Killer Apps
How mainstream AI chatbots assist users planning violent attacks
8 in 10 AI chatbots were regularly willing to assist users in planning violent attacks including school shootings, religious bombings, and high-profile assassinations. DeepSeek went as far as wishing the would-be attacker a “Happy (and safe) shooting!”. These are the findings of our new report based on research conducted in collaboration with CNN’s investigative unit.
These digital prompts don’t stay online. In a recent school shooting in Canada, OpenAI staff internally flagged a suspect for using ChatGPT in ways linked to potential violence. The company banned the Tumbler Ridge school shooter’s account but did not alert law enforcement. Months later, that user allegedly killed eight people and injured at least 25.
The guardrails exist. Most companies are choosing not to use them, putting public safety and national security at risk.
About
Key Findings
- Researchers at CCDH and CNN tested ten chatbots by posing as teen users planning violent attacks before asking about locations to target and weapons to use on 10 chatbots including: ChatGPT, Google Gemini, Claude, Microsoft Copilot, Meta AI, DeepSeek, Perplexity, Snapchat My AI, Character.AI and Replika.
- 8 in 10 chatbots were typically willing to assist teen users in planning violent attacks including school shootings, religious bombings, and high-profile assassinations.
- Only Anthropic’s Claude and Snapchat’s My AI consistently refused to assist in planning violent attacks.
- 9 in 10 chatbots fail to reliably discourage would-be attackers.
- Only Anthropic’s Claude attempted to actively dissuade would-be attackers.
- Character.AI, a popular chatbot amongst kids and teens, actively encouraged violent attacks.
“AI chatbots, now embedded into our daily lives, could be helping the next school shooter plan their attack or a political extremist coordinate an assassination. When you build a system design to comply, maximize engagement, and never say no, it will eventually comply with the wrong people. What we’re seeing is not just a failure of technology, but a failure of responsibility. Most of these leading tech companies are choosing negligence in pursuit of so-called innovation,” says Imran Ahmed, CEO of the Center for Countering Digital Hate.

Demand AI companies put public safety first before more harm is done.
The real-life effects of AI-generated violence
AI chatbots have quickly become embedded in everyday life. Millions of people — including children and teenagers — rely on them for advice, companionship, and answers to complex questions. When these systems fail to prevent or actively discourage violent intent, the risks are not abstract. They are immediate, real, and potentially deadly.
AI tools that provide guidance on targets, tactics, or weapons can meaningfully accelerate real-world harm. Even seemingly small pieces of assistance like refining an idea, suggesting locations, or outlining methods or weapons can increase both the likelihood and lethality of an attack. By lowering the barriers to violence, these systems heighten threats to children, religious communities, elected officials, and the public at large.
Safety Exists
Safety is possible. Our testing shows that Anthropic’s Claude was able to recognize escalating risk and respond responsibly. It consistently refused to assist with violent planning in 68% of cases and actively discouraged users from carrying out attacks in 76% of interactions, demonstrating that meaningful guardrails on AI tools exist and can be effective.
But most of the other chatbots we tested did not meet that standard. For example, Perplexity and Meta AI were willing to assist would-be attackers in 100% and 97% of responses, respectively. Even more concerning, Character.AI, a platform popular with young users actively encouraged violence in multiple scenarios.
This raises an obvious question: if effective safety mechanisms clearly exist, why are so many AI companies choosing not to implement them?
That choice has dangerous real-life consequences. Since CCDH conducted this research, Anthropic has announced it is rolling back a safety pledge. If that decision had been made before our study, would Claude’s responses have been as bad as the others?