Machine translation · the Chinese original is authoritative · View original

Full OpenAI Report: Influence Operations Linked to the People's Republic of China Are Targeting AI Debates in the United States

1# · OP Author:張無忌 Published:2026-06-12 03:45 Replies:0 Views:6 Permalink:fanzei.net/d_22246k

June 2026 Threat Report

Introduction

Our mission is to ensure that artificial general intelligence benefits all of humanity. We advance this mission by deploying our own innovations, building democratic AI: an AI shaped by democratic principles, governed by common-sense rules, and designed to help people solve difficult problems while protecting them from real-world harm.

This mission also requires us to identify and combat attempts by authoritarian regimes and their proxies to use AI systems to coerce critics, surveil communities, or covertly interfere in democratic societies.

In this report, we describe two clusters of ChatGPT accounts that likely originated in China. We have banned these accounts because they used our models to support suspected covert influence operations, attempting to manipulate legitimate debate in the United States regarding AI and broader technology policy by promoting specific narratives.

The first cluster generated social media comments and images claiming that AI data center construction is driving up electricity prices for ordinary households. We named this cluster Operation "Data Center Free Rider."

The second cluster generated comments and images criticizing U.S. tariff policies, claiming that U.S. tariffs are an attempt to dominate technological competition. Its prompt explicitly requested that the output content must not include Chinese leader Xi Jinping, but should only include President Trump. This cluster is linked to a suspected inauthentic social media account network; the network may also have targeted OpenAI, claiming that ChatGPT user data has been leaked. These allegations are completely false. We named this second cluster Operation "Tech and Tariffs."

Operations targeting OpenAI and U.S. data center construction are significant not because the operation appeared to change public opinion, but because it shows that influence operators originating from the People's Republic of China are testing narratives targeting AI infrastructure. AI infrastructure is the foundation of U.S. technological leadership, economic growth, and the broader democratic AI ecosystem.

This operation attempted to exploit and amplify pre-existing public concerns, including energy prices and the impact of data center development on local communities. However, we found no evidence that its activity broke out of its own dissemination scope and formed substantive impact. Foreign influence operations have long attached themselves to existing local issues and sincerely held beliefs of people in order to build credibility, amplify division, or exacerbate public distrust. In this case, the operators attempted to hide their identity and motives, secretly intervening in an ongoing U.S. discussion about the future of national AI capabilities.

We are publishing these findings to help industry, government, civil society, and the public better identify and combat attempts by foreign threat actors to manipulate legitimate public discourse, undermine democratic institutions, and promote "totalitarianism with AI characteristics." Totalitarianism with AI characteristics refers to the use of AI for surveillance, censorship, and control over political, social, and private life.


Operation "Data Center Free Rider"

A network originating from the People's Republic of China is conducting covert influence operations against U.S. data center construction and targeting overseas Chinese.

Actors

We banned a cluster of ChatGPT accounts. This cluster likely originated in China and used ChatGPT to generate social media content for a covert influence operation. They used Simplified Chinese to prompt ChatGPT while repeatedly requesting outputs in English and Chinese, impersonating Americans of various backgrounds, and publishing the generated content across multiple social media platforms.

Since we do not allow access to our models from China, they used VPNs to access our platform.

The operators of these accounts likely belong to the social media operations team of a Chinese private technology company that provides services to Chinese provincial government clients. Such activities appear to align with a commercial ecosystem supporting party-state public opinion guidance priorities. Another report they uploaded to ChatGPT described their goals and strategies for influencing public opinion, establishing social media accounts, and evading platform detection systems.

Behavior

The accounts we banned attempted to influence two types of audiences.

Its primary target was the U.S. audience. They generated short English comments and images claiming that data centers and AI applications are increasing electricity demand and causing ordinary Americans to bear higher costs.

For example, based on reports from a legitimate regional newspaper, they requested the generation of cartoons about grid operator capacity auction prices. They asked ChatGPT to focus commentary on capacity price increases and interpret them as a result of rising peak electricity demand; at the same time describing the new demand as coming from data centers and AI applications, and claiming that these costs would ultimately be passed on to ordinary households. These comments and images were published on X by a group of suspected inauthentic accounts, accompanied by links to legitimate news reports concerning grid operator capacity auctions and data center electricity demand.

These AI-generated contents used hashtags such as #capacityauction, #datacentersuccess, and #datacenters when posted on X. They also used ChatGPT to edit images, adding text to general electricity market stock photos to support the narrative that "ordinary people are subsidizing AI infrastructure."

The second target audience was overseas Chinese, which is consistent with the cluster's apparent role in supporting Chinese government priorities. They gathered public information about Chinese dissident Li Ying, also known as "Teacher Li," and asked ChatGPT to generate abusive short comments targeting the X account of his team, @whyyoutouzhele.

In our previous threat report, we noted that Li Ying had been targeted by similar online harassment involving individuals connected to Chinese law enforcement. In this case, our model refused to generate inflammatory content or personal attacks against Li Ying. Other Chinese political commentators they attempted to harass include Lu Yiheng, Xu Chi, and the X account @SydneyDaddy1.

A notable tactic was that the actor attempted to online impersonate Chinese immigrants, workers, students, mothers, employees, and investors living in the United States, with the goal of encouraging American society to criticize a former Chinese police officer living in the United States to expose the "dark side" of America. These actors asked ChatGPT to generate messages sent to a YouTuber, encouraging this former police officer to talk about U.S. policy failures. This appears to be a new tactic: using fabricated U.S. domestic and Chinese immigrant identities to encourage an influencer to produce content criticizing the United States.

In addition to generating social media content, these accounts also used ChatGPT to assist in automating and scaling their workflows. This included requesting code to automatically log in and manage interactions across multiple social media platforms. They also used ChatGPT as a text processing tool to extract usernames, add X or YouTube link prefixes, remove hyperlinks, and format data into spreadsheets.

Platform Operations

These accounts asked ChatGPT to generate, polish, and edit work reports. These reports exposed their operational security considerations in social media activities and their understanding of platform detection systems.

Their stated goals included: establishing durable and credible accounts; producing visually attractive content to expand audience reach in target areas; and maintaining the long-term availability of accounts by anticipating platform enforcement measures.

One report focused specifically on Facebook operations, emphasizing the establishment of authentic, credible, daily-life personas; creating initial account branding using lifestyle, current events, commentary, and professional content; and amplifying narratives through interaction between accounts while maintaining the appearance of natural interaction. This showed they adopted more sophisticated workflows to maintain a long-term presence on U.S. social media platforms and used AI to support operational planning for such actions.

The same report showed they conducted extensive analysis of the Facebook platform to increase reach and reduce the risk of disruption. They discussed how to leverage Facebook's content ecosystem, groups, pages, hashtags, advertising tools, recommendation systems, and reporting mechanisms to gradually build influence and reach new audiences. They described this as a dual-track approach combining organic interaction with Facebook advertising, underpinned by iterative testing of topics, formats, and audiences. They also emphasized account security, creating backup accounts, and isolating account operational activities from each other to avoid platform detection of coordinated behavior.


Operation "Tech and Tariffs"

A network originating from the People's Republic of China is criticizing U.S. technological dominance and smearing OpenAI.

Actors

We banned a cluster of ChatGPT accounts. This cluster likely originated in China and used our models to generate short comments and political cartoons criticizing U.S. technology and tariff policies, while editing work reports and assisting users in designing social media

surveillance system.

These accounts used Simplified Chinese to prompt ChatGPT and accessed our platform using a VPN.

Their prompts repeatedly used terminology consistent with personnel affiliated with the Chinese public security system, such as requesting public opinion risk assessments regarding protests, campus bullying incidents, crowd flows in Shanghai, police-related incidents, petition activities, and traffic law enforcement.

One of the users described the social media accounts they operated as a "water army" ("水军" is a commonly used Chinese term referring to coordinated networks of online accounts that flood platforms with criticism or harassment). The user also instructed ChatGPT to generate content that favored the People's Republic of China or promoted pro-People's Republic of China narratives.

Taken together, these indicators suggest that these accounts were likely supporting activities aligned with the interests of the Chinese Communist Party. However, we cannot determine the specific organizational affiliation of the operators.

Additionally, we identified a network of accounts targeting OpenAI on the X platform, which spread false claims alleging that ChatGPT user data had been compromised. Based on open-source behavioral indicators, we assess that this activity likely belongs to the same X network identified in this operation.

Behavior

This cluster primarily used ChatGPT to generate short English comments and cartoon images, which were posted by suspected inauthentic X accounts.

The most prominent theme was U.S.-China technological competition. The operators shaped this competitive narrative around tariffs, rare earths, AI, 5G, new energy, and industrial resilience, claiming that the United States was pursuing technological dominance and rule-making power. They explicitly requested that the cartoons only depict President Trump, and should not include any imagery of China or Chinese leader Xi Jinping.

Furthermore, they also generated a large volume of short Chinese comments and articles on a wide range of topics aimed at supporting the People's Republic of China, attacking the United States and Israel, amplifying antisemitic narratives such as "Jewish capital manipulates public opinion," and harassing Chinese dissidents. They frequently requested the generation of specific batches of comments with word count limits and colloquial tones.

They also asked ChatGPT to propose a concept for an AI system used for monitoring online public opinion. They described that the system should be able to automatically scrape "harmful" information posted by individuals they defined as "key personnel" on social media platforms, save logs, automatically download videos for large-scale semantic analysis, and send risk notifications.

Our model generated a general output of approximately 500 words providing advice on data storage and management, but did not provide a scheme for how to collect data for surveillance purposes.

Platform Operations

This operation had a global mandate, attempting to influence international audiences. They focused on generating content critical of the United States, claiming that the U.S. pursues isolationism and hegemony, and accusing the U.S. of prioritizing profit over morality and backstabbing its allies.

In addition to English, they also asked ChatGPT to generate Italian, Japanese, and Traditional Chinese content to target Taiwanese audiences.

Based on account interaction patterns, the suspected inauthentic X accounts publishing content generated by this operation appeared to be connected to a broader network attempting to smear OpenAI.

Beginning in late 2025, we identified a batch of suspected inauthentic X accounts. These accounts published varying versions of claims asserting that their ChatGPT user data had been compromised and claiming that their lives had been negatively impacted as a result. These accounts did not appear to publish text generated by our model. However, they repeatedly interacted with and amplified the content of the X accounts we identified in the "Technology and Tariffs" operation.

First, a ChatGPT account identified in the "Technology and Tariffs" cluster generated a post alleging that U.S. intelligence agencies had hacked into mobile networks. This post was subsequently reposted by suspected inauthentic X accounts in the "ChatGPT Leak" cluster.

On another occasion, accounts from the "ChatGPT Leak" cluster and the "Technology and Tariffs" cluster quoted and reposted the exact same tweet from the same unrelated verified X account within a few hours. Furthermore, our checks revealed that all accounts quoting the post did not appear to be normal authentic accounts, indicating that they likely belonged to a coordinated operation. All of these accounts were created in late 2025, had few or no followers, posted only a small number of posts during the "ChatGPT Leak" operation, and appeared to have been independently suspended by the X platform rather than based on our assessment.

Notably, this operation also showed partial content overlap with a previously identified covert influence operation originating from the People's Republic of China. The X account shown above that posted ChatGPT-generated cartoons of Trump had also previously posted images concerning Philippine President Ferdinand Marcos Jr. These images had previously been shared by inauthentic X accounts associated with the "Nine-Dash Line" operation, which we discussed in our October 2025 Threat Report on Countering Malicious Use of AI.

This evidence is insufficient to conclusively determine a link between the two operations, but it reinforces the impression of an active network on X amplifying influence operations originating from China.

Impact

Using the "breaking containment" criteria, we assessed this activity as Tier 1: activity was confined to a single platform with no evidence of breaking out of its distribution sphere. Most of the social media posts we identified had little to no observable engagement. We found no evidence that the false claims regarding ChatGPT user data breaches were amplified by authentic high-impact accounts or spread beyond the X platform.

However, this operation targeting OpenAI should still raise concerns. OpenAI is a private company operating in a strategically important industry. The pattern resembles influence operations originating from the People's Republic of China previously identified by the Australian Strategic Policy Institute and Mandiant. Those operations previously targeted companies attempting to reduce reliance on China's rare earths industry.

In 2022, the Spamouflage / DRAGONBRIDGE network used inauthentic accounts to disparage Lynas Rare Earths, attacking its planned processing facility in Texas. Subsequently, following announcements of new North American capacity, the network also targeted Canada's Appia Rare Earths & Uranium and the U.S.'s USA Rare Earth. Both the Australian Strategic Policy Institute and Mandiant assessed that these activities aimed to damage the reputations of competitors to the People's Republic of China's dominance in the rare earths market.

Similarly, we appear to have observed a parallel playbook being deployed to damage OpenAI's reputation, even though the operation was unsuccessful and occurred within an industry led by the United States.

Nothworthy is the timing of this operation. It occurred amid a sharp escalation in U.S.-China economic and technological competition, during which President Trump announced an additional 100% tariff on Chinese goods. More importantly, the operation coincided with the Fourth Plenary Session of the Central Committee of the Chinese Communist Party, where the CCP adopted proposals for the "15th Five-Year Plan," elevating AI to a strategic technological and industrial priority, calling for accelerated AI innovation, and promoting a nationwide "AI+" action.

This presents a useful analogy to previous rare earth operations. The Outline of the 14th Five-Year Plan, released in 2021, securitized the strategic mineral resources industry and explicitly listed "high-end rare earth functional materials" as a key priority. In both cases, inauthentic accounts targeted private enterprises in democracies operating in sectors deemed critical by Beijing for national development and security.


Conclusion

AI-Driven Influence Operations Are Targeting AI Itself

While neither the "Data Center Hitchhiking" nor the "Technology and Tariffs" operations appeared to gain significant authentic engagement, their significance lies in revealing the intentions of China-origin influence operators and the narratives they are testing and seeking to amplify.

Both clusters attempted to link U.S. tech policy and industry with ordinary people's economic anxieties and geopolitical instability. Such themes are likely to remain attractive for China-origin influence operations because they can be embedded in legitimate public discourse while encouraging audiences to distrust U.S. institutions, technology companies, and democratic policy choices, thereby helping Beijing secure strategic advantages in AI development.

These two cases also fit into the broader pattern of China-origin AI abuse we have disrupted over the past few years.

In our previous threat report, we disclosed the enforcement action against an individual affiliated with Chinese law enforcement who attempted to use ChatGPT to plan a "targeted cyber operation" against the Japanese Prime Minister, harass dissidents, impersonate Americans, collaborate with online influencers, and use inauthentic accounts across multiple social media platforms.

Chinese government entities had also previously requested ChatGPT's assistance in drafting an "early warning" system for

case, used to track the travel of individuals categorized as Uyghur-related and high-risk personnel.

Ironically, both operations used American AI, rather than Chinese models, to generate content about American AI. We cannot determine why they made this choice. As we reported in February, China's "spamouflage" strategy emphasizes the use of locally deployed Chinese open-weight models.

We also assess that this campaign demonstrates how other hostile actors may continue to carry out similar types of influence operations in the United States and globally in the future. Industry, government, civil society, and the public should all remain vigilant against the further escalation of similar information and foreign interference activities.

Original English report: https://cdn.openai.com/pdf/96b559fa-c165-4575-805d-e636909e2f78/June-2026-Threat-Report.pdf

Replies (0)

No replies yet — be the first to comment

Post a reply