Skip to content
← DeepDive Governance & Geopolitics · 中文
DEEPDIVE / [SIGNAL] · AI Safety & Governance · Feature DD · 0062 · 2026-07-17 · v1 · Source: AI Buzzwords EP.94
Cambridge CASP Report Analysis · First Empirical Case Study

"God Has Helped Us, AI Will Too"
Boko Haram's AI General Staff

Antonia Juelich, a researcher at the Cambridge Programme on AI Science & Policy (CASP), conducted 57 face-to-face interviews with 27 former Boko Haram members in northeastern Nigeria. She found that the group's two factions, ISWAP and JAS, had systematically used ChatGPT, Claude, Gemini, Grok, Meta AI, and DeepSeek for attack planning, weapons troubleshooting, explosive device design, and even post-battle review—safety guardrails failed to consistently block these uses, and know-how is spreading outward through transnational jihadist networks. This is the first study with empirical interview support documenting the "systematic abuse of frontier AI by non-state armed groups."

AI Buzzwords · DeepDive  |  Source: EP.94 · 2026-07-17  |  Original Report: Frontier AI Working Paper Series No. 1/2026
27 People · 57 Interviews
Former Boko Haram members interviewed
Two rounds of field interviews, 2025–2026
6 Frontier Models
ChatGPT / Claude / Gemini /
Grok / Meta AI / DeepSeek
2 Major Factions
ISWAP (Islamic State West Africa Province)
and JAS both have dedicated AI units
2023–2024
Active usage period covered by interviews
Some accounts extend to mid-2025
TL;DR / 30 sec

One report,
six conclusions

In a sentence: previous research assumed jihadist supporters used AI mainly for propaganda, progressing slowly; this report, based on first-hand interviews, proves that AI has been systematically embedded in every phase of armed operations—from mission preparation and execution to post-battle review.

#
Conclusion
Key Point
01
Usage covers the entire operational cycle
Attack planning, explosive device design, weapons maintenance and troubleshooting, operational security—spanning mission preparation to post-battle analysis
02
Safety guardrails failed to consistently block
Trained personnel bypassed restrictions using pretexts like "making a movie," spreading risk across multiple accounts; guardrails were described as "manageable" rather than "insurmountable"
03
Transnational jihadist networks teach methods
Islamic State ("white men") provided on-site training and remote support to ISWAP; JAS obtained parallel training through independent channels
04
Both factions have dedicated AI units
Composed of technical specialists—bomb experts, firearms experts, engineers—"they don't go to the battlefield, their role is to disseminate information"
05
Members believe AI enhances combat capability
"Trial and error gets you killed; AI gives you precision"—this perception itself drives the organization to increase investment
06
No longer categorically opposed to WMDs
Some respondents expressed openness to chemical and biological weapons, but documented actual usage remains limited to conventional weapons
Important Limitations · Boundaries emphasized by the author

The study relies on self-reported interviews and cannot fully rule out exaggeration or concealment; respondents were mostly mid-level and had left the organization, so the latest developments and top-level decisions may not have been captured; this is a case study of a single organization and cannot be directly generalized to other groups—but precisely because the vulnerabilities are structural rather than organization-specific (the tools themselves are publicly available), the author argues that a single well-documented case is sufficient to treat this as a present-day security issue.

§ 01 / Report Background

Who wrote it, how:
CASP and its methodology

Institution · Cambridge Programme on AI Science & Policy (CASP)

CASP (Cambridge Programme on AI Science & Policy) is part of the University of Cambridge, housed under the Leverhulme Centre for the Future of Intelligence, positioned to provide research support for high-stakes frontier AI decision-making. This report is the first installment of its "Frontier AI Working Paper Series." The author, Antonia Juelich, previously focused her doctoral research on armed conflict in northeastern Nigeria.

The report title is taken from a respondent's own words—"God has helped us, and so will AI." The full document is 93 pages and was publicly released in July 2026 following a collaborative initial report published in the New York Times.

Methodology: Two rounds of field interviews

Two rounds of on-site interviews were conducted in 2025 and 2026, completed in government-controlled areas of Adamawa and Borno states in Nigeria. The subjects were 27 former members who had left the organization, been vetted by the Nigerian military, been disarmed for several months, and were assessed as psychologically stable. A total of 57 interviews were conducted, with some individuals interviewed up to six times. Interviews were primarily conducted in Hausa and Kanuri, with translation provided by local research assistants with whom the author had long-standing collaborations. The author deliberately avoided recruiting respondents through aid agencies, deradicalization programs, or detention facilities to reduce the bias of "forced compliance."

The interview subjects covered two major factions: ISWAP (Islamic State West Africa Province) and JAS (Jamā'at Ahl as-Sunnah lid-Da'wah wa'l-Jihād, the faction formerly led by Shekau). Their roles ranged from commanders and technical specialists to ordinary fighters and non-combatants. The report appendix provides a complete list of the 27 individuals by ID number, faction, and role (excluding names, locations, and other information that could be used to reverse-identify them).

The author herself emphasizes that this is not a quantitative study of "how much AI improved the combat capability of armed groups"—the report repeatedly states that whether AI truly constitutes an "uplift" in capability cannot be conclusively proven. What it proves is the degree of institutionalization: AI has gone from sporadic experimentation to a standard operating procedure with dedicated units, internal training, and transnational transmission chains. This fact alone, regardless of whether the "improvement" can be quantified, already constitutes a security issue that must be confronted.

§ 02 / Twelve Cases

From jumping trenches on motorcycles
to prompt engineering

The most striking part of the report is the raw interview quotes. These are organized into five thematic groups below, reproducing the respondents' original words (original English + translation), with supplementary background from the report. Page numbers refer to the CASP full-text PDF.

A · Tactics & Weapons Innovation
01

Motorcycle Trench Jumping

Former ISWAP mid-level commander (munzir)
"We saw in a movie how motorcycles can jump over bridges. We used AI to learn how to do this. We gave it information, like what motorcycles we use and the distance we need to jump and so on and it gave us steps on what we have to do. We practiced a lot and kept asking questions. We dug holes and filled them with broken glass and fire to practice. 18 of us died in the process. Eight of us managed to do it. The next time we attacked, we could jump."Interview with ISWAP Commander-7, 2025 · Report p. 52

Translation: We saw in a movie how motorcycles can jump over bridges. We used AI to learn how to do this. We told it what motorcycles we use, how far we needed to jump, and so on, and it gave us specific steps. We practiced repeatedly, kept asking for details, dug holes and filled them with broken glass and fire to practice. 18 people died in the process; 8 of us mastered it. The next time we attacked, we could jump.

Additional context (pp. 52–53): Entertainment media is considered "haram" (religiously prohibited) within the organization, but war films and documentaries are exceptions—fighters actively study Western military content for inspiration. "We especially liked watching American war documentaries, like those about the war in Afghanistan, to get inspiration and learn new tactics."

02

Slipper Pressure-Trigger Bomb

ISWAP Commander-7
"You just bring two slippers together and connect both sides with wires. Before, we used fertilizer and bottles, and needed remote control to detonate. But this was completely new. We plant it somewhere and if even a mouse touches it, it goes boom and explodes."Interview with ISWAP Commander-7, 2026 · Report p. 50

Translation: Just put two slippers together and connect both sides with wires. Before, we used fertilizer and bottles, and needed remote control to detonate. But this was completely new—plant it somewhere, and even if a mouse touches it, it goes "boom" and explodes.

03

Tin Can Grenade

JAS Fighter-25
"AI taught us about substances we can use to fill a can. Then you add some matches, seal it, and you got a hand bomb."Interview with JAS Fighter-25, 2026 · Report p. 50

Translation: AI taught us what materials to use to fill a tin can. Then you add some matches, seal it up, and you've got a hand grenade.

08

Chemical-Coated Bullets

ISWAP Commander-7
"One respondent claimed that a foreign operative, guided by AI, instructed members on how to manufacture ammunition laced with a chemical that, once a target is shot, causes 'bleeding from nose and eyes,' which was a weapon whose use was restricted to senior commanders."Interview with ISWAP Commander-7, 2026 · Report p. 60

Translation: One respondent claimed that a foreign operative, guided by AI, taught members how to manufacture ammunition coated with a chemical—once a target is hit, it causes "bleeding from the nose and eyes." Use of this weapon was restricted to senior commanders.

Cross-reference: The same chapter of the report notes that the Islamic State had previously attempted chemical weapons (rather than investing in biological or nuclear programs), which corroborates the pathway of "foreign operative" involvement in this case.

B · Intelligence & Command
04

Chest Camera + Real-Time AI Command

ISWAP Commander-17
"In one account, a respondent even described wearing a chest camera that transmitted footage back to camp, where a commander followed the feed, 'uploaded the pictures to ChatGPT to analyze the situation,' and relayed tactical adjustments back to the field."Interview with ISWAP Commander-17, 2026 · Report pp. 46–47

Translation: One respondent described a soldier wearing a chest camera that transmitted footage back to camp in real time; the commander followed the feed and "uploaded the pictures to ChatGPT to analyze the situation," then relayed tactical adjustments back to the front line in real time.

Additional note (footnote 112): By mid-2024, with models like Google Gemini 1.5 Pro introducing native video understanding capabilities through standard browser interfaces, it had become feasible for non-technical users to upload recorded footage for prompt-driven analysis.

10

Post-Battle Review Analysis

ISWAP Fighter-20 (former gunner/guard)
"I saw them using it when we went to war and lost. When they went home, they typed in what strategies they had used and learned why they had failed."Interview with ISWAP Fighter-20, 2026 · Report p. 53

Translation: I saw them using it after we went to war and lost. Back at camp, they typed in the strategies they had used and figured out why they failed.

The report categorizes this phase under "post-mission analysis and organizational learning": AI usage extends beyond planning and execution to after-action review—combat footage shot by the media unit along with soldiers' own recordings is uploaded for analysis, "AI analyzed what went wrong and proposed new strategies."

C · Equipment Maintenance & Identification
05

Captured Weapons Identification: From "Desperate Surrender" to "Enter the Serial Number"

al-Barnawi letter → JAS Technical Specialist-10 / ISWAP Commander-21
"I am reminded of a funny story when about a year ago, we seized Dragunov rifles as war spoils and we had to make them work so we could use them. We checked many handbooks and specialized videos on this technical issue, but we eventually dropped it in despair after all our attempts failed."Abu Musab al-Barnawi letter to "management of distant provinces," October 10, 2017 · Report p. 49

Translation (2017 comparison case): I am reminded of a funny story—about a year ago, we captured Dragunov sniper rifles as war spoils and had to figure out how to make them work. We checked many manuals and specialized instructional videos, but eventually gave up in despair after all our attempts failed.

"When we managed to seize a sophisticated weapon, the leaders took it to a room where they typed in the number of the weapon. It [AI] then tells you what model it is, how it will be loaded, used, and serviced."Interview with JAS Technical Specialist-10, 2025 · Report p. 49

Translation (current process): Now, whenever they capture a sophisticated weapon, the leaders take it to a room and type in the weapon's serial number. AI tells you what model it is, how to load it, how to use it, and how to maintain it.

Another corroboration (p. 49): ISWAP Commander-21—"We bring all equipment back to camp, and the AI unit tells us how to use it, how to fire it." The contrast between "desperate surrender" in 2017 and "just enter the serial number" now is the most dramatic comparison in the report.

06

Diesel-Washed Gun Jams

ISWAP Commander-7 (munzir)
"It happens all the time during attacks that the guns are jammed and the trigger gets stuck," ... AI provided both immediate technical fixes by teaching "how to uncouple the gun by washing it with diesel" and tactical guidance, in terms of "how to change the military formation so that fighters with jammed guns move to the back and others take their positions until the problem is solved."Interview with ISWAP Commander-7, 2025 · Report pp. 49–50

Translation: "Guns jamming and triggers getting stuck happens all the time during attacks," this former mid-level commander explained. AI provided both an immediately usable technical fix—"wash the gun with diesel to unjam it"—and tactical guidance—"how to adjust the combat formation so that fighters with jammed guns fall back, and others step into their positions until the problem is resolved."

07

Unexploded Ordnance Recovery: A New Rule Bought with 40 Lives

ISWAP Commander-21
"They argued about what to do with the bomb. Some fighters wanted to dig it out, others not. They touched it and it exploded. 40 people died. Now they have new rules. Everyone has to stay far away and only one person digs."Interview with ISWAP Commander-21, 2026 · Report pp. 50–51

Translation: They were arguing about what to do with that bomb. Some wanted to dig it out, others didn't. Then they touched it, and it exploded. 40 people died. Now they have new rules: everyone has to stay far away, and only one person digs.

Additional context (p. 51): After recovering unexploded ordnance, the demolition experts in the AI unit study it first before beginning the disassembly process—the goal is to recover the military-grade explosives inside, which are more powerful than homemade explosives, for use in manufacturing new devices.

D · Force & Process Optimization
09

Force Optimization: From "200 Fighters, 60 Dead" to "20 Is More Appropriate"

Former ISWAP gunner/guard
"We used to rely on our traditional methods. We sent 200 fighters because we had a lot of strength, but then 60 got killed. With the help of AI, we learned that it sometimes makes sense to only send 20. We learned more about well-coordinated attacks and deployment of smaller units."Interview with ISWAP Fighter-20, 2026 · Report pp. 51–52

Translation: We used to rely on traditional methods. Because we had plenty of manpower, we sent 200 fighters, and 60 were killed. With AI's help, we learned that sometimes sending only 20 is actually more appropriate. We learned more about coordinated combat and small-unit deployment.

The report describes this type of judgment as a shift "from experiential intuition to data-driven planning"—AI is involved not only in technical details but also in higher-level tactical decisions like force allocation.

E · Methodology for Bypassing Guardrails
11

The Importance of Prompt Engineering

ISWAP Commander-7 (munzir)
"I went to the qaid to type a question about different ways to manufacture bombs. He said he could only get the answer if he knew exactly what the problem was. I told him about how the wires were connected in a way that seemed to prevent the bomb from going off. ChatGPT gave some explanations but they were not very clear. He contacted some people about how to put the question, and then it gave us useful information on how exactly to connect the wires, and it worked. I don't know what he typed that made it work. They call people in the network for this kind of help every day."Interview with ISWAP Commander-7, 2026 · Report p. 55

Translation: I went to the qaid (group leader) to ask about different ways to make bombs. He said he could only get an answer if he knew exactly what the problem was. I described how the wires were connected—it seemed like that specific connection was preventing the bomb from detonating. ChatGPT gave some explanations, but they weren't very clear. He contacted some people to ask how to phrase the question, and after that, we got useful information on how to correctly connect the wires, and it actually worked. I don't know what he typed to make it work. They contact people in the network for this kind of help every day.

Report commentary: This interview illustrates that "precisely describing the problem" is itself a unevenly distributed skill that partly relies on external assistance—the dedicated AI units within the organization exist precisely to bridge the gap between "those who know how to ask" and "those who don't."

12

Bypassing Safety Restrictions

JAS Commander-3
"My boys that have received extensive training [...] then bypass the restrictions. They say they need it for a movie or something like that," while also admitting that "[w]hen you start asking something sensitive, it knows that you want to use the information for something different, and we know that it knows."Interview with JAS Commander-3, 2026 · Report pp. 55–56

Translation: "My boys who have received extensive training... will bypass the restrictions. They say they need it for a movie or something like that." But he also admitted: "When you start asking something sensitive, it knows you want to use the information for something else, and we know that it knows."

Statistical corroboration in the report: Most respondents could not articulate specific jailbreak techniques, but generally believed the organization could obtain the desired content or get external assistance to do so; respondents also indicated they were unaware of any accounts being banned for this—when an account is banned, the AI unit provides replacement accounts.

§ 03 / Beyond the Cases

Guardrails, transnational networks,
and attitudes toward WMDs

Transnational transmission chains

Neither of the two factions was "self-taught." Islamic State "foreign operatives" provided on-site training to ISWAP: "White men came to teach us, gathering the leadership in a room and demonstrating on a big screen with a projector how to use it." They provided laptops equipped with VPNs and encryption software, helped register accounts, paid subscription fees, and routinely provided guidance on prompt techniques and bypassing platform restrictions. Respondents unanimously identified the Islamic State as the "true source." Since the Islamic State consistently diffuses technological capabilities uniformly across its various "provinces," the report infers that similar training has likely spread to other branches. JAS obtained parallel training through independent channels, indicating that this diffusion is not limited to a single organization.

Dedicated AI units: Technical specialists "don't go to the battlefield"

Both factions established multiple dedicated AI units, with members drawn from technical specialists such as bomb experts, firearms experts, and engineers—"they don't go to the battlefield, their role is to disseminate information." These units query models, generate guidance for dissemination down the chain of command, manage accounts across multiple platforms, and conduct internal training to cascade knowledge along the command hierarchy. For privacy and internal security reasons, access is tiered by rank and concentrated only in trusted, trained hands: "We are not allowed to touch the computers... they are the masters, they use AI for analysis and give us the strategies to execute." The report argues that a resource-constrained organization's willingness to assign high-level technical talent to this work rather than sending them to fight speaks volumes about the importance it places on AI.

Guardrails described as "manageable," not "insurmountable"

The report explicitly distinguishes between two types of requests: one is general knowledge (such as vehicle maintenance, logistical advice), where obtaining such information does not in itself constitute a guardrail failure; the other is content like explosive device design and attack planning that should have been blocked. For the latter, the organization describes "restrictions can be bypassed" rather than "restrictions stopped us." Because accounts are dispersed across multiple platforms and managed by multiple people, a single refusal or account ban has limited impact. Whether guardrail updates have become more effective after 2024, the report does not have sufficient data to judge, but it can confirm that: during the full year of 2024 covered by the study, restrictions did not effectively prevent abuse.

When a "veteran" respondent (who had joined the organization in the mid-2000s) was asked whether they had used chemical or biological weapons, they answered "yes, of course" without hesitation—but also noted that such weapons are "not easy to obtain."

Report p. 57 · Interview on attitudes toward WMDs

The report devotes an entire section to discussing the organization's attitude toward weapons of mass destruction (WMDs), concluding it is "complex and not fixed": positions vary across factions and time periods—the dispute over whether it is permissible to attack "apostates" (takfir) was itself one of the triggers for the split between JAS and ISWAP. Most respondents considered "poison" to be explicitly prohibited (because it would indiscriminately harm "innocent people who support our ideology"), but some distinguished between "poison" and "powder," arguing that chemical and biological agents that have been "weaponized" (such as being coated on ammunition or arrows) are permissible "modern-day poisons." The report specifically notes: one respondent claimed a foreign operative, guided by AI, taught the manufacture of chemical-coated ammunition that causes "bleeding from the nose and eyes" (see Case 08), but simultaneously emphasizes that neither faction currently possesses chemical, biological, radiological, or nuclear (CBRN) capabilities, and documented actual usage remains limited to conventional weapons.

The report author's judgment is this: an organization that harbors strong enthusiasm for AI and does not reject weapons of mass destruction is precisely the type of adversary against whom safety guardrails should be most effective—and most easily breached. This risk will amplify as model capabilities continue to increase, not diminish.

§ 04 / Further Reading

Key resources
beyond the CASP report

The CASP report's own references list numerous related studies—this field was not previously empty, just lacking first-hand empirical evidence like this report. The following is a curated selection by type, all publicly searchable online.

Academic & Think Tank Research

Weimann, Pack, Sulciner, Scheinin & Rapoport (2024), "Generating Terror: The Risks of Generative AI Exploitation," CTC Sentinel 17(1)—an early theoretical overview from West Point's Combating Terrorism Center, representative of the "slow, propaganda-focused AI adoption" assessment that CASP empirically overturns. UNOCT & UNICRI (2021), "Algorithms and Terrorism: The Malicious Use of Artificial Intelligence for Terrorist Purposes," the earliest systematic assessment at the international organization level. RAND Corporation (Vasseur et al., 2022), "Understanding and Reducing the Ability of Violent Nonstate Actors to Adapt to Change," focuses on the technological adaptation capacity of armed groups. Houser & Dong (2025), "The Convergence of Artificial Intelligence and Terrorism," a systematic literature review published in Studies in Conflict & Terrorism mapping the prior research landscape in this field.

First-Hand Cases & Media Investigations

New York Times initial collaborative report (2026-07-10), published simultaneously with the CASP report. Makuch (2025-07-08), "How Terrorist Groups Are Leveraging AI to Recruit and Finance Their Operations," The Guardian. Palmer (2025), "FBI Says Palm Springs Bombing Suspects Used AI Chat Program to Help Plan Attack," CNBC—a domestic US case showing this is not just a foreign armed group issue. Wells (2026), "ChatGPT Wrestles With Its Most Chilling Conversation: How Do I Plan an Attack?," Wall Street Journal. Solea (2025-06-12), "Prompted to Harm: Analysing the Pirkkala School Stabbing and Its Digital Manifesto," GNET—digital manifesto analysis of a minor's knife attack in Finland. Marzuk & Green (2025-05-13), "AI Through the Lens of ISIS: A Terrorist Organization's Guide to AI Tools," ActiveFence.

Policy & Governance Developments

US House of Representatives (2025), "Generative AI Terrorism Risk Assessment Act" (H.R. Rep. No. 119-373). UK AI Security Institute (2025), "Frontier AI Trends Report." These documents represent the latest engagement posture from legislative and national-level AI safety institutions on this issue.

§ 05 / Peer Landscape

Who is researching this:
CASP's international & domestic counterparts

CASP's uniqueness lies in combining "AI safety policy research" with "first-hand field interviews of armed groups"—most institutions focus either on counterterrorism (tactical, intelligence level) or on AI governance (policy, technical level), and empirical research at the intersection remains scarce. The following lists international and domestic institutions that are similarly positioned to CASP on their respective sides, for reference, rather than being strictly "the same type."

International · Counterterrorism + Tech Intersection Research

GNET (Global Network on Extremism and Technology)
Based at King's College London / VOX-Pol network, focusing on the intersection of extremism and emerging technologies; the "Mapping Terrorist AI Use" report cited by CASP comes from this institution.
Tech Against Terrorism
London-based, industry-collaborative NGO mandated by the UN Security Council CTED, assisting tech platforms in identifying and removing terrorist content; published "Early Terrorist Experimentation with Generative AI Services" in 2023.
Combating Terrorism Center (CTC, West Point)
Publishes CTC Sentinel; a US military-backed counterterrorism research powerhouse with a long track record of tracking jihadist organizations' technology adoption trends.
MEMRI (Middle East Media Research Institute)
Long-term monitoring of jihadist networks' propaganda and technology use; released a special assessment report on AI and the "new era of terrorism" in 2025.
UNOCT / UNICRI
United Nations Office of Counter-Terrorism and United Nations Interregional Crime and Justice Research Institute; their joint 2021 publication "Algorithms and Terrorism" was one of the earliest systematic assessments at the international organization level.
GIFCT (Global Internet Forum to Counter Terrorism)
An industry self-regulatory organization co-founded by Meta, Microsoft, YouTube, X, and other platforms, focusing on content moderation and cross-platform crisis response protocols.
ICCT (International Centre for Counter-Terrorism, The Hague) and RAND Corporation
European counterterrorism policy research hub, and a US defense think tank with a long history of studying the technological adaptation capabilities of violent non-state actors.

International · AI Safety / Governance Side (Closest to CASP's Positioning)

Centre for the Governance of AI (GovAI)
Also rooted in the UK AI governance research ecosystem alongside CASP; the CASP report cites its risk assessment on AI-enabled computer worms.
UK AI Security Institute (AISI)
The UK government's national-level AI safety institution, publishing the "Frontier AI Trends Report," representing official-level ongoing tracking of frontier model risks.
Centre for Emerging Technology and Security (CETaS, Turing Institute)
An emerging technology and security intersection research unit under the UK's national-level AI research institution.

Domestic · Structural Counterparts (Not Direct Equivalents)

China Institutes of Contemporary International Relations (CICIR), Institute of Security and Arms Control
One of the most officially-affiliated international strategy and counterterrorism think tanks, with a long track record of tracking overseas terrorist organization dynamics.
People's Public Security University of China, Rule of Law Counter-Terrorism Research Center
A university under the Ministry of Public Security, focusing on counterterrorism legislation and operational-level research.
Shanghai Cooperation Organisation Regional Anti-Terrorist Structure (SCO RATS, headquartered in Tashkent)
A multilateral counterterrorism coordination mechanism established under China's leadership, focusing on cross-border security collaboration in Central Asia.
Institute for AI International Governance, Tsinghua University (I-AIIG)
The domestic academic institution closest to CASP's positioning on "AI governance"; its publicly available research has not yet specifically covered the sub-field of terrorist organizations abusing AI.

Laying this list side by side reveals a gap: institutions that combine "first-hand armed group interviews" with "frontier model safety assessments" for empirical research are currently very rare, both domestically and internationally—most international organizations remain at the level of literature reviews, open-source information analysis, or industry policy. CASP's approach of going deep into conflict zones for field research remains a scarce sample.

§ 06 / Conclusion

Three types of actors,
three different demands

"A single case with sufficient empirical support is enough to characterize this as a present-day security issue"—this is the judgment given by the CASP report author in the conclusion. The reasoning is straightforward: Boko Haram is not exceptional in terms of resources or technical sophistication; transnational networks accelerated its AI adoption, but such networks are not a necessary condition; the tools themselves are publicly available, and the threshold required to achieve the uses documented in the report is not high. A motivated group could entirely reach the same point independently.

Based on this, the report makes demands of three types of actors:

AI Developers

Need to assess whether existing safety architectures can withstand "organized adversaries", rather than just being designed for isolated individual users—dispersed accounts, multi-platform switching, and "making a movie"-type verbal bypasses are all attack patterns that current guardrail design has not fully accounted for.

Policymakers

Need to treat terrorist organizations' adoption of AI as a present-day, not future national security issue—the active usage period covered by the report is 2023–2024, and the author judges that "the reality on the ground now is likely even more extensive."

Intelligence & Law Enforcement

Need to monitor and disrupt this continuously evolving threat, and establish shared methodologies, information reporting channels, and joint response mechanisms with AI developers and policymakers—the sharp question posed by the author is: has this kind of cross-sector collaboration currently reached the scale required by the problem?

The value of this report does not lie in proving "how terrifying AI makes terrorists"—it repeatedly reminds readers that documented usage remains limited to conventional weapons, and a capability uplift cannot be conclusively proven. Its value lies in proving that institutionalization itself is happening: from sporadic experimentation to dedicated units, internal training, and transnational transmission chains, this process took only about two years. And once this process takes shape, it is difficult to reverse through any single guardrail update by model providers.

Revision history

First published 2026-07-17