How did fake experts reach real newsrooms?
OpenAI says two covert influence operations used false journalist identities and a front research centre to place material in real outlets. AI mostly helped with drafting, translation and internal reporting; the harder failure was identity and source verification, and claimed reach remains only partly corroborated.
Editorial responsibility: The Impact of AI Editorial Desk · Report a factual concern
At a glance
- 1OpenAI says a Russia-origin operation built a front research centre and an Iran-origin operation used seven false journalist identities; it removed the associated accounts.
- 2The Iranian operation placed or syndicated almost 100 articles across roughly 12 outlets from July 2025 to October 2026, while the Russian front published more than 60 original articles on its own site.
- 3AI reduced language and production friction, but the report does not show that AI invented the tactics, persuaded readers or caused the reported political outcomes.
Research topic
AI-enabled covert influence operations and newsroom verification

The direct answer: borrowed trust carried the message
The operators did not need to build a mass audience entirely from scratch. According to OpenAI, they created apparently credible intermediaries—a research centre, a founder persona and seven journalist identities—and then used familiar editorial routes to move their material into public view. Real outlets, contributors and readers supplied the legitimacy that a newly created influence account could not. AI helped the operators write, translate, pitch and report on the work, but false identity and weak provenance checks were the decisive bridge into news ecosystems.
That makes this primarily a story about institutional verification rather than a demonstration of autonomous AI persuasion. OpenAI says it banned accounts linked to both operations. It describes the Russia-origin campaign, which it calls Dark Clark, as its first Category 5 influence operation and the Iran-origin campaign, Bogus Bylines, as having a Category 4 article-placement stream. Those categories describe observed amplification beyond the operators' own insertion points. They do not measure whether readers believed the claims or changed behaviour because of them.[1][2]
What the investigation can—and cannot—show
OpenAI had direct visibility into the use of its own service and says it combined account signals with open-source reporting. That gives the company unusual evidence about how operators used ChatGPT: drafting and refining text, translating material, preparing pitches, and producing internal reports. The report also names websites, personas and examples that outside researchers can inspect. Yet the public article does not provide a complete account list, every prompt and output, total message denominator, preserved publication dataset or independent audit of the attribution.
The company also marks an important boundary around operator claims. Some internal reports could not be corroborated, and in places the operators appeared to claim credit for developments that could have occurred without them. That caution matters because an influence operator has incentives to exaggerate impact to sponsors, while a platform report can benefit from demonstrating effective detection. The most defensible conclusion is that the operations used OpenAI accounts and achieved some documented publication or amplification—not that every self-reported success was real or that the resulting content changed public opinion.[1][2]
Dark Clark: a research-centre facade aimed at Latin America
OpenAI attributes Dark Clark to Russia and says it targeted audiences in Latin America, including material intended to undermine support for Ukraine and affect political discussion in Argentina and Bolivia. A supposed founder named Mia Clark fronted a Social Research Center. OpenAI says local staff who contributed to the project appeared not to know who ultimately controlled it. The centre published more than 60 original articles on its own site, creating an inventory that could be cited, translated or offered to other publishers under an institutional-looking name.
The model's role was narrower than a claim of automated propaganda production might suggest. OpenAI says the operators used ChatGPT mainly for internal activity reports, with some drafting and translation of public content. The operation nevertheless reached the company's Category 5 because material or narratives moved into wider political and media discussion, including responses by prominent figures. OpenAI links examples of fact-checks and official denials, but also says some claimed effects remain unverified. A high category therefore records breakout events, not the volume of AI-written text or proof of causal political influence.[1]
Bogus Bylines: seven identities and almost 100 articles
The Iran-origin operation used seven fictitious journalist personas to submit articles, pitches and comments. OpenAI says it identified almost 100 published or syndicated articles across roughly 12 outlets between July 2025 and October 2026. The subjects included Iran, Israel, the United States and regional conflict. ChatGPT was used to refine long-form pieces, adapt pitches and prepare internal reporting. The result was not one viral synthetic post but a repeated attempt to pass covert advocacy through ordinary publishing workflows.
OpenAI separates the operation's article stream from its comment activity. It rates the article placements Category 4 because material escaped the original accounts and appeared in established media, while batches of comments remained Category 2 and attracted little engagement. The operators' internal reports sometimes counted views on the parent post as though every viewer had seen or engaged with their comment. That is not a valid readership denominator. Potential exposure, parent-post views, article opens, attentive reading and persuasion are different quantities, and the public evidence does not join them into a conversion chain.[1]
Why Category 5 is serious but not a persuasion score
The Breakout Scale was published by Ben Nimmo through Brookings in 2020 as a six-level comparative framework. Categories rise as an operation spreads across platforms and communities, enters mainstream media, is amplified by high-profile people, or prompts concrete action. It was designed around observable, replicable events available to investigators in real time. That is useful because covert campaigns rarely provide reliable audience surveys or behavioural data. It also prevents a large number of low-engagement posts from looking more important than a single verified institutional response.
But the scale's author distinguishes probable impact from measured belief change. A Category 5 finding says prominent people amplified the operation; it does not say how many humans saw the specific item, understood its origin, accepted its claim or acted differently. OpenAI's first Category 5 case is therefore consequential evidence that a covert campaign crossed social and institutional boundaries. It is not evidence that this was the most persuasive campaign, that AI caused the breakout, or that the political outcomes claimed in operator reports would otherwise have been different.[1][2]
The control point is the contributor, not just the prose
Newsrooms can screen machine-written prose and still miss a human-managed false identity. The stronger controls sit around contributor provenance: confirming a writer's employment and publication history through independently obtained contacts; verifying who controls a research organisation and its domain; asking for conflicts, funding and relevant data; and treating polished biographies or social profiles as claims rather than proof. A disclosed AI-editing policy may help, but it will not expose a covert sponsor when the named author is invented.
Those safeguards must be proportionate. Requiring government identity documents from every freelancer could exclude vulnerable writers, whistleblowers and contributors working under legitimate pseudonyms. A safer approach layers checks according to risk, keeps sensitive identity evidence separate from editorial systems, and allows a trusted editor or specialist to verify a confidential identity. Publications also need a rapid correction and provenance-notice process, because one accepted article can be syndicated or cited long after an account is removed from a model platform.[1][2]
What changes for readers, editors and platforms now
For readers, a familiar outlet or named expert is evidence of an editorial process, not a guarantee of origin. The practical response is not to distrust every article but to look for a traceable author record, primary documents, transparent conflicts and corrections when a consequential claim depends on an unfamiliar contributor. For editors, the report turns identity assurance into a routine security control. For legitimate freelancers, clearer verification can protect reputations by making it harder for fabricated personas to borrow the standing of independent journalism.
For AI providers, removing accounts limits future use of one service but does not retract already published material or establish who read it. Sharing indicators with affected publishers and other platforms can reduce recurrence, provided disclosures protect investigations and innocent contributors. Because both operations resemble pre-AI influence techniques, controls also need to work when operators switch models, use local systems or hire human writers. Focusing only on generated-text detection would leave the underlying false-front strategy intact.[1]
Evidence limits and what would change the assessment
This is a first-party enforcement account from the company that investigated the activity and supplied the model used by the operators. The public report offers important examples and candid caveats, but no independent party can reproduce its account-level findings from the released material alone. It does not state the total number of associated accounts, messages or generated words, so there is no denominator for how frequently the model was used or how often attempted placements failed. Deleted, private and never-published material may also limit outside reconstruction.
Confidence would rise if affected publishers disclosed which submissions they accepted and how each identity passed review; if independent researchers or authorities corroborated attribution and account linkages; and if preserved datasets showed article-level views, referrals and corrections without conflating them with follower counts or parent-post traffic. Evidence that audiences changed beliefs or behaviour would require a different design, such as careful surveys or experiments. Until then, the strongest finding is operational: two covert networks used AI to make established deception workflows cheaper and smoother, and some of their false fronts reached real media systems.[1][2]
What this means for people
- Readers can encounter covert messaging through the borrowed credibility of an apparently legitimate outlet or expert.
- Journalists, freelancers and local staff may unknowingly work for a false-front organisation and suffer professional or personal harm when it is exposed.
- Newsrooms need stronger contributor verification without forcing vulnerable or pseudonymous writers into unsafe identity disclosure.
Global context
The documented operations link Russia, Iran, Latin American political audiences, US and Middle Eastern issues, and internationally read publications. They do not represent every influence network or every AI provider. Their wider significance is the portability of the method: fluent drafting and translation can lower operating costs anywhere, while newsroom trust, syndication and expert identity remain cross-border amplification channels.
What the evidence does not yet show
- OpenAI is both the investigating platform and the model provider; the public report is not an independent regulatory or judicial finding.
- The underlying account logs, full prompt dataset, complete article list and reproducible attribution method are not public.
- The report provides no total account, message or attempted-placement denominator.
- Breakout Scale categories measure observable amplification pathways, not audience belief, behavioural change or causal political impact.
- Potential outlet reach and parent-post views are not article reads, unique readers or evidence that a covert message was noticed.
- Some operator claims could not be corroborated and may have exaggerated or misattributed impact.
What to watch next
- Corrections, contributor notices or identity-review changes from affected publishers.
- Independent or official corroboration of the attribution, account links and claimed political effects.
- Publication of a privacy-protected dataset or methodology that outside researchers can reproduce.
- Cross-platform action that addresses already published material rather than only the model accounts.
- Evidence about audience exposure and belief change that does not substitute potential reach for measured impact.
Living evidence record
Impact record IAI-1VZ499J
Evidence stage
Announced
Confidence
Supported
Reporting basis
Multi-source analysis
Independent or research support
Present
Record status
Monitoring
Last checked
8 October 2026
Source trail
2 direct sources across 2 source types.
People impact
Documented in this record.
Uncertainty
Limits and next checks are explicit.
Stages describe the evidence available—not whether a technology is good or bad. See the public method.
Evidence trail
Sources used for this report
Links checked 8 October 2026
This report is labelled multi-source analysis. We summarise and analyse source material in our own words; company statements remain attributed claims until independently supported. Translated summaries preserve the meaning of the original source and link back to it. Read our editorial standards.
Continue the story
Related reporting
Society & Media
When should newsrooms disclose AI use?
A peer-reviewed case study based on 13 interviews with 12 Financial Times managers and 28 internal documents finds that AI disclosure is treated as a spectrum shaped by oversight, risk and context. It describes one newsroom's practice and does not test whether labels improve audience trust.
7 min · 1 source
Society & Media
What is changing in ChatGPT for teens?
OpenAI says a US College Planner for grades 10–12 is coming, alongside flashcards, easier quizzes and multi-photo note capture. The company also released large usage counts, but no study protocol, denominators for several comparisons or evidence that the tools improve learning or admissions outcomes.
7 min · 1 source
Society & Media
Do safer-driving AVs change human behaviour?
A peer-reviewed quasi-experiment found that Lyft automated vehicles followed more smoothly and conservatively, while human drivers left shorter gaps behind matched automated leaders. The study analysed real trajectories, but it did not randomise drivers or measure crashes, injuries or current vehicle systems.
8 min · 3 sources
The Impact Brief
Keep the evidence trail, not the noise.
Get the most consequential AI developments with direct sources and clear limits.
Reader commentary
Add evidence, experience or a question
No account is required. Reader notes are published after a brief civility, relevance and safety check; disagreement is welcome.
Explore commentary across the portal →Published reader notes
0No published reader notes yet. You can start the evidence-led discussion above.
Prefer a private correction or response? Contact the newsroom.