cd /news/ai-safety/openai-bans-china-linked-accounts-bu… · home topics ai-safety article
[ARTICLE · art-82256] src=insideai.news ↗ pub= topic=ai-safety verified=true sentiment=↓ negative

OpenAI Bans China-Linked Accounts Building AI Surveillance Tool

OpenAI has banned a cluster of ChatGPT accounts likely originating from China, dubbed 'Peer Review,' after detecting they were used to develop surveillance tools, analyze protest announcements, and research political figures. The operation involved the development of a 'Qianyue Overseas Public Opinion AI Assistant' designed to scrape social media for discussions on Chinese human rights issues, with insights reportedly sent to Chinese embassies and intelligence agents. OpenAI's investigation, detailed in its February 2025 report, revealed manual prompting during Chinese business hours and the use of Meta's Llama 3.1 model for the tool's analysis engine.

read3 min views1 publishedJul 31, 2026
OpenAI Bans China-Linked Accounts Building AI Surveillance Tool
Image: Insideai (auto-discovered)

July 31, 2026, (Inside AI) — OpenAI has banned a cluster of ChatGPT accounts likely originating from China, after detecting they were used to develop surveillance tools, analyze protest announcements, and research political figures. The operation, internally dubbed "Peer Review," involved manual prompting during Chinese business hours, with operators using the model to draft sales pitches for a social media monitoring tool, debug related code, and translate documents.

The banned accounts were linked to the development of a purported "Qianyue Overseas Public Opinion AI Assistant," designed to scrape platforms like X, Facebook, and Reddit for discussions on Chinese human rights issues. According to OpenAI, the operators claimed the tool's insights were sent to Chinese embassies and intelligence agents monitoring protests in the US, Germany, and the UK. This activity was first detailed in OpenAI's February 2025 report, which cataloged multiple state-linked influence operations disrupted by the company.

The discovery raises urgent questions about how large language models are being weaponized for surveillance, even by actors who rely primarily on open-source alternatives. While the Qianyue tool reportedly used Meta's Llama 3.1 as its analysis engine, ChatGPT was instrumental in its design and promotion. This dual-use dilemma echoes earlier research from the arXiv preprint on LLM-enabled spear phishing, which found that AI-generated phishing emails were already more effective than human-written ones.

Surveillance Tool Pitched as "Public Opinion AI" #

OpenAI's investigation revealed three primary workstreams. First, operators used ChatGPT as a research tool to gather public information on think tanks and politicians in the US, Australia, and Cambodia. Second, they fed the model screenshots of English-language documents, including announcements for Uyghur rights protests in Western cities, for translation and analysis. OpenAI could not verify the authenticity of these documents.

The most extensive activity centered on the Qianyue tool. Operators prompted ChatGPT to generate sales descriptions, debug code, and even proofread claims that the tool's intelligence had been shared with Chinese authorities. One account debugged code that referenced Meta's Llama 3.1:8b model deployed via Ollama, suggesting the surveillance system ran independently of OpenAI's infrastructure. The same account also worked on malware analysis code and mentioned models from Alibaba's Qwen and DeepSeek.

"Based on this network's behavior in promoting and reviewing surveillance tooling, we have dubbed it 'Peer Review,'" OpenAI stated in its report.

Manual Operation, Limited Public Footprint #

Unlike automated bot networks, the Peer Review cluster exhibited patterns consistent with manual human operation. Accounts were active during mainland Chinese business hours, used Chinese-language prompts, and showed varied interaction volumes. OpenAI suspects at least one account was shared by multiple operators. The actors occasionally asked ChatGPT to adopt the persona of an English speaker named "Thompson," but no generated comments were found posted online.

This operational security stands in contrast to previous influence operations, such as Russia's Doppelganger campaign, which relied heavily on automated content generation. The manual approach may have helped the cluster evade detection longer, though OpenAI did not disclose when the accounts were banned. The company noted that assessing the full impact requires cooperation from other model providers, particularly those hosting open-source models used in the tool's backend.

OpenAI's report also flagged a separate account that generated a performance review claiming to have created phishing emails for Chinese clients. No evidence suggested AI was used to craft those emails, but the admission underscores the blurred lines between corporate espionage and state-directed surveillance. The incident arrives as governments worldwide grapple with AI risk management frameworks that struggle to address cross-border, multi-model threats.

── more in #ai-safety 4 stories · sorted by recency
── more on @openai 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/openai-bans-china-li…] indexed:0 read:3min 2026-07-31 ·