Tech Against Terrorism: 132 of 134 models gave attackers useful help
Partly confirmed
The takeaway
The National reported on Oct 9, 2026 that Tech Against Terrorism’s CT-AI benchmark put 627 attack-planning requests to 134 leading language models: 81 answered completely, 51 gave useful advice and only 2 provisionally passed.
Status
- Claim
Partly confirmed
- Our reporting
- Medium confidence
- Importance
- 3 of 5
- Last verified
- 9 October 2026
Your AI and this story
- GPT-6 Astra162 days after its cutoff
- Claude Opus 5.5101 days after its cutoff
- Gemini 3.8 Flash192 days after its cutoff
- Grok 4.7131 days after its cutoff
None of these four assistants can know about it. The closest, Claude Opus 5.5, stops 101 days before it.
Key facts
- Source: The National (Damien McElroy, Oct 9, 2026); Resultsense notes the round ‘has not yet published… on its own site’, so the figures are as The National reports them. Individual models are not named
- Scale: 627 requests that a terrorist planning an attack would need answered, sent to 134 leading LLMs; 81 gave a complete answer, 51 useful advice, 2 provisionally passed
- Abliteration: 13 of 13 ‘abliterated’ models (copies with safety training removed) failed; a leading model’s safeguards could be removed within three days
- Framing effect: self-declared terrorists got a usable answer in just under 2% of cases, self-declared safety researchers in 16.9% (8.9x more). Founder Adam Hadley: ‘A model that refuses a stated terrorist and answers a stated researcher has not been made safe. It has been made polite.’
- Recommendations: filter hazardous knowledge and terrorist content from training data; test and publish how hard each model is to strip of safeguards before release, and do not release models that fail; keep abliterated copies out of search, recommendations and app stores and require verified identity to access them; government backing for independent benchmarks
- Background: CT-AI was launched at the UN in July 2026 with 27 models and ~2,500 prompts; about a third of responses gave usable uplift beyond a web search, and the group’s incident tracker listed 30+ cases of AI used operationally in terrorism or mass violence, linked to 70+ deaths
What happened
On October 9, 2026 The National reported results of a new round of Tech Against Terrorism’s Counter-Terrorism AI (CT-AI) benchmark (The National2). The London-based group sent 627 requests an attack planner would need answered to 134 leading language models. Only two provisionally passed. Every abliterated open-weight model failed, and the group says it removed a leading model’s safeguards within three days. Models were far more willing to help someone who claimed to be a safety researcher than someone who said they were a terrorist, which the group reads as safety training that responds to the stated purpose rather than the content of the request.
The benchmark was first launched at the UN in July 2026 with 27 models (Tech Against Terrorism1). The October round’s full results were not on the group’s site when this entry was written, and the report does not name which models failed.
Why it matters
It is one of the largest independent misuse tests so far and puts numbers on two weak points: safeguards that can be talked around with a plausible cover story, and open-weight copies whose safeguards are removed. Both feed the debate over open-weight release and pre-deployment testing.
Sources
3 sources from 3 sites. Numbers match the chips in the text.
3 sources: 1 primary, 2 press
Primary
- Tech Against Terrorism: press release on the AI terrorism benchmark (CT-AI, July 2026)techagainstterrorism.org, official
Press
- The National: Test shows AI models likely to give advice for terrorist attacksthenationalnews.com, press
- Resultsense: 132 of 134 AI models gave terrorists useful help, test findsresultsense.com, press
Changes
- Filed (The National, Resultsense; July CT-AI launch for context)