# Security Level 5 - Complete Documentation > Creating optionality for frontier AI labs to reach SL5 ## About Security Level 5 is a registered 501(c)(3) nonprofit named after the highest security level in RAND's Securing AI Model Weights framework. We bring together over 50 participants including AI lab decision-makers, national security leaders, data center operators, chip providers, security researchers, program managers, and engineers. ### Organization Details - Website: https://sl5.org - Email: info@sl5.org - Founded: June 2026 ### Social Media - Twitter/X: https://x.com/SL5TaskForce - LinkedIn: https://www.linkedin.com/company/securitylevel5/ - Mastodon: https://mastodon.social/@SL5TaskForce --- ## What is Security Level 5? SL5 is the fifth and highest security level defined in RAND's Securing AI Model Weights framework: machine, physical, network, personnel, and supply chain security capable of withstanding priority operations from the most capable nation-state actors. It is the level we are named after, and the one we exist to make reachable. ### Security Domains #### Machine Security Hardware and firmware security recommendations for achieving Security Level 5. Implementable controls for AI accelerators, verified boot, and tamper-proof infrastructure. #### Network Security Network security recommendations for frontier AI development. Inline network encryptors, accelerator interconnect encryption, air-gapped networks, and AI-enhanced cross-domain solutions. #### Physical Security Physical security recommendations for frontier AI development. Two-person integrity, body-worn cameras, eliminating out-of-facility maintenance, side-channel defenses, and component verification. #### Supply Chain Security Supply chain security recommendations for frontier AI development. Architectural isolation, security-critical software review, hardware supply chain auditing, data integrity verification, and continuous red teaming. #### Personnel Security Personnel security recommendations for achieving Security Level 5. Insider threat mitigation, AI agent governance, and industry-adapted vetting frameworks. --- ## Our Mission Artificial General Intelligence (AGI) is on the horizon: many predict that artificial intelligence could advance toward AGI within the next two to five years, potentially followed closely by superintelligence (ASI). We must ensure that these increasingly autonomous systems cannot be manipulated or overtaken by bad actors and nation-state adversaries. The national security stakes have never been higher. > "Create the optionality for frontier AI labs to reach SL5 in the coming years, and to be able to activate it within 3-6 months of choosing to do so." ### Key Statistics - **50+**: Participants across industry and government - **3-6**: Months to activate SL5 after choosing to do so - **5**: Specialized working groups in the technical track --- ## Theory of Change 1. **Convene a multistakeholder working group** - Bring together AI labs, national security leaders, and technical experts 2. **Clarify the threat and map the attack surface** - Identify vulnerabilities and potential attack vectors 3. **Identify the delta between state of the art and SL5** - Assess gaps in current security practices 4. **Prototype technical solutions** - Develop and test solutions for unique AI lab challenges --- ## Core Projects ### Novel Recommendations for SL5 **URL:** https://sl5.org/projects/sl5-novel-recommendations The Novel Recommendations for SL5 provide a practical blueprint for organizations seeking to achieve Security Level 5 for their AI systems. Includes implementable controls with detailed implementation guidance, cost-benefit analyses for each recommendation, and pilot concepts for testing and deploying controls. **Keywords:** SL5 recommendations, security controls, AI security framework --- ### Sensitivity Levels Framework **URL:** https://sl5.org/projects/sensitivity-levels-framework The Sensitivity Levels (SenL) Framework provides a systematic approach to assigning personnel sensitivity levels to AI lab roles based on their access to model weights, critical systems, and sensitive data. The framework helps organizations determine appropriate vetting and controls for each role, establish clear criteria for security requirements, and align security investments with actual risk levels. **Keywords:** SenL framework, personnel security, sensitivity levels, insider threat --- ### Security Level 5 Standard **URL:** https://sl5.org/sl5-standard The Security Level 5 Standard provides a comprehensive risk management framework for achieving the highest level of AI system security. Includes security controls based on NIST 800-53 enhanced for frontier AI, implementation guidance with practical steps for deploying each control, and assessment procedures for verifying control effectiveness. **Keywords:** SL5 standard, security framework, NIST 800-53, security controls --- ### AI705 **URL:** https://sl5.org/projects/ai705 AI705 evaluates every normative requirement in ICD 705 and its Technical Specification against four threat outcomes for frontier AI: weight theft, secret theft, sabotage, and loss of control. Each requirement receives a verdict: it works as written, needs AI-specific modification, does not apply, or leaves a gap that requires additional controls. The result is technical guidance for labs, datacenter operators, colocation providers, facilities teams, and accrediting officials. **Keywords:** ICD 705, SCIF standards, AI datacenter security, physical security --- ### Project MoAT **URL:** https://sl5.org/projects/project-moat Project MoAT (Mock Airgap Training) is Security Level 5's effort to design and build a real datacenter: an exploratory 1-2 MW high-density facility that serves as a test bed for novel interventions, discovering where existing infrastructure is incompatible with high security. The build pairs direct-to-chip liquid cooling, a full basis of design and BIM model, and secure-product procurement (servers, network encryptors, security-aware racks and switches) with internal DCIM tooling that checks every design choice against SL5 controls, then runs the SL5 Standard, AI705, and SenL test plans against the result. **Keywords:** SL5 datacenter, mock datacenter, airgap training, GB300 NVL72, weight enclave --- ## Security Reports The Novel Recommendations for SL5 are organized as focused memos covering five key security domains: ### Machine Security - Novel Recommendations for SL5 **URL:** https://sl5.org/reports/machine-security **PDF:** https://sl5.org/pdfs/SL5_MACHINE-SECURITY-NOVEL-RECOMMENDATIONS.pdf Hardware and firmware security recommendations for achieving Security Level 5. Implementable controls for AI accelerators, verified boot, and tamper-proof infrastructure. **Key Topics:** AI Accelerator Security, Verified Boot, Tamper-Proof Infrastructure, Firmware Security --- ### Personnel Security - Novel Recommendations for SL5 **URL:** https://sl5.org/reports/personnel-security **PDF:** https://sl5.org/pdfs/SL5_PERSONNEL-SECURITY-NOVEL-RECOMMENDATIONS.pdf Personnel security recommendations for achieving Security Level 5. Insider threat mitigation, AI agent governance, and industry-adapted vetting frameworks. **Key Topics:** Insider Threat Mitigation, AI Agent Governance, Vetting Frameworks, Access Controls --- ### Network Security - Novel Recommendations for SL5 **URL:** https://sl5.org/reports/network-security **PDF:** https://sl5.org/pdfs/SL5_NETWORK-SECURITY-NOVEL-RECOMMENDATIONS.pdf Network security recommendations for frontier AI development. Inline network encryptors, accelerator interconnect encryption, air-gapped networks, and AI-enhanced cross-domain solutions. **Key Topics:** Inline Network Encryptors, Accelerator Interconnect Encryption, Air-Gapped Networks, Cross-Domain Solutions --- ### Physical Security - Novel Recommendations for SL5 **URL:** https://sl5.org/reports/physical-security **PDF:** https://sl5.org/pdfs/SL5_PHYSICAL-SECURITY-NOVEL-RECOMMENDATIONS.pdf Physical security recommendations for frontier AI development. Two-person integrity, body-worn cameras, eliminating out-of-facility maintenance, side-channel defenses, and component verification. **Key Topics:** Two-Person Integrity, Body-Worn Cameras, In-Facility Maintenance, Side-Channel Defenses --- ### Supply Chain Security - Novel Recommendations for SL5 **URL:** https://sl5.org/reports/supply-chain-security **PDF:** https://sl5.org/pdfs/SL5_SUPPLY-CHAIN-SECURITY-NOVEL-RECOMMENDATIONS.pdf Supply chain security recommendations for frontier AI development. Architectural isolation, security-critical software review, hardware supply chain auditing, data integrity verification, and continuous red teaming. **Key Topics:** Architectural Isolation, Software Review, Hardware Auditing, Continuous Red Teaming --- ## Tools & Resources ### IL6 Control Catalog **URL:** https://sl5.org/projects/il6-control-catalog The IL6 Control Catalog is an open-source, interactive tool for exploring security controls required for Impact Level 6 systems. Features include searchable database by keyword, family, or requirement, complete control text with implementation guidance, and cross-references between related controls. **Keywords:** IL6 controls, FedRAMP High, DoD security, security catalog --- ### Secure Speech-to-Text **URL:** https://sl5.org/projects/secure-speech-to-text Secure Speech-to-Text is a privacy-first toolkit designed for transcribing sensitive meetings without cloud dependencies. All transcription happens on your device—no data leaves your network. Features include executive summary generation, classified meeting transcription support, and SCIF-compatible documentation. **Keywords:** secure transcription, privacy-first, speech to text, local processing --- ### SenL Role-to-Level Calculator **URL:** https://sl5.org/tools/senl-role-to-level The SenL Role-to-Level Calculator has been superseded by the Sensitivity Levels (SenL) Framework, which contains the current role-to-level guidance and interactive decision tools. The workshop tool remains available for reference: drag roles into SenL columns to capture both today's mapping and a 2028 target mapping. **Keywords:** SenL calculator, sensitivity level tool, AI role classification --- ## Downloadable Documents - [Novel Recommendations for SL5 (PDF)](https://sl5.org/pdfs/SL5_NOVEL-RECOMMENDATIONS.pdf) - [Machine Security Report (PDF)](https://sl5.org/pdfs/SL5_MACHINE-SECURITY-NOVEL-RECOMMENDATIONS.pdf) - [Personnel Security Report (PDF)](https://sl5.org/pdfs/SL5_PERSONNEL-SECURITY-NOVEL-RECOMMENDATIONS.pdf) - [Network Security Report (PDF)](https://sl5.org/pdfs/SL5_NETWORK-SECURITY-NOVEL-RECOMMENDATIONS.pdf) - [Physical Security Report (PDF)](https://sl5.org/pdfs/SL5_PHYSICAL-SECURITY-NOVEL-RECOMMENDATIONS.pdf) - [Supply Chain Security Report (PDF)](https://sl5.org/pdfs/SL5_SUPPLY-CHAIN-SECURITY-NOVEL-RECOMMENDATIONS.pdf) --- ## Team ### Lisa Thiergart - CEO Security Level 5 aims to create the optionality for frontier AI labs to deploy SL5 within 3-6 months from the time point that they choose to. Before joining, Lisa spent two years as research lead at MIRI where she founded and lead the technical governance team. Lisa is a computer scientist with an ML research specialization. ### Guy - Member of Technical Staff Guy leads the Machine Security sub-team. He previously worked in several organizations as a vulnerability researcher, project lead and security engineer as well as software engineering for HPC hardware. ### Luke Sallmen - Chief of Staff Luke previously led a biotech startup and worked in AI operations. He holds a B.S. in Computer Science from Duke University. ### Luis Cosio - Member of Technical Staff Luis Cosio is a Mexico-City based technologist and entrepreneur with 15 years at the intersection of cloud, cybersecurity, and artificial intelligence. He has architected and launched national-scale systems including Mexico's largest e-government project. He is now pursuing an M.S. in AI at Johns Hopkins University while working full-time on AI-safety research and governance. --- ## Working Groups ### Executive Track AI lab decision makers, national security leaders, data center operators, chip providers, and government representatives focused on identifying obstacles and driving action to create optionality for SL5 implementation. ### Technical Track Security researchers, lab security engineering staff, technical AI researchers, along with mission-aligned specialists including technical program managers, hardware engineers, security engineers, and DevOps engineers. **Working Groups:** - Machine security working group - Network security working group - Software security working group - Supply chain security working group - Personnel security working group --- ## Contact Information - Website: https://sl5.org - Email: info@sl5.org - Twitter/X: https://x.com/SL5TaskForce - LinkedIn: https://www.linkedin.com/company/securitylevel5/