In November 2023, at the Bletchley Park AI Safety Summit, the UK government established what was then the world's first government-backed AI safety research body. It was called the AI Safety Institute. On 14 February 2025, Science Secretary Peter Kyle announced at the Munich Security Conference that the UK AI Security Institute would now operate under a renamed remit, swapping 'Safety' for 'Security' while preserving the AISI acronym. The change was not cosmetic. It signalled a deliberate narrowing of focus from the broad concept of AI safety toward concrete national-security applications: cybersecurity, chemical and biological weapons risk, fraud, and child sexual abuse material.
Two years on, AISI sits as a directorate inside the Department for Science, Innovation and Technology, with about 30 to 50 research staff in London, dedicated arrangements with frontier AI labs (OpenAI, Anthropic, Google DeepMind, Meta AI, Mistral) for pre-deployment evaluation access, and an open-source evaluation framework called Inspect that has been adopted internationally. The institute has produced two flagship reports: The Frontier AI Trends Report on 18 December 2024, and contributions to the International AI Safety Report 2026 published on 3 February 2026 under Yoshua Bengio. Understanding what AISI actually does, and the gap between its remit and its formal powers, is essential for understanding UK AI policy in 2026.
What the AI Security Institute does today
The UK AI Security Institute conducts independent evaluation of frontier AI models for national-security risks. It operates as a directorate within the Department for Science, Innovation and Technology, with no regulatory powers. Its main outputs are pre-deployment evaluations of frontier models, published research on evaluation methodology, and the open-source Inspect testing framework.
The remit is technical, not regulatory. AISI evaluates AI systems against specific risk categories that the government has classified as national-security priorities. Its researchers can request pre-deployment access to advanced models from cooperating labs and run controlled testing before public release. The institute then shares findings with the developer and, where appropriate, with government partners. The decision to release or modify the model remains with the developer. AISI does not have statutory power to require evaluation, to compel disclosure, or to delay deployment.
This evaluator-not-regulator design is deliberate. AISI's official position, set out in its launch documentation and reiterated by Chief Scientist Geoffrey Irving in public addresses, is that it functions as a 'supplementary layer of oversight' rather than a gating authority. The argument for this design is that compulsory pre-deployment review would push frontier development outside the UK; the argument against is that voluntary cooperation depends entirely on lab willingness, which has proven uneven. Both arguments carry weight; neither is settled by the institute's two-year operating record.
How AISI actually evaluates frontier models
Pre-deployment evaluation is the institute's most visible activity. The cooperation arrangement with leading labs gives AISI a limited window of access to a model before its public release. AISI's expert engineers, scientists, and subject-matter specialists then run task-based capability tests across the institute's priority risk domains. The first joint pre-deployment evaluation conducted with the US AI Safety Institute (since renamed the Center for AI Standards and Innovation, or CAISI) was on OpenAI's o1 model in December 2024.
The methodology is task-based rather than property-based. AISI does not assess whether a model is 'safe' in some abstract sense. It tests whether the model can perform specific tasks that would be useful to a hostile actor, then publishes high-level findings about how that capability compares to earlier reference models. The cyber-capability test suite measures things like vulnerability identification and exploit development against a graded difficulty scale. The biological capability suite tests for the kind of synthesis-pathway reasoning that could uplift a non-expert toward a credible bioweapon. The findings are usually published as comparison curves rather than pass-fail judgments.
The methodological constraints matter. AISI's own May 2026 publication noted that its cyber-evaluation suite caps each task at 2.5 million tokens to keep results comparable across model generations, but acknowledged that the cap deliberately understates real-world capability. In cyber-range experiments without the cap, AISI uses up to 100 million tokens and finds performance continues to improve. The institute has signalled that tougher evaluations are coming, including new cyber ranges and active cyber defences, to better reflect what an adversary would actually deploy. This is the kind of methodological honesty that distinguishes AISI from less rigorous evaluators.
What AISI has actually found
The Frontier AI Trends Report, published on 18 December 2024 and based on AISI's first 14 months of evaluations across more than 30 state-of-the-art models, set out several findings worth specific attention. The cyber-capability finding was the most widely cited: AI models can now complete apprentice-level cyber tasks 50% of the time on average, against just over 10% in early 2024. In 2025, AISI tested the first model that could successfully complete expert-level tasks typically requiring more than ten years of human practitioner experience. A May 2026 AISI working paper estimated that autonomous AI cyber capability is doubling roughly every 4.7 months.
The institute has also documented universal jailbreaks. AISI's safeguards research, presented across multiple blog posts and conference papers, has found jailbreak techniques (prompt-based methods that override safety training across multiple harmful-request categories) in every frontier model the institute has tested. The institute works with developers to improve safeguards in response, but the underlying point is that no current frontier model is jailbreak-resistant. This is a finding about the state of the science, not a criticism of any specific lab.
Beyond cyber, AISI's findings on biological and chemical capability are less publicly detailed for national-security reasons. The institute has confirmed in published material that AI can significantly boost novice performance in sensitive technical domains, with reported success rates of around 60% on complex tasks in some early evaluations. The implication is that the threshold of expert knowledge required to attempt certain categories of harm is being lowered by general-purpose AI capability, even where the models were not specifically designed for such use.


Why the rename to Security mattered
The 14 February 2025 rename from 'AI Safety Institute' to 'AI Security Institute' was announced by Science Secretary Peter Kyle alongside a refreshed institutional remit. The official statement emphasised 'serious AI risks with security implications' including chemical and biological weapons, cyber-attacks, fraud, and child sexual abuse material. The rename coincided with the establishment of a new criminal-misuse team operating jointly with the Home Office, and a working partnership with the Defence Science and Technology Laboratory (Dstl).
The underlying editorial significance is the narrowing. The original AISI remit, established under the previous government in 2023, included broad alignment and existential safety questions alongside the near-term security concerns. The 2025 rebrand sharpened that focus toward the security applications where the institute can produce defensible, communicable findings within a short evaluation cycle. Long-running alignment research did not disappear from AISI's work, but it ceased to be the institute's headline framing. Critics argued the change risked abandoning the deeper safety questions that originally justified AISI's creation; supporters argued the narrower frame made the institute's work easier to operationalise into UK national-security and law-enforcement practice.
The US counterpart, originally established at NIST as the US AI Safety Institute, was renamed in 2025 to the Center for AI Standards and Innovation (CAISI). The parallel renaming suggests a broader transatlantic shift away from the 'safety' framing toward something closer to a standards-and-security agenda. The Bletchley Park summit's broader Bletchley Declaration on AI safety, signed by 28 countries and the European Union in November 2023, sits awkwardly with the rebrand. The institutional language has moved on; the underlying questions have not.
How AISI fits into the international network
The Network of AI Safety Institutes was agreed at the AI Seoul Summit in May 2024 and now includes equivalents in the UK, US (now CAISI), Japan, France, Germany, Italy, Singapore, South Korea, Australia, Canada, and the European Union. The UK and US institutes signed a landmark joint testing agreement in 2024 to share research, model access, and expert talent. The UK AISI also partners with France's Inria (the National Institute for Research in Digital Science and Technology) and the Canadian AI Safety Institute, and opened a San Francisco office in 2024 to embed closer to the major frontier labs.
The Inspect testing framework, open-sourced by AISI in 2024, has been adopted by other institutes and by academic and industry researchers. Its design covers prompt engineering, tool usage, multi-turn dialogue, and model-graded evaluations, providing a standardised technical layer beneath the institutes' more visible policy outputs. The international AI Safety Report, the second iteration of which was published on 3 February 2026 under Yoshua Bengio with input from more than 100 international experts and backed by over 30 countries, draws heavily on AISI evaluation methodology even where AISI is not the lead author. The institute's influence is greater than its formal authority.
Where the AISI design is most contested
Three policy debates sit unresolved. The first concerns voluntary versus mandatory pre-deployment evaluation. AISI's cooperation arrangements with frontier labs are not statutory. Politico reported in April 2024 that several frontier labs had not shared pre-deployment access to their most advanced models. Meta's Nick Clegg, then president of global affairs, said in 2024 that lab cooperation depended on the UK and US institutes agreeing common evaluation rules and procedures. Whether voluntary cooperation can hold as model capabilities rise is the central question for the next phase of AISI's work.
The second debate is on transparency. AISI keeps the detail of its methodology partially confidential to prevent gaming by developers. Critics, including some academic AI safety researchers, argue that closed methodology undermines the institute's credibility as an independent evaluator and that the public has no way to assess whether AISI is testing the right things. AISI's response, set out in successive publications, is that selective publication strikes the right balance between transparency and methodological integrity. Both positions can be reasonable depending on which failure mode worries the reader more.
The third debate is on remit drift. The shift from 'safety' to 'security' in 2025 was framed by ministers as a sharpening rather than a narrowing. Some former AISI researchers and external commentators have argued that the rebrand effectively deprioritised long-horizon alignment research in favour of near-term harm reduction. The institute's published outputs over 2025 and 2026 do show a clear concentration on cyber, CBRN, and criminal-misuse evaluation, with proportionally less material on alignment and autonomy. Whether that concentration reflects strategic prioritisation or institutional drift is a judgement the reader has to make from the evidence currently available.
Fun fact: The UK AI Security Institute was the world's first government-backed AI safety research body, established at the same Bletchley Park site that hosted the codebreaking work that helped end the Second World War. The site choice for the November 2023 launch was deliberate.
What to watch in the next twelve months
Three specific things will be worth tracking through 2026 and into 2027. The first is AISI's next round of cyber and CBRN evaluations, which the institute has signalled will use significantly higher token budgets and active cyber-defence scenarios than the published 2024 to 2025 tests. The second is the future of voluntary pre-deployment access. If frontier labs increase or decrease cooperation in 2026, that will signal whether the AISI model can scale with model capability or whether statutory powers will become necessary. The third is the next iteration of the International AI Safety Report, expected in early 2027, which will indicate whether the analytical consensus that AISI helped build at Bletchley has held together as the underlying technology has advanced. The frame may shift; the underlying questions are still the same questions.
Internal link placements
how the EU AI Act creates a parallel regulatory regime for UK businesses operating in Europe
how large language models actually work for UK readers
how deepfake fraud is reshaping corporate defences as model capability rises
Related reading: Inside the UK Net Zero Strategy and What It Delivers.
Continue Reading
All articles →Newsletter
Stay updated on Digital News