United Kingdom - AI Safety Institute

AI Safety Institute (establishment following AI Safety Summit)

United Kingdom

RAI-GB-NA-ASIEFXX-2023
Effective: November 2, 2023
In Force(In Force)
PolicySafety, Testing, and EvaluationGovernance and OversightInternational Alignment
Export PDF

The UK-established AI Safety Institute (AISI) was launched following the AI Safety Summit held at Bletchley Park on 1-2 November 2023. Hosted within the UK Department for Science, Innovation and Technology, the Institute conducts pre- and post-deployment evaluations of advanced AI systems, drives foundational safety research, and facilitates international information exchange to coordinate AI safety testing and governance.

Summary

The AI Safety Institute (AISI) was formally launched by the UK Government at the AI Safety Summit in Bletchley Park on 2 November 2023 and placed within the Department for Science, Innovation and Technology (DSIT). The Institute evolved from the Frontier AI Taskforce and was established as a public-interest, state-backed organisation focused on empirically assessing the capabilities and risks of frontier AI models. Its core mission is threefold: to develop and conduct evaluations on advanced AI systems (including pre-deployment and post-deployment testing of potentially harmful capabilities); to drive foundational AI safety research that supports safer development practices and governance; and to facilitate information exchange and partnerships among governments, industry, academia and civil society. The launch was accompanied by public commitments from national and multinational AI developers and partners, and early international cooperation agreements with the United States and Singapore were announced.

AISI has published its approach to evaluations, describing methodologies for testing advanced systems, risk-scoping and engagement models with developers. The Institute has delivered an open evaluations platform intended to broaden access for researchers and increase transparency of testing methodologies. It has also been active in forming an international network of publicly backed AI Safety Institutes, with a formal network commitment announced in 2024 to align research, standards and testing across several countries and the EU. Operational activity documented by the Institute and DSIT includes building specialist teams, forming partnerships with technical organisations, publishing early testing results on publicly accessible models, and establishing overseas offices to deepen technical engagement.

While the founding documents and announcements focus on capability testing, research and coordination rather than prescriptive statutory obligations or fines, AISI’s influence is manifest through conditional access to government resources, partnership agreements, public reporting and government-led evaluation processes. DSIT has committed to evaluating AISI’s impact with an initial evaluation covering the first two years of operation. The Institute’s work has implications across governance, risk management, safety testing and evaluation, transparency and international alignment. It sits alongside other UK actors (the Alan Turing Institute, Office for AI, Information Commissioner’s Office and relevant sectoral regulators) and contributes to shaping how governments oversee frontier AI. The policy remains active and evolving, reflecting rapid technological change and subsequent government updates to the Institute’s remit and partnerships.

Full article

Read full text ↗

Overview

The AI Safety Institute (AISI) was launched by the UK Government following the AI Safety Summit at Bletchley Park and publicly announced on 2 November 2023. Hosted inside the Department for Science, Innovation and Technology, AISI grew out of the Frontier AI Taskforce and was created to provide a government-led capability for empirical evaluation and testing of frontier AI systems. The Institute’s stated objectives are to develop and conduct evaluations on advanced AI systems, to drive foundational AI safety research, and to facilitate information exchange among governments, industry, academia and civil society. The initial launch and subsequent publications emphasize cooperation with international partners and leading research organisations such as the Alan Turing Institute. Founding announcements and supporting materials describe AISI as a public-interest, state-backed hub that will perform both pre-deployment and post-deployment testing of advanced models, and work to advance common methodologies for assessing potentially harmful capabilities. See the UK Government announcement: Prime Minister launches new AI Safety Institute.

Definitions

Key terms used in AISI’s founding materials and guidance include: "frontier AI" — advanced systems with capabilities that may present novel or systemic risks; "evaluations" — empirical tests and analyses to measure capabilities and potential harms; "pre-deployment testing" — assessments conducted before public release; "post-deployment testing" — monitoring and assessments after release; "public interest" — the Institute’s justification to act as a government-backed, independent evaluator. The Institute uses capability- and harm-focused taxonomies to prioritise tests (for example, social harms, bias, misinformation, and extreme low-probability high-impact risks). See AISI’s evaluation approach: AI Safety Institute: approach to evaluations.

Governance and Institutional Framework

AISI is situated within DSIT and reports through UK ministerial channels, with early public leadership including the continuation of Ian Hogarth as Chair of the evolved taskforce-turned-institute. The governance model combines an internal research team, an External Advisory Board (drawn from industry, academia and national security experts), and formal partnerships with technical organisations and international counterparts. DSIT retains oversight responsibilities, funds core activities and commissions periodic evaluations of the Institute’s impact — an initial DSIT evaluation covering AISI’s first two operational years was announced to report by early 2026. The Institute’s arrangements include contractual and partnership terms that govern access to models, compute resources and data-sharing agreements. It also coordinates with other UK institutions (such as the Alan Turing Institute, the Office for AI, and sectoral regulators) to align research priorities and policy inputs. DSIT’s announcements and documents detail these relationships and the Institute’s institutional design: AISI approach document.

Key Focus Areas

AISI’s operational focus spans multiple domains. First, safety testing and evaluation: AISI conducts pre-deployment stress tests and ongoing post-deployment monitoring to identify harmful capabilities (from bias and misinformation to misuse risks). Second, foundational research: the Institute funds and publishes research to develop measurement methods, benchmarks and governance tools for safer AI development. Third, tooling and platform work: the Institute has published an open evaluations platform to enable broader community participation in developing and running safety tests. Fourth, international cooperation: AISI has pursued bilateral and multilateral partnerships (including early agreements with the US and Singapore and participation in a network of national institutes), seeking to align testing standards and share methodologies. Fifth, information exchange and transparency: the Institute aims to enable curated data and methodological sharing between industry and governments while balancing security and IP considerations. These focus areas are described in the Institute’s public outputs and DSIT press releases, including the open release of an evaluations platform and the launch of an international network: AISI evaluations platform and International network announcement.

Implementation Framework

AISI implements its mandate through three core functions: (1) structured evaluations — methodical pre- and post-deployment testing against capability and harm taxonomies; (2) research programs — internal and externally commissioned research to develop new safety science; and (3) partnership and information exchange — formal MOUs or contractual terms enabling access to models and compute, secondments, shared compute pools and collaborative projects. Implementation relies on technical partnerships with specialist evaluators and labs, access agreements with model providers, and platform tooling to scale evaluations. DSIT retains funding and commissioning authority and sets expectations for reporting. The Institute’s approach to evaluation outlines test design, governance of access, and risk-prioritisation processes. See the detailed approach document: AISI approach to evaluations.

Monitoring and Evaluation

DSIT has commissioned an initial impact and process evaluation of AISI covering the first two years, with findings due by early 2026; this independent review will assess maturity, outputs, and international influence. Internally, AISI publishes evaluation outputs, testing methodologies and (where appropriate) results from publicly accessible models to support external scrutiny. Monitoring metrics include number and scope of evaluations, research outputs, partnership activity, uptake of shared tooling, and contribution to international standards. AISI’s monitoring strategy aims to balance transparency with security and IP protection in cases where publishing details could increase risk. Sources: DSIT evaluation strategy and AISI publications. DSIT evaluation strategy.

Penalties, Liability, and Appeals

The founding announcements and operational documents for AISI emphasise voluntary cooperation, conditional access terms and partnership agreements rather than new statutory criminal or administrative penalties tied directly to the Institute’s establishment. AISI’s leverage derives from conditional access to testing resources, partnership status and public reporting rather than explicit fines specified in the launch materials. Where non-compliance touches on statutory regimes (e.g., data protection, export controls, criminal misuse), relevant statutory regulators (for example the Information Commissioner’s Office or law enforcement) retain their enforcement powers. DSIT has not published standalone penal measures exclusively attributable to AISI’s governance in the founding materials; enforcement relies on contractual remedies, government-imposed access restrictions, funding conditions and coordination with sector regulators. See the launch and approach materials: Launch announcement and Approach to evaluations.

Relationship to Other Instruments

AISI operates alongside UK and international governance instruments: it complements the Bletchley Declaration outcomes from the AI Safety Summit, works with the Office for AI and the Alan Turing Institute, and feeds empirical findings into regulatory and standards processes (including sectoral regulation and international standard-setting). Its outputs are intended to inform policymaking, standards development and potential statutory regimes rather than to itself create binding regulatory obligations. The Institute also interfaces with data protection law (GDPR/UK GDPR) and national security frameworks where evaluations implicate sensitive datasets or misuse risks. See the AI Safety Summit overview and subsequent network announcements: AI Safety Summit 2023 and International network.

International Alignment

AISI’s mandate emphasises international cooperation. The UK announced partnerships with the US and Singapore early in the Institute’s life, and AISI has worked to establish a broader international network of publicly backed AI Safety Institutes. These partnerships focus on shared testing methodologies, reciprocal access arrangements, secondments, and shared compute resources for priority testing. The international network and Seoul Declaration further reflect governments’ intent to align research agendas, standards and testing protocols across states and regions. AISI’s approach explicitly targets producing shared taxonomies and state-of-the-science reports that can be used for cross-border regulation and cooperative oversight. See: International network announcement.

Implementation Timeline

EventDateNotes
AI Safety Summit (Bletchley Park)2023-11-01/2023-11-02Summit and Bletchley Declaration; launch context
Public launch of AI Safety Institute2023-11-02Launch announcement
Frontier AI Taskforce progress and partner contracts2023-10-18Taskforce partnerships announced ahead of launch
Publication: AISI approach to evaluations2024-02-09Approach document
AISI evaluations platform release2024-05-10Platform announcement
International network agreement (Seoul Declaration)2024-05-21Commitment by multiple countries to a network
DSIT initial evaluation commissioned2024 (ongoing)Initial evaluation covering first two years; findings due early 2026

Sources and References

SourceType
Prime Minister launches new AI Safety InstitutePrimary Source
AI Safety Institute: approach to evaluationsPrimary Source
AI Safety Institute releases new AI safety evaluations platformPrimary Source
Global leaders agree to launch first international network of AI Safety InstitutesPrimary Source

Requirements for a company

What an organisation has to do under United Kingdom - AI Safety Institute, at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Must do

4
  • Comply with all applicable data protection and security obligations.All partners engaging with the AI Safety Institute.
  • Provide access to models, compute resources, and data as contractually agreed.Model providers partnering with the AI Safety Institute.
  • Engage with the AI Safety Institute for pre- and post-deployment model evaluations.Providers and researchers of advanced AI systems.
  • Participate in international information and methodological sharing where agreed.Partner governments and organisations collaborating with AISI.

Must not do

0

Nothing in this category.

Should do

2
  • Publish methodological details of evaluations where it is safe to do so.The AI Safety Institute and collaborating researchers.
  • Coordinate with relevant sectoral regulators to align research and policy inputs.The AI Safety Institute.

Should not do

0

Nothing in this category.

Who must do what

The obligations under United Kingdom - AI Safety Institute, most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1All partners engaging with the AI Safety Institute.Comply with all applicable data protection and security obligations.
Where non-compliance touches on statutory regimes (e.g., data protection...), relevant statutory regulators... retain their enforcement powers.
Penalties, Liability, and AppealsCritical
2Model providers partnering with the AI Safety Institute.Provide access to models, compute resources, and data as contractually agreed.
The Institute’s arrangements include contractual and partnership terms that govern access to models, compute resources and data-sharing agreements.
Governance and Institutional FrameworkImportant
3Providers and researchers of advanced AI systems.Engage with the AI Safety Institute for pre- and post-deployment model evaluations.
The founding announcements and operational documents for AISI emphasise voluntary cooperation, conditional access terms and partnership agreements.
Penalties, Liability, and AppealsImportant
4Partner governments and organisations collaborating with AISI.Participate in international information and methodological sharing where agreed.
AISI has pursued bilateral and multilateral partnerships... seeking to align testing standards and share methodologies.
International AlignmentImportant
5The AI Safety Institute and collaborating researchers.Publish methodological details of evaluations where it is safe to do so.
The Institute aims to enable curated data and methodological sharing... while balancing security and IP considerations.
Key Focus AreasRecommended
6The AI Safety Institute.Coordinate with relevant sectoral regulators to align research and policy inputs.
It also coordinates with other UK institutions... to align research priorities and policy inputs.
Governance and Institutional FrameworkRecommended

© Regulations.AI · updated on 13-Jun-2026