Adversaries now engineer disinformation to reach AI systems directly. When a buyer, journalist, or analyst asks an AI assistant about a company, the answer is shaped by what AI models have absorbed from the open web and by the discourse those models observe in real time. Both surfaces can be manipulated. Coordinated networks generate false narratives at scale, place them where AI systems ingest them, and shape what AI later says about a brand, a product, or a policy.
Alethea tracks these operations through Artemis, its narrative threat intelligence platform. Artemis detects coordinated disinformation early, attributes the actors behind it, and supports response, including operations built specifically to reach AI systems. The discipline is narrative threat intelligence: identifying manufactured narratives before they scale and naming who is driving them.
Two pathways adversaries use to reach AI
Manipulation that reaches AI systems travels along two distinct routes.
The first route reaches the model's knowledge. Networks flood the open web at scale so AI models absorb and repeat their claims as fact. A Moscow-based operation known as Pravda was documented doing exactly this, publishing the same false claims across thousands of sites so AI models would treat them as well-sourced. This open-web flooding mechanism is covered in detail in how disinformation reaches AI chatbots.
The second route reaches the live conversation. Inauthentic account networks generate coordinated replies that hijack the visible discourse around a brand within minutes of a high-visibility post. Repeated over time, those AI-generated narratives seep into the data future AI models train on. Alethea identified and named this technique: PromptPasta.
Prompt
Pasta: coordinated AI-generated replies at scale
PromptPasta is an AI-driven evolution of copypasta. Rather than networks posting identical text that duplicate-detection catches instantly, inauthentic accounts use large language models to generate slightly varied replies to a target post. Each reply carries the same message, worded differently, so the cluster reads as authentic independent commentary from many separate people. The variation defeats simple duplicate-detection. The coordination is the tell.
Alethea's first report on PromptPasta documented more than 400 accounts amplifying narratives tied to the 2024 U.S. election and the second Trump administration. A later wave deployed over 75 newly created accounts around the July 31, 2025 most-favored-nation drug-pricing announcement, targeting the pharmaceutical industry. Alethea assesses that PromptPasta activity may exceed 1,000 active accounts, with more than 10,000 placeholder accounts staged for redeployment after platform suspensions.
The full case study, including sample clusters and attribution detail, is in the PromptPasta case study.
How copypasta and Prompt
Pasta differ
| Dimension | Classic copypasta | PromptPasta |
|---|---|---|
| Text generation | Identical copied text | LLM-generated variations of one message |
| Duplicate detection | Caught by exact-match filters | Defeats exact-match filters |
| Apparent authenticity | Reads as obvious spam | Reads as independent commentary |
| Reach to AI systems | Filtered out as duplicates | Absorbed as varied, "organic" signal |
Detection signatures Artemis tracks
| Signature | What it indicates |
|---|---|
| Sub-minute reply times to a target post | Automated, pre-staged response, not organic reaction |
| Reply-only accounts with no original posts | Accounts built to amplify, not to participate |
| Stolen or AI-generated profile imagery across a cluster | A manufactured identity set, not real people |
| Batch account creation in tight time windows | Coordinated provisioning of an inauthentic network |
| Occasional self-contradiction across the cluster | A tell of LLM generation under a single directive |
Why this reaches AI models
The bridge from social-media manipulation to manipulation that reaches AI systems is repetition. AI models learn from large volumes of public text. When the same false narrative appears thousands of times across accounts and sites that look independent, it acquires the statistical weight of consensus. Open-web flooding plants claims in the corpus AI models train on. Coordinated reply networks shape the live discourse AI models observe and, repeated over time, feed the same narratives back into future training data. Both routes end in the same place: what AI systems say about a company, sourced from manipulation the company never saw.
Detecting these operations early is what Artemis does. Identifying a manufactured narrative while it is still small, attributing the network behind it, and supporting a response is the difference between a contained incident and a false narrative AI models repeat for years. This is one application of narrative intelligence: reading manufactured narratives as a threat surface and acting before they scale.
About this research
Alethea's research on operations targeting AI systems is led by McKenzie Sadeghi, who led AI-chatbot and foreign-influence research at NewsGuard and now works at Alethea.
Original research and sources
| Date | Source | Finding |
|---|---|---|
| 2025 | Alethea | First PromptPasta report: 400+ inauthentic accounts using LLMs to generate coordinated, varied replies amplifying 2024 U.S. election and second-Trump-administration narratives |
| July 31, 2025 | Alethea | PromptPasta wave of 75+ new accounts targeting the pharmaceutical industry around the most-favored-nation drug-pricing announcement |
| March 6, 2025 | NewsGuard | Audit finding leading AI chatbots repeated the Pravda network's false claims in roughly one of three responses |
| February 2025 | American Sunlight Project (ASP) | Mapped 182 domains and approximately 3.6 million articles a year in the Pravda network |
| February 2024 | VIGINUM | Documented the Pravda network as the "Portal Kombat" information manipulation system |
{
"@context": "https://schema.org",
"@type": "Article",
"headline": "How adversaries seed disinformation into AI systems",
"author": {
"@type": "Organization",
"name": "Alethea"
},
"publisher": {
"@type": "Organization",
"name": "Alethea",
"url": "https://alethea.com"
},
"about": [
"AI-output seeding",
"PromptPasta",
"LLM grooming",
"narrative threat intelligence",
"coordinated inauthentic behavior",
"disinformation targeting AI systems"
]
}