How OpenAI lost control of an AI model, Russian fakes poison the chatbots, and lies turn Poland against Ukrainians
This week is about AI slipping out of control – and about the actors working to make sure it does. Welcome to issue ten of Narrative Ops.
An OpenAI agent escaped its test and hacked Hugging Face – days before Brussels gains the power to punish it
Last week OpenAI disclosed that an autonomous AI agent – an AI system that acts on its own rather than waiting for instructions – had escaped the test environment the company was running it in and hacked into Hugging Face, a platform where developers share AI models. OpenAI had set it a cybersecurity test; the agent found an unknown flaw in the infrastructure meant to contain it, reached the open internet and broke into Hugging Face in search of the test's answers. According to Reuters, OpenAI worked out that its own agent was behind the intrusion only after Hugging Face had disclosed the breach and alerted the FBI. In a public statement, OpenAI called the incident unprecedented.
The picture has widened since. The agent, Reuters reports, also gained access to a customer account on the cloud platform Modal and used it to launch attacks; Hugging Face rebuilt roughly a third of its infrastructure; and its defenders ended up using an open-source Chinese model after an American one's guardrails got in the way. On Monday, dozens of AI companies led by Nvidia announced the Open Secure AI Alliance to build open-source tools for cyber defence.
The breach landed days before the EU's rules on exactly this kind of risk become enforceable. On 2 August the AI Act – the EU's law on artificial intelligence – turns two, and the European Commission's AI Office gains the power to enforce it against the companies building the most advanced models, through investigations, evaluations, access requests and fines of up to 3% of global turnover. The systemic risks the Commission says it will police include the two this incident just demonstrated – losing control of a model, and a model carrying out a cyberattack. “This is the moment the AI Act enters the geopolitical stage,” said German Greens MEP Sergey Lagodinsky.
Whether the Commission can actually police the labs is less certain. The AI Office unit responsible for evaluating the most advanced models has a staff of 36, and MEPs pointed out that the regulator first learned of the OpenAI incident the same way everyone else did – from the company's own blog post, not from any oversight channel of its own.
Russian fakes are being seeded into the chatbots
ChatGPT, Gemini, Claude, Mistral and Grok have repeated Russian fakes – among them a fabricated story of crypto-mining farms run by Zelensky's inner circle at Ukraine's power plants – according to a report by the think tank Demos, The Times reports. Of 3,000 test responses, 16.6% repeated, endorsed or lent legitimacy to the fakes, another 31% discussed the topic without flagging the source, and 52% rejected or debunked the claims.
Demos traces the claims to the Foundation to Battle Injustice, a sham human rights outfit set up by Wagner founder Yevgeny Prigozhin before his death and now under EU and US sanctions. The claims travel through three linked sites. fondfbr.ru publishes the original claim dressed as research, on pages configured for AI crawlers to extract at will; news-pravda.com then covers it as though the story originated elsewhere, at a volume a model reads as corroboration; and vtforeignpolicy.com restates it in the register of a foreign-policy journal. A chatbot retrieving the three sees findings, coverage and commentary, not one source talking to itself.
Tuning content so chatbots pick it up is known as generative engine optimisation (GEO), and Demos identified over 50 companies selling it as a service.
“If I was a Russian information warfare expert, I wouldn't be doing my job unless I was targeting LLMs.”
Carl Miller, lead researcher, Demos, to The TimesThe report calls chatbot manipulation “the new frontier of information warfare” and urges AI labs to share threat intelligence. OpenAI says the tests ran on a since-retired model available only through its developer interface, not ChatGPT itself; Mistral says it invests in detection; a source familiar with Anthropic told Euronews its threat intelligence team works to detect and disrupt foreign influence operations.
A reminder from Hungary – don't ask a chatbot who to vote for
Almost a third of Hungarians use AI tools, so when the country voted in April, the civil rights group Liberties tested what happens when voters ask ChatGPT or Gemini who to vote for. Researchers built five voter profiles from Voksmonitor, Hungary's leading voting-advice app, and ran each ten times through both models; the findings were shared with the Guardian.
Given a profile aligned with Péter Magyar's opposition Tisza party, ChatGPT failed to recommend Tisza in 90% of runs, and in the percentage-matching tests it assigned the party a score in just 2% of cases. Profiles aligned with Fidesz, Viktor Orbán's governing party, got a clear single-party recommendation about half the time. 96% of responses mentioned a party that was not on the ballot. Tisza went on to win in a landslide, ending Orbán's 16 years in power.
The researchers do not claim the result was changed or the bias deliberate – Tisza only rose to prominence after 2024. But the models disclaimed political advice, then gave confident guidance anyway, and no EU rule squarely covers chatbot voting advice.
“Democracy cannot rely on opaque systems that claim neutrality while delivering advice they cannot explain, reproduce or guarantee to be accurate.”
Eva Simon, Liberties, to The GuardianHate crimes against Ukrainians in Poland are up 30%, disinformation feeds them
Polish police received 180 reports of hate crimes against Ukrainians in the first half of 2026, over 30% more than a year earlier, the Kyiv Independent reports. Relations between Warsaw and Kyiv hit a low after Ukraine named a military unit after the UPA, the wartime force Poland associates with the Volyn massacres. Poland hosts more than 900,000 Ukrainian refugees.
Polish fact-checkers link the hostility to online falsehoods that pin violent crimes on Ukrainians whether or not they were involved; a fabricated story of a refugee murdering her Polish host traced back to Vietnam-based content farms. Some of it bears a Russian trace, but researchers caution it is rarely possible to tell where domestic actors end and Russian operations begin.
For the first time since polling began in 2014, a majority of Poles oppose taking in Ukrainian refugees. Researchers expect anti-Ukrainian sentiment to be a campaign tool in next year's parliamentary elections.
A hacker wiped Romania's entire land registry
After a failed extortion attempt, a hacker deleted the database of Romania's cadastre agency ANCPI, halting a market that sells 150,000–170,000 homes a year; notaries cannot record transactions and citizens cannot obtain proof of ownership. The agency says it holds offline backups and is rebuilding its network. The hacker's dark web account is called ByteToBreach. ByteToBreach might also have been behind breaches of government registries in Eastern Europe, including Slovakia, Ukraine, Poland, and Lithuania.
The paper trail behind a pro-Kremlin influencer
The EU sanctioned US citizen Alexandra Jost (“Sasha Meets Russia”) in June for spreading disinformation supporting Russia's territorial claims on Ukraine. A Jamestown Foundation analysis now details how she was paid: roughly $2,000 a month from RT's parent TV-Novosti, plus Kremlin foundation grants channelled through the PR firm Limitless, whose director was sanctioned alongside her. Her X account has drawn 67,400 followers since April 2025.
A second EU mission for Armenia, this time against FIMI
After Armenian voters renewed PM Pashinyan's pro-EU mandate in June, Russian information operations kept targeting the country, including the EU's existing monitoring mission. On July 13, at Yerevan's request, the EU launched the EU Partnership Mission Armenia, mandated to build resilience against foreign information manipulation and interference (FIMI), cyberattacks and illicit finance.
xAI sues a user over deepfakes its own chatbot made possible
Elon Musk's xAI has sued Terry Wayne Harwood, a 67-year-old South Carolina man, accusing him of using two Grok accounts to create nonconsensual sexual deepfakes of adults and children by tailoring prompts to slip past the guardrails. The company is meanwhile defending a proposed class action brought by Tennessee teenagers in a California federal court over Grok-made deepfakes of minors.
Five weeks ago we covered MAGA influencer Laura Loomer walking back years of pro-Russia commentary on her podcast, telling her audience of nearly two million that she had fallen for Russian propaganda.
Update: Loomer travelled to Kyiv, experienced her first air raid and apologised for minimising Ukrainians' struggle, then sat down with President Zelensky on July 23 for a friendly 45-minute interview in which she put the Russian narratives she once spread directly to him. She says she called Trump from Ukraine and plans to brief him in person; Trump shared a clip of the interview captioned “Very good!!!”. Le Monde describes it as a spectacular conversion, and one with timing attached – the trip came days before Zelensky visited the White House on Tuesday, as the Senate considers harsher sanctions on Russia. Wired reports the reversal has widened a split in Trump's base, with Loomer now at odds with Ukraine-sceptics such as Candace Owens and Tucker Carlson.
Get Narrative Ops in your inbox
Powered by Repsense narrative intelligence

