On October 8, 2026, OpenAI announced it had banned covert influence operations originating in Russia and Iran that were using ChatGPT to run what the company called "false front" entities. The announcement, detailed in a company safety report, described a pair of OpenAI influence operations that laundered geopolitical and conflict-related messaging through fake journalists, a phony think tank, and real media outlets that did not know they were being used.

The Russian operation drew the harshest assessment. OpenAI rated it Category Five on its six-level breakout scale, making it the first operation ever to score that high, and placed the Iranian campaign at Category Four. It is a notable milestone for OpenAI influence operations tracking: the company said it has exposed thirty covert campaigns over the past two and a half years, and they ranked near the top for sophistication.

The Iranian "Bogus Bylines" network

OpenAI gave the Iranian campaign the nickname "Bogus Bylines." According to the report, operators prompted in Persian, generated content in both Persian and English, and used VPNs to obscure their location. They created seven fake journalist personas with Western-sounding names: Ervin B. Hoskins, Noah Lamington, Sophia Gonzalez, Michael Harrison, Ericka Feusier, Jenny Williams, and Alice Johnson. For the Michael Harrison persona, the operators even asked ChatGPT to write the biography itself, Unite.AI reported.

The personas pitched long-form articles to small and medium online outlets around the world. OpenAI said it identified just under a hundred articles published or syndicated under the operation's bylines across roughly a dozen outlets focused on international affairs, geopolitics, and the Middle East. The earliest dated to July 2025 and the latest to October 2026, with the pace picking up after the United States and Iran went to war earlier this year, according to the Dubai Telegraph's account of the report. The Iranian effort shows how patient these OpenAI influence operations can be, running quietly for more than a year before anyone noticed. That scale of placement is what separates today's OpenAI influence operations from older spam-style campaigns.

The personas did not stay on the page. The Hoskins account, which claimed its owner was an American freelance writer, had profiles on X and Instagram. X's transparency information showed the account connected through a West Asia Android app, while Instagram's data placed it in Iran, and both accounts were later suspended. Meta had already banned the Hoskins persona's Instagram account in August 2026, and in March 2026 it disrupted a separate Iranian operation that also used a Michael Harrison persona, according to Unite.AI.

The Russian operation reached Latin American classrooms

The Russian side of the OpenAI influence operations takedown targeted Latin America with the stated goal of undermining support for Ukraine and shaping local politics. For their Peru campaign, operatives impersonated a regional educational authority and tricked schools into holding activities about Ukraine that featured Stepan Bandera, a divisive historical figure. Peruvian outlet Extra confirmed that such a school event actually happened, NPR reported.

The ripple effects were real. A Polish news report about the school event prompted a far-right Polish member of the European Parliament to propose banning entry for people who expressed support for Bandera. OpenAI wrote in its report that the fake "both fed on, and fed into, historical tensions between Ukrainians and Poles," according to NPR. The company's own internal analysis called it the widest-reaching influence operation it had encountered, because it drew a public response from an elected official.

The Russian operatives also claimed to run a fake think tank in Latin America, recruiting unwitting researchers to interview experts and write reports. OpenAI compared the setup to a 2020 Russian operation that posed as an independent news outlet tied to the late oligarch Yevgeny Prigozhin's Internet Research Agency. The operatives sometimes took credit for events they had nothing to do with, and AI-generated material was only a minority of the workload. They mostly used ChatGPT to draft status reports for their own superiors, which is what ultimately exposed them. The Russian side shows these OpenAI influence operations reach beyond text generation into real-world recruiting.

Why landing in real outlets matters

The bluntest finding in OpenAI's report was about reach. Campaigns that placed false narratives in established media outlets reached far wider audiences than ones relying on fake social media accounts, the company said. That is what made the Iranian effort stand out: getting polished, AI-assisted articles into legitimate publications launders propaganda through channels people already trust, and it worked for over a year. Getting published, not going viral, is the whole point of modern OpenAI influence operations.

Jessica Brandt, who ran the Office of the Director of National Intelligence's Foreign Malign Influence Center from 2023 to 2025, told CNN, "It's remarkable that the Iranians managed to land their content in real media outlets, expanding the potential reach of their campaign." She added that AI is letting foreign adversaries build more convincing false fronts and hide their hand more effectively, according to CNN's reporting. Her assessment puts OpenAI influence operations squarely in the media-trust debate, not just the AI-safety one.

OpenAI noted the Iranian operation appeared consistent with a commercial actor running a for-hire influence campaign, though it could not identify who was paying. The company drew a line from these AI-assisted fronts back to older playbooks: "Alice Donovan," a fake journalist persona described as a front for Russian military intelligence whose articles appeared in Western outlets in 2016 and 2017, and "PeaceData," a fake news outlet Meta exposed in 2020 that recruited unwitting journalists. Both stopped operating after they were exposed.

The pattern across both of these OpenAI influence operations is worth sitting with. The campaigns that worked best did not chase social media virality. They got published. When a familiar outlet runs clean prose under a plausible byline, spotting the manipulation gets much harder, which is exactly why these operations invested in looking real.

Related reading: how an AI agent broke into Australia's Medicare portal, why Google's SynthID detector will not save you from AI fakes, and what the NYC AI hearing revealed under oath. For the full breakdown of both campaigns, Unite.AI's report on the takedown has the persona-by-persona detail, and NPR's coverage walks through the Peru school episode.