Decoding the world of cybersecurity

OpenAI disrupts Russia-origin influence campaign

OpenAI has banned accounts it says very likely originated in Russia and were used to support an elaborate but relatively low-reach covert influence campaign.

OpenAI disrupts Russia-origin influence campaign
Summary
  • OpenAI says it banned ChatGPT accounts that were very likely operated from Russia, including through VPN access.
  • The accounts supported content associated with the self-described International Burke Institute and attempted to conceal Russian linguistic signals.
  • OpenAI says the campaign remained relatively limited in audience reach despite a more elaborate infrastructure than earlier operations.

OpenAI has disrupted a covert influence operation that it says was very likely operated from Russia and used ChatGPT to support an online network built around a self-described expert organisation.

The company said on 25 August that it banned a cluster of accounts linked to activity promoting the International Burke Institute, or IBI, which presented itself as an expert community based in Israel.

According to OpenAI’s investigation, operators used ChatGPT to generate social media comments for platforms including Substack, Telegram, X, Facebook, and LinkedIn. Prompts were submitted in Russian, while much of the resulting content was produced in English. The operators also instructed the model to avoid linguistic clues that could reveal Russian origins.

OpenAI said the accounts accessed its services using virtual private networks because its models are not directly available from Russia. Its assessment is that the accounts very likely originated there; that is a platform attribution by OpenAI rather than an independent finding of responsibility by a government or law-enforcement body.

The investigation expanded beyond AI-generated posts. OpenAI said the broader operation included a website containing copied or misattributed academic material and a “sovereignty” index that presented Russia favourably. The company described the campaign as more elaborate in construction than other Russia-origin influence operations it has previously disrupted.

Reach appears to have been limited. OpenAI said the activity attracted relatively small audiences, an important constraint on claims about its actual political or social effect. The use of generative AI can reduce the cost of producing multilingual or stylistically varied material, but the ability to generate content does not guarantee distribution, credibility, or influence.

That gap between production and impact has become central to assessing AI-enabled influence activity. Generative systems can help operators create comments, translations, personas, and supporting material at volume, but campaigns still depend on accounts, websites, distribution channels, trusted intermediaries, and an audience willing to engage with the material.

The IBI operation also shows why attribution based only on visible content is becoming more difficult. Operators can ask models to remove linguistic indicators, vary tone, or translate material into a target language, reducing some of the clues that historically helped analysts identify origin or coordination.

At the same time, dependence on a major AI platform creates another source of investigative evidence. Providers can observe account behaviour, prompting patterns, infrastructure signals, and relationships between otherwise separate pieces of content. That gives platform operators a role in discovering and disrupting activity that may be difficult to identify from public posts alone.

There are limits to that visibility. A provider can assess how its own service was used but cannot automatically establish the full chain of command behind an operation, measure its influence across every external platform, or determine whether the activity was directed by a state unless the evidence supports that conclusion.

OpenAI’s report therefore establishes a narrower but still material finding: a Russia-origin account cluster used ChatGPT as one component of a deceptive influence operation, the company identified and banned the accounts, and the campaign’s observable reach remained relatively small despite its elaborate supporting infrastructure.

×