In the shadows of the internet, where the line between authentic debate and manufactured deception has grown increasingly blurry, OpenAI recently pulled back the curtain on two quietly sophisticated influence operations—one Russian, one Iranian—and banned the ChatGPT accounts behind them. The company’s investigation report paints a picture that is both familiar and unsettling, but not for the reasons you might expect. These weren’t the loud, troll-infested social media campaigns that have dominated our headlines for years, complete with bot armies and viral hashtags. Instead, both operations took a slower, more insidious path: they used fake identities to plant content directly into legitimate media outlets, disguising propaganda as journalism and think-tank analysis. It is a reminder that influence operations evolve, that they learn from their failures, and that the battlefield is no longer just our social feeds but the very institutions many of us still turn to for credible information. OpenAI’s report also notes that this wasn’t the first time the company had uncovered Russian activity; a previous campaign had leaned heavily on social media and even built a fake think tank. But this time, the approach was different, more careful, and arguably more dangerous, because it blurred into the background noise of real news and policy discourse. For those who follow the twists and turns of AI-driven manipulation, the report is less a shock than a confirmation: the same generative tools that empower creators, students, and businesses are also being weaponized by state-linked actors seeking to shape how whole regions understand the world.
The first operation, which OpenAI internally tracked as “Dark Clark,” was Russian in origin and focused its energy on Latin America, a region that has become a key battleground for influence and counterinfluence. The goal, according to the report, was twofold: to discredit Ukraine and to destabilize local politics in ways that would benefit Russian strategic interests. Rather than relying on a sprawling network of anonymous social media accounts, the creators behind Dark Clark built something more convincing: a think tank controlled through a fictitious persona, a classic trope in influence operations but executed with enough polish to be dangerous. The fake persona likely recruited or co-opted local staffers, possibly without their full knowledge, to lend legitimacy to the operation. The group distributed fabricated audio files and forged documents that were designed to look like leaked intelligence or official communications. These materials were convincing enough to trigger real-world consequences: fact-checkers in Ecuador and Peru were forced to respond, and official government denials were issued to rebut claims that had never been true in the first place. This is the moment when an influence operation stops being a harmless rumor and becomes something closer to a weapon. OpenAI rated Dark Clark as a category 5 on its Breakout Scale, a six-point system used to measure how far an operation has spread beyond its original platform. It marked the first time in two and a half years of reporting that an operation had reached that level, meaning politicians were responding to and repeating the content, amplifying it into mainstream political conversation. That is a sobering milestone, because it shows how quickly well-crafted disinformation can move from the fringes to the center of public life.
The second operation, named “Bogus Bylines,” was Iranian and more focused in its scope, though no less troubling. Instead of building a fake think tank, the actors behind this campaign created seven fictional journalists, each with a plausible-sounding name and background, and used them to place nearly a hundred articles about the US-Iran conflict in online outlets around the world. The articles were designed to look like routine commentary or reporting, but they pushed a narrative favorable to Tehran while undermining the United States and its allies. The operation also included social media comments generated to accompany the articles, though those comments apparently gained almost no traction, a testament to how difficult it can be to manufacture organic engagement even with the help of AI. What makes Bogus Bylines particularly interesting is its restraint. It did not try to go viral. It did not chase clicks or outrage in the way we have come to expect from foreign influence campaigns. Instead, it aimed for persistence and credibility, dripping a relatively modest number of articles into the information ecosystem in the hope that they would be read, shared, and cited by unwitting journalists, analysts, and policymakers. In that sense, it was less a flood and more a slow leak, designed to contaminate the well of public knowledge without anyone noticing until much later. The contrast with the Russian operation is instructive: Russian operatives sought to provoke immediate political reactions in Latin America, while the Iranian operation sought to shape long-term narratives around a geopolitical conflict. Both were dangerous, but in different ways, with different timelines and different measures of success.
What is perhaps most striking about both operations is how they used artificial intelligence. OpenAI’s investigation found that neither campaign was built around mass-produced, AI-generated content at the scale we might fear. There were no millions of bot posts, no endless variations of the same message, no obvious tells of machine generation. Instead, the operators used AI largely for internal reporting and for adapting propaganda to different languages. They used ChatGPT to translate their content, to adjust tone for specific audiences, to create plausible biographies for fake journalists, and to help draft the internal memos that guided their own work. In other words, AI was being used as a productivity tool, a force multiplier for human operators who already knew exactly what they wanted to achieve. This is a crucial nuance in the debate about AI and disinformation. The common fear is that large language models will enable an explosion of automated propaganda, drowning out human voices with endless machine-generated noise. But these operations suggest something more subtle and more concerning: AI can make relatively small operations far more efficient, allowing a handful of people to manage false personas, maintain consistent stories across languages, and produce content that is just good enough to pass as authentic. It is not about replacing human deception; it is about perfecting it. This also explains why detection is so hard. The telltale signs of bot-driven campaigns—repetitive phrasing, glaring factual errors, strange timing—are less likely to appear when AI is used to polish rather than generate wholesale. The result is an information environment where the cost of running a credible influence operation has dropped, and where the line between human and machine authorship is increasingly impossible to draw.
Beyond the specific campaigns, there are broader implications for journalism, media literacy, and public trust that deserve our attention. The fact that both operations successfully placed content in legitimate media outlets is a reminder that journalistic institutions remain vulnerable to astroturfing, particularly when budgets are tight and vetting is rushed. Fake experts, fake authors, and fake institutions can slip through the cracks, especially when their work is polished, well-sourced, and seemingly aligned with a publication’s editorial slant. For ordinary readers, the danger is not just being told what to think; it is being made unable to trust what they read. Every time a think tank is revealed to be a fiction, every time a byline turns out to be a phantom, every time a leaked document is exposed as a forgery, a little more of the common ground on which democratic debate depends is eroded. In that sense, the ultimate target of these operations is not any particular election or policy; it is the very possibility of shared reality. When people cannot agree on basic facts, they cannot have productive arguments, and when they cannot have productive arguments, they become vulnerable to the loudest, most divisive voices. OpenAI’s report is therefore important not only because it exposes specific actors, but because it offers a case study in how modern influence operations work. It shows that the attackers are not necessarily trying to convince us of something; they are trying to leave us so disoriented that we no longer know what to believe. And in that fog, almost any narrative can take hold.
OpenAI’s decision to publish its findings and ban the accounts involved is a necessary step, but it is also, in the grand scheme of things, a small one. Banning accounts is reactive; it addresses the symptoms rather than the underlying incentives. The operations will adapt, create new personas, find new vulnerabilities, and continue their work in some other corner of the digital world. The real defense lies in building resilience among publishers, platforms, and the public. Publishers need better tools to verify the identity and history of the people they publish, and they need to be willing to ask uncomfortable questions about funding and motives. Platforms need to share threat intelligence more openly, so that a campaign exposed on one service does not simply migrate to another without consequences. And the public needs a renewed commitment to media literacy—not the kind that teaches people to distrust everything, but the kind that helps them evaluate sources, seek out original reporting, and recognize the difference between evidence and assertion. OpenAI, for its part, says it is committed to investigating and disclosing these operations, and that is genuinely valuable. But the deeper lesson is about the fragility of the information ecosystem. The same openness that allows anyone to publish a blog post, submit an op-ed, or start a think tank also allows adversaries to impersonate, fabricate, and deceive. We will never live in a world where influence operations do not exist. What we can do is make it harder for them to succeed, and to respond with clarity and resolve when they do. The fight is not for who controls the algorithm, but for who controls the story.

