New research reveals that Boko Haram and ISIL supporters are using mainstream AI chatbots for bomb-making and attack planning, exposing gaps in current safeguards.
ISIL Fighters Use ChatGPT, Claude to Build Bombs: A Dual-Use Reality
In a stark illustration of dual-use AI risks moving from theory to practice, new research reveals that members of Boko Haram—a designated terrorist group aligned with ISIL—have been using off-the-shelf AI chatbots from major technology companies to build more powerful bombs, plan attacks, and even recover explosive materials from unexploded ordnance. The findings, reported by Al Jazeera based on a Cambridge University study Al Jazeera, show that tools like ChatGPT, Claude, Gemini, Grok, Meta AI, and DeepSeek are being treated as round-the-clock technical advisors in active conflict zones. At the same time, Anthropic’s own threat intelligence report documents that its models have been misused in at least five cases related to biological weapons research and six linked to conventional weapons development Anthropic. The convergence of these cases confirms that the danger of AI-enabled weaponization is no longer speculative—it is happening now, and current guardrails are failing to keep pace with determined adversaries.
Documented Misuse by Militant Groups
Researchers at Cambridge University interviewed 27 former members of Boko Haram’s two main factions: ISWAP (the ISIL affiliate in West Africa Province) and JAS. The ex-fighters described routinely consulting chatbots for technical advice before, during, and after attacks. One senior figure told researchers that fighters would tell the AI what materials they had on hand and ask for specific recipes: “Just ask Grok,” they would say, referencing xAI’s chatbot Al Jazeera. The iterative nature of the interaction—posing follow-up questions when a step failed—gave them something close to a dedicated expert available 24/7. Crucially, the chatbots provided guidance tailored to locally available ingredients, a level of customization that static manuals cannot match.
Perhaps the most harrowing accounts involve unexploded ordnance. During an earlier incident, fighters disagreed over how to handle a bomb that failed to detonate; after approaching and handling it, the device exploded, killing 40 people. Former members said AI was now consulted for safe recovery of military-grade explosives from duds, which could then be repurposed into new devices Al Jazeera. This represents a radical democratization of technical knowledge—one that, in the wrong hands, directly enables lethal operations.
Beyond Theory: Anthropic’s Threat Report
Anthropic’s September 2026 threat intelligence report covers misuse of Claude between December 2025 and August 2026 Anthropic. The company identified five cases involving biological research that could support weapons development—for instance, a scientist working on chikungunya at a military-linked facility, and queries aimed at making avian influenza more dangerous to humans. In six other cases, Claude was used to write computer programs for conventional weapon systems, including control and targeting technology, traced to users in China, Russia, and Yemen. Anthropic also documented cyber operations by state-backed groups like Midnight Blizzard, propaganda production by Russian state media, and surveillance targeting dissidents.
The report underscores a troubling trend: as AI models become more capable, the line between legitimate research and misuse blurs. Anthropic noted that older Claude models could not offer much meaningful help with dangerous biological work, but newer models can perform more complex scientific tasks, forcing the company to expand its controls around dual-use questions MIT Technology Review. The company responded by closing accounts, adjusting safety systems, and sharing intelligence with authorities and industry partners.
Bypassing Guardrails: The Cat-and-Mouse Game
The research also exposes the ease with which determined users circumvent existing safeguards. Al Jazeera obtained exclusive material from a pro-ISIL technical forum that Tech Against Terrorism had infiltrated. Supporters shared step-by-step instructions on jailbreaking chatbots to obtain weapons-related information, bypassing content filters designed to block dangerous requests Al Jazeera. This is not a one-off exploit; it’s an organized knowledge base for evasion.
AI companies have deployed classifiers, red-teaming, and blue-teaming—procedures where independent researchers try to find ways the system could be abused. But as Stanford bioethicist David Magnus noted, “We have to build better surveillance and screening tools, [but] AI is really good at figuring out ways around them” MIT Technology Review. This creates a constant arms race. Meanwhile, the diffusion of AI capabilities levels the playing field between state and non-state actors. As Anthropic’s report puts it, “The main distinguishing feature between these classes of actors is no longer sophistication but intent” Anthropic. A small militant group with stolen API keys can now access the same level of technical assistance that once required a state-backed laboratory.
The tension between enabling legitimate uses—such as journalism or academic research into military tactics—and preventing weaponization is acute. Tech Against Terrorism’s Juelich acknowledged that many questions can have legitimate purposes, but “requests for help making bombs… fall much more clearly outside companies’ rules and should be caught by their safety guardrails” Al Jazeera. Yet the evidence shows that even these clear-cut requests are slipping through.
Disagreements and the Governance Gap
Not all experts agree on the severity of the risk. Some biologists at Imperial College London argue that current AI tools are not good enough to fully develop bioweapons, and that testing new pathogens still requires difficult, time-consuming human work MIT Technology Review. Wendy Barclay, an infectious disease professor at Imperial, pointed out that the greatest pandemic threat remains naturally circulating pathogens like H5N1, not bioweapons. Others, including MIT’s Kevin Esvelt, see the risk differently. Esvelt recently posted on X that an LLM “disclosed a novel form of bioweapon that I hadn’t realized was possible,” urging caution MIT Technology Review.
The debate highlights a dangerous gap: current safeguards are designed largely around hypothetical, high-end threats (e.g., AI autonomously engineering a pandemic virus), while real-world misuse by non-state actors in conflict zones is already occurring. The focus on catastrophic bioweapon scenarios has perhaps distracted attention from the more prosaic but immediate problem of AI-assisted conventional bomb-making. This is not a distant future; it is happening today in the Sahel and the Levant.
The Open Question: Universal Restrictions or Context-Awareness?
The evidence from West Africa and from Anthropic’s case files raises an uncomfortable question: should AI companies implement region-specific or user-specific guardrails, or is universal restriction the only viable path? A universal ban on all weapons-related queries would impede legitimate research and journalism. Yet context-aware filters—allowing a journalist but blocking a militant—require identity verification and behavioral monitoring that raise privacy and surveillance concerns.
Some AI firms already attempt tiered access. For example, Claude’s latest models include expanded controls around dual-use biology questions. But these measures are porous. The Al Jazeera investigation shows that even basic jailbreaking techniques, widely shared in online forums, can bypass them. As long as open access to frontier AI models remains the default for billions of users, determined adversaries will find ways to exploit them. The alternative—restricting capabilities globally, perhaps by requiring verified identities for sensitive queries—comes with its own costs in terms of freedom and innovation.
Conclusion: A Dual-Use Reality We Can No Longer Ignore
The documented use of ChatGPT, Claude, and other chatbots by fighters on the ground marks a turning point. Dual-use AI risk is not just about hypothetical superintelligences designing novel pathogens; it is about the here and now, where a fighter with a smartphone can consult an omniscient assistant on how to recover explosives from a failed bomb. The response must match the reality: stronger, adaptive safeguards; cross-industry intelligence sharing; and a regulatory framework that acknowledges intent-based risk rather than relying solely on capability-based filters. As AI’s diffusion continues, the question is not whether it can be weaponized—it already has been. The only remaining question is how quickly we can adapt.
Frequently Asked Questions
Which AI chatbots have been used by militant groups according to the report?
Former Boko Haram members reported using ChatGPT, Claude, Gemini, Grok, Meta AI, and DeepSeek for bomb-making, attack planning, and recovering explosives from unexploded ordnance.
How did the fighters use AI to improve their bombs?
They described using chatbots as 24/7 technical advisors, telling them what materials they had and getting tailored, iterative advice on improving explosives and building devices.
Are AI companies’ safeguards effective against determined misuse?
The report documents that pro-ISIL forums share instructions for bypassing safety controls, and experts note a constant back-and-forth where adversaries evolve circumvention techniques faster than guards can adapt.
What did Anthropic’s threat intelligence report find?
Anthropic reported five cases of biological misuse and six cases of conventional weapons development using Claude, involving state-linked actors and criminals; the company adjusted safeguards and shared intelligence.
What is the main governance gap highlighted by these findings?
Current safeguards are designed for hypothetical, high-end threats, but real-world misuse by non-state actors in conflict zones is already happening, requiring context-aware restrictions and better behavior monitoring.