Terrorists are using AI — and the chatbot is killing them
Today we have a report by Antonia Juelich at the Cambridge Programme on AI Science and Policy, CASP: “‘God has helped us, and so will AI’: How the Terrorist Group Boko Haram Uses Frontier AI”. Oh no! The bad guys have AI! [CASP, PDF, archive] CASP’s organisational mission is to produce criti-hype —…
Today we have a report by Antonia Juelich at the Cambridge Programme on AI Science and Policy, CASP: “‘God has helped us, and so will AI’: How the Terrorist Group Boko Haram Uses Frontier AI”. Oh no! The bad guys have AI! [CASP, PDF, archive] CASP’s organisational mission is to produce criti-hype — reports that act like they’re warning about AI, but their real job is to make the AI look super-cool. If the AI can work for terrorists, it can definitely do your TPS reports. Juelich went to Nigeria and interviewed former members of the terrorist group Boko Haram about how the group had used chatbots in 2024 and 2025. The 15 interviewees did not use the chatbot themselves. All of this is only these guys repeating their senior commanders’ stories of how they used the chatbot. But it’s very scary, OK? Serious implications: Terrorist adoption of AI has thus advanced further and more systematically than prior analysis has recognized, making it a present and growing reality that warrants attention from policymakers, security communities, and AI developers. Let’s say the murderous terrorists are using the chatbot. But Juelich says “present reality” — not present danger. Is there any present danger? What are Boko Haram using the bot for? It has aided in attack planning, weapons troubleshooting, and the design of explosive devices, as users have successfully circumvented some safeguards. Sounds bad! So what precisely does that entail? Here’s the New York Times covering the report as serious evidence of AI being of substantial assistance to terrorism: [NYT, archive] We saw in a movie how motorcycles can jump over bridges … We used A.I. to learn how to do this. We gave it information, like what motorcycles we use and the distance we need to jump and so on, and it gave us steps on what we have to do. Sounds enabling! But the NYT left off the punchline — what happened next: We dug holes and filled them with broken glass and fire to practice. 18 of us died in the process. Eight of us managed to do it. The chatbot’s advice killed two-thirds of the squad! A chatbot took out 18 terrorists without firing a shot. Why did the bot suggest practicing with a flaming pit full of broken glass? Because Boko Haram got the AI to tell them this by asking for script ideas for an action movie. That was their jailbreak. They could have filled the pits with water or something for practice. But no, the bot said fire and glass, so they used fire and glass. I can appreciate the researcher not saying to the murderous terrorists’ faces, “that’s really dumb.” But it’s really very dumb. At this point I’m wondering if the terrorists are having a lend of the researcher. I expect it gets boring out there between strikes, you’ve got to have your fun. Leaping a firepit is literally the example the New York Times used to make the chatbot sound dangerous. They go straight from this very dumb story to calling chatbots “digital nuclear weapons.” What Boko Haram does with this “digital nuclear weapon” is just use it as a fancy search engine: when ISWAP fighters were handed out new guns and they did not know how to correctly use them, they approached their qaid, who passed on the message to a specialist, who in turn replied, “just ask Grok,” which they then did. Using Grok? Sounds like a win — for their opponents. Is AI making Boko Haram more dangerous than other training methods they have access to would have? Well, we can’t actually say that: These perceptions and revealed preferences indicate uplift, though it is important to note that it cannot be conclusively determined. Juelich just admitted her 93-page report doesn’t show that anything happened. But the perception itself matters, since the belief that AI improves performance drives institutional investment and potentially the pursuit of higher-risk capabilities. CASP is saying that the real threat is thinking the AI works. That sounds like we can fight terrorism by telling people that AI is lying trash. Let’s be clear what happened here — Boko Haram used chatbots that had read the whole Internet and answered questions. That is, a search engine, reading existing information. That’s a sort of threat? But so is reading in general. And if Boko Haram have chatbots, they have the internet. The substantial threat is Boko Haram’s disregard for their own members’ lives. I’m pretty sure that’s what makes the group a serious threat. Not one bit of the problem here is AI. That’s just CASP’s hook to make the report sound scary. You definitely need to fund CASP to do more research into how frightening the AI is! Lack of funding is the true terrorist threat. Video — PodcastSource: Pivot to AI — Published — Category: Business