Welcome to the forefront of conversational AI as we explore the fascinating world of AI chatbots in our dedicated blog series. Discover the latest advancements, applications, and strategies that propel the evolution of chatbot technology. From enhancing customer interactions to streamlining business processes, these articles delve into the innovative ways artificial intelligence is shaping the landscape of automated conversational agents. Whether you’re a business owner, developer, or simply intrigued by the future of interactive technology, join us on this journey to unravel the transformative power and endless possibilities of AI chatbots.
Home → Science → News
"It's like a human robot, we used it a lot."
A trench surrounding a Nigerian military base stopped motorcycle-riding militants from getting inside. So, according to a former commander, they asked an AI chatbot for help.
The commander told Cambridge researcher Antonia Juelich that fighters had seen motorcycles perform jumps in a movie. They supplied a chatbot with information about their bikes and the distance they needed to cross, then used its responses while developing a technique of their own.
What followed was horrific. The commander said the group dug practice trenches and filled them with broken glass and fire. Eighteen fighters died during training, he claimed, while eight eventually mastered the jump. During a later attack, he said, they cleared the trench and overcame the military base.
It is the most dramatic example in Juelich’s new report, but it’s perhaps not even the most important one. The interviews increasingly suggest that the terrorist group is treating AI like infrastructure, using it to solve their problems and using it in many different ways. Juelich’s new report describes two factions operating dedicated AI units, managing accounts across competing services, paying for subscriptions, training personnel and circulating chatbot-generated advice through the chain of command.
In other words, terrorist groups appear to have started treating AI as operational infrastructure.
Boko Haram is the umbrella name commonly used for a jihadist insurgency that emerged in northeastern Nigeria in the early 2000s. It has since fractured into rival factions. The conflicts involving these factions have killed tens of thousands of people and displaced millions. It’s not the first time these organizations have adopted technology. Previously, they also used technologies from satellite internet to weaponized drones. AI, the new research suggests, is becoming the latest addition to that arsenal.
Juelich, a researcher with the Cambridge Programme on AI Science and Policy, conducted 57 in-person interviews with 27 former Boko Haram members in northeastern Nigeria during 2025 and 2026. The report uses “Boko Haram” as a collective label for two rival factions: the Islamic State West Africa Province, or ISWAP, and Jamā’at Ahl as-Sunnah lid-Da’wah wa’l-Jihād, usually shortened to JAS.
Of the 27 former members interviewed, 12 said they had no knowledge of their faction’s AI use. The remaining 15, including commanders and technical specialists, supplied the accounts on which the AI-specific findings are based. Juelich also adjusted her second round of recruitment to focus more heavily on people whose positions made exposure to AI more likely.
Stay ahead with ZME Science and subscribe.
Please check your inbox and confirm your subscription.
However, these accounts primarily describe activity from 2023 and 2024. So, them using AI isn’t exactly a new thing. The group also isn’t limiting itself to one AI provider.
Former members identified ChatGPT, Claude, Gemini, Grok, Meta AI and DeepSeek. The groups appear to have used whichever system produced a useful answer. In fact, their approach seems mirror that of large corporations. Maintain several accounts, compare outputs, route a task to the model that handles it best. Don’t let one vendor’s outage, policy change or refusal interrupt operations.
The tasks themselves, of course, were different.
Interviewees said their factions consulted AI systems for attack planning, logistics, operational security, weapons troubleshooting, explosive-device design, and reviews of failed operations. “You type in the question or use your voice and it [AI] gives you a detailed answer, like ‘How can I build a bomb?’ and then it tells you how. It is like a human robot! We used it a lot.”
A chatbot doesn’t need to invent a new weapon to be useful. It can translate technical language, organize scattered information, troubleshoot equipment or give an inexperienced user a plausible sequence of steps. A small improvement can be consequential when the user is already armed, organized and willing to experiment.
One former member summarized the perceived benefit bluntly: “Trial and error can kill you. AI gives you accuracy.”
The terrorists even have an almost corporate training system. Former members said Islamic State-linked operatives delivered training in person and remotely. Trainers arrived with laptops, projectors, VPNs, encrypted software, accounts, and paid chatbot subscriptions. They demonstrated prompting techniques and taught members how to evade platform restrictions.
“The white guys came and taught us,” one former commander recalled. “They assembled the top people in a room and used a projector to show how it works on a big screen.”
Major AI providers prohibit using their systems to facilitate terrorism, violence, or weapons development. Some also explicitly ban attempts to circumvent their safeguards. But there’s a problem: those guardrails can be overcome.
Several studies have shown that you can get AI to say things it’s not supposed to.
Former Boko Haram members also figured this out. They trained users to bypass restrictions by reframing questions as fictional scenarios or asking for information in smaller pieces. One commander said younger members told chatbots they needed the information “for a movie or something like that.” When one of the models still refused, they switched to others.
The terrorists also became quite profficient at jailbreaking AI. A question about increasing a motorcycle’s acceleration is legitimate. So is a question about calculating a jump. So is advice on welding, suspension, fuel mixtures, radio discipline, or drone payload balance. You can ask a seemingly legit question and a chatbot can’t tell what the applicaiton would be.
AI companies had different responses.
Google disputed whether the chatbot responses described in the research were specific enough to be operationally useful. Anthropic said its systems were designed to refuse requests related to violence and explosives. Meta emphasized that the study concerned older models, while OpenAI said bad actors would continue trying to misuse its tools and that the company would keep strengthening its defenses.
All of those statements may be technically true, but they don’t address the central finding: former members of a terrorist organization believed the systems were useful enough to build teams around them.
The report found no evidence that the factions used AI to develop nuclear or biological weapons. Some former members expressed interest in chemical or biological attacks, but their documented chatbot use remained focused on conventional weapons and operations.
That’s hardly reassuring.
Terrorist groups don’t need science-fiction weapons to become more dangerous. Small improvements in logistics, equipment maintenance, reconnaissance, coordination, or decision-making can matter when an organization already possesses guns, explosives, drones, and trained fighters. This is where the AI industry faces a fundamental problem.
Companies are racing to create systems that are more capable, more accessible, and better at supplying expertise on demand. Those same qualities make the tools valuable to programmers, engineers, mechanics, students — and violent groups.
That makes terrorists disturbingly well suited to the modern AI market. They are highly motivated, indifferent to terms of service, willing to experiment, and happy to shop around. Better guardrails may raise the cost of misuse, but the underlying tension remains: the industry is trying to make expertise easier for everyone to access while somehow ensuring that the wrong people cannot use it for the wrong reasons.
“The terrorists are not waiting for us to make A.I. safe,” Juelich told The New York Times.
Neither, apparently, is the AI industry.
The study can be read in its entirety here.
Dr. Andrei Mihai is a geophysicist and founder of ZME Science. He has a Ph.D. in geophysics and archaeology and has completed courses from prestigious universities (with programs ranging from climate and astronomy to chemistry and geology). He is passionate about making research more accessible to everyone and communicating news and features to a broad audience.
© 2007-2025 ZME Science – Not exactly rocket science. All Rights Reserved.
© 2007-2025 ZME Science – Not exactly rocket science. All Rights Reserved.