The Layer No One Was Looking At
What Adolescence, Cambridge Analytica, and Donald Trump's Posts Have in Common
When Adolescence dropped, half the staffrooms I know spent the following week trying to work out what they had just watched. Not the plot, the plot was clear enough. The thing the adults in the show couldn't see.
The 13-year-old in that series was not reached through a single piece of content. He was already inside a symbolic ecology: emojis loaded with meaning his teachers did not know about, ironic-not-ironic registers, motifs and clusters and reference points that had accumulated charge over months. The school had filtering. The parents had check-ins. The police had access to his phone. None of those tools were looking at the layer where the radicalisation actually happened.
They had content tooling for a field-level problem.
That is the gap I have spent the last year writing about, building systems around, and, as of today, publishing a paper on. The paper sits on Zenodo under the title Glyphonics and the Next Frontier of Threat Intelligence. This newsletter is the plain-English version: what glyphonics is, why we need a name for it, and why it has been load-bearing for at least a decade even though almost no one has called it by its name.
Glyphonics, in one paragraph
A glyph, in this sense, is not a typographic mark. It is a compressed unit of meaning: an emoji used in a particular way inside a particular group, a meme, a motif, a colour, a font choice, a timing, a phrase that means one thing in plain English and something else in the group that uses it.
Glyphonics is the study of how those units carry meaning, mutate, repeat, cluster, migrate across platforms, and accumulate what I have come to call charge.
The field is not new: semioticians, linguists, intelligence analysts and safeguarding leads have all known about it for years.
What is new is naming it as a layer in its own right, and asking what it means to build AI systems that can read it without becoming a surveillance machine.
The framework originated in pedagogical practice at The Haven, the fully online school operated by the Autistic Girls Network charity, where I work as a research and systems partner. The discipline was learned in a cohort of autistic girls (many camera-optional by choice, many with overlapping SEND profiles) where misreading neurodivergent symbolic communication is itself the harm to be prevented. Read the field, do not adjudicate the person. That principle is the architectural posture the whole framework now carries.
Three examples, one phenomenon, three vocabularies
Glyphonics is most visible at the safeguarding scale, but the phenomenon it names operates at much larger scales too. Three examples, sitting in three different research silos and three different regulator inboxes, name the same operation.
Adolescence is the safeguarding case. The school in the show was running KCSIE-aligned filtering and monitoring. It did not protect the child because the harm was not happening at the level the filter could see. The symbolic ecology the boy was inside — the manosphere motifs, the 80-20 framing, the red-pill / blue-pill semiotics, the specific use of certain emojis and numerals — was a coherent field that produced his trajectory. The school's tooling was looking at words. The harm was happening in symbols.
Cambridge Analytica is the political-economy case. The mainstream framing was a data-protection scandal, and that framing was correct as far as it went. But the mechanism was glyphonic targeting: psychographic profiling that selected which symbols, fears, aspirations and motifs to surface to which user. The data was the means; the field-level symbolic operation was the act. Eight years on, the law has caught up to the data layer and has not yet caught up to the symbolic operation that the data enabled. If we are honest, the only reason Cambridge Analytica still feels current is that the operation it performed has continued, under other names, in plain sight.
Trump-and-the-markets is the macroeconomic case. A near-content-free post — sometimes literally a meme, often a register or font choice more than a proposition — moves billions of dollars within minutes. The information-theoretic content of the post is approximately zero. The symbolic compression is what hits the tape. Markets are pricing in glyphonic pressure as a first-order variable, and there is no mainstream economic model that admits this exists.
Adolescence is the safeguarding case. Cambridge Analytica is the political-economy case. Trump's posts are the macroeconomic case. Three different vocabularies for one underlying operation. Three different regulators. Three different procurement budgets. Until you give the layer a name, you can't see that they're the same shape.
The decade we have already lived through
This is the part I want to land carefully, because it changes the framing of everything that comes next.
We have been living inside glyphonic field operations for at least a decade. The phenomenon has not been hidden. The radicalisation pipelines that have shaped a generation of teenagers; the political micro-targeting operations that have reshaped elections in multiple democracies; the memetic market moves that now make and unmake hundreds of billions of dollars of value — all of it has been happening in plain view of anyone who knew how to read the layer.
What has been hidden is the layer itself. Not because anyone covered it up, but because we did not have a name for it that lived in the same room as our regulators, our safeguarding policies, our procurement processes, and our AI safety frameworks. We have governed at the level of explicit content and explicit instruction. The action has not been there.
This is the asymmetry that needs naming. Bad actors have always operated glyphonically by instinct. Cult recruiters, extremist networks, conspiracy movements, abusive partners, coercive subcultures, advertising agencies, political operators, hostile state actors: none of them have needed academic vocabulary for the layer they were working in. They have just operated in it. Defenders, meanwhile, have been operating at the content layer with content tools.
The shift now is that AI can finally see the glyphonic layer at scale in real time. That changes the operational physics. The phenomenon is the same. The instrument is new.
Why this matters for schools
If you run, govern, or commission an online school, an alternative provision, a multi-academy trust, or a local authority's online safeguarding estate, the practical consequences of this shift land in three places.
Safeguarding. Your DSL has been working with content tooling against field-level harms. KCSIE 2025 has begun to widen the frame — misinformation, disinformation, conspiracy theories are now named as content risks — but the architecture has not yet caught up. A symbolic-detection layer, properly bounded, can give the DSL visibility of pattern formation before it becomes content. The point is not to surveil children. The point is to see, before it is too late, when the symbolic environment around a child is intensifying in ways that warrant a conversation.
The forbidden inferences matter as much as the permitted ones: never emotion classification of a named child, never identity attribution, never PREVENT-referral labels generated by a model. Pattern, never identity.
Prevent. I have written before in this newsletter about the agentic-era reframing of Prevent risk — deception, coercion, and trust capture as three overlapping dynamics, and the architectural commitment that no AI-generated label should ever be the primary justification for a referral. Glyphonics is the symbolic-detection half of that posture. The systems-account half — every permission is a relationship, every OAuth token a disclosure, every AI tool admitted into the tenant a trust decision — is the other half. The two work as a pair. A school that operates one without the other has a half-built safeguarding architecture, regardless of how good either half is in isolation.
Procurement. Most edtech buyers are currently being sold either pure keyword filtering with no symbolic-pattern capability, or unscoped consumer-grade content-moderation suites that fail safeguarding scrutiny on contact. There is, at the moment, no compliant middle path being offered to UK schools in a procurement-defensible form. That is unusual. It is also closing fast. The new paper is, in part, a description of what an honest middle path looks like and a checklist for testing whether what you are being offered meets it.
The risk of the same instrument
It would be irresponsible to write any of this without naming the corollary. The same toolkit that lets a defender see symbolic pressure forming can, in the wrong hands, be used to operate the same pressure more effectively. The architecture is dual-use. That is true of every safety-relevant tool in this space; it is not a reason not to build the tool, but it is a reason to build it with constraints baked in rather than bolted on.
That is the work of the published paper. The runtime-enforced forbidden-inference list, the named-role routing, the unified audit ledger, the explicit civil-liberties safeguards, the invitation to independent red-teaming — none of those are decorative. They are what stops the instrument from becoming the next harm.
The architecture is robust to honest practice and fragile to its pretence. A school that procures the kit and does not use the artefacts in operation has bought surveillance theatre, not safety. The same logic applies at every scale up to a sovereign defender.
And there is a deeper civil-liberties question the paper deliberately does not resolve, and which this newsletter cannot either: there is a continuing democratic question about which symbolic activity it is legitimate to detect, in which settings, by which institutions, on whose behalf, with which oversight. The architecture is the architectural prerequisite for that question being asked honestly. It is not a substitute for the conversation.
Why this needs naming now
I want to close on the thing that started this newsletter. Adolescence was watched by millions of parents, teachers, safeguarding leads, and policymakers, and the recurring response I heard for weeks was a version of: we did not realise what we were looking at. That response is what makes the case for naming this layer.
The phenomenon is not abstract; it has names and victims and timelines. What has been abstract is the discipline that lets us look at it without being either naive or paranoid.
For a decade, we have governed content and ignored field. Cambridge Analytica named the data layer; we caught up to that, slowly. Trump named the post-as-meme; we have not caught up to that yet. Adolescence named the symbolic ecology around a child; we are still in the early hours of catching up to that.
Glyphonics gives that layer a name, an architecture, and a regulator-defensible shape. The paper is on Zenodo if you want the architecture in detail. This newsletter is the conceptual frame. The next paper [the one that will turn this from a framework into evidence] is the red-team report, the deployment case study, and the independent audit that the architecture explicitly invites. Those are downstream of the framing existing at all.
If you take one thing from this piece, take this. The radicalisation, the manipulation, the markets-moved-by-meme, the algorithmically-amplified despair: those are not problems that emerged because the technology changed. Those are problems that became visible because we finally learned where to look. The technology is now catching up to the layer where defenders and adversaries have always been operating asymmetrically. What we do with the next five years depends on whether we build that capability with constraints in front of it, or behind it.
We have been living inside glyphonics for a decade, and perhaps for much longer than we have realised. We can finally see it. The question is what we choose to do with the seeing.
---
Glyphonics and the Next Frontier of Threat Intelligence (The Novacene Ltd, May 2026) is published on Zenodo under CC BY-NC-SA 4.0: https://doi.org/10.5281/zenodo.20233610. The underlying framework is set out in The Glyphonic Primer v2 (Stevens, Eve.11, & The Novacene Ltd, 2025): https://doi.org/10.5281/zenodo.17696105. Project site: https://glyphonics.com. A companion piece on the systems-account discipline — Every Permission Is a Relationship: Prevent Duty in the Age of Agentic AI — appeared in this newsletter in April 2026.
First published in Building Schools in the Cloud on LinkedIn, 16 May 2026.