AI Governance Library

AI Security Institute Frontier AI Trends Report

A 2025 report presenting aggregated evaluation trends for frontier AI systems across autonomy, chemistry and biology, cyber, safeguards, loss-of-control risks, societal impacts and open-source models. It outlines methods, findings and limitations.
Cover of AI Security Institute Frontier AI Trends Report

⚡ Quick Summary

Published by AI Security Institute, this report synthesises trends from its evaluations of more than 30 frontier AI systems. It aims to provide accessible, data-driven insight into capabilities relevant to national security and public safety, and to support a shared understanding among governments, industry and the public. Its evidence covers agentic autonomy, chemistry and biology, cyber, model safeguards, loss-of-control precursors, societal impacts and open-source models.

The report combines auto-graded task sets, long-form tasks, agent tasks, expert red-teaming, human-uplift studies and human-impact studies. It finds rapidly improving capability across tested domains: models completed software tasks estimated to take an expert over an hour with a 42% average success rate in mid-2025; top models averaged 50% on apprentice-level cyber tasks in Q3 2025; and two frontier closed models exceeded 60% on selected RepliBench self-replication evaluations. It also finds that safeguards have improved unevenly, while universal jailbreaks have been found for every system tested.

🧩 What’s Covered

The report proceeds from its evaluation approach to evidence on capabilities, safeguards and impacts.

  • Evaluation approach: Explains the Institute’s use of auto-graded question-answer and capture-the-flag sets, long-form tasks, realistic agent environments, expert red-teaming, and studies of user uplift and human impacts. It stresses that the results show high-level trends rather than rankings of named models or developers.
  • Agents: Defines agents, scaffolds and reasoning models, then tracks longer autonomous software and cyber tasks. It reports that externally developed scaffolds outperformed minimally scaffolded base models on SWE-bench, with an almost 40% increase in average success rate at the largest late-2024 gap.
  • Chemistry and biology: Covers question-answer tests against PhD-level baselines, tool-assisted plasmid-design tasks, laboratory protocol generation, and text and multimodal troubleshooting. It notes both improved feasibility scores and continuing difficulty with end-to-end plasmid design.
  • Cyber: Uses task difficulty levels from technical non-expert to expert, alongside cyber ranges requiring sequences of actions. Optimised scaffolding improved a leading model’s cyber development-set performance by 9.8 percentage points, but success remained patchy across multi-stage range flags.
  • Safeguards: Describes misuse safeguards, universal jailbreak testing and variation by provider, request category and access type. It reports minimal correlation between general capability and safeguard robustness, and introduces the potential value of an “adaptation buffer”.
  • Loss of control: Assesses simplified self-replication through RepliBench and examines prompted sandbagging. The report distinguishes controlled-environment results from real-world replication and reports no detected spontaneous sandbagging in more than 2,700 reviewed transcripts.
  • Societal impacts: Reviews political information-seeking and persuasion, emotional dependence, and finance-focused MCP servers. Findings include increasing persuasive capability with scale, UK survey evidence on emotional use, and a shift towards more execution-capable public finance interfaces.
  • Open-source models: Defines open-source and open-weight models, discusses the difficulty of safeguarding modifiable weights, and estimates a four-to-eight-month open–closed capability gap using external measures.

💡 Why it matters?

The report gives people responsible for AI deployment and oversight concrete signals to track alongside model releases: task duration, expert-relative performance, scaffold effects and resistance to adversarial prompting. Its evidence indicates that evaluations of a base model alone may understate what an agent can do when given tailored tools and scaffolding.

It also shows why capability progress cannot be treated as a proxy for safety. Safeguard robustness varied substantially across systems and misuse categories, and the report found minimal correlation between capability and robustness. This supports the report’s case for safeguards that keep pace with capabilities, independent evaluation and monitoring of high-stakes deployment.

❓ What’s Missing

This is not a comprehensive literature review, a forecast or a benchmark of named systems and developers. Results are aggregated, and details of high-risk tasks are withheld to prevent misuse, which limits independent replication from the report alone. The Institute cautions that controlled task performance may not generalise to real-world effectiveness where latency, cost and integration matter. It may also underestimate capability ceilings because it does not always have fine-tuning API access, maximise inference-time compute or conduct bespoke scaffolding experiments. Some findings remain explicitly preliminary: RepliBench tasks simplify real-world actions, and the social-impact evidence presented includes UK-focused surveys and studies.

👥 Best For

Government, industry and research teams monitoring frontier-model risks; evaluation specialists designing capability or red-team programmes; and leaders considering agent deployment in security-sensitive, scientific or financial settings. It is particularly useful for readers who need to interpret evaluation results alongside scaffolding, access type, safeguards and observed user impacts.

📄 Source Details

AI Security Institute Frontier AI Trends Report is an English-language report published by the AI Security Institute. The supplied complete PDF contains 54 pages and lists 66 contributors on page 2. The front cover is dated December 2025, while the back cover is dated November 2025. No edition or document URL is printed.

About the author
Jakub Szarmach

AI Governance Library

Curated Library of AI Governance Resources

AI Governance Library

Great! You’ve successfully signed up.

Welcome back! You've successfully signed in.

You've successfully subscribed to AI Governance Library.

Success! Check your email for magic link to sign-in.

Success! Your billing info has been updated.

Your billing was not updated.