The AI Bot Farm Crisis: Why U.S. Law Can't Keep Up With Fake Personas Targeting Elections
The United States lacks a comprehensive legal framework to govern AI-powered bot farms and coordinated political manipulation, leaving a critical gap in election security as foreign actors deploy increasingly sophisticated influence operations. In July 2024, the Department of Justice disrupted a Kremlin-backed bot farm operating fake personas on X, formerly Twitter. But that rare enforcement win masked a troubling reality: the technology has evolved far beyond what existing U.S. law was designed to address, and the next operation may be harder to detect and stop.
How Are AI Bot Farms Different From Old Spam Networks?
Traditional bot farms were relatively easy to spot. They relied on networks of fake accounts mimicking human posting behavior, and their repetitive patterns made coordinated inauthentic behavior detectable by researchers and platforms. The new generation of AI-enabled influence operations has erased many of those detection advantages.
A Frontiers in Artificial Intelligence study found that AI-generated election disinformation is now indistinguishable from authentic human-written journalism in more than half of evaluated instances, meaning that the tools platforms and researchers built to flag synthetic content are increasingly inadequate. The same research documented that bot-driven amplification accounts for roughly 25 percent of Twitter activity, and that AI-generated fake news websites have grown tenfold, with over 1,200 such sites identified by 2024 alone.
What makes this evolution particularly dangerous is the persuasion dimension. Research published in late 2025 found that AI chatbots shifted voters' political views by a substantially larger margin than traditional political advertising. Bot farms are no longer simply amplifying messages that humans might otherwise ignore. They are actively constructing and updating in real time the information environment in which political judgments are made.
What Evidence Shows the Scale of This Threat?
In September 2025, leaked documents from a Beijing-based technology firm called GoLaxy provided an unsettling window into how far this evolution has gone. The documents described what the company called a "Smart Propaganda System," a network of artificial intelligence-generated personas engineered to build psychological profiles of targets, adapt their messaging in real time, and saturate search results with fabricated content to warp the targets' perceptions. One internal dossier revealed that the system had targeted 117 members of the U.S. Congress. The accounts did not just broadcast propaganda. They listened, learned, and persuaded.
GoLaxy was not alone in this capability. In June 2026, OpenAI disclosed that it had disrupted a Chinese influence operation that used its own tool, ChatGPT, to generate social media posts targeting U.S. public opinion on tariffs, AI policy, and data centers. A July 2026 Brennan Center report confirmed that foreign influence threats to U.S. elections remain elevated.
Why Can't Current U.S. Laws Address This Problem?
The existing U.S. regulatory architecture was not designed to address this threat. In 2024, the Federal Election Commission (FEC) declined to issue binding rules addressing AI-generated content in campaign communications, adopting only an interpretive rule that clarified existing misrepresentation prohibitions apply, regardless of the technology used. The FEC's authority under the Federal Election Campaign Act applies specifically to candidates and their agents, but it does not extend to political action committees, foreign state actors, or private firms operating AI persona networks from abroad.
The Justice Department has pursued foreign bot operations under the International Emergency Economic Powers Act and federal money laundering statutes, while separately charging foreign operatives under the Foreign Agents Registration Act. This is reactive, case-by-case enforcement that leaves the underlying infrastructure of AI-driven influence operations largely unaddressed. Several states, including California, have enacted bot disclosure laws requiring operators of automated accounts to identify themselves as such, but disclosure requirements designed for crude spam bots offer limited protection against AI systems sophisticated enough to evade current detection systems.
Steps to Close the Regulatory Gap in AI Governance
- Platform Transparency Obligations: Require designated platforms to conduct annual risk assessments addressing systemic threats including information manipulation and coordinated inauthentic behavior, and provide vetted researchers with access to platform data for independent auditing, similar to the European Union's Digital Services Act approach.
- Mandatory Bot Labeling for AI-Generated Accounts: Establish clear labeling requirements for AI-generated content and automated accounts, making it easier for users and researchers to identify synthetic personas and reducing the persuasion advantage of undetected bot networks.
- Pre-Bunking Standards During Election Periods: Implement structural interventions aimed at reducing the economics of manipulation, including pre-bunking standards that prepare voters to resist misleading narratives before they encounter them during critical election windows.
The Frontiers study's policy recommendations reflect these constraints. Rather than targeting content directly, the authors propose structural interventions aimed at reducing the economics of manipulation. However, the Trump Administration's response to date points in the opposite direction. In January 2026, the Department of Justice established an AI Litigation Task Force tasked with challenging state AI laws, including the bot disclosure laws that currently represent the only domestic legal check on automated political accounts. In March 2026, the White House released a National AI Legislative Framework that explicitly recommends against creating any new federal rulemaking body to regulate AI and calls instead for governing AI through existing agencies whose mandates were not designed with influence operations in mind.
How Does Europe's Approach Differ From the U.S. Model?
The contrast with the European Union is instructive. The EU's Digital Services Act, which entered into force for large platforms in 2023, requires designated platforms to conduct annual risk assessments addressing systemic threats including information manipulation and coordinated inauthentic behavior, and to provide vetted researchers with access to platform data for independent auditing. The EU AI Act separately requires that AI-generated content be clearly labeled. Neither Act fully closes the regulatory gap, but together they create obligations directed at the infrastructure of manipulation and they provide researchers and regulators with data access that no U.S. framework currently mandates.
Constructing an analogous U.S. framework faces genuine legal obstacles. The First Amendment offers broad protection to anonymous political speech, and courts have been skeptical of disclosure requirements that chill protected expression. Any federal statute governing AI-generated political content would need to navigate the line between regulating deceptive foreign manipulation and regulating domestic political speech, which holds the highest constitutional protection.
In October 2025, members of Congress wrote a letter asking social media platforms to share metrics on bot prevalence and describe their coordination with federal agencies, an acknowledgment of how much remains unknown and ungoverned. Senator Schiff recently reintroduced legislation targeting AI-generated political deepfakes, but a bill focused on synthetic images alone does not address the bot farm infrastructure at the heart of the problem. Closing it will require federal legislation that treats coordinated inauthentic behavior as a structural regulatory problem rather than as just a content moderation challenge for platforms to manage on their own.
The conclusions drawn from the GoLaxy documents suggest that the gap between what AI-powered influence operations can do and what the law can address is widening, not narrowing. Without comprehensive federal action, the infrastructure of AI-driven manipulation will continue to evolve faster than the regulatory response, leaving U.S. elections vulnerable to increasingly sophisticated foreign and domestic influence campaigns.