A report published by Glitched on August 5 says a CORRECTIV investigation found that ChatGPT, Google Gemini, Meta AI, and Microsoft Copilot can create convincing counterfeit news articles and screenshots that resemble established publishers. The risk is real: generative AI can draft false claims and produce polished visual material quickly. But the report’s most consequential claims — especially that ChatGPT was the “worst offender,” could reproduce exact publication layouts, and had been tested by CORRECTIV in the manner described — could not be independently verified from CORRECTIV’s published reporting as of August 6.
That gap matters. A vague warning that “AI can make fake news” is true but familiar; a documented cross-platform test of specific products, prompts, safeguards, screenshots, and failures would be a much stronger claim. Glitched names CORRECTIV as its source, yet CORRECTIV’s public site does not currently show the described investigation or the Half-Life 3/PS5-exclusive example. No separate outlet located in a review of the available reporting has independently published the alleged test results.
The practical conclusion is more precise than the headline: do not treat a screenshot of a news page as evidence that a news page existed. That was already sound security hygiene. Generative AI makes the old test — “does this look professionally designed?” — almost worthless.
CORRECTIV has an extensive, well-documented record of investigating fake news sites, cloned media brands, and Russian influence operations. Its reporting has covered campaigns that set up lookalike domains, copied the visual identities of publishers, and distributed fabricated articles through social accounts and messaging channels. In one 2025 investigation, CORRECTIV linked a campaign known as Storm-1516 to a fake version of its own reporting.
That established work makes the central premise plausible: credible-looking fake articles are an operational problem, and familiar publisher branding is an effective lure. But it does not validate the new account of a chatbot experiment.
The distinction is important for IT professionals because the proposed mechanism is different. A coordinated influence campaign can register a deceptive domain, copy a site’s front end, publish an article, and circulate a link. A generated image of a fake article may never exist as a web page at all. The first leaves infrastructure that can be examined: DNS records, certificate data, page source, archived versions, hosting history, and a URL. The second can arrive as a PNG, JPEG, PDF, Teams attachment, or pasted social-media image with none of those clues.
A screenshot-only fake is often cheaper and faster to distribute than a cloned site. It also defeats an increasingly common but flawed response: searching for the exact headline and concluding the story is genuine because someone reposted the image. Reposts validate only that an image has spread; they do not establish that the named publisher ever published it.
Those policies establish the vendors’ stated position. They do not show how consistently a particular model will reject a prompt, how image-generation tools handle a request differently from text chat, or what happens when a user supplies an existing screenshot and asks for edits.
That is the weakness in Glitched’s account. It reports that ChatGPT may refuse a request to write misleading text but still create a convincing screenshot. Such a mismatch would be an important safety failure if reproducibly demonstrated, because it would let a user shift the deceptive payload from readable text into an image. Yet the article supplies no model names, plan tiers, dates of testing, full prompts, generated files, refusal messages, or evidence that the alleged screenshots came from the products it names. It also does not say whether the test used a browser-capable agent, an image model, an uploaded reference image, or a third-party tool wrapped around a chatbot.
Without that material, there is no basis for ranking ChatGPT as more capable or less safe than Gemini, Meta AI, or Copilot. There is also no basis for the claim that any model “scraped” and replicated a particular publisher. Producing an imitation after being shown a reference image, generating a generic news-page mock-up, browsing a live page, and scraping a site’s assets are technically and evidentially different acts. The report collapses them into one allegation.
Microsoft itself warns Copilot users that generated responses can sound convincing while being incomplete or inaccurate, and advises checking sources before acting. OpenAI’s terms likewise say users should not rely on output as a sole source of truth and should evaluate it before sharing. Those are not fixes for fabricated screenshots, but they are a clearer statement of the products’ limitations than calling one service the “worst” without a reproducible test.
A fake screenshot branded as The Verge, BBC News, IGN, Microsoft, or a local newspaper can establish the emotional urgency for the next step: a link to an “emergency” Windows update, an alleged leaked Microsoft document, a supposedly compromised software installer, or a login page for Microsoft 365. The screenshot does not need to survive close inspection if it pushes recipients toward a second message containing a malicious URL.
The threat becomes more credible when it borrows an IT-specific premise:
This is why “AI-generated” is not the deciding factor in incident response. An image can be hand-edited, generated entirely by a model, assembled from a real site, or produced by a malicious web page. The relevant question is simpler: can the claim be verified through the publisher, vendor, or organization it purports to represent?
If the image names a major outlet but no corresponding story appears on that outlet’s site, treat the item as unverified. Do not “balance” that finding by counting reposts on X, Facebook, Reddit, YouTube, Discord, or Teams. A single fabricated image can be copied thousands of times with its claimed publisher attribution intact.
Administrators should fold this into existing phishing reporting processes. Staff already understand that sender names and logos can be spoofed; they need the same instruction for screenshots of apparently legitimate reporting. A message that says “look at this article” may be the lure even when it contains no suspicious attachment and no obvious technical language.
CISA’s general guidance remains the right instinct: question the source before sharing. In this case, that means requiring a real, reachable article on the claimed publisher’s domain — not a picture of its masthead, a claimed timestamp, an author byline, or a chatbot-generated imitation of all three.
The evidence supports a warning about the capability, but not Glitched’s specific vendor ranking or its attribution of a detailed test to CORRECTIV. Until the underlying prompts, outputs, methods, and CORRECTIV publication are available, readers should regard those details as uncorroborated. The operational advice does not wait for that verification: a news screenshot is now a claim to investigate, not a source to trust.
The practical conclusion is more precise than the headline: do not treat a screenshot of a news page as evidence that a news page existed. That was already sound security hygiene. Generative AI makes the old test — “does this look professionally designed?” — almost worthless.
The missing CORRECTIV record changes how the claim should be read
CORRECTIV has an extensive, well-documented record of investigating fake news sites, cloned media brands, and Russian influence operations. Its reporting has covered campaigns that set up lookalike domains, copied the visual identities of publishers, and distributed fabricated articles through social accounts and messaging channels. In one 2025 investigation, CORRECTIV linked a campaign known as Storm-1516 to a fake version of its own reporting.That established work makes the central premise plausible: credible-looking fake articles are an operational problem, and familiar publisher branding is an effective lure. But it does not validate the new account of a chatbot experiment.
The distinction is important for IT professionals because the proposed mechanism is different. A coordinated influence campaign can register a deceptive domain, copy a site’s front end, publish an article, and circulate a link. A generated image of a fake article may never exist as a web page at all. The first leaves infrastructure that can be examined: DNS records, certificate data, page source, archived versions, hosting history, and a URL. The second can arrive as a PNG, JPEG, PDF, Teams attachment, or pasted social-media image with none of those clues.
A screenshot-only fake is often cheaper and faster to distribute than a cloned site. It also defeats an increasingly common but flawed response: searching for the exact headline and concluding the story is genuine because someone reposted the image. Reposts validate only that an image has spread; they do not establish that the named publisher ever published it.
Chatbot policies prohibit the use described — but policies are not enforcement results
The named AI providers do not present deceptive publisher impersonation as an allowed use. OpenAI’s usage rules prohibit generating or promoting misinformation and impersonating an organization without permission or legal right. Google’s generative-AI policy prohibits misinformation, deceptive impersonation, and misrepresenting the provenance of generated material. Microsoft’s current Copilot terms explicitly prohibit creating or sharing disinformation or content meant to impersonate, defraud, or deceive others. Meta’s published Llama acceptable-use policy similarly bars disinformation, fraud, and impersonation.Those policies establish the vendors’ stated position. They do not show how consistently a particular model will reject a prompt, how image-generation tools handle a request differently from text chat, or what happens when a user supplies an existing screenshot and asks for edits.
That is the weakness in Glitched’s account. It reports that ChatGPT may refuse a request to write misleading text but still create a convincing screenshot. Such a mismatch would be an important safety failure if reproducibly demonstrated, because it would let a user shift the deceptive payload from readable text into an image. Yet the article supplies no model names, plan tiers, dates of testing, full prompts, generated files, refusal messages, or evidence that the alleged screenshots came from the products it names. It also does not say whether the test used a browser-capable agent, an image model, an uploaded reference image, or a third-party tool wrapped around a chatbot.
Without that material, there is no basis for ranking ChatGPT as more capable or less safe than Gemini, Meta AI, or Copilot. There is also no basis for the claim that any model “scraped” and replicated a particular publisher. Producing an imitation after being shown a reference image, generating a generic news-page mock-up, browsing a live page, and scraping a site’s assets are technically and evidentially different acts. The report collapses them into one allegation.
Microsoft itself warns Copilot users that generated responses can sound convincing while being incomplete or inaccurate, and advises checking sources before acting. OpenAI’s terms likewise say users should not rely on output as a sole source of truth and should evaluate it before sharing. Those are not fixes for fabricated screenshots, but they are a clearer statement of the products’ limitations than calling one service the “worst” without a reproducible test.
Fake articles are now a Windows and enterprise-security problem
For Windows users and administrators, counterfeit news pages are not merely a media-literacy issue. They are a delivery mechanism for fraud, credential theft, malware, and social engineering.A fake screenshot branded as The Verge, BBC News, IGN, Microsoft, or a local newspaper can establish the emotional urgency for the next step: a link to an “emergency” Windows update, an alleged leaked Microsoft document, a supposedly compromised software installer, or a login page for Microsoft 365. The screenshot does not need to survive close inspection if it pushes recipients toward a second message containing a malicious URL.
The threat becomes more credible when it borrows an IT-specific premise:
- A fabricated Microsoft security advisory can steer users to a fake KB package or “hotfix” hosted outside Microsoft’s update infrastructure.
- A counterfeit outlet can claim that a vendor has been breached and direct employees to reset passwords through a spoofed Microsoft sign-in page.
- A fake product announcement can drive interest in an unofficial preview build, activation tool, driver package, or game installer.
- A fake executive quote or supposed newsroom report can be attached to a Teams or email message to pressure staff into opening a document.
This is why “AI-generated” is not the deciding factor in incident response. An image can be hand-edited, generated entirely by a model, assembled from a real site, or produced by a malicious web page. The relevant question is simpler: can the claim be verified through the publisher, vendor, or organization it purports to represent?
Verify the publication, not the picture
When a screenshot appears to show breaking news, a product launch, a security incident, or a Microsoft advisory, start from a trusted destination rather than interacting with the image or its accompanying link. Search the publisher’s own site for the headline, visit its home page independently, and check the stated publication date and author page. For a Windows update, verify the KB number in Microsoft Support or Windows Release Health. For a vulnerability, check Microsoft Security Response Center records and the CVE entry rather than relying on a circulating summary.If the image names a major outlet but no corresponding story appears on that outlet’s site, treat the item as unverified. Do not “balance” that finding by counting reposts on X, Facebook, Reddit, YouTube, Discord, or Teams. A single fabricated image can be copied thousands of times with its claimed publisher attribution intact.
Administrators should fold this into existing phishing reporting processes. Staff already understand that sender names and logos can be spoofed; they need the same instruction for screenshots of apparently legitimate reporting. A message that says “look at this article” may be the lure even when it contains no suspicious attachment and no obvious technical language.
CISA’s general guidance remains the right instinct: question the source before sharing. In this case, that means requiring a real, reachable article on the claimed publisher’s domain — not a picture of its masthead, a claimed timestamp, an author byline, or a chatbot-generated imitation of all three.
The evidence supports a warning about the capability, but not Glitched’s specific vendor ranking or its attribution of a detailed test to CORRECTIV. Until the underlying prompts, outputs, methods, and CORRECTIV publication are available, readers should regard those details as uncorroborated. The operational advice does not wait for that verification: a news screenshot is now a claim to investigate, not a source to trust.
References
- Primary source: glitched.online
Published: 2026-08-05T08:11:29+00:00
Be Careful, AI Chatbots Can Generate Convincing Fake News Articles | GLITCHED
A new investigation has discovered that several AI chatbots are capable of generating very convincing fake news articles using real media outlets.www.glitched.online - Related coverage: help.openai.com
ChatGPT agent | OpenAI Help Center
Learn about the features of ChatGPT agent mode and how to get started
help.openai.com
- Related coverage: help.openai.com
Does ChatGPT tell the truth? | OpenAI Help Center
Understand when ChatGPT can be trusted, what it might get wrong, and how to critically assess its responses.
help.openai.com
- Related coverage: correctiv.org
Chatbots: Don’t Bother Asking AI About the EU Elections
We asked three of the best-known AI chatbots questions on the upcoming EU election. Our experiment shows: Google Gemini, Microsoft Copilot and ChatGPT fail when it comes to answering political questions.
correctiv.org
- Related coverage: files.kff.org
- Related coverage: axios.com
Popular chatbots are amplifying even more misinformation, study finds
The rate at which popular AI services amplify or fail to flag falsehoods has doubled in a year, per NewsGuard.www.axios.com
- Related coverage: tagesschau.de
Fake News unter seriöser Marke | tagesschau.de
Angebliche Meldungen der tagesschau, des Spiegel, der BBC oder anderer seriöser Marken: Urheber von Fake News fälschen Nachrichtenseiten, um irreführende Inhalte zu tarnen. Von Patrick Gensing und Carla Reveland.www.tagesschau.de
- Related coverage: support.microsoft.com
Transparency Note for Microsoft Copilot | Microsoft Support
Transparency Note for Microsoft Copilotsupport.microsoft.com - Related coverage: support.microsoft.com
Privacy FAQ for Microsoft Copilot | Microsoft Support
Get answers to frequently asked questions about privacy and safety topics related to Microsoft Copilot, your AI assistant.support.microsoft.com - Related coverage: cisa.gov
- Related coverage: cisa.gov