At the same time, analysts should avoid simplistic assumptions about causality. Most socially isolated people do not become terrorists. Exposure to extremist content rarely automatically leads to violence. AI may reinforce existing grievances and ideological tendencies, but it will still operate in broader social, political and psychological contexts.
Table of Contents
Operations planning and tactical support
AI can also support terrorist organizations and individuals in operational planning. These abilities are likely to be more evolutionary than transformative in nature.
AI systems can support a range of operational planning functions, including reconnaissance, translation, target research, IED design, itinerary planning, document creation, coding, communications security and open source intelligence analysis. Much of this information is already available online. The most important change is that AI can organize and personalize information faster and more efficiently. AI can also help users iterate by suggesting ideas, learning more about problems, and providing advice on how to address those problems.
While major tech companies building large language models (LLMs) try to build in at least some guardrails that limit the creation of extremist content, there are workarounds that pose a significant threat. There are thousands of LLMs available on open source software and model sharing sites (e.g. GitHub, Hugging Face) whose independent developers have had little incentive to build in guardrails, allowing even mediocre software developers to create “extremist chatbots.” For example, as of May 26, 2026, Hugging Face (a GitHub for machine learning models) hosted 368,944 text generation models, each of which could be downloaded and potentially used to create extremist chatbots. It hosted 100,333 text-to-image models (which use a text prompt to generate an image), 5,670 text-to-speech models, and 1,723 text-to-video models. The uploaded models are improving every day, and the latest models are probably not far behind the models from the major AI companies.15 As a result, the guardrails are often less effective than their developers hoped, allowing terrorists to better exploit the AI.
For inexperienced actors, AI can significantly reduce information friction and enable those with limited technical expertise to become more powerful. For example, a “charge sheet” filed in May 2026 by India’s National Investigation Agency in connection with a Delhi bombing in November 2025 states that the accused director, who was associated with al-Qaeda in the Indian subcontinent, used YouTube and ChatGPT to learn “how to build a rocket.” [IED] and in what proportion should the mixture be.”16
However, important operational limitations remain. Violence is difficult and untrained people often fail to carry out operations. Many attacks fail due to stress, inexperience, lack of technical skill or logistical incompetence.17 AI cannot eliminate these limitations. In addition, advanced terrorist operations typically require trust, organizational coordination, operational security, funding and practical experience. AI can improve planning efficiency, but it does not replace organizational infrastructure.
The likely outcome, therefore, is not a dramatic increase in sophisticated attacks, but rather a modest increase in the competence of lower-level actors. Small improvements in operational capability still matter, particularly in environments where individual actors already pose significant risks or where a capable group is already conducting a large number of attacks.
CBRN terrorism and biological risks
The interface between AI and chemical, biological, radiological and nuclear terrorism (CBRN) has raised great concerns. Biological risks in particular have become the focus of debates about AI border systems.
An immediate risk is the use of a combination of AI and drones to target CBRN sites. Many terrorist groups have already adopted the use of drones.18 At the same time, the war in Ukraine has accelerated the use of various forms of AI in drones, such as acoustic detection and low-cost interception.19 Elsewhere, terrorists can use AI to improve their operations using off-the-shelf machine learning and image analysis libraries to identify targets without the need for GPS, intentionally inject noise into acoustic emissions to confuse acoustic detectors, and limit communications to prevent positioning information from being passed to defenders.
Another concern is the use of AI models like AlphaFold to determine how proteins fold, an essential step in creating new proteins.20 Current protein folding methods and protein language models have few guardrails that prevent malicious individuals and nation-states from developing deadly pathogens instead of medicines that benefit humanity.21 More broadly, recent assessments suggest that advanced models are increasingly outperforming highly trained human experts in narrow scientific tasks such as troubleshooting laboratory procedures or synthesizing specialized technical information. As models improve, the possibility that AI systems could help malicious actors identify pathogens, optimize experimental procedures, or overcome technical bottlenecks becomes increasingly plausible.
However, caution is advised. Biology remains chaotic and uncertain. Success in simulated environments or theoretical modeling does not necessarily translate into successful weaponization. Tacit knowledge, laboratory infrastructure, material procurement, security protocols, environmental variables, and organizational competence remain important obstacles that terrorist groups will likely require significant expertise, funding, and support to overcome.
Historically, most terrorist organizations have shown limited interest in biological terrorism involving real mass casualties. Even groups that seek to kill large numbers of civilians often seek symbolic, political, or strategic effects rather than apocalyptic destruction. Likewise, even groups that engage in horrific violence (e.g., the Islamic State) have voters, and they do not want large numbers of their supporters affected. Large-scale biological attacks are operationally difficult, strategically unpredictable and potentially counterproductive.
A greater danger comes from nihilistic individuals, cults, and others who want the end of the world or mass human casualties rather than political change. In the past, cults like Aum Shinrikyo were on the hunt for biological weapons. The group had numerous scientists and engineers in its ranks and managed to use limited weaponry. The Federal Bureau of Investigation recently published the category of “nihilistic violent extremists,” defined as “individuals who engage in criminal behavior in the United States and abroad to advance political, social, or religious goals that stem primarily from hatred of society as a whole and a desire to bring about its collapse by sowing indiscriminate chaos, destruction, and social instability.” Many of these people seek mass casualties and care little about harm to society because they themselves lack voters.22
https://www.csis.org/analysis/artificial-intelligence-and-future-terrorism
