Antonia Juelich, a researcher at the Cambridge Programme on AI Science & Policy (CASP), conducted 57 face-to-face interviews with 27 former Boko Haram members in northeastern Nigeria. She found that the group's two factions, ISWAP and JAS, had systematically used ChatGPT, Claude, Gemini, Grok, Meta AI, and DeepSeek for attack planning, weapons troubleshooting, explosive device design, and even post-battle review—safety guardrails failed to consistently block these uses, and know-how is spreading outward through transnational jihadist networks. This is the first study with empirical interview support documenting the "systematic abuse of frontier AI by non-state armed groups."
In a sentence: previous research assumed jihadist supporters used AI mainly for propaganda, progressing slowly; this report, based on first-hand interviews, proves that AI has been systematically embedded in every phase of armed operations—from mission preparation and execution to post-battle review.
The study relies on self-reported interviews and cannot fully rule out exaggeration or concealment; respondents were mostly mid-level and had left the organization, so the latest developments and top-level decisions may not have been captured; this is a case study of a single organization and cannot be directly generalized to other groups—but precisely because the vulnerabilities are structural rather than organization-specific (the tools themselves are publicly available), the author argues that a single well-documented case is sufficient to treat this as a present-day security issue.
CASP (Cambridge Programme on AI Science & Policy) is part of the University of Cambridge, housed under the Leverhulme Centre for the Future of Intelligence, positioned to provide research support for high-stakes frontier AI decision-making. This report is the first installment of its "Frontier AI Working Paper Series." The author, Antonia Juelich, previously focused her doctoral research on armed conflict in northeastern Nigeria.
The report title is taken from a respondent's own words—"God has helped us, and so will AI." The full document is 93 pages and was publicly released in July 2026 following a collaborative initial report published in the New York Times.
Two rounds of on-site interviews were conducted in 2025 and 2026, completed in government-controlled areas of Adamawa and Borno states in Nigeria. The subjects were 27 former members who had left the organization, been vetted by the Nigerian military, been disarmed for several months, and were assessed as psychologically stable. A total of 57 interviews were conducted, with some individuals interviewed up to six times. Interviews were primarily conducted in Hausa and Kanuri, with translation provided by local research assistants with whom the author had long-standing collaborations. The author deliberately avoided recruiting respondents through aid agencies, deradicalization programs, or detention facilities to reduce the bias of "forced compliance."
The interview subjects covered two major factions: ISWAP (Islamic State West Africa Province) and JAS (Jamā'at Ahl as-Sunnah lid-Da'wah wa'l-Jihād, the faction formerly led by Shekau). Their roles ranged from commanders and technical specialists to ordinary fighters and non-combatants. The report appendix provides a complete list of the 27 individuals by ID number, faction, and role (excluding names, locations, and other information that could be used to reverse-identify them).
The author herself emphasizes that this is not a quantitative study of "how much AI improved the combat capability of armed groups"—the report repeatedly states that whether AI truly constitutes an "uplift" in capability cannot be conclusively proven. What it proves is the degree of institutionalization: AI has gone from sporadic experimentation to a standard operating procedure with dedicated units, internal training, and transnational transmission chains. This fact alone, regardless of whether the "improvement" can be quantified, already constitutes a security issue that must be confronted.
The most striking part of the report is the raw interview quotes. These are organized into five thematic groups below, reproducing the respondents' original words (original English + translation), with supplementary background from the report. Page numbers refer to the CASP full-text PDF.
Translation: We saw in a movie how motorcycles can jump over bridges. We used AI to learn how to do this. We told it what motorcycles we use, how far we needed to jump, and so on, and it gave us specific steps. We practiced repeatedly, kept asking for details, dug holes and filled them with broken glass and fire to practice. 18 people died in the process; 8 of us mastered it. The next time we attacked, we could jump.
Additional context (pp. 52–53): Entertainment media is considered "haram" (religiously prohibited) within the organization, but war films and documentaries are exceptions—fighters actively study Western military content for inspiration. "We especially liked watching American war documentaries, like those about the war in Afghanistan, to get inspiration and learn new tactics."
Translation: Just put two slippers together and connect both sides with wires. Before, we used fertilizer and bottles, and needed remote control to detonate. But this was completely new—plant it somewhere, and even if a mouse touches it, it goes "boom" and explodes.
Translation: AI taught us what materials to use to fill a tin can. Then you add some matches, seal it up, and you've got a hand grenade.
Translation: One respondent claimed that a foreign operative, guided by AI, taught members how to manufacture ammunition coated with a chemical—once a target is hit, it causes "bleeding from the nose and eyes." Use of this weapon was restricted to senior commanders.
Cross-reference: The same chapter of the report notes that the Islamic State had previously attempted chemical weapons (rather than investing in biological or nuclear programs), which corroborates the pathway of "foreign operative" involvement in this case.
Translation: One respondent described a soldier wearing a chest camera that transmitted footage back to camp in real time; the commander followed the feed and "uploaded the pictures to ChatGPT to analyze the situation," then relayed tactical adjustments back to the front line in real time.
Additional note (footnote 112): By mid-2024, with models like Google Gemini 1.5 Pro introducing native video understanding capabilities through standard browser interfaces, it had become feasible for non-technical users to upload recorded footage for prompt-driven analysis.
Translation: I saw them using it after we went to war and lost. Back at camp, they typed in the strategies they had used and figured out why they failed.
The report categorizes this phase under "post-mission analysis and organizational learning": AI usage extends beyond planning and execution to after-action review—combat footage shot by the media unit along with soldiers' own recordings is uploaded for analysis, "AI analyzed what went wrong and proposed new strategies."
Translation (2017 comparison case): I am reminded of a funny story—about a year ago, we captured Dragunov sniper rifles as war spoils and had to figure out how to make them work. We checked many manuals and specialized instructional videos, but eventually gave up in despair after all our attempts failed.
Translation (current process): Now, whenever they capture a sophisticated weapon, the leaders take it to a room and type in the weapon's serial number. AI tells you what model it is, how to load it, how to use it, and how to maintain it.
Another corroboration (p. 49): ISWAP Commander-21—"We bring all equipment back to camp, and the AI unit tells us how to use it, how to fire it." The contrast between "desperate surrender" in 2017 and "just enter the serial number" now is the most dramatic comparison in the report.
Translation: "Guns jamming and triggers getting stuck happens all the time during attacks," this former mid-level commander explained. AI provided both an immediately usable technical fix—"wash the gun with diesel to unjam it"—and tactical guidance—"how to adjust the combat formation so that fighters with jammed guns fall back, and others step into their positions until the problem is resolved."
Translation: They were arguing about what to do with that bomb. Some wanted to dig it out, others didn't. Then they touched it, and it exploded. 40 people died. Now they have new rules: everyone has to stay far away, and only one person digs.
Additional context (p. 51): After recovering unexploded ordnance, the demolition experts in the AI unit study it first before beginning the disassembly process—the goal is to recover the military-grade explosives inside, which are more powerful than homemade explosives, for use in manufacturing new devices.
Translation: We used to rely on traditional methods. Because we had plenty of manpower, we sent 200 fighters, and 60 were killed. With AI's help, we learned that sometimes sending only 20 is actually more appropriate. We learned more about coordinated combat and small-unit deployment.
The report describes this type of judgment as a shift "from experiential intuition to data-driven planning"—AI is involved not only in technical details but also in higher-level tactical decisions like force allocation.
Translation: I went to the qaid (group leader) to ask about different ways to make bombs. He said he could only get an answer if he knew exactly what the problem was. I described how the wires were connected—it seemed like that specific connection was preventing the bomb from detonating. ChatGPT gave some explanations, but they weren't very clear. He contacted some people to ask how to phrase the question, and after that, we got useful information on how to correctly connect the wires, and it actually worked. I don't know what he typed to make it work. They contact people in the network for this kind of help every day.
Report commentary: This interview illustrates that "precisely describing the problem" is itself a unevenly distributed skill that partly relies on external assistance—the dedicated AI units within the organization exist precisely to bridge the gap between "those who know how to ask" and "those who don't."
Translation: "My boys who have received extensive training... will bypass the restrictions. They say they need it for a movie or something like that." But he also admitted: "When you start asking something sensitive, it knows you want to use the information for something else, and we know that it knows."
Statistical corroboration in the report: Most respondents could not articulate specific jailbreak techniques, but generally believed the organization could obtain the desired content or get external assistance to do so; respondents also indicated they were unaware of any accounts being banned for this—when an account is banned, the AI unit provides replacement accounts.
Neither of the two factions was "self-taught." Islamic State "foreign operatives" provided on-site training to ISWAP: "White men came to teach us, gathering the leadership in a room and demonstrating on a big screen with a projector how to use it." They provided laptops equipped with VPNs and encryption software, helped register accounts, paid subscription fees, and routinely provided guidance on prompt techniques and bypassing platform restrictions. Respondents unanimously identified the Islamic State as the "true source." Since the Islamic State consistently diffuses technological capabilities uniformly across its various "provinces," the report infers that similar training has likely spread to other branches. JAS obtained parallel training through independent channels, indicating that this diffusion is not limited to a single organization.
Both factions established multiple dedicated AI units, with members drawn from technical specialists such as bomb experts, firearms experts, and engineers—"they don't go to the battlefield, their role is to disseminate information." These units query models, generate guidance for dissemination down the chain of command, manage accounts across multiple platforms, and conduct internal training to cascade knowledge along the command hierarchy. For privacy and internal security reasons, access is tiered by rank and concentrated only in trusted, trained hands: "We are not allowed to touch the computers... they are the masters, they use AI for analysis and give us the strategies to execute." The report argues that a resource-constrained organization's willingness to assign high-level technical talent to this work rather than sending them to fight speaks volumes about the importance it places on AI.
The report explicitly distinguishes between two types of requests: one is general knowledge (such as vehicle maintenance, logistical advice), where obtaining such information does not in itself constitute a guardrail failure; the other is content like explosive device design and attack planning that should have been blocked. For the latter, the organization describes "restrictions can be bypassed" rather than "restrictions stopped us." Because accounts are dispersed across multiple platforms and managed by multiple people, a single refusal or account ban has limited impact. Whether guardrail updates have become more effective after 2024, the report does not have sufficient data to judge, but it can confirm that: during the full year of 2024 covered by the study, restrictions did not effectively prevent abuse.
When a "veteran" respondent (who had joined the organization in the mid-2000s) was asked whether they had used chemical or biological weapons, they answered "yes, of course" without hesitation—but also noted that such weapons are "not easy to obtain."
Report p. 57 · Interview on attitudes toward WMDs
The report devotes an entire section to discussing the organization's attitude toward weapons of mass destruction (WMDs), concluding it is "complex and not fixed": positions vary across factions and time periods—the dispute over whether it is permissible to attack "apostates" (takfir) was itself one of the triggers for the split between JAS and ISWAP. Most respondents considered "poison" to be explicitly prohibited (because it would indiscriminately harm "innocent people who support our ideology"), but some distinguished between "poison" and "powder," arguing that chemical and biological agents that have been "weaponized" (such as being coated on ammunition or arrows) are permissible "modern-day poisons." The report specifically notes: one respondent claimed a foreign operative, guided by AI, taught the manufacture of chemical-coated ammunition that causes "bleeding from the nose and eyes" (see Case 08), but simultaneously emphasizes that neither faction currently possesses chemical, biological, radiological, or nuclear (CBRN) capabilities, and documented actual usage remains limited to conventional weapons.
The report author's judgment is this: an organization that harbors strong enthusiasm for AI and does not reject weapons of mass destruction is precisely the type of adversary against whom safety guardrails should be most effective—and most easily breached. This risk will amplify as model capabilities continue to increase, not diminish.
The CASP report's own references list numerous related studies—this field was not previously empty, just lacking first-hand empirical evidence like this report. The following is a curated selection by type, all publicly searchable online.
Weimann, Pack, Sulciner, Scheinin & Rapoport (2024), "Generating Terror: The Risks of Generative AI Exploitation," CTC Sentinel 17(1)—an early theoretical overview from West Point's Combating Terrorism Center, representative of the "slow, propaganda-focused AI adoption" assessment that CASP empirically overturns. UNOCT & UNICRI (2021), "Algorithms and Terrorism: The Malicious Use of Artificial Intelligence for Terrorist Purposes," the earliest systematic assessment at the international organization level. RAND Corporation (Vasseur et al., 2022), "Understanding and Reducing the Ability of Violent Nonstate Actors to Adapt to Change," focuses on the technological adaptation capacity of armed groups. Houser & Dong (2025), "The Convergence of Artificial Intelligence and Terrorism," a systematic literature review published in Studies in Conflict & Terrorism mapping the prior research landscape in this field.
New York Times initial collaborative report (2026-07-10), published simultaneously with the CASP report. Makuch (2025-07-08), "How Terrorist Groups Are Leveraging AI to Recruit and Finance Their Operations," The Guardian. Palmer (2025), "FBI Says Palm Springs Bombing Suspects Used AI Chat Program to Help Plan Attack," CNBC—a domestic US case showing this is not just a foreign armed group issue. Wells (2026), "ChatGPT Wrestles With Its Most Chilling Conversation: How Do I Plan an Attack?," Wall Street Journal. Solea (2025-06-12), "Prompted to Harm: Analysing the Pirkkala School Stabbing and Its Digital Manifesto," GNET—digital manifesto analysis of a minor's knife attack in Finland. Marzuk & Green (2025-05-13), "AI Through the Lens of ISIS: A Terrorist Organization's Guide to AI Tools," ActiveFence.
US House of Representatives (2025), "Generative AI Terrorism Risk Assessment Act" (H.R. Rep. No. 119-373). UK AI Security Institute (2025), "Frontier AI Trends Report." These documents represent the latest engagement posture from legislative and national-level AI safety institutions on this issue.
CASP's uniqueness lies in combining "AI safety policy research" with "first-hand field interviews of armed groups"—most institutions focus either on counterterrorism (tactical, intelligence level) or on AI governance (policy, technical level), and empirical research at the intersection remains scarce. The following lists international and domestic institutions that are similarly positioned to CASP on their respective sides, for reference, rather than being strictly "the same type."
Laying this list side by side reveals a gap: institutions that combine "first-hand armed group interviews" with "frontier model safety assessments" for empirical research are currently very rare, both domestically and internationally—most international organizations remain at the level of literature reviews, open-source information analysis, or industry policy. CASP's approach of going deep into conflict zones for field research remains a scarce sample.
"A single case with sufficient empirical support is enough to characterize this as a present-day security issue"—this is the judgment given by the CASP report author in the conclusion. The reasoning is straightforward: Boko Haram is not exceptional in terms of resources or technical sophistication; transnational networks accelerated its AI adoption, but such networks are not a necessary condition; the tools themselves are publicly available, and the threshold required to achieve the uses documented in the report is not high. A motivated group could entirely reach the same point independently.
Based on this, the report makes demands of three types of actors:
Need to assess whether existing safety architectures can withstand "organized adversaries", rather than just being designed for isolated individual users—dispersed accounts, multi-platform switching, and "making a movie"-type verbal bypasses are all attack patterns that current guardrail design has not fully accounted for.
Need to treat terrorist organizations' adoption of AI as a present-day, not future national security issue—the active usage period covered by the report is 2023–2024, and the author judges that "the reality on the ground now is likely even more extensive."
Need to monitor and disrupt this continuously evolving threat, and establish shared methodologies, information reporting channels, and joint response mechanisms with AI developers and policymakers—the sharp question posed by the author is: has this kind of cross-sector collaboration currently reached the scale required by the problem?
The value of this report does not lie in proving "how terrifying AI makes terrorists"—it repeatedly reminds readers that documented usage remains limited to conventional weapons, and a capability uplift cannot be conclusively proven. Its value lies in proving that institutionalization itself is happening: from sporadic experimentation to dedicated units, internal training, and transnational transmission chains, this process took only about two years. And once this process takes shape, it is difficult to reverse through any single guardrail update by model providers.
First published 2026-07-17