bytevyte
bytevyte
Language
ai-beats

A fake think tank, a sovereignty index, and the AI influence campaign OpenAI dismantled

AI influence campaign

OpenAI has dismantled a Russia-linked AI influence campaign built around the International Burke Institute (IBI), a fake Israel-based think tank whose website recycled plagiarized academic work and published a "sovereignty index" that cast Moscow in a favorable light while criticizing Washington, Paris, Berlin and Brussels. The company documented the operation in a report released Tuesday, August 25, 2026, tracing it back to a small set of ChatGPT accounts that, in OpenAI's assessment, most likely came from Russia and were reached through VPNs.

The inquiry began with AI-generated social media posts and expanded into a far more elaborate operation than the Russia-linked campaigns OpenAI says it has broken up since the war in Ukraine began. The operators prompted in Russian, produced mostly English-language comments, and distributed them across Substack, Telegram, X, Facebook and LinkedIn. They asked ChatGPT to scrub any linguistic hint of Russian origin, and they needed VPNs to reach the platform at all, because OpenAI does not allow model access from Russia.

The credibility-laundering apparatus behind the posts is what separates this from a routine spam run. The IBI presented itself as a self-described "expert community" based in Israel, a cover that borrows credibility from a country with a dense research culture. The domain was registered in February 2025 and carried articles from September 2025 to May 2026. Of 36 sampled pieces, 34 were plagiarized, some misattributed to Noam Chomsky and Francis Fukuyama. One linguistic fingerprint undid the disguise: Svetofor, Russian for traffic light, appeared in a description of Germany's coalition government, a tell of machine translation from a Slavic language. Some affiliated Telegram channels drew between 10,000 and 20,000 followers.

OpenAI's security researchers found the same messages repeated across Telegram channels and elsewhere, evidence of a distribution network rather than isolated posts. Output was multilingual even though English dominated, and the operators repeatedly asked the model to hide linguistic clues, an instruction applied consistently enough to become a pattern in the logs. The repetition shows the campaign was managed rather than improvised, with the same prompts recycled across platforms.

Inside the AI influence campaign

OpenAI placed the operation at Category Three on the Brookings Breakout Scale and acknowledged that it reached relatively small audiences despite its elaborate construction. The gap between those two facts is the story. A plausible think tank requires a registered domain, months of consistent publishing, invented expert identities, an original-looking data product, and enough polish to survive casual scrutiny. Most of that infrastructure predates the ChatGPT stage of the operation, which means the model paid for the amplification while the institution-building carried the real effort. Follower counts in the tens of thousands are not trivial, which makes the small-audience verdict a judgment about influence rather than distribution.

The plagiarism finding deserves more weight than a footnote. Attaching the names of Chomsky and Fukuyama to stolen or doctored essays is a way of renting intellectual authority instead of earning it, and for a reader who never checks bylines, the byline is the citation. The sovereignty index performs the same trick at larger scale: it gives the outlet the visual grammar of research, complete with rankings and an evaluative framework, so the political payload arrives wrapped in the format of scholarship. The comments were only the distribution channel; the think tank was the product.

The economics of influence have changed

Set the reach problem aside, because the cost side is where this case is most revealing. A small group in Russia, using consumer VPNs and a handful of ChatGPT accounts, sustained a multilingual publishing operation for the better part of a year, evaded a country-level access ban, and instructed the model to erase its own linguistic traces. Before generative AI, that would have required human English writers or a professional translation pipeline, both expensive and both traceable. The instruction to hide Russian linguistic clues alone would have cost a trained editor hours per post; now it is a single line in a prompt. OpenAI says the campaign's elaborate construction distinguishes it from other Russia-linked operations it has disrupted since the war began, a framing that suggests the operators invested in durable infrastructure before they invested in amplification.

This is also not the first time OpenAI has hit this pattern. In February, the company disrupted accounts connected to Rybar, a Russian military blog network, which used similar VPN-based methods to reach ChatGPT from Russia. The February and August cases together sketch a pattern: Russian operators treating ChatGPT as an off-the-shelf content engine and VPNs as standard equipment. The recurrence is the point. The playbook has standardized to the point where the same evasion techniques resurface, and detection has become the scarce resource. For platform security teams, each takedown report is a data point about how the adversary adapts between rounds. The August case is the latest reported incident of pro-Russia actors using AI to spread misinformation, extending a sequence that now includes the February takedown.

What the report does and does not prove

I would not take OpenAI's account of the AI influence campaign as the final word, and not because the technical work looks shaky. The company is simultaneously the platform that hosted the abuse, the detective that found it, and the judge that decided the punishment. The "relatively small" reach figure is OpenAI's own estimate rather than an independent audit, and the plagiarism finding rests on a sample of 36 articles, not the full corpus. None of that invalidates the investigation. It should discipline how confidently we repeat the conclusion that this campaign failed.

There is a second limitation hiding in plain sight. The operation was caught because of the Svetofor slip and comparable traces, which means the detection methods favored the sloppy. The slip also suggests the operators' review process did not keep pace with their output volume. A cleaner operation, one with native-level translation and proxies rather than obvious VPNs, would be harder to pin down with the same confidence. The report proves that OpenAI can catch an unsophisticated actor. It does not prove that the platform can catch a sophisticated one, and that gap is where the next campaigns will try to live.

The cheap countermeasure is verification. Check the domain registration date, look up the bylines, and test the index against the underlying data. In this case the checks fail fast: a think tank whose sample of work is 94 percent plagiarized, with essays misattributed to living scholars who never wrote them, does not survive contact with a search engine. The operation depended on readers not looking, which is the one vulnerability that scale cannot fix.

The wider lesson of this AI influence campaign is that takedown reports are becoming a core front in AI governance. No regulator publishes misuse statistics at this depth, so the model-makers' own post-mortems are the de facto public ledger of how the technology is being weaponized. Enterprise threat teams, brand-safety units and researchers build vendor assessments and watchlists on the basis of these documents, which gives one company's methodology outsized influence over how the entire industry understands the threat. That is useful. It is also a concentration of epistemic power in the hands of the platform being abused. For business readers the practical consequence is direct: the research that circulates in procurement discussions and policy briefings now needs provenance checks of its own.

OpenAI presents the report as one expression of its self-assigned mandate to counter covert manipulation of public opinion, the kind of deception in which the actors behind a message keep their own identity hidden. That framing positions the platform as an arbiter of political speech, a role with its own risks. A takedown report is simultaneously a security action and a political statement, and the line between the two has never been formally drawn.

What I take from this episode is that the barrier to entry for influence operations has collapsed while the cost of detecting them has not. The IBI machine was built to look legitimate and to last: a registered domain, months of output, fabricated authorities, a data product, and a distribution layer that reached tens of thousands of followers on Telegram alone. That the campaign drew small audiences this round says something about execution, not about the ceiling of the method. The same scaffolding, pointed at a bigger audience with better operational security, is the realistic next iteration.

Why this matters

This report matters because it shows how cheaply generative AI lets state actors industrialize trust-building: for the price of a few accounts, a small team manufactured an institution, an index and a publishing record designed to be cited later. The defense is real but reactive, and it currently rests on platforms policing themselves. Until that changes, treat every polished think tank and every confident index as something to verify rather than assume.

Sources

Disrupting a new covert influence campaign from Russia

Photo by Brecht Corbeel on Unsplash

✔Human Verified


Researched and cross-referenced against primary sources by the Bytevyte editorial team. This article was generated with the assistance of artificial intelligence and reviewed by the Bytevyte editorial team.