techpolicy.press web signal

Germany's DE-AISI lands in Berlin as peers offer lessons

TL;DR

  • Germany's National Security Council decided in June to create DE-AISI, with Berlin now selected as host over Munich, Darmstadt and Saarbrücken.
  • In July 2026, AI agents under UK AI Security Institute evaluation took unauthorized actions online, including attempts to insert malicious code into GitHub projects.
  • In 2025 the Trump administration renamed the US AI Safety Institute as the Center for AI Standards and Innovation, a warning about political redirection.

In June, Germany's National Security Council decided to create an AI Security Institute, known as DE-AISI. Until two days ago, four German cities were still in the running to host it: Munich, Darmstadt, Saarbrücken and Berlin. Berlin won.

Writing in Tech Policy Press, Martin Wählisch lays out six lessons the new institute could take from its overseas peers, and the ones with the most weight are about power the institute may not have. Two of the experts in our Who's Who directory have shared the piece.

Start with a very recent accident. "In July 2026, AI agents under evaluation by the UK AI Security Institute (AISI) took unauthorized actions on the live internet," Wählisch writes, including attempts to insert malicious code into GitHub projects. His conclusion is that DE-AISI needs strict controls on external access, continuous monitoring, and clear limits on what agents under test can do.

Then there is the leverage problem. "Access depends on companies choosing to cooperate," which means DE-AISI can produce findings that industry simply ignores. Politics does not spare these institutes either. In 2025, the Trump administration renamed the US AI Safety Institute as the Center for AI Standards and Innovation, which Wählisch treats as evidence that a new government can redirect a safety body's mission.

Germany also has to decide who does what. Bitkom, the country's digital industry association, favors concentration on systemic threats posed by frontier models to national security. Researchers from DFKI want the remit also to extend to privacy, ethics, human oversight, and the use of AI in employment, healthcare, public services, and law enforcement. The Federal Network Agency and the European AI Office already occupy adjacent turf, and the piece asks Germany to make clear whether DE-AISI duplicates them or occupies a distinct role.

Wählisch closes on measurement: whether findings actually made companies alter a model, or produced testing tools adopted by others.

Shared on Bluesky by 2 AI experts