Fast-track your move to Frontier AI security

A 5-day fully funded intensive in Singapore. Security and ML practitioners learn to attack and defend frontier models, agents, and the systems built around them.

Applications close by 6th Aug 2026
00Days
00Hrs
00Min
00Sec
Applications have closed.
Format
5 days, in person
Location
Singapore
When
28 Sep – 2 Oct 2026
Cohort
20 participants
Track
Technical
Participants and instructors affiliated with
Why this, why now

Frontier AI moves fast

Frontier models and autonomous agents are creating new attack surfaces faster than existing security practices can adapt. There is no established playbook and too few people with expertise spanning both AI and cybersecurity.

The field urgently needs more AI security talent.

FAST is designed for participants who already have a background in cybersecurity or machine learning. Over five intensive days, you'll learn to attack and defend frontier AI systems alongside twenty peers equally committed to tackling these challenges.

You'll leave with a practical introduction to AI security, a clearer understanding of where you can contribute, and an entry point into a global network of researchers, practitioners, and funders working on frontier AI security.

“Frontier ML is conceptually dense, but the code is simple and the papers are accessible — we really can get to the state of the art in not much time at all.”

— W.B., participant of AISB Singapore (April 2026), co-delivered by SASH
Who it's for

Designed for experienced practitioners

Frontier AI Security Training (FAST) prepares cybersecurity and machine learning practitioners to tackle the frontier of AI security: discovering where models and agents fail, building defences that remain effective even when models can't be trusted, and developing techniques to verify what AI systems actually do.

It is best suited to professionals in one of the following areas:

Security engineers

You work (or have worked) in a hands-on technical security capacity where you make complex trade-offs: security engineering at scale, vulnerability research, offensive security, or infrastructure security. Compliance, audit, and advisory backgrounds are usually not the right fit for this programme.

ML engineers & researchers

You have hands-on experience with fine-tuning or pre-training a model yourself. Reading about these would not be enough as the labs assume you have run the training loop.

This is not an introductory programme. If you can read these papers and have an opinion on them, you’ll get the most out of FAST:

You should have hands-on PyTorch at roughly the level of ML4Good or ARENA (i.e. you’ve fine-tuned or trained a model).

If your fundamentals are rusty, StatQuest’s Neural Networks / Deep Learning series takes you from the basics to transformers.

If you are unsure whether your experience is sufficient, we encourage you to apply. We’ll prioritise evidence of ability over credentials.

Who's in the room

Twenty competent peers securing frontier AI in the field

We bring together participants from cybersecurity and machine learning around the world — with a particular focus in Asia.

You'll work in pairs in hands-on labs, exchange ideas in small discussion groups, and build lasting relationships with peers tackling the same frontier challenges.

As reference, the AISB Singapore April 2026 cohort included participants and instructors affiliated with Meta, Microsoft, Zoom, IBM, LinkedIn, Darktrace, Niantic, Mila, ERA, the University of Oxford, the University of Cambridge, UC Berkeley, NUS, GovTech Singapore, the Monetary Authority of Singapore, and the UK AI Security Institute. SASH served as the delivery partner for that cohort. FAST is a separate programme developed and operated by SASH that will have a similar caliber of participants.

“The peer discussion, alongside the guest lectures, was the real highlight — a great cohort, with real experts from around the world.”

— W.B., participant of AISB Singapore (April 2026), co-delivered by SASH
What you'll do

Five days on the open problems in frontier AI security

Each day takes a different layer of the AI security stack. Mornings introduce the core concepts and current research and the afternoons are dedicated to hands-on labs where you'll learn to attack, defend, and analyze frontier AI systems.

Day0

Pre-work (before you arrive)

Set up your environment, refresh the fundamentals of frontier models, and complete the prerequisite material so everyone starts with the same technical foundation.

Day1

AI model recap

Understand what models read and produce. Explore log probabilities, instruction hierarchies, prefilling, prompt injection, and how guardrails succeed and fail.

Day2

AI control

Explore the defences you can build when you cannot trust the model. Build and evaluate monitoring systems, control protocols, and techniques for supervising increasingly capable agents.

Day3

Open-weight security

Attack the model itself. Remove safety fine-tuning from open-weight models, introduce backdoors through data poisoning, and distill models using only API access.

Day4

Verification and open problems

Verify what a model (and the hardware running it) is actually doing. Explore emerging approaches to compute verification, security assurance, and the open research questions shaping the field.

Day5

Next Steps

Translate the week's work into your next move. Refine a project with instructor feedback, understand the landscape of research labs, fellowships, grants, and career pathways, meet one-on-one with instructors, and leave with introductions and a concrete plan for staying involved in AI security.

What you'll leave with

Capabilities, a plan, a map, and a network

“This program helped to bridge the gap between traditional cyber security and AI security. Highly recommend due to the high quality of the instructors, peers, materials and facilitating by SASH.”

— H., participant of AISB Singapore (April 2026), co-delivered by SASH

“…really loved the in-depth knowledge of instructors as well as exercises that were focussed on the practical aspects of understanding the various attacks and defenses for the novel-attacks in AI pipeline, which made the learning feel very real and relevant…”

— B.G., participant of AISB Singapore (April 2026), co-delivered by SASH
How it runs

How the week is structured

Instruction & Training Build

Team

Lead Instructor

David Williams-King

Research Manager, ERA

A researcher and educator working at the intersection of frontier AI security, AI safety, and cybersecurity. He is a Senior Research Manager at ERA, where he supports technical AI safety research and researcher development. Previously, he worked with LawZero and Mila on AI alignment research, co-founded the cybersecurity startup Elpha Secure as CTO, and earned a PhD in Computer Science from Columbia University specializing in systems security. He also teaches AI security and creates educational content on AI safety for a broad audience.

Instructor

Jannis Kirschner

Security Researcher, Niantic

A security researcher specializing in AI security, offensive security, and secure software engineering. He is a Security Engineer at Niantic, where he helps build security into software used by millions of people worldwide. His background spans vulnerability research, reverse engineering, penetration testing, and AI safety, with a track record of discovering high-impact vulnerabilities, speaking at security conferences, and advancing practical approaches to securing complex systems.

Curriculum Build

Bary Levy

Independent AI Security Researcher

AI security researcher specializing in adversarial machine learning, reinforcement learning, and mechanistic interpretability. His work spans AI security research, LLM red teaming, and agent security, with experience at Pillar Security, Unit 8200, and independent AI safety research supported by Open Philanthropy. He is currently co-founder and CTO of a stealth AI startup, where he works on advancing the security and reliability of frontier AI systems.

AI Security Advisor

Nitzan Shulman

Head of Cyber, Heron AI Security Initiative

Head of AI Security at the Heron AI Security Initiative, where he works on advancing frontier AI security research and practice. His background spans offensive cybersecurity, reverse engineering, and technical leadership, with over six years in Israeli Military Intelligence leading cyber R&D and innovation teams. He also advises organizations as an independent cybersecurity consultant, bringing practical security expertise to the emerging challenges of advanced AI systems.

What it costs

Funding and support

The programme is fully funded by philanthropic grants. There is no tuition, and no commercial sponsor. Workspace and food are provided across all five days.

Travel and accommodation are covered on a needs basis. Cost shouldn’t be a barrier for participants.

Applications are open

Applications for the cohort — 28 September – 2 October 2026, in Singapore — are open until 6th August 2026.
The cohort is confirmed early to allow time for travel planning.
Selection is competitive and places are limited.

Apply now
FAQ

Common questions

Do I need a machine learning or AI security background?

No prior AI security experience is required.

You do need a strong base in either security or ML. Security side: hands-on technical work, not compliance or advisory. ML side: you have fine-tuned or trained a model.

If you can read the papers listed under “Who it's for” and have an opinion on them, you're at the right level.

What do you mean by “experienced”?

We are not screening on years of experience. We are screening for technical depth.

We want applicants who have done the work: shipping security systems, finding vulnerabilities, conducting offensive or infrastructure security, or training, fine-tuning, and evaluating models themselves — not just reading papers or taking courses.

Some of our strongest past participants were still master's or PhD students. If you have the required hands-on experience, your career stage does not matter.

What does the application process look like?
Step 1
Apply (Closes ~6th Aug 2026)
Submit a short application form, reviewed on a rolling basis. The earlier the better.
Step 2
Work exercise
Shortlisted applicants complete a short, technical work exercise.
Step 3
Interview
For top applicants, a 30-minute chat about your background, the work exercise, and any questions you have.
Decision
Offers (By ~12th Aug 2026)
Final selections, made holistically. Apply early! The cohort is confirmed early to allow time for travel planning.
Can I apply if I'm currently employed?

Yes. Most participants are. The programme is five working days, so you'll likely need to arrange leave. Participants are expected to participate full-time for the whole training to get the most value.

We can provide a support letter for your employer if useful.

What environment will I be working in?

Most likely, this will be within Google Colab, provisioned by us. You need a browser and a Google account.

We cover the compute costs.

What expenses are covered?

Tuition is covered by philanthropic grants, and workspace and food are provided across all five days.

Travel and accommodation are covered on a needs basis. Cost shouldn’t be a barrier for participants.

Why is this free? Who pays for it?

Philanthropic grants, awarded to SASH to grow the number of people working on frontier AI security.

There is no vendor sponsorship, no recruitment fee, and we don't sell or share your data without your permission (we may recommend you to fellowships and residencies and other organizations that need your talents!).

If you need something in writing to justify the trip to your employer, we'll provide it.

Will you support my visa application?

Most participants can enter Singapore visa-free. If you need a visa or an invitation letter, we'll provide supporting documentation.

What is AI security?

AI security is the discipline of securing frontier AI systems against misuse and compromise. It spans protecting model weights, securing the infrastructure and hardware models run on, defending AI applications and agents against attack, and developing techniques to verify what AI systems are actually doing rather than relying on their outputs alone.

It matters because capability is outpacing security. Models can already find and exploit zero-day vulnerabilities and run offensive operations end to end, while a frontier model's weights (which cost hundreds of millions of dollars to train) can be copied far more easily than the machines they run on, and safety training can be stripped from an open-weight model for under $200.

It's an emerging field, and progress is constrained above all by the number of people who can work at the intersection of AI and cybersecurity.

This is the gap FAST is working on.

What is AI safety?

AI safety is the broader field focused on ensuring advanced AI systems remain reliable, aligned with human intent, and safe to deploy as they become more capable, autonomous, and integrated into high-stakes domains. It encompasses alignment, robustness, evaluation, governance, and other approaches to reducing catastrophic risks from advanced AI.

FAST focuses on the security layer: understanding how frontier AI systems fail under attack, building defenses that withstand capable adversaries, and verifying that security measures work in practice.

Is this AI safety or AI security?

Both. We won't pretend otherwise. AI security is part of AI safety. FAST focuses on the security challenges that arise as frontier AI systems become more capable and widely deployed. The training is hands-on — attacking and defending real systems — but the motivation is safety: reducing the risk that vulnerabilities in advanced AI lead to failures with large-scale consequences.

What is the difference between FAST and AISB?

Frontier AI Security Training (FAST) was inspired by the AI Security Bootcamp (AISB) Singapore. SASH was the delivery partner for that cohort in April 2026. FAST is a separate programme developed and operated by SASH that more closely aligns to its mission as an AI safety ecosystem builder between the East and the West.

What does a typical FAST day look like?

A short framing session in the morning, then lab work for most of the day with instructors on hand throughout as well as some guest speakers on specific topics. You'll pair with cohort peers, and evenings are for dinners and informal sessions with the cohort.

Why Singapore?

We begin in Singapore because it combines strong government engagement on AI, a vibrant research ecosystem, and a neutral position between major AI powers. But FAST is global by design. Building from Asia is a strategic choice, placing the programme at the intersection of Eastern and Western AI ecosystems, where long-term cooperation on frontier AI security will be essential.

What happens after FAST?

Participants join the alumni track with follow-up advising sessions and warm introductions within the field, then connect with alumni from allied AI security programmes across the region and beyond, such as the Frontier AI Security Residency (FASR) and Heron residencies.

Are the dates flexible?

The week is designed around a single cohesive cohort, so attendance across all five days is expected. If you're a strong candidate with a conflict, tell us in your application.

Five days to fast-track your move
to Frontier AI Security

Apply to the cohort