SAN FRANCISCO, 26 AUG 2026 — OpenAI has banned a cluster of ChatGPT accounts operating from Russia which were building out a fictitious think tank called the International Burke Institute and using it to push narratives favourable to the Kremlin.
The most informative detail is not the artificial intelligence. Of 36 articles sampled from the institute's supposed experts, published between September 2025 and May 2026, 34 were copied from elsewhere on the internet.
What was taken down
The operators worked in Russian and routed their connections through VPNs, since OpenAI does not permit model access from Russia. They used ChatGPT to draft social media content, which was then posted on Substack, Telegram, X, Facebook and LinkedIn.
The centrepiece was the International Burke Institute, presented as an expert community, with a website listing a street address in Israel. The operation also produced a sovereignty index, a ranking that praised Russia and marked down Western countries.
The credibility layer was stolen, not generated
The common mental model of an AI influence operation is a machine producing fake expertise at volume. That is not what happened here, and the 34 figure says so plainly.
The long-form articles that made the institute look like a real research body were largely lifted from other people's work. Plagiarism, not generation. Whoever built this judged that copied human writing would pass inspection better than model output, or simply that it was cheaper, and either way the credibility layer was assembled from theft.
That has a practical consequence for anyone trying to detect this class of operation. A detector tuned to spot machine-written text would have cleared 34 of those 36 articles, correctly, because a human wrote them — just not the human whose name was on them. The signal that would have caught this is duplication, which is far easier to test for and which nobody appears to have run.
What the model was actually for
The model was reportedly used for three jobs, none of them the authorship of the core articles.
It drafted the social posts that carried the material outward, which is volume work across five platforms in a language the operators speak. It worked in Russian, so it was also removing the friction of operating in a second language at scale.
It was also explicitly instructed to strip from the text any features that might betray where it came from. That was not a prompt for good writing but for unremarkable writing — a different objective, and one a model is unusually well suited to.
This runs directly against the direction provenance efforts are moving. The current industry answer to synthetic content is to mark it — the same logic behind declared AI labels on music and behind statutory detection requirements such as California's transparency act. Those schemes work on content the producer is willing to declare. An operator asking the model to launder its own fingerprints is the population the schemes cannot reach.
A think tank with an address and no people
The institutional shell is worth examining because it is reusable and cheap.
A think tank needs remarkably little to look real from the outside. A name with a respectable ring, a website, a street address, a list of fellows and a body of published work. Every item on that list can be fabricated or stolen, and none of them is routinely verified by the journalists, aggregators or search engines that will encounter it.
The sovereignty index is the sharpest part of the design. An index is a manufactured citation magnet. It produces a ranking, which generates coverage, which in turn confers the very authority the ranking was invented to claim. It is also self-renewing, since it can be published annually.
The Israeli street address deserves its own note. An operation running from Russia and promoting Kremlin narratives chose to present itself as based somewhere else entirely, which is the whole purpose of the apparatus — the geography of the letterhead is a claim, and it costs nothing to make.
Reach is no longer the metric, and that cuts both ways
OpenAI frames this takedown by the apparatus the operators built rather than by how many people saw the content. That is a real shift and it is mostly right.
Engagement numbers were always a poor measure of an influence operation. Most fail to reach anyone, and reporting a takedown alongside a low view count invites the conclusion that nothing happened, when the intended audience may have been a handful of journalists or a single search result.
The caveat is that apparatus is harder to verify than reach. A view count can be checked. An assessment that infrastructure was significant rests on the assessor's judgement, and the assessor is the company that removed it. That is not a reason to disbelieve OpenAI, whose disclosure here is detailed and specific. It is a reason to notice that the industry has moved to a metric which cannot be independently audited, at the same time as it has become the sole reporter of its own enforcement.
The block that a VPN solved
OpenAI does not serve users in Russia. The operators used a VPN, and that was the whole of it.
Nobody should be surprised, and the point is not that the control failed. Geographic restrictions of this kind are compliance instruments — they establish that a company does not knowingly serve a jurisdiction — and they were never security controls. A determined operator crosses them for a few dollars a month.
Access restrictions are clearly not the whole defence. The detection that mattered here was behavioural — noticing a cluster of accounts working in a characteristic pattern, regardless of their apparent origin.
What it means from here
For readers in this region the transferable lesson is about verification rather than about Russia. A named institute with a website, an address and a body of published research is not evidence of anything, and the components that make it look substantial are the cheapest parts to fake.
Two checks would have caught this one, and neither requires specialist tooling. Paste a paragraph of an institute's flagship research into a search engine and see whether it appears elsewhere first. Then look for the people — not a list of names, but whether those individuals have a professional existence that predates the organisation.
Indices deserve particular scepticism, because they are the highest-leverage format in this genre. Anything that ranks countries should be traceable to a stated methodology and to researchers who can be found working somewhere else. If it cannot, the ranking is the product and the research is the packaging.