Wiki · Pattern · Last reviewed August 12, 2026

Coordinated Inauthentic Behavior

Coordinated inauthentic behavior (CIB) is Meta's term for coordinated efforts to manipulate public debate for a strategic goal when fake accounts are central to the operation. In broader usage, it describes networks that conceal common control or manufacture false social proof. It is a claim about deceptive behavior and provenance—not automatically about content falsity, bots, foreign sponsorship, or persuasive impact.

Snapshot

Definition

Meta defines CIB narrowly: coordinated efforts to manipulate public debate for a strategic goal in which fake accounts are central. The company says it focuses on groups of accounts and Pages that work together to mislead people about who they are and what they are doing, and that enforcement is based on behavior rather than the viewpoint or truth of the content. A network removal can include authentic assets directly involved with the deceptive operation, not only the fake accounts.

Outside Meta, analysts sometimes use “CIB” more loosely for concealed account control, undisclosed paid amplification, fake grassroots activity, or coordinated persona networks across services. That broader usage can be useful, but a report should name the policy or test being applied. Otherwise the label can hide a disagreement about whether fake accounts, strategic intent, public-debate manipulation, or merely suspicious synchronization is required.

Adjacent terms have different scope. An influence operation may be overt or covert and need not satisfy Meta's fake-account threshold. Disinformation concerns intentionally deceptive false or misleading information, while CIB can distribute true material. The European External Action Service's foreign information manipulation and interference (FIMI) framework concerns intentional, coordinated, manipulative behavior within its external-affairs mandate and does not use Meta's CIB rule as its legal threshold. “Foreign,” “government-linked,” and “state-controlled media” are attribution or sponsorship claims, not synonyms for inauthenticity.

Boundary Tests

Lifecycle and Indicators

Deceptive operations are better understood as a lifecycle than as a list of bad keywords. Carnegie's platform-agnostic Online Operations Kill Chain begins with observable tactics and covers acquiring infrastructure and accounts, disguising assets, building audiences, coordinating activity, engaging targets, moving people or material across services, and preserving or rebuilding the operation after disruption.

Common tactics include fake, duplicate, purchased, or compromised accounts; invented personas and front organizations; copied or generated profile media; misleading news brands; shared administrators or payment instruments; burner domains; coordinated comments and reposts; fake followers or reactions; undisclosed paid amplifiers; and laundering through screenshots, websites, messaging apps, or apparently independent outlets. No operator must use every tactic.

Content and identity strategies often mix authentic and deceptive elements. A network may quote legitimate news, recruit real supporters, purchase advertising, or amplify a sincere local concern while hiding the controller. That blend is why an investigation must map assets and actions rather than declare an entire topic or audience illegitimate.

Evidence Layers

Coordination evidence. Shared administrators, infrastructure, payment records, recovery details, posting tools, repeated content, synchronized timing, unusual sequences of hashtags or links, and mutual amplification can support a coordination finding. Research by Pacheco and colleagues shows how shared behavioral traces can construct coordination networks, but a similarity edge is an investigative signal rather than proof of misconduct.

Inauthenticity evidence. Fabricated or stolen identities, concealed common control, false claims of independence, undisclosed client relationships, misleading location, account purchase or compromise, and deliberate enforcement evasion bear on deception. Ordinary use of the same scheduling service, campaign toolkit, or news source does not establish this layer.

Attribution evidence. Technical infrastructure, financial records, organizational documents, account recovery data, operator mistakes, human sources, and intelligence may support attribution at different confidence levels. “Originated in,” “operated by,” “funded by,” “worked for,” “aligned with,” and “benefited” are not interchangeable.

Reach and effect evidence. Asset count, posts, followers, impressions, authentic engagements, cross-platform pickup, news coverage, conversions, attitude change, and offline action measure different things. Fake followers can inflate apparent audience size; views do not prove belief; removal before breakout does not prove that every attempted harm was prevented.

Detection needs a comparison baseline. Synchronized posting may be ordinary for a newsroom or advocacy coalition and anomalous for supposedly unrelated local residents. Thresholds should be tested across languages, time zones, accessibility tools, and community practices before enforcement.

Minimum Evidence Record

AI Relevance

Generative systems can assist with persona biographies, profile images, message variants, translation, localization, research, comments, articles, and code used in an operator's workflow. If connected to posting and monitoring tools, automation can also reduce the labor needed to maintain many assets. These are production and operations capabilities; distribution still depends on accounts, platform access, ranking, advertising, audience response, and operational security.

Public provider reports support a measured assessment. OpenAI reported in May 2024 that five disrupted covert operations used its models for tasks including writing, translation, persona creation, research, and code, but none achieved meaningful breakout into authentic communities in its assessment. Google's January 2025 review of government-backed actors using Gemini found productivity gains in research, localization, persona and content work, but no novel capability in the observed dataset. Meta's review of 2024 elections similarly characterized generative AI gains for the CIB networks it observed as incremental.

OpenAI's June 10, 2026 report adds a current case: it described two clusters of ChatGPT accounts assessed as likely originating in China that generated comments and images about U.S. AI data centers, tariffs, and technology policy. OpenAI said it found no evidence of meaningful breakout beyond the operators' own activity. That is a provider finding from the evidence available to OpenAI, not an independent measurement of every related account or audience across the internet.

AI origin and network deception remain separate. A watermark, label, detector result, or Content Credential can inform whether an artifact was generated or edited, but it does not identify a network's controller or prove coordination, falsity, intent, or impact. C2PA likewise states that provenance alone cannot establish whether content is true. Investigators need both artifact evidence and network evidence.

Current Context

As of August 12, 2026, CIB remains Meta's platform-policy language, not a general statutory offense. In its February 2026 U.S. midterm-election announcement, updated June 1, Meta said it continues to expose and disrupt foreign influence operations and has removed 200 CIB networks since 2017. That number is a cumulative company disclosure based on Meta's own policy, visibility, and counting rules; it is not an independent prevalence estimate.

The wider policy vocabulary is plural. The EEAS describes FIMI as mostly non-illegal, intentional, coordinated, manipulative behavior threatening political values or processes, and published its fourth annual threat report in March 2026. FIMI is useful for foreign-affairs analysis but is broader than Meta's fake-account-centered CIB policy. U.S. agencies use still other terms, including foreign malign influence and election influence. Reports should retain the originating institution's definition rather than translate every framework into CIB.

In the European Union, the Digital Services Act requires very large online platforms and search engines to assess and mitigate systemic risks, including risks to civic discourse and electoral processes. The Commission's 2024 election guidelines discuss measures across recommender systems, political advertising, generative AI, incident response, and cooperation. The voluntary Code of Conduct on Disinformation became a DSA code of conduct on July 1, 2025; the Commission says its commitments are an auditable benchmark for adhering services, not a universal legal definition of CIB. The first reports after that recognition, published in March 2026, covered July through December 2025.

A separate EU transparency layer took effect on August 2, 2026. Article 50 of the AI Act requires machine-readable marking of certain AI-generated or manipulated outputs by providers and disclosure by deployers for deepfakes and certain AI-generated public-interest text, subject to the regulation's scope and exceptions. The Commission published final guidelines on July 20 and a voluntary transparency code to support compliance. These duties may improve artifact-level evidence; they do not determine whether accounts coordinated or acted inauthentically.

Governance and Safety

Responsibilities differ by actor. Platforms can investigate account control, ads, ranking, and on-service behavior. AI providers can examine model-use telemetry and enforce misuse policies, but may not see where outputs travel. Researchers can compare public artifacts and cross-platform traces but rarely possess private account data. Regulators assess legal compliance, while law-enforcement and intelligence bodies apply different authorities and evidentiary standards. A platform takedown is not a criminal judgment or government attribution.

Enforcement should be graduated and evidence-matched. Measures can include verification challenges, rate limits, reach reduction, ad or monetization restrictions, warnings, removal of deceptive assets, preservation of a network for investigation, notification of affected parties, and public threat reporting. Network-wide removal and public attribution demand stronger corroboration than a temporary anti-spam friction. High-impact actions need a named decision owner, documented confidence, and review.

The rights risk is substantial. Device linkage, graph analysis, location inference, and identity checks can expose dissidents, journalists, survivors, diaspora groups, or whistleblowers. Programs should apply data minimization, access controls, retention limits, language and regional review, red-team tests for false positives, and meaningful notice and appeal. Delayed notice may be justified during a live investigation, but permanent secrecy should not be the default.

Cross-platform sharing should carry context: indicator type, time window, confidence, purpose, expiry, handling limits, and the evidence needed before action. Meta's 2024 Moldova report itself cautioned that merely sharing or engaging with an operation's links was insufficient for attribution without corroboration. Indicator exchange should not become guilt by association or an unreviewable private blocklist.

Provenance and synthetic-media labels are supporting controls, not substitutes for network analysis. Ad libraries, public threat reports, independent audits, researcher access, archived artifacts, and appeal outcomes are needed to test whether integrity systems work fairly. Governance should measure both missed operations and wrongful enforcement against authentic communities.

Source Discipline

Write CIB findings as a claim ladder. First state the observed assets and behavior. Then state the coordination and deception inference. Treat actor, sponsor, client, location, strategic purpose, reach, and effect as additional claims, each with its own evidence and confidence. Do not let “linked to” carry all of those meanings at once.

Source type sets the visibility boundary. A platform report may have private administrator, device, ad, and recovery data but is also reporting on its own enforcement. An AI-provider report may show prompts and account clusters but not downstream distribution. Government attribution may include classified evidence the public cannot inspect. Open-source research can be reproducible yet incomplete after deletions or API restrictions. A regulator document establishes a legal or procedural act, not the factual accuracy of every company submission.

Use dates and procedural verbs. A network can be suspected, investigated, assessed, removed, attributed, appealed, or reconstituted; these are not the same event. Record whether asset totals are observed, removed, or estimated and whether follower counts include likely fake engagement. A current policy page should not be used to rewrite the rule that applied at an earlier takedown without checking the historical version.

Do not infer persuasion from production volume, follower counts, impressions, or AI use. Demonstrated impact requires defined outcomes and methods. Provider reports that found little breakout are important counterevidence to hype, but they also should not be generalized beyond their datasets, services, and time windows.

Spiralist Reading

For Spiralism, coordinated inauthentic behavior is synthetic congregation: a concealed operator stages a crowd so that real people encounter manufactured social evidence as if a community had already formed.

The injury is not merely a disputed claim. It is deception about who is present, how many voices exist, and why attention is moving. The corrective discipline is equally important: preserve the network record without treating coordination, anonymity, or collective speech itself as suspect.

Open Questions

Integrity and information disorder

Platform governance

AI, persuasion, and evidence

Sources


Return to Wiki