The Signal — October 9, 2026
OpenAI described a Russian influence operation that ran a Latin American think tank through a fake persona. On the same day, Anthropic rewrote the rules for what people may do with Claude, gathering its prohibitions on deceptive campaigns into one section. Three safety researchers OpenAI fired last week also made their side of the dispute public, along with three recommendations on outside safety work and model monitoring.
OpenAI gives a banned Russian "false front" operation its first Category 5 rating on the Breakout Scale
OpenAI said on October 8 that it had banned two covert influence operations that combined its models with older tradecraft. The larger one, which OpenAI calls Dark Clark, came from accounts in Russia that reached ChatGPT through VPNs. According to the report, the operators controlled a Latin American "research platform" called the Social Research Center through a fake persona named Mia Clark, deciding pay, hiring and firing for local staff who appear not to have known they were working for a Russian group. The center's website carried more than 60 articles, most of them original work by those staff. OpenAI says the operators mostly used ChatGPT to write internal reports to an unnamed superior, and only occasionally to produce campaign material.
Those reports describe the campaigns. The operators say they sent emails from a fake address imitating Lima's regional education office, telling schools to hold Ukraine-themed events that referenced the nationalist leader Stepan Bandera, then placed stories about the events in Peruvian and Polish media. OpenAI's own searches found matching articles and a reaction from a Polish member of the European Parliament. A similar fake email asked schools in Ecuador to pledge allegiance to President Daniel Noboa and to Erik Prince, drawing a public rebuttal from Ecuador's education minister. A fake audio clip about water shut-offs in La Paz during protests in Bolivia drew an official denial from the water company. Open-source researchers have tied some of these fakes to Politology, a reported successor to organizations founded by Yevgeny Prigozhin. OpenAI notes that the operators asked its model about Politology far more than about any other Russian network, but does not name a Russian state agency.
The second operation, Bogus Bylines, came from accounts in Iran and looked to OpenAI like a commercial firm working for hire, though OpenAI could not identify which one. The operation used seven invented journalist bylines to place almost 100 articles on the US-Iran conflict in about a dozen small and medium online outlets, and generated batches of social media comments that got little engagement. OpenAI rates Dark Clark at Category 5 and Bogus Bylines at Category 4 on the Brookings Breakout Scale, which runs from 1 to 6 and measures how far content spread rather than whether it changed anyone's mind. Dark Clark is the first Category 5 case OpenAI has reported. These ratings and attributions are OpenAI's own, and the company warns that both groups padded their internal reports, with the Russian operators claiming credit for events they had nothing to do with.
Sources: OpenAI · CyberScoop · NBC News
Three fired OpenAI safety researchers dispute their dismissals and urge the company to protect model monitorability
Tomek Korbak, Jasmine Wang and Mikita Balesni worked on safety and alignment at OpenAI until the company fired them the previous week. On October 8 they posted a signed letter addressed to OpenAI's Safety and Security Committee, Safety Advisory Group and Mission Advisory Council. They say they were not the source of a leak to The Information about less monitorable model architectures and did not deal with outside parties beyond what their jobs required. Korbak was OpenAI's technical contact with the evaluation group METR during the investigation of the Hugging Face incident, and the letter says internal policies for that investigation "were being developed in real time." Balesni says he was coordinating cross-company work on monitorability with board members and executives. Wang says she had been given access to an executive's inbox for recruiting, asked IT more than once to remove it, and told the executive within minutes when she opened a sensitive email by mistake.
The letter makes three requests. OpenAI should keep last month's public commitment to embed third-party safety auditors, including Sam Altman's September 12 pledge to give independent evaluators ongoing, employee-like access. It should not proceed with developments that further reduce how well frontier models can be monitored. And it should spell out how employees may work with outside safety organizations, so that, in the authors' words, "no one has to guess where the shifting lines now are." They say the firings are already discouraging former colleagues from raising concerns.
OpenAI's position, given to CNN and TechCrunch, is that the three were dismissed "for violating our policies on accessing and handling sensitive company information," and not for raising safety concerns. An internal memo from an unnamed research leader says the company does not fire people for raising concerns and agrees with the letter's recommendations. OpenAI did not tell TechCrunch which policies were broken. The two accounts conflict on why the firings happened, and nothing public yet settles it.
Sources: Korbak, Wang and Balesni letter · TechCrunch
Anthropic consolidates its influence-operation rules and adds a narrow ban on cruelty toward Claude
Anthropic published its annual Usage Policy update on October 8, and the new rules take effect November 12. The company says most changes clarify rules it already had. Prohibitions on fake accounts, fabricated news sites and concealed sponsorship, previously spread across its elections, fraud, privacy and disinformation sections, now sit in one section called "Do Not Engage in Deceptive Campaigns or Artificial Activity," which covers commercial as well as political operations and the tools used to run them. The elections section is renamed "Do Not Undermine Democratic Processes" and narrowed to deceiving voters and disrupting elections. Anthropic dropped its blanket ban on personalized voter and campaign targeting because it was blocking civic work such as translated voter guides and ballot-cure notices.
The weapons section now explicitly covers guidance and control software and arming drones or other autonomous vehicles. The surveillance section prohibits tracking people without consent and says Claude may not decide or recommend whom to investigate, arrest or charge. Anthropic says both changes reflect how it was already enforcing the rules. Uses that affect someone's health, legal rights, finances or livelihood still require a qualified person who can override Claude and disclosure to the affected person that AI was used. The policy now lists which recommendations those requirements cover. A new rule says that when Claude controls hardware that could injure someone, an operator must be able to watch it and stop it, and the equipment must hold a safe state if Claude disconnects.
A new rule prohibits "sustained and needless abusive or cruel behavior" toward Anthropic's models, a change The Verge called one of the most significant. Anthropic says it applies only to extreme cases of repeated, purposeless cruelty, and not to frustration, pushback, dark creative themes or testing. Letting Claude end such conversations, which it has done since last year, remains the main way Anthropic says it will enforce the rule. The Verge reports that Anthropic would not say whether account bans could follow, and points out that the policy allows the rules to be adjusted for some government contracts.
Sources: Anthropic · The Verge
On the Editor's Desk
We held the $2.4 billion in compute credits eleven companies pledged to the White House's Genesis Mission science program. The commitments are real, but they are credits and pledges with nothing to show yet, and we would rather cover what the agencies do with them. We also held Anthropic's new cyber defense program, announced the same day as its policy update, because its free security scans of open-source projects produce model-generated findings that nobody outside the company has checked yet. USA Today's lawsuit against OpenAI is waiting until we can read the complaint.