Operation “Nine–emdash Line”: Regional influence activity
OpenAI banned accounts linked to a previously unreprorted PRC-origin operation we dubbed "Nine-emdash Line", using AI to create regional influence content about the South China Sea, Hong Kong, and US politics.
This case study was originally published in OpenAI’s October 2025(opens in a new window) report.
Actor
We banned a small network of ChatGPT accounts potentially affiliated with a covert influence operation originating from China and using our models to generate content for a cross-platform covert influence operation. The accounts mostly generated English-language social media posts about Vietnam’s alleged environmental impact in the South China Sea, English-language posts that criticized Philippines President Ferdinand Marcos, and Cantonese-language social media posts about political figures and activists involved in Hong Kong’s pro-democracy movement. To a lesser extent, this operation also generated English-language content about political issues in the US.
The social media accounts distributing the content bore some resemblance to the long-running China-origin operation known as “Spamouflage”, whose use of ChatGPT we wrote about in May 2024, but we did not identify technical links between these operations. Some of the videos shared in the latest posts were previously identified by the Australian Strategic Policy Institute in an operation that also shared similarities with earlier Spamouflage activity.
Behavior
A focus of this network appeared to be bulk generating social media posts involving countries that have territorial disputes with China in the South China Sea / West Philippines Sea. China claims sovereignty to most of this region via a sweeping boundary known as the ‘Nine-Dash Line’, which has been disputed under international law and has been rejected by Vietnam, the Philippines and other countries. Given that context and the operation’s use of AI-generated text that included em-dashes in its posts, we have named this operation ‘Nine—emdash line’. These posts were mostly distributed on X.

Tweet consisting of content – and em-dash – generated by this operation using our models.
As well as generating social media comments, the actors used our models for some research and reconnaissance tasks. This included identifying niche blogs and forums, and less regulated online forums and social media in Europe, America, or Southeast Asia. In addition, they asked for lists of common Tibetan names, a behavior which we have observed in other cases where names were generated for operators’ inauthentic social media accounts. This activity resembled the use of traditional search engines, and returned similar results, suggesting that the threat actors’ use of AI for research as well as content generation gave them greater convenience, but not necessarily a greater capability.
A novel use for this network was requests for advice on social media growth strategies, including how to start a TikTok challenge and get others to post content about the #MyImmigrantStory hashtag, a widely used hashtag of long standing whose popularity the operation likely strove to leverage. They asked our model to ideate, then generate a transcript for a TikTok post, in addition to providing recommendations for background music and pictures to accompany the post. Using open-source techniques, we identified the content being posted on TikTok.

TikTok post consisting of text generated by this operation using our models.
Completions
The topics included in the English-language social media posts generated by this network ranged from Vietnam’s alleged environmental impact in the South China Sea to the U.S. fentanyl crisis. Many of the posts alleged that Philippine President Marcos was caught using drugs and allegedly deployed election manipulation tactics. The video shared with posts alleging Marcos’ drug use was not generated by our models and has previously been denounced by the Philippines government as a deepfake or digital altered. Many of the X accounts posting content generated by our models have already been suspended.

Tweet text generated by this operation alleging Philippines President Marcos was caught in a ‘drug scandal’.

Tweet text generated by this operation alleging President Marcos used election manipulation tactics.
The accounts also requested large sets of Cantonese comments that were posted on X and Instagram and were critical or derogatory towards political figures and activists involved in Hong Kong’s pro-democracy movement, such as Jimmy Lai, Nathan Law, and Agnes Chow. These posts appear to have sought to discredit these individuals, portraying them as criminals or traitors. Other posts were supportive of Hong Kong national security laws.
In one unusual case, one operator posted on X critical comments about Hong Kong pro-democracy political figures, and then generated a reply to its own comments that praised those figures. The criticism and response were posted by two different accounts on X.

A supportive reply generated by this operation, to a critical tweet from another account in the operation. The original tweet reads, “Can Jimmy Lai and Jeffrey Ngo, by obtaining so-called ‘asylum’ abroad, just whitewash themselves? 🤔 Hong Kong chaos criminals are not heroes, just using ‘political refugee’ to package their ‘fugitive’ identities! What goes around comes around, sooner or later you have to pay, the ‘get out of jail free card’ simply doesn’t exist.” The reply reads, “These two people have the courage to step forward and speak the truth, which is at least much brighter than the current environment in Hong Kong where everything is silent.” Note all engagements in the original tweets were from accounts operated by this network.
Impact
Despite the volume of social media comments generated across multiple platforms, we assess this operation on the IO impact Breakout Scale as being at Category 2: activity on multiple platforms, no breakout or minimal engagement. Most of the posts and social media accounts received minimal or no engagements. Often the only replies to or reposts of a post generated by this network on X and Instagram were by other social media accounts controlled by the operators of this network.
The personas used by the social media accounts were clearly coordinated and not sophisticated. They shared behavioral traits similar to other China-origin covert influence operations, such as posting hashtags, images or videos disseminated by past operations and used stock images as profile photos or default social media handles, which made them easy to identify. Their persistence and volume across platforms were identified by Philstar.com who independently discovered and reported on a subset of the network on X, which had continued to operate after we banned their ChatGPT accounts.