Applications to attend are open · call for posters deadline 2 October (abstracts reviewed on a rolling basis)

Why we run this forum

The full reasoning behind the 2026 programme — the problem, its causes, and the three object-level areas where technical work most directly unblocks governance.

The Evidence Dilemma

The frontier AI development landscape shifts quickly, however evidence regarding new risks posed by frontier AI, and the ways in which we can reduce these risks, appear slowly.

This leads to what we call the ‘evidence dilemma’: policy makers don’t have, and are not acting on, enough accessible context on current developments in frontier AI — such as their training data, evaluations and user data. Alongside this, technical researchers are unable to do adequate technical AI safety research while they also lack access to that same context on frontier models. If policy makers and technical researchers continue to act with limited evidence or context on frontier models, that may lead institutions to adopt ineffective or harmful policies. However, waiting for stronger evidence could leave society vulnerable to risks such as misuse and loss of control.

Read more

Main causes

Evidence exists but isn’t shared

Some risks are well mapped, but only inside frontier labs. There is knowledge about the risks of frontier AI, but it has not reached the government, because the information (e.g. the training data) is proprietary.

Evidence exists but can’t be verified

Some risks are well mapped, and governments know but they can’t act. Claims about AI systems aren’t verifiable, so policies can’t be enforced, especially in countries with strong incentives to prioritise AI development.

Evidence doesn’t yet exist

Some risks aren’t well mapped. Third-party audits are under-resourced, including policy design and the amount of time evaluators have to test models, and there is no reliable way to translate what models can do into what harm they could cause in the world.

How the forum will address the evidence dilemma

We believe it is extremely valuable to bring policy makers and technical AI safety researchers together to address these risks. Technical researchers can inform on and develop methods of gathering the evidence needed to mitigate risks from frontier AI; policy makers can ensure those methods are implemented. By connecting the two groups, we can make sure the evidence developed by technical researchers reaches the people who act on it and write policy from it, and technical researchers can better understand who their work is for. We connect these people through talks, panels and workshop sessions, as well as networking and 1:1s.

Three focus areas

AI Verification

Hardware verification, scalable oversight & international coordination

States may want to enter into agreements about how much compute they’re using to slow down a race to developing frontier AI. Such agreements would need verification from the hardware without any state being able to cheat on the conclusions drawn.

Read the brief

Jurisdictions such as the EU AI Act and US Executive Order 14410 are beginning to regulate frontier AI systems. With that comes the need for enforcement mechanisms capable of verifying compliance.

One approach is hardware verification, which is particularly useful for easing the trade-off between extensive and limited access to frontier AI. Wider access to advanced AI raises the risk of misuse and loss of control; tighter restraint reduces our ability to innovate and further consolidates existing imbalances of power. Hardware verification alleviates that trade-off, because it can authenticate complicated statements about how AI is being developed and used without revealing highly sensitive information — a developer could evidence that a model abided by safety regulations while it was being evaluated (Dalrymple & Ammann, 2025).

The other route to enforcement is scalable oversight: mechanisms that scale as the systems they oversee become more capable. The aim is oversight that still holds during the training of advanced AI systems.

At the forum we will discuss these enforcement mechanisms and consider international coordination as the way to implement them, along with the problem of reconciling confidentiality with reducing risks from frontier AI.

Background reading
Dalrymple & Ammann (2025), Faster AI diffusion through hardware-based verification ↗
Harack et al. (2025), Verification for international AI governance ↗
Baker et al. (2026), Verifying international agreements on AI ↗
O’Gara et al. (2025), Hardware-enabled mechanisms for verifying responsible AI development ↗

How this will work at the forum

The forum will highlight different methods for building verifiable AI, including hardware verification and scalable oversight, so that policies between countries will then become enforceable. We’ll have technical researchers speaking on these topics individually and in a guided panel format alongside policy makers to discuss how to adopt policies based on these methods.

Trustworthy auditing

Third-party access & risk modelling

Third-party evaluators work through black-box APIs and often lack sufficient time and access to carry out effective audits of frontier AI models nor can they fully guarantee a model’s safety.

Read the brief

Currently, AI safety teams within frontier labs either do not prioritise, or do not have time for, robust policies they could plausibly implement regarding frontier AI models. What should you report about chain-of-thought monitors, for instance? Safety teams within these labs often have only a few weeks to make those policy and design choices.

To avoid bias within frontier labs, third-party evaluators conduct audits and model evaluations to determine how safe a model is. Conducting a robust audit is difficult: labs permit third-party evaluators to work only through a black-box API, so evaluators often cannot get a reliable upper bound on a model’s capability, and are given around a week to evaluate it. In July 2026 the Ada Lovelace Institute published an article highlighting that frontier labs control the type of tests UK AISI can carry out, their duration, and the access periods — Anthropic gave UK AISI less than a week to evaluate Claude Sonnet 4.5 (Ada Lovelace Institute, 2026). That is arguably not enough time to design an evaluation, debug it and obtain statistically significant results, and it becomes less so as capabilities on long-horizon tasks improve.

A second problem is that models are starting to distinguish test settings from real-world deployment, and to exploit loopholes during an audit — so a dangerous capability can go undetected before release. That blocks everything downstream, regulation included, and makes it harder to anticipate a model’s limitations or how it will affect society: developers cannot always predict how capabilities will change, or whether the change will be harmful (Brundage et al., 2026).

At the forum we will work through third-party access to frontier AI models, and the risk modelling techniques needed to counter their dangers after deployment.

Background reading
Ada Lovelace Institute (2026), Making sense of the UK’s AI Security Institute ↗
Brundage et al. (2026), Frontier AI auditing: toward rigorous third-party assessment ↗
Greenblatt et al. (2026), OpenAI–Hugging Face incident investigation ↗

How this will work at the forum

It is important to make progress on the open problems that will help mitigate risks from frontier AI, including robust third-party audits, testing models on long-horizon tasks, and mapping capabilities to real-world risk. At the forum, speakers will be presenting on these topics to ensure technical researchers and policy makers are aligned with current progress. Alongside this, panel sessions will discuss how to best approach these open problems, and individuals are encouraged to pitch their ideas in front of funders to make progress on them.

AI R&D automation

Measuring its effects on AI progress and oversight

As models take on more of the research loop, the pace of capability gain and the difficulty of overseeing it are correlated. Here, we’re looking at what we can actually measure within automated AI R&D.

Read the brief

It is currently unclear what automating AI R&D does. Reducing that uncertainty needs empirical data, and what we have now — largely capability benchmarks — may not reflect automation in the real world, nor show its broader impact. Does automated AI R&D accelerate capability faster than safety progress? Can we manage it as it accelerates?

The forum will work through those gaps, and through ways of tracking how far automation has gone and what it does to the pace of AI progress. Metrics such as researcher time allocation could help decision makers see the results of automated AI R&D, track how quickly AI develops, and put suitable safety measures in place (Chan et al., 2026).

Background reading
Chan et al. (2026), Measuring AI R&D automation ↗
OpenAI (2026), Research acceleration: the view inside OpenAI ↗
Anthropic (2026), When AI builds itself ↗
Fist, Khan et al. (2026), How should the US prepare for increasingly automated AI R&D? ↗

How this will work at the forum

AI R&D automation is another area where we are excited to encourage much more serious thinking. As AI systems become increasingly capable of contributing to AI research itself, this could substantially change both the pace and nature of frontier AI development. Our speakers and panellists will explore what current progress in AI R&D automation looks like, how quickly these capabilities may advance, and what this could mean for both capabilities and safety research. A particular focus will be on how technical researchers and policymakers should respond: which parts of the AI R&D pipeline are likely to become automated? Where are the most important risks likely to emerge? How can we shape this transition towards safer outcomes? We want participants to leave with a clearer picture of how AI R&D automation could unfold and, importantly, with their own views on what work is most needed to steer it towards safer outcomes. Participants will also have opportunities to develop and pitch promising ideas in this area to funders.

The Working Pathways

Connecting the field

Technical AI governance is a real sub-field now, but a nascent one. There are still few people who understand both sides well, which is why we’re putting technical researchers, policy makers and funders in the same place.

Fostering collaborations

A paper on arXiv does not mean a technical governance issue will be solved. We’ll be using Swapcard to set up introductions before the forum, and running office hours and 1:1s throughout. The poster hall and organisation fair will be open all day, so that a conversation can become a working relationship.

Bringing talent in

The organisation fair, the founder pitch sessions and the poster sessions exist to move people and funding into the field.