Announced 8 Oct 2026 · Sources checked
What did OpenAI publish on 8 October?
The report sits in OpenAI’s Safety stream. The RSS item is timestamped 8 October 2026 at 00:00 GMT. The teaser says OpenAI “disrupted two AI-enabled influence operations that used false-front journalists and a think tank to spread geopolitical messaging.” The page we opened on 9 October is a case study, not a product note. It says the company banned two ChatGPT account clusters, shared information with “the relevant authorities,” and is publishing so that “further research and disruption” are easier.
OpenAI compares the Iranian journalist personas to “Alice Donovan,” a 2016–17 fake byline it attributes to Russian military intelligence, and the Latin American think-tank cutouts to PeaceData, a 2020 fake outlet it ties to people around the Internet Research Agency. Those older cases are OpenAI’s analogies. The new facts it claims are the two 2026 account clusters, the prompts it saw, and the open-source pages it says matched some of the operators’ own reports.
This is a platform-abuse disclosure, not a model launch. It sits next to, and is not the same story as, OpenAI’s September note on a Moonshot distillation campaign. That earlier page was about attempted extraction of model behavior. This one is about covert influence. Both are OpenAI’s own enforcement write-ups.
What does OpenAI say Operation Dark Clark did?
The Russia-origin cluster, OpenAI writes, prompted mostly in Russian. One user prompted in Spanish but “nevertheless appeared to be located in Russia.” Because OpenAI “do[es] not allow access to our models from Russia,” the operators used VPNs. The company nicknamed the campaign Dark Clark after a fake persona, Mia Clark, that it says controlled a self-described research platform called the Social Research Center (SRC).
ChatGPT’s main job, in the report, was not to invent the public forgeries. “The main way the operators used ChatGPT was to draft and update internal reports to an unknown superior.” Those reports covered three workstreams: denigrating Ukraine and undermining recruitment for the Ukrainian Armed Forces; interfering in domestic politics, “especially Bolivia and Argentina”; and managing the SRC. OpenAI says the operators also asked the model to explain public reporting about Politology or La Compañía, “a reported successor to the Wagner Group.”
The SRC detail is the part OpenAI calls unusual. Internal reports referred to pay scales, hiring, firing and staffing plans. OpenAI’s reading is that the Russian operators controlled the entity, and that Latin American employees “were not aware that they were working for a Russian group.” The company says it found well over 60 articles on the SRC site, “the great majority of which appeared to be original compositions,” and calls this “the most complex attempt to run a front identity that we’ve disrupted over the past two and a half years.” Those are OpenAI’s inferences. We did not interview SRC staff or inspect payroll.
Some fakes in the internal reports, OpenAI says, later showed up in open sources: a fake Lima education-directorate email about Ukraine events, later covered in Peruvian and Polish press; a fake Ecuador education email later denied by Ecuador’s education minister; and fake audio and video in Ecuador and Bolivia that fact checkers or state utilities later debunked. Other claimed fakes OpenAI could not corroborate. In Argentina, the operators claimed credit for United Nations arguments OpenAI says have been Argentina’s official position for years.
What does OpenAI say Operation Bogus Bylines did?
The Iran-origin cluster prompted in Persian and produced Persian and English. OpenAI says the actors used VPNs. Typical article prompts asked ChatGPT to check an English draft against a named outlet’s submission rules, then to write the pitch email. The seven bylines listed are Ervin B. Hoskins, Noah Lamington, Sophia Gonzalez, Michael Harrison, Ericka Feusier, Jenny Williams and Alice Johnson. For Michael Harrison, “the operators asked the model to write the bio itself.” OpenAI notes that Meta disrupted an Iranian operation that also used a Michael Harrison persona in March 2026, and banned the Hoskins Instagram account in August after transparency settings showed Iran.
Open-source work by OpenAI found “almost 100 articles” published or syndicated under those bylines “across roughly a dozen” small and medium international-affairs outlets, from July 2025 through October 2026, with volume rising after the US–Iran conflict. One unnamed outlet is described as having almost 2 million Facebook followers as of August 2026. The company says the pattern “appeared consistent with a commercial actor running a for-hire influence campaign,” and that it could not name the buyer.
A second workstream generated batches of English and Persian comments, often posted within minutes of each other, including replies that praised the operation’s own articles. OpenAI rates that comment activity Category 2: present on more than one platform, little sign it dominated a thread. The same operators asked ChatGPT to polish internal decks that treated views on the original posts — not views on their replies — as impact. How to read a company announcement is the right habit here: the metric in the operators’ slides is not a measurement of persuasion.
How does OpenAI score “breakout,” and what did the operators exaggerate?
The IO Breakout Scale in the report runs from 1 to 6. OpenAI puts Dark Clark in Category 5 because, it says, some fakes drew fact checks, official denials, and comment from politicians — “the first Category 5 operation we’ve disrupted since we began our reporting.” It puts the Iranian article-planting workstream in Category 4, “based on its consistent breakout to a number of media outlets,” and the Iranian comments in Category 2. A matrix classifies 30 exposed operations by main distribution method. OpenAI’s lesson is that landing copy in real outlets has had more potential reach than farming fake social accounts.
The same report is careful about self-reporting. Dark Clark “tried to claim” a Brazilian captive’s televised statement as its own messaging. Bogus Bylines used a view-count method that “greatly exaggerated the operation’s impact figures.” OpenAI also says it did not see the Russian operators use its models to create most of the public content — only to report on campaigns and, occasionally, to fix accent, vocabulary, or the layout of a fake contract.
None of this is a measured audience study, and none of it is a software exploit. For a different failure mode — a backdoored coding model that a researcher actually ran — see ProjectDiscovery’s Codex-CLI case. OpenAI’s false-front page has no CVEs, no malware hashes, and no count of banned accounts.
What should readers not assume?
A Category 5 on OpenAI’s scale is not an outside finding that the campaigns changed an election or a government’s policy. It is OpenAI’s rating that some forgeries left the operators’ own channels and drew public rebuttals. The company does not publish the list of outlets that ran Bogus Bylines pieces, and it does not claim it identified the Iranian commercial client. NPR’s 8 October story, timestamped 20:25 EDT, restates the same report; it is secondary coverage, not a second investigation.
The report is also not a claim that ChatGPT was the only tool. OpenAI writes that both operations used “our models in combination with more traditional techniques,” including fake email addresses, TikTok channels, and, in one Dark Clark example, a photo of a generated letter under a genuine TVN Noticias logo. That mix is closer to classic cutout work than to a single-prompt prompt-injection incident.
We opened the official page on 9 October after a simple fetch returned HTTP 403. The text quoted here is from that inspected body. We did not obtain the chat logs, contact the named personas, or rerun the open-source searches. The inspectable facts are the dated report, the nicknames and bylines OpenAI published, the Category 5/4/2 scores on its scale, and the company’s warning that the operators inflated their homework.
Common questions
Did OpenAI say these campaigns changed an election?
No. The report rates reach on OpenAI’s Breakout Scale and describes fact checks, denials, and some politician comments. It does not publish a turnout, vote, or policy effect.
Is Category 5 an independent ranking?
No. It is OpenAI’s label on its own 1–6 scale. The company says this is the first Category 5 disruption in the 30 covert IO cases it has reported since early 2024.
Did ChatGPT write the published articles?
OpenAI says the Iranian operators used the model to refine drafts and pitch emails, and that the Russian operators mostly used it for internal reports. It also says not all planted content came from its models.
What to remember
Use the 8 October OpenAI page for the launch date, the two nicknames, and the company’s own scores. Keep the operators’ impact slides in the unreliable column, and treat NPR as a restatement of the same disclosure.
Sources & further reading
How this story was made
Written by Kristian Kostov with AI assistance and checked against the linked sources. Company performance claims are attributed to the company. Analysis reflects AiLookout’s interpretation; we have not independently tested the products discussed. Cover photography is illustrative and does not depict the specific announcement or product.
Our editorial standards





