A Fake Candidate Chatbot Ran Freely Until OpenAI Enforced Its Own Rules
What happened
In January 2024, a chatbot appeared at dean.bot, built with ChatGPT and designed to impersonate Dean Phillips, a Minnesota congressman running against Joe Biden for the Democratic presidential nomination. The bot used deepfake technology to simulate Phillips's voice and persona, letting visitors hold what appeared to be a conversation with the candidate himself. Phillips had not authorized it.
The people behind the bot were Matt Krisiloff and Jed Somers, Silicon Valley entrepreneurs who had also created a Super PAC called We Deserve Better to support Phillips's long-shot primary campaign. They built the DeanBot through a developer called Delphi. The stated purpose was to generate enthusiasm for a candidate who lacked the funding and infrastructure to reach voters at scale. The backers positioned it as an innovative campaigning tool rather than an impersonation risk.
OpenAI had policies that made the bot impermissible on two counts. Its developer rules barred use of the platform for political campaigning or lobbying and separately prohibited impersonating real individuals without their consent. The DeanBot violated both. When coverage of the bot appeared in late January 2024, OpenAI banned the account behind it and issued a statement confirming the platform breach. The incident amplified broader concerns about how easily synthetic media tools can be deployed in electoral politics.
The episode exposed a structural problem with how AI platform policies function in practice. The rules were clear on paper. Nothing in the deployment process required the operators to demonstrate that Phillips had consented to being impersonated before the bot went live. The bot ran until reporters noticed it, stories broke, and OpenAI acted. The candidate himself was not consulted first, and the Super PAC's backers did not need his permission to proceed.
That enforcement gap is the more durable lesson here. A policy that activates only after public exposure offers no protection during the window when a deepfake can circulate and shape perception without correction. There is no mechanism described in this incident for verifying, before deployment, that a synthetic representation of a real person carries the authorization it requires. A provable record of what a system did, who approved its release, and whether any consent was on file would have made the violation visible before the bot launched rather than weeks after it had already run.
Reported impact
- Affected parties
- Not publicly disclosed
- Harm type
- Not publicly disclosed
- Scale
- Not publicly disclosed
- Financial impact
- Not publicly disclosed
- Regulatory action
- Not publicly disclosed
Classification
Relevant governance controls
Governance control mapping is not available for this record.
- No controls mapped
Not publicly disclosed
Control mapping is analytical. It does not state that any control would have prevented the incident.
Sources and evidence
This record was researched and written by the Index. The event is also catalogued in the following database, which is listed for cross-reference.