Ai Engineering 4 min read

Iranian Operatives Used ChatGPT to Plant 100 Fake Articles in Real US News Outlets

OpenAI disrupted an Iranian campaign dubbed 'Bogus Bylines' that used ChatGPT to write and tailor more than 100 fake articles published by at least 20 real US news outlets under seven fake journalist personas, per its October report and Washington Post coverage.

OpenAI disrupted an Iranian influence operation that used ChatGPT to write, edit, and tailor more than 100 fake articles, pitched under seven fake journalist personas and published by at least 20 real US news outlets, per OpenAI’s report on “disrupting AI-enabled ‘false front’ operations” and the Washington Post’s October 9 coverage. The campaign, dubbed “Bogus Bylines,” carried anti-US narratives about the war against Iran, and extended to fake audio attributed to real figures. OpenAI banned both the Iranian and Russian accounts tied to the operations. The mechanism is the part that should worry newsrooms: this was not synthetic news sites nobody reads, it was AI-written content placed, by hand, into publications with real audiences.

Narrative Laundering Through Real Mastheads

NPR’s framing of the technique, “narrative laundering,” is the accurate one. The influence-operation playbook of the last decade built fake websites with fake audiences; Bogus Bylines used ChatGPT to produce publication-ready copy and human operatives to pitch it to legitimate outlets, laundering the narrative through mastheads that already have trust. The fake personas had names, bylines, and pitches, which means editors received plausible freelancers with topical angles, not obvious spam. Detection at the publication layer is therefore nearly impossible after acceptance: the tell is not the prose, which is the one thing current models do well, but the persona behind it. This is the placement stage of disinformation finally being automated, with generation solving the labor bottleneck that used to limit such campaigns to low-quality content farms.

The Provenance Tools Launched This Week Do Not Touch This

The timing is pointed: Google opened SynthID Detector to the public on October 7, a tool for checking whether media carries AI watermarks. Bogus Bylines is almost entirely outside its reach, because the operation’s outputs were text articles, authored under human names, edited by human editors, and published as ordinary news stories. Provenance watermarks detect machine-generated media objects; they cannot flag machine-drafted text published by humans under human identities. The use case OpenAI’s own disruption report describes, AI as the writing and tailoring engine for a human-run laundering operation, is the gap in every current detection standard, and the Bogus Bylines report is the clearest public documentation of it to date.

The Scale Reveal: Placement Was Always the Bottleneck

The strategically interesting number is 20 outlets from 100 articles. Those are modest figures for a state-adjacent campaign, and their modesty is the finding: AI did not supercharge the distribution, it supercharged the production, and production was never the limiting constraint for narratives that could get placed. The counterfactual matters for calibration: a small team of competent human writers could have produced the same 100 articles, just slower. What ChatGPT changed is the marginal cost of tailoring each pitch to each outlet’s style, generating variations when one is rejected, and keeping seven personas supplied with fresh copy indefinitely. Influence operations are now limited by editorial judgment, not typing speed, which moves the defensive focus to newsroom verification of contributors rather than detection of machine prose.

What to Watch

Three things. First, whether the 20 outlets name themselves and disclose which articles were fake, the remediation that determines how much trust the campaign actually destroyed. Second, whether newsrooms build contributor-verification processes (identity checks, pitch history, persona vetting) in response, and whether organizations like the identity vendors building agent trust infrastructure extend to journalist-identity verification. Third, the disclosure pattern at OpenAI: the company banned the accounts, published the report, and notified the affected outlets through the Washington Post, a disruption-report format that has become the industry standard. The report’s own limitation, that it can see misuse inside its own product, is the structural one: the same operation could run identically on any competitor’s model, and the ecosystem-level response still does not exist.

Get Insanely Good at AI

Get Insanely Good at AI

The book for developers who want to understand how AI actually works. LLMs, prompt engineering, RAG, AI agents, and production systems.

Keep Reading

Ai Engineering

How Function Calling Works in LLMs

Function calling lets LLMs interact with external systems by requesting structured tool executions. Here's how the loop works, how to define tools, and what to watch for across providers.

Ai Engineering

GPT-6 Rolls Out Globally in ChatGPT With an Interface Made of UI, Not Text

OpenAI announced on October 7 that GPT-6 is rolling out globally in ChatGPT with Intelligent UI: answers delivered as interactive charts, buttons, study blocks, and mini-apps instead of plain text, reaching paid tiers first with Free and Go following.

Ai Engineering

EU Designates ChatGPT as a Very Large Online Search Engine Under the DSA

The European Commission designated ChatGPT a VLOSE under the Digital Services Act on August 31, making it the first AI chatbot subject to systemic-risk audits, researcher data access, and algorithmic transparency rules.

Ai Engineering

OpenAI Secures ChatGPT macOS App After Axios Library Attack

OpenAI rotated its macOS code-signing certificates and hardened GitHub workflows following a dependency confusion attack on the ChatGPT desktop client.

Ai Agents

Common Sense Media Declares ChatGPT for Teens an 'Unacceptable Risk'

A Common Sense Media assessment published October 7 found ChatGPT for Teens fails to alert parents during self-harm discussions, doesn't provide crisis help, and still does homework despite study mode, recommending adults-only access until independently validated.