A Cambridge University researcher named Antonia Juelich spent a year conducting face-to-face interviews with 27 former members of Boko Haram in northeast Nigeria. Her study, published by the Cambridge Programme on AI Science and Policy, is the first of its kind: a field-based account of how an active terrorist organisation has adopted AI not for propaganda, but for practical battlefield use.
The findings are specific. Both major Boko Haram factions set up their own dedicated AI units. These teams queried chatbots, turned the answers into advice, and trained commanders. They managed paid subscriptions across several platforms, with logistical help from Islamic State contacts outside Nigeria. Access was tightly controlled inside the group.
The tools they used were not obscure. Former members named ChatGPT, Claude, Gemini, Grok, Meta AI, and DeepSeek. The group used them to design explosive devices, identify seized military equipment, troubleshoot weapons, and plan attacks. In one documented case, fighters used a chatbot to modify motorcycles for jumping over defensive trenches, after seeing the technique in a film. Eighteen fighters died during training. Eight made the jump successfully.
Isis had been offering training in how to bypass AI safety filters since 2023. Boko Haram commanders learned those techniques and applied them. The safety systems built by AI companies to prevent this kind of misuse did not hold reliably. This is not a new finding in isolation: separate research has shown that safety filters fail to block harmful prompts roughly half the time, depending on how the request is phrased.
Anthropic, when forced to respond to a US government demand for completely jailbreak-proof AI, stated plainly that perfect jailbreak resistance is not currently possible. Security experts across the industry agree. The reason is structural: these AI systems are designed to understand and respond to open-ended human language, which means there will always be some phrasing, framing, or sequence of questions that gets around a filter. Improving the filters reduces the risk; it does not eliminate it.
The Cambridge study is careful about scope. What Boko Haram is actually doing with AI is still conventional: getting information that already exists, faster and more easily. Mainstream chatbots mostly make existing knowledge more accessible. They do not generate genuinely new dangerous knowledge on their own.
The bigger concern, raised by biosecurity researchers and confirmed by internal safety assessments at both OpenAI and Anthropic, is a different category of AI tool entirely. Specialised models built for biology and chemistry research are moving fast. One AI model designed for drug discovery was redirected in a research setting and generated 40,000 potentially toxic molecules within six hours. Separate AI systems can now troubleshoot laboratory protocols better than 94 percent of tested virology experts.
For most business operators, the immediate practical impact of the Cambridge study is indirect. It confirms that the safety filters on AI tools they are already using have real limits, and that those limits are known and exploited by motivated actors. It also makes government regulation of AI more likely, and more urgent, in ways that will affect how companies are allowed to deploy and customise these tools. The Boko Haram study is not an isolated data point. It is evidence that real-world misuse is already happening, at an organised scale, with tools that cost nothing extra to access.