A Russia-linked operation used ChatGPT to build a credible-looking research institute, complete with papers, an index, and real experts—including ones at CFR—who never agreed to be listed. Its posts earned little reach, but the infrastructure it created, using artificial intelligence (AI), shows the advancement of tech-powered influence operations.
By experts and staff
- Published
- Jessica BrandtCFR ExpertSenior Fellow for Technology and National Security
Jessica Brandt is a leading expert on the national security implications of AI, foreign malign influence, and the governance of emerging technologies. She previously served as director of the Foreign Malign Influence Center at the Office of the Director of National Intelligence.
The International Burke Institute (IBI) presents itself as an Israel-based expert community. Its website features research papers, a proprietary sovereignty index, and a roster of affiliates that includes at least three current and former Council on Foreign Relations (CFR) experts. (None of them had ever heard of IBI.) Much of the academic work on the site appears to be copied and misattributed.
IBI appears to sit at the center of a Russian influence operation that OpenAI exposed last week. According to the firm, a group of influence actors in Russia used virtual private networks (VPNs) to log in to ChatGPT. They asked it to generate social media posts, mostly in English, that later appeared across the Western web, on platforms including X, LinkedIn, Facebook, Substack, and Telegram. The actors instructed ChatGPT to hide any linguistic clues that they were Russian.
The posts tended to criticize Ukraine, the European Union, and other Western governments, and they advocated for better relations with Russia. They also heavily promoted IBI and its sovereignty index, which praises Russia and denigrates the West.
IBI pushed back in a heated statement, disputing reporting by Le Monde on the OpenAI report. It did not, however, address the fact that UNICEF denied IBI was a partner institution—contrary to what IBI’s website still states. A person’s name is not attached to the statement. IBI does not list a founder or leader. The website remains live and it continues to post content.
This influence operation’s reach was modest. Most posts did not receive a substantial number of views. OpenAI placed this operation at the low end of level three of the Breakout Scale, a six-level framework that researchers use to characterize the reach of influence operations. IBI’s level is characterized as reaching multiple platforms, with some indications of breakout to authentic audiences.
While its reach isn’t particularly notable, the operation’s creation of substantial infrastructure certainly is. This effort built a credible-appearing institution complete with purported expert affiliates, research papers, and a proprietary sovereignty index. Its perpetrators used AI as a tool to promote that infrastructure in multiple languages, without the language mistakes that previously gave campaigns away, and often using AI-generated personas, profile photos, and face-to-camera video reels. The campaign thus highlights the ways that AI is enabling influence actors to produce targeted content at scale and complicate attribution—accelerating, if not wholly revolutionizing, foreign information operations.
The operators even attempted to seed fabricated research papers featuring fictitious authors on authentic academic research-hosting platforms, according to Meta, which disrupted related activity on Facebook and Instagram after reviewing information shared by OpenAI. Russia has long attempted to launder campaigns across multiple platforms and to manufacture credibility by disguising their content as the product of authentic domestic voices. These attempts to work across the full information environment and better hide their hand while doing so are emblematic of the maturation of influence campaigns over the past decade.
Broadly, the episode highlights the value of regular threat intelligence reporting from AI labs, which have unique insight into consequential activity that social media platforms and governments may not. Over the past decade, social media companies have routinized their threat intelligence reporting—AI labs should too.
Consistent industry reporting would create an important public-interest record of foreign influence activity, offer investigative leads for academic researchers and journalists seeking to build a picture of this activity as it evolves, and enable other companies to act as appropriate. This alone would help policymakers in and out of government deal with current threats and anticipate those to come.
This work represents the views solely of the author(s). The Council on Foreign Relations is an independent, nonpartisan membership organization, think tank, and publisher, and takes no institutional positions on matters of policy.
Facts Only
* The International Burke Institute (IBI) identifies as an Israel-based expert community.
* IBI's website includes research papers, a sovereignty index, and a list of affiliates.
* Three current and former Council on Foreign Relations (CFR) experts were listed as IBI affiliates without their knowledge or consent.
* OpenAI identified a Russia-linked operation using VPNs and ChatGPT to generate English-language social media posts.
* Content was distributed via X, LinkedIn, Facebook, Substack, and Telegram.
* IBI's website claims a partnership with UNICEF, which UNICEF has denied.
* The operation's reach is categorized as low end of level three on the Breakout Scale.
* Meta disrupted related activity on Facebook and Instagram.
* IBI issued a statement disputing reporting by Le Monde but did not name a founder or leader.
* The IBI website remains active.
Executive Summary
A Russia-linked influence operation utilized generative AI to establish the International Burke Institute (IBI), a fraudulent research entity designed to appear credible to Western audiences. By leveraging ChatGPT, actors created a professional infrastructure featuring a "sovereignty index" and academic papers, while misappropriating the reputations of legitimate experts from the Council on Foreign Relations to manufacture authority. The operation focused on criticizing Western governments and the European Union while advocating for improved relations with Russia.
While the actual reach of the social media campaign was modest—earning limited views and sitting at a low level on the Breakout Scale—the sophistication of the infrastructure is significant. The use of AI-generated personas, face-to-camera videos, and the elimination of linguistic markers typically associated with Russian origin demonstrates an evolution in foreign information operations. There is a noted gap in reporting standards; while social media platforms routinely disclose threat intelligence, AI labs are only beginning to do so. Consistent reporting from these labs is proposed as a necessary tool for policymakers and researchers to track evolving threats.
Full Take
The strongest version of this narrative is that AI has fundamentally lowered the cost of "institutional forgery." By automating the production of academic-style veneers—indices, white papers, and fake affiliations—malign actors can now simulate credibility at scale, shifting from simple bot-farms to the creation of entire synthetic think tanks.
The pattern here is the "Borrowing of Reputations." The operation didn't just create fake experts; it grafted itself onto real ones (CFR) and established organizations (UNICEF). This is a sophisticated play for cognitive shortcuts: the reader doesn't vet the IBI; they see "CFR" or "UNICEF" and subconsciously check the "trustworthy" box. This represents a shift from *quantity* of content to *quality* of infrastructure.
Root Cause: The narrative operates on the assumption that "institutional prestige" is the primary currency of trust in Western intellectual circles. By hacking the aesthetics of prestige, the operators exploit a vulnerability in how we verify expertise in a digital environment.
Implications: This erodes the value of professional affiliations. If a name on a website no longer guarantees consent or authenticity, the "credential" becomes a liability. We move toward a "zero-trust" information environment where the burden of verification shifts entirely to the consumer.
Bridge Questions:
1. If institutional affiliations can be forged so easily, what new markers of authenticity can replace them?
2. How do we balance the need for AI lab transparency with the risk of providing a roadmap for more sophisticated bad actors?
Counterstrike Scan: A coordinated campaign pushing this narrative would focus on inciting panic about the "death of truth" to justify restrictive AI censorship or to discredit legitimate Russian academic output through association. The current content does not match this; it focuses on a specific technical case study and a policy recommendation for industry reporting.
Patterns detected: none
