About
About Security Level 5 and this standard
Document Details
- Version
- 0.1
- Date
- March 2026 (updated June 23, 2026)
- Focus
- Long lead times
Security Level 5
A non-profit cross-industry effort working to ensure frontier AI infrastructure can achieve nation-state-level security by 2028/2029.
- Founded
- June 2026
- Contact
- standard@sl5.org
- Website
- https://sl5.org
About Security Level 5
Security Level 5 is a non-profit cross-industry effort working to ensure frontier AI infrastructure can achieve nation-state-level security by 2028/2029. We are a core team of engineers and security strategists leading a 100-person technical track (comprising security engineers from frontier AI labs, government security specialists, and datacenter colocation providers) alongside an executive track of AI industry security leaders providing steering input. Security Level 5 is named after the highest security level in RAND's Securing AI Model Weights framework: the level the standard exists to make reachable.
Over the past nine months, we have conducted a series of workshops and research programs to clarify what it takes to reach Security Level 5 in a way that is sensitive to competitive pressures, the need to maintain speed of innovation, and the reality of a rapidly shifting threat landscape. Our mission is to create the optionality for frontier AI labs to reach Security Level 5 in the coming years, and to be able to activate that security level within six months of choosing to do so.
In service of that mission, we have convened this broad task force to clarify what needs to be done, and in particular what needs to be done early, to preserve that optionality. This standard represents one output of that collaborative effort.
For more information or to engage with our work, contact us at standard@sl5.org or visit sl5.org.
Authors
Lisa Thiergart
Yoav Tzfati
Peter Wagstaff
Guy
Luis Cosio
Philip Reiner
Acknowledgments
Contributors and reviewers who shaped the SL5 Standard
This standard was shaped by the collective expertise of Security Level 5's two specialized tracks. Our Executive Track, comprising AI lab decision-makers, national security leaders, datacenter operators, chip providers, and government representatives, provided strategic direction and identified key obstacles to SL5 implementation. Our Technical Track, comprising security researchers, lab security engineering staff, technical AI researchers, hardware engineers, and security engineers working across five specialized working groups (machine security, network security, software security, supply chain security, and personnel security), developed and stress-tested the control specifications and architectural recommendations in this document.
We are deeply grateful to every participant across both tracks for their willingness to engage in rigorous, honest discussion and for the time they generously contributed to this effort. Please note that the following list of acknowledgments is not yet finalized and will be updated in the coming days. Additionally, inclusion in this list reflects an individual's informative contributions to this effort and does not necessarily represent their personal views or endorsement of all the contents of this document. The following individuals wished to be acknowledged for their contributions:
This list remains in progress as we hear from members.
Jason Clinton
Deputy CISO, Anthropic
Dane Stuckey
CISO, OpenAI
Vijay Bolina
former CISO, GDM
Rob Joyce
former Cybersecurity Director, NSA
Phil Venables
former CISO, Google Cloud, current Partner at Ballistic Ventures
Jason Kichen
CISO, Fluidstack
Eric Grosse
former VP Security & Privacy Engineering, Google
Dominic Rizzo
CEO ZeroRISC
Omer Nevo
CTO, Irregular
Evan Miyazono
CEO, Atlas Computing
Kristian Rönn
CEO, Lucid Computing
Jarrah Bloomfield
Anthropic & former Google
Keri Warr
Anthropic
Steven Hernandez
former CISO, United States Agency for International Development
Tanya Verma
CEO, Tinfoil
Gil Gekker
CoS to CEO, Irregular
davidad (David A. Dalrymple)
Paul Crowley (ciphergoth)
Anthropic
Jason Kikta
CTO, Automox
How to Contribute
This standard was developed collaboratively with frontier AI laboratories, government partners, and security experts. As version 0.1, significant refinement is expected through continued stakeholder engagement.
We explicitly invite frontier AI labs, government agencies, datacenter operators, and security researchers to engage with this work. Contact us at standard@sl5.org or visit sl5.org.
You can also leave feedback directly on any control specification using the feedback tool at the bottom of each control page.