On August 25, 2026, OpenAI published a report disclosing and banning a batch of Russia-linked ChatGPT accounts. Centered on the fictitious "International Burke Institute" (IBI), these accounts used VPNs to bypass Russia's user access restrictions and mass-produced pro-Kremlin content across five platforms: Substack, Telegram, X, Facebook, and LinkedIn. According to OpenAI's investigation, of the 36 articles IBI published between September 2025 and May 2026, 34 were plagiarized from other online sources, and some were falsely attributed to prominent scholars including Francis Fukuyama and Noam Chomsky.
Not a Content Factory, But an Authority-Forging Machine
Compared with previously known AI propaganda patterns, the core strategy of this operation marks a clear shift. In May 2024, OpenAI published its first influence operations report, documenting five operation networks originating from Russia, China, Iran, and Israel—including Russia's "Bad Grammar" (using AI to write bot code and post short political comments on Telegram) and "Doppelganger" (forging fake news in the style of mainstream Western media), and China's "Spamouflage" (multilingual cross-platform content distribution), among others. At the time, all operations scored only Level 2 on the Brookings Breakout Scale, meaning content spread across communities within a single platform but never truly gained traction among real user groups.
The IBI operation was far more ambitious. The operators did not merely use ChatGPT as a content accelerator; they used it to build an institution with the appearance of academic credibility: generating English-language reports for IBI, producing a "Sovereignty Index" (which graded Russia leniently while giving low scores to France, Germany, and the United States), and lending authority to their conclusions through forged bylines of prominent scholars. According to The Decoder, OpenAI rated this operation Level 3 on the Brookings Scale—meaning the content had achieved cross-platform, multi-community dissemination with the infrastructure in place to spread further. This is the highest rating in any of OpenAI's public disclosures to date.
Flaws Hidden in Translation Errors
The operators explicitly instructed ChatGPT to "eliminate features in the text that might reveal Russian-language origins," yet the language still betrayed them. Analysts found a critical error in content related to German politics: the operators referred to Germany's ruling coalition as the "Svetofor coalition"—Svetofor being the transliteration of the Russian word for "traffic light"—rather than the conventional German term "Ampelkoalition" (which likewise means "traffic light coalition," referring to the three-party governing alliance of the Social Democrats, Greens, and Free Democrats). This detail not only exposed the operators' native language background but also revealed a structural weakness in current AI-assisted translation: models can mimic the grammar of a target language but struggle to reproduce the idiomatic expressions rooted in a specific cultural context.
Meanwhile, another distribution line of the operation—a Telegram channel called "Lahme Ente" (German for "lame duck")—focused specifically on criticizing Ukraine, the EU, and Germany. According to The Decoder, the Telegram channels in question amassed between 10,000 and 20,000 subscribers. This stands in stark contrast to the extremely low subscription numbers on the IBI website itself, suggesting the operators clearly understood that the real distribution channels were not the fake think tank's website but the Telegram ecosystem with its existing community base. ChatGPT's role here was that of a content production workshop; actual dissemination relied on a manually maintained network of channels.
Detectable Doesn't Mean Preventable
The fundamental reason OpenAI was able to detect and ban these accounts lies in its business model: every conversation between a user and ChatGPT is recorded on its servers. The operators used VPNs to gain access, believing they had concealed their geographic location, but they could not conceal their content patterns—mass-generating English-language propaganda texts with specific linguistic fingerprints is precisely the kind of target that machine-learning detection systems are best at identifying.
But there is a structural paradox here: the capability that enables OpenAI to perform content moderation essentially depends on its permanent retention of all user inputs. The Register noted in its report that OpenAI was able to detect Russian propaganda because "everything you ask an AI is permanently recorded on a tech company's servers." A system capable of scanning for Russian propaganda characteristics is equally capable of scanning for any other type of political content, and OpenAI has not established an independent third-party oversight mechanism on this issue.
The True Cost Structure of AI Propaganda
If one looks only at the IBI operation's direct reach numbers—most posts drew scant readership, and the official accounts had very few subscribers—it would be easy to conclude the operation was "ineffective." But this judgment ignores the actual operating logic of modern influence operations: infiltration is not the goal; building infrastructure is.
A fictitious think tank equipped with a "Sovereignty Index," forged scholar endorsements, and a multi-platform presence can be activated at any moment to serve as an "expert source" for specific events. The IBI website was registered in February 2025 and had been operating for roughly six months by the time OpenAI discovered it—long enough to accumulate a degree of credibility in some search results and community discussions. As The Guardian quoted OpenAI as saying, the goal of such operations is to "manufacture authority, obscure narrative sourcing, and build assets that can be scaled up in the future"—a fundamentally different threat model from factory-style mass disinformation production.
Independent Assessment
OpenAI's release of a detailed technical report disclosing the operators' tactics is a rare example of transparency among current AI platforms. The takedown itself is an inherently asymmetric contest: the operators merely need to open a new account and switch to a new VPN node, while the defenders must continuously maintain detection capabilities and counter ever-evolving evasion techniques.
The leap on the Brookings Scale from Level 2 to Level 3 shows that in 2024, AI-assisted propaganda was described as "limited in reach and failing to break into real communities"; by 2026, operations under the same framework had risen to the level of multi-platform, cross-community dissemination. This is not because AI models have become more persuasive, but because operators have learned to use AI more sophisticatedly: not to replace humans, but to rapidly forge institutional credibility and mass-produce content that "looks human-written." Current platform takedown mechanisms can only sever one identified tentacle at a time, without yet addressing the deeper issue—how to rebuild the fundamental premise of "source credibility" in the information ecosystem after AI has dramatically lowered the barrier to manufacturing fake authority.
© 2026 Winzheng.com 赢政天下 | 转载请注明来源并附原文链接