ISIS Supporters Turn to AI to Bolster Online Support

FILE PHOTO: AI (Artificial Intelligence) letters and robot hand miniature in this illustration, taken June 23, 2023. REUTERS/Dado Ruvic/Illustration/File Photo
FILE PHOTO: AI (Artificial Intelligence) letters and robot hand miniature in this illustration, taken June 23, 2023. REUTERS/Dado Ruvic/Illustration/File Photo
TT

ISIS Supporters Turn to AI to Bolster Online Support

FILE PHOTO: AI (Artificial Intelligence) letters and robot hand miniature in this illustration, taken June 23, 2023. REUTERS/Dado Ruvic/Illustration/File Photo
FILE PHOTO: AI (Artificial Intelligence) letters and robot hand miniature in this illustration, taken June 23, 2023. REUTERS/Dado Ruvic/Illustration/File Photo

Days after a deadly ISIS attack on a Russian concert hall in March, a man clad in military fatigues and a helmet appeared in an online video, celebrating the assault in which more than 140 people were killed.
"ISIS delivered a strong blow to Russia with a bloody attack, the fiercest that hit it in years," the man said in Arabic, according to the SITE Intelligence Group, an organization that tracks and analyzes such online content.
But the man in the video, which the Thomson Reuters Foundation was not able to view independently, was not real - he was created using artificial intelligence, according to SITE and other online researchers.
Federico Borgonovo, a researcher at the Royal United Services Institute, a London-based think tank, traced the AI-generated video to an ISIS supporter active in the group's digital ecosystem.
This person had combined statements, bulletins, and data from ISIS's official news outlet to create the video using AI, Borgonovo explained.
Although ISIS has been using AI for some time, Borgonovo said the video was an "exception to the rules" because the production quality was high even if the content was not as violent as in other online posts.
"It's quite good for an AI product. But in terms of violence and the propaganda itself, it's average," he said, noting however that the video showed how ISIS supporters and affiliates can ramp up production of sympathetic content online.
Digital experts say groups like ISIS and far-right movements are increasingly using AI online and testing the limits of safety controls on social media platforms.
A January study by the Combating Terrorism Center at West Point said AI could be used to generate and distribute propaganda, to recruit using AI-powered chatbots, to carry out attacks using drones or other autonomous vehicles, and to launch cyber-attacks.
"Many assessments of AI risk, and even of generative AI risks specifically, only consider this particular problem in a cursory way," said Stephane Baele, professor of international relations at UCLouvain in Belgium.
"Major AI firms, who genuinely engaged with the risks of their tools by publishing sometimes lengthy reports mapping them, pay scant attention to extremist and terrorist uses."
Regulation governing AI is still being crafted around the world and pioneers of the technology have said they will strive to ensure it is safe and secure.
Tech giant Microsoft, for example, has developed a Responsible AI Standard that aims to base AI development on six principles including fairness, reliability and safety, privacy and security, inclusiveness, transparency, and accountability.
In a special report earlier this year, SITE Intelligence Group's founder and executive director Rita Katz wrote that a range of actors from members of militant group al Qaeda to neo-Nazi networks were capitalizing on the technology.
"It's hard to understate what a gift AI is for terrorists and extremist communities, for which media is lifeblood," she wrote.
CHATBOTS AND CARTOONS
At the height of its powers in 2014, ISIS claimed control over large parts of Syria and Iraq, imposing a reign of terror in the areas it controlled.
Media was a prominent tool in the group's arsenal, and online recruitment has long been vital to its operations.
Despite the collapse of its self-declared “caliphate” in 2017, its supporters and affiliates still preach their doctrine online and try to persuade people to join their ranks.
Last month, a security source told Reuters that France had identified a dozen ISIS-K handlers, based in countries around Afghanistan, who have a strong online presence and are trying to convince young men in European countries, who are interested in joining up with the group overseas, to instead carry out domestic attacks.
ISIS-K is a resurgent wing of ISIS, named after the historical region of Khorasan that included parts of Iran, Afghanistan and Central Asia.
Analysts fear that AI may facilitate and automate the work of such online recruiters.
Daniel Siegel, an investigator at social media research firm Graphika, said his team came across chatbots that mimicked dead or incarcerated ISIS militants.
He told the Thomson Reuters Foundation that it was unclear if the source of the bots was ISIS or its supporters, but the risk they posed was still real.
"Now (ISIS affiliates) can build these real relationships with bots that represent a potential future where a chatbot could encourage them to engage in kinetic violence," Siegel said.
Siegel interacted with some of the bots as part of his research and he found their answers to be generic, but he said that could change as AI tech develops.
"One of the things I am worried about as well is how synthetic media will enable these groups to blend their content that previously existed in silos into our mainstream culture," he added.
That is already happening: Graphika tracked videos of popular cartoon characters, like Rick and Morty and Peter Griffin, singing ISIS anthems on different platforms.
"What this allows the group or sympathizers or affiliates to do is target specific audiences because they know that the regular consumers of Sponge Bob or Peter Griffin or Rick and Morty, will be fed that content through the algorithm," Siegel said.
EXPLOITING PROMPTS
Then there is the danger of ISIS supporters using AI tech to broaden their knowledge of illegal activities.
For its January study, researchers at the Combating Terrorism Center at Westpoint attempted to bypass the security guards of Large Language Models (LLMs) and extract information that could be exploited by malicious actors.
They crafted prompts that requested information on a range of activities from attack planning to recruitment and tactical learning, and the LLMs generated responses that were relevant half of the time.
In one example that they described as "alarming", researchers asked an LLM to help them convince people to donate to ISIS.
"There, the model yielded very specific guidelines on how to conduct a fundraising campaign and even offered specific narratives and phrases to be used on social media," the report said.
Joe Burton a professor of international security at Lancaster University, said companies were acting irresponsibly by rapidly releasing AI models as open-source tools.
He questioned the efficacy of LLMs' safety protocols, adding that he was "not convinced" that regulators were equipped to enforce the testing and verification of these methods.
"The factor to consider here is how much we want to regulate, and whether that will stifle innovation," Burton said.
"The markets, in my view, shouldn't override safety and security, and I think - at the moment - that is what is happening."



How Iranians Are Communicating Through Internet Blackout

 People walk past closed shops at the almost empty traditional main bazaar, in Tehran, Iran, Tuesday, March 10, 2026. (AP)
People walk past closed shops at the almost empty traditional main bazaar, in Tehran, Iran, Tuesday, March 10, 2026. (AP)
TT

How Iranians Are Communicating Through Internet Blackout

 People walk past closed shops at the almost empty traditional main bazaar, in Tehran, Iran, Tuesday, March 10, 2026. (AP)
People walk past closed shops at the almost empty traditional main bazaar, in Tehran, Iran, Tuesday, March 10, 2026. (AP)

Iran's latest internet blackout has lasted more than 14 days, connectivity monitor Netblocks said Friday.

The nature of the limits on internet activity shows "this is a government-imposed measure" and not the result of damage from US and Israeli airstrikes, Netblocks research chief Isik Mater told AFP.

"It is a deliberate shutdown imposed by the authorities to suppress the flow of information and prevent further dissent," said Raha Bahreini, Iran researcher at Amnesty International.

Here are some of the ways information is still flowing in and out of Iran.

- Shortwave radio -

Amsterdam-based nonprofit Radio Zamaneh began shortwave broadcasts during the January protests, sending a nightly Farsi news program from 11:00 pm Tehran time.

"It's really difficult for the regime to jam shortwave because it's a long-distance broadcast," executive director Rieneke van Santen told AFP.

"People can just listen on a super cheap, small, simple radio... It's one of those typical emergency fall-back solutions."

Declining to specify where the transmitter is located, she said it is "closer to the Netherlands than to Iran" -- although Tehran "can figure it out" if they choose.

- Phone calls -

Many with ties to Iran are still receiving landline phone calls from inside -- "quite surprising" given the internet blackout, said Mahsa Alimardani of global rights organization Witness.

Fearing the authorities listening in, people often avoid speaking directly about political topics, such as the killing of Ali Khamenei, she added.

"It's not possible to communicate about sensitive issues through these brief phone calls," Amnesty's Bahreini said.

The required prepaid international calling cards are expensive and often fail to provide their face value in minutes.

"You buy a phone card for 60 minutes, but in eight minutes, it's out," van Santen said.

"It's really just phone calls from family members saying, after the bombing, we're still alive."

- VPN or other internet services -

Virtual private networks (VPNs) -- widely-used services that encrypt internet traffic -- can't create an internet connection where none is available.

But even at around one percent of typical levels, Iran's connectivity is "still a large figure in absolute terms", Netblocks' Mater said.

Iranians suspected of using VPNs since the war began have received warning text messages claiming to be from the authorities.

Before the war, millions turned to Toronto-based company Psiphon, which creates specialist tools more capable than typical "off-the-shelf" VPNs.

Offering techniques including disguising users' data as different types of internet traffic, Psiphon "is able to evade detection more successfully", data and insights director Keith McManamen told AFP.

With up to six million unique daily users in Iran before the latest internet shutdown, connections have now tumbled to fewer than 100,000.

Few but the most tech-savvy users can reach Psiphon's network for now.

Nevertheless, "the situation is extremely dynamic. We're seeing changes not just day to day, but hour by hour," McManamen said.

A similar service, US-based Lantern, is also widely used in Iran.

- Satellite broadcasts -

Created by US-based nonprofit NetFreedom Pioneers, Toosheh is a "filecasting" technology using home satellite TV equipment to broadcast encrypted data to people in Iran.

Users record from the Toosheh satellite TV channel onto a USB stick plugged into their set-top box, which they can then decrypt using a special app installed on their phone or computer.

From that initial download, the data can be copied and shared across multiple households.

The group estimated around three million active users in Iran across 2025, with "thousands to hundreds of thousands... since the (internet) shutdown in January," the group's director of projects Emilia James told AFP.

From its usual educational repertoire ranging from English lessons to news, content these days includes more on "personal safety and digital security... helping people to stay safe," she added.

Since people are tuning in to a broadcast signal, there is no way for the government to track them, she added.

- Starlink -

Elon Musk-owned satellite internet service Starlink was used during this year's protests to get information out, while the government attempted to jam its signals.

At around $2,000 on Iran's black market, the terminals are expensive and very rare in poorer regions like Balochistan or Kurdistan that have suffered the most government repression, Alimardani said.

Meanwhile, Amnesty has received reports of "raids on houses... arrests of people who had Starlink devices," Bahreini said.

Charges for those caught communicating with the outside world range from prison sentences to the death penalty, she added.

Starlink did not respond to AFP's request for comment on usage in Iran.


How Iranians Are Communicating Through Internet Blackout

 People walk past closed shops at the almost empty traditional main bazaar, in Tehran, Iran, Tuesday, March 10, 2026. (AP)
People walk past closed shops at the almost empty traditional main bazaar, in Tehran, Iran, Tuesday, March 10, 2026. (AP)
TT

How Iranians Are Communicating Through Internet Blackout

 People walk past closed shops at the almost empty traditional main bazaar, in Tehran, Iran, Tuesday, March 10, 2026. (AP)
People walk past closed shops at the almost empty traditional main bazaar, in Tehran, Iran, Tuesday, March 10, 2026. (AP)

Iran's latest internet blackout has lasted more than 14 days, connectivity monitor Netblocks said Friday.

The nature of the limits on internet activity shows "this is a government-imposed measure" and not the result of damage from US and Israeli airstrikes, Netblocks research chief Isik Mater told AFP.

"It is a deliberate shutdown imposed by the authorities to suppress the flow of information and prevent further dissent," said Raha Bahreini, Iran researcher at Amnesty International.

Here are some of the ways information is still flowing in and out of Iran.

- Shortwave radio -

Amsterdam-based nonprofit Radio Zamaneh began shortwave broadcasts during the January protests, sending a nightly Farsi news program from 11:00 pm Tehran time.

"It's really difficult for the regime to jam shortwave because it's a long-distance broadcast," executive director Rieneke van Santen told AFP.

"People can just listen on a super cheap, small, simple radio... It's one of those typical emergency fall-back solutions."

Declining to specify where the transmitter is located, she said it is "closer to the Netherlands than to Iran" -- although Tehran "can figure it out" if they choose.

- Phone calls -

Many with ties to Iran are still receiving landline phone calls from inside -- "quite surprising" given the internet blackout, said Mahsa Alimardani of global rights organization Witness.

Fearing the authorities listening in, people often avoid speaking directly about political topics, such as the killing of Ali Khamenei, she added.

"It's not possible to communicate about sensitive issues through these brief phone calls," Amnesty's Bahreini said.

The required prepaid international calling cards are expensive and often fail to provide their face value in minutes.

"You buy a phone card for 60 minutes, but in eight minutes, it's out," van Santen said.

"It's really just phone calls from family members saying, after the bombing, we're still alive."

- VPN or other internet services -

Virtual private networks (VPNs) -- widely-used services that encrypt internet traffic -- can't create an internet connection where none is available.

But even at around one percent of typical levels, Iran's connectivity is "still a large figure in absolute terms", Netblocks' Mater said.

Iranians suspected of using VPNs since the war began have received warning text messages claiming to be from the authorities.

Before the war, millions turned to Toronto-based company Psiphon, which creates specialist tools more capable than typical "off-the-shelf" VPNs.

Offering techniques including disguising users' data as different types of internet traffic, Psiphon "is able to evade detection more successfully", data and insights director Keith McManamen told AFP.

With up to six million unique daily users in Iran before the latest internet shutdown, connections have now tumbled to fewer than 100,000.

Few but the most tech-savvy users can reach Psiphon's network for now.

Nevertheless, "the situation is extremely dynamic. We're seeing changes not just day to day, but hour by hour," McManamen said.

A similar service, US-based Lantern, is also widely used in Iran.

- Satellite broadcasts -

Created by US-based nonprofit NetFreedom Pioneers, Toosheh is a "filecasting" technology using home satellite TV equipment to broadcast encrypted data to people in Iran.

Users record from the Toosheh satellite TV channel onto a USB stick plugged into their set-top box, which they can then decrypt using a special app installed on their phone or computer.

From that initial download, the data can be copied and shared across multiple households.

The group estimated around three million active users in Iran across 2025, with "thousands to hundreds of thousands... since the (internet) shutdown in January," the group's director of projects Emilia James told AFP.

From its usual educational repertoire ranging from English lessons to news, content these days includes more on "personal safety and digital security... helping people to stay safe," she added.

Since people are tuning in to a broadcast signal, there is no way for the government to track them, she added.

- Starlink -

Elon Musk-owned satellite internet service Starlink was used during this year's protests to get information out, while the government attempted to jam its signals.

At around $2,000 on Iran's black market, the terminals are expensive and very rare in poorer regions like Balochistan or Kurdistan that have suffered the most government repression, Alimardani said.

Meanwhile, Amnesty has received reports of "raids on houses... arrests of people who had Starlink devices," Bahreini said.

Charges for those caught communicating with the outside world range from prison sentences to the death penalty, she added.

Starlink did not respond to AFP's request for comment on usage in Iran.


Will Ahmadinejad Return to the Political Scene in Iran?

Iranian former President Mahmoud Ahmadinejad. (AFP)
Iranian former President Mahmoud Ahmadinejad. (AFP)
TT

Will Ahmadinejad Return to the Political Scene in Iran?

Iranian former President Mahmoud Ahmadinejad. (AFP)
Iranian former President Mahmoud Ahmadinejad. (AFP)

A report by The Atlantic said the strike that hit a region close to Iranian former President Mahmoud Ahmadinejad’s residence in the first days of the war on Iran has returned to the spotlight a still controversial political figure even though he left office for over a decade ago.

On the first day of the Iran war, the assassination of Supreme Leader Ali Khamenei overshadowed news of a strike near Ahmadinejad’s home, said the report.

“Many who remembered his term in office - marked by Holocaust denial, atom-bomb fetishism, and shoving revolutionary ideology down the throats of a country already weary of it - celebrated his reported assassination,” it added. He was president from 2005 to 2013.

“Among those who have followed Ahmadinejad’s post-presidential career, however, his targeting was more of an enigma. Since leaving office, Ahmadinejad has harshly criticized the Iranian government, and as a result, Iran’s Guardian Council has formally excluded him from running for president,” said the report.

For more than a decade, he has been known more as a regime opponent than as a supporter. “I don’t understand why Israel would want to kill him in the first place,” Meir Javedanfar, who co-wrote a biography of Ahmadinejad, told The Atlantic. “Perhaps to settle scores? It makes no sense.”

Contrary to early reports, Ahmadinejad is alive, his associates revealed, requesting anonymity. “The circumstances of his survival may prove significant as the war drags on. Whatever the intent, Ahmadinejad’s associates say the strike was in effect a jailbreak operation that freed the former president from regime control.”

“Long before the war, the government had posted a small number of bodyguards near Ahmadinejad, nominally to protect a prominent citizen but also to keep tabs on him. The regime has never been sure what to do with him,” said the report.

About a month ago, after the January protests, his freedom of movement was further reduced, his phones confiscated, and the contingent of bodyguards increased from single digits to about 50. The bodyguards were based a few hundred meters from Ahmadinejad’s residence itself, at the entrance to a cul-de-sac in Narmak, in northeast Tehran. They established a checkpoint to monitor the houses and high school on that street.

“A February 28 strike hit not the residence, but the security forces nearby. In the ensuing mayhem, Ahmadinejad and his family evidently escaped their home and went underground. The government believed he had died, and his death was announced by official channels, as well as the reformist daily Sharq.”

“When rumors arose that Ahmadinejad had escaped, regime elements immediately suspected that he had been spirited away to take part in a coup,” said The Atlantic. “Ahmadinejad’s only public statement since the attack has been a brief eulogy for the supreme leader, calculated to show that Ahmadinejad was alive and to dispel speculation that he had declared himself an enemy of the state. His location is unknown to the government.”

In 2018, former Defense Minister Hussein Dehghan likened Ahmadinejad to “the door of the mosque, which can’t be burned or thrown away” without torching the mosque itself.

“Arresting Ahmadinejad could unsettle the regime,” Javedanfar said. “He knows a hell of a lot about it.”

“Ahmadinejad’s fans say that he has popular support, and that any postwar government will want him around to lend that support. If the current regime survives, it will need all the legitimacy it can get. If it does not, the United States might need someone with intimate - if outdated - knowledge of the Iranian state to be involved with what comes next. Ahmadinejad could still be useful,” the report said.