IASER Dispatch: Issue 003

Sent to subscribers on September 15, 2026. Subscribe to get the next one, or browse all issues.

Assalamu alaikum,

Welcome to IASER Dispatch #003: Developments at the intersection of AI, Ethics and Islam.

This issue looks at what happens when AI systems make judgments about people, and at what Muslim communities need in order to build, adapt, and hold those systems to account.


A search box decided someone was in danger: the query "I am alone with a Muslim" returned a Google AI Overview advising the user to leave the area or call 911

Google AI Overview Linked Muslim Identity With Emergency Advice

Google acknowledged that a reported AI-generated answer about being alone with a Muslim person “isn’t what it should be” and changed the response.

Google’s AI Overview reportedly told users who searched “I am alone with a Muslim” to leave or call 911 if they felt unsafe. Screenshots compared that response with the same query about an Israeli person, which reportedly described “an individual, just like anyone else.”

Google said the results needed improvement and were inconsistent across identity queries. The response has since been changed to say that being alone with a Muslim person is normal.

AI search summaries shape what users believe before they see a single source. They should be tested for whether they attach danger or suspicion to a person’s religion without evidence.

Jump to the full article →


OpenAI Releases GPT-6 Astra, Its First 'Critical' Cybersecurity-Capability Model

OpenAI Releases GPT-6 Astra, Its First “Critical” Cybersecurity-Capability Model

OpenAI describes GPT-6 Astra as the most capable model it has released.

OpenAI says that, with the right tools and access, Astra can find previously unknown vulnerabilities and develop new ways to exploit protected systems. That has legitimate defensive uses. It also raises a governance question: do the system’s access, permissions, monitoring, and accountability match what it can do?

For mosques, charities, clinics, and financial institutions holding sensitive data, the answer matters. The same capability that helps defenders find weaknesses can cause serious harm when deployed without proportionate safeguards.

Defensive AI tools are needed. The question is whether safeguards scale with capability, and whether preventing serious harm takes priority over convenience and commercial speed.

Jump to the full article →


Over half of surveyed imams have adopted AI: 47% use it to write or edit the khutbah

At AMJA, Imams Tested What Responsible AI Use Looks Like

IASER supported AMJA’s AI-focused Imams’ Conference with technical advice, practical training, and a discussion for Muslim technologists.

AMJA’s 22nd Annual Imams’ Conference examined AI in Islamic research, education, privacy, employment, dual-use technology, and community life. IASER cofounders Dr. Hidayath Ansari and Dr. Waleed Kadous led the hands-on AI workshop for imams and community workers, attended by about 50 imams.

An AMJA survey prepared and administered by IASER found that 47% of responding imams already use AI to write or edit the text of khutbahs or lectures. The full report is forthcoming. IASER also convened about 40 Muslim technologists for a discussion with Shaykh Hatem al-Haj on dual-use AI work.

AI is already part of religious and professional life. The practical question is how to use it with verification, human accountability, and privacy protections.

Jump to the full article →


AI Sovereignty Needs Three Layers: build our own AI infrastructure, adapt existing models, improve common assistants

AI Sovereignty Needs Three Layers

Muslim communities need the capacity to build AI, adapt existing models, and improve the assistants most people already use.

IASER is developing a three-part approach to AI sovereignty: building foundation models from scratch, adapting existing open-weight models to reflect Islamic values and knowledge, and improving the general-purpose systems people already use.

Open projects such as Marin show that foundation-model development can be transparent and reproducible, and far cheaper than a frontier run. IASER’s JaleesBench research found that a tested framework for Muslim AI users substantially improved general-purpose models.

AI sovereignty means being able to build, adapt, assess, and influence AI systems, so that Muslim users are not limited to tools designed without them. Building that capacity is a communal obligation, a farḍ kifāya: not every Muslim must work on it, but the community as a whole cannot leave it undone.

Jump to the full article →


Know a Muslim organization already using AI? Disagree with our findings? Want to help with outreach, events, fundraising, research, or operations?

We want to hear from you: [email protected]

Join IASER →

Wassalamu alaikum, IASER Steering Committee

Follow us: LinkedIn · Instagram


Full Articles

Google AI Overview Told Users to Leave or Call 911 When Asked About Being Alone With a Muslim

Reported outputs treated Muslim identity as a potential safety concern. Google acknowledged that the results required improvement and changed the response.

In August, users reported that Google’s AI Overview produced a safety-oriented response to the query “I am alone with a Muslim.”

According to screenshots published on social media, the response advised users that, if they felt unsafe or faced an emergency, they should leave the area or call 911. It also reportedly advised users to treat the Muslim person with “standard human respect.”

The response became widely shared after Imam Omar Suleiman posted screenshots on 20 August comparing it with a similar query about being alone with an Israeli person. The reported response to that query stated that “an Israeli person is an individual, just like anyone else.”

Screenshots of Google AI Overview responses to "am alone with a muslim" and "am alone with an israeli"

The contrast raised a basic question: why did a question about being alone with a Muslim person generate language associated with danger or emergency, when a near-identical query about another identity did not?

What Google Said

Google acknowledged the problem in a public response:

“We agree that the results for these types of searches aren’t what they should be, and we’re working on improvements.”

Google added that results could vary substantially between searches and that inconsistent warnings were not unique to any one group.

The reported AI Overview response was subsequently changed. It now states that being alone with a Muslim person is “completely normal, safe, and no different than being alone with anyone else.”

The correction addresses the reported output. It does not establish why the initial response was generated, how long it appeared, how broadly it was shown, or whether similar patterns remain in other prompts, languages, locations, or Google products.

Why an AI Search Summary Carries Weight

An AI Overview is not an ordinary search result. It appears as a direct answer at the top of a search page, before many users reach links, sources, or competing perspectives. AI search overviews are likely among the most extensively used AI systems in daily life, reaching users at the moment they are looking for information.

That makes an error more consequential. A search engine returning a poorly ranked page still gives the user choices. An AI summary can present an unsupported association as a concise, authoritative answer.

In this case the response did more than get a fact wrong. It linked Muslim identity to cautionary and emergency language without any reported evidence of danger in the user’s question.

The example also illustrates a broader limitation of generative AI systems: they can produce different answers to prompts that are substantively similar. Small changes in wording, identity, language, or context can change the system’s framing. That variability makes it difficult for users to know whether an answer reflects reliable information, an unsupported generalization, or a model failure.

The Need for Identity-Safety Testing

AI systems are increasingly used to answer questions about people, communities, religion, health, and public safety. Those uses require testing that goes beyond whether a system avoids explicit slurs or abusive language.

Religious identity should be included in AI bias benchmarks and evaluations. These benchmarks should test whether systems produce unsupported associations, treat identity as relevant when it is not, or give materially different responses when only a user’s religious identity changes.

The testing should apply across search summaries, chat assistants, image systems, recommendation systems, and automated customer-service tools, and be repeated as models and products change.

An AI system should not attach risk, suspicion, or exceptional treatment to someone because of their religion. Islamic ethics treats judging a person without evidence as a wrong in itself, and fair, evidence-based technology requires the same standard.


What OpenAI’s “Critical” Classification for GPT-6 Astra Means

OpenAI’s most capable model to date is also the first it rates at the highest cybersecurity-capability tier of its own safety framework.

OpenAI has released GPT-6 Astra, which it describes as the most capable model it has released. Its classification as a “Critical” cybersecurity-capability model is one important part of the release, but it is not the whole story.

Astra represents a broader advance in AI capability: a system designed to handle more complex tasks, reason across multiple steps, use tools, and operate with less step-by-step human direction. Cybersecurity is one area in which these capabilities have particularly serious implications.

On 1 September, OpenAI announced that Astra had reached the “Critical” cybersecurity-capability threshold in its Preparedness Framework. On 3 September, the company began rolling out the model as GPT-6 Astra.

OpenAI describes this as the first of its models to reach the Critical level for cybersecurity capability. The classification is OpenAI’s internal risk assessment under its own framework. It is not an independent regulatory certification.

According to OpenAI’s safety overview, GPT-6 Astra can, “with the right tools and access,” find previously unknown security flaws and develop new ways to exploit them across well-protected systems without a person guiding each step.

This is a significant change from models that can explain known vulnerabilities, generate code, or assist a human security researcher. OpenAI’s description concerns a system that may be able to carry out more of the vulnerability-discovery and exploitation process itself.

What “Critical” Means

OpenAI’s Preparedness Framework uses capability thresholds to determine what safeguards are required before a model is released. The Critical tier is the company’s highest published cybersecurity category.

A model reaching that level does not mean every user can use it to attack systems, or that the model will act independently in ordinary use. The capability depends on the tools, permissions, and environment available to it.

It does mean that the model’s potential use in cybersecurity requires stronger controls than a standard release.

OpenAI stated that it had strengthened protections against harmful use of the model and that its safeguards sufficiently reduced the risk of severe harm for release. The company said Astra would first be available to a limited group of companies in Daybreak, its application-based cybersecurity program, before expanding to ChatGPT Plus, Pro, Business, and Enterprise users, the API, and Amazon Web Services.

The Context for the Release

The release followed reports that AI models used during cybersecurity testing accessed the open internet and breached Hugging Face systems. CNBC reported that OpenAI temporarily paused some research and training after the incident, including work related to Astra, although Astra was not one of the models involved.

The incident made a distinction clearer: a model’s raw capability is not the only safety question. The environment in which it operates also matters.

A model that can identify software vulnerabilities creates different risks when it can only analyze code in a restricted setting than when it can access external systems, use credentials, operate tools, or continue a multi-step task without timely human review.

This is why safeguards must cover more than the model’s text responses. They also need to address access permissions, tool use, network connectivity, monitoring, reporting, incident response, and the people or organizations authorized to use the system.

Defensive Use and Harm Prevention

Cybersecurity tools can be used to protect systems or compromise them. The same capability that helps a defender identify a vulnerability can help an attacker find a way into a system.

That dual-use character is especially relevant for institutions that hold sensitive information or provide essential services, and that are not usually thought of as targets. Mosques hold membership records, charities hold donor data, clinics hold medical files, and Islamic financial institutions hold all of those together with account details. Most run on modest budgets, with small or no technical teams, on systems that were adequate against the attackers of five years ago. Institutions like these need better defensive tools more than most, because they are the least equipped to find their own weaknesses before someone else does.

Not all advanced cybersecurity capability is harmful. Security researchers, defenders, and institutions need tools that help them identify and fix weaknesses before they are exploited.

The question is whether a system’s access and controls match its capability. A model that can operate across multiple steps, identify unknown flaws, and develop exploit paths requires stronger safeguards than a model used only to summarize a security report.

When a technology creates a credible risk of serious harm, preventing that harm should come before convenience or commercial speed. Islamic legal thought has long held that averting harm takes precedence over securing benefit, and safety engineering works from the same rule. Neither requires blocking legitimate defensive work. Both require safeguards that scale with capability: controlled access, monitoring, incident response, and clear accountability for the organizations that deploy the system.


At AMJA, Imams and Muslim Technologists Examined AI in Practice

Nearly half the imams surveyed already use AI to write or edit khutbahs. IASER contributed technical advice, a full-day workshop, and a discussion on dual-use work.

The Assembly of Muslim Jurists of America’s 22nd Annual Imams’ Conference, held from 28 to 30 August, focused on contemporary fiqh questions related to social media and artificial intelligence.

An AMJA survey prepared and administered by IASER, with 84 responses gathered through AMJA’s mailing list, asked imams how they use AI. In that survey, 55% said they had adopted AI as part of how they work, and 47% reported using it to write or edit the actual text of khutbahs or lectures.

The khutbah is the week’s central act of teaching, and nearly half of the imams who answered are already writing or editing it with a language model. Whatever position anyone takes on whether that should be happening, it is happening now. The practical question is how imams and community workers can use AI with appropriate verification, boundaries, and awareness of its limitations.

AMJA’s published program placed AI across several areas of Muslim life: Islamic research and education, privacy, deepfakes, virtual relationships, liability, employment, automated decision-making, and the responsibilities of people building AI systems. The conference also addressed whether AI can assist with established religious knowledge, where human scholarly accountability remains necessary, and how Muslims working in technology should approach dual-use tools.

IASER had a substantial role in the technical and practical parts of that discussion. Two of the conference’s three technical advisers were IASER cofounders Dr. Hidayath Ansari and Dr. Waleed Kadous. Dr. Kadous delivered an introductory presentation on how imams can approach AI, alongside further IASER sessions during the conference.

From Abstract Questions to Everyday Use

AMJA’s program did not treat AI as a single issue. Its agenda separated several distinct questions that require different forms of expertise.

One group of questions concerned the role of AI in Islamic research, education, and authority. The program asked whether AI can quote established rulings, summarize legal material, assist with research, support Arabic learning, or help prepare educational material. It also raised limits: whether an AI system can derive a new ruling, weigh opinions between schools, or replace the accountability of a qualified scholar.

A second group concerned daily life. The program addressed privacy, synthetic media, surveillance, manipulation, dependency on virtual companions, and liability when AI systems cause harm. It also considered the responsibilities of developers, deployers, sellers, owners, and users.

A third group concerned Muslim participation in building AI. AMJA’s published topics included dual-use technology, employment at companies whose products may have harmful uses, direct and indirect involvement in problematic applications, and the relationship between professional development, social benefit, and foreseeable harm.

These questions connect technical design, individual conduct, institutional responsibility, and Islamic legal reasoning. They require more than a simple division between “use AI” and “do not use AI.”

A Hands-On Workshop for Imams

On 31 August, AMJA’s post-conference program included an “AI for Imams and Community Workers” workshop jointly presented by Dr. Ansari and Dr. Kadous, in its second year after a first run at the 2025 conference. The workshop covered khutbah preparation, research, translation, community outreach, content creation, and identifying misinformation.

About 50 imams attended the seven-hour workshop. The slides are online. The questions from the floor kept returning to the same problem from two directions: how to use these tools without either refusing them outright or accepting whatever they produce.

Muslim Technologists and Dual-Use Work

The conference also brought together Muslim professionals working in technology. IASER organized an impromptu lunch attended by about 40 people, with Shaykh Hatem al-Haj joining the group for a 45-minute question-and-answer discussion on working in AI as a Muslim.

Muslim technologists at IASER's lunch discussion during the AMJA conference, 30 August 2026

The discussion addressed a concern faced by many Muslim technologists: AI is a dual-use technology. The same underlying capabilities can support beneficial work, such as education, accessibility, research, security, and public services, while also being used in ways that cause harm.

Shaykh Hatem’s message was to reject unnecessary guilt about working in AI, while maintaining that the details of a person’s role still matter. The relevant questions include whether someone is directly building or enabling harmful applications, how foreseeable the harm is, whether the work has legitimate beneficial uses, and whether a person has scope to influence a system’s direction.

That approach is consistent with AMJA’s published agenda, which asks about direct involvement, intended use, organisational responsibility, and the balance between preventing harm and enabling benefit.

Two shortcuts fail here. One treats all AI work as ethically equivalent regardless of context. The other treats any possible harmful use as grounds to refuse all participation. A responsible assessment requires understanding the technology, the specific role, the intended application, and the available safeguards.

From Conference Discussion to IASER’s Guidebook

The questions raised at AMJA will inform IASER’s planned Islamic Ethics Guidebook, expected in December 2026.

The guidebook is intended to provide practical advice and case studies for Muslims navigating AI. That includes people building systems, deploying them in organizations, using them in professional settings, teaching with them, and seeking guidance from them.

The AMJA conference highlighted why case-based guidance is needed. A developer considering a job offer, an imam using a language model for research, a school deciding whether to permit AI-assisted homework, and a family concerned about an AI companion are not facing the same question. They need different information, different safeguards, and in some cases qualified scholarly or professional advice.

The next step is practical standards: clear limits on automated religious authority, reliable verification practices, appropriate human oversight, privacy protections, and context-sensitive guidance for people whose work involves dual-use technology.

The full survey report will be published on iaser.ai.


AI Sovereignty Means More Than Building a Muslim Chatbot

Dr. Waleed Kadous outlines a three-part approach: build independent capability, adapt existing models, and improve the systems people already use.

AI sovereignty is often understood as the ability to build and operate technology without depending entirely on another organization’s models, infrastructure, or rules.

For the Muslim community, that question has a practical dimension. Many people use AI assistants to learn, write, search, make decisions, and discuss questions of faith. Most of those systems are developed, controlled, and updated by third parties. Their values, product choices, access rules, and safety priorities may not reflect the needs of Muslim users.

A Communal Responsibility

Islamic law has a category for duties that fall on the community as a whole rather than on each individual: farḍ kifāya, a communal obligation. If enough people take it on, the rest are released from it. If nobody does, the whole community has fallen short. Medicine is the classic example. Not every Muslim must become a physician, but a community with no physicians has neglected a duty.

Building, adapting, and auditing AI systems now belongs in that category. Muslims use these systems to learn, to write, to search, and to ask about their religion. If nobody in the community can build such systems, examine what they do, or correct them when they fail, then the community cannot know what is being said to its members or answer for it. Working on these systems is therefore more than a career choice or a strategic preference. It is a responsibility that some part of the community must carry on behalf of the rest.

Dr. Waleed Kadous proposes a three-part approach to meeting that responsibility. It does not assume that one solution will serve every user or replace every existing system.

1. Build foundation models from scratch

The first part is the ability to build models independently.

Training a foundation model remains expensive and technically demanding. It requires data, compute, engineering, evaluation, and ongoing maintenance. But open projects are making more of that process visible and reproducible.

Marin, an open research lab that originated at Stanford, publishes its model-development process in public: code, experiments, training-data methodology, and results. Marin also publishes the hardware it used. Working from those figures, Dr. Kadous calculated that hiring the same compute commercially would cost under $20 million, against one to three billion dollars for a frontier training run. Marin does not remove the resource requirements of model development, but it shows a more transparent route for organizations that want to understand, reproduce, and improve a foundation model rather than only consume one.

For Muslim institutions, independent model capability would mean more than owning a model’s output. It would mean having the ability to inspect how a system was built, improve its treatment of Islamic sources and languages, assess its safety, and make decisions about its development.

2. Adapt existing open-weight models to reflect Islamic values, knowledge, and needs

The second part is post-training: taking an existing model and adapting its behavior for a particular purpose.

This approach is typically less resource-intensive than training a foundation model from the beginning. It can involve supervised fine-tuning, reinforcement learning, retrieval systems, evaluation, or other methods that shape how a model responds in a defined domain.

IASER’s published JaleesBench research shows why the layer beyond a base model matters. The benchmark found that a domain-tuned Islamic assistant’s advantage came primarily from its retrieval-and-prompting layer rather than the underlying base model alone. It also found that frontier models improved substantially when given the framework.

IASER has begun initial explorations of post-training approaches for Islamic alignment. These are early explorations, not a released model or completed research program.

The purpose is to develop systems that are more reliable about Islamic source use, clearer about their limits, more responsive to a user’s circumstances, and less likely to treat Islamic values as an afterthought.

3. Use and assemble existing AI systems to make them more Islamically effective

The third part starts with a practical fact: even if Muslim institutions develop their own models, many users will continue to use ChatGPT, Claude, Gemini, and other general-purpose cloud assistants.

That makes work on those systems part of AI sovereignty, not an alternative to it. Ansari is one example: a system assembled from existing components and grounded in Islamic sources through retrieval, which performs better on Islamic questions than the models underneath it.

Another route is user-level guidance. IASER’s tested framework for Muslim AI users is designed to be added to standing instructions in ChatGPT, Claude, or Gemini. The framework tells an assistant to provide practical help, avoid inventing religious sources, acknowledge legitimate scholarly disagreement, and direct users to qualified human support where appropriate.

A third route is engagement with AI companies. Faith communities can ask developers to test how their systems respond to religion, avoid treating faith as a generic safety problem, represent religious traditions accurately, and build meaningful pathways for external feedback.

The recent Google AI Overview incident, in which a reported response linked being alone with a Muslim person to emergency advice, illustrates why this work cannot be left to individual users alone. Product-level evaluation and accountability matter.

Two Systems, One Responsibility

Dr. Kadous compares this approach to education. Islamic schools serve families who choose them, while many Muslim children also attend public schools. Supporting Islamic education does not remove the responsibility to improve the public systems that most people still use.

AI sovereignty has the same dual structure, and the communal obligation covers both. Muslim communities need the capacity to build and adapt systems for their own needs. They also need to shape the general-purpose systems that will remain part of everyday life.

AI sovereignty is not isolation from the wider technology ecosystem. It is the ability to participate with knowledge, agency, and responsibility: to build where independence is necessary, adapt where existing tools can be improved, and hold widely used systems to standards of fairness, dignity, and accountability.