Imagine a woman living in Chicago. She talks about rent prices, comments on the news, replies to her neighbours' messages, likes their photos. One day, she shares a strong opinion on American foreign policy.
She does not exist. And neither does the person who created her account: an AI did it.
That is what an investigation published in mid-September by the New York Times describes, and it is worth pausing over.
What the investigation found
According to the American daily, Iran, China and private Israeli companies have run influence campaigns of a new kind in recent months. Hundreds of AI agents, built from freely downloadable Chinese models, opened networks of fake accounts on Instagram, Facebook, X and TikTok themselves.
They did not stop at creating the accounts. They wrote the posts on politics and current affairs, coordinated messages between themselves, and replied to other users.
American officials and researchers see this as one of the first known cases in which AI agents have handled almost an entire influence campaign. The Iranian network targeted the American public, with accounts posing as ordinary residents of major cities. It gathered close to 80,000 followers in the first half of 2026.
One Israeli company named in the report confirmed it had used the Chinese model DeepSeek, claiming it was defensive research.
Crude, but troubling
Investigators describe these campaigns as still fairly crude. They have not swayed American opinion.
What is troubling is what they demonstrate. Until now, a "troll farm" required hundreds of employees, paid to write messages all day. That cost limited the number of fake accounts that could be kept credibly active.
With AI agents, that brake disappears. A few people and a free model are enough. The only limit left is the ability of social networks to spot these accounts.
These campaigns did not use a paid service that could have been blocked. They used models released under open access, which anyone can download and run on their own machines. No company can switch them off remotely. This is the flip side of open models, which we had already observed when an attacker had hooked DeepSeek up to Telegram to target hundreds of systems.
What it changes for us
On Wednesday, we explained that Instagram's label on AI-generated profiles relied first and foremost on the good faith of creators. These campaigns show its limit: an account designed to deceive will obviously not declare itself.
The battle is therefore no longer fought over the content of a message, which is increasingly hard to tell apart from a real one. It is fought over behaviour: accounts that are born together, that talk alike, that amplify one another. That is what we detail tonight in our guide to spotting a network of fake accounts.
What we take away
These campaigns are still clumsy. The next ones will be less so, because the models improve every month and their cost keeps falling.
The question is no longer whether entire crowds of fake accounts can be manufactured. They can. The question is how we will keep telling a real crowd from an invented one.