Skip to content

About Security Level 5

Security Level 5 and the SL5 Standard.

About Security Level 5

Security Level 5 is a non-profit cross-industry effort working to ensure frontier AI infrastructure can achieve nation-state-level security by 2028/2029. We are a core team of engineers and security strategists leading a 100-person technical track (comprising security engineers from frontier AI labs, government security specialists, and datacenter colocation providers) alongside an executive track of AI industry security leaders providing steering input. Security Level 5 is named after the highest security level in RAND's Securing AI Model Weights framework: the level the standard exists to make reachable.

Over the past nine months, we have conducted a series of workshops and research programs to clarify what it takes to reach Security Level 5 in a way that is sensitive to competitive pressures, the need to maintain speed of innovation, and the reality of a rapidly shifting threat landscape. Our mission is to create the optionality for frontier AI labs to reach Security Level 5 in the coming years, and to be able to activate that security level within six months of choosing to do so.

In service of that mission, we have convened this broad task force to clarify what needs to be done, and in particular what needs to be done early, to preserve that optionality. This standard represents one output of that collaborative effort.

For more information or to engage with our work, contact us at standard@sl5.org or visit sl5.org.

About This Document

Security Level 5 (SL5) is a security posture for AI systems that could plausibly thwart top-priority operations by the world's most cyber-capable institutions: those with extensive resources, state-level infrastructure, and expertise years ahead of the public state of the art. The SL5 terminology originates from the RAND Corporation's 2024 report "Securing AI Model Weights" [1].

Version 0.1 of the SL5 standard focuses on requirements with long lead times: interventions that must be planned years in advance, such as facility construction, hardware procurement, and organizational capability development. We prioritize these requirements because preserving optionality for SL5 by 2028/2029 requires starting now. These capabilities cannot be retrofitted on short notice when the need becomes urgent. Some requirements represent significant departures from current-day standard practice. We believe bold measures are necessary for this level of security and see clear opportunities to optimize existing and novel solutions for the AI industry while addressing practical operational requirements. Our organization exists to begin paving this path. Some requirements approximate government security capabilities where private-sector approaches may be insufficient. We identify these gaps and note where government involvement may ultimately be necessary.

This standard was developed collaboratively with frontier AI laboratories, government partners, and security experts through sustained engagement over several months. As version 0.1, significant refinement is expected through continued stakeholder engagement. We explicitly invite frontier AI labs, government agencies, datacenter operators, and security researchers to engage with this work, whether through direct collaboration, feedback, or implementation experience. Please reach out through standard@sl5.org.

The SL5 Standard is an integrated security control profile for frontier AI infrastructure, anchored in NIST SP 800-53 Rev. 5 and extended with NIST SP 800-161 Rev. 1 Update 1 supply-chain controls and ICD 705-derived facility requirements [2], [3], [6], [7], [18], [19]. This is comparable in structure to high-assurance baselines such as FedRAMP High that combine requirements and guidance from multiple authorities rather than deriving every requirement from one publication. We use NIST SP 800-53 as the primary control vocabulary because it is a battle-tested framework familiar to high-security organizations. The profile format supports adoption by organizations already implementing NIST controls and clearly expresses the SL5-specific selection, parameter assignments, and supplemental guidance without restating an entire baseline.

Many other security controls are necessary for SL5, including most controls from existing high-security baselines. Future revisions will provide detailed mappings from DoD Impact Level 6 (IL6) and its reference frameworks (FedRAMP High and CNSSI 1253) to SL5 requirements [4], [5]. The machine-readable OSCAL profile imports selected controls from the NIST SP 800-53 Rev. 5 catalog and a separately published local catalog for SR-13 from NIST SP 800-161 Rev. 1 Update 1 [2], [3]. Physical security requirements draw on ICD 705 and ICS 705-1 as a basis and are published as a separate normative section because they do not map cleanly to individual SP 800-53 controls [6], [7], [18], [19].