top of page

From Years to Minutes: AI Has Collapsed the Terrorist Planning Timeline

18 hours ago
5 min read
Federal agencies warn that artificial intelligence has compressed the terrorist attack planning cycle from years to minutes, forcing defenders to respond at machine speed.
Federal agencies warn that artificial intelligence has compressed the terrorist attack planning cycle from years to minutes, forcing defenders to respond at machine speed.

Federal agencies and former homeland security officials now warn that artificial intelligence allows a lone, unsophisticated individual to build a detailed attack plan, including weapon construction guidance, in minutes rather than years. A separate joint advisory from the NSA, FBI, and CISA alleges that China-based AI companies are extracting American AI capabilities at industrial scale. Nearly a decade ago, my doctoral research argued that terrorist organizations adopt emerging technology faster than the governments pursuing them. That thesis is no longer an academic claim. It is now an official United States government warning.


Almost ten years ago, I defended a dissertation built on a simple argument: terrorist organizations move faster than states when new technology arrives. They used the early internet to recruit and spread propaganda. They used social media to radicalize followers at a global scale. They used encrypted messaging to raise funds and plan in the dark. Each wave shortened the distance between intent and attack. This week, the United States government described the next wave in plain language, on the record, and the warning should command the attention of every security professional in the country.

"Terrorist groups did not wait for permission to innovate. They never do."

What the Warnings Actually Say

Former DHS Acting Undersecretary for Intelligence John Cohen told the ABC7 Chicago I-Team that terrorist groups and criminal organizations are already using artificial intelligence to improve their cyberattack capability, develop detailed attack playbooks, and better understand how to construct weapons. His most sobering point was about time. The September 11 attacks took years to plan, prepare, and execute. Today, Cohen warned, an unsophisticated, angry, socially isolated individual can develop a detailed attack plan, including instructions for building an explosive device or another lethal weapon, "in a matter of minutes."


The Department of Homeland Security reinforced the point in a bulletin issued ahead of the 9/11 anniversary. Terrorists are increasingly experimenting with generative AI, not only to create violent propaganda but to explore explosives and biological agents. DHS assessed that AI advancements could make terrorist activity "faster, more scalable, and harder to detect."

This is the practical meaning of AI-enabled terrorism. The technology does not create the intent. It removes the friction between intent and capability. The skills gap that once separated an aspiring attacker from a competent one is closing, and it is closing fast.


The State Dimension: Shortcuts at Industrial Scale

Terrorists are not the only actors taking shortcuts. On September 8, the NSA, FBI, and CISA issued a joint cybersecurity advisory accusing six China-based AI companies, including DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI, of running industrial-scale knowledge distillation campaigns against American frontier AI models since at least late 2024. The agencies allege these firms extracted billions of tokens across millions of exchanges, likely with the awareness of the Chinese government. China rejects the allegations and describes distillation as a normal technical practice.


Why should counterterrorism and law enforcement professionals care about a commercial AI dispute? Because the agencies themselves drew the line: industrial-scale distillation does more than cut research costs. It strengthens adversary military and cyberattack capabilities. Capability theft at the state level eventually cascades downward. What a nation-state extracts today, a proxy group or criminal network exploits tomorrow.


Moreover, Anthropic's September 10 threat intelligence report shows how far misuse has already advanced. The company disclosed disrupted operations including a Russia-linked espionage campaign targeting drone manufacturers and Ukrainian officials, an actor who reverse-engineered a military drone vision system, an attempt to build a kamikaze drone swarm, and five blocked attempts to use its models for research that could support biological weapons development. These are not tabletop hypotheticals. They are documented operations from the past nine months.

"The planning cycle that once took years now fits inside an afternoon."

The Pattern I Documented a Decade Ago

My doctoral research examined how terrorist organizations exploited cyberspace for three purposes: facilitating attacks, raising funds, and spreading propaganda. The core finding was uncomfortable then and remains uncomfortable now. Adversaries adopt technology on offense faster than institutions adapt on defense, because attackers face no procurement cycles, no legal reviews, and no committee approvals. They simply try things.


Artificial intelligence supercharges all three functions I studied. Attack facilitation now includes machine-generated playbooks and autonomous reconnaissance. Fundraising now includes AI-assisted fraud and scams at industrial volume. Propaganda now includes synthetic media produced in any language, at any scale, tuned to any audience. However, the deeper change is structural. Previous technologies helped terrorists communicate and organize. AI helps them execute.


What Practitioners Should Do Now

The threat is moving quickly, but the response playbook is within reach. Four steps matter most:

  1. Rebuild your threat models around compressed timelines. If planning cycles have shrunk from years to minutes, detection strategies built on long pre-attack windows are obsolete. Shift resources toward behavioral indicators and rapid-response fusion between agencies.

  2. Treat AI misuse indicators as intelligence collection priorities. Queries about explosives, drone modification, and biological agents on AI platforms are early warning signals. Build relationships with AI providers and demand structured threat reporting, as Anthropic's disclosures now model.

  3. Close the defender speed gap. Adversaries operate at machine speed. Agencies and companies must adopt AI-assisted triage, monitoring, and analysis under proper governance, or accept a permanent disadvantage.

  4. Press for accountability frameworks. Policymakers must clarify liability when AI systems enable or execute attacks. Ambiguity favors the adversary.


An Analyst's View

I take no satisfaction in watching a decade-old thesis become a federal warning. Nevertheless, the lesson deserves to be stated plainly. We lost years treating terrorist technology adoption as a niche academic topic rather than a core planning assumption. We should not repeat that mistake with artificial intelligence. The question for every security leader is no longer whether adversaries will weaponize AI. They already have. The question is whether your organization can detect and disrupt an attack planned in minutes, and whether your nation is building the sovereign capacity to defend at machine speed rather than renting that capability from others.


The Bottom Line

AI has collapsed the terrorist planning timeline, lowered the barrier to sophisticated attacks, and given both lone actors and nation-states dangerous shortcuts. Organizations that adapt early will set the standard for everyone else.


OSRS can help. Our team provides intelligence-driven security research, AI threat assessments, counterterrorism analysis, and strategic advisory services for government, law enforcement, and private-sector leaders. Contact us to schedule a briefing or an AI-readiness assessment for your organization.


Enjoyed this article? Share it with a colleague who needs to see it. Stay informed by subscribing to our email list and following us on Google News, Twitter, and LinkedIn for more exclusive cybersecurity insights and expert analyses.


About the Author

Dr. Sunday Oludare Ogunlana is the Founder and CEO of OGUN Security Research and Strategic Consulting LLC, a Professor of Cybersecurity, a national security scholar, and a television commentator. His doctoral research on terrorism in cyberspace examined how violent extremist organizations exploit emerging technology to facilitate attacks, raise funds, and spread propaganda. He advises government, academic, and private-sector organizations on security strategy and artificial intelligence threats.


Intelligence. Protection. Strategy. www.ogunsecurity.com

Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating
bottom of page