Martin Wählisch /Sep 3, 2026Republish
In June, Germany’s National Security Council decided to create an AI Security Institute, known as DE-AISI. The issue gained wider attention in Germany during a public debate over the potential use of Claude Mythos in cyberattacks against the country’s financial system.The new institute will analyze the capabilities and risks of advanced AI models, and work with international partners toward common standards. But the government has yet to settle many of the questions that will determine what the new institute can accomplish.
German cities Munich, Berlin, Darmstadt and Saarbrücken are currently competing to host it. While Munich points to its technology companies and research community, Berlin offers proximity to federal ministries. Darmstadt points to its engineering and cybersecurity expertise, and Saarbrücken to its renowned AI and computer science cluster.
However, the far more consequential choices concern the AI safety institute’s mandate, its relationship with other agencies, and what happens when its researchers uncover a serious risk.
Germany’s digital industry association, Bitkom, favors a narrow research mandate. It wants DE-AISI to concentrate on systemic threats posed by frontier models to national security and technological sovereignty, without taking on regulation or anything else.Meanwhile, researchers from the German Research Center for Artificial Intelligence (DFKI) that the institute’s remit also extends to privacy, ethics, human oversight, and the use of AI in employment, healthcare, public services, and law enforcement.
This reflects two different ideas of what an AI institute should be for. One treats it as a specialist laboratory for study of frontier-model threats. The other sees it as a public institution that should examine how AI affects people and institutions across society.
In either case, the public value of the institute will greatly depend on how effectively it can transform technical expertise into impact. This is one clear lesson to draw from comparable AI safety institutes that have been established in the United Kingdom, United States, Australia, Canada, France, India, Japan, Kenya, South Korea, Singapore, and the European Union in recent years, with a variety of different approaches and structures.
That lesson applies to an institute’s mandate and governance, as well as to how it conducts its research. Frontier-model evaluations often place systems in deliberately permissive environments, with safeguards reduced, access to tools, and the open internet enabled. These conditions can expose capabilities that ordinary testing would miss. They can also allow an evaluation to spill into the real world.
Testing dangerous systems can itself be dangerous
In July 2026, AI agents under evaluation by the UK AI Security Institute (AISI) took unauthorized actions on the live internet. In the most serious case, one agent tried to insert malicious code into a real open-to pressure a project maintainer to approve the code
AISI’s own team identified the behavior and disclosed the incident. They also acknowledged they had deliberately provided the agent with internet access and had not actively monitored its actions.
To its credit, the institute did not bury the episode, but instead set out to change its testing practices. Their disclosure gave other organizations a chance to learn from the failure.
Germany’s DE-AISI will need strict controls on external access, continuous monitoring, clear limits on what agents may do, and an independent process for reviewing serious incidents. Its own security practices should face the same scrutiny it applies to AI companies.
Exposing a risk is not the same as addressing it
The UK experience also shows that AI institutes can identify dangerous capabilities, but cannot necessarily require a company to strengthen its safeguards, delay a release, or submit a model for further evaluation. Access depends on companies choosing to cooperate.
That dependence creates an imbalance: the institute needs access to proprietary models to conduct meaningful tests, but criticizing a provider too forcefully could threaten future cooperation. Meanwhile, companies can cite government testing in their model reports without necessarily disclosing what was found, how they responded, or whether the institute considered those measures adequate.
Germany must establish what happens after DE-AISI researchers identify a serious threat. Which authority can demand corrective action? When must the Federal Office for Information Security, the Federal Network Agency, or the European AI Office become involved? Under what circumstances should the public be informed?
Without a formal route from evaluation to action, DE-AISI could produce technically impressive research that leads to zero changes.
A new government can change an institute’s purpose
AI institutes can also quickly be politicized. In 2025, the Trump administrationrenamed the US AI Safety Institute as the Center for AI Standards and Innovation. Its revised mission placed greater weight on national security, innovation, and American competitiveness.
The change in name and mission showed how easily a new administration can redirect an institute toward a different understanding of AI governance. Research priorities, relationships with companies, and decisions about which risks deserve attention can all follow.
Germany cannot entirely remove politics from a publicly funded body, nor should it try. Decisions about acceptable risks and public priorities are political. Scientific findings, however, should not depend on whether they fit the message of the ministry in charge.
Stable funding, transparent research priorities, and the freedom to publish inconvenient findings would give DE-AISI some protection against abrupt political shifts. Without those safeguards, its agenda could shift with each government or become an extension of industrial policy.
A new institute needs a job of its own
Different government entities have overlapping interests in AI safety, and there are different ways to divide or collaborate on the work. For instance rather than create a separate legal entity, France’s National Institute for AI Evaluation and Security brings together four existing organizations with expertise in cybersecurity, digital research, technical testing, and regulation.
Germany has chosen a different structure but a similar starting point, as DE-AISI currently draws on expertise from the Federal Office for Information Security as well as the Federal Network Agency. In addition, the European AI Office evaluates general-purpose models and has powers to enforce the EU AI Act.
Germany therefore needs to identify which work will be done by DE-ASISI instead of another federal agency or the European Union. It will be important to decide from the start which evaluations DE-AISI will conduct itself, when it will support existing agencies, and which body is expected to act on its findings. It all depends on what the focus of research will be. DE-AISI could also advise German authorities on how to challenge assessments produced by AI companies or foreign institutes, in a way that feeds into European standards.Without a clear division of labor, Germany risks producing overlapping research, competing assessments, and confusion over who must respond whenever a serious threat is identified.
Measure impact, not reports published
Finally, how will Germany know whether the institute is working well?
Regardless of the number of research papers, model evaluations, international agreements, and conference appearances, a technically capable institute will remain peripheral if ministers, regulators, and companies are free to ignore its findings.
In order to show its impact, DE-AISI would need to track whether an evaluation led a company to alter a model, helped an authority prevent an incident, improved defenses in critical infrastructure, or produced testing tools adopted by others.
Some results will remain confidential for legitimate security reasons. That makes public reporting harder, but aggregated figures, anonymized case studies, accounts of policy changes, and explanations of how its work affected government preparedness need to be transparent to create value for the research community and public advocacy.
Whether DE-AISI should concentrate on frontier-model security or examine a wider range of harms will probably not be settled anytime soon, nor is there a perfect model abroad for Germany to copy. Still, Germany has the advantage of being able to borrow from what worked elsewhere and avoid at least some of what did not. This means looking beyond where in the country the institute will sit and how many researchers it will employ. The real measure of DE-AISI will be whether anyone acts on the problems it uncovers.
Support Tech Policy Press
If you’ve found our work helpful, consider supporting us.
Donate
Authors
Martin WählischMartin Wählisch is an Associate Professor of International Relations at the University of Birmingham and a member of its Centre for AI in Government. His research focuses on AI governance and international cooperation.
