OpenAI says it shut down Russian and Iranian ChatGPT networks built to fake journalists and seed anti-Ukraine copy
The company disclosed on 8 October 2026 that Russian and Iranian operations had used its chatbot to manufacture fake journalist personas and, in the Russian case, to backstop a purported think tank pushing anti-Ukraine content into US and international outlets.

OpenAI on Thursday 8 October 2026 said it had terminated ChatGPT accounts tied to Russian and Iranian influence operations, disclosing that the networks used its models to create fake journalist personas and, in the Russian case, to backstop a purported think tank pushing anti-Ukraine content. France 24 reported the action at 23:42 UTC on 8 October 2026, the same day the disclosure landed in reporters' inboxes. The available thread evidence does not include OpenAI's full report or specify whether the company held a separate press briefing; this article treats the disclosure as defined by the wire coverage of it.
What is new is not that generative AI has been used to launder foreign messaging. What is new is the level of operational detail a major lab is now willing to publish about who was running the accounts, what those accounts were for, and which downstream venues the content was aimed at. The shift turns a recurring story about bots into a recurring story about disclosure hygiene, where the question is no longer whether the platforms see the operation, but how much of what they see they choose to put on the record.
How the two networks were wired
The wire coverage separates the two operations cleanly and that separation is the load-bearing fact in the disclosure. France 24 reported the Iranian operation ran seven profiles posing as Western journalists in an attempt to place lengthy articles in media outlets worldwide, using ChatGPT to draft long-form social posts and maintain those synthetic bylines. France 24's framing of the Russian operation is distinct: Russian operatives used the chatbot to support a purported think tank spreading anti-Ukraine propaganda. NPR's 8 October 2026 write-up added a second Russian detail, that Russian operatives used the chatbot to update their bosses, a use of the tool that the available report framing reads as a coordination function rather than a content-minting one.
That distinction matters for what gets caught and what gets logged. A network that uses AI to generate posts produces an output stream a defender has to scrub downstream. A network that uses AI to coordinate itself produces a paper trail, and the accounts that briefed the people running the operation appear to have been doing so through a tool that keeps logs. Monexus assessment: the implication reads as a structural advantage for the defending platform; the tradecraft disclosed here gives an investigator a much cleaner handle than a takedown of finished propagandistic posts would. The same disclosure splits the two networks by tradecraft, the Iranian operation generating copy under fake bylines, the Russian operation using the lab's product both to seed a think-tank front and to brief its own operators, and that split is the part of the story with the longest half-life.
What got placed, and where
OpenAI's disclosure names the destination, not just the source. France 24 reported the Russian network placed regime-friendly content into US and international news outlets via a purported think tank. The Iranian network's seven fake journalist personas were aimed at media outlets worldwide. The available thread evidence does not specify which outlets accepted copy, how many stories were placed, or whether the placements were paid, syndicated, or accepted in good faith. A Russia-aligned channel, rnintel, summarised the disclosure in the same terms: that Russian and Iranian influence operations used ChatGPT to place regime-friendly content in US and international news outlets.
That gap is worth marking. A takedown that names the operators but not the venues is a takedown that leaves the venues to find out for themselves. The Russian-aligned and Iranian-aligned channels that distributed the news treated it as confirmation of a long-running claim: that the major Western AI lab is, in practice, an arm of US foreign-policy information warfare. Russia-aligned channel Intelslava reposted the story in the early UTC hours of 9 October 2026 (01:34 UTC); rnintel reposted France 24's wire on 8 October 2026 at 23:54 UTC, before the calendar turned. The Western-wire treatment (NPR, France 24) treated the same disclosure as evidence that the threat model has moved from botnets to language models. Both frames are doing work; neither is the whole story.
What the disclosure is really for
Read as a corporate document, the OpenAI report is a threat-model update. Read as a press release, it is a product statement. Read as raw intelligence, the report confirms that a state-adjacent foreign operation has used a major US AI product for both content production and operator coordination. Monexus assessment: the disclosure also functions as a stress test of the platforms that distributed the propaganda. If a fake journalist persona published a piece in a real outlet in 2025, that outlet is now on notice that the byline is a question the newsroom has to answer. The available source items do not specify how many real outlets accepted copy from these personas, or whether any of those outlets have since retracted. That ledger is the one that matters next, and it is the one the company is not going to write for the press.
What stays contested
Three things are genuinely unresolved in the available thread evidence. First, scale. OpenAI has named the operations and the tradecraft, but the available coverage does not specify how many personas were active beyond the Iranian network's seven, how many outlets were successfully targeted, or how much of the content can be attributed to a single sponsor state versus a freelance influence-for-hire shop. Second, the chain of custody. Russia and Iran are named because OpenAI named them. The unmediated link from a server in Moscow or Tehran to a byline in a Western outlet is the part that gets asserted in the disclosure, not the part that gets shown in the wires. Third, what the briefing contained. The available source items describe the disclosure as the company saying it shut the networks down, but the thread does not contain OpenAI's full threat report, and this article has not independently established its full contents.
The contested part is also the small part. The thing that is not in dispute is that the accounts existed, that the personas existed, and that a major AI lab has now published enough operational detail to put every platform team in the industry on notice. Whether that footing holds is the test for the next quarter, not the last one.
Desk note: Monexus read this as a platform-governance disclosure, with the newsrooms that received the copy as the second-order subject. Where the available thread evidence did not specify a number, outlet, or institutional detail, the article said so in prose rather than filling the gap from inference.
Wire provenance
This editorial synthesis draws on the following public wire/social posts:
- https://www.france24.com/en/technology/20261008-openai-bans-russian-iranian-chatgpt-propaganda-networks
- https://www.npr.org/2026/10/08/nx-s1-5995576/openai-russia-iran-influence-operations-chatgpt
- https://t.me/intelslava/95961
- https://t.me/france24_en/18916
- https://t.me/rnintel/67472
Follow the event.
These dated source records provide context. They do not retrospectively verify this archive article.
A dated voting record is evidence of one decision. Use the original UN record before turning it into an alignment label.
Visual explainer · historical vote of 2022-03-02 →