OpenAI report on Iranian ops shows why tech policy fails
By Nikhil Raghavan · Reporting from San Francisco ·
Iranian operatives used ChatGPT to plant fabricated stories in media outlets, proving that dual-use models easily launder state propaganda through weakened copy desks.
The mechanics of synthetic narrative laundering
For years, policy debates over artificial intelligence fixated on grand abstractions like existential risk. We spent time in legislative hearings worrying whether a neural net might seize control of the Pentagon. Meanwhile, we ignored a simpler reality in plain sight. State actors do not need an artificial intelligence to achieve sentience. They just need it to write passable prose, draft pitches, and bypass sleep-deprived copy desks.
OpenAI reported that Iranian operatives used its models and fake personas to plant articles critical of US policy. Reporting by CNN and France 24 noted the campaign reached about a dozen outlets worldwide with roughly 100 articles. The operation relied on seven fictitious Western journalist bylines. OpenAI identified profiles for Ervin B. Hoskins, Noah Lamington, Sophia Gonzalez, Michael Harrison, Ericka Feusier, Jenny Williams, and Alice Johnson. Operatives used Farsi prompts in ChatGPT to refine long-form articles and draft email pitches. They also generated social media comments on missile strikes, ceasefires, and diplomatic maneuvering.
The mechanism here is not autonomous cyber warfare. It is industrial-scale writing designed to exploit the economics of modern digital journalism. Under the Internet Research Agency, a Russian company engaged in online propaganda and influence operations, state campaigns relied on manual workflows. Today, a state-backed actor can spin up a fluent Western freelancer persona in ten minutes. The operative gets a social media footprint and a pitch letter that reads like it came from a coffeehouse in Brooklyn or London. Large language models now automate the production of fluent prose at scale.
Darren Linvill, co-director of Clemson University's Watt Family Innovation Center Media Forensics Hub, spoke to NPR. He noted that artificial intelligence helped operatives create authentic language that legitimate outlets published. That is the leverage point of modern state-sponsored disinformation. It is not about hacking power grids or seizing broadcast networks. It is about exploiting the structural collapse of mid-tier editorial oversight.
Where the copy desks break under scale
The fault line in this story is not located in San Francisco boardrooms. Nor is it in the weights of frontier models. It runs through the content management systems of small digital outlets. These newsrooms can no longer afford editors with time to check whether Ervin B. Hoskins actually exists.
The London-based Middle East Monitor and the Los Angeles-based LA Progressive picked up these AI-assisted pieces. LA Progressive published an article titled “Is America’s Iran Policy Being Privatized? The Jared Kushner Question.” NBC News reported that Middle East Monitor published at least 21 articles by four fake authors before removing their pages. Daily Kos published material under its community section. That section prohibits pretending to be someone else, yet leaves posts unreviewed before publication.
Jessica Brandt ran the Foreign Malign Influence Center at the Office of the Director of National Intelligence. She put it plainly to CNN. It is remarkable that the Iranians landed content in real media outlets to expand reach. Brandt added that artificial intelligence lets foreign adversaries hide their hand. They build false fronts to launder content through authentic channels.
Middle East Monitor has nearly two million Facebook followers. When such an outlet publishes these fabricated bylines, narrative laundering is complete. The state-backed material sheds its origin and acquires institutional legitimacy. The social media comments drew only single or double digits in likes. But the real prize was the byline on a third-party site. Mainstream pickup acts as an amplifier, turning an API prompt into a geopolitical citation.
The three o'clock call nobody answers
To understand why proposed legislative fixes fail, ask the core question of infrastructure design. Who gets paged at three in the morning when the system breaks? What tools do they have to fix it?
In hearings on foreign influence operations, lawmakers demand policy memos and voluntary safety frameworks. But an API key does not care who uses it. A prompt asking to critique Western moral credibility could come from a Tehran student or a Berlin researcher. Generative AI infrastructure is dual-use. Forcing providers to police every downstream application is like asking word processor makers to stop forged passport applications.
OpenAI assessed the Iranian campaign as a Category 4 operation for media planting and Category 2 for social media replies. Operatives ran under cover of a commercial actor running a for-hire campaign. You cannot patch this vulnerability with safety classifiers or subpoenas. Threat actors will migrate to open-weights models on self-hosted infrastructure outside American jurisdiction. Russian operatives adapted their workflows in the exact same way after earlier platform crackdowns.
We are living through the permanent democratization of deception. Generating fluent, localized propaganda now costs zero. Meanwhile, verifying human identity across digital publishing platforms remains prohibitively expensive. Regulatory bodies and media institutions need cryptographic author verification that can withstand automated pitch storms. Until then, foreign intelligence agencies will treat digital newsrooms as free printing presses.
Sources
- CNN: Iranian operatives used AI to plant fake stories in multiple US media outlets
- OpenAI: Disrupting AI-enabled “false front” operations
- NPR: OpenAI caught Russians and Iranians using ChatGPT for influence campaigns
- France 24: OpenAI bans Russian, Iranian ChatGPT propaganda networks
- CNA: Russian fake think-tank with real employees exposed in 'most complex' influence operation attempt, OpenAI says