---
title: Google GTIG documents Iranian state-linked actors expanding AI use to generate photorealistic personas and specialist persuasion narratives for influence operations
url: https://propagandaarchive.org/briefs/20260909-0510Z-iran-google-ai-influence-personas/
description: Google Threat Intelligence Group’s Q3 2026 AI Threat Tracker, released 8 September 2026, reports that Iranian government-linked actors (including APT42 /…
section: Watch briefs
---

![Illustration: a dossier collage of a typewriter, drafted press releases and an annotated speech transcript.](https://propagandaarchive.org/static/generated/hero-write.jpg)

[Watch briefs](https://propagandaarchive.org/briefs/) · September 9, 2026

# Google GTIG documents Iranian state-linked actors expanding AI use to generate photorealistic personas and specialist persuasion narratives for influence operations

- **Filed:** September 9, 2026, 05:10 UTC
- **Actor:** Iranian state-linked actors (APT42 / CALANQUE ION / IRGC-affiliated; Google GTIG attribution)
- **Target:** Global online audiences, particularly Western and regional users of social platforms and information environments susceptible to synthetic personas and expert-framed narratives
- **Confidence:** **high** Multiple independent open sources, low disagreement about the facts
- **Techniques:** [Synthetic media](https://propagandaarchive.org/techniques/synthetic-media/) [Plain folks](https://propagandaarchive.org/techniques/plain-folks/) [Card stacking](https://propagandaarchive.org/techniques/card-stacking/) [Narrative laundering](https://propagandaarchive.org/techniques/narrative-laundering/)
- **Channels:** large language models (Gemini and others)text-to-image generation systemsphotorealistic synthetic personasspecialist-identity narrative generation

## Summary

Google Threat Intelligence Group’s Q3 2026 AI Threat Tracker, released 8 September 2026, reports that Iranian government-linked actors (including APT42 / CALANQUE ION, affiliated with the IRGC) have moved beyond basic LLM prompting to craft highly detailed text-to-image instructions specifying lighting, camera angles and facial textures for photorealistic online personas, and to instruct models to adopt expert identities such as energy-market analysts or psychological-warfare specialists while embedding advanced persuasion techniques into state-aligned narratives.

## Analysis

Primary evidence is Google Threat Intelligence Group’s AI Threat Tracker for Q3 2026, publicly summarised on 8 September 2026 by multiple outlets including Ynet and Gizmodo. The report states that Iranian actors previously used LLMs mainly for open-source intelligence and phishing; they now generate granular technical prompts for image systems—explicitly specifying studio lighting, camera angles and realistic skin textures—to produce photorealistic fictitious online personas. Concurrently, operators instruct models to adopt specialist identities (energy-market analysts, psychological-warfare experts) and to incorporate advanced persuasion techniques into narratives advancing Tehran’s objectives.

The core mechanism is synthetic-media generation of both visual identity and authoritative voice. Photorealistic personas transfer apparent ordinary or expert credibility (plain-folks and transfer elements) onto fabricated accounts, while the selective construction of expert-framed, state-aligned arguments constitutes card-stacking of the information environment. By routing content through models that can be prompted to sound independent or specialist, the operation launders origin and intent (narrative-laundering). The shift from simple prompting to detailed, multi-step generative pipelines and autonomous agentic patterns shortens production cycles and raises the volume of plausible synthetic content that can be injected into social platforms or search corpora.

This qualifies as an influence operation because the decisive features are concealment of origin, artificial construction of interpersonal and epistemic credibility, and deliberate alignment with state political objectives. Identical technique families—synthetic personas, specialist-identity scripting, AI-assisted persuasion—appear across state and commercial actors; scoring the methods therefore remains independent of any particular national attribution. Google’s own mitigations (account and project blocks, safety-filter updates) confirm detection of the activity but do not eliminate the underlying capability once operators migrate to open or less-restricted models.

Literacy counter: treat newly appearing accounts that present as domain experts or everyday citizens yet display unusually polished, photorealistic imagery and highly consistent narrative framing as provisional. Reverse-search profile images for generation artifacts, cross-check claimed expertise against primary credentials or institutional records, and prefer multi-source verification over single synthetic-looking voices. When an AI system or social feed surfaces an ‘expert’ analysis that maps tightly onto known state talking points, demand provenance and independent corroboration before accepting the frame. Platform and model providers should publish clearer indicators of synthetic-persona detection rather than relying solely on post-hoc researcher or threat-intel disclosure.

## Evidence

1. [Ynet: Google: Iran expanding AI use in cyberattacks and influence operations (8 Sep 2026)](https://www.ynetnews.com/tech-and-digital/article/syojl2tuzl)
2. [Gizmodo: Silicon Valley’s AI Agent Push Has Been Paying Off—for Cybercriminals (8 Sep 2026)](https://gizmodo.com/silicon-valleys-ai-agent-push-has-been-paying-off-for-cybercriminals-2000808764)
3. [Cyber Magazine summary of GTIG Q3 2026 AI Threat Tracker (8 Sep 2026)](https://cybermagazine.com/news/google-ai-now-powers-every-threat-actors-playbook)
4. [Prior Recorded Future Insikt Group reporting on Iran AI asymmetric playbook (Aug 2026)](https://www.recordedfuture.com/research/iran-ai-asymmetric-playbook)
