In November 2023 London and Washington launched "AI safety institutes" in the same week, in the afterglow of Bletchley Park. By mid-2025 both had new names. The UK body is the AI Security Institute, a DSIT directorate that now lists more than 100 technical staff on its homepage. The US body is NIST's Center for AI Standards and Innovation, carved out of the old AISI in June 2025. The EU never used the word institute. It built an AI Office with inspection powers and a fine schedule, and on 2 August 2026 those powers switched on.
The diplomatic sequence was Bletchley, then Seoul in May 2024, then Paris in February 2025. The institute network that actually convened put the US, UK, EU, Japan, Singapore, Korea, Canada, France, Kenya, and Australia in one club. Germany and Italy signed the Seoul statement and then sat out that first membership list. CSIS, writing in October 2024, put most annual budgets around $10 million, with the UK as the outlier at about £50 million a year and a £100 million envelope through 2030. In August 2026 the UK still has the people. For the rest of the Seoul list the public number is still a pledge, a rename, or a slice of a bigger AI pot.
Bletchley produced a photograph and a noun that any capital could copy. A directorate with 100 researchers costs real money. A statute that can stop a release is something else again. The UK built the lab. The Commission wrote the regulation. Most of the Seoul list got a named body a minister can point at.
Most of these bodies run evals and sit on ISO. That does not change a lab's week. A fine does. Only the AI Office can issue one.
Britain hired
The Frontier AI Taskforce became the AI Safety Institute, then, in 2025, the AI Security Institute. The homepage in August 2026 still says more than 100 technical staff, alumni from OpenAI, DeepMind, and Oxford, and "substantial" compute. The original government overview kept the Taskforce's funding as an annual amount through the decade, subject to review, against the £100 million seed.
What they publish is evaluations. Open-weight cyber capability versus closed frontier: they put recent open models a few months behind, not a year. A persuasion study in Science. A pre-release look at Anthropic's Mythos, which is how a rumour about hacking skill became a written eval instead of a leak. A joint note with CAISI on Kimi K3 in July 2026. Labs still ship on their own calendar. The institute writes after, or just before, by invitation.
They dropped Safety for Security because the brief is now cyber, biosecurity, and national capability, not Bletchley-era alignment. The 100 people on the homepage are the same shop. The noun changed because the government did. A reader can treat that as a real shift in mission, or as a label change on the same evaluators. The homepage still lists the staff. The statute still does not give them a fine.
The UK's other output is a paper with 30 flags on it. The International AI Safety Report 2026, published 3 February, lists the UK institute as secretariat, with Mila. Yoshua Bengio chairs. The panel has nominees from more than 30 countries and organisations, including China, the EU, India, Japan, Kenya, Korea, Singapore, and the UN. The report's own findings are cautious: capabilities up in reasoning, code, maths; disagreement on timing; malicious use, malfunction, and systemic risk as the 3 buckets. Training compute still growing about 5x a year. Software tasks that take a human 30 minutes already done about 80% of the time, duration doubling every 7 months.
That paper is what the Seoul network actually produced together. It is a consensus document that lets every capital say it sat at the table. The UK paid for the secretariat. Everyone else paid for a nomination. The report can be the most serious scientific product among those institutes, and membership can still be cheaper than hiring 100 evaluators.
Washington renamed the shop. The public cash line stayed small
NIST stood up a US AISI after the 2023 executive order. In June 2025 Commerce Secretary Howard Lutnick turned it into CAISI. The NIST page lists the job: voluntary standards, unclassified evals of cyber and bio risk, assessments of US and "adversary" models, and a brief to fight "burdensome" foreign rules on American tech.
The last clause is the published brief. CAISI still runs evals. The NIST page puts those evals next to "adversary" models and "burdensome" foreign rules. Congress attached that talking point. It did not attach a fine. Whether that brief is the right one is a political argument. The statute, as funded, is the fact.
The money is small. IFP, in August 2025, put FY2026 at about $15 million: up to $10 million in appropriations plus a Technology Modernization Fund loan spread across 2 years. That is still the public ledger. The FY2027 request asked for $27 million. House and Senate appropriators had to put NIST back after a proposed cut in early 2026. There is still no public headcount comparable to the UK's 100.
CAISI does publish. DeepSeek V4 Pro in April 2026: about 8 months behind the US frontier on CAISI's aggregate, the most capable PRC model they have run, 32% versus GPT-5.5's 71% on cyber, 9 benchmarks in 5 domains, 2 of them unpublished. Z.ai's GLM-5.2 in July. An RFI on agent security that closed 9 March 2026. An agent-standards initiative in February 2026. A CRADA with OpenMined. An 8-month gap on DeepSeek is a useful number for export-control hearings. It will not make a lab in San Francisco delay a release.
Brussels can knock on the door
The AI Office sits inside the Commission. As of the page update on 13 August 2026 it employs more than 125 people across 6 units, including AI Safety, and is recruiting about 40 contractual agents for enforcement. Deadline 8 September 2026. Setup funding in 2024 was €46.5 million, reallocated, not a fresh multi-year envelope on the UK pattern. They would not be hiring paralegals for a think tank.
The AI Act is the difference. The Office can evaluate general-purpose models, demand technical files, inspect, order corrective action, restrict a release, and fine. GPAI rules on paper applied from 2 August 2025. Commission enforcement powers over those providers switched on 2 August 2026. Wilson Sonsini, writing the next day, put the GPAI fine at the higher of 3% of worldwide turnover or €15 million, matching Article 101. That is not the prohibited-practices ceiling, which sits higher at 7% or €35 million under Article 99. Mixing those 2 invents a bigger stick than the GPAI file gives. The first year was compliance without a penalty. That year is over. The Commission's own 31 July 2026 note said the switch-on out loud.
Open-weight providers are not automatically out. The Act's free-and-open exemption is narrow. Systemic-risk GPAI stays in. Article 50 transparency stays in. A DeepSeek or Llama checkpoint that is widely used in the Union can still owe documentation. Apache on the card is an input to that test, not the test. The GPAI guidelines say an Apache card does not cancel copyright or documentation duties. Providers who signed the July 2025 Code of Practice get a softer enforcement path: the Commission said it will focus on whether they kept the code. That path is a queue, not a free pass.
A 125-person office that can fine is a different machine from a 100-person lab that can blog. The Seoul network treated them as cousins because both showed up at Bletchley. One is a research directorate. One is a regulator that has not yet used the fine. Between 2 and 14 August 2026, no Commission press note announced a first documentation request, model evaluation, or fine. The Commission's own FAQ says the first tool is a technical compliance dialogue, with formal powers reserved for cases where dialogue is not enough. "The EU enforced," in the past tense, is early.
Pour Demain has argued that the Office's GPAI supervision unit should reach at least 160 staff by 2030. That is an advocacy target, not a Commission hiring plan. The recruiting round with an 8 September 2026 deadline is on the Commission's own AI Office page.
The rest of the network
Japan AISI opened in February 2024 inside IPA. CSIS, writing that October, put more established institutes around 20 to 30 staff. Tokyo has said it will double size and budget. The doubled number is not on a single audited line I could find. Japan already cared about ISO. Putting a few dozen people in IPA and calling it an institute is how you stay in the Seoul photograph without building the UK's shop.
Singapore folded the work into the Digital Trust Centre at NTU and the IMDA, rebranded as an AISI in 2024. CSIS put about S$10 million a year against the institute, on top of a larger 2022 Digital Trust grant. Singapore hosted the 2026 International Scientific Exchange and the Singapore Consensus on research priorities. Hosting a meeting is not the same as funding 100 evaluators.
India announced an IndiaAI Safety Institute on 30 January 2025. The only rupee figure that maps onto it in the parliamentary record is the Safe & Trusted AI pillar: ₹20.46 crore of a ₹10,372 crore mission, 0.2%. That line is a budget ceiling. I could not find a published staff count or an eval series. India is in the International Report's panel list. The panel list is free.
Canada pledged C$50 million in 2024 without a clean public spend line. France's LNE/Inria evaluation partnership is in the network notes. Kenya and Australia signed the Seoul statement without adding evaluators.
Korea is the easy country to misread. Seoul put ₩10.1 trillion against national AI in the 2026 budget. That is the industrial AI pot. It is not the institute's operating line. Mixing the 2 invents "Korea funded safety." If the institute has a published headcount and a released-cash figure separate from that pot, it has not put both on one page I could check.
What they have actually produced
Evals of open Chinese and open-weight models, jointly and separately. RFIs. A Science paper. The International Report. ISO work Japan already cared about. The AI Act's first enforcement week.
What they have not produced is a forced delay of a Western frontier release, or a fine, or a public list of models that failed a statutory test. The UK and US bodies cannot issue that list. The Office can, and as of early August 2026 had just received the clock.
Ministers wanted the photograph. The UK wanted a lab and a secretariat. The Commission wanted a regulation it had already written. CAISI wanted a brief against foreign rules and a number on DeepSeek. Everyone got what they funded. A shared machine that can stop a model was never on that list.
The UK hired. The US rebranded and kept a small public cash line. The EU wrote a regulation and is now hiring the people who will use it. From 2 August 2026 the Office can ask for files, inspect, and fine. An Apache card does not cancel that. A UK or US eval still cannot.