OpenAI bans Iranian and Russian networks that placed bylined articles in real publications
A report published Thursday describes seven invented Iranian “journalists” pitching long-form pieces to small outlets, and a Russian front posing as a Latin American think tank. The company’s own hedges are already falling out of the coverage.
OpenAI published a threat report on 8 October titled “Disrupting AI-enabled ‘false front' operations,” disclosing bans on two clusters of ChatGPT accounts: one Russia-origin, nicknamed Dark Clark, and one Iran-origin. “Using the IO Breakout Scale, which rates IO on a scale of 1 (lowest) to 6 (highest), we would assess the Russia-origin operation as belonging in Category 5,” the report states. “This is the first Category 5 operation we’ve disrupted since we began our reporting. The Iran-origin operation reached Category 4. Both managed to land their content (not all of which was generated from our models) in mainstream media outlets, rather than simply posting it on social media.” Quoted by The Hill, the company describes “a stable of seven ‘journalist' personas which it used to pitch long-form articles to small and medium online outlets around the world,” while the Russian operation “appears to have co-opted unwitting people in Latin America to run a ‘think tank' on the ground.”
The quantities circulating in coverage reach us through aggregators rather than OpenAI’s document. A summary at yellow.com puts the Iranian placements at almost 100 articles published or syndicated under the seven bylines across roughly a dozen outlets, with the earliest dated July 2025 and the latest October 2026 — a fifteen-month run before disclosure. The same summary reports both clusters reached ChatGPT through VPNs, that OpenAI attributed neither campaign to a specific government agency, and that it assessed the Iranian activity as resembling a commercial, for-hire operation. Two further aggregator write-ups, at cellcog.ai and resultsense, agree on the model’s actual role: the Russian operators used ChatGPT mainly to draft progress reports for an unnamed superior, the Iranian operators to polish drafts, write pitch emails and generate comments. That is consistent with OpenAI’s own parenthesis.
No publisher has been named in anything we retrieved. OpenAI says roughly a dozen outlets; the Washington Post’s piece of 9 October carries the headline “A Florida local newspaper ran an op-ed. It was an Iranian AI fake,” which would be the first concrete placement, though we have the headline and URL only and not the body. CNN ran the story on 8 October as “Iranian operatives used AI to plant fake stories in multiple US media outlets.” Iran International reported on 9 October that the campaign targeted Iran International itself alongside foreign media — a claim we have not been able to examine, and one made by an outlet that is both a subject of the alleged operation and a party to the wider dispute. On the Russian side, The Hill and resultsense describe a front called the Social Research Center, run through a persona named “Mia Clark,” publishing more than sixty mostly original articles aimed at Ukraine’s reputation and at politics in Argentina, Bolivia and Ecuador.
Assessment: The headline number is a self-rating. OpenAI assigned Category 5 on a scale it did not author, to an operation it discovered and banned, with no external audit of either the placements or the scoring. Treat it as a company’s internal severity judgement, not a finding. Two things are already being lost: the company declined to attribute either cluster to a state agency and read the Iranian one as for-hire work, and it said plainly that not all the published content came from its models. “Iranian operatives used AI” compresses both away. The mechanism here is not synthetic text; it is pitch emails that small editors accepted. Those editors, not the chatbot, are the control that failed, and so far they are not the subject of anyone’s reporting.