Russian propaganda is poisoning AI chatbots, report finds

Share
Russian propaganda is poisoning AI chatbots, report finds

The information war has found a new delivery channel: the chatbots millions now ask for answers. A new investigation details how a Kremlin-linked outfit posed as a human rights group to seed propaganda into the sources AI systems trust — and how badly the models failed to filter it.

A Kremlin-linked unit that poses as a human rights organization has been manipulating ChatGPT and its rivals, opening a new front in the misinformation war — and in Russian-language tests, chatbots repeated the propaganda in up to 86 percent of cases, according to the investigation shared widely Monday. The operation works by flooding the web with seemingly credible, pro-Kremlin content designed to be absorbed into training data and retrieval systems, a tactic researchers call "data poisoning" or "LLM grooming." Both major AI labs' models broke under the tests, per the reporting. The findings land alongside a body of evidence that the attack surface is real: Bloomberg's investigation into the SDA network documented more than 40 sites built to inject Russian narratives into what chatbots and search engines rely on, NewsGuard's regular testing finds the most popular chatbots repeat circulating falsehoods in more than a quarter of cases, and an arXiv analysis of the Moscow-based "Pravda" network counted roughly 150 domains publishing millions of articles a year to contaminate model outputs. The take: the weak point isn't the model's reasoning — it's the hygiene of the sources it learns from, and that's a problem no amount of alignment work alone will fix. English-language models resist better; models in languages with fewer online resources are far more exposed, which is exactly where trust and safety teams have the least linguistic coverage.


Mark Zuckerberg published a 6,500-word manifesto Monday arguing the most common fears about AI are overblown — and that the real risk is one government or company holding too much control over it. The essay, excerpted as a Wall Street Journal op-ed, pushes back on the panic of the moment: models escaping their sandboxes, AI-designed viruses, and the wave of Washington pressure that same day — including Bernie Sanders' demand that Meta, OpenAI and Anthropic pause development, which we covered — Anthropic, Macquarie and GIC launch Theseus Infrastructure. Zuckerberg's answer to doomerism is distribution: billions of individually aligned personal agents and competing labs as checks and balances, with most compute pointed at human goals rather than a single centralized superintelligence. On jobs, he argues capability growth can keep pace with automation, so people gain new abilities before their current roles vanish. The take: it's the sharpest counter-narrative yet from the industry's most prominent optimist, and it frames the coming fight over AI governance as a choice between distributed abundance and concentrated power.


The FBI's terror watchlist office is shopping for predictive AI that would score people as threats before any crime occurs, according to procurement documents obtained by Reason. The bureau's Threat Screening Center posted a request for information in March seeking "Predictive Modeling Using Enhanced Data with Traceable Lineage" — software that would compare new information against existing records across federated government databases and predict where investigators should look next, just as the list's focus shifts from Islamist terrorism toward domestic dissent. The watchlist already holds roughly two million names, up from about 120,000 in 2003. The FBI declined to comment, and this is a procurement request, not a deployed system — but civil-liberties groups are already calling it pre-crime policing, pointing to the bias and false-positive risk of algorithmic threat scoring. The take: even at the request-for-information stage, this is the clearest signal yet that predictive surveillance is moving from research papers into federal procurement.

What to watch: whether the labs respond to Sanders publicly — and whether any vendor answers the FBI's call for predictive threat scoring.

If states can poison what chatbots learn, how do we decide which AI answers to trust? Tell us in the comments.

Sources: r/OpenAI discussion · r/technology discussion · The Ukrainian Week · Cybersecurity Insiders — Demos research · InfoOpsBench (arXiv) · Axios — Zuckerberg manifesto · The Hill — Zuckerberg · AOL — WSJ excerpt · Reason — FBI watch list · CBS News via Yahoo — FBI predictive AI