AI-enabled terrorism: Addressing radicalization and CBRN risks in the age of LLMs
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur.
September 22, 2026
Summary
The rapid development and deployment of LLMs present new risks to peace and security. AI can be exploited to produce and disseminate extremist content and propaganda, which can lead to radicalization and recruitment. Terrorists are also increasingly using LLMs to scale up weapons development and attack planning.
The convergence of AI capabilities with chemical, biological, radiological, nuclear, and explosives (CBRNE) risks raises urgent questions for the international community. How can countermeasures keep up with rapidly evolving models?
FAR.AI hosted an event on AI-enabled terrorism on the sidelines of the 81st session of the UN General Assembly (UNGA 81). It focused on building a shared understanding of the risks, existing technical safeguards and benchmarks, and opportunities for cross-sector and international coordination to help mitigate them.
The event opened with remarks by Karl Berzins, President and co-founder of FAR.AI, and Steven Siqueira, Deputy Director of the United Nations Counter-Terrorism Center (UNCCT) in the UN Office of Counter-Terrorism. Lightning talks followed from Dina Hussein, Product Policy at OpenAI; David Scharia, Chief of Branch, UNCTED; and Brian Tse, Founder and CEO, Concordia AI.
Patricia Paskov, Director of Standards at the AI Verification and Evaluation Research Institute (AVERI), then moderated an expert panel. The panelists were Adam Gleave, Co-founder and CEO, FAR.AI; Adam Hadley, Founder and Executive Director, Tech Against Terrorism; and Paul Ash, Chief Executive, Christchurch Call Foundation.
Key themes from the event:
- The threat is already here. Extremists are using generative AI to plan, recruit, and carry out attacks with far less effort and cost than before, and to scale quickly.
- We are only as safe as the weakest models. Mitigation requires shared threat models and common evaluation standards.
- Existing coordination frameworks can be adapted. Multilateral efforts around counterterrorism, cybersecurity, and social media offer useful lessons.
- Collaboration and information sharing are essential. Governments, AI companies, and counterterrorism experts need more secure, multi-stakeholder channels for sharing, including across the U.S.-China divide.
- Policymakers' attention is lagging. Adam Hadley called this the field's central challenge, and Karl closed by urging attendees to hold people in power to account while also helping them do better.
The talks
Karl began by noting that terrorism-related AI safety concerns were largely science fiction when FAR.AI was founded four years ago. Now, he said, news of AI misuse, or near loss of control, is constant. Some red lines set only two years ago have already been crossed or are about to be, including autonomous cyberattacks. He added that frontier labs have kept moving their own goalposts.
Still, Karl argued, there's no reason to feel helpless: many of the tools needed to mitigate these risks already exist. These include testing models before release, filtering dangerous requests, controlling who can access the most capable systems, and establishing content-sharing networks in the counterterrorism community.
Karl called on intelligence agencies to monitor more closely how terrorist groups use AI, on frontier labs to be more transparent and more rigorous about their red lines, and on governments to make collaboration easier. He urged that inaction should not be the default just because responsibility for coordination doesn't sit neatly inside any one organization's mandate.
Deputy Director Siqueira pointed to Tech Against Terrorism's updated benchmark, which tested 160 AI models with about 100,000 requests. Many models gave detailed answers to harmful requests even when users openly declared terrorist intent. He argued that independent testing must be repeated as models evolve, and that its findings must lead to better safeguards.

For the lightning talks, David Scharia noted that terrorist groups have historically been slow to adopt new technologies, but said UN CTED now sees an inflection point, with groups moving from experimental to operational use of AI. The normative framework to respond already exists, he argued, though some tools don't transfer. Hashing, which has historically helped take down known terrorist content on social media, doesn't work for LLMs, since every response is newly generated. He pointed to UNCTED's role in developing GIFCT and Tech Against Terrorism, and offered its support for similar public-private efforts on AI.
Brian Tse cited a field study published in July that found Boko Haram using six frontier models across the attack chain, from operational planning to building explosives, with members also expressing interest in chemical threats. Concordia AI's own testing found several leading models outperforming PhD-level experts at troubleshooting wet-lab protocols, while the worst-performing models complied with more than 95% of malicious prompts. He proposed three steps: universal screening of DNA synthesis orders, clear controls on high-risk data, and shared evaluation standards for red-line scenarios.

Adam Gleave framed the panel discussion by reminding the audience that security safeguards are achievable now: it's a question of implementation, not more research. For example, while developing FAR.AI's AI Security Leaderboard, the team found hundreds of universal jailbreaks for Google's Gemini and SpacexAI's Grok, both costing under $300. Grok has since moved from last to third place, and Adam expects Google to ship improved safeguards.
Adam noted that safeguards can't be "bolted on" at the last minute. Anthropic and OpenAI have reasonably well-defended models because they started years before it was required, iterating with third-party red teamers.
“Safeguards should be "battle-tested by the time we need it."
Adam also argued that threat models need to be better aligned. An issue that one company considers catastrophic could be considered moderate by another, and governments, and even different agencies within them, disagree. The result is a "mosaic" of safeguards that's easy to route around. Adam expects abliterated models (ones that are modified to dampen their learned refusal direction while preserving the rest of its reasoning, language, and tool-use capability as much as possible) with advanced capabilities within six to 12 months. These are open-weight models whose refusal behavior has been stripped out by directly editing their weights, a cheap process that needs no retraining. He called for quick action and warned against waiting for an incident before acting.
Adam shared four specific recommendations to mitigate these risks:
- Proprietary developers should implement the state-of-the-art safeguards that already exist.
- Open-weight developers should start experimenting with pre-training data filtering: removing the small fraction of training data that covers topics like weaponizing anthrax. A model that never learns this can't share it, even with its guardrails stripped away. FAR.AI is working to bring this to production with one open-weight developer.
- Export controls need updating for AI. These controls can block useful safety collaboration, such as sharing CBRNE threat models with Chinese developers so that they can prevent misuse.
- Governments should create a secure incident-reporting mechanism for AI misuse, similar to the one announced for loss of control.
In the discussion that followed, panelists agreed that threats are converging and accelerating. Misuse, radicalization, and loss of control are becoming intertwined. Adam Hadley named agentic AI in the hands of hostile states as his top concern, since most terrorist groups are slow to adopt new technology. Paul Ash added that AI shapes intent. Radicalization through sycophantic chatbots and AI companions, especially among young people, is an important population-level risk alongside weapons uplift.
All agreed that abliterated models are the weak link. Adam Hadley noted that the leading models, open or closed, American or Chinese, have reasonable guardrails, but abliterated versions are freely available online and undermine everyone's efforts. Minimal security standards can be met today. The gaps come from inconsistent effort and misaligned threat models.
The panel closed with priorities for the international community:
- Safety benchmarks need to become a competitive standard. The panel welcomed recent benchmarks from FAR.AI and Tech Against Terrorism, as well as the Christchurch Call Foundation's forthcoming benchmark for chatbots and AI companions. They called for more, so that safety scores matter to developers, investors, and policymakers.
- Information sharing needs dedicated infrastructure: secure, trusted mechanisms for governments, AI developers, and the counterterrorism community to share threat intelligence and misuse incidents.
- Risk communication needs to happen before a major attack. The field must make the case to policymakers without advertising vulnerabilities to bad actors. Existing sanctions and material-support laws, and multistakeholder models like the Christchurch Call, offer feasible approaches.
Looking ahead
A series of public and closed-door convenings in the coming months will build on these shared priorities and safety standards to mitigate known and emerging risks. We'll share new research findings and recommendations as the conversations develop.
We frequently publish new research and host events like this around the world. Stay in touch for new publications and event invites:
- Subscribe to our newsletter for updates on our work
- Follow us on X and LinkedIn
- Explore our AI Security Leaderboard to see how frontier AI models stack up against CBRNE and cyber threats
You can watch all the talks from this event on our YouTube channel.
