AI Helps Terror Groups Plan, Execute Attacks

Key Takeaways:

A Cambridge study by Antonia Juelich, based on interviews with 27 former Boko Haram and ISWAP members in northeastern Nigeria (last active in 2024), says those groups now use general AI chat tools not only for propaganda but as a routine “problem-solver” for planning and technical questions. She argues earlier assessments understated how systematic that use has become.
The report claims specialized units and internal training, plus help from foreign IS trainers with laptops and accounts. Interviewees described current content filters as inconvenient rather than blocking: rejected queries are retried on other accounts or recast as fictional. Rand’s Steph Guerra separately notes safeguards are split across firms and countries and work better against lone actors than well-resourced groups.
Neither group is reported to have obtained CBRN weapons. Juelich’s policy point is that companies and governments need stronger, coordinated limits as models improve—without treating AI-aided terrorism as a future problem only.

No longer simply a way to produce propaganda, AI has become a key tool for terrorist groups who use it to plan attacks, teach how to build explosives and more.

“You type in the question or use your voice and it [AI] gives you a detailed answer, like ‘How can I build a bomb?’ and then it tells you how. It is like a human robot! We used it a lot,” one former member of Boko Haram told a researcher with the University of Cambridge.

In a recently published study, researcher Antonia Juelich revealed the extent to which Boko Haram and Islamic State West Africa Province use AI tools such as ChatGPT, Grok and DeepSeek for instructions and guidance.

“This AI use is institutionalized through specialized units and internal training,” Juelich wrote. “It has aided in attack planning, weapons troubleshooting, and the design of explosive devices, as users have successfully circumvented some safeguards.”

Juelich based her report on interviews with 27 former Boko Haram and ISWAP members in northeastern Nigeria. The interviewees included mid-level commanders and technical specialists who were last involved with the groups in 2024.

Earlier assessments that terrorists used AI only for producing propaganda underestimated the reality of the situation, according to Juelich.

“Former members describe AI as a go-to problem-solver,” she wrote in her report, titled “‘God has helped us, and so will AI’: How the Terrorist Group Boko Haram Uses Frontier AI.”

When ISWAP terrorists found their attacks stymied by defensive trenches around military bases, commanders turned to AI to find ways of jumping over the trenches with their motorcycles to breach the bases’ defenses.

Former ISWAP members told Juelich that foreign Islamic State group trainers, whom they described as the “white guys,” supplied ISWAP leaders with laptop computers, encrypted internet connections and online accounts. They also trained ISWAP members on how to write AI queries that avoided restrictions on potentially harmful information.

In a separate report, Steph Guerra, a researcher at Rand Corp., noted that AI systems vary in their capacity for blocking the kind of information and instructions terrorists seek.

“Unfortunately, today’s safeguards are fragmented across companies, governments and countries and are not designed to work together,” Guerra wrote in her report, “Building a Defense-in-Depth Biosecurity Strategy for the AI Era.”

“A lone individual with limited resources or technical expertise may be disrupted by cutting off access to key materials and information,” Guerra wrote. “A well-funded group or state program is a harder target and may be more likely to be discouraged by raising the costs of an attack — or the odds of getting caught.”

Ex-Boko Haram and ISWAP fighters told Juelich that current AI restrictions on things such as making bombs are “manageable rather than prohibitive.” Specialized teams understand how to manipulate the AI search to get what they want.

“They say they need it for a movie or something like that,” one interviewee told Juelich.

Should a query trigger a rejection or suspension, terrorists simply try again using another online account.

Although neither Boko Harm nor ISWAP have been able to acquire chemical, biological, radiological or nuclear weapons, the threat is real. Tech companies and governments must increase safeguards as AI models continue to evolve to prevent their use in the planning of mass casualty attacks, Juelich wrote.

“Terrorist adoption of AI has thus advanced further and more systematically than prior analysis has recognized, making it a present and growing reality that warrants attention from policymakers, security communities, and AI developers,” she added.