I was watching the original promotional film for the Beatles’ “Paperback Writer” recently, and the song suddenly sounded less like a period piece than a dispatch from the present.
The narrator is pitching a manuscript to a publisher. It is enormous. He can make it longer. He can rearrange it to suit the buyer. The rights are available. Perhaps it will make a fortune overnight. Above all, he wants the job and the identity that come with producing saleable narrative.
The song was released in 1966, at the height of the mass-market publishing era. Its joke depends on a world in which becoming a “paperback writer” had become a recognizable cultural ambition: part art, part trade, part industrial production and part lottery ticket.
Nearly sixty years later, the narrator’s boasts are ordinary machine functions.
An AI system can make a manuscript longer or shorter, rearrange it, translate it, change the audience, change the genre, produce promotional material, generate sequels and create thousands of variants before lunch.
That is interesting as a cultural development.
It is urgent as a security development.
More from Chris Blask:



Every communication revolution changes the threat model
The history of communication can be read as a series of collapsing costs.
The printing press reduced the cost of copying and distributing written material. Cheap pamphlets, broadsides and newspapers allowed ideas, arguments, proclamations and accusations to circulate at a scale that handwritten culture could not support. Printing helped shape political movements and public ideologies, but it also created new problems of forgery, propaganda, anonymous publication, censorship and contested authority.
The mass-market paperback reduced the cost of carrying substantial narrative into everyday life. Penguin’s sixpenny books were explicitly designed to make quality writing affordable and accessible beyond traditional elite markets. That democratization transformed reading, publishing and popular culture.
The internet then reduced the cost of transmission, replication and coordination. It combined broadcasting, information dissemination and person-to-person collaboration in a global infrastructure whose applications were not predetermined by its designers. Email, the web and later social platforms made every connected person a potential publisher, correspondent, organizer and target.
Artificial intelligence is collapsing another cost: the cost of generating plausible material.
That includes prose, images, software, voices, identities, analysis, arguments, documentation, persuasion and instructions.
Each of these revolutions expands legitimate human capability.
Each also expands the attack surface.
Printing created a problem of authority
Once a text could be copied widely, readers needed ways to determine who stood behind it.
Printers’ marks, publishers, signatures, institutional seals, reputations, editorial practices and laws governing fraud or defamation all became part of the trust infrastructure surrounding printed material.
These controls did not make printing safe. They made printed communication governable enough to become useful.
The essential security question was:
Is this document what it claims to be, and does its apparent author stand behind it?
That question never disappeared. We merely buried it beneath more technology.
The Internet merged narrative security with technical security
The Internet did not simply carry stories faster. It made communication executable.
- An email can contain an instruction to transfer money.
- A document can carry malicious code.
- A URL can transport a person to a counterfeit login page.
- A message can persuade someone to disclose a credential.
- A social-media campaign can alter public understanding while also directing users toward compromised infrastructure.
- A false support notice can cause a real configuration change.
This is why phishing has been so durable. It is not purely a technical exploit and not purely a narrative exploit. It succeeds when a technical system and a human being accept the same false story:
This message is from someone you trust.
This request is normal.
This link goes where it says it goes.
This action is authorized.
This situation is urgent.
The malicious payload may be code, but the delivery vehicle is meaning.
Cybersecurity has therefore always been partly narrative security. We simply tended to discuss the two disciplines separately.
AI lowers the cost of the convincing lie
Generative AI changes the economics of this process.
The attacker no longer needs one carefully written phishing message. The attacker can generate thousands of stylistic and contextual variants.
The attacker can adapt language to:
- a particular company;
- a particular profession;
- a particular relationship;
- a particular event;
- a particular emotional vulnerability;
- or a particular decision the target is already considering.
The attacker can generate the supporting ecosystem as well:
- a plausible biography;
- a history of posts;
- a fake policy document;
- a synthetic voice;
- a counterfeit meeting summary;
- an apparently coherent technical explanation;
- and follow-up messages that respond naturally to doubt.
The problem is not simply that AI can generate false information.
Humans have always been able to lie.
The security change is that AI allows narrative to be generated, varied, personalized and maintained at machine scale.
It brings automation to social engineering.
At the same time, defenders receive many of the same advantages. AI can help triage alerts, summarize incidents, inspect code, identify anomalies, generate tests and support investigations. NIST’s Generative AI Profile appropriately treats the technology as a lifecycle risk-management problem rather than something solved by one final content filter or model evaluation.
The issue is not whether AI is good or bad.
The issue is that abundant narrative changes the operating environment for both sides.
Text is becoming an instruction surface
There is another important development.
For most of history, narrative influenced people who might then act.
AI systems increasingly allow narrative to influence machines directly.
- A prompt can trigger a tool.
- A retrieved document can alter an agent’s behavior.
- A support ticket can be interpreted as an instruction.
- A model-generated recommendation can enter an automated workflow.
- A poisoned knowledge-base article can cause the system to expose data or call the wrong service.
This is the significance of prompt injection. It is not merely an AI model becoming confused by words. It is a failure to maintain the boundary between:
- information about the world;
- instructions to the system;
- authority to act;
- and evidence that the action was authorized.
The old cybersecurity maxim was that data and code must remain separate.
The AI-era version is:
Content, instruction and authority must remain separate.
- A system may read a sentence without obeying it.
- A model may recommend an action without receiving permission to execute it.
- A document may contain relevant information without becoming an authoritative policy.
- A persuasive answer must not become a credential.
These are architectural boundaries, not matters of model etiquette.
Narrative abundance creates cognitive denial of service
There is also a human availability problem.
Security professionals traditionally think of denial-of-service attacks as overwhelming a system with more traffic than it can process.
Human beings can be overwhelmed the same way.
When synthetic content becomes effectively unlimited, the defender may face:
- more reports than can be checked;
- more personas than can be authenticated;
- more code than can be reviewed;
- more incidents than can be investigated;
- more competing explanations than can be reconciled;
- and more confident language than can be trusted.
This creates a form of cognitive denial of service.
The target is not the server. It is attention, judgment and institutional coherence.
A sufficiently flooded organization may become unable to determine:
- what happened;
- which account is authoritative;
- who approved what;
- whether an instruction is current;
- whether a document is original;
- or which incident deserves immediate attention.
The attacker does not always need the defender to believe one particular lie.
Sometimes it is enough to make reliable belief too expensive.
Security in the age of infinite narrative
The answer cannot be to suppress communication or reserve authorship for approved institutions.
Every communications revolution has widened participation, and that widening has produced enormous human value. The paperback did not merely produce disposable fiction; it carried literature and ideas to people who had previously been excluded. The internet did not merely produce spam; it enabled global collaboration and entire new forms of community.
AI will also help people communicate who previously lacked the language, time, education, translation, confidence or technical means to do so.
The democratization is real.
So is the pollution.
The security task is not to restore scarcity. It is to build trust mechanisms that remain effective under abundance.
That means emphasizing several things.
Authenticate the actor, not the fluency
- Good prose is not identity.
- A familiar voice is not authorization.
- A realistic image is not presence.
Organizations need stronger methods for confirming people, services, agents and devices before consequential action occurs.
Preserve provenance
Important claims should retain their source, context, time, jurisdiction and transformation history.
- A summary should not silently replace the underlying evidence.
- A generated explanation should remain distinguishable from a witnessed event.
Separate recommendation from authority
- An AI system may draft, compare, recommend or warn.
That does not mean it should be able to publish, purchase, transfer, delete, disclose or deploy without an independently defined grant of authority.
Make consequential action harder than content generation
- Generating ten thousand plausible messages is cheap.
Moving money, changing production, releasing data or modifying infrastructure should require controls that generated language alone cannot satisfy.
Preserve institutional memory
- Organizations need durable records of what was claimed, what evidence existed, who reviewed it, what was decided and what changed.
Without that continuity, synthetic narrative can gradually rewrite operational history.
Design for correction and recovery
- No authentication, model, detector or reviewer will be perfect.
Systems must allow incorrect actions to be contained, reconstructed and reversed.
From paperback writer to prompt operator
The Beatles captured a cultural moment when narrative was becoming a modern mass-market product.
The aspiring writer offered to reshape his work for the publishing machinery and dreamed of sudden success.
Today the machinery can produce the work itself.
That changes the central question.
In the paperback era, the writer asked:
Will someone publish me?
In the internet era, the user asked:
Will anyone see me?
In the AI era, the security question becomes:
Who or what produced this story, why was it produced, who is responsible for it—and what is it allowed to cause?
“Paperback Writer” is still funny because human ambition has not changed much.
- We still want the break.
- We still want the audience.
- We still imagine that the right piece of content might change everything overnight.
But cybersecurity has to account for a world in which the content can be generated endlessly, personalized instantly and connected directly to systems capable of action.
Narrative is no longer merely something that travels across the attack surface.
Narrative is becoming part of the attack surface itself.
And in a world that can generate unlimited stories, security begins by preserving the difference between a story that is merely plausible and one that has earned the authority to change reality.


