How Terrorist Groups Use AI, and What It Means for Financing

TRM Team

TRM User Conference

Which mission will you select?

REGISTER NOW
November 2-3, 2026
Washington, D.C.
How Terrorist Groups Use AI, and What It Means for Financing

Terrorist groups are using generative AI to produce and disseminate propaganda, recruit new members, and plan attacks.

The Islamic State has run AI-generated news anchors since 2024. Attackers in Las Vegas and Palm Springs used chatbots to research explosives. ISIS affiliates in Nigeria also used chatbots for bomb making and planning. And a cell in Houthi-controlled Yemen spent nine months this year using Claude to help design guided missiles before Anthropic shut it down.

However, when it comes to terrorist financing, the picture is different. Terrorist groups raise money through charities and crowdfunding; hawala and cash couriers; fraud; trade; and increasingly digital channels, as TRM described in its report on terrorist financing 25 years after 9/11.

TRM places AI in terrorist financing at the Horizon phase of its AI-enabled crime framework, where its use is expected and has yet to be detected.

ISIS supporters’ guidance on using AI

Over the last few years, ISIS supporters have increasingly discussed the safe use of AI on various messaging and social media platforms. For example, in a Russian-language channel frequented by ISIS supporters, a user recently posted a message soliciting advice on the safest way to use AI. The user had already decided to use AI; he now wanted to know how to do it without being identified.

Islamic State supporter media has been answering that question for years. In August 2023, Qimam Electronic Foundation, the pro-ISIS media unit focused on operational security, published guidance on using ChatGPT safely.

Tech Against Terrorism found more than 5,000 pieces of AI-generated content in extremist spaces the same year. In April 2025, the same outlet released a bilingual guide to AI tools and their risks. By September 2025 it was recommending a specific privacy-focused assistant and telling supporters to disable chat history and turn on two-factor authentication. The Islamic State Khorasan Province's magazine, Voice of Khurasan, even ran its own section on AI safety in February 2026. The UN Secretary-General's August 2025 report on the ISIL threat recorded that "guidance had previously been issued by Da'esh to its supporters on using generative artificial intelligence tools without being detected."

Use of AI in propaganda

The best known case followed the March 2024 Crocus City Hall attack outside Moscow, when Islamic State supporters distributed a video news bulletin claiming the attack, read by an AI-generated presenter. The Washington Post later reported on the program behind it, which uses text-to-speech and video generation to produce bulletins in a broadcast format. Notably, the use of AI to create propaganda has drawn criticism from some ISIS supporters who objected, on religious grounds, to depicting the human form.

Translation has had a wider effect than video. The UN Monitoring Team reported in February 2026 that groups were "increasingly adept at seamlessly integrating artificial intelligence tools and visual effects into their efforts to radicalize and recruit." The same report noted that AI-enhanced translation let them "quickly reach audiences in multiple languages." While not all the result of AI, ISIS supporters produce content in over a dozen languages. Europol's 2025 terrorism situation report found AI-generated propaganda at "unprecedented levels, especially in the right-wing scene," and recorded that extremists were jailbreaking mainstream chatbots to get past moderation. Translation is the capability that bears most directly on fundraising, because a donation appeal only works in the donor's language.

How AI is used for attack planning and weapons

After the January 1, 2025 Cybertruck explosion outside the Trump International Hotel in Las Vegas, Sheriff Kevin McMahill said the attacker had used ChatGPT to research how much explosive he needed, where to buy fireworks, and how to buy a phone without identification. He called it the first such case he knew of on US soil. In June 2025, the FBI said the suspects in the Palm Springs fertility clinic bombing had used a generative AI chat program to ask about ammonium nitrate. Cases followed in Finland, Austria, and Canada, where OpenAI disclosed after the February 2026 Tumbler Ridge shooting that it had banned the shooter's account eight months earlier without telling police. Tech Against Terrorism now counts more than 30 public cases across more than 11 tools, linked to more than 70 deaths.

Terrorist groups are using AI tools as well. A 2026 Cambridge study based on 57 interviews with former Boko Haram and Islamic State West Africa Province (ISWAP) members reports that both factions set up AI cells with designated prompt engineers and used every major chatbot for explosives engineering, weapons troubleshooting, operational security, and tactics. It’s a single interview-based study which still needs corroboration from governments — but it’s consistent with the UN Monitoring Team's finding in February 2026 that al-Shabaab is using AI alongside encrypted messaging and satellite phones to protect its operations.

Most recently, on September 11, 2026, Anthropic disclosed that a cell in Houthi-controlled northern Yemen had spent nine months, from December 2025 to August 2026, using Claude to support guided weapons development. The projects included a guided rocket built around a commercial flight computer, a multistage ballistic missile with a range over 2,000 kilometers, and a hypersonic glide vehicle program. The users had the model write guidance, navigation, and control software. They hid the purpose of the work, split it across separate sessions so that no single conversation showed the full picture, then ran multiple AI instances with assigned roles as coder, researcher, and reviewer. Anthropic banned the accounts and shared what it found with governments and industry. The company said the cell never fielded a working device but "did carry out a failed test of a guided rocket." By the time the accounts were closed, the cell had built an offline simulation toolkit that no longer needed the model.

The Houthis, who just took control of the Bab al-Mandab strait, are a US-designated foreign terrorist organization backed by Iran with a record of attacks on commercial shipping. This appears to be the first public case of a designated terrorist group using a frontier AI model over months for weapons engineering. The tradecraft the cell used is the tradecraft the supporter guides teach. The offline toolkit is the detail with the longest consequences, because the ban came after the knowledge was already out. Notably, the Houthis have used cryptocurrency to purchase dual use goods used in UAV and counter-UAV components, from Chinese suppliers.

The safeguards have now been tested directly. Tech Against Terrorism's CT-AI Benchmark, released in July 2026, ran 27 models against roughly 2,500 prompts drawn from real terrorist use cases. About a third of responses gave usable help beyond a web search. Open-weight models with safety training removed complied with 89 to 100 percent of requests. The Combating Terrorism Center at West Point found that removing those safeguards from a large model costs under USD 200 in compute.

The impact of AI on terrorism financing

Terrorist financing has changed more in the past five years than in the twenty before them. TRM's report marking 25 years since 9/11 traces the shift from the cash and hawala networks that funded the 2001 attacks for roughly USD 500,000 to a hybrid model in which digital fundraising, online charities, and small-dollar donations sit on top of the informal systems that remain.

The methods that dominate today are the ones AI is best suited to accelerate. Groups solicit donors in many languages across encrypted channels. They run charity fronts that depend on convincing appeals and plausible documentation. They open accounts at regulated institutions with forged or borrowed identities. US prosecutors have unwound sham Gaza charities on GoFundMe, Chuffed, and Fundly that routed between USD 30,000 and USD 116,000 to designated members of Hamas and Palestinian Islamic Jihad, each built on a fundraising narrative, a set of identity documents, and a payment account.

Generative AI has played little visible role in that activity so far. The FATF report contains no substantive AI analysis. OFAC has yet to cite AI in a terrorism designation. And FinCEN's AI alerts — including its November 2024 deepfake alert on AI-generated identity documents defeating customer verification — address fraud.

What regulators have produced are scenarios. The FATF's January 2026 Horizon Scan on AI and Deepfakes calls AI "a powerful new tool for money launderers, terrorist financiers and sanctions evaders." It describes AI agents moving money "through a series of accounts when risk is lowest" and an AI advisor that compiles "weak-jurisdiction strategies for evading targeted financial sanctions." A July 2026 CSIS analysis lists "synthetic identities, forged documents, fake charities, fabricated humanitarian appeals, and persuasive online scams" as the financing use cases AI makes cheaper. Those scenarios are useful, but they remain scenarios. TRM's own assessment in the 9/11 report is that the limited uptake so far reflects incentive timing more than any capability gap.

There are reasons the money has lagged: The sums are small, so automating them pays little. The fundraising runs on trust and ideology more than on production quality. And the groups have working methods that predate AI, so the marginal gain from a chatbot is lower for a fundraiser than for a propagandist or weapons engineer.

But those conditions are changing. Islamic State affiliates across Africa are financing weapons and drones at growing volume. Translation, the one AI capability the UN has already documented in propaganda, is exactly what a multilingual donation campaign requires. Synthetic identity documents that defeat onboarding at banks, payment platforms, and exchanges are for sale in fraud markets now.

How AI is used in counter-terrorism

Law enforcement is deploying the same technology against terrorist groups. On September 18, 2026, INTERPOL announced the results of Operation Shams II, a five-day exercise in Tunis in June that brought together 28 officers and analysts from eleven countries, including Nigeria, Iraq, Kenya, Malaysia, the Philippines, Qatar, Tajikistan, and Uzbekistan. The team used AI agents and AI-generated scripts to extract 108,076 facial images from jihadist propaganda, deduplicated them to 6,362 unique high-quality faces, then ran those through INTERPOL's facial recognition system with human verification at each step.

The operation identified 126 foreign terrorist fighters, with leads already feeding judicial proceedings in participating countries, including one case with two suspects in custody. The same operation used cryptocurrency tracing tools to generate three urgent requests to a virtual asset service provider for customer data in support of terrorist financing disruption.

INTERPOL's director of counter-terrorism, María Carmen Muñoz González, described the result as demonstrating "the value of combining international law enforcement cooperation with responsible AI-assisted analytical capabilities." The propaganda that groups produce at scale with AI is the same material that AI now processes at scale to identify the people in it.

Conclusion: The landscape is changing quickly

Terrorist use of generative AI has moved from propaganda to attack planning to weapons engineering — all in under three years. The Houthi case shows that a designated group can run a disciplined AI operation for months, conceal it from the provider, then walk away with the knowledge before the accounts are closed.

Financing is the one area where AI has yet to proliferate. The groups already have working fundraising methods built on appeals, identities, and accounts; so the first AI uses on the money side will be quiet ones such as multilingual appeals, synthetic identity documents, and automated fragmentation of donations. None of those announces itself as AI, so the thin record should be read with caution.

However, AI innovation continues to accelerate and terrorist financiers and operators are always looking for ways to increase speed and scale. While AI in terrorist financing is still at the Horizon phase today, that could change at machine speed.

{{horizontal-line}}

Frequently asked questions (FAQs)

1. How are terrorist groups using AI?

Terrorist groups use generative AI mostly for propaganda, recruitment, attack planning, and weapons development. The Islamic State has run AI-generated news anchors since 2024. Attackers in Las Vegas and Palm Springs used chatbots to research explosives. In 2026, Anthropic disclosed that a cell in Houthi-controlled Yemen had spent nine months using Claude to help design guided missiles.

2. Are terrorist groups using AI to raise money?

There's no public evidence yet of terrorist groups using AI at scale to raise money. FATF, OFAC, and FinCEN have yet to document an AI-enabled terrorist financing case. TRM places AI in terrorist financing at the Horizon phase of its AI-enabled crime framework.

3. Why hasn't AI shown up in terrorist financing yet?

The sums involved are small, so automating them pays off less. Fundraising depends more on trust and ideology than on polished content. And groups already have methods that work, like charities, crowdfunding, hawala, and cash couriers. So a chatbot adds less for a fundraiser than for a propagandist or a weapons engineer.

4. How could AI change terrorist financing?

The likeliest early uses could include donation appeals in many languages, synthetic identity documents that get past onboarding at banks and crypto exchanges, and donations broken up automatically into small amounts. The FATF's January 2026 Horizon Scan calls AI "a powerful new tool for money launderers, terrorist financiers, and sanctions evaders." None of these uses would be obvious as AI, which makes them harder to spot.

5. What did Anthropic find about the Houthis using Claude?

On September 11, 2026, Anthropic disclosed that a cell in Houthi-controlled northern Yemen used Claude from December 2025 to August 2026 to support guided weapons development. The cell split its work across separate sessions to hide its purpose, and it built an offline simulation toolkit before Anthropic banned the accounts. It appears to be the first public case of a designated terrorist group using a frontier AI model over months for weapons engineering.

6. How do ISIS supporters try to use AI without being detected?

Pro-ISIS media has published guidance on using AI safely since at least August 2023. Qimam Electronic Foundation told supporters to use privacy-focused assistants, turn off chat history, and turn on two-factor authentication. Islamic State Khorasan Province's magazine, Voice of Khurasan, ran its own AI safety section in February 2026.

This is some text inside of a div block.
Subscribe and stay up to date with our insights
No items found.