OpenAI has identified and disrupted a covert influence operation that used generative AI to construct the appearance of an independent research institution and media network, according to an analysis of the takedown made public this week. The operation, which focused its attention on Germany, the United States, France, Poland and Türkiye, deployed AI for a surprisingly routine set of tasks: generating promotional social media posts, responding to real users on platforms like Substack, designing logos for a constellation of Telegram channels and creating profile pictures. Some of those Telegram channels amplified narratives traced to an entity referred to as IBI. Although the operation’s immediate reach was modest, its infrastructure was substantial. The case highlights a worrying trend in which AI acts as a force multiplier for influence campaigns, allowing a small number of operators to build a credible-looking institutional brand from scratch and seed stories into public discussion without leaving obvious fingerprints. Rather than deploying deepfakes or attempting to manipulate audio and video, this campaign used AI as a form of administrative labor, producing the kind of material that would normally require a team of writers, designers and social media managers. A handful of operators could therefore run multiple accounts in different national contexts while maintaining a consistent public persona. The analysis suggested that the true objective was not immediate virality but long-term positioning: the creation of an entity that could later be activated for influence, or whose past publications could be cited as independent authority. The operation’s reliance on AI was visible in both its output and its mistakes. One of the Telegram channels featured a bio with bizarrely stilted English—”a totally unhackneyed perspective on hazzy”—a phrase that reads as machine-generated rather than native. Such tells are increasingly valuable to researchers attempting to uncover AI-enabled influence networks before they take hold.

At the operational level, AI was used primarily to generate promotional social media content and replies to real users on platforms like Substack. This was not a matter of posting the same prewritten message across dozens of accounts; rather, the operators appear to have used custom prompts to produce fresh text that could keep the network active. Automated responses to real users are particularly concerning because they allow malicious actors to engage with unsuspecting audiences who think they are interacting with a legitimate organization. By automating those interactions, the operators could create a feedback loop: users see an interesting post, leave a comment or subscribe, and receive an intelligent reply, building within those users a false sense of trust. Over time, the target may begin to share or recommend the account, amplifying the narrative to their own followers. This technique bypasses the traditional model of influence operations that relies on armies of human trolls or sock puppets, replacing them with algorithms that never need to sleep and can quickly adapt their language to context. Beyond text, the campaign also invested in visual branding. The operators created logos for various Telegram channels focused on Germany, the USA, France, Poland and Türkiye. These logos were not necessarily elaborate, but they served to make the channels look like established media outlets or civic groups rather than low-effort propaganda vehicles. In one instance, an operator generated a profile picture for one of the channels, completing a coherent visual identity. The same operator also appears to have written or selected a bio for the channel, producing the tellingly awkward English phrase quoted in the analysis. This mix of AI-generated text and imagery illustrates how generative tools have lowered the cost of creating a complete, maintained presence across multiple platforms.

One of the more interesting details in the analysis concerned the choice of platforms. StartupHub.ai data indicated that Substack currently has a low score of 10 out of 100 for engagement and reach, while Telegram scores a significantly higher 57 out of 100 in terms of user engagement and reach within the current digital media landscape. On its face, that would seem to make Substack a poor target for an operation trying to bring its content to a large audience. But influence campaigns do not necessarily seek the largest possible audience in the first phase. By establishing a toehold on Substack, which is often used by journalists and academics, the operation could borrow some of the platform’s credibility. Articles could appear in newsletter form, with bylines and publication dates, making them easier to quote and archive. Telegram, by contrast, provides a more direct and less moderated channel to distribute the same content to communities that are already organized around political topics. The combination reflects a strategic division of labor: Substack for archival legitimacy, Telegram for distribution and amplification. These metrics also help explain why the operation’s social media posts received low views in its early days. On Substack, where the platform’s low engagement score signals a narrow audience and little organic discovery, a newly created publication with no subscriber base will naturally struggle to attract traffic. Telegram’s higher score, on the other hand, indicates that channels there can participate in a more active and widespread ecosystem of sharing, groups and reposts. The operators seemed to realize this: they built out multiple Telegram channels, aligned to national audiences, rather than relying solely on a Substack homepage. The low engagement numbers cited in the analysis should therefore be read with caution. They reflect a starting phase, not a finished operation. The infrastructure was designed to be scaled, and the AI tools allowed that scaling to happen without large staff or budgets.

The most sobering aspect of the operation is not what it achieved but what it attempted to become. Even with low immediate view counts, the campaign succeeded in manufacturing the appearance of an entity with experts, research outputs and a brand. That is a qualitative step beyond the often sloppy influence content that has plagued social media for years. Instead of false claims in broken English or disjointed memes, the target audience encountered what looked like an independent institute with a professional logo, a consistent voice and an active digital presence. The purported experts may have been invented or repurposed personas, but their names could still be searched online, and their articles could be shared as evidence. This ability to create a paper trail is one of the most dangerous elements of AI-enabled influence. A journalist writing about a topic might see a study or report from IBI and cite it as legitimate, thereby laundering the narrative into mainstream coverage. Even if the eventual correction comes, the original claim has already entered the information ecosystem. The OpenAI assessment described the campaign’s strength as lying precisely in this creation of a credible-looking institution, one that could obscure the true origins of favored narratives. The operation did not need to convince everyone; it needed to produce enough material that at least a few gatekeepers—writers, editors, social media moderators, civic leaders—would mistake it for a genuine source. Once those gatekeepers were fooled, the institution’s authority would do the rest. This is why the takedown matters beyond the specific accounts. It demonstrates that the asset-building phase of an influence operation is becoming cheaper and faster. What used to require months of website development, social media growth and fake author recruitment can now be accomplished in days with the help of generative AI. The low barrier to entry means that more actors, including states and fringe groups, can attempt such operations, and the failure of any one attempt tells us little about the danger of the next.

OpenAI assessed the operation at the lower end of Category Three on the Brookings Breakout Scale, a framework developed to measure the ability of influence campaigns to move beyond their own controlled networks and reach authentic audiences. The exact meaning of that rating can be unpacked as follows. Category One or Two operations remain mostly confined to the operators’ own accounts, with little or no traction among genuine users. A Category Three rating indicates that the operation used multiple platforms and at least occasionally succeeded in engaging with real audiences, but it did not sustain the kind of mass breakout that would put the content before millions. In this case, the operation had achieved some responses from real users on Substack and may have found readers through Telegram, but its posts generally generated low views. The lower end of Category Three suggests that the operators were making contact with authentic users in a limited way—enough to test messaging and gather reactions, but not enough to trigger a broad response. Importantly, the rating is not simply a measure of success. It is a snapshot of where the operation stood at the moment of disruption. Many influence campaigns are designed to grow gradually, and this network appears to have been following that pattern. The existence of multiple Telegram channels, each with its own logo and national focus, indicates preparations for a more extensive rollout. The use of AI to respond to real users suggests a desire to build relationships with the people who did stumble across the content. All of that infrastructure could have been activated at any time, reaching audiences in several countries or shifting its focus to a breaking news event. The takedown removed that capacity, but it also revealed how unremarkable the earliest stages of a modern influence campaign may look. It can be a few low-view posts and odd phrases, indistinguishable from the noise of the internet—until it suddenly is not.

The broader lesson of the operation is that AI does not need to produce viral deepfakes to be dangerous. Its most consequential role in influence operations may be as a supporting tool, one that helps obscure the true origins of narratives and manufacture authority at a speed and scale previously unavailable. By automating routine writing, design and interaction, AI lowers the cost of operating a fake institution, and it allows small teams to maintain a persistent presence across borders. The incident also illustrates the difficulty of measuring an influence operation’s impact in its early days. Low engagement metrics can deceive, because the real value of the assets is latent. Even if the operation never gained a large following, its output remains archived, searchable and potentially citable. A future actor could repurpose the same logos, accounts or narratives, or a journalist could find an old report and treat it as genuine. The internet does not forget easily. Platforms and researchers are beginning to respond by looking for AI tells, such as the non-idiomatic English in the channel bio, and by tracking the infrastructure connecting accounts across platforms. OpenAI’s public disclosure of its takedown is part of that effort, offering a case study for other companies and law enforcement agencies. But the report also cautions that the current detection methods are likely to be a perpetual race. As AI models improve, the awkward phrases and visual errors that expose machine-generated content may become rarer. The next operation might not leave such obvious clues. In the meantime, the best defense may be a skeptical audience. Readers, journalists and platform moderators need to be aware that an institution can look credible online without being real, and that AI makes it easier than ever to create an entire research organization overnight. The takedown of this operation is a small victory, but it is also a reminder of the long-term challenge that lies ahead.

Share.
Leave A Reply

Exit mobile version