Defending Information Integrity in the Age of Generative Al: The Problem of Coordinated Manipulation – Insights from VERA.AI

Below is the presentation I gave on June 24, 2026, at the headquarters of the Italian national broadcaster RAI (Radiotelevisione Italiana) during the event “Verification and Fact-Checking: Transforming European Newsrooms for the Al Age”, Rai and CIRCOM International Workshop in Rome (24th and 25th June 2026).

The RAI “Raffaella Carrà” production center in Rome, which hosted the event.

Good afternoon, everyone, and thanks for attending this presentation. A special thanks to the RAI and CIRCOM for hosting and supporting this event.

My name is Nicola Righetti, and I am a researcher and teacher at the University of Urbino, specializing in digital and computational social science methods for the study of online communication. In this presentation, we’ll explore how coordinated behavior shapes online information flows, why detecting it matters, and how we can address its challenges.

In particular, we’ll discuss the Coordinated Sharing Detection Service. This tool is designed to help journalists, verification professionals and disinformation researchers identify and visualize coordinated networks on social media. It builds on CooRTweet (Righetti & Balluff, 2025). The service aims to allow users without technical expertise to run coordinated detection tasks that previously required specialized skills.

Before we dive into the details, here’s a quick overview of today’s outline. We’ll start with a brief introduction to the vera.ai project and the University of Urbino’s contribution to this work. Then, we’ll move into the core concepts: we’ll define what coordinated behavior on social media is, how it connects to problematic information, and discuss its key characteristics. After that, we’ll look at the methods — specifically, how we can detect coordinated behavior in practice. We’ll then explore a variety of real-world examples to show the different forms that coordinated networks can take. We then examine how the introduction of generative AI is transforming coordinated behavior, both by changing how campaigns are conducted and by creating new challenges and opportunities for researchers and platforms seeking to detect them. Finally, we’ll introduce the tool we’ve developed, the Coordinated Sharing Detection Service, and demonstrate how it can help users identify and analyze coordinated activity more easily.

Let me start by briefly introducing the vera.ai project, which frames the work I’m presenting today.

Vera.ai stands for VERification Assisted by Artificial Intelligence, and it is a project funded under the Horizon Europe Framework Program. It has focused on developing AI solutions to counter advanced disinformation techniques, specifically designed for media professionals. What makes vera.ai unique is its strong focus on co-creation: technology experts work directly alongside journalists, researchers, investigators, and other future users to ensure the tools are practical, accessible, and widely usable.

Now let me also say just a few words about the University of Urbino Carlo Bo, where I am working, and our role in the vera.ai project. The University of Urbino is located in the historic city of Urbino, Italy, and was founded in 1506. Today, it is renowned for its excellence in the humanities and social sciences.

Our team, in particular, has a strong track record in network science, media studies, and political communication. Within the vera.ai project, we focused on social media analysis for detecting and understanding the spread of disinformation on digital platforms.

Let’s move into the core concepts of coordinated behavior.

At its core, coordinated behavior is a media manipulation practice. It happens when groups of accounts — which we can think of as networks — coordinate their actions to artificially boost the visibility of certain content. Typically, this involves posting the same or very similar content at the same time to maximize reach and impact.

There are two main assumptions behind this strategy:

  • First, broadcasting — the idea is to maximize the spread of a message by pushing it simultaneously across multiple pages, groups, or profiles. This way, the content reaches a much wider audience quickly.
  • Second, algorithm hacking — by synchronizing posts, these networks can try to trick social media algorithms into perceiving the content as highly popular or trending. As a result, the platforms themselves can further amplify the visibility of the message.

Both mechanisms aim to manipulate the natural flow of information online and can have significant effects on public discourse.

This is an example of coordinated content sharing by a network of Facebook accounts.

The same article link is posted at the exact same second by different accounts, and this simultaneity and identical content strongly suggest centralized control of the network by an individual, group, or organization.

Although coordinated behavior can vary in nature and is not always illegitimate, research has clearly shown that it often serves to spread spam, scams, false or misleading information, and propaganda.

This graph, taken from our past research on coordination during national and European elections in Italy (Giglietto et al., 2020), shows that coordinated Facebook activity shares a higher percentage of problematic domains, such as fake news outlets, than non-coordinated activity.

Coordinated behavior on social media involves two key dimensions: coordination and authenticity. 

  • Coordination refers to the synchronization of messages across multiple accounts, suggesting a deliberate effort to amplify specific narratives. 
  • Authenticity concerns the nature of the accounts involved, as coordinated behavior may include the use of fake, deceptive, or misrepresented accounts. Taken together, these two dimensions define the phenomenon known as “coordinated inauthentic behavior”.

The concept of “coordinated inauthentic behavior” emerged from Meta in 2018 (Gleicher, 2018) to describe organized efforts by networks of accounts to mislead users about their identity and intentions. It refers to groups of accounts coordinating actions to manipulate public debate while concealing their true origins or control.

Social media platforms are increasingly attentive to this issue. Major companies like TikTok, Meta, and X (formerly Twitter) have developed specific policies to detect and counteract coordinated efforts that manipulate public debate. Their focus highlights the importance of maintaining authentic participation in online spaces and preventing the use of fake networks to mislead or distort public discussion.

But why should journalists care about coordinated behavior?

Coordinated behavior is relevant to journalists because it can reveal actors and influence operations that are not immediately visible to the public. Rather than focusing on individual accounts or posts, coordination analysis helps uncover networks working together to amplify messages, shape public narratives, or manipulate online attention.

As one of the core tasks of journalism is to make visible what would otherwise remain hidden and to hold powerful actors accountable, coordinated behavior analysis provides a valuable investigative tool. For investigative reporting, these methods make it possible to trace connections between accounts, organizations, and campaigns, providing evidence about how information spreads and who may be driving it. This is particularly important in areas such as elections, disinformation, foreign influence operations, financial scams, public health misinformation, and coordinated harassment.

More broadly, coordination analysis helps journalists distinguish between genuine public engagement and artificially amplified activity, contributing to more accurate reporting on digital public discourse

Coordinated behavior is relevant to journalism not only because journalists investigate it, but also because journalists and news organizations can themselves become targets of coordinated campaigns. This can take the form of coordinated harassment directed at individual journalists, but also of organized efforts to influence discussions taking place on the social media pages of major news organizations.

News-media comment sections are particularly attractive targets because they provide access to large audiences and are often perceived as spaces where public opinion is expressed. By coordinating comments, amplification strategies, or attacks against journalists, these actors can create misleading impressions of public sentiment, promote specific narratives, discourage participation by other users, and ultimately shape the broader information environment.

A recent report by ORF, the Austrian public broadcaster, to which I had the pleasure of contributing by providing some general insights into coordinated behavior, illustrates this dynamic. By analyzing millions of Instagram comments posted under its news content, ORF uncovered networks of accounts posting highly similar messages in a coordinated manner. The case demonstrates that news organizations are not only observers of coordinated behavior but can also become direct targets of attempts to manipulate public debate.

Now that we have a clearer idea of what coordinated behavior is and why it matters, the next question is: how can we actually detect it?

Our approach to detection is based on network analysis. We start by observing the activity of different social media accounts, often focusing on those related to a controversial topic or an election campaign. In network analysis, each account is represented as a node. visually depicted as a circle, like the ones you see here (Righetti, 2026).

Each account publishes a series of posts, and by analyzing these posts, we can extract elements of interest — that is, the communicative features that could signal coordinated sharing (for instance, links, or pictures).

From there, we build connections between accounts when they share the same content within a time window we define — for example, within one minute.

We then look at whether this behavior happens repeatedly over time and with different pieces of content. This repetition allows us to assess whether the accounts are simply acting by chance or if their behavior shows a statistically significant pattern — a strong indicator of centralized coordination behind the scenes (Giglietto et al., 2020).

Depending on the dataset used (the larger and broader it is, the more likely it becomes to observe forms of coordination), a variety of coordinated networks may emerge, each characterized by the sharing of specific content. 

When we analyze coordinated behavior, we can do so at different levels — both in terms of platforms and modalities.

First, coordination can happen within a single platform, like Facebook or Twitter/X, but it can also occur across multiple platforms. In the networks you see here, nodes from Twitter/X and Facebook are combined, showing how coordination can extend beyond one platform, reinforcing visibility and impact.

Second, coordination can be single-modal or multi-modal. This means we can detect coordination based on one specific type of shared element — such as URLs, hashtags, or images — or by combining several of these modalities. On the right, you can see examples of networks built separately based on URLs, hashtags, domains, and images, while the larger network shows coordination taking into account all modalities together.

Now that we’ve seen how coordination can occur across different platforms and modalities, I’d like to spend a few minutes highlighting the variety of coordinated networks that we can observe when applying computational methods for detecting coordination.

It’s important to understand that not all coordinated networks look the same — their structure, purpose, and transparency can vary widely. This is why it’s crucial for researchers and journalists to be clear about what they are looking for when conducting an analysis, and why computational detection always needs to be accompanied by a careful qualitative inspection and interpretation of the results.

Let’s look at some examples to better illustrate this point.

During our analysis of the 2021 German elections, we encountered a case involving Facebook fan groups supporting the AfD party (Righetti et al., 2022).

Facebook groups are often seen as grassroots spaces, where users can post freely and engage in decentralized communication. However, in this case, we found something different: several groups that were sharing coordinated content were actually administered by the same small set of individuals.

In the graph shown at the right, each administrator of different groups––anonymized here for privacy reasons––is represented by the same color. As you can see, the same individuals appear across multiple groups, explaining the observed coordination.

This case highlights an important ambiguity: although these groups appeared to be grassroots spaces, their communication was in fact centralized and top-down. This raises important questions about astroturfing — that is, the practice of simulating spontaneous popular support for certain ideas or content, when in reality it is orchestrated by a central organization.

This example nicely introduces the element of ambiguity that can emerge when analyzing coordinated behavior on social media.

In fact, a certain level of ambiguity is often strategically useful for those engaging in coordination. It allows them to avoid detection and to reduce the risk of sanctions, bans, or content removal that could result from more blatant violations of platform policies.

In another case, we studied protest networks on Twitter related to the imprisonment of Russian opposition leader Alexey Navalny.

Here, the opposition appeared to be coordinated, with a significant role played by Navalny’s own social media team. However, we also detected coordinated activity among Navalny’s opponents and supporters of the Russian regime, raising important questions about whether this support was genuinely spontaneous or strategically organized (Kulichkina et al., 2025).

This case, shows that coordinated networks can also be employed to suppress protest and dissent (Kulichkina et al., 2026).

An even more striking example of coordinated behavior for political activism comes from the case of the firestorm triggered by pro-Vietnam supporters on the Facebook page of the Chinese embassy in Italy (Righetti, 2025).

The Chinese embassy had published a map including islands disputed by Vietnam. Vietnamese nationalists noticed this and organized a protest in the form of a coordinated bombardment of comments and negative reactions under the embassy’s post.

Even more recently, our team studied a group of Facebook accounts active during the Romanian elections and found that they were working together to share the same posts in a coordinated way. Most of the content they shared was emotional — including sad stories, celebrity gossip, and dramatic news. However, some posts also addressed political topics, strongly promoting far-right ideas and criticizing mainstream political parties and the European Union. This coordinated sharing strategy helps amplify populist and extreme political views more effectively across online platforms.

Coordination characterizes the activity of partisan communities, such as pro-Lula and pro-Bolsonaro groups like in this example (Marino et al., 2024).

And can also share links aimed at promoting cryptocurrency scams and online gambling websites (Terenzi, 2024).

Coordinated behavior has also been adopted in commercial digital marketing. Rather than relying on artists’ own social media accounts to promote music, specialized agencies operate networks of thousands of meme pages, fan pages, sports pages, and other content accounts on platforms such as TikTok. These accounts simultaneously incorporate a song into their content, creating the impression that it is organically trending and widely adopted by users.

Additionally, when a major performance or release occurs, the objective is to rapidly populate comment sections with positive reactions at scale, helping to create social proof and influence how subsequent users interpret the content. The goal is therefore not only to make content go viral, but also to shape the discourse surrounding it.

By coordinating the simultaneous use of a song across these accounts, marketers create the appearance of spontaneous popularity and organic virality, effectively influencing public perceptions of the artist and the content. As one of the company’s founders put it, “everything on the internet is fake.” While the statement is deliberately provocative, it reflects the underlying logic of these practices: many users form their opinions based on comment sections, engagement signals, and what appears to be popular online.

To conclude, as we have seen through these examples, coordinated behavior can take a wide variety of forms — from political activism to astroturfing, from amplifying disinformation to suppressing dissent and promoting music by controlling the online narratives.

There are multiple ways in which attention on social media can be strategically manipulated and manufactured, as we underline in this paper co-authored with Richard Rogers, which has also been developed within the framework of the vera.ai project (Rogers & Righetti, 2025).

It’s important to remember that computational methods like network analysis can detect patterns of coordination and bring potential cases to light, but they do not replace the need for careful qualitative inspection. Researchers, journalists, and fact-checkers must still play a crucial role in analyzing these cases, understanding their context, and assessing their meaning. The combination of computational detection and human interpretation is essential to accurately uncover the dynamics behind coordinated networks online.

What changes in online coordinated behavior phenomena occur with the widespread adoption of generative AI?

Generative AI has transformed the operational capacity of coordinated campaigns. Rather than relying on human operators to manually produce content, actors can now generate large amounts of messages quickly and at minimal cost. This allows coordinated networks to increase both the scale and diversity of their activities while maintaining a consistent strategic narrative.

In this picture, we see the example of coordinated networks promoting online gambling (Giglietto, Terenzi et al., 2026). Before the public release of ChatGPT, these networks generated relatively limited volumes of content, averaging around 2,100 posts per month. Following its launch, however, activity increased dramatically, eventually reaching peaks of more than 10 million posts per month.

The analysis also identifies a structural break in mid-2023, suggesting that this was not simply a gradual increase but a significant shift in the dynamics of these operations. While this evidence does not establish a direct causal relationship, it is consistent with the hypothesis that generative AI substantially reduced the costs and barriers associated with producing and scaling coordinated content campaigns.

At the same time, generative AI creates significant challenges for detection efforts (Giglietto et al., 2025; Giglietto, Graham, Righetti, 2026). Because AI-generated content can closely resemble human-created material, conventional indicators such as duplicate messages become less effective. Coordinated actors can produce numerous variations of the same message, making campaigns appear more authentic and reducing the visibility of coordinated activity.

Generative AI is likely to give rise to entirely new forms of coordinated behavior. Campaigns may increasingly rely on personalized content tailored to specific audiences, while AI-generated personas could interact alongside human operators. The result may be hybrid coordination networks that are more sophisticated and difficult to identify than previous forms of manipulation.

Recent developments in AI offer important opportunities for detecting coordinated behavior. Traditional approaches focused mainly on text, but coordinated campaigns increasingly rely on videos and other multimodal formats. AI systems can now analyze multiple content layers simultaneously—text, images, audio, and video—allowing researchers to identify patterns that would otherwise remain hidden. Emerging visual language models may further strengthen these capabilities in the coming years.

To address these challenges, researchers are developing new AI-based countermeasures. These include watermarking systems designed to identify AI-generated content, classifiers trained to distinguish human and machine-generated material, and embedding-based similarity methods capable of detecting coordinated narratives despite content variations. However, as generative AI continues to evolve, detection systems will require constant refinement to remain effective.

After exploring the variety and complexity of coordinated behavior, it’s time to move from concepts and examples to practice.

Let’s dive in.

There are now several tools available for detecting coordinated networks on social media

Here you see three examples: the Coordination Network Toolkit developed by Graham and colleagues in 2020, the CooRnet package, and the most recent one, CooRTweet, which introduces several important advances (Righetti & Balluff, 2024; 2025). 

However, one limitation is that using CooRTweet involves writing and running code, which can be a barrier for many researchers, journalists, and fact-checkers.

That’s why, within the vera.ai project, and in collaboration with the Athens Technology Center (ATC), we developed the Coordinated Sharing Detection Service (https://coortweet.lab.atc.gr/) — a new tool designed to democratize access to coordinated network detection.

The service makes it easier to run coordination analyses without any coding skills, opening up these methods to a broader range of users who are interested in monitoring and investigating information flows online.

This short video provides a very brief overview of how this tool works. The tool is already fully operational, although still subject to changes to improve its usability. 

Starting from the upload of a CSV file containing the data, the user initiates the analysis, which generates a navigable network and a series of tables providing information about the analyzed accounts and the shared content.

Now, let me briefly guide you through the different sections of the tool.

In the tool’s home page, accessible after logging in (currently without requiring any registration), you will find the information needed to understand the essential concepts of coordinated networks, as well as the key guidelines for using the tool. Among these, the most important is the information regarding the construction of the dataset necessary for the tool to function. The user must provide their own data, which could, for example, have been downloaded from social media platforms using tools and access privileges that these platforms make available to researchers and journalists upon request.

Let’s pause for a moment to focus on the format that the data must have in order to work with the tool.

The data should be provided in CSV format and must include four columns: account_id, content_id, object_id, and timestamp_share.

The account_id column contains a unique identifier for each user or account that shares content. This is typically the user ID or handle provided by the social media platform’s API. 

The content_id column records a unique identifier for each post created by a user, allowing the tool to distinguish between different pieces of content.

The object_id column identifies the specific object being shared, such as a URL, a hashtag, or a full message. This element is essential for detecting coordination, as it highlights when multiple accounts focus on amplifying the same object. 

Finally, the timestamp_share column records the exact moment when the content was shared. This needs to be in UNIX timestamp format (the number of seconds since January 1, 1970), and if the time is recorded differently, it should be converted beforehand to ensure proper analysis.

To make data formatting easier, we have developed a tool that can automatically transform CSV data downloaded from various sources into the standard format required by the detection service. Specifically, it can process data exported from the Meta Content Library, the TikTok Research API, BlueSky (via Communalytic), YouTube Data Tools, and Telegram. This allows users to quickly adapt datasets from different platforms without manually restructuring their files.

Once users have their data ready, they can navigate to the “Network” page, where they simply need to upload a CSV file containing the information they want to analyze.

After uploading the file and setting a few parameters, the tool takes care of the rest.

Once the analysis is complete, the tool returns an interactive visualization of the coordinated network.

Users can explore the network directly, zooming in and out to better understand the structure and the relationships between accounts.

In addition to the graph, the tool also provides tables with detailed information about the accounts involved in the coordinated activity and the specific content they shared.

All of this data — both the network visualization and the tables — can be downloaded for further, more detailed analysis outside the platform, giving users full flexibility to continue their investigation.

The first table provides information at the cluster level, meaning it describes individual groups of accounts that are connected to each other but distinct from other groups.

Through this table, users can identify clusters with a faster average sharing time (which might suggest a bot network), clusters that have shared the highest number of contents, and clusters composed of more or fewer accounts.

The second table provides information at the shared object level, allowing users to sort and analyze objects based on several criteria: the number of coordinated shares for each specific object, the number of social media accounts that shared it, the number of distinct clusters involved, and the average sharing time.

The third table provides information at the account level, allowing users to distinguish accounts based on several features: the average speed at which the account has shared content, the number of distinct objects it has shared in a coordinated way, the number of other accounts it is connected to within the network, and the cluster to which it belongs.

To access the service and start using it, you can either visit this link or scan the first QR code provided. The second QR code links to a sample dataset that you can download and use to try the tool.

References

Giglietto, F., Graham, T., Righetti, N. (2026). Navigating Coordination and Inauthentic behaviour: Challenges and Innovations in Social Media Detection, in Bruns, A. (Editor), Routledge Companion to Social Media and Politics.

Giglietto, Righetti, N., Graham, T. (2025). Manipolazione dei media ed influenza digitale. Sfide, tecnologie e risposte. In Boccia Artieri, G. (ed.), Democrazia ai margini. Disinformazione e manipolazione dell’opinione pubblica digitale, pp. 225-238. Feltrinelli Editore, Milano. ISBN 9788807991059.

Giglietto, F., Righetti, N., Rossi, L., & Marino, G. (2020). It takes a village to manipulate the media: coordinated link sharing behavior during 2018 and 2019 Italian elections. Information, Communication & Society, 23(6), 867-891.

Giglietto, F., Terenzi, M., Chakraborty, A., & Marino, G. (2026). Synthetic seduction: Evolving visual persuasion in coordinated online gambling promotion with generative AI. In Countering Disinformation in the Era of Generative AI (pp. 67-99). Cham: Springer Nature Switzerland.

Gleicher, N. (2018, December 6). Coordinated inauthentic behavior explained. Meta Newsroom. https://about.fb.com/news/2018/12/inside-feed-coordinated-inauthentic-behavior/  

Kulichkina, A., Righetti, N., & Waldherr, A. (2025). Protest and repression on social media: Pro-Navalny and pro-government mobilization dynamics and coordination patterns on Russian Twitter. New Media & Society, 27(9), 5433-5454.

Kulichkina, A., Balluff, P., Righetti, N., & Waldherr, A. (2026). Connective action and digital repression during China’s COVID-19 protests: a computational analysis of multilingual coordinated activity on Twitter. EPJ Data Science.

Marino, G., Paroni, B. A., & Giglietto, F. (2024). THE BRAZILIAN DIGITAL BATTLEFIELD: INVESTIGATING THE DYNAMICS OF POLITICAL INFORMATION CAMPAIGNS IN POST-BOLSONARO ERA. AoIR Selected Papers of Internet Research.

Righetti, N. (2025). The multiple nuances of online firestorms: The case of a Pro-Vietnam attack on the Facebook digital embassy of China in Italy amidst the pandemic. Italian Sociological Review, 15(1), 1-1.

Righetti, N. (2026). Computational methods: tools and techniques for studying communication networks. In Bastos & Rossi (eds.) Handbook of Social and Communication Networks (pp. 215-233). Edward Elgar Publishing.

Righetti, N., & Balluff, P. (2025). CooRTweet: A generalized R software for coordinated network detection. Computational Communication Research7(1), 1.

Righetti, N., & Balluff, P. (2025). CooRTweet: Coordinated networks detection on social media (Version 2.1.2) [R package]. Comprehensive R Archive Network (CRAN).  https://CRAN.R-project.org/package=CooRTweet⁠

Righetti, N., Giglietto, F., Kakavand, A. E., Kulichkina, A., Marino, G., & Terenzi, M. (2022). Political advertisement and coordinated behavior on social media in the lead-up to the 2021 German federal elections. Dusseldorf: Media Authority of North Rhine-Westphalia, 6.

Rogers, R., & Righetti, N. (2025). Coordinated inauthentic behaviour on Facebook? A typology of manufactured attention. Platforms & Society, 2, 29768624251369784.

Terenzi, M. (2024). Modeling Persuasion in Social Media: A Theoretical Approach to Algorithmic Content Distribution and Manipulation. Journal of Sociocybernetics, 19(1).





Scroll to Top