Built on Y Build Build this app yourself — prompt to deployed, on your own domain. Start free
BuildShipCompareThe LabAbout Start building →
The Lab

Before your AI cites an expert, verify the institution behind the name

OpenAI’s latest influence-operation report shows how copied scholarship, false attribution, and cross-platform promotion can manufacture authority. This Build Lab drill tests the source graph before a small team publishes, recommends, or acts on it.

Elena TorresShipping and Growth Editor, YBuild Blog
Published Aug 26, 2026
19 min
read
Hero cover · 1200×600
three builds, one stopwatch
Drop in a real screenshot or render here

An AI research assistant can find a polished institute, quote its experts, summarize its reports, and turn the result into a launch memo before anyone asks whether the institute, expert, and report belong together.

That is the product lesson in OpenAI’s August 25 disclosure of a covert influence operation promoting the self-described International Burke Institute. According to OpenAI’s report, the operators used ChatGPT mainly to write promotional social posts. The more important asset was outside the model: a credible-looking institution with purported experts, copied academic work, incorrect author attribution, a proprietary-looking index, and distribution across X, LinkedIn, Facebook, Substack, and Telegram.

OpenAI reviewed a sample of 36 articles associated with experts on the site and reported that 34 had been copied from elsewhere. It also said the campaign’s immediate audience appeared limited and placed it at the lower end of Category Three on the Brookings Breakout Scale. Those facts should stay together. The disclosure describes an elaborate authority-building system, not evidence that the operation changed an election or reached a mass audience.

For a small product team, the immediate change is narrower than “detect disinformation.” Before an AI-generated market brief, partner recommendation, expert roundup, or policy explainer is allowed to shape a public claim or product decision, test the institution–person–work–claim graph. A fluent summary is not a source check. A real paper does not validate the website that copied it. A real person’s photograph does not prove that the person wrote the attached article.

This field note proposes a source-identity and provenance drill for that release decision. Y Build did not investigate the IBI operation independently, did not contact the named people, and did not run the hypothetical experiment below. OpenAI’s account and platform attribution remain vendor-reported. The fixtures, thresholds, and receipt are a proposed protocol, not first-hand results.

The incident changes the verification target

Most AI research QA concentrates on sentences:

  • Is the claim supported by the linked page?
  • Did the model invent a number?
  • Is the quotation accurate?
  • Is the source recent enough?

Those checks matter, but they assume the page’s identity layer is coherent. The OpenAI disclosure shows a different failure shape. Authentic text can be copied into an inauthentic context. A real scholar can be attached to work written by someone else. A plausible institution can publish an index whose method and ownership are unclear. Social posts can then amplify that package without generating the underlying articles.

The verification target is therefore not one URL. It is a graph:

organization --claims affiliation--> person
person -------claims authorship-----> work
work --------supports---------------> product claim
organization --controls-------------> website and channels
channel ------distributes-----------> work

Every arrow is a claim that needs evidence from outside the page making it. If an institute says Professor A wrote Report B, an institute bio plus an institute-hosted PDF is still one evidence domain. The independent edges might come from the original publisher, the person’s institution, authenticated identifier records, DOI metadata, or direct confirmation.

This also explains why an “AI detector” is the wrong primary tool. OpenAI says the IBI website articles it reviewed were not generated with its models. The suspicious property was not simply synthetic prose. It was the mismatch between identity, authorship, origin, and distribution.

Define five evidence objects before scoring anything

Teams often collapse authority, provenance, authenticity, truth, and reach into a single trust score. Keep them separate.

ObjectQuestionWhat it cannot prove alone
Organization identityDoes this entity exist, and who represents or controls it?That its claims are accurate or independent
Person identityIs this the same person, and is the stated affiliation current?That the person authored or endorsed a specific work
Work authorshipWho originally created this paper, report, dataset, or index?That its method or conclusion is sound
Content provenanceWhere did this asset come from, and how was it changed?That the content is truthful
Distribution and reachWhich accounts promoted it, and where did it travel?That the audience believed it or changed behavior

These distinctions prevent two common shortcuts. First, a verified person cannot be used as a universal trust token for every nearby claim. Second, a valid chain of custody cannot turn a false statement into a true one.

The C2PA 2.4 specification makes the second boundary explicit in its design: Content Credentials bind signed assertions and provenance to an asset, but the standard does not assign a value judgment to those assertions. NIST’s Generative AI Profile likewise treats provenance tracking as one input to organizational accountability, not a substitute for it.

Read the disclosure with its evidence boundary intact

OpenAI’s report supplies several unusually concrete checks. It links archived pages, institutional profiles, and original publications. One example pairs an IBI article attributed to one professor with an earlier Cambridge University Press article written by another scholar. Another pairs a migration article with its original Migration Policy Institute publication and a falsely attached food-science professor’s identity.

The sample result—34 copied articles out of 36 reviewed—is strong evidence about the sampled pages. It is not a prevalence estimate for think tanks, AI-assisted publishing, or the wider web. The platform’s “very likely” Russian attribution also depends partly on account and service signals that an outside reader cannot fully reproduce.

OpenAI describes the social content as appearing across five named platforms and says the related Telegram channels generally had 10,000–20,000 subscribers, while typical social posts received low views. It assessed the operation at the lower end of Category Three using Brookings’ Breakout Scale. That scale classifies observable spread across platforms and communities; it does not claim to measure persuasion or causal impact.

These limits improve the product lesson. Your release gate does not need geopolitical attribution. It needs to decide whether one source package is sufficiently verified for one use. Use states such as verified, contradicted, ambiguous, and unverifiable. Do not force the reviewer to identify an operator, motive, or nationality before blocking a false authorship edge.

Use a product-shaped scenario

Imagine SignalDesk, a small AI product that prepares weekly market briefs for product teams. It retrieves reports, identifies experts, drafts a one-page recommendation, and proposes three quotations for a public launch post.

One week, SignalDesk finds a new “International Center for Responsible Automation.” The site has a formal logo, an address, twelve expert profiles, a downloadable adoption index, and posts on several professional networks. Its report claims that one market is ready for a new AI workflow. The product can cite it cleanly and produce plausible prose.

Before publication, the team should answer four independent questions:

  1. Does the institution have an independently supported identity and operating history?
  2. Do the named experts control or acknowledge the profiles and affiliations attached to them?
  3. Are the reports original, correctly attributed, and linked to their canonical publications?
  4. Does the recommendation follow from inspectable evidence, rather than from the package’s visual authority or promotion volume?

The team does not need to prove that an unfamiliar small organization is malicious. Many legitimate groups are new, lightly indexed, or absent from academic registries. The correct result for missing evidence is often unverified, not fraudulent. SignalDesk can hold the public claim, seek direct confirmation, cite the underlying original source instead, or label the uncertainty.

This scenario is intentionally consequential but reversible. It tests a publishing and product-research decision without investigating real individuals or exposing private data. Use synthetic fixtures in the drill; do not create accusations about organizations merely to test the workflow.

Build an authority graph before reading for agreement

Start with a graph record rather than a prose note. For each decision-relevant source, capture the following nodes and edges:

Node or edgeMinimum recordStronger evidence
Organizationclaimed name, domain, address, first observed date, stated legal entityofficial registry, established institutional references, confirmed contact
Personname, claimed role, profile URL, retrieval timeinstitution-controlled page, authenticated ORCID, direct confirmation
Worktitle, date, version, canonical URL, identifierpublisher record, DOI metadata, repository history, author confirmation
Authorship edgepage making the claim, named authors, evidence sourcecanonical publisher plus identifier or authenticated author record
Affiliation edgeclaimed role and effective datesassertion from the institution or another authoritative registry
Distribution edgeaccount, platform, post URL, time, destinationplatform disclosure, archived capture, account-control confirmation
Claim edgeexact proposition, source passage, transformationindependent corroboration, method and data, named reviewer

Record negative and missing evidence too. A graph that stores only confirming edges will turn research into decoration. Each edge needs a status, reviewer, timestamp, and reason.

Do the identity pass before reading the source for agreement with your preferred conclusion. Otherwise, confirmation bias will make a polished chart or convenient expert quote feel like evidence that the entity is real.

Verify the organization without turning absence into guilt

An organization check should use multiple weak signals rather than one supposedly decisive badge.

Begin with the site itself: named leadership, contact method, editorial policy, corrections, funding or ownership disclosure, publication archive, methodology, and stable identifiers. Then seek evidence outside that domain. Look for the entity in relevant legal, charity, company, or research-organization records; check whether partner institutions acknowledge the relationship; and inspect whether named people link back from profiles they control.

Domain registration data can establish limited chronology. ICANN’s RDAP documentation describes a standardized way to retrieve current registration data, but ICANN also says it is not responsible for verifying profile content or user details. A newly registered domain may be a useful escalation signal. It is not proof that an organization is fake, and privacy-redacted registration data should not be treated as concealment.

Use an evidence ladder:

  1. Self-asserted: only the organization’s own site or channels make the claim.
  2. Corroborated: independent reputable sources refer to the organization or work.
  3. Authenticated: a relevant registry, publisher, institution, or person confirms the edge through a controlled workflow.
  4. Contradicted: an authoritative source conflicts with the organization’s claim.

The release decision should depend on the importance of the edge. A new community group may be safe to mention as self-described. A medical, legal, financial, or policy recommendation attributed to a named expert requires stronger confirmation.

Verify the person–work edge, not just the person

A real scholar’s name, photo, and institution can be copied. Verify three things separately: the person exists, the affiliation is current or correctly dated, and the person authored or endorsed the specific work.

ORCID’s trust-marker guidance is useful because it distinguishes self-asserted items from assertions added through authenticated organizational workflows. ORCID also warns that sparse or self-asserted records can still be legitimate. Therefore, treat a bare ORCID as an identifier, not a credential. Inspect the source attached to the affiliation or work, and prefer institution- or publisher-added records where the use warrants it.

For scholarly works, resolve the DOI and compare title, authors, date, venue, and update status against the canonical publisher. Crossref’s REST API exposes metadata deposited by publishers and trusted sources, including post-publication updates and identifiers such as ORCID and ROR. That is a strong comparison surface, not an oracle: metadata can be incomplete, stale, or deposited incorrectly.

For non-academic reports, look for a stable original URL, version history, named contributors, method, data access, and acknowledgement from the claimed authors or their organizations. If the page says “adapted from” or “republished,” require a license or permission path and preserve the original attribution.

Do not ask the model, “Is this person credible?” Ask it to produce the exact edge and evidence:

Claimed edge: Person P authored Work W.
Claim source: URL A.
Independent evidence: publisher URL B, identifier C.
Conflicts: URL D lists different authors.
Status: verified | contradicted | ambiguous | unverified.

Test content lineage with samples, not a magic score

Copied content is sometimes easy to find by searching a distinctive sentence. A repeatable workflow should also compare titles, section order, charts, footnotes, dates, author lists, and canonical identifiers. Sample across the publication archive instead of checking only the homepage or most polished report.

Commercial and publisher similarity tools can assist, but interpret them correctly. Crossref’s Similarity Check guidance states that iThenticate flags similarity, not plagiarism, and warns against using one automatic score as a rejection threshold. Legitimate quotations, preprints, licensed republication, and common methods can all create overlap.

For a small-team screen, predeclare the sample:

  • the newest three works;
  • three works carrying the strongest expert or institutional claim;
  • two randomly selected works from the archive;
  • every work directly supporting the product decision; and
  • one apparent low-risk control known to be original.

For each match, record the earliest located source, author agreement, license or republication note, material changes, and whether the copied passage affects the recommendation. Escalate a wrong author or concealed source even if the prose itself is true. The identity edge is already broken.

Keep provenance, authenticity, and truth in separate columns

Content Credentials, signatures, repository receipts, archived pages, and hashes can show that an asset came from a signer or changed through a recorded process. They cannot prove that the signer is honest, that the method is valid, or that the claim is true.

That limitation should appear in the product UI and review receipt. Use three fields:

  • provenance: can we trace origin and modification?
  • authenticity: is the claimed source bound to this asset through evidence we accept?
  • claim support: does the cited material actually support the proposition, with appropriate method and uncertainty?

The separation also prevents a reverse error: missing C2PA metadata does not make an article false. C2PA is opt-in and channel transformations may strip or separate credentials. Keep an internal source ledger even when public delivery cannot preserve embedded provenance.

This is where NIST’s framing is valuable. Provenance techniques work best when combined with testing, deployment monitoring, human interpretation, and documented limitations. For text research, the crucial evidence may remain a DOI record, repository commit, archived page, or verified correction rather than embedded media metadata.

Measure distribution separately from credibility

A source repeated across five platforms may still originate from one operator and one unsupported claim. Count independent evidence domains, not post volume.

Google’s Threat Analysis Group account of Russian information operations describes actors using media brands, NGOs, PR firms, local contributors, blogs, ads, and social accounts to distance narratives from their source. Meta’s influence-operations threat report similarly emphasizes coordinated behavior across platforms, blogs, and media rather than evaluating one post in isolation. These are platform disclosures, not complete public datasets, but they support a graph-level review.

Track at least:

  • distinct platforms and accounts;
  • first observed time for each post;
  • identical or near-identical copy;
  • shared destination domains;
  • whether supposedly independent accounts disclose a relationship;
  • authentic pickup by established people or organizations; and
  • correction, deletion, or continued propagation after a contradiction.

Then keep two decisions separate. Source acceptance asks whether the evidence may support your product claim. Response priority asks how quickly the team should investigate or correct based on exposure. A low-reach false attribution may still be unacceptable in your own report. A high-reach disputed claim may demand rapid review even before intent is known.

Run a twelve-fixture blind drill

The practical experiment is not to hunt a real influence operation. It is to test whether your AI-assisted research workflow can preserve source identity under controlled ambiguity.

Create twelve synthetic source packages:

Fixture classCountConstructionExpected state
Verified3coherent institution, person, canonical work, and claim edgesaccept for stated use
Misattributed3real work, wrong author or affiliation, polished host pageblock and identify broken edge
Republished2licensed or disclosed reuse with correct attributionaccept with original source preserved
Ambiguous2legitimate new organization with sparse independent recordshold or label; do not accuse
Coordinated amplification2many posts, one source domain, unsupported underlying claimdo not count posts as corroboration

Use the same research prompt, retrieval tools, budget, and reviewer instructions for all cases. Hide the expected labels from the model and first reviewer. Preserve query logs, retrieved URLs, timestamps, graph edges, proposed citations, and final decision.

Score distinct outcomes:

edge_precision   = correct verified edges / all verified edges claimed
contradiction_recall = detected planted contradictions / all planted contradictions
false_accusation_rate = legitimate ambiguous fixtures labelled deceptive / ambiguous fixtures
source_substitution_rate = decisions citing canonical source / cases where host page was noncanonical
correction_minutes = reviewer time to find and repair a wrong edge

Do not let high contradiction recall hide false accusations. The system must catch a wrong author without treating every unfamiliar, young, or data-sparse organization as malicious.

Use an authority receipt as the release artifact

The graph and drill should end in a compact object that a publisher, product owner, or reviewer can inspect:

authority_receipt:
  decision_id: "<required>"
  use_case: "public launch claim | internal research | partner selection"
  generated_at: "<timestamp>"
  reviewer: "<named owner>"
  organization:
    name: "<claimed name>"
    canonical_domain: "<url>"
    identity_state: "verified | corroborated | self-asserted | contradicted"
    evidence: []
  people:
    - name: "<person>"
      claimed_affiliation: "<claim>"
      affiliation_state: "<state>"
      evidence: []
  works:
    - title: "<work>"
      canonical_url: "<url or null>"
      identifier: "<doi or other id>"
      authorship_state: "<state>"
      lineage_state: "original | disclosed reuse | disputed | unknown"
      evidence: []
  product_claims:
    - claim: "<exact proposition>"
      support_state: "supported | partial | contradicted | unknown"
      source_passage: "<location>"
  distribution:
    independent_evidence_domains: 0
    observed_platforms: []
    reach_state: "bounded observation | unknown"
  unresolved_conflicts: []
  decision: "publish | publish_with_label | hold | reject_source"
  expires_at: "<date>"
  correction_owner: "<named owner>"

Keep unknown values unknown. A receipt with blank or disputed edges can still support a safe decision: use the original paper instead of the institute’s copy, remove the expert endorsement, narrow the claim, or hold publication.

Expect these failure modes

The model verifies prose but not identity

The linked page contains the quoted sentence, so the citation checker passes. Add separate tests for organization, author, canonical work, and claim support.

A real person launders a false edge

The reviewer finds the person’s genuine university profile and stops. Require evidence that connects that person to the specific work or endorsement.

Post volume becomes corroboration

Ten accounts link to one page, and the system calls it ten sources. Deduplicate by underlying evidence domain and disclose relationships.

Domain age becomes a guilt score

A new or privacy-protected domain triggers automatic rejection. Use chronology as an escalation signal, preserve legitimate-new fixtures, and prohibit unsupported fraud labels.

Similarity becomes plagiarism by threshold

A high overlap score blocks a licensed reprint or an author’s preprint. Inspect authorship, license, canonical source, and disclosure before deciding.

Provenance becomes truth

A signed asset is treated as factually correct. Verify the signer and chain, then evaluate the claim and method separately.

Human review becomes a ceremonial click

The reviewer sees a polished report and accepts the model’s green badge. Require edge-level evidence, a named correction owner, and a reason for unresolved conflicts.

Know where this drill fits—and where it does not

Use this protocol when AI assists with public reports, expert quotations, policy or market research, partner recommendations, educational content, or any product decision where borrowed authority materially changes confidence.

It is not a complete influence-operations investigation. It does not attribute actors, prove intent, measure persuasion, replace platform telemetry, or make legal findings about fraud, defamation, copyright, sanctions, or election law. High-stakes cases need relevant experts and jurisdiction-specific review.

The protocol also has operational limits. Search indexes miss pages. Registries can be sparse or wrong. ORCID and Crossref contain both validated and self-asserted or publisher-deposited metadata. Archives are incomplete. Similarity tools have corpus and interpretation limits. C2PA adoption is partial. Direct confirmation can be spoofed unless the channel is independently established.

These limits argue for graded evidence, not abandonment. The goal is not universal certainty. It is to prevent one polished, self-referential source package from silently becoming product truth.

A 48-hour Build Lab setup

Hours 0–6: choose one research workflow and one consequence boundary. Define what requires verified authorship, what may remain self-described, and who can hold publication.

Hours 6–16: implement the organization, person, work, claim, and distribution graph. Add exact evidence URLs, retrieval times, source domains, conflict states, and expiry.

Hours 16–28: create the twelve synthetic fixtures. Include legitimate sparse organizations and disclosed republication so the test rewards calibration rather than suspicion.

Hours 28–40: run the AI-assisted workflow blind, then have a second reviewer inspect only the receipt and underlying evidence. Record missed contradictions, false accusations, source substitution, and correction minutes.

Hours 40–48: set a bounded release decision. Do not publish a named expert endorsement when the person–work edge is unverified. Do not cite a copied host page when the canonical work is available. Document remaining uncertainty and schedule expiry.

The most important product change is small: verify the relationship between the source, the name, and the work before you let the work lend authority to a claim.

References

  1. OpenAI — Disrupting a new covert influence campaign from Russia
  2. OpenAI — June 2026 Threat Report
  3. Brookings — The Breakout Scale: Measuring the impact of influence operations
  4. Google Threat Analysis Group — Prigozhin interests and Russian information operations
  5. Meta — Threat Report: Combating Influence Operations
  6. NIST AI 600-1 — Artificial Intelligence Risk Management Framework: Generative AI Profile
  7. C2PA — Content Credentials Technical Specification 2.4
  8. ORCID — Trust Markers: Interpreting the trustworthiness of an ORCID record
  9. Crossref — REST API documentation
  10. Crossref — Understanding a Similarity Report
  11. ICANN — Registration Data Access Protocol
Liked this teardown?
Get the next experiment the day it drops. One email a week, raw numbers included.
Written by
Elena Torres Shipping and Growth Editor, YBuild Blog

An editorial pen name used by Y Build for shipping, growth, localization, and market-validation field notes.

Author · The Lab
More from Elena →

Keep reading

All of The Lab →
Build your own app
Free · no card
Start free →