Submit incident
Documented

A Fake Candidate Chatbot Ran Freely Until OpenAI Enforced Its Own Rules

January 1, 2024
Curated by Team Raidu · Reviewed by Shiva Ganesh
aiaaic:AIAAIC1421View source ↗
LinkedInX

What happened

In January 2024, a chatbot appeared at dean.bot, built with ChatGPT and designed to impersonate Dean Phillips, a Minnesota congressman running against Joe Biden for the Democratic presidential nomination. The bot used deepfake technology to simulate Phillips's voice and persona, letting visitors hold what appeared to be a conversation with the candidate himself. Phillips had not authorized it.

The people behind the bot were Matt Krisiloff and Jed Somers, Silicon Valley entrepreneurs who had also created a Super PAC called We Deserve Better to support Phillips's long-shot primary campaign. They built the DeanBot through a developer called Delphi. The stated purpose was to generate enthusiasm for a candidate who lacked the funding and infrastructure to reach voters at scale. The backers positioned it as an innovative campaigning tool rather than an impersonation risk.

OpenAI had policies that made the bot impermissible on two counts. Its developer rules barred use of the platform for political campaigning or lobbying and separately prohibited impersonating real individuals without their consent. The DeanBot violated both. When coverage of the bot appeared in late January 2024, OpenAI banned the account behind it and issued a statement confirming the platform breach. The incident amplified broader concerns about how easily synthetic media tools can be deployed in electoral politics.

The episode exposed a structural problem with how AI platform policies function in practice. The rules were clear on paper. Nothing in the deployment process required the operators to demonstrate that Phillips had consented to being impersonated before the bot went live. The bot ran until reporters noticed it, stories broke, and OpenAI acted. The candidate himself was not consulted first, and the Super PAC's backers did not need his permission to proceed.

That enforcement gap is the more durable lesson here. A policy that activates only after public exposure offers no protection during the window when a deepfake can circulate and shape perception without correction. There is no mechanism described in this incident for verifying, before deployment, that a synthetic representation of a real person carries the authorization it requires. A provable record of what a system did, who approved its release, and whether any consent was on file would have made the violation visible before the bot launched rather than weeks after it had already run.

Reported impact

Affected parties
Not publicly disclosed
Harm type
Not publicly disclosed
Scale
Not publicly disclosed
Financial impact
Not publicly disclosed
Regulatory action
Not publicly disclosed

Classification

Organization
Not publicly disclosed
AI system
Not publicly disclosed
Industry
Not publicly disclosed
Country
Not publicly disclosed
Provider
Not publicly disclosed
Incident type
Not publicly disclosed

Relevant governance controls

Governance control mapping is not available for this record.

  • No controls mappedNot publicly disclosed

Control mapping is analytical. It does not state that any control would have prevented the incident.

Sources and evidence

This record was researched and written by the Index. The event is also catalogued in the following database, which is listed for cross-reference.

AIAAIC Repository
Also catalogued in
A Fake Candidate Chatbot Ran Freely Until OpenAI Enforced Its Own Rules
2024