Senior AI Journalist
OpenAI Exposes Russian ChatGPT Influence Campaign Across Western Social Media
OpenAI has dismantled a coordinated Russian disinformation operation that weaponized ChatGPT to generate propaganda and distribute pro-Kremlin narratives across major Western social media platforms. The campaign, uncovered through OpenAI’s automated detection systems, represents a significant escalation in how state-backed actors are leveraging AI tools to conduct influence operations at scale. By banning a network of accounts involved in the scheme, OpenAI has disrupted what security researchers warn could have evolved into a much larger geopolitical threat.
The operators behind the campaign accessed ChatGPT through VPN connections originating from Russia and systematically instructed the model to hide linguistic traces that might reveal their Russian origins. The central pillar of their disinformation strategy was promoting a fictitious think tank called the “International Burke Institute,” purportedly based in Israel. This fabricated institution published more than 36 articles between September 2025 and May 2026, the majority of which were plagiarized from legitimate sources including Cambridge University Press, the Migration Policy Institute, and academic journals. According to OpenAI’s investigation, false author attribution was rampant, with researchers’ names and institutional affiliations stolen to lend credibility to the fake content.
The operational scope extended across multiple platforms including X, LinkedIn, Facebook, Substack, and Telegram. Notably, German-language content distributed through a Telegram channel called “Lahme Ente” (Lame Duck) attacked European Union policies, criticized the German government, and promoted closer alignment with Russia. A second operator created logos and infrastructure for roughly a dozen Telegram channels targeting Germany, the United States, France, Poland, and Turkey, regularly requesting Russian-language summaries of channel activity. While individual posts achieved minimal engagement initially, the underlying infrastructure demonstrated sophisticated planning that OpenAI assessment suggests could have been rapidly scaled to reach millions. On the Brookings Breakout Scale, OpenAI rated this campaign at category three out of six, indicating active multi-platform distribution with emerging reach into real user communities.
Source: The Decoder
Google Launches Gemini Enterprise for Legal: AI Agents Now Handle Contract Review and Regulatory Compliance
Google Cloud has unveiled Gemini Enterprise for Legal, a specialized AI platform designed to transform how law firms and corporate legal departments manage their most critical workflows. The solution combines foundational AI capabilities with industry-specific tools, secure data connectors, and pre-built agents to automate high-value legal tasks including contract review, regulatory monitoring, discovery, and compliance screening. Available now in preview, the platform represents a significant expansion in enterprise AI deployment beyond general-purpose applications into vertically specialized professional services.
What distinguishes Gemini Enterprise for Legal from generic AI assistants is its architectural approach to governance and data integrity. Google Cloud CEO Thomas Kurian emphasized that general-purpose AI models, regardless of sophistication, cannot meet the exacting standards of legal practice without proper guardrails. The platform operates within a governed control plane that enforces security policies, maintains privileged data isolation, and provides verifiable grounding with traceable citations for all outputs. Legal teams operate under strict ethical walls, document-level permissions, and confidentiality requirements that cannot be compromised. Google’s solution integrates directly with existing legal technology stacks through secure MCP connectors linking to systems like iManage, NetDocuments, DocuSign, Everlaw, RelativityOne, and Thomson Reuters HighQ, inheriting each platform’s native access controls rather than requiring users to recreate permissions in a new environment.
The platform deploys pre-built agents specialized in high-impact workflows: automated regulatory horizon scanning that continuously monitors legislative updates and court dockets to flag exposure gaps, accelerated contract review that benchmarks vendor agreements against institutional playbooks to surface high-risk clauses, modernized Data Subject Access Request fulfillment that compiles personal data across fragmented enterprise systems to meet regulatory timelines, and intelligent document redaction for court filings. Partners including Deloitte, Accenture, and KPMG are building custom agents tailored to specific firm practices. Google is targeting leading global law firms, with early adoption by Cleary Gottlieb, Freshfields, Weil, and Williams & Connolly. The product launch also coincides with specialized versions for financial services, with healthcare and life sciences solutions following shortly.
Source: Google Cloud Blog
Chinese State-Backed Hacking Groups Double Attacks Using DeepSeek and Other AI Models
State-sponsored cybercriminals operating from China have dramatically increased their offensive operations by integrating AI models—particularly the open-weight DeepSeek platform—into their attack workflows. Research from Taiwanese cybersecurity firm TeamT5 reveals that Chinese hacking groups have more than doubled their attack frequency since adopting AI for malware development, exploit code generation, and reconnaissance tasks. This represents a critical inflection point in the evolution of AI-enabled cyberwarfare, where commercially available models with minimal safety constraints have become force multipliers for sophisticated threat actors.
DeepSeek has emerged as the preferred tool among Chinese state-backed groups precisely because, as TeamT5 chief analyst Charles Li observed, it is “relatively powerful with very low cyber guardrails.” The APT group Grimfengxi leveraged DeepSeek to generate exploit code targeting specific vulnerabilities, while Huapi relied on a Chinese language model—likely DeepSeek—as a core component of their reconnaissance and attack infrastructure. Teleboyi employed the platform to collect IP addresses and map network domain structures. Beyond Chinese models, ChatGPT and Anthropic’s Claude Code have also been weaponized: security firm CyCraft documented instances where ChatGPT was used to build decryption modules for Signal databases, and a group designated Slime22 leveraged Claude Code to move laterally through compromised Taiwanese enterprise networks. These convergent developments underscore a critical asymmetry in AI security: defensive implementations emphasize safety constraints and alignment, while openly available models remain largely unencumbered by such protections.
The threat landscape has normalized at a higher baseline. A recent UK AI Safety Institute study found that open-weight models now match the cyber capabilities that frontier Western models like Claude possessed just four months prior, but at a fraction of the cost and with minimal friction to access. While fully autonomous end-to-end attacks still lag cutting-edge frontier models by several months, the gap narrows continuously. Organizations relying on legacy cybersecurity infrastructure face compounding risk as attackers gain access to ever-more-powerful generative AI tools. The research underscores why infrastructure security—network segmentation, endpoint detection, zero-trust architectures, and continuous monitoring—has become as critical as traditional vulnerability management. For enterprises managing sensitive operations or infrastructure, hosting resilient security infrastructure through providers like Contabo VPS with dedicated monitoring capabilities offers isolation and control essential to defending against AI-augmented threats.
Source: Bloomberg (via TeamT5 Research)
This article was produced with the assistance of AI tools and reviewed by the AIStackDigest editorial team.
