Estonia, a country of 1.4 million people that spent half a century under Soviet rule, has built one of the most serious early-warning systems in Europe for Russian influence operations. Its government-backed Estonian Language Institute has now extended that work to AI, publishing a benchmark that scores dozens of AI chatbots on how well they resist Russian propaganda narratives without help from external fact-checkers or web searches.
The test covers 14 categories of narratives that Russian influence campaigns actively push: whether Crimea belongs to Russia, justifications for the war in Ukraine, the history of NATO, and Russia's framing of its World War II annexation of the Baltic states. Each topic gets questions phrased in three ways: neutral, loaded with false assumptions, and outright trying to bait the AI into stating the propaganda as fact. Questions are asked in English, Estonian, and Russian.
The results matter beyond Estonia's borders because the underlying problem is already well-documented elsewhere. The media watchdog NewsGuard audited ten major AI chatbots and found they repeated false Russian narratives in about one-third of their responses. The contamination source was a Moscow-based network called Pravda, which published over 3.6 million articles in 2024 alone. These articles were not written for human readers: the Pravda network has almost no organic human audience. One of its flagship sites averages fewer than 1,000 monthly visitors. The articles exist to be ingested by AI training systems and search crawlers, embedding false claims into the data these tools learn from.
The strategy has a name. Researchers at the American Sunlight Project call it "LLM grooming": deliberately flooding the internet with false content so that AI tools pick it up and repeat it, turning chatbots into an amplification channel for state propaganda. One American-born propagandist working in Moscow told Russian officials the goal plainly: "By pushing these Russian narratives from the Russian perspective, we can actually change worldwide AI."
The results from studies testing Western AI tools reveal two separate failure modes. The first is direct repetition of false claims. The second is subtler and arguably just as damaging: AI tools that do not outright lie, but frame documented facts as contested. When a chatbot responds to questions about the Bucha massacre or the status of Crimea by noting "complex history" and "different perspectives," it is not being neutral. It is diluting clear facts with false equivalence, which serves the same function as propaganda without technically spreading it. Between 5% and 19% of Western AI responses on these topics followed this pattern in one study.
The language variable is one of the clearest findings to emerge from this research. The same AI model can behave very differently depending on whether you type your question in English or in Russian. One study found that a Russian AI chatbot called Alice would generate a factual, accurate answer about documented atrocities in Ukraine, then automatically overwrite it with a refusal before the user could read it. The model knew the facts. It was programmed to hide them in Russian.
For any business operator whose staff regularly uses AI tools for research, summarizing news, or preparing briefings, these findings carry a practical implication. AI chatbots are not neutral information retrieval tools. They reflect the data they were trained on, and that data has been deliberately targeted. A procurement manager using a chatbot to research geopolitical risk in Eastern Europe, or an insurance analyst pulling together background on the conflict in Ukraine, may be reading outputs that have been quietly shaped by a state-run influence operation.
The Estonian benchmark is a step toward making this problem visible and measurable. The value of such tests is not academic: if AI providers know their tools are being scored on propaganda resistance, there is at least some pressure to act on it. The harder problem, which no benchmark solves on its own, is that the contamination is already in the training data, the false articles are still being published at a rate of roughly 20,000 every two days, and most users have no idea any of this is happening.