P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

Two of OpenAI's 30 exposed influence operations rate Category 5 and 4; its text names no outlet that ran them

OpenAI's matrix of 30 exposed influence operations puts 4 at Category 4 or 5, and its 8 October report rates a Russia-origin and an Iran-origin case 5 and 4. It gives no account counts, attribution confidence or outlet names, so UK publishers must check contributors themselves.

By Parminder Kumar Sharma · · 27 min read

An empty newsroom desk at dusk with an open laptop showing an article page made of blank shapes, a blank press-pass lanyard, a printed page proof with one highlighted byline slot and a row of wooden blocks stepping upward, two of them amber. No people. Overlaid text reads: Two of 30 rated Category 5 and 4, no outlet named in the text, 5 of 6.

Four of thirty, and what that does not show

OpenAI's report of 8 October 2026, Disrupting AI-enabled "false front" operations, says it banned two influence operations that used ChatGPT: one that it says originated in Russia and one that it says originated in Iran. It rates the first Category 5 and the second Category 4 for its articles, on a scale of 1 to 6. The page also prints a matrix of the 30 influence operations OpenAI says it has exposed since early 2024, and the matrix is the checkable fact. Read off its cells, 5 operations sit at Category 1, 17 at Category 2, 4 at Category 3, 3 at Category 4, 1 at Category 5 and none at Category 6. That is 22 of 30 (73%) at the bottom two categories and 4 of 30 (13%) at Category 4 or 5, and all four of those used external publications, not social media or a website the operation ran, as their main route. The counts are OpenAI's; the percentages are ours (derived: 22 ÷ 30 and 4 ÷ 30).

What that does not establish is how many people saw any of it. The scale is the Breakout Scale, published by the Brookings Institution in September 2020 (Brookings). It measures whether content stays on one platform and in one community or travels to others, to mainstream media and to high-profile people. It is not an audience count. OpenAI describes the ratings as assessments of "potential reach", the matrix covers only operations that ran through its own product, and the text of the page names none of the outlets that carried the content. "AI-enabled" in the title does not mean AI made the operations effective: of the Russia-origin operation, OpenAI says that in most cases it did not see operators use its models to create campaign content, only to report on it.

This briefing reports what OpenAI's page, one Brookings page, two Anthropic documents and a set of UK pages say. It makes no claim about who ran either operation, and country attributions are OpenAI's assessments, attributed as such throughout. It does not repeat the persona names, front names, outlet names, account handles or content that OpenAI's page prints: naming them adds nothing a defender needs, and OpenAI's page is the place to read them. OpenAI sells ChatGPT, wrote the page, sees only its own platform and chose what to publish, so its interest in being seen to police misuse is plain. The same is true of Anthropic, which is treated identically in the comparison below.

What OpenAI says it found, and what it does not say

OpenAI's page is about 5,200 words (our count, captions included) and covers two cases. "False front" is described rather than defined. OpenAI says the operations used "false front" entities to "launder geopolitical, conflict-related messaging into their target audiences", and gives two examples. One is a stable of seven "journalist" personas that pitched long-form articles to small and medium online outlets around the world. The other is a "think tank" run on the ground in Latin America by people OpenAI says appear to have been co-opted without knowing who they worked for. The table sets what the page states beside what it leaves out.

What OpenAI's page of 8 October 2026 states and does not state, by question. Source: the page, read in full on 9 October 2026.

QuestionStated on the pageNot stated
How many operationsTwo banned, one Russia-origin and one Iran-origin. A matrix of 30 exposed since early 2024.How many accounts. Each case is "a cluster of ChatGPT accounts" with no count. The date of either ban: "recently".
Basis for attributionPrompts in Russian or Persian, VPN use, the operators' own reports and, for the Iran-origin case, account settings that show Iran. For the Iran-origin case: "consistent with a commercial actor running a for-hire influence campaign".Any confidence level: the word does not appear. A named state body for either case. An error rate.
Products and tasksChatGPT and "our models". Russia-origin: mostly internal reports, some drafting, translation and proofreading. Iran-origin: refining articles and pitch emails, batches of comments, internal reports.Which models or versions. Whether images, code or agents were used. What share of the published content a model wrote: OpenAI says not all of it did.
What OpenAI didBanned the accounts. Shared information with "the relevant authorities" on both cases and with "industry partners" on the Iran-origin case.Which authorities or partners. Whether any outlet, fact-checker or person named in a fake was told. How the clusters were detected: the word "detect" does not appear.
ReachRussia-origin: Category 5, its first. Iran-origin: Category 4 for the articles and Category 2 for the social media replies. One outlet that ran articles had almost 2 million Facebook followers as of August 2026.Readers or viewers of any article or fake. Whether the ratings were checked by anyone outside OpenAI.
Outlets, fronts and peopleThe text prints the personas and the front's name, and links open-source coverage of the Russia-origin fakes. It says the Iran-origin articles ran in "roughly a dozen" outlets, and its screenshots redact account and page names.The names of the outlets that ran the Iran-origin articles. Whether those outlets knew, paid, were told or have removed them.
Whether AI made the differenceThe operations "closely resembled complex influence operations of the pre-AI age", with AI making "some of the workflows easier".A comparison with the same operations run without AI. How much of the Category 4 and 5 reach came from AI-written text.

Attribution is narrower than the headline. OpenAI attributes the first operation's accounts to Russia and the second's to Iran, and neither to a named government body. For the second it says the activity looked like a for-hire commercial campaign and that it could not identify the actor. For the first, it says some of the fakes the operators claimed have been attributed by open-source researchers to a Russian entity described as a reported successor of a mercenary group, and that the operators asked its models about that entity far more than about any other Russian network. That is a link of interest, not an identification. The page also says the operators used VPNs, and that OpenAI does not allow access to its models from Russia.

One operation has two ratings. The Iran-origin operation's social media replies are Category 2: OpenAI says they typically made up a minority of the comments on a post and drew likes, views and comments in the single or double digits. Its articles are Category 4. The matrix gives each operation one cell, set by the route that appeared to be its core, so a reader who sees only "Category 4" misses that the operation's other main workstream rated 2.

The page uses "mainstream" and "small to medium" for the same outlets. Its summary says both operations landed content in "mainstream media outlets". Its detail says the Iran-origin outlets were small to medium and focused on international affairs, geopolitics and the Middle East, with one of them at almost 2 million followers on Facebook, almost 355,000 on X and over 544,000 on Instagram as of August 2026. The Brookings scale puts Category 4 where content breaks out of social media and is amplified by mainstream media. Whether about a dozen small and medium outlets meet that is OpenAI's call, and the page does not argue it.

How far it reached, by OpenAI's own scale

OpenAI links the Brookings paper for its scale. Brookings describes the six categories this way: Category 1 spreads within one community on one platform; Category 2 across platforms in one community, or across communities on one platform; Category 3 across multiple social platforms and communities; Category 4 breaks out of social media completely and is amplified by mainstream media; Category 5 is amplified by high-profile people such as celebrities and political candidates; and Category 6 triggers a policy response or other concrete action, or includes a call for violence. The diagram draws OpenAI's matrix to scale. The page does not label which cells are the two operations in this report, so the notes show the ratings its text gives them.

Horizontal bars show OpenAI's 30 exposed influence operations by Breakout Scale category: Category 1 has 5, Category 2 has 17, Category 3 has 4, Category 4 has 3, Category 5 has 1 and Category 6 has none. Social media and websites account for categories 1 to 3; external publications account for all of categories 4 and 5. Notes mark OpenAI's stated ratings for its two new cases, Category 4 for the Iran-origin articles and Category 5 for the Russia-origin operation.
Drawn from the matrix image on OpenAI's page of 8 October 2026, counts read cell by cell (they sum to 30). The 22 of 30 and 4 of 30 are derived.

Two points follow. Route predicts rating. No operation whose main route was social media or its own website sits above Category 3, and every operation whose main route was external publications sits at Category 4 or 5. OpenAI says the same in words: operations that land content in real media outlets "tend to have the highest potential reach and impact". The matrix describes one vendor's caseload. Four in 30 at Category 4 or 5 is a rate among the operations one company found, on one product, and chose to publish. It is not a rate of influence activity on the internet, and the 30 have no denominator of operations that went undetected.

The ratings come with OpenAI's own caveats, and they differ by case.

Russia-origin, Category 5. OpenAI says the operators' internal reports took credit for activity "which had nothing to do with their operation", so their claims of impact "cannot be taken at face value". The rating instead rests on open-source evidence OpenAI says it found: fakes that fact-checkers reported and governments denied, and one planted story that was reported in Latin America and Europe and "appears to have led to comment from at least one Polish MEP". For the rating it cites evidence of public comment by politicians in a number of countries. OpenAI records official denials in this case yet rates it 5, not 6; Brookings puts a policy response or other concrete action at Category 6. The page does not say why a denial falls short of that, which may be a sound judgement but is not explained.

Iran-origin, Category 4 for the articles. The page's own timeline of the articles sums to 96: the seven bylines are credited with 29, 16, 14, 12, 12, 11 and 2, which matches the chart's footer of 96 rows (derived: the legend sums to 96). Of the 96, 51 (53%) are tagged to US and Iran (derived). The text says "almost 100" articles across "roughly a dozen" outlets in one place and "over a dozen" in another, with the earliest in July 2025 and the latest in October 2026, a span of 15 months by month name (derived). The chart's footer dates its data 2026-09-08 and its caption ends in September 2026, so the page does not make clear whether articles were added after that date. Separately, OpenAI says the operators' main impact figure counted views of the posts they replied to, not views of the replies, which "greatly exaggerated" the result. OpenAI does not use that figure, and it is a reminder that an operation's own reach claim is not evidence.

What "AI-enabled" does and does not mean here

OpenAI's own summary is that the operations "closely resembled complex influence operations of the pre-AI age", with AI making "some of the workflows easier". It compares the Iran-origin personas with an earlier fake-journalist front attributed to Russian military intelligence whose articles Western outlets published in 2016 and 2017, and the Russia-origin front with a fake news outlet exposed in 2020 that used unwitting writers. In both comparisons the playbook is old, and the page says the aim of reporting false-front operations is to make them easier to disrupt, because earlier ones ceased activity after exposure.

In practice the Russia-origin operators used ChatGPT mainly to write reports about their own activity and about activity they could plausibly claim. The Iran-origin operators used it to refine articles against an outlet's stated submission criteria, to draft the pitch emails and to produce batches of comments. Our inference is that the page gives no way to say how much of the reach came from AI-written text: OpenAI says some of the content was not generated by its models, and the placement of articles in outlets and the spread of fakes in Latin America happened off its platform.

A vendor sees one platform. Operators who used other models, or none, are invisible to it, so a vendor report is a view of misuse of that vendor's product and not a census. Anthropic says so of itself: "Our visibility into these operations ends once it's live." (Anthropic, September 2026). The same limit is why OpenAI says it shared the Iran-origin case with "industry partners, who are best placed to provide holistic assessments on engagement".

The headline against the page

CyberScoop's report of 8 October is headed "OpenAI says Iran, Russia used AI journalists, think tanks to influence Western media". Its body matches OpenAI's page on attribution, saying the report does not attribute the Russia-origin activity to a specific government or intelligence agency and did not attribute the Iran-origin activity to a specific actor. Where the headline, standfirst and some body lines differ from the page, the article follows the page.

CyberScoop's wording set beside OpenAI's page. Sources: CyberScoop, 8 October 2026; OpenAI, 8 October 2026.

CyberScoop wroteOpenAI's page saysSo
"AI journalists"; a "fake AI persona"Seven fake bylines and a fake persona. Operators used ChatGPT to refine articles, write pitch emails and, for one byline, the biography. Whether any persona photo was generated is not stated.The personas are fake people with AI help, not AI authors.
"Western media"Iran-origin outlets are "around the world", small to medium, focused on international affairs and the Middle East. The Russia-origin target is Latin America, with matching stories in Peruvian, Polish, Hungarian and Ecuadorian press.The page does not describe Western media as the target.
"dozens of stories""Almost 100 articles"; its chart sums to 96.Follow the page.
The first time OpenAI has reported a high-impact campaignThe first Category 5. Its matrix has 3 at Category 4.Narrower than the standfirst: if the Iran-origin case is one of the 3, at least two Category 4 operations came earlier (our inference).
Rated "4 and 5 out of 6 for severity"A rating of potential reach and impact on the Breakout Scale."Severity" is CyberScoop's word.

Two vendors, one class of misuse

On the same day, Anthropic published its 2026 Usage Policy update, which says it has seen "state media outlets, government propaganda offices, and commercial firms using Claude to run networks of fake accounts and fabricated news sites". The post points to Anthropic's September 2026 threat intelligence report, which covers activity disrupted between December 2025 and August 2026 and details nine influence-operation cases. The table sets what each document says on the same questions and says nothing beyond what each states. Both vendors are treated alike: each describes misuse of its own product, sees only its own platform, chose which cases to publish, and has a commercial interest in being seen to police misuse. OpenAI competes with Anthropic.

Two vendors on influence-operation misuse: what each document states. Sources: OpenAI, 8 October 2026; Anthropic, September 2026 report and 8 October 2026 policy post. The counts of rated Anthropic cases are derived.

OnOpenAI, page of 8 OctoberAnthropic, September report and 8 October post
ScopeTwo operations banned; 30 exposed since early 2024.Nine cases detailed; the number disrupted overall is not given. Policy post: seen "in the past year".
Product named"ChatGPT" and "our models"; no model or version.Claude Haiku, Sonnet and Opus across the report; no Fable or Mythos-class use apart from one distillation case.
Accounts banned"A cluster" per case; no count.A count in some cases (4, 3 and 29 accounts in three cases); "an account" in others.
Who is namedPersonas and the front printed; no outlet or sponsor named for the Iran-origin case; screenshots redacted.Organisations it attributes cases to, including state bodies, with indicator tables and an indicators download.
Attribution wording"Originated in"; "appears to"; no confidence term."High confidence" in two influence cases; "no evidence of direction by any government" in others.
Reach ratingBreakout Scale: 5 and 4, with replies at 2; matrix of 30.Breakout Scale: 8 of 9 cases rated, one at 1, three at 2, three at 3, one at 4, none at 5 or 6; the ninth not rated.
Where reach came fromOperations that land content in real media outlets "tend to have the highest potential reach and impact".The widest authentic reach was where state media outlets were the distribution mechanism; most content drew little or no authentic engagement.
Visibility and sharingInformation to "relevant authorities" and "industry partners"; reach rests on open-source evidence."Our visibility into these operations ends once it's live"; indicators shared with industry and research partners; one case began with a tip from OpenAI.

Where they agree. Both use the same scale. Both say reach follows distribution through established outlets, and both say they can see an operation being built on their own platform and little of what happens afterwards. Both report sharing information with others, and Anthropic credits a tip from OpenAI in one case, so on Anthropic's account at least one lead has passed between the vendors.

Where they differ. Anthropic names more organisations, gives account counts in some cases and publishes indicator tables. OpenAI names no sponsor for these two cases and spends more of its page on how the operators measured their own success; Anthropic notes self-reported operator figures in one case. OpenAI's page is a deep reading of two cases; Anthropic's section is nine shorter ones. Anthropic's 8 October post is a policy statement, not a case report: it describes the pattern in a sentence and adds no number.

What the pair does not establish. Neither document gives a baseline, a rate of undetected activity or an error rate, and each vendor applies the Breakout Scale to its own cases without audit by the other. Together they show that two vendors describe the same class of misuse. They do not show how much of it exists, or what a vendor that publishes nothing has not seen.

What UK material exists, and what it covers

The OpenAI page mentions the UK twice. It says the Iran-origin operators generated more than two dozen batches of hostile Persian-language replies to posts by a UK-based satellite broadcaster, and it records a claim about the Falkland and Malvinas islands that the Russia-origin operators took credit for. It names no UK election, outlet or policy, and the word "election" does not appear on it. UK material that bears on the story was not written for it. The table lists what we read, what it says, and what it does not cover. We did not read press regulators' codes or broadcasters' rules, which are the first places a publisher's own duty to check would sit.

UK pages read on 9 October 2026, what each says and what it leaves out for a publisher or communications team facing a false-front operation.

UK sourceWhat it saysGap for this case
[NCSC, impact of AI on cyber threat to 2027](https://www.ncsc.gov.uk/report/impact-ai-cyber-threat-now-2027) (7 May 2025)Assesses AI in cyber intrusion operations to 2027.Says it does not cover wider AI-enabled threat "such as influence operations".
[NCSC, Defending democracy](https://www.ncsc.gov.uk/collection/defending-democracy) (published 7 December 2023, reviewed 29 May 2024)Guidance for political parties, think tanks, local authorities and high-risk individuals on accounts, devices, websites and election systems.Cyber defence of people and systems, not vetting of contacts, pitches or outlets.
[NCSC chief executive's blog](https://www.ncsc.gov.uk/blog-post/looking-back-at-the-ballot-securing-the-general-election) (7 August 2024)Warns against blaming deepfakes or hack and leak before the authorities with the details have assessed; premature claims invite accusations of irresponsibility.A discipline for language, not a method.
[National Security Act 2023, section 13](https://www.legislation.gov.uk/ukpga/2023/32/section/13)Foreign interference offence: prohibited conduct, a foreign power condition (or, since 8 July 2026, a designated body condition) and intent or recklessness as to an interference effect. Up to 14 years.Whether the conduct OpenAI describes meets those conditions is a legal question. OpenAI links no government to the Iran-origin case.
Ofcom, [foreign influence page](https://www.ofcom.org.uk/online-safety/illegal-and-harmful-content/assessing-the-risk-of-foreign-influence-in-uk-search-results) (19 September 2023) and [open letter to providers](https://www.ofcom.org.uk/siteassets/resources/documents/about-ofcom/public-correspondence/2026/open-letter-on-elections.pdf?v=415530) (1 April 2026)The 2023 page, written at Bill stage, says the offence is a priority offence requiring services to assess and mitigate the risk. The 2026 letter says providers should take down illegal content targeting UK elections when they become aware of it, for example content amounting to a foreign interference offence; the duties apply to AI-generated content; the Act does not itself treat misinformation as a harm.Duties fall on platforms, not on a publisher's choice of contributor. Ofcom's help page says it cannot respond to or investigate individual complaints.
Electoral Commission ([17 June 2024](https://www.electoralcommission.org.uk/media-centre/new-advice-voters-disinformation-and-campaigners-using-generative-ai); [page updated 24 July 2024](https://www.electoralcommission.org.uk/voting-and-elections/campaigning-your-vote/engaging-campaign-material-elections))No legal power to regulate the content of campaign material, and it says no UK organisation has one. Asks campaigners using generative AI to make that clear. Election material needs an imprint.About campaign material at elections, not a newsroom or communications desk.
[Defending Democracy Taskforce](https://www.gov.uk/government/news/ministerial-taskforce-meets-to-tackle-state-threats-to-uk-democracy) (28 November 2022)Launch notice: protect democratic integrity from foreign interference; threats include disinformation.We found no Taskforce publication on information operations for publishers or communications teams. The page found is the launch notice.
[Government Communication Service, RESIST 3](https://www.communications.gov.uk/publication/resist-3-building-resilience-to-information-threats/) (29 October 2025)Coordinated inauthentic networks are not illegal in themselves; use of AI is not in itself a sign of an information threat; judge accounts by behaviour; escalate to units with the expertise.Written for government communicators. The Recognise section covers messages and accounts, not vetting an outside contributor.
NPSA, [Think Before You Link](https://www.npsa.gov.uk/security-campaigns/think-you-link-tbyl-0) (updated 10 April 2026) and [launch notice](https://www.gov.uk/government/news/new-app-to-counter-malicious-approaches-online) (17 May 2022)Campaign to help people spot malicious profiles. In 2022 MI5 said it had seen over 10,000 disguised approaches on professional networking sites. Staff report concerns through organisational processes.Aimed at people with access to sensitive information, not at a publisher weighing a pitch.
[Foreign Office, UK action against Russian foreign information warfare](https://www.gov.uk/government/publications/uk-action-against-russian-foreign-information-warfare/new-uk-action-against-foreign-information-warfare) (updated 13 July 2026)Says 106 entities and individuals have been sanctioned since October 2024 for Russia's information warfare, and cites platforms including OpenAI among those that exposed malign activity attributed to one designated entity.Sanctions name actors. They do not tell a publisher how to check a contributor.
[The Register](https://www.theregister.com/security/2026/10/08/uk-and-germany-team-up-against-russian-cyberattacks-as-brexit-rethink-looms/5301914) (8 October 2026), a news reportReports that the Prime Minister has asked security chiefs to establish a National Centre for Information Defence, and fast-tracked legislation on designating state-backed organisations. Says the UK-Germany announcement names no agencies and specifies no funding.A report of a proposal. On what we read, no centre exists and no source says what it would publish or whom it would serve.

The pattern is plain. There is a good deal of UK material on defending the cyber security of political and electoral actors, and on what platforms must do about illegal content. There is little on how a publisher or communications team should check a contributor, an expert or a think tank before relying on them. The duties we read sit on platforms and, through section 13, on people who engage in prohibited conduct for a foreign power; nothing we read puts a duty on a newsroom to vet a byline. The proposed National Centre for Information Defence is a proposal, and we have not seen a primary government source for it.

What a communications or security team can check

The label is not a control. "Think tank", "research platform" and "journalist" are descriptions an operation chose for itself. OpenAI says the Russia-origin front's website carried well over 60 articles, the great majority original, and that the evidence indicates its staff in Latin America did not know who ran it. The evidence that it was a front came from the operators' internal reports, which OpenAI could read because they were written in its product. Our inference: a visitor to the public site would have seen original, researched-looking output, which is also what a real institute produces. The Iran-origin bylines had biographies and social accounts. Neither public face was a check.

Before quoting or engaging a journalist or think-tank contact. The page lists signs OpenAI cites in these cases, and none needs special tools. OpenAI says one byline's biography claimed to be American while platform settings placed its accounts in Iran, that some comment accounts with Western-seeming names showed Iran as their location, that three bylines listed social handles that were later suspended, and that comment batches were posted within minutes of each other, in spans of 10 and 13 minutes. It says a front's professional-network page counted 961 followers, claimed 200 to 500 staff and listed two employees. Two points cut across any list. A real, contactable person is not proof. OpenAI says the Russia-origin front's staff in Latin America appear to have worked in good faith for an operation they did not know was Russian-run. Meeting your guidelines is not proof. OpenAI says the Iran-origin operators checked drafts against an outlet's submission criteria before pitching.

Checking that an outlet or expert is real. The UK sources read give a method and no tool list. The Electoral Commission page, quoting Ofcom, says to check the source (where it originated) and question it: who wrote it, where it was published and who benefits from you believing it. RESIST 3 says to judge an account by how it behaves and how it fits with others in its network, because identity cannot always be established, to look for profile details that do not match behaviour and for identical content released at the same moment, and to weigh the accumulation of indicators, not one. It also says use of AI is not in itself a sign of an information threat. Our own practical suggestions, not drawn from a UK source: ask how long the outlet or think tank has existed and whether its archive is as deep as its claims; who is named as editor or legally responsible and whether that person can be found elsewhere over time; whether a contributor has a track record under the same name from before the news event that makes the piece timely; and whether the address and phone number reach a person.

Reporting routes, from the pages read. Report a profile or content to the service where it appears: Ofcom says it should be possible to report directly to the service, and that Ofcom itself cannot respond to or investigate individual complaints (Ofcom). Report a suspected approach through your organisation's reporting process, as NPSA says. Report Fraud is, per Ofcom's page, the centre for fraud and cybercrime in England, Wales and Northern Ireland. MI5's contact page has an option to report a national security concern and asks you to consider carefully whether MI5 is the right body. The Electoral Commission says it will seek to correct false information about voting or election processes. No source we read offers a route for a publisher that has run a false byline; that is a gap, and the platform and your own corrections process are the practical routes.

What a platform disclosure like OpenAI's gives a UK organisation, and what it does not.

It gives youIt does not give you
An attributed assessment of where operators were based, with some reasoning.A confidence level, a named sponsor, or proof that a state directed anything.
Ratings on a public scale.An audience count, or any outside check of the rating.
Signs of the fronts: account settings, posting bursts, staff claims against listed staff.A list of outlets or contacts to search your own records against. Outlet names are not in the text.
A statement that information went to "relevant authorities" and "industry partners".Notice to the outlets or people involved. No one named is said to have been told.
A view of one vendor's platform.Operators on other models, or on none.

The last row is the pattern in an earlier briefing: a vendor disclosure that counts what it found and publishes no list a recipient can check against. Here the persona and front names are printed, so a publisher can search its own archive for them on OpenAI's page, but the outlets that ran the articles are not named in the text, so no outlet can tell from the page whether it is one of them.

What to do, in order

Take this with you

Today, for a communications or security lead

  • Read OpenAI's page yourself, because this briefing does not repeat the byline, front or outlet names it prints, and search your own archive, contributor list, speaker lists and contact book for each of them. Treat a match as a lead and a non-match as no clearance.
  • If you find a match, keep the evidence (the pages, emails, dates and who handled them), stop engaging, and use your organisation's reporting process before anyone makes a public claim. The NCSC chief executive wrote in 2024 that discussion of information integrity should stay measured until the authorities with the details have assessed; the same discipline is sensible for a public claim about a contributor (our inference).
  • Report through the route that fits: the platform for a profile; your security manager under your own process; Report Fraud for fraud or cybercrime; MI5's online contact route only for a national security concern.
  • Write down in one paragraph who decides whether a contributor or expert is genuine and what they check. If the answer is that the person seemed credible, that is the gap.
  • Agree wording now for a statement that says what you know and what you do not, names no state or sponsor, and leaves attribution to the authorities.

Take this with you

For publishers and editors, before the next pitch is accepted

  • Verify the byline as a person before the piece runs: a call or video meeting on a number you found independently, a track record under the same name that predates the news hook, and an editor or employer who will vouch.
  • Do not treat a polished draft, compliance with your guidelines or a contactable address as evidence. OpenAI says both operations used AI to polish material, and that the evidence indicates the Russia-origin front's staff were real people who did not know who ran it.
  • Check the outlet or think tank behind a quote or a guest: how long it has existed, who is named as responsible, whether the staff it claims match the staff it lists, and whether its output arrived in a burst around one news event.
  • Keep a note of who commissioned or accepted each external piece and why, so that a later notice can be matched in an hour.
  • Decide in advance how you would correct or remove a piece if a contributor proved false, and tell readers.

Take this with you

For trust and safety, election-related and public body teams

  • List which of your channels take outside contributions or quote outside experts, and who signs each off.
  • Use the RESIST 3 early-warning and escalation steps, judge accounts by behaviour, and do not treat AI use as a sign of malign intent in itself.
  • Know what Ofcom's letter asks of providers (take down illegal content targeting UK elections when aware, easy complaint processes) and that the Electoral Commission says it will correct false information about voting processes.
  • Treat the proposed National Centre for Information Defence as a proposal until a primary source says what it will do and whom it will serve. Do not plan around it.

The question that exposes the gap

OpenAI says the Iran-origin articles ran in about a dozen outlets, and that the evidence indicates the Russia-origin front's staff did not know who they worked for. Its text names none of the outlets. A vendor can tell you that an operation reached Category 4 or 5; it cannot tell you whether your byline list, your expert panel or your guest speakers contain one of its personas, and its page does not say it told anyone who ran them. If a board or a regulator asked you today which of the contributors, experts and think-tank contacts in your own archive and contact book you had verified, and how, would you have an answer other than that they seemed credible?

Key facts

Sources

  1. PrimaryThe report of 8 October 2026, "Disrupting AI-enabled false front operations", read in full in a browser with its eleven images: both cases, the Breakout Scale ratings, the matrix of 30 operations, the Iran-origin article timeline and the page's own caveats. It is the report; no separate full report is linked.OpenAIaccessed 2026-10-09
  2. PrimaryThe Breakout Scale paper of September 2020: the definition of the six categories that OpenAI and Anthropic both apply.Brookings Institutionaccessed 2026-10-09
  3. PrimaryDetecting and countering misuse of AI, September 2026: the influence operations section read in full (nine cases, trends, Breakout Scale ratings, account counts, attribution wording, sharing), and the introduction.Anthropicaccessed 2026-10-09
  4. PrimaryThe 2026 Usage Policy update of 8 October 2026: the sentence on state media outlets, government propaganda offices and commercial firms, and the new deceptive-campaigns section.Anthropicaccessed 2026-10-09
  5. PrimaryImpact of AI on cyber threat from now to 2027, published 7 May 2025: scope statement that it does not cover influence operations.National Cyber Security Centreaccessed 2026-10-09
  6. PrimaryDefending democracy guidance collection, published 7 December 2023 and reviewed 29 May 2024: audiences and what the guidance covers.National Cyber Security Centreaccessed 2026-10-09
  7. PrimaryChief executive's blog of 7 August 2024 on securing the 2024 general election: the advice to avoid premature claims about deepfakes and disinformation.National Cyber Security Centreaccessed 2026-10-09
  8. PrimaryNational Security Act 2023, section 13, foreign interference: general, up to date to 8 October 2026, with the designated body condition inserted on 8 July 2026.legislation.gov.ukaccessed 2026-10-09
  9. PrimaryPage of 19 September 2023, written at Bill stage: the foreign interference offence as a priority offence and the risk assessment duty.Ofcomaccessed 2026-10-09
  10. PrimaryOpen letter to online service providers of 1 April 2026 on elections: take-down expectations for illegal content including foreign interference, application to AI-generated content, and the statement on misinformation. Read as a PDF by text extraction.Ofcomaccessed 2026-10-09
  11. PrimaryHarmful online content: how to report it, last updated 21 September 2026: report to the service, Report Fraud, and that Ofcom cannot investigate individual complaints.Ofcomaccessed 2026-10-09
  12. PrimaryPress release of 17 June 2024: no legal power over campaign content, a request that campaigners label generative AI, and the imprint requirement.Electoral Commissionaccessed 2026-10-09
  13. PrimaryEngaging with campaign material at elections, last updated 24 July 2024: the check-the-source and question-the-source tips and fact-checker list.Electoral Commissionaccessed 2026-10-09
  14. PrimaryPress release of 28 November 2022 on the first meeting of the Defending Democracy Taskforce: its remit, including disinformation.Home Office and Cabinet Officeaccessed 2026-10-09
  15. PrimaryUK action against Russian foreign information warfare, updated 13 July 2026: the count of sanctions since October 2024 and the citation of platforms that exposed one designated entity.Foreign, Commonwealth and Development Officeaccessed 2026-10-09
  16. PrimaryRESIST 3, published 29 October 2025: the foreword, introduction and Recognise section, read to the end of the Recognise the behaviour passage.Government Communication Serviceaccessed 2026-10-09
  17. PrimaryThink Before You Link campaign page, last updated 10 April 2026: aims and the instruction to report through organisational processes.National Protective Security Authorityaccessed 2026-10-09
  18. PrimaryPress release of 17 May 2022 launching the Think Before You Link app: the MI5 figure of over 10,000 disguised approaches.Cabinet Office and Centre for the Protection of National Infrastructureaccessed 2026-10-09
  19. PrimaryContact page: the option to report a national security concern and the advice to consider carefully whether MI5 is the right organisation.MI5accessed 2026-10-09
  20. Reported byNews report of 8 October 2026 on the OpenAI page, read in full and compared claim by claim with the page. A pointer only; where it differs the article follows OpenAI.CyberScoopaccessed 2026-10-09
  21. Reported byNews report of 8 October 2026 on the UK-Germany security partnership and the proposed National Centre for Information Defence. Treated as a news report of a proposal.The Registeraccessed 2026-10-09

Share this briefing

Know someone who owns this problem? Send it to them.

Related briefings

The briefing, in your inbox

Practitioner analysis of cyber and AI security news. No vendor noise.

How often

Every new briefing in one email, at 7am, or at 7am, 12:30pm and 6pm. Nothing is sent when nothing is new. Unsubscribe any time.