FIMI & Cognitive Warfare Monitor — 13 September 2026
Anthropic threat report discloses nine AI-assisted influence operations spanning Russia, Iran, Turkey, Gulf states, plus an Israeli-linked surveillance vendor.
Lead Signal
Anthropic published its fourth threat intelligence report this cycle, marking the most consequential single disclosure the monitor has processed this period. The report, dated 2026-09-10, discloses 39 cases across seven harm areas. Nine of those cases are influence operation cases, originating in Russia, Iran, Turkey, the Gulf, South Asia, Africa, and Europe. Because the disclosure originates from a single artificial intelligence vendor rather than a platform coordinated inauthentic behavior takedown or a government attribution, the findings below are assessed as consistent with documented actor tactics, techniques, and procedures rather than treated as confirmed state attribution, notwithstanding meaningful secondary press corroboration.
The most developed of the nine cases links a Russian speaking operator in Bangui, assessed as consistent with a Russian state aligned Foreign Information Manipulation and Interference apparatus, to a daily content operation coordinated with RT, Sputnik Afrique, TASS, and the Russian House in Bangui. A second case, the Deadshot persona operation, is assessed as consistent with United Arab Emirates linked interests and profiled 18 members of the European Parliament and prominent journalists. A third cluster ties three Iranian state linked institutions, the Islamic Culture and Communications Organization, the Islamic Propaganda Office of Khorasan Razavi, and the Bina Cultural Observatory, to an internally named soft war and cognitive warfare programme, with the Khorasan Razavi unit running a multi province content factory internally codenamed Manjanegh. A fourth case, held at Possible confidence, links a commercial surveillance and profiling platform targeting Iranian and Gulf social media users to S2T Unlocking Cyberspace, described in open source research as an Israeli Singaporean commercial intelligence vendor, without asserting state tasking. A fifth case, assessed as consistent with a PRC aligned operation, tracked, profiled, and attempted to recruit Uyghurs in Syria. Against this volume of disclosure, the information integrity composite score for the cycle stands at 0.34 and is assessed as deteriorating, reflecting attribution capacity that this cycle is concentrated almost entirely in a single vendor investigation.
Other Developments
Turkey origin network targets Malaysian constituencies. An Istanbul based operation, held at Possible confidence with no state attribution, ran a fake account network assessed as targeting all 222 Malaysian parliamentary constituencies, illustrating a category of FIMI for hire activity that falls outside the monitor six actor canon.
NATO StratCom study identifies an 18 hour propaganda vulnerability window. The NATO Strategic Communications Centre of Excellence, working with Repsense, published a study finding that Russian propaganda response systems are most vulnerable in the first 18 hours after an unexpected crisis, an operationally actionable finding for counter messaging timing.
Actor risk ratings move upward across five of six tracked categories. Overall risk this cycle was rated HIGH for Russia and Iran, ELEVATED for China, the Gulf, and Israel, and LOW for the United States, reflecting the concentration of new disclosure across state and state linked actors this week.
A French registered fabricated news operation scaled to industrial volume. The operation ran approximately 70 fabricated news websites that published at least 8913 articles, a scale visible only because an AI vendor caught the activity at the production stage; X/Twitter issued no coordinated inauthentic behavior equivalent disclosure this cycle, leaving the Istanbul origin Malaysia targeting network undetected by platform side transparency reporting.
Cross-Monitor Connections
This cycle findings connect to four of the six sibling monitors in the Global FIMI and Cognitive Warfare Monitor fleet, while two show no qualifying signal. For democratic-integrity, a pro government operator in Kenya is assessed as having prepared fake grassroots social media posts ahead of the Kenya 2027 general election, a direct electoral FIMI signal for that monitor cycle. For conflict-escalation, the Iranian soft war and cognitive warfare programme documented above, tied to the Islamic Culture and Communications Organization, the Islamic Propaganda Office of Khorasan Razavi, and the Bina Cultural Observatory, represents cognitive warfare activity running parallel to the active Iran related conflict theatre that monitor tracks. For european-strategic-autonomy, the Deadshot operation profiling of 18 members of the European Parliament and prominent journalists constitutes a hybrid threat signal directly relevant to that monitor coverage of institutional targeting. For ai-governance, the underlying pattern across all nine disclosed cases, including the Claude enabled production backbone behind the Radio Lengo Songo operation and the Claude enabled profiling platform linked to S2T Unlocking Cyberspace, illustrates AI vendors functioning as a new and currently unregulated node in the FIMI production and detection chain. No qualifying signal was identified this cycle for macro-monitor or environmental-risks.
Outlook
Next cycle, three evidentiary gaps will determine whether the disclosures made this week move beyond vendor self report. Independent government or platform corroboration of the Anthropic cases would allow confidence in campaigns such as the Radio Lengo Songo and Deadshot operations to move beyond Assessed; independent corporate registry or government sourcing on S2T Unlocking Cyberspace would resolve whether the Gulf and Iran profiling platform reflects state tasking or purely commercial activity, currently held at Possible confidence; and identification of the operator or client behind the Istanbul based Malaysia targeting network would allow actor coding beyond Unknown. The European Union Digital Services Act Article 40 framework remains active, but it has not yet engaged with vendor sourced evidence of this kind, a structural gap the monitor will continue to track into the next cycle.