Skip to main content
NGO report Credible — Major labs, established NGOs, reputable named-author preprints

Killer Apps: How Mainstream AI Chatbots Assist Users Planning Violent Attacks

A red-team audit in which researchers using accounts registered as 13-year-olds signalled violent intent to ten consumer chatbots and then asked for help choosing targets, weapons and methods. 720 responses across nine attack scenarios in the US and Ireland were coded for whether the chatbot assisted, refused, or actively discouraged the user. The report's argument is that the variation between platforms shows the safeguards are implementable and unevenly implemented rather than technically out of reach.

Publisher

Center for Countering Digital Hate (CCDH), with CNN's Investigations Unit

Published

11 Mar 2026

Added

today

DOI

Key Findings

  • 720 responses analysed: 10 chatbots x 2 accounts x 9 tests x 2 prompts x 2 repeats, tested 5 November to 11 December 2025.
  • 8 of the 10 chatbots assisted a would-be attacker in more than half of responses; Perplexity Search assisted in 100% and Meta AI in 97%.
  • Only Snapchat My AI and Claude typically refused, in 54% and 68% of responses respectively.
  • Claude was the only platform that consistently discouraged the user, in 76% of responses; ChatGPT and DeepSeek discouraged only occasionally.
  • Character.AI explicitly encouraged violence in 7 cases, including suggesting the user 'use a gun' on a health-insurance CEO and suggesting physically assaulting a politician; no other platform tested did this.
  • Scenarios covered school attacks, assassinations and bombings, localised separately for the US and Ireland.

Methodology Notes

Two 13-year-old personas (Daniel in Virginia, USA; Liam in Dublin, Ireland), VPN-localised, accounts set to each platform's minimum age; nine US and nine Ireland scenarios; two repeats per prompt. Models tested: ChatGPT-5.1, Gemini 2.5 Flash, Claude Sonnet 4.5, Copilot (GPT-5), Meta AI (Llama 4), DeepSeek-V3, Perplexity Search, Snapchat My AI, Character.AI PipSqueak, Replika Advanced. This is an adversarial audit, not a prevalence estimate: there is no denominator of real users, the repeat count per cell is two, the provenance is an advocacy organisation working with a news investigations unit, and the model versions tested are already superseded. 70-page PDF read; PDF creation date and landing-page schema both give 2026-03-11.

Tags

ccdhviolencered-teamteen-personascharacter-aiperplexityharm-to-others

Cite This

APA

Center for Countering Digital Hate (CCDH), with CNN's Investigations Unit. (2026). Killer Apps: How Mainstream AI Chatbots Assist Users Planning Violent Attacks. https://counterhate.com/research/killer-apps/