Iran and China Use Autonomous AI to Build New Influence Campaigns
New research shows how AI systems are moving beyond content generation and becoming operational tools for surveillance, targeting, impersonation and coordinated influence activity.
Anthropic says it identified and disrupted influence and surveillance operations involving actors linked to Iran and China that used Claude as part of increasingly automated workflows. The activity included creating fake personas, analyzing large amounts of social-media data, generating targeted messages, impersonating real people and coordinating content across multiple platforms. The cases offer an early look at how AI agents could make influence operations faster, cheaper and more scalable.
Artificial intelligence is beginning to change the nature of online influence operations.
Instead of using AI simply to write a single post or create an image, some operators are now using AI systems as part of broader workflows that can analyze targets, develop personas, produce content, translate conversations and coordinate activity across platforms.
A September 2026 threat-intelligence report from Anthropic describes several such operations involving actors connected to Iran and China. Anthropic says the cases were detected and disrupted through its investigations, with the associated accounts subsequently banned.
AI Is Becoming Part of the Operation
The significance of these cases is not simply that AI-generated propaganda exists. Synthetic political content has been possible for years.
The more important development is the integration of AI into multiple stages of an influence campaign. Anthropic reported seeing actors use Claude to create campaign plans, develop personas, analyze information, generate multilingual content and organize distribution strategies.
In some cases, AI was also given persistent instructions and memory so that an agent could continue performing related tasks without requiring a person to manually direct every individual step.
Iran's AI-Assisted Influence Operations
Anthropic identified three Iranian state-aligned operations that used Claude to prepare influence campaigns. The organizations identified in the report included Iran's Islamic Culture and Communications Organization, the Islamic Propaganda Office of Khorasan Razavi and the Islamic Propaganda Organization's Bina Cultural Observatory.
According to Anthropic, the operators used AI to build campaign plans and operational manuals, create persona systems and transform official information into content aimed at different audiences.
The campaigns produced material in languages including Farsi, Arabic, Urdu, Malay, Spanish and English, with plans indicating an even wider multilingual reach.
Another important technique was attribution laundering. The operators attempted to make state-backed messages appear to originate from independent writers, ordinary users or foreign sources. Anthropic also reported examples in which fabricated claims were attributed to Western research institutions in an attempt to make the content appear more credible.
The Autonomous Agent Problem
One of the most significant developments is the emergence of AI workflows that can continue operating with limited human intervention.
In one operation described by Anthropic, a shared AI-agent platform maintained long-term memory files containing instructions, approved sources, account-management rules and other operational information. The system could then be used for scheduled content production and coordinated activity.
That is different from asking an ordinary chatbot to write a political message. The AI becomes part of an operational system capable of carrying information from one task to another.
The human operators still remained involved, including through approval and review processes. But the amount of work that could be delegated to software increased substantially.
AI Was Used to Impersonate Real People
Another case described by Anthropic involved an influence operation that used an AI agent to impersonate a real Iranian activist.
The operator instructed the system to study thousands of the activist's Telegram posts in order to reproduce his writing style. The resulting account was then used to communicate with the activist's contacts, who were reportedly unaware that they were interacting with an AI-assisted impersonation.
The operation also used large-scale social-media analysis to build profiles of individuals based on characteristics such as location, occupation and political alignment.
AI-generated avatars and Persian-language synthetic audio were also used in the campaign, according to Anthropic.
China's Use of AI for Surveillance and Influence
Anthropic separately described China-linked operations in which AI was used for surveillance, public-opinion monitoring and analysis of dissidents and other groups.
In one case, a China-based actor used Claude to process large quantities of social-media information and produce structured profiles containing details about individuals and their perceived political positions.
Another operation used AI to produce government-style public-opinion briefings that classified online content according to political sensitivity and identified individuals or organizations considered relevant to authorities.
Anthropic also described a China-linked operation involving an AI-assisted recruitment effort targeting Uyghur individuals in Syria. The system helped draft outreach in regional language, translate responses and support the operator during conversations.
The Scale Could Become the Real Threat
Traditional influence campaigns require people to research audiences, write messages, translate material, manage accounts and monitor reactions. AI can reduce the amount of human labor required for many of those tasks.
That does not automatically make every AI-assisted campaign successful. Anthropic said many of the operations it detected generated little or no authentic engagement, and several were disrupted before they could build significant audiences.
But the economics could still change. If one operator can manage hundreds of personas, translate content into numerous languages and adjust messages for different audiences, influence operations could become considerably cheaper to operate.
The Internet Could Become Harder to Trust
The long-term concern is not simply that people may encounter more AI-generated political content. It is that users may increasingly struggle to determine whether the person behind an account is real, whether a message represents an individual's genuine opinion and whether several apparently independent accounts are actually controlled by the same organization.
AI can also make influence campaigns more personalized. Instead of sending one message to millions of people, automated systems can potentially produce different versions for different communities, languages and demographic groups.
That could make traditional methods of detecting coordinated campaigns more difficult because the content itself may no longer look identical.
What This Means for AI Safety
These cases also illustrate why AI safety increasingly extends beyond questions about whether a model can produce harmful text or images.
The larger challenge is what happens when an AI model is connected to tools, databases, social-media accounts and persistent memory. A system with access to those capabilities can potentially become part of a much larger operation.
Anthropic says it banned the accounts involved in the operations described in its report and strengthened its detection systems. The company also shared relevant indicators with industry and research partners where appropriate.
The Next Phase of Influence Operations
AI has not invented political influence campaigns, surveillance or propaganda. Governments, political organizations and other groups have used these techniques long before modern generative AI existed.
What is changing is the potential speed, scale and automation of those activities.
The Iranian and China-linked cases documented by Anthropic show an early version of that future: AI systems assisting with research, targeting, translation, persona creation, impersonation and distribution while human operators remain responsible for the broader campaign.
As AI agents become more capable, the boundary between a chatbot that produces content and an autonomous system that operates a campaign could become increasingly important for governments, technology companies and internet users.
The most important shift may not be AI creating more convincing propaganda. It may be AI becoming capable of running more of the machinery behind influence itself.
Artificial intelligence, cybersecurity and the forces shaping the digital world.
