Major AI chatbots, including OpenAI's ChatGPT, Google's Gemini, xAI's Grok, and DeepSeek, have been found to cite Russian state-affiliated sources and repeat pro-Kremlin narratives when responding to queries about the war in Ukraine. Research by the Institute for Strategic Dialogue (ISD) and NewsGuard revealed that up to a quarter of chatbot answers referenced Russian state media or sites linked to Russian intelligence, even when those sources are sanctioned in the EU. The studies tested responses in multiple languages and with various prompt types, highlighting the risk that large language models (LLMs) may inadvertently amplify disinformation and undermine sanctions on Moscow-backed media.
The ISD's research emphasized that chatbots are increasingly used as search engines, raising concerns about their role in spreading sanctioned propaganda and the effectiveness of current safeguards. The findings suggest that Russian disinformation networks, such as the "Pravda" network, are successfully "grooming" LLMs by seeding misleading content online, which is then parroted by AI systems. This situation underscores the need for greater scrutiny and regulatory oversight of AI platforms to prevent the dissemination of state-backed disinformation, especially in sensitive geopolitical contexts like the Russian invasion of Ukraine.

Track how attackers are adapting to this technology.
6 events from the most recent confirmed update back to the earliest known activity.
Previous research by NewsGuard found that AI chatbots were susceptible to Russian disinformation campaigns, establishing an earlier warning sign that generative AI systems could surface Kremlin-aligned narratives.
OpenAI and other companies said they recognize the problem of chatbots surfacing Russian propaganda and are working to improve model behavior. Researchers and vendors noted that the challenge remains difficult because disinformation networks rapidly adapt to evade detection.
Following the findings, the report urged clearer industry standards and stronger regulatory action to prevent AI systems from referencing sanctioned or disinformation-linked sources. The results also raised concerns about whether chatbot providers can effectively comply with EU sanctions as these tools are increasingly used for real-time information.
Across the tested systems, ChatGPT was reported to cite Russian sources most frequently, while Google's Gemini surfaced the least state-attributed media and gave the strongest warnings about questionable content. The comparison highlighted uneven safety performance among major AI platforms.
The ISD found that biased or malicious prompts increased the likelihood that chatbots would reference Russian propaganda, with one report noting up to 24% of malicious queries eliciting state-attributed sources. The research also identified the Pravda disinformation network as a notable actor in flooding the web with Russian propaganda, though only a small share of findings were directly tied to it.
The Institute for Strategic Dialogue reported that chatbots including ChatGPT, Gemini, Grok, and DeepSeek returned answers about the war in Ukraine that cited Russian state-attributed sources, including sanctioned outlets and sites linked to Russian intelligence. The study found this occurred in nearly 18% of tested responses overall.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.