Separating myths and anecdotes from evidence and measurable impact.
In June 2026, OpenAI announced they had disrupted an organized network of accounts aimed at castigating data centers through inauthentic resistance. The sockpuppet accounts, routed through Chinese infrastructure and writing in Mandarin, produced a variety of artificial engagement, including charged comments and cartoon illustrations of frustrated American homeowners.
The incident, while familiar in both host and target scope, represents a new frontier in amplified stimulus for coordinated influence operations. This is a noteworthy shift in target focus for the People’s Republic of China (PRC), largely pressurized by a global AI arms race diverging national interests partially away from traditional endpoints like rare earths and critical infrastructure. Interestingly, AI is both a broad target as defense-capable infrastructure and the offending new instrument stretching the upper bound of disinformation attack readiness, a dynamic warned against by Fred Heiding & Chris Inglis in Foreign Affairs.
OpenAI’s June report documents two clusters operating from the same host. The first, titled “data center bandwagon,” used social media engagement and generated imagery to amplify the claim that data center construction increases costs for average families. The second cluster, labeled as “Tech and Tariffs,” pushed anti-tariff messaging alongside the base operator’s broader activity, while also pushing to exonerate PRC leader Xi Jinping of any political responsibility in the ongoing trade war. The campaign’s engagement impact was minimal, with the discovering party (OpenAI) classifying the incident as a category 1 on its proprietary breakout scale, an IO-specific tool designed to measure impact based on observable, verifiable, & replicable data. The congressional response was disproportionate, highlighting the degree to which highly implicatory conversations about AI have achieved exoneration from standard checks and balances, mirroring recent economic anomalies observed in the valuation of AI companies. Despite the campaign’s reportedly low reach, the House Energy and Commerce Committee recently requested an FBI briefing on foreign adversary propaganda targeting data center (DC) development. This comes on the heels of two separate congressional members urging the DOJ to formally address foreign influence in public AI perceptions as an investigative priority. These outsized moves on Capitol Hill stimulate the conversation around national security interests and the implicit acknowledgment that survivorship bias pervades the corpus of foreign influence detection.
The incident MO itself presents as an offshoot of the Dragonbridge/Spamouflage group, an extensively documented People’s Liberation Army (PLA) information operation (IO) network being tracked continuously since at least 2019, when it targeted prominent Chinese Communist Party critic, Guo Wengui, and Hong Kong democracy protestors using troll farms and other high-velocity scam operations. The network then tried to forcefully install a dominant narrative around the Xinjiang Olympics controversy in 2021. In 2022, Mandiant flagged it for running astroturfing campaigns against American rare earth companies, posing as rural residents concerned about the environmental impact of processing facilities that would inevitably reduce Western dependence on Chinese rare earth refinement. Soon after, Meta’s i3 team reported a bold shift in actor behavior toward the end of 2022, in which US policy decisions became the dedicated target rather than an ancillary topic critiqued to international audiences. As a counterbalance, Beijing’s state security directorate issued its own warning against intentional Western influence through demoralization efforts funded by American private entities.
The OpenAI team explicitly cites the rare earths precedent for PLA-backed disruption in key American sectors; the methods are framed as consistently aligned with prior adversarial campaigns from the broader PRC conglomerate, which index incrementally on existing controversial or politically charged topics rather than manufacturing new ones. This particular strategy pairs appropriately with China’s broader militarized objective. Recent RAND testimony prepared for the US/China Economic and Security Review Commission notes Chinese military researchers coining “cognitive domain operations,” a formal PLA philosophy that treats information as a contestable domain alongside land, air, sea, and cyberspace. Additionally, they propose several frameworks for leveraging AI to achieve specific intelligence objectives, including “precision cognitive attacks” and poisoning data consumed by popular enterprise models. Finally, even muffled influence operations carry second-order effects. Rybar, a well-known Kremlin-sympathizing channel, dismissed OpenAI’s findings as inaccurate, arguing the movement was organic. While the straight-line inference from Moscow to Beijing may not be axiomatic, mutual interests are observable in respective state responses to ongoing domestic rhetoric. Whatever the actual fallout level of the OpenAI campaign, it sits inside a stated doctrine the PRC has publicly endorsed, and one likely to expand explosively in coming months.
Data centers themselves seem to be appropriate proxies for how CN views AI as strategic infrastructure. Chinese military and public security institutions have reportedly integrated DeepSeek’s models into research, intelligence, and surveillance capacities as part of a concerted advancement towards “intelligentized warfare” and “algorithmic sovereignty” from Western technology. Researchers report state control over DeepSeek scaling in proportion to the company’s vertical progression, with municipal authorities screening investors, US travel bans, and passport confiscations for top secret collaborations. With Western technology companies’ uncertain relationship to national defense lines and the existing polarization around expanding domestic infrastructure in the AI arms race, conditions are ripe for continued aggression in this sector.
From a research standpoint, we are particularly interested in how commercial LLM applications absorb the labor cost traditionally fulfilled by an organic operator, the same augmentation we previously tracked in phishing and more financially incentivized cybercrime. This OpenAI report is one of the first documented instances of a nation-state using frontier models to manage the logistical burden of disinformation campaigns, not just create content. Operators used GPT to write comments and create graphic imagery, but also to power the campaign itself by handling bulk identity management, data distribution, and internal reporting. At one point, the model was prompted on social media growth strategies to weigh paid and organic tactics for maximum reach. This shows that many components of a disinformation attack, from content creation to infrastructure generation, can be tangibly outsourced to AI models. While the current landscape hasn’t clearly demonstrated tangible uplift in nation states’ efficacy using AI to enhance IO, there is a measurable increase in at least the effort to accelerate or diversify existing threat streams using AI.
Additionally, the spotlight on AI as contested terrain holds plausible implications for targets of future HUMINT campaigns. A June 2026 Five Eyes briefing warned against an increase in Chinese intelligence posing as recruiters and consultancies and primarily targeting defense officials, military personnel, reporters, and anyone else with credible or peripheral access to classified information. Given the US government’s somewhat opaque relationship with some leading AI companies (in comparison to the PLA’s more hierarchical connection to DeepSeek), there is less certainty in the degree to which private employees of these firms are prepared for similar outreach efforts. Historically reserved for military and government personnel, PLA spear phishing scope may expand to private employees of leading AI companies given their outsized remit in brokering raw technological capacity.
In short, as AI models become more capable, they will increasingly be used in influence operations, as they lower costs and enable attacks to scale. Technical experts, policymakers, and other stakeholders must collaborate to evaluate different defensive countermeasures across sectors, industries, and use cases, invest in the most promising areas, establish clear accountability across the defensive ecosystem, and strengthen deterrence by clearly defining unacceptable actions and the consequences of crossing those lines.
References
Alethea. (2026). How state actors and AI slop are amplifying the data center revolt. Alethea. https://alethea.com/insights/how-state-actors-and-ai-slop-are-amplifying-data-center-revolt
Beauchamp-Mustafaga, N. (2024). Exploring the implications of generative AI for Chinese military cyber-enabled influence operations [Testimony]. RAND Corporation. https://www.rand.org/content/dam/rand/pubs/testimonies/CTA3100/CTA3191-1/RAND_CTA3191-1.pdf
Beauchamp-Mustafaga, N. (2024). Exploring the implications of generative AI for Chinese military cyber-enabled influence operations [Testimony]. RAND Corporation. https://www.rand.org/pubs/testimonies/CTA3191-1.html
Clemson University Media Forensics Hub. (2023). The 5-year spam: Tracking a persistent Chinese influence operation. Clemson University. https://open.clemson.edu/cgi/viewcontent.cgi?article=1007&context=mfh_ci_reports
Cotton, T. (2026, June 10). Letter to Attorney General Pam Bondi [Letter]. U.S. Senate. https://www.cotton.senate.gov/wp-content/uploads/media/doc/61026blancheletter.pdf
Du, Q., & Sun, L. (2026, April 28). China’s MSS exposes anti-China forces concocting ’class solidification’ narratives and promoting ’lie-flat’ thinking among Chinese youth. Global Times. https://www.globaltimes.cn/page/202604/1360009.shtml
Federal Bureau of Investigation, National Security Agency, MI5, & partner agencies. (2026, June 3). Safeguarding our secrets: Joint cybersecurity advisory (Advisory No. 260603). Internet Crime Complaint Center. https://www.ic3.gov/CSA/2026/260603.pdf
Heiding, F., & Inglis, C. (2026, March). America’s endangered AI: How weak cyberdefenses threaten U.S. tech dominance. Foreign Affairs. https://www.foreignaffairs.com/united-states/americas-endangered-ai.
House Energy and Commerce Committee. (2026). Chairmen Guthrie, Joyce, and Latta request investigation of foreign adversaries’ efforts to block American data center buildout [Press release]. U.S. House of Representatives. https://republicans-energycommerce.house.gov/posts/chairmen-guthrie-joyce-and-latta-request-investigation-of-foreign-adversaries-efforts-to-block-american-data-center-buildout
Jamestown Foundation. (2026). DeepSeek use in PRC military and public security systems. Jamestown Foundation. https://jamestown.org/deepseek-use-in-prc-military-and-public-security-systems/
Mandiant. (2022). DRAGONBRIDGE targets rare earths mining companies. Google Cloud Blog. https://cloud.google.com/blog/topics/threat-intelligence/dragonbridge-targets-rare-earths-mining-companies
Menlo Park Intelligence. (n.d.). ScamBench. Menlo Park Intelligence. Retrieved September 2026, from https://menloparkintelligence.com/research/scambench/
Meta. (2022, September). Removing coordinated inauthentic behavior from China and Russia. Meta Newsroom. https://about.fb.com/news/2022/09/removing-coordinated-inauthentic-behavior-from-china-and-russia/
Microsoft Threat Intelligence. (2024). East Asia threat actors employ unique methods. Microsoft Security Insider. https://www.microsoft.com/en-us/security/security-insider/threat-landscape/east-asia-threat-actors-employ-unique-methods
Nimmo, B. (2020, September 25). The breakout scale: Measuring the impact of influence operations. Brookings Institution. https://www.brookings.edu/articles/the-breakout-scale-measuring-the-impact-of-influence-operations/
OpenAI. (2026, June). Disrupting malicious uses of AI: Data center bandwagon. OpenAI. https://openai.com/index/disrupting-malicious-uses-of-ai-data-center-bandwagon/
Singer, S., & Sheehan, M. (2025, July). China’s AI policy at the crossroads: Balancing development and control in the DeepSeek era. Carnegie Endowment for International Peace. https://carnegieendowment.org/research/2025/07/chinas-ai-policy-in-the-deepseek-era
U.S. Army Training and Doctrine Command, Foreign Military Studies Office. (n.d.). Chinese military researchers debut precision strike concept for cognitive domain operations. https://oe.t2com.army.mil/product/chinese-military-researchers-debut-precision-strike-concept-for-cognitive-domain-operations/
U.S. Department of Justice. (2026). Justice Department and FBI seize platforms operated and used by China state-sponsored hackers [Press release]. Office of Public Affairs. https://www.justice.gov/opa/pr/justice-department-and-fbi-seize-platforms-operated-and-used-china-state-sponsored-hackers