Overlooking the obvious: The most likely way AI can enable terror attacks忽略显而易见的事实:人工智能最有可能促成恐怖袭击的方式
Nightmare scenarios of AI-engineered super-plagues or nuclear bombs have, understandably, attracted the most attention. But there is lots of lower-hanging fruit for terrorists.

Could terrorist groups seek to exploit artificial intelligence? (Getty Creative/Stefan Klein)
Sometimes a fixation on the most dangerous threats can lead you to overlook the most probable dangers, like being so worried about an asteroid impact that you walk around staring at the sky… and then fall into an open manhole. The American government and AI industry are in danger of making that very mistake when it comes to artificial intelligence and terrorism.
US frontier AI labs like OpenAI and Anthropic have focused on preventing the most potentially disastrous abuses of their products: the exploitation of AI to help terrorists build weapons of mass destruction. And, indeed, there have been a handful of such attacks in recent decades, from the Aum Shinrikyo cult’s release of nerve gas in the Tokyo subway in 1995, killing 19, to anthrax-laced letters in the US in 2001, which killed five. AI advice on how to manufacture and spread these lethal substances might make similar attacks much more deadly.
But terrorists already kill thousands every year with conventional guns and explosives. So the most likely kinetic abuse of artificial intelligence is terrorist groups, individual psychopaths, and other malign actors using AI to stage more effective conventional attacks. We have clear evidence that danger is growing:
ISIS — still the deadliest terrorist organization on the planet — has circulated a “Guide to AI Tools and Risks” to its supporters and provides in-person AI training. While the most common use so far is AI-generated propaganda, ISIS operatives also have consulted AI for help homebrewing bombs and designing remote-controlled vehicles to deliver them. One recent study of Nigeria-based Boko Haram, meanwhile, found the extremist group was using AI “in attack planning, weapons troubleshooting, and the design of explosive devices.”
Even “lone wolf” actors are taking advantage. Law enforcement described the January 2025 Las Vegas Cybertruck bombing as the first known incident in which ChatGPT was used to build an explosive device. And in February 2026, a Canadian school shooter allegedly consulted ChatGPT before carrying out a deadly attack. These are the canaries in the coal mine.
Now, paying attention to mass-destruction threats is laudable and understandable. Experts break these dangers down into the categories of chemical (poison gasses and liquids), biological (germs), radiological (the spreading of radioactive material), and nuclear bombs — collectively known as CBRN threats. Preventing AI from helping engineer a super-smallpox or a nuclear weapon is obviously a good thing! Minimizing chemical and radiological threats is also important, although terrorist attacks using explosives have often proven more deadly than the world’s worst chemical terrorist attack , and no radiological or nuclear terrorist attack has yet occurred. Signs the labs are taking these threats seriously include their hiring spree over the past year for CBRN-related safety roles, repeated references to CBRN threats in their risk reports , and grant awards to organizations that work on CBRN threat reduction.
Yet there is a relative dearth of similar actions to address conventional threats. And while terrorists and criminals usually lag behind national militaries in adopting new tactics and methods , they have also shown remarkable ingenuity and adaptiveness. So while the armed forces of the United States , China , Russia , Ukraine , South Korea , and many more are working to deeply integrate AI in all aspects of their conventional warfighting — from intelligence collecting to operational planning to drone strikes — increasingly, so are terrorists .
Such AI adoption by malign non-state actors could substantially increase their capacity to kill, especially because technical incompetence and poor logistics are major causes of failed terrorist attacks. Greater access to information can overcome these obstacles.
Frontier AI labs should not underestimate how much simplified access to open-source information can help attackers, especially lone-wolves or small cells unsupported by larger organizations. If Boston Marathon bombing -style attacks (5 killed) becomes as effective as the Oklahoma City bombing (168 killed), or if San Bernardino -style (14 killed) terror attacks become as complex as the Paris ISIS attacks (130 killed), the cumulative effects would be devastating. Notably, the difference in lethality within these pairs of attacks is largely a result of differences in knowledge, planning, and logistics, all things which AI can assist with.
The Oklahoma City bombing , for instance, — still the worst terror attack on US soil conducted by US citizens — involved a relatively complex improvised explosive device weighing thousands of pounds, which required sourcing and assembling materials like nitromethane and Tovex explosives. The terrorists learned how to do this from their military training, survivalist and weapons manuals, and a novel, The Turner Diaries , written as a detailed “blueprint for victory” for white supremacists. In comparison, the Boston Marathon bombers assembled much smaller and rudimentary weapons, using instructions from al-Qaeda’s Inspire magazine. Superior access to information led to a much deadlier result.
This phenomenon could extend to numerous other types of conventional weapons, especially when foreign terrorist groups capture advanced weapons. Consider a scenario: al-Qaeda-linked militants ambush a Russian military convoy in Africa, killing dozens and capturing vehicles and equipment. The loot includes a Russian Kord heavy machine gun — but none of the militants know how to operate it. Turning to AI, however, they are able to find a Russian-language technical manual, as well as an English-language instructional video . Using AI to translate both to their native language, Bambara, the militants learn how to operate and maintain the machine gun. That significantly increases their firepower, making future attacks more successful, which in turn allows them to seize even more resources and weapons — which they can also get AI help in using. Each of these steps is eminently possible and could apply to much more advanced systems like tanks and anti-aircraft systems , both of which ISIS captured in large quantities in 2014/2015.
In addition to the cost in human life, failing to preemptively address conventional risks could create serious blowback for frontier labs. AI development already polls quite poorly with the American public, especially the data center construction that undergirds AI scaling. A major AI-enabled terrorist attack could stoke additional anxiety over the technology’s proliferation and increase the probability of unpredictable, heavy-handed regulations that the labs are trying to avoid. This could include more direct regulation of safety filters , mandated data collection and surveillance, export controls , and restrictions on model distribution — all of which could stunt U.S. AI development to the benefit of adversaries like China and undermine AI’s appeal for consumers.
So where should labs begin to address the problem?
First, assign conventional threats a similar level of importance as CBRN threats. That would require hiring experts in terrorism and conventional weapons systems alongside the CBRN specialists. It would also necessitate a thorough risk review, ensuring that the probability of threats is considered, not just their magnitude.
Second, cooperate with law enforcement and intelligence agencies to proactively identify accounts used for illicit activities, even if the specific interactions with AI models do not immediately violate terms of use. This could offer insights into what terrorists are planning and avert attacks before they occur.
Third and most important, strengthen prompt safeguards surrounding conventional weapons systems, particularly with regards to translating technical and operational manuals and designing replacement components. Simplified access to information, even when it is theoretically available in other open sources, increases the probability that it will be used.
Terrorists are actively working to exploit US AI models. A failure to stop them could create waves of fear and anti-tech backlash that spread far beyond the physical damage inflicted.
Ryan Brobst is the deputy director of the Center on Military and Political Power (CMPP) at the Foundation for Defense of Democracies (FDD).
恐怖组织会试图利用人工智能吗?(Getty Creative/Stefan Klein)
有时,过分关注最危险的威胁会导致人们忽略最可能发生的危险,就像过度担忧小行星撞击而四处张望,盯着天空发呆……结果却掉进敞开的下水道井盖里。美国政府和人工智能产业在人工智能和恐怖主义问题上,正面临着犯下类似错误的危险。
美国前沿人工智能实验室,例如OpenAI和Anthropic,一直致力于防止其产品最可能造成灾难性后果的滥用:即利用人工智能帮助恐怖分子制造大规模杀伤性武器。事实上,近几十年来确实发生过几起此类袭击事件,例如1995年奥姆真理教在东京地铁释放神经毒气,造成19人死亡;以及2001年美国寄出炭疽邮件,造成5人死亡。人工智能如果能够提供关于如何制造和传播这些致命物质的建议,可能会使类似的袭击造成更大的伤亡。
但恐怖分子每年已经用传统枪支和爆炸物杀害了数千人。因此,人工智能最有可能被滥用的动能手段是恐怖组织、精神变态者和其他恶意行为者利用人工智能发动更有效的常规袭击。我们有确凿的证据表明,这种危险正在加剧:
伊斯兰国(ISIS)——仍然是地球上最致命的恐怖组织——已向其支持者散发了一份“人工智能工具与风险指南”,并提供面对面的人工智能培训。虽然目前最常见的用途是利用人工智能生成宣传材料,但ISIS成员也曾利用人工智能来协助自制炸弹和设计用于投放炸弹的遥控车辆。与此同时,最近一项针对尼日利亚博科圣地组织的研究发现,该极端组织正在“利用人工智能进行袭击策划、武器故障排除和爆炸装置设计”。
就连“独狼”式犯罪分子也在利用ChatGPT。执法部门称,2025年1月拉斯维加斯Cybertruck爆炸案是已知首例利用ChatGPT制造爆炸装置的事件。2026年2月,一名加拿大校园枪击案凶手据称在实施致命袭击前咨询了ChatGPT。这些都是危险的预兆。
关注大规模杀伤性威胁是值得称赞且可以理解的。专家将这些危险分为化学(毒气和毒液)、生物(病菌)、放射性(放射性物质扩散)和核弹四类——统称为核生化(CBRN)威胁。防止人工智能被用于制造超级天花或核武器显然是一件好事!尽量减少化学和放射性威胁也很重要,尽管事实证明,使用爆炸物的恐怖袭击往往比世界上最严重的化学恐怖袭击更致命,而且至今尚未发生放射性或核恐怖袭击。实验室认真对待这些威胁的迹象包括:过去一年中,他们大量招聘与核生化相关的安全人员;他们在风险报告中多次提及核生化威胁;以及向致力于减少核生化威胁的组织提供资助。
然而,针对传统威胁采取类似行动的情况却相对匮乏。虽然恐怖分子和犯罪分子在采用新战术和新方法方面通常落后于各国军队,但他们也展现出了惊人的创造力和适应能力。因此,尽管美国、中国、俄罗斯、乌克兰、韩国以及其他许多国家的军队都在努力将人工智能深度融入其常规战争的各个方面——从情报收集到作战计划再到无人机打击——但恐怖分子也在日益这样做。
恶意非国家行为体若采用人工智能,可能会大幅提升其杀戮能力,尤其因为技术能力不足和后勤保障薄弱是恐怖袭击失败的主要原因。而更广泛的信息获取渠道则有助于克服这些障碍。
前沿人工智能实验室不应低估简化开源信息获取途径对攻击者,尤其是那些缺乏大型组织支持的独狼式或小型恐怖小组的帮助。如果波士顿马拉松爆炸案(5人死亡)的杀伤力与俄克拉荷马城爆炸案(168人死亡)相当,或者圣贝纳迪诺枪击案(14人死亡)的复杂程度与巴黎ISIS袭击案(130人死亡)相当,那么其累积效应将是毁灭性的。值得注意的是,这两起袭击事件的致命性差异主要源于知识、计划和后勤方面的不同,而人工智能恰恰可以在这方面提供帮助。
例如,俄克拉荷马城爆炸案——至今仍是美国公民在美国本土实施的最严重恐怖袭击——使用了重达数千磅的相对复杂的简易爆炸装置,这需要采购和组装硝基甲烷和托维克斯炸药等材料。恐怖分子从军事训练、生存手册、武器手册以及一本名为《特纳日记》的小说中学习了如何制造这种装置。《特纳日记》是为白人至上主义者撰写的一份详细的“胜利蓝图”。相比之下,波士顿马拉松爆炸案的凶手组装的武器要小得多,也简陋得多,他们使用的说明来自基地组织的《激励》杂志。信息获取渠道的优越性导致了更为致命的后果。
这种现象可能扩展到许多其他类型的常规武器,尤其是在外国恐怖组织缴获先进武器的情况下。设想这样一个场景:与基地组织有关联的武装分子在非洲伏击了一支俄罗斯军用车队,造成数十人死亡,并缴获了车辆和装备。缴获的物品中包括一挺俄罗斯科尔德重机枪——但这些武装分子都不会操作。然而,借助人工智能,他们找到了俄语技术手册和英语教学视频。利用人工智能将两者翻译成他们的母语班巴拉语,武装分子学会了如何操作和维护这挺机枪。这显著提升了他们的火力,使未来的袭击更加成功,进而使他们能够缴获更多资源和武器——他们还可以借助人工智能来使用这些武器。以上每一步都完全可行,并且可以应用于更先进的系统,例如坦克和防空系统,而“伊斯兰国”在2014/2015年就大量缴获了这些武器。
除了人员伤亡之外,未能预先应对传统风险可能会给前沿实验室带来严重的负面影响。人工智能发展在美国公众中的支持率已经很低,尤其是支撑人工智能规模化的数据中心建设。一次重大的人工智能恐怖袭击可能会加剧公众对这项技术扩散的担忧,并增加实验室试图避免的、难以预测的严苛监管的可能性。这些监管可能包括对安全过滤器的更直接监管、强制数据收集和监控、出口管制以及对模型分发的限制——所有这些都可能阻碍美国的人工智能发展,使中国等对手受益,并削弱人工智能对消费者的吸引力。
那么实验室应该从哪里着手解决这个问题呢?
首先,应将常规威胁与核生化威胁赋予同等重要的地位。这就需要聘请反恐和常规武器系统方面的专家,以及核生化专家。此外,还需要进行全面的风险评估,确保不仅考虑威胁的严重程度,还要考虑其发生的概率。
第二,与执法和情报机构合作,主动识别用于非法活动的账户,即使与人工智能模型的具体交互并未立即违反使用条款。这有助于深入了解恐怖分子的计划,并在袭击发生前加以阻止。
第三,也是最重要的一点,要加强对常规武器系统的快速保障措施,尤其是在技术和操作手册的翻译以及替换部件的设计方面。即使信息理论上可以从其他开放渠道获取,简化获取途径也会增加信息被利用的可能性。
恐怖分子正积极利用美国的人工智能模型。如果不加以阻止,可能会引发恐慌和反科技浪潮,其影响远远超出实际造成的破坏。
Ryan Brobst 是保卫民主基金会 (FDD) 下属军事和政治力量中心 (CMPP) 的副主任。