On 8 October OpenAI reported two banned operations that launder geopolitical messaging through fake organizations and fake journalists. By its own assessment the Russian one is Category 5 on the IO Breakout Scale, the first since OpenAI began these reports. In two and a half years it has exposed 30 influence operations.
- 8 October 2026: OpenAI announces it banned ChatGPT accounts of two covert influence operations that used “false front” organizations and personas. One is Russia-origin, the other Iran-origin, by OpenAI’s assessment.
- “Dark Clark” (Russia, Latin America): a fake think tank, the Social Research Center, run, according to OpenAI, through the invented persona “Mia Clark”. OpenAI rates it Category 5 of 6 on the IO Breakout Scale, the first it has disrupted since it began reporting.
- “Bogus Bylines” (Iran): seven fake journalist names, almost 100 articles in about a dozen online outlets worldwide; Category 4. For both cases OpenAI says it shared information with the relevant authorities.
According to OpenAI, the Russian operators mostly did not ask ChatGPT to write the fakes themselves. They asked it to write the reports about them, addressed to a superior OpenAI does not know.
One example from the Russians’ reports. They claim that in May 2026 they created an email address posing as the Regional Directorate of Education in Lima, and used it to instruct schools to hold events about Ukraine on 21 May. They also claim the stories ran in the press in Peru and Poland. OpenAI found matching articles in both countries, and in some of them a reaction from at least one Polish MEP.
Another: a fake recording of a worker at the state water company EPSAS saying the water in La Paz would be shut off. Spread in late May, at the height of the protests in Bolivia, it was publicly denied by EPSAS itself.
If you run a small outlet that takes guest writers, the Iranian operation was aimed squarely at you. The operators had ChatGPT check a draft against the submission rules of a specific outlet and then write the email to the editor. The articles ran under seven names of supposedly Western journalists, and the accounts of one of them, by their transparency settings, were located in Iran.
The comments were something else: their likes are counted in single or double digits. But the operators’ report measured the views of the posts they replied to, not of the replies themselves, so the number came out large. The Russian reports are the same story: OpenAI writes that the operators took credit for things that were not theirs and that their claimed impact cannot be taken at face value.
OpenAI itself notes that both operations resemble the complex operations of the pre-AI age, only with lighter workflows. The Iranian “journalists” bear a family resemblance to “Alice Donovan”, a front for Russian military intelligence whose articles ran in Western outlets in 2016 and 2017. The Russian scheme of unwitting local staff, it writes, recalls “PeaceData” from 2020.
One more thing about reach. Both landed their content, not all of it generated with OpenAI's models, in real outlets, not only on social media. Of the 30 operations exposed, OpenAI writes, the ones that try to land content in real outlets tend to have the highest potential reach.
The weak spot of a false front is that it is secret. “Alice Donovan” and “PeaceData” stopped after they were exposed. The report counts on that.