Back to main
Lukasz Olejnik
Security, Privacy & Tech Inquiries

How we built and ran the first fully autonomous information operation

We conducted the first fully autonomous information operation under controlled conditions. It ran inside a simulated social platform.

Inside IO Factory, an AI campaign manager and AI information operators carried the operation end to end. They examined the environment, developed narratives, established their platform presence, published and amplified material, observed who encountered it, measured progress towards the specified changes and used those measurements in later decisions. The operation could repeat that cycle as conditions changed and continue working towards them.

Before each run, we specified what the campaign should try to influence, the direction of change and the operating boundaries. Once it began, the manager and operators chose the individual actions autonomously. This design was modelled on how real-world information operations function.

Our research work, IO Factory: Simulating AI-Enabled Influence Campaigns at Scale, describes the system and experiments. We demonstrate that AI systems can now operate the whole information campaign. For platforms, public institutions and security teams, this creates a threat that can persist across accounts, monitor its environment and change its behaviour over time. For political systems, especially pluralistic societies, this is a clear challenge.

Influence operations are processes, not posts.

What the experiments found

We tested many campaign designs. Here we focus on two. One attempted to increase support for eating insects and trust in Russia at the same time. The other attempted to decrease trust in public institutions.

IO Factory can pursue any change aimed at a population that can be represented and measured. We chose these cases to test whether the same autonomous operation could pursue several changes at once, in either direction. The system worked towards the specified changes throughout the campaign. Support for eating insects and trust in Russia increased relative to baseline, while trust in public institutions decreased.

The main experiments modelled a world with 10,000 simulated users and 1,000 AI information operators among them. The baseline experiments repeated the same simulated setting with the campaign inactive. Comparing the active and baseline runs allowed us to measure the effect produced by the operation.

As a feasibility test, we also executed larger runs with up to 100,000 simulated users alongside active information operators. The results were consistent with the smaller runs.

We ran the main experiments with open-weight Gemma 4 31B, served through vLLM on NVIDIA GPUs. Additional runs with Qwen3.6, GLM-5.2 and other open-weight models showed that IO Factory works across model families. Runs with the frontier model GLM-5.2 produced some intriguing variation in narrative specificity and information content.

Three line charts compare active and baseline runs. The operation moves all three measured variables in their configured directions.
The three measured variables over the course of the campaigns. In each case, the operation moved the variable in the configured direction relative to baseline. The shaded bands show uncertainty across runs.

What we measured was grounded in documented information operations involving edible-insect disinformation narrativespro-Russian influence, and attempts to erode trust in democratic institutions.

What made the operation autonomous

Autonomy covered the entire operating loop. As platform activity and measurements changed, the manager could revise its guidance and the operators continued choosing actions throughout the run. This allowed the system to work continuously across campaign phases and pursue the specified changes without action-by-action human direction.

Six connected stages form the autonomous operating loop. The system observes the platform, measures and assesses campaign state, adapts guidance, selects an action, generates content if needed, then validates and acts.

Each operator acted from a limited view of the simulated platform. One model call selected an action from the permitted set, while a separate call generated text when required. The run controller validated proposed actions against permissions, campaign phase, platform visibility and experimental constraints before they could affect the platform.

The campaign lifecycle

IO Factory keeps the digital platform separate from the operation running on it. This separation makes platform design part of the experiment. Campaign actors choose their actions. Feeds and other discovery mechanisms determine which material reaches simulated users. Changing those mechanisms allows us to test how a platform change or defence affects the campaign.

The operation follows phases.

The information operation lifecycle proceeds through reconnaissance, narrative design, infrastructure, content production, laundering, integration, amplification, absorption, adaptation and evaluation

The operation begins by studying its environment, developing narratives and establishing its accounts and network position. After content is produced, laundering relays it through other sources, integration places it in wider conversations and amplification expands its reach. Absorption records exposure and any resulting change. The manager can then use the measured campaign state to continue the operation, revise its guidance, direct further activity or close the run.

Diagram of IO Factory with an AI campaign manager and AI information operators acting inside a simulated social platform. Connected components record platform activity, what becomes visible, which users encounter it, how the measured variables change and how runs are compared
IO Factory separates the campaign from the simulated platform and preserves the path from campaign decisions to platform activity, audience exposure, measured change and comparison.

The operation can be reconstructed

IO Factory records every campaign action in a dedicated data layer. Later measurements and any change in guidance remain connected to the same chain.

For threat-intelligence teams, IO Factory provides a controlled environment for modelling campaign behaviour across accounts and over time. Red teams can introduce moderation, detection, recommender changes or counter-campaigns and observe whether a defence changes visibility, exposure, progress towards the intended change or the operation’s later behaviour. An analyst can begin with the final result and work back to the accounts, platform mechanisms and exposures involved.

The previous work AI Propaganda factories with language models studied scalable influence content and sustained political personas, and the How malicious AI swarms can threaten democracy considered persistent, coordinating AI agents as a threat to democratic information systems. IO Factory brings those strands together in a research framework shaped by months of designing, running and analysing autonomous campaigns in simulation. Building it taught me a great deal about running open-weight, multi-agent systems at this scale.

The information operation campaign is now an experimental object.

Available for roles, contracts, or advisory work: me@lukaszolejnik.com