Bletchley Park, Buckinghamshire · 1–2 November 2023
The world's first AI Safety Summit succeeded because it aimed low — deliberately, publicly, and by design.
Britain wanted a landmark. It scaled back its ambitions for a new global regulator before the doors opened, and its own Technology Secretary said plainly that the summit was not designed to produce a blueprint for global legislation. That modesty is exactly why twenty-eight countries and the European Union — the United States and China among them — signed the same page.
What it was for
The Summit was convened by the United Kingdom to identify next steps for the safe development of frontier AI. Not to regulate it. Not to write law. Not to create a global agency. To get the governments and the laboratories into the same building and establish that the risk was real enough to talk about — and to agree what to call it.
That sounds unambitious now. At the time it was not obvious it was achievable at all.
Two kinds of AI: frontier models with broad capability, and narrow AI with dangerous specific capability — bioengineering being the example everyone reached for. And two kinds of risk: misuse, and loss of control.
That 2×2 is still the frame the entire safety debate runs on. It was set in a country house over two days.
Before the summit there was serious talk of an IPCC-style global body for AI. London reportedly scaled that back amid a perceived lack of enthusiasm from the countries who would have had to join it.
The Declaration ended up resolving to support a research network instead — wording that commits nobody to build anything.
Michelle Donelan, the Technology Secretary, said outright that the summit was not designed to produce a blueprint for global legislation — it was designed to forge a path ahead and get a better handle on the risks of frontier AI.
Governments rarely say the quiet part. Saying it is arguably why it worked.
What came out of it
Strip away the photography and the Musk interview and four concrete things left Bletchley Park. Two are still alive today. Select any one.
Who was there
Roughly one hundred and fifty representatives — governments, the frontier laboratories, academia and civil society — from twenty-eight countries and the European Union. King Charles III addressed the summit by video, urging international collaboration against what he called the significant risks of unchecked development.
And then the part the official record is quieter about: most heads of government did not attend.
US Vice President Kamala Harris. European Commission President Ursula von der Leyen. UN Secretary-General António Guterres. China sent a vice-ministerial delegation — and signed. Italy's Giorgia Meloni was among the only serving world leaders to appear alongside the host.
The people actually building the systems under discussion: OpenAI's Sam Altman, Google DeepMind's Demis Hassabis, Anthropic's Dario Amodei, and Elon Musk — who stayed for a much-covered on-stage conversation with Sunak after the summit closed.
Biden. Macron. Scholz. Trudeau. For a summit billed as a landmark moment for humanity, the absence of the G7 was the story the UK press could not quite let go — and it is a fair measure of how much political capital AI safety commanded in late 2023.
Police patrolled a temporary secure perimeter around the wartime complex. Beyond it, a small group from Pause AI held placards calling for a halt to training runs more powerful than GPT-4. The museum's usual visitors — pensioners and school parties — were displaced for two days.
The composition mattered more than the attendance. Bletchley was the first time the people who build frontier systems and the people who might regulate them were put in a room and made to agree on a vocabulary. That had not happened before, and it has not happened in the same way since.
Honestly
A historical resource that only reports the communiqué is a press release with a date on it. The Summit drew serious, well-argued objections, and several of them have aged well.
The strongest criticism: the agenda privileged long-horizon frontier risk — catastrophe, loss of control — over harms already documented and measurable. Bias in hiring and lending algorithms. Discriminatory outcomes with empirical evidence behind them. Those got a clause; the existential got the roundtables.
Civil society was represented, but thinly relative to industry. A summit about the risks AI poses to people was attended overwhelmingly by governments and by the companies building it.
General commitments to safe, secure and trustworthy systems, with nothing enforceable attached. No thresholds, no penalties, no test. The safety testing agreement was announced with the details left light, and light they largely stayed.
The summit served a domestic purpose too: positioning post-Brexit Britain as a convening power between Washington and Brussels. That does not make the outcome less real, but it explains the urgency, the venue and the timing.
All of that can be true at once. Bletchley was a piece of soft-power theatre with a real document at the end of it, an agenda skewed towards the risks the loudest people cared about, and still the most productive two days of AI diplomacy anyone has managed. History is usually like this.
The venue
Nothing about the location was accidental. Bletchley Park is where British and Allied codebreakers broke Enigma during the Second World War, where Alan Turing worked, and where the machines that became modern computing were built. It is, as the government kept saying, the birthplace of computer science.
The argument the venue was making, without anyone having to make it out loud: this country has done this before. A technology that could decide the fate of nations, an international effort, a secret kept and a war shortened. Come and sit in the room where that happened, and take the next one seriously.
Bletchley's wartime achievement was a closed, classified, national programme. The Declaration signed there argued for open international scientific collaboration. Choosing a monument to secrecy as the setting for a plea for transparency is a choice with some irony in it.
The man who asked whether machines can think, prosecuted for being gay by the country he had served, dead at 41. Every AI summit invoking Bletchley invokes him, and it is worth remembering what the British state did to him while it was benefiting from his work.
The site is run by the Bletchley Park Trust and is open to the public. The summit was a two-day interruption to the school parties. You can go and stand where the Declaration was agreed, which is not something you can say of most diplomacy.
What happened next
Donelan announced the sequels before Bletchley had even finished: South Korea in six months, France in a year. Both happened. Neither repeated it.
Fifteen months from “safety” to “action”. Read the three titles in order and you have the whole arc of international AI politics without needing to read a word of the communiqués. Whether Bletchley was the start of something or the peak of it is still, genuinely, an open question.
About this resource
This page is maintained by Matthew Blakemore, a member of the BSI and ISO artificial intelligence committees and sub-editor of ISO/IEC 8183. Bletchley agreed that frontier risk needed shared scientific understanding and risk-based policy. The standards committees are where a good deal of that turned into text — years later, in rooms with no photographers in them.
The summit set the vocabulary. Turning “safe, secure and trustworthy” into something an organisation can actually be assessed against is what the standards do, and that is the day job.
Questions
The world's first international summit on artificial intelligence safety, held at Bletchley Park in Buckinghamshire on 1–2 November 2023. It was convened by the United Kingdom government under Prime Minister Rishi Sunak to identify next steps for the safe development of frontier AI, and brought together around 150 representatives from 28 countries and the European Union — governments, the frontier AI laboratories, academics and civil society.
Its headline output was the Bletchley Declaration, agreed on the first day and signed by every country represented, including both the United States and China. The Declaration in full ›
US Vice President Kamala Harris, European Commission President Ursula von der Leyen, UN Secretary-General António Guterres, Italian Prime Minister Giorgia Meloni, and a vice-ministerial delegation from China. From industry: OpenAI's Sam Altman, Google DeepMind's Demis Hassabis, Anthropic's Dario Amodei and Elon Musk. King Charles III addressed the summit by video.
Notably absent: Biden, Macron, Scholz and Trudeau. Meloni was among the only serving world leaders to attend alongside the host, which tells you something about how much political capital AI safety commanded in late 2023.
Four things. The Bletchley Declaration, agreed on 1 November by 28 countries and the EU. The UK AI Safety Institute, the first state body established to test frontier models. An agreement on 2 November to support an independent and inclusive “State of the Science” report, which became the International AI Safety Report. And an agreement that governments would receive early access to frontier models for safety testing before deployment — announced with the details left light.
Two further summits were also announced: South Korea within six months, and France within a year. Both happened.
Symbolism, and deliberate symbolism. Bletchley Park is where British and Allied codebreakers broke the Enigma cipher during the Second World War, where Alan Turing worked, and where the machines that became modern computing were built. The UK government repeatedly called it the birthplace of computer science.
The argument the venue made without anyone having to say it: Britain has faced a nation-defining technology before, and international cooperation is how it was handled. There is some irony in choosing a monument to state secrecy as the setting for a declaration about open scientific collaboration.
By its own stated aims, yes — and its stated aims were deliberately modest. Technology Secretary Michelle Donelan said outright that it was not designed to produce a blueprint for global legislation, but to forge a path ahead and get a better handle on frontier risk. Judged against that, it delivered: a signed declaration, an institute, a report and a vocabulary that is still in use.
Judged against what many hoped for — binding rules, a global agency, enforceable testing — it delivered none of it, and the ambition for an IPCC-style body was reportedly scaled back before the summit even opened. The honest reading is that it succeeded because it aimed low. Had it pushed for binding rules, China would not have signed and neither would the United States.
The most substantial criticism was that it privileged speculative long-horizon risk — catastrophe, loss of control — over harms already documented and measurable, such as bias in hiring and lending algorithms and the amplification of misinformation. Those got a clause; the existential got the roundtables.
Others noted that civil society was thinly represented next to industry, that no enforceable mechanism emerged, and that the summit served a British diplomatic purpose in positioning post-Brexit Britain as a convening power between Washington and Brussels. All of those can be true while it still being the most productive two days of AI diplomacy anyone has managed.
The UK body announced at the summit and stood up immediately afterwards — the first state institution anywhere built to evaluate the capabilities and risks of frontier AI models directly. The United States announced its own within days, and a network of institutes grew out of the Seoul summit that followed.
It has since been renamed the AI Security Institute, a change of name that is also a change of emphasis, and it is the most durable institutional legacy of the two days at Bletchley.
The Summit is the event: two days, roughly 150 people, roundtables, a chair's summary, a press conference and an on-stage interview with Elon Musk. The Declaration is one of the documents that came out of it — agreed on the first day, about 1,300 words, signed by 28 countries and the EU.
People use the names interchangeably and they are not the same thing. The Summit produced four outputs; the Declaration was one. The Declaration, in detail ›
The Republic of Korea co-hosted the second in Seoul in May 2024, producing the Seoul Declaration and the Frontier AI Safety Commitments under which major developers published frontier safety frameworks. France hosted the third in Paris in February 2025 — renamed the AI Action Summit, with “safety” dropped from the title and the agenda turned to investment and competitiveness.
The United States and the United Kingdom declined to sign the Paris statement. Read the three titles in order — Safety, Safety, Action — and you have the arc of international AI politics in three words.
Nothing direct. No obligation on any company came out of Bletchley. What came out of it was the vocabulary and the direction that the binding instruments then followed: the EU AI Act's treatment of frontier and general-purpose models, the AI Safety Institutes and their evaluations, and the ISO/IEC standards that turn “safe, secure and trustworthy” into something auditable.
The summit will never be enforced against you. The things it started very much will be. The EU AI Act › · ISO/IEC 42001 ›
GOV.UK holds the primary documents: the Bletchley Declaration, published 1 November 2023, and the Chair's Summary of the AI Safety Summit 2023, published 2 November by the UK in its capacity as chair. Both are © Crown copyright under the Open Government Licence v3.0, which means anyone may copy, publish and adapt them with acknowledgement.
Hansard carries the Technology Secretary's statement to the House of Commons on 9 November 2023, which is the fullest official account of what the UK believed it had achieved.
From summit to system
Bletchley agreed that frontier risk needed shared scientific understanding and risk-based policy. Turning that into something your organisation can evidence — to a regulator, an insurer or a customer — is the work the summit pointed at and could not do. That is judgement, and it is what these three do.