Report | 
August 2026

Germany Establishes an AI Safety and Security Institute

Maximilian Pralle, Tarmio Frei, Oskar Wernitz, Hannes Bastians, Christoph Winter

This piece is forthcoming in the Journal of AI Law and Regulation.

I. Introduction: Virtual beginnings and open questions1

On 8 June 2026, Germany formally decided to establish a German AI Safety and Security Institute (DE-AISI).2 The decision was adopted by the National Security Council and implements Germany’s commitment under the 2024 Seoul Declaration’s Statement of Intent3 to support the development of AI Safety and Security Institutes and to nurture networks between them. It reflects a shift in German AI governance towards strengthening governmental capacity to understand the capabilities, limitations, and security implications of frontier AI models.4 According to the Government, the DE-AISI will provide scientific and technical expertise and support strategic risk assessment.5

The initiative draws inspiration from institutions like the UK AI Security Institute, which is regarded as a prominent example of government-backed scientific evaluation of frontier AI models.6 Joint statements with the United Kingdom and France indicate that the DE-AISI is intended to become part of the growing international network of AI Safety and Security Institutes.7 Government statements also emphasise that the DE-AISI is intended to complement rather than duplicate the governance framework established under the EU AI Act.8 In particular, it is expected to support scientific cooperation and frontier AI evaluation with a purely non-regulatory mandate distinct from the enforcement functions of the AI Office and the national market surveillance authorities designated under Germany’s AI Market Surveillance and Innovation Promotion Act (KI-MIG).9

Although the permanent legal structure has yet to be settled, the German Federal Government has indicated that the DE-AISI will initially operate as a virtual institution anchored in a ‘nucleus’ drawing on existing capacities at the Federal Office for Information Security (BSI – the cybersecurity regulator) and the Federal Network Agency (Bundesnetzagentur, BNetzA).10 In this initial build-up phase, the focus will be on security and safety aspects of advanced AI models.11 In early August 2026, a spokesperson for the Federal Ministry for Digital Affairs and State Modernisation (BMDS) reportedly confirmed that this nucleus was already operational, describing a step-by-step, modular build-up approach and noting that exchanges with international partner institutions, including counterparts in France and the United Kingdom, and with the AI Office were already under way; the formal announcement of the establishment of the DE-AISI followed on 31 August 2026.12 The subsequent official announcement envisages a broader scope for the long-term mandate but does not fully specify its boundaries.13

For the long-term structure of the DE-AISI, current policy proposals advocate for an institution with a narrowly defined technical and scientific mandate, organisational independence, and close integration into Germany’s national security architecture, rather than a new regulatory authority.14 Several open questions remain, including the exact scope of the DE-AISI’s mandate, its financial flexibilities, and its long-term location. This report outlines and comments on each, highlighting the possibility of establishing the DE-AISI as a federally owned limited liability company (GmbH).

II. An AISI with an unsettled scope

The most consequential open question concerns the material scope of the DE-AISI’s mandate. The National Security Council’s decision seems to refer mainly to assessing the cybersecurity-related challenges of advanced AI models for Germany.15 The nucleus, in turn, is to cover both ‘security’ (BSI) and ‘safety’ (BNetzA) aspects of such models.16 Parliamentary State Secretary Jarzombek has since indicated a build-up towards an institution positioned more broadly, both thematically and in terms of capacity.17 The BMDS has confirmed this trajectory, announcing that the DE-AISI will be expanded thematically and in terms of capacity in a second phase.18 The announcement indicates a broader remit in two further respects. First, the institute is to evaluate not only the risks that advanced AI models present for Germany, but also the opportunities they bring, and to strengthen German resilience in the field of artificial intelligence.19 Second, the DE-AISI is envisaged to engage beyond the Federal Government and the administration, ensuring a structured transfer of security-relevant findings to business and civil society.20 A broader design had also been proposed by a group of researchers in October 2025.21 In comparison, the Seoul Statement of Intent frames the role of such institutes more narrowly as facilitating ‘AI safety research, testing, and/or developing guidance to advance AI safety for commercially and publicly available AI systems’.22

On the distinct question of institutional function, the German policy debate seems to be converging on a non-regulatory, scientific and technical mandate aimed at enabling the Federal Government to reach informed decisions on frontier AI model risks. Interest groups have argued that the DE-AISI should be clearly distinct from regulatory authorities such as the BNetzA and the BSI to enable trust-based cooperation with frontier AI model developers,23 and the BSI itself has recently clarified that the DE-AISI is designed not to carry out regulatory or market surveillance activities.24 These proposals envision that the DE-AISI would produce recurring cross-departmental situational assessments for the Federal Government, conduct systematic technical evaluations of frontier AI models, carry out research in service of those tasks, contribute to the development of technical standards, and cooperate with partner institutions at national, supranational, and international levels.25 Its focus would extend beyond cybersecurity to chemical, biological, radiological, and nuclear (CBRN) risks and to loss-of-control (LoC) risks,26 comparable to the focus of the UK AISI.27

Another question concerns which models precisely the DE-AISI should observe and evaluate.28 Arguably, a national security-focused institute should not confine itself to general-purpose AI (GPAI) models with systemic risk within the meaning of the EU AI Act,29 but should also capture more specialised models capable of generating comparable risks: genome language models capable of facilitating the design of dangerous pathogens could be one example.30 The definition should remain technology-neutral, so that the institute’s remit is not restricted only to proprietary models or tied to today’s model architectures. At the same time, defining the frontier of AI capabilities is not straightforward. A functionally wide interpretation of frontier AI could overextend the focus of the DE-AISI.31

Persistent uncertainty about the material scope of the DE-AISI’s mandate will come at a cost. Developers deciding whether to grant pre-deployment access as well as access to otherwise unreleased models need to know whether they are dealing with a scientific partner or with an institution whose remit may later expand into adjacent, potentially regulatory territory. Industry associations have therefore called for a research mandate clearly delineated from that of existing enforcement bodies, arguing that questions of labour law, consumer protection, data protection, and AI ethics are already competently addressed elsewhere.32

After all, the preliminary nucleus arrangement may come to sit uneasily with the institute’s intended function. The BNetzA recently became Germany’s central node of the AI Act’s national-level enforcement architecture,33 and the BSI holds its own enforcement powers in the field of information security.34 An institute housed within or governed by authorities exercising such powers may struggle to obtain the confidential access on which its work depends. For instance, GPAI model providers may worry that the BNetzA could use information voluntarily shared with the DE-AISI to request the European Commission to exercise its enforcement powers under Chapter V of the AI Act, where this is necessary and proportionate to assist the BNetzA in fulfilling its market surveillance tasks.35 Closing precisely this kind of access gap is among the institute’s purposes and of outsized importance to national security. Indeed, obtaining pre-release access to frontier models may prove difficult in any event as recent reporting on the UK AI Security Institute illustrates.36 Whatever its institutional setup ends up being, it may therefore be advisable to ensure a sufficiently clear delineation between the DE-AISI and regulatory powers. This may mean limiting the cooperation between the DE-AISI and the BSI and the BNetzA to general, non-developer-specific findings on frontier AI risks, rather than confidential information capable of being used for regulatory purposes. In this respect, it is promising that the BSI has expressly described the DE-AISI as a non-regulatory institution.37

III. Pay, flexibility, and the case for a GmbH

Germany’s Federal Digital Minister has stated that the DE-AISI should be staffed with ‘top expertise from world-class experts’.38 Delivering on that ambition will be difficult within ordinary German public-sector pay structures, which may be insufficient to compete for highly sought-after frontier AI experts. One industry report by the payroll platform Rise records a 45 per cent increase in compensation for AI safety and alignment specialists since 2023.39 The UK AISI has recognised these dynamics. It operates not only with GBP 66 million in annual funding and priority access to compute, but also with a more competitive salary structure than the rest of the civil service.40 Proposals in the German debate have mostly suggested funding similar to that of the UK institute ranging from EUR 60 million41 to at least EUR 75 million annually.42

However, funding levels alone do not determine whether these resources can be deployed effectively. Choosing a legal form that allows the DE-AISI to effectively deploy funding will be equally crucial. Establishing the institute as a federally owned limited liability company (GmbH) would be a promising option in this regard. It would constitute a formal privatisation (formelle Privatisierung), leaving the operational task itself in state hands while changing only the organisational vehicle through which it is performed.43 A reference point for formal privatisation of this kind is the Federal Agency for Disruptive Innovation (Bundesagentur für Sprunginnovationen, SPRIND).44 SPRIND is a wholly federally owned GmbH created to fund high-risk innovation projects and governed by its own statute, the SPRIND Act (SPRIND-Freiheitsgesetz45) of 2023.46 It was designed for a field in which recruitment and funding decisions must be taken quickly and in competition with the private sector. In several ways, the DE-AISI faces a comparable situation, necessitating a legal form that allows it to meet similar key challenges.

One particular challenge is the DE-AISI’s staffing. As a company under private law, the institute would not be bound by public-sector collective agreements in the same way as a federal authority. It could seek exemptions from the prohibition on preferential treatment (Besserstellungsverbot), which otherwise prevents federally funded bodies from paying their staff more than comparable federal employees. § 5 of the SPRIND Act transfers that decision to the company itself where compelling reasons so require, based on the legislature’s reasoning that contract negotiations in highly competitive fields must be conducted quickly and concluded with binding effect. Bitkom, one of Germany’s largest digital industry associations, has argued for a comparable arrangement for the DE-AISI.47

As for budgetary flexibility, the frontier AI risk landscape develops on timelines that do not align with annual budget tranches. Evaluation and research priorities in this field can shift within months, if not weeks. § 15(2) of the Federal Budget Code (Bundeshaushaltsordnung) permits appropriations to be designated for self-administration (Selbstbewirtschaftung), allowing funds to be carried across financial years and redeployed within the approved purposes as project needs change. § 3(2) of the SPRIND Act makes use of this instrument, for 30 per cent of the annual federal allocation to the company. The same instrument has been extended to non-university research institutions to strengthen their performance and international competitiveness,48 which suggests its relevance for a body operating in a field that is at once fast-moving and research-based, such as the DE-AISI.

Regarding governance, the articles of association (Gesellschaftsvertrag) would allow the Federal Government’s specific requirements to be reflected in tailored form,49 while limited liability, in principle, caps the exposure of the federal budget.50 Democratic accountability can be maintained through the instruments of company law. The Federal Government, as sole shareholder, would appoint the executive director, could issue instructions, and would hold comprehensive information rights.51 Furthermore, the GmbH structure allows for a high degree of organisational and personnel flexibility.52

None of this follows necessarily from the choice of the GmbH as the legal form as such. As in the case of SPRIND, it depends on the enabling legislation providing for it.53 In particular, it depends on exemptions from the prohibition on preferential treatment and on the self-administration rate adopted, as well as on the articles of association. Whether comparable arrangements could be achieved within a public law structure remains an open question. In its July 2026 parliamentary response, the Federal Government stated that it was not yet in a position to provide details on the institute’s long-term legal structure.54

IV. A location fit for purpose

The Federal Government initially deferred a decision on the DE-AISI’s location. On 31 August 2026, it announced that the institute would be established in Berlin, where the virtual nucleus formed by the BSI and the BNetzA now operates.55 Reports suggest the choice of location for this first phase of the DE-AISI was driven by the aim of securing close proximity to the work of the Federal Government; the BMDS, the the Federal Ministry of the Interior and the Chancellery were all involved in the decision.56 Where the institute will be sited in its second phase, however, appears to remain undecided.

Both the Saarland and Bavaria had formally campaigned for the institute. In August 2026, the CDU group in the Saarland state parliament – in opposition at state level, but the party of the Chancellor and, with its sister party the CSU, of the ministries leading on the DE-AISI – formally called for the institute to be based in Saarbrücken. Stephan Toscani, chair of the group, described the Saarland as ‘the ideal location’.57 Saarbrücken hosts Saarland University, the German Research Center for Artificial Intelligence (DFKI), the CISPA Helmholtz Center for Information Security, two Max Planck Institutes, as well as branch offices of both the BSI and the BNetzA.58 Minister-President Anke Rehlinger offered financial support, including the possibility of temporarily covering the institute’s rent, and several Saarland research institutions backed the bid in a letter.59 Bavaria campaigned for Munich;60 individual members of the Bundestag advocated for Dresden61 and Darmstadt.62 Bonn, for its part, would have placed the DE-AISI at the same location as the BSI headquarters.63 Following the decision on the institute’s structure and location for its first phase, the Saarland’s Minister of Economy, Innovation, Digital Affairs, and Energy stated that he would have preferred a single decision on the institute as a whole, taken strictly on substantive criteria, and that the state would pursue its chance in the second phase.64

The Berlin location aligns with the institute’s intended advisory function. If the DE-AISI’s defining task will be advising the Federal Government on frontier AI risks, its work will consist largely of recurring cross-departmental situational assessments, ad hoc analysis when risks shift at short notice, and exchanges that might involve classified material. In this respect, proximity to the ministries carries particular weight, as the UK AISI’s location in London illustrates. The relocation of the headquarters of the Federal Intelligence Service (BND) from Pullach to Berlin was justified on similar grounds, given the need for swift communication and intensive coordination between the BND and federal government bodies.65 Berlin also offers access to one of Germany’s largest AI industry clusters, hosts a DFKI branch,66 and, as a capital city, may prove easier to recruit for than the alternatives.

Regional policy considerations pull in the other direction and are likely to resurface in the second phase. Germany has a long-standing practice of distributing federal institutions across the country, and the Saarland bid is expressly framed as part of that state’s structural transition towards a technology location.67 These are legitimate objectives in their own right, but they are distinct from the question of where the institute can most effectively perform its advisory function. Insofar as the above considerations of proximity to the Federal Government and talent recruitment are crucial factors, they point towards Berlin for the second phase as well.

V. Conclusion: What Germany stands to gain, or forgo

The establishment of the DE-AISI is an important opportunity for Germany to contribute to the safety and security of frontier AI models as their risks for national security and critical infrastructure become increasingly central. Existing institutes provide case studies for success factors and possible failure modes. For example, the UK AI Security Institute has benefited from financial flexibility in hiring, access to compute, an attractive location, and a scientific mandate clearly distinct from regulatory functions – a feature now expressly included in the German institute’s published design. Drawing on these experiences, the DE-AISI can make vital contributions to national security by assessing frontier AI risks specifically in line with the mandate of the German National Security Council.

Such a role provides a rationale for dedicated national capacity alongside EU-level and international cooperation. National security remains the responsibility of each Member State, while the AI Office supervises general-purpose AI model obligations at Union level. The AI Act’s definition of systemic risk refers to a significant impact on the Union market and harms that can propagate at scale across the value chain rather than to the exposure of any single Member State.68

Until these capacities are fully built up, Germany’s ability to anticipate and respond to frontier AI risks remains substantially dependent on what partner institutions abroad are willing to share. Timely progress will therefore be essential. The decision to establish the institute came more than two years after Germany endorsed the Seoul Statement of Intent in May 2024.69

Two important elements of the institutional design have now been clarified. Berlin has been confirmed as the seat of the first phase, securing the proximity to the Federal Government that the institute’s advisory work requires. Whether the second-phase expansion will involve a separate location remains open. What is more, the institute’s non-regulatory character has been stated expressly. The legal form, by contrast, remains undecided. A GmbH could afford the needed financial and personnel flexibilities, subject to appropriate statutory and budgetary arrangements that clearly define the institute’s mandate and its relation to other governmental bodies.

If these steps are taken, the DE-AISI can move to the forefront of international AI safety and security institutions and anchor Germany’s preparedness for frontier AI risks.

Share
Germany Establishes an AI Safety and Security Institute
Maximilian Pralle, Tarmio Frei, Oskar Wernitz, Hannes Bastians, Christoph Winter
Germany Establishes an AI Safety and Security Institute
Maximilian Pralle, Tarmio Frei, Oskar Wernitz, Hannes Bastians, Christoph Winter