A 5-day fully funded intensive in Singapore. Security and ML practitioners learn to attack and defend frontier models, agents, and the systems built around them.
Frontier models and autonomous agents are creating new attack surfaces faster than existing security practices can adapt. There is no established playbook and too few people with expertise spanning both AI and cybersecurity.
The field urgently needs more AI security talent.
FAST is designed for participants who already have a background in cybersecurity or machine learning. Over five intensive days, you'll learn to attack and defend frontier AI systems alongside twenty peers equally committed to tackling these challenges.
You'll leave with a practical introduction to AI security, a clearer understanding of where you can contribute, and an entry point into a global network of researchers, practitioners, and funders working on frontier AI security.
“Frontier ML is conceptually dense, but the code is simple and the papers are accessible — we really can get to the state of the art in not much time at all.”
— W.B., participant of AISB Singapore (April 2026), co-delivered by SASH
Frontier AI Security Training (FAST) prepares cybersecurity and machine learning practitioners to tackle the frontier of AI security: discovering where models and agents fail, building defences that remain effective even when models can't be trusted, and developing techniques to verify what AI systems actually do.
It is best suited to professionals in one of the following areas:
You work (or have worked) in a hands-on technical security capacity where you make complex trade-offs: security engineering at scale, vulnerability research, offensive security, or infrastructure security. Compliance, audit, and advisory backgrounds are usually not the right fit for this programme.
You have hands-on experience with fine-tuning or pre-training a model yourself. Reading about these would not be enough as the labs assume you have run the training loop.
This is not an introductory programme. If you can read these papers and have an opinion on them, you’ll get the most out of FAST:
You should have hands-on PyTorch at roughly the level of ML4Good or ARENA (i.e. you’ve fine-tuned or trained a model).
If your fundamentals are rusty, StatQuest’s Neural Networks / Deep Learning series takes you from the basics to transformers.
If you are unsure whether your experience is sufficient, we encourage you to apply. We’ll prioritise evidence of ability over credentials.
We bring together participants from cybersecurity and machine learning around the world — with a particular focus in Asia.
You'll work in pairs in hands-on labs, exchange ideas in small discussion groups, and build lasting relationships with peers tackling the same frontier challenges.
As reference, the AISB Singapore April 2026 cohort included participants and instructors affiliated with Meta, Microsoft, Zoom, IBM, LinkedIn, Darktrace, Niantic, Mila, ERA, the University of Oxford, the University of Cambridge, UC Berkeley, NUS, GovTech Singapore, the Monetary Authority of Singapore, and the UK AI Security Institute. SASH served as the delivery partner for that cohort. FAST is a separate programme developed and operated by SASH that will have a similar caliber of participants.
“The peer discussion, alongside the guest lectures, was the real highlight — a great cohort, with real experts from around the world.”
— W.B., participant of AISB Singapore (April 2026), co-delivered by SASH
Each day takes a different layer of the AI security stack. Mornings introduce the core concepts and current research and the afternoons are dedicated to hands-on labs where you'll learn to attack, defend, and analyze frontier AI systems.
Set up your environment, refresh the fundamentals of frontier models, and complete the prerequisite material so everyone starts with the same technical foundation.
Understand what models read and produce. Explore log probabilities, instruction hierarchies, prefilling, prompt injection, and how guardrails succeed and fail.
Explore the defences you can build when you cannot trust the model. Build and evaluate monitoring systems, control protocols, and techniques for supervising increasingly capable agents.
Attack the model itself. Remove safety fine-tuning from open-weight models, introduce backdoors through data poisoning, and distill models using only API access.
Verify what a model (and the hardware running it) is actually doing. Explore emerging approaches to compute verification, security assurance, and the open research questions shaping the field.
Translate the week's work into your next move. Refine a project with instructor feedback, understand the landscape of research labs, fellowships, grants, and career pathways, meet one-on-one with instructors, and leave with introductions and a concrete plan for staying involved in AI security.
“This program helped to bridge the gap between traditional cyber security and AI security. Highly recommend due to the high quality of the instructors, peers, materials and facilitating by SASH.”
— H., participant of AISB Singapore (April 2026), co-delivered by SASH
“…really loved the in-depth knowledge of instructors as well as exercises that were focussed on the practical aspects of understanding the various attacks and defenses for the novel-attacks in AI pipeline, which made the learning feel very real and relevant…”
— B.G., participant of AISB Singapore (April 2026), co-delivered by SASH
A researcher and educator working at the intersection of frontier AI security, AI safety, and cybersecurity. He is a Senior Research Manager at ERA, where he supports technical AI safety research and researcher development. Previously, he worked with LawZero and Mila on AI alignment research, co-founded the cybersecurity startup Elpha Secure as CTO, and earned a PhD in Computer Science from Columbia University specializing in systems security. He also teaches AI security and creates educational content on AI safety for a broad audience.
A security researcher specializing in AI security, offensive security, and secure software engineering. He is a Security Engineer at Niantic, where he helps build security into software used by millions of people worldwide. His background spans vulnerability research, reverse engineering, penetration testing, and AI safety, with a track record of discovering high-impact vulnerabilities, speaking at security conferences, and advancing practical approaches to securing complex systems.
AI security researcher specializing in adversarial machine learning, reinforcement learning, and mechanistic interpretability. His work spans AI security research, LLM red teaming, and agent security, with experience at Pillar Security, Unit 8200, and independent AI safety research supported by Open Philanthropy. He is currently co-founder and CTO of a stealth AI startup, where he works on advancing the security and reliability of frontier AI systems.
Head of AI Security at the Heron AI Security Initiative, where he works on advancing frontier AI security research and practice. His background spans offensive cybersecurity, reverse engineering, and technical leadership, with over six years in Israeli Military Intelligence leading cyber R&D and innovation teams. He also advises organizations as an independent cybersecurity consultant, bringing practical security expertise to the emerging challenges of advanced AI systems.
The programme is fully funded by philanthropic grants. There is no tuition, and no commercial sponsor. Workspace and food are provided across all five days.
Travel and accommodation are covered on a needs basis. Cost shouldn’t be a barrier for participants.
Applications for the cohort — 28 September – 2 October 2026, in Singapore — are open until 6th August 2026.
The cohort is confirmed early to allow time for travel planning.
Selection is competitive and places are limited.
No prior AI security experience is required.
You do need a strong base in either security or ML. Security side: hands-on technical work, not compliance or advisory. ML side: you have fine-tuned or trained a model.
If you can read the papers listed under “Who it's for” and have an opinion on them, you're at the right level.
We are not screening on years of experience. We are screening for technical depth.
We want applicants who have done the work: shipping security systems, finding vulnerabilities, conducting offensive or infrastructure security, or training, fine-tuning, and evaluating models themselves — not just reading papers or taking courses.
Some of our strongest past participants were still master's or PhD students. If you have the required hands-on experience, your career stage does not matter.
Yes. Most participants are. The programme is five working days, so you'll likely need to arrange leave. Participants are expected to participate full-time for the whole training to get the most value.
We can provide a support letter for your employer if useful.
Most likely, this will be within Google Colab, provisioned by us. You need a browser and a Google account.
We cover the compute costs.
Tuition is covered by philanthropic grants, and workspace and food are provided across all five days.
Travel and accommodation are covered on a needs basis. Cost shouldn’t be a barrier for participants.
Philanthropic grants, awarded to SASH to grow the number of people working on frontier AI security.
There is no vendor sponsorship, no recruitment fee, and we don't sell or share your data without your permission (we may recommend you to fellowships and residencies and other organizations that need your talents!).
If you need something in writing to justify the trip to your employer, we'll provide it.
Most participants can enter Singapore visa-free. If you need a visa or an invitation letter, we'll provide supporting documentation.
AI security is the discipline of securing frontier AI systems against misuse and compromise. It spans protecting model weights, securing the infrastructure and hardware models run on, defending AI applications and agents against attack, and developing techniques to verify what AI systems are actually doing rather than relying on their outputs alone.
It matters because capability is outpacing security. Models can already find and exploit zero-day vulnerabilities and run offensive operations end to end, while a frontier model's weights (which cost hundreds of millions of dollars to train) can be copied far more easily than the machines they run on, and safety training can be stripped from an open-weight model for under $200.
It's an emerging field, and progress is constrained above all by the number of people who can work at the intersection of AI and cybersecurity.
This is the gap FAST is working on.
AI safety is the broader field focused on ensuring advanced AI systems remain reliable, aligned with human intent, and safe to deploy as they become more capable, autonomous, and integrated into high-stakes domains. It encompasses alignment, robustness, evaluation, governance, and other approaches to reducing catastrophic risks from advanced AI.
FAST focuses on the security layer: understanding how frontier AI systems fail under attack, building defenses that withstand capable adversaries, and verifying that security measures work in practice.
Both. We won't pretend otherwise. AI security is part of AI safety. FAST focuses on the security challenges that arise as frontier AI systems become more capable and widely deployed. The training is hands-on — attacking and defending real systems — but the motivation is safety: reducing the risk that vulnerabilities in advanced AI lead to failures with large-scale consequences.
Frontier AI Security Training (FAST) was inspired by the AI Security Bootcamp (AISB) Singapore. SASH was the delivery partner for that cohort in April 2026. FAST is a separate programme developed and operated by SASH that more closely aligns to its mission as an AI safety ecosystem builder between the East and the West.
A short framing session in the morning, then lab work for most of the day with instructors on hand throughout as well as some guest speakers on specific topics. You'll pair with cohort peers, and evenings are for dinners and informal sessions with the cohort.
We begin in Singapore because it combines strong government engagement on AI, a vibrant research ecosystem, and a neutral position between major AI powers. But FAST is global by design. Building from Asia is a strategic choice, placing the programme at the intersection of Eastern and Western AI ecosystems, where long-term cooperation on frontier AI security will be essential.
Participants join the alumni track with follow-up advising sessions and warm introductions within the field, then connect with alumni from allied AI security programmes across the region and beyond, such as the Frontier AI Security Residency (FASR) and Heron residencies.
The week is designed around a single cohesive cohort, so attendance across all five days is expected. If you're a strong candidate with a conflict, tell us in your application.