AI influence ops are learning to fake institutions, not just posts

AI influence ops are learning to fake institutions, not just posts

4 min read

OpenAI’s disruption of Russia-origin accounts promoting a fake Israel-based think tank points to the real AI risk in propaganda: cheap institutional theater that gives weak narratives a stronger costume.

TL;DR: The practical risk in AI-enabled influence work is not better slogans, it is cheaper fake legitimacy at scale.

What did OpenAI actually disrupt?

OpenAI reported in its post, “Disrupting a new covert influence campaign from Russia,” that it banned Russia-origin accounts using AI to promote a fake Israel-based think tank and a “sovereignty” index that praised Russia and criticized the West.

That is the claim we can stand on. Not that this campaign changed minds. Not that it reached millions. Not that AI made it persuasive. OpenAI’s public note, as provided, does not give enough to say those things.

But the shape of the operation matters.

The campaign was not just “post pro-Russia content.” It created institutional wrappers: a think tank, an index, a geopolitical frame. That is a different layer of manipulation. A fake account says, “trust me.” A fake think tank says, “trust the institution behind me.” A fake index says, “trust the measurement.”

That is where AI changes the cost curve.

It becomes easier to generate the surrounding material that makes a weak operation look thicker than it is: policy language, mission statements, pseudo-academic framing, executive summaries, quote-ready claims, social snippets, maybe even localized variants for different audiences. The operator still needs distribution. They still need people to believe it. But the scaffolding gets cheaper.

Why does a fake think tank matter more than fake comments?

Because institutional theater travels better than raw propaganda.

A random anonymous post praising Russia is easy to discount. A “sovereignty” index published by a supposed research outfit gives journalists, influencers, and aligned political actors something to cite. It creates an object in the world. Something with a name. Something that can be screenshotted, linked, argued over, and laundered into other channels.

That does not mean the object is effective. It means the attack surface is broader.

Search systems, social platforms, assistants, and human researchers all tend to treat named entities as anchors. A named think tank feels more real than a batch of posts. An index feels more concrete than an opinion. This is exactly the kind of middle layer where low-quality synthetic content can punch above its weight, especially if nobody checks provenance.

an artificial institution façade feeding polished reports and social posts into a wider public information stream

The catch is that AI is not the whole story. Russia-origin accounts could have run a fake think tank before large language models. Influence operations are old. Front groups are old. Bogus metrics are old.

What changes is throughput and polish. A small team can produce more variants, in more tones, with fewer obvious mistakes. They can test narratives faster. They can make the fake institution look “alive” with a steady drip of content.

That is less cinematic than autonomous persuasion bots taking over public opinion. It is also more useful to understand.

What should platforms and builders watch for?

The detection problem should not stop at account behavior or model-generated prose. The more interesting signal is entity behavior.

Is a newly created “research institute” publishing indexes with no transparent methodology? Are multiple accounts citing the same obscure report in coordinated ways? Does the organization have a thin public footprint but unusually polished content? Are claims being recycled across domains, social profiles, and supposed experts who all appeared at once?

For AI product teams, this matters beyond trust and safety departments. If you are building search, RAG, market intelligence, media monitoring, agentic research, or enterprise knowledge tools, you are building systems that may ingest synthetic institutions as if they are normal sources.

A retrieval system that treats every named organization as equally credible will be easier to poison. An agent that summarizes a fake index without provenance checks becomes a laundering machine. A dashboard that ranks citations without source history can make a front group look important just because it is loud.

Practitioners should add provenance work before they add another summarizer. Track source age, ownership signals where available, citation patterns, methodology transparency, and whether an entity has a history outside the current narrative push. Test your workflow with fake think tanks, fake indexes, and synthetic reports, not only fake tweets. The miss most teams make is treating influence ops as a content moderation problem. Increasingly, it is also a knowledge supply chain problem.