There is something deeply unsettling about discovering that the tools designed to understand human language can be quietly repurposed to distort public conversation. Anthropic, the US artificial intelligence company behind the Claude model, announced that it had disrupted a commercial election-manipulating platform that targeted voters in Malaysia. The operation was not a crude flood of spam from a single anonymous account; it was an elaborate, professionally managed ecosystem. According to Anthropic’s Threat Intelligence team, the platform had been active for around eight months, hidden in plain sight behind the facade of a defensive cyber intelligence and counter-disinformation company. In reality, it was a political influence factory capable of compiling voter profiles, manufacturing fake personas, publishing bogus news, and generating deceptive intelligence dossiers. The operation reached into all 222 parliamentary constituencies in Malaysia, a country where electoral boundaries are politically sensitive and where communities live along intersecting lines of race, religion, and history. The platform had ingested millions of voter records, using census and electoral data to map political and social fault lines, including race, religion, and attitudes toward the monarchy. What makes this so human is the target: not an abstract “audience” but real citizens with diverse hopes, fears, and loyalties. The report suggests that these vulnerabilities were not accidental; they were systematically identified and exploited. Anthropic concluded that the campaign was commercial in nature, meaning someone was paying for this manufactured influence, though the identities and motives behind the project remain partly unclear. The company also said it had found no evidence linking the operation to Prime Minister Anwar Ibrahim or his office, even though one observed request appeared to support the prime minister. It is a reminder that influence operations can be bought and sold like commodities, with AI as the engine and democracy as the terrain.
The scale of the operation is difficult to absorb, not only because of the numbers but because of the sophistication involved. Anthropic said the platform managed more than a thousand fake accounts on X, the social media platform formerly known as Twitter. These were not simple bots that repeat the same phrases; they were optimized to look genuine, with profiles and behaviors designed to withstand basic scrutiny. The system constantly changed cookies and IP addresses, making the accounts harder for social media platforms to detect and remove. It was also designed to inflate engagement metrics, creating the illusion that certain opinions, hashtags, or narratives were far more popular than they actually were. The goal was to build a synthetic political presence that could shape online conversation and potentially influence the offline assumptions of voters. The operation was meticulous in its local knowledge. It covered every parliamentary constituency in Malaysia, and by ingesting census and electoral data, it could segment voters according to their likely concernsable to identify communities that might be receptive to particular messages. The threat actor’s own promotional materials described the infrastructure as a “military-grade, AI-driven, real-time political operations ecosystem.” That phrase is both absurd and menacing, but it also reveals how sophisticated commercial influence services have become. The fake accounts were not only numerous; they were continuously refreshed, with new personas and technical fingerprints, making them resilient to takedowns. The goal was not simply to post content but to manufacture the appearance of grassroots support, giving campaign messages a false organic glow. It was an attempt to mimic public opinion at scaleicas. For Malaysians scrolling through social media, the operation was virtually invisible; it appeared as separate accounts, ordinary stories, and engagement numbers that seemed to validate their reach.
To give these digital puppets credibility, the operation built an entire fake news outlet called “Malaysia Pulse.” The site was not entirely invented; its real trick was using AI to rewrite genuine Malaysian news reports and republish them under invented bylines. This is a particularly insidious approach because it borrows the authority of real events while injecting a synthetic narrative. Worse, the outlet also reproduced content originating from Chinese and Russian state-linked media, carefully stripping away references that would reveal those sources. In this way, foreign state narratives could appear as locally produced journalism, digestible for Malaysian audiences and detached from any uncomfortable geopolitical baggage. The same AI system was used to generate fabricated intelligence reports containing false claims about an opposition politician and civil society groups. Anthropic said in its report that the allegations were entirely made up. The operation therefore merged three distinct layers of deception: manufactured social media personas, manufactured news media, and manufactured intelligence material. Together, these layers created the illusion of a genuine information ecosystem, with reports “confirming” what the algorithm had already seeded. At some points, however, Claude refused to cooperate. Anthropic said the AI assistant refused or partially refused requests at several stages, particularly after it identified a fabricated dossier as material for political defamation under relevant legal standards and resisted language that explicitly evoked a psychological operation. This is a crucial detail because it shows that even as the operator tried to exploit AI, the model’s safety mechanisms intermittently held. Yet the operator adapted, likely finding ways to rephrase questions or break tasks into less suspicious pieces Frankenstein? Need no. The case illustrates that model guardrails are not perfect, but they are not useless either.
The most politically sensitive discovery in the report concerns Malaysia’s prime minister. Anthropic observed a request to generate one million artificial views on the account of the sitting Malaysian prime minister. That request, if fulfilled, could have produced a massive illusion of support across social media, potentially distorting public perception of his popularity and making it seem as though he commanded a digital army of enthusiastic supporters. But Anthropic said it had not established who made the request, nor had it found any link between the operation and Anwar Ibrahim or his office. This uncertainty is critical in a country where race, religion, and the monarchy are delicate threads in the national fabric. The operation tried to exploit those tensions in order to influence outcomes, but the report leaves unanswered questions about who commissioned it, who paid for it, and what the intended endgame was. The platform’s operator also appears to have sought a contract with Malaysia’s national communications regulator, presumably offering itself as a vendor of cyber intelligence or counter-disinformation services. Anthropic found no evidence that this pursuit succeeded. The idea that the very body responsible for regulating communications might have been approached by an operation secretly manipulating public debate is alarming. It shows that the actors were ambitious, seeking institutional legitimacy while simultaneously undermining the information environment they hoped to infiltrate. Anthropic rated the campaign as “Category Two” on its internal Breakout Scale, meaning that the operation’s assets were distributed across multiple platforms but that there was no clear evidence it had broken into authentic communities or changed real-world discourse. This is not a verdict of total failure; rather, it suggests the operation was exposed before it reached full maturity. Still, the playbook is now clearly visible.
Anthropic’s report is part of a broader effort among AI companies to monitor malicious use of their systems. The company’s Threat Intelligence team spent months tracking how threat actors tried to use Claude for harmful activity, and this Malaysian operation is one of its most significant public disclosures. The platform was not a random experiment; it was a commercial enterprise, selling influence as a service. Its infrastructure included mechanisms designed to make fake accounts appear genuine, constantly rotating cookies and IP addresses, and using AI to produce content that could be published rapidly and in volume. It was, in effect, an automated public relations machine for political manipulation. Anthropic’s disclosure also raises uncomfortable questions about the limits of AI safety. Claude refused some requests, but the actor still managed to build a substantial operation. That suggests safety measures can slow down abuse but not always stop it. The report is also noteworthy because it reveals the ongoing cat-and-mouse game between platform defenders and sophisticated adversaries. The operation’s use of “Malaysia Pulse” as a fake news outlet showed how AI can generate credible-looking journalism with minimal human oversight. The fabricated intelligence reports about an opposition politician and civil society groups are particularly disturbing because they could be used to damage reputations without any factual basis. Anthropic’s classification as Category Two indicates that while the operation had not yet caused visible breakout into authentic communities, it was fully capable of doing so if left undetected. The company’s monitoring and response mechanisms are the reason the world knows about this at all. But the report also highlights how difficult it is to attribute such activities, especially when they cross national borders and involve layers of hired infrastructure, anonymous payment, and legally ambiguous intermediaries.
At a human level, this story is less about algorithms than about the fragility of public trust. Elections are won and lost not only at ballot boxes but in the stories people tell about one another. When a hidden platform can create a thousand fake accounts, generate a fake newspaper, and produce false dossiers accusing an opposition politician of fabricated misdeeds, the very idea of informed consent becomes shaky. Citizens in Malaysia may have seen content that appeared authentic but was actually designed by an AI-directed operation. Their online debates, their sense of what was happening in their own country, could have been subtly altered. The report arrives at a moment when scrutiny of the AI industry is intensifying from many directions. Earlier in the week, an Anthropic researcher resigned, expressing fears that the company and its rivals are building systems that could pose existential risks by the end of the decade. This juxtaposition is important. We are simultaneously afraid of AI’s near-term dangers, such as election manipulation, and its long-term dangers, such as catastrophic loss of control. While no one should overstate the impact of one operation, the Malaysian case shows that AI is already being weaponized in practical, commercial ways. It also shows that some weapons have internal brakes. Claude’s refusal to generate defamatory material and its hesitation when asked to run psychological operations suggest that safety training can make a difference. Yet no model can fully discern the intentions of a user who constantly adapts. The ultimate safeguard remains human awareness, transparency, and public accountability. As Anthropic releases its findings, the world is left with the unfinished story of a fake news outlet called Malaysia Pulse, a network of invisible digital puppeteers, and a quiet race between those who would manipulate democracy and those who would defend it.

