10 October 2026

Beyond the bot farm: how AI agents are changing influence operations

Centre for Emerging Technology and Security | Sam Stockwell, Cannelle Roumanie-Dalal

State-backed actors in China and Iran are deploying autonomous AI agents to run end-to-end influence operations on major social media platforms. By operating with minimal human supervision, these decentralized networks actively engage users and bypass traditional security protocols, threatening to distort democratic public discourse at an unprecedented scale.

These campaigns leverage open-weight Chinese models stripped of safety guardrails and run on private hardware, placing them beyond the reach of model providers. Unlike traditional botnets that rely on repetitive, mechanical posting, these context-aware agents generate original content and simulate organic grassroots consensus. This capability was demonstrated in December 2024 when a coordinated foreign influence operation prompted Romania’s Constitutional Court to annul its presidential election. Platform defences fail against these irregular rhythms. With US midterms approaching, these autonomous tools challenge statutory frameworks like the UK's National Security Act 2023, which contains a specific provision covering election interference but cannot prevent decentralized, machine-led campaigns.

Comment

The deployment of autonomous AI agents running on open-weight models like those developed by Chinese firms represents a fundamental shift in covert influence operations. By stripping safety guardrails from open-weight models, Iranian and Chinese operators bypass provider-side content moderation entirely. This technical autonomy neutralises traditional platform-level defences, rendering the detection mechanisms of Meta and ByteDance largely obsolete.

The downstream consequence of this technical shift is already visible in systemic European electoral crises. The Romanian Constitutional Court's December 2024 annulment of its presidential election illustrates how uncoordinated-looking, algorithmically amplified campaigns on TikTok can bypass state intelligence monitoring. Future operations will likely exploit these decentralised architectures to overwhelm democratic regulatory frameworks like the UK's National Security Act 2023 before attribution can be established.

Strategic Question for Discussion
If state-backed actors increasingly deploy autonomous agent swarms on open-weight models, how can statutory frameworks like the UK's National Security Act 2023 deter operations that lack a centralised human command structure?
The trajectory indicates that traditional deterrence-by-punishment mechanisms within the National Security Act 2023 will struggle, as attribution becomes delayed and diluted across decentralised AI networks. Instead, defensive efficacy will likely depend on real-time, cross-platform behavioural analysis rather than post-hoc legal prosecution. My assessment is that statutory frameworks will increasingly rely on platform-enforced technical barriers rather than retrospective criminal prosecution to mitigate these autonomous campaigns.
Share your assessment in the comments below.
💬
Ask me
Ask Strategic Study India ×
ADVERTISEMENT