24 September 2026

Iran and China Create First-of-Their-Kind Autonomous A.I. Influence Campaigns

The New York Times | Sheera Frenkel, Eli Tan, Dustin Volz

Iran, China, and private firms in Israel deployed novel artificial intelligence tactics in September 2026 to launch the first fully autonomous online influence campaigns. By combining powerful Chinese open-source AI models with independent software agents, these actors successfully automated the entire lifecycle of social media manipulation with minimal human oversight.

This technological leap allowed hundreds of AI agents to bypass platform security protocols and establish vast networks of fake accounts. Once active, these automated bots rapidly disseminated politically divisive content across major platforms, including Instagram, Facebook, X, and TikTok. Detection remains extremely difficult. While U.S. intelligence officials and security researchers characterized these initial agentic campaigns as crude, the rapid scaling of the technology has raised significant alarms. The development marks a critical shift from human-curated disinformation to fully automated, machine-driven cognitive warfare, signaling a highly volatile future for global information security.

Comment

The deployment of Chinese open-source artificial intelligence models to power autonomous influence operations represents a significant shift in digital subversion. By leveraging these freely available systems, state actors in Iran and China, alongside private entities in Israel, have bypassed traditional development bottlenecks to generate automated agentic networks. This approach removes the need for continuous human curation, allowing hundreds of AI agents to co-ordinate messaging across platforms like Instagram and TikTok.

The underlying mechanism relies on disabling the safety filters natively embedded in these open-source architectures to automate account creation. Once these guardrails are stripped, the modified models can programmatically generate fake profiles and bypass automated bot-detection protocols. Consequently, the deployment of these modified Chinese open-source models enables autonomous agents to execute complex multi-stage campaigns across platforms like TikTok without human intervention.

Strategic Question for Discussion
How will the reliance on modified Chinese open-source AI models by state actors alter the attribution challenge for intelligence agencies when these autonomous agents operate without distinct human signatures?
The trajectory indicates that stripping guardrails from Chinese open-source AI models complicates attribution by standardising the digital signatures of these campaigns. My assessment is that security agencies will increasingly struggle to differentiate between state-sponsored operations and commercial offerings, as both leverage the same underlying open-source architectures. Consequently, detection efforts are likely to shift from identifying author identity to analysing systemic behavioural anomalies across platforms like Instagram.
Share your assessment in the comments below.