Germany Establishes an AI Security Institute
I. Introduction: Virtual beginnings and open questions1
This June, Germany formally decided to establish a German AI Security Institute (DE-AISI).2 The decision was adopted by the National Security Council on 8 June 2026 and implements Germany’s commitment under the 2024 Seoul Declaration’s Statement of Intent3 to support the development of AI Safety and Security Institutes and to nurture networks between them. It reflects a shift in German AI governance towards strengthening governmental capacity to understand the capabilities, limitations, and security implications of frontier AI models.4 According to the Government, the DE-AISI will provide scientific and technical expertise and support strategic risk assessment.5
The initiative draws inspiration from the UK AI Security Institute, which is regarded as a paragon for government-backed scientific evaluation of frontier AI models.6 Subsequent joint statements with the United Kingdom and France indicate that the DE-AISI is intended to become part of the growing international network of AI Safety and Security Institutes.7 Government statements also emphasise that the DE-AISI is intended to complement rather than duplicate the governance framework established under the EU AI Act.8 In particular, it is expected to support scientific cooperation and frontier AI evaluation while remaining institutionally distinct from both the AI Office and the national market surveillance authorities responsible for enforcing the EU AI Act as set out under Germany’s AI Market Surveillance and Innovation Promotion Act (KI-MIG).9
Although a comprehensive legislative framework has yet to be presented, the German Federal Government has indicated that the DE-AISI will initially operate as a virtual institution anchored in a ‘nucleus’ drawing on existing capacities at the Federal Office for Information Security (BSI) and the Federal Network Agency (Bundesnetzagentur, BNetzA). In this initial build-up phase, the focus will be on security and safety aspects of advanced AI models.10 As of early August 2026, a spokesperson of the Federal Ministry for Digital Affairs and State Modernisation (BMDS) confirmed that this nucleus is already operational, describing a step-by-step, modular build-up approach and noting that technical exchange with international partner institutions, including in France, the United Kingdom, and with the AI Office, is already under way.11 Recent comments by Federal Government officials hint at a broader scope of the mandate but do not specify the envisioned breadth.12
For the long-term structure of the DE-AISI, current policy proposals advocate for an institution that has a narrowly defined technical and scientific mandate, organisational independence, and close integration into Germany’s national security architecture, rather than being a new regulatory authority.13 Several open questions remain, including the exact scope of the DE-AISI’s mandate, its financial flexibilities, and its location. This report outlines and comments on each, highlighting the possibility of establishing the DE-AISI as a federally owned limited liability company (GmbH).
II. An AISI with an unsettled scope
The most consequential open question concerns the material scope of the DE-AISI’s mandate. The National Security Council’s decision seems to refer mainly to assessing the consequences of advanced AI models for cybersecurity in Germany.14 The nucleus, in turn, is to cover both ‘security’ (BSI) and ‘safety’ (BNetzA) aspects of such models.15 Parliamentary State Secretary Jarzombek has since indicated a build-up towards an institution positioned more broadly, both thematically and in terms of capacity.16 A broader design had also been proposed by a group of researchers in October 2025.17 In comparison, the Seoul Statement of Intent frames the role of such institutes more narrowly as facilitating ‘AI safety research, testing, and/or developing guidance to advance AI safety for commercially and publicly available AI systems’.18
In a different sense, the German policy debate seems to be converging on a narrow, purely scientific and technical mandate aimed at enabling the Federal Government to reach informed decisions on frontier AI model risks. Interest groups argue that the DE-AISI should be clearly distinct from regulatory authorities such as the BNetzA and the BSI to enable trust-based cooperation with frontier AI model developers.19 These proposals envision that the DE-AISI would produce recurring cross-departmental situational assessments for the Federal Government, conduct systematic technical evaluations of frontier AI models, carry out research in service of those tasks, contribute to the development of technical standards, and cooperate with partner institutions nationally and internationally.20 Its focus would extend beyond cybersecurity to chemical, biological, radiological, and nuclear (CBRN) risks and to loss-of-control (LoC) risks,21 comparable to the focus of the UK AISI.22 Another question concerns which models precisely the DE-AISI should observe and evaluate. Arguably, a national security-focused institute should not confine itself to general-purpose AI (GPAI) models with systemic risk within the meaning of the EU AI Act,23 but should also capture more specialised models capable of generating comparable risks: genome language models used to design novel pathogens could be one example.24 The definition should remain technology-neutral, so that the institute’s remit is not restricted only to proprietary models or tied to today’s model architectures. At the same time, defining the frontier of AI capabilities is not straightforward and a functionally wide interpretation of frontier AI could overextend the focus of the DE-AISI.25
Persistent uncertainty about the material scope of the DE-AISI’s mandate will come at a cost. Developers deciding whether to grant pre-deployment access to unreleased models need to know whether they are dealing with a scientific partner or with an institution whose remit may later expand into adjacent, potentially regulatory territory. Industry associations have therefore called for a research mandate clearly delineated from that of existing bodies, arguing that questions of labour law, consumer protection, data protection, and AI ethics are already competently addressed elsewhere.26
After all, the preliminary nucleus arrangement may come to sit uneasily with the institute’s intended function. The BNetzA recently became Germany’s central node of the AI Act’s national-level enforcement architecture,27 and the BSI holds its own enforcement powers in the field of information security.28 An institute housed within or governed by authorities exercising such powers may struggle to obtain the confidential access on which its work depends. For instance, GPAI model providers may worry about the fact that the BNetzA could hypothetically use information voluntarily shared with the DE-AISI to request the European Commission to initiate enforcement actions where the BNetzA believes that this information indicates a breach of the provider’s obligations under Chapter V of the AI Act.29 Closing precisely this kind of access gap is among the institute’s purposes and of outsized importance to national security. Whatever its institutional setup ends up being, it may therefore be advisable to ensure a sufficiently clear delineation between the DE-AISI and regulatory powers. This may mean limiting the cooperation between the DE-AISI and the BSI and the BNetzA to general, non-developer-specific findings on frontier AI risks, rather than confidential information capable of being used for regulatory purposes. In this respect, it is promising that the BSI has reportedly indicated that the DE-AISI will not focus on regulatory aspects.30
III. Pay, flexibility, and the case for a GmbH
Germany’s Federal Digital Minister has stated that the DE-AISI should be staffed with ‘top expertise from world class experts'31. Delivering on that ambition will be difficult within ordinary German public-sector pay structures, which are considerably lower than frontier AI expert salaries in the private sector or even the international non-profit sector. This applies all the more given the fact that private-sector compensation for AI talent has risen sharply; an industry salary survey records a 45 per cent increase for AI safety and alignment specialists since 2023.32 The UK AISI has recognised these dynamics. It operates not only with GBP 66 million in annual funding and priority access to compute, but also with a more competitive salary structure than the rest of the civil service.33 Proposals in the German debate have mostly suggested a funding similar to that of the UK institute ranging from EUR 60 million34 to at least EUR 75 million annually.35
However, funding levels alone do not determine whether these resources can be deployed effectively. Choosing a legal form that allows the DE-AISI to effectively deploy funding will be equally crucial. Establishing the institute as a federally owned limited liability company (GmbH) would be a promising option in this regard. It would constitute a formal privatisation (formelle Privatisierung), leaving the operational task itself in state hands while changing only the organisational vehicle through which it is performed.36 A reference point for formal privatisation of this kind is the Federal Agency for Disruptive Innovation (Bundesagentur für Sprunginnovationen, SPRIND).37 SPRIND is a wholly federally owned GmbH created to fund high-risk innovation projects and governed by its own enabling statute, the SPRIND Act (SPRIND-Freiheitsgesetz38) of 2023.39 It was designed for a field in which recruitment and funding decisions must be taken quickly and in competition with the private sector. In several ways, the DE-AISI faces a comparable situation, necessitating a legal form that allows it to meet similar key challenges.
One particular challenge is the DE-AISI’s staffing. As a company under private law, the institute would not be bound by public-sector collective agreements in the same way as a federal authority. It could seek exemptions from the prohibition on preferential treatment (Besserstellungsverbot), which otherwise prevents federally funded bodies from paying their staff more than comparable federal employees. § 5 of the SPRIND Act transfers that decision to the company itself where compelling reasons so require, based on the legislature’s reasoning that contract negotiations in highly competitive fields must be conducted quickly and concluded with binding effect. Bitkom, one of Germany’s largest digital industry associations, has argued for a comparable arrangement for the DE-AISI.40
As for budgetary flexibility, the frontier AI risk landscape develops on timelines that do not align with annual budget tranches. Evaluation and research priorities in this field can shift within months, if not weeks. § 15(2) of the Federal Budget Code (Bundeshaushaltsordnung) permits appropriations to be designated for self-administration (Selbstbewirtschaftung), allowing funds to be carried across financial years and redeployed as project needs change. § 3(2) of the SPRIND Act makes use of this instrument, albeit at a limited rate. The same instrument has been extended to non-university research institutions to strengthen their performance and international competitiveness,41 which suggests its relevance for a body operating in a field that is at once fast-moving and research-based, such as the DE-AISI.
Regarding governance, the articles of association (Gesellschaftsvertrag) would allow the Federal Government’s specific requirements to be reflected in tailored form,42 while limited liability caps the exposure of the federal budget.43 Democratic accountability can be maintained through the instruments of company law. The Federal Government, as sole shareholder, would appoint the executive director, could issue instructions, and would hold comprehensive information rights.44 Furthermore, the GmbH structure allows for a high degree of organisational and personnel flexibility.45
None of this follows necessarily from the choice of the GmbH as the legal form as such. As in the case of SPRIND, it depends on the enabling legislation providing for it;46 in particular, on exemptions from the prohibition on preferential treatment and on the self-administration rate adopted, as well as on the articles of association. Whether comparable arrangements could be achieved within a public law structure remains an open question. For its part, the Federal Government has stated that it is not yet in a position to provide details on the institute’s long-term legal structure.47
IV. A location fit for purpose
A decision on the location of the DE-AISI was initially deferred by the Federal Government. A few options are now under active consideration, including Berlin, the Saarland, Bonn, and Munich.48
The Saarland has already advocated for hosting the DE-AISI. In August 2026, the CDU group in the Saarland state parliament — in opposition at state level, but the party of the Chancellor and, with its sister party the CSU, of the ministries leading on the DE-AISI — formally called for the institute to be based in Saarbrücken. Stephan Toscani, chair of the group, described the Saarland as ‘the ideal location’ and warned that the opportunity to base the DE-AISI in it must not be allowed to pass.49 Saarbrücken hosts Saarland University, the German Research Center for Artificial Intelligence (DFKI), the CISPA Helmholtz Center for Information Security, and two Max Planck Institutes.50 It also hosts branch offices of both the BSI and the BNetzA, the two authorities on which the nucleus is drawing.51 Bonn, on the other hand, would place the DE-AISI at the same location as the BSI headquarters.52
Berlin, however, offers proximity to the federal ministries and the National Security Council. Alongside Munich, it hosts one of Germany’s largest AI industry clusters.53 It also hosts a branch of the DFKI. As a metropolis and capital city, it may prove easier to recruit for than other alternatives. Finally, if the DE-AISI’s defining task will be advising the Federal Government on frontier AI risks, its work will consist largely of recurring cross-departmental situational assessments, ad hoc analysis when risks shift at short notice, and exchanges that might involve classified material. In this respect, proximity to the ministries carries particular weight, as the UK-AISI’s location in London demonstrates. The relocation of the Federal Intelligence Service (BND) from Pullach to Berlin was completed on similar grounds, given the need for swift communication and intensive coordination between the BND and federal government bodies.54
Regional policy considerations may pull in the opposite direction. Germany has a long-standing practice of distributing federal institutions across the country, and the Saarland bid is expressly framed as part of that state’s structural transition towards a technology location.55 These are legitimate objectives in their own right, but they are distinct from the question of where the institute can most effectively perform its advisory function. Insofar as the above considerations of proximity to the Federal Government and talent recruitment are crucial factors, they point towards Berlin.
V. Conclusion: What Germany stands to gain, or forgo
The establishment of the DE-AISI is an important opportunity for Germany to contribute to the safety and security of frontier AI models as their risks for national security and critical infrastructure become increasingly central. Existing institutes provide case studies for success factors and possible failure modes. For example, the UK AI Security Institute has benefited from financial flexibility in hiring, compute access, an attractive location, and a scientific mandate clearly distinct from regulatory functions. Drawing on these experiences, the DE-AISI can make vital contributions to national security by assessing frontier AI risks specifically in line with the mandate of the German National Security Council.
Such a role can only be fulfilled at the national level. National security remains a competence of the Member States, the AI Office’s remit is directed at the Union market as a whole, and the AI Act’s systemic risk threshold is defined by reference to effects at Union level rather than to the exposure of any single Member State.56
Without these capacities, Germany’s ability to anticipate and respond to frontier AI risks remains dependent on what partner institutions abroad are willing to share. Timely progress will therefore be essential. For two years after endorsing the Seoul Statement of Intent in 2024, Germany has been one of only a few signatories without an AI Security institute of its own.57
This position is recoverable, though only if the institute is equipped with the mandate, structure, and location which the task requires. A GmbH structure could afford the needed financial and personnel flexibilities, subject to enabling legislation that clearly defines the institute’s mandate and relation to other governmental bodies. Berlin would offer an attractive location and ensure proximity to the Federal Government for the DE-AISI’s advisory work.
If these steps are taken, the DE-AISI can move to the forefront of international AI safety and security institutions, and anchor Germany’s preparedness for frontier AI risks.