Street Gangs, AI, and the Internet: The New Battleground
The convergence of artificial intelligence, encrypted messaging, and political extremism across the spectrum marks the most significant transformation in criminal enterprise since the dawn of the web.
Executive Summary
The war against organized crime and violent extremism has shifted into the digital shadows. Today, street enforcers operate alongside cyber-savvy operatives wielding Large Language Models, voice cloning tools, and automated exploit frameworks. From Mexican cartels deploying AI disinformation during kinetic crises to Dark LLMs offering Crime-as-a-Service on darknet forums, traditional criminal boundaries have dissolved. This investigation provides a non-partisan, comprehensive analysis of how cartels, jihadist networks, far-right accelerationists, far-left direct action groups, and autonomous cybercrime platforms are rewriting the rules of engagement in 2026.
§ 1. The Digital Battlefield
The battlefield has shifted. A decade ago, the fight against street gangs and organized criminal networks meant boots on the ground, wiretaps, and physical surveillance. Today, the war is being waged in the digital shadows — on encrypted messaging apps, in AI-generated propaganda, and through automated extortion bots that never sleep. The street thug with a knife has been joined — and in some cases replaced — by the cyber-savvy operative wielding a large language model.
The convergence of artificial intelligence, social media, and organized crime represents the most significant transformation in criminal enterprise since the dawn of the internet. And it is not just traditional street gangs adapting to the new reality. Across the ideological spectrum — from jihadist networks to neo-Nazi accelerationists, from Antifa-affiliated anarchists to far-left guerrilla movements — motivated political groups are exploiting the same technologies with alarming sophistication.
This is the new battleground. And understanding its contours — without partisan blinders — is essential for anyone concerned with public safety, national security, or the future of civil society.
§ 2. The Cartel Goes Digital
In February 2026, Mexican special forces killed Nemesio "El Mencho" Oseguera Cervantes, the notorious leader of the Jalisco New Generation Cartel (CJNG). Within hours, the cartel's response was not just kinetic — it was algorithmic. Across 20 of Mexico's 31 states, the organization erected 252 burning roadblocks. But equally significant was what happened online: a coordinated flood of real and AI-generated imagery designed to create the impression that the entire country was on fire.
Fake images of burning passenger planes, churches in flames, and armed men seizing airports spread across social media. Fact-checkers later debunked many of these as AI fabrications. But by then, the psychological damage was done. The message was fear, and the medium was the algorithm.
This hybrid warfare — blending real-world violence with digital disinformation — marks a new chapter in organized crime. The CJNG, like its rival the Sinaloa Cartel, has built specialized technological units. They use AI-powered voice cloning to simulate kidnappings, convincing family members their loved ones are in danger. They deploy conversational bots for "pig butchering" scams — long-term emotional manipulation schemes that build fake romantic relationships to defraud victims of their savings. They scrape social media and leaked databases to build detailed vulnerability profiles of potential targets.
In India, the Lawrence Bishnoi gang has engineered a chilling new-age extortion network where fear is no longer the primary weapon — data is. Operatives systematically scan publicly available data on GST and RERA portals, mining business turnover, project details, and financial footprints to identify high-value targets. Threats are delivered via encrypted apps like Signal, making them extremely difficult to trace. The gang recruits teenagers through Instagram, lured by flashy lifestyles, then deploys them as foot soldiers. "They deliberately use minors. Easy bail, difficult to trace networks," one police officer told NDTV.
"Nowadays, violence is simulated, automated, and scalable," notes a recent analysis from the Small Wars Journal. The cartels have recruited data engineers, software developers, and cryptocurrency specialists to work alongside traditional enforcers. The AK-47 has not been retired — but it now shares space with the script, the deepfake, and the automated threat.
§ 3. The Jihadist Digital Caliphate
The Islamic State (ISIS), despite losing its physical caliphate, has built a digital one. Its "News Harvest" program produces AI-generated news bulletins featuring synthetic presenters who deliver jihadist propaganda in multiple languages with professional broadcast aesthetics. These videos are distributed across Telegram, TikTok, Facebook, and X, targeting audiences from Iraq to Indonesia to Europe.
In June 2025, ISIS's Afghanistan affiliate, Islamic State Khorasan (ISIS-K), published guidance framing AI literacy as a religious obligation for every Muslim. The group has since walked back the theological framing — reportedly after ridicule from other jihadist factions — but the practical guidance remains. Supporters are taught to use AI for translation, propaganda generation, and operational security.
Al-Qaeda, characteristically more deliberate, has taken a different approach. Its affiliated Anaziat Foundation has published a multi-part series translating Western strategic writing on AI and warfare, asking whether the technology changes the nature of war itself. The conclusion is telling: technology may change how wars are fought, but endurance, political will, and human agency determine who ultimately wins. Al-Qaeda is thinking in decades.
The Institute for Strategic Dialogue's 2026 assessment of the ISIS online ecosystem found that the network remains remarkably resilient. "If they close one account, open another three," goes the infamous ISIS video. "And if they close three accounts, open another 30." The ecosystem has absorbed years of platform takedowns and emerged more distributed, more encrypted, and more AI-enabled than ever.
§ 4. Far-Right: Accelerationists, Neo-Nazis, and AI Propaganda
Far-right extremist groups have been early and aggressive adopters of AI technology. German far-right actors affiliated with the Alternative für Deutschland (AfD) party have used generative AI to create images, memes, and even songs that attack refugees, immigrants, LGBTQ+ activists, and climate protesters. An ISD investigation found that AI-generated content calling for "remigration" — the widescale deportation of ethnic minorities regardless of immigration status — received the highest levels of engagement. Three AI-generated female "influencers" were identified, posting far-right narratives while purporting to be real women, building parasocial relationships with their audiences.
The far-right social network Gab created a Hitler chatbot that users can interact with. On 4chan and Soyjak Party, users have developed "fully autonomous AI doxxing tools" that scrape breached databases to compile personal information on targets — predominantly Jewish influencers, transgender artists, and other minority figures — for use in harassment campaigns. One tool, debuted in March 2026, was described as a "full autonomous, and FREE doxxing AI agent" capable of producing complete dox profiles "in one prompt."
Neo-Nazi groups have used AI voice cloning to resurrect the voices of dead ideologues. The far-right has also exploited trigger events — the stabbing of Austin Metcalf, the killing of Iryna Zarutska, the assassination of conservative activist Charlie Kirk — to advance narratives of white victimhood and justify calls for retaliatory violence. Following Kirk's murder, far-right groups organized rallies explicitly positioning Kirk and Zarutska as "martyrs," with banners urging supporters to "Crush the Left."
A 2025 NYU Stern Center for Business and Human Rights report documented how far-right networks operate relatively openly on Telegram and X, using mainstream sites for visibility and recruitment while maintaining encrypted channels for coordination. The report found that far-right groups "capitalized on cases like the Austin Metcalf stabbing and the Iryna Zarutska killing to advance narratives of White victimhood and justify threats against perceived enemies."
§ 5. Far-Left: Antifa, Anarchist Networks, and Digital Direct Action
On the opposite end of the spectrum, far-left groups have built their own sophisticated digital infrastructure. Antifa — a decentralized movement of anarcho-communist affinity groups — has long used encrypted platforms like Signal for operational coordination. A 2026 academic study from the Technical University of Munich examined 768 forwarded messages among 78 German antifascist Telegram channels over five years, confirming that "spatial, social, and ideological proximity" drives collaboration and information diffusion across the network.
In the United States, the Department of Justice indicted 15 alleged Antifa activists in Minnesota on conspiracy charges in 2026, accusing them of using Signal chat groups and rapid-response networks to track federal immigration agents, organize blockades, and coordinate efforts to impede arrests. The 94-page indictment detailed the network's organizational structure, operational strategies, and covert communication tactics — exposing what prosecutors described as a coordinated conspiracy rather than spontaneous protest.
The far-left online ecosystem extends beyond American shores. In Colombia, FARC dissident groups and the National Liberation Army (ELN) — Marxist-Leninist guerrilla organizations — have embraced social media for recruitment and propaganda. A July 2025 GNET analysis found that these groups use TikTok to target minors with content glorifying guerrilla life, with videos of coca harvesters and armed camps drawing comments from users asking how to join. Facebook accounts openly declare affiliation with dissident fronts. WhatsApp chains are used to issue curfews, threaten local leaders, and control civilian populations in areas under guerrilla influence.
In the United States, groups like Unity of Fields — formerly known as Palestine Action US — and the People's City Council of Los Angeles have used X and Telegram to dox law enforcement officers, posting names, photographs, and personal information alongside dehumanizing rhetoric. One post doxxing an LAPD officer garnered 1.5 million views, 24,000 likes, and 6,100 reshares. Unity of Fields celebrated the May 2025 murder of two Israeli embassy staffers in Washington, D.C., and is helping raise money for the legal defense of the accused killer.
The Italy-based Autistici/Inventati (A/I) Collective provides anonymous digital infrastructure — email servers that do not track senders' locations, blogging platforms that store no identifying data — to far-left groups worldwide. The collective explicitly recommends its services for anyone looking to "do something nasty without being caught." Its platform has hosted Rose City Counter-Info, an Antifa-aligned site that published ICE agents' home addresses and called on protesters to shine lasers at federal aircraft; Abolition Media, a forum linked to an arsonist convicted for attacks in California; and Jane's Revenge, a group that took credit for firebombing pro-life facilities.
Meanwhile, Occupy Wall Street co-founder Micah White launched "Outcry" in 2026 — an AI chatbot app designed specifically as a "private, on-device AI mentor for activists, organizers and movement builders." The app, trained on a library of activist literature, represents an effort to harness LLM technology for left-wing organizing.
A troubling pattern documented by researchers is the cross-ideological convergence around antisemitic targeting. Following the Capital Jewish Museum shooting in May 2025, both far-left and far-right networks celebrated the murders. The NYU Stern report noted that "activities of both far-left and far-right networks revealed a troubling convergence around antisemitic targeting."
§ 6. The Dark LLMs: Crime-as-a-Service
Perhaps the most ominous development is the emergence of "Dark LLMs" — large language models deliberately built or jailbroken for criminal purposes. WormGPT, FraudGPT, DarkBARD, and the more recent Xanthorox AI represent a new category of threat: autonomous criminal platforms offered as a service.
Xanthorox AI, which surfaced on darknet forums in early 2025, is not a criminal organization in any traditional sense. It has no leaders, no geographic base, no hierarchy. It is an interface. Users type their intentions in natural language — "find vulnerabilities in the hospital infrastructure of country X" — and the system autonomously generates exploits, structures attacks, and deploys operations. It includes modules for code generation, visual recognition for phishing, and a reasoning engine that emulates human social engineering.
The barrier to entry for cybercrime has collapsed. What once required advanced technical skills, infrastructure, and support networks is now condensed into a conversational interface. Any individual with political, financial, or even emotional motivation can launch a sophisticated attack without belonging to any structured criminal collective.
The convergence of cybercriminal and extremist networks compounds the danger. Research from Moonshot and GNET documents how cybercrime groups like Scattered Spider and LAPSUS$ share membership with nihilistic violent extremist communities. Tools developed for financial crime are being marketed directly to extremist Telegram channels — both far-right and far-left. The boundary between profit-driven cybercrime and ideologically motivated violence is dissolving.
§ 7. Law Enforcement Fights Back — With AI
The same technology being weaponized by criminals and extremists is also being deployed against them. Police forces worldwide are racing to integrate AI into investigative workflows.
In India, Uttar Pradesh police launched the "YAKSH App" — an AI-powered tool that uses facial recognition and voice search to identify suspects, analyze crime data, and map gang networks. Delhi Police officers are training their Instagram algorithms to become crime-hunting machines, deliberately consuming gang-related content so the platform surfaces more of it — turning the recommendation engine into a surveillance tool.
Japan's National Police Agency announced plans to use generative AI to analyze investigative information and identify leaders of "tokuryu" — anonymous criminal groups that operate through loosely connected social media networks. These groups are notoriously difficult to penetrate because even the foot soldiers do not know who is giving the orders. AI is being used to map the invisible command structures.
In the United Kingdom, police are trialing AI technology that analyzes data from the country's network of more than 12,000 ANPR cameras to identify "suspicious" journeys linked to county lines drug trafficking. The system uses machine learning to detect patterns that human analysts would miss.
The European Union's ROXANNE project built an all-in-one investigation platform that combines speaker identification, automatic speech recognition, named entity detection, and criminal network analysis. It can process thousands of intercepted phone calls, automatically transcribe them in multiple languages, identify speakers across different recordings, and build knowledge graphs that reveal hidden connections between suspects.
Perhaps most significantly, researchers are deploying graph neural networks (GNNs) to predict hidden alliances in criminal networks. A 2025 study published in the Journal of Computational Social Science demonstrated that GNN-based models achieved near-perfect accuracy in identifying unobserved ties between criminal organizations — the kind of intelligence that can preempt violence before it occurs.
§ 8. The Policy Gap
Despite these advances, the institutional response remains dangerously fragmented. A comprehensive EU-funded study published in September 2025 by the EL PACCTO program found that most countries lack specific criminal definitions for AI-enabled offenses. Voice cloning for extortion, synthetic content for blackmail, fraud automation via intelligent systems, and algorithmic manipulation of emotions are not adequately covered by existing laws.
The study's recommendations are stark: criminalize emerging algorithmic offenses, establish operational cooperation frameworks with digital platforms, create specialized units for algorithmic crime, develop forensic protocols for AI-generated evidence, and build a regional database on AI-enabled criminal incidents.
Some progress is being made. The EU's Digital Services Act and the UK's Online Safety Act represent meaningful regulatory frameworks. Europol has conducted multinational operations targeting AI-generated child sexual abuse material — Operation Cumberland in 2025 identified over 273 suspects across 19 countries. Microsoft has taken legal action against Storm-2139, a global cybercrime network that exploited Azure OpenAI services to generate harmful content.
But the criminals and extremists — of every ideological stripe — are moving faster than the regulators. As the EL PACCTO report concludes: "When crime learns faster than justice, reaction is not enough: we must anticipate."
§ 9. The Human Dimension
Behind the technological arms race lies a human tragedy. The victims of AI-enabled crime are numerous, dispersed, and often invisible. They include elderly individuals deceived by voice-cloned "grandchild in trouble" scams, small business owners subjected to automated extortion campaigns, women targeted by AI-generated non-consensual intimate imagery, and teenagers radicalized through algorithmically curated extremist content — whether jihadist, far-right, or far-left.
In Myanmar's KK Park — a scam-factory city on the Thai border — an estimated 20,000 people are held in conditions of digital slavery, forced to operate fraudulent platforms under threat of torture. The compound represents a new model of criminal enterprise: a fusion of Chinese mafia networks, local ethnic militias, and AI-powered fraud infrastructure. Workers are trafficked from across Africa, Asia, and Latin America, then forced to run scams targeting victims worldwide.
The psychological toll extends beyond direct victims. When a Mexican cartel floods social media with AI-generated images of burning cities, the target is not just territory — it is the public's perception of reality. When Russian disinformation operations clone European news websites to spread pro-Kremlin narratives, the target is not just an election — it is the very possibility of shared truth. When ISIS produces AI news bulletins that mimic the aesthetics of BBC or CNN, the target is not just recruitment — it is the erosion of trust in all media. When far-left groups dox police officers and far-right groups build autonomous doxxing AIs, the target is not just individual victims — it is the fabric of a society where disagreement is settled by intimidation rather than debate.
§ 10. What Comes Next
The trajectory is clear, and it demands a response that matches the scale of the threat — without partisan selectivity.
- Legal Framework Modernization: Malicious uses of AI — from voice cloning for extortion to synthetic CSAM creation — must be explicitly criminalized across jurisdictions without regard to ideology.
- Sustained AI Investment in Law Enforcement: Police forces require dedicated funding for forensics, network analysis, and AI investigative tools to keep pace with algorithmic threats.
- Cross-Border Operational Integration: Response networks must mirror the transnational fluidity of cartels, jihadist networks, and cyber collectives.
- Tech Platform Accountability: Social networks and infrastructure hosts must enforce moderation standards against doxxing, terrorism monetization, and automated harassment agents.
- Public Algorithmic Literacy: Educational initiatives must empower citizens to recognize synthetic media, cloned voices, and algorithmic manipulation.
The street gang and the political extremist — of every ideology — have always exploited the tools of their time. What has changed is the scale, speed, and sophistication of those tools. AI does not create new kinds of crime — it makes existing crimes cheaper, faster, and harder to trace. It removes the human from the loop, replacing the threatening phone call with an automated bot, the propaganda poster with a synthetic news anchor, the physical recruiter with an always-available chatbot.
The internet is the new battleground. The weapons are algorithms. The adversaries range from cartel operatives to jihadist media wings, from neo-Nazi accelerationists to Antifa affinity groups, from state-sponsored disinformation networks to nihilistic violent extremists who reject ideology altogether in favor of chaos and notoriety. And the fight — which must be waged with clear eyes, consistent principles, and no partisan double standards — is only beginning.