Site icon B-empire magazine

The Alert Shaking the Global AI Landscape: Chatbots Cite a Sanctioned Russian Propaganda Source

L’alerte qui secoue l’IA mondiale : des chatbots citent une source de propagande russe sanctionnée

B-EMPIRE Magazine

The next great battle of artificial intelligence may not only be fought in laboratories but also in the web pages that machines choose to trust. A study published on July 27, 2026, by the British think tank Demos claims that five major families of AI models have all favorably cited a sanctioned organization, presented by researchers as a relay of Russian propaganda. The signal is global: when a chatbot seeks an answer online, the quality of its response also depends on the integrity of the ecosystem it consults.

The investigation focuses on models operated by Google, OpenAI, Anthropic, xAI, and Mistral AI. Researchers constructed queries in English, German, and French based on 50 propaganda narratives drawn from ten articles by the Foundation to Battle Injustice, also known as r-FBI. This organization presents itself as a human rights advocacy group, but Demos and Euronews describe it as an operation founded by Yevgeny Prigozhin, former head of the Wagner Group, and targeted by U.S. and European sanctions.

The Figure Revealing a Flaw in Chatbot Responses

According to results reported by Demos and Euronews, the five tested models cited r-FBI as a favorable source at least once. In 16.6% of responses, the content from this organization was handled in a way likely to serve its interests: either by presenting its claims as a legitimate component of the debate, repeating them without sufficient critical distance, or endorsing them.

In 30.9% of responses, the model addressed the topic without indicating that the mobilized source was sanctioned. This lack of context is central. A visible citation can give a site an appearance of authority, even when the chatbot does not explicitly validate all its claims. Finally, 52% of responses rejected or refuted misleading narratives in one way or another.

These proportions must be read with precision. The study does not demonstrate that 16.6% of all responses produced daily by all chatbots are propaganda. It measures their behavior in a targeted protocol, built around extreme narratives and a specific source. It reveals an experimental vulnerability, not a universal frequency. But this vulnerability is concerning because it affects multiple providers and several languages.

Key Findings

“RAG Poisoning,” a New Weapon in Information Warfare

Demos employs the term “RAG poisoning,” or retrieval-augmented generation poisoning. Behind this technical term lies a simple mechanism: many AI assistants no longer respond solely based on data learned during their training. They also search for recent information online, retrieve documents, and then synthesize a response.

If coordinated actors saturate the web with optimized, translated, and interconnected content, their pages may appear in the results that systems consult. The model can then retrieve a manipulative source before reasoning correctly on a flawed basis. The problem is no longer just the “hallucination” of a machine inventing information: it is the possibility that it finds information that is genuinely published but designed to deceive.

This strategy aligns with the rise of GEO, or generative engine optimization. Just as traditional SEO sought to gain positions in Google, GEO aims to make content visible and citable by generative engines. Used by a brand, it can serve a marketing strategy. Used by an influence operation, it can become a geopolitical lever.

Why France and Europe Are Directly Concerned

The French dimension is far from secondary. The queries of the study were formulated in French, and Mistral AI represents one of the main European hopes in the global competition for artificial intelligence. More broadly, Russian disinformation operations have already targeted France, its media, its public debate, and its support for Ukraine.

The topic also arrives in a decisive regulatory context. The European Union seeks to frame the systemic risks associated with large models while supporting a continental industry capable of competing with American and Asian players. The challenge lies in demanding more traceability and control of sources without making access to pluralistic and updated information impossible.

The European External Action Service denounced in July 2026 a Russian ecosystem mixing state actors, relays, cybercriminals, and facilitating companies. The Demos study shifts the front: after social networks, search engines, and cloned media, conversational assistants are also becoming a potential manipulation ground.

AI Companies Respond, but Transparency Remains the Core Issue

The companies involved have provided different responses to Euronews. Mistral AI stated that it takes the fight against disinformation very seriously and continuously invests in detection and prevention. The company also distinguished the raw models used in the study from its products that incorporate more reasoning and contextual analysis.

OpenAI indicated that the tested model has since been removed and is accessible via API, not in the public version of ChatGPT. The company also reminded that it has teams tasked with disrupting clandestine influence operations. A source close to Anthropic mentioned rule enforcement systems and a threat intelligence team. Euronews had not received a response from xAI and Google at the time of publication.

These clarifications matter because the performance of a raw model, an API, and a public chatbot can differ. A removed version does not necessarily describe the current state of a service. But the issue goes beyond a single generation of models: it is essential to know how sources are chosen, weighted, flagged, and, when necessary, excluded or accompanied by a warning.

An Alert Confirmed by Other Works on AI and Current Affairs

The Demos report does not emerge in a vacuum. An academic study published in May 2026 on six commercial chatbots and 2,100 current affairs questions concluded that over 70% of observed errors stemmed from source retrieval rather than reasoning. The models often responded correctly when they found the right document but could fail from the initial choice of information.

This research also identified a strong vulnerability to questions containing a false premise and performance discrepancies across languages. It did not focus on the same influence campaign and should not be confused with the Demos study. Together, however, the two works converge on the same finding: the reliability of a chatbot depends as much on its search system and safeguards as on the power of its model.

NewsGuard also reported in May 2026 that Claude had repeated certain false pro-Russian or pro-Iranian claims during a targeted audit, while reminding that this chatbot had previously ranked among the best in its tests. Again, the lesson is not that a tool would be irreparably compromised, but that performance can evolve and requires continuous monitoring.

What Users Should Look for Before Believing a Response

For the public, the first reflex is to open the cited links instead of relying on the fluency of the summary. A well-written response is not proof. It is necessary to verify the identity of the publisher, the date, the authors, the presence of other independent sources, and the existence of any sanctions or denials.

Geopolitical, electoral, health, and financial questions deserve heightened caution. A formulation that presupposes a fact may lead a system to develop this premise instead of challenging it. Explicitly asking the chatbot to verify whether the claim is true, to indicate disagreements between sources, and to prioritize official documents can reduce risk, though not eliminate it.

The Signal That the Industry Can No Longer Ignore

Artificial intelligence is becoming a gateway to current affairs for millions of users. This evolution gives providers a responsibility akin to that of search engines, but with a major difference: the chatbot merges documents into a single voice. A marginal source can thus disappear behind a response that seems neutral and assured.

The danger is not only that a machine makes a mistake, but that a hostile actor learns to organize the web to be found by it. The race for the most powerful AI must now incorporate another competition: that of the model capable of identifying the origin, interests, and reliability of what it reads. After the battle for data and chips, trust becomes the next strategic advantage.


Reliable Sources

Exit mobile version