Iran and China AI Agents Used for Social Media Campaigns: NYT Report
.png)
Nearly 80,000 people followed a network of Instagram, Facebook and X accounts posing as ordinary Americans in cities such as Washington, D.C., San Diego and Atlanta. The accounts did not belong to the people they claimed to represent. Behind the network was a coordinated influence operation that, according to reporting and researchers, relied heavily on AI agents rather than conventional human-run account management.
A New York Times investigation published on September 18, 2026, linked the operation to Iran. The same investigation described a separate China-linked campaign that used a comparable AI-driven approach, although fewer operational details were publicly available about the Chinese case.
Together, the cases point to a possible shift in how state-linked influence operations are organized: from humans producing and managing individual pieces of content to software systems capable of handling multiple connected tasks with limited human supervision.
An AI Agent Is More Than a Content Generator
The distinction matters.
A standard generative AI tool answers a prompt at a time. Ask it to write a post or translate a sentence, and a human still has to decide what to do with the result, review it and publish it.
An AI agent works differently. Given a broader objective, it can complete a sequence of tasks with less direct supervision: researching a subject, generating material, interacting with accounts, organizing information and adjusting actions based on what it observes.
That is the capability highlighted by the Times investigation.
The reported operations used AI systems together with social-media infrastructure to automate parts of the campaign lifecycle. Instead of simply generating text or images, the systems could help coordinate networks of accounts and maintain activity across multiple platforms.
In effect, AI was becoming part of the operational machinery rather than remaining only a writing assistant.
The Iran-Linked Network Was the Clearest Example
The Iran-linked campaign is the more thoroughly documented of the two.
According to the Times investigation and officials familiar with the activity, AI-generated accounts built fake identities as everyday Americans, engaged with journalists and politicians by tagging them directly, and circulated memes and political talking points. During the first half of 2026, the network accumulated nearly 80,000 followers combined.
That number needs context.
Followers do not equal people who were persuaded, and audience size does not by itself establish political impact. An influence operation can instead seek to amplify a narrative, make a particular viewpoint appear more common than it is, or pull genuine users into arguments that help spread the intended message.
A separate case disclosed by Meta in August provides another useful comparison. Meta removed four Facebook accounts and 31 Instagram accounts linked to an Iran-based operation that used AI to generate some political content. The accounts posed as Americans, including activists, students and graphic designers, and were followed by roughly 79,400 Instagram accounts before removal. Meta assessed the operation's overall reach as moderate and described its engagement as meaningful but limited.
That is an important distinction between visibility and measurable influence.
Why the China Evidence Needs More Care
Less public detail is available about the Chinese side of the Times investigation, and that limits what can safely be concluded from it.
The New York Times reported that investigators identified a China-linked campaign using comparable AI-agent techniques and assessed both the Iranian and Chinese operations as state-backed. But the publicly described evidence for the Chinese campaign was less detailed than the material discussed about Iran.
The broader technical issue is easier to establish.
The campaigns reportedly relied on Chinese open-source or open-weight AI models. These systems can be downloaded, modified and operated outside the direct control of the company that originally developed them.
That creates a different governance challenge from a closed commercial AI service.
A company can suspend access to its own hosted model. A locally deployed copy of an open model is much harder for a model provider to monitor or shut down.
Anthropic's September Findings Show the Problem Is Broader
The Times investigation was not an isolated warning.
Anthropic's September 2026 threat-intelligence report documented a wider range of state-aligned actors using Claude for influence and surveillance activities. The company said the cases covered operations it had disrupted between December 2025 and August 2026.
In several Iranian cases, Anthropic said state-aligned actors used Claude to build campaign plans, persona systems, target databases and other material for influence operations. It also found evidence of attribution laundering, in which content was designed to appear as if it came from independent or foreign sources.
The company separately documented China-linked surveillance activity in which Claude was used to process social-media content and identify material considered politically sensitive. It also described a China-aligned recruitment operation targeting Uyghur individuals in Syria, while noting the nature and confidence level of its attribution.
Another case involving an Iranian opposition network illustrated a different capability: Anthropic said operators used an AI agent to study roughly 8,400 Telegram posts from a real activist and then use the resulting material to imitate that person's writing during live conversations.
These cases are not identical to the Iranian campaign described by the New York Times. They do, however, reinforce the broader point that AI agents are being tested for tasks that previously required larger teams of human operators.
The Real Innovation Is the Workflow
AI-generated propaganda is not new.
Foreign influence campaigns have used automated text generation, fake personas, bots and synthetic media for years. The newer development is the ability to connect several of those functions into a single workflow.
An agent can be instructed to identify an audience, create or manage an online persona, generate material, interact with users and continue operating according to a broader objective.
That changes the economics of influence operations.
A campaign that previously required people to perform repetitive tasks manually can potentially automate a meaningful portion of that workload.
The content itself may not be especially sophisticated.
The important development is that the operation can become more persistent.
Why Detecting These Networks Is Getting More Difficult
Past influence campaigns often produced recognizable signals: repeated language, similar posting schedules, groups of accounts created around the same time, or clear patterns of manual coordination.
AI agents can make some of those signals harder to detect.
A system can generate different wording for different audiences while maintaining the same underlying narrative. It can also operate across platforms and react to user responses more quickly than a small human team could.
Researchers have cautioned that the campaigns identified so far were still relatively crude.
That is significant.
The concern is not that AI agents have already mastered human persuasion. It is that the amount of human labor needed to operate deceptive networks may be falling.
A campaign does not need every fake account to become influential.
A small number of successful accounts can acquire genuine followers, enter real conversations or get content amplified by real users.
That creates a hybrid environment in which automated activity can eventually be mixed with authentic human engagement.
The 2026 U.S. Election Makes the Timing More Sensitive
The development comes at a particularly important point in the U.S. political calendar.
The next regularly scheduled U.S. federal general election is November 3, 2026, meaning the country is now just over a month away from the midterms.
That does not mean the Iranian or Chinese campaigns identified in September will influence the election.
There is currently no evidence that the nearly 80,000-followers Iranian network changed voting behavior on a measurable scale.
The more immediate concern is operational.
If AI agents make it cheaper to create fake identities, maintain networks and interact with real users, the number of attempts to influence political discussion could increase.
That could make it harder for voters to distinguish genuine grassroots activity from coordinated foreign operations.
Social Platforms Are Already Using AI to Fight AI-Enabled Abuse
Social-media companies are responding with their own detection systems.
Meta has said AI-generated content is increasingly common across influence networks it disrupts. The company combines behavioral signals, account relationships, technical infrastructure and other indicators to identify coordinated inauthentic activity.
The August Iran-linked takedown demonstrated both the scale and the limits of the problem.
The network attracted tens of thousands of followers, but Meta assessed its actual reach as moderate and its engagement as meaningful but limited.
The company also said the operators used infrastructure in the United States and Canada to make the operation's Iranian origin harder to detect.
This illustrates why content moderation alone is not enough. Platforms must examine how accounts behave as networks, not simply what a single post says.
Open Models Create a Different Kind of Governance Problem
Closed AI systems are relatively easier to govern.
The company operating the service can impose usage rules, monitor suspicious activity, require verification and remove accounts.
Open models distribute that responsibility across a much wider ecosystem.
An AI model can be developed in one country, downloaded somewhere else, modified by another group, hosted on private infrastructure and then used to target people in an entirely different jurisdiction.
That creates a difficult enforcement problem.
Social-media companies control their own platforms. AI developers control their hosted services. Cloud providers control infrastructure. Governments control national laws.
But no single actor necessarily controls the entire chain.
The Election Risk Is About Trust as Much as Persuasion
It is easy to measure followers, views and posts.
It is much harder to measure whether an influence campaign actually changes what people believe.
That distinction is particularly important here.
The Iranian network's nearly 80,000 followers may sound large, but the available reporting does not establish that those followers were persuaded or even that they were all unique individuals exposed to the campaign's broader messaging.
The more measurable risk may be the gradual weakening of trust.
If users cannot reliably tell whether an account represents a real American, a political organization, a foreign operation or an automated system, ordinary online discussion becomes harder to interpret.
That can affect journalism, political organizing, advertising and public debate even without a campaign directly changing many people's views.
The Next Phase Will Be About Scale and Persistence
Expect the next stage of this technology competition to focus less on making one fake post look perfect and more on keeping entire networks active for longer periods.
Platforms will likely continue improving behavioral detection, identity verification and network-level analysis.
Intelligence agencies and researchers will also keep looking for connections between online activity and the people or organizations behind it.
The harder scenario would be a system that can sustain a believable persona over months, respond naturally to users and coordinate activity across several services at once.
That is where the distinction between a bot and an autonomous influence system becomes increasingly important.
The Bigger Question Is Whether Online Crowds Are Real
Social media has never been a perfect measure of public opinion. Bots, fake accounts and coordinated campaigns existed long before today's AI systems.
AI agents do not create that problem from nothing.
What they change is the cost and flexibility of running it.
The September 18 investigation describes a threshold in which AI agents were used across much of the influence-operation workflow, while Anthropic's September report documents related examples involving Iranian and Chinese state-aligned actors in influence and surveillance activities.
The evidence does not show that autonomous AI campaigns are already capable of reliably controlling public opinion at scale.
It does show that the infrastructure for automated influence is becoming more capable.
The important question for the coming U.S. election period is therefore not whether every political account might be artificial.
It is whether platforms, regulators, researchers, journalists and ordinary users can still distinguish authentic public participation from increasingly automated networks designed to look authentic.
As AI systems become better at maintaining identities, generating varied content and interacting continuously, the challenge will move beyond detecting individual fake posts.
It will become a question of whether the structure behind online activity can still be trusted.
About The Author
Amjad Ali Abid is a Senior Analyst at The American Times, specializing in U.S. Politics, Global Finance, and Economic Policy. With a focus on fact-based reporting, his analysis is based on primary sources, official data, and verified reports from Reuters, Associated Press, and U.S. Government releases.Editorial Disclaimer: This article is for informational purposes only and does not constitute financial or political advice. All information is accurate as of the publication date and has been cross-checked with credible sources. The American Times strives for accuracy but encourages readers to verify key facts from official sources.
Amjad Ali Abid is a Senior Analyst at The American Times, specializing in U.S. Politics, Global Finance, and Economic Policy. With a focus on fact-based reporting, his analysis is based on primary sources, official data, and verified reports from Reuters, Associated Press, and U.S. Government releases.
.png)

Comments
Post a Comment