Skip to content

About

About Security Level 5 and this standard

Document Details

Version
0.1
Date
March 2026 (updated June 23, 2026)
Focus
Long lead times

Security Level 5

A non-profit cross-industry effort working to ensure frontier AI infrastructure can achieve nation-state-level security by 2028/2029.

Founded
June 2026

About Security Level 5

Security Level 5 is a non-profit cross-industry effort working to ensure frontier AI infrastructure can achieve nation-state-level security by 2028/2029. We are a core team of engineers and security strategists leading a 100-person technical track (comprising security engineers from frontier AI labs, government security specialists, and datacenter colocation providers) alongside an executive track of AI industry security leaders providing steering input. Security Level 5 is named after the highest security level in RAND's Securing AI Model Weights framework: the level the standard exists to make reachable.

Over the past nine months, we have conducted a series of workshops and research programs to clarify what it takes to reach Security Level 5 in a way that is sensitive to competitive pressures, the need to maintain speed of innovation, and the reality of a rapidly shifting threat landscape. Our mission is to create the optionality for frontier AI labs to reach Security Level 5 in the coming years, and to be able to activate that security level within six months of choosing to do so.

In service of that mission, we have convened this broad task force to clarify what needs to be done, and in particular what needs to be done early, to preserve that optionality. This standard represents one output of that collaborative effort.

For more information or to engage with our work, contact us at standard@sl5.org or visit sl5.org.

Authors

Lisa Thiergart

Yoav Tzfati

Peter Wagstaff

Guy

Luis Cosio

Philip Reiner

Acknowledgments

Contributors and reviewers who shaped the SL5 Standard

This standard was shaped by the collective expertise of Security Level 5's two specialized tracks. Our Executive Track, comprising AI lab decision-makers, national security leaders, datacenter operators, chip providers, and government representatives, provided strategic direction and identified key obstacles to SL5 implementation. Our Technical Track, comprising security researchers, lab security engineering staff, technical AI researchers, hardware engineers, and security engineers working across five specialized working groups (machine security, network security, software security, supply chain security, and personnel security), developed and stress-tested the control specifications and architectural recommendations in this document.

We are deeply grateful to every participant across both tracks for their willingness to engage in rigorous, honest discussion and for the time they generously contributed to this effort. Please note that the following list of acknowledgments is not yet finalized and will be updated in the coming days. Additionally, inclusion in this list reflects an individual's informative contributions to this effort and does not necessarily represent their personal views or endorsement of all the contents of this document. The following individuals wished to be acknowledged for their contributions:

This list remains in progress as we hear from members.

Jason Clinton

Deputy CISO, Anthropic

Dane Stuckey

CISO, OpenAI

Vijay Bolina

former CISO, GDM

Rob Joyce

former Cybersecurity Director, NSA

Phil Venables

former CISO, Google Cloud, current Partner at Ballistic Ventures

Jason Kichen

CISO, Fluidstack

Eric Grosse

former VP Security & Privacy Engineering, Google

Dominic Rizzo

CEO ZeroRISC

Omer Nevo

CTO, Irregular

Evan Miyazono

CEO, Atlas Computing

Kristian Rönn

CEO, Lucid Computing

Jarrah Bloomfield

Anthropic & former Google

Keri Warr

Anthropic

Steven Hernandez

former CISO, United States Agency for International Development

Tanya Verma

CEO, Tinfoil

Gil Gekker

CoS to CEO, Irregular

davidad (David A. Dalrymple)

Paul Crowley (ciphergoth)

Anthropic

Jason Kikta

CTO, Automox

How to Contribute

This standard was developed collaboratively with frontier AI laboratories, government partners, and security experts. As version 0.1, significant refinement is expected through continued stakeholder engagement.

We explicitly invite frontier AI labs, government agencies, datacenter operators, and security researchers to engage with this work. Contact us at standard@sl5.org or visit sl5.org.

You can also leave feedback directly on any control specification using the feedback tool at the bottom of each control page.