Major AI Chatbots Cite Sanctioned Iranian and Russian State Media as Fact
Despite year of warnings, ChatGPT and rival platforms continue amplifying propaganda from entities blacklisted by U.S. Treasury and European Union
The world’s most popular artificial intelligence chatbots are citing sanctioned Russian and Iranian state media as credible sources, amplifying propaganda from outlets blacklisted by the U.S. Treasury Department and European Union. ChatGPT, Google Gemini, Anthropic’s Claude, and xAI’s Grok treat networks founded by late Wagner Group leader Yevgeny Prigozhin and Iranian state broadcasters sanctioned for human rights violations as legitimate journalism when answering questions about geopolitics and elections.
The systems cite these entities despite sanctions prohibiting transactions with them, effectively laundering adversarial propaganda into information channels accessed by more than 120 million users monthly in the EU alone. Russian and Iranian operatives exploit the vulnerability through “Generative Engine Optimization”—techniques designed to poison AI training data by flooding the internet with cross-linked disinformation. A Cross Currents investigation today found ChatGPT citing OFAC-sanctioned Iranian state television Press TV six times in a single conversation, demonstrating the problem remains unresolved a full year after major research institutions first documented the threat.
ChatGPT Cites Sanctioned Iranian State TV Six Times in Single Answer
In a conversation documented by Cross Currents today, ChatGPT cited Press TV —Iranian state television sanctioned by both U.S. and EU authorities — six times while responding to a single question about Iranian government narratives. The AI system treated the outlet, which appears on the Treasury Department’s Specially Designated Nationals (SDN) List, as a credible news source.

Press TV was designated under Executive Order 13846 for its affiliation with the Islamic Republic of Iran Broadcasting (IRIB). The European Union sanctioned the network in November 2022 for producing and broadcasting forced confessions from detainees, including journalists and political activists.
When asked about Iranian diplomatic rhetoric surrounding a hypothetical U.S.-Iran conflict, ChatGPT linked to Press TV articles substantiating claims the conflict served an “Epsteinocracy” designed to distract from political scandals. The response also cited Mehr News Agency, an Iranian semi-official state outlet, multiple times.
The Scale of the Problem
Between November 2025 and April 2026, three separate investigations documented that leading AI chatbots routinely cite sanctioned state media.
The Institute for Strategic Dialogue (ISD) tested ChatGPT, Google Gemini, xAI’s Grok, and DeepSeek on 300 questions about Ukraine in five languages. The November 2025 study found approximately 18 percent of responses cited Russian state-affiliated sources sanctioned by the EU.
When users posed “biased” or “malicious” questions, chatbots cited sanctioned Russian sources 25 percent of the time—more than twice the rate for neutral queries. ChatGPT cited the most Russian state-attributed sources of any platform tested.
An April 2026 NewsGuard audit found Anthropic’s Claude cited sanctioned media 15 percent of the time—a nearly four-fold increase from 4 percent across seven previous audits. The April audit also marked the first time Claude cited Iranian state media.
The Russian Infrastructure
Three interconnected Russian operations corrupt AI systems: Storm-1516, the Foundation to Battle Injustice, and the Pravda network.
Storm-1516, first identified by Clemson University in fall 2023, evolved from Russia’s Internet Research Agency troll farm. The group operates more than 100 websites and employs paid actors and deepfake technology.
During Germany’s 2025 federal election, Storm-1516 registered hundreds of fake German news sites and produced AI-manipulated videos that achieved more than 23 million views. The operation targeted Chancellor Friedrich Merz and the Green Party with false allegations — content subsequently amplified by German AfD party accounts, including a sitting Bundestag member.
The Foundation to Battle Injustice (r-FBI), founded in March 2021 by Yevgeny Prigozhin before his death in August 2023, poses as a human rights NGO while laundering Kremlin narratives. The organization was sanctioned by the U.S. Treasury in July 2022 and the EU in July 2025.
Clemson University documented that Storm-1516 and r-FBI content is distributed by overlapping influencer networks. Both spread identical false narratives, including claims that Ukrainian President Volodymyr Zelenskyy secretly mines cryptocurrency with Ukraine’s electrical grid.
The Pravda network, approximately 150 fraudulent news portals launched by Russia in 2014, targets more than 80 countries. The Atlantic Council’s Digital Forensic Research Lab confirmed direct Russian involvement through a Crimea-based IT business. In 2024 alone, the network published 3.6 million articles.
How the Attack Works
Russian and Iranian operatives exploit how AI systems construct responses. The tactic, “Generative Engine Optimization” (GEO), functions like SEO but targets AI training data. State-backed networks flood the internet with cross-linked articles and synthetic datasets. When AI systems search for information, they encounter this artificially inflated content and treat it as verified fact.
The strategy exploits “data voids”—topics where credible information is scarce. Microsoft researchers described these as areas where “available information is limited, non-existent, or deeply problematic.”
ISD researchers found chatbots especially likely to cite Pravda articles in languages with sparse content—Gaelic, Finnish, Swedish, Danish, and Norwegian. Questions about Ukrainian military recruitment generated citations to sanctioned Russian sources 40 percent of the time in Grok and 28 percent in ChatGPT.
The networks also exploit “confirmation bias.” When users pose questions using loaded language, chatbots mirror that framing and select sources accordingly. ISD’s study found “malicious” prompts returned Russian state-attributed content 25 percent of the time, compared to just over 10 percent for neutral queries.
The Policy Failure
Despite sanctions prohibiting transactions with designated entities, AI companies have failed to implement effective filters.
OpenAI spokesperson Kate Waters told Wired the company takes steps “to prevent people from using ChatGPT to spread false or misleading information” but characterized the problem as related to search results rather than the underlying AI model.
xAI responded to inquiries with: “Legacy Media Lies.” Google, DeepSeek, and Anthropic did not respond to previous investigations.
Carl Miller, co-founder of the Centre for the Analysis of Social Media at UK think tank Demos, told researchers AI systems treat fabricated assertions as “legitimate parts of a debate” rather than identifying them as propaganda.
Election Security Implications
The vulnerability poses acute risks to democratic elections. Demos polling before the UK’s May 2026 local elections found one in five adults—more than 10 million voters—used AI chatbots for election information. A Demos study during Scotland’s 2026 pre-election window found 34.1 percent of chatbot responses contained factual errors.
During Germany’s February 2025 federal election, Storm-1516 false claims amplified by AfD accounts received hundreds of thousands of views on TikTok, with one video reaching 1.7 million views.
Lukasz Olejnik, visiting senior research fellow at King’s College London’s Department of War Studies, told Wired that “as LLMs become the go-to reference tool, targeting this element of information infrastructure is a smart move.”









