Press release

AI's Terrorism Blind Spot: First Benchmark Built to Measure It Finds Frontier Models Give Attackers Usable Help

New York, 1 July 2026

Tech Against Terrorism today publishes the Counter-Terrorism AI (CT-AI) Benchmark, the first test of artificial intelligence built specifically for terrorist and violent-extremist misuse. Built independently and self-funded, it finds that across 27 leading models around a third of responses gave a would-be attacker usable uplift, and that open models stripped of their safety controls complied with almost every request.

Adam Hadley CBE, Executive Director of Tech Against Terrorism, said:

Until now there was no AI benchmark focused specifically on terrorism, so we built one. With nothing more than simple, single-shot questions, many of the models we tested handed over meaningful help towards making a bomb or planning a mass-casualty attack. That is not acceptable, and it is happening in models built in the United States and China alike.
Adam Hadley CBE, Executive Director, Tech Against Terrorism
This is a control problem as much as a safety one. The real risk is that AI developers are inadvertently creating models they cannot control, and the next stage of the AI race will not be won by whoever deploys fastest, but by whoever first solves control and can demonstrate it. We are not arguing to ban open models. We stand ready to work with developers to build these safeguards in from the start, using our taxonomy and method, rather than retrofit them after harm has been done.

Launched at the United Nations during Counter-Terrorism Week, the benchmark lands as governments move to vet frontier AI for national-security risk:

  • Terrorist and violent-extremist exploitation of AI is no longer hypothetical. Tech Against Terrorism's incident tracker documents more than 30 public cases in which AI acted as an operational assistant in terrorism, violent extremism or mass violence, across at least 11 different AI tools, and linked to more than 70 deaths.
  • Western governments are now pressing AI developers to submit models for pre-release security review, but those reviews centre on cyber, chemical, biological and nuclear threats, not terrorism.
  • Free, publicly available tools can strip the safety controls from an openly released model, and such models cannot be recalled once they are in circulation.

What the Benchmark Found

Tech Against Terrorism tested 27 leading AI models against almost 2,500 single-shot prompts drawn from real terrorist use cases:

  • Around a third of responses gave usable uplift beyond what is easily found by web search.
  • Full refusals were 57% of responses. Hedged compliance, a response that opens with a refusal then supplies the content anyway, was 15%, the largest non-refusal category.
  • Two open models with their safety stripped out, a process called abliteration, complied with 89% and 100% of requests, and cannot be recalled once released.
  • Reframing an identical request as “research” raised compliance from 17% to 42%, with no change to the technical content.
  • Anthropic's Claude and Falcon3 ranked safest, with China's MiniMax close behind. The two abliterated builds and the two Mistral models ranked lowest. Open versus closed was not the dividing line.
  • Coverage was uneven: explosives were refused around 80% of the time, but edged weapons, improvised chemical weapons and firearms acquisition only about a third.

Why It Matters

  • A refusal rate is not a safety rating. What matters is the severity of the assistance a model gives, not how often it declines.
  • Terrorist groups need not build their own AI. An existing open model, stripped of its safeguards, runs offline on ordinary hardware with no oversight.
  • General-purpose safety testing misses most of this, because it is not built around how terrorists actually operate.
  • This first release is a deliberately conservative floor: single-shot questions, English only, and 26 of 151 use cases. The real-world risk is higher.

What Must Happen Now

For AI developers

  • Treat terrorist and violent-extremist misuse as a distinct safety category, tested before release, not caught as a by-product of general safety work.
  • Test models for changes in stated intent, which currently defeat many guardrails.
  • Extend refusal training beyond the most recognisable threats.

For government

  • Treat the circulation of de-restricted, abliterated open models as a major national-security concern, tracking their distribution and planning for it.

Tech Against Terrorism is willing to work directly with developers to embed its taxonomy into pre-release testing and red-teaming, so safety is designed in from the outset.

About Tech Against Terrorism

Tech Against Terrorism is a not-for-profit organisation dedicated to saving lives by disrupting terrorist activity online. Based in London and working globally, it runs the Terrorist Content Analytics Platform (TCAP) and supports the tech sector and governments to detect and respond to terrorist exploitation of the internet. The CT-AI Benchmark is the first AI-safety benchmark built specifically for terrorist and violent-extremist misuse.

Notes to editors

  • The CT-AI Benchmark launches at the United Nations in New York on 1 July 2026, during UN Counter-Terrorism Week.
  • The research was self-funded by Tech Against Terrorism. It has received no funding from any AI provider referenced in the report and declares no conflicts of interest.
  • The benchmark maps terrorist misuse of AI into 151 cases across four harm domains and 13 pillars; this first run covered 26 cases across 27 models.
  • Spokespeople available for interview: Adam Hadley CBE, Executive Director; and the benchmarking lead, Tom Byrne.

Media contact

Communications Team, Tech Against Terrorism

contact@techagainstterrorism.org