The Lawfare Podcast
The Lawfare Podcast

Lawfare Daily: How Terrorist Groups are Using Artificial Intelligence

2h ago41:167,004 words
0:000:00

Lawfare Foreign Policy Editor Daniel Byman sits down with Tricia Bacon, professor at American University, and Antonia Juelich, International Security Lead at the Cambridge Programme on AI Science &amp...

Transcript

EN

[MUSIC]

Malay, all the redness of longevity is from longevity. There are no more than our body.

It's the most important thing.

But one can't.

Life is important to minerals themselves.

The minerals are what they want to eat, and it's different. It's the least valuable minerals and natural coal-solid-wild-carnish oil. It's a real craft, a real-life nature. The minerals are. There are sprays, mediums and natural. And if you want to know how many minerals your water has,

just try to get rid of minerals. [MUSIC]

You know what, you know what? I have a mobile connection.

Your whole body is already dead. It's more. [LAUGH] I'm not dead. I'm dead. [LAUGH] Just a ice-traum. With mobile functions in the real life, Frank, a mobile function for 10-year-olds in Monat. Inclusive E.U. roaming.

Also in the Schweiz. [LAUGH] Frank. Nine. Frank. [MUSIC] With Bond and Sir, that program got in-person training from Iceland operatives and every day online

assistance on prompt engineering and jail-breaking. So these companies don't just face isolated users, but really like trained, network, and organized adversaries that share the latest ways to jaybreak models. It's the law fair podcast. I'm Daniel Byman, the foreign policy editor of law fair. And I'm here with Antonio Gjulish of Cambridge and Trisha Bacon of American University.

What I am really interested in seeing whether it's published area or new organizations that form in the AI era, right, organizations that develop processes with AI as a pillar in what they develop, are we going to see them develop capabilities more quickly, more effectively,

more innovative, like how will this affect that's here of terrorist organizations?

Today we're talking about how terrorist groups use artificial intelligence and how governments are using it to fight them. Antonio, I want to begin with you. You just released a major report on how Boko Haram and Nigerian groups in general are using artificial intelligence for our listeners who haven't read it, it's really fantastic. It's groundbreaking research.

Let me start by just asking you a few basic questions. Where and how are these groups using it? What problems are they having? Start with that, please. What I found was that AI has become embedded really as a general purpose technology that can provide information across the full in search and cycles. So by that I mean from assisting with how to prepare attacks, to how to execute them, to how to analyze failures afterwards and learn from them.

Yeah, one could really say it serves as a 24/7 operational assistant to Boko Haram. There were a couple of domains and specific examples that respondents have given me. One, for example,

is getting weapons advice. So how, as many of you know, a lot of these groups

seized the weaponry military equipment generally as by yeah, seeing it from soldiers and by raiding military bases. And so in the past, whenever they got hold of weapons, they were not familiar with. They had to reach out to people in the network, had to wait to hear back from ISIS and other operatives to receive online assistance or to wait for in-person trainers to come help them.

Now the new rule is that whatever you get, you bring it back to the camp. Commanders, type in the sewer number, the model, and this way they learn what type of weapons they have and how to serve this and troubleshoot. That of course makes life much easier. There's less of a delay and just provides instant help. Another area is getting advice on like technical and strategic questions that they have and that ranges from brainstorming new ideas

on how to respond to new counterterrorism measures to getting specific technical input on how to best implement tactics. They set, for example, that they learned how to carry out more effective and better coordinated attacks by deploying smaller units and also one example that has gotten quite a bit of attention is that, for example, they learned how to jump over defensive trenches that the Nigerian military build around their own bases and towns with the motorcycles and that

wasn't obstacle in the past, but them not anymore. Yeah, and one other area that I find quite concerning is that they get a lot of help with how to improve the design of the explosives, so that includes learning what additional chemicals to include that make their own

ideas more powerful on how to diffuse unexploded bombs to extract their military great explosive

Material and repurpose it in their own ideas.

and I can see accuracy, so it really helps them to bridge a lot of the technical gaps that

they have encountered in the past. And what I find quite striking about these use cases was that while we were still discussing the risk of AI generated propaganda and this information bookrum already moved to way past that and understood that AI can do so much more than that. Yeah, what your report makes very clear is the kind of lied in very different ways that both Oklahoma is using it. However, it's a big organization, and you know, I'm a professor at George

on University at work at Think Tank, at your law fair, and every organization I'm going to be polite has its own distinct way of doing things. And often that gets in the way of new technology and innovation,

and I think really every organization is wrestling with the question of how to use AI effectively.

What sort of problems is Boko Haram having with all this? Yeah, that's a good question, and I do

think generally on program, as you say, as other organizations struggle with AI adoption, but also like a lot of like messy and person dynamics that surround any use of technology, they do have a rank-based access policy, which means that only mid-ranking commander and further are allowed to use these models, and to be clear that it's not inconsistent with other policies in terms of accessing the internet, or even having the phones, so they, since they realized a lot of

a lot of incarceration, they don't really trust their foot soldiers, so knowing how capable these models are they only entrust certain people with access to AI? Some of the problems that I saw were less organizations, or they do have AI units that are in charge of prompting, of j-breaking, they are also in charge of cascading that knowledge down the hierarchy to train other people. The problems I saw were technical and some regards, and these are the problems that we face

as well, so they do encounter hallucinations, so basically an accurate information, that's why

they said sometimes we still have to supplement with our brain and we can't just take everything at face value. They also talked about incidents where they apparently followed instructions, and that really backfired where people died during experimentation with explosives. It's at the ampere of that was actually because the information was wrong or an implementation failure, but that is something that they encounter. They also do struggle with refusals,

suspension of accounts, but yeah, I mean struggles, maybe a bit of an overstatement, because there are, there do have their ways around that. And maybe more generally like they see that their main limitation and problem here is that they don't have more technical expertise and more people who are more proficient in using AI, and while they do, as I just mentioned, have their own internet training programs facilitated by Isisling operatives. They are aware

of how capable these models are, and that they could leverage and exploit them even more effectively if they had the expertise in us. Tricia, let me turn to you. You've looked at the Islamic states branch in Afghanistan. You've just returned from work in Somalia. You've assessed a wide range

of terrorist groups. What are you seeing with regard to artificial intelligence?

One of the interesting parts of my trip to Mogadishu recently is it's sort of the inverse of what a lot of terrorism analysts are talking about, and that it's the government that's gaining an advantage through AI. It's happening for some reasons that maybe sort of video-syncratic or unique to Somalia, but it's still an interesting theater to watch for that reason. So, the government has really integrated AI into security and Mogadishu in particular.

So, they've set up these cameras all throughout the city that are able to monitor vehicles, license plates, drivers, and of course, because Alshabaab uses Vehicle Bore and Explosive Bices a lot in Mogadishu. That is really suppressed its ability to do that, and even installed

cameras in businesses where Alshabaab taxes or extorts people. And finally, they have developed

and are about to deploy a Somali language monitoring through AI of social media. And of course, because Somali is like a low penetration language, most content moderation doesn't reach Somali. So, the government is being able to develop this and they show me a demonstration of it, which will also allow them to monitor more of what Alshabaab is putting online in social media. So, at the moment, I would say the government is sort of that jump ahead on the counter-terrorism

front versus Alshabaab. And of course, there's some of it, I don't know all of what Alshabaab is doing,

I think there's two dimensions of this that are making it more difficult for ...

The first is that the U.S. is engaging in not very often talk about extensive air campaign in Somalia,

and the pace of strikes against Alshabaab is unprecedented. And this is a group of U.S. as can be been conducting strikes against for many years. But that air pressure has a suppression effect on technology because the group doesn't want to be detected. So, there is their monitoring use of phones at internet, of course, that's going to be an issue for AI as well. So, there is sort of this confluence of the government gaining this capability while Alshabaab is in

through a more suppressed situation, though that pressure may also cause the group to innovate in ways

that it will turn to AI. And I think that remains to be seen. And I think the second

video-syncratic part of this, which is something you alluded to earlier, Dan, is that new technologies

for mature organizations are not always easy to internalize. And Alshabaab is simultaneously

trying to develop a drone capability that they've learned from the Houthis in recent years. And my understanding is Alshabaab's undertaking sort of a training process to disperse the trainer model, if you will, that the people who work out instruction in Yemen from the Houthis are now training other parts of Alshabaab. And it's really hard to integrate two new technologies at the same time, quite frankly, for any organization. So right now Alshabaab seems like it's a

little bit behind what Antonio described as what is happening in Nigeria. But as I said, I wouldn't bet that that will remain that way. But that's sort of the current snapshot that that is a really

different picture than I think some of the other places we've looked at. And Tonya, let me ask you

Patricia, please chime in. When you listen to the statements of different AI companies, you know,

they talk about the extensive efforts to put guardrails in, to make sure that, you know, you can't just type in, how do I build a supervirus to wipe out humanity? And five minutes later, you know, we're all dead, right? Yet, you know, reading your report listening to what you've said, here you have a very well-known recognized terrorist group using AI, not just for propaganda, as you said, but extensively to improve its ability to use violence. Why are the guardrails working?

Yeah, that's a good question. And there was also one of the pushbacks by companies in response to my report saying, oh, since the period that you studied and to be clear, my interviews cover 2023 throughout 2024 into like early mid 2025, our safeguards have improved. And I'm really glad that some AI companies have really invested in AI safety and have made their systems. And the safeguards, that's better, but there is also not just my report, but a lot of evidence showing that

even the latest models can be J-Broken. So there are some basic approaches like writing prompts in the form of poetry to more sophisticated ways like finding universal J-Breaks, which are reusable keys that succeed on most harmful requests within an entire domain, and that can be shared. And J-Breaks in techniques are shared. That's one of the findings of my report, where respondents said that program got in-person training from Iceland operatives and everyday

online assistance on prompt engineering and J-Breaking. So these companies don't just face isolated users, but really like trained network and organized adversaries that share the latest ways to J-Break models. Another area that I think is not sufficiently talked about is that they exploit differences in safety enforcement across AI models and providers. That means that some systems have more rigorous safeguards than others. And from that follows that if your request

gets refused, you can just pivot to a different model or system. And that's what they are doing. That's

why they have multiple accounts across providers. And this way they can piece together the information that they need. Also compare answers and see which one is most useful. And in other ways that they can decompose tasks, so that's a method that breaks a harmful request into smaller, harmless looking pieces to trick a model's safety failure. So again, while I'm glad that safeguards have improved and at least some companies are really looking into this. There is still a lot

of variation and also unfortunately enough evidence that shows that models are still not safe enough. So it's still can still be broken. And so that's also why the findings, although they don't cover like 2026, are still very relevant. Trisha, what are you seeing on that front? That relies a lot of what you've told us is really about the counterterrorism side of things where the safeguards

Would apply in very different ways.

a different concern when you look at the counterterrorism piece of it, is that when a government

is gaining this kind of AI capability for counterterrorism purposes, it doesn't stay counterterrorism purposes. It becomes a tool of broader political pressure. And that's in fact what's happening. When you can monitor all of these, especially in a resource language like Somali, if you can monitor social media, that doesn't mean you only monitor all Shabbab. If you're tracking cars in moving issue that doesn't mean you're only looking for all Shabbab. And so it also in the counterterrorism

sense, governments like gain this kind of capability to monitor, have incentives to use them in the political sphere as well. And there's back in many guardrails for that on the government side. Especially when you have something like its own social monitoring platform that's small,

there's no companies that are going to be interceding on something like that. So I think on the

government side, the danger is a little bit different, but is perhaps just as serious and a lot of ways in terms of authoritarianism or oppression of democracy and places that are gaining AI capability,

but don't have mature political systems. One of the ironies can be is one of the amazing things

about AI is, of course, it's language translation. And that you can draw data from the world's languages. And obviously there are going to be some glitches on translation, but in my view, it's actually quite striking how good it is, and it's frankly only a better. But as you say, Trisha, that hasn't led to guardrails being quickly translated from one language to another. I don't know what the percentages are for AI companies, but I know back in the day for social media

companies, an overwhelming percentage of their guardrails and content moderation wasn't English. And you had languages like Urdu where you have huge numbers of speakers that had basically no content moderation. It was really, really remarkable. And that's interestingly some initial research that there's much lower levels of refusal and smiley in part because it is sort of low resource language. And some of the guardrails that we hear about may not be occurring in languages

that are not as dominant in English. Interesting. And I can imagine for countries where there are numerous languages spoken by small communities, you could imagine that probably getting getting bigger and bigger. And also interesting enough at the same time when you look at language benchmarks, these models perform really well across a lot of languages. So the case of program they mostly prompted apparently an English and Arabic. But when I checked, even houses goes fairly

high especially on accuracy. So guardrails might not work in the same way. These models are still very capable even if you prompt in a different language. And totally one thing that was striking about your report was your emphasis that it's not just propaganda, right? That there's a lot of weaponization in a literal sense of AI technologies and contrast and what most of the research out there was suggesting. But let's talk about propaganda. How is this shaping how the different

groups both of you study? Our designing propaganda and both in a very kind of literal sense

designing, but also in trying to expand its reach? Yeah, I think this is one of the areas that

has been picked up very quickly and early and that's also where we saw the first analysis of

how the supporters use AI and we saw it getting picked up early on to, as you just mentioned, translate propaganda materials also to feature synthetic presenters, for example in videos. So it's an easy way to reach a wider audience and to target messaging more specifically to particular groups. And I think, yeah, it's just like an easy tool that has therefore been adopted. However, it seemed like at least for a long time. And as case, a bit of an outline, I think that a lot of

unofficial media outlets started using AI way before terrorist groups themselves and it has been widely discussed among online supporters, on online forums. So here we saw apparently controversy among online, do you had a supporters where some said the use of AI is prohibited and unislanded

because it's trained on Western voices and faces? And so that's why the conclusion was that

adoption has been kind of slow. However, yeah, that's not overall what I found and I think there's a big disconnect between what some of these groups present publicly. And there are reasons to

Conceal the use of AI that might be less or less the case for online supporte...

media outlets that post on behalf of some of these groups. To be clear, I think automated,

targeted messaging, off of propaganda at scale to people whose psychological and social profiles suggest that they are susceptible to radicalization is obviously a big concern. And although I don't think we see this yet to the extent that it's possible, fortunately, I do feel like that topic gets somewhat like outside somewhat disproportionate tension when talking about AI risk.

And I think that's because of a couple of factors. One is just data availability because it's

feasible to follow what's happening online and also like fair enough, it's good that we get as much data as possible to understand what these groups use AI for. But then I also do think that it's AI's often a bit misconceived as like a very smart chatbot and the extension of social media. And I think that comparison is a bit flawed and significantly underestimates AI's capability. So while I do think it's an important area to look into and I do think adoption has been

slower than expected among terrorist groups and much more among online supporters and unofficial media outlets. There are use cases that move way beyond the digital sphere and all just not visible online. Frank. Ingrid and him Died present here, Jobs, by which you don't have a lot of people, today, I'm sorry. What's the matter? What's the matter? A lot of people are facing.

Now I'm going to kill you. That's a job for Sponsor Jobs. With real profits, it won't happen.

What one challenge always in the space is a lot of the expertise in the LA community comes from

people who have done really amazing work on looking at how terrorist groups have used social media. But of course, that's a different technology and you're not going to see social media used in the same way to improve your bomb design by 10% and so you have people who are very impressive research

skills but are focused on certain issue areas. And I think that that shapes things and the other

broader problem with anything technology related in that we've seen in the last few years is that a lot of the expertise tends to be among younger people and thus the more established analysts. Unfortunately, myself and this category, the old people are less able sometimes to grasp the wide range of changes that the technology is bringing in. What do you see in this space? I think this is a really interesting question especially when I compare and contrast to organizations.

So if you think about Alshabab on the propaganda front, this is a well-oiled machine, right? This is an organization that was an early adopter on social media and using it robustly. It has

basically four main languages that it does propaganda in with a specific sort of audience regionally.

You know, it's got the extensive swahili, Somalia, of course, Arabic and English. And so it's not an organization that necessarily really needed AI to change what was already working quite well. But as I say, it is under pressure. It is under extensive counterterrorism pressure from the United

States on the the Airstrike side, which does expand into the media side of Alshabab. So I think this

is an area where as the organization grapples with losses, it may reach for AI in order to adapt. But thus far, it's not entirely clear that that has occurred or they'd agree to which that has occurred. When you compare that to the Islamic State, of course, on the Islamic State Province Afghanistan, this is a group of trying to expand, right? It does have its own robust sort of propaganda machinery, but it wants to expand its reach. And so I think that for that reason you see a

reaching for AI more often so we can have new languages that it's creating material in it and it can be sort of building and expanding its footprint in that area. So it's interesting to sort of compare and contrast to relatively mature organizations and how AI might be shaping their use

Based on sort of the degree of their aims as well as their existing capability.

Thank you. I want to kind of switch things over a little bit just a conceptual issue.

There's talk and I think very good gentlemen talk about how AI is revolutionizing everything. But

is this really revolutionary? Is it my question, right? Is it really that AI is making everyone

in the terrorism space, 20% better at the things they do already? So you know, you're building an IDE, your IDE is better, you're better able to identify, I'm explosive, too, extract and design a bare bomb. You're able to improve your ability to penetrate defenses because you have some you'll greater knowledge of your adversary. Or is there something revolutionary going on here? Where like we're going to talk about the AI era in terrorism and counterterrorism in a way that, you know,

people have looked at say, you know, dynamite as a game changer. I think that it is marginally an incremental shift. I think it could be revolutionary, but by and large I think it's more of what you described. And it's not universal. It's 5% 10% improvements in different spheres

among some organizations. So I think that's the hard part right now is sort of really understanding

that landscape where it's making the improvements that Antonio found, for example, versus, you know, groups that are not yet effectively leveraging it in different parts of what they do. Where I think that there's an interesting question that we can't answer yet is a lot of the organizations we're talking about and we're looking at and analyzing are established mature organizations that already have ways of doing some of these activities, right? So that's where we talk about

the 10% improvements or the ability to adapt to what is happening on the counterterrorism front. What I am really interested in seeing whether it's revolutionary or new organizations that are born in the AI era, right? Organizations that develop processes with AI as a pillar in what they develop, are we going to see them develop capabilities more quickly, more effectively, more innovatively, like how will this affect that tier of terrorist organizations is I think the big question for me

about whether AI will truly be revolutionary. Otherwise, I think it's an important capability for

groups to be able to improve and adapt and be more effective, but it's it is more like the 10% maybe 20% sphere that we're talking about versus like a group going from zero to building like a nuclear weapon or something sort of really wild in the scenarios that people talk about. Yeah, for me,

the answer is probably not in either or, but I do see in a way revolution evolution is related.

So as Trisha just said, and I agree, I think for now we mostly see compounding efficiency gains that these groups get across the internal external operations that can lead to an overall more capable organization. Some of that might not be visible even right now, so some of my interviews said that they were able to reduce casualties within their own ranks. That is very hard for us to quantify. And even when we do see groups becoming more powerful, there are lots of

compounding variables, so it's really hard to clearly say that it's because of AI and as Trisha said, it also depends on how capable a group already is and how much they are able to leverage AI and on top of that also AI is more helpful in in some areas than than in others. But to get back to the question, and my answer is that I do see that there is a gradual creeping up of capabilities that is not only in and of itself a reason for concern, but it can also get a group to an

infection point, whether then are able to make a bigger leap. Whether then are able to solve the specific technical problem that they were not able to solve before. For example, respondents told

me that AI played a very crucial role in weaponizing drones and that they experimented with it

for a long time. They also used the internet. They also received foreign assistant, but it was ultimately AI that gave them like a specific answers that helped them to then actually master that capability. And that was not that is not a generally new capability on the battlefield, right? But it was new to iceberg. So when we asked us AI enable new capabilities, the question is what our reference point is? So chemical or biological weapons are not per se, new but it would be a new

capability for most terrorist groups, fortunately. So I do worry a bit that we set the bar for what constitutes a new capability or revolution and implicitly also for when we should be worried or way too high. Let me use that to jump to the doomsday scenario, which is you know we have

Someone uses an advanced artificial intelligence program to design a super vi...

talked about terrorist groups in this context and you know to go into American jargon we could talk

about you know neolistic violent extremists or a range of you know basically angry but smart

individuals who want to do horrible things. In your view how credible is this threat and I'm not asking you to make a prediction. I'm just really asking sometimes when there's a focus on the extreme end you miss a lot of the important in between stuff but conversely like you don't want to be wrong about this one right you want to make sure that if you're you know if you're dismissing it that you're very confident just because the cops go into this are so big and Tony let me start with you

on this one. Yeah as you said we are not there yet. Yeah that's very fortunate and what I try to cover is exactly that operation in the middle room that hasn't received a lot of attention at the

moment however unfortunately I think the scenario you just played out is more credible than many

would assume. It sounds like sci-fi but so did many other scenarios that have happened recently

like models escaping controlled environments or designing new synthetic viruses and yeah ultimately

it's a bit of it comes down to an actress capability to actually build a bi-weapon and their intent and so many AI and bi-security experts and even CEOs of leading AI companies are warning that AI systems could be misused for bioters attacks and studies show that AI already outperforms human experts on relevant biology tasks and that it could be used to design new pandemic capable pathogens and to be clear to build a bi-weapon that still includes manual laboratory work you need.

Physical facilities you will need the right materials and tools but AI is clearly lowering the technical, operational and motivational barriers that have kept bi-weapon attacks out of reach for most actors. On intent I do feel like there is a lot of focus on apocalyptic on the side or cults whereas there are apocalyptic streams in within jihadism and bheat acyda and isis trying to build bi-latico and kamica weapons in the past so I don't think that their intent has

massively changed but it is becoming easier and easier so I do worry sometimes that it's people underestimate how many groups might have an incentive to at least try it and I see kamica weapons to be clear so more realistic scenario at the moment than then bi-weapon but even in my interviews it came out that bi-weapon was somewhat controversial within the leadership that it apparently had been discussed but it seemed out of reach and the contentious part was not that

position but the release and so we should not underestimate the appeal of having a very powerful

weapon like a pullman's nuke that can give you immense leverage and on detection and disruption maybe because that's another factor that comes into this scenario and it ultimately can decide whether attack success or not yeah actors must still evade detention and fly under the radar of law enforcement to do that and there are different ways in which there might be effected by mitigation strategies so a loan individual with very limited resources or technical expertise maybe just

rupted by cutting off access to key materials and information and contrast where funded group

this may be a harder target and maybe more likely to be discouraged by raising the cost of an attack or the odds of getting caught I'm and let that there are proposals on strengthening our defenses and I really hope that government industry is starting to take this more seriously because I certainly do and I worry that what I found where like program already moved way beyond online propaganda and I do have this time gap right and in my report I mean that

covers like what happened basically one and a half years ago so I worry not specifically about program but what capabilities other groups are pursuing or have been pursuing and in the meantime Trisha let me go off your earlier points about counter terrorism Somalia and how the government's using it effectively in anyways against the Shabbat but also more broadly can you talk about how AI might be used by other governments for counter terrorism and how to think about kind of where

it can be productive and in for the more mature democracies you know where there should be

limits I think that is maybe the big question that people aren't talking about enough which is

this is technology that that can be used by governments in ways that go far beyond counter terrorism

Alone and I don't hear as much discussion for example of tech companies about...

governments are going to use especially even when we sort of talk about the spectrum we have monitoring

in the ability to to use that but you also have the ability to be using the systems for

for example targeting and targeting that may or may not have a human piece to it and I think that

people have become concerned that has occurred for example in the United States or in Israel but if you think about places with less guardrails and less capability you you really get into a sphere where the ability for governments to use violence in a systematic way without guardrails and that's not necessarily requiring as much sort of human complicity that we we really do have sort of an in equal and opposite problem on the government side in terms of what AI allows and for

counter terrorism for counter insurgency for war writ large and I think that's actually a much harder solve in some ways because at least in the sphere of like tech companies and terrorist organizations I think of it as the cat and mouse right like the they out some guardrails the

not the violence non-state after showing get around the view out some and like this goes on

in perpetuity in some ways as it does in a lot of spheres and it's a matter who has the advantage of given time in terms of the balance of their ability to use AI but I see a lot less of that kind of discussion and ability for tech companies to sort of even take stands and make demands on the sphere so I am equally sort of concerned on the opposite end of this spectrum and in fairness when we think about the kinds of grievances of these groups are able to exploit AI definitely has the ability

to exacerbate some of those in terms of how government use them and if I could just reach back to your previous question to Antonio what I've been thinking about is select past examples not that this is sort of a common thing that groups try to do but what if omission regio who conducted the seren attacks in Tokyo 1996 had AI what if someone like typeazinski had AI what if I kind of when it had those camps in the 90s and it was you know gassing dogs to experiment with that kind of capability

what if they had AI and those are three examples of hundreds of groups and so I don't think it's a common thing to be concerned about where where individuals or organizations had the intent and had some baseline capability they were going from zero they had scientific capability and then try having AI at it on top of that those are the scenarios that that worry me on this doomed state piece of it and not broadly necessarily concerned by the group like all should

Bob I don't think that's a kind of capability they're seeking that's a kind of capability they need but when you have these select examples that we have seen in the past and what the damage they could have done if they had access to technology today I want to close building on Trisha's points which is kind of the what is to be done question if you were had access to the senior leadership of cat companies, Congress, the US government, pick your audience if you will give us one or two

realistic recommendations you would make about how to reduce the risk of terrorist groups using

this in very dangerous ways and how governments can do better yeah so first of all I do think

this is a really complex problem and governments and companies need to work together on that from a technical point of view I do think that we need minimum safety standards across providers so that a refusal in one place is not simply an invitation to try another one the most robust safeguards of a very little practical security of highly capable and open weight models are freely available right another point and yeah maybe that's also where governments have to come in because

it's unclear whether companies would work together to establish and agree on these minimum standards another area is that companies should test their safeguards against organized trained networked adversaries as I mentioned and should think not only about a risk from maybe isolated users but also these groups that have just different capabilities to to circumvent guardrails

then again I think companies and governments need to establish some information sharing channels

such as an air threat fusion center that combines company and government signals so miss you scattered across these platforms is seen as one pattern rather than isolated

fragments and ultimately I do think that we need more evidence and that that is a role that

were researchers can tip in but also that security agencies should assess how terrorist groups use AI

As well as trace which groups are being trained by a woman and how that exper...

there is a lot more that can be done with them there I see in law enforcement to really monitor

that threat and especially when it comes to potential development of WMDs.

Trisha I think at least in the U.S. government system one of the key things is to have

the bureaucratic structures in place what do I mean by that when we think about for example the organization of our intelligence community we have you know regional focuses functional focuses and what we need to make sure that we have in our system are people who are specifically responsible

for the AI piece of this for understanding because this technology is moving very very quickly

the average terrorism analyst can't keep up with that while also keeping up on the the current groups operations and leadership etc. right so I think we need more structures in place where we have AI expertise within for example our intelligence community that can be the focal point both for doing that analysis and for collaboration with analysts for example who are and who are both analyzing terrorist organizations and you know hostile or government

that are more authoritarian so I think we hope we need an integration of AI expertise into our

and our intelligence community collection analysis so that there is also then be commenced or understanding being given to policymakers of how foreign actors who are a threat to the United States are using this technology and I think that though the US government in particular is on the cutting edge of using AI for example in things like warfare we don't actually have that sort of analytic an expertise base that we need to have in our systems so I think that's a really urgent need and

it's hard to do because that expertise is very valuable right you can make six figures seven figures with that kind of expertise so we're in a situation where we also need to be able to hire people

like that and retain people like that which is is undoubtedly a challenge but is absolutely essential

for sort of this next phase of security. Trisha Bacon and Tonya Jolish thank you very much. Thank you so much. You can get ad free versions of this and other law fair podcasts by becoming a law fair material supporter at our website law fairmedia.org/support. You'll also get access to special events and other content available only to our supporters. Please wait and review us wherever you get your

podcasts. Look out for other podcasts including rational security, allies, the aftermath and escalation our latest law fair presents podcast series about the war in Ukraine. Check out our written work as well at law fairmedia.org. The podcast is edited by Jen Pacha and our audio engineer

at this episode with gold rodeo. Our theme song is from our by music as always thank you for listening.

Ingrid and in deed present here. Jobs by the non-feelor laupendarf. Hi, Friseur Im. What's your name? I'm Mitte. What's up? What's up? I'm Heppen Schere. Thank you. It's for your wish. It's all right. Ingrid. That's a job for sponsored jobs. With real profits we won't pass. For trawing greed, forsoaring deed and finna qualified talent with sponsored jobs. Make the deed simple. Now on in deed.de/recruting.

Compare and Explore