AI as a Force Multiplier, Not a Standalone Weapon
OpenAI has published a new threat intelligence report, "Disrupting malicious uses of AI," detailing how threat actors are folding AI models into existing operations rather than using them to create novel attack types. According to the report, malicious actors are primarily using tools like ChatGPT to scale established tactics: generating more convincing phishing emails, drafting propaganda articles, writing social-media bot comments, and translating content for wider reach.
Cross-Platform Abuse
The report describes campaigns that span multiple platforms rather than staying confined to one. A typical operation might use an LLM to draft a disinformation article for a newly created website, then amplify it through networks of automated accounts on platforms such as X, Facebook, or Telegram — some of which also rely on AI-generated text for posts and replies. OpenAI says this cross-platform structure is designed to create an appearance of grassroots authenticity, and that it complicates detection because no single platform sees the whole campaign.
Detection and Disruption
OpenAI outlined several defensive measures it says it uses to identify and disrupt these operations:
- Monitoring API usage for patterns such as rapid content generation linked to known threat-actor infrastructure.
- Model-based safety systems fine-tuned to flag deceptive or manipulative content, including hate speech, propaganda, and phishing lures.
- Industry collaboration, including sharing threat intelligence with other tech companies, researchers, and government agencies.
OpenAI frames this collaboration as necessary because abuse spreads across services it does not control, meaning coordinated information-sharing is needed to dismantle full campaigns rather than individual accounts or websites.