OpenAI's first Category 5 influence op targeted editors, not feeds

Share
OpenAI's first Category 5 influence op targeted editors, not feeds

OpenAI banned two state-linked influence campaigns on October 8 — and the number worth sitting with is not the ban count but the rating attached to one of them: the first Category 5 operation the company has disrupted in two and a half years of publishing threat reports. The deeper signal, though, is in the fine print of what the models were actually used for.

What happened

OpenAI's report describes two operations it calls "false front" entities — shells that launder geopolitical messaging through apparent independence. The Russian one, "Dark Clark," ran across Latin America; the Iranian one, "Bogus Bylines," seeded articles into online outlets worldwide. Both were rated on the Breakout Scale, the Brookings yardstick that scores influence operations from 1 to 6 by how far they escape their original channel. Dark Clark landed at Category 5 — OpenAI's first ever at that level — because its fabricated stories provoked fact-checks and official denials in Ecuador and Peru, and public comment by politicians in several countries. Iran's article-planting workstream scored Category 4; its social-media commenting scored Category 2.

The pattern behind those scores is the report's real finding. Across the 30 covert operations OpenAI has exposed since early 2024, campaigns that pushed content into real publications reached Categories 4 and 5; campaigns that leaned on social feeds never broke past Category 3. Dark Clark's mechanics show why. A fake persona named "Mia Clark" ran a supposed think tank, the Social Research Center, whose staff in Latin America appear to have been co-opted without knowing who they worked for — the operators' internal reports discuss pay scales and hiring as though they owned the entity. Well over 60 articles on the center's site were mostly original work by those unwitting staff, not generated text. The operation's own fakes — a forged email tricking Peruvian schools into a Ukraine-themed event, fake audio of a Bolivian water utility announcing shutoffs — spread far enough to trigger press coverage and a ministerial denial.

Iran's operation was leaner and more editorial. Seven fake bylines — Western journalist personas backstopped by social accounts — pitched nearly 100 articles to roughly a dozen small and medium outlets between July 2025 and October 2026, concentrated after the outbreak of the US-Iran conflict. One of the publishing outlets counted close to 2 million Facebook followers.

What the models actually did

Strip out the geopolitics and OpenAI's description of the model's role is underwhelming in a revealing way. ChatGPT was not the content factory. Its main jobs were bureaucratic: drafting the operators' internal status reports to an unknown superior, reviewing article drafts against each outlet's submission criteria, generating the pitch emails, and translating or localizing copy — including one fake letter taken from Russian into Spanish with an audio script attached. Actual content creation was "a relatively small proportion of the overall workload," in OpenAI's words, helped by the fact that the Russian operation employed a native Spanish speaker.

The commenting half failed on its own terms: single- and double-digit engagement, a minority of replies under each post, Category 2. The operators' internal reporting measured "impact" by counting views on the posts they replied to rather than on their replies — a metric OpenAI flags as inflated, possibly deliberately. In other internal reports, the operators took credit for events that had nothing to do with them, including years-old Argentine official positions on the Falklands. OpenAI's dry conclusion: the operators were running an influence operation against their own employers.

Why the editor is the new perimeter

The defender who can stop the next one is not a platform moderation team. Account bans are invisible to the outlets: when OpenAI closes a ChatGPT cluster, the small international-affairs site that keeps publishing the personas' articles never learns of it, and its standard defenses — bot detection, inauthentic-coordination analysis — never fire, because the attack arrives as a normal freelance pitch by email from a plausible byline with backstopped profiles. The model functions as an editorial intern that has read the outlet's submission guidelines. And the outlets' own distribution does the amplification, promotion through the same social accounts that make the byline look real.

This is where the week's other provenance stories connect. Content labelling and watermarking — the rules OpenAI itself began rolling out for ChatGPT output in the EU — help a reader spot machine-generated text after publication; they do nothing for an editor vetting a contributor who has no generated artifact to label. We have tracked this same blind spot before, in different clothes: in Israel's FARA-funded influence push now feeds ChatGPT directly, the model was the distribution channel for a state's messaging, and in Kremlin deepfakes put surrender pleas in Ukrainian lawmakers' mouths, fabricated media aimed at institutions rather than feeds. The tooling fix being pursued — OpenAI adds text watermarking to ChatGPT and Codex — EU first — addresses generation, not editorial intake.

The contrarian case

OpenAI is simultaneously accuser, investigator, judge and sole witness: the account data, the prompts and the ban decisions are all its own, with no independent audit. Its threat reports are also policy artifacts — the documents regulators quote when asking for visibility into lab internals — which gives the company an incentive to publish vivid cases. To its credit, this report concedes more than most: it admits the operators exaggerated their own success, that some claimed fakes never surfaced in open-source searches, and that "not all of which was generated from our models." The uncomfortable read is that this is old-fashioned human influence work — co-opted staff, fake institutions, pitched articles — with AI compressing the editorial labor, not inventing a new attack. The Category 5 score, meanwhile, ultimately rests on corroboration OpenAI chose and politicians' reactions it counted.

What to watch

Watch whether other labs adopt the Breakout Scale or keep inventing their own taxonomies — a rating only one company applies to its own cases is marketing until it's standard. Watch publishers: if byline vetting becomes routine at small outlets, the attack gets expensive again; if nothing changes, expect more of the same category of report. And watch the persona reuse — "Michael Harrison" appeared in both this operation and one Meta disrupted in March — the strongest sign these are shared commercial toolkits rather than one-off state projects.

If a model can satisfy your outlet's submission guidelines, what check should an editor actually run on a freelance pitch? Tell us in the comments.

Read more

The Take — OpenAI's $20B gap is definitional, and that's worse

The Take — OpenAI's $20B gap is definitional, and that's worse

The $20 billion never went missing from OpenAI's business — it was never in it. OpenAI's annualized revenue was always a number only OpenAI gets to define, and with a confidential 2027 IPO filing on record and a $1.2 trillion private round under consideration, I think a self-defined metric heading into underwriter season is worse than a number that was simply wrong. A wrong number gets corrected once; a self-defined number survives every headline it produces. Our afternoon brief on Wednesday l

OpenAI busts influence ops that planted fake stories in real media

OpenAI busts influence ops that planted fake stories in real media

The day's AI news runs through one seam: the work is showing up in places nobody planned for — inside real newsrooms, across the whole night sky, and in the M&A column. OpenAI has banned two state-backed influence operations that used ChatGPT to plant fabricated stories inside legitimate news outlets — and rated the Russian one the most disruptive it has seen in two and a half years. In a report dated October 8, OpenAI detailed "Dark Clark," run from Russia across Latin America, which ran a th

Open Source Radar — October 9: plugins, sandboxes, tokens

Open Source Radar — October 9: plugins, sandboxes, tokens

Today's open-source signal is infrastructure rather than hype: Microsoft's code sandbox reaches 1.0, Anthropic's knowledge-worker plugins keep climbing, a beloved token counter flips its default, and LocalLLaMA squeezes a usable 2B model into about 700 MB. knowledge-work-plugins (Python, ~27,900 stars, Apache-2.0) — Anthropic's repository of role-shaped plugins for Claude Cowork is the top AI repository on today's daily trending page, and the stars keep coming: roughly 2,100 more than when we

Deep Dive — The four-token blind spot inside DeepSeek V4

Deep Dive — The four-token blind spot inside DeepSeek V4

ByteDance's Seed research team says it has found the cause of one of the stranger recurring complaints about DeepSeek's models: the same question, asked with nothing changed except a few junk characters bolted onto the front, can flip the model from right to wrong. Their paper, posted to arXiv on September 28, traces the wobble to a memory-saving trick used during long-context inference, and reports that DeepSeek-V4-Flash-Base's retrieval accuracy swings by as much as 40.2 percentage points depe