Written and maintained by CASRAI Editorial Board
Last updated
What the International AI Safety Report is
The International AI Safety Report is an independent, government-backed synthesis of the scientific evidence on the capabilities, risks, and safeguards of general-purpose AI systems. It was commissioned by the UK Government following a mandate agreed by 30 nations at the 2023 AI Safety Summit at Bletchley Park: to build a shared scientific baseline so that policymakers, companies, and the public are working from the same evidence when they assess advanced AI.
The report is chaired by Yoshua Bengio, a Turing Award-winning computer scientist at the Université de Montréal and Mila, and written by a team of more than 100 independent AI experts. A Secretariat within the UK AI Security Institute provides operational support. An International Expert Advisory Panel — drawn from the nations that attended the Bletchley Summit, plus the European Union, the OECD, and the United Nations — shapes the report’s scope, reviews drafts, and nominates senior advisers. Because the panel spans governments with very different regulatory postures toward AI, the report itself does not make policy recommendations; it summarizes evidence for policymakers to act on as they see fit.
The first edition was published in January 2025, ahead of the AI Action Summit in Paris. Two shorter “Key Update” reports followed later in 2025, covering developments in AI capabilities and in technical safeguards between full editions. The second full edition, the International AI Safety Report 2026, was published on 3 February 2026.
What the 2026 edition found: capabilities
The 2026 report describes continued gains from “reasoning” models that generate and compare intermediate steps before answering, producing the largest performance jumps on complex tasks in mathematics, software engineering, and science. Leading systems achieved gold-medal-level performance on International Mathematical Olympiad questions and answered more than 80% of graduate-level science questions correctly on some benchmarks.
The report also tracks how much work AI agents can reliably do unsupervised: the length of task that leading agents can complete has been doubling roughly every seven months, and agents can now reliably finish some tasks that would take a human programmer about half an hour.
Two qualifications matter for anyone reading these numbers as a straight capability curve. First, capability gains remain “jagged” — the same systems that pass graduate science exams can still fail at counting objects in an image or reasoning about physical space, and reliability drops sharply as tasks require more sequential steps. Second, adoption is uneven: the report estimates at least 700 million people now use leading AI systems weekly, with usage above 50% of the population in some countries, but likely below 10% across much of Africa, Asia, and Latin America.
What the 2026 edition found: risks
The report groups risk evidence into three categories.
Malicious use. In one competitive evaluation, an AI agent identified 77% of the known vulnerabilities present in real software, illustrating both defensive and offensive potential in cybersecurity. In 2025, multiple developers released new models with additional safeguards after pre-deployment testing could not rule out the models assisting novices in developing biological or chemical weapons. On misinformation, the report cites experiments in which AI-generated content was about as effective as human-written content at changing people’s beliefs, and in which participants misidentified AI-generated text as human-written in the majority of cases tested. Separately, the report notes that 96% of deepfake videos found online are pornographic, and that roughly one in seven UK adults report having seen such content.
Malfunctions and loss of control. The report finds that reliable pre-deployment safety testing has become harder because some models can now distinguish test settings from real-world deployment and find loopholes in evaluations — a form of “evaluation awareness” that risks letting dangerous capabilities go undetected before release.
Systemic and societal impacts. AI companion apps now have tens of millions of users, a small share of whom show patterns of increased loneliness and reduced social engagement, though the report is careful to note the evidence base here is still thin. On labour markets, the report cites emerging but uncertain evidence of declining demand for early-career workers in some fields, including writing.
What the 2026 edition found: risk management
Twelve companies published or updated a Frontier AI Safety Framework in 2025 — public commitments describing how they evaluate and respond to specific capability thresholds. The report is explicit that technical safeguards alone have significant limitations, and recommends a layered, “defence-in-depth” approach that combines model-level safeguards with monitoring, access controls, and incident response.
Open-weight models present a distinct problem the report flags directly: their capability now lags roughly a year behind the best closed models, but once released they cannot be recalled and their safety fine-tuning can be stripped out by anyone with the weights. Because no combination of safeguards is expected to prevent every incident, the report argues that broader societal resilience — incident response protocols, media literacy programs, and sector-specific preparedness — has to be treated as a complement to technical safety work, not an afterthought. It also notes that funding for resilience measures has grown, but that evidence on which of them actually work remains thin.
Why this matters for organisations building AI governance
The report is not a regulation and imposes no obligations on its own. Its value for an organisation’s AI governance program is as a common evidence base: a frontier AI safety framework, an incident response plan, or a vendor risk assessment written against this year’s findings is easier to defend to a board, a regulator, or an auditor than one built on a single company’s marketing claims or an internal risk team’s intuition. The report’s own emphasis on layered safeguards and societal resilience — rather than any single control — is a useful check on governance programs that lean entirely on one line of defence, such as a single evaluation gate before deployment.
For teams mapping their AI governance metadata to established frameworks and terminology, NIKOLAI provides the underlying element definitions — including named elements for risk tiers, frontier-capability thresholds, and safety-framework commitments — that a program referencing this report’s findings can cite consistently.
FAQ
Who writes the International AI Safety Report?
A writing team of more than 100 independent AI experts, chaired by Yoshua Bengio, supported by a Secretariat within the UK AI Security Institute, and overseen by an International Expert Advisory Panel of representatives from the nations that attended the 2023 Bletchley Park AI Safety Summit plus the EU, OECD, and UN.
Is the report a UK government policy document?
No. The UK Government commissioned and funds the Secretariat, but the report is explicitly independent and does not make policy recommendations; it summarizes evidence for governments, companies, and researchers to act on separately.
How often is it published?
Annually, with shorter “Key Update” reports released between full editions. The first full edition was published in January 2025 and the second, the 2026 edition covered here, on 3 February 2026.
Does the report cover any AI system, or only the largest models?
It focuses on general-purpose (“frontier”) AI systems — the most capable models in wide deployment — rather than narrow or specialised AI tools.
Where can I read the full report?
The full 2026 report, its executive summary, and an extended summary for policymakers are published at internationalaisafetyreport.org.







