OpenAI has disclosed two influence operations that used its models to support false-front organisations and personas. The 8 October report describes one Russia-origin network targeting Latin America and one Iran-linked operation that placed long-form articles through invented journalist identities. OpenAI says it banned the associated accounts and shared relevant information with authorities.
The cases are significant because the operators did not rely on obviously synthetic social posts alone. They combined AI with older influence techniques: front organisations, misleading biographies, external publications, fabricated material and inflated internal reporting. The model made parts of the workflow easier, but the campaigns still depended on people, distribution channels and institutional vulnerabilities.
Russia’s operation built a think-tank front
OpenAI nicknamed the Russia-origin campaign “Dark Clark”. Actors used ChatGPT for tasks linked to covert influence across Latin America, often seeking to undermine Ukraine or affect political debates in countries including Argentina and Bolivia. The company says operators connected from Russia through VPNs because direct access to its models is not allowed there.
The network appears to have co-opted unwitting people to operate a think tank on the ground. It also produced fake leaked documents, scripts and internal reports. OpenAI notes that the operators spent substantial effort using the model for internal documentation, sometimes exaggerating their own impact or taking credit for unrelated activity.
Iran-linked personas pitched real outlets
The second operation maintained seven supposed journalist identities and pitched English-language geopolitical articles to small and medium online publications. Operators asked ChatGPT to review drafts against each outlet’s submission criteria and suggest edits. OpenAI identified almost 100 published pieces linked to the personas across more than a dozen outlets.
The same network generated batches of social comments about the US-Iran conflict, but OpenAI found little evidence of meaningful engagement with those posts. Long-form publication was more consequential because established outlets could place the material in front of audiences who did not know the authors’ true origin or motivation.
AI amplified familiar methods
OpenAI’s central finding is that the operations resembled pre-AI influence campaigns. Models increased linguistic fluency, editorial capacity and production scale, but did not eliminate the need to recruit people, establish credible fronts or secure distribution. Defenders should therefore watch for organisational and behavioural signals, not only stylistic signs of generated text.
That conclusion complicates simplistic detection strategies. A polished article may be human-edited, AI-assisted or entirely human, while a false institution can distribute authentic-looking material through ordinary channels. Publishers need stronger author verification, conflict-of-interest checks and escalation paths when submissions show unusual coordination or deceptive backstories.
Impact claims require independent evidence
The Russian operators claimed broad success, but OpenAI could not corroborate every assertion. Some alleged stories were absent from open sources, while other activity was independently reported or debunked by governments. The company assessed the campaign at Category 5 on the IO Breakout Scale, its first disrupted operation at that level.
The report cautions against treating an adversary’s internal metrics as reliable. Influence contractors may exaggerate to satisfy clients, secure funding or justify continued work. Analysts need corroborating evidence such as publication records, audience engagement, public reactions and links between accounts before drawing conclusions about real-world reach.
Disclosure can raise the cost of deception
False-front operations depend on secrecy, making responsible disclosure a disruptive tool. Once identities, organisations and methods are exposed, publishers and audiences can reassess earlier material and remove the infrastructure that gave the campaign credibility. OpenAI points to historical operations that stopped after public identification.
Platform action alone is insufficient because actors combine multiple services and offline relationships. Model providers, social platforms, publishers, researchers and authorities need mechanisms for sharing indicators while protecting legitimate users and investigative methods. The report contributes detailed case evidence that other defenders can compare with their own observations.
A governance lesson beyond content generation
The cases show that misuse policy must cover workflows, not just final text. Translation, editorial review, research summaries and internal planning can all support a deceptive campaign even when each isolated prompt appears ordinary. Detection therefore requires attention to patterns of accounts, repeated targets and coordinated behaviour.
OpenAI’s disclosure is valuable because it separates capability from impact and acknowledges uncertainty. AI lowered the cost of some tasks, but distribution and trust remained the decisive resources. Organisations defending against influence operations should strengthen identity and editorial controls while avoiding the assumption that generated prose will always reveal itself.
Newsrooms can respond with proportionate checks rather than blanket suspicion of unfamiliar writers. Verification might include confirming employment history, checking whether contact details and social accounts developed naturally, reviewing repeated submission patterns and requesting evidence for unusual claims. These steps also help detect non-AI deception, making them more durable than tools focused narrowly on identifying generated language.
Shared indicators from exposed operations can help smaller publishers apply those checks without building a specialist intelligence team of their own.