For the past decade, nation-state actors — primarily Russia, China, and Iran — have regularly sought to influence voters in American elections. These actors have run coordinated social media campaigns to amplify divisive content, created fake news websites to push political narratives, generated misleading photos and videos to cast doubt on election integrity, and probed and occasionally breached election websites. Similar efforts will likely occur throughout the 2026 midterm elections. Because the Trump administration has dismantled, weakened, and politicized many of the entities set up to monitor election influence and interference by nation-states, it’s harder for Americans to see how foreign adversaries are trying to meddle with U.S. democracy this year.
To better understand what foreign operations against U.S. elections may look like in 2026, the Brennan Center reviewed public threat analysis reports from technology companies including Anthropic, Google, Meta, OpenAI, Microsoft, and Cloudflare, as well as nongovernmental organizations like the Institute for Strategic Dialogue and the Atlantic Council’s Digital Forensic Research Lab.
These sources underscore three key points. First, AI is now a standard feature of both influence operations and cyber operations, changing the speed and scale of what is possible. Additionally, adversaries remain interested in exploiting division and furthering political objectives in U.S. elections. Despite both of these, however, the layers of safeguards that states have in place to protect election security make it difficult, if not impossible, for adversaries to alter vote counts at scale without detection.
These sources also offer signals for foreign election influence in 2026.
AI is enabling influence operations to produce more content, with greater apparent authenticity, at a lower cost.
On the information influence side, threat actors are using AI to develop synthetic online personas, generate video, audio, and images, and comment at scale on social media networks. With AI, influence operation networks can produce more content, with a greater appearance of authenticity, that can be more effectively boosted.
A 2026 Meta threat analysis said that every coordinated inauthentic behavior network that the company had disrupted “incorporated some form of generative AI that [Meta] could identify — ranging from basic profile photo generation to fully automated, multi-modal content production pipelines.” Anthropic similarly observed influence campaigns that used AI “to build networks of fake social media profiles and entire news sites, leveraging these platforms to publish deceptive content, while completely concealing the entities behind these operations.”
In recent months, China, Iran, and private groups in Israel each separately launched autonomous influence campaigns, using Chinese open-source AI models that lack many of the safety protocols found in proprietary systems and that can be freely modified to avoid the restrictions that do exist. According to reporting, AI agents carried out nearly every step of the influence campaigns, from creating fake social media accounts to coordinating messaging.
Technology companies and nongovernmental organizations have identified nation-state activity leading up to elections across the world in 2026, clearly indicating that foreign influence has become a regular feature of elections in the United States and globally.
In September, a social media campaign that researchers linked to a Russian influence operation shared synthetic videos of celebrities to American audiences, with AI-generated audio targeting the Democratic Party and urging viewers to vote Republican. The same operation shared videos that impersonated CNN and pushed false news stories about various Democratic senatorial candidates. According to New York Times reporting, “classified U.S. intelligence assessments from recent months have determined that the Kremlin has again authorized a digital influence campaign” to influence voters and exploit division for the 2026 midterms.
A Meta threat report identified an Iran-linked network that targeted American audiences earlier this year. The network used fake personas and built audiences by managing meme accounts and tagging real journalists and politicians, before producing and amplifying content focused on American politics. And the operators used exclusively United States and Canadian proxy or hosting IPs to cover their Iranian origins.
The Digital Forensic Research Lab observed a long-standing China-linked influence operation network targeting April 2026 elections for the Tibetan Parliament-in-Exile. The operation — which is connected to a larger network that operates in the United States, the Philippines, Taiwan, and Japan — used coordinated accounts across Tumblr, X, and Facebook to push narratives that attacked specific candidates, cast doubt on election integrity, and sought to exploit wedges on political controversies.
AI is collapsing the skills and resource barriers that once limited who could carry out sophisticated cyberattacks and how much damage they could do.
On the cybersecurity side, threat actors are using AI to identify vulnerabilities, develop exploits, create more effective phishing attacks, and harvest access credentials. A recent Google threat report explains that threat actors have transitioned from “basic prompting to agentic AI workflows and AI-enabled automation,” where networks of AI agents scan infrastructure and exfiltrate data on a broad scale, all with limited human involvement. One Russian espionage campaign that Anthropic observed used AI at every point of its operation, including reconnaissance, access, collection, and exfiltration, and even “developed an AI-assisted workflow that automatically rebuilt and re-deployed their toolkit if it was detected by security products.”
A recent Anthropic report exemplifies how AI is changing the cybersecurity threat profile in two key ways. First, access to AI models has collapsed the skills gap “that used to separate well-resourced, state-sponsored operations from individual operators,” opening the door to far more threat actors who can conduct sophisticated cyber operations. Relatedly, sophistication is no longer a reliable indicator of the perpetrator of an attack, making it more difficult to trace cyber operations to their source.
Second, the movement to autonomous AI operations means that the scale and impact of cyberattacks are no longer limited by human skill, time, and capacity. Even if the types of cyberattacks themselves are not new, AI models can work much faster and in parallel, accomplishing far more in far less time than human operators were previously capable of. Facing fewer trade-offs and resource constraints, threat actors do not have to pick and choose their targets to the same extent: “everything connected to the internet is a potential target for exploitation.”
2026 cybersecurity threat reports from Google, Microsoft, and Cloudflare each outline a similar shift in tactics that Cloudflare describes as going from “breaking in” to “logging in” — using stolen credentials, social engineering, and phishing attacks to undermine and infiltrate systems and software, rather than using novel exploits. AI capabilities have been the primary cause of this shift, by making it easier to map networks, create hyper-realistic deepfakes and phishing attacks to gain trust and access, and extract data on a much larger scale.
Google’s 2026 Cybersecurity Forecast assesses China as the most active state cyber actor overall, focused on targeting edge devices (such as routers) that have fewer security safeguards, and third-party providers that offer downstream access to many organizations. China-aligned groups have previously used these techniques to gain long-term access to critical infrastructure systems, including communications, energy, water, and transportation systems, with potential large-scale disruptive impacts.