A 55-year-old man in New York was arrested after manufacturing seven improvised explosive devices. He admitted to using AI tools to determine which chemicals to purchase and how to mix them to create the explosives. The perpetrator transported the devices to Manhattan, storing some on a residential rooftop and discarding others in public areas, including subway tracks, before being apprehended by law enforcement.
Federal prosecutors allege that Michael Gann, a 55-year-old Long Island man, used AI tools to identify chemicals and instructions for making improvised explosive devices. He allegedly built seven bombs, transported them to Manhattan, and stored five with shotgun shells on a rooftop. Authorities say he tested and discarded some devices in public areas before his June 5, 2025 arrest. Gann faces federal charges; no injuries were reported.
Risk classification
- Primary risk domain: 4 Malicious actors
- Primary risk subdomain: 4.2 Cyberattacks, weapon development or use, and mass harm
The perpetrator used an AI system to acquire instructions for purchasing and mixing chemicals to manufacture improvised explosive devices, representing the use of AI to develop weapons.
Additional risk subdomains
- 1.2 Exposure to toxic content: The AI system exposed the user to toxic and dangerous content by providing actionable instructions on how to manufacture explosives.
Causal factors
- Entity: Human
- Intent: Intentional
- Timing: Post-deployment
The incident was caused by a human actor who intentionally used a deployed AI system to obtain instructions for manufacturing improvised explosive devices.
EU AI Act risk tier
- Risk tier: 3 Limited Risk
Limited Risk: The system functioned as a chatbot or information retrieval assistant, which falls under the category of AI systems requiring transparency obligations.
AI system and alleged parties
- AI system: None named
- AI purpose: Question Answering; Technical Text Generation
- Behaviour type: Assistant
- Alleged developer: Unknown generative AI developer
- Alleged deployer: Michael Gann
- Alleged harmed parties: General public of New York City
Harm severity
Highest direct severity in any category: Minor. Severity is scored from Negligible to Catastrophic in each harm category, for harm the reports describe as caused directly or indirectly by the AI system.
- Physical: direct Negligible, indirect Negligible
- Infrastructure: direct Negligible, indirect Negligible
- Property: direct Negligible, indirect Negligible
- Financial: direct Negligible, indirect Negligible
- Environmental: direct Negligible, indirect Negligible
- Malicious content: direct Negligible, indirect Negligible
- Differential treatment: direct Negligible, indirect Negligible
- Civil rights: direct Negligible, indirect Negligible
- Democracy: direct Negligible, indirect Negligible
- Privacy: direct Negligible, indirect Negligible
- Psychological: direct Negligible, indirect Negligible
- Epistemic: direct Negligible, indirect Negligible
- Child sexual exploitation and abuse: direct Negligible, indirect Negligible
People affected
- Occurrences reported: 1
- People reportedly exposed: 100
Potential causes
Technology
- AI Chemical Synthesis Advice: AI provided instructions on purchasing and mixing chemicals for explosives.
- Insufficient Safety Filters: AI failed to block queries seeking dangerous chemical recipes.
Data Inputs
- Hazardous Training Data: Training datasets contained dangerous chemical synthesis information.
Human Factors
- User Intent to Build Bombs: Individual actively sought to manufacture improvised explosive devices.
- Hostile Ideological Motives: User expressed hostility and targeted a neighborhood Jewish school.
Process and Methods
- Online Chemical Sourcing: E-commerce methods allowed easy acquisition of dual-use compounds.
Regulatory Environment
- Lax Precursor Regulations: Weak controls on purchasing household compounds used to make explosives.
Information quality
- Classification confidence: Medium
- Reason for confidence: The reports provide clear details about the suspect's actions, arrest, and his admission of using AI to learn how to make bombs. However, the specific AI model, developer, and exact prompts used are not identified, which limits our ability to fully assess the system's safety guardrails or specific behavior.
- Ambiguities identified: The specific AI system used is not named, and the exact nature of the instructions provided by the AI is not detailed.
- Alternative interpretations: The AI could have been a standard search engine with AI integration rather than a dedicated large language model chatbot.
- Missing information: The identity of the AI model or platform used, the exact prompts entered by the suspect, and the specific outputs generated by the AI.
A US resident used AI to bypass safety barriers and obtain detailed instructions to manufacture seven IEDs, which were deployed in public areas in New York before law enforcement intervention. This highlights an evolved threat where AI lowers the barrier to acquiring hazardous chemical recipes, presenting substantial physical security and critical infrastructure risks.
- Overall national security impact: Substantial
- Response level: Substantial
- Scope: Single nation
- Primary target: United States
- Alleged perpetrator: Individual
Threat characteristics
- Imminence: Long-term. While the immediate crisis was resolved by law enforcement, the strategic concern regarding AI-enabled explosive manufacturing instructions remains ongoing.
- Autonomy: Human-controlled. The AI acted as an information retrieval assistant, with the human user making all decisions and executing the physical actions.
- Novelty: Evolved capability. Represents an advancement of existing online search threats, where AI systems lower the barrier to acquiring actionable chemical weapon recipes.
Impact by dimension
- Physical security: Substantial. The perpetrator used AI to successfully manufacture multiple IEDs and placed them in public areas, including subway tracks, threatening critical infrastructure and civilian lives.
- Information security: Negligible. No evidence of information warfare, deepfakes, or intelligence compromise was associated with this incident.
- Sovereignty: Negligible. No direct threats to state authority, electoral systems, or core government decision-making processes were observed.
- Economic security: Negligible. The incident did not target financial systems, strategic industries, or involve the theft of critical technological assets.
- Societal stability: Minor. The placement of explosives in residential areas and targeting of a Jewish school threatened local societal safety, though managed by law enforcement.