Skip to content

Cite the Standard

Use the formats below to cite the SL5 Standard for AI Security.

Publication mirrors may lag the repository. See the changelog for the authoritative release history.

Authors
Lisa Thiergart, Yoav Tzfati, Peter Wagstaff, Guy, Luis Cosio, Philip Reiner
Published
March 2026
DOI
10.48550/arXiv.2605.08449
arXiv
2605.08449

APA

Thiergart, L., Tzfati, Y., Wagstaff, P., Guy, Cosio, L., & Reiner, P. (2026). SL5 Standard for AI Security. arXiv. https://doi.org/10.48550/arXiv.2605.08449

BibTeX

@misc{thiergart2026sl5,
  title = {{SL5 Standard for AI Security}},
  author = {Lisa Thiergart and Yoav Tzfati and Peter Wagstaff and Guy and Luis Cosio and Philip Reiner},
  year = {2026},
  eprint = {2605.08449},
  archivePrefix = {arXiv},
  primaryClass = {cs.CR},
  doi = {10.48550/arXiv.2605.08449},
  url = {https://doi.org/10.48550/arXiv.2605.08449}
}

RIS

TY  - RPRT
TI  - SL5 Standard for AI Security
AU  - Lisa Thiergart
AU  - Yoav Tzfati
AU  - Peter Wagstaff
AU  - Guy
AU  - Luis Cosio
AU  - Philip Reiner
PY  - 2026
DA  - 2026/03//
PB  - arXiv
DO  - 10.48550/arXiv.2605.08449
UR  - https://doi.org/10.48550/arXiv.2605.08449
AB  - Security Level 5 (SL5) is a security posture for AI systems that could plausibly thwart top-priority operations by the world's most cyber-capable institutions: those with extensive resources, state-level infrastructure, and expertise years ahead of the public state of the art. The SL5 terminology originates from the RAND Corporation's 2024 report "Securing AI Model Weights" [1].  Version 0.1 of the SL5 standard focuses on requirements with long lead times: interventions that must be planned years in advance, such as facility construction, hardware procurement, and organizational capability development. We prioritize these requirements because preserving optionality for SL5 by 2028/2029 requires starting now. These capabilities cannot be retrofitted on short notice when the need becomes urgent. Some requirements represent significant departures from current-day standard practice. We believe bold measures are necessary for this level of security and see clear opportunities to optimize existing and novel solutions for the AI industry while addressing practical operational requirements. Our organization exists to begin paving this path. Some requirements approximate government security capabilities where private-sector approaches may be insufficient. We identify these gaps and note where government involvement may ultimately be necessary.  This standard was developed collaboratively with frontier AI laboratories, government partners, and security experts through sustained engagement over several months. As version 0.1, significant refinement is expected through continued stakeholder engagement. We explicitly invite frontier AI labs, government agencies, datacenter operators, and security researchers to engage with this work, whether through direct collaboration, feedback, or implementation experience. Please reach out through standard@sl5.org.  The SL5 Standard is an integrated security control profile for frontier AI infrastructure, anchored in NIST SP 800-53 Rev. 5 and extended with NIST SP 800-161 Rev. 1 Update 1 supply-chain controls and ICD 705-derived facility requirements [2], [3], [6], [7], [18], [19]. This is comparable in structure to high-assurance baselines such as FedRAMP High that combine requirements and guidance from multiple authorities rather than deriving every requirement from one publication. We use NIST SP 800-53 as the primary control vocabulary because it is a battle-tested framework familiar to high-security organizations. The profile format supports adoption by organizations already implementing NIST controls and clearly expresses the SL5-specific selection, parameter assignments, and supplemental guidance without restating an entire baseline.  Many other security controls are necessary for SL5, including most controls from existing high-security baselines. Future revisions will provide detailed mappings from DoD Impact Level 6 (IL6) and its reference frameworks (FedRAMP High and CNSSI 1253) to SL5 requirements [4], [5]. The machine-readable OSCAL profile imports selected controls from the NIST SP 800-53 Rev. 5 catalog and a separately published local catalog for SR-13 from NIST SP 800-161 Rev. 1 Update 1 [2], [3]. Physical security requirements draw on ICD 705 and ICS 705-1 as a basis and are published as a separate normative section because they do not map cleanly to individual SP 800-53 controls [6], [7], [18], [19].
KW  - AI security
KW  - frontier AI
KW  - model weight security
KW  - AI datacenter security
KW  - nation-state security
KW  - NIST SP 800-53
KW  - NIST SP 800-161
KW  - OSCAL
ER  -

Plain text

Lisa Thiergart, Yoav Tzfati, Peter Wagstaff, Guy, Luis Cosio, Philip Reiner, "SL5 Standard for AI Security," arXiv:2605.08449 [cs.CR], 2026. doi: 10.48550/arXiv.2605.08449. https://doi.org/10.48550/arXiv.2605.08449