For months, a foreign agent has been cultivating some of the most powerful figures in the United States in hopes of turning them into unwitting allies. Targeting their weak spots, the foreign agent is feeding them hour after hour of falsehoods. Already the would-be proxies are passing on the foreign propaganda to tens of millions of their followers.
If this sounds like a chapter from another century — think K.G.B. officers swaying unsuspecting fellow travelers in London or New York — it’s actually worse. The spy runner is a Russia-backed network called Portal Kombat that operates hundreds of websites to spread disinformation. The powerful figures it’s seeking to influence? Artificial intelligence-driven large language models such as ChatGPT, Grok and Gemini.
Portal Kombat’s goal is to influence these models so that they will pass along propaganda to trusting users in response to questions. Portal Kombat pushed over 3.6 million stories across hundreds of independent websites in dozens of languages in 2024, according to NewsGuard, an organization that tracks online disinformation. NewsGuard researchers systematically tested A.I. chat systems and found that Portal Kombat propaganda was regularly provided to users.
Large language model influence operations are just one way that America’s adversaries are using A.I. to try to steer its politics. China directs its A.I. platforms to push false claims about the treatment of Uyghurs and to censor dissent and criticism of the Chinese Communist Party. Russia is using A.I. to generate scores of news websites to turn Americans against democracy and Western alliances. Like many, these adversaries use A.I. to create fake written, audio or video content that is nearly indistinguishable from the real thing.
The greatest danger, though, isn’t A.I.’s ability to lie. It’s the ability to persuade. These new agents of influence are less like a traditional propaganda pamphlet — static and lifeless — and more like a living, breathing case officer, as I used to be. A.I. agents try to manipulate us through sustained engagement. And unlike the K.G.B.’s espionage machinations during the Cold War, which focused on recruiting powerful individuals, today’s A.I. influence operators are trying to persuade all of us.
To fight back, Americans need to learn the counterspy techniques of C.I.A. officers: using multiple sources to check information; testing those sources regularly for reliability; never getting complacent and trusting one source without thinking.
Learning those tools has broader benefits. We are all asking ourselves: How do I believe anything in a world of A.I.? Foreign actors may be in the vanguard of this new era of disinformation, but it’s spreading at home, too, and fast. Already, politicians are changing what A.I. has to say about them by manipulating content to be picked up by A.I. models.
From resisting foreign influence campaigns, to safely navigating our domestic politics, to understanding rapidly developing marketing techniques, we all need to start thinking like spies.
Social media has long-used algorithms to make propaganda more effective. Studies by the Network Contagion Research Institute at Rutgers University have showed that the amount of time spent on TikTok correlates with more benevolent views of Chinese human rights. What’s new about A.I. is its personalization and interactivity. A.I. can identify your online expressions of belief and desire and create content tailored to persuade you, in real time. That used to take teams of well-paid people weeks to do. Now, bad actors can do it in seconds at little cost.
The Chinese company GoLaxy has already advertised such an integrated, A.I.-driven persuasion system. Researchers at Vanderbilt University analyzed leaked documents showing that GoLaxy used A.I. to mine user information from social media, create psychological profiles, develop personalized content and then engage users in conversation to change their political opinions. GoLaxy used this capability in 2020 in Hong Kong and again ahead of Taiwan’s 2024 election, likely at the behest of the Chinese government. (GoLaxy denies it has done election-related work, developed psychological profiles or deployed bots.)
Further afield, Reporters Without Borders showed that the Chinese A.I. model Qwen advanced the Communist Party line on Uyghur internment camps, calling them “education and vocational training centers” and saying questions about them were “baseless speculation” despite extensive independent reporting showing otherwise.
Another propaganda house, CopyCop, uses A.I. to create seemingly real local journalism sites in an effort to persuade Americans to support Moscow’s aims. CopyCop publishes its articles on seemingly authentic websites such as The Boston Times and mimics the branding of existing major news sites like The San Francisco Chronicle, according to the cyberresearch firm Recorded Future. The French government has linked CopyCop, also known as Storm-1516, and one of its operators, an American who was once a deputy sheriff in Palm Beach County, Fla., John Mark Dougan, who now lives in Moscow, to the Russian intelligence agency G.R.U.
In June, OpenAI presented evidence that their ChatGPT model was likely used by China to create covert propaganda messages about data center construction. The “Data Center Bandwagon” campaign used OpenAI’s models to create social media comments and images on issues like electricity costs, which were then posted to X in an apparent attempt by China to handicap American A.I. ambitions.
It works. A recent study in the scientific journal Nature showed that A.I. dialogue is roughly four times as persuasive as traditional political ads.
Over time, intelligence officers have developed tools and techniques for finding useful truth amid deception. At heart, those techniques rely on what makes us human: our natural ability to understand people and their lies, to spot patterns and assess trust. Most of all, they train us to remain aware that any piece of information may be purposefully deceptive. These techniques include:
-
Triangulation. If you prefer one source of news — The New York Times, say — also check The Wall Street Journal, Newsmax and The South China Morning Post on any given report. If all say the same thing, the story is more likely right than wrong. The same is true for A.I. systems: if you are a Claude user, then check ChatGPT, or vice versa.
-
Operational testing. Ask a question to which you already know the answer. To test an A.I. bot for accuracy about, say, an impending war or civil unrest, first check recent satellite imagery to see if there are actually troops in the area or visit the website of a protest movement. Then see how close the bot’s answer is to the primary source.
-
Trust no one. The hardest part of spy craft may be never taking anything as permanently true. A.I. makes it especially easy to go soft. Chat systems are good at providing answers and it’s tempting to just accept their answers. But A.I. is optimized to get you to like it and to continue using it, not to give you the truth. Remain skeptical.
Those defenses won’t be widely adopted on their own, and we need a plan for how to spread them around the country. We need to develop an education curriculum for critical thinking, including sustained efforts to teach how to identify misinformation online, to spot A.I. fakes and to strengthen critical thinking. Then we need lifelong training, as we do with cybersecurity today. We need to create communities of trust to crowdsource the truth.
Analogues exist already in the world of law enforcement: Apps like Nextdoor and Citizen allow users to share information with each other about crime or other hyperlocal concerns. There are Reddit groups in which users investigate cold case murders like r/coldcases. Bellingcat is a citizen journalism site that provides tools and techniques for anyone to investigate war crimes and other worthy causes.
The challenges of a world in which adversaries try to undermine our society by manipulating truth via A.I. are real. But there is hope. We can learn how to spot and confront these agents of influence by using the tools and techniques of the intelligence officer.
Anthony Vinci is a founder and the C.E.O. of VICO.io, a venture backed A.I. company, and the author of “The Fourth Intelligence Revolution: The Future of Espionage and the Battle to Save America.”
Source photographs by Connect Images and PhotoAlto/Sigrid Olsson/Getty Images
The Times is committed to publishing a diversity of letters to the editor. We’d like to hear what you think about this or any of our articles. Here are some tips. And here’s our email: [email protected].
Follow the New York Times Opinion section on Facebook, Instagram, TikTok, Bluesky, WhatsApp and Threads.
The post A Spy’s Guide to Fighting A.I. Propaganda appeared first on New York Times.




