OpenAI said Thursday that it has banned two covert influence operations — one originating in Russia and one in Iran — that used ChatGPT to run sophisticated "false front" entities designed to launder geopolitical propaganda into real media outlets. The company said the Russia-origin campaign is the most far-reaching influence operation it has disrupted since it began publishing threat reports two and a half years ago.
The disclosure, published on OpenAI's website, is the latest entry in a string of reports on how state-aligned actors misuse commercial AI models. It also underscores, as we noted in our latest breaking AI news roundup, a pattern OpenAI has observed across the 30 covert operations it has exposed since early 2024: campaigns that succeed in placing their content in genuine publications reach far larger audiences than those relying on fake social media accounts.
A Category 5 first: Operation "Dark Clark"
The Russian operation, which OpenAI nicknamed "Dark Clark," centered on a self-styled research organization in Latin America called the Social Research Center (SRC). According to OpenAI, the operators controlled the think tank through a fabricated persona named "Mia Clark," while local employees in Latin America conducted interviews and drafted research papers without knowing they were working for a Russian group.
Using the Breakout Scale — a 1-to-6 measure of an influence operation's potential reach developed at Brookings — OpenAI assessed Dark Clark at Category 5, the highest rating it has assigned to any operation since its reporting began. The Iran-origin campaign reached Category 4.
Much of the operators' ChatGPT usage went into internal reports to an unknown handler, OpenAI said, describing campaigns to denigrate Ukraine, undermine recruitment for Ukraine's armed forces, and interfere in domestic politics in Argentina and Bolivia. The operators mostly prompted in Russian and relied on VPNs to access the service, which blocks traffic from Russia.
OpenAI's researchers corroborated several of the operation's claimed campaigns through open sources. One involved fake emails purporting to come from Lima's regional education directorate, instructing schools in the Peruvian capital to hold events honoring Stepan Bandera — the controversial Ukrainian nationalist figure — on a national diversity day. Peruvian and Polish outlets covered the ensuing controversy, and a Polish member of the European Parliament was quoted in coverage of it. In Ecuador, operators used a fake email address to trick schools into holding a pledge of allegiance to President Daniel Noboa and former Blackwater head Erik Prince; the stunt drew media coverage and a public rebuttal from Ecuador's education minister.
The operation also spread fabricated audio recordings, including one attributed to a worker at Bolivia's state water company EPSAS claiming the government would cut supply to La Paz, and another attributed to Ukraine's consul in Ecuador. Fact-checkers in both countries debunked the claims. Open-source researchers have previously linked similar activity to "Politology" or "La Compania," entities described as successors to the late Yevgeniy Prigozhin's operation, and the operators' own reports claimed campaigns targeting Argentina's President Javier Milei that match that public reporting.
Seven fake journalists: Operation "Bogus Bylines"
The Iranian operation took a different route into the media ecosystem. Its operators, who prompted ChatGPT in Persian, used the model to refine long-form English-language articles about the US-Iran conflict, then pitched them to editors at small and mid-sized online outlets using seven fabricated journalist personas: Ervin B. Hoskins, Noah Lamington, Sophia Gonzalez, Michael Harrison, Ericka Feusier, Jenny Williams, and Alice Johnson.
OpenAI identified nearly 100 articles published or syndicated under those bylines across roughly a dozen outlets worldwide, most focused on international affairs and the Middle East. The operation also generated batches of social media comments, though OpenAI said these drew little real engagement — and noted that the operators used a deceptive calculation in their internal reports to inflate their apparent social media impact. The company said the activity appeared consistent with a commercial actor running a for-hire influence campaign, and that it has shared information with relevant authorities.
Old tradecraft, new tools
What strikes researchers most, OpenAI wrote, is how closely both operations resembled influence campaigns from the pre-AI era. The fake journalist personas bear a family resemblance to "Alice Donovan," a fictitious reporter fronting for Russian military intelligence whose op-eds appeared in Western outlets in 2016 and 2017. The SRC's unwitting local staff echo "PeaceData," the fake news site that co-opted real journalists in 2020.
AI did not invent these techniques — it made them cheaper, faster, and more fluent. Operators used models to tailor fakes to local vocabulary and institutional style, translate scripts into regional Spanish variants, and produce polished pitch emails for editors. But OpenAI argued that the covert, person-to-person nature of false-front operations also makes them vulnerable to exposure: both Alice Donovan and PeaceData shut down after being named publicly.
Reading the evidence with care
OpenAI was careful to caveat its own findings. The operators routinely claimed credit for events they had nothing to do with, and some fakes they reported planting could not be found in open sources. What OpenAI could verify — through fact-checks, official denials, and published articles matching the operators' descriptions — suggests genuine penetration of media and political discourse in at least four countries.
For the AI industry, the report is a reminder that the most effective uses of models in disinformation are often the least visible ones: drafting internal reports, refining pitches, polishing translations. The entities best positioned to detect these campaigns, as OpenAI's earlier cases showed, are frequently the platforms whose own tools are being used to run them.
---
Stay Ahead of AIGet the latest AI news, analysis, and breakthroughs — all in one place.
Read more AI news →