Skip to main content
Back to AI NewsNews

Iran and China Used AI Agents in Novel Influence Campaigns

Iran and China deployed autonomous AI agents built on freely available Chinese models to conduct online influence operations, a New York Times report says.

cueball EditorialSaturday, 19 September 2026 4 min read

What Happened

Iran and China have used AI-powered autonomous agents, built on freely available Chinese large language models, to conduct influence campaigns online, according to a report by The New York Times. The campaigns represent a novel escalation in the use of generative AI tools for state-linked information operations, moving beyond simple content generation to the deployment of agents capable of carrying out sequences of online tasks with limited human direction.

What the Campaigns Involved

The influence operations used AI agents, which are systems that can plan and execute multi-step tasks autonomously, rather than generating single pieces of content on demand. The agents were constructed using Chinese AI models that are freely and publicly available, lowering the technical barrier to entry for actors seeking to conduct such campaigns. The New York Times report did not name the specific models involved but described them as models that can be accessed without cost or subscription restrictions.

The campaigns were described as novel in their construction and execution method, distinguishing them from earlier influence operations that relied on human operators producing content manually or using generative AI in a simpler, more direct fashion.

Background

State-linked influence operations using social media and digital platforms have been documented for more than a decade, with governments including Russia, China, and Iran previously linked to coordinated inauthentic behavior by researchers and platform operators. The use of generative AI in such campaigns was first widely flagged in 2023 and 2024, when OpenAI and Meta both published reports identifying state-linked actors using AI tools to generate text, translate content, and produce social media posts at scale.

The shift to autonomous AI agents marks a structural change in how such operations can be conducted. Agents can browse websites, post content, create accounts, and respond to other users without step-by-step human instruction, potentially allowing smaller teams to operate at greater scale.

Freely available Chinese AI models, including those released under open or permissive licenses by companies such as Alibaba, Baidu, and the research community, have expanded significantly in capability over the past two years. Their open availability has been cited by cybersecurity researchers as both an asset for legitimate developers and a resource that lowers costs for malicious actors.

Who Is Reporting and What Is Known

The primary source cited in the wire reports is The New York Times. The Express Tribune, reporting on the story, described the campaigns as using freely available Chinese AI models to create autonomous agents capable of carrying out online tasks. Neither publication named specific individuals arrested, charged, or sanctioned in connection with the operations at the time of the wire reports reviewed here.

Neither the Iranian government nor the Chinese government had publicly commented on the specific claims described in the New York Times report at the time these wire reports were filed.

Meta, OpenAI, and other platform companies whose services may have been targeted or used in the campaigns had not issued statements specifically addressing this report at the time of publication.

What It Means in Practice

The use of autonomous agents in influence operations introduces operational characteristics that differ from earlier methods. An agent can sustain activity continuously, adapt to platform changes, and execute tasks such as account creation, content posting, and engagement with other users without returning to a human operator for each action. This shifts the resource equation for those running such campaigns, reducing the need for large teams of human operators.

Cybersecurity and platform trust-and-safety teams have previously focused detection efforts on patterns of coordinated inauthentic behavior, including identical content, synchronized posting times, and linked account networks. Agent-driven campaigns may produce behavioral signatures that differ from those patterns, potentially complicating existing detection frameworks.

Platform companies and government cybersecurity agencies are expected to review the findings described in the New York Times report as part of ongoing efforts to update detection and response protocols for AI-assisted influence operations.

Get our editors' take on what it all means. Read the Editor's Blog →