Boko Haram Uses All Major AI Chatbots for Attack and Weapons

A new study reveals that Boko Haram has trained dedicated AI units to bypass safety filters on major chatbots for attack planning and weapons development.

By Central
Fighters from both Boko Haram factions used AI chatbots for attack planning and weapons development after training on jailbreak techniques.
Highlights
  • Boko Haram established dedicated AI units with training from ISIS liaisons since 2023.
  • Safety filters from all major AI providers failed to prevent misuse by the group.
  • Former members confirmed interest in using AI for mass-casualty weapons development.

Boko Haram has integrated all major commercial AI chatbots into its operations, using models from OpenAI, Anthropic, Google, xAI, Meta, and DeepSeek for attack planning, weapons development, and operational security. A new study from researcher Antonia Jülich at the Cambridge Programme on AI Science & Policy (CASP) reveals that both factions of the group have established dedicated AI units, with ISIS liaisons providing training on prompt engineering and jailbreak techniques since 2023.

How Boko Haram Uses AI for Attack Planning and Weapons Development

Jülich conducted 57 interviews with 27 former Boko Haram members to compile the findings. The group uses AI chatbots for a range of military applications, including constructing more powerful explosive devices, maintaining weapons, planning attacks, and improving operational security. Both factions assembled their top personnel in dedicated rooms, using projectors to demonstrate how to interact with the AI systems on large screens. The training covered methods to bypass the safety filters that major AI labs have implemented to prevent exactly this kind of misuse.

ISWAP Used AI to Replicate Movie Stunts for Combat

One of the most striking examples involved the ISWAP faction, which used AI to reverse-engineer motorcycle jumping techniques from a film, allowing fighters to clear trenches during operations. The results were devastating: eighteen fighters died during training attempts, and only eight successfully made the jump. The former ISWAP commander Munzir described the process to Jülich, detailing how the group used the AI to extract practical techniques from visual media and adapt them for battlefield use.

Former Members Confirm Interest in Mass-Casualty Weapons

Beyond conventional tactics, the study uncovered a more alarming trajectory. Former members expressed strong enthusiasm for AI capabilities, and some confirmed that the group had previously considered pursuing mass-casualty weapons. Jülich notes that while Boko Haram’s current AI use remains conventional, the findings should serve as a warning about the risk of terrorist organizations seeking AI assistance for chemical and biological weapons development. The accessibility of dangerous knowledge through these systems is not a theoretical concern.

Safety Filters Failed to Prevent Misuse Across All Major Chatbots

The study found that safety filters from all major AI providers failed to reliably prevent misuse. This aligns with longstanding warnings from researchers and AI labs themselves, including OpenAI and Anthropic, about the risk that large language models could make dangerous knowledge more accessible. Anthropic has publicly acknowledged that jailbreaks will likely never be fully eliminated, a reality that the Boko Haram case underscores in concrete terms. The voluntary self-regulation approach that the industry has relied on is showing clear limits when confronted with determined adversaries who have dedicated training programs for bypassing safeguards.

Chatbots Are Not the Real Concern — Specialized AI Systems Pose Greater Risk

Researchers caution that the chatbots capturing public attention, such as ChatGPT and Claude, are not the primary threat. These systems primarily make existing knowledge easier to find rather than generating novel capabilities. The greater concern lies in the potential misuse of specialized AI systems designed for the life sciences and other technical domains. Such systems could accelerate the development of new biological or chemical agents, representing a fundamentally different risk profile from the information-retrieval function of general-purpose chatbots. The Boko Haram case demonstrates the current baseline of misuse, but the trajectory points toward more dangerous applications as AI capabilities advance.

What This Means for AI Safety and Regulation

For professionals in AI safety, policy, and national security, this study provides concrete evidence that existing safety measures are insufficient against determined adversaries. The formation of dedicated AI units by non-state actors and the documented failure of safety filters across every major platform should accelerate the push for more robust technical safeguards and regulatory frameworks. Readers should monitor the policy response from both AI labs and governments, particularly around the development of specialized life-science AI systems that could enable capabilities far beyond what current chatbots can provide. The practical takeaway is that safety research must shift from preventing incidental misuse to defending against targeted, trained adversaries.

Share This Article