What happened
OpenAI said this week that it banned a cluster of Russian ChatGPT accounts used to run an influence operation. The accounts relied on VPNs to get around access restrictions, and most of the content they produced was in English, with instructions to ChatGPT to hide any linguistic clues pointing to Russian origins.
The operation promoted the International Burke Institute, a self-described "expert community" based in Israel. OpenAI says what began as an investigation into AI-generated social media posts led to a much broader setup: a website carrying copied and misattributed academic work, a "sovereignty" index that cast Russia in a favorable light, and persistent efforts to disguise the operators' Russian provenance. One user also used ChatGPT to create a profile picture for a Telegram channel called "American Observer."
The campaign reached relatively small audiences, with the associated Telegram channels attracting roughly 10,000 to 20,000 followers each. OpenAI stressed that the actors only used ChatGPT for isolated promotional posts, but those posts pointed to an otherwise credible-appearing institution with purported experts, republished academic work and a purported proprietary risk index. The company described it as a demonstration of how influence actors use AI as a supporting tool to manufacture authority and obscure the source of favored narratives.
Why this is a GRC story
This is AI governance in the open. A platform found abuse, investigated it, disclosed it and shut it down, and published enough detail for defenders to learn from. That transparency is exactly what risk teams should expect from the AI vendors they rely on, and the episode is worth reading as a case study in how provider abuse reporting works.
The method matters as much as the actors. Building a think tank with a website, experts and a proprietary index is a playbook for manufacturing credibility, and it is not limited to AI. For organizations, this is a reminder that influence operations can target your brand, your customers and your sector, and that reputation risk from disinformation deserves a place in the risk register.
What to watch
Expect the group to adapt. Account bans displace operations rather than eliminate them, so the same institution or index may resurface under new channels. OpenAI publishes threat research on these disruptions, and those reports are a practical input for security awareness and disinformation playbooks.
For GRC teams the durable takeaway is to ask your AI vendors how they detect, investigate and disclose abuse of their platforms. The answer tells you a lot about how safe your own use of those tools is, and how quickly you would learn if someone tried to abuse them in your name.
Attribution: Analysis based on The Hacker News' reporting and related public reporting. This article is original commentary, not a repost of the source material.
