UK remote
Control Red Team - Research Engineer/Research Scientist
About this role
About the AI Security Institute The AI Security Institute is the world's largest and best-funded team dedicated to understanding advanced AI risks and translating that knowledge into action. We’re in the heart of the UK government with direct lines to No. 10 (the Prime Minister's office), and we work with frontier developers and governments globally. We’re here because governments are critical for advanced AI going well, and UK AISI is uniquely positioned to mobilise them.
With our resources, unique agility and international influence, this is the best place to shape both AI development and government action. The deadline for applying to this role is 30 th September 2026 , end of day, anywhere on Earth. Team Description Control measures — monitors, permission systems, sandboxing, resampling, escalation protocols — are designed to detect and prevent misaligned behaviour from advanced AI systems.
Though the measures are already critical to safety, whether they would in fact catch a capable model attempting to cause harm is an empirical question that remains largely untested. The Control Red Team at AISI is stress-testing control monitors ( including from GDM and Anthropic ) – finding attacks that beat monitors and attempting to design experiments to measure real-world risk. We’re based within the Red Team, about a dozen people who have spent the last two years breaking developer’s alignment and misuse safeguards, and grew out of AISI’s previ o us research in to contro l evaluations and safety cases.
We're opening roles on the Control Red Team, and we think it's an unusually good place to do this work. You'd join early, with real ownership over the team's direction; you'd have frontier model access, serious compute and strong infrastructure support from across AISI; and you'd get privileged insight into control measures across several frontier developers, working alongside some of the most experienced red teamers in the field.
Our current bet is to focus our effort on monitoring : the measures frontier companies lean on most heavily, and the ones where the science of evaluation is not yet settled. About the Role What You'll Be Doing You’ll spend your time across two tracks of work: 1. Research: How and what should we measure to understand the efficacy of control measures? How can we gather empirical evidence about how likely a monitor is to prevent harm — and what can we legitimately conclude from it? How do you estimate a monitor's recall against dangerous behaviours nobody has seen yet? These are difficult questions – conceptually and empirically.