For decades, successive US national security strategies have warned that violent non-state actors could acquire sophisticated technologies and use them to overcome conventional military advantages. Weapons of mass destruction, advanced military systems and other high-consequence technologies have occupied a prominent place in those warnings. Yet the history of the past quarter-century presents a more complicated picture.
The most catastrophic scenario has largely remained unrealised. Violent non-state actors have not successfully acquired and employed weapons of mass destruction on the scale once feared, apart from a limited number of cases. But that does not mean the technological threat has diminished. Instead, terrorists, insurgents, militias and criminal organisations have increasingly turned to something far more accessible: technologies already available to ordinary consumers.
An assessment by The Soufan Center argues that this quieter technological transformation may have been more corrosive to US national security than the spectacular threats that have dominated strategic planning. Rather than depending on weapons that require extraordinary resources, violent non-state actors have demonstrated an ability to incorporate commercially available technologies into their operations, allowing them to plan attacks, communicate, raise money, gather intelligence, recruit supporters and adapt to changing security environments.
The concern is not new. Violent non-state actors, particularly terrorist organisations, have featured in every US national security strategy since the passage of the Goldwater-Nichols Act in 1986 and the release of the first US National Security Strategy under President Ronald Reagan in 1987. Following the Cold War and the September 11 attacks, successive administrations repeatedly warned that non-state groups could exploit advanced technologies, including weapons of mass destruction, in ways that threatened American security and challenged traditional US military advantages.
The 2006 National Security Strategy, for example, identified the prospect of violent non-state actors engaging in malign cyber operations. The 2010 and 2015 strategies expanded attention to threats posed by terrorist networks, criminal hackers and organised criminal groups, including the exploitation of financial systems dependent on cyberspace. By 2017, the US strategy was explicitly highlighting terrorist organisations, drug traffickers and criminal cartels for their ability to adapt rapidly and outpace American defences.
Jihadist organisations were also identified for their sophisticated use of technology for information campaigns, recruitment and encouragement of attacks against the United States and its allies. Cybercriminals were noted for exploiting online marketplaces and cryptocurrencies, while cyberspace itself had become a means through which adversaries could disrupt American political, economic and security interests and damage the infrastructure and networks on which daily life increasingly depends.
The 2022 National Security Strategy continued to address cybercrime and the illicit use of cryptocurrency. The 2025 strategy placed particular emphasis on threats to the US homeland from narco-terrorists, cartels and other transnational criminal organisations, all of which have made use of technological tools to advance their interests.
What has changed is not simply the technology available to these groups, but the range of activities it enables. Over several decades, violent non-state actors have employed two-way radios, mobile phones, manned aircraft, personal computers, satellite navigation, satellite imagery, the internet, satellite communications, artificial intelligence, virtual reality, digital encryption and unmanned aerial vehicles.
These technologies have been used for everything from planning attacks and moving drugs, weapons and explosives to money laundering, gathering resources, training personnel and managing organisations. The technology does not necessarily have to be sophisticated to be strategically useful. Its value often lies in its availability, affordability and adaptability.
The Islamic State demonstrated this evolution particularly clearly. The group became an early adopter of unmanned aerial vehicles for surveillance and reconnaissance and subsequently used them to conduct crude but effective attacks. It also adopted artificial intelligence for propaganda and targeted communications.
The 2025 New Orleans terrorist attack committed by Shamsud-Din Jabbar offered another illustration of how commonplace technologies can become part of an extremist operation. According to the source material, the attack was supported by numerous technologies, including Meta Ray-Ban glasses for surveillance and social media to broadcast his allegiance to Islamic State.
This broader phenomenon has been described as “malevolent innovation”: the conversion of ordinary technologies into tools that facilitate violence, profit, destruction and disorder. Such innovation allows terrorists, criminals and insurgents to adapt rapidly, often at relatively low cost, and potentially to remain ahead of law enforcement agencies accustomed to more traditional methods of detection and disruption.
The same technological proliferation has opened opportunities that barely existed for many violent non-state actors a decade ago. Cheap computers and smartphones have enabled groups and their adherents to exploit vulnerabilities within cyberspace and software-defined systems. Cyber-espionage, ransomware, hacking for profit, network-enabled bank fraud and identity theft have all become part of the repertoire associated with non-state actors.
There is an irony at the heart of this transformation. Technologies once considered advanced remain sophisticated, but many are now cheap and commercially available. More strikingly, much of the technology used by violent non-state actors was developed in the United States by American inventors and companies, often benefiting from US government research and development funding.
The prospect of terrorists acquiring truly sophisticated weapons remains a serious concern. Ballistic missiles and weapons of mass destruction remain extraordinarily difficult for violent non-state actors to acquire and employ. Yet jihadist organisations have demonstrated a continuing interest in chemical and biological weapons. Osama bin Laden and al-Qaeda established a research programme examining ricin, botulinum toxin and anthrax. Islamic State produced and used sulfur mustard and explored crude applications of toxic industrial chemicals in weapons and explosives.
The difficulty of acquiring such capabilities may itself have become a deterrent. The longstanding international concern surrounding terrorist access to weapons of mass destruction may have made states and other potential suppliers reluctant to facilitate such transfers. But the possibility of that calculation changing remains.
For most violent non-state actors, the more practical choice may be to avoid technologies whose acquisition would immediately attract attention and trigger efforts to disrupt their organisations. Whether this reflects a deliberate strategic decision to favour less spectacular but more practical technologies, or an adaptation imposed by their operating environment, remains difficult to determine.
What is clearer is that technological proliferation has transformed the nature of the threat. The danger does not depend solely on terrorists obtaining the most destructive weapons ever created. It can emerge through the steady democratisation of technology itself, as devices developed for communication, commerce, navigation, surveillance and entertainment become available for exploitation.
The enduring challenge for US national security is therefore not simply to prevent violent non-state actors from acquiring extraordinary weapons. It is to recognise how quickly ordinary technology can be repurposed for extraordinary consequences. The most persistent threat may not be the spectacular weapon that requires access to a sophisticated state arsenal, but the commonplace device that can be obtained, adapted and deployed with little warning.

