The safety-institute network — and what the renames tell you
Lesson 2 of 5 in Summits, Safety Institutes, and Comparing Regimes Like a Pro.
Between 2023 and 2025, roughly a dozen governments built something that had never existed: state technical bodies whose job is to evaluate frontier AI models. None of them regulates. That is the design insight — an AI safety institute gives a government eyes on frontier capability without needing the statute it has not yet passed. Testing capacity first, rules later (or never).
| Body | Established | Signature feature |
|---|---|---|
UK AISI → AI Security Institute | Nov 2023 (renamed Feb 2025) | First mover; Inspect open-source evaluation platform; pre-release testing arrangements with Anthropic, Google DeepMind, OpenAI |
Japan J-AISI | Feb 2024 | Hosted within the IPA; evaluation guides aligned with Japan’s agile-governance stance |
US AISI → CAISI | Feb 2024 (renamed Jun 2025) | NIST-housed; renamed Center for AI Standards and Innovation — ‘safety’ excised, standards-and-competitiveness framing in |
Singapore AISI | May 2024 | Grew out of the Digital Trust Centre; plugs into AI Verify and Project Moonshot tooling |
EU AI Office | 2024 | The outlier: an evaluator with actual regulatory teeth over GPAI models under the AI Act |
Korea AISI | Nov 2024 | Under ETRI; companion to the AI Framework Act’s safety duties |
Canada AISI | Nov 2024 | Research-led (CIFAR ecosystem) — capacity without a statute after AIDA’s death |
India AISI | Announced Jan 2025 | Hub-and-spoke model under the IndiaAI Mission |
France INESIA | Jan 2025 | National institute for AI evaluation and security, announced ahead of the Paris summit |
Australia AISI | Announced Nov 2025 | Late entrant, paired with an existing-laws-first regulatory posture |
Kenya | Joined the network | First African member — the network’s claim to being more than a rich-country club |
The International Network of AI Safety Institutes — launched at Seoul in May 2024, first convened in San Francisco that November — is where the interoperability work happens: shared evaluation methods, multilingual testing exercises, and in July 2025 a joint evaluation of AI agents focused on data leakage and cybersecurity. The strategic goal is mutual recognition: if London’s evaluation of a model counts in Seoul and Ottawa, frontier oversight scales without every state duplicating scarce expertise.
Now read the renames like you read the summit names. The UK’s February 2025 shift to AI Security Institute narrowed the mission to national security, cyber and bio misuse — societal harms out. The US rename to CAISI in June 2025 went further, repositioning the body around standards and American competitiveness, alongside a visible US drift away from the network’s safety framing (recall: no US support for the second safety report, no US signature in Paris). The institutes survived the mood swing — but their vocabulary did not.
Key terms: AI safety institute, evaluation (evals), red-teaming, AI Office
Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.