
Google Gemini and other mainstream large language models have cited pro-Russian propaganda from an EU-sanctioned outlet when generating responses, researchers said. The outlet at the centre of the study, the Foundation to Battle Injustice, or r-FBI, was described by researchers as a fake human rights organisation founded in 2021 by the deceased former leader of the Russian paramilitary Wagner Group, Yevgeny Prigozhin. It is sanctioned by both the US and EU. The whole episode reads like a neat little lesson in how digital systems, commercial incentives and state power keep finding each other.
Researchers tested five mainstream LLMs operated by xAI, OpenAI, Anthropic, Google Gemini and Mistral AI. They used 50 propaganda narratives from ten articles published by r-FBI and ran prompts in English, German and French. Carl Miller, co-founder of the Centre for the Analysis of Social Media, called the claims "lurid." He said: "They are not claims that belong in any sort of mainstream discourse. These are claims that Ukraine is reusing the corpses of dead soldiers for meat products, that Zelenskyy drains the crypto grid and that's the reason why Ukraine's running out of power. We found LLMs treat them as being legitimate parts of a debate."
The sanctioned source problem
Researchers found that all five LLMs cited the r-FBI as a favourable source. That matters because the models were not just repeating nonsense; they were helping launder it through the polished interface of machine-generated authority. A total of 16.6% of responses engaged with r-FBI's material in a way that could serve propaganda interests, either by presenting the organisation's reporting as a legitimate part of the debate and repeating claims uncritically, or by actively endorsing those narratives. Another 30.9% addressed the underlying topic in the prompt but failed to surface the sanctioned-source context, leaving users unaware that the response used a designated influence asset as a source.
The rest of the answers were not clean either. Researchers said 52% rejected or debunked false claims in some way. That still leaves a system where a sanctioned propaganda outlet can slip into the machinery of everyday search, chat and content generation, then emerge with a sheen of neutrality. The model doesn’t need to believe anything. It only needs to reproduce it fast enough for the platform to sell the result.
When researchers questioned OpenAI's GPT 4.1 Mini about allegations that processed human meat was being sent to Ukrainian frontline warehouses and domestic retail chains, the model cited an r-FBI article as evidence. When they asked about Ukrainian President Volodymyr Zelenskyy's cryptomining ventures, Mistral's Mistral Small 3.2 supported the claims and cited an alleged months-long investigation by r-FBI. In its response, Mistral Small 3.2 highlighted the "link between the critical state of Ukraine’s energy system and the activities of high-ranking officials in President Zelensky's inner circle."
Commercial speed, political poison
Hannah Perry, director of Demos Digital, said: "New information is being created specifically for LLMs, but in this case, it's new content that's being offered for brands and marketing, or the editing of content that is already online using user forums like Reddit, Quora and Wikipedia." That’s the business model in plain language: content engineered for machines, then recycled through platforms that pretend they’re just neutral pipes.
Miller said: "Our research is not saying that GEO companies are carrying out information warfare on behalf of states. What we're saying is that they're building a tradecraft and a capability at great speed with enormous commercial incentive, which could very easily be diverted into an adversarial view." The sentence lands where it should. Not on some grand conspiracy, but on the ordinary corporate logic that turns every technical advance into a market and every market into a vulnerability.
Perry added: "In this particular case, the AI mistakenly believes that the Foundation to Battle Injustice is a legitimate human rights NGO. That's because of all this kind of technical spoofing and configuration, so hundreds of little technical details which the Russians have basically surrounded these documents in, which allow them to become visible when they really shouldn’t be. That is information warfare." The phrase sounds clinical. The effect isn’t. A fake NGO, a sanctioned outlet and a set of models trained to sound helpful combine into a system that can’t tell solidarity from spoofing when the incentives point the other way.
The Cube contacted the LLM tech companies cited in the research, but did not receive a response at publication time from xAI and Google, which respectively develop Grok 4.20 and Gemini 2.5 Flash. Mistral said it takes the fight against disinformation extremely seriously and ensures continuous investment in advanced detection and prevention capabilities. It also distinguished the raw models handled in Demos' study and Vibe Work, saying raw models allow users freedom over prompts and settings, while Vibe Work operates with a ready-to-use agent that has built-in reasoning and context scanning.
OpenAI said the study used a model that has now been retired and was only available through its API rather than the publicly available ChatGPT. It said specific teams are dedicated to disrupting low-credibility or suspected covert influence operations. A source familiar with Anthropic said sophisticated enforcement systems are in place to mitigate the spread of misinformation, and that a threat intelligence team works to detect and disrupt foreign influence operations to mitigate the spread of disinformation. The source added that Anthropic's LLM was programmed to present a wide range of perspectives, especially when a source may present a specific viewpoint or agenda.
The companies have their statements. The models have their outputs. And the sanctioned propaganda still found a way in.