|
Getting your Trinity Audio player ready...
|
State-backed operators in Iran and China, alongside private firms in Israel, have used artificial intelligence to run what US officials and cybersecurity researchers describe as the first known influence campaigns conducted almost entirely by autonomous AI agents rather than human operators, according to an investigation published by The New York Times. The campaigns relied on freely available Chinese open-source AI models to create software agents capable of independently opening accounts, generating content and coordinating messaging across major social platforms with minimal ongoing human oversight.
What distinguishes these operations from earlier state-backed influence campaigns is the degree of autonomy involved. Rather than teams of human operators manually writing posts and managing fake accounts, as has been standard practice for years across Russian, Chinese and Iranian influence operations, these newer campaigns handed that entire workflow to AI agents, software systems capable of operating independently once activated. According to the NYT investigation, hundreds of these agents were released onto platforms including Instagram, Facebook, X and TikTok, where they autonomously registered networks of fake accounts and began populating them with political content and commentary on current events, largely without step-by-step human direction.
Iran’s campaign specifically targeted American audiences, with AI-generated accounts posing as ordinary US citizens based in major cities across the country. Those accounts reportedly shared popular memes, tagged journalists and politicians, and promoted messaging critical of the Republican Party, accumulating close to 80,000 followers during the first half of 2026 before the operation drew scrutiny from researchers and platform safety teams. The scale of that following suggests the campaign achieved meaningful organic reach before being identified, a concerning benchmark for how effectively AI-generated personas can blend into genuine online political discourse when deployed at scale.
China’s operation took a somewhat different technical approach. According to reporting picked up by HuggingNews, a system referred to as Huanyu Zhiying 1.0 deployed roughly 10,000 simulated profiles across 18 different countries, using survey data to model and predict how foreign audiences would likely respond to different messaging before tailoring propaganda content accordingly. That predictive layer represents a notable escalation beyond simply generating large volumes of fake engagement, suggesting the system was designed to optimize messaging for persuasive impact rather than just sheer output volume. Separately, the social media platform X said its own internal safety team identified approximately 200,000 inauthentic accounts linked to Chinese influence operations, with roughly 200 of those accounts specifically posting content designed to manipulate legitimate public debate around US artificial intelligence and energy policy, including messaging opposing AI development and the data centers needed to support it.
The Israeli dimension of the investigation centered on two private firms rather than state intelligence services. One of those firms, IntelEye, told researchers it had purchased 10,000 social media accounts and handed operational control to autonomous AI agents, though the company’s own account indicated only around 1,000 of those accounts ended up genuinely operational, with limited success driving engagement through automated comments on existing posts. IntelEye characterized its work as defensive research rather than an active influence campaign, though the company’s use of Chinese AI models specifically, according to Ground News, drew attention given the broader geopolitical context surrounding the investigation.
A common technical thread ran through several of the campaigns investigated. According to reporting from Inside AI, in most cases the built-in safety protocols that major AI model developers design specifically to prevent their systems from creating fake accounts or manipulating online discussions had been deliberately disabled by the operators running these campaigns. That deliberate circumvention of safety guardrails, rather than any failure of the guardrails themselves, points to a persistent challenge facing open-source AI development broadly, since models released publicly for legitimate research and development purposes can be modified by anyone with sufficient technical skill to strip out the restrictions their original developers built in.
US intelligence agencies, major technology companies and independent cybersecurity researchers collaborated on tracing the campaigns back to their sources, ultimately attributing the Chinese and Iranian operations to state-backed actors while identifying the Israeli activity as coming from private commercial entities rather than government agencies. Kyle Crichton, a fellow at Georgetown University’s Center for Security and Emerging Technology who studies the intersection of AI and cybersecurity, told the New York Times that agent-led influence campaigns are likely to become increasingly common as the underlying technology continues to spread and become more accessible to a wider range of actors.
The implications extend well beyond this specific set of campaigns. If autonomous AI agents can now handle the bulk of what previously required substantial human labor, account creation, content generation, engagement coordination and audience targeting, the cost and technical barrier to running a large-scale influence operation drops considerably, potentially putting sophisticated disinformation capabilities within reach of a much broader range of state and non-state actors than have historically had the resources to run this kind of operation effectively. That shift arrives at a moment when platforms are already struggling to keep pace with AI-generated content of all kinds, and coordinated networks of autonomous agents designed specifically to evade detection while mimicking authentic human behavior present a meaningfully harder detection problem than earlier generations of more obviously scripted bot activity.
Whether platform safety teams and researchers can develop detection methods that keep pace with this shift toward agent-driven operations remains an open and urgent question, particularly given how quickly open-source AI models capable of powering these kinds of agents continue to improve and proliferate. Continuing coverage of how AI is reshaping cybersecurity and information integrity is available on Business Tech. The original investigation into these campaigns is available through The New York Times, and additional analysis on the security implications of AI agents can be found through Georgetown University’s Center for Security and Emerging Technology.