OpenAI reports first disruption of covert influence operations using its models
One Russian network's posts still carried the model's own refusal messages, which a researcher cited as evidence the operations were poorly executed rather than AI-supercharged.
- Security & misuse
- Notable
OpenAI published a report describing five covert influence operations it said it had identified and banned from its models over the preceding three months — its first public disclosure of this kind. Two campaigns, “Bad Grammar” and “Doppelganger,” were linked to Russia and had used the models to debug code for a Telegram bot and to generate and translate social-media posts and news commentary in English, French, German, Italian and Polish, targeting Ukraine, Moldova, the Baltic states and the US. A Chinese network, “Spamouflage,” used the models to research social-media activity and produce multilingual posts across platforms including X, Medium and Blogspot. An Iranian operation, the International Union of Virtual Media, used them to translate and generate long-form articles and headlines supportive of Iran and critical of Israel and the US. An Israeli political-marketing firm used them to generate comments and articles about the Gaza conflict for placement on social media and news sites.
OpenAI assessed that none of the five had achieved meaningful reach, scoring no higher than 2 out of 6 on the Brookings Institution’s Breakout Scale, a measure of whether influence content spreads beyond the network that produced it into authentic audiences. The report also noted that the operations were, in places, executed poorly enough to undercut themselves: the Bad Grammar network posted content that included the model’s own refusal messages, exposing it as AI-generated. Thomas Rid, a Johns Hopkins researcher who reviewed the findings, was quoted saying the weakness of these first exposed campaigns was a surprise, since “we all expected bad actors to use LLMs to boost their campaigns.”
The report established a format OpenAI and other labs repeated in later disclosures — periodic threat-intelligence updates naming state-linked and commercial operations caught using their models, alongside an explicit judgment that AI assistance had not yet translated into greater real-world reach for propaganda content.