OpenAI busts “Peer Review” op using ChatGPT to pitch surveillance tools
Curated by the Inblix editorial team
OpenAI has pulled back the curtain on a banned cluster of accounts it’s calling “Peer Review,” a network likely originating in China that used ChatGPT to develop and pitch AI-powered surveillance tooling. The operation wasn’t some automated bot army—analysts noted the activity was manual, happening during mainland Chinese business hours, with prompts written in Chinese. The mundane, human-operated nature of the operation is exactly what makes it a notable evolution in threat actor behavior: the misuse wasn’t about hacking the model, but about leveraging it as a multilingual, overqualified research assistant and coding partner.
One of the network’s primary workstreams was drafting promotional materials for something called the “Qianyue Overseas Public Opinion AI Assistant.” According to the sales pitches generated by ChatGPT (which OpenAI can’t independently verify), this tool was designed to vacuum up posts from X, Facebook, YouTube, and other social media platforms to identify conversations about Chinese human rights topics. The operators had the model proofread claims that resulting insights were sent to Chinese embassies and intelligence agents monitoring protests in the US, Germany, and the UK. The operators even prompted the model to roleplay as an English speaker named “Thompson” to generate comments about dissident groups like Falun Gong and US politics.
A separate account in the same cluster focused on the technical grunt work, using ChatGPT to debug and edit the code designed to run the monitoring tool. Interestingly, that code pointed to Meta’s Llama 3.1:8b running via Ollama as the analytical engine, not an OpenAI model. The operator also debugged code referencing Alibaba’s Qwen and DeepSeek, and generated an end-of-year performance review claiming they had created phishing emails for unspecified Chinese clients. This reliance on open-weight, locally-deployed models for the actual surveillance work suggests a deliberate architectural choice to avoid API-based detection, while still requiring a frontier model for the creative and high-context tasks like translation and pitch-writing.
What’s striking here is the sheer administrative blandness of the abuse. Beyond the geopolitical spying implications, this operation looks a lot like a scrappy startup’s workflow—debugging code, analyzing screenshots of protest announcements, and polishing sales decks. It’s a reminder that state-linked groups don’t just want AI to write propaganda; they want it to help manage the project. The fact that the output was largely for internal capability development and promotional review, rather than direct distribution, suggests we’re seeing the professionalization of the surveillance supply chain.
💡 Key Takeaways
- The operation used ChatGPT for mundane business tasks like drafting sales pitches and debugging code, not just for generating disinformation for public distribution.
- The actual AI-powered surveillance tool was designed to run on non-OpenAI models like Meta’s Llama 3.1, indicating a layered approach to avoid detection.
- OpenAI assessed the network likely operated manually from mainland China, using the model to analyze documents about Uyghur rights protests and research diplomatic targets.
Keep reading: See related articles below for more coverage on this topic.
Get smarter about AI
The sharpest AI news, curated daily. Delivered free to your inbox.