What the AI Security Institute Is

The body now known as the AI Security Institute began life as the AI Safety Institute (AISI), announced by the UK government at the AI Safety Summit held at Bletchley Park in November 2023. It traces back to a smaller unit announced in April 2023 and backed with an initial £100 million in government funding, originally named the Foundation Model Taskforce and renamed the Frontier AI Taskforce in September 2023, according to the GOV.UK announcement of that funding. The Institute sits inside the Department for Science, Innovation and Technology (DSIT) and describes its own mission, in its official founding overview, as working "to minimise surprise to the UK and humanity from rapid and unexpected advances in AI."

That founding document sets out three core functions: conducting independent evaluations of advanced AI systems, including dual-use risks, security and loss-of-control scenarios; carrying out foundational safety research; and acting as a trusted intermediary for information exchange between AI developers, policymakers, academia and civil society. Crucially, the same document states plainly that the Institute "is not a regulator and will not determine government regulation." Its output is evidence and technical evaluation, not enforcement.

Relationship With Frontier Model Developers

Following the Bletchley summit, the UK secured voluntary commitments from major AI developers, reported at the time to include OpenAI, Google DeepMind, Anthropic, Meta and others, to give government evaluators access to models ahead of public release. This is not a legal requirement; companies choose to participate. In practice the Institute has used that access to run pre-deployment evaluations, publishing its own account of testing OpenAI's o1 model and Anthropic sharing its upgraded Claude 3.5 Sonnet ahead of release, as described in the Institute's pre-deployment evaluation write-up for the o1 model. These arrangements give the Institute a window into frontier capability before the public does, but they do not give it a veto: no developer is legally obliged to submit a model, and the Institute has no statutory power to delay or block a launch.

International Role: the AI Safety Report, Hiroshima Process and GPAI

The UK Institute provides the Secretariat for the International AI Safety Report, the independent, Bletchley-mandated synthesis of the global evidence base on advanced AI risk chaired by Turing Award winner Yoshua Bengio and supported by an Expert Advisory Panel drawn from around thirty countries plus the UN, EU and OECD. The first full report was published in January 2025, with the second annual edition, the International AI Safety Report 2026, published on 3 February 2026 and summarised on arXiv. Separately, the UK's Hiroshima summit was a precursor process rather than one the Institute itself runs; the G7's Hiroshima AI Process Comprehensive Policy Framework, agreed in December 2023, and its Code of Conduct reporting arrangements are operationalised through the OECD in partnership with the Global Partnership on AI (GPAI), as set out on the OECD.AI Hiroshima page. The UK Institute is one node in this wider international network of safety institutes rather than the sole owner of either process.

The 2025 Rename: Safety to Security, Verified

Public reporting that the Institute was renamed is correct, and the date can be pinned down precisely. On 14 February 2025, then Technology Secretary Peter Kyle announced at the Munich Security Conference, three days after the Paris AI Action Summit, that the AI Safety Institute would become the AI Security Institute, a change confirmed in Hansard and in a formal written ministerial statement to Parliament. Coverage of the change, including Infosecurity Magazine's report and Computer Weekly's coverage, describes the stated reason as a shift in government emphasis toward AI risks with security implications, particularly cyber-attacks, cyber fraud and other crime, rather than the broader "safety" framing used at Bletchley.

Did the mandate actually change? Partially. The rename came with one clearly new addition: a criminal misuse team working jointly with the Home Office on how AI can be abused for crime, alongside closer partnership with the Ministry of Defence's Defence Science and Technology Laboratory, the Laboratory for AI Security Research and the National Cyber Security Centre. But the Institute's core evaluation and research work did not stop or get replaced. Through 2025 and into 2026 it kept publishing frontier model evaluations under the same GOV.UK domain (aisi.gov.uk), so the rename reads as an added security-crime strand and a rebrand of emphasis layered onto continuing evaluation and research functions, not a wholesale redefinition of what the body does day to day.

2026 Activity: Evaluations and Publications

The Institute published its first Frontier AI Trends Report in December 2025, a synthesis of two years of evaluations across more than thirty frontier models covering cyber, chemistry and biology, autonomy, safeguards and societal impact, summarised in the Institute's own key findings post. It reported that a model first surpassed biology PhD-level performance on its test set in 2024, that cyber task performance at apprentice level rose from around 9 percent in late 2023 to around 50 percent by 2025, and that "universal jailbreaks" persist across every system it has tested, even as the effort needed to find some jailbreaks rose roughly 40-fold between two models released six months apart.

On 30 April 2026 the Institute published its evaluation of OpenAI's GPT-5.5 on cyber tasks, recording a 71.4 percent pass rate on its expert-tier cyber suite against 68.6 percent for Anthropic's Claude Mythos Preview and notably lower scores for two earlier models, detailed in its GPT-5.5 cyber capabilities write-up; an early GPT-5.5 checkpoint completed a simulated corporate network attack end to end, a task the Institute estimates would take a skilled human around 20 hours. It has also published comparative work on how far open-weight models trail the frontier on cyber capability, in its open-weight cyber gap analysis. Separately, the Institute helped launch the Alignment Project, an international funding coalition on AI alignment research backed by partners including Anthropic, AWS and Canada's AI Safety Institute, announced on GOV.UK on 30 July 2025.

What It Is Not

For enterprise risk and compliance teams tracking this body, the single most important fact is a negative one. The AI Security Institute is an evaluation, research and advisory body. It has no statutory authority to approve, delay or block the release of any AI product, no power to fine a company, and no enforcement remit comparable to a financial or safety regulator. Its evaluations shape international evidence, inform ministers and feed voluntary safety commitments from developers, but a frontier lab that declines to share a model, or that disagrees with an evaluation finding, faces no legal penalty from the Institute itself. Any future UK regulatory power over frontier AI would need to come from separate legislation and a body with statutory enforcement authority, not from AISI as currently constituted.

Primary sources: GOV.UK: Introducing the AI Safety Institute · GOV.UK: AI Security Institute about page · AISI: Pre-deployment evaluation of OpenAI's o1 · AISI: Frontier AI Trends Report findings · AISI: GPT-5.5 cyber evaluation · AISI: Open-weight cyber gap · Hansard: AI Security Institute debate · UK Parliament written statement HLWS454 · Infosecurity Magazine: rebrand coverage · Computer Weekly: rebrand and Anthropic partnership · OECD.AI: Hiroshima AI Process · International AI Safety Report 2026 · GOV.UK: Alignment Project launch · GOV.UK: initial Taskforce funding