In September 2025 a trove of internal documents from a Beijing technology firm called GoLaxy began circulating among researchers. They described something more ambitious than the crude bot networks that have cluttered social media for a decade. The system, which GoLaxy called a "Smart Propaganda System", used AI-generated personas to build psychological profiles of named targets, then reshaped its own output as those targets responded. One dossier listed 117 members of the United States Congress as subjects.

For European regulators, the disclosure landed at an awkward moment. The European Union spent the early 2020s writing rules for exactly this category of harm. The Digital Services Act, applied to large platforms from 2023, forces them to audit systemic risks including information manipulation, and to give qualified researchers the data needed to do their own audits. The AI Act, agreed in 2024 and phasing in through 2026, separately requires that AI-generated content be clearly labelled. Whether those rules will prove sufficient is now an open question, but the structural pieces exist. In Washington, almost nothing does.

What changed in the bot factory

The GoLaxy leak matters less for the number of accounts involved than for how the accounts behaved. Traditional influence operations were volume games: armies of fake profiles posting the same message, with predictable posting patterns that researchers could fingerprint. The new generation does something different. Personas hold conversations, remember what a target has said, and adjust their tone and arguments accordingly. They also feed into search results, pushing fabricated articles up the rankings for the queries a target is most likely to type.

A peer-reviewed study published in Frontiers in Artificial Intelligence put a figure on the deception problem. AI-generated election disinformation was judged indistinguishable from authentic human journalism in more than half of evaluated cases. The same paper found that bot-driven amplification accounted for roughly 25% of Twitter activity, and that more than 1,200 AI-generated fake news websites were in circulation by 2024, a tenfold increase in a short window. These are not edge cases; they are the new baseline of the information environment.

The persuasion effect appears to be larger than the reach. Research published in late 2025 found that conversations with AI chatbots shifted voters' political positions by a substantially larger margin than exposure to traditional political advertising. The implication is uncomfortable. The bottleneck for foreign influence operations used to be the cost of producing convincing content. AI has removed that bottleneck. The remaining constraint is computational, not human.

OpenAI, ChatGPT and a Chinese operation

In June 2026, OpenAI disclosed that it had disrupted a Chinese-linked influence campaign that used ChatGPT to draft social media posts targeting US public opinion on three subjects: tariffs, AI policy and data centres. The company did not frame it as a sophisticated operation. What it showed was how accessible the tooling has become. A determined actor no longer needs to build its own language model. It needs a subscription.

The GoLaxy and OpenAI cases are not the only evidence. In July 2024 the US Department of Justice disrupted a Kremlin-backed network that had created two personas, "Sue Williamson" and "Ricardo Abbott", both pushing pro-Russian views on X, the platform formerly known as Twitter. That takedown was widely cited as a success. It also illustrated the limits of success: a case-by-case prosecution leaves the infrastructure intact for the next operator.

What Europe has already built

The EU's response is built on two laws, and on the assumption that platforms themselves are part of the problem. The Digital Services Act obliges designated large platforms and search engines to run annual risk assessments covering illegal content, systemic risks to civic discourse and fundamental rights, and coordinated inauthentic behaviour. They must publish those assessments, hand over data to vetted researchers, and explain to regulators what they are doing about it. The Commission has used these powers. Proceedings against X over its handling of the Hamas-Israel conflict, and against Meta and TikTok over child safety, are working their way through the system.

The AI Act, agreed in 2024 and entering force in stages, adds a labelling layer. Generative AI outputs must be marked in a machine-readable way, and users must be told they are looking at synthetic content. Critics argue the rules are not strong enough and the timetable is too generous. Supporters point out that the United States has neither obligation. The two systems reflect different theories of harm. Brussels treats coordinated deception as a market failure that platforms should be forced to fix. Washington has treated it as a content moderation problem that platforms are free to ignore.

The American vacuum

The US Federal Election Commission declined in 2024 to issue binding rules on AI-generated campaign content, settling for an interpretive note that existing misrepresentation prohibitions apply regardless of the technology. The FEC's statutory authority covers candidates and their agents, not political action committees, foreign state actors or private firms. The Department of Justice has prosecuted foreign influence operations under sanctions law, money-laundering statutes and the Foreign Agents Registration Act, all on a case-by-case basis.

Several US states, notably California, have enacted bot disclosure laws requiring automated accounts to identify themselves. Those rules are calibrated for spam bots that post the same message repeatedly, and offer little against a persona that carries on a fluent conversation. In October 2025, members of Congress wrote to social media platforms asking for metrics on bot prevalence and details of federal coordination. The letter was a public admission of how little the federal government actually knows.

The Trump administration's direction of travel is the opposite of interventionist. In January 2026 the Department of Justice created an AI Litigation Task Force whose stated purpose includes challenging state AI laws, including the bot disclosure statutes. In March 2026, the White House published a National AI Legislative Framework recommending that AI be governed through existing agencies with unrelated mandates, and explicitly opposing the creation of any new federal AI regulator. Senator Adam Schiff has reintroduced legislation aimed at AI-generated political deepfakes, but a bill focused on synthetic images leaves the bot-farm backbone of the problem untouched.

Why this matters in Europe

The temptation in Brussels is to read the GoLaxy files as a problem that happens to other people. It is not. The same methods that profiled 117 American lawmakers can be turned on members of the European Parliament, national ministers or referendum campaigns. The 2024 European Parliament election was already a target; the next one, in 2029, will be conducted against a backdrop of more capable tools. Foreign operations are not the only concern. Domestic political actors now have access to the same generation of generative AI, with none of the institutional guardrails that professional campaigns once provided.

Europe's structural advantage is data access. Researchers in the EU can request platform data through the Digital Services Act's vetted researcher regime, and what they find can feed directly into the Commission's risk assessments. That feedback loop did not exist five years ago. The AI Act adds a second loop, around content provenance. Whether the two together are enough is the open question. A July 2026 Brennan Center report concluded that foreign influence threats to US elections remain elevated. The same assessment would apply, with adjustments, to most EU member states.

The tests coming up

The next real measure of the European framework will be its enforcement against a major generative AI platform over labelling failures, and a Commission decision on whether a designated platform has run a credible systemic risk assessment covering coordinated inauthentic behaviour. The first such decisions are expected before the end of 2026. In the United States, the question is whether Congress will pass anything at all before a federal election cycle in which the tooling has been demonstrated, in leaked documents, to target elected representatives by name.

The gap between what the GoLaxy-style systems can do and what any current law can reach is widening rather than narrowing. Europe has closed part of it. The United States, for the moment, has not.

People mentioned

  • Adam Schiff

    US Senator, United States Senate

Organisations

GoLaxy · OpenAI · US Department of Justice · Federal Election Commission · European Commission · European Parliament