The Internet Research Agency, Russia’s troll farm that intervened in the 2016 American election, employed approximately 1,000 people at its peak. They worked in shifts, posting content on Facebook and Twitter, managing hundreds of fake personas, engaging with real Americans, seeding division, amplifying wedge issues. The operation cost an estimated $25 million per year. For that investment, Russia purchased a sustained influence campaign that reached an estimated 126 million Facebook users.

By any subsequent analysis, the IRA’s 2016 operation was also quite crude. The content was often grammatically awkward. The personas were detectable with relatively simple analysis. The operation was geographically confined to a building in St. Petersburg. It was, in the end, discovered.

What the Senate Intelligence Committee documented in its 2019 report on the IRA was the last time a major foreign influence operation would be this legible. The 2016 playbook has been fully automated, and the result is something qualitatively different from a thousand people in an office building.

The Automation Stack

A current-generation AI-powered influence operation — the type that intelligence services across Europe and North America are now documenting in 2025 and 2026 — works through a layered system.

At the base layer, large language models generate content. Not the kind of obviously artificial content that the IRA’s English-second-language operators sometimes produced, but content that is, at the sentence and paragraph level, indistinguishable from authentic American or European political discourse. The models are fine-tuned on large corpora of authentic political writing from the target country — op-eds, Reddit posts, Twitter arguments, local news comment sections — and produce content that captures the specific register and concerns of the target demographic. A model fine-tuned on rural Midwestern conservative political discourse writes differently from one fine-tuned on urban progressive discourse, and both write in ways that feel authentically local.

At the persona layer, AI generates and maintains coherent fake social media identities. These are not simple bot accounts posting identical content at machine speed — the detection for those is straightforward. Modern AI personas maintain posting history, express opinions that are internally consistent, occasionally contradict themselves in humanly plausible ways, show interest in non-political content (sports, local events, personal life) alongside political content, and manage the relative timing of posts to simulate a real person’s sleep schedule and work patterns. One AI persona management system documented by Stanford Internet Observatory researchers in August 2026 was maintaining 3,800 distinct synthetic personas with posting histories stretching back two years, all on a single server cluster.

At the coordination layer, AI determines what narratives to push, when to push them, and which personas should amplify which content to maximize organic spread. This is where the operation’s strategic intelligence enters the system. The AI doesn’t determine the strategic goal — that is set by whatever human operator or state actor controls the system. But it determines the operational execution: which specific stories, images, and emotional framings are most likely to be shared by real users, and how to introduce synthetic content into real conversation threads in ways that appear organic.

What 2026 Has Actually Looked Like

The most extensively documented AI disinformation campaign of the 2026 cycle targeted the German federal election held in February. The campaign, attributed with high confidence by the German Federal Office for the Protection of the Constitution (BfV) to a network linked to Russian military intelligence, operated from at least November 2025 through election day.

The campaign’s core operation: a network of approximately 2,400 AI-managed personas planted a series of fabricated stories about the SPD candidate, Saskia Esken, into German social media ecosystems. The stories were about corruption allegations — specific, detailed, backed by fabricated documents that circulated as images. The stories were false. But they were detailed enough, and the supporting “evidence” convincing enough, that they were picked up and discussed by legitimate German media — not uncritically, but picked up. The conversation about whether the allegations were true ran for several weeks and reached voters who never saw a clear resolution.

Esken’s campaign team identified the network as coordinated in early December 2025. Meta and X/Twitter suspended several thousand accounts. Within 72 hours, the network had rebuilt to approximately 80 percent of its prior capacity using new accounts with pre-aged posting histories (another AI capability — synthetic accounts that were created months earlier and “seasoned” with non-political content before being activated for influence operations).

The SPD lost the election, significantly. Attribution of electoral causation is inherently difficult, and the SPD faced genuine political headwinds unrelated to the disinformation campaign. But the campaign demonstrably reached tens of millions of German social media users, generated sustained negative coverage of Esken specifically, and operated for weeks before it was identified, and continued operating after identification. The counterfactual is unknowable.

The Human-AI Hybrid Problem

Intelligence analysts have consistently underestimated the capability shift because they have been looking for AI operations, expecting them to be distinguishable from human operations.

The current generation of influence operations is explicitly designed to blur this distinction. Human operators set strategy and handle the operations that require genuine human judgment — identifying real grievances to amplify, making decisions about when to escalate narrative intensity, managing the contacts with journalists or political insiders who might unwittingly amplify campaign content. AI handles the high-volume content generation and persona management work. The result is an operation that is more capable than either pure human operation or pure AI operation would be alone.

The Senate Intelligence Committee’s 2016 analysis worked because the IRA’s operation was mostly human and humans make detectable patterns. The BfV’s 2026 analysis of the German operation worked because they had strong prior intelligence about the operation before it began. Without that intelligence advantage, catching a well-designed hybrid operation through post-hoc content analysis is genuinely hard.

This is the fundamental shift: disinformation operations used to be slow enough that they were primarily retrospective problems — you could study what had happened after the election and understand how you’d been manipulated. Now they run faster than the response cycles of any democratic institution.

Domestic vs. Foreign — An Increasingly Meaningless Distinction

The discourse about AI disinformation has focused heavily on foreign state actors: Russia in American and European elections, China in Taiwanese elections, Iran in Israeli politics. This focus is understandable — foreign interference in democratic elections carries a particular symbolic weight and triggers national security responses that domestic political manipulation does not.

But the capability doesn’t check passports. An AI influence operation architecture built for foreign state interference is, technically, identical to an AI influence operation architecture built for domestic political use.

In the 2026 election cycle, American political consultants have been using AI-generated content and coordinated amplification networks that, if run by a foreign government, would be called influence operations. When a domestic political action committee runs a network of AI-managed social media personas to amplify specific narratives in swing states, it is doing the same thing the IRA did — with better tools, at lower cost, and with legal cover that foreign actors don’t have.

The FEC’s rules on political advertising disclosure were not written to address coordinated networks of synthetic personas. Operating such a network does not clearly violate any federal law, because no federal law was written with this technology in mind. The law prohibits coordination between campaigns and independent expenditure groups. It does not address what “coordination” means when both the campaign and the independent group are using AI systems that generate similar content based on similar strategic inputs without any direct communication.

This is a genuine legal gray zone, and it is being actively exploited on both sides of the partisan divide. The people exploiting it are not, in most cases, evil. They are political professionals doing what political professionals do: using available tools to win elections. The tools available now happen to include scaled automated influence operations that would have been state-actor-only capabilities five years ago.

The Volume Problem

There is a useful analogy in the history of spam email. Email spam was a genuine problem in the late 1990s and early 2000s, when the volume of junk email threatened to make email unusable. The solution — spam filters — worked by identifying the statistical signatures of spam and automatically routing it away from inboxes. Spam filters became good enough that most users today don’t experience email spam as a significant problem, though the underlying spam volume is actually higher than ever.

Political disinformation has a spam problem, and the analogy to spam filtering is both instructive and limited.

Instructive: the spam problem was solved not by making spam illegal (it is illegal; people still send it) but by building filtering infrastructure that made spam ineffective at reaching its targets. The equivalent for political disinformation would be platform-level detection and demotion of coordinated inauthentic behavior — not removal necessarily, but reducing the algorithmic amplification that makes synthetic content reach audiences it wouldn’t reach organically.

Limited: email spam doesn’t have supporters. Nobody argues that spam filters are censoring legitimate speech. Political disinformation does have defenders, because in a polarized environment, one side’s disinformation is the other side’s truth, and any filtering system will face accusations of political bias from whoever’s content gets filtered. The spam filter analogy breaks down exactly where it would be most useful.

The volume problem is also genuinely new. The IRA’s 1,000 employees could produce content at a certain pace. An AI system can produce content at a pace that exceeds any human moderation operation’s capacity to review. When content generation scales to a million posts per day from a single operation, the moderation model built for human-paced content creation fails on volume alone.

The Scale of What We Are Not Seeing

The documented cases are almost certainly a small fraction of the actual activity. For every German federal election where the BfV had advance intelligence and was watching closely, there are dozens of local and regional elections across Europe and North America where no intelligence service is specifically monitoring for AI influence operations.

The United States has 50 state election systems, thousands of local elections, and an essentially decentralized election administration structure. The federal government’s capacity to monitor AI influence operations targeting state-level races is limited. The states’ own capacity varies enormously — Massachusetts has more sophisticated election security infrastructure than, say, West Virginia or Louisiana. The targeting incentive for malicious actors is to hit the races where monitoring is weakest, which is almost always below the federal level.

What we are seeing in 2026 is a technology that has made nation-state-level information warfare capabilities available to anyone with a modest server budget and the motivation to use them. Criminal groups, domestic political actors, foreign intelligence services, ideological extremists — all of these groups now have access to the same capability class, differentiated only by the sophistication of their strategy.

The 2016 IRA operation shocked the United States because a foreign state had run a significant influence operation on American voters. The shock was about foreign interference in domestic politics. The 2026 environment makes that framing inadequate. When the capability is ubiquitous, the question is no longer which foreign actors are using it. The question is whether the information environment of democratic elections is compatible with tools that make sustained, scaled deception trivially easy.

The answer to that question determines whether the elections being run under these conditions are genuinely democratic in anything other than formal procedure.

Get the best of Think Different in your inbox

One email a month: new articles, reviews and the upcoming live webinar + free recording. No spam, unsubscribe anytime.