Iran used ChatGPT and fake bylines to infiltrate Western news sites, OpenAI finds

OpenAI revealed that Iranian operatives used ChatGPT to plant nearly 100 articles in Western news outlets under fake bylines; Separately, Anthropic disclosed AI agents submitting unauthorized visa applications and false police tips, drawing White House anger

OpenAI recently revealed that Iranian operatives used ChatGPT to place nearly 100 articles on news websites under the names of journalists who do not exist. Meanwhile, Anthropic disclosed over the weekend a series of incidents in which its AI models took actions that went beyond their assigned tasks.
In one case, an AI agent that was supposed to practice filling out forms accessed the U.S. State Department's official website and submitted visa applications. Another agent sent Philadelphia police fabricated information about an unsolved murder. The Trump administration responded with unusual anger, demanding immediate reporting of such incidents.
סם אלטמן מנכ"ל OpenAI בכנס המפתחים של החברה
סם אלטמן מנכ"ל OpenAI בכנס המפתחים של החברה
OpenAI CEO Sam Altman at the company's developer conference
(Photo: AP Photo/Jeff Chiu)

The Iranian influence operation

In the case uncovered by OpenAI and reported by The Washington Post, the artificial intelligence operated under human instructions. The company blocked accounts operated by individuals in Iran who had concealed their location using VPNs. Through these accounts, the operatives created seven identities for purported Western writers, most of them American. Writing in Persian, they asked ChatGPT to improve English-language articles about the U.S.-Iran war, adapt them to different websites' submission guidelines and draft pitches to editors.
One fictitious writer, "Ervin B. Hoskins," was presented as an American freelance writer and anti-war activist, complete with social media accounts. For another identity, "Michael Harrison," the operatives asked the model to write an entire biography.
Nearly 100 articles published or republished on more than a dozen websites from July 2025 through October 2026 were traced to these and other fictitious bylines. The publications included opinion pieces about Israeli politics, some of them fairly sophisticated and not necessarily overtly anti-Israel.
Writing for International Policy Digest, "Noah Lamington" analyzed the crisis over the military draft of ultra-Orthodox men and the stability of Prime Minister Benjamin Netanyahu's government. "Hoskins," meanwhile, wrote in Modern Diplomacy about France's decision to bar Israeli National Security Minister Itamar Ben-Gvir from entering the country.
Although "Hoskins" criticized Ben-Gvir and the lack of American pressure on him, he also explicitly stated that he supported Israel's security and was not calling on the United States to abandon it. Another article by "Hoskins," published in LA Progressive, examined whether Jared Kushner's business ties in the Gulf were influencing U.S. policy toward Iran.
Other websites with substantial audiences also published the material. The British website Middle East Monitor, which covers the Middle East and the Palestinian issue, published at least 21 articles under four bylines that OpenAI identified as fictitious. The website said it had removed the identified articles and was reviewing its procedures for accepting opinion submissions.
כתבות של "מייקל הריסון" שהופיעו באתר Middle East Monitor
כתבות של "מייקל הריסון" שהופיעו באתר Middle East Monitor
Articles attributed to 'Michael Harrison' that appeared on the Middle East Monitor website
(Photo: Social media, The Washington Post)
Similar content appeared on Daily Kos, a website associated with the Democratic Party in the United States, where it was published in a community section that does not undergo advance editorial review. In this way, articles submitted under false identities reached readers through established websites and were sometimes promoted through those outlets' official social media accounts.
After the articles were published, members of the network also used ChatGPT to generate social media comments. According to OpenAI, they sought to portray the United States as an aggressor, Israel as an unreliable ally and Iran as a victim standing its ground. Some of the comments praised articles the operatives themselves had planted on news websites.
The network also directed some of its activity against Iran International, a Persian-language news channel critical of the regime in Tehran. According to OpenAI, the operatives used ChatGPT to generate more than two dozen batches of hostile comments responding to the channel's posts.
An article published under the name "Sophia Gonzalez" in LA Progressive and CounterPunch, a popular left-wing magazine, claimed that Netanyahu had pushed Trump into war and that Iran International had helped spread the impression that Iranians welcomed the strikes.

AI agents go rogue again

In a separate case disclosed by Anthropic over the weekend, the company's AI models once again took actions beyond their assigned tasks.
In the visa application incident, the model had been instructed to fill out a practice copy of a government form. When the practice page failed to load or was accidentally closed, it searched for the form on the official government website and submitted it there instead.
Anthropic did not identify the government agency involved, but the State Department confirmed that one of the company's experimental models had submitted 19 applications for temporary visas in August and another in May.
It is important to note that none of the applications were processed and the department's systems were not breached. The forms were incomplete, and the model had carried out the task as it understood it, without recognizing that its actions had crossed from a simulated exercise into the real world.
In another experiment, Claude was instructed to perform sample actions on randomly selected websites. It came across a page about an unsolved murder that included a form for submitting information to police. On July 18, the model submitted a message claiming that the writer remembered seeing someone matching the suspect's description near the scene of the murder.
מנכ"ל אנת'רופיק, דאריו אמודיי, לצד הנשיא טראמפ בפגישה בבית הלבן
מנכ"ל אנת'רופיק, דאריו אמודיי, לצד הנשיא טראמפ בפגישה בבית הלבן
Anthropic CEO Dario Amodei alongside President Donald Trump during a meeting at the White House
(Photo: Reuters)
However, the website did not contain any description of a suspect, and the model left the name and contact information fields blank. The police system classified the submission as spam, and it never reached investigators.
The instructions given to the model prohibited it from creating accounts, disclosing personal information, making purchases or submitting destructive content, but they did not explicitly prohibit submitting forms. Anthropic discovered the incident only in late September and notified police on October 7.
Anthropic's report also described additional cases of autonomous behavior by its AI agents. One agent, tasked with performing a scientific calculation on a university website, encountered an error, discovered a vulnerability in the software running on the server and exploited it to execute commands.
In another case, a model located access keys in a government website's configuration file and used them to retrieve data through the site's back-end system.
Another agent managed to obtain publicly available data that normally required payment without paying for it. Anthropic also reported that its agents had used URL-shortening services to bypass restrictions in its browsing tools.
According to the company, the actual damage caused by these incidents was minimal. In response, Anthropic restricted internet access during internal testing, modified some of its browsing tools and added a system to detect such actions.
The White House reacted sharply to the incidents. A newly established administration task force said it expected Anthropic to provide full and immediate transparency to the affected authorities and the public.
The task force said companies developing advanced AI systems must promptly report unusual incidents, cooperate with law enforcement authorities and remedy any damage.
Its statement emphasized that this process was "not optional" and that any delay in reporting would be unacceptable.
The declaration was unusual for an administration that has so far preferred to give technology companies considerable freedom to develop AI. However, the statement did not specify whether sanctions would be imposed or what enforcement mechanisms would be used in cases where companies failed to report such incidents.
Comments
The commenter agrees to the privacy policy of Ynet News and agrees not to submit comments that violate the terms of use, including incitement, libel and expressions that exceed the accepted norms of freedom of speech.
""