SDSignal Desk

Disrupting AI-enabled “false front” operations

Oct 7, 2026, 5:00 PM · OpenAI

Image: OpenAI

OpenAI's latest threat report shows AI helping old-school propaganda fronts reach real newsrooms, and the most effective trick was not deepfakes but fake journalists and unwitting staff.

Why it matters

OpenAI says it banned accounts tied to two covert influence operations, one from Russia and one from Iran, that used its models alongside traditional tradecraft to run 'false front' entities. The Russian operation, which OpenAI calls Dark Clark, appears to have run a self-described research center in Latin America staffed by people who did not know who they were working for. The Iranian one, Bogus Bylines, used seven fake journalist personas to pitch long-form articles to small and medium outlets.

The reach is what stands out. OpenAI rates the Russian operation Category 5 on the six-point IO Breakout Scale, the first it has disrupted at that level since it began reporting, with fakes that drew fact checks and official denials. The Iranian personas landed almost 100 articles across roughly a dozen outlets, which OpenAI rates Category 4. OpenAI says it shared information on both cases with the relevant authorities.

From the desk

We give OpenAI credit for this kind of disclosure. The report itself makes the point that exposure works: earlier fronts like the fake journalist 'Alice Donovan' and the outlet PeaceData stopped after they were named. Publishing detailed case studies, with personas, tactics and timelines, makes the next operation harder and gives editors something concrete to check against.

The lesson for newsrooms is uncomfortable. The Iranian operators used the model to tailor drafts to each outlet's submission guidelines and then write the pitch email. That is a direct attack on the trust small publications extend to freelancers. Fluent, on-brief copy from a plausible byline used to take real effort to fake. It does not anymore. We think every editor taking outside contributions should treat identity verification as part of the job now, not an extra.

The Russian case is darker because of the people in the middle. According to OpenAI, the operators controlled hiring, pay and firing at the research center through a fake persona, while the staff on the ground did their work in good faith. Separately, the operators claim to have sent fake emails posing as an education authority in Lima to get schools to hold events referencing Stepan Bandera, then planted stories about those events in Peruvian and Polish media. OpenAI found coverage matching that claim. Real schools, real headlines and real diplomatic tension, set off by a forged email.

Two cautions. First, this is OpenAI grading its own platform's misuse, and by its own account most of the Russian operators' AI use was writing internal reports, not making the propaganda. The fakes would likely exist without ChatGPT; the AI made the paperwork and polish cheaper. Second, both operations inflated their own impact to their bosses, which OpenAI documents in detail. That cuts both ways: some claimed wins were fiction, but the ones OpenAI corroborated were real enough to draw government denials.

Where this leads if it scales: the fake-social-media-account era is giving way to laundering through legitimate publishers, which OpenAI says is the pattern across the 30 operations it has exposed in two and a half years. I'm watching whether the outlets that ran these articles disclose and correct, and whether other AI providers publish comparable detail. One company's visibility is not the whole picture.

Context

The IO Breakout Scale rates influence operations from 1, lowest, to 6, highest, by how far their content spreads beyond the operators' own channels. OpenAI says some of the Russian operation's fakes have been attributed by open-source researchers to an entity known as Politology or La Compania, reported as a successor to Wagner Group-linked organizations. The Iranian operation's social media comments, by contrast, drew little engagement and were rated Category 2.

Who feels it

Editors and small publishers
Freelance pitches from unverified bylines are now a known vector for state propaganda; identity checks and disclosure policies matter.
Unwitting contractors and staff
People can be recruited into foreign influence fronts without knowing it, which carries reputational and possibly legal risk.
Platforms and AI providers
Cross-company sharing and detailed public reporting are proving useful; gaps between providers remain an open door.
Governments in Latin America
Fakes targeting Argentina, Bolivia, Ecuador and Peru show how cheaply local crises can be inflamed from abroad.

What to watch

  1. Corrections or retractions from outlets that published the Bogus Bylines articles
  2. Whether the Social Research Center goes dark after exposure, as earlier fronts did
  3. Comparable disclosures from other AI and social media companies
  4. New editorial verification standards for freelance contributors
  5. Further Category 5 operations in future threat reports

Read the original

Continue at the source.

OpenAI

Companies: OpenAI