Security1 distinct publisher3 min readPublished
The operators told the model to strip clues pointing to their Russian origin. The tells that survived came from the pages ChatGPT never wrote.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
Instructing a model to hide linguistic clues is one line of a prompt, and prompt lines are free. The operators of this cluster told ChatGPT to conceal anything indicating their Russian provenance, and most of what they published came out in English [6]. Defensive attribution of text still leans on the residue a first language leaves behind: dropped articles, calqued idiom, the flatness of a machine-translated paragraph. That residue does appear in this case. It does not appear in anything the model wrote.
By OpenAI's account, articles on ibi.institute were copied from academic writing, in some cases with false attribution, while others seem to have been drafted by a Slavic speaker and then machine translated into English, and there is no evidence any of them came from ChatGPT [8]. The generated material was the promotional layer, the posts and comments pushed onto Substack, Telegram, X, Facebook and LinkedIn [2]. The half written by hand carried its origin. The half written by the model had that removed on request.
So the case was not made on the language of the output. OpenAI says the investigation started from AI-generated social media posts and widened into the website, the index and the effort to disguise the operators' origins [4]. The identifying material sits on the account side: VPNs used to get around access restrictions [1], a profile picture generated for a Telegram channel called American Observer, and repeated requests for Russian-language summaries of that channel's activity [13]. None of that is legible to anyone outside the model provider. An outside researcher working from the artifacts gets the version the operator configured.
The authority prop repays a close read, because people built it. The Burke, or Sovereignty, Index sums seven components (political, economic, technological, information, cultural, cognitive and military), each scored against a maximum of 100, for a cumulative total between 100 and 700 [10]. Russia scores 601.4, which places it fourth, behind the United States at 650.9, China at 649.1 and Switzerland at 610.7 [11][1]. An index that OpenAI assesses was created to project Russia favourably and criticise Western countries [9] leaves Russia 49.5 points short of the United States [2], while the accompanying country report calls it one of three world powers with full digital and military nuclear sovereignty [12]. That is calibration for plausibility rather than for a win, which is the same instinct as the de-tell prompt.
The ban costs the cluster its accounts. It does not cost it the domain registered in February 2025 [7], the self-described expert community based in Israel [3], the republished papers or the index. OpenAI's own reading is that the significance lay in the infrastructure rather than the audience, which peaked at Telegram channels of roughly 10,000 to 20,000 followers each [14][5], and it describes the model here as a supporting tool inside a broader effort to manufacture authority and obscure where narratives come from [15]. Model access was the replaceable component.
Ranked by verification strength, evidence, and original report placement.
OpenAI said on Tuesday it banned a cluster of Russian ChatGPT accounts that used VPNs to bypass access restrictions and run an influence operation, using the tool to generate social media posts and comments.
The generated posts and comments were shared on Substack, Telegram, X, Facebook and LinkedIn.
OpenAI said the accounts were being used to promote the International Burke Institute (IBI), a self-described 'expert community' based in Israel.
OpenAI said: 'What began as an investigation into AI-generated social media posts led us to a much broader influence operation, built around a website containing copied and misattributed academic work, a sovereignty index that cast Russia in a favourable light, and efforts to disguise the operators' Russian origins.'
The campaign is assessed to have reached relatively small audiences, with Telegram channels amassing about 10-20,000 followers each.
The majority of the generated content was in English, and the operators instructed ChatGPT to conceal any linguistic clues that could allude to their Russian provenance.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Detailed but single-source and vendor-originated
The account is specific and quotable - named front organization, domain and registration month, index methodology, country scores, concrete prompt behaviours - and the publisher independently describes the IBI website's content. But one publisher carries the story and every attribution claim rests on OpenAI's own investigation, with no corroborating researcher, platform or government assessment and no count of banned accounts or detection method.
Real enforcement, narrow reach
The action itself is concrete and dated - accounts banned, assets identified - but the abuse it addressed operated at small scale: Telegram channels of roughly 10,000-20,000 followers each, ChatGPT used for isolated promotional posts, an avatar and Russian-language summaries. No figures are given for account volume, post counts or downstream engagement, so measured adoption stays low.
Slightly overstated by framing, tempered by the vendor itself
The 'influence operation' framing runs ahead of the measured footprint - a handful of Telegram channels in the tens of thousands and isolated promotional posts - and the coverage does not note that the index built to flatter Russia in fact ranks Russia fourth, 49.5 points behind the U.S. Against that, OpenAI explicitly downplays reach and states there is no evidence the site's articles were AI-generated, which keeps the gap small rather than large.
Sole witness is also the enforcing vendor
OpenAI is simultaneously the investigator, the attributor, the enforcer and the publisher of the narrative, and threat-report disclosures serve its safety positioning; the emphasis on 'infrastructure' over measurable reach and the closing note that AI use exposed the operation both flatter that position. The publisher is an independent security outlet with no disclosed stake, but adds no counterweight sourcing.
Moderate: internally consistent, externally unchecked
Claims are internally consistent, richly specified and clearly attributed, and the publisher is a credible security outlet - but with one source, one originating party, no independent attribution check and no response from IBI or the named platforms, confidence in the wider interpretation stays middling even where the individual facts are well stated.
science
Text watermarks land on 2 December. The detection they imply does not.1 distinct publisher
invest
A Connecticut judge just priced prompt injection: no fine, no e-filing2 distinct publishers
product
OpenAI's plan to hand everyone a coding agent leaves the hard part to the model1 distinct publisher
product
A long press in ChatGPT is now the fastest visual assistant on an EU iPhone2 distinct publishers
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 26, 2026