The Soviet Union spent billions infiltrating the West. Russia just bought a $20 AI subscription

.

When Meta disclosed in a recent threat report that covert networks from Russia and Iran were leveraging generative artificial intelligence models to flood online platforms with synthetic political commentary — a pattern consistent with OpenAI’s own findings on foreign influence operations — the reaction in Western capitals was alarm. To those of us who spent years inside Soviet-legacy national security structures analyzing aktivnye meropriyatiya — active measures — the reaction was recognition.

The Kremlin is not inventing a new strategy. It is simply automating an old one.

During the Cold War, a Soviet active measure was a labor-intensive operational enterprise. Subverting a political process, inserting a forged document into a European newspaper, or funding a local proxy movement required covert officer networks, diplomatic pouch runs, and years of patient staging. The objective was rarely to convert the target population to Soviet ideology. It was to exhaust the target’s societal trust, degrade confidence in democratic institutions, and widen existing internal fault lines.

OPINION: GEORGIA IS DEMOLISHING ITS WESTERN FUTURE — ONE LANDMARK AT A TIME

Operation Denver is the textbook case. In 1983, the KGB planted an anonymous letter in an Indian newspaper with long-standing Soviet ties, claiming the Pentagon had engineered AIDS as a biological weapon. Working through its East German counterpart, the KGB then brought in a scientist to dress the claim in academic language, routed it through Soviet wire services, and waited. By the late 1980s, the fabrication had reached American television screens, and it took Moscow’s own intelligence chief admitting the operation in 1992 to put it to rest. That was the cost of a single successful active measure: a front newspaper, a recruited scientist, and the better part of a decade.

Today, Russia’s security services no longer need undercover officers, covert funding channels, or recruited foreign journalists. Commercial technology platforms inadvertently built much of the digital distribution infrastructure they now exploit. Modern influence operations run on cloud servers, algorithmic engagement engines, and language models that generate culturally contextualized content at scale. What once required a trained officer, a forged byline, and years of patient placement can now be prompted into existence in seconds.

The Soviet Union spent billions over four decades attempting to infiltrate Western institutions. Modern active measures simply rent access to Silicon Valley’s distribution channels.

Consider the Russian-linked campaign known as “Doppelganger.” Operatives did not bother infiltrating mainstream newsrooms. Instead, they built automated systems that created near-perfect digital clones of outlets such as the Washington Post and Germany’s Der Spiegel, populated them with AI-generated propaganda targeting Western military aid, and used commercial networks to push those links directly to millions of voters. Similarly, during recent election cycles in Moldova and Romania, coordinated bot networks on social platforms did not invent political outrage from scratch; they identified hyper-local economic anxieties, deployed locally tailored content, including AI-assisted material, and amplified radical candidates into national contention within days.

Iran has run the same playbook. In 2024, OpenAI dismantled a covert network called Storm-2035 that used ChatGPT to mass-produce articles and social media comments on the U.S. election, the war in Gaza, and Scottish independence — some accounts posing as progressives, others as conservatives — seeding the material across a handful of fabricated news sites. No forger, no printing press, no diplomatic pouch. Just a subscription and a set of prompts.

Georgia — my own country — supplies a case closer to home. In 2024, Meta dismantled a Russia-based network of more than 100 fake Facebook and Instagram accounts and pages pushing links to fabricated Georgian news sites, timed to the protests against Tbilisi’s “foreign agents” law and tuned to amplify the ruling party’s line. The accounts were fake. The confusion they produced was real.

This reveals the fundamental flaw in Western defense against foreign subversion. Western policy treats foreign influence primarily as a content moderation debate — relying on fact-checkers and platform algorithms to police individual posts.

Meta and OpenAI frame their takedowns as victories, and by the narrow metrics of content moderation, they are. But even law enforcement has struggled to keep pace: when the Justice Department seized dozens of Doppelganger’s websites in September 2024, replacement domains were live within 24 hours. Whack-a-mole is not a defense strategy. It is a maintenance schedule.

This reflects a deep misunderstanding of psychological warfare. Active measures do not operate on the level of factual debate. They operate on emotion, perception, and identity. Correcting a false claim still requires repeating it, making it more familiar to audiences. Modern operations do not care whether citizens believe a specific narrative; they care that citizens lose faith in the possibility of objective truth altogether. Soviet doctrine had a name for this: reflexive control — shaping an adversary’s perception of reality so thoroughly that the adversary chooses, on its own, the course of action you wanted all along. A fact-check cannot counter reflexive control, because reflexive control was never about facts.

By viewing automated subversion merely through the lens of free speech or platform moderation, the West attempts to fight a structural foreign intelligence threat with legal and philosophical theories.

The Kremlin no longer needs to break through democratic defenses. The West’s own engagement economy performs the subversion automatically. Commercial algorithms are optimized to maximize user attention through outrage and division. Foreign intelligence services have simply recognized that this engagement model aligns seamlessly with their strategic objectives.

Countering this threat does not require censorship, nor does it mean blaming technology companies for building open platforms. It requires recognizing that open digital infrastructure can be systematically weaponized by foreign adversaries.

Congress should devote as much attention to the security of algorithmic distribution systems as it already does to financial networks and critical infrastructure. The next major intelligence failure will not begin at a military border crossing or through a recruited diplomat. It will begin inside a recommendation engine, unseen without the capacity to look.

That capacity used to exist, and Washington killed it for a reason that deserves its due. The FBI’s Foreign Influence Task Force was disbanded in 2025. The Cybersecurity and Infrastructure Security Agency fared little better: a federal appeals court found it had become a “primary facilitator” in pressuring platforms to suppress Americans’ own political speech — podcasters, bloggers, ordinary users — all under the banner of “foreign influence,” and it has since lost much of its disinformation staff. That drift is the danger this essay has described from the start: treat foreign subversion as a speech problem, and eventually someone decides speech itself is the subversion.

OPINION: I SURVIVED THE FALL OF GEORGIA. WASHINGTON IS REPEATING THE MISTAKE THAT DESTROYED IT

None of that should simply be restored. What replaces it should be narrower and legally walled off: a standing capability whose sole statutory mandate is identifying foreign, AI-generated coordinated inauthentic networks, with no authority over the political speech of American citizens. It should require platforms to disclose the scale and origin of AI-generated influence campaigns, the way banks disclose suspicious transactions, and fund the threat-intelligence teams at OpenAI and Meta as partners in that narrower mission — not volunteers doing work the government once did itself, and at times to its own citizens.

Operation Denver took the KGB the better part of a decade — a front newspaper, a recruited scientist, an entire intelligence bureaucracy — to convince the world of one fabricated story. Its successors do the same work before lunch, using tools built in San Francisco. Washington is still debating whether that counts as a national security problem.

Emzari Gelashvili is a Georgian-born American geopolitical analyst and columnist. From 1996 to 2008, he served as a senior official across Georgia’s state security, defense, and interior ministries, specializing in counterintelligence against Russian operations, and he was a member of the Georgian Parliament from 2008 to 2012.

Related Content