Production, Persuasion, and Power: How Generative and Agentic AI Are Transforming Influence Operations
Iranian state propagandists have been using Claude to draft the doctrine for their influence campaigns—and to plan the Supreme Leader’s funeral. Russia’s state media has found novel uses for it too: A former Sputnik Moldova editor-in-chief used it to churn out articles and push fabricated claims about Moldova’s president ahead of the country’s 2025 election. And a staffer at a Russian state media outlet had it writing on-air chyrons.
China-linked operators, meanwhile, have been using American artificial intelligence (AI) to meddle in the American debate about AI. In June, OpenAI reported that accounts likely run by a Chinese tech contractor had falsely claimed that ChatGPT had leaked its users’ data. Another cluster used ChatGPT to generate political cartoons blaming data centers for Americans’ rising electric bills. The operators were exploiting a real American debate; the foreign presence nevertheless prompted Republican members of Congress to demand Department of Justice investigations and the State Department to weigh in.
But have these efforts accomplished their goals?
Read the threat reports released by frontier AI companies and social media platforms, and a clearer picture emerges of how generative and agentic AI are changing foreign influence operations. The most obvious change is in production: Actors linked to Iran, Russia, China, and other states, along with commercial firms selling influence as a service, are using AI to write and translate propaganda, create personas, mimic target audiences, and produce content at scale. But that is only part of what the reports describe. AI is also being used for coding, reconnaissance, intelligence processing, and workflow automation. One operator can now do more jobs. Work can continue overnight. Coordination can move from human handoffs to software. There’s been a significant shift in administrative processes.
Yet the harder question, the reports make clear, is persuasion. AI can make an influence apparatus cheaper, faster, and more persistent, but it cannot manufacture trusted distributors. There is now abundant evidence that AI is increasing capacity, but much less evidence that AI-generated influence operations are actually changing public opinion.
Production
State-linked actors have been early adopters of AI technology; they adopted AI-generated profile pictures produced via generative adversarial networks early on and have demonstrably incorporated new tools since. A troll farm benefits from the same productivity gains that AI offers a small business: more output, at lower cost. For trolls, the quality often increases as well. More content, with fewer telltale mistakes. No botching African American Vernacular English when pretending to be Black Americans on X. No forgetting what persona you’re supposed to be in a given moment, or what that persona has said previously. No getting caught because you plagiarized an entire article for a front-media site.
So it is no surprise that Iran, Russia, and China—repeat offenders in platform takedown reports—are now recurring characters in frontier company disclosures on adversarial abuse of their AI tools.
But the most interesting aspect of the disclosures is that the operational efficiency extends far beyond the content production shifts that researchers predicted early on. What these reports show is administrative transformation. Models are taking over the back office: audience research, timing strategies, data processing, and control software. The Chinese operators behind the manipulative data center campaign had ChatGPT write code to automate logins across platforms.
One of the most persistent ways of minimizing Russian interference, and particularly the Internet Research Agency (IRA) 2015-2017 operation targeting the American public, is to describe that effort as “only $100,000 in Facebook ads.” That number is real, but the implication is not. By September 2016, according to a Justice Department indictment, the troll factory’s monthly budget for what it called “Project Lakhta” exceeded $1.25 million. Trolls visited the United States to study their targets. They held stand-ups to review their organic engagement and pivoted accounts that underperformed with American target audiences. Before “Army of Jesus” was rebranded into a successful Christian meme account—most notable for a visual of Satan-Hillary fighting Jesus—it had been a Kermit the Frog meme page.
AI can significantly reduce the overhead of that work, and reports show it’s happening. Iranian propaganda institutions had Claude produce doctrine manuals and ministerial planning documents that, in Anthropic’s assessment, would otherwise have required a fully staffed program office. In the Central African Republic, a local coordinator for Politology, the Wagner Group influence arm (now assessed to be under the control of Russia’s foreign intelligence service), used Claude to manage the staff of a Wagner-founded radio station. The coordinator had it write contracts pledging loyalty to “Russia and its contingent,” score reporters’ articles against a rubric, and recommend whom to fire. The IRA’s stand-up meeting has become a prompt.
There are both efficiency gains and capacity gains. AI now appears to be doing four kinds of work in these operations. Two are familiar: generation, where models produce the content, and operational support, such as background research or maintaining personal databases. But observers are also now seeing workflow orchestration and the beginnings of autonomous execution. To put it concisely: Generative AI scales content. Agentic AI scales operations.
A French advertising agency, LKM Company, built a pipeline in which every prompt demanded a specific form of text output, exact character counts, and three to four internal links for search ranking. The output flowed straight into roughly 70 fake local news sites. Operators aligned with the Iranian opposition group MEK went further. They ran a shared AI agent whose memory files held banned words, approved sources, and detection-evasion rules, so it kept producing content without a human directing each session. Anthropic notes that the operators using it never needed to coordinate with—or even know—one another; one was building a course to teach the workflow to others; some of the coordination that traditionally occurs among human operators was being embedded in the system itself. That matters for platforms, whose detection systems have long looked for accounts coordinating with each other.
The reports also describe increasingly autonomous cyber operations—perhaps the biggest capacity transformation. Google describes Russian, Iranian, and North Korean groups using Gemini across cyber intrusion efforts, from password-spraying scripts to multilingual phishing lures. Anthropic describes a Russia-linked actor using agents to monitor whether security products had detected its malware; when they did, the agents modified and rebuilt it until it slipped through again. This is a remarkable feedback loop: AI enables a system to observe a defender’s response, change its behavior, and try again without waiting for a human operator. Historically, detection forced attackers to retool, imposing costs and slowing their operational tempo. Anthropic argues that AI may reverse that dynamic: an agent can detect the defender’s response, rebuild the malware, and try again faster than defenders can develop and deploy new means of detection. Its report also argues that sophistication is becoming a less reliable signal of who is behind an operation: One case study describes a French-speaking operator using stolen API keys to sustain activity that, Anthropic says, would previously have required a team.
That matters for influence operations because cyber collection and influence have never been fully separate. The Russian Main Intelligence Directorate (GRU)’s theft and release of Democratic Party emails in 2016 arguably did far more to shift the national conversation than the IRA’s troll activity. In Anthropic’s report, the Russia-linked actor took over the WhatsApp accounts of at least two former senior Ukrainian officials and quietly exported their conversations—rich fodder for a hack-and-leak operation.
Persuasion
Production capacity is only the first hurdle. An operation still has to solve two different problems: distribution—getting a message in front of people—and effect—getting them to do, believe, discuss, or amplify that message.
The 2016 email leaks mattered primarily because American newsrooms covered them.
The GRU had the documents; the American press had the audience. A Russian state-media operation such as RT has both: Per the recent AI company disclosures, it is using large language models to make its existing newsroom faster. Anthropic describes a staffer at a Russian state outlet turning wire copy and Defense Ministry claims into on-air tickers and voiceover scripts for RT’s English broadcast, and at least one such script made it to air. This content is distinct from several of the other operations because it is reaching an existing audience, not just falling into a void.
Indeed, the widest authentic reach Anthropic observed came where operators could plug AI-generated content into existing state-media distribution. It ran daily on a Wagner-founded FM radio station in the Central African Republic, with preexisting listeners. By contrast, another incident in Anthropic’s report described a French ad agency’s network: Approximately 70 fake news sites published nearly 9,000 articles in about 20 languages, and drew almost no real engagement. Similarly, OpenAI rated both of its China-linked campaigns “Category One” on the influence operations breakout scale, meaning neither spread beyond its own accounts.
Distribution has always been a limiting factor in propaganda. Attention is very hard to capture, and trust takes years to earn. This is why Russia-linked actors moved from trying to build up fake personas to simply hiring established (but unwitting) influencers such as Tim Pool and Benny Johnson. There are useful idiots willing to say things for money, and many already have plenty of fans.
The AI campaign operators recognize this challenge. The Chinese team behind the data center campaign wrote an internal plan for Facebook built around slowly cultivating “real, trustworthy” everyday personas, backed by ad spend and backup accounts. When trust can’t be built, they try to borrow it: The same team posed as Chinese immigrants in the U.S. to lobby a real YouTuber to air a former Chinese police officer’s criticisms of America. MEK operators had an AI agent study about 8,400 of a real activist’s Telegram posts, then hold live conversations masquerading as him with his contacts inside Iran. An operation linked to United Arab Emirates (UAE) officials quietly funded a network of about 300 influencer accounts; its internal reports described the network’s appearance of independence as its greatest strategic asset.
Roughly speaking, frontier companies now have unique visibility into content creation while social media companies have better visibility into distribution. Anthropic says as much in its report: It often catches an operation while it’s still being built, but its visibility is limited once the operation goes live. An AI provider can see hundreds of prompts and a sophisticated production workflow, while a social platform may see that the resulting accounts failed to generate authentic reactions. Creation, distribution, and effect are analytically distinct: Evidence that an operation can produce enormous amounts of content tells us little about whether anyone saw it, and reach alone tells us little about whether it affected an audience.
Only by reading across both sets of inauthentic activity reports can observers distinguish increased capacity from actual reach; assessing downstream effect remains the social science research challenge it has always been. Researchers who dug into the Chinese data center campaign announced by X found that the accounts got essentially no reach or engagement. Despite the congressional Justice Department investigation demand, it’s hard to argue that they were in any way persuasive.
Persuasion implies that a message is capable of changing belief or behavior. Can models be persuasive? In controlled settings, it seems, yes. Last December, a pair of studies in Nature and Science showed that multi-turn conversations with large language models can shift people’s attitudes toward political candidates and policy issues. But those experiments put a person directly into a sustained conversation with a chatbot. That is a different problem from getting a sockpuppet’s post noticed in a crowded feed. And influence operations also pursue activation, agenda-setting, or intimidation; an operation can therefore achieve something politically consequential without measurably changing anyone’s underlying beliefs.
Some of the activities these reports describe can have impact without a mass audience. The UAE-linked operation that Anthropic described borrowed the identity of a real Sudanese human rights organization. It ghost-wrote testimony for two people to deliver at the UN Human Rights Council as independent witnesses, engineered to be favorable to the UAE. It also compiled dossiers on the UN Special Rapporteurs who had criticized the Emirates’ conduct in Sudan. Influence and surveillance increasingly run on the same tools: The Russian operation in the Central African Republic tracked opposition figures, and the MEK network profiled Iranians inside the country by their arrest histories.
Power
The ultimate objective of these efforts is not to produce propaganda. It’s to maximize power. Sophisticated and well-resourced actors have long run influence operations spanning the whole media spectrum: broadcast, social, overt, covert. A state that can sustain more operations across more targets with less staff time has gained capacity, even if many of its attempts go nowhere. It can afford to keep trying. Whether that produces a political advantage is a further question.
As production gets cheaper, the relative value of what AI can’t manufacture rises: established accounts, credible intermediaries, and names people already trust. As AI creates abundance in content production, the resulting scarcity is in attention, distribution, trust, and authentic identity. Fabricated bios and backstories are now trivial to generate. The harder problem is convincing an increasingly skeptical audience to trust them. Expect operators to increasingly buy, rent, and impersonate real identities rather than build fake ones.
If the U.S. were serious about tackling foreign interference, government leaders across the political spectrum would be encouraging—if not mandating—transparency reports spanning the chain from creation to distribution, and ensuring outside researchers had access to the data underlying platform disclosure. Instead, things have gone in the other direction: Major social platforms have shifted away from regular disclosure. Meta now reports semiannually. X’s first inauthentic-network disclosure in two years was a single tweet about its takedown of Chinese accounts linked to data center discourse manipulation—posted three months after OpenAI exposed the effort. What the public should want to see instead is interindustry sharing. Several frontier companies now publish detailed reports, and they are beginning to share with one another; Anthropic found a domestic astroturfing operation in Kenya after a tip from OpenAI.
The Iranian propagandists who had Claude draft their doctrine sought “not to be the narrator, but the director.” AI has made directing easier and cheaper. But at the moment, based on what researchers and the public can see, there is little evidence that it has made audiences easier to reach—or persuade.
