Expertise

Blog

The Changing Face of Terrorism, the Detection Challenge, and the Role of AI in Monitoring and Screening

AI

AML

Compliance

Regulatory

Terrorism is not going away; it is moving, fragmenting and digitising. The money behind it is doing the same. 

For banks, the result is one of the hardest problems in financial crime: the sums involved are often tiny, the funds are frequently clean in origin, and the signal is buried in billions of ordinary payments. 

This paper looks at the current state of terrorism, how it is reshaping the way financial institutions try to detect terrorist financing, and at the role artificial intelligence is now playing in both transaction monitoring and screening.

The Current State of Terrorism

The headline figures point in two directions at once. Deaths from terrorism fell to 7,555 in 2024, a 13% reduction on the previous year, according to the 2025 Global Terrorism Index. Yet the threat is spreading: the number of countries recording a terrorist incident rose from 58 to 66 over the same period [1] [2]. Terrorism is becoming less concentrated and more widely distributed, which makes it harder, not easier, to police.

The centre of gravity has shifted decisively to the Sahel, which now accounts for 3,885 deaths, or 51% of the global total, a near tenfold increase since 2019. Five of the 10 countries most affected sit in the region, led by Burkina Faso. Islamic State remains the deadliest organisation, active across 22 countries. 

At the same time, attacks in the West are increasingly carried out by lone actors and small cells, radicalised online and operating on minimal budgets [1][2]. The financial footprint of all this is small, scattered and global, which is precisely what makes it so difficult to catch.

The nature of attacks has changed as well. Alongside organised groups, much of the threat in Western countries now comes from lone actors and small cells radicalised online, including a rising share of racially and ethnically motivated violent extremism. These individuals are typically self-funded from everyday income, and they need very little money to act, so there is often no external financier to find and no unusual transfer to flag. Where a financial signal exists at all, it is faint, and it looks almost exactly like ordinary life.

Indicator

Figure

Terrorism deaths (2024)

7,555 (down 13%) [2]

Countries with an attack

66 (up from 58)[2]

Sahel share of deaths

51% (3,885) [2]

Stablecoins' share of illicit virtual-asset volume

84% (2025) [3]

Jurisdictions with major TF enforcement gaps

69% [4]

How Terrorists Raise and Move Money Now

In July 2025, the Financial Action Task Force (FATF) published a comprehensive update on terrorist financing risks, and its central message was that the methods are converging. Terrorist financiers increasingly blend conventional channels with digital ones, layering several techniques together to add complexity and reduce visibility [4]. 

The toolkit is broad: cash couriers and hawala still matter, but they now sit alongside online payment services, social-media fundraising, crowdfunding campaigns aimed at a global audience, virtual assets, and the abuse of shell companies and other legal entities.

Virtual assets deserve particular attention. The FATF found that stablecoins, now numbering more than 250 with a combined market value above $300B, accounted for 84% of illicit virtual-asset transaction volume in 2025 [3]. 

Crowdfunding is just as significant in a different way: a cause can solicit small donations from thousands of sympathisers across many countries, each contribution too small to look suspicious on its own. The common thread is fragmentation. Modern terrorist financing is rarely one large, traceable transfer; it is many small flows from many sources through many channels.

It helps to think in terms of four stages: raising funds, moving them, storing them, and using them. Terrorist networks now mix methods at every stage, which is what makes the activity so hard to follow end-to-end. Non-profit and charitable structures can be abused to raise and move money under a legitimate banner; prepaid cards, e-money, and peer-to-peer crypto transfers move value quickly across borders; and the final use is frequently a small, local cash purchase that leaves no digital trace at all. 

Recent enforcement has shown the pattern plainly, with authorities seizing cryptocurrency wallets used to solicit donations for designated groups through public social-media appeals. Modern terrorist financing is rarely one large transfer. There are many small flows, from many sources, through many channels.

Why Terrorist Financing Is So Hard To Detect

Terrorist financing inverts the usual money-laundering problem. Laundering takes dirty money and tries to make it look clean; terrorist financing often takes clean money, from salaries, benefits, small businesses or genuine donations, and channels it towards harm. That means the classic laundering indicators frequently do not apply, and the amounts are small enough to pass beneath every sensible threshold. A foreign fighter may need only the price of a flight and a few weeks of expenses.

Adversaries exploit this deliberately. Analysts now describe the systematic fragmentation of funding into transfers of roughly $50 to $500, small enough to mimic ordinary activity and to fall into the blind spot of rules-based systems. A single $100,000 donation can be split into 2,000 transfers of $50, spread across days, accounts and wallets [5]. Against this, a traditional transaction-monitoring system, built on fixed rules and thresholds, faces an impossible trade-off: set thresholds low and analysts drown in false positives; set them higher and the very transactions that matter slip through. 

It is little wonder the FATF found that 69% of assessed jurisdictions have major or structural deficiencies in investigating, prosecuting and convicting terrorist-financing cases [4].

Two Fronts: Screening and Transaction Monitoring

Banks defend against terrorist financing on two fronts, and each is under strain. 

The first is screening: checking customers and payments against sanctions and terrorist designation lists maintained by the United Nations, EU, UK, OFAC, and others. Screening is essential, but legacy name-matching generates enormous volumes of false matches, especially across different alphabets and transliterations of Arabic, Cyrillic, or Chinese names, and it only catches those already on a list. 

The second front is transaction monitoring, which looks for suspicious behaviour rather than known names. As we have seen, the behaviour in question is faint, fragmented, and easily mistaken for normal life. The two fronts together still leave a wide gap, and that gap is exactly where modern terrorist financing operates.

The operational reality compounds the problem. A large bank can generate tens of thousands of monitoring alerts a month, the overwhelming majority of them false, and each one has to be reviewed by a person. Analysts working through that volume have little time to spot the faint, fragmented pattern that signals terrorist financing, and genuine cases can be closed in the rush to clear a queue. Volume is therefore not only a cost problem; it is a detection problem, because sheer noise conceals the very signals that matter most.

Where AI Changes The Picture

AI does not remove the difficulty, but it materially improves a bank's odds on both fronts. In transaction monitoring, AI shifts the question from 'did this single payment break a rule?' to 'does this pattern of behaviour, across many accounts and over time, look like terrorist financing?'. Applied responsibly, it contributes in several ways:

  • Network and graph analytics link accounts, devices, beneficiaries and wallets that share hidden connections, exposing the distributed micro-transaction patterns that defeat single-account rules.

  • Behavioural and anomaly detection learns what is normal for each customer and flags the subtle deviations that fixed thresholds miss, such as sudden fan-out of small transfers or links to higher-risk corridors.

  • Typology models trained on confirmed cases recognise combinations of weak signals, such as crowdfunding inflows followed by rapid dispersal to multiple jurisdictions, that a human could not feasibly assemble at scale.

  • Risk-based prioritisation ranks alerts by genuine likelihood, cutting the false-positive burden so investigators spend time where the real risk is.

On the screening front, AI strengthens name and sanctions screening by understanding names, context, and relationships rather than matching strings, which raises true detection while reducing false positives across scripts and transliterations. 

Natural-language processing extends screening beyond static lists, scanning adverse media, court records and open sources to surface emerging threats before they are formally designated. Together, these capabilities help close the gap between what the lists know and what is actually happening.

Two further benefits matter to anyone running a compliance function. The first is perpetual KYC: rather than freezing a customer's risk picture at onboarding, AI continuously reassesses it as behaviour and external data change, so emerging risk is caught sooner. The second is efficiency. By ranking alerts intelligently, AI can sharply reduce the false positives that consume analyst time, freeing skilled people to concentrate on genuine threats. The aim is not to remove human judgement, but to aim it where it counts. AI shifts the question from ‘did this payment break a rule?’ to ‘does this behaviour look like terrorist financing?’.

The Human Role, and The Next Threat

AI is a force multiplier, not a replacement for judgement. The consequences of getting terrorist-financing decisions wrong, in either direction, are severe, so explainability and human oversight are essential rather than optional. 

Skilled analysts provide the context a model cannot, decide what a signal means, and produce the timely, accurate intelligence that law enforcement and financial intelligence units can act on. The right model is human-in-the-loop by design: AI to find the faint signal at scale, expert analysts to interpret it, and systems transparent enough that every decision can be explained to a supervisor.

The urgency is growing. Researchers are already warning of 'agentic smurfing' – the use of autonomous AI to fragment and move illicit funds faster than traditional detection can respond [5]. When adversaries automate, defenders must do the same. A bank relying on fixed rules and manual review will not keep pace with AI-driven financing; only AI-enabled monitoring and screening, governed by expert humans, realistically can.

What This Means for Banks

Whether an institution operates in a high-risk corridor or a mature market, the practical implications are consistent,:

  • Treat terrorist financing as a distinct discipline, not a by-product of anti-money-laundering controls. The indicators, amounts and direction of funds are different.

  • Move beyond fixed rules towards behavioural and network analytics that can see distributed, low-value activity across accounts and channels.

  • Modernise screening so it understands names and context across languages and extends to adverse media, rather than relying on static lists alone.

  • Invest in explainability and skilled analysts, because terrorist-financing decisions must be defensible to regulators and genuinely useful to law enforcement and financial intelligence units.

  • Assume adversaries are using AI, and plan to meet automation with automation.

Next Steps for Detection

Terrorism is more dispersed than it has been in years, its financing smaller and more digital, and the detection problem correspondingly harder. The numbers make the point: a threat now touching 66 countries, funded increasingly through stablecoins and crowdfunding, against a system in which most jurisdictions still struggle to convict. 

Banks sit at a critical chokepoint, but the tools that served the last decade will not serve this one. AI, paired with skilled analysts and a commitment to explainable, well-governed systems, offers the most realistic path to detecting the small, scattered money that funds violence, and staying ahead of adversaries who are themselves turning to AI.

Contributor

James Booth

Head Anti-Money Laundering, Counter Terrorism & Sanctions

James Booth

Head Anti-Money Laundering, Counter Terrorism & Sanctions

Share article

Latest news

Discover how AI is Revolutionising Compliance and Risk Adjudication

Download our latest collateral to stay ahead.

Discover how AI is Revolutionising Compliance and Risk Adjudication

Download our latest collateral to stay ahead.

Discover how AI is Revolutionising Compliance and Risk Adjudication

Download our latest collateral to stay ahead.