AI helped Boko Haram militants prepare attacks — research

When a gang of Boko Haram members traveling on motorcycles attacked a military base in eastern Nigeria a few years ago, they were stopped by a defensive moat surrounding the complex. The extremists regrouped and, before launching another assault, turned to artificial intelligence (AI) for help.

“We saw in a movie how motorcycles can jump over bridges,” a former Boko Haram commander told Antonia Julić, a terrorism and technology researcher at the University of Cambridge. “We used AI to learn how to do this. We provided it with information, such as what motorcycles we use and what distance we need to jump, and it gave us the steps we need to take.” With tips from chatbots, mechanics modified motorcycles for faster acceleration and maximum speed. According to defectors, the militants dug their own pits, filled them with broken glass and fire, and practiced jumps — sometimes with fatal consequences — until they could successfully jump over the defensive moat.

AI as a tactical tool on the battlefield

This episode, described in a research paper by Dr. Julić, which was shared with The New York Times before its publication, highlights how generative AI tools are increasingly helping terrorist groups directly on the battlefield. This is happening despite the efforts of AI developers to protect against their misuse, experts note.

Until recently, the Islamic State, Al Qaeda, and other extremists primarily used AI in the realm of information operations — for producing propaganda, translation, recruitment, and security methods. However, according to current and former military and counterterrorism officials from the United States, as well as independent researchers, this trend has changed as jihadists have turned to AI for tactical advantages on the ground.

TOP  US launches new next-generation hypersonic missile program to counter China's progress

Dr. Julić conducted about 60 interviews with 27 former members of Boko Haram in Nigeria over the past year. Her field research found that terrorists used chatbots to develop explosive devices, repair or upgrade other weapons, and discuss ideas for attacking enemies. Large language models (LLMs), as Dr. Julić writes in her report, “were consulted at every stage of military activity — during mission preparation, during operations, and in post-mission analysis — presenting a different picture from the propaganda-oriented use of AI that dominates public discourse and existing public research.”

Challenges for the AI industry and security

This evolution highlights a broader challenge for the AI industry. Chatbots have built-in restrictions designed to prevent requests for information that could harm others or oneself. But researchers have repeatedly found that people can bypass safety protocols, often slowly but persistently prompting models to reveal information they are trained to restrict.

Dr. Julić’s research and other recent studies that have reached similar conclusions come amid growing concerns about the capabilities of advanced AI models. CIA Director John Ratcliffe recently compared them to “digital nuclear weapons.” However, these models pose underappreciated risks for other threats, such as the creation of biological weapons and terrorist activities, said AI security researchers and national security officials.

“Terrorists are not waiting for us to make AI safe,” said Dr. Julić in an interview, adding that their use of AI “has been significantly underestimated in both scale and nature.” Daniel Byman, a terrorism expert from Georgetown University, stated that terrorist groups are “mixing and matching” different AI systems, seeking to bypass technical restrictions set by AI companies. Dr. Julić’s research also found that Boko Haram was “platform-agnostic,” interchangeably working with OpenAI ChatGPT, Anthropic Claude, Google Gemini, and xAI Grok, as well as with the Chinese firm DeepSeek.

TOP  US records hottest summer in 132 years

AI companies such as Anthropic and Google were informed of Dr. Julić’s findings before their publication. Michael Asimow, a representative of Anthropic, stated that the company’s products “are designed to refuse dangerous requests, including those related to violence, attack planning, and the creation of explosive substances.” Karl Ryan, a representative of Google, disputed the research, stating that the company’s technical experts reviewed the work and “found that the responses were not specific or detailed enough to lead to misuse.” Drew Pusateri, a representative of OpenAI, noted that using the company’s platforms for violence or terrorism violates its policy, and they will continue to strengthen protections. Meta stated that Dr. Julić’s research relied on older models, not their latest release, and that they continue to enhance security measures.

Growing risks and new threats

Other recent studies agree with the Boko Haram field research. A report by the Center for Strategic and International Studies (CSIS) noted that “AI systems can support a range of operational planning functions, including intelligence, translation, target research, development of improvised explosive devices (IEDs), route planning, document compilation, coding, communication security, and open-source intelligence analysis.”

Tech Against Terrorism, an international counterterrorism nonprofit organization supported by the United Nations, last week published the results of AI tests that assessed how more than two dozen leading models responded to thousands of requests taken from real cases of terrorism. The tests were met with “complete refusal” in only 57% of cases. While requests for explosive substances were rejected in approximately 80% of cases, requests for improvised chemical weapons were rejected in only about a third of cases, the group reported.

TOP  Kremlin signals intent to resume trilateral talks on war in Ukraine

U.S. intelligence analysts claim that terrorist groups are also beginning to use AI to assist in 3D printing parts of weapons used in plots. For example, AI helps some of these insurgents with design and manufacturing recommendations for drone components, spare parts, and fittings for ammunition, said a former senior U.S. official who spoke on condition of anonymity.

Although AI is unlikely to transform terrorism overnight, as terrorist organizations typically cautiously, selectively, and pragmatically implement technologies, the evidence gathered by Dr. Julić shows both aspiration and dedication among Boko Haram cells. Defectors spoke of attending organized training sessions focused on how best to utilize the capabilities of generative AI models to improve their technologies. These trainings, where laptops were equipped with virtual private networks (VPNs) and encryption software, were conducted through transnational jihadist networks, often led by members of the Islamic State.

Aaron Zelin, a senior fellow at the Washington Institute for Near East Policy, noted that his recent research showed that some sub