# The fake is learning to hire real people

OpenAI’s first Category 5 influence-operation takedown involved a Russian-controlled research front staffed by unwitting people in Latin America, while an Iran-origin network placed almost 100 articles under seven fake journalist identities. AI is lowering the cost of maintaining false institutions, so trust now depends on verifying who controls the organisation behind the content, not only whether the words look synthetic.

**AyEye Today · 2026-10-09**

LEAD SUMMARY — ANALYSIS. The most effective fake may no longer be the post, the profile or even the publication. It may be the organisation that persuades real people to do real work while hiding who controls the brief.

On 8 October, OpenAI disclosed two influence operations that used ChatGPT alongside older covert techniques. One Russia-origin operation appears to have controlled a Latin American research centre through a fake manager, employing people who did not know they were working for a Russian group. An Iran-origin operation used seven invented journalist identities to place or syndicate almost 100 articles across roughly a dozen online outlets.

The AI contribution matters, but not for the familiar reason. This is not mainly a story about a model flooding social media with synthetic text. It is about AI lowering the maintenance cost of false institutions: drafting internal reports, translating, pitching, localising and keeping several identities or workstreams coherent. Real researchers, editors and audiences then supply the credibility the operation cannot manufacture by itself.

## 1. The front moved from the account to the organisation

CONFIRMED — PRIMARY SOURCE. OpenAI says it banned a cluster of ChatGPT accounts originating in Russia that supported covert activity across Latin America. The operators appear to have controlled a self-described research platform called the Social Research Center through a fake persona named “Mia Clark”. Their internal reports discussed pay scales, hiring, firing, staffing plans and projects. Available evidence indicated that the centre’s Latin American employees did not know they were working for a Russian operation. [OpenAI: Disrupting AI-enabled “false front” operations](https://openai.com/index/disrupting-ai-enabled-false-front-operations/)

The centre was not merely a shell website. OpenAI identified well over 60 articles on its site, most apparently original. Staff reportedly interviewed experts and wrote research papers on subjects ranging from BRICS opinion to Brazil’s economy. That is why OpenAI calls it the most complex attempt to run a front identity it has disrupted in two and a half years.

INDEPENDENT CONTEXT. Earlier reporting from openDemocracy and Forbidden Stories documented Russian influence specialists and former Wagner-linked networks operating in Latin America, including Bolivia. OpenAI links some publicly investigated fakes to entities known as Politology or La Compania, but it does not attribute the entire operation to a specific Russian government or intelligence service. [openDemocracy: Russian influence activity in Bolivia](https://www.opendemocracy.net/en/russia-bolivia-south-america-putin-evo-morales-wagner-prigozhin-covert-operations-propaganda-disinformation-foreign-interference/)

ANALYSIS. The front has acquired an organisational layer. Instead of impersonating one expert, it can commission genuine interviews and original writing through a structure whose workers see only legitimate tasks. The output may be factually ordinary, competently researched and human-authored. Its deception sits upstream, in control and purpose.

## 2. Real labour can become credibility infrastructure

Unwitting staff are not incidental to the operation. They are how it becomes more believable. Their language, contacts, judgement and local knowledge help the front pass tests that a synthetic persona would fail.

ANALYSIS. This reverses a common mental model of AI-enabled manipulation. The model does not have to replace people. It can help a hidden operator organise them. A real researcher can conduct the interview; a real editor can assess the prose; a real outlet can publish the result. Each participant may perform a reasonable local check while the whole chain remains deceptive.

The human stakes are sharper than “bots versus users”. Workers can discover that good-faith research was commissioned by a concealed principal. Editors can become distribution infrastructure for a campaign they would have rejected if ownership and intent were visible. Readers can encounter material carrying the social proof of real labour without knowing that the institution connecting those people was invented.

IMPORTANT LIMIT. The evidence does not show that every article on the research centre’s site was false, that its staff knowingly participated, or that AI wrote the majority of its public output. OpenAI says that in most observed Russian activity, the models were used to report on campaigns rather than create campaign content. The deception is the hidden chain of control.

## Concept to learn today: Institutional provenance

INSTITUTIONAL PROVENANCE is evidence about who controls, funds and directs an organisation or persona that asks others to create, publish or trust information.

### Control

Who can hire, fire, set pay, choose projects and approve publication? A public biography or registration record is weaker than evidence about decision rights.

### Commission

Who asked for the work, what outcome did they seek, and what constraints did they conceal? A truthful article can still serve a deceptive commission.

### Editorial chain

Which people and organisations handled the material before publication, and what did each know about its origin? The chain can contain genuine work and still begin with a false principal.

### Financial trail

Who paid the workers, domains, promotion and distribution? Payment intermediaries and remote managers can be as revealing as text metadata.

### Disclosure history

Can the organisation show stable ownership, accountable officers, corrections, conflicts and a record that survives scrutiny over time?

ORIGINAL SYNTHESIS. Content provenance asks where a file came from and how it changed. Institutional provenance asks who assembled the people and incentives behind it. The first can help identify a synthetic image or altered document. The second is needed when the words, interviews and bylines are real but the organising entity is not.

## 3. Distribution through real outlets is the multiplier

CONFIRMED — PRIMARY SOURCE. The Iran-origin operation, which OpenAI calls “Bogus Bylines”, used seven invented journalist personas. OpenAI identified almost 100 articles published or syndicated under those bylines across roughly a dozen small and medium online outlets. One publisher had almost two million Facebook followers, about 355,000 followers on X and more than 544,000 on Instagram as of August 2026.

The same operation also generated batches of social-media comments, but those attracted little authentic engagement. OpenAI rates the article-placement activity Category 4 on the Breakout Scale and the commenting activity Category 2. It rates the Russia-origin operation Category 5, the first operation at that level among the 30 it has exposed since early 2024.

INDEPENDENT METHOD. The Breakout Scale measures observable spread and response, not whether a claim is true or whether it caused an event. Category 4 means an operation has broken beyond its own communities and is amplified by mainstream media; Category 5 adds amplification by prominent individuals or political figures. [Brookings: The Breakout Scale](https://www.brookings.edu/articles/the-breakout-scale-measuring-the-impact-of-influence-operations/)

ANALYSIS. The trusted distribution channel is now the scarce resource. A thousand comments from fresh accounts may look synthetic and remain unseen. One article accepted by a real publication inherits an editor, a domain, a search history and an audience. The operation’s goal is not necessarily to make the fake channel popular. It is to enter a channel that is already trusted.

That changes the defensive centre of gravity. Platforms still need coordinated-behaviour detection. Publishers also need contributor due diligence proportionate to reach: identity checks, commissioning records, conflict disclosures, contact verification and escalation when a new writer repeatedly supplies polished material from a thin or unstable professional history.

## 4. AI was managing the operation’s story about itself

CONFIRMED — PRIMARY SOURCE. Both operations made heavy use of AI to draft internal reports. For the Russian operation, OpenAI says this was the main use. Operators reported to an unknown superior, sometimes claiming credit for other people’s activity or for unrelated public events. In one example, they tried to present coverage based on a captive’s own video as proof that their messaging had spread.

ANALYSIS. Influence operations have two audiences. The external audience sees the narrative. The internal sponsor sees the performance report. Generative AI can serve both: it can polish public material and manufacture organisational confidence about reach, productivity and success.

This matters because deceptive measurement can allocate more money and attention to weak operations. A model can make an activity look systematic before it makes it effective. The resulting feedback loop is managerial: operators produce reports, sponsors reward apparent output, and teams learn to optimise the evidence they present upward.

INFERENCE. Investigators should treat internal AI use as an intelligence surface, not only an administrative detail. Repeated requests for campaign summaries, invented metrics, translation and credit-taking can reveal control relationships even when the public artefacts are mostly human-made.

## 5. Detection has to follow authority, not only artefacts

Most current provenance proposals attach information to content: who created a file, which tool transformed it, whether a signature is intact. Those mechanisms are useful, but a false-front organisation can publish authentic photographs, original interviews and human prose.

INFERENCE. A stronger review asks a second set of questions:

  - Does the named leader have a verifiable history beyond the organisation’s own pages?

  - Do staff know the legal entity, funder and decision-maker behind their work?

  - Can editors confirm a contributor through an independent channel rather than the contact details supplied in a pitch?

  - Do payment, domain, account-location and staffing signals tell the same story?

  - When an outlet syndicates an article, does origin information travel with it?

None of these checks is perfect. Anonymous and pseudonymous work can be legitimate; dissidents and vulnerable sources may need protection. The point is not universal identity exposure. It is accountable disclosure to the people assuming the editorial, employment or financial risk.

## Noise: AI did not invent the false front

NOISE CHECK. OpenAI itself compares these campaigns with pre-AI operations, including fake journalist “Alice Donovan” and the PeaceData outlet, which recruited unwitting writers in 2020. AI made some workflows easier, more fluent and more efficient. It did not create the underlying technique.

Nor does a provider’s takedown report offer complete visibility. OpenAI can observe activity on its own service and join it with open-source evidence, but it cannot see every tool, payment, meeting or editorial decision. Its impact ratings describe documented reach, not a complete measure of persuasion or political effect. Independent reporting broadly corroborates parts of the Russia-linked ecosystem; other claims remain based on the company’s investigation.

The wrong conclusion is that synthetic text has become undetectable and nothing can be trusted. The more useful conclusion is narrower: text-level detection cannot solve an organisational deception.

## Mental-model update

Yesterday: the safety envelope around a mass-market model is part of the release, because capability, monitoring, permissions and interface controls act together.

Today add: the trust envelope around information extends behind the content. A document may be authentic and an author may be real while the institution commissioning, coordinating and distributing the work is false.

In the illustration, separate pale blocks hold their own edges above the surface while a dark current gathers beneath them. No person or publication is literal. The unresolved question is the article’s question: how independent are visible actors when the force organising them is hidden?

## Questions to carry forward

  - What minimum ownership and funding evidence should a research centre or contributor provide to staff and publishers?

  - How can outlets preserve contributor privacy while still verifying control and conflicts?

  - Which signals reveal a false institution before its content breaks into trusted distribution?

  - Should provenance standards describe the commissioning organisation as well as the content file?

  - How should AI providers report uncertainty when linking model activity to events observed elsewhere?

Canonical: https://www.lecxie.com/publications/ayeye-today/2026-10-09.html
