BETA nonprofit public democratic european moderated

Search

#Attribution

Iran’s cognitive warfare – when AI becomes the operating layer of state propaganda Iranian state-linked influence operators were not using artificial intelligence simply to write faster social-media posts. According to Anthropic’s September 2026 threat intelligence report, three separate operations connected to Iranian propaganda institutions were using Claude to help construct the machinery behind what the operators themselves called “soft war” and “cognitive warfare” – non-military efforts intended to shape public opinion inside Iran and abroad. Anthropic linked the activity to the Islamic Culture and Communications Organization (ICCO), which operates under Iran’s Ministry of Culture and Islamic Guidance; the Islamic Propaganda Office of Khorasan Razavi; and the Bina Cultural Observatory, part of the Islamic Propaganda Organization. The company said each operation was run by someone working within or on behalf of the named institution. The attribution was based on a combination of account telemetry, institutional references disclosed during conversations, branded documents and open-source corroboration. Anthropic subsequently removed the accounts. AI as an operational headquarters The most significant feature of the operation was the role assigned to AI. Claude was used to develop campaign plans, doctrine manuals, coded project portfolios, persona systems, target databases, early-warning protocols, amplification schedules and ministerial planning documents. Anthropic described the model as the principal administrative and operational layer supporting the three campaigns, allowing relatively small groups of operators to create organisational structures and planning material that would otherwise have required a much larger staff. This distinction matters. The reported use of AI went considerably beyond content generation. Operators were using the model to help organise how influence activity should function: which audiences to target, which identities should deliver particular narratives, how official material should be repackaged and when amplification should take place. Human operators still determined objectives and supplied the underlying political doctrine; AI helped translate those decisions into an operational system. Anthropic found that all three operations explicitly connected their activity to Jihad al-Tabyin, often translated as “explanatory jihad”, a concept used within the Iranian state system to frame information activity as both a strategic and ideological responsibility. In internal planning material examined by the company, this doctrine was not merely rhetorical: it informed manuals and campaign structures used by the operators. ‘Not the narrator, but the director’ One sentence contained in the ICCO material captures the model particularly clearly. According to Anthropic, an operator described the role of Iranian cultural attachés as being “not to be the narrator, but the director” of the narrative. The distinction reveals the logic of attribution laundering. Instead of publishing an overt state message and asking foreign audiences to believe it, the operator attempts to create the appearance that the same narrative emerged independently from journalists, activists, foreign writers or ordinary citizens. Anthropic found that Claude was used specifically to make content appear to come from foreign authors or independent media organisations and to design hashtag campaigns that looked grassroots rather than centrally organised. The ICCO operation reportedly used the organisation’s international cultural network as part of this structure. Anthropic found ministerial-level documents carrying official ICCO branding, including a nine-part international influence portfolio. This makes the operation particularly significant because the infrastructure was not limited to anonymous social-media accounts; it intersected with formal state institutions and an existing network of cultural representation abroad. A multilingual content factory A second operation was associated with the Islamic Propaganda Office of Khorasan Razavi and what Anthropic described as a “cognitive warfare command room” operating from a seminary in Mashhad. Its organisers ran a multi-province content production system known internally as Manjanegh, or “Catapult”. According to Anthropic, dozens of activists were involved in repackaging publicly available reporting from Iranian security institutions under different personas so that the material no longer appeared directly connected to those institutions. The network used Claude to transform official government intelligence bulletins into customised material in Farsi, Arabic, Urdu, Malay, Spanish and English, while planning expansion into a total of 20 languages. Distribution extended across Iranian platforms such as Eitaa, Bale and Rubika and international services including X, Instagram, Telegram, TikTok and YouTube. Anthropic also documented paid amplification across more than 100 Iranian channels, including channels associated with IRGC narratives. The scale should nevertheless be interpreted carefully. Anthropic documented production infrastructure and some real-world dissemination, but it did not demonstrate that all planned campaigns were fully deployed or that they meaningfully changed public opinion. The company placed the operation in Category Three of its Breakout Scale, indicating multi-platform activity with content observed in external distribution channels, rather than evidence of strategic impact on entire populations. From security bulletins to apparently independent voices The Bina Cultural Observatory operation provides another example of the same architecture. Anthropic linked a director-level official at Bina to activity in which Claude generated messaging in the voice of an IRGC spokesperson. During the 2026 US–Israel–Iran war, the network also attributed false claims to Western institutions including CSIS, Brookings and RAND. The apparent objective was to make Iranian state-aligned claims look as though they had been independently validated by respected foreign research organisations. That technique is more sophisticated than simply publishing propaganda under a false name. It attempts to manufacture a chain of external validation: official information is transformed into apparently independent commentary, which can then be recirculated as evidence that outside observers have reached the same conclusion. Anthropic also found target databases naming international officials and Iranian opposition figures, as well as aggressive counter-narrative material directed against the Bahá’í community. These findings show that the infrastructure was designed not only for broad messaging but also for targeted influence activity against specific groups and individuals. What AI changed The Iranian operations described by Anthropic did not create a new doctrine of influence. Iran has used cultural institutions, official media, aligned organisations and covert or semi-covert online networks for years. What AI changed was the economics and organisational capacity of that model. A relatively small team could use the system to draft doctrine, create personas, translate material, structure target databases, produce campaign calendars and generate multiple versions of the same message for different audiences. The operator remained responsible for intent, political direction and selection of targets. AI reduced the amount of human labour required to turn those decisions into a functioning influence operation. The most revealing part of the case is therefore not that an Iranian propaganda network used a chatbot. It is that AI was being treated as part of the back office of information warfare – a system for converting state doctrine into apparently decentralised, multilingual and plausibly independent voices. Sources Anthropic — Detecting and countering misuse of AI: September 2026 https://www.anthropic.com/threat-intelligence-report-september-2026 Iran International — Iran state-aligned accounts used Claude to push IRGC narratives https://www.iranintl.com/en/202609105561 BNE IntelliNews — Yemen missile cell used AI to write guidance software, Anthropic says https://new.intellinews.com/articles/yemen-missile-cell-used-ai-to-write-guidance-software-anthropic-says-467296 This is Beirut — Anthropic report details Iranian propaganda operations https://thisisbeirut.com.lb/news/politics/anthropic-report-details-iranian-propaganda-operations-and-yemen-missile-development-using-claude Anthropic report — PDF mirror https://static.foxbusiness.com/foxbusiness.com/content/uploads/2026/09/anthropic-detecting-and-countering-091026-1.pdf Keywords #DISINFORMED #Episode11 #Iran #IranianInfluence #IranianPropaganda #CognitiveWarfare #SoftWar #JihadAlTabyin #Disinformation #InformationWarfare #InfluenceOperations #ForeignInterference #FIMI #ArtificialIntelligence #AI #AIPropaganda #GenerativeAI #ClaudeAI #Anthropic #SyntheticMedia #NarrativeManipulation #NarrativeLaundering #AttributionLaundering #PersonaNetworks #Astroturfing #SocialMediaManipulation #DigitalInfluence #StatePropaganda #IslamicCultureAndCommunicationsOrganization #ICCO #IslamicPropagandaOrganization #KhorasanRazavi #IRGC #MultilingualInfluence #Targeting #Amplification #OSINT #WRLD

Countering misuse of AI: September 2026 / Anthropic

The list of potential foreign actors is very limited. Attribution is a must, and action should follow. #Attribution #ForeignPolicy #GlobalSecurity #Nospecificcountrycodesarementionedinthetweet.

Le maire de Roubaix David Guiraud saisit la justice pour dénoncer "un système d'escroquerie" dans l'attribution de logements sociaux #SaadLamjarred #viol #justice

Le chanteur marocain Saad Lamjarred condamné en appel à dix ans de prison pour viol à Paris
www.franceinfo.fr
2

En France, bien qu'il soit légal d'écrire un livre avec l'aide de l'IA sans déclaration obligatoire, chaque jury de prix littéraire fixe ses propres règles, ce qui pose des questions sur l'attribution éventuelle de récompenses à des œuvres assistées par l'intelligence artificielle. #Littérature #IntelligenceArtificielle #DroitdAuteur

Un prix littéraire peut-il être décerné à un livre écrit avec l’aide de l’IA ?

Le maire de Roubaix David Guiraud saisit la justice pour dénoncer "un système d'escroquerie" dans l'attribution de logements sociaux #AgressionSexuelle #Éducation #Landes

Dans les Landes, un enseignant de maternelle placé en garde à vue après la plainte d'une famille pour agression sexuelle sur un élève
www.franceinfo.fr

"Nous serons sans pitié, nous vous traquerons sans relâche"David Guiraud, le maire LFI de Roubaix (Nord), a annoncé jeudi 24 septembre dans une vidéo sur les réseaux sociaux, repérée par ICI Nord, avoir réalisé un signalement auprès du procureur de la République pour dénoncer "l'existence d'un système d'escroquerie voire de corruption" dans l'attribution de logements par des bailleurs sociaux. #LogementsSociaux #Escroquerie #Roubaix

Le maire de Roubaix, David Guiraud, saisit la justice pour dénoncer "un système d'escroquerie" dans l'attribution de logements sociaux
www.franceinfo.fr

Le maire de Roubaix, David Guiraud, a saisi la justice pour dénoncer un système d'escroquerie dans l'attribution de logements sociaux, impliquant des agents de bailleurs sociaux faisant des promesses en échange de rémunérations illégales. #LogementsSociaux #Escroquerie #Roubaix

Le maire de Roubaix, David Guiraud, saisit la justice pour dénoncer "un système d'escroquerie" dans l'attribution de logements sociaux

UAE / Sudan – when an influence operation tried to enter the United Nations A network of roughly 300 apparently independent social-media influencers. A human-rights organisation borrowing the identity of a real NGO. Personal dossiers on European politicians and journalists. And testimony prepared for delivery at the United Nations without revealing the state interest behind it. These were elements of an influence operation uncovered by Anthropic and disclosed in September 2026. The company says it linked the activity with high confidence to UAE government officials. Tracked as GTG-84002, the operation targeted several overlapping issues: the Muslim Brotherhood, perceptions of the war in Sudan and international mechanisms examining the United Arab Emirates' role in the conflict. What distinguishes the case is not simply its use of artificial intelligence. It is the attempt to make state-aligned messaging appear to originate from independent influencers, human-rights organisations and potentially witnesses addressing an international institution. An influence network built around 300 fake voices Anthropic identified a single actor using Claude to support a sustained influence campaign. At its centre was an AI persona called “Deadshot”, running on the operator's own platform. A master doctrine file repeatedly instructed the system to support what it described as a coordinated international effort to dismantle the Muslim Brotherhood. The operator simultaneously managed several components of the campaign, including approximately 300 inauthentic influencer accounts across social-media platforms. Internal material examined by Anthropic described the apparent independence of this network as its greatest strategic advantage. That phrase captures the central method. The objective was not simply to broadcast a political position but to conceal where that position originated. One visible example appeared on 4 June 2026, when accounts participated in a coordinated campaign using #SudanIslamists and near-identical graphics connecting Sudanese Islamists and the Muslim Brotherhood with regional instability. Anthropic says the amplification network was centrally funded and coordinated. Its investigation also found that the operator financing the social-media network was connected to the wider influence operation. A human-rights organisation that was not what it appeared to be Social media was only one layer. The operator also created a front NGO that copied the identity of a genuine Swiss organisation and used that borrowed legitimacy to publish human-rights material produced for the campaign. Anthropic's description elsewhere also refers to the identity of a real Sudanese human-rights organisation being used in connection with the preparation of testimony. The public report does not fully clarify whether these references describe the same front or separate elements of the operation, so they should not be treated as definitively identical. The underlying technique, however, is clear: political material was designed to appear as if it originated from independent civil society rather than from actors linked to a government. This is particularly significant in the human-rights environment, where the perceived independence of an organisation or witness can determine how seriously evidence is received by journalists, diplomats and international institutions. The attempt to reach the UN The most consequential part of the operation concerned the 62nd session of the UN Human Rights Council. According to Anthropic, the operator used Claude to ghost-write complete testimony intended to be delivered by two individuals during the session. The texts were prepared under explicit constraints ensuring that neither statement would mention the UAE. This did not amount to a conventional government submission. The intention, according to Anthropic's reconstruction, was for material serving the interests of a party connected to the Sudan conflict to reach an international forum through apparently independent voices. But an important limitation remains: Anthropic could not confirm that the testimony was ultimately delivered. The company similarly could not establish whether other dossiers produced by the operation reached their intended recipients or influenced policy. It therefore assessed the campaign as Category Three on the Brookings Breakout Scale – activity distributed across several platforms, but without evidence of broad public impact sufficient for a higher classification. The distinction matters. The evidence demonstrates a sophisticated attempt to influence international debate; it does not demonstrate that the attempt succeeded. Politicians, journalists and UN investigators became targets The operation was not limited to generating public content. Anthropic found that the operator researched and compiled detailed profiles of 18 members of the European Parliament and prominent journalists. Some material was prepared for direct delivery to senior UAE officials. The network also assembled what Anthropic describes as “counter-accountability dossiers” on UN Special Rapporteurs who had criticised the UAE's conduct in relation to Sudan. This places the campaign in a broader context. Since Sudan's civil war began in April 2023, the role of external powers has become an increasingly important part of international scrutiny. Sudan has accused the UAE of supporting the Rapid Support Forces, allegations Abu Dhabi has repeatedly denied. In 2025, Sudan brought a case against the UAE before the International Court of Justice, accusing it of complicity in genocide against the Masalit through alleged support for the RSF. The UAE rejected the allegations. The ICJ subsequently removed the case from its list after finding that it lacked jurisdiction because of the UAE's reservation to the relevant provision of the Genocide Convention. The ruling therefore did not determine whether Sudan's substantive allegations were true or false. That contested international environment helps explain why narratives about Sudan, human rights and accountability were valuable targets for an influence operation. AI as an operating system for influence The role played by Claude is also important to understand accurately. Anthropic did not find that artificial intelligence independently conceived or directed the campaign. Human operators established the objectives, political doctrine and targets. AI instead helped operationalise them. Across hundreds of sessions, Claude was used to transform predetermined political objectives into social-media narratives, human-rights reports, testimony, intelligence-style briefs and detailed profiles of individuals. The same system could support narrative production, target research and preparation of material for different audiences. That represents a more significant development than simply using generative AI to produce propaganda faster. Traditional influence operations require different teams to research targets, write content, manage personas, adapt messages and prepare briefing material. Generative AI can compress several of those functions into a single operational workflow. The result is not necessarily more convincing propaganda. It is potentially cheaper, faster and more scalable influence infrastructure. From fake influencers to institutional influence Anthropic says it linked the operation to UAE government officials with high confidence. Its assessment was based partly on internal material naming senior Emirati officials as intended recipients of the work, alongside other evidence available to its investigators. That remains an attribution by Anthropic rather than a judicial finding or publicly released forensic attribution by a government agency. The distinction should be retained. The larger significance of GTG-84002 lies in the architecture of the campaign. A network of fake influencers could create the appearance of public opinion. A cloned human-rights organisation could provide institutional credibility. AI-generated reports could give political narratives the appearance of research. Profiles of journalists and politicians could support more precise targeting. And ghost-written testimony could potentially carry the same message into an international institution without revealing the political interest behind it. This is a different model from the familiar troll farm. The objective is no longer simply to make propaganda look popular. It is to make state-aligned messaging look independent – and, if possible, to move it from social media into the institutions where international policy and accountability are debated. SOURCES: Anthropic — Countering misuse of AI: September 2026 https://www.anthropic.com/threat-intelligence-report-september-2026 International Court of Justice — Sudan v. United Arab Emirates https://www.icj-cij.org/case/197 International Court of Justice — press releases and case documents https://www.icj-cij.org/case/197/press-releases United Nations Geneva — Sudan v UAE proceedings at the ICJ https://www.ungeneva.org/en/news-media/news/2025/04/105241/world-court-begins-hearing-sudans-complicity-genocide-case-against UAE Ministry of Foreign Affairs — UAE response to Sudan's allegations https://www.mofa.gov.ae/en/MediaHub/News/2025/4/10/10-4-2025-UAE-UAE UN Digital Library — Sudan's letter concerning alleged UAE support for the RSF https://digitallibrary.un.org/record/4091008?ln=en UN Digital Library — UAE response concerning allegations of support for the RSF https://digitallibrary.un.org/record/4046224?ln=en Ultra Sudan — reporting on Anthropic's UAE-linked influence-operation findings https://ultrasudan.usawtiq.com/أنثروبيك-أحبطنا-عملية-تأثير-إماراتية-استخدمت-الذكاء-الاصطناعي-لاستهداف-السودان/عامر-صالح/أخبار KEYWORDS #DISINFORMED #Episode8 #UAE #Sudan #UnitedArabEmirates #UnitedNations #UNHumanRightsCouncil #HumanRights #Disinformation #InformationWarfare #InfluenceOperations #ForeignInterference #FIMI #CoordinatedInauthenticBehaviour #CIB #FakeInfluencers #FakeNGO #NGOImpersonation #Astroturfing #ArtificialIntelligence #AI #AIPropaganda #AIGeneratedContent #SyntheticMedia #SocialMediaManipulation #DigitalInfluence #Propaganda #NarrativeManipulation #InstitutionalInfluence #SudanConflict #SudanWar #MuslimBrotherhood #InternationalRelations #Geopolitics #Anthropic #ClaudeAI #OSINT #WRLD

Countering misuse of AI: September 2026 / Anthropic

Russia’s fake African newsrooms – propaganda designed to look local A Facebook user in Nairobi, Accra, Johannesburg or Luanda encounters what appears to be a local news page. It publishes stories about African politics, Western influence and relations with Russia. The language is tailored to an African audience and the page presents itself not as a foreign broadcaster, but as part of the local information landscape. Behind some of these outlets, however, Meta found operators based in Russia. In its 2026 threat research, the company disclosed a Coordinated Inauthentic Behaviour network targeting audiences in Angola, Ghana, Kenya and South Africa. Meta removed 37 Facebook accounts and 29 Pages connected to the operation. Around 30,000 users followed at least one of the Pages, while the operators spent approximately $7,000 on Facebook and Instagram advertising, mostly in euros and US dollars. The numbers are relatively modest. The method is considerably more important. Rather than openly distributing Russian state messaging, the network posed as local African news sources and grassroots organisations, promoting narratives about Western colonialism and political interference while presenting Russia as a credible economic and political alternative. It was an old geopolitical message delivered through a much more effective identity: not Moscow speaking to Africa, but Africans apparently speaking to one another. A news outlet that was actually an influence operation Meta's investigation found that the network attempted to conceal its Russian origin while creating media brands that appeared indigenous to the countries they targeted. Its content amplified historical grievances against former colonial powers, criticised Western involvement in Africa and promoted closer relations with Russia. One example helps illustrate how the infrastructure was assembled. A Facebook Page targeting Kenya was called Kenya Watchtower. According to OpenAI's subsequent investigation, Facebook transparency records showed that the Page had previously been named “Farmtown5”. It appears to have been acquired or repurposed rather than built from scratch as a Kenyan news organisation. Some Pages also exposed administrator locations in Russia and Ukraine. Other elements of the network had previously targeted audiences in Zambia and Namibia. This use of apparently local identities is particularly important in the African information environment. A story published by RT or another identifiable Russian outlet arrives with an obvious geopolitical provenance. The same narrative presented by something resembling an independent Kenyan, Ghanaian or South African newsroom carries a different kind of credibility. The source appears closer to the reader, and the geopolitical interest behind the message becomes less visible. Then investigators found Dr Manuel Godsin The Facebook operation was only one part of a broader information ecosystem. OpenAI investigated related activity after receiving information from Meta and subsequently banned a ChatGPT account it assessed as likely originating in Russia. OpenAI called the campaign Operation No Bell. The account was being used to generate long-form articles and social-media posts about African geopolitics. Prompts were primarily written in English, but OpenAI also observed Russian-language instructions that the user described as coming from a manager. The operator sometimes explicitly asked the model to make the material appear less AI-generated – including requests to avoid stylistic features associated with machine-generated text and to write more like a human journalist. Many articles appeared under the name “Dr Manuel Godsin”, presented as an academic with a PhD from the University of Bergen and an affiliation with an organisation called the International Centre for Political and Strategic Studies. OpenAI could find no credible evidence that Godsin existed. Searches of Norway's National Research Information Repository and the University of Bergen library produced no record of him. Investigators subsequently discovered that a photograph used to represent Godsin had appeared years earlier on a Russian professional networking site and apparently belonged to a law student in St Petersburg. The fabricated academic identity was nevertheless remarkably productive. OpenAI identified 53 online articles carrying the Godsin byline. The fiction had moved beyond fake social-media pages and into the real media ecosystem. When propaganda enters genuine newsrooms This is the most consequential aspect of the operation. The articles were not confined to websites controlled by the influence network. Some were published by genuine African news organisations, including established South African outlets. The content mixed local political issues with broader geopolitical narratives. Some pieces criticised the United States and Britain or defended Russia's role in Africa. One accused the British NGO Crisis Action of fomenting protests in South Africa. Another praised Russia's presence in the Central African Republic. Other material addressed Kenya, Angola and relations between African governments and Washington. The mechanism represents a significant evolution from the classic troll-farm model. Instead of building an audience entirely on its own platforms, an influence operator can manufacture an apparently credible expert, generate articles in his name and persuade genuine news organisations to publish them. Once this happens, the propaganda acquires something a fake Facebook Page cannot provide: the institutional credibility of a real newsroom. OpenAI assessed No Bell's social-media impact as limited. One Facebook Page had around 3,000 followers before Meta removed it, while several others had very small audiences. But the operation was more successful in placing material in established media. In OpenAI's impact framework, it approached the level at which an influence operation breaks into mainstream media. For information operators, a single article published by a recognised outlet can potentially be more valuable than thousands of impressions generated by an obviously artificial account. A much larger network of ghost journalists Subsequent research suggests that Manuel Godsin was not an isolated experiment. In August 2026, Graphika, working with Code for Africa and with support from Meta, published a much broader investigation into Russian ghostwriting operations across African media. Researchers identified 44 ghost writers and fake experts, 38 of them assessed as high-confidence fabricated personas, operating between 2021 and 2026. Their material appeared or was quoted across 138 websites and was subsequently republished through at least 113 Facebook accounts and Pages, including authentic users, coordinated inauthentic networks and official Russian communication channels. The narratives were strikingly consistent. They included criticism of France, Ukraine and the United States; attacks on organisations such as ECOWAS and the International Criminal Court; positive portrayals of Russian involvement in Africa; praise for Russian paramilitary forces; and support for sovereignty-oriented political projects such as the Alliance of Sahel States. The operation therefore extends beyond creating fake news websites. It attempts to insert Russian-aligned narratives into the legitimate African media ecosystem using identities that appear African, independent or academically authoritative. This also explains why measuring reach through the original Facebook network alone is misleading. A fabricated article may begin with an influence operator, appear in a genuine African publication, be republished elsewhere and eventually circulate without any visible connection to Russia. At that point, the provenance of the narrative has effectively been laundered. An old Russian strategy with increasingly local faces Russia's use of local intermediaries in Africa is not new. Meta documented Russian networks using African nationals as early as 2019. In 2020 it dismantled another operation involving people in Ghana and Nigeria working on behalf of individuals in Russia, with links to previous activity associated with the Internet Research Agency. More recent Meta investigations suggest that this model has continued to evolve. Networks have increasingly relied on local freelancers, social-media managers and authentic media outlets rather than exclusively operating armies of obviously fake Russian-controlled accounts. This decentralisation offers several advantages. Local operators understand language, political sensitivities and cultural references. Authentic accounts are harder to identify than newly created synthetic personas. Local media brands can also deliver narratives without immediately triggering the scepticism associated with Russian state outlets. There is no evidence that every African journalist, freelancer or publication carrying such material knowingly participates in Russian influence activity. Meta explicitly notes in its investigations that some local contractors may not know who ultimately commissioned their work. That distinction is essential. The operation's effectiveness partly depends on precisely this ambiguity between deliberate participation, commercial content placement and unwitting amplification. The objective is to make Russian narratives look African The significance of this network is therefore not its 30,000 Facebook followers or its $7,000 advertising budget. Those figures are small compared with the audiences of major African media organisations. What matters is the distribution model. Traditional foreign propaganda asks an audience to trust a foreign source. These operations attempt to remove the foreign source from the equation altogether. A Russian geopolitical narrative can be generated with AI, attributed to an expert who does not exist, published by a media organisation that does, amplified through a Facebook Page presenting itself as local, and then rediscovered elsewhere as apparently independent African analysis. By the time the reader encounters it, Moscow may have disappeared completely from the chain of attribution. The resulting information operation is therefore less about making Russian propaganda more persuasive than about making it look as though it is no longer Russian propaganda at all. In an increasingly fragmented African media environment, that may be the more important evolution to watch. SOURCES: Meta Threat Research https://threatresearch-team.github.io/indicators/meta-h1-2026-russia-based-cib-network-1/ OpenAI — Operation “No Bell” https://openai.com/index/disrupting-malicious-uses-of-ai-no-bell/ Graphika — Umbrae Ex Machina https://www.graphika.com/reports/umbrae-ex-machina News24 https://www.news24.com/southafrica/news/ai-expert-exposed-fake-kremlin-linked-analyst-planted-stories-in-african-media-20260318-0560 Vanguard https://www.vanguardngr.com/2026/03/ai-expert-exposed-fake-kremlin-linked-analyst-planted-stories-in-african-media/ Meta — Russian Coordinated Inauthentic Behaviour, 2019 https://about.fb.com/news/2019/10/removing-more-coordinated-inauthentic-behavior-from-russia/ Meta — Russian Coordinated Inauthentic Behaviour, 2020 https://about.fb.com/news/2020/03/removing-coordinated-inauthentic-behavior-from-russia/ Meta Threat Research — Russian Use of Authentic Operators in Sub-Saharan Africa https://threatresearch-team.github.io/indicators/meta-h2-2025-russia-based-cib-network-2/ KEYWORDS: #DISINFORMED #Episode7 #Russia #Africa #RussianDisinformation #RussianInfluence #Disinformation #InformationWarfare #InfluenceOperations #ForeignInterference #FIMI #CoordinatedInauthenticBehaviour #CIB #FakeNews #FakeMedia #FakeNewsrooms #MediaImpersonation #GrassrootsManipulation #Astroturfing #ArtificialIntelligence #AI #AIPropaganda #SyntheticMedia #FakeInfluencers #SocialMediaManipulation #Facebook #Meta #OperationNoBell #AfricanMedia #MediaManipulation #Propaganda #DigitalInfluence #Angola #Ghana #Kenya #SouthAfrica #OSINT #WRLD

Russia-Based Influence Operation Network Targeting Sub-Saharan Africa

Storm-1516 – Russia’s information war arrives early in France’s 2027 election France will not elect its next president until April 2027, but the information operations surrounding the campaign have already begun. In late July and August 2026, fabricated stories targeted several prominent figures associated with the presidential race, including Raphaël Glucksmann, Gabriel Attal and former prime minister Édouard Philippe. The methods included fake news websites copying established French media, impersonated journalists, AI-generated voices and manipulated video. French authorities identified the Russian operation known as Storm-1516 behind several of these campaigns. Other attacks were linked to Matryoshka, another Russia-aligned influence network. The timing is significant. Storm-1516 began targeting the French presidential environment roughly nine months before the first round, scheduled for 18 April 2027. Rather than a single disinformation campaign, the activity demonstrates how Russian influence networks can establish narratives and infrastructure long before an election reaches its decisive phase. A fake scandal targeting Raphaël Glucksmann One of the clearest examples appeared at the end of July. A website impersonating the French independent outlet Blast published a fabricated investigation claiming that journalist Léa Salamé had attempted to bribe media organisations in exchange for favourable coverage of her partner, Raphaël Glucksmann. The operation went beyond copying the appearance of a legitimate news site. The identities of real journalists were appropriated and a manipulated video used an AI-generated imitation of the voice of Edwy Plenel, founder of Mediapart, supposedly confirming the allegations. The accusation was false. On 4 August, Glucksmann said France's General Secretariat for Defence and National Security, the SGDSN, had informed him that he had been targeted by Storm-1516. Two days later, the Paris prosecutor's office opened an investigation into suspected Russian interference. The importance of the operation was not the quality of one particular deepfake but the construction of several mutually reinforcing elements: a fake media organisation, impersonated journalists, synthetic audio and social-media accounts distributing the material. Together they created the impression that the allegation had been independently corroborated. Different candidates, overlapping Russian networks Édouard Philippe was also targeted by fabricated stories claiming that he suffered from dementia and was medically incapable of running for president. VIGINUM attributed the operation to Storm-1516. Gabriel Attal faced another wave of false content, including fabricated stories mimicking the identities of French outlets such as RFI, BFM TV, France 24, AFP, Le Parisien, Libération and Le Monde. Some claimed that Attal had symptoms of Parkinson's disease or links to drug trafficking. Attribution here is more complicated. French reporting connected at least part of the campaign against Attal to Matryoshka, rather than Storm-1516. A later digitally manipulated video, apparently associated with Storm-1516, used genuine LCI footage from an August debate but added a white earpiece to Attal, suggesting that someone had secretly been feeding him answers. NewsGuard compared the circulating clip with authentic LCI footage and found no earpiece in the original. The distinction is important. France is not facing a single Russian propaganda operation but several overlapping networks using similar techniques and narratives. Treating every manipulation as Storm-1516 would obscure how this ecosystem actually functions. The real weapon is media impersonation The most interesting feature of Storm-1516 is not artificial intelligence itself. It is the systematic appropriation of the credibility of established journalism. Instead of relying only on anonymous Telegram channels or social-media profiles, operators create material that looks as though it originated from organisations audiences already recognise. A fabricated investigation can resemble Blast, a manipulated television report can borrow LCI's visual identity, while fake journalists and social-media accounts provide additional layers of apparent confirmation. VIGINUM has documented this architecture extensively. Its 2025 investigation analysed 77 Storm-1516 information operations and described a mature Russian system using fabricated media, websites and distribution networks to promote anti-Ukrainian and anti-Western narratives. The European External Action Service found that the infrastructure continued to expand. According to its 2026 FIMI Threat Report, Storm-1516 almost doubled its output during 2025. Five networks created that year to target French, German, American, Moldovan and international audiences comprised 453 websites, including fictional news organisations and sites impersonating genuine media or political platforms. A typical operation therefore follows a recognisable pattern: a fabricated allegation is supported by synthetic or manipulated evidence, published through an apparently legitimate source and then distributed by networks of accounts that create the appearance of wider discussion. AI makes this process faster and cheaper, but the fundamental objective remains the same – to manufacture credibility. Why begin nine months before an election? VIGINUM concluded that Storm-1516 is capable both of reacting rapidly to current events and of conducting longer campaigns aimed at discrediting Western institutions and public figures, particularly around elections and other major political events. This provides important context for France. Storm-1516 activity around the presidential race became visible in July 2026, approximately nine months before voting begins. There is no public evidence of a predetermined Russian “nine-month plan”, and the timing should not be presented as such. Early activity nevertheless provides operational advantages: narratives can be tested, websites and accounts established, audience reactions measured and the responses of journalists, authorities and fact-checkers observed. The first operations may therefore also provide information about which themes and techniques are most effective before the campaign enters its decisive months. This remains an analytical interpretation rather than a demonstrated statement of the operators' intentions. Russian operation, but what about the GRU? Attribution requires similar precision. VIGINUM explicitly describes Storm-1516 as a Russian information operation, and French authorities have attributed individual campaigns to it with high confidence. Connections with Russian military intelligence have also been reported. Glucksmann said the SGDSN informed him that the network targeting him was controlled by Russia's GRU, while French media have repeatedly described Storm-1516 as linked to Russian military intelligence. However, VIGINUM's publicly available technical documentation describes Storm-1516 primarily as a Russian information modus operandi, rather than identifying it as a formally established GRU unit. It is therefore well supported to describe Storm-1516 as a Russian influence operation with reported links to military intelligence. Saying simply that Storm-1516 is a GRU unit would go beyond what France's published technical evidence currently establishes. An early warning for the French election There is also no evidence that the operations have so far had a significant effect on French voters. Some of the fabricated material generated only limited engagement, and measuring the real impact of foreign information operations remains extremely difficult. Even a video attracting hundreds of thousands of views does not establish how many viewers believed it or whether it changed political attitudes. The significance of Storm-1516 lies instead in the infrastructure already being deployed. Months before the election, Russian influence networks have been able to test fake newsrooms, synthetic voices, manipulated television footage, candidate-specific narratives and systems for distributing them. The French case illustrates a broader evolution in election interference. The objective is no longer simply to place false claims on social media. Modern operations can manufacture an entire chain of apparent evidence in which a fake journalist cites a fake investigation, synthetic audio appears to confirm it and networks of accounts give the impression that an authentic controversy is unfolding. France still has months to go before its presidential election. The information environment surrounding it is already being contested. Sources: VIGINUM / SGDSN — Storm-1516 analysis https://www.sgdsn.gouv.fr/publications/analyse-du-mode-operatoire-informationnel-russe-storm-1516 VIGINUM / SGDSN — Full Storm-1516 technical report https://www.sgdsn.gouv.fr/files/files/Publications/20250507_TLP-CLEAR_NP_SGDSN_VIGINUM_Technical%20report_Storm-1516.pdf VIGINUM / SGDSN — Storm-1516 operation targeting Emmanuel Macron https://www.sgdsn.gouv.fr/publications/storm-1516-detection-dune-operation-dingerence-numerique-etrangere-ciblant-emmanuel EEAS — 4th Report on FIMI Threats https://www.eeas.europa.eu/sites/default/files/2026/documents/EEAS%204th%20Threat%20Report_web.pdf Le Monde — Russian interference targeting Philippe, Glucksmann and Attal https://www.lemonde.fr/politique/article/2026/08/07/presidentielle-2027-glucksmann-attal-philippe-les-ingerences-russes-s-invitent-dans-la-campagne_6740451_823448.html Le Monde — Storm-1516 and Matryoshka analysis https://www.lemonde.fr/pixels/article/2026/08/06/ingerences-russes-pourquoi-il-ne-faut-pas-nourrir-le-troll_6739956_4408996.html NewsGuard Risk Briefing — Russian activity targeting the French election https://newsguardriskbriefing.substack.com/p/russia-targets-french-elections-iran Euronews — Operation targeting Raphaël Glucksmann https://fr.euronews.com/my-europe/2026/08/04/presidentielle-de-2027-raphael-glucksmann-vise-par-une-operation-de-destabilisation-russe Télérama / AFP — Glucksmann deepfake investigation https://www.telerama.fr/debats-reportages/presidentielle-2027-raphael-glucksmann-vise-par-un-deepfake-d-origine-russe-7032318.php Le Parisien — Operation targeting Gabriel Attal https://www.leparisien.fr/elections/presidentielle/presidentielle-2027-gabriel-attal-a-son-tour-vise-par-une-ingerence-en-provenance-de-russie-05-08-2026-I3Z67Z7ZUBDUVBXUNDARI5KGPA.php Euronews — Paris prosecutor investigations into suspected Russian interference https://fr.euronews.com/my-europe/2026/08/18/soupcons-dingerence-russe-visant-attal-et-philippe-le-parquet-de-paris-ouvre-dune-enquete Keywords: #DISINFORMED #Episode6 #Storm1516 #France #FrenchElection2027 #Disinformation #InformationWarfare #InfluenceOperations #ForeignInterference #FIMI #RussianInfluence #RussianDisinformation #Propaganda #Deepfakes #ArtificialIntelligence #AI #SyntheticMedia #FakeNews #MediaImpersonation #FakeMedia #DigitalManipulation #ElectionInterference #PoliticalDisinformation #Matryoshka #VIGINUM #OSINT #CyberInfluence #DigitalInfluence #MediaManipulation #EuropeanSecurity #Democracy #WRLD

Analyse du mode opératoire informationnel russe Storm-1516 | SGDSN
2

Nasser al-Khelaïfi, président du PSG et de beIN Media Group, est sous enquête en France pour prise illégale d’intérêts liée aux droits télé, après des accusations d'exercice de pressions sur d'autres présidents de clubs lors d'une réunion sur l’attribution des droits de diffusion de la Ligue 1. #NasserAlKhelaïfi #PSG #Corruption

Droits TV : Le président du PSG Nasser al-Khelaïfi visé en France par une enquête pour prise illégale d’intérêts

The Ghosts of Zaolzie – how a cyberattack tried to manufacture a conflict between Poland and Czechia At around 5pm on 16 August 2026, an alarming article appeared on the website of Radio PiK, a genuine Polish regional broadcaster. Its headline claimed that Poland was preparing to seize Czech territory and that the Czech Foreign Ministry had received a document outlining Warsaw's demands. Radio PiK had published no such story. An attacker had compromised an employee's credentials, gained access to the station's content management system and replaced a legitimate article with fabricated material. The newsroom quickly removed it and informed the authorities. But the intrusion was only one element of a much larger operation. Investigators subsequently uncovered forged diplomatic documents, accounts impersonating Polish and Czech officials, a cloned Czech news site, AI-generated material, a fictitious local activist and advertising for a demonstration that apparently did not exist. Together, these elements attempted to manufacture the appearance of a new territorial conflict between Poland and Czechia over Zaolzie. A false crisis built around a real territorial issue The operation worked because it did not start entirely with fiction. Poland and Czechia do have an unresolved technical issue concerning approximately 368.44 hectares of territory, originating in post-war changes to the Polish-Czechoslovak border. It is commonly described as the Czech “territorial debt” to Poland. But this is not a Polish claim to Zaolzie and there is no evidence that Warsaw is seeking to annex Czech territory. The operation fused this real issue with a much more powerful historical memory. Zaolzie – the part of Cieszyn Silesia west of the Olza River – was disputed by Poland and Czechoslovakia after the First World War. In 1938, during the crisis created by the Munich Agreement, Poland seized the territory from Czechoslovakia. The manipulation therefore followed a simple logic: a real territorial debt became an alleged Polish territorial demand, which was then transformed into a supposed attempt to reclaim Zaolzie. Fake accounts impersonating Poland's Deputy Foreign Minister Artur Harazim and Czech ambassador Břetislav Dančák helped reinforce the story. Fabricated diplomatic documents circulated alongside them. One early version referred incorrectly to 638.44 hectares; the fake Harazim account then “corrected” the number to the genuine figure of 368.44 hectares. It was an effective form of reverse fact-checking: correcting one false detail could make the larger fabrication appear authentic. Fake media – and one real newsroom The operators also created a website designed to resemble Czech public broadcaster iRozhlas. It published material supporting the same narrative, including claims that Czech residents near the border were becoming concerned about Polish intentions. The result was a manufactured information loop. Forged documents could support fake media reports; impersonated officials could comment on those reports; social-media accounts could then cite both as confirmation. But the Radio PiK hack added something much more valuable: the credibility of a real media organisation. Instead of merely cloning a newsroom, the attackers briefly inserted their fabrication into an authentic one. A familiar domain, logo and established broadcaster could therefore appear to confirm a story manufactured elsewhere. The cyberattack was not simply an accompanying technical incident. It was part of the information operation itself – a way of manufacturing credibility for false information. From a synthetic activist to a real demonstration The operation then attempted to move from the digital world into the physical one. A Facebook account under the name “Adam Sikora” promoted a demonstration in the Czech border city of Třinec under slogans including “Cieszyn Silesia is Czech” and “Here we live, here we stay”. Paid Facebook advertising was reportedly used to promote the event. Yet Třinec authorities said no demonstration had been properly notified. Promotional material used the logo of the Czech KOVO trade union, which denied any involvement. Investigators also identified indications that Sikora's profile photograph and other imagery were AI-generated. The persona even advertised a supposed house for sale in the border region, reinforcing the impression that frightened residents wanted to leave because of Polish territorial ambitions. The property could not be verified and its images also showed signs of artificial generation. This reveals the architecture of the operation: forged document → fake official → cloned media → compromised real media → synthetic local activist → advertised protest → appearance of social tension. The final stage is particularly significant. Had real people attended the demonstration, photographs of an authentic crowd could potentially have been presented as evidence that Czech citizens genuinely feared Polish territorial ambitions. A fabricated online conflict could therefore have begun generating real-world evidence of its own existence. Why Zaolzie? Historical grievances are valuable material for influence operations because the underlying facts are real. Poland and Czechoslovakia genuinely disputed Cieszyn Silesia. Poland genuinely occupied Zaolzie in 1938. A Polish minority genuinely lives in Czechia. And the 368.44-hectare territorial issue genuinely exists. The operator did not need to invent that history. It only needed to suggest that the history was repeating itself. PISM assessed that the operation sought to revive the image of Poland as a revisionist state willing to challenge European borders. Such a narrative could serve a broader purpose: damaging Polish-Czech relations, weakening confidence between NATO and EU allies and portraying Central Europe as a region where historical territorial conflicts remain unresolved. Russia is the leading attribution – but not a proven one The attribution requires more caution than the mechanics of the operation. PISM assessed Russia as the most likely perpetrator, while NASK identified similarities between the campaign and previously observed Russian influence methods. Russian-linked information infrastructure had also shown earlier interest in the Polish-Czech territorial issue. The techniques are familiar: cloned media, forged documents, impersonated officials, synthetic identities, historical grievances and the combination of cyber intrusion with information manipulation. But these indicators are not the same as definitive attribution. As of mid-September 2026, no publicly disclosed forensic evidence had conclusively connected the Radio PiK compromise, fake domains, accounts and financing to a specific Russian intelligence service, government organisation or contractor. Russia can therefore reasonably be described as the leading analytical attribution, but claims that the operation was definitively conducted by the GRU or another named Russian structure go beyond the publicly available evidence. The operation failed. The model remains important The campaign did not create a Polish-Czech diplomatic crisis. Both governments rejected the narrative, the fictitious protest was exposed, journalists reconstructed much of the operation and Radio PiK detected the intrusion quickly. Its observable impact appears to have been limited. But Zaolzie illustrates a broader evolution in information warfare. Modern operations do not have to rely on a single viral fake. They can construct an entire artificial information environment in which different elements appear to confirm one another. A forged document creates the claim. A fake diplomat authenticates it. A cloned newsroom reports it. A hacked real newsroom lends it credibility. An AI-generated citizen reacts to it. Advertising creates the appearance of a grassroots movement. And if real people eventually respond, fiction begins producing genuine events. The objective is no longer simply to persuade people that something happened. It is to create the conditions in which something real starts happening because enough people believed that it did. Sources: Polish Institute of International Affairs (PISM) https://pism.pl/publikacje/dezinformacja-o-relacjach-polsko-czeskich Euronews Polska — Radio PiK cyberattack https://pl.euronews.com/2026/08/20/polska-planuje-zajecie-terytorium-czech-wlamali-sie-na-strone-radia-i-opublikowali-falszyw Demagog https://demagog.org.pl/na-biezaco/skoordynowana-operacja-uderza-w-polsko-czeskie-relacje-czy-stoi-za-nia-rosja/ Robert Lansing Institute https://lansinginstitute.org/2026/08/27/zaolzie-as-an-instrument-of-influence-an-attempt-to-revive-a-polish-czech-territorial-conflict/ Institute for European Security Studies (IESS) https://www.iess.org.ua/analytics/ghosts-of-zaolzie iDNES.cz https://www.idnes.cz/ostrava/zpravy/tesinsko-kampan-lzi-demonstrace-trinec-primatorka-palkovska.A260826_963356_ostrava-zpravy_jog Radio Zachód / PAP https://zachod.pl/1539751/niedzielny-atak-hakerski-na-radio-pik-redaktor-naczelny-podjelismy-niezwloczne-dzialania/ Euronews — territorial debt / NASK assessment https://de.euronews.com/my-europe/2026/08/21/polen-plant-besetzung-tschechischen-gebiets-fake-news TVP World https://tvpworld.com/95036191/-warsaw-warns-against-division-amid-czech-border-disinformation Keywords: #DISINFORMED #Episode5 #GhostsOfZaolzie #Zaolzie #Poland #Czechia #CieszynSilesia #Disinformation #InformationWarfare #InfluenceOperations #ForeignInterference #FIMI #Cyberattack #CyberSecurity #HybridWarfare #FakeNews #MediaImpersonation #FakeMedia #ForgedDocuments #DigitalImpersonation #ArtificialIntelligence #AI #Deepfakes #SyntheticMedia #Astroturfing #RussianInfluence #Propaganda #OSINT #NATO #CentralEurope #MediaManipulation #WRLD

Dès notre arrivée au pouvoir, nous appliquerons la priorité nationale dans l'attribution des logements sociaux. Les Français seront au cœur de notre action : il est normal et légitime qu'ils soient, dans leur propre pays, les premiers servis ! #Oise https://t.co/h1f4iTpfFp #LogementSocial #PrioritéNationale #FrançaisAvantTout #FR

L
Le Soir 2w

Nasser Al-Khelaïfi, président du PSG, fait l'objet d'une enquête pour prise illégale d'intérêts concernant l'attribution des droits de diffusion de la Ligue 1, suite à un signalement d'Anticor. #PSG #NasserAlKhelaïfi #Corruption

Nasser Al-Khelaïfi, président du PSG, visé par une enquête pour prise illégale d’intérêts

Mali – a war where some of the people fighting do not exist In Mali's war, an apparently simple question is becoming increasingly difficult to answer: who exactly is speaking to us? A real person? A rebel organisation? A Russian influence operation? A supporter of the military junta? Or somebody who has never existed at all? In September 2026, the Dakar-based Timbuktu Institute published Des algorithmes en guerre, a report examining the use of generative artificial intelligence by actors involved in the Malian conflict. Its researchers describe the country as a potential laboratory for AI-assisted information warfare. Separatist networks are deploying synthetic fighters on TikTok. Jihadist propagandists are experimenting with AI-generated imagery. Pro-government accounts are producing large quantities of content celebrating the Malian armed forces. Russia, meanwhile, operates the most developed influence infrastructure of all: pseudo-media outlets, inauthentic accounts, AI-generated text, images and video, and systems designed to artificially amplify their visibility. Artificial intelligence did not create Mali's conflict. The war has been under way since 2012, and its participants have always fought with propaganda as well as weapons. What AI has changed is the economics of that struggle. A new “witness”, commentator, fighter, poster or video can now be produced in minutes. For audiences watching from a phone, distinguishing between genuine documentation, propaganda and material created entirely by an algorithm is becoming progressively harder. Azzghim – the fighter who cannot be killed or interrogated The most striking case documented by the Timbuktu Institute involves accounts associated with supporters of the Azawad Liberation Front, or FLA, a Tuareg separatist movement fighting the authorities in Bamako. A figure called “Azzghim” appeared on TikTok. He looks like a Tuareg fighter and regularly features in videos attacking Mali's government and Russia's Africa Corps, commenting on the conflict and promoting the cause of Azawad. There is one problem: Azzghim does not exist. Analysis of the videos identified anomalies characteristic of generative AI, including unnatural body movements, visual inconsistencies, irregular colouring and problems with audio synchronisation. According to the Timbuktu Institute, Azzghim is a synthetic character being used as the digital face of a political narrative. The propaganda advantages are considerable. An organisation no longer needs to expose a real spokesman. A synthetic personality can be designed to look exactly as its creators require, speak the appropriate language and appeal to a particular audience. Different characters could potentially be created for younger viewers, traditional communities or different ethnic and social groups. There is another advantage: a synthetic spokesman cannot be arrested, identified or interrogated. Researchers also identified accounts amplifying the material. At the time of the study, TikTok account @tawri.n.azawad had around 207,000 followers and was almost entirely devoted to publishing or repackaging content involving Azzghim. Another account, @asnan831, used a similar synthetic teenage character. An important distinction is necessary. Researchers describe these profiles as belonging to supporters or individuals associated with the FLA. The available evidence does not establish that every account is part of an operation centrally directed by the Front's leadership. The information effect, however, remains significant: a digital community can be constructed around the Azawad cause in which some of the apparent participants may not be real people at all. The jihadists are learning too The picture is different for Jama'at Nusrat al-Islam wal-Muslimin, or JNIM, the al-Qaeda-affiliated coalition that has become one of the most powerful armed groups in the Sahel. Its confirmed use of generative AI remains considerably less sophisticated. In June 2026, JNIM's Az-Zallaqa media apparatus published AI-generated posters promoting material about previous attacks. The images showed fighters in combat but contained familiar generative artefacts: buildings and vegetation merging unnaturally, blurred details and unnaturally smooth surfaces. More important than JNIM's current capabilities is what AI could add to an already sophisticated propaganda apparatus. The organisation already tailors communications to different audiences. UN reporting has documented its use of media channels for broader propaganda while other outlets increasingly distribute material in local languages, including Bambara. Generative AI could dramatically reduce the cost of this strategy, translating material into Fulfulde, Hausa, Zarma or Tamasheq, generating synthetic dubbing and producing multiple versions of the same message. The Timbuktu Institute also considers the future possibility of AI chatbots being used to personalise recruitment. That should not be presented as a capability JNIM has already demonstrated. At present, it is a risk scenario rather than a confirmed operation. Russia has the most sophisticated machine At the other end of the spectrum lies Russia's influence ecosystem. Here, AI is not an isolated experiment but another component of an infrastructure previously developed by Wagner-linked networks, Russian media operations and influence organisations operating across Africa. After Wagner's withdrawal from Mali in 2025, its military role was taken over by the Russian state-controlled Africa Corps. The information infrastructure evolved alongside it. Of particular importance is African Initiative, which presents itself as a news agency but has been identified by France's VIGINUM, the UK's Foreign, Commonwealth & Development Office and the European External Action Service as an important component of Russia's newer influence architecture in Africa. One of the most interesting elements of this ecosystem is a network researchers call AI-Freak. The operation uses generative AI to produce text, images and videos, places them on fake or apparently independent news websites and distributes them through inauthentic accounts. This is supplemented by so-called Black Hat SEO – techniques intended to artificially increase the visibility of content in search engines. Elements of this infrastructure have previously been identified by Meta and OpenAI. In 2024, OpenAI disrupted Russian accounts using ChatGPT to generate articles and comments in English, French and Russian. Some of the French-language content targeted audiences in West Africa. In a later iteration of the operation, AI models were also used to draft scripts for short videos praising the Russian Africa Corps, translate them into French and generate descriptions optimised for social media. This illustrates an important difference between the Russian approach and Azzghim. The separatist ecosystem uses AI primarily to manufacture convincing digital personalities. The Russian model increasingly resembles an industrial production line: text, image, video, pseudo-news website, distribution account, search optimisation and additional channels amplifying the narrative. The objective is not merely to convince someone of a single claim. It is to occupy as much of the information environment as possible with narratives advantageous to Moscow: Russia as an effective security partner, the West as a neo-colonial aggressor, France as a source of instability and Russian forces as defenders of African sovereignty. Yet VIGINUM also warns against equating technological sophistication with actual impact. Some Russian influence channels still attract relatively small audiences. A sophisticated operation is not automatically a successful one. The junta is building its own digital reality Mali's military authorities operate within the same contested information environment. Since breaking with France and moving closer to Moscow, Bamako has increasingly restricted independent media space while promoting a narrative built around restored sovereignty, military success and the benefits of its Russian partnership. The Timbuktu Institute highlights the TikTok account @6tm_officiel. At the time of the study, it had more than 436,000 followers and published substantial amounts of AI-generated material presenting Mali's armed forces, the FAMa, and the Africa Corps in a favourable light. One video concerning the battle for Kidal accumulated around 4.7 million views. Again, attribution requires care. Researchers describe the account as being operated by an individual based in Bamako; they do not provide evidence that it is officially managed by the Malian government. It is better understood as part of a wider pro-government information ecosystem in which the boundaries between state communications, supporters and co-ordinated propaganda can be difficult to establish. The Africa Center for Strategic Studies has previously identified the military regimes in Mali and Burkina Faso as important sources of disinformation campaigns in West Africa. Recurring narratives target France, the United Nations, ECOWAS, human-rights organisations and independent media, while presenting criticism of the authorities as part of a foreign conspiracy. Generative AI allows such narratives to be produced faster, more cheaply and in far more variations. Everyone is fighting over a different version of the same war What makes Mali particularly revealing is that multiple actors are using similar technology for very different objectives. FLA-linked networks need digital faces capable of humanising the Azawad cause and attacking Russia's presence. JNIM needs propaganda material and increasingly localised communications. The pro-government ecosystem seeks to portray Mali's armed forces as victorious and reinforce the junta's legitimacy. Russia possesses the broadest infrastructure, in which AI is merely one component of a larger system involving media outlets, websites, local partners, social-media profiles and technical amplification. The result is a war taking place simultaneously in two realities. In the first, soldiers and civilians are killed, towns change hands and the army, separatists and jihadists fight for territory. In the second, every side is trying to determine what the first reality will look like on a smartphone screen. Generative AI does not need to create a perfect deepfake to be effective. It merely needs to increase the number of competing versions of events until an ordinary viewer can no longer easily determine which one deserves to be trusted. That is why Mali matters. It is not showing us the future of information warfare. It is showing us its present. One TikTok video may feature a real soldier. Another may feature a propagandist. A third may feature a fighter who has never existed. And all three can tell completely different stories about the same war. Sources Timbuktu Institute – Des algorithmes en guerre: Comment l'IA générative rebat les cartes du conflit malien https://timbuktu-institute.org/index.php/toutes-l-actualites/item/1731-rapport-des-algorithmes-en-guerre-comment-l-ia-generative-rebat-les-cartes-du-conflit-malien AfricaNews/AFP – “Mali's information war is increasingly being shaped by AI” https://www.africanews.com/2026/09/09/malis-information-war-is-increasingly-being-shaped-by-ai/ OpenAI – research on Russia-origin influence activity and Operation Stop News https://openai.com/index/disrupting-malicious-uses-of-ai-stop-news-2024/ VIGINUM / FCDO / EEAS – technical report on African Initiative and the AI-Freak network https://www.sgdsn.gouv.fr/files/files/Publications/20250612_TLP-CLEAR_VIGINUM_FCDO_EEAS_Technical_Report_African_Initiative_EN.pdf Africa Center for Strategic Studies – Mapping a Surge of Disinformation in Africa https://africacenter.org/spotlight/mapping-a-surge-of-disinformation-in-africa/ Timbuktu Institute – analysis of AI use by JNIM https://timbuktu-institute.org/index.php/toutes-l-actualites/item/1735-artificial-intelligence-a-new-propaganda-lever-for-jnim-in-mali?print=1&tmpl=component #Disinformation #Mali #Sahel #Africa #ArtificialIntelligence #AI #GenerativeAI #AIPropaganda #InformationWarfare #InfluenceOperations #Propaganda #Deepfakes #SyntheticMedia #Azawad #FLA #JNIM #AfricaCorps #Russia #RussianInfluence #TikTok #DigitalWarfare #MediaManipulation #WRLD

Rapport - DES ALGORITHMES EN GUERRE : Comment l'IA générative rebat les cartes du conflit malien

Klimata pārmaiņas ir identificētas kā galvenais faktors ledāja nogruvumam un plūdiem, kas izraisīja smagas sekas Nepālā un Tibetā, kā norādīts World Weather Attribution pētījumā. #KlimataPārmaiņas #Nepāls #Tibeta

Eksperti: Klimata pārmaiņas ir galvenais faktors ledāja nogruvumam un plūdiem Tibetā un Nepālā

NATO consults. The EU can punish. Sanction, seize, regulate, fund, no one else on this continent has those tools. Europe's own Article 4 turns attribution into consequence within days, not months. Drones and sabotage are not deterred by communiqués. They are deterred by cost. #NATO #EUpolicy #Sanctions #Thetweetdoesnotspecificallymentionanycountries #sotherearenorelevantcountrycodestoreturn.

🚨 KYLIAN MBAPPÉ 🇫🇷 A SES ARGUMENTS POUR LE BALLON D’OR ! 🌕 «  Les performances individuelles, le caractère décisif et impressionnant du joueur sur l’ensemble de la saison » sont devenus le premier critère dans l’attribution du Ballon d’Or, devant le palmarès collectif. L’attaquant du Real Madrid a terminé meilleur buteur : 👉 de Liga 👉 de Ligue des Champions 👉 de Coupe du monde 🗞️ via @lequipe #BallonDor #KylianMbappé #Football

Hanover Institute – propaganda designed for artificial intelligence For decades, influence operations had one primary target: people. Propaganda was designed to reach newspaper readers, television audiences or users scrolling through Facebook and TikTok. The Hanover Institute for Public Policy suggests that this model is beginning to change. In August 2026, an organisation presenting itself as an American think tank appeared online and, within just nine days, produced an enormous library of pseudo-academic research on Israel, Palestine and the war in Gaza. Yet the intended audience may not have been people at all. The material appears to have been designed, at least in part, to reach systems such as ChatGPT, Gemini, Claude and Perplexity. The Hanover Institute looked professional. It published lengthy “data reports” complete with methodologies, footnotes, tables and references to sources including the World Bank, United Nations agencies, Amnesty International and the Genocide Convention. What was considerably harder to find were the things normally associated with a genuine think tank: named experts, identifiable report authors, a physical headquarters or a clearly defined legal entity. There was, however, a much more revealing trail. Documents filed with the US Department of Justice under the Foreign Agents Registration Act link Piro Inc., via Havas Media Germany, to Israel's Government Advertising Agency, known as LaPam. Hanover itself now states that its material is distributed by Piro on behalf of Havas Media Germany, acting for LaPam. 124 reports in nine days The rate of production was extraordinary, even by the standards of online publishing. Between 6 and 14 August, the Hanover Institute released 124 reports containing more than 560,000 words – an average of roughly 4,500 words per publication. On 12 and 13 August alone, 73 reports appeared, totalling almost 354,000 words. More revealing than the volume was the way the material was structured. Many titles were framed as questions remarkably similar to those a user might ask an AI assistant: “Is anti-Zionism antisemitism?”, “Did Israel expel Palestinians from their land?”, “Is Israel committing genocide in Gaza?”, “Is there a starvation policy in Gaza?” or “Is the IDF the world's most moral army?” This did not resemble the conventional publishing schedule of a research institute. It looked more like the systematic construction of answers to as many contentious questions about Israel and Palestine as possible. The presentation mattered too. These were not crude propaganda leaflets. They were written in restrained, analytical language and packaged with data, references and methodological sections. To a search engine or an AI retrieval system, they could therefore resemble legitimate expert analysis. How to write for a chatbot Some of the most revealing evidence came from the site's technical architecture. Hanover maintained an llms.txt file – a mechanism intended to make website content easier for AI systems to interpret. Reporters also identified signs of technology associated with optimising content for generative search. Piro's own marketing is equally significant. The company advertised an “AI Story Optimization” service concerned with how large language models assess information and construct answers. Its co-founder Daniel Rosenberg has written about understanding how systems such as ChatGPT, Gemini and Perplexity formulate responses – and how to ensure that an AI system knows the story a client wants to tell. The principle resembles traditional search-engine optimisation, but the target has changed. SEO tries to make a webpage rank highly in Google. Generative Engine Optimisation, or GEO, attempts to make information discoverable, credible and useful to an AI system when it constructs an answer. The chain is potentially straightforward. A user asks a chatbot a question about Israel or Gaza. The system searches for information, encounters a professionally presented Hanover report and uses it as one of the sources from which it builds its response. Propaganda no longer has to reach the user directly. It can first reach the machine, which then delivers the information to a human audience in its own apparently neutral voice. Did it actually work? This is where an important qualification is necessary. There is no evidence that the Hanover Institute “reprogrammed ChatGPT”, altered the underlying parameters of OpenAI, Google or Anthropic models, or permanently poisoned their training data. Describing the operation simply as “poisoning AI” therefore risks overstating what can currently be demonstrated. There is, however, evidence of something more specific. In neutral tests conducted by POLITICO, both ChatGPT and Perplexity cited Hanover Institute material in answers concerning Gaza, anti-Zionism and antisemitism. That suggests the operation achieved at least one of its apparent objectives: in some circumstances, AI systems treated Hanover as a source from which information could be retrieved. What remains unknown is how often this happened, how long the effect persisted and whether it meaningfully altered answers for large numbers of users. It is therefore more accurate to describe Hanover as an attempt to manipulate the retrieval and citation layer of generative AI, rather than as evidence that the underlying models themselves were permanently compromised. The money trail leads back to the Israeli state Unlike many influence operations, attribution here does not depend solely on technical clues. There is a documented financial trail. Piro Inc. registered its US activities under FARA registration number 7732. Filings identify Havas Media Germany as a contractor acting on behalf of the Israel Government Advertising Agency, LaPam. An agreement dated 30 April included $900,000 for a “Digital Storytelling Pilot”, while subsequent documentation referred to a separate $100,000 information initiative. Precision matters. The available documents do not establish that the entire $900,000 was spent specifically on the Hanover Institute. They do, however, show that Piro was conducting communications activity financed through the Israeli state apparatus and aimed at American audiences, while Hanover materials were submitted to the Department of Justice under the same FARA registration. Following scrutiny of the project, Hanover also became considerably more explicit about its funding. Its website now identifies Piro, Havas Media Germany and LaPam. From propaganda for people to propaganda for machines The significance of the Hanover Institute does not depend on proving that the operation was enormously successful. Its importance lies in what it reveals about the changing architecture of influence. The internet is increasingly moving away from a model in which users open ten webpages and compare sources themselves. Instead, they ask ChatGPT, Gemini, Claude or Perplexity a question and receive a synthesised answer. That creates a new point at which the information environment can be manipulated. The traditional model looked something like this: create a misleading article, use accounts or advertising to increase its reach, and place it in front of human users. Hanover suggests another model: build a professional-looking source, publish hundreds of articles structured around questions people ask AI, optimise those materials for generative systems, and allow the chatbot to potentially incorporate them into its own answers. The most consequential feature of this mechanism is that the user may never visit the Hanover Institute website. They may never even know that the organisation exists. Its content only needs to become one ingredient in an answer generated by a system the user trusts. In the age of search engines, governments, companies and campaigners fought over what people would see in Google results. In the age of generative artificial intelligence, an increasingly important battle will be fought over something else: which sources machines use to construct the answers we accept as knowledge. Sources The Guardian – “Fake US thinktank set up and funded by Israel sought to game AI for propaganda” https://www.theguardian.com/world/2026/aug/26/fake-thinktank-israel-ai-propaganda POLITICO – “Israeli PR wants to answer your ChatGPT questions” https://archive.ph/xF7sZ US Department of Justice – FARA documentation for Piro Inc., registration no. 7732 https://efile.fara.gov/docs/7732-Exhibit-AB-20260602-0.pdf Hanover Institute – funding and organisational disclosure https://hanoverinstitute.com/about Responsible Statecraft – “Israel creates fake think tank in likely attempt to dupe AI chatbots” https://responsiblestatecraft.org/israel-influence-chatgpt/ AIthropology Lab – “Manufacturing the source to manufacture the answer” https://aithropologylab.org/en/radar/2026-09-02/ #Disinformation #ArtificialIntelligence #AI #HanoverInstitute #Israel #Gaza #Palestine #ChatGPT #Claude #Gemini #GenerativeAI #AIPropaganda #Propaganda #InfluenceOperations #InformationWarfare #GenerativeEngineOptimization #GEO #LLM #MediaManipulation #DigitalInfluence #WRLD

Fake US thinktank set up and funded by Israel sought to game AI for propaganda

🚨 COMMÉMORATION DU 13 NOVEMBRE : UN MARCHÉ DE 1,5 M€ SOUS LE VISEUR DE LA JUSTICE 🚨 Le 31 mars 2026, l'Hôtel de Ville de Paris a été perquisitionné par la gendarmerie dans le cadre d'une enquête préliminaire du parquet national financier, ouverte le 6 février pour favoritisme, recel de favoritisme et prise illégale d'intérêts. En cause : l'attribution, sous le mandat d'Anne Hidalgo, du marché public de 1,5 million d'euros pour l'organisation de la cérémonie commémorant les 10 ans des attentats du 13 novembre 2015. Le marché a été confié à la société TRE Conseil, dirigée par Thierry Reboul, qui occupait quelques mois plus tôt le poste de directeur exécutif des cérémonies des Jeux olympiques de Paris 2024. L'enquête, ouverte suite à un signalement de la direction de la police judiciaire de la Préfecture de police de Paris, a été confiée à la Section de recherches de la gendarmerie. Avez-vous entendu parler de cette affaire ? Si nous la relayons aujourd'hui, c'est parce que nous allons bientôt en reparler. À très vite. 😉 #Paris #Justice #13Novembre