Iran's use of AI has enhanced its existing asymmetric warfare tactics and cyber capabilities, posing significant threats to regional stability and security.

Introduction
Between January and June of 2026, Iran adapted to intense military, economic, and political pressures by effectively leveraging its established hybrid warfare strategy. This involved a sophisticated combination of asymmetric military operations, cyber initiatives, and information warfare. In this context, AI acted as a vital force multiplier, significantly enhancing Iran’s operational speed, scale, and overall effectiveness without fundamentally reshaping its strategic approach.
AI's Role in Iran's Hybrid Warfare
Instead of developing entirely new capabilities, AI likely intensified existing strengths in Iran's arsenal, especially within cyber operations and information warfare. The recent crises revealed that Iran's adaptable and scalable military tactics remained paramount, even as AI technologies improved efficiency. For instance, the production of propaganda and disinformation was notably accelerated by AI systems, allowing for rapid dissemination of narratives that could influence both internal and external perceptions.
Enhancements in Cyber Operations
Iran's application of AI within its cyber warfare strategy predates the recent crises, but the need to counter US and Israeli actions prompted a more aggressive deployment of these tools. State-sponsored hackers reportedly utilized generative AI to improve productivity across various cyber domains, including reconnaissance and malware development. However, the core tactics remained consistent with previous operations, primarily involving spearphishing and the use of wiper malware, indicating AI's role was more about refining existing methods than inventing new ones.
Reconnaissance and Targeting
Reports suggest that Iranian threat actors, such as the hacktivist group CyberAv3ngers, have leveraged AI tools for effective reconnaissance on critical infrastructure, demonstrating how generative AI helps streamline the research phase of cyber attacks. For instance, potential vulnerabilities in industrial control systems became easier to identify using AI, leading to more precise targeting strategies against adversaries like the U.S. The focus on exploiting supply chain vulnerabilities highlights Tehran's emphasis on disrupting key industries of its opponents.
Malware Development
Iranian-linked groups are also reportedly utilizing AI to expedite malware creation, employing platforms like Google’s Gemini. In 2026, various campaigns delivered novel malware types via techniques such as spearphishing, with findings suggesting that AI tools may have been used to enhance both efficiency and effectiveness in code development. For example, an analysis of specific malware samples indicated indicators consistent with AI-generated content, showing potential lapses in traditional coding practices.
State Control and Domestic Repression
On the domestic front, AI-driven surveillance technologies played a significant role during and after the 2022 “Woman, Life, Freedom” protests. These systems likely bolstered the Iranian regime's capabilities to suppress dissent, illustrating AI’s dual-use potential in both warfare and internal security operations. While the primary goal of these implementations remains the preservation of state power, the effectiveness and scalability of AI-enhanced methods pose new challenges for counteracting state repression.
Future Implications for Regional Security
The ongoing low-level conflict with the US and Israel and the prospect of future hostilities make Iran's expanding use of AI-based cyber operations a significant concern. The rapid generation of persuasive narratives using AI exposes various sectors—both corporate and governmental—to targeted influence operations. As Iran looks to upgrade its military assets, particularly through alliances with Russian-backed drone technology, critical infrastructure and regional logistics will likely remain at risk from AI-enhanced threats.
Strategic Partnerships and Limitations
Iran's technological ambitions have faced severe constraints due to international sanctions and economic isolation, impacting its ability to achieve its AI objectives fully. Nevertheless, these challenges have not deterred Tehran from pursuing international partnerships, notably with Russia and China, to enhance its capabilities further in military AI, surveillance technologies, and critical infrastructure defenses. The drive to harness foreign innovations within its established strategies underscores Iran's unyielding quest to stay relevant in an increasingly competitive technological landscape.
Conclusion
Through the lens of AI application, Iran's asymmetric warfare tactics have been recalibrated, amplifying existing capabilities while maintaining traditional strategic frameworks. As the conflict landscape shifts, organizations must recognize and prepare for the elevated risks posed by Iran's evolving tactics, rooted in its hybrid warfare doctrine. Continuous advancements in AI by Iranian state actors could further complicate the security dynamics in the region, necessitating proactive resilience measures from both state and corporate entities.
Discussion
Sign in to join the discussion.