OpenAI said on 25 August that it had disrupted a covert influence operation very likely originating in Russia which used ChatGPT to promote a fabricated expert organisation called the International Burke Institute.
The campaign does not appear to have achieved a large audience. That is an important limit on the story. What makes it useful is the operating model: AI-generated promotional material pointed people towards a credible-looking institution stocked with copied academic work, false affiliations and a purported “sovereignty index” that favoured Russia. The operation was not simply manufacturing posts. It was manufacturing the appearance of authority behind them.
What OpenAI established
In its primary account of the disruption, OpenAI said it banned a cluster of ChatGPT accounts that very likely originated in Russia. The operators used virtual private networks because OpenAI does not permit access to its models from Russia. They prompted mostly in Russian, requested outputs mainly in English and explicitly asked the model to remove linguistic clues that might reveal their origin.
The generated material was posted across Substack, Telegram, X, Facebook and LinkedIn. Some posts promoted the International Burke Institute, or IBI, through accounts carrying its identity. Others appeared to come from ordinary users whose main activity was sharing IBI material. The operation also produced replies to genuine Substack users and content for Telegram channels aimed at audiences in several countries.
OpenAI described IBI as the operation’s core. The institute presented itself as an Israel-based expert community, complete with prominent specialists, international partners and its own research. OpenAI reviewed 36 articles associated with experts on the IBI website and found that 34 had been copied from elsewhere. Some were attributed to the wrong people. Its “sovereignty index” placed Russia favourably while marking down Western countries.
There is an important distinction in the evidence. OpenAI said the articles on the IBI website were not generated by its models. The identified ChatGPT use centred on promotional posts and comments, while one operator also generated logos for Telegram channels. AI supported the distribution and presentation of the operation; it did not create every component.
Independent reporting adds useful checks
Le Monde independently examined the network and reported that the institute claimed links to bodies including the United Nations and UNICEF. UNICEF told the newspaper that IBI was not an approved partner and that it had no record of joint work. Le Monde also reported that people displayed as experts had not worked for the institute.
That corroboration matters because most of the detailed technical and attribution evidence currently comes from OpenAI, a company reporting abuse of its own service. OpenAI is authoritative about the accounts and prompts it observed, but its assessment is still one organisation’s investigation. Public evidence does not identify the individual operators, establish a formal relationship with the Russian state or measure a change in anyone’s beliefs.
OpenAI assessed the operation at the lower end of Category Three on the Brookings Breakout Scale: activity across multiple platforms with some indications of reaching authentic audiences. Typical posts received low numbers of views and the official IBI accounts had few subscribers. Some associated Telegram channels had roughly 10,000 to 20,000 followers, but follower counts do not by themselves demonstrate attention, persuasion or coordinated state control.
The operational and governance consequence
The practical lesson is that content moderation alone is too narrow. A persuasive-looking post can be checked, labelled or removed, while the institution it cites continues to supply false credentials, recycled scholarship and apparently independent analysis. The trust signal has moved from the sentence to the surrounding organisation.
Publishers, public bodies and research teams should therefore verify institutional provenance as well as individual claims. That means checking whether named experts acknowledge the affiliation, whether quoted research matches the original source, whether partnership claims are confirmed by the supposed partner, and whether a new index publishes a reproducible method. As our earlier analysis argued, finding a polished source is not the same as establishing evidence.
Platforms and AI developers also need to join signals across the operation. Model-account behaviour, repeated translation requests, attempts to disguise origin, common links, coordinated posting patterns and false institutional identities are individually ambiguous. Together they can expose an influence network. This is the operating logic behind treating AI transparency as a continuing workflow, with provenance and escalation built into the process rather than added after publication.
For organisations using AI-generated research or briefings, there is a further control to add: verify the source before evaluating the prose. Fluent summaries can make a fabricated institution easier to circulate internally. Procurement, policy and communications teams should retain the original publication, author identity, methodology and affiliation evidence, especially where a source is new, politically aligned or unusually prolific.
What remains unresolved
OpenAI called this a new and previously unreported campaign, but the public record is still incomplete. It is not clear who financed or directed it, how many people operated the network, how much of its non-OpenAI content used other AI systems, or whether the associated Telegram audiences were authentic. There is also no public evidence that the operation materially altered political outcomes.
The wider risk is therefore an inference, not a demonstrated effect: once a fabricated institution, contributor network and distribution system exist, AI can reduce the cost of keeping them active across languages and platforms. The campaign’s weak reach is reassuring about this instance, but it does not remove the replicable governance problem.
What to watch next
The next useful evidence would be coordinated disclosures from the social platforms that carried the material, further attribution from an independent threat-intelligence body, and action by organisations whose names or work were misused. Researchers should also watch whether the IBI assets reappear under new names after the ChatGPT accounts were banned.
The proportionate conclusion is not that AI has made propaganda automatically persuasive. This operation did not establish that. It showed something more specific: AI can help a small influence operation promote the trappings of institutional credibility across several channels, while the underlying authority is copied, misattributed or invented. The defensive priority is to verify the institution behind the content and connect evidence across the whole operation.

