The history of foreign interference in democratic elections is not, contrary to the post-2016 discourse, primarily a story about Russia and the 2016 American election. It is a long and remarkably consistent story about the United States doing it to others, the Soviet Union doing it to everyone it could reach, and smaller powers doing it wherever their interests and capabilities allowed.
The CIA’s interventions in Italian elections from 1948 onward — funding Christian Democratic candidates, producing anti-Communist propaganda, reportedly dumping bags of money at election offices — were systematic and sustained for decades. The Soviets ran analogous operations in Western European countries throughout the Cold War, and in Latin America, Africa, and Asia. In 1996, the Clinton administration facilitated loans to the Yeltsin government and permitted American political consultants to run his reelection campaign. The pattern of powerful states trying to shape other countries’ political outcomes through covert means predates the internet by centuries.
What the internet changed, and what AI is changing again, is the technical infrastructure required to operate at a given scale. The intelligence services conducting foreign election interference in 2026 are not doing something new. They are doing something old with radically cheaper, faster, and more scalable tools.
The Pre-AI Operation: What It Actually Required
It is worth being specific about what large-scale foreign election interference required before AI tools were available, because the contrast clarifies what has changed.
The KGB’s “active measures” program at its peak in the 1970s and 1980s employed thousands of officers and an extensive network of agents, witting and unwitting collaborators, and front organizations. Producing convincing forged documents — fake American policy papers, fabricated letters from government officials — required deep subject matter expertise, native speakers with sophisticated cultural fluency, and printing infrastructure. Distributing the forgeries required physical infrastructure and relationships with sympathetic journalists and publishers.
The Internet Research Agency’s 2016 American operation, which is the best-documented modern example, employed approximately 1,000 people, required significant investment in Russian speakers with American cultural fluency (who could write convincingly in American vernacular English about American social divisions), and needed years of groundwork building and aging social media personas.
The cultural fluency requirement was the most significant constraint. Convincing American political content required people who understood American political culture from the inside — who knew not just the words but the cadence, the specific grievances, the cultural references, the tone of voice that reads as authentic to American eyes. Foreign-language speakers without deep cultural immersion produced content that felt slightly off to native audiences.
AI has largely eliminated this constraint.
The Cultural Fluency Problem, Solved
A large language model fine-tuned on a large corpus of authentic American political discourse — Reddit arguments, Twitter debates, newspaper comment sections, local political blogs, Facebook political groups — can produce text that is, at the sentence and paragraph level, indistinguishable from authentic American political writing. The fine-tuning cost is relatively modest; the publicly available corpus is enormous; and the resulting capability means that any state actor with moderate technical resources can produce politically convincing content in American political vernacular without hiring a single native speaker.
The same is true for other democratic societies. A model fine-tuned on German political discourse produces German political content that passes as authentic to German readers. Fine-tuned on Brazilian political speech patterns, it produces Brazilian content. The cultural fluency problem that constrained foreign interference operations to a small number of states with significant intelligence infrastructure has been dissolved.
This matters enormously for the global distribution of foreign interference capability. In 2016, the list of states with the capability to run significant foreign election influence operations was short: Russia, China, Iran, and a few others with sophisticated intelligence services. The resources required — human, financial, and infrastructural — set a floor below which state actors couldn’t operate effectively.
In 2026, the floor is much lower. The core technical capability for a foreign influence operation — generating convincing political content in the target country’s language and cultural register — costs a few hundred thousand dollars in AI infrastructure. A medium-sized state with a competent technical ministry can now operate influence campaigns against the elections of its regional neighbors that would have required CIA or GRU resources five years ago.
The 2026 Attribution Cases
The United States intelligence community has, as of October 2026, publicly attributed AI-enhanced foreign election interference to five state actors in ongoing 2026 election cycles: Russia (targeting German, Polish, and American elections), China (targeting Taiwanese and Australian elections), Iran (targeting Israeli and American elections), North Korea (targeting South Korean legislative elections), and Venezuela (targeting Colombian elections).
These public attributions reflect, almost certainly, the subset of cases where attribution confidence is high enough for public release. The classified picture is almost certainly more extensive.
The Russian operation targeting German elections has already been discussed. The Chinese operation targeting Taiwan is perhaps the most technically sophisticated of the documented cases. Taiwan’s Central Election Commission reported in March 2026 that its monitoring systems had identified a coordinated network of approximately 8,000 AI-managed social media personas, operating in Traditional Chinese at a quality level indistinguishable from authentic Taiwanese political discourse, pushing narratives about the incumbent DPP’s corruption, military inadequacy, and economic mismanagement in the run-up to legislative by-elections. The personas were active across Taiwanese social platforms including PTT, Dcard, and Line groups.
The Iranian operation targeting the 2026 American midterm elections is the most concerning for American national security officials. Unlike the Russian 2016 operation, which focused on amplifying existing domestic divisions, the documented Iranian operation of 2026 has targeted specific policy areas of direct Iranian interest — American attitudes toward the Iran nuclear deal’s successor framework, American public opinion on military engagement in the Middle East, and the electoral prospects of specific congresspeople who sit on the House Foreign Affairs Committee. This is foreign election interference with specific foreign policy goals, not just general democratic destabilization.
The Detection Asymmetry Gets Worse
The intelligence community’s ability to detect and attribute foreign influence operations has, historically, relied on a combination of signals intelligence (monitoring the technical infrastructure of the operations), human intelligence (sources within foreign intelligence services), and behavioral analysis (identifying the statistical signatures of coordinated inauthentic behavior in platform data).
AI makes all three of these harder.
Signals intelligence: an influence operation run primarily on commercial cloud infrastructure, paying with cryptocurrency through layers of shell companies, leaves a different — and more fragmented — technical signature than an operation running on attributable state infrastructure. Modern AI operations deliberately use commercially available tools and hosting specifically to create plausible deniability.
Human intelligence: the human footprint of an AI operation is dramatically smaller than a human-staffed operation. Where the IRA employed 1,000 people, an equivalent-scale AI operation might employ 20 to 30 technical staff. There are fewer humans to recruit as sources, fewer people who know what the operation is doing, and fewer human error points where tradecraft failures can be exploited.
Behavioral analysis: AI-managed personas, designed specifically to avoid the statistical signatures of bot behavior, are harder to identify through the automated detection systems that platforms deploy. The early-generation bot accounts that dominated 2016-2018 were detectable because they posted at machine regularity, used repetitive phrase patterns, and lacked the organic variation of human behavior. AI personas are designed to reproduce that organic variation — and they do so convincingly enough to evade current detection tools at significant rates.
The Ally Problem
The foreign interference discussion has, until recently, focused primarily on adversarial states: Russia, China, Iran, North Korea. The uncomfortable extension of the analysis is to allied states.
The United States has intelligence-sharing relationships with the United Kingdom, Canada, Australia, and New Zealand (the Five Eyes alliance) and broader relationships with dozens of NATO allies. These states, by and large, do not run influence operations against each other’s elections — at least not openly, and not with the kind of aggressive destabilization agenda that characterizes Russian and Chinese operations.
But the technical capability is widely distributed. British intelligence services have AI influence operation tools. Israeli intelligence — the Mossad and Unit 8200 — has some of the most sophisticated technical intelligence capabilities in the world. Several NATO allies have intelligence services that have been documented, historically, running more active political influence operations than the alliance’s democratic norms would officially endorse.
The AI capability proliferation doesn’t respect alliance relationships. It creates a global ecosystem in which any state with moderate technical resources can run foreign election interference against any other state. The relevant constraint is not technical capability — that is now broadly available — but political will and the risk-benefit calculation around getting caught.
The risk calculation is changing. Attribution is harder. Detection is more uncertain. The consequences of discovered interference have not, historically, been severe enough to constitute a meaningful deterrent — Russia’s 2016 operation produced sanctions that were more symbolic than economically punishing. In that risk environment, the technology’s proliferation lowers the barrier for less powerful states that would previously have assessed that the capability wasn’t worth the risk.
Taiwan Is the Template
Taiwan deserves particular attention because it has been the most extensively targeted and the best-defended democratic society in the world when it comes to foreign information warfare.
Since 2018, Taiwan has developed the most sophisticated democratic ecosystem for countering Chinese information operations of any country in the world. This includes: an active-response government team called the Cofacts fact-checking initiative; a strong culture of media literacy education starting in elementary schools; a highly engaged civil society technology community (the g0v civic tech community) that monitors and publicizes influence operations; and a democratic political culture that has developed healthy skepticism toward information coming from certain vectors.
Despite all of this, the 2026 AI-enhanced Chinese influence operation targeting Taiwan’s legislative by-elections produced measurable effects. The operation’s synthetic content reached an estimated 18 million social media users in a country of 23 million people. Even in the best-defended information environment in the democratic world, AI-generated foreign influence at scale has measurable penetration.
If Taiwan — with its two decades of specifically developing defenses against Chinese information warfare — cannot fully defend against AI-enhanced interference, no other democracy is better positioned.
This is not cause for despair. Taiwan’s defenses are meaningful; the operations have not achieved their strategic objectives of destabilizing Taiwanese democracy. But it is cause for honesty about the difficulty of the problem.
The Response Architecture
The democracies that have invested most seriously in foreign interference defense are moving toward a platform-government-civil society architecture rather than a purely governmental response.
Finland, which developed its information resilience programs after Russian interference in its 2017 parliamentary elections, has the most advanced model. The Finnish approach combines: early and comprehensive media literacy education; a rapid-response government communications capacity that can quickly publish authoritative information to counter false narratives; formal information-sharing agreements between the government and major social media platforms operating in Finland; and strong investment in Finnish-language content production by trusted domestic institutions.
The Finnish model’s key insight is that the response to foreign information operations cannot be primarily defensive — detection and removal — because detection is too slow and removal too incomplete. The response must also be affirmative: creating enough authentic, trusted information that foreign-generated synthetic content is crowded out rather than corrected.
This approach requires resources, institutional capacity, and public trust in government information — none of which can be assumed in all democratic contexts. The United States, which has deep institutional distrust and no national media literacy curriculum, is particularly poorly positioned for the Finnish model.
The alternative, for the United States, is less coherent: platform self-regulation, intelligence community warnings, civil society monitoring, and scattered state-level initiatives. This decentralized response has not been adequate, and the 2026 election cycle continues to provide evidence of its inadequacy.
Foreign interference didn’t become a problem in 2016. It became visible in 2016. The AI upgrade is making it harder to see again — not because it has moved underground, but because the scale, diversity, and technical quality of operations have exceeded the detection and response capacity of the institutions tasked with addressing them.
One email a month: new articles, reviews and the upcoming live webinar + free recording. No spam, unsubscribe anytime.