same logic that underpins existing transparency regimes for surveillance cameras and biometric technology (Surveillance Camera Code of Practice, Biometrics and Surveillance Camera Commissioner).

Chilling-effect risk

If criteria for flagging "coordinated inauthentic behaviour" are broad, vague, or undisclosed, ordinary political expression can be misclassified and actioned without the speaker ever knowing why. Publishing the criteria (not the operational detail) lets people understand what is and isn't likely to draw attention, which is a recognised safeguard against overreach.

Value-for-money scrutiny

Commissioned research and procurement contracts are public spending. Titles, dates, authors, and contract values (as distinct from methodology or vendor trade secrets) are the minimum disclosure needed for the public to judge whether spending in this area is proportionate and effective.

Precedent for platform-government relationships

Ofcom's new powers under the Online Safety Act 2023 make the terms on which government bodies coordinate with platforms a live and evolving area of policy. MOUs and protocols in this space set precedent for how much influence the state has over content moderation decisions — a question relevant to press freedom as much as to disinformation policy.

Request 1 — DSIT: Online Information Operations Research & NSOIT

Recipient: Department for Science, Innovation and Technology · Act: FOIA 2000 · Status: Submitted, awaiting response (20 working day statutory deadline)
  1. Any research, evaluation, or internal assessment held by the department concerning the measurable effectiveness or public impact of coordinated online information operations — including automated account networks, synthetic profiles, and manipulation of content recommendation systems. Includes work commissioned from external researchers or contractors.
    likely s.43 commerciallikely s.36
    Why it mattersPublic bodies routinely commission research from external contractors on public-opinion topics; knowing what was studied, by whom, and at what cost lets taxpayers and researchers assess whether the conclusions drawn (and any policy built on them) rest on sound methodology rather than being taken on faith.
  2. Any assessment or briefing held by the department concerning the influence of such activity on UK electoral processes or public opinion during elections.
    likely s.24 national security
    Why it mattersVoters are entitled to know whether the government believes UK elections were meaningfully affected by online manipulation, and if so, on what evidence — this is core information for public trust in electoral outcomes, independent of any specific technique named elsewhere in this request.
  3. Any guidance, standard operating procedures, or terms of reference governing the work of the National Security Online Information Team (NSOIT), including its criteria for identifying content or accounts of concern.
    NSOIT is DSIT's successor unit to the former Counter Disinformation Unit (CDU) / Rapid Response Unit. Its operating criteria have not been made public in detail as of this writing.
    likely s.31 law enforcement
    Why it mattersThe predecessor unit was already reported to have flagged posts by sitting MPs and journalists for platform action. Publishing the criteria used to decide what counts as "content of concern" — not operational case files — is a direct, low-risk way to let the public judge whether the threshold is drawn narrowly enough to avoid catching ordinary political speech.
  4. A list (titles, dates, and authors only) of internal briefings, assessments, or commissioned research produced on these topics during the relevant period.
    Metadata-only request — designed to survive redaction of substantive content even if the underlying documents are withheld.
    Why it mattersEven a bare list establishes the scale and cadence of government attention to this issue and gives journalists and researchers a map of what to request next under more specific, harder-to-refuse follow-ups.
  5. Any memoranda of understanding, terms of reference, or protocols governing DSIT's engagement with online platforms, Ofcom, or other public bodies in relation to coordinated inauthentic behaviour.
    likely s.43 commercial
    Why it mattersThese documents define how much influence government has over what platforms remove or demote. That boundary matters to press freedom and free expression regardless of whether any given takedown decision was correct — the public interest is in knowing the rules of the relationship, not any single case.

Request 2 — Police Scotland: Feed Manipulation, Bot Networks & Foreign Influence Advisories

Recipient: Police Scotland · Act: Freedom of Information (Scotland) Act 2002 · Period specified: 1 Jan 2022 – 31 Dec 2024 · Status: Submitted, awaiting response
Scope note: the NCA is a UK body and can be sent a parallel FOIA 2000 request. The FBI and CIA are US federal agencies and fall outside UK FOI legislation entirely — they are not bound by a request framed under FOISA/FOIA. Reaching them requires a separate request under the US Freedom of Information Act, 5 U.S.C. § 552, filed directly with each agency.
  1. Adversary Interception Policies: recorded directives or guidance concerning technical protocols for identifying or mitigating "Man-in-the-Middle" (MITM) manipulation affecting algorithmic content feeds.
    No public evidence currently confirms this as a documented practice or threat category; the request asks the force to confirm or deny holding any such guidance.
    Why it mattersConfirming a negative has value too: a "no such guidance exists" response rules out one category of concern and lets scrutiny focus on categories where something demonstrably does exist (e.g. platform-level content moderation, which is well documented).
  2. Algorithmic Interventions: policy documents, operational guidelines, or research assessing third-party or unauthorized external influence over content recommendation algorithms.
    Why it mattersRecommendation algorithms already shape what millions of people see daily. Understanding what a police force believes about external manipulation of those systems — true or not — reveals how threat models in this space are being built, which affects any future policing or regulatory response.
  3. Automated Content Generation: procurement records, capability evaluations, or usage policies for tools designed for synthetic profile generation or mass-injection of media into online networks.
    likely s.35 law enforcementlikely s.33 commercial
    Why it mattersIf any UK police force holds or has evaluated tools that can generate synthetic profiles or mass-inject content, that is directly relevant to public trust in what is and isn't authentic online — including citizens' ability to tell whether accounts engaging with them are real.
  4. Public notices or advisories issued to warn the public about foreign intelligence units structuring narratives, including political rhetoric, for influence purposes.
    Why it mattersPublic advisories, by definition, are meant to be public — asking whether any were issued (and if so, requesting copies) tests whether public-facing risk communication is actually reaching the public it's meant to protect.
  5. Use of synchronised automated accounts ("bot" networks) to alter likes, comments, or reposts on social media content, and whether this is standard practice during any interception or MITM-type event.
    Framed as-sent. This asks the force to confirm or deny the practice — it is not asserted here as an established fact.
    Why it mattersAstroturfing and engagement manipulation (by any actor, state or otherwise) degrades the reliability of public discourse metrics people use to gauge opinion. Establishing whether police hold any policy on this — even a "we don't do this and have no guidance on it" answer — is useful baseline information.
  6. High-level policy documents, SOPs, or training manuals regarding deployment of automated software or accounts ("bots") to interact with public social media content.
    Why it mattersUndercover and covert online activity by UK police is already a regulated area under RIPA 2000 and the Investigatory Powers Act 2016; knowing whether automated accounts specifically are covered by existing authorisation frameworks is a legitimate oversight question, not a novel one.
  7. Procurement records or contracts from the past three years relating to acquisition of social media manipulation, engagement modification, or automated profile management tools.
    likely s.33 commercial
    Why it mattersContract values and supplier names (as distinct from technical specifications) are standard public-spending transparency data. This mirrors existing campaigns for disclosure of police surveillance technology procurement (e.g. facial recognition, IMSI catchers) led by groups like Liberty and Big Brother Watch.
  8. Formal guidance, alerts, or advisory notices issued to social media platforms or public bodies regarding foreign state-sponsored narrative manipulation between 1 Jan 2022 and 31 Dec 2024.
    Why it mattersThis window covers a UK General Election and continued reporting on Russian and other state-linked influence operations targeting Western democracies; knowing what, if anything, was formally communicated to platforms during this period is directly relevant to assessing the state's preparedness.

Follow-up framing — defensive/protective angle

Sent as a narrower follow-up, emphasising public-protection guidance rather than operational capability
  1. Guidance or technical standards for identifying, reporting, or mitigating MITM attacks or external tampering affecting digital communications and content feeds.
  2. Policy documents, threat assessments, or public guidance concerning unauthorized manipulation of content recommendation algorithms by hostile actors.
  3. Public alerts or briefings issued to inform public bodies or citizens about state-sponsored narrative manipulation or online disinformation campaigns.
  4. Guidance, SOPs, or analytical frameworks used to detect synchronized bot networks or artificial engagement inflation.
  5. Formal protocols for liaising with platforms, regulators, or public agencies on foreign state-sponsored information operations.
Recast as a defensive-guidance request in case the operational-capability framing above triggers a blanket neither-confirm-nor-deny (NCND) response under s.24/s.31 — public-facing advisory material is more likely to exist and be releasable than internal operational SOPs.

What would settle each question

Some of the items above rest on premises I cannot currently support with public evidence. Setting out in advance what would count as confirming or ruling out each one is the difference between a transparency exercise and a search for material that fits a conclusion already reached. These criteria are fixed before any response arrives, so they can't be quietly adjusted afterwards to accommodate whatever comes back.

"MITM manipulation of algorithmic content feeds"

Would confirmA held document describing network-layer interception used to alter recommendation feed content, or a threat assessment treating this as a live category with named incidents.
Would rule out"Information not held" from multiple authorities, particularly bodies that would necessarily hold it if it existed (NCSC, NCA). Two or more independent negatives should be treated as settling this.
Proves nothingA refusal under s.24 or an NCND. Both are routinely applied to entire subject areas regardless of whether anything is on file. Prior view: I consider this the weakest premise on the page. MITM is a transport-layer concept; recommendation ranking happens server-side at the platform, where interception of the connection would not reach it. I expect this to return nothing, and if it does, I will say so here.

Police or government operation of "bot armies"

Would confirmProcurement records for engagement-manipulation tooling, or an SOP authorising automated accounts to alter likes, comments, or reposts on public content.
Would rule outA clean procurement disclosure covering the period with no such tooling. Procurement is the strongest test available here — contract data is rarely exempt, so an empty return is meaningful in a way that a policy-document refusal is not.
Proves nothingDisclosure of covert-account policy alone. UK police have held authorised covert online capability under RIPA/RIP(S)A for years; finding that is finding a known, regulated, and separate thing — not evidence of engagement manipulation. Conflating the two would be the main way to get this wrong.

NSOIT criteria catching lawful political speech

Would confirmDisclosed criteria whose scope extends to lawful domestic political expression rather than being limited to state-linked or inauthentic coordinated activity.
Would rule outDisclosed criteria narrowly limited to attributable foreign-state or demonstrably inauthentic activity, with a documented exclusion for lawful speech.
Proves nothingRefusal under s.31. Note: this is the one item on the page with an existing evidential basis — Big Brother Watch's 2023 FOI work and subsequent parliamentary questions established that the predecessor unit's monitoring reached posts by MPs and journalists. This item is therefore a narrowing question about current criteria, not an open one.

Measurable electoral effect of online influence operations

Would confirmA held assessment concluding that a specific UK electoral outcome was materially affected, with stated methodology.
Would rule outHeld assessments concluding reach without measurable persuasion effect — which is where most published academic work currently sits.
Proves nothingGovernment concern about a threat is not evidence the threat succeeded. Departments produce assessments of risks that never materialise; that is what assessments are for. A large volume of documents here would show attention, not impact.
If responses come back and I conclude a premise was wrong, that conclusion gets recorded on this page in the same place and at the same size as everything else. A tracker that only ever accumulates supporting material isn't tracking anything.

Planned and parallel requests

Bodies not yet approached, ordered by likelihood of a substantive response

Ofcom strong prospects

Online Safety Act 2023 workstreams on coordinated inauthentic behaviour produce written outputs, and Ofcom publishes extensively on its own initiative. Low national-security exposure. Best first target for anything about platform-side manipulation and the regulatory response to it.

Scottish Police Authority strong prospects

Holds board papers, budget lines, and oversight correspondence covering Police Scotland capability. As an oversight body it is structurally less defensive than the force it oversees, and frequently a better route to the same underlying information. FOISA 2002.

Cabinet Office mixed prospects

Holds Defending Democracy Taskforce material. The documents certainly exist, but s.35 (policy formulation) and s.24 are heavily applied. Metadata-only requests — titles, dates, attendee lists, terms of reference — are far more likely to succeed than requests for content.

National Crime Agency mixed prospects

Subject to FOIA 2000 but with broad exemptions across its intelligence functions. Worth a narrow, procurement-focused request rather than anything touching capability or tasking.

Home Office weak prospects

Relevant material sits close to counter-terrorism and state threats, so s.23 (security bodies, absolute) and s.24 apply broadly and NCND is common. Included for completeness rather than expectation.

Bodies outside scope. GCHQ, MI5, and MI6 are listed under s.23 FOIA as security bodies and are wholly exempt — requests to them are not merely likely to fail but legally cannot succeed. The FBI and CIA fall under the US Freedom of Information Act, 5 U.S.C. § 552, and require separate filings with each agency; US FOIA has no standing requirement for non-citizens but response times commonly run to years rather than weeks.
Check before sending. WhatDoTheyKnow (whatdotheyknow.com) publishes FOI requests and responses; several of the categories above have been asked before, and the previous responses show which phrasing produced disclosure and which produced "not held." Reusing wording that already worked is the single highest-value preparation step, and avoids a repeat-request refusal under s.14(2) FOIA / s.14(2) FOISA.
Expected outcome. Based on how UK authorities typically handle requests touching national security, ongoing law enforcement capability, and commercial procurement, I expect most substantive content to be withheld or heavily redacted, and some items (particularly bot-detection SOPs and procurement contracts) may draw a "neither confirm nor deny" (NCND) response. Metadata-only requests (titles/dates/authors) and public-facing advisory material are the most likely to yield releasable content. This page will be updated as responses arrive.

Notes on the process

Qualified vs. absolute exemptions. Most of the exemptions flagged above (s.31 law enforcement, s.36 effective conduct of public affairs, s.43 commercial interests under FOIA; the FOISA equivalents) are qualified, not absolute — the authority is legally required to run the public interest test (s.2) and, if it withholds information, to state which exemption it relied on and give at least a brief indication of how the balance was struck. A response that withholds everything with no explanation of that balancing exercise is itself challengeable.

NCND is not unlimited. Neither-confirm-nor-deny responses under s.23/s.24 FOIA (or the FOISA equivalent) are meant to be used where confirming or denying the existence of information would itself cause harm — e.g. revealing operational capability. Public authorities sometimes over-apply NCND to categories, like whether a public advisory was ever issued, where the fact of existence is not obviously sensitive. Each NCND response can be queried via internal review.

Escalation path. If a request is refused, partially refused, or not answered within the 20-working-day deadline, the next steps are: (1) request an internal review from the same public authority, then (2) if unsatisfied, appeal to the relevant regulator, which can order disclosure. The two regimes have different regulators and this matters: FOIA 2000 requests (DSIT, Cabinet Office, Home Office, Ofcom, NCA) go to the Information Commissioner's Office at ico.org.uk. FOISA 2002 requests (Police Scotland, the Scottish Police Authority, Scottish Government) go to the Scottish Information Commissioner at itspublicknowledge.info. There is no reserved-matters carve-out sending Scottish public authorities to the ICO — sending a FOISA appeal to the wrong regulator wastes the appeal window, which is six months from the internal review outcome under FOISA and three months under FOIA.

Internal review timing. Under FOISA an authority has 20 working days to complete an internal review. FOIA sets no statutory deadline for internal review, but ICO guidance expects 20 working days and 40 in exceptional cases; an authority that exceeds 40 working days can be complained about to the ICO without waiting further.

Distinguishing outcome from claim. A refusal or heavy redaction on national security grounds is not evidence that the underlying claim (e.g. MITM feed manipulation) is true — it is equally consistent with there being nothing on file, and the exemption being invoked defensively or as a blanket policy for a whole subject area. This page will record the actual response text for each item once received, rather than treating silence or redaction as confirmation either way.