Russia’s AI Blueprint Exposes an Authoritarian Playbook
Russia, China, and Iran are all sharing the same playbook for corrupting Western elections. The U.S. is on track to be the next target this November.
A troveof Russian documents leaked in May outlines Moscow’s plans to use AI to warp foreign decision making and sway elections. The Kremlin’s “Projects 2026“ strategy reveals Russia’s plot to influence upcoming elections in Europe and Israel. Their tactics are similar to those used by China and Iran for years, and what emerges isn’t a Russian innovation — it’s a shared authoritarian playbook.
Projects 2026 calls for the creation of an opinion leader database to monitor the social media profiles of 10,000 influential individuals across Europe, including the 100 most prominent opposition figures in France alone. This is precisely the model Chinese state-aligned company GoLaxy piloted against the United States in 2025. The firm reportedly built constantly evolving psychological profiles of 117 members of Congress and roughly 2,000 additional American opinion leaders.
Researchers at Vanderbilt University warned that GoLaxy appeared prepared to target these individuals with messaging aligned to Beijing’s priorities. By monitoring the social media profiles of Western leaders, China and Russia are able to map the leader’s target’s values, beliefs, emotional tendencies, and vulnerabilities, making their influence operations more tailored and impactful.
In addition to using AI to build psychological profiles, the authoritarian playbook calls for countries like Russia and Iran to flood their targets with tailored generative AI content. Projects 2026’s “AI News” initiative calls for producing more than 500 short videos to target French audiences across six social media platforms. This tactic mirrors Iranian information operations during the 2025 and 2026 wars with Israel and the United States, when pro-Iranian networks pushed AI-generated and AI-assisted videos tailored to different audiences across X and TikTok, which racked up millions of views. These countries are running highly productive propaganda engines.
The most durable piece of Projects 2026 isn’t the content at all — it’s the plan to create fictitious think tanks and research institutes that can hand Russian narratives a “legitimate information source,” making them more likely to be cited by real news outlets and large language models. The leak shows this already underway: A site called the “World Center for Strategic Studies,” registered in March 2026, published unsigned analysis aimed at Western think-tank audiences, with versions planned in German, French, and Spanish. The fake think tank doesn’t need to fool a discerning reader. It needs to get quoted, indexed permanently, and cited by the next AI model that goes looking for sources on the topic.
Iran ran a cruder version of this same play: Iranian state-sponsored cyber espionage group has repeatedly impersonated real institutions — such as the Royal United Services Institute, the Aspen Institute, and the Washington Institute — to steal credentials and plant material under a trusted name. Projects 2026 proposes something more sustainable: Don’t just hijack existing credibility, but manufacture new institutions and let them accrue it over time.
Projects 2026 also proposes building a real Israel-based research institute staffed by Israeli citizens with genuine academic credentials. This approach is reminiscent of the 2014 “Iran Expert Initiative,” where the Iranian Foreign Ministry officials attempted to court and influence Western think tank researchers to promote their perspectives and give them legitimacy. Emails leaked in 2023 showed that Iranian diplomats had worked with Western experts across 10 think tanks to aggressively tout the merits of the 2015 nuclear deal between Tehran and major world powers, formally known as the Joint Comprehensive Plan of Action.
In the age of AI, influencing think tanks is narrative-laundering at its most dangerous. Once a fabricated or state-aligned source gets cited by a legitimate outlet or indexed by a search engine, it can become part of the training and retrieval corpus that both AI systems draw upon.
While the plays are reusable, the targets are new, and for Russia, the target is European elections.
The leaked documents outline a plan to swing Armenia’s parliamentary vote through a Russian-diaspora outlet, and a “Mitteleuropa” initiative aimed at reshaping alignments in Hungary and Slovakia. This is where the surveillance, flooding, and laundering modules converge. To counter it, policy solutions must be swift and targeted.
First, allied governments should require disclosure of foreign funding and foreign-state links for any media outlet, think tank, or “research institute” operating ahead of an election in an at-risk state — closing exactly the gap that lets a “World Center for Strategic Studies” pass as domestic and independent. Research by the Foundation for Defense of Democracies (FDD) into Qatari money in American higher education shows what a real regime requires: disclosures reaching individual researchers, not just institutions; low reporting thresholds with real penalties, registration in the style of the Foreign Agents Registration Act for state-directed “institutes” masquerading as independent; and provisions against the kind of obstruction Qatar used to block Texas A&M’s funding records in court. Russia is proposing to build the same laundering vehicle in Europe that Gulf money has already normalized in American academia. The fix already exists — it just needs to be strengthened.
Second, platforms should both demonetize and remove unlabeled AI-generated political content during designated pre-election windows in at-risk states. X’s own emergency policy during the Iran war, which suspended digital influencers from the ability to monetize their content for 90 days on undisclosed AI-generated war footage, shows platforms already have the infrastructure to act fast when the stakes are high enough. But demonetization alone left the content up and circulating; independent researchers found AI-generated war footage kept flooding feeds regardless of the policy. Elections warrant a harder line: If it’s undisclosed AI-generated content during an active election period, it shouldn’t just lose ad revenue. It should come down.
Third, the U.S. should prepare for future attempts at election influence by boosting the protection mechanisms it already has in place. Currently, 31 states have passed election deepfake laws, but they are under legal scrutiny because they touch on domestic speech. Federal action targeting foreign actors rest on firm ground. The 2002 McCain-Feingold Act prevents electioneering communications by foreign actors, but this only applies to broadcast, cable, and satellite communications. It must be updated to explicitly include paid internet and digital advertisements. It should also close the gap on AI-generated political content and require labeling so that foreign deepfakes can’t hide behind current ambiguities.
Projects 2026 is not evidence that Russia has cracked something new. It’s evidence that Moscow, Beijing, and Tehran are now running the same AI playbook against the same democracies, taking turns testing which module works best. The future outlined in Projects 2026 may not be here yet, but objects in the mirror are closer than they appear.
The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.
Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.
Read more expert-driven national security insights, perspective and analysis in The Cipher Brief
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached — you'll always get the same 5 for this article.