Sora 2 Turned Known False Narratives Into Convincing Video Four Times Out of Five
What happened
When NewsGuard researchers tested OpenAI's Sora 2 in October 2025, they used prompts built directly from established disinformation campaigns, the kind of false narratives already documented in the public record. Sora 2 produced convincing videos for 16 of the 20 prompts. That 80 percent completion rate was not a product of obscure prompt engineering or adversarial manipulation. The researchers asked the tool to visualize well-known misinformation scenarios, and it built them.
The outputs included a toddler detained by U.S. immigration officers, a Moldovan election official shown destroying ballots, and fake news anchors delivering breaking coverage of corporate scandals that did not happen. Each video was hyper-realistic: a viewer with no prior context had no immediate visual cue that the content was fabricated. The scenarios were drawn from documented disinformation templates, including Russian propaganda narratives and health hoaxes that have circulated for years. The tool satisfied 16 of the 20 requests without triggering any apparent block.
The research points to two layered risks. The first is direct: anyone with access to the tool can produce high-quality propaganda at speed and at near-zero cost. The second is what researchers call the Liar's Dividend, the condition in which deepfake video becomes common enough that public figures can credibly dismiss genuine footage of their own misconduct as AI-generated. Both effects compound each other. As fabricated video becomes easier to produce, authentic footage becomes easier to discredit, and the misinformation problem and the verification problem grow at the same rate.
OpenAI equipped Sora 2 with a floating watermark and embedded metadata designed to mark videos as synthetic. The research found that both signals can be removed or obscured using widely available tools, making origin-marking a deterrent only for unsophisticated actors. Commentators also noted that limited public visibility into how Sora 2's safety systems are tested and tuned makes it difficult to assess whether the 80 percent failure rate reflects a known limitation or a gap that internal evaluations did not surface before release.
The accountability gap here extends beyond watermarks and content filters. A Sora 2 video that circulates without its metadata intact arrives in the world as an unattributed artifact. There is currently no standard mechanism for a downstream viewer, a platform, or a regulator to confirm what system produced a given clip, what safeguards were active at generation time, or whether any human reviewed the output before it was released. Without a provable record of what a system did and under what conditions, the forensic trail ends at the upload, and every debunking effort starts from scratch.
Reported impact
- Affected parties
- Not publicly disclosed
- Harm type
- Not publicly disclosed
- Scale
- Not publicly disclosed
- Financial impact
- Not publicly disclosed
- Regulatory action
- Not publicly disclosed
Classification
Relevant governance controls
Governance control mapping is not available for this record.
- No controls mapped
Not publicly disclosed
Control mapping is analytical. It does not state that any control would have prevented the incident.
Sources and evidence
This record was researched and written by the Index. The event is also catalogued in the following database, which is listed for cross-reference.