Washington (TNND) — Artificial intelligence is changing how foreign influence campaigns operate online, allowing some actors to automate tasks that previously required large numbers of people. A recent report from The New York Times found that Iran and China, along with private Israeli companies, have used AI agents in novel social media influence campaigns. The technology allowed agents to perform multiple steps of an operation, including creating accounts, generating posts, and coordinating activity across platforms such as Facebook, Instagram, X and TikTok. AI-generated content and fake online personas are not new. U.S. officials have previously warned that foreign actors, including Iran, have used generative AI and inauthentic personas in attempts to influence Americans and sow discord. What researchers say is different about these newer campaigns is the degree of automation. In the past, a foreign influence operation might employ hundreds or even thousands of humans working in “troll farms” to write posts, manage accounts, and amplify messages. Those operations were labor-intensive, slow, and vulnerable to takedowns because human workers made mistakes, reused infrastructure, or were exposed by defectors. AI agents change that calculus. They can work around the clock, in multiple languages, and across numerous platforms without fatigue. They can create profile pictures, write plausible posts, respond to comments, and adjust their behavior based on engagement metrics. The result is a new kind of digital actor: one that looks like a normal internet user but is actually part of a coordinated, automated campaign designed to manipulate public opinion. The New York Times report is one of the most detailed looks yet at how this new generation of influence operations is being deployed, and it raises urgent questions about whether American voters can trust what they see online in the run-up to the 2026 midterm elections and beyond. It also highlights the difficulty of measuring the real-world impact of such campaigns, as researchers warn that the number of accounts, posts, and followers involved does not necessarily translate into actual persuasion or changes in political behavior.
How does an AI influence campaign actually work? AI agents are software systems that can complete a series of tasks with less direct human involvement than traditional automation. According to The New York Times, hundreds of AI agents were used in some of the newly identified campaigns. They created networks of fictitious accounts, generated political and current-events content, and coordinated messages online. In the Iranian operation, the AI-generated accounts presented themselves as ordinary Americans living in major U.S. cities. The accounts posted memes and political commentary, tagged journalists and politicians, and promoted messages critical of the Republican Party. The accounts accumulated nearly 80,000 followers during the first half of 2026. That number, however, should not be interpreted as 80,000 Americans being persuaded by the operation. The reporting establishes the number of followers, but it does not establish how many people believed the content or changed their political views as a result. The distinction between “reach” and “influence” is a recurring challenge in the study of influence operations. A follower count can be inflated by bot accounts, and platforms’ recommendation systems may show content to users who do not engage with it meaningfully. Even when an AI-generated post receives thousands of likes or shares, those metrics can be manipulated by coordinated networks. What matters is whether the content changes the way real people think, vote, or talk about public issues. Researchers have long cautioned that social media metrics are not a reliable proxy for persuasion. The same caution applies to the AI campaigns described in the Times report. What the report shows is that foreign actors are capable of building believable networks of fake users at scale; what it does not show is whether those networks succeeded in altering American public opinion. The Iranian operation is just one example. The Times report also cited operations linked to China and private Israeli companies, each with different objectives and target audiences. Chinese accounts have historically focused on issues such as Taiwan, Hong Kong, and U.S. policy toward China, while private Israeli companies have been known to offer services to governments seeking to influence foreign audiences. The common thread is the use of AI agents to automate the mechanics of influence: creating identities, building social authority, and injecting propaganda into existing conversations.
Why does this matter? One concern is that foreign actors can exploit political divisions that already exist in the United States. Instead of simply producing a piece of propaganda, an automated system can potentially create an entire network of accounts designed to make a particular viewpoint appear more widespread than it actually is. This is sometimes called “astroturfing” because it manufactures a fake grassroots movement. In traditional politics, a candidate or advocacy group might organize a rally to show public support; in the online age, an AI agent can create a hashtag, a swarm of supportive accounts, and a stream of coordinated replies that make a marginal opinion seem like a popular uprising. The danger is not just that people might be persuaded by a false argument; it is that the general public may become so skeptical of online discourse that genuine grassroots movements are dismissed as foreign manipulation. The FBI and CISA have previously warned that foreign actors could use generative AI and fake personas to conceal their involvement and attempt to sow discord among Americans. Those warnings have been repeated frequently since the 2016 election, when Russian operatives used both fake accounts and amplified content to exploit racial, political, and social tensions. The new AI-enabled campaigns go a step further: they can operate continuously, adapt to countermeasures, and target micro-audiences with personalized messages. The technology is not limited to one political side. Foreign influence operations can promote different messages depending on the audience and the strategic objective. Researchers have identified efforts aimed at increasing distrust and polarization rather than simply supporting one political party. For example, an operation might create pro-Democratic accounts that attack Republicans and pro-Republican accounts that attack Democrats, all operated by the same AI system. The goal is not to elect a candidate but to make American society more divided, more cynical, and easier to manipulate in the future. That is a particularly difficult threat to counter because it does not fit the simple narrative of a foreign enemy trying to elect one party or another. In this sense, the most important effect of AI influence operations may be to weaken the shared factual basis of democracy itself.
How far can the content spread? In a separate analysis, the Institute for Strategic Dialogue documented more than one billion views generated by two coordinated pro-Iran networks on X during the first month of the Iran war. The networks circulated false, misleading, and AI-generated material. ISD’s analysis found that recommendation algorithms, reposting by larger accounts, and coordinated amplification helped some of the content reach large audiences. A billion views is difficult to comprehend; it is roughly the number of times every person in the United States would have to see a post for the metric to add up, or the equivalent of many repeated viewings by a smaller population. But the ISD analysis, like the Times report, is careful to distinguish between views and persuasion. A post receiving millions of views tells us how widely it was seen or counted by the platform’s metrics; it does not establish how many people believed it or changed their opinions. In fact, the relationship between social media exposure and attitude change is deeply contested. Some studies have found that repeated exposure to false information can increase belief, while others have found that users are more likely to scroll past content that conflicts with their existing views. The algorithms that amplify viral content are optimized for engagement, not for accuracy. Thus, AI-generated propaganda that provokes outrage or curiosity can achieve high view counts without necessarily convincing anyone. Moreover, the same content may be seen by fact-checkers, journalists, and researchers who share it as an example of manipulation, inadvertently increasing its reach. Platform metrics are designed to measure activity, not impact. The one-billion-views figure is a measure of the scale of the operation, not its success. It is a sign that the Iranian network was able to bypass or exploit X’s recommendation algorithms and gain the attention of a large audience. Whether that attention translated into support for Iran, opposition to the war, or any other attitude change remains an open question. What is clear is that the scale of AI-enabled influence operations has grown rapidly and is likely to grow further.
What is actually new? The use of AI in foreign influence operations isn’t itself new. AI has been used for years to generate articles, images, videos, and social media posts. Automated accounts, sometimes called bots, have been active on social media for more than a decade. The newer development is agentic AI — systems capable of carrying out multiple tasks with less human intervention. An ordinary AI text generator requires a human to supply a prompt and review the output. An agentic system can do much more: it can decide what to write, create an account with a realistic profile, post the content, tag relevant users, respond to comments, and adjust its strategy based on what performs well. It can also coordinate with other AI agents to amplify messages, create the illusion of trending topics, and drown out opposing viewpoints. Anthropic’s September 2026 threat-intelligence report similarly documents the expanding use of AI in malicious influence operations and other forms of abuse. The report warns that AI capabilities are advancing faster than defensive countermeasures and that the same technology can be used for both legitimate and malicious purposes. For social media users, the practical consequence is that a post that looks like it came from an ordinary person may not necessarily represent an authentic grassroots political conversation. A profile with a friendly photo, a location in an American city, and a history of posts about sports or weather can be entirely fabricated. Even worse, AI agents can learn to mimic the speech patterns and interests of specific communities, making them harder to detect. The danger is not limited to text. AI-generated images and videos can be used to create realistic-looking evidence of events that never occurred. The combination of generative AI and agentic automation creates a powerful toolkit for those who seek to manipulate public opinion. Researchers are now in an arms race with the developers of these systems, trying to build detection tools that can identify AI-generated content and automated networks before they cause major harm. But the same technology that enables AI agents to be detected can also be used to make them more sophisticated, and the cycle shows no signs of slowing down.
The documented campaigns show that foreign actors are experimenting with ways to automate the process of influence. But determining whether those campaigns actually change Americans’ political beliefs requires evidence beyond follower counts, views, or the existence of fake accounts. It requires surveys, longitudinal studies, and careful analysis of behavior change. The absence of such evidence does not mean the campaigns are harmless; it means the threat is more complex than a simple metric. Influencing a society is not like influencing a search algorithm. It requires sustained repetition, emotional appeal, and trust, all of which are difficult to achieve with fake accounts. Yet AI can make repetition easier, emotional appeal more targeted, and trust more easily faked. Policymakers and platforms are under pressure to respond. Some companies have invested in automated detection tools and have taken down networks of inauthentic accounts. Governments have issued sanctions and indictments against foreign operatives. But the underlying technology continues to evolve, and the gap between detection and creation is unlikely to close. For American voters, the lesson is to treat online certainty with skepticism, especially when a post seems designed to provoke an emotional reaction. It is important to verify claims through reputable sources and to be aware that social media is a battlefield. The AI influence campaigns of 2026 are experiments, but they are experiments with the foundations of public opinion. Whether they succeed is not determined by how many accounts they create or how many views they generate, but by whether they can change the way real people think and act. So far, the evidence of that success is considerably weaker than the evidence of their existence. But the trajectory is clear: AI will continue to make influence operations cheaper, faster, and more autonomous. The burden of proof will increasingly be on platforms, researchers, and the public to distinguish authentic speech from engineered noise. The report from The New York Times, along with the work of ISD and Anthropic, is an important step in that direction. It offers a detailed picture of what is happening now, and it challenges everyone—government, tech companies, and ordinary users—to grapple with a future in which the line between real and artificial social influence becomes ever harder to draw.



