Islamic State operatives flew into Lake Chad with laptops and a projector, and taught Boko Haram’s commanders how to work the models and how to get past the refusals. Every safeguard failed. What held them back was people — and people leave a payment trail.
A bomb in the Lake Chad basin would not go off. The wires ran in a way that seemed to be stopping detonation, and the man holding it could not ask anyone for help, because his rank did not permit him to work an AI model. So he went to his commander, the last rank in Islamic State West Africa Province allowed to touch one, and the commander put the question to ChatGPT. The answers, he said, “were not very clear.” Then the commander “contacted some people about how to put the question, and then it gave us useful information on how exactly to connect the wires, and it worked.”
Somebody outside Nigeria knew how to ask. “They call people in the network for this kind of help every day.”
Islamic State operatives — “the white guys,” a commander called them, meaning men from Libya, France and Arab countries — arrived at the Lake Chad stronghold with laptops, with VPNs and encryption software, and with a projector. Every five-hundred-man battalion sent its top people, 30 to 50 leaders drawn from the whole of the province’s territory, in to watch the screen.
They were taught how to phrase a question. They were also taught how to get past the refusals.
“The ‘white guys’ taught us how to bypass restrictions,” one said, and the cover story the trained men used was that they needed the answer for a movie. Below them access thins by rank and stops at commander. “We are not allowed to access the computers,” a squad leader said. “They are the masters.”
That is the only documentation anywhere of a terrorist organization using frontier AI in the field. It comes from a peer-reviewed Cambridge working paper built on interviews with defectors from Boko Haram’s two factions.
Asked about a jammed rifle, one model told fighters to wash it with diesel. The tools taught them that a two-hundred-man assault could sometimes be done with 20, after 60 men died doing it the larger way. “Trial and error can kill you,” one commander said. “AI gives you accuracy.”
None of that cleared a published safety threshold. Those thresholds are written for chemical, biological, radiological and nuclear weapons, and this was rifles and motorcycles.
The word “terrorist” appears exactly once in OpenAI’s Preparedness Framework, as an illustration inside the safeguards section. Across thirteen vendor threat-intelligence reports published between February 2024 and February 2026, not one names a designated terrorist organization as a user of its models.
Those accounts were opened in other people’s names, supporters or, in cases, the identities of the dead, and paid for from outside the country by “leaders in Sudan and all over.” One trained user did not know whose account he was on: “I don’t know who installed it and signed up. I was just told what platforms to use.”
Every safeguard between that group and a working answer failed.
The limit was people. The men who knew how to phrase the hard questions were somewhere else, and had to be flown in, telephoned, or paid.
I think that constraint is loosening. That is a judgment and not a finding — but the direction seems obvious, and the paper’s author, Antonia Juelich, reads the arrangement growing self-sufficient too.
The transcripts carry something heavier than wiring advice. Asked which weapons were forbidden, most respondents named poison, and one gave the enforcement plainly: “It is a general rule of engagement. You would get killed right away if you did this.” A senior figure qualified it. “Chemical or biological weapons are allowed. Traditionally, they are prohibited. But they have been legitimized.” Another set the expiry on the whole category: “Today, this is the rule; tomorrow it may change.”
Sobriety cuts both ways here. Juelich asked about CBRN directly and found no programme. She reads chemical weapons as the likelier near-term pursuit, and the constraint narrows hardest at biology, where the barrier is physical handling. A model does not lower that one. It lowers the other kind, the kind that killed sixty men before somebody thought to ask.
Follow the citations behind the claim that Hezbollah, Hamas, Palestinian Islamic Jihad, and the Houthis are already using AI operationally, and the chain thins at each step. The paper cited as the evidence, “Generating Terror” in the CTC Sentinel, is a jailbreak experiment — 2,250 prompts put to three platforms — and every terrorist organization in it appears inside a prompt the researchers wrote themselves. The Hezbollah coverage leans on a conditional that an outlet’s own pull-quote block created by dropping the speaker’s closing sentence, and that speaker is the lead author of “Generating Terror.”
To be sure, bad sourcing for a claim is not evidence against it. These organizations do not file reports, and everything documented in Nigeria happened in person. Much of it orally — and above a certain rank threshold — where open-source monitoring never sees a minute of it. The published record cannot establish that Hezbollah is using these tools and cannot establish that it isn’t. Which is a worse situation than either camp admits, because it means the loudest voices in the policy conversation are working from next to nothing.
The number that travels furthest about Israel’s own use of AI comes from +972 Magazine’s Lavender reporting: about twenty seconds spent on each flagged target. Read +972’s own account and those seconds are scoped twice — to confirming the target was male, and to one category of strike. The army’s answer was not a quibble about timing. In the fullest published version of its response, the one given to the Guardian, the IDF denied the premise: it “does not use an artificial intelligence system that identifies terrorist operatives or tries to predict whether a person is a terrorist,” and the “system” the questions referred to “is not a system, but simply a database whose purpose is to cross-reference intelligence sources.” From my sources, the IDF statement is accurate. And 972, well, let’s call it a not-so-credible source.
So where does that leave a government trying to act?
Not with content filters. Researchers broke a hosted, closed, commercial model’s alignment with ten examples for under twenty cents, through the vendor’s own fine-tuning interface, and stripped another’s protections with 340 examples at a 95 percent success rate. A safeguard that costs less than lunch is not a control.
The West has its own case, and it is worse, because there the warning was generated and went nowhere. In June 2025 OpenAI’s systems flagged a Canadian user’s account, reportedly over conversations about gun violence, and banned it. Roughly a dozen employees are reported to have weighed whether it warranted referral to law enforcement. The company concluded it did not meet the criteria. Eight months later Jesse Van Rootselaar killed eight people in Tumbler Ridge, British Columbia, and then herself. Sam Altman apologized in April, and OpenAI conceded it would refer that account today. The ban bound an account. She opened another one.
And notice what the Western record actually documents these models contributing. A civil complaint against OpenAI records the man charged in the Florida State shooting asking ChatGPT about the campus student union and being told it “experiences its busiest periods during weekday lunchtimes, typically between 11:30 a.m. and 1:30 p.m.” Police place the attack inside that window. Target selection and outcome modelling — no chemistry, no breakthrough, nothing any red-team evaluation is built to test. The Nigerian case used the models for exactly that too: twenty fighters where two hundred had been the habit, and a rally point to retreat to together.
The place all of this points is duller and more useful than a filter. Every route to a model ran through a person, and every one of those people left a payment trail. Someone opened those accounts. Someone paid the subscriptions from outside the theatre. Sanctions screening on AI access reportedly already runs at consumer scale — and it checks the name on the account, which is a supporter or a dead man, while the money arrives from somewhere else entirely. Paying a designated organization’s subscription, knowing what it is, is already a federal crime under the material-support statute. Nobody is looking.
And notice what has been built on two years of confident claims about terrorist AI. The American rule that would have made cloud providers verify who was renting the hardware was scrapped in December 2025. California’s version was vetoed and its successor dropped the customer language. Massachusetts stripped it in redraft. The only prohibition standing anywhere is a European sanctions measure aimed at Russia, and it imposes no duty to identify a customer at all.
We have had the loud conversation. What we have not done is the boring thing that would work: make the refusals actually hold, and find out who is paying.
Uri Zehavi directs the Mitzpe Institute and writes the daily Israel Brief at israelbrief.com. The full dossier behind this piece, “Borrowed Fluency,” with every source, is published free at mitzpe.org.