A recurring problem in ASI governance is that governments have historically lacked the in-house expertise to evaluate the systems they are meant to regulate. The safety institutes exist to close that gap. They are government or government-backed bodies staffed with technical researchers whose job is to assess the capabilities and risks of frontier models, the state finally building the ability to see what the labs are building, rather than taking their word for it.

Beginning with the UK and US in late 2023, national AI safety institutes have multiplied and linked into an international network. They are unglamorous, and they may be the most important governance infrastructure yet created.

Where the network came from

The United Kingdom announced its AI Safety Institute around the Bletchley summit in November 2023, the first of its kind. The United States established its own institute at NIST shortly after. At the Seoul summit in May 2024, a wider group of governments (including Japan, Singapore, Canada, South Korea, the EU, and others) agreed to build institutes and connect them into an international network to align their work. What began as two national bodies became the seed of a cooperative system.

A note on names: the two founding institutes have since been renamed, the UK's is now the AI Security Institute, and the US body became the Center for AI Standards and Innovation (CAISI) in 2025. The network and its evaluation work continue under the new names.

What the institutes actually do

  • Evaluate frontier models. They test advanced systems for dangerous capabilities (including in high-stakes domains) developing the methods to measure what a model can actually do.
  • Develop the science of evaluation. Rigorous, standardized testing of AI is an unsolved technical problem. The institutes are building the methodology that reliable governance requires.
  • Advise governments. They give states independent technical judgment about AI risks, reducing dependence on the developers' own assessments.
  • Cooperate across borders. Through the network, institutes share methods, coordinate testing, and work toward common standards, the beginnings of interoperable, international evaluation.

Why they matter for a treaty

The connection between the institutes and a future binding agreement is direct and underappreciated. Every serious proposal for an AI treaty depends on the ability to evaluate whether a system crosses a dangerous threshold and to verify compliance with safety obligations. That ability does not exist by default; it has to be built. The safety institutes are building exactly it. They are, in effect, constructing the technical organs that a verification regime would later use.

They also solve a sequencing problem. A treaty that specified evaluation requirements would be worthless if no independent body could perform the evaluations. By developing that capacity now (before the treaty exists) the institutes ensure the tools are ready when the political agreement arrives. The network is the practical groundwork on which binding governance can eventually stand, and it is being laid quietly while the higher-profile diplomacy proceeds in parallel.

The limits to be honest about

The institutes are not a substitute for binding governance, and it would be a mistake to treat them as one. Their access to models generally depends on the voluntary cooperation of developers; they cannot compel testing of a system a company declines to share. Their remits and resources vary widely between countries, and the network's coordination is still nascent and non-binding. And evaluation itself remains scientifically immature, reliably determining whether a model is dangerous is genuinely hard, and current methods have real gaps.

A treaty that requires safety evaluations is empty if no one can perform them. The safety institutes are building the eyes that any real verification regime will need. That work has to happen before the treaty, not after.

The infrastructure of enforceable governance

The safety institutes represent a shift from talking about AI risk to building the capacity to measure it. That shift matters because governance without measurement is just aspiration. The realistic path is for the network to mature, gaining guaranteed access to frontier models through legal mandate rather than goodwill, converging on shared standards, and building the independent, well-resourced evaluation capacity that a verification regime requires. The institutes will not save the world on their own. But they are assembling the instruments without which no binding treaty could function, and strengthening them is among the most concrete and immediately useful things governments can do while the larger agreement is still being negotiated.