⚡ Quick Summary
Published by The Institute for AI Policy and Strategy, this policy memo proposes a US frontier-AI agenda centred on safety, security, national competitiveness and resilience to AI-enabled threats. It argues that safeguards should be proportionate to capability and use case and apply through the full model lifecycle. Its three pillars are to govern the most powerful systems across their lifecycle, advance American AI leadership, and strengthen national resilience.
The memo recommends mandatory government access to and evaluation of frontier models before internal deployment, regular risk reports for internal and external deployments, and expanded measurement of AI R&D automation through the Center for AI Standards and Innovation (CAISI). It proposes domestic pacing arrangements for dangerous development, including continuous monitoring and shutdown contingencies. Other recommendations include agent identifiers and an Agentic Cybersecurity Exchange; standards and independent assurance for evaluations; a graduated security standard based on RAND security levels SL1–5; strengthened intelligence and export controls; incident reporting; differential model access for defenders; and a National AI Reserve Corps with an emergency assessment council.
🧩 What’s Covered
The memo develops its recommendations through three policy pillars:
- Internal-model oversight and automated R&D: Calls for mandatory government access to, and evaluation of, frontier models before internal deployment, alongside regular developer risk reports. It proposes measuring AI R&D and broader R&D automation through an expanded CAISI testing and evaluation remit, including opportunities for medical science and cyber defence.
- Pacing and agent detection: Defines pacing as deliberately slowing dangerous parts of AI development until security measures catch up. Recommendations include legal mechanisms for coordinated pacing, limits on fully automated AI R&D or systems that evade shutdown commands, rehearsed shutdown arrangements, continuous monitoring, and work on incident reporting and risk thresholds with Beijing. It also proposes a common agentic security alert standard, verifiable identifiers for agents interacting with critical infrastructure, and an Agentic Cybersecurity Exchange.
- Evaluations and assurance: Identifies evaluation awareness, benchmark saturation, underweighted scaffolding effects, and weak measurement of propensity and safeguard efficacy as limitations. It calls for CAISI, DARPA and DOE investment; published standards for evaluators; and funding or market mechanisms that reduce evaluators’ financial dependence on AI developers.
- Security of advanced AI assets: Recommends a NIST/CAISI graduated security standard based on SL1–5, third-party assessment methods, mandatory biannual assessments validated by NSA red teams, and a proof-of-concept SL5 inference/fine-tuning data centre estimated at $37–50M.
- Intelligence and export controls: Proposes a dedicated intelligence capability and an AI-specific indicators-and-warning framework tied to response triggers. It calls for aligned controls on semiconductor manufacturing, stronger chip-export licensing and location verification, authority over foreign remote access, whistleblower measures, and greater Bureau of Industry and Security enforcement capacity.
- Defence, reporting and crisis response: Sets out differential access to cyber-capable models for agencies, contractors and critical-infrastructure operators; ODNI-led threat-information fusion with CAISI; safety cases and defensive research capacity; harmonised risk, near-miss and incident reporting; and reserve-expert and emergency-council arrangements for severe incidents.
💡 Why it matters?
The memo addresses governance gaps that arise before public model release as well as after deployment. For policymakers and assurance bodies, it connects model evaluations, security levels, risk reporting and independent verification to concrete points in the development lifecycle. For cyber defenders and critical-infrastructure operators, its differential-access and information-sharing proposals aim to make defensive use of frontier models and threat intelligence more timely.
It also treats frontier AI as a national-security issue involving model theft, offensive cyber operations, biological and conventional weapons development, and adversarial access to advanced compute. Its recommendations link domestic oversight to intelligence collection, export-control enforcement and incident-response arrangements.
❓ What’s Missing
The memo is a concise policy agenda rather than an implementation plan. It recommends capability-proportionate safeguards but does not define capability thresholds, identify which models count as frontier systems, or provide model risk-assessment criteria. It calls for agreements on dangerous development and for incident-severity thresholds, but does not specify their terms or trigger levels. Beyond the proposed $37–50M proof-of-concept SL5 data centre, it does not provide costings, legislative text, implementation timelines or a detailed allocation of responsibilities across all named agencies. It also proposes standards and reporting protocols without supplying templates, technical specifications, or reporting forms. The document has no bibliography or consolidated source list for the incidents and estimates discussed.
👥 Best For
US congressional staff, executive-branch policymakers and national-security officials developing frontier-AI oversight proposals. It is also relevant to frontier-model providers, independent evaluators, security teams and critical-infrastructure operators considering assurance, agent detection, incident reporting, secure model access and cyber-defence arrangements.
📄 Source Details
Priorities for Frontier AI Policy is a six-page English IAPS policy memo published by The Institute for AI Policy and Strategy on September 11, 2026. The named authors are Theo Bearman, Joe O’Brien, Erich Grunewald, Cassia King, Hamish Low and Sarah Godek. No version number, edition or document URL is printed.