On September 11, 2001, al-Qaeda demonstrated that a relatively small organisation, protected by a territorial haven and possessing centralised leadership, training camps, and transnational networks, could transform a few dozen operatives into a strategic capability capable of striking the United States and altering the international agenda for decades. Twenty-five years later, however, simply searching for “the new al-Qaeda” risks being the wrong way to view jihadism.
The architecture that produced 9/11 has been largely dismantled. Osama bin Laden and Ayman al-Zawahiri have been eliminated, much of the historic leadership has been neutralised, and al-Qaeda no longer enjoys the Afghan environment that, before 2001, allowed it to train militants and plan international operations with a level of freedom that would be difficult to replicate today.
The Islamic State has undergone an equally radical transformation. The loss of Mosul, Raqqa, and finally Baghouz destroyed the territorial project that, between 2014 and 2019, had consolidated territory, population, resources, foreign fighters, military apparatus, and propaganda under a single structure.
Yet global jihadism has not disappeared; it has adapted, underscoring the need to remain vigilant and responsive to evolving threats.
In 2001, the threat was characterised primarily by a concentration of capability. In 2014, the Islamic State added an unprecedented territorial concentration. In 2026, the dominant model is different: distributed capability.
Today, jihadist capability is distributed across regional organisations, insurgencies, Islamic State provinces, clandestine cells, logistical and financial networks, propaganda apparatuses, and digital communities. Recognising these regional nodes can help the audience appreciate their strategic importance and the need for targeted responses.
The 2026 paradox: a weaker centre, a more resilient periphery.
Measuring the strength of jihadism solely by the state of central leadership yields an incomplete picture today. Al-Qaeda’s leadership is presumably weaker than it was in 2001. The 38th report by the United Nations Analytical Support and Sanctions Monitoring Team, published on August 10, 2026, and based on information available up to June 9, describes al-Qaeda’s senior leadership as marginalised and views both its capacity for and priority regarding the conduct of external operations as uncertain. However, the same report assesses that the overall threat level has remained substantially unchanged, even as it has intensified in the Sahel and South Asia1.
The American assessment presents the same paradox from a different perspective. The 2026 Annual Threat Assessment estimates the number of al-Qaeda members worldwide at between 15,000 and 28,000, and those linked to the Islamic State at between 12,000 and 18,000. According to the U.S. Intelligence Community, the growth recorded over the past five years has occurred primarily within African conflicts, where some of the largest and most violent affiliates are located2.
Decentralisation has made jihadism harder to gauge and, consequently, complicates threat assessment and strategic planning, affecting how policymakers allocate resources in certain theatres.
The centre has weakened, so counterterrorism efforts must now focus more on peripheral branches that operate independently, requiring adjustments to operational security measures and intelligence priorities.
The centre has weakened. Some peripheral branches have strengthened.
No single epicentre remains.
The second transformation is geographical. In 2001, the primary jihadist stronghold was Afghanistan. Over the next decade, Iraq, Yemen, Somalia, and North Africa became central theatres of operation. Between 2014 and 2019, Syria and Iraq constituted the symbolic, territorial, and propaganda hub of the Islamic State. By 2026, no single geographical equivalent exists.
The UN Monitoring Team employs a significant phrase: the threat is “multipolar and increasingly complex.” This highlights the need for the audience to appreciate the multifaceted nature of the threat landscape and adapt strategies accordingly.
Statistically, however, the growth in Africa is unmistakable. Attacks attributed to the Islamic State and al-Qaeda have nearly doubled. This shift does not mean that the Middle East has become irrelevant. It means that the geography of jihadism can no longer be interpreted through the Iraq-Syria paradigm. The Sahel, the Lake Chad basin, Somalia, East Africa, the Democratic Republic of the Congo, Mozambique, and the Afghanistan-Pakistan ecosystem are now strategically central areas.
Case Study: JNIM, when counting attacks is no longer enough.
The Sahel arguably represents the most significant laboratory for this transformation. JNIM should no longer be analysed merely as a regional al-Qaeda affiliate capable of carrying out attacks, but rather as an insurgent system.
Operational monitoring conducted for the “Strategic Outlook” series on this site recorded 85 attacks in January 2026, 71 in February, 89 in March, 78 in April, 92 in May, 52 in June, 158 in July, and 93 in August, totalling 718 actions over eight months3.
However, the number of attacks is not the most critical indicator. An August 2026 UN report estimates JNIM’s membership at approximately 7,000–8,000, with about half concentrated in Mali, and identifies the group as the primary terrorist threat in the Sahel. The Monitoring Team highlights the organisation’s command, control, and coordination capabilities across its combat units as a key strength, noting its increasing use of commercial satellite communication systems to maintain resilient connectivity and real-time coordination in remote areas4.
Financial capacity is even more significant. The same report indicates that a large portion of a roughly $50 million ransom received in 2025 was redistributed among JNIM’s *katibas*, playing a major role in funding the 2026 offensive in Mali. Some funds were reportedly allocated to AQIM, while the report assesses it as likely that a share of the revenue flowed into the broader al-Qaeda network5.
Here, an often-underestimated strategic variable emerges. When an organisation simultaneously possesses thousands of fighters, inter-regional coordination capabilities, substantial independent revenue streams, geographic depth, resilient communication systems, and the ability to influence transportation and economic activity, a simple tally of attacks captures only part of the threat. JNIM is progressively developing the capacity to determine not only where to strike the state, but also where the state can manoeuvre, resupply, and maintain a presence. This represents a fundamental difference.
From Terrorism to Insurgency
The transformation in the Sahel highlights a broader issue. Many of the organisations we continue to classify as “terrorist” employ terrorism merely as one component of a much wider operational repertoire. JNIM and al-Shabaab are prime examples. Al-Shabaab has not survived for nearly two decades simply because it remains capable of constructing explosive devices or assassinating officials. Its resilience stems from a combination of military activity, intelligence gathering, taxation, coercion, parallel justice systems, propaganda, and the ability to embed itself within local economies.
Monitoring conducted for my Strategic Outlook reports on the group recorded 73 attacks in January 2026, 53 in February, 72 in March, 54 in April, 64 in May, 48 in June, 97 in July, and 152 in August, totalling 613 actions6.
Furthermore, al-Shabaab has undergone a qualitative shift in its operational conduct, moving toward more “targeted and strategic” operations. International military pressure remains high. AFRICOM recorded 78 strikes in Africa during 2026 up to early August, with a significant portion concentrated on Somalia. In July alone, strikes against al-Shabaab were reported in Jamaame, Welmaro, Sablaale, Qumbi, Baqdaad, Juba, Jamame, Farsooley, and Jilib7.
The campaign’s persistence does not prove the strikes are ineffective; that would be a methodologically flawed conclusion.
Rather, it demonstrates that tactical degradation and strategic resolution are not the same thing.
Counterterrorism and counterinsurgency are not synonymous.
Leadership can be eliminated. A financial network can be disrupted. A camp can be destroyed. But when an organisation has embedded itself in local economies, community disputes, criminal networks, and areas where the State’s presence is intermittent, neutralising it cannot be reduced to a targeting problem.
Islamic State: The Caliphate has been destroyed, but the network has not.
The same distinction applies to the Islamic State. The destruction of the territorial caliphate represented a massive strategic defeat. It eliminated the ability to govern millions of people openly, utilise state infrastructure, concentrate vast economic resources, and attract tens of thousands of foreign fighters; however, the central territory and the global network were not the same.
The 38th UN report from August 2026 describes the organisation’s core as struggling, subjected to persistent counter-terrorism pressure, plagued by leadership issues, and unable to provide coherent direction to the network as a whole. Nevertheless, its propaganda and capacity for incitement remain potent8.
This combination is significant, as a strategically weakened core can coexist with highly active regional affiliates. ISWAP, IS Sahel, ISCAP, Islamic State Mozambique, and Islamic State Somalia do not share the same capabilities, priorities, or trajectories.
The pertinent question is not simply how strong the Islamic State is, but rather what function each node within the system performs. Some provinces primarily constitute local insurgencies, whereas others generate resources, facilitate the transfer of personnel and know-how, and hold greater importance for the trans-regional network.
A case in point is the Islamic State Khorasan Province (ISKP), which remains one of the most critical nodes for assessing the external threat.
The UN Monitoring Team believes that ISKP has suffered serious setbacks due to counter-terrorism operations conducted by the Taliban and Pakistan. Yet, it simultaneously highlights the group’s persistent intent to carry out external operations. The group appears to be in a rebuilding phase, retaining the capacity to carry out infrequent yet high-profile attacks and, according to UN-consulted member states, possessing drones, night-vision devices, thermal imagers, and specialised training9.
Like ISKP, AQAP is among the groups most likely to engage in future external plotting activities. This assessment highlights a fundamental distinction: intent does not equate to capability.
While numerous jihadist organisations threaten the West in their propaganda, far fewer possess the combination of reliable personnel, facilitators, funds, documentation, secure communications, know-how, and access to the target area required to turn intent into a complex operation. A proper threat assessment must therefore measure the gap between will and capability. ISKP is particularly significant because it has demonstrated a greater inclination than many other affiliates to attempt to bridge that gap.
Al-Qaeda: Leadership in Decline, AQAP Seeks Centrality
Al-Qaeda today requires a more granular analysis; while its leadership remains marginalised, the network has not disappeared. A particularly important element of the 2026 landscape is AQAP, which appears increasingly intent on assuming greater ideological and operational leadership within the global al-Qaeda network. In August, the aforementioned Monitoring Team went further, defining the group as “the vanguard of the global Al-Qaida movement” and highlighting its commitment to external operations.
In February 2026, member states also reported an improvement in AQAP’s financial situation, fueled by the smuggling of goods and weapons between Somalia and Yemen, as well as by kidnapping for ransom and extortion. The Monitoring Team also noted economic ties with al-Shabaab10.
AQAP took advantage of the security vacuum in southern Yemen during the first months of the year to strengthen its capabilities; however, none of these indicators demonstrates that AQAP has returned to the external operational capacity of its most dangerous years. Given a history of external plotting, a deteriorating environment, improved finances, and the ambition to assume a more central role in the network, this warrants priority monitoring.
Afghanistan-Pakistan: The Problem Is the Ecosystem
South Asia constitutes the other theatre where the threat intensified in 2026. The most evident operational data concerns the TTP. Monitoring conducted for this site’s Strategic Outlooks recorded 245 attacks in January 2026, 352 in February, 385 in March, 409 in April, 309 in May, 336 in June, 315 in July, and 406 in August, totalling 2,757 actions over eight months11. While the TTP remains primarily focused on the Pakistani state, there is insufficient evidence to automatically translate this immense insurgent capability into a comparable direct threat to Europe or the United States. However, a different strategic factor is at play, as highlighted by the UN, namely that al-Qaeda continues to provide the TTP with ideological guidance, training, and support. Meanwhile, AQIS remains a regional entity that has become more cohesive, even as it continues to operate through decentralised cells and, as of 2025, supports the IMP in Pakistan.
The key variable to monitor, therefore, is not merely the existence of formal alliances, but the cross-pollination of capabilities. An ecosystem where the TTP, IMP, ISKP, AQIS, elements of al-Qaeda’s central leadership, and other militant organisations coexist facilitates the exchange of operational experience, facilitators, technologies, tactics, and personal networks. A group can remain locally focused while simultaneously contributing to an environment from which other organisations derive transnational capabilities.
Europe: The Threat is Contained but Persistent
The threat facing Europe and North America can be described as primarily linked to homegrown “lone actors” inspired online by jihadist propaganda; these individuals are generally involved in small-scale plots and lack direct ties to the organisation or its affiliates.
In the early months of 2026, security services thwarted several plots in France, Germany, Italy, and Spain, mostly involving young sympathisers of the Islamic State and al-Qaeda.
Europol provides the quantitative picture for 2025: 45 terrorist attacks were recorded in the European Union, 22 completed, 20 thwarted, and three failed, with 24 of them being jihadist in nature. A total of 486 people were arrested for terrorism-related offences, 347 of whom (71%) were linked to jihadism. Jihadist attacks resulted in five deaths and 81 injuries12.
However, the most significant aspect is the online ecosystem that enables dispersed networks, lone actors, and self-initiated cells to radicalise, mobilise, and act autonomously. Many individuals display only a superficial ideological understanding, while personal grievances, a fascination with violence, a search for identity, and extremist narratives may overlap. Another factor to consider is the shift in age demographics. In 2025, 130 people arrested in the EU for terrorism offences were 18 years old or younger; the youngest was 1213. While this figure covers the entire terrorist spectrum, not just jihadism, it highlights the growing exposure of minors to digital extremist ecosystems.
We are not witnessing a reconstruction of the 9/11 model. We are witnessing a lowering of the organisational threshold required to generate violence. In 2001, a strategic operation required selecting attackers, training, international travel, funding, communications, and a lengthy preparation phase. By 2026, an organisation can produce terrorist effects without personally knowing the perpetrator. This reduces the organisational cost of the attack, without necessarily increasing its lethality, but it does reduce its signature.
The digital realm has not replaced the sanctuary.
Digital transformation represents one of the most significant changes to occur since 9/11. In response to the degradation of capabilities required for complex attacks, Al-Qaeda and the Islamic State have invested more heavily in information operations, propaganda, and the inspiration or facilitation of individuals with access to the West. The increasing use of short, emotionally evocative content centred on grievances allows them to reach young audiences with limited knowledge of traditional jihadist doctrine.
The digital realm, however, does not replace territorial sanctuary; it complements it.
A digital ecosystem can radicalise, connect, and instruct, but territory can generate different capabilities: trainers, bomb-makers, protected leadership, documentation, funding, logistics, military experience, and freedom to plan. For this reason, the territorial expansion of an organisation seemingly focused on a local conflict must also interest those assessing threats to the West and global security. The question is not necessarily what JNIM or Al-Shabaab intend to do today in Rome, Paris, or London. The intelligence question concerns the capabilities they could develop if they acquired sufficient sanctuary, revenue, expertise, and freedom of action.
What has counter-terrorism actually achieved?
Finally, interpreting the post-9/11 era requires more rigorous examination. The fact that jihadist organisations continue to exist does not prove that twenty-five years of counter-terrorism efforts have been futile. The infrastructure that enabled 9/11 has been severely degraded, Al-Qaeda’s historic leadership has been progressively eliminated, and the Islamic State’s territorial caliphate has been destroyed. Financial intelligence, biometrics, watchlists, Passenger Name Records, screening, battlefield evidence, and multilateral cooperation have vastly improved the ability to identify suspicious movements and networks.
Interpol offers a concrete measure of this evolution. Operation Neptune VII, conducted in 2025 across more than 70 border points in Europe, the Middle East, and North Africa, resulted in approximately 30 million checks against Interpol databases. Authorities identified 328 individuals subject to Interpol Notices or Diffusions, 57 of whom had suspected links to terrorism, while the checks yielded further information on the movements of nearly 60 alleged foreign terrorist fighters14.
The correct conclusion, therefore, is neither “success” nor “failure.” Counterterrorism efforts have vastly increased the cost of centralisation. This is arguably one of the most overlooked strategic consequences of the past twenty-five years. The most adaptive organisations have learned to reduce their operational footprint, distribute functions, grant autonomy to their peripheries, embed themselves in local conflicts, and survive the loss of their leaders. The jihadism of 2026 is thus, at least in part, the product of the selective pressure exerted upon it by twenty-five years of military, financial, investigative, and intelligence operations.
This is not an argument against counterterrorism; it is a reason to adapt it once again.
What should be monitored?
JNIM represents a prime contemporary example of jihadist expansion driven by insurgency, economic coercion, military capability, and the gradual penetration of state peripheries. However, its expansion toward coastal West Africa should not be viewed as inevitable. The group’s leadership maintains a relatively cautious approach to geographic expansion, prioritising internal cohesion and consolidation. This balance between growth and discipline makes it strategically significant. Al-Shabaab remains one of the most mature jihadist insurgencies in terms of longevity, institutional capacity, and resilience. ISKP remains a critical focal point for monitoring potential external power projection. The TTP represents one of the most intense insurgent campaigns within the Afghanistan-Pakistan theatre. Yet, it must be assessed primarily through the lens of its domestic and regional priorities, rather than automatically equating its tactical capabilities with a threat to the West. The Islamic State’s African provinces require nuanced analysis; some may remain primarily local organisations, while others could gain greater financial, logistical, or territorial importance for the network. Finally, AQAP poses a significant risk of resurgence.
The point is not to argue that it has already regained its past capabilities, but rather to observe the convergence of a permissive environment, financial resources, a history of external plotting, and its growing centrality within the al-Qaeda network.
Conclusions: The next strategic surprise
Merely tallying the attacks carried out by al-Qaeda and the Islamic State in Western nations or globally is insufficient to understand what might lie ahead.
A strategic threat is not necessarily the actor generating the most violence today; it may well be the one amassing capabilities that have not yet been deployed. Twenty-five years later, al-Qaeda no longer possesses the organisational structure it had in 2001. The Islamic State no longer controls the territory it held in 2014. Military, financial, investigative, and intelligence pressures have made it much harder to recreate the conditions necessary for complex transnational operations. Yet, the jihadist system has not disappeared; it has simply changed its architecture.
No single centre of global jihadism exists; instead, regional systems evolve at different speeds. Some control territory, while others build insurgencies, generate resources, and maintain transnational networks. Still others harbour ambitions for external operations and can survive the loss of their commanders.
Today, this system is likely less capable of rapidly concentrating resources on the scale that enabled the 9/11 attacks, but it is more dispersed and thus harder to neutralise as a whole.
The next strategic surprise might not take the form of another 9/11; it could unfold gradually, through a state progressively losing control of its peripheral regions, a local organisation expanding across borders, an insurgent network amassing tens of millions of dollars, a province acquiring specialists and logistical capabilities unnecessary for its local conflict, a propaganda apparatus successfully mobilising a new generation in Europe, or a peripheral haven transforming into a hub for external operations.
The challenge for intelligence agencies lies in identifying this transition before it culminates in an attack. Hence the question, twenty-five years after 9/11, of whether another al-Qaeda exists today capable of replicating the events of 2001. Based on current evidence, the answer is likely no.
However, a more useful question is: which organisations are currently acquiring the conditions that could enable them to pose a strategic threat in the future?
The jihadist movement of 2026 is weaker at its core but more expansive at its periphery. The strategic error would be to interpret the absence of another 9/11 as proof that the system capable of generating transnational jihadist violence has disappeared. It has not disappeared; it has adapted.
UN Security Council, Thirty-eighth Report of the Analytical Support and Sanctions Monitoring Team, S/2026/651, August 10, 2026.
Office of the Director of National Intelligence, Annual Threat Assessment, 2026
Daniele Garofalo, Monitoring, Strategic Threat Outlook | JNIM — August 2026. Operational Trends, Risk Assessment, and Forecast, September 6, 2026.
UN Security Council, S/2026/651, paras. 12–17.
UN Security Council, S/2026/651, paras. 9 and 16.
Daniele Garofalo, Monitoring, Strategic Threat Outlook | Harakat al-Shabaab al-Mujahidin — August 2026. Operational Trends, Regional Risk, and Forecast, September 6, 2026.
U.S. Africa Command, 2026 Strikes.
UN Security Council, S/2026/651, paras. 6–7.
UN Security Council, S/2026/651, paras. 92-95
UN Security Council, S/2026/44, 108
Daniele Garofalo Monitoring, Strategic Threat Outlook | Tehrik-i-Taliban Pakistan (TTP) — August 2026. Operational Trends, Risk Assessment, and Forecast, September 6, 2026.
Europol, EU Terrorism Situation and Trend Report 2026 / TE-SAT 2026
Europol, July 13, 2026
Interpol Operation Neptune VII, October 16, 2025.
🔒Executive Intelligence Cycle
This assessment is part of a broader analytical cycle.
Founding subscribers receive the Executive Intelligence Briefing, which integrates all threat assessments, cognitive domain analysis, and a rolling 30–90-day forecast into a single monthly strategic synthesis.
© Daniele Garofalo Monitoring - All rights reserved.
ISSN (International Standard Serial Number): 3103-3520
NATO NCAGE: AX664 (NATO Commercial and Governmental Entity)
UNITED NATIONS Global Marketplace ID: 1210727
ORCID Code: 0009-0006-5289-2874Daniele Garofalo is an independent researcher and analyst specialising in Intelligence, Jihadist Terrorism, Islamist insurgencies, Non-State Armed Groups (NSAG), Cognitive Warfare, and Hybrid Warfare.
His work focuses on continuous intelligence monitoring, threat assessment, and analysis of propaganda and cognitive/information dynamics, with an emphasis on decision-oriented outputs, early warning, and strategic trend evaluation.


