🌿freegardner

Synapse

OpenAI Bans Chinese Accounts Using ChatGPT for US Influence Operations

12 Jun 2026 · via Openai

OpenAI Bans Chinese Accounts Using ChatGPT for US Influence Operations

They are not soldiers. They are not spies. They are something closer to scriptwriters working for a propaganda studio that never sleeps, except the scripts are never performed on a stage — they are posted, shared, and liked by fake accounts pretending to be real people in a country thousands of miles away. And the tool they used to write those scripts is the same one you might use to draft an email, summarize a meeting, or explain a complex concept: ChatGPT.

This is the quiet, unsettling truth at the heart of a recent report from OpenAI. The company identified and banned two clusters of accounts, likely originating from China, that used its AI models to generate content for covert influence operations targeting American debates about technology policy. The campaigns, called “Data Center Bandwagon” and “Tech and Tariffs,” were small in scale and failed to gain traction. But their existence reveals something deeper: the point where AI stops being a tool for productivity and becomes a weapon for manipulation, wielded not by rogue hackers but by state-aligned operators testing the boundaries of what is possible.

What is gained when AI is used this way? Speed and scale. A human propagandist might write a dozen comments a day. An AI can generate hundreds, each tailored to a specific narrative, each sounding plausibly like a concerned citizen. What is lost? Authenticity, trust, and the very fabric of democratic discourse. The balance tilts toward efficiency, but at a cost that is hard to measure until it is too late.

The “Data Center Bandwagon” campaign focused on a genuine, existing debate: the construction of massive AI data centers in the United States and their impact on local communities. Critics worry about rising electricity prices, strain on water resources, and the displacement of other industries. These are legitimate concerns, debated openly by lawmakers, environmental groups, and residents. Into this space stepped the operators, using ChatGPT to generate comments and images that amplified fears about energy costs for average families. They did not invent the concern — they latched onto it, like a parasite attaching itself to a healthy host.

The “Tech and Tariffs” campaign took aim at a different target: US tariffs on Chinese goods, announced by President Donald Trump in October 2025. The operators generated comments and political cartoons criticizing the tariffs as an attempt to dominate technological competition. In a revealing detail, the prompts explicitly instructed the AI to exclude any images of China’s leader, Xi Jinping, and to focus only on President Trump. This was not about defending China’s position — it was about attacking the US position, using AI to create the illusion of domestic dissent.

OpenAI’s investigation traced the accounts to what it described as a social media operations team at a private Chinese technology company, working for provincial-level government clients. The operators used VPNs to access ChatGPT from within China, where the service is blocked. They prompted the AI in Simplified Chinese, asking for English- and Chinese-language outputs. They designed fake personas with daily-life content, cross-account interactions, and careful attention to platform features like recommendation systems and ad tools. This was not amateur work. It was a professional operation, applying the same techniques used by marketing teams, but for political influence.

OpenAI Bans Chinese Accounts Using ChatGPT for US Influence Operations (Bild 1)

The irony is sharp. As Ben Nimmo, OpenAI’s principal investigator on the Intelligence and Investigations team, noted: “Under the circumstances, it’s particularly ironic that they use American AI to do it.” The operators were using a tool built in the United States, by a company committed to democratic principles, to undermine the very debates that shape American AI policy. This is the first trade-off: the openness of AI platforms enables innovation and accessibility, but it also lowers the barrier for malicious actors. What is gained in democratization is lost in security.

Historically, foreign influence operations have always sought to exploit existing divisions. The Soviet Union used front organizations and sympathetic journalists to amplify anti-war sentiment during the Vietnam War. Russia’s Internet Research Agency used fake social media accounts to stoke racial tensions during the 2016 US election. What changes with AI is the volume, the speed, and the ability to scale. A human operator can maintain maybe a dozen fake accounts. An AI-powered operation can manage hundreds, each generating unique content that passes basic scrutiny.

The campaigns described by OpenAI were small and ineffective. Most posts gained little to no authentic engagement. But the intent matters more than the outcome. As Nimmo explained, the operation shows “the intentions of influence operators from China, and the narratives they’re testing.” This is reconnaissance, not assault. The operators are probing for weak points, learning what works, and refining their methods. Next time, the scale may be larger. Next time, the content may be more convincing. Next time, the target may be more vulnerable.

The targeting of AI infrastructure is significant for another reason: data centers are the physical foundation of US technological leadership. They house the servers that run AI models, process data, and connect the global internet. They are also energy-intensive, often controversial, and increasingly central to national security. An influence operation that sows doubt about data centers is not just attacking a company or a policy — it is attacking the infrastructure of the future.

OpenAI’s report links these operations to broader patterns of PRC-linked activity, including previous campaigns targeting rare earths companies in North America. In both cases, inauthentic accounts attempted to undermine companies operating in sectors deemed strategically important by China. The pattern is consistent: identify a legitimate debate, insert false voices, amplify existing concerns, and erode trust in institutions. AI makes each step faster and cheaper.

What does this mean for the average person? It means that the comments you read on social media, the images you see shared, the arguments that seem to come from ordinary citizens — some of them may be generated by AI, scripted by operators thousands of miles away, designed to manipulate your opinion. This is not paranoia. It is a documented reality, confirmed by the companies that build the tools.

OpenAI Bans Chinese Accounts Using ChatGPT for US Influence Operations (Bild 2)

The challenge for platforms like OpenAI is to detect and disrupt these operations without undermining the legitimate uses of AI. The same technology that enables a student to learn faster, a doctor to diagnose better, or a writer to draft more creatively can also be used to deceive. The balance between openness and security is not fixed. It shifts with each new capability, each new exploit, each new campaign.

OpenAI’s response was transparent: it published a report detailing the campaigns, the methods used, and the lessons learned. This is a model for the industry. Secrecy breeds suspicion. Transparency builds trust. But transparency alone is not enough. Detection must be faster, consequences must be clearer, and international cooperation must be stronger. Influence operations are not a problem any single company can solve.

The “Data Center Bandwagon” campaign tried to exploit concerns about energy prices. The “Tech and Tariffs” campaign tried to exploit divisions over trade policy. Both failed to gain traction. But failure today does not guarantee failure tomorrow. The operators are learning. The AI is improving. The stakes are rising.

Consider the historical echo: in the 1930s, radio was a revolutionary technology that connected people across vast distances. It brought news, entertainment, and education into homes for the first time. It also became a tool for propaganda, used by authoritarian regimes to spread lies, incite hatred, and consolidate power. The same technology that enabled Franklin D. Roosevelt’s fireside chats enabled Joseph Goebbels’s broadcasts. The medium was neutral. The intent was not. AI is today’s radio.

AI can elevate or deceive. It can inform or manipulate. It can connect or divide. The choice is not in the technology itself, but in how we design, deploy, and govern it. The campaigns described in OpenAI’s report are a warning. They show what happens when the tools of creation are turned into tools of deception. They also show what can be done when we pay attention, investigate, and act.

The future is not written. It is generated, line by line, by the choices we make today. Every prompt, every post, every platform decision shapes the world we will live in. The operators in China are testing narratives. The rest of us are testing something more fundamental: our ability to recognize the difference between a genuine voice and a synthetic one, between a real debate and a manufactured one, between the truth and a plausible lie. That is the trade-off that matters.

What is gained in speed and scale is lost in trust. What is gained in convenience is lost in discernment. What is gained in reach is lost in authenticity. The balance is not predetermined. It is negotiated, every day, by every user, every developer, every regulator. The question is not whether AI will be used for influence operations. It already is. The question is whether we will be prepared for the next one, and the one after that, and the one after that.

The radio did not destroy democracy. It was used by those who wanted to. The same will be true of AI. The difference is that we have seen this story before. We know how it ends if we do not act. And we have the power to write a different ending. .

← back to the garden