A population gains political power through its capacity to reason, understand institutions, and act on shared knowledge. Citizens exercise that power when they investigate a public decision or organize around evidence that those in authority would prefer to ignore. Actors who compromise that capacity can gain influence while concealing their intervention.
Disinformation recruits the institutions through which people judge claims. Fabricated authors borrow a publication’s reputation; forged directives invoke an authority’s mandate; coördinated websites make repetition look like independent corroboration. People can retain access to information while losing the means to establish who produced it and why. Holding power accountable requires institutions that can investigate those origins and protect people who challenge what they find.
The operations examined here document concealed state direction, fabricated publications, and citizens recruited into political activity under false pretenses. Those breaches establish that operators have penetrated processes through which people assess authority and decide how to act. Establishing state capture or a decisive electoral shift requires evidence connecting the intervention to that outcome. Institutions must address documented deception while investigators assess its wider consequences.
The long game
Soviet intelligence practiced these methods decades before generative AI. A September 1985 KGB telegram to Bulgarian State Security, reproduced with archival records by the Wilson Center, requested help spreading the false claim that AIDS originated in U.S. biological-weapons experiments. A September 1986 Stasi coöperation plan proposed distributing purported scientific evidence to strengthen anti-American sentiment and provoke political controversy in the United States. These records establish a coördinated effort across intelligence services and years, using publication and the appearance of scientific authority to advance a fabricated account (Selvage & Nehring, 2019).
These records establish a strategy sustained across years and institutions. Operators returned to a fabricated claim and sought new outlets through which to lend it authority. Contemporary campaigns continue that practice of concealing origins and recruiting trusted intermediaries. Assessing its consequences requires following changes in belief, behavior, and institutional decisions across campaigns; an election result alone cannot settle that question.
AI accelerates the production work by reducing the labor required to draft, translate, revise, and adapt material for different audiences. The contemporary operations examined below use it to prepare submissions and maintain fabricated identities (OpenAI, 2026). When those tasks require less time, operators can sustain more attempts to enter trusted institutions and respond to editorial demands. The strategic danger lies in making a repeated practice of deception easier to maintain. The resulting capacity for repeated submissions and tailored revisions gives operators more opportunities to secure institutional acceptance.
Manufacturing authority
In its October 8, 2026 investigation, OpenAI (2026) reported that operators linked to a Russia-origin operation claimed to have impersonated Lima’s Regional Directorate of Education. They described sending schools instructions for activities involving Ukraine, obtaining responses and photographs, and placing coverage in Peruvian and Polish media. OpenAI found coverage corresponding to parts of the operators’ account.
That coverage supports parts of the operators’ account, although OpenAI (2026) found that their reports could exaggerate achievements. Establishing the full sequence would require authenticated directives and testimony from the institutions involved.
If a school follows a forged directive, it can produce a real event whose photographs support a misleading explanation. The operator can use participants’ actions as evidence while concealing the purpose that brought them together. Disentangling fact from fiction thus gets messy and requires examining how the event came about as well as whether any of its outputs are authentic.
The same report (OpenAI, 2026) describes an Iran-origin operation using seven fabricated journalistic identities to place about 100 published or syndicated articles in legitimate outlets. The operators used ChatGPT to adapt submissions and pitches. The fabricated identities passed through editorial processes and reached readers under the authority of legitimate publications.
The publication’s reputation lends credibility to the fabricated author. An editor can assess an article’s quality while missing the “big picture” operation behind its submission. Once the outlet accepts the text, it gives the fabricated identity the appearance of editorial endorsement. Readers can mistake the publication’s acceptance for verification of the author’s identity.
Operators can recruit institutional authority by inducing people to publish an article or follow a directive. Those acts give deceptive accounts legitimacy, while AI helps operators meet the institution’s expectations for correspondence, revision, and administration.
The European External Action Service’s March 2026 report (European External Action Service [EEAS], 2026) documented 540 foreign information manipulation incidents involving 10,500 channels during 2025. It attributed 29 percent of the incidents to Russia and 6 percent to China; 65 percent remained unattributed. Its mapping of recurrent channels traces connections among state sources and covert networks. The report maps an infrastructure for distributing deceptive accounts across borders and platforms.
Compromising democratic choice
The U.S. Senate Intelligence Committee’s investigation of Russian interference in 2016 (U.S. Senate Select Committee on Intelligence, 2019) found that the Kremlin tasked and supported the Internet Research Agency. In one example of weaponizing disinformation, the committee documented IRA-controlled Facebook pages promoting opposing demonstrations at the same Houston location on May 21, 2016. Both events occurred. It also found that operators recruited Americans into offline activity, including organizing rallies and sharing personal information. This establishes a behavioral consequence: people acted through an operation whose identity they did not know. The deception reached beyond online circulation into political activity on the ground.
During the Czech Republic’s 2023 presidential election, the Interior Ministry documented a manipulated video that made Petr Pavel appear to advocate entering war with Russia. The ministry (Ministry of the Interior of the Czech Republic, Centre against Hybrid Threats, 2023) identified a Sputnik-linked Telegram account as the apparent first uploader. Its monitoring found that the outlets it examined shifted toward supporting oligarch Andrej Babiš in the runoff. The findings show foreign propaganda entering domestic electoral debate in support of Babiš. The manipulated video supplied a fabricated position on war for voters to judge.
In Germany, Doppelganger operators impersonated established media to circulate political narratives under borrowed editorial authority. The FBI’s September 2024 affidavit (Federal Bureau of Investigation [FBI], 2024) alleged that Russian companies operated the campaign under the direction of the Russian Presidential Administration. It describes notes from at least 20 meetings with that administration between April 2022 and April 2023 and attaches operational records as exhibits. The records describe target audiences, production tasks, and distribution methods; the affidavit attributes supervision to Sergei Kiriyenko. A note quoted in the filing states, “They are expecting fake news from us every day” (FBI, 2024, p. 23). The affidavit grounds its allegations of coördinated direction in operational records. EU DisinfoLab’s subsequent Germany assessment (Miguel, 2025) identifies support for the AfD among the goals described in leaked operational documents. By impersonating German media, operators presented foreign intervention as domestic journalism.
In Moldova, information manipulation accompanied other forms of interference. In its assessment of the September 2025 parliamentary election, the Organization for Security and Co-operation in Europe’s Office for Democratic Institutions and Human Rights (OSCE/ODIHR, 2026) identified foreign interference, illicit financing, cyberattacks, and widespread disinformation. The EU attributed a broader hybrid campaign to Russia and its proxies (Council of the European Union, 2025). OSCE/ODIHR (2026) found that the election remained competitive while these conditions hindered informed choice. Its concerns about legal remedies for parties excluded near election day underscore the need to hold countermeasures to democratic standards.
Domestic institutional bias creates a separate problem of democratic accountability. Here, incumbents use public resources and media access to shape the conditions of electoral competition. OSCE observers of Hungary’s 2022 election (OSCE/ODIHR, 2022) documented the overlap between government and ruling-party messaging, media bias, and opaque campaign financing under Viktor Orbán. They found that these conditions limited voters’ ability to make an informed choice, despite a competitive election and an orderly voting day. When incumbents use public institutions to amplify their party’s account, the authority of the state can become an electoral resource.
Conspiracy claims can undermine institutions’ ability to respond to a policy dispute. In the Netherlands, research on disinformation around farmers’ protests (Jahangir, 2023) describes unsupported accusations that environmental policy concealed plans to seize farmland for immigrant housing. Within far-right and anti-institutional mobilization, these claims cast officials, researchers, and journalists as participants in a hidden project. Their corrections can become evidence of the supposed conspiracy, leaving the claims insulated from scrutiny. The conspiracy makes the institutions responsible for explaining and evaluating policy appear complicit in a plot.
Covert interference, domestic conspiracy claims, and incumbent control of public communication require different explanations and remedies. Comparing them helps identify where citizens’ ability to assess evidence and contest authority comes under pressure. Evidence of electoral effects must account for each mechanism and the conditions in which it operates.
Targeting the production of evidence
Attacks on journalism extend this problem beyond elections. In July 2026, Graphika reported that Spamouflage-linked accounts targeted six Chilean journalists after their coverage of a copper-smuggling investigation involving Chinese buyers. The accounts circulated allegations of professional and personal misconduct while attempting to discredit the investigation. Turner (2026) assessed the operation as Chinese state-linked and described the content as showing signs of AI generation. The campaign targeted the journalists investigating the trade, attacking their credibility alongside their reporting.
A campaign against journalists can impose costs through threats, reputational attacks, and demands to answer fabricated allegations. Investigators should measure those costs, including time diverted from reporting and decisions to abandon an investigation. Those measures would capture pressure on the production of evidence alongside changes in audience belief.
A 2023 U.S. State Department disclosure (U.S. Department of State, 2023) described a Russian plan to route content through Latin American editorial teams for adaptation and publication. The department described a method for giving foreign-directed content the credibility of local publication.
In Lithuania and Latvia, investigations of Ghostwriter (Foster et al., 2020) documented fabricated content distributed through compromised websites and impersonated communications. Mandiant’s attribution assessment (Roncone et al., 2021) linked the technical group UNC1151 to Belarus and assessed Ghostwriter as supporting Belarusian government interests. A compromised website allows operators to distribute fabricated material under the guise of its owner’s authority and reputation.
Manufacturing corroboration
Website networks make coördinated repetition look like independent corroboration. France’s VIGINUM identified 193 sites in its February 2024 Portal Kombat investigation (VIGINUM, 2024), documenting coördinated distribution of pro-Russian material and efforts to gain search visibility. A reader encountering the same account across several domains might infer agreement among separate sources, although the sites can draw on common origins.
Citizen Lab’s 2019 investigation of Endless Mayfly (Lim et al., 2019) documented fabricated articles on domains impersonating outlets including The Guardian. Some stories crossed into mainstream coverage. Operators used redirects and deleted content to obscure the source after circulation, leaving references to articles whose origins became harder to inspect. Citizen Lab assessed the network as Iran-aligned with moderate confidence; the identities of its operators remained unknown. Once another publication repeats the story, the fabricated source has acquired the authority of an outlet the operator does not control.
AI can carry this manufactured agreement into a single answer. When a system retrieves several pages repeating the same planted claim, it may cite them as supporting sources without identifying their shared origin. The reader sees several references for an account that traces back to one operation. Repetition acquires the appearance of corroboration because the answer omits the relationship among its sources.
Operators can target the material a system retrieves for an answer or publish material that reaches a model’s training process. These routes require different evidence, because collection, training exposure, and influence on an answer are separate findings.
The American Sunlight Project documented examples (Freuden et al., 2025) of OpenAI models citing Pravda-network material in responses to selected prompts. Its small, purposive sample establishes that this retrieval can occur, without supplying a general rate across ordinary use.
An April 2026 DFRLab audit (Digital Forensic Research Lab [DFRLab], 2026) found about 40,000 English-language Pravda items in Common Crawl by November 2025. Common Crawl supplies data for some training pipelines, but inclusion in the archive does not establish inclusion in a particular model. DFRLab found that an open model could reproduce passages from other propaganda sources under prompted completion tests. Memorization does not establish endorsement or measure political influence on answers. The audit shows that coördinated publishing can reach archives used in training pipelines.
More troubling, Souly et al. (2025) found that 250 poisoned documents could induce a specified backdoor behavior in models ranging from 600 million to 13 billion parameters. Their experiment tested gibberish generation in response to a trigger. It establishes a vulnerability to that backdoor behavior under the tested conditions. Extending the finding to political persuasion would require experiments measuring changes in substantive answers and their effects on users. The study gives developers grounds to examine training security while leaving that political question unresolved.
As people rely on AI information and answers, the security of these pipelines becomes a public concern. Coördinated accounts can enter retrieval or training systems and reach users through answers that conceal their origins. Establishing whether an operation succeeded requires evidence from the systems involved.
These compromises exploit different grounds for trust: who issued an instruction, who published a claim, whether sources are independent, and how an AI system produced its answer. Identifying the point of compromise determines what an investigation must examine.
| Compromise | How it exploits trust | Example |
|---|---|---|
| Authority impersonation | Operators forge instructions so an institution acts on authority the sender does not possess. | Operators described impersonating Lima’s education directorate; OpenAI corroborated parts of their account through published coverage (OpenAI, 2026). |
| Fabricated authorship | A legitimate publication lends its reputation to a concealed operator using an invented identity. | Seven fabricated identities placed about 100 published or syndicated articles in legitimate outlets (OpenAI, 2026). |
| Publication infrastructure compromise | Operators insert fabricated material into a website whose owner readers recognize. | Ghostwriter distributed fabricated content through compromised websites and impersonated communications (Foster et al., 2020). |
| Manufactured corroboration | Coördinated websites make repetition from shared origins appear to be agreement among independent sources. | VIGINUM mapped 193 sites distributing pro-Russian material through a coördinated network (VIGINUM, 2024). |
| Retrieval contamination | An AI system brings coördinated material into an answer, giving it another channel of distribution. | Selected prompts elicited answers citing Pravda-network material (Freuden et al., 2025). |
| Training-data poisoning | Attacker-supplied training material changes a model’s behavior, allowing the compromise to persist without live retrieval. | An experiment induced trigger-based gibberish with 250 poisoned documents. It tested a backdoor, rather than political persuasion (Souly et al., 2025). |
Controlling the terms of participation
Deception conceals who is shaping public judgment. Officials can also constrain judgment by demanding that people adopt their account as a condition of access. The following cases concern this overt use of authority: political leaders prescribe language and treat refusal as disloyalty.
Trump’s January 2025 executive order (Trump, 2025) directed federal naming changes from the Gulf of Mexico to the Gulf of America. His August 2026 order (Trump, 2026a) directed the renaming of Lake Ontario as Lake America in federal geographic records and communications. These directives govern U.S. federal usage; they do not establish international acceptance.
Renaming has many purposes, including the restoration of identities that earlier authorities suppressed. The democratic concern depends on how officials impose a change and respond to people who challenge it.
For example, on February 11, 2025, the Associated Press stated that the White House had conditioned access to an Oval Office event on acceptance of the Gulf naming order in its editorial standards. Associated Press (2025) reported that its journalist was excluded. According to this firsthand account, access became a means of enforcing a political choice.
Google carried the naming change into its maps. In its February 10, 2025 announcement, Google (2025) stated that U.S. users would see “Gulf of America,” Mexican users would retain “Gulf of Mexico,” and users elsewhere would see both names. It explained the change as its practice of following official geographic records. Through that policy, an executive naming decision became the label displayed in a commercial information service. Google implemented the government’s preferred terminology while AP retained its editorial standard and faced exclusion. The comparison shows how platform policy can extend a political naming decision beyond federal communications.
Trump has since extended this demand for linguistic conformity to AI. His September 29, 2026 executive order (Trump, 2026b) directed executive agencies to replace “artificial intelligence” with “super intelligence,” while retaining the existing statutory definition of the technology. The order establishes a preferred designation without demonstrating a change in capability. In an October 8 social media post (preserved in an archive), Trump (2026c) called anyone who used the established term “THE ENEMY!”
Declaring citizens enemies for refusing a leader’s vocabulary uses the language of totalitarian conformity. It turns a choice of terminology into a test of allegiance and casts dissenters, including fellow citizens, as people outside legitimate public discussion. Language itself has become weaponized against the citizenry.
Orwell’s (1946) analysis of political language helps explain the stakes of this demand. Authorities can preserve a word’s meaning while making its use a reason to withhold access or question a person’s allegiance. In the AP case, a preferred vocabulary became a condition of participation. The AI declaration extends that demand by branding people enemies for retaining the established term.
AI systems influence how users interpret these demands. I use ChatGPT and Gemini to review my writing. In a review of this article, Gemini described Trump’s enemy designation as “standard, albeit toxic, political rhetoric” and dismissed its relevance to the argument. Calling it toxic acknowledges the harm; invoking its familiarity discounts the demand for conformity. Calling citizens “enemies” for their vocabulary in a country that champions itself for free speech draws a boundary around who belongs in legitimate public discussion. It draws boundaries between citizens, creating rifts that allow the formation of first-class and second-class citizenry.
Industry leaders have also adopted the administration’s terminology. The September 29 White House accord (White House, 2026) bears the “super intelligence” title and the signatures of leaders from Google, Anthropic, OpenAI, Meta, xAI, and Nvidia alongside Trump’s. This records accommodation of the administration’s preferred language in a joint industry commitment. The political choices of those who govern AI companies belong under the same scrutiny as the systems they deploy. Institutions that rely on those systems must examine how their answers characterize demands for obedience and whose judgments define acceptable dissent.
Private control over public judgment
AI providers shape the information users receive and hold records needed to investigate manipulation of their systems. When they also choose which incidents to disclose, they control much of the evidence by which the public judges their performance. This concentration of authority requires transparency backed by regulation.
OpenAI and Anthropic’s investigations reveal activity that outside researchers cannot observe. Anthropic (2026) states in its September 2026 threat report that it selected notable cases. That selection leaves readers without a basis for judging how representative those cases are. Providers must disclose their monitoring priorities, case-selection criteria, coverage gaps, and known detection failures, including failures identified through external audits.
Regulation must require security testing, evidence preservation, incident reporting, and public disclosures that permit comparison across providers. Those reports should distinguish detected attempts, verified distribution, and demonstrated effects, explain attribution standards, and document corrective action. Providers must also disclose government requests to remove or alter content, subject to defined legal restrictions. These records would let institutions examine both covert manipulation and political pressure on the systems they use.
Independent regulators need legal authority to obtain records, commission audits, order corrective action, and impose penalties for breaches of these duties. Qualified researchers need protected access to evidence for testing providers’ claims. Confidential review can protect personal information and detection methods while producing public findings. Companies must justify restrictions on access before an independent authority. Providers cannot remain the final judges of their own security.
Oversight must include the authority to suspend or disable a compromised system. Regulators must establish that poisoning, unauthorized interference, or manipulation of a system’s information sources has compromised its operation and creates a serious, ongoing risk. An erroneous answer or disputed interpretation alone provides insufficient grounds. Orders must target the affected model, retrieval pipeline, or deployment and extend to the wider system when the provider cannot contain the compromise. Resuming service must depend on independent verification of containment and compliance with defined security requirements. Disclosure alone leaves people exposed when the compromised system continues to operate.
These powers require safeguards against political capture. Law must define the grounds for intervention, protect regulators from dismissal for decisions that challenge government or industry, and require reasons that affected parties can contest in court. Emergency suspension must be temporary and receive prompt judicial review. A shutdown order must rest on evidence of compromise and risk; criticism of officials or refusal to adopt their terminology cannot qualify. The same law that enables intervention must protect inquiry from those who would use regulation to enforce obedience.
Education as a foundation for political power
Education shapes a population’s capacity to assess authority and exercise power. Years of schooling provide a poor measure of that capacity when institutions reward compliance and the reproduction of approved accounts. The political value of education depends on whether people can examine evidence and act on their judgments.
People need access to information connected with reality, institutions that can investigate, and the freedom to challenge claims and organize around their findings. Intellectual safety protects them from coercion or retaliation for inquiry, criticism, and the expression of ideas, including ideas that challenge those who control their employment, funding, access, or freedom. Expertise depends on access to evidence and protection for those who question authority.
A campaign can undermine these conditions without targeting a curriculum. It can undermine journalism, misrepresent research, impersonate public authorities, or contaminate the systems people use to answer questions. Such attacks target the settings through which a society learns about itself. When foreign actors conduct them, they can weaken a population’s capacity to judge its own political circumstances while concealing the intervention.
In Democracy and Education, Dewey (1916) links democratic life to shared experience and communication, extending the educational question beyond formal schooling. Disinformation corrupts the relationships through which people develop that common basis for action. When operators compromise those channels, they obstruct the process through which people connect experience to public claims and examine their choices.
Institutional responsibility
Schools and universities bear responsibility because their authority over students’ lives can contribute to that compromise. The reported Peru operation illustrates the risk: a school that follows a forged directive can turn an operator’s claim into an event. A university can give a concealed sponsor access through a partnership. An educator can turn an AI synthesis into teaching material without examining the sources supporting it. These are institutional decisions whose consequences reach beyond the person making them.
Educational institutions need support matched to the threats they face. Public authorities must investigate covert financing and impersonation and fund specialists who can trace domains, accounts, and financing across borders. Schools and universities need access to that expertise; a teacher cannot audit a model’s training history or reconstruct a state-backed network from its public pages. Assigning those tasks to educators without investigative support leaves the sources of compromise beyond their reach.
Open Government Partnership’s information-integrity guidance (Open Government Partnership, n.d.) recommends disclosure of media ownership and financing, platform reports on government takedown requests, and support for independent investigation through public, rule-based funding. These measures address concealed control and give researchers evidence for examining public decisions. Their effectiveness requires evaluation, and restrictions on expression require legal remedies. A government must remain subject to scrutiny when it claims to be defending the public from deception.
People and institutions also need authority to act on what they discover. Staff and students must be able to report suspected manipulation, obtain an independent review, and seek correction without risking their employment, funding, or standing. Institutions need procedures for suspending decisions based on compromised evidence and replacing providers that fail to remedy documented breaches. Protection for whistleblowers and access to appeal make these powers usable when the findings implicate institutional leaders or commercial partners.
Protecting inquiry requires resources and authority. Institutions need to confirm consequential instructions through established channels, examine the control and financing behind partnerships, and assess whether sources provide independent evidence. Staff need time, access, and authority to carry out those checks. Policies that assign verification duties without resources create an appearance of protection while leaving the underlying dependence intact.
When institutions discover compromised information, they must correct the decisions and materials that relied on it and explain their verification process and what remains uncertain. That record gives people grounds to judge whether the institution deserves their trust.
Build a Positive Rebellion:
Create New Education Futures
(available in print and PDF download).
In Build a Positive Rebellion: Create New Education Futures (Moravec, 2026), I connect learning to the agency people need to examine and change the conditions of their lives. That commitment requires examining who shapes public understanding and whether agreement across sources reflects independent inquiry. Knowledge depends on the interpretation of evidence, so educational institutions must keep their accounts of reality open to examination. Trust grows when people can question a claim, inspect its grounds, and seek a correction without penalty. These obligations extend to the institution itself, including its leaders, partners, and technology providers.
Students should participate in this work through investigations that let them trace a claim, compare its sources, and explain the limits of their findings. Institutions must support them when that investigation reaches an official account or a commercial partner. An exercise in critical thinking has little credibility if the student learns that some authorities are protected from the questions the exercise encourages.
Leaders must accept scrutiny of their judgments and protect people whose evidence challenges an accepted account. That protection allows an institution to discover deception and correct its consequences.
An institution can retain its reputation and procedures while losing the capacity to explain its decisions. Operators who secure its acceptance can exploit that authority, teaching people to trust claims the institution has failed to examine.
Democratic education depends on people being able to act on what they know when doing so challenges power. Protecting that capacity requires institutions to defend inquiry and the people who undertake it, providers to secure the systems that shape public knowledge, and public authorities to support investigation and accountable oversight. When these actors surrender those responsibilities, they leave the people they serve exposed to those who would exercise power through deception.
References
Anthropic. (2026, September). Detecting and countering misuse of AI: September 2026. https://www.anthropic.com/threat-intelligence-report-september-2026
Associated Press. (2025, February 11). AP statement on Oval Office access. https://www.ap.org/the-definitive-source/announcements/ap-statement-on-oval-office-access/
Council of the European Union. (2025, September 29). Republic of Moldova: Statement by the High Representative on behalf of the EU on the parliamentary elections. https://www.consilium.europa.eu/en/press/press-releases/2025/09/29/republic-of-moldova-statement-by-the-high-representative-on-behalf-of-the-eu-on-the-parliamentary-elections/pdf/
Dewey, J. (1916). Democracy and education: An introduction to the philosophy of education. Macmillan. https://www.gutenberg.org/cache/epub/852/pg852-images.html
Digital Forensic Research Lab. (2026, April 8). Pravda in the pipeline: Early evidence of state-adjacent propaganda in AI training data. Atlantic Council. https://dfrlab.org/2026/04/08/pravda-in-the-pipeline/
European External Action Service. (2026, March). 4th EEAS report on foreign information manipulation and interference threats. https://www.eeas.europa.eu/sites/default/files/2026/documents/EEAS%204th%20Threat%20Report_web.pdf
Federal Bureau of Investigation. (2024, September 4). Affidavit in support of seizure warrant, United States v. Certain Domains (Case No. 2:24-mj-01395, Document 4). U.S. District Court for the Eastern District of Pennsylvania. https://www.justice.gov/d9/2024-09/doppelganger_affidavit_9.4.24.pdf
Foster, L., Riddell, S., Mainor, D., & Roncone, G. (2020, July 28). Ghostwriter influence campaign: Unknown actors leverage website compromises and fabricated content to push narratives aligned with Russian security interests. Google Cloud. https://cloud.google.com/blog/topics/threat-intelligence/ghostwriter-influence-campaign/
Freuden, S., Jankowicz, N., & Marcus, G. (2025, July 11). Bad actors are grooming LLMs to produce falsehoods. American Sunlight Project. https://americansunlight.substack.com/p/bad-actors-are-grooming-llms-to-produce
Google. (2025, February 10). Gulf of America name change in the U.S.: What you’ll see in Maps. The Keyword. https://blog.google/products-and-platforms/products/maps/united-states-geographic-name-change-feb-2025/
Jahangir, R. (2023, September 19). The disinformation landscape in the Netherlands. EU DisinfoLab. https://www.disinfo.eu/wp-content/uploads/2023/09/20230919_NL_DisinfoFS.pdf
Lim, G., Maynier, E., Scott-Railton, J., Fittarelli, A., Moran, N., & Deibert, R. (2019, May 14). Burned after reading: Endless Mayfly’s ephemeral disinformation campaign. The Citizen Lab. https://citizenlab.ca/research/burned-after-reading-endless-mayflys-ephemeral-disinformation-campaign/
Miguel, R. (2025). The disinformation landscape in Germany. EU DisinfoLab. https://www.disinfo.eu/wp-content/uploads/2025/08/20250714_Disinfo-landscape-in-Germany-v2-2.pdf
Ministry of the Interior of the Czech Republic, Centre against Hybrid Threats. (2023). Souhrn poznatků k českým prezidentským volbám 2023 [Summary of findings on the Czech presidential elections 2023]. https://mv.gov.cz/chh/souhrn-poznatku-k-ceskym-prezidentskym-volbam-2023
Moravec, J. W. (2026). Build a positive rebellion: Create new education futures. Education Futures LLC. https://doi.org/10.5281/zenodo.18744715
Open Government Partnership. (n.d.). Digital governance: Disinformation and information integrity. Open Gov Guide. https://www.opengovpartnership.org/open-gov-guide/digital-governance-disinformation-and-information-integrity/
OpenAI. (2026, October 8). Disrupting AI-enabled “false front” operations. https://openai.com/index/disrupting-ai-enabled-false-front-operations/
Organization for Security and Co-operation in Europe, Office for Democratic Institutions and Human Rights. (2022, April 4). Hungary’s parliamentary elections well-run and offered distinct alternatives but undermined by absence of level playing field, international observers say. https://odihr.osce.org/odihr/elections/hungary/515135
Organization for Security and Co-operation in Europe, Office for Democratic Institutions and Human Rights. (2026, February 18). Moldova parliamentary elections 2025: ODIHR election observation mission final report. https://odihr.osce.org/news/odihr/662254
Orwell, G. (1946). Politics and the English language. The Orwell Foundation. https://www.orwellfoundation.com/the-orwell-foundation/orwell/essays-and-other-works/politics-and-the-english-language/
Roncone, G., Wahlstrom, A., Revelli, A., Mainor, D., Riddell, S., Read, B., & Mandiant Research Team. (2021, November 16). UNC1151 assessed with high confidence to have links to Belarus, Ghostwriter campaign aligned with Belarusian government interests. Google Cloud. https://cloud.google.com/blog/topics/threat-intelligence/unc1151-linked-to-belarus-government/
Selvage, D., & Nehring, C. (2019, July 22). Operation “Denver”: KGB and Stasi disinformation regarding AIDS. Wilson Center. https://www.wilsoncenter.org/blog-post/operation-denver-kgb-and-stasi-disinformation-regarding-aids
Souly, A., Rando, J., Chapman, E., Davies, X., Hasircioglu, B., Shereen, E., Mougan, C., Mavroudis, V., Jones, E., Hicks, C., Carlini, N., Gal, Y., & Kirk, R. (2025). Poisoning attacks on LLMs require a near-constant number of poison samples [Preprint]. arXiv. https://doi.org/10.48550/arXiv.2510.07192
Trump, D. J. (2025, January 20). Restoring names that honor American greatness (Executive Order 14172). The White House. https://www.whitehouse.gov/presidential-actions/2025/01/restoring-names-that-honor-american-greatness/
Trump, D. J. (2026a, August 27). Honoring the American history of the Great Lakes and renaming Lake Ontario as Lake America (Executive Order 14422). Federal Register, 91(169), 56543–56544. https://www.govinfo.gov/content/pkg/FR-2026-09-02/pdf/2026-18020.pdf
Trump, D. J. (2026b, September 29). Inaugurating the era of super intelligence (Executive Order 14434). The White House. https://www.whitehouse.gov/presidential-actions/2026/09/inaugurating-the-era-of-super-intelligence/
Trump, D. J. (2026c, October 8). The White House considers anyone that uses the term, “Artificial Intelligence” [Post]. Truth Social. Archived by Trump’s Truth. https://www.trumpstruth.org/statuses/42201
Turner, L. (2026, July 30). Ore else: Spamouflage targets Chile’s copper smuggling coverage. Graphika. https://www.graphika.com/reports/ore-else
U.S. Department of State. (2023, November 7). The Kremlin’s efforts to covertly spread disinformation in Latin America. National Security Archive. https://nsarchive.gwu.edu/sites/default/files/documents/semon9-ryglx/2023-11-7-DOS-Kremlin-Covert-Disinformation-in-Latin-America.pdf
U.S. Senate Select Committee on Intelligence. (2019). Report on Russian active measures campaigns and interference in the 2016 U.S. election: Volume 2, Russia’s use of social media, with additional views. https://www.intelligence.senate.gov/sites/default/files/documents/Report_Volume2.pdf
VIGINUM. (2024, February). Portal Kombat: Un réseau structuré et coordonné de propagande prorusse [Portal Kombat: A structured and coördinated network of pro-Russian propaganda]. Secrétariat général de la défense et de la sécurité nationale. https://www.sgdsn.gouv.fr/files/files/20240212_NP_SGDSN_VIGINUM_RAPPORT-RESEAU-PORTAL-KOMBAT_VF.pdf
White House. (2026, September 29). White House accord on super intelligence. The American Presidency Project. https://www.presidency.ucsb.edu/documents/white-house-accord-super-intelligence




