What OpenAI says it found
OpenAI published a threat-intelligence report on October 8, 2026, titled "Disrupting AI-enabled 'false front' operations." The company says it banned accounts connected to two covert influence operations, one originating in Russia and one in Iran, that used its models together with traditional tactics to run front organizations: a stable of fake journalist personas pitching articles to small and medium outlets worldwide, and a Latin America "think tank" staffed by people who reportedly did not know they were working for a Russian group.
This is an analysis, not a claim check that settles the question. OpenAI is the reporting party. It detected the activity, banned the accounts, graded the operations, and is the source of every account-ban claim in this article. Where open-source researchers or fact-checkers corroborate specific incidents, that corroboration comes as links cited inside OpenAI's own report; the underlying pages could not be independently retrieved for this piece, so those items are labeled accordingly.
The operations behind the headlines
The Iranian operation, according to the report, ran a stable of seven "journalist" personas that pitched long-form articles to small and medium online outlets around the world. It also generated batches of social media comments, generally on topics related to what OpenAI describes as the US-Iran war. The Russian operation, nicknamed "Dark Clark" after a fake persona called "Mia Clark," controlled a self-described "research platform" in Latin America called the Social Research Center (SRC), created fake "leaked" documents and audio scripts, and, in OpenAI's telling, co-opted unwitting people in Latin America to run the front organization on the ground.
The single most important detail for readers trying to weigh this story is how the models were actually used. OpenAI's own text states that the Russian operators' main use of ChatGPT was drafting and updating internal reports to an unknown superior, and that in the majority of cases it did not observe them using the models to create campaign content, only to report on it. The operators also used VPNs, because OpenAI blocks access to its models from Russia. Both operations, the report says, used questionable or outright deceitful methodologies to exaggerate their own effectiveness in internal reporting.
What the Breakout Scale measures, and who is doing the measuring
To rate the impact of influence operations, OpenAI uses the IO Breakout Scale, a methodology developed by the Brookings Institution that grades covert influence operations from 1 (lowest) to 6 (highest). The scale is essentially a measure of reach and impact: an operation stuck posting on its own social accounts scores low, while one that breaks into authentic communities, mainstream media, or offline consequences scores high. OpenAI says it assesses the Russia-origin operation, Dark Clark, at Category 5, and the Iran-origin operation at Category 4. Category 5, it writes, is "the first Category 5 operation we've disrupted since we began our reporting."
A definitional note is worth adding: Brookings' Category 5 definition is framed around amplification by high-profile individuals and mainstream reach, while OpenAI's applied grading for Dark Clark rests on the operation landing content in mainstream media outlets, so the applied reading in the report is OpenAI's, not a verbatim application of the scale text.
Two caveats belong next to that number, stated plainly. First, the score is OpenAI's own grading of its own detection work; no independent body has certified it. Second, OpenAI itself observes that these operations "closely resembled complex influence operations of the pre-AI age, but used AI to make some of the workflows easier." The headline scale record and the modest AI role are both in the same report, and honest coverage has to hold both at once.
Why landing in real media drives reach
OpenAI has now reported disrupting about 30 covert influence operations over roughly two and a half years, beginning with its February 2024 report on state-affiliated threat actors. Across that history, the company identifies a consistent pattern: the operations that land their content in real media outlets, rather than relying on fake social media distribution, tend to have the highest potential reach and impact. Both of the October 8 operations, it says, managed to place some content (not all of it AI-generated) in mainstream media.
That pattern explains why the Breakout Scale numbers rose. Getting an article published in an actual outlet borrows the outlet's credibility and distribution. Fake accounts posting into the void reach mostly bots and each other. The false-front model, where fabricated personas or institutions trick real editors and real employees into amplifying messaging, converts other people's trust into reach. This is also why the report's most concrete alleged incidents are not AI stories at all: fake emails purporting to come from a Lima education directorate instructing schools to hold Ukraine-themed events, and fake emails tricking schools in Ecuador into a pledge ceremony involving President Daniel Noboa and Erik Prince. The alleged AI involvement was in reporting on, drafting, and managing this machinery, not in generating the viral moment itself.
Responsible disclosure worked before
The history here is instructive. OpenAI's report notes that the Iranian operation's journalist personas bear "a family resemblance" to "Alice Donovan," a fake journalist front for Russian military intelligence whose articles were published by a range of Western outlets in 2016 and 2017. In 2020, people associated with past activity by the Russian Internet Research Agency ran a fake outlet called "PeaceData," which co-opted unwitting journalists into writing for it. Both, the report notes, ceased their activity after they were exposed.
That is the logic of responsible disclosure: false-front operations depend on not being known. Once researchers name the front, editors stop accepting pitches, contributors leave, and platforms remove the infrastructure. OpenAI's stated goal in publishing is to make further research and disruption easier and continuing the operations harder. The caveat is symmetric: exposure worked for Alice Donovan and PeaceData, but each of those operations ran for years before exposure, and OpenAI does not claim disclosure prevents such operations from starting.
How much did AI matter? An assessment
For all the record-setting framing, the AI component of these operations looks modest in OpenAI's own account. The models supplied internal reporting, translation, drafting help, and workflow efficiency. OpenAI's very first influence-operation report, from May 2024, found that none of the five operations then disrupted had meaningfully increased their audience through its services, and that none scored higher than 2 on the Breakout Scale. What changed by October 2026 is not that AI became a propaganda superweapon; it is that operators got better at the older, human craft of fronts, pitches, and unwitting intermediaries, and used AI as office software around that craft.
My reading, clearly marked as analysis: the most significant signal in this report is not the Category 5 score but the observation that Dark Clark allegedly fooled people in Latin America into doing real-world actions, holding school ceremonies, producing original content for the SRC. The vulnerability being exploited is human trust in institutions and correspondence, which predates language models entirely. AI made the bookkeeping easier; the vulnerability was always the same. Readers should treat the Breakout Scale figures as a vendor's self-assessment, note that the fact-checks and official denials OpenAI cites (from Ecuadorian and Peruvian outlets) could not be independently retrieved for this article, and watch whether independent researchers confirm the attribution and the reach claims in the coming weeks. OpenAI says it has shared information on the Russian case with relevant authorities.
