SL5 Standard for AI Security
An integrated security control profile for frontier AI infrastructure, anchored in NIST SP 800-53 and extended with supply-chain and facility requirements, targeting nation-state-level security by 2028/2029.
This version 0.1 focuses on long lead time controls, prioritizing measures that must be planned years in advance. Future versions will extend to shorter-lead-time measures and fine-grained controls.
60 controls across 12 families - March 2026 (updated June 23, 2026)
About This Document
Security Level 5 (SL5) is a security posture for AI systems that could plausibly thwart top-priority operations by the world's most cyber-capable institutions: those with extensive resources, state-level infrastructure, and expertise years ahead of the public state of the art. The SL5 terminology originates from the RAND Corporation's 2024 report "Securing AI Model Weights" [1].
Version 0.1 of the SL5 standard focuses on requirements with long lead times: interventions that must be planned years in advance, such as facility construction, hardware procurement, and organizational capability development. We prioritize these requirements because preserving optionality for SL5 by 2028/2029 requires starting now. These capabilities cannot be retrofitted on short notice when the need becomes urgent. Some requirements represent significant departures from current-day standard practice. We believe bold measures are necessary for this level of security and see clear opportunities to optimize existing and novel solutions for the AI industry while addressing practical operational requirements. Our organization exists to begin paving this path. Some requirements approximate government security capabilities where private-sector approaches may be insufficient. We identify these gaps and note where government involvement may ultimately be necessary.
This standard was developed collaboratively with frontier AI laboratories, government partners, and security experts through sustained engagement over several months. As version 0.1, significant refinement is expected through continued stakeholder engagement. We explicitly invite frontier AI labs, government agencies, datacenter operators, and security researchers to engage with this work, whether through direct collaboration, feedback, or implementation experience. Please reach out through standard@sl5.org.
The SL5 Standard is an integrated security control profile for frontier AI infrastructure, anchored in NIST SP 800-53 Rev. 5 and extended with NIST SP 800-161 Rev. 1 Update 1 supply-chain controls and ICD 705-derived facility requirements [2], [3], [6], [7], [18], [19]. This is comparable in structure to high-assurance baselines such as FedRAMP High that combine requirements and guidance from multiple authorities rather than deriving every requirement from one publication. We use NIST SP 800-53 as the primary control vocabulary because it is a battle-tested framework familiar to high-security organizations. The profile format supports adoption by organizations already implementing NIST controls and clearly expresses the SL5-specific selection, parameter assignments, and supplemental guidance without restating an entire baseline.
Many other security controls are necessary for SL5, including most controls from existing high-security baselines. Future revisions will provide detailed mappings from DoD Impact Level 6 (IL6) and its reference frameworks (FedRAMP High and CNSSI 1253) to SL5 requirements [4], [5]. The machine-readable OSCAL profile imports selected controls from the NIST SP 800-53 Rev. 5 catalog and a separately published local catalog for SR-13 from NIST SP 800-161 Rev. 1 Update 1 [2], [3]. Physical security requirements draw on ICD 705 and ICS 705-1 as a basis and are published as a separate normative section because they do not map cleanly to individual SP 800-53 controls [6], [7], [18], [19].
Read the Standard
The standard is designed to be read in order. Start with the threat model before exploring control specifications.
Threat Model
The adversaries, targets, and attack vectors that define SL5 requirements. Nation-state operations with budgets up to $1B.
1.2Security Architecture
Five security streams in depth: network, physical, machine, personnel, and supply chain.
1.3Open Questions
Areas of genuine uncertainty and active research, from personnel vetting to adversarial detection.