AGI Soon As Possible · Deep reads on AI & tech
Article

The AI only did the promotion, the authority was copied: inside the Russian influence operation OpenAI disrupted

2026-08-25 · 10 min read

OpenAI disclosed on August 25, 2026 that it banned a cluster of ChatGPT accounts originating in Russia that promoted the International Burke Institute (IBI), a self-described "expert community" claiming an address in Israel. ChatGPT's role in the operation was confined to social media posts and comments, while the website that supplied the credibility was stocked with copied work: of 36 sampled articles, 34 were lifted from elsewhere on the internet, sometimes attributed to the wrong authors. OpenAI states that the elaborate construction of this campaign distinguishes it from other Russia-linked operations the company has disrupted since the start of the war in Ukraine. ASAP summarizes the official OpenAI report as the primary source.

What the banned accounts actually produced

The banned cluster very likely originated in Russia, and everything it generated with ChatGPT was social media content rather than the website material itself. The operators prompted in Russian while most of the output was in English, and they instructed the model to hide any linguistic clues that they were Russian. Because OpenAI does not allow access to its models from Russia, they reached the platform through VPNs.

The generated content surfaced on five platforms: X, LinkedIn, Facebook, Substack and Telegram. Some posts came from accounts bearing the IBI name and logo, while others came from accounts that looked like everyday users but whose activity consisted mainly of posting IBI articles. Alongside those proactive posts, the operators generated replies to real Substack users across a range of topics, and those replies typically ended with a request to follow the IBI channel.

One operator also produced German-language posts for a Telegram channel called "Lahme Ente," meaning lame duck. Those posts routinely criticized Ukraine, the EU and the German government while advocating better relations with Russia. A second operator generated logos for a dozen Telegram channels focused on Germany, the USA, France, Poland and Türkiye, and repeatedly asked for Russian-language summaries of those channels' activity. One US-focused channel posed as an American outlet with a bio carrying multiple indicators of non-native language.

Thirty-four of thirty-six articles were copies

Of the 36 articles linked to experts on the IBI website and published between September 2025 and May 2026, 34 are copies taken from elsewhere on the internet, which is what OpenAI's review of that sample established. Some were years old and others were attributed to the wrong authors, and none of them were generated by OpenAI models.

The two examples OpenAI published show the method precisely. An article on the China-Pakistan Economic Corridor was copied, on OpenAI's reading, from a Cambridge University Press original written by Professor Emeritus Yunas Samad of Bradford University and published on July 7, 2025, yet it ran on the IBI site dated December 28, 2025 under the name of Professor Katharine Adeney of Nottingham University, a specialist in South Asian politics. A second article on migration governance was published by the Migration Policy Institute in April 2025 and written by Meghan Benton, Natalia Banulescu-Bogdan and Kate Hooper, yet it ran on IBI dated January 21, 2026 under a purported expert named Kate Howell. The photograph used for that profile belongs to an Australian professor of food chemistry and dates from 2017.

The roster of names was inflated in the same spirit. As of July 17, the site claimed a wide range of world-class experts, including figures such as Francis Fukuyama and Noam Chomsky. The domain carrying the IBI brand was registered in February 2025, and the site advertised a street address in Israel.

The sovereignty index as a device

The proprietary "sovereignty index" is the most distinctive component of the operation, and OpenAI states this is the first time it has disrupted a Russia-linked influence operation that went to such elaborate lengths. The index reports were split between two-country comparisons and single-country studies, concentrating on France, Germany and the European Union, states that criticize Russia's war on Ukraine. The operation pushed similar narratives about the United States.

The tone of the reports ran toward polemic rather than analysis. The France report argued that ten years of Macronism opened the country like a safe holding historical capital that is now being sold off in parts. The USA report described Trump arriving in Beijing with the world's number one sovereignty index and leaving after steps that qualify as a voluntary reduction in autonomy. The Germany report demanded real military sovereignty instead of dependence on American bases, and politicians whose first loyalty runs to the German people rather than to corporate boards in New York.

The machine-translation residue showed up in the website text, not in the model output. A German-focused article referred to the country's coalition of socialists, liberals and greens as "the Svetofor coalition," where the German original would be Ampelkoalition, or traffic-light coalition. The word "svetofor" means traffic light in several Slavic languages including Russian, and it is exceptionally unlikely to occur to an English or German speaker describing that coalition.

Small audience, large structure

The immediate reach of the operation was limited, and OpenAI assessed it at the lower end of Category Three on the Brookings Breakout Scale. Typical social media posts received low numbers of views and the official IBI accounts had low subscriber counts. The Telegram channels performed better, generally counting between 10,000 and 20,000 followers each.

OpenAI locates the significance in the infrastructure rather than the audience. The operators used ChatGPT only for isolated promotional posts, but those posts pointed to an otherwise credible-appearing institution complete with purported experts, republished academic work and a purported proprietary risk index. The case illustrates how influence actors can use AI as a supporting tool inside a broader effort to manufacture authority, obscure the source of favored narratives, and establish assets that could be scaled over time.

Why AI was the cheapest part of this operation

The structure of this operation is inverted from the "AI fake news" framing, because ChatGPT handled only the last mile of distribution while every component that produced trust came from outside the model. The promotional copy that pushed links outward is the whole of what the model contributed. The academic articles, the expert roster and the index reports were sourced through copying and misattribution, methods that were available twenty years ago.

That arrangement inverts the usual cost curve. In older influence operations the expensive line item was distribution, the labor of writing volume and running accounts, while credibility was the part that got abandoned. Generative models pushed the price of distribution close to zero, and the bottleneck moved upward. The remaining question is no longer what to publish but why anyone should believe it, and these operators answered that question with plagiarism rather than with a model.

The same structure exposes the limits of platform-level defense. OpenAI can cut off its own accounts, but what got cut was a promotion channel and not the institution. The website, the articles and the index remain, and the promotion can resume through another model or through human hands. A model provider's threat report is valuable because it publishes the blueprint, not because it ends the operation.

The detection point flipped

The most instructive irony in this case is where the operation was caught. The operators succeeded in stripping Russian linguistic tells from the AI output, because they instructed the model to do exactly that and the English posts complied. The residue survived in the part that never touched a model, the website articles that a human drafted and a machine translated, which is where "Svetofor" appeared in place of a traffic-light coalition.

The practical implication follows directly. Content authenticity work has concentrated on the question of whether a text was written by AI, yet AI authorship was not what identified this operation. Provenance tracing was. Pulling 36 articles, locating their originals and confirming that authorship had been swapped, then finding the true owner of a profile photograph in a 2017 record, is what brought the whole institution down.

Any organization budgeting for AI detection should revisit that ordering. Comparing a cited work against its actual source produces far more decisive evidence than inferring machine authorship from stylistic statistics. The first approach returns a probability and the second returns an original.

Where the same method would land in Korea

Translated into the Korean context, the exposure sits with indexes and institutes rather than with news articles. Korean policy debate leans heavily on international rankings and indicators, and an index from an unfamiliar organization gets cited quickly once it arrives with numbers and a country table. That format is exactly what IBI built. An index with a name, a methodology and per-country reports is verifiable in principle, and citable in practice long before anyone verifies it.

The way AI answer engines select sources compounds the problem. A site that presents itself as an institution and holds many topic documents becomes a citation candidate in both search and generative answers. Filling a site with copied academic work is an attempt to deceive human readers, and simultaneously an attempt to forge trust signals aimed at indexes and models.

The procedure Korean newsrooms and research teams need is not novel. Before citing an index from an unfamiliar institution, check when the domain was registered, contact two or three of the listed experts to confirm they actually participate, and search a few sentences from one flagship report verbatim to see whether the original lives somewhere else. Those three steps are what dismantled IBI, and a single reporter can run them in half an hour.

What the report does not establish

The scope OpenAI confirmed is bounded by activity observed on its own platform. The report notes online traces suggesting that a handful of real individuals in Israel may also have represented IBI in article submissions and at conferences, while stating plainly that OpenAI is not in a position to determine the relationship between those individuals, the institute and the operators in Russia. The report makes no claim about state direction or funding.

The nature of the sample deserves equal care. The 36 reviewed items were a sample of articles linked to experts on the site rather than a census of everything published there, and the figure of 34 holds within that sample. The Telegram follower counts of 10,000 to 20,000 are not a measure of reach or of authentic audience either. An assessment at the lower end of Category Three means the operation spread across multiple platforms with some indications of breakout to authentic audiences, which is not a finding that opinion moved.

Scalability is the open question. This campaign spent heavily on human labor to manufacture authority, and that labor left fingerprints. If the copying, the misattribution, the author profiles and the methodology documents all move inside a model, verification gets more expensive than it is today. OpenAI's observation that supporting use of AI led to the broader operation being exposed may not hold for the next generation of campaigns, and building the verification procedure before that happens is the safer plan.

Source: OpenAI, "Disrupting a new covert influence campaign from Russia" (OpenAI Global Affairs, August 25, 2026), summarized by ASAP.

ASAP — AGI Soon As Possible

AI & tech,
read in depth

Beyond the headlines — into the context and the structure

AGI Soon As Possible · asapai.co.kr

← All posts