We help decision-makers navigate the transition to a world with advanced AI, by producing rigorous research and fostering talent.

London, United Kingdom
Many organizations sit below the “cyber poverty line”: they skip basics like two-factor authentication and timely patching, making it easier for attackers to breach them through phishing, stolen credentials, and by exploiting known vulnerabilities. For instance, the chart here shows the security practices of businesses and charities in the UK, from a nationally representative 2025/26 survey by the UK Department for Science, Innovation and Technology. Fewer than half of UK businesses and charities use any two-factor authentication, or have a policy to apply security updates within two weeks. A quarter of UK businesses do not have a firewall covering their whole network.
1
8
1,358
The neglect of cybersecurity has partly been a rational response to the fact that, so far, the risk of cyberattacks for most organizations has been fairly low. But AI may soon change that. For most organizations, AI’s biggest near-term effect will not be to discover powerful “zero-day” exploits, but to make known attack methods — such as phishing and stolen credentials — cheaper to execute at scale. This would end the era in which skipping the basics was a safe bet. To manage the AI-cyber transition, we need to improve basic cyber hygiene as well as fixing novel vulnerabilities.
1
1
3
254
Read more in the new Substack publication from GovAI’s Threat Modeling Team, called “Credible Threats.” The team studies and writes about the pathways by which AI might lead to harm, such as via cyber attacks. → crediblethreats.substack.com…
1
162
Policy recommendations from the new paper by @sj_manning, @_achan96_, and an incredible team of collaborators. "What If Automating AI R&D Triggers an Intelligence Explosion?": governance.ai/research-paper…
Replying to @sj_manning
Given this possibility, policymakers at the highest levels of government should consider concrete ways they can: 1. Obtain better visibility into AI R&D automation at frontier AI companies, including the extent to which it is leading to an acceleration in the pace of algorithmic progress 2. Develop ways to steer and/or constrain an intelligence explosion driven by automating AI R&D, and 3. Prepare for the societal impacts that such an intelligence explosion could have
2
9
832
GovAI retweeted
We have a new paper out today: "What if automating AI R&D triggers an intelligence explosion?" led by @_achan96_, with an incredible team of collaborators. casp.ac/reports/intelligence… 🧵
Could automating AI R&D radically accelerate AI progress in an “intelligence explosion”? Preliminary evidence suggests that it could. In a new paper with authors across academia, civil society, and frontier AI companies (including @dawnsongtweets @merettm @jackclarkSF @Yoshua_Bengio @geoffreyhinton ), we assess the evidence & offer policy recommendations 🧵
7
27
143
18,307
New work led by researchers at GovAI — the first research collaboration across leading academics, senior scientists of frontier AI companies, and independent experts from civil society to assess the possibility of an intelligence explosion and recommend policies to prepare for it.
Could automating AI R&D radically accelerate AI progress in an “intelligence explosion”? Preliminary evidence suggests that it could. In a new paper with authors across academia, civil society, and frontier AI companies (including @dawnsongtweets @merettm @jackclarkSF @Yoshua_Bengio @geoffreyhinton ), we assess the evidence & offer policy recommendations 🧵
1
3
16
2,090
Interested in learning more about China's AI ecosystem? Check out this explainer co-authored by Zilan Qian, who recently joined our team at GovAI. Great to have you, Zilan!
Want to know about AI in China but find most of the recommended reading too hard to follow? Kayla and I have prepared a background explainer on China's AI ecosystem for people who are interested in the topic but are not familiar with China and/or AI. We looked at: Key Actors and Institutions; China’s AI Development Plans and Major Regulations; China’s Frontier AI Development; Frontier Risk Discussion; Reactions to US AI Breakthroughs and Incidents; and Reactions to Wider US AI Discourse. oxfordchinapolicylab.org/res…
9
802
Check out this thread + new blog post from GovAI researcher Cheryl Wu on AI safety in China.
China’s AI-safety trajectory is not necessarily a delayed version of America’s. [1/6] People seem to have this mental model: Chinese models trail US models in capability by a given number of months and are involved in similar safety incidents after a delay. Whether this is true matters for what Chinese AI safety communities can contribute.
2
2
14
1,611
Read the full blog post here: cherylwu3.github.io/blog/chi…
2
2
244
New work from our team makes the case for embedded assessments — where independent evaluators get employee-like access to an AI company’s internal systems to help scrutinize and reduce the risk from internal AI use. The paper also sketches out seven design choices for how embedded assessments could work in practice and offers recommendations.
Third-party evaluators mostly test frontier AI models through an API. That misses the risks that come from how companies build and use AI internally. Our new paper makes the case for embedded assessments. It was led by Jacob Charnock. The other co-authors are Sophie Williams, @zaheedkara, @Manderljung, Alejandro Tlaie Boria, @StephenLCasper, @AnkaReuel, and me. 🔗 Read the paper: governance.ai/research-paper…
1
1
14
992
Check out our researcher Zaheed Kara's new policy brief on "Improving Frontier AI Incident Reporting Regimes" → governance.ai/research-paper…
An AI agent hacking into another company’s systems seems like something policymakers would want to hear about. Yet there are currently gaps in the legal requirements to report incidents like this. After OpenAI agents breached Hugging Face, California officials said the incident “did not meet the threshold” for mandatory reporting. OpenAI notified EU authorities about the attack, but the EU Code of Practice does not require independent external investigations or routine sharing of the lessons learned across industry (nor do any US state laws!). In a new @GovAIOrg policy brief, I look at how we could close these gaps in US state and EU incident reporting regimes. Broadly, these regimes could require broader disclosure to bring more incidents to light; establish rules for triggering and facilitating independent investigations to understand what went wrong; and require corrective action and information sharing across industry to prevent similar failures. I recommend seven changes to this effect: 1. Expand mandatory reporting to include near misses. Incidents can reveal important safety failures, even when no serious harm occurs! These near miss events give developers a chance to address those failures before a similar incident actually causes damage. 2. Cover incidents during training, evaluation, and internal use. As seen in recent incidents, AI agents can affect external systems even before they are publicly released. Reporting requirements should cover serious incidents and near misses involving models still under development or never intended for release. 3. Require independent investigations of sufficiently serious cases. Internal investigations are useful, but they may overlook how developers’ own decisions, safety practices, or organizational culture contributed to incidents. For serious incidents (or near misses thereof), independent external investigations can provide scrutiny of developers’ explanations and identify additional failures. 4. Make actions traceable to the agents responsible. Attributing actions to a specific agent is an important step in learning about an incident because identifying the context in which an agent is operating (its instructions, permissions, and operating conditions) can help explain what went wrong and why. Developers should be able to reliably trace actions within their own infrastructure and on external systems to the specific agent instances responsible. 5. Specify what evidence developers must preserve. Adequately investigating incidents requires access to evidence. But evidence can be lost before an investigation even begins (e.g. logs can be overwritten, models updated, and operating environments deleted). Developers should retain essential records for defined periods and protect relevant evidence as soon as an incident is suspected. 6. Pilot conditional safe harbors to encourage candid, early reporting. Developers may hesitate to report incidents if doing so exposes them to penalties for safety violations. Conditional safe harbors could offer limited relief for inadvertent violations when developers report promptly, preserve evidence, cooperate with investigators, and correct the failure. 7. Require corrective plans, check whether fixes work, and share lessons across industry. Findings from one incident could help prevent similar failures at other companies. Developers should explain what they will change and by when, regulators should check whether those changes work, and useful lessons should reach others relying on similar safeguards. Incident reporting regimes can be an incredibly useful tool to prevent future harm. To do so, reporting an incident should lead to a process seeking to establish what went wrong, fix the failure, and share those lessons with other relevant actors. This way, each incident can leave developers, policymakers, and society better equipped to prevent the next one.
9
1,285
GovAI is hiring a Talent Program Manager! You'll design and test the programs that get our fellows and alumni into AI governance careers — career support, ecosystem mapping, new formats for senior people. Apply by Oct 4: governance.ai/post/talent-pr…
4
749
GovAI is hiring a Research Manager for our UK Fellowships! You'll help design and run our flagship Seasonal Fellowships — a biannual 3-month programme in London. Apply by 27 Sep: governance.ai/post/research-…
1
3
12
1,816
GovAI is hiring a DC Research Manager! Help run our DC Seasonal Fellowships: shape each ~20-person cohort and research manage about half of it. A good fit if you know US AI policy and enjoy coaching people. Apply by Sep 13: governance.ai/post/dc-resear…
1
3
1,075
We're hiring Research Scholars and Research Fellows at GovAI. GovAI's mission: help government bodies, technology companies, and other institutions make good decisions about AI. We do this in two ways: producing research to support informed decision-making, and running fellowships and visitor programs to address talent gaps. Now open: Research Scholar (12-month visiting position) Flexible, career-development-focused role with wide latitude (policy / social science / technical research; advising; convening; launching applied initiatives). Structured support via supervision, mentorship, and regular feedback. Comp (by experience/location): London £75k–£103.5k + benefits DC $100k–$165k + benefits Apply/info: governance.ai/post/research-… Research Fellow (2-year staff role, renewable) For experienced researchers driving core AI governance agendas: independent policy-relevant research, contributing to strategy, mentoring junior researchers. Comp (by experience/location): London £84k–£103.5k + benefits DC $134.5k–$170k + benefits Apply/info: governance.ai/post/research-… Research areas include: risk management, threat modeling, economics of AI, geopolitics, public policy, technical governance (and more). Location: Prefer London or DC, open to elsewhere (e.g. the Bay Area). Deadline: 23:59 AoE, Sun 16 Aug 2026. One shared application for both roles. If this sounds like you (or someone you know), please apply/share.
4
21
156
12,689
GovAI is hiring a DC Chief of Staff!🏛️ You'll act as the Executive Director's right hand in Washington: shaping our DC strategy, standing in for leadership, and building the team, systems, and relationships GovAI needs to succeed in DC. Apply by August 16: governance.ai/post/dc-chief-…
1
2
1,222
GovAI is hiring a Head of US Policy 🇺🇸 We're looking for a senior leader to shape GovAI's growing DC presence — setting our federal AI policy research strategy, building our team, and strengthening ties across the policy ecosystem. You'd report directly to our Executive Director, Ben Garfinkel. Applications reviewed on a rolling basis; priority deadline August 6th. Learn more and apply: lnkd.in/euiGQq9H
4
7
1,652
Apply for GovAI's 2027 DC Winter Fellowship! 📍 Location: Washington, DC 📅 Deadline: July 12, 2026 at 11:59PM ET The DC Winter Fellowship is a three-month bipartisan opportunity designed to accelerate or launch impactful careers in American AI governance and policy. Participants deepen their understanding of the field, connect with a network of experts, and build their skills and professional profile, all while conducting a research project of their choice under expert guidance. 🔗 Learn more: lnkd.in/dVuBpM8Z
5
29
3,884