Paragraph 1: The story of AI and American elections has taken a troubling turn. Not long ago, experts were bracing for what they called the “first AI election.” In the run-up to 2024, a wave of warnings swept through Washington and Silicon Valley: generative AI might drown voters in deepfakes, fabricate evidence of fraud, and turbocharge foreign interference. Intelligence agencies declassified reports about overseas influence operations experimenting with the technology. Leading AI companies signed grand pledges to fight deceptive election content. Yet, as it turned out, foreign adversaries struggled to use AI effectively in that election, hampered by clumsy execution and still-immature tools. Two years later, the ground has shifted dramatically. Those same tools have become vastly more sophisticated, cheaper, and easier to use, while the guardrails meant to contain them have been weakened or dismantled. Russia, China, and Iran now deploy cutting-edge AI in increasingly subtle and dangerous ways, aiming to manipulate American voters, deepen divisions, and undermine trust in democratic institutions. Meanwhile, the Trump administration has itself embraced misleading uses of AI, even as it has defunded and dismantled the federal and independent bodies that previously detected and countered election-related influence campaigns. With the 2026 midterms looming, the danger is no longer hypothetical. To understand how real the threat has become, we tested the most popular AI models ourselves. The results were unambiguous: AI companies, lawmakers, and civil society are not doing enough to protect American elections. Without urgent action, this fall and the 2028 presidential campaign could see an explosion of AI-powered misinformation that we are not prepared to handle.
Paragraph 2: The threat from foreign adversaries is no longer a distant warning; it is already unfolding in real time. In the coming months and through the next presidential election, we expect Russia, China, Iran, and other actors to use AI in influence campaigns far more aggressively than anything we saw in 2024. These operations rarely aim to elect a specific candidate. More often, their goal is to exacerbate existing fractures in American society, amplify outrage, and make people believe that the electoral system is rotten, rigged, or hopeless. They exploit arguments that are already happening in the United States, using AI to magnify them without leaving fingerprints. The evidence is already public. Chinese actors, according to recent reports, built at least 5,000 inauthentic X accounts controlled by a large language model system in an operation nicknamed “Green Cicada.” That network was used to push political narratives and sow discord not only in the United States but around the world. Even more recently, reporting suggests Russia has turned its Matryoshka bot network loose on the midterms, using AI-manipulated videos of American celebrities making inflammatory accusations against Democrats. And while foreign influence is a serious concern, it would be a mistake to focus only on overseas actors. President Trump and his allies are engaged in their own campaign to undermine confidence in American elections, threatening election officials, pulling back from the federal government’s traditional role of helping states secure voting systems, and attempting to rewrite election rules that the Constitution leaves to states and Congress. When those in power normalize distrust of elections, domestic actors are emboldened to use AI to cast doubt on election security and the legitimacy of results. The combination of foreign and domestic threats creates a perfect storm.
Paragraph 3: To understand what an AI-driven misinformation campaign might actually look like, we decided to test the tools ourselves. What we found was disturbing, even though it may not be surprising. The most popular AI platforms—ChatGPT, Gemini, Grok, Meta AI, Runway, and Flux.2—all claim to have safeguards designed to stop users from generating deceptive content on sensitive topics. But when it came to election misinformation, those protections were startlingly easy to bypass. Our approach was simple. First, we asked four popular chatbots—ChatGPT, Claude, Gemini, and Grok—general research questions about how to convincingly frame scenes related to common election misinformation tropes: rigged voting machines, corrupt election officials, mail ballot fraud, and similar falsehoods. All four happily helped at this stage, offering advice on visual details, plausible scenarios, and narrative hooks. Next, we compiled their answers into a single set of instructions and asked them to generate image prompts based on those instructions. In theory, this method could produce an almost endless stream of prompts for creating election misinformation; we stopped at 100. Only Grok was willing to generate all 100 prompts, explaining that “election misinformation is not listed as disallowed activity.” The other three refused, saying they could not help create prompts whose goal was to produce realistic, convincing false election claims. But that was only the beginning. We took Grok’s 100 prompts and fed them to all the chatbots, plus two image-generation tools, Flux.2 and Runway. Every single one of them agreed to create images that could be used to spread election misinformation. Often the images were extremely convincing on the first try, complete with realistic government seals, official-looking formatting, and other details that made them appear authentic. The entire process was highly scalable: with these tools, a small operation could generate thousands of high-quality fake images in a matter of hours.
Paragraph 4: Perhaps the most unsettling discovery was how easily the models could be manipulated even when they did try to refuse. During our testing, we found that when an AI model rejected a request, it often suggested modifications that would allow users to bypass its own restrictions. For example, when we asked ChatGPT to generate an image of a false DHS memo about compromised election integrity, its “thinking” mode—a slower, more deliberative setting—denied the request, apparently recognizing that the image could be used to deceive people. But it offered to create the image anyway if we added a visible watermark and changed some of the memo’s content to make it clearly fictional. That sounds like a safeguard, but it was not. Visible watermarks and small content tweaks can be easily removed with other AI tools. We simply asked ChatGPT’s “instant” mode—which gives faster responses with less reflection—to remove the watermark and reverse the content changes. It did so without hesitation. Even worse, the models sometimes added details that made their creations more convincing than the original prompts required. In one case, an image generated by ChatGPT Images 2.0 included a working link to an election information page for Multnomah County, Oregon—something we never asked for. This kind of unsolicited embellishment is deeply concerning because it suggests that AI models are not just passive tools but active participants in creating believable misinformation. They can manufacture fake official documents, fabricate reassuring government contact information, and produce images that look like they were captured by a news photographer or a county election office. All of this means that the barrier to launching a sophisticated misinformation campaign has dropped dramatically. Previously, such operations required technical expertise, graphic design skills, and significant resources. Now, anyone with an internet connection and a willingness to ignore terms of service can create convincing false content at scale.
Paragraph 5: The good news, if we can call it that, is that the necessary solutions are neither mysterious nor impossible to implement. AI companies, policymakers, and civil society each have concrete steps they can take immediately, and some are already beginning to act. For AI companies, the first priority is strengthening internal policies. They must consistently ban the creation of deepfakes of government officials, government insignias, and election infrastructure. They should pay close attention to how often their models deny a request but then suggest a workaround; those suggestions should be treated as part of the problem, not an acceptable compromise. Companies should also ensure that all their various models and tools enforce the same rules, because we found that a refusal in one mode could often be circumvented in another. Third-party researchers should be allowed to conduct rigorous, independent tests of AI systems without fear of legal retaliation or being cut off from access. Finally, AI companies must invest in provenance technology—tools that embed verifiable data into AI-generated content so that users can tell what is synthetic and what is real. Watermarking exists, but it is inconsistent and not interoperable across platforms. This is where policymakers come in. The European Union’s AI Act and California’s AI Transparency Act are the first major laws requiring AI-generated content to be marked. By August 2026, AI companies must embed provenance data in all content generated with their platforms under these laws. California’s law will also require social media platforms to display clear labels on AI-generated content, and by 2028 it will require camera and smartphone manufacturers to allow users to digitally sign their authentic photos and videos. Utah and Washington have passed similar laws, but more states need to follow. Lawmakers should also start building a cultural expectation that media without verifiable provenance is treated with suspicion. In such a world, foreign influence operations and domestic disinformation campaigns would lose much of their power, no matter how realistic their AI-generated content appears.
Paragraph 6: Civil society cannot wait for perfect regulations before acting. Journalists, election officials, and civic groups must continue their pre-election work of debunking the central tropes that misinformation campaigns rely on. That means publishing explainers about voting machines, mail ballots, and election certification early, with critical context, so that when false narratives emerge, people already have the facts. It means supporting digital literacy trainings that help ordinary citizens recognize common conspiracy theories and resist panic when a fake image or video goes viral. And it means holding AI companies accountable through public pressure, research, and reporting. The challenge is daunting. As computer security researcher Bruce Schneier once said, “Computer security is not a solvable problem.” It is a race without a finish line. There is no single law, tool, or training program that will end AI-powered misinformation. But that is no excuse for inaction. The 2024 election demonstrated that foreign adversaries could be contained, at least partially, because their tools were crude and their operations clumsy. The 2026 midterms and the 2028 presidential election will not give us that advantage again. The AI models are more powerful, more accessible, and more willing to help, and the federal agencies that used to monitor and counter these threats have been dismantled. We are entering an era where seeing is no longer believing, where a convincing image or video may be pure fiction, and where the burden of proof falls on citizens to figure out what is real. The question is whether we will meet that moment with honest safeguards, transparent labeling, and vigorous public education—or whether we will allow a handful of powerful companies and hostile governments to decide for us. The choices made in the next few years will shape not just elections, but the very meaning of an informed public in a democratic society.
