OpenAI Disrupts Its First Category 5 Influence Operation

OpenAI said on 8 October 2026 that it banned two covert influence operations, one originating in Russia and one in Iran, that used its models alongside traditional techniques to support “false front” entities. It rates the Russian one at Category 5 on the Breakout Scale of 1 to 6, the first Category 5 operation it has disrupted since it began reporting.

According to OpenAI, the Russia-origin operation appears to have co-opted unwitting people in Latin America to run a “think tank”, while the Iran-origin operation used seven fake journalist personas to pitch long-form articles to online outlets. It rates the Iranian article work at Category 4.

Business Pill · DECLARED IDENTITY

A short explainer of declared identity: rules need someone to apply them to. It teaches the general idea only and says nothing about any company or country in this story.

The key insight: As we read it, OpenAI’s account puts much of the AI use in the operations’ back offices: by its description, the Russian operators used ChatGPT mainly to write internal reports, and the Iranian operators to polish articles and pitches and to present their own impact figures.

The Russian Operation

OpenAI says it banned a cluster of ChatGPT accounts originating in Russia that targeted countries across Latin America, much of it aimed at undermining Ukraine’s reputation in the region and some at local political outcomes, especially in Argentina and Bolivia. The operators used VPNs because OpenAI does not allow access from Russia, it says.

It says the operators appear to have controlled a self-described research platform, the Social Research Center, through a fake persona named “Mia Clark”, and that its on-the-ground employees were not aware they were working for a Russian group. OpenAI identified well over 60 articles on the center’s website, most of them apparently original.

The main use of ChatGPT, OpenAI says, was drafting internal reports to an unknown superior. In those reports the operators claimed, among other things, to have sent fake emails in May 2026 instructing schools in Lima, Peru, to hold events referencing Stepan Bandera, and OpenAI says its open-source searches found stories matching this claim in the Peruvian and Polish press.

OpenAI’s ratings on the Breakout Scale (1 lowest, 6 highest), from its report of 8 October 2026: the Rus
OpenAI’s ratings on the Breakout Scale (1 lowest, 6 highest), from its report of 8 October 2026: the Russia-origin operation at Category 5, the Iran-origin operation’s articles at Category 4 and its social media comments at Category 2.
OpenAI has exposed 30 covert influence operations since early 2024
OpenAI says it has exposed 30 covert influence operations since early 2024; the Russia-origin operation is its first rated Category 5, per its report of 8 October 2026.

The Iranian Operation

OpenAI says the Iran-origin accounts used ChatGPT to refine English-language articles about the US-Iran conflict against outlets’ submission criteria and to draft pitch emails to editors. It identified almost 100 articles published under the operation’s bylines across over a dozen outlets, from July 2025 to October 2026.

The operation also generated batches of social media comments, which OpenAI says drew little engagement and which it rates at Category 2. It says the activity appeared consistent with a commercial actor running a for-hire campaign, but that it could not identify the actor.

OpenAI adds that the Iranian operators measured their impact by views on the posts they replied to, not views on their own replies, a method it says greatly exaggerated their figures.

OpenAI’s Reading

“What is most striking about these operations is that they closely resembled complex influence operations of the pre-AI age, but used AI to make some of the workflows easier,” OpenAI writes.

Across the 30 covert influence operations it has exposed in the last two and a half years, OpenAI says, those that try to land content in real media outlets, rather than relying on fake social media distribution, tend to have the highest potential reach and impact. It says it has shared information on both cases with the relevant authorities.

The Structural Read

Reach came through real outlets. OpenAI says both operations landed content in mainstream media outlets, and that operations which do so tend to have the highest potential reach.

The front had real staff. OpenAI says the Social Research Center’s employees appear not to have known who they worked for, and that most of its well over 60 articles appeared to be original.

Self-reporting was unreliable. OpenAI says the Russian operators took credit for events unrelated to them, and the Iranian operators used a metric that greatly exaggerated their impact.

OpenAI, 8 October 2026

“This stands out as the most complex attempt to run a front identity that we’ve disrupted over the past two and a half years.”

Three Implications

EDITORS AS THE ENTRY POINT OpenAI says the Iranian personas pitched long-form articles to small and medium online outlets.

RATED, NOT COUNTED OpenAI rates impact on the Breakout Scale; the Russian operation is its first Category 5.

SHARED WITH AUTHORITIES OpenAI says it has shared information on both cases with the relevant authorities.

The Business Engineer Lens

This story maps onto the Business Engineer framework Inside Anthropic’s Permission Layer.

The framework describes the governance layer of the AI stack as the place where “decisions are made about who gets access to frontier intelligence, under what conditions, and for which purposes.”

As we read it, OpenAI’s report shows that layer working after the fact: by its account, the operators reached ChatGPT through VPNs from a country it does not serve, and its response was to ban the accounts and publish what it found.

What Is Not Established

We read OpenAI’s report in full. Its account of the operators’ activity relies partly on their own internal reports, which OpenAI says cannot be taken at face value, and some of the fakes they claimed could not be corroborated from open sources. The Breakout Scale ratings are OpenAI’s assessments. We did not contact OpenAI.

Business Engineer Framework

Inside Anthropic’s Permission Layer

A Business Engineer framework on the governance layer of the AI stack: who decides access, use and oversight.

Read the Map of AI →

The Bottom Line

OpenAI says it banned a Russia-origin operation that appears to have run a Latin American “think tank” through a fake persona, its first Category 5 disruption, and an Iran-origin operation that placed almost 100 articles under seven fake bylines, rated Category 4.

94,000+ executives read Business Engineer for the AI strategy frameworks cited by ChatGPT, Claude, and Perplexity.

A note on sourcing. We read OpenAI’s report of 8 October 2026 in full; the ratings and findings are OpenAI’s, and parts of its account rest on the operators’ own internal reports. We did not contact OpenAI. Nothing here is a forecast, and nothing here is financial or investment advice.

Sources: OpenAI: Disrupting AI-enabled ‘false front’ operations (8 Oct 2026)

Scroll to Top

Discover more from FourWeekMBA

Subscribe now to keep reading and get access to the full archive.

Continue reading

FourWeekMBA