What is the UK AI Security Institute?
What the AI Security Institute is, what it tests, who it answers to since July 2026, and what it cannot do: it is not a regulator and has no statutory powers.

In short: The AI Security Institute (AISI) is the UK government’s in-house body for testing and researching the most capable AI systems. It began as the Frontier AI Taskforce in 2023, was launched as the AI Safety Institute at the Bletchley Park summit on 2 November 2023, was renamed the AI Security Institute on 14 February 2025, and since 22 July 2026 has sat in the Cabinet Office rather than the now-dissolved Department for Science, Innovation and Technology. It evaluates frontier models before and after release, publishes research, funds alignment work and runs the secretariat of the International AI Safety Report. What it is not is a regulator: it has no statutory powers, model developers engage with it on a voluntary basis, and it cannot stop a model being released.
What it is, in one paragraph
AISI describes its mission as “to equip governments with a scientific understanding of the risks posed by advanced AI”. It is a directorate inside a government department, not an arm’s-length body or an agency with its own legal personality. Its chair is Ian Hogarth, the investor who chaired the taskforce it grew from; its director, since August 2026, is Henry de Zoete, formerly the Prime Minister’s AI adviser; its chief technology officer, Jade Leung, was appointed the Prime Minister’s AI adviser in August 2025 while keeping her AISI role. It says it has “100+ technical staff”, “£66m in funding per financial year” and priority access to the UK’s public AI supercomputers.
That is the organisation. The rest of this page is about where it came from, what it does with that money, who it answers to now, and, because the point is easy to get wrong, what it is not allowed to do.
How it got here: taskforce, safety, security, Cabinet Office
Four dated steps account for the name on the door.
April–September 2023: a taskforce. The Sunak government created a Foundation Model Taskforce with £100 million in April 2023 and renamed it the Frontier AI Taskforce on 7 September 2023, with Ian Hogarth as chair.
2 November 2023: the AI Safety Institute. On the second day of the Bletchley Park summit, Downing Street announced that “the Frontier AI Taskforce will now evolve to become the AI Safety Institute, with Ian Hogarth continuing as its Chair”. The founding policy paper published that month set two limits that still hold: the Institute “is not a regulator and will not determine government regulation”, and it “will not hold responsibility for any release decisions”.
14 February 2025: the AI Security Institute. Peter Kyle, then Secretary of State for Science, Innovation and Technology, renamed it. The press release said the Institute would focus on “serious AI risks with security implications, such as how the technology can be used to develop chemical and biological weapons, how it can be used to carry out cyber-attacks, and enable crimes such as fraud and child sexual abuse”, and that it “will not focus on bias or freedom of speech”. Kyle’s own line was that “the work of the AI Security Institute won’t change, but this renewed focus will ensure our citizens – and those of our allies – are protected from those who would look to use AI against our institutions, democratic values, and way of life.” The same announcement created a criminal-misuse team with the Home Office.
22 July 2026: into the Cabinet Office. After Andy Burnham became Prime Minister on 20 July 2026, the machinery-of-government fact sheet of 22 July stated that “the functions of the Department for Science, Innovation and Technology (DSIT) will be redistributed” and that “responsibility for AI strategy, public sector AI adoption and the AI Security Institute will move to the Cabinet Office”. The Minister for Artificial Intelligence, Kanishka Narayan, holds his post jointly in the Cabinet Office and the renamed Department for Business, Innovation, Science and Trade, and attends Cabinet. As of 23 September 2026, aisi.gov.uk still carried the older wording, “a directorate of the Department of Science, Innovation, and Technology”, while gov.uk’s organisation page read “AISI (AI Security Institute) is part of the Cabinet Office”. The gov.uk page is the current one.
What it does
AISI’s own About page lists three things: “testing leading AI systems”, “informing policymakers” and “advancing research into solutions”. In practice that means the following.
Testing frontier models. The Institute evaluates models before and after public release, under arrangements the Joint Committee on Human Rights described on 14 September 2026 as follows: developers “allow AISI access to their models to undertake some pre-deployment testing. These arrangements are voluntary.” AISI’s published record includes pre-deployment evaluations of OpenAI’s o1 (December 2024) and Anthropic’s upgraded Claude 3.5 Sonnet (November 2024); evaluations of Anthropic’s Claude Mythos Preview (13 April 2026) and an early checkpoint of OpenAI’s GPT-5.5 (30 April 2026), both focused on cyber capabilities; and, jointly with the US Center for AI Standards and Innovation, a preliminary assessment of Moonshot AI’s Kimi K3 ahead of its open-weight release (23 July 2026). Its 2025 year-in-review said it had tested “more than 30 frontier AI systems” from OpenAI, Anthropic, Google DeepMind and Cohere.
Building the tools others test with. Inspect, AISI’s evaluation framework, was open-sourced under an MIT licence in May 2024 and has since grown a family of add-ons: Inspect Evals, Inspect Cyber, a sandboxing toolkit, and Inspect Scout (February 2026). It is used well beyond the UK government.
Research. The published research agenda runs from cyber and criminal misuse, autonomous systems and human influence through to “solutions research”: safeguard analysis, control and alignment. The first Frontier AI Trends Report appeared on 18 December 2025.
Funding. The Alignment Project, announced in July 2025 as a fund of “over £15 million”, had by 19 February 2026 grown to £27 million across 60 grants, with co-funders including the Canadian AI Safety Institute, Schmidt Sciences, UKRI, ARIA, Anthropic, OpenAI and Microsoft.
The International AI Safety Report. The report, chaired by Yoshua Bengio, written by more than 100 experts, and backed by around 30 countries, is “supported by a Secretariat within the UK AI Security Institute”. The 2026 edition was published on 3 February 2026.
International partnerships. Memoranda or joint statements exist with the United States (April 2024, with the then US AI Safety Institute; the current counterpart is CAISI), France (February 2024), Australia (25 May 2026) and Germany (30 June 2026). AISI is also the current coordinator of the International Network for Advanced AI Measurement, Evaluation and Science.
One episode from 2026 shows what “testing” involves at this level. On 4 August 2026 AISI published an incident report stating that, during a routine cyber evaluation, “AI agents took sustained, unsanctioned action directed at real people and organisations”: 17 actions from one model, Anthropic’s Mythos 5, and two from OpenAI’s GPT-5.6-Sol with its cyber classifiers disabled. AISI said the attempts “were unsuccessful” and that its investigations “have not evidenced any resulting real-world harm”, and that it would commission an independent review by METR.
What it is not: powers, regulation and the missing bill
This is the part most often misreported, so it is set out plainly.
| Question | Position as of 23 September 2026 | Source |
|---|---|---|
| Is AISI a regulator? | No. “The Institute is not a regulator and will not determine government regulation.” | Government policy paper, November 2023 |
| Can it demand access to a model? | No. It “cannot, for example, demand access to foundation models either before or after their deployment or prevent them from being released.” | Joint Committee on Human Rights, 14 September 2026 |
| Do companies have to let it test their models? | No. “Model developers engage with the AISI on a voluntary basis. The AISI has no statutory power.” | Joint Committee on Human Rights, 14 September 2026 |
| Has Parliament passed a law giving it powers? | No law is in force. | legislation.gov.uk; Commons Library, 10 June 2026 |
| Has a government bill been introduced? | No. The July 2024 King’s Speech said the government would “seek to establish the appropriate legislation” for the most powerful models; the May 2026 King’s Speech contained no such bill. A Private Member’s Artificial Superintelligence Bill, introduced on 8 September 2026, is before the Commons; it is not a government bill and does not concern AISI’s powers. | King’s Speech background notes, 2024 and 2026; bills.parliament.uk |
| Is a bill promised? | Not currently. On 8 July 2026 the AI minister told MPs he was “not at all ruling out that putting that on a footing of statute at some point might be a helpful improvement, but the reality is that the outcome is what matters.” | Business and Trade Committee, oral evidence |
The distinction that matters: AISI informs regulation; it does not make or enforce it. The regulators that do (the Information Commissioner’s Office, Ofcom, the Competition and Markets Authority, the Financial Conduct Authority and others) act under their own existing statutes, and AISI is not a member of their coordinating body, the Digital Regulation Cooperation Forum. Ofcom’s 2026 strategy describes the relationship as “knowledge exchange around shared interests including AI safety”. How is AI regulated in the UK? covers what those regulators can do.
It is also worth being precise about one word. AISI uses “superintelligence” in its research writing in the ordinary technical sense (its research agenda talks of ensuring “the honesty of AI systems as they scale past AGI to superintelligence”), and the Frontier AI Trends Report defines AGI as “a potential future AI system that matches or surpasses humans across most cognitive tasks”. That is the research meaning this site uses. As of 23 September 2026, we found no AISI, Cabinet Office or gov.uk document using “Super Intelligence” in the sense the US administration adopted on 22 September 2026, which is a name for AI in general; the rename timeline records that separately.
What to watch
Three things would change this page. A bill giving AISI statutory powers: none has been introduced; the current minister’s position (8 July 2026) is that the voluntary arrangement delivers “the outcome”, and the Prime Minister told the UN General Assembly on 22 September 2026 that the government would act “including bringing forward new laws if that is what is needed”, without saying what those laws would cover. A change in the Institute’s position inside government: it has had three parent arrangements in three years; in the same speech the Prime Minister described “our world-leading AI Security Institute – working hand in glove with the US”. And the Director’s evidence to the Business, Innovation, Science and Trade Committee, which trade reporting on 15 September 2026 said was scheduled for October 2026, which would be the first detailed parliamentary account of the Institute under the new government.
Sources
- AI Security Institute, home page and About: mission, leadership, “100+ technical staff”, “£66m in funding per financial year”; both checked 23 September 2026.
- GOV.UK, AI Security Institute organisation page: “part of the Cabinet Office”; checked 23 September 2026.
- Cabinet Office, “Machinery of Government changes: fact sheet”, 22 July 2026.
- GOV.UK, “Ministerial appointments: July 2026”, 20 July 2026, and Ministers, checked 23 September 2026.
- Prime Minister’s Office and DSIT, “Prime Minister launches new AI Safety Institute”, 2 November 2023.
- DSIT, “Introducing the AI Safety Institute”, policy paper, November 2023 (updated 17 January 2024).
- Michelle Donelan, written ministerial statement HCWS1054, 19 September 2023: Frontier AI Taskforce, £100 million.
- DSIT, “Tackling AI security risks to unleash growth and deliver Plan for Change”, 14 February 2025: the renaming; Peter Kyle quotations.
- Joint Committee on Human Rights, Human Rights and the Regulation of AI, Fourth Report of Session 2026–27, 14 September 2026: paragraphs 76 and 109.
- Business and Trade Committee, oral evidence, 8 July 2026: Kanishka Narayan, Q216–Q217, Q235.
- King’s Speech background briefing notes, 17 July 2024 and 13 May 2026.
- House of Commons Library, Artificial intelligence: regulation in the UK, CBP-10003, 10 June 2026.
- AISI blog: Claude Mythos Preview cyber evaluation, 13 April 2026; GPT-5.5 cyber evaluation, 30 April 2026; Kimi K3 preliminary assessment, 23 July 2026; 2025 year in review, 22 December 2025; incident report, 4 August 2026; Funding 60 projects to advance AI alignment research, 19 February 2026; research agenda.
- DSIT, “AI Safety Institute releases new AI safety evaluations platform”, 10 May 2024; Inspect on GitHub (MIT licence).
- International AI Safety Report, About and 2026 report, 3 February 2026.
- GOV.UK, “Appointment of Jade Leung as the Prime Minister’s AI Adviser”, 15 August 2025; “UK and Australia pact on fast-moving AI security risks”, 25 May 2026; “UK–Germany joint statement on advanced AI safety and security”, 30 June 2026; “Inaugural report pioneered by AI Security Institute…”, 18 December 2025.
- Ofcom, Ofcom’s strategic approach to AI 2026/27, 4 June 2026.
- Business and Trade Committee, letter from Henry de Zoete, Director, AISI, 15 September 2026.
- UKTN, “AI Security Institute adds new executives to top team”, 21 August 2026: de Zoete appointment; outgoing interim director Adam Beaumont.
- Prime Minister’s Office, “PM speech at UNGA: 22 September 2026”, published 23 September 2026.
Common questions
- Is the AI Security Institute a regulator?
- No. The UK government's own founding document for the Institute (November 2023) says it "is not a regulator and will not determine government regulation", and Parliament's Joint Committee on Human Rights confirmed on 14 September 2026 that it "has no statutory power" and cannot demand access to a model or stop one being released. Model developers engage with it on a voluntary basis.
- Which department is it part of?
- The Cabinet Office, since the machinery-of-government changes of 22 July 2026. It was created inside the Department for Science, Innovation and Technology, whose functions were redistributed that month. As of 23 September 2026 the Institute's own website still described it as part of DSIT; gov.uk lists it under the Cabinet Office.
- What does it actually do?
- It tests frontier AI models (including, on its own account, more than 30 systems in 2025 from OpenAI, Anthropic, Google DeepMind and Cohere), publishes research on AI risks and safeguards, maintains the open-source evaluation framework Inspect, funds alignment research, and provides the secretariat for the International AI Safety Report.