What is an AI safety institute, and what can it actually do?
Governments now run bodies that test the most powerful AI models before release. Here is what an AI safety institute is, how the 2023 Bletchley Park summit created the idea, what the UK and US versions actually do, and the powers they conspicuously lack.
By Zain
Published

What an AI safety institute actually is
An AI safety institute is a government body set up to test and understand the most powerful AI systems, before and after they reach the public. In practice that means a small team of technical staff, housed inside a national science or standards agency, doing four things: running pre-deployment evaluations of frontier models, red-teaming them to probe for dangerous capabilities, publishing research on how to measure AI risk, and helping write the technical standards that the rest of government and industry can lean on.
The word to hold onto is evaluation. These institutes are not ethics panels debating whether AI is good or bad. They are laboratories that ask concrete questions: can this model meaningfully help someone build a chemical or biological weapon, write novel malware, or run a convincing fraud at scale. The frontier systems they examine are the same ones behind mainstream chatbots and AI agents, which is why what these bodies find, and what they cannot compel, reaches well beyond policy circles.
Born at Bletchley Park
The idea has a clear birthplace. On 1 to 2 November 2023 the UK convened the first AI Safety Summit at Bletchley Park, the wartime codebreaking site, and 28 countries plus the European Union signed the Bletchley Declaration. The text pulled rival governments, the United States and China among them, into agreeing in writing that "actors developing frontier AI capabilities, in particular those AI systems which are unusually powerful and potentially harmful, have a particularly strong responsibility for ensuring the safety of these AI systems." Modest wording, but a real shift: safety established by testing, not by trust.
That shared premise, that frontier developers should be evaluated rather than taken at their word, is what national institutes were built to act on. Within weeks the UK stood up its AI Safety Institute, growing it out of an earlier Frontier AI Taskforce, and the United States announced its own at the National Institute of Standards and Technology, or NIST. Several other governments and the EU have since built or proposed their own versions.
“actors developing frontier AI capabilities, in particular those AI systems which are unusually powerful and potentially harmful, have a particularly strong responsibility for ensuring the safety of these AI systems”

The UK and US bodies, renamed
Naming here is fiddly, and getting it right is a fair test of whether a source knows the terrain. The UK institute launched in November 2023 as the AI Safety Institute. In February 2025 the government renamed it the AI Security Institute, keeping the acronym AISI but narrowing the public framing to risks with a clear security edge: cyber-attacks, fraud, child sexual abuse material, and chemical and biological weapons. It still sits inside the Department for Science, Innovation and Technology and describes its mission as equipping governments with a scientific understanding of the risks posed by advanced AI.
The US body took a sharper turn. Established at NIST in late 2023, following President Biden's October 2023 executive order on AI, the US AI Safety Institute was reorganised in June 2025 by Commerce Secretary Howard Lutnick into the Center for AI Standards and Innovation, or CAISI. The change dropped the word safety on purpose, recasting the mission around national security, voluntary standards and keeping American AI competitive, rather than the broader safety brief of the previous administration. Same institutional home, different emphasis, different name.
What they can and cannot do
This is where the hype and the reality part company. An AI safety institute is not a regulator. It issues no licences, and it cannot legally force a company to hand over a model, halt a launch, or pay a fine. Its testing runs on access that developers grant voluntarily, usually under commitments the labs made at Bletchley and the summits that followed. CAISI's published remit is built on "voluntary agreements" with AI developers. Independent analysts describe the UK institute in the same terms: a research body with world-class technical capacity but no statutory power to require submissions or block a release.
That voluntary footing is the whole ballgame. The institutes can produce genuinely rigorous evaluations, but only on the models companies choose to show them, on the timelines companies allow. When a lab cooperates, the public gets an expert read on a model's dangerous capabilities. When a lab declines, there is no backstop. These bodies convene, measure and advise; they do not approve or forbid.
Why they matter
Strip the powers away and it is fair to ask what the point is. The answer is that independent measurement is scarce and valuable. Before these institutes existed, more or less the only people stress-testing frontier models for weapons or cyber uplift were the companies selling them. A government team with security clearances, real compute and no product to ship changes that. Their findings feed into standards, into other agencies' decisions, and into an emerging shared vocabulary for what "tested" even means. That is early warning and a check on marketing, not a rubber stamp.
The honest limit matters just as much. An evaluation from AISI or CAISI tells you a model was examined by capable people. It does not certify the model is safe, and it cannot stop a company from shipping something the institute never saw. Read their reports as some of the best independent signal available, and treat anyone who calls these institutes AI's regulators as either confused or selling something.
Our take
AI safety institutes are one of the more sober developments in a field addicted to hype: real technical teams, inside government, measuring what frontier models can actually do. But read the labels. The UK's is now the AI Security Institute, the US body is CAISI, and neither is a regulator with the power to say no. They test with permission and publish what they find, which is both genuinely useful and genuinely limited. The question worth watching is not whether these institutes do good work. It is whether any government ever gives them the authority to act on what they learn.
Frequently asked questions
What is an AI safety institute?
It is a government body set up to test and understand the most powerful AI systems, before and after they reach the public. In practice it is a small technical team, housed inside a national science or standards agency, that runs pre-deployment evaluations of frontier models, red-teams them to probe for dangerous capabilities, publishes research on how to measure AI risk, and helps write technical standards.
Where did AI safety institutes come from?
The idea took shape at the first AI Safety Summit, held on 1 to 2 November 2023 at Bletchley Park in the UK, where 28 countries plus the European Union signed the Bletchley Declaration. The UK stood up its institute within weeks, growing it out of an earlier Frontier AI Taskforce, and the United States announced its own at the National Institute of Standards and Technology (NIST).
Can an AI safety institute force a company to hand over a model or stop a launch?
No. An AI safety institute is not a regulator: it issues no licences and cannot legally compel a company to submit a model, halt a release, or pay a fine. Its testing runs on access that developers grant voluntarily, usually under commitments the labs made at Bletchley and the summits that followed. When a lab declines, there is no backstop.
What happened to the UK and US institutes' names?
The UK institute launched in November 2023 as the AI Safety Institute and was renamed the AI Security Institute in February 2025, keeping the acronym AISI. The US body, established at NIST in late 2023, was reorganised in June 2025 by Commerce Secretary Howard Lutnick into the Center for AI Standards and Innovation (CAISI), dropping the word safety.
If they cannot enforce anything, why do AI safety institutes matter?
Because independent measurement is scarce and valuable. Before these institutes existed, more or less the only people stress-testing frontier models for weapons or cyber uplift were the companies selling them. A government team with security clearances, real compute and no product to ship provides early warning and a check on marketing, and its findings feed into standards and other agencies' decisions.
Sources
What each one is, and whose it is.
- 1
The Bletchley Declaration by Countries Attending the AI Safety Summit, 1-2 November 2023, Department for Science, Innovation and Technology, GOV.UK (November 1, 2023)
DocumentationIndependent of the vendor - 2
AI Security Institute, AI Security Institute (UK)
DocumentationIndependent of the vendor - 3
Center for AI Standards and Innovation (CAISI), National Institute of Standards and Technology (NIST)
DocumentationIndependent of the vendor