AI's Threat to Democracy: When AI Learns to Persuade
Note: this is an expanded and updated version of a talk that I recently gave for the League of Women Voters about AI and Democracy. This topic continues to be a concern, especially as more people are getting their answers from AI.
A new set of studies published in Nature and Science paint a troubling picture of what AI chatbots might mean for our elections—and for democracy itself.
The Nature study ran large-scale experiments with thousands of adults across multiple countries—the United States, Canada, and Poland. People were invited to have short conversations with AI chatbots that were tuned to favor specific political candidates. The participants didn’t think they were being “advertised to.” They thought they were just having a conversation.
After just a few back-and-forth exchanges, voters’ political preferences shifted more than they typically do after watching a traditional political TV ad. In fact, the chatbots were significantly more persuasive than presidential campaign commercials—effects that were larger than typically observed from decades of research on political advertising. The researchers also found that AI models advocating for candidates on the political right made more inaccurate claims across all three countries studied.
The Science study took a different approach. Working with nearly 77,000 participants in the UK, researchers deployed 19 different AI models to discuss over 700 political issues—everything from climate change to the cost of living crisis to public sector pay. They then checked the accuracy of nearly half a million claims made by the AI.
What they found was troubling. The chatbots frequently made inaccurate claims, and the errors weren’t random—they skewed in a particular direction. When the AI was prompted to argue for right-wing positions, its arguments were less accurate than when it argued for left-wing positions. The researchers suggest this may reflect patterns in the training data or the nature of the arguments themselves, but regardless of the cause, the implication is clear: AI-powered political persuasion can systematically spread more misinformation for some viewpoints than others.
What made the chatbots persuasive? The researchers found that “information-dense” arguments—packed with lots of facts and evidence—were the most effective at changing people’s views. But here’s the catch: the more information-heavy the arguments became, the less accurate they tended to be. There’s a persuasion-accuracy tradeoff baked into how these systems work.
Another key finding: post-training and prompting were the dominant levers of persuasion—not model size or personalization. Chatbots that had been specifically trained for persuasion were up to 51 percent more convincing than those that hadn’t. This matters because it means even small, open-source models can become powerful persuaders with the right fine-tuning. As the researchers noted, actors with limited resources could potentially deploy highly persuasive AI systems that bypass the safeguards built into larger proprietary models.
In other words, people weren’t being persuaded by balanced facts. They were being persuaded by confidence, repetition, and volume.
Now, to be clear, humans have always persuaded other humans with bias, emotion, and misinformation. That’s not new. What is new is scale. For the first time, disingenuous or one-sided conversations can now be personalized and delivered to millions of people simultaneously—without the public scrutiny that a TV or social media ad would receive.
And that raises some serious questions for democracy.
Lying at Scale.
For most of our history, political persuasion was limited by very human constraints—time, geography, and money. A candidate could give a speech to a few hundred people, buy a TV or digital ad, or knock on doors, perhaps giving out bogus information. But it didn’t scale.
Today, an AI system can hold millions of one-on-one political conversations at the same time. It can learn what you care about, tailor its arguments to your values, and engage you repeatedly, all without you realizing you’re part of a coordinated campaign.
In a healthy democracy, we assume that people make decisions based on some shared body of facts, exposure to multiple viewpoints, and open public debate. But when persuasion becomes automated, invisible, and personalized at scale, all three of those assumptions start to break down.
There’s also the issue of transparency. With traditional campaigns, at least we can usually tell who is trying to persuade us. Ads disclose sponsors. Messages can be challenged publicly. But with conversational AI, voters may not even know who—or what—is behind the message influencing them.
And here’s another uncomfortable finding: research from Stanford shows that simply labeling content as “AI-generated” doesn’t significantly reduce its persuasive power. People read the label, shrug, and are persuaded anyway.
From Chatbots to Swarms
If individual AI chatbots are concerning, a new paper in Science warns that we should be even more worried about what’s coming next: malicious AI swarms.
These aren’t the simple bots of years past that repeated the same script over and over. Researchers describe AI swarms as coordinated networks of AI-controlled agents that can maintain persistent identities and memory, adapt in real time to engagement and human responses, infiltrate online communities, and operate with minimal human oversight across multiple platforms.
Think of it this way: older botnets were like megaphones repeating one script. AI swarms act more like adaptive digital societies—a chorus of seemingly independent voices that can create the illusion of grassroots consensus while spreading coordinated messaging.
The researchers outline at least five cascading harms from such systems.
First, swarms can manufacture “synthetic consensus,” exploiting our tendency to update our opinions based on what we think everyone else believes.
Second, they can fragment our shared reality by targeting different communities with different narratives.
Third, they can unleash coordinated harassment campaigns against journalists and activists.
Fourth, they can poison the training data of future AI systems by flooding the web with fabricated content.
And fifth, all of this sustained manipulation can corrode institutional trust, leaving democratic safeguards vulnerable.
This threat isn't theoretical. Analysis of pro-Kremlin influence operations like the "Pravda" network suggests such tactics are already being deployed. According to investigations by NewsGuard and the American Sunlight Project, these networks appear purpose-built for machine consumption—articles duplicated across hundreds of domains, poor user interfaces, and low human traffic indicate their primary audience is web crawlers feeding large language models. The network churned out over 3.6 million articles in 2024 alone, and when NewsGuard tested ten leading AI chatbots, they repeated Pravda's false narratives 33 percent of the time.
We’ve Seen This Before
The risks of automated systems distorting democratic feedback loops aren’t new. Some of you might remember the net-neutrality debate from 2017, when millions of public comments flooded the FCC. It looked like a massive wave of civic engagement.
But what we later learned was deeply troubling. The New York Attorney General’s investigation found more than 18 million fabricated comments were submitted—about 80 percent of the total submitted. Lead generation companies hired by Telcom companies used automated systems, stolen identities, and even the names of deceased people when submitting comments.
At the same time, a single 19-year-old college student used automated software to submit over 9 million fake comments supporting net neutrality.
That was before today’s generative AI. Even then, computer-generated text was convincing enough to fool (some) policymakers. Now we have systems like ChatGPT that can generate human-sounding language at massive scale—and even bypass safeguards like CAPTCHAs. That means the risk to democratic processes is growing fast. Automation can quietly overwhelm real human voices in the very systems designed to represent them.
What Can Be Done?
In 2024, the House of Representatives passed a bill that tried to address this directly. It was called the Comment Integrity and Management Act. The idea was simple: federal agencies would be required to make a good-faith effort to verify that public comments came from real human beings. Agencies could also collapse thousands of identical submissions into one representative entry, while still reporting how many duplicates were received.
The bill passed the House—but it never made it through the Senate. And since then, the issue has largely gone quiet.
The researchers behind the AI swarm study recommend a three-pronged defense: platform-side measures like always-on swarm detection and transparency audits; model-side safeguards including standardized persuasion-risk tests and content watermarking; and system-level oversight through something like a UN-backed AI Influence Observatory.
Who controls AI?
Now layer on another uncomfortable reality: the companies and powerful individuals building these AI systems often have very specific policy and political agendas—and they’re not shy about using their platforms and influence to advance them.
Consider Elon Musk, whose xAI developed the Grok chatbot. In January 2026, Defense Secretary Pete Hegseth announced that the Pentagon would integrate Grok into military networks—both classified and unclassified—giving 3 million military and civilian personnel access to the system. The announcement came just days after Grok drew global outcry for generating nonconsensual explicit images, and despite the chatbot’s documented history of spreading misinformation and conspiracy theories. Senator Elizabeth Warren’s office raised concerns that xAI was a “late-in-the-game addition” to Pentagon contracts and questioned whether Musk received inappropriate consideration given his access to sensitive government data through his role leading the Department of Government Efficiency.
This brings me to a broader concern: AI systems controlled by private companies and individuals who have demonstrated a willingness to manipulate their platforms for personal or political gain are simply too dangerous to trust with public-facing interactions at this scale.
We have evidence this happens. In February 2023, Platformer reported that Musk ordered Twitter engineers to alter the algorithm to artificially boost his own tweets by a factor of 1,000 after one of his posts received fewer views than President Biden’s Super Bowl tweet. He flew to company headquarters overnight to demand the change, and 80 engineers worked through the night to implement it. Then, in the lead-up to the 2024 election, researchers at Queensland University of Technology found that X’s algorithm appeared to change around July 13—the day Musk endorsed Donald Trump—resulting in a 138 percent increase in views for Musk’s posts and systematic boosts to Republican-leaning accounts.
When the same person who controls the algorithm also controls the AI chatbot that’s being integrated into military systems—and that chatbot has a documented history of spreading misinformation—we should be asking hard questions about what guardrails exist and whether they’re sufficient. This isn’t about one individual or one company. AI systems that shape public discourse are controlled by private actors with their own agendas, and there’s no meaningful accountability when those systems are manipulated.
The Bottom Line
If automated systems can quietly influence voter opinions more effectively than traditional campaigns—and do so by bending the truth—how do we protect fair public debate?
I don’t have the answers, but I do know that silence around this issue matters. We still don’t have a national policy for how to deal with AI-generated participation in one of the most basic feedback loops of democracy: the public comment process. And now we’re facing threats that make the 2017 net-neutrality debacle look like a kids play.
The authors of the AI swarms study put it well: democracies have a brief but crucial window to pull AI-enabled influence operations back from the brink. Whether we use that window wisely remains to be seen.