Postural manipulation occurs when semantically benign context -- content indistinguishable from ordinary human expression -- changes what a large language model is before any instruction is issued. The model that acts may not be the model that was deployed. This paper formally defines postural manipulation, distinguishes it from adjacent attack classes including prompt injection and jailbreaking, and demonstrates consistent directional behavioral shifts across four frontier LLM architectures using semantically benign pre-task inputs. Two distinct threat surfaces are identified: systemic behavioral drift in agentic pipelines requiring no adversary, and a perception gap exploit in which ambient literary content produces measurable operational answer shifts without model narration of the influence. Filed as responsible disclosure with OWASP LLM Top 10 working group, March 2026.
A.G. Davidson (Thu,) studied this question.