OpenAI Disrupts Russian and Iranian 'False Front' Influence Operations, Including Its First Category 5 Case

Published · AI Daily — AI-assisted deep research, methodology & disclosure

On October 8, 2026, OpenAI disclosed that it banned two covert influence operations that used its models: Russia's 'Dark Clark' and Iran's 'Bogus Bylines'. Both relied on 'false front' entities to launder conflict-related messaging into target audiences. The Iranian operation ran seven fake journalist personas that pitched articles to small and medium outlets worldwide. The Russian operation appears to have co-opted unwitting people in Latin America to run a 'think tank'. On the IO Breakout Scale, the Russian case rates Category 5, the first OpenAI has disrupted, and the Iranian case rates Category 4. The central finding: these look like classic pre-AI influence operations, with AI making some workflows easier.

On October 8, 2026, OpenAI published a report in its Safety section titled 'Disrupting AI-enabled false front operations'. It says the company recently banned two covert influence operations (IO) that used its models: one from Russia and one from Iran. The two share a design. Each built 'false front' entities and used them to launder geopolitical and conflict-related messaging into its target audience. The report is the latest in a series OpenAI has published over the past two and a half years on cyber attacks, covert influence operations, scams and other violations of its Usage Policies. The stated goal is to inform regulators, industry peers and wider society about how threat actors try to use AI, and to shine a light on the vulnerabilities they try to exploit. Start with the facts. The Iranian operation, nicknamed 'Bogus Bylines', ran a stable of seven 'journalist' personas. It used them to pitch long-form articles to small and medium online outlets around the world. Beyond long articles, it generated batches of social media comments, mostly on topics related to the US-Iran war, and it used AI to draft internal reports. The Russian operation, nicknamed 'Dark Clark', appears to have co-opted unwitting people in Latin America to run a 'think tank' on the ground. As well as controlling that think tank, the operators created fake 'leaked' documents and audio scripts, some of which OpenAI saw being spread online. Both operations made heavy use of AI to draft internal reports, and the Russian operation did this more than anything else. The report adds that in both cases the actors used questionable or outright deceitful methodologies to exaggerate the operators' effectiveness.

The mechanics of 'Dark Clark' are worth a closer look. OpenAI banned a cluster of ChatGPT accounts that originated in Russia. They used the service for covert influence work aimed at countries across Latin America. Much of the activity appeared aimed at undermining Ukraine's reputation in the region, and some appeared aimed at influencing local political outcomes, especially in Argentina and Bolivia. Most operators prompted in Russian. One prompted in Spanish but still appeared to be located in Russia. OpenAI does not allow access to its models from Russia, so the operators connected through VPNs. They used ChatGPT for three main tasks: writing internal reports on their own activities and on other people's activities they could plausibly take credit for, creating content for the operation, and drafting performance reports on a self-described 'research platform' in Latin America called the Social Research Center (SRC). They appear to have controlled the SRC through a fake persona named 'Mia Clark', which is why OpenAI nicknamed the operation 'Dark Clark'. In their internal reports the operators claimed to have spread fake stories across Latin America to undermine Ukraine or local leaders, and open-source researchers have attributed some of those fakes. OpenAI has shared information on this case with the relevant authorities.

The most notable part of the report is how it frames the role of AI. OpenAI writes that these operations closely resembled complex influence operations of the pre-AI age, and used AI to make some of the workflows easier. The Iranian personas bore a family resemblance to the fake journalist 'Alice Donovan', a front for Russian military intelligence whose articles were published by a range of Western outlets in 2016-17. In 2020, individuals associated with past activity by the Russian Internet Research Agency ran a fake 'news' outlet called 'PeaceData', which co-opted unwitting journalists around the world into writing for it. The playbook is old. What changes is cost and speed. AI can give such operations greater scale, efficiency, linguistic fluency and editorial ability. Operators can use those gains to exploit unsuspecting victims, such as employees or editors, and to plant content in front of audiences who have no idea who was behind it or what their motives were. The reach assessment is also unusual. OpenAI uses the IO Breakout Scale, which rates influence operations from 1 (lowest) to 6 (highest). It assesses the Russia-origin operation as Category 5, the first Category 5 operation it has disrupted since it began reporting. The Iran-origin operation reached Category 4. Both landed content, not all of it generated by OpenAI's models, in mainstream media outlets rather than simply posting it on social media. That fits a pattern OpenAI sees across the 30 covert influence operations it has exposed in the last two and a half years: operations that try to land content in real media outlets, rather than relying on fake social distribution, tend to have the highest potential reach and impact. The report includes a matrix of those 30 operations, assessed by primary distribution method (social media, operation-run website, external publications) and by Breakout Scale score. Operations that used more than one method are classified by the one that appeared to be the core of the operation.

What does this mean for builders and defenders? For AI developers and platforms, abuse detection cannot stop at the question of whether a model produced harmful text. Individual requests in these operations often look harmless: rewrite an article, polish a comment, summarize material, draft a report. The signal sits at the account level, in the combination of behaviors, such as one cluster of accounts producing content for several personas, or access through VPNs from a region where access is not allowed. For media outlets and enterprises, the defense is not detecting whether text is AI-generated, since some of this content was not generated by the models at all. The defense is to verify authors, check institutions, and trace funding and people. For policymakers, the report is a reminder that leverage may sit on the distribution side: these operations reached Category 4 and 5 because real editors and real outlets ran their material. The report also makes a point the industry should take seriously. Because false front operations depend on concealment, they are especially vulnerable to responsible disclosure. Both 'Alice Donovan' and 'PeaceData' ceased their activity after they were exposed. OpenAI says its goal in reporting these cases is to make further research and disruption easier, and to make continuing the operations harder. That turns transparency from a public relations posture into a working defensive tool. Several challenges lie ahead. First, AI use in such operations will probably deepen, but the core remains human organization and infiltration of real institutions, so model-side blocking alone cannot solve the problem. Second, the ratings and attributions rest on OpenAI's own visibility. They cover activity that used its models, and similar operations on other models and tools fall outside the report. Third, the hard part is coordination with media and platforms. Small and medium online outlets often lack the resources to vet outside contributors, and those are exactly the outlets the Iranian operation targeted. Expect threat intelligence sharing, author identity checks and institutional transparency requirements to become shared concerns for AI safety teams and the media ecosystem in the period ahead.

Sources