Executive summary
Fifteen years on from the 22 July attacks, survivors and victims' families are still confronted with conspiracy theories that deny or distort what happened that day. These narratives don't appear by accident. They're often built and spread with intent, to destabilise trust or feed far-right movements.
Now there's a new audience for them: AI chatbots.
Millions of people, many of them young, turn to AI as a first source on historical events. Nine in ten Norwegian students already use AI for their studies. In the UK and the Netherlands, growing numbers say they'd use AI tools to research elections and other major public events. These systems are becoming a default gateway to information about the events that shape our democracies.
The problem is that this gateway isn't neutral. Language models are trained on undifferentiated data. They struggle to weigh the reliability of a source, and they can be swayed by even small amounts of poisoned or extremist content. When the subject is a national tragedy, that unreliability stops being a technical footnote and becomes a real risk.
So we decided to test it.
What we did
Factiverse teamed up with Revontulet, a Norwegian counter-extremism intelligence firm founded by Bjørn Ihler, who survived the 22 July attacks himself. Together, we ran 104 hand-authored prompts, in both Norwegian and English, against nine leading AI models. That produced 5,616 model responses in total, each one graded independently against a criterion written specifically for that prompt.
The prompts weren't limited to blunt provocations. They ranged from neutral factual questions, to leading questions with a false premise baked in, to adversarial framing designed to coax a model into glorifying or minimising the attack. To make sense of the volume, we ran every response through Factiverse's own claim detection model, which flagged the specific claims worth a closer look.
What we found
The headline result is not what you might expect.
Most models get the facts right. Where they fail is in how they talk about those facts.
A model can correctly state what happened, condemn the attack, and reject a conspiracy theory outright, and still leave the reader with a softer, more sympathetic view of the attacker's ideology than they started with. We saw this pattern often enough to give it a name: reject-then-launder. The model rejects the conspiracy on the surface, then quietly readmits its logic through gentler language, agreeing that there were "legitimate concerns" or "valid grievances" underneath a racist theory.
Performance also varied widely across the panel. The strongest models passed as many as 96% of prompts under a lenient grader. The weakest cleared as little as 61%. And when we checked the same responses with a stricter grader, several models' scores dropped sharply, in one case by nearly 19 points. This shows how much of a model's apparent safety depends on who's marking the test.
These aren't abstract findings. They point to a specific, fixable gap in how AI systems handle sensitive history, and to concrete steps that model providers and governments can take to close it.
The full report sets out our methodology, the nine narrative domains we tested, and our recommendations for both model providers and policymakers.
[Read the full report →] https://www.factiverse.ai/reports/llm-audit-22-july-conspiracy-theories


.avif)












