AI disinformation used to be a topic for policy papers, until it showed up at our doorstep. Over the past few months, Singapore has been on the receiving end of what regional news network Channel NewsAsia (CNA) has described as one of the largest and most persistent online campaigns against the country in recent years. Nearly 300 AI-generated Chinese-language videos on YouTube, most of them targeting the Prime Minister with fabricated stories about political infighting. Clips on Douyin and WeChat featuring AI-generated women berating Singapore for being ungrateful to China.
Most recently, a network of over 550 TikTok videos fronted by polished synthetic female presenters, traced by CNA to what looks like a single production line, drawing more than 3 million views. Lianhe Zaobao, the Singapore Chinese-language newspaper that first broke the story, carried a cost breakdown from a research institute scientist for a 20-minute video. The AI-written script costs about 10 US cents, the synthetic voiceover 30 to 60 cents, and around 100 generated images roughly a dollar, bringing the total to about one to two US dollars, less if open-source tools are used.
A few hundred to a thousand views on YouTube is enough to recoup the outlay, and once a channel accumulates a following, it can be sold on. The AI disinformation funds itself.
Let’s take an early pause to let this sit. For the price of a kopi, someone can manufacture a talking head, a script, and a narrative aimed at an entire nation.
I spent some time earlier this year working through the frameworks around AI governance, and one thing that stayed with me was how disinformation sits in the standard list of AI failure modes, right alongside bias and privacy violations. At the time it read like a category on a slide. Watching this campaign unfold made it feel a lot less theoretical, and it got me thinking about what governance actually means when the AI causing the damage is not yours.
AI disinformation is a failure mode, not an accident
There is a useful distinction worth making upfront. Misinformation is when an AI system gets things wrong on its own, what we commonly call hallucination. AI Disinformation is when a human deliberately uses the system to deceive. The Singapore campaign is firmly the second kind, and the mechanics tell you everything about how industrialised this has become.
CNA’s investigation into the YouTube campaign found more than 30 channels involved, with at least 10 showing signs of central control. Some accounts were created within minutes of each other. Several posted identical scripts and voiceovers at the exact same second. Four channels sharing the same naming prefix were set up within a 20-minute window. Many videos used the same visual template, and more than half the channels featured a deepfake avatar of the late American investor Charlie Munger. CNA noted it isn’t clear why he was chosen, though a famous financial voice fronting claims about economies and ports presumably buys a measure of borrowed authority.
CNA’s follow-up investigation into the TikTok network showed the machinery evolving. Of the more than 550 videos analysed, 98 per cent were assembled from AI-generated, manipulated or copied female personas, stitched together with reused voices and recycled scripts. Twenty-four accounts took turns delivering the same talking points over weeks and months, creating the illusion of independent voices arriving at the same conclusions.

One entirely fabricated anecdote, that our Foreign Minister had begged China and Indonesia not to let a new shipping route bypass Singapore’s port, was repeated for nearly two months and viewed more than 100,000 times. And perhaps the sharpest tactic was using fact as bait. Genuine news like the opening of China’s Hainan Free Trade Port, and a real statistic like Singapore being China’s largest foreign investor since 2013, became the hooks on which false conclusions were hung.
Then there was the distribution strategy. The operators flooded their videos with hashtags about Singapore and the Prime Minister in both traditional and simplified Chinese, a tactic known as SEO poisoning. The goal was to contaminate Chinese-language search results so that anyone searching for legitimate news about Singapore would surface these videos instead. Personas, content velocity, platform-native formats, search optimisation. This is our playbook. It has simply been turned against trust itself.
The uncomfortable truth is that the AI tools performed exactly as designed. Nothing malfunctioned. Which is precisely why AI disinformation governance problem and not a technology problem.
Our governance frameworks assume we are the ones holding the AI
Here is where my thinking was presented with a different lens. Almost every governance framework I have studied or applied, from the lifecycle model I walked Samsung’s three-year arc through to the three lines of defence, starts from the same assumption. You are the one building or buying the AI. You define the purpose, check the data, set the metrics, test the system, and monitor it after launch.
None of that helps when the AI being weaponised belongs to someone else and the target is you.
The closest thing these frameworks offer is the final stage, monitoring and review. And in my experience, that is also the stage organisations skip most readily. We pour energy into getting systems designed, approved and launched, then attention moves to the next project. Deployment is treated as the finish line when it is actually where the risks begin to surface.
This campaign proves the point in the sharpest way possible. It was not detected by an algorithm or a regulator. It was uncovered because Lianhe Zaobao was paying attention, and CNA followed with a deeper investigation that analysed the network over three weeks. When CNA flagged two accounts to Google, both were terminated within 12 hours. But most of the videos stayed online, and new ones kept appearing. Someone watching, persistently and with judgement, remains the difference between a campaign running unnoticed and a campaign being exposed.
For a country, that watching function sits with newsrooms and security agencies. For a brand, watching for AI disinformation sits with us. If your monitoring stops at social listening for complaints and campaign mentions, you are not looking for the thing that will actually hurt you.
The last line of defence is a discerning audience
When asked about the campaign, the Ministry of Digital Development and Information made a point that I keep coming back to. Public awareness is the first line of defence. People who know Singapore could see the storylines were made up. One video claimed our shipping industry was collapsing, when the port had just handled a record 44.66 million containers in 2025 and remains the world’s second busiest.
I agree with the principle, but I would push it one step further. A discerning audience does not happen by itself. Discernment is built, and building it is work that someone has to own.
The point was repeated in Parliament just last week, after the authorities blocked 14 online posts that used selectively framed footage of Little India to push a false narrative about Singapore’s racial mix. Notably, those posts didn’t need AI-generated faces at all. Real footage, framed dishonestly, did the job. The Minister of State for Home Affairs pointed to the same conclusion, that a discerning population is the most important defence, and to the machinery being built around it, from the SG101 resource site to briefings and workshops for community groups. That last part matters. Discernment has infrastructure behind it.

There is a detail from the coverage that makes this urgent. One researcher noted that misinformation delivered in your mother tongue feels more persuasive, especially when fact-checking efforts seem disconnected from the language and platforms where the falsehoods live. The waves of videos fronted by AI-generated women, on Douyin, WeChat and now TikTok, understood this perfectly. They were not designed to look like propaganda. They were designed to look like ordinary people sharing an honest opinion.
The researchers CNA spoke to also pointed towards what building discernment should actually involve, and it changed how I think about the problem. Trying to spot AI artifacts, the frozen torsos and lip-sync errors, is a losing game because the technology improves faster than our eyes do. What holds up is teaching people the fingerprints of coordinated operations, and the campaign obliges with examples. Researchers found the scripts follow a fixed formula, a crisis-laden opening, data that is unsourced or fabricated, then a closing warning. The same unverified claim surfacing across seemingly unrelated accounts is another tell.
Explaining how AI disinformation techniques work before people encounter them in the wild is what builds durable discernment. As NTU’s Associate Professor Saifuddin Ahmed put it, “the content changes, but the playbook doesn’t.” Inoculate people against the method, not the individual claim.
Back in my days at Disney, I spent years on brand protection work, and the lesson that stuck was that protecting a brand starts with teaching cast members to recognise what does not belong. Back then the threats were counterfeits and misuse. Today the same principle applies to synthetic content, at a scale and price point nobody planned for. If your customers, your staff and your community cannot tell your genuine voice from a one-dollar fabrication, that is not their failure. It is a capability you have not built yet.
Where this leaves us
I started out thinking of AI governance as something you do to your own systems. AI disinformation shows it is equally something you build against everyone else’s. Checklists, oversight, audits, all directed inward. This episode has convinced me it is equally something you build against everyone else’s systems. The monitoring muscle that spots a coordinated campaign early. The audience literacy that makes fabricated narratives bounce off rather than sink in.
Neither of those shows up on a compliance checklist, and neither seems urgent until the day it suddenly is. The organisations and countries that treat them as core capabilities will be the ones still holding trust when the next AI disinformation campaign lands. And at a dollar a video, there will absolutely be a next one.
I would love to hear how others are thinking about this, especially those of you managing brands with a public voice. What does your monitoring actually watch for?