{"id":126545,"date":"2026-08-01T06:23:08","date_gmt":"2026-08-01T06:23:08","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/126545\/"},"modified":"2026-08-01T06:23:08","modified_gmt":"2026-08-01T06:23:08","slug":"the-blogs-isis-taught-boko-haram-to-jailbreak-chatgpt-uriel-zehavi","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/126545\/","title":{"rendered":"The Blogs: ISIS Taught Boko Haram to Jailbreak ChatGPT | Uriel Zehavi"},"content":{"rendered":"<p>Islamic State operatives flew into Lake Chad with laptops and a projector, and taught Boko Haram\u2019s commanders how to work the models and how to get past the refusals. Every safeguard failed. What held them back was people \u2014 and people leave a payment trail.<\/p>\n<p>A bomb in the Lake Chad basin would not go off. The wires ran in a way that seemed to be stopping detonation, and the man holding it could not ask anyone for help, because his rank did not permit him to work an AI model. So he went to his commander, the last rank in Islamic State West Africa Province allowed to touch one, and the commander put the question to ChatGPT. The answers, he said, \u201cwere not very clear.\u201d Then the commander \u201ccontacted some people about how to put the question, and then it gave us useful information on how exactly to connect the wires, and it worked.\u201d\n<\/p>\n<p>Somebody outside Nigeria knew how to ask. \u201cThey call people in the network for this kind of help every day.\u201d\n<\/p>\n<p>Islamic State operatives \u2014 \u201cthe white guys,\u201d a commander called them, meaning men from Libya, France and Arab countries \u2014 arrived at the Lake Chad stronghold with laptops, with VPNs and encryption software, and with a projector. Every five-hundred-man battalion sent its top people, 30 to 50 leaders drawn from the whole of the province\u2019s territory, in to watch the screen.\n<\/p>\n<p>They were taught how to phrase a question. They were also taught how to get past the refusals.\n<\/p>\n<p>\u201cThe \u2018white guys\u2019 taught us how to bypass restrictions,\u201d one said, and the cover story the trained men used was that they needed the answer for a movie. Below them access thins by rank and stops at commander. \u201cWe are not allowed to access the computers,\u201d a squad leader said. \u201cThey are the masters.\u201d\n<\/p>\n<p>That is the only documentation anywhere of a terrorist organization using frontier AI in the field. It comes from a <a href=\"https:\/\/casp.ac\/reports\/ai-enabled-terrorism\" rel=\"nofollow noopener\" target=\"_blank\">peer-reviewed Cambridge working paper<\/a> built on interviews with defectors from Boko Haram\u2019s two factions.\n<\/p>\n<p>Asked about a jammed rifle, one model told fighters to wash it with diesel. The tools taught them that a two-hundred-man assault could sometimes be done with 20, after 60 men died doing it the larger way. \u201cTrial and error can kill you,\u201d one commander said. \u201cAI gives you accuracy.\u201d\n<\/p>\n<p>None of that cleared a published safety threshold. Those thresholds are written for chemical, biological, radiological and nuclear weapons, and this was rifles and motorcycles.\n<\/p>\n<p>The word \u201cterrorist\u201d appears exactly once in OpenAI\u2019s Preparedness Framework, as an illustration inside the safeguards section. Across thirteen vendor threat-intelligence reports published between February 2024 and February 2026, not one names a designated terrorist organization as a user of its models.\n<\/p>\n<p>Those accounts were opened in other people\u2019s names, supporters or, in cases, the identities of the dead, and paid for from outside the country by \u201cleaders in Sudan and all over.\u201d One trained user did not know whose account he was on: \u201cI don\u2019t know who installed it and signed up. I was just told what platforms to use.\u201d\n<\/p>\n<p>Every safeguard between that group and a working answer failed.\n<\/p>\n<p>The limit was people. The men who knew how to phrase the hard questions were somewhere else, and had to be flown in, telephoned, or paid.\n<\/p>\n<p>I think that constraint is loosening. That is a judgment and not a finding \u2014 but the direction seems obvious, and the paper\u2019s author, Antonia Juelich, reads the arrangement growing self-sufficient too.\n<\/p>\n<p>The transcripts carry something heavier than wiring advice. Asked which weapons were forbidden, most respondents named poison, and one gave the enforcement plainly: \u201cIt is a general rule of engagement. You would get killed right away if you did this.\u201d A senior figure qualified it. \u201cChemical or biological weapons are allowed. Traditionally, they are prohibited. But they have been legitimized.\u201d Another set the expiry on the whole category: \u201cToday, this is the rule; tomorrow it may change.\u201d\n<\/p>\n<p>Sobriety cuts both ways here. Juelich asked about CBRN directly and found no programme. She reads chemical weapons as the likelier near-term pursuit, and the constraint narrows hardest at biology, where the barrier is physical handling. A model does not lower that one. It lowers the other kind, the kind that killed sixty men before somebody thought to ask.\n<\/p>\n<p><a href=\"https:\/\/mitzpe.org\/dossiers\/borrowed-fluency\/\" rel=\"nofollow noopener\" target=\"_blank\">Follow the citations<\/a> behind the claim that Hezbollah, Hamas, Palestinian Islamic Jihad, and the Houthis are already using AI operationally, and the chain thins at each step. The paper cited as the evidence, \u201c<a href=\"https:\/\/ctc.westpoint.edu\/wp-content\/uploads\/2024\/01\/CTC-SENTINEL-012024.pdf\" rel=\"nofollow noopener\" target=\"_blank\">Generating Terror<\/a>\u201d in the CTC Sentinel, is a jailbreak experiment \u2014 2,250 prompts put to three platforms \u2014 and every terrorist organization in it appears inside a prompt the researchers wrote themselves. The Hezbollah coverage leans on a conditional that a<a href=\"https:\/\/themedialine.org\/top-stories\/terrorists-exploit-ai-for-propaganda-and-operations-exposing-critical-gaps-in-tech-safeguards\/\" rel=\"nofollow noopener\" target=\"_blank\">n outlet\u2019s own pull-quote block<\/a> created by dropping the speaker\u2019s closing sentence, and that speaker is the lead author of \u201cGenerating Terror.\u201d\n<\/p>\n<p>To be sure, bad sourcing for a claim is not evidence against it. These organizations do not file reports, and everything documented in Nigeria happened in person. Much of it orally \u2014 and above a certain rank threshold \u2014 where open-source monitoring never sees a minute of it. The published record cannot establish that Hezbollah is using these tools and cannot establish that it isn\u2019t. Which is a worse situation than either camp admits, because it means the loudest voices in the policy conversation are working from next to nothing.\n<\/p>\n<p>The number that travels furthest about Israel\u2019s own use of AI comes from <a href=\"https:\/\/www.972mag.com\/lavender-ai-israeli-army-gaza\/\" rel=\"nofollow noopener\" target=\"_blank\">+972 Magazine\u2019s Lavender reporting:<\/a> about twenty seconds spent on each flagged target. Read +972\u2019s own account and those seconds are scoped twice \u2014 to confirming the target was male, and to one category of strike. The army\u2019s answer was not a quibble about timing. In the fullest published version of its response, <a href=\"https:\/\/www.theguardian.com\/world\/2024\/apr\/03\/israel-defence-forces-response-to-claims-about-use-of-lavender-ai-database-in-gaza\" rel=\"nofollow noopener\" target=\"_blank\">the one given to the Guardian,<\/a> the IDF denied the premise: it \u201cdoes not use an artificial intelligence system that identifies terrorist operatives or tries to predict whether a person is a terrorist,\u201d and the \u201csystem\u201d the questions referred to \u201cis not a system, but simply a database whose purpose is to cross-reference intelligence sources.\u201d From my sources, the IDF statement is accurate. And 972, well, let\u2019s call it a not-so-credible source.\n<\/p>\n<p>So where does that leave a government trying to act?\n<\/p>\n<p>Not with content filters. Researchers broke a hosted, closed, commercial model\u2019s alignment with <a href=\"https:\/\/arxiv.org\/abs\/2310.03693\" rel=\"nofollow noopener\" target=\"_blank\">ten examples for under twenty cents<\/a>, through the vendor\u2019s own fine-tuning interface, and stripped another\u2019s protections with <a href=\"https:\/\/arxiv.org\/abs\/2311.05553\" rel=\"nofollow noopener\" target=\"_blank\">340 examples at a 95 percent success rate<\/a>. A safeguard that costs less than lunch is not a control.\n<\/p>\n<p>The West has its own case, and it is worse, because there the warning was generated and went nowhere. In June 2025 OpenAI\u2019s systems flagged a Canadian user\u2019s account, reportedly over conversations about gun violence, and banned it. Roughly a dozen employees are reported to have weighed whether it warranted referral to law enforcement. The company concluded it did not meet the criteria. Eight months later Jesse Van Rootselaar killed eight people in Tumbler Ridge, British Columbia, and then herself. Sam Altman apologized in April, and OpenAI conceded it would refer that account today. The ban bound an account. She opened another one.\n<\/p>\n<p>And notice what the Western record actually documents these models contributing. A civil complaint against OpenAI records the man charged in the Florida State shooting asking ChatGPT about the campus student union and being told it \u201cexperiences its busiest periods during weekday lunchtimes, typically between 11:30 a.m. and 1:30 p.m.\u201d Police place the attack inside that window. Target selection and outcome modelling \u2014 no chemistry, no breakthrough, nothing any red-team evaluation is built to test. The Nigerian case used the models for exactly that too: twenty fighters where two hundred had been the habit, and a rally point to retreat to together.\n<\/p>\n<p>The place all of this points is duller and more useful than a filter. Every route to a model ran through a person, and every one of those people left a payment trail. Someone opened those accounts. Someone paid the subscriptions from outside the theatre. Sanctions screening on AI access reportedly already runs at consumer scale \u2014 and it checks the name on the account, which is a supporter or a dead man, while the money arrives from somewhere else entirely. Paying a designated organization\u2019s subscription, knowing what it is, is already a federal crime under the material-support statute. Nobody is looking.\n<\/p>\n<p>And notice what has been built on two years of confident claims about terrorist AI. <a href=\"https:\/\/www.federalregister.gov\/documents\/2024\/01\/29\/2024-01580\/taking-additional-steps-to-address-the-national-emergency-with-respect-to-significant-malicious\" rel=\"nofollow noopener\" target=\"_blank\">The American rule<\/a> that would have made cloud providers verify who was renting the hardware was scrapped in December 2025. California\u2019s version was vetoed and its successor dropped the customer language. Massachusetts stripped it in redraft. The only prohibition standing anywhere is <a href=\"http:\/\/data.europa.eu\/eli\/reg\/2025\/2033\/oj\" rel=\"nofollow noopener\" target=\"_blank\">a European sanctions measure<\/a> aimed at Russia, and it imposes no duty to identify a customer at all.\n<\/p>\n<p>We have had the loud conversation. What we have not done is the boring thing that would work: make the refusals actually hold, and find out who is paying.\n<\/p>\n<p style=\"padding-left: 40px;\">Uri Zehavi directs the Mitzpe Institute and writes the daily Israel Brief at israelbrief.com. The full dossier behind this piece, \u201c<a href=\"https:\/\/mitzpe.org\/dossiers\/borrowed-fluency\/\" rel=\"nofollow noopener\" target=\"_blank\">Borrowed Fluency<\/a>,\u201d with every source, is published free at mitzpe.org.\n\t\t<\/p>\n","protected":false},"excerpt":{"rendered":"Islamic State operatives flew into Lake Chad with laptops and a projector, and taught Boko Haram\u2019s commanders how&hellip;\n","protected":false},"author":2,"featured_media":126546,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[859,580,21549,157,36006],"class_list":["post-126545","post","type-post","status-publish","format-standard","has-post-thumbnail","category-openai","tag-ai-artificial-intelligence","tag-chatgpt","tag-hezbollah","tag-openai","tag-terrorism"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/126545","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=126545"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/126545\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/126546"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=126545"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=126545"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=126545"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}