Markus Anderljung
  • Home
  • Research
  • Blog
  • Talks & Podcasts
  • AI calibration game
  • Music

What can middle powers do for frontier AI governance?

6/7/2026

 

Written by:
 Markus Anderljung and Stephen Clare


Sometimes people round the influence of countries other than the US and China on the AI trajectory down to zero. The most capable models are built by a handful of American companies; China is the only serious challenger; and the US government is increasingly interested in controlling who – including which states – can access frontier systems. It looks like everyone else will have to be content watching from the sidelines.

That seems like a mistake. In this piece, we give the other side of the argument, offering reasons why states other than China and the US can play important roles. The “middle AI powers” – countries which have strong political institutions and economic power, but lack frontier AI companies – have already shaped frontier AI development, and in fact could do more to shape the AI trajectory than they currently are.

These AI middle powers are, roughly, the G20 (minus the US and China), and a few AI-specific players like Taiwan, the Netherlands, Norway, and the UAE.

Read More

Environment-Based Safeguards for AI Cyber Risk

21/5/2026

 
Safeguards for cyber risk on proprietary frontier AI (e.g. from Anthropic, OpenAI, Google DeepMind) currently focus on two questions: what the model is being asked to do – the type of task, the user’s intent – and who is asking – the identity behind the account. 

This post proposes adding a third question: where the model is operating. If a model’s context shows it is interacting with the control systems of a power grid, the trading infrastructure of a major bank, the internal network of a defense contractor, or, plausibly, the internal systems of an AI company itself, you might want to apply safeguards unless the user is authorized to be there. If the user isn’t authorized the AI provider could notify the owner of the software environment, downgrade to a less capable model, or have the model outright refuse the task.

I’m not sure this can be made to work; I’d love cybersecurity and cryptography folks to look into it. The two key questions are: 
  • Can identifiers be built that an AI system reliably encounters during normal operation in a sensitive environment, but that a sophisticated adversary cannot reliably remove? 
  • Are there safeguards subtle enough that adversaries won't bother looking for the identifier – even though they could find it if they did?​​

Read More

The Case for Outsourcing Frontier AI Safeguards

30/3/2026

 
Frontier AI companies don’t grow their own coffee beans. Like every other company, they make constant decisions about what to do in-house and what to buy from someone else. They already outsource significant AI-related work. Surge AI generated $1.2 billion in revenue in 2024, almost entirely from selling data labelling and RLHF services to most frontier labs. METR, Apollo Research, and the UK AI Security Institute run evaluations that now feature prominently in frontier model system cards.

I think this pattern will and should extend further – to safeguards: technical measures that reduce risks from AI systems, such as content classifiers, jailbreak detectors, monitoring tools, and know-your-customer checks. This would be both in AI companies’ interest and good for the world. 

Concretely, I think: 
  • If you’re currently working on safeguards inside a frontier AI company, you should seriously consider whether you’d have more impact offering that service as a third party to the whole industry. 
  • Funders should support a thriving safeguards market by providing organisations with startup capital and, where needed, longer-term funding that allows them to prioritise pro-social outcomes over purely commercial incentives.
  • Evaluation organisations should consider expanding into safeguard development; they likely have a lot of the necessary skills. 
  • Frontier AI companies should work more closely with third-party safeguard developers – sending clear demand signals and working closely enough with them to enable rapid iteration, including sharing data on safeguard performance. ​

Read More
<<Previous
  • Home
  • Research
  • Blog
  • Talks & Podcasts
  • AI calibration game
  • Music