
UK AI Security Institute
UK government frontier-AI evaluation body; confirmed GPT-5.5 and Mythos both clear the 32-step autonomous attack benchmark.
AISI's Frontier AI Trends Report, published 1 May 2026, confirmed GPT-5.5 cleared the same 32-step autonomous attack-chain benchmark Claude Mythos had passed weeks earlier, the second frontier model to do so within five days.
Last refreshed: 4 August 2026 · Appears in 3 active topics
Two frontier models cleared the same 32-step attack chain in five days; what comes next?
Timeline for UK AI Security Institute
Named as sitting in the Cabinet Office
European Tech Sovereignty: Whitehall's AI brief has no named ownerWashington pulls a live AI model
AI: Jobs, Power & MoneyPublished Frontier AI Trends Report confirming GPT-5.5 cleared the 32-step autonomous attack chain on 6 May
AI: Jobs, Power & Money: GPT-5.5 clears 32-step attack chain; two models in five daysPublished evaluation finding GPT-5.5 matched Mythos on 32-step attack chain
AI: Jobs, Power & Money: AISI: GPT-5.5 matches Mythos on 32-step attackPublished independent evaluation on 15 April confirming Mythos attack-chaining but refuting single-task superiority
AI: Jobs, Power & Money: AISI confirms Mythos 20-hour attack chainBackground
The UK AI Security Institute was established in November 2023 after the first international AI Safety Summit at Bletchley Park, under the UK Department for Science, Innovation and Technology. Its mandate is to evaluate frontier AI models for safety risks before or after deployment, with privileged access to unreleased systems, and it works alongside the National Cyber Security Centre and international counterparts including the US AI Safety Institute.
AISI's April 2026 Mythos evaluation tested a model Anthropic had withheld from public release, demonstrating that privileged-access mandate in practice. Its findings closed a loop opened by the Bessent-Powell emergency meeting of 8 April, which Treasury and the Federal Reserve had convened over AI cybersecurity risks they could not themselves verify; the UK now has a standing independent evaluator publishing results where the US has had ad hoc emergency convening with no public follow-up document.
The Institute has since rebranded operationally to the AI Security Institute, retaining AISI as its abbreviation, reflecting a widened REMIT beyond frontier-model safety evaluation alone.
Two models clear the same attack chain
AISI published an independent evaluation of Anthropic's Claude Mythos Preview on 15 April 2026, confirming the model's attack-chaining capability was genuine: it autonomously completed AISI's 32-step "Last Ones" benchmark, an operation the Institute estimates would take a trained human roughly 20 hours.
Its Frontier AI Trends Report, published 1 May, then confirmed GPT-5.5 cleared the same benchmark, scoring 71.4% on the expert cyber suite and completing it end-to-end in 2 of 10 attempts, the second frontier model to pass in under five days. AISI's 1 May report put the trend line at frontier cyber capability doubling roughly every four months.