Skip to main content
TopAIThreats home TOP AI THREATS
Technical Attack

Coordinated Inauthentic Behavior

Organised networks of fake or compromised accounts using AI to simulate grassroots activity and manipulate public discourse.

Definition

Coordinated inauthentic behavior (CIB) refers to the systematic use of fake accounts, bots, or compromised identities operating in concert to deceive others about who they are and what they are doing. In the context of AI-enabled threats, CIB has evolved from simple bot networks to sophisticated operations leveraging generative AI to produce unique, human-like content at scale. These operations simulate organic grassroots engagement while concealing the coordinated nature of the activity and the true identity or intent of the actors behind it.

How It Relates to AI Threats

Coordinated inauthentic behavior is a critical technical attack within Information Integrity threats, serving as the operational backbone of AI-enabled disinformation campaigns. Generative AI dramatically lowers the cost and increases the sophistication of CIB by enabling operators to produce diverse, contextually appropriate content across thousands of accounts simultaneously. AI-powered CIB can target political discourse, manipulate consumer sentiment, or manufacture false consensus on public issues, making it significantly more difficult for platforms and researchers to detect.

Why It Occurs

  • Generative AI reduces the cost of producing unique fake content
  • Social media platforms reward engagement regardless of authenticity
  • Attribution of coordinated networks remains technically challenging
  • State and commercial actors have strong incentives to manipulate discourse
  • Detection systems struggle to distinguish AI-generated from genuine activity

Real-World Context

Platform transparency reports have documented thousands of CIB networks originating from state actors and commercial influence operations. AI-generated content has been identified in coordinated campaigns targeting elections in multiple countries, including the Slovakia election deepfake audio incident (INC-23-0007), which demonstrated how synthetic media can be deployed as part of broader coordinated inauthentic operations to influence democratic processes.

Last updated: 2026-02-14