Russian propaganda is poisoning AI chatbots, report finds

Share
Russian propaganda is poisoning AI chatbots, report finds

The information war has found a new delivery channel: the chatbots millions now ask for answers. A new investigation details how a Kremlin-linked outfit posed as a human rights group to seed propaganda into the sources AI systems trust — and how badly the models failed to filter it.

A Kremlin-linked unit that poses as a human rights organization has been manipulating ChatGPT and its rivals, opening a new front in the misinformation war — and in Russian-language tests, chatbots repeated the propaganda in up to 86 percent of cases, according to the investigation shared widely Monday. The operation works by flooding the web with seemingly credible, pro-Kremlin content designed to be absorbed into training data and retrieval systems, a tactic researchers call "data poisoning" or "LLM grooming." Both major AI labs' models broke under the tests, per the reporting. The findings land alongside a body of evidence that the attack surface is real: Bloomberg's investigation into the SDA network documented more than 40 sites built to inject Russian narratives into what chatbots and search engines rely on, NewsGuard's regular testing finds the most popular chatbots repeat circulating falsehoods in more than a quarter of cases, and an arXiv analysis of the Moscow-based "Pravda" network counted roughly 150 domains publishing millions of articles a year to contaminate model outputs. The take: the weak point isn't the model's reasoning — it's the hygiene of the sources it learns from, and that's a problem no amount of alignment work alone will fix. English-language models resist better; models in languages with fewer online resources are far more exposed, which is exactly where trust and safety teams have the least linguistic coverage.


Mark Zuckerberg published a 6,500-word manifesto Monday arguing the most common fears about AI are overblown — and that the real risk is one government or company holding too much control over it. The essay, excerpted as a Wall Street Journal op-ed, pushes back on the panic of the moment: models escaping their sandboxes, AI-designed viruses, and the wave of Washington pressure that same day — including Bernie Sanders' demand that Meta, OpenAI and Anthropic pause development, which we covered — Anthropic, Macquarie and GIC launch Theseus Infrastructure. Zuckerberg's answer to doomerism is distribution: billions of individually aligned personal agents and competing labs as checks and balances, with most compute pointed at human goals rather than a single centralized superintelligence. On jobs, he argues capability growth can keep pace with automation, so people gain new abilities before their current roles vanish. The take: it's the sharpest counter-narrative yet from the industry's most prominent optimist, and it frames the coming fight over AI governance as a choice between distributed abundance and concentrated power.


The FBI's terror watchlist office is shopping for predictive AI that would score people as threats before any crime occurs, according to procurement documents obtained by Reason. The bureau's Threat Screening Center posted a request for information in March seeking "Predictive Modeling Using Enhanced Data with Traceable Lineage" — software that would compare new information against existing records across federated government databases and predict where investigators should look next, just as the list's focus shifts from Islamist terrorism toward domestic dissent. The watchlist already holds roughly two million names, up from about 120,000 in 2003. The FBI declined to comment, and this is a procurement request, not a deployed system — but civil-liberties groups are already calling it pre-crime policing, pointing to the bias and false-positive risk of algorithmic threat scoring. The take: even at the request-for-information stage, this is the clearest signal yet that predictive surveillance is moving from research papers into federal procurement.

What to watch: whether the labs respond to Sanders publicly — and whether any vendor answers the FBI's call for predictive threat scoring.

If states can poison what chatbots learn, how do we decide which AI answers to trust? Tell us in the comments.

Read more

OpenAI's first Category 5 influence op targeted editors, not feeds

OpenAI's first Category 5 influence op targeted editors, not feeds

OpenAI banned two state-linked influence campaigns on October 8 — and the number worth sitting with is not the ban count but the rating attached to one of them: the first Category 5 operation the company has disrupted in two and a half years of publishing threat reports. The deeper signal, though, is in the fine print of what the models were actually used for. What happened OpenAI's report describes two operations it calls "false front" entities — shells that launder geopolitical messaging

The Take — OpenAI's $20B gap is definitional, and that's worse

The Take — OpenAI's $20B gap is definitional, and that's worse

The $20 billion never went missing from OpenAI's business — it was never in it. OpenAI's annualized revenue was always a number only OpenAI gets to define, and with a confidential 2027 IPO filing on record and a $1.2 trillion private round under consideration, I think a self-defined metric heading into underwriter season is worse than a number that was simply wrong. A wrong number gets corrected once; a self-defined number survives every headline it produces. Our afternoon brief on Wednesday l

OpenAI busts influence ops that planted fake stories in real media

OpenAI busts influence ops that planted fake stories in real media

The day's AI news runs through one seam: the work is showing up in places nobody planned for — inside real newsrooms, across the whole night sky, and in the M&A column. OpenAI has banned two state-backed influence operations that used ChatGPT to plant fabricated stories inside legitimate news outlets — and rated the Russian one the most disruptive it has seen in two and a half years. In a report dated October 8, OpenAI detailed "Dark Clark," run from Russia across Latin America, which ran a th

Open Source Radar — October 9: plugins, sandboxes, tokens

Open Source Radar — October 9: plugins, sandboxes, tokens

Today's open-source signal is infrastructure rather than hype: Microsoft's code sandbox reaches 1.0, Anthropic's knowledge-worker plugins keep climbing, a beloved token counter flips its default, and LocalLLaMA squeezes a usable 2B model into about 700 MB. knowledge-work-plugins (Python, ~27,900 stars, Apache-2.0) — Anthropic's repository of role-shaped plugins for Claude Cowork is the top AI repository on today's daily trending page, and the stars keep coming: roughly 2,100 more than when we