In November 2023 London and Washington launched "AI safety institutes" in the same week, in the afterglow of Bletchley Park. By mid-2025 both had new names. The UK body is the AI Security Institute, a DSIT directorate that now lists more than 100 technical staff on its homepage. The US body is NIST's Center for AI Standards and Innovation, carved out of the old AISI in June 2025. The EU never used the word institute. It built an AI Office with inspection powers and a fine schedule, and on 2 August 2026 those powers switched on.
A name is not a budget. A budget is not a headcount. A headcount is not a statute. I kept those apart.
The diplomatic sequence was Bletchley, then Seoul in May 2024, then Paris in February 2025. The Seoul network put the US, UK, EU, Japan, Singapore, Korea, Canada, France, Kenya, and Australia in one club. CSIS, writing in October 2024, put most annual budgets around $10 million, with the UK as the outlier at about £50 million a year and a £100 million envelope through 2030. Two years later the letterheads have moved. The cash, for most of them, has not.
Three jobs get sold as one launch.
- Measure. Run evals. Publish a blog. Share notes with allies.
- Standardise. Write a framework. Sit on ISO. Take comments on an RFI.
- Enforce. Demand weights, restrict a release, fine a provider.
Only the third changes a lab's week. Only the AI Office has it in the statute.
Britain hired
The Frontier AI Taskforce became the AI Safety Institute, then, in 2025, the AI Security Institute. The homepage in August 2026 still says more than 100 technical staff, alumni from OpenAI, DeepMind, and Oxford, and "substantial" compute. The original government overview kept the Taskforce's funding as an annual amount through the decade, subject to review, against the £100 million seed.
What they publish is evaluations. Open-weight cyber capability versus closed frontier: they put recent open models a few months behind, not a year. A persuasion study in Science. A pre-release look at Anthropic's Mythos, which is how a rumour about hacking skill became a written eval instead of a leak. A joint note with CAISI on Kimi K3 in July 2026. That is measurement. It is real work. It is not a licence condition. Labs still ship on their own calendar. The institute writes after, or just before, by invitation.
The rename matters. "Safety" was Bletchley-era alignment talk. "Security" is cyber, biosecurity, and national capability. The staff stayed. The branding followed the government.
Washington renamed the shop and left the till light
NIST stood up a US AISI after the 2023 executive order. In June 2025 Commerce Secretary Howard Lutnick turned it into CAISI. The NIST page lists the job: voluntary standards, unclassified evals of cyber and bio risk, assessments of US and "adversary" models, and a brief to fight "burdensome" foreign rules on American tech.
The money is small. IFP, in August 2025, put FY2026 at about $15 million: up to $10 million in appropriations plus a Technology Modernization Fund loan spread across two years. That is still the public ledger. The FY2027 request asked for $27 million. House and Senate appropriators had to put NIST back after a proposed cut in early 2026. There is still no public headcount comparable to the UK's 100.
CAISI does publish. DeepSeek V4 Pro in April 2026. Z.ai's GLM-5.2 in July. An RFI on agent security that closed 9 March 2026. An agent-standards initiative in February 2026. A CRADA with OpenMined. That is measurement and standards. Congress did not attach a fine.
Brussels can knock on the door
The AI Office sits inside the Commission. As of the page update on 13 August 2026 it employs more than 125 people across six units, including AI Safety, and is recruiting about 40 contractual agents for enforcement. Deadline 8 September 2026. Setup funding in 2024 was €46.5 million, reallocated, not a fresh multi-year envelope on the UK pattern.
The AI Act is the difference. The Office can evaluate general-purpose models, demand technical files, inspect, order corrective action, restrict a release, and fine. GPAI rules on paper applied from August 2025. Commission enforcement powers over those providers switched on 2 August 2026. The first year was compliance without a penalty. That year is over.
Open-weight providers are not automatically out. The Act's free-and-open exemption is narrow. Systemic-risk GPAI stays in. Article 50 transparency stays in. A DeepSeek or Llama checkpoint that is widely used in the Union can still owe documentation. Apache on the card is an input to that test, not the test.
A 125-person office that can fine is a different object from a 100-person lab that can blog. They would not be hiring paralegals for a think tank.
The rest of the network
Japan AISI opened in February 2024 inside IPA. Public write-ups put staff around 23. Tokyo has said it will double size and budget. The doubled number is not on a single audited line I could find.
Singapore folded the work into the Digital Trust Centre at NTU and the IMDA, rebranded as an AISI in 2024. The same write-ups put S$10 million a year against the institute, on top of a larger 2022 Digital Trust grant. Singapore hosted the 2026 International Scientific Exchange and the Singapore Consensus on research priorities. Convening is not headcount.
India announced an IndiaAI Safety Institute on 30 January 2025. The only rupee figure that maps onto it in the parliamentary record is the Safe & Trusted AI pillar: ₹20.46 crore of a ₹10,372 crore mission, 0.2 percent. That is a ceiling inside another ceiling. It is not a staffed directorate with a published eval series.
Canada pledged C$50 million in 2024 without a clean public spend line. France's LNE/Inria evaluation partnership is in the network notes. It is not a copy of the UK directorate. Kenya and Australia signed the Seoul statement. Signing is not hiring.
Korea is the easy country to misread. Seoul put ₩10.1 trillion against national AI in the 2026 budget, inside a ₩35.3 trillion R&D envelope. That is industrial policy. It is not the AISI's operating line. Mixing the two is how "Korea funded safety" gets invented. If the institute has a published headcount and a released-cash figure separate from that pot, it has not put both on one page I could check.
What they have actually produced
Evals of open Chinese and open-weight models, jointly and separately. RFIs. A Science paper. The International AI Safety Report 2026, whose secretariat sat in the UK institute and whose panel ran past 30 countries. ISO work Japan already cared about. The AI Act's first enforcement week.
What they have not produced is a forced delay of a Western frontier release, or a fine, or a public list of models that failed a statutory test. The UK and US bodies cannot issue that list. The Office can, and as of early August 2026 had just received the clock.
Ask for three numbers and one statute. How many technical staff are on payroll this quarter. How much cash was released this fiscal year, not pledged at a summit. Whether the organic law lets them restrict a model or only write a blog. If a government answers with a network membership and a rename, it has answered a fourth question it was not asked.
The UK hired. The US rebranded and underfunded. The EU wrote a regulation and is now hiring the people who will use it. The rest of the network is, with a few exceptions, a letterhead.
A CAISI appropriation that looks like the UK envelope would change the US row. So would a published India or Japan headcount next to released cash. So would an AI Office fine with a named model, or a UK or US statute that turns an eval into a licence condition. Until then "institute" is doing the same job "investment" does in the compute essays: one noun for three different machines.