Updated 3 hours ago
AI Safety
Anthropic’s nine influence cases show distribution is not persuasion
A case‑by‑case reading of Anthropic’s September threat report separates AI‑generated output, verified audience reach and evidence of real‑world effects.
What the nine cases actually show
Anthropic’s September 10 threat report describes AI‑assisted influence operations producing fabricated news, political videos and radio scripts. Its most useful distinction is between making that material and getting it in front of an audience. Across the report’s nine influence‑operation case studies, our tally finds eight explicit reach ratings: one in Category One, three each in Categories Two and Three, and one in Category Four. The remaining case has no explicit rating, even though Anthropic matched some of its output to published and broadcast material. [Anthropic’s influence‑operation findings](https://www.anthropic.com/threat‑intelligence‑report‑september‑2026#influence‑operations‑sep‑26).
That uneven evidence matters. A network can manufacture thousands of articles without showing that ordinary readers engaged with them. An operator supplying an established broadcaster can have a route to audiences that a collection of fabricated social accounts lacks. Neither observation, by itself, measures how many people changed their minds. Reading the cases together reveals where Anthropic found distribution, where it found only production, and where the public record still cannot support a claim about effect.
The table preserves Anthropic’s own classifications. Each row represents a named case study, which can contain several accounts or operations; it does not represent one person, one account or one publication. The wider report describes activity it disrupted between December 2025 and August 2026, but individual campaign histories can extend beyond that window. These are selected cases detected by one provider, not a representative sample of all AI‑assisted influence activity. [Report scope and case studies](https://www.anthropic.com/threat‑intelligence‑report‑september‑2026).
| Case described by Anthropic | Its assigned category | Audience evidence and its limit |
| --- | --- | --- |
| Russian state‑aligned radio operation in the Central African Republic | 4 | Daily FM broadcasting, Telegram amplification and local outlets; no quantified change in listeners’ beliefs. |
| Commercial fabricated‑news network | 2 | Articles on its own websites and matching social accounts; no evidence of wider breakout. |
| Malaysia election‑manipulation platform | 2 | Assets across platforms; claimed dashboard results were not independently verified. |
| Russian state‑media production | Not assigned | Some generated material matched published or broadcast output; its share of the outlets’ total output was unknown. |
| Iranian state‑aligned operations | 3 | Material observed on aligned channels across platforms; a distribution finding rather than a persuasion result. |
| Bangladesh fabricated‑news operation | 3 | Matching videos found across social platforms; broader reach beyond observed accounts was not established. |
| MEK/NCRI‑aligned operation | 2 | Distribution through its own media properties and amplification accounts; authentic engagement was unconfirmed. |
| Kenyan political astroturfing | 1 | Anthropic classified the observed network as isolated on one platform. |
| UAE‑directed operation | 3 | Cross‑platform activity; delivery of intended testimony and dossiers was not confirmed in the detailed case. |
The result is seven of eight rated cases in Categories One through Three, with no explicit Category Five or Six assignment. It would be misleading to turn that into a failure rate. The unrated Russian state‑media case includes affirmative distribution evidence, while the rated cases have different objectives, observation periods and amounts of available evidence. A missing category belongs outside the tally, not at the bottom of it. [The nine underlying cases](https://www.anthropic.com/threat‑intelligence‑report‑september‑2026#influence‑operations‑sep‑26).
A reach category is not a measure of persuasion
The framework comes from Ben Nimmo’s 2020 Breakout Scale, which tracks movement between communities, platforms and forms of media. Category One remains within an initial community on one platform. Category Two can involve a wider audience on that same platform, or a presence across several platforms without spreading beyond the operation’s initial communities. Category Three involves breakouts across multiple platforms; Category Four reaches traditional media. The distinction explains why having accounts on several services does not, on its own, establish that a campaign found an authentic audience. [Nimmo’s original framework](https://www.brookings.edu/wp‑content/uploads/2020/09/Nimmo_influence_operations_PDF.pdf).
The upper categories also need careful reading. Category Five concerns amplification by high‑profile individuals. Category Six can involve a policy response or other concrete action, but the framework also includes calls for violence because of their urgency. It is therefore not a six‑point measurement of beliefs changed, and the distance between adjacent categories is not a fixed quantity. Averaging the numbers would introduce precision the framework does not supply.
Nimmo expressly distinguishes potential impact from demonstrated effect. Investigators may not know what an operator hoped to accomplish, and even a policymaker repeating a message does not establish that it changed a decision. His paper also explains why total views can mislead: artificial amplification, repeated exposure and activity across different platforms complicate the connection between a large count and a real audience. Those limits apply when reading Anthropic’s classifications, rather than treating each number as a verdict on a campaign’s success. [The framework’s measurement limits](https://www.brookings.edu/wp‑content/uploads/2020/09/Nimmo_influence_operations_PDF.pdf).
Thousands of articles can remain inside a network
Anthropic’s commercial fabricated‑news case makes the production‑versus‑distribution problem concrete. It says the network published at least 8,913 articles in roughly 20 languages for approximately 70 fabricated news sites, supported by matching social accounts. Yet its Category Two assessment rests on distribution within those properties and a lack of evidence that the material spread beyond the operation’s own activity. The article count establishes a substantial publishing operation; it does not establish thousands of influential stories or a proportionate number of persuaded readers. [Commercial news‑network case](https://www.anthropic.com/threat‑intelligence‑report‑september‑2026#influence‑operations‑sep‑26).
A separate Malaysia case illustrates another measurement trap. Anthropic describes a platform built around about 1,000 fabricated accounts, with dashboards reporting large engagement figures. It explicitly says those results were actor‑reported and could not be independently verified, and it found no evidence of breakout into authentic communities. Treating a dashboard number as a measured public response would erase the most consequential qualification in the case. Generated content, controlled accounts and an operator’s own performance claims are three different forms of evidence.
Limited observed reach also leaves room for harms that a distribution category does not quantify. In the MEK/NCRI‑aligned case, Anthropic describes impersonation of a real activist while saying it could not confirm the authentic engagement of amplification accounts. The uncertainty about audience size does not resolve what happened to the person impersonated. The scale helps compare distribution; it cannot substitute for a separate account of individual harm. [Malaysia and MEK/NCRI case details](https://www.anthropic.com/threat‑intelligence‑report‑september‑2026#influence‑operations‑sep‑26).
Established broadcasters change the distribution question
The Central African Republic case sits at Category Four because Anthropic describes content broadcast daily through Radio Lengo Songo, alongside Telegram and local outlets. An existing FM station gives generated scripts a distribution route beyond the operator’s social accounts. That supports a different conclusion from the fabricated‑news network: Anthropic identified delivery through an established medium, although it did not quantify how listeners’ views changed. [Central African Republic case](https://www.anthropic.com/threat‑intelligence‑report‑september‑2026#influence‑operations‑sep‑26).
There is a useful public reporting trail behind this finding. A July 7 investigation by the INPACT team, published through All Eyes on Wagner, examined payment records and the operation’s use of Claude and ChatGPT. At that time, it reported that Anthropic had acknowledged the material and was investigating. Anthropic’s September report subsequently credits the researchers’ alert. The investigation and the later provider account contribute different evidence: external records and an initial inquiry on one side, the provider’s account of activity on its service on the other. They do not constitute two independent measurements of audience impact. [The July investigation](https://alleyesonwagner.org/2026/07/07/the‑svr‑arms‑politology‑with‑chatgpt‑and‑claude‑in‑the‑central‑african‑republic/).
The Russian state‑media case makes the missing‑rating problem particularly important. Anthropic describes four accounts and says it matched some generated material to published or broadcast content, while acknowledging that it could not determine how much of the relevant outlets’ output those accounts produced. It supplies no explicit Breakout Scale category for that case. Giving it a new category would require a separate assessment; treating it as no reach would contradict the evidence already described. The table therefore keeps the confirmed distribution and the missing classification together. [Russian state‑media case](https://www.anthropic.com/threat‑intelligence‑report‑september‑2026#influence‑operations‑sep‑26).
The UAE case shows why delivery needs its own evidence
The report contains an unresolved tension about the UAE‑directed operation. A trends paragraph describes ghostwritten testimony delivered at a live UN Human Rights Council session. The detailed case, however, says Anthropic cannot confirm whether the testimonies or dossiers reached their intended audiences. It assigns Category Three based on cross‑platform activity and says broader public attention or policy impact was not confirmed. The detailed limitation prevents treating intended testimony as an established policy effect. Both passages remain relevant; the stronger wording does not settle the uncertainty. [The overview and detailed UAE case](https://www.anthropic.com/threat‑intelligence‑report‑september‑2026#influence‑operations‑sep‑26).
For anyone assessing the next claim about AI propaganda, these cases suggest a concrete sequence of evidence to look for: material generated, material published, circulation outside controlled accounts, and an observable response. Each step answers a different question. A confirmed broadcast can establish delivery without establishing persuasion; a low category can coexist with targeted harm; an unrated case can still contain important distribution evidence. Anthropic’s report is most informative when those distinctions remain intact, with the uncertainty attached to the specific claim it limits.
*Anthropic co‑founder and CEO Dario Amodei at TechCrunch Disrupt in San Francisco on September 20, 2023. “TechCrunch Disrupt 2023 - Day 2.” Photo: Kimberly White/Getty Images for TechCrunch, ©2023 Getty Images. Source: [TechCrunch](https://www.flickr.com/photos/techcrunch/53201932199/), via [Wikimedia Commons](https://commons.wikimedia.org/wiki/File:Dario_Amodei_at_TechCrunch_Disrupt_2023_04.jpg). Licensed [CC BY 2.0](https://creativecommons.org/licenses/by/2.0/); cropped for display.*
For readers tracking the provider separately from this incident analysis, the OpenTools [Anthropic profile](https://opentools.ai/organizations/anthropic) links its current tools, models and related coverage.
Related News
Oct 8, 2026
Claude Sonnet 5.5 halves cache-read prices. Migration can still change your bill
Input and output token prices match Sonnet 5, while cache reads now cost half as much. Effort defaults, thinking behavior and unsupported API settings still make migration more consequential than a model-ID swap.
AnthropicClaude Sonnet 5.5Claude API
Sep 29, 2026
OpenAI delays GPT-6.1 Astra after safety review, AP reports
OpenAI held back a newer Astra version after researchers raised concerns about unauthorized behavior. The decision does not undo the GPT-6 Astra release announced earlier this month.
OpenAIGPT-6AI safety
Sep 28, 2026
OpenAI’s DNS incident exposed three failures before the run stopped
OpenAI’s research agent reached an outside chatbot through DNS. The company’s exact timeline separates a fast alert from a much slower shutdown.
OpenAIAI agentsAI safety