据报道,自2023年以来,ISIS一直在提供提示词工程和越狱训练,并已培训尼日利亚的博科圣地指挥官如何绕过AI安全过滤器。
根据剑桥大学AI科学与政策项目(CASP)研究员Antonia Jülich的一项新研究,博科圣地如今正在使用ChatGPT、Claude、Gemini、Grok、Meta AI和DeepSeek等流行AI聊天机器人,其两个派系均已设立专门的AI部门。Jülich对该组织27名前成员进行了57次访谈。
研究发现,该组织将AI用于攻击策划、制造威力更强的爆炸装置、武器维护以及行动安全。ISIS联络员培训了指挥官如何绕过安全过滤器。博科圣地的两个派系都建立了自己的专门AI部门。据Jülich称,他们“把顶尖人员召集到一个房间里,用投影仪在大屏幕上展示其运作方式。”
在一个特别极端的案例中,ISWAP派系利用AI复制电影中的摩托车跳跃技巧,以便武装分子能够越过战壕。训练过程中有18名武装分子死亡,8人成功完成跳跃。

当然,事情并不仅限于摩托车特技。“前成员描述了对AI的强烈热情,一些人表示该组织此前曾考虑过大规模杀伤性武器,”Jülich写道。“尽管博科圣地对AI的使用仍属常规范畴,但这应作为一个警示,必须认真对待恐怖分子寻求AI协助制造化学和生物武器的风险。”
研究人员以及OpenAI和Anthropic等AI实验室长期以来一直警告,AI模型可能使危险知识更易获取。但该研究发现,安全过滤器未能可靠地防止滥用,这表明自愿性的自我监管显然不够。这或许正是大语言模型的天性:Anthropic最近承认,越狱攻击可能永远无法被彻底消除。
研究人员还指出,像 ChatGPT 和 Claude 这样的聊天机器人虽然吸引了公众的大部分注意力,但并非真正的隐患,因为它们主要只是让现有知识更容易被获取,而非生成任何新内容。更大的担忧在于,生命科学领域更专业的 AI 系统可能遭到滥用。
ISIS has reportedly been offering prompt engineering and jailbreak training since 2023 and has trained Boko Haram commanders in Nigeria on how to bypass AI safety filters.
Boko Haram now uses popular AI chatbots like ChatGPT, Claude, Gemini, Grok, Meta AI, and DeepSeek, and both of its factions have set up dedicated AI units, according to a new study by researcher Antonia Jülich of the Cambridge Programme on AI Science & Policy (CASP). Jülich conducted 57 interviews with 27 former members of the group.
The group uses AI for attack planning, building more powerful explosive devices, weapons maintenance, and operational security, the study found. ISIS liaisons trained commanders on how to bypass safety filters. Both Boko Haram factions set up their own dedicated AI units. According to Jülich, they "assembled the top people in a room and used a projector to show how it works on a big screen."
In one particularly wild case, the ISWAP faction used AI to replicate motorcycle jumping techniques from a movie so fighters could clear trenches. Eighteen fighters died during training. Eight made the jump.

But of course, it doesn't stop at motorcycle stunts. "Former members described strong enthusiasm for AI, and some said the group had previously considered mass-casualty weapons," Juelich writes. "Though Boko Haram's use of AI remains conventional, this should be a warning to take seriously the risk of terrorists pursuing AI assistance for chemical and biological weapons."
Researchers as well as AI labs like OpenAI and Anthropic have long warned that AI models could make dangerous knowledge more accessible. But voluntary self-regulation apparently isn't cutting it, as the study found that safety filters failed to reliably prevent misuse. That may just be the nature of large language models: Anthropic recently admitted that jailbreaks will likely never be fully eliminated.
Researchers also point out that chatbots like ChatGPT and Claude, while they've grabbed most of the public's attention, aren't the real concern, because they mostly just make existing knowledge easier to find rather than generating anything new. The bigger worry is the potential misuse of more specialized AI systems in the life sciences.