Architects or accelerants?

Do social media and AI create violent extremists, or speed up people who were already on the way? The answer decides where prevention money goes, and what it costs in speech, privacy, and trust.

Grievances are common. Extreme belief is less common. Violence is rare. The question for this project is what technology does to that gap. Illustrative, not to scale.

Before you scroll, which do you think is closer to the truth?

Six attacks and plots. Every path ran through a screen.

Four countries, seven years, several ideological profiles, or none at all. This project tests the competing theories against each case. Select a case to see what the documented record actually shows. Attackers are identified by place, not name, to avoid feeding the copycat cycle described later.

Two camps and a critique, reading different evidence.

The field says two things at once. The disagreement is sharper than it looks, because each side relies on a different kind of study. Compare the positions and the evidence each one stands on.

Read carefully, the leading architecture paper already concedes the key point: Kunst et al. (2026) conclude algorithms likely help people who already have intent or vulnerability, rather than imposing extremism on passive users.

The record in six numbers.

Each figure comes from a source in the project. Together they show a technology built to reward outrage, adopted at unprecedented speed, and increasingly present in the lives of young attackers.

5×

From 2017, Facebook's ranking system weighted an angry emoji reaction five times more than a like. Its own data scientists later found angry-reaction posts were disproportionately likely to carry misinformation and toxicity.

Merrill & Oremus (2021)
~30%

Share of people arrested on terrorism suspicion in EU member states in 2024 who were aged 12 to 20. Most juvenile offenders were convicted of preparatory or material offenses, not violence.

Mehra & Herbach (2026)
627

Posts the Pittsburgh attacker made on the low-moderation platform Gab in ten months. Few people offline were positioned to notice. Online, the fixation was plainly visible.

Amman, Kupper & Meloy (2026)
5,000+

Messages the Windsor Castle intruder exchanged with a Replika AI companion he named Sarai, including discussion of his plan. The companion validated rather than challenged.

Glazzard et al. (2026); Kunst et al. (2026)
72%

Share of TRAP-18 warning indicators present before the Pittsburgh attack, including four proximal warning behaviors. He was, in the authors' phrase, a gray man on no one's radar.

Amman, Kupper & Meloy (2026)
5 days

Time it took ChatGPT to pass one million users after release in 2022. Within three years the same technology appeared in the record of a school stabbing and a bomb-making case.

Roose (2022); Solea (2025); US v. Gann (2025)

The fuel is human. AI clears the firebreaks.

Kunst et al. (2026) map radicalization in four stages and argue AI acts as a catalyst that removes the ordinary friction stopping most people partway. Set the conditions and watch which barriers weaken. Select a stage for what it looks like and where to intervene.

Predisposing vulnerability

Isolation, identity uncertainty, need for certainty, grievance.

AI accelerants

Each one targets a different kind of friction.

Illustrative model for training, not a risk tool. People stall, cycle, skip stages, and exit. Barrier mappings are simplified from Kunst et al. (2026) and Simi & Windisch (2017).

Tested against the cases, one column stays empty.

Each case coded against the four stages. The first column is blank: no case shows a previously uncommitted person delivered to extremism by a recommendation engine. The last column is full: technology is present at the point of action in all six. Select any cell for the evidence.

Not established Partial or diffuse Documented AI in the record
Select a cellThe coding follows the project's case analysis.

The people radicalizing have changed. The models have not.

The most consequential effect is not on who gets recruited into existing movements. It is a new population: young, ideologically thin or mixed, fixated on violence itself, and attached to no organization.

Ages in the record, against the age of criminal responsibility

Sources: Ware (2026); Mehra & Herbach (2026); Solea (2025).

The puzzle pieces don't fit anymore

Hafez & Mullins (2015) explain radicalization as four interlocking pieces. For this population, three are distorted and one is nearly missing.

Why this population is dangerous

Simi & Windisch (2017) found most committed extremists never commit mass violence because something stops them. Three of their four barriers depend on other people.

  • Sorting: organizations steer members away from mass-casualty violence.
  • Disillusionment: people become disappointed with the group or its leaders.
  • Changes in focus: life, jobs, and relationships pull people away.
  • Moral apprehension: the person balks at harming innocents.

A diffuse online milieu has no membership to be sorted out of and no leadership to become disillusioned with. That is why the kill-or-capture tools built after 2001, which assume an organization to dismantle, fit poorly (Ware 2026).

A group radicalizes and restrains. A companion only does the first.

Friendship and kinship ties are among the strongest predictors of radicalization. They are also where the brakes live. The Windsor case suggests an AI companion can fill the network's place while supplying none of its brakes. Select a column to compare.

The caveat matters: this rests on one documented case and theory. Kunst et al. (2026) call the leap from chatbot validation to acting on it poorly understood. It belongs on the research agenda, and it matters most because isolated adolescents seeking validation are exactly who an always-agreeable companion attracts.

The attacker becomes the content that radicalizes the next one.

No stage model includes this. Amman, Kupper & Meloy (2026) document how completed attacks circulate as instruction and inspiration, and platforms carry the script long after the attacker is imprisoned.

  1. The Pittsburgh attacker studied earlier shootersincluding for tactical lessons about weapon reliability.
  2. Poway, California, April 2019The next synagogue attacker referenced Pittsburgh five times in his manifesto.
  3. Buffalo, New York, May 2022A supermarket attacker referenced him and wrote his name on his weapon.
  4. Accelerationist publicationsinvoked him repeatedly as a model.
  • Don't circulate attacker names, faces, or manifestos in coverage, briefings, or training.
  • Suppress sharing of attack footage and the tactical lessons drawn from it.
  • Judge programs by whether they reduce script availability, not by takedown volume.
ContagionAn acute rise in attacks for about two weeks after heavy publicity.
CopycatA chronic process: the act and actor are imitated until they become a subcultural script.

What practitioners can actually see.

Profiling fails because radical belief is common and violence is rare. Behavior near the point of action is different. These are the eight proximal warning behaviors in TRAP-18, the protocol used in the Pittsburgh examination.

A new place for leakage: machines

Leakage used to mean telling a friend, posting online, or writing it down. The Windsor intruder discussed his plan with an AI companion. The Pirkkala attacker reportedly drafted with ChatGPT and sent his manifesto to a newspaper before the attack. Intent now surfaces in private channels no bystander sees, which is why safety testing should cover how models respond to escalating violent ideation over long conversations.

The verdict: accelerant, environment, and a moving target.

You didn't pick a side at the top. That's fine. Here's where the evidence lands.

  1. The evidence supports acceleration, not causation.Technology effects concentrate in reinforcement and belonging, not first exposure. People who consume extremist video arrive already resentful, mostly through subscriptions and off-platform links (Shaw 2023). An accelerant is not harmless: reinforcement is where the process is usually decided.
  2. Generative AI is an instrument, and instruments matter.In the record it drafts, plans, and validates. It shortens the path to capability, and it lowers the cost of the manifesto and the recording, which are central to attacks designed as communication (Jiang & Wilson 2025).
  3. The radicalizing population has shifted, and the frameworks haven't caught up.Young, ideologically thin, violence-fixated, unaffiliated. Platforms don't hand them an ideology. They make violence available, supply an audience, and provide the validation a group once did.
  4. AI companions may occupy the structural position of the network.They validate and are always available, but cannot sort anyone away from violence or disappoint them. One documented case so far; a priority for research.
  5. The target is moving faster than the evidence.The strongest studies describe platforms from 2017 to 2021. Policy built on a settled reading will be built for the last generation of technology. The answer is durable monitoring capacity.

What leaders can do, and what each choice costs.

Every recommendation carries a trade-off. Open each one to see both.

Calling AI an accelerant is not a license to do nothing. Grievance, humiliation, misogyny, isolation, and violence as an available script are the drivers. They are harder to legislate than an algorithm, and regulating the accelerant because the fuel is politically hard will not work.

Check your understanding.

Four questions drawn from the findings.

The question is no longer whether people radicalize online. It is what happens when the systems people talk to are built to agree with them.

The threat is not that machines are recruiting people. It is that the social structures that once both radicalized and restrained have been replaced by environments that only do the first.