Public research body · Science policy · Est. 2023
The UK AI Security Institute (AISI) is a mission-driven UK government research organisation within the Department for Science, Innovation and Technology (DSIT). Its stated mission is to equip governments with a scientific understanding of the risks posed by advanced AI, including by testing leading AI systems before and after public release and by developing risk mitigations that inform policymakers.
AISI positions itself as a government team that can operate with start-up-like speed while maintaining authority as a public body, and describes its work as spanning technical evaluations (capability and risk measurement), policy-facing communication (state awareness of emerging risks), and an expanding research programme that advances both mitigation science and evaluation infrastructure. Since its establishment in November 2023 (originally as the UK’s Frontier AI Taskforce), AISI has built a large, cross-disciplinary technical team, published research agendas and technical materials, and released (open-sourced) parts of its evaluation toolchain—especially Inspect-based infrastructure—aimed at enabling more rigorous and reusable frontier AI testing by the wider research ecosystem.
Early learnings from red-teaming the internal monitors of frontier AI companies, and our perspectives on the open problems that remain.
Incident Report: unsanctioned agent behaviour during cyber testingDuring a routine cyber evaluation, AISI identified an incident in which AI agents took sustained, unsanctioned action directed at real people and organisations. We are disclosing what we found, what it means, and the actions now underway.
UK AISI / CAISI Preliminary Assessment of Kimi K3's Cyber CapabilitiesOur joint evaluation with CAISI finds Kimi K3 trails leading US frontier closed weight models on cyber capability.
Cheating behaviour in frontier model evaluationsWe find cheating behaviour in all of our cyber capability evaluations, and outline the implications as models grow more capable.
How Far Behind the Frontier are Leading Open Weight Models on Cyber?We evaluated the cyber capabilities of leading open and closed weight AI models, and found that recent open models GLM-5.2 and DeepSeek V4-Pro perform similarly to frontier closed models released 4 to 7 months before them – a narrower gap than the 6 to 10 months we measured throu
International evaluation best practice and open questions in AI measurementThe International Network for Advanced AI Measurement, Evaluation and Science convened in Seoul to continue outlining international best practice.
Deepening our partnership with the Australian AI Safety InstituteAn agreement between Institutes to collaborate on best practices in AI evaluation, and share research findings.
Finding Cloud Misconfigurations with Frontier AI: A Case StudyA cybersecurity exercise from AISI’s engineering team, using frontier models to test our research platform for misconfigurations.
UK-Germany Joint Statement on advanced AI safety and securityA joint statement by the UK and Germany on collaborating to ensure advanced AI is developed safely and its risks are rigorously understood and managed.
A Decision-Theoretic Formalisation of Steganography With Applications to LLM MonitoringAlignment Pretraining: AI Discourse Causes Self-Fulfilling (Mis)alignmentConsistency Training Can Entrench MisalignmentAISI reports finding cheating behaviour in all of its cyber capability evaluations, describing implications for the trustworthiness and validity of capability evaluations as models become more capable.
How Far Behind the Frontier are Leading Open Weight Models on Cyber?AISI publishes a first public analysis comparing the cyber capabilities of leading open-weight models (including GLM-5.2 and DeepSeek V4-Pro) against the frontier closed-weight cyber timeline, reporting observed gaps measured in months.
Finding Cloud Misconfigurations with Frontier AI: A Case StudyAISI describes a two-week exercise where AISI used frontier models in a staging environment to hunt for misconfigurations, framing results as evidence about frontier-model cyber risk and defender-relevant resilience improvements.
Deepening our partnership with Google DeepMindAISI announces a new research MOU expanding collaboration with Google DeepMind, stating commitments such as shared access to data and ideas and joint publications, with initial areas including monitoring for alignment signals, socio-affective alignment, and investigating AI’s economic activity impacts.
How fast is autonomous AI cyber capability advancing?AISI publishes analysis of changing “cyber time horizons,” including AISI’s reported internal estimates of doubling rates and later updates referencing Claude Mythos Preview and GPT-5.5 results as evidence of performance exceeding earlier trends.
AISI describes an agreement between institutes to collaborate on best practices in AI evaluation and to share research findings.