Move into AI security.

A three-month, salary-matched fellowship for senior security professionals.

Apply by Aug 14

Past AISB participants have been affiliated with

Amazon Web Services, Apollo Research, Apple, CERN, Epoch AI, FGV, Fraunhofer-Gesellschaft, Georgia Tech, Google, University of Helsinki, INSA Lyon, Jane Street, King's College London, Meta, Microsoft, OpenAI, Safer AI, Santa Fe Institute, Stanford University, UC San Diego, Università di Bologna, University of Oxford, University of Washington

A week in London to scope your project, then up to three paid months to work on it.

1–3
months
10
hrs/week
$100
/hour cap

Timeline

  1. Week oneweek 1 · London

    In person. Mornings are research blocks: you read the field and write down what is missing. Afternoons are discussion sprints, with field experts there to red-team the parts you cannot see.

  2. Buildweeks 2–5 · remote

    A paid month on your own project, alongside your job, at your rate up to $100 an hour. A weekly standup with three peers and one facilitator keeps the accountability tight. Nobody directs your work.

  3. Demo dayweek 6 · Oct 3

    You present what you built to the cohort and to the people who can move it forward. Papers get routed to workshops and arXiv referrals, tools go to the open source community, and new orgs get introductions to funders.

  4. Extensionmonths 2–3 · by invitation

    Promising projects get two more financed months to keep going at the same rate and cadence, with the same routing onward when the work is ready.

M3 is designed for

  1. (1)

    The researcher

    You push the frontier of AI Security.

    You have a question the field has not answered, a tool AI Security needs, or a direction that needs to be explored.

  2. (2)

    The founder

    You see a gap worth an organisation.

    A non-profit that governments will need and nobody has built yet. You want the time to scope it, test whether it holds, and leave with something fundable.

  3. (3)

    The field builder

    You want to scale up AI Security.

    You have spent years inside the area and the bottleneck you see is people, not ideas. You want to build the thing that widens the door.

You pick the direction. These are the problems we think are most neglected relative to how much they matter.

  1. 01Compute governance
  2. 02Inference verification
  3. 03Model attestation
  4. 04Hardware security
  5. 05Securing model weights
  6. 06Treaty verification
  7. 07Agent security
  8. 08Authorization against misuse

Scope

(1)

Empirical or theoretical

Both count. A benchmark nobody had built and a harness that makes an existing claim testable are both outputs we can route onward.

A survey of work other people already did does not count.

(2)

Off this list is fine

The list is where we think the gaps are. If you have spent a decade inside a problem we did not think to name, that is a better reason to work on it than anything written here.

Bring it in week one and let the group try to break it.

Questions we get asked.

(1)How does the pay work?

You are paid for the hours you put into your project, at your rate, capped at $100 an hour. The build phase starts with one paid month; projects that need more time can extend by two more.

(2)What does the first week cost me?

Nothing. We cover flights, hotel, food and anything else you need to be there. Your salary starts after that week, when the build phase begins.

(3)Do I have to quit my job?

No. The build phase is remote and runs alongside your job, so you decide how many hours to commit. The only in-person block is the first week, in London.

(4)Do I need a project going in?

No. Week one exists to find it: mornings reading the field, afternoons letting a small group and field experts try to break your hypothesis. The problems list is where we think the gaps are, and off-list is fine.

(5)Who directs the work?

Nobody. A weekly standup with three peers and one facilitator keeps the accountability tight, but the direction stays yours.

(6)What happens after demo day?

Papers get routed to workshops and arXiv referrals, tools go to the open source community, and new orgs get introductions to funders. Projects that need more time can extend by two paid months.

(7)Who is behind M3?

A collaboration between Constellation, Kairos and AISB. Anything this page does not answer: fernando@m3fellowship.com.

(8)What's your relationship with AISB?

M3 is a collaboration between Kairos, Constellation and AISB. M3's first in-person week runs alongside AISB London, giving fellows from both programs access to each other.