How AI Became the New Battlefield for State Disinformation
OpenAI discovered Russian and Iranian operatives using ChatGPT to craft and amplify false narratives across Latin America and into Western media. The findings reveal a new phase in state-sponsored influence operations — one where AI isn't just a tool, but a force multiplier.
The Shortcut That Got Caught
OpenAI published a blog post on Thursday that quietly upended a few assumptions about how disinformation works in the age of large language models. Russian and Iranian operatives had been using ChatGPT — not to flood social media with bots, but to produce polished reports, fake author personas, and narratives that landed in real newsrooms across Latin America, the United States, and Europe. The finding is significant because it marks a shift from the blunt-instrument era of influence operations toward something more subtle, and more dangerous: narrative laundering at scale.
The Russian campaign, OpenAI found, was primarily about updating superiors. Operatives fed their boss drafts written by ChatGPT, giving the appearance of productivity without doing the underlying investigative legwork. But inside those reports lay the actual operational blueprint — fake think tanks, recruited researchers, impersonated regional officials. One document described what OpenAI called the widest-reaching operation it had encountered, because it produced a tangible political response.
In Peru, Russian operatives impersonated an educational authority and tricked schools into hosting events about Ukraine featuring Stepan Bandera, a figure who evokes sharply divided memories. To Ukrainian nationalists, he is a freedom fighter; to Poles and Jews, he is associated with collaboration and violence against civilians. A Peruvian outlet confirmed one such event occurred. A Polish news report about it followed. Then a far-right member of the European Parliament suggested banning entry to anyone who expressed support for Bandera.
“The Russian fake thus both fed on, and fed into, historical tensions between Ukrainians and Poles,” OpenAI wrote. The operation didn’t create the tension — it had centuries of history behind it. It simply found a place where the fault line was thin and pushed.
Who Catches the False Narratives
What makes this particularly alarming is that these operations weren’t contained to fringe platforms or troll farms. Several pieces of content ended up in established outlets: the Daily Kos in the United States and the Middle East Monitor in the UK. The Iranian operatives created seven fake author personas and published nearly 100 long-form articles pitched to small media organizations worldwide, mostly focusing on the US-Iran conflict and, secondarily, American domestic politics.
The Middle East Monitor has since taken down the author pages but did not respond to requests for comment. The Daily Kos confirmed its community section allows unrestricted posting under the guise of user-generated content, with only a vague prohibition against pretending to be someone else. The posts remain live.
The Daily Kos detail matters less for the volume of damage than for what it signals about the new friction point in information warfare. Outlets that previously served as hard stops for verified sourcing now have porous editorial boundaries. A well-crafted piece written by an AI-powered persona can slip through community guidelines and be cited by reporters who never realized they were engaging with fiction.
The Iranian Commercial Model
Iran’s operation looked strikingly different from Russia’s. While Russian accounts used AI as an efficiency tool for internal reporting, Iranian accounts weaponized AI as a content engine — generating text in both Persian and English, pitching articles to media outlets, and maintaining a portfolio of fabricated authors. OpenAI noted the activity resembled a commercial influence operation run by a for-hire firm, though it could not confirm the actor’s identity.
This distinction may reflect different institutional approaches to disinformation. Russia appears to treat AI as bureaucratic armor — a way to make lower-level operatives look productive while senior handlers decide strategy. Iran appears to be treating it as a production line. Either model is functional. Both are scalable.
Why This Changes Everything
For years, the playbook for counting disinformation was simple: track the accounts, count the amplification, assess the reach. That model assumed the bottleneck was distribution — getting enough people to see a lie. The new bottleneck is credibility. An AI-generated article published in a legitimate outlet carries a veneer of institutional approval that no bot network can replicate.
“AI was valuable to them above and beyond just being a shortcut,” said Darren Linvill of Clemson University’s Watt Family Innovation Center Media Forensics Hub. “It helped them create language that looked and felt and read authentic to the point where it was being published by legitimate outlets. And I think that is something that a few years ago, an Iranian operation like this would have struggled a lot more with.”
That trajectory is the problem. A few years ago, this operation would have failed at the drafting stage — stilted phrasing, obvious hallucinations, structural incoherence. Today, the output is indistinguishable from mid-tier opinion writing. The gatekeepers are not AI companies. They are editors, fact-checkers, and readers — all of whom are operating under increasing pressure to publish faster and verify less.
What Comes Next
OpenAI banned the accounts. That is a containment measure, not a solution. The operatives will migrate to other platforms. The personas will be recreated. The methodology has been field-tested and refined.
What openAI’s report does is force a reckoning that had been deferred for too long: AI models are not neutral tools in information ecosystems. They are force multipliers that lower the barrier to producing persuasive, publishable propaganda. The same technology that helps a journalist draft a story in half the time also helps a foreign operative draft a credible fabrication in half the time.
The Russian operation targeted Latin America because it is an under-monitored theater — historically overlooked by Western intelligence and news organizations alike. The Iranian operation targeted American outlets through community sections because it knew the path of least resistance led through open publishing environments. Both mapped their strategies to the same reality: the infrastructure of influence is no longer centralized around state media apparatuses or known troll farms. It runs through the comments sections, community blogs, and opinion pages of outlets that never imagined they would become distribution channels for foreign influence operations.
The lesson is not that AI is dangerous. It is that any tool that makes high-quality writing cheap and immediate will be used by anyone who benefits from it — including adversaries who have spent decades perfecting the art of the believable lie.