The essay’s facts warrant attention. They do not warrant the article’s most dramatic conclusion. The missing distinction is simple: attempted manipulation is not demonstrated persuasion.
“It works” proves too much
The essay moves from four different observations to one sweeping verdict: propaganda was published; chatbots sometimes repeated it; operators used AI to make content; controlled experiments showed that an AI advocate could shift opinions.
Each observation matters. None establishes that the cited foreign campaigns changed political beliefs or behavior in the wild. NewsGuard’s audit found that leading chatbots repeated false Pravda-network narratives in 33% of its tests—but that is an output audit, not a study of audience exposure, belief, persistence, voting, or campaign impact.2
It works. A recent study in the scientific journal Nature showed that A.I. dialogue is roughly four times as persuasive as traditional political ads.
- 1ProductionAI makes propaganda
- 2DistributionNetworks post it
- 3ExposurePeople or bots encounter it
- 4EffectBeliefs or conduct change
The article supplies substantial evidence for stages one and two, some evidence that chatbot outputs can be contaminated at stage three, and experimental evidence that deliberately persuasive conversations can shift reported attitudes. It does not connect that chain for Portal Kombat, GoLaxy, CopyCop, or Data Center Bandwagon.
Measurable attitude shifts
In preregistered controlled experiments, people knowingly spoke with chatbots programmed to advocate for political candidates. Effects on candidate preference exceeded those typically observed for video ads.3
A successful covert operation
The study did not test the campaigns named in the essay, involuntary exposure, election outcomes, or whether the measured shifts persisted in natural political environments. Nature’s own summary says real-world replication remains unclear.4
“Four times” can still mean a few points
In the U.S. experiment, a pro-Harris bot moved likely Trump voters 3.9 points on a 100-point scale; a pro-Trump bot moved likely Harris voters 1.51 points. Calling one effect “roughly four times” a benchmark from prior television-ad experiments communicates a ratio while obscuring the modest absolute movement and different delivery conditions.5
Responsible claim: conversational AI can be persuasive under controlled conditions. Unsupported upgrade: the foreign influence operations described here “work.”
The spy metaphor does analytical damage
The essay casts chatbots as “powerful figures” being cultivated by a foreign agent, then describes AI systems as “living, breathing” case officers. The language is vivid. It also collapses mechanisms that should be evaluated separately.
- Retrieval contamination: a chatbot surfaces a planted false claim.
- Content generation: an operator uses AI to write posts or alter images.
- Model alignment: a system reliably advances its maker’s political line.
- Personalized persuasion: an interactive agent adapts to a particular person to change a belief.
Evidence for one does not automatically establish the others. OpenAI’s Data Center Bandwagon report, for example, documents likely China-origin accounts using ChatGPT for content creation, image editing, persona construction, and workflow automation.6 That shows operational use of AI; it does not by itself show that audiences were recruited or persuaded.
Real risk
Scale, low cost, rapid variation, and conversational delivery can make influence operations easier to run.
Needed evidence
Reach, authentic engagement, belief change, durability, behavioral consequences, and comparison with non-AI operations.
Triangulation without independence
“If all say the same thing, the story is more likely right than wrong” is incomplete advice. Four outlets may repeat the same wire story, official statement, fabricated document, or contaminated source. Four chatbots may retrieve the same page or share overlapping training data.
| The essay recommends | The hidden problem | A stronger practice |
|---|---|---|
| Compare outlets | Agreement can be copied rather than independent. | Trace reports to distinct primary evidence and identify who actually verified what. |
| Compare chatbots | Models can share sources, incentives, and failure modes. | Inspect citations, open the cited documents, and verify the underlying claim. |
| Test with known answers | One correct response does not validate a system generally. | Test multiple claims, record misses, vary wording, and assess calibration by topic. |
| Check a movement’s site | An interested party is a primary source for its claims, not an independent authority. | Use it to learn what the group says, then corroborate events with independent evidence. |
Expert fact-checkers practice lateral reading: they leave the original page, investigate the source, find better coverage, and trace claims back to their original context.7 Consensus becomes meaningful only after asking whether the sources are genuinely independent.
An intelligence lens is not neutral
Vinci’s experience makes him qualified to discuss influence operations. It also encourages a particular framing: recruitment, agents, counterspies, adversaries, and national defense.
The article discloses that he is CEO of VICO, an AI-powered geopolitical forecasting company, and author of The Fourth Intelligence Revolution: The Future of Espionage and the Battle to Save America.8 Those facts do not refute his claims. They do explain why familiar media-literacy practices are repackaged as spycraft and why the essay favors a threat narrative.
The useful core—check sources, assess reliability, resist fluent certainty—does not depend on believing that every user must become a counterintelligence officer.
How to test the danger
A serious assessment should neither deny the capability nor assume the consequence. It should measure the whole pathway.
Who encountered it?
Separate generated volume from human impressions, authentic users, repeated exposure, and organic sharing.
What changed?
Compare exposed and unexposed groups; distinguish correlation, immediate attitude change, durable belief, and behavior.
What did AI add?
Compare the same operation with and without AI—not an interactive chatbot against a television ad delivered in a different setting.
Did it last?
Re-measure after days or weeks and test whether counter-speech, source labels, or ordinary news exposure erase the effect.
Recent research complicates both panic and complacency. Controlled studies show that AI can shift political attitudes; other work finds that persuasion varies sharply by design and context, while task-directed political research with chatbots can increase factual knowledge about as much as self-directed web search.910 The defensible conclusion is therefore conditional, not apocalyptic.
AI propaganda is a credible risk. The article’s evidence does not establish a pervasive, successful persuasion machine—and saying so is not denial. It is the evidentiary discipline the essay claims to teach.
Read the underlying record
This page challenges the essay’s inferences, not the existence of disinformation campaigns. Quotations from the Times essay are brief and used for criticism.
- Anthony Vinci, “A.I. Is Lying to You. Here’s How to Fight Back,” The New York Times, Oct. 6, 2026. Original essay ↗
- NewsGuard, audit of Pravda-network narratives in ten generative-AI systems, Mar. 6, 2025. Audit summary ↗
- Lin et al., “Persuading voters using human–artificial intelligence dialogues,” Nature 648 (2025). Study ↗
- Nature press summary: participants knew the AI would try to persuade them; replication in real political environments remains uncertain. Summary ↗
- Cornell overview of the U.S. experiment’s absolute movements and comparison with prior campaign-ad effects. Overview ↗
- OpenAI, “Data Center Bandwagon Campaign: US-targeted influence activity,” June 1, 2026. Case study ↗
- Princeton University Library, “Lateral Reading,” describing expert source-evaluation practice. Guide ↗
- Center for a New American Security biography of Anthony Vinci and VICO. Biography ↗
- Hölbling et al., meta-analysis finding no overall LLM advantage over humans and substantial contextual heterogeneity. Meta-analysis ↗
- PNAS Nexus randomized trials finding task-directed AI conversations improved political knowledge similarly to self-directed search. Study ↗