Opinion & Analysis
Networks & Digital Warfare, Opinion

Overlooking the obvious: The most likely way AI can enable terror attacks

Nightmare scenarios of AI-engineered super-plagues or nuclear bombs have, understandably, attracted the most attention. But there is lots of lower-hanging fruit for terrorists.

Could terrorist groups seek to exploit artificial intelligence? (Getty Creative/Stefan Klein)

Sometimes a fixation on the most dangerous threats can lead you to overlook the most probable dangers, like being so worried about an asteroid impact that you walk around staring at the sky… and then fall into an open manhole. The American government and AI industry are in danger of making that very mistake when it comes to artificial intelligence and terrorism.

US frontier AI labs like OpenAI and Anthropic have focused on preventing the most potentially disastrous abuses of their products: the exploitation of AI to help terrorists build weapons of mass destruction.  And, indeed, there have been a handful of such attacks in recent decades, from the Aum Shinrikyo cult’s release of nerve gas in the Tokyo subway in 1995, killing 19, to anthrax-laced letters in the US in 2001, which killed five. AI advice on how to manufacture and spread these lethal substances might make similar attacks much more deadly.

But terrorists already kill thousands every year with conventional guns and explosives. So the most likely kinetic abuse of artificial intelligence is terrorist groups, individual psychopaths, and other malign actors using AI to stage more effective conventional attacks. We have clear evidence that danger is growing:

ISIS — still the deadliest terrorist organization on the planet — has circulated a “Guide to AI Tools and Risks” to its supporters and provides in-person AI training. While the most common use so far is AI-generated propaganda, ISIS operatives also have consulted AI for help homebrewing bombs and designing remote-controlled vehicles to deliver them.  One recent study of Nigeria-based Boko Haram, meanwhile, found the extremist group was using AI “in attack planning, weapons troubleshooting, and the design of explosive devices.”

Even “lone wolf” actors are taking advantage. Law enforcement described the January 2025 Las Vegas Cybertruck bombing as the first known incident in which ChatGPT was used to build an explosive device. And in February 2026, a Canadian school shooter allegedly consulted ChatGPT before carrying out a deadly attack. These are the canaries in the coal mine.

Now, paying attention to mass-destruction threats is laudable and understandable. Experts break these dangers down into the categories of chemical (poison gasses and liquids), biological (germs), radiological (the spreading of radioactive material), and nuclear bombs — collectively known as CBRN threats. Preventing AI from helping engineer a super-smallpox or a nuclear weapon is obviously a good thing! Minimizing chemical and radiological threats is also important, although terrorist attacks using explosives have often proven more deadly than the world’s worst chemical terrorist attack, and no radiological or nuclear terrorist attack has yet occurred. Signs the labs are taking these threats seriously include their hiring spree over the past year for CBRN-related safety roles, repeated references to CBRN threats in their risk reports, and grant awards to organizations that work on CBRN threat reduction.

Yet there is a relative dearth of similar actions to address conventional threats. And while terrorists and criminals usually lag behind national militaries in adopting new tactics and methods, they have also shown remarkable ingenuity and adaptiveness. So while the armed forces of the United StatesChinaRussiaUkraineSouth Korea, and many more are working to deeply integrate AI in all aspects of their conventional warfighting — from intelligence collecting to operational planning to drone strikes — increasingly, so are terrorists.

Such AI adoption by malign non-state actors could substantially increase their capacity to kill, especially because technical incompetence and poor logistics are major causes of failed terrorist attacks. Greater access to information can overcome these obstacles.

Frontier AI labs should not underestimate how much simplified access to open-source information can help attackers, especially lone-wolves or small cells unsupported by larger organizations. If Boston Marathon bombing-style attacks (5 killed) becomes as effective as the Oklahoma City bombing (168 killed), or if San Bernardino-style (14 killed) terror attacks become as complex as the Paris ISIS attacks (130 killed), the cumulative effects would be devastating. Notably, the difference in lethality within these pairs of attacks is largely a result of differences in knowledge, planning, and logistics, all things which AI can assist with.

The Oklahoma City bombing, for instance, — still the worst terror attack on US soil conducted by US citizens — involved a relatively complex improvised explosive device weighing thousands of pounds, which required sourcing and assembling materials like nitromethane and Tovex explosives. The terrorists learned how to do this from their military training, survivalist and weapons manuals, and a novel, The Turner Diaries, written as a detailed “blueprint for victory” for white supremacists. In comparison, the Boston Marathon bombers assembled much smaller and rudimentary weapons, using instructions from al-Qaeda’s Inspire magazine. Superior access to information led to a much deadlier result.

This phenomenon could extend to numerous other types of conventional weapons, especially when foreign terrorist groups capture advanced weapons. Consider a scenario: al-Qaeda-linked militants ambush a Russian military convoy in Africa, killing dozens and capturing vehicles and equipment. The loot includes a Russian Kord heavy machine gun — but none of the militants know how to operate it. Turning to AI, however, they are able to find a Russian-language technical manual, as well as an English-language instructional video. Using AI to translate both to their native language, Bambara, the militants learn how to operate and maintain the machine gun. That significantly increases their firepower, making future attacks more successful, which in turn allows them to seize even more resources and weapons — which they can also get AI help in using. Each of these steps is eminently possible and could apply to much more advanced systems like tanks and anti-aircraft systems, both of which ISIS captured in large quantities in 2014/2015.

In addition to the cost in human life, failing to preemptively address conventional risks could create serious blowback for frontier labs. AI development already polls quite poorly with the American public, especially the data center construction that undergirds AI scaling. A major AI-enabled terrorist attack could stoke additional anxiety over the technology’s proliferation and increase the probability of unpredictable, heavy-handed regulations that the labs are trying to avoid. This could include more direct regulation of safety filters, mandated data collection and surveillance, export controls, and restrictions on model distribution — all of which could stunt U.S. AI development to the benefit of adversaries like China and undermine AI’s appeal for consumers.

So where should labs begin to address the problem?

First, assign conventional threats a similar level of importance as CBRN threats. That would require hiring experts in terrorism and conventional weapons systems alongside the CBRN specialists. It would also necessitate a thorough risk review, ensuring that the probability of threats is considered, not just their magnitude.

Second, cooperate with law enforcement and intelligence agencies to proactively identify accounts used for illicit activities, even if the specific interactions with AI models do not immediately violate terms of use. This could offer insights into what terrorists are planning and avert attacks before they occur.

Third and most important, strengthen prompt safeguards surrounding conventional weapons systems, particularly with regards to translating technical and operational manuals and designing replacement components. Simplified access to information, even when it is theoretically available in other open sources, increases the probability that it will be used.

Terrorists are actively working to exploit US AI models. A failure to stop them could create waves of fear and anti-tech backlash that spread far beyond the physical damage inflicted.

Ryan Brobst is the deputy director of the Center on Military and Political Power (CMPP) at the Foundation for Defense of Democracies (FDD).