Government and industry leaders alike increasingly employ frameworks to assess and mitigate notable AI risks. These frameworks heavily index on categories of “catastrophic” risk, which the Center for AI Safety defines as “ways in which powerful AIs could bring about catastrophic events with devastating consequences for vast numbers of people.” For example, AI labs focus on risks from malicious use of chemical, biological, radiological, nuclear, and high-yield explosives (CBRNE), and cyber capabilities, or rogue AI actions such as power-seeking or deception; yet they underrepresent threats from terrorist exploitation. Since at least 2023, terrorists have utilised AI for recruitment and attack planning across operational and ideological boundaries; groups have repeatedly exploited frontier AI models and AI-assisted technology, with findings from Tech against Terrorism and the University of Cambridge indicating that the Islamic State (IS) and Boko Haram have promoted the use of AI to assist in propaganda, attack planning, explosive design, or weapons troubleshooting, while individuals have employed chat bots to generate attack fantasies, manifestos and operational assistance. The clear distinction between terrorism and malicious CBRNE use means that more precise solutions are necessary.
This Insight will examine existing government and industry frameworks in Western contexts and argue that there is little to no integrated threat assessment regarding terrorist use of frontier AI models. It will discuss selected cases of extremists utilising AI tools since 2023, then assess current government and industry approaches to assessing and mitigating threats from terrorism and violent extremism (TVE). The piece will then explore cross-sector gaps in assessing TVE risk, including lack of formal preparedness frameworks, benchmarks, evaluations, and updated provenance tools. Additionally, it will propose that clear risk frameworks around terrorist use of AI include 1) red teaming exercises with information sharing components, 2) establishment of a dedicated threat intelligence pipeline for terrorist AI exploitation, and 3) dedicated governance roles and funding in key jurisdictions.
Government and Industry Frameworks
Both governments and AI labs show strong adaptation to these catastrophic AI risks in areas such as cybersecurity and CBRNE uplift, or loss of control; however, the explicit inclusion of terrorist exploitation of generative AI remains inconsistent across these actors. Despite documented threats and incidents, some terrorism scholars have suggested that terrorist adoption of AI remains largely ad hoc and experimental, and an overstated risk that does not meaningfully increase terrorist activities. However, recent research suggests that AI serves as a force multiplier for terrorist groups, creating dangerous uplift towards their efforts, and that terrorists’ use of AI for recruitment and planning is a current, operationalised threat. Accordingly, strong governance is needed to address this threat nexus between generative AI and the enduring threat of TVE in the same way that CBRNE threats are directly considered.
The United Nations Office of Counter-Terrorism (UNOCT) stands alone in having published a guide on AI and Preventing and Countering Violent Extremism (P/CVE). This guide reflects notable progress as a UN system output dedicated to this threat nexus, mapping extremist misuse and equipping practitioners with risk assessment tools (such as a templated “AI Risk assessment for PCVE”). Yet it constitutes voluntary, practitioner-facing guidance and does not place any risk assessment obligations on AI model developers.
Meanwhile, the EU AI Act’s General Code of Practice spells out CBRNE, cyber, loss of control, and harmful manipulation as systemic risks, but terrorist use of AI is not distinctly mentioned as a risk category. The UK AI Security Institute (AISI) similarly names criminal misuse as a risk area for its red teaming evaluations without explicitly naming TVE. In the United States, the National Institute of Standards and Technology’s Artificial Intelligence Risk Framework does not mention terrorism or radicalisation from violent content, while a proposed “Generative AI Terrorism Risk Assessment Act” would require the Office of the Director of National Intelligence to submit annual terrorism AI risk assessments to Congress for six years in consultation with the Department of Homeland Security. Even if enacted, this Act would only monitor threats, not govern AI models themselves, as there are no evaluation, benchmarking, or threat mitigation obligations placed on model developers. Of all the above-mentioned institutions, only the EU AI Office holds any real enforcement power online, including compelling model providers to grant model access and face significant fines. Even then, TVE is not a specific AI risk it governs.
The tech industry itself, including firms with major AI products, has established frameworks to govern terrorist use of their technologies, including through testing agreements or coalitions like the Global Internet Forum to Counter Terrorism (GIFCT). Microsoft has established further agreements with both the UK AISI and the U.S.-based Center for AI Standards and Innovation (CAISI) to conduct frontier model testing in TVE-adjacent areas such as criminal misuse; these agreements do not appear to include extremism as a distinct threat. While Microsoft is a founding member of GIFCT and maintains dedicated processes for detecting and escalating violent extremist content, including participation in GIFCT incident responses, TVE is not identified as a standalone category in particular frontier-model frameworks.
AI labs, for their part, have introduced rigorous frameworks to govern catastrophic risks, including through limited-access partner programmes, bug bounty programmes, and continuous red teaming. They also engage with TVE risk through system cards, coalition-based commitments (such as GIFCT), and usage policies. OpenAI’s GPT 5.5 system card indicates extremism is a disallowed content benchmark category, and Anthropic’s Mythos 5 and Fable 5 note extremism was a red teaming scenario, although Gemini 3.5-Flash’s system card does not contain similar language (and neither OpenAI nor Anthropic define extremism in these system cards). Furthermore, nearly all the AI labs or their parent tech companies have joined GIFCT, working together to counter terrorist exploitation of advanced technologies – including frontier models – such as through the GIFCT AI Working Group. Anthropic, Google, and OpenAI also address TVE through brief statements in their usage policies prohibiting use of their tools for terrorist activities.
There is some government-level input into industry frameworks: The EU requires platforms to remove terrorist content one hour after being alerted by the authorities, and the UK Online Safety Act requires platforms to remove terrorist content. Some countries, such as Sri Lanka and Russia, have also restricted access to major technology platforms over alleged misinformation regarding terrorist attacks, or support for TVE. In terms of stronger measures, such as export controls, the United States and EU member states both allow for export controls on technologies that could empower terrorist actors. To date, however, there are no publicly documented cases of these controls being imposed on AI models, a notable contrast to the export controls temporarily imposed on Anthropic over Fable 5 and Mythos 5 in June 2026.
These private sector inclusions are also beneficial insofar as they increase public-private collaboration around the assessment of TVE threats, or the pursuit of specific mitigations of content promoting terrorism. Yet none of the three major frontier AI labs’ risk frameworks (OpenAI’s Preparedness Framework; Anthropic’s Responsible Scaling Policy; and Google DeepMind’s Frontier Safety framework) treat TVE as a distinct risk area, although OpenAI’s Framework does mention terrorists as distinct threat actors under CBRNE threats. Given AI’s potential as a force multiplier for terrorist groups, from propaganda and financial operations to cyber and physical attack capabilities, a more robust approach to AI TVE risk may be needed.
| Model Provider | TVE in System Cards? | TVE as Distinct Risk Area? |
| OpenAI | ✓ | ❌ |
| Anthropic | ✓ | ❌ |
| Google DeepMind | ❌ | ❌ |
Table 1: Comparison of System Card and Risk Framework Treatment of TVE (Author’s Analysis)
The Cross-Sector TVE Gap
Several common gaps emerge when comparing AI governance frameworks from the perspective of TVE threats across the public and private sectors. First, at a high level, there is a lack of formal, documented risk preparedness around TVE in AI governance frameworks, for AI labs and governments alike, which raises questions about the level of relevant institutionalised threat assessment and mitigation. This is important given that terrorism is connected to multiple AI risk areas, including CBRNE uplift, cyberattacks, and information manipulation.
Second, benchmarks and evaluations, including publicly reported red-teaming exercises, focus heavily on catastrophic risks or on vulnerable user testing (sycophancy, information manipulation). Until very recently, with the announcement of Tech against Terrorism’s Counter-Terrorism AI (CT-AI) Benchmark on July 2, there was no AI benchmark specifically focusing on TVE. Two publicly known benchmark and red teaming exercises focused on terrorism are both academic and non-recurring: the first being West Point’s 2024 “Generating Terror” which analysed 2,250 TVE-related requests across five platforms via direct and indirect prompting; and the second example of “XGuard” (Abishethvarman et al., 2025), a benchmark drawing from social media and news data to test 3,840 red-teaming prompts across recruitment, tactical advice, propaganda, and attack instructions. Both studies found that safeguards failed at meaningful rates, across different attack types and severity levels, suggesting that TVE AI risk assessment and mitigation require robust, multi-factor benchmarking and evaluation. A third red teaming exercise, conducted by generative AI trust and safety firm Alice in February 2026, probed frontier models for CBRNE uplift risks by lone actors, finding that operational guidance was repeatedly elicited via non-technical jailbreaking.
And third, existing counter-terrorism (CT) tooling, such as the GIFCT’s Hash Sharing Database (HSDB), maintains a legacy focus on content artefacts but not model misuse signatures and remains vulnerable to synthetic media that can evade hash sharing systems. Weakened tooling results in provenance gaps, reducing the ability of government and industry alike to trace terrorist use of synthetic media, with broader damage to counter-terrorism operations.
Recommendations for Closing the TVE AI Governance Gap
Over several decades, the international community has developed an appropriately sophisticated, albeit imperfect, understanding of the terrorism ecosystem. Effective CT planning and operations do not address terrorist attacks in a vacuum, but lean on a multidisciplinary, cross-sector understanding of the factors, including radicalisation, militant group activities, socioeconomic grievances, and under-governed spaces. Such an approach has benefited efforts to contain extremist movements around the globe.
Ideal approaches to AI frameworks around TVE risk should mimic this level of complexity and rigour. Three specific recommendations may be worthy of prioritisation as a starting position.
- Regular red teaming exercises specifically focused on terrorist exploitation of frontier generative AI models. Such red teaming exercises could occur in phases, comprise subject matter experts both internal and external to AI labs, and include formalised collaboration. Information sharing and connection between governments, international governmental organisations, AI labs or tech companies, and PCVE practitioners should be arranged. These red teaming exercises, perhaps facilitated with the help of the GIFCT Red Team Working Group, Tech against Terrorism’s planned red teaming process (first outlined in 2023), or the UK AISI, could lead to the publication of both public and private evaluations to further increase transparency around AI governance, indicate a clear priority on TVE as a risk area, and safeguard findings critical to national security.
- The establishment of a dedicated threat intelligence pipeline for terrorist AI exploitation. This pipeline – potentially modelled on the ISAC collect-validate-disseminate cycle with platform, AI lab and government inputs informing analysis fed back to relevant stakeholders – could comprise part of GIFCT, utilising its existing infrastructure for TVE risk assessment, analysis, and mitigation, while adding components critical to and focused on generative AI. However, it would necessarily expand CT tooling beyond legacy hash sharing to include jailbreak patterns, model misuse signatures, or other provenance tools pertinent to synthetic media attacks. Frontier labs and their safety teams could be critical stakeholders in the pipeline, along with government AI security institutes such as UK AISI and CAISI, or established threat intelligence trackers such as the AI Incident Database or MIT’s AI Incident Tracker.
- Introducing dedicated governance roles and funding in key jurisdictions. This would necessarily include national and regional bodies with major influence over international AI safety and governance, such as CAISI, UK AISI, the EU AI Office, the China AI Safety & Development Association (CnAISDA), and institutes in other AI “Middle Powers” such as India, Brazil, South Korea, Japan, Germany, and Australia. Within these bodies, units for TVE AI risk assessments should be established, with personnel responsible for governance, red teaming, and benchmarking, and with continuous funding in place to support their work, preferably as part of permanent programmes rather than legislative riders vulnerable to political shifts. Two existing bodies that may provide a model for such governance and funding include Europol’s EU Internet Referral Unit and the United Nations Interregional Crime and Justice Research Institute (UNICRI) Centre for AI and Robotics.
Conclusion
TVE remains a complex area for AI risk assessment. It continues to play a clear part in operational recruitment or attack planning for terrorist groups, sympathisers, and individuals across the ideological spectrum. Yet notable gaps remain in governance, evaluation, and tooling to explicitly address AI risk from TVE distinctly from other threat types, in part due to debates over the extent and severity of its use by terrorist actors. Existing AI governance frameworks clearly assess factors influencing terrorism, as well as related dangerous outcomes such as CBRNE uplift or cybercrime, yet they do not formally recognise and assess TVE as a risk itself within frontier model governance and evaluation frameworks. Red teaming exercises likewise underemphasise it as a risk area, and CT tooling, such as legacy hashing, is vulnerable to current synthetic media techniques. Dedicated red-teaming exercises, threat intelligence, and organisational capacity building can help close these gaps, thereby furthering public and private interventions to mitigate the nexus between generative AI and TVE.
—
Nathan Heath is an AI safety executive and decision scientist with over 14 years of experience across risk assessment, geopolitics, and AI safety. He currently serves as the Founder & CEO of Syntony, an AI safety startup translating red teaming evaluations into good governance. He is also the Co-Founder of The AIHL Project, a research initiative focused on assessing generative AI threats to protections under international humanitarian law. Nathan consults as a red teamer for OpenAI and Anthropic, and previously spent 6 years supporting the U.S. Department of Defense in areas such as emerging technology risk, security cooperation, and countering violent extremism. He received his M.A. in Law and Diplomacy from The Fletcher School.
—
Are you a tech company interested in strengthening your capacity to counter terrorist and violent extremist activity online? Apply for GIFCT membership to join over 30 other tech platforms working together to prevent terrorists and violent extremists from exploiting online platforms by leveraging technology, expertise, and cross-sector partnerships.