OpenAI banned two covert influence operations, one Russian and one Iranian, that used its models to build fake media personas and plant articles in real outlets, the company said in a report published October 8. The Russian operation is the first the company has rated Category 5 on its own impact scale, the highest level it has ever disrupted.
The report, titled Disrupting AI-enabled false front operations, describes something more unsettling than the usual bot farms. These operations used AI to run realistic front organizations: a stable of seven fake journalists pitching bylined articles to small and medium news outlets, and a genuine-seeming think tank run by real people in Latin America who likely had no idea who was behind it. The content landed in mainstream media rather than dying on fake social accounts, which is why OpenAI rates these operations its most impactful disruptions in two and a half years of reporting.
The Iranian operation: seven fake reporters
OpenAI’s team dubbed the Iranian operation Bogus Bylines. Its most far-reaching activity involved asking ChatGPT to review and refine long-form English articles about the geopolitics of the US-Iran conflict, then generate pitch emails to send to editors of online outlets. The pitches carried seven different fake bylines: Ervin B. Hoskins, Noah Lamington, Sophia Gonzalez, Michael Harrison, Ericka Feusier, Jenny Williams and Alice Johnson. For one of them, Michael Harrison, the operators asked the model to write the biography itself.
The trappings were careful enough to fool at least some editors. The persona accounts carried Western-seeming names while account transparency panels showed locations in Iran and the use of a West Asia Android app, details OpenAI’s investigators surfaced after the fact. Alongside the articles, the operation generated batches of social media comments in English and Persian, often replying to screenshots of posts with sets of aligned takes, then posting them within minutes of each other. Many of the commenters praised the operation’s own articles, likely to make them look popular.
The comment targeting stayed mostly on the conflict between Iran, the United States and Israel. Where investigators found the replies in the wild, they typically made up a minority of responses on any given post, which suggests the operation was not dominating any conversation, only tinting it.
The Russian operation: a think tank that wasn’t
The Russian operation ran a different play. Rather than building fake journalists, it appears to have co-opted unwitting people in Latin America to operate a think tank on the ground, laundering geopolitical and conflict-related messaging into coverage through an organization that looked legitimate from the outside. OpenAI assesses this operation at Category 5 on the IO Breakout Scale, a framework developed at Brookings that rates influence operations from 1 to 6, where 5 and above implies operations capable of shaping public opinion across multiple countries.
OpenAI has disrupted operations at Category 4 before, but never a 5. The report also notes the Russian team created fake leaked documents and audio scripts, some of which spread online, and used the models heavily for drafting internal reports on the operation’s own performance. Both operations, the company notes, used questionable or outright deceitful methods to exaggerate their effectiveness in those internal reports, inflating their own metrics for whoever was paying.
The pattern behind the operations
| Operation | Origin | Breakout Scale | Main techniques |
|---|---|---|---|
| Bogus Bylines | Iran | Category 4 | 7 fake journalist personas, pitched articles to online outlets, batch-commenting on social media |
| Unnamed Russian op | Russia | Category 5 | Co-opted think tank run by unwitting people, fake leaked documents and audio scripts, heavy internal AI reporting |
The wider claim in OpenAI’s report is structural. Across the 30 covert influence operations the company has exposed since early 2024, the ones that tried to land content in real media outlets rather than relying on fake social accounts reached the highest breakout categories. The matrix OpenAI includes in the report shows external-publication operations clustered at categories 4 and 5 while social-media-led operations stayed at 1 through 3.
There is a historical echo here that the company itself draws out. The fake journalist personas bear a family resemblance to Alice Donovan, a fabricated byline used by Russian military intelligence whose articles ran in Western outlets between 2016 and 2017. Bogus Bylines is, in effect, the same play with a generative model handling the drafts, the pitches and one of the biographies. What AI changes is the cost: producing twenty convincing article drafts and twenty tailored editor pitches used to take a staff. Now it takes prompts.
Both operations closely resembled complex influence operations of the pre-AI age, but used AI to make some of the workflows easier.
What this means for newsrooms
The practical exposure lands on editors at small and medium outlets, the kind of publications that depend on submissions and have thin verification capacity. An operation like Bogus Bylines does not need to fool anyone permanently. One accepted article from a fake reporter puts a desired narrative into a real publication, with a real editorial masthead behind it, at zero distribution cost to the operator.
OpenAI argues these false-front operations carry a particular weakness: their covert nature makes them fragile once exposed. Both Alice Donovan and PeaceData, an earlier operation exposed in 2019, ceased activity after their cover was blown. The company’s stated goal in publishing the report is to make further research and disruption easier, and continuing the operations harder. Banning the accounts removes their access to the tools, though of course it does not remove their access to other models.
The worrying part is what the report cannot rule out. OpenAI’s visibility extends only to its own platform. Operations that use a mix of providers, or that rely on open-weight models run locally, leave no trace in any company’s abuse logs. The 2.5 years of reporting that produced this dataset covers exactly one company’s slice of the problem, and the slice is not random: it is the portion of threat actors careless or desperate enough to touch a monitored API.
Still, the report offers one clear takeaway for readers and editors alike. The tells that used to betray Russian and Iranian influence ops were clumsy prose, broken English, obviously fake accounts. Those tells are gone. The article that renders cleanly, the byline with a plausible headshot, the pitch email with no spelling errors, none of that means a human writer was ever involved. Verification now has to rest on the persona’s footprint rather than the prose’s quality, and the publications most at risk are precisely the ones least equipped to do that checking.
