What I learnt co-leading an AI Safety bootcamp for authorized and governance practitioners — LessWrong

AI security has gone mainstream. More individuals than ever wish to work on AI security analysis, and there are actual coverage wins within the US, the UK and Europe.
But political will and market incentives are actually the bottleneck, and coverage officers cannot personal appropriate implementation alone.
Having constructed a Responsible AI program at an Accenture three way partnership, I do know profit-driven corporations are arduous to steer, but additionally that folks inside them can shift follow in ways in which compound: tighter contractual clauses, extra scrutiny of distributors and suppliers, fewer methods for suppliers to get away with non-compliance.
The EU has no native frontier labs, however it’s a big market (with a regulatory physique that has an AI safety unit!),
That leverage solely works if the professionals implementing AI security laws, and drafting the authorized mechanisms behind it, perceive the technical image: the right way to learn the analysis, and the place security guarantees break down.
The market must be selecting not essentially the most succesful fashions, however the companions with the strongest incentives in direction of security, and solely a neighborhood with this data can unfold that.
Earlier in September, ML4Good, in partnership with EquiStamp, ran the primary European Seminar on Frontier AI and Law: an intensive five-day residential bootcamp in East Sussex for 19 senior authorized, governance and danger professionals from 12 jurisdictions. [1]
It took members by way of the complete frontier AI pipeline, from coaching and evaluations to brokers and safeguards. Each stage was tied to the questions they face in their very own work: procurement, danger evaluation, and the place distributors’ security claims break down.
What made this bootcamp completely different from probably from comparable AI security fellowships, was the viewers we introduced collectively [2] . We had been particularly focusing on skilled professionals who’re already answerable for authorized, compliance, danger, and accountable AI capabilities inside their organisations, and with little to no earlier publicity to AI Safety occasions or EA.
The cohort included legal professionals working each in regulation corporations and in-house, privateness and compliance professionals engaged on AI governance, danger and monetary professionals advising on AI governance, in addition to authorized students and analysis fellows. We additionally had illustration from the judiciary and the general public sector.
For context, I co-led this primary version with Elsa Donnat, and designed the curriculum’s sensible workouts monitor. The technical classes had been delivered by Douw Marx and Jeff Iuliano, who had the very difficult process of adopting fairly advanced technical ideas to a non-technical and largely authorized viewers!
This publish shares the principle private {and professional} realisations I had within the course of resulting in it, through the occasion, and attributable to post-bootcamp conversations.
Some of the “caught in motion” moments, and the networking occurring across the technical classes!
People with massive job titles at massive corporations could be surprisingly remoted in the case of the issues they care about.
I skilled this firsthand after I was one of many solely individuals in my skilled atmosphere pondering severely about questions like: What makes AI secure? What are the results of deploying a number of various kinds of AI programs, for very completely different use circumstances, throughout a big firm? What does that imply for society, for the market, or for the sector as an entire?
To somebody studying this, these might sound like very primary inquiries to have. But when your precise job is accountable AI, AI compliance, regulation, or danger, having these issues can typically be perceived as distracting from the duty at hand. And even when they aren’t, you might merely not have the time or the area to have significant conversations about what worries you, what pursuits you, or what you assume would possibly occur subsequent.
When we introduced collectively a gaggle of very senior practitioners, every coping with their very own challenges in skilled contexts, they may not get sufficient of one another.
The neighborhood aspect ended up being one of many greatest belongings of the programme: the friendships, the connections, and the conversations that continued lengthy after the formal classes ended.
That ought to maybe not have stunned me. But it gave the programme a number of its that means.
As is custom in ML4Good bootcamps, we had sugar cubes: envelopes with everybody’s names, the place members might go away Post-its with one thing optimistic for the individual named on the envelope.
One of essentially the most senior / influential members within the cohort left a observe for me. It stated, basically:
“Thank you for this. I’ve discovered my individuals.”
That actually moved me.
Many researchers right here already know this sense. What could also be much less apparent is that folks on the opposite facet of the equation, the individuals overseeing vendor clauses, negotiating contracts, approving deployments, and governing these programs, can expertise one thing remarkably comparable once they share these issues.
One of our classes on evaluations and safeguards centered partly on the Hugging Face incident. It took for much longer than anticipated as a result of everybody had so many questions.
And the most effective factor about these questions was that folks weren’t in search of validation of what they already believed. They got here with the humility of figuring out that they weren’t consultants. They had entry to individuals who had been consultants, and so they wished to grasp.
On different classes, members referenced the unique AI Control paper from Redwood Research, the Golden Gate Claude work, and different items of AI security analysis that had landed on their desks or that they’d encountered independently.
Sometimes correcting a quite simple misunderstanding results in two issues without delay: extra curiosity about persevering with to study, and a a lot larger appreciation of why a few of these issues matter.
What truly occurs to a mannequin throughout inference?
No, ChatGPT is just not merely recording all the pieces you say and “studying” from it through the dialog.
No, the factor you see when Claude seems to be pondering is just not the mannequin’s precise chain of thought.
Those little moments of “Oh, I assumed it labored otherwise” had been a few of my favorite components of the programme.
And actually, it felt as if we might have spent one other complete day simply answering questions.
Which results in my subsequent statement.
If you’re product counsel at an organization constructing AI programs, your job is just not merely to be sure that nothing unlawful occurs, or that the phrases and circumstances are drafted appropriately.
You are going to be held accountable when one thing goes mistaken.
And you aren’t essentially going to obtain the identical stage of willingness from technical groups to clarify what a challenge is doing, or how the underlying know-how works, as you’ll obtain criticism in the event you miss one thing vital.
That is comprehensible. It is our job to know what we’re doing, and we should always not count on fixed hand-holding.
But it additionally signifies that if you lastly have a chance to ask all of the technical questions you may have amassed, you’ll take it.
You will ask in regards to the variations between proprietary and open-weight fashions. You will ask how capabilities differ between fashions. You will ask how completely different phases of post-training have an effect on each security and efficiency. You will ask what evaluations truly let you know. You will ask what they don’t let you know.
And it’ll most likely nonetheless really feel prefer it was not sufficient.
There was, after all, some choice bias right here. We chosen for character as a lot as expertise. We wished a cohort of people that had been keen to study, who had been humble sufficient to recognise what they didn’t know, and who genuinely cared about AI going properly.
But it was nonetheless exceptional to see how a lot individuals wished to grasp as soon as they’d the chance.
AI security researchers and engineers deliver capabilities to the desk that different skilled profiles merely do not need.
If you labored as a product developer or software program engineer and are actually doing AI security analysis, you might perceive each side of the equation. You perceive fashions, security coaching, evaluations, and the logic utilized to fashions. But you additionally perceive merchandise, purposes, and what truly occurs when a mannequin is built-in into an actual system.
You might perceive risk modelling.
But importantly, you may apply it in each instructions.
Security professionals typically ask: How might a 3rd get together or exterior dangerous actor hurt this method, and the way will we cease them?
AI security asks a complementary query: How might the system itself hurt individuals? What is the worst-case situation? How might what we’re constructing have an effect on shoppers, customers, or society? And what mechanisms do we have to forestall that?
To play on stereotypes, legal professionals care about lawsuits.
We are risk modellers of types. We ask: How might this resolution result in a dispute, regulatory motion, shopper safety declare, or different authorized consequence? What can we do to stop that?
But when you find yourself a accountable AI, GRC, danger, or authorized skilled working in a technical firm, lots of your authorized issues in the end require technical options.
That is why individuals in these positions are so keen to construct technical literacy themselves.
We have to know what we’re in search of.
In AI security, we are likely to concentrate on the handful of frontier AI corporations that matter most to the event of the know-how.
That is smart. But there’s a entire planet outdoors these corporations: traders, enterprise clients, shoppers, customers (information topics) companions, and organisations seeking to embed AI into their workflows and make these workflows more and more agentic.
Somehow, AI security discussions can stay closely centered on altering what the large labs are doing, with out paying fairly as a lot consideration to the ecosystem creating the incentives round them.
Even the frontier labs are topic to market incentives created by everybody else.
When we take into consideration the income of AI labs, we would take into consideration subscriptions, enterprise contracts, or funding rounds. But the market sign behind these investments can also be being generated by hundreds of corporations integrating these programs into more and more vital workflows.
An enterprise buyer paying, say, $500,000 for an AI coding product is just not creating huge worth (if any) for a frontier lab. But if hundreds of mature corporations are doing one thing comparable, throughout industries, and people programs have gotten business-critical dependencies, the mixture sign may be very completely different.
It alerts that their fashions not solely matter, they’re all over the place. Organisations have crucial dependencies on them. Maybe whoever controls them sits beneath an more and more vital layer of the marketplace.
And who understands that dependency significantly properly?
The legal professionals, governance professionals, danger and compliance groups, and accountable AI professionals sitting inside these corporations.
This is why lots of them have already got that annoying voice at the back of their heads saying:
Something about that is heading in a harmful course, and I believe I’m enjoying a task in it, however I’m not totally certain what that function is.
This is why it issues that AI security data will get outdoors the prevailing bubble.
I massively respect the work of organisations similar to ML4Good, BlueDot Impact, Lens Academy or particular person creators like Robert Miles in making AI security ideas extra accessible to wider audiences.
What I’m making an attempt to do is considerably narrower.
I wish to attain the skilled communities I do know finest: the people who find themselves already sitting inside corporations making choices about AI, however who might by no means have had the chance to correctly perceive the technical dangers related to these choices.
Even if market incentives usually are not what in the end decide whether or not superior AI is secure, I believe they’re related. And the individuals sitting closest to these incentives want to grasp what they’re collaborating in.
In the ultimate session, members had been requested to consider how they’d apply what they’d realized to their capabilities, their departments, and their wider communities.
People talked about disseminating the coaching inside their very own groups. They thought-about making use of for AI security fellowships. They mentioned forming native communities and teams to remain on prime of latest safety-relevant analysis and take into consideration the way it might inform authorized follow.
They wished to community extra with coverage professionals who may gain advantage from insights about how insurance policies truly break down in follow.
I’m all the time a bit pessimistic on the hole between “oh cool, they wish to do stuff” and “hey, look, they’re doing stuff!”.
And then issues began occurring.
Two days after leaving the programme, a senior regulation agency associate rejected an organization’s safeguards claims for one among their purchasers and requested for baseline security necessities.
Another participant started asking for data with stakeholders related to their operate, scrutinising their use of AI brokers in mild of current developments round agent containment and management.
Others started actively recruiting individuals with AI security abilities and pursuits into their groups.
Others reached out in connection to imminent conferences, asking for AI Safety illustration amongst audio system. [3]
These issues occurred inside a really brief interval after the programme ended.
That was maybe one of the encouraging issues I noticed. People didn’t go away pondering, “That was fascinating.” They left pondering, “I can do one thing with this.”
Finally, and on a extra private observe: One of my favourite moments was when one among our ML4Good coordinators introduced this occasion house by stating one thing I had maybe forgotten:
“Turns out that legal professionals are additionally nerds!”
Some of us take notes by hand, go on rants about very particular issues once they’re passionate in regards to the matter, and might have extremely particular and quirky pursuits.
We get a really “caught up” rep, and infrequently deservingly so. But extremely senior profiles can have surprisingly robust character similarities with individuals in STEM.
Yes, legal professionals typically like networking and people-facing work. But you may also put a room full of individuals with spectacular titles, in depth authorized expertise, and demanding jobs collectively, give them a technical or philosophical query, and watch them utterly nerd out.
That was one of the enjoyable issues about this programme.
And it has made one thing very clear to me.
Building a neighborhood for individuals who wish to advance AI security is vital.
And I wish to construct it particularly for people who find themselves sitting within the positions I as soon as occupied: legal professionals, governance professionals, danger professionals, compliance professionals, and accountable AI practitioners who’re shut sufficient to the know-how to see the stakes, however who might not but have a neighborhood round them that shares their pursuits.
I hope this can lead not solely to higher practices and requirements, but additionally to new organisations, new collaborations, and a unique set of execs coming into the AI security neighborhood,
Thanking Elsa Donnat for main this system and making this shared imaginative and prescient a actuality.
Jack Stennett, Linda Broglio and Nia Gardner from ML4Good for carrying the operational and logistical organisation- NOTHING would have occurred with out you.
Douw Marx and Jeff Iuliano for the supply of the technical classes, and the unimaginable work they did to condense a lot content material, into an audience-specific format.
Honor Chan, Chris Canal and Daniel O’Connell at EquiStamp for supporting this program with work, assets, and technical experience.
- ^
I co-led this initiative with ML4Good from late 2025, earlier than becoming a member of EquiStamp, and continued by way of EquiStamp’s partnership. I’m posting in a private capability.
- ^
Just a few months in the past, I got here throughout a post by Jenn about rationalists versus professionals’ dynamics. I discovered the excellence significantly insightful, particularly the dialogue of the method of acculturation. I assumed this publish might deliver complementary perception!
- ^
I’m selecting to not allocate every declare to particular members as a result of I would like that they both publish right here straight if they need. I also can reply personal enquiries with their consent.
