Bletchley Park, Buckinghamshire · 1–2 November 2023

Most world leaders
didn't come.
It worked anyway.

The world's first AI Safety Summit succeeded because it aimed low — deliberately, publicly, and by design.

Britain wanted a landmark. It scaled back its ambitions for a new global regulator before the doors opened, and its own Technology Secretary said plainly that the summit was not designed to produce a blueprint for global legislation. That modesty is exactly why twenty-eight countries and the European Union — the United States and China among them — signed the same page.

2 days1–2 November 2023
The first of its kind
~150Representatives, from
28 countries and the EU
4Things that actually
came out of it
1G7 leader besides the host
who turned up

What it was for

A narrow question, asked on purpose.

The Summit was convened by the United Kingdom to identify next steps for the safe development of frontier AI. Not to regulate it. Not to write law. Not to create a global agency. To get the governments and the laboratories into the same building and establish that the risk was real enough to talk about — and to agree what to call it.

That sounds unambitious now. At the time it was not obvious it was achievable at all.

The frame it set

Two kinds of AI: frontier models with broad capability, and narrow AI with dangerous specific capability — bioengineering being the example everyone reached for. And two kinds of risk: misuse, and loss of control.

That 2×2 is still the frame the entire safety debate runs on. It was set in a country house over two days.

The ambition it dropped

Before the summit there was serious talk of an IPCC-style global body for AI. London reportedly scaled that back amid a perceived lack of enthusiasm from the countries who would have had to join it.

The Declaration ended up resolving to support a research network instead — wording that commits nobody to build anything.

The honesty about it

Michelle Donelan, the Technology Secretary, said outright that the summit was not designed to produce a blueprint for global legislation — it was designed to forge a path ahead and get a better handle on the risks of frontier AI.

Governments rarely say the quiet part. Saying it is arguably why it worked.

The counter-intuitive lesson of Bletchley is that it achieved something precisely by refusing to attempt the thing everyone wanted it to attempt. Had the UK pushed for binding rules or a new agency, China would not have signed, the United States would not have signed, and there would be nothing to write a history of.

What came out of it

Four things, and one of them still runs.

Strip away the photography and the Musk interview and four concrete things left Bletchley Park. Two are still alive today. Select any one.

A summit's output is whatever is still standing three years later. On that test, Bletchley did better than most.

Who was there

About 150 people, and a conspicuous number of empty chairs.

Roughly one hundred and fifty representatives — governments, the frontier laboratories, academia and civil society — from twenty-eight countries and the European Union. King Charles III addressed the summit by video, urging international collaboration against what he called the significant risks of unchecked development.

And then the part the official record is quieter about: most heads of government did not attend.

The governments

US Vice President Kamala Harris. European Commission President Ursula von der Leyen. UN Secretary-General António Guterres. China sent a vice-ministerial delegation — and signed. Italy's Giorgia Meloni was among the only serving world leaders to appear alongside the host.

The laboratories

The people actually building the systems under discussion: OpenAI's Sam Altman, Google DeepMind's Demis Hassabis, Anthropic's Dario Amodei, and Elon Musk — who stayed for a much-covered on-stage conversation with Sunak after the summit closed.

Who wasn't there

Biden. Macron. Scholz. Trudeau. For a summit billed as a landmark moment for humanity, the absence of the G7 was the story the UK press could not quite let go — and it is a fair measure of how much political capital AI safety commanded in late 2023.

Outside the gate

Police patrolled a temporary secure perimeter around the wartime complex. Beyond it, a small group from Pause AI held placards calling for a halt to training runs more powerful than GPT-4. The museum's usual visitors — pensioners and school parties — were displaced for two days.

The composition mattered more than the attendance. Bletchley was the first time the people who build frontier systems and the people who might regulate them were put in a room and made to agree on a vocabulary. That had not happened before, and it has not happened in the same way since.

Honestly

The criticism, which was substantial.

A historical resource that only reports the communiqué is a press release with a date on it. The Summit drew serious, well-argued objections, and several of them have aged well.

It chose the speculative over the actual

The strongest criticism: the agenda privileged long-horizon frontier risk — catastrophe, loss of control — over harms already documented and measurable. Bias in hiring and lending algorithms. Discriminatory outcomes with empirical evidence behind them. Those got a clause; the existential got the roundtables.

The people affected weren't in the room

Civil society was represented, but thinly relative to industry. A summit about the risks AI poses to people was attended overwhelmingly by governments and by the companies building it.

It produced no mechanism

General commitments to safe, secure and trustworthy systems, with nothing enforceable attached. No thresholds, no penalties, no test. The safety testing agreement was announced with the details left light, and light they largely stayed.

It was, in part, a British project

The summit served a domestic purpose too: positioning post-Brexit Britain as a convening power between Washington and Brussels. That does not make the outcome less real, but it explains the urgency, the venue and the timing.

All of that can be true at once. Bletchley was a piece of soft-power theatre with a real document at the end of it, an agenda skewed towards the risks the loudest people cared about, and still the most productive two days of AI diplomacy anyone has managed. History is usually like this.

The venue

Why a country house in Buckinghamshire.

Nothing about the location was accidental. Bletchley Park is where British and Allied codebreakers broke Enigma during the Second World War, where Alan Turing worked, and where the machines that became modern computing were built. It is, as the government kept saying, the birthplace of computer science.

The argument the venue was making, without anyone having to make it out loud: this country has done this before. A technology that could decide the fate of nations, an international effort, a secret kept and a war shortened. Come and sit in the room where that happened, and take the next one seriously.

The symbolism cut both ways

Bletchley's wartime achievement was a closed, classified, national programme. The Declaration signed there argued for open international scientific collaboration. Choosing a monument to secrecy as the setting for a plea for transparency is a choice with some irony in it.

Turing is the ghost in the room

The man who asked whether machines can think, prosecuted for being gay by the country he had served, dead at 41. Every AI summit invoking Bletchley invokes him, and it is worth remembering what the British state did to him while it was benefiting from his work.

It is a museum, and it stayed one

The site is run by the Bletchley Park Trust and is open to the public. The summit was a two-day interruption to the school parties. You can go and stand where the Declaration was agreed, which is not something you can say of most diplomacy.

What happened next

Two more summits, and a change of subject.

Donelan announced the sequels before Bletchley had even finished: South Korea in six months, France in a year. Both happened. Neither repeated it.

WhenWhat happenedThe word
Nov 2023 Bletchley Park. The AI Safety Summit. The Declaration, the AI Safety Institute, the State of the Science report, the testing agreement. Twenty-eight countries and the EU, including the US and China. Safety
May 2024 Seoul. The AI Seoul Summit, co-hosted with the Republic of Korea. Kept the promise. Produced the Seoul Declaration and the Frontier AI Safety Commitments, under which major developers published frontier safety frameworks. The network of AI Safety Institutes began to form. Safety
Feb 2025 Paris. The AI Action Summit. Safety left the title. The agenda turned to investment, adoption and competitiveness. The United States and the United Kingdom declined to sign the final statement — the two countries that had convened and championed the process. Action

Fifteen months from “safety” to “action”. Read the three titles in order and you have the whole arc of international AI politics without needing to read a word of the communiqués. Whether Bletchley was the start of something or the peak of it is still, genuinely, an open question.

Matthew Blakemore, AI standards practitioner and member of the BSI and ISO artificial intelligence committees, speaking on stage at an AI summit

About this resource

Matthew Blakemore

This page is maintained by Matthew Blakemore, a member of the BSI and ISO artificial intelligence committees and sub-editor of ISO/IEC 8183. Bletchley agreed that frontier risk needed shared scientific understanding and risk-based policy. The standards committees are where a good deal of that turned into text — years later, in rooms with no photographers in them.

The summit set the vocabulary. Turning “safe, secure and trustworthy” into something an organisation can actually be assessed against is what the standards do, and that is the day job.

  • CommitteesMember, BSI and ISO artificial intelligence committees, including BSI ART/1
  • StandardSub-editor, ISO/IEC 8183 — Data life cycle framework
  • AdvisoryInnovate UK BridgeAI programme
  • CompanyChief Executive, AI Caramba!
  • FrameworkOriginator of the Snakes and Ladders AI Framework™
  • BookSnakes and Ladders: A Leader's Playbook for AI Strategy, Governance and Risk (forthcoming)

Questions

The AI Safety Summit, answered.

What was the AI Safety Summit?

The world's first international summit on artificial intelligence safety, held at Bletchley Park in Buckinghamshire on 1–2 November 2023. It was convened by the United Kingdom government under Prime Minister Rishi Sunak to identify next steps for the safe development of frontier AI, and brought together around 150 representatives from 28 countries and the European Union — governments, the frontier AI laboratories, academics and civil society.

Its headline output was the Bletchley Declaration, agreed on the first day and signed by every country represented, including both the United States and China. The Declaration in full ›

Who attended the AI Safety Summit?

US Vice President Kamala Harris, European Commission President Ursula von der Leyen, UN Secretary-General António Guterres, Italian Prime Minister Giorgia Meloni, and a vice-ministerial delegation from China. From industry: OpenAI's Sam Altman, Google DeepMind's Demis Hassabis, Anthropic's Dario Amodei and Elon Musk. King Charles III addressed the summit by video.

Notably absent: Biden, Macron, Scholz and Trudeau. Meloni was among the only serving world leaders to attend alongside the host, which tells you something about how much political capital AI safety commanded in late 2023.

What was agreed at the AI Safety Summit?

Four things. The Bletchley Declaration, agreed on 1 November by 28 countries and the EU. The UK AI Safety Institute, the first state body established to test frontier models. An agreement on 2 November to support an independent and inclusive “State of the Science” report, which became the International AI Safety Report. And an agreement that governments would receive early access to frontier models for safety testing before deployment — announced with the details left light.

Two further summits were also announced: South Korea within six months, and France within a year. Both happened.

Why was it held at Bletchley Park?

Symbolism, and deliberate symbolism. Bletchley Park is where British and Allied codebreakers broke the Enigma cipher during the Second World War, where Alan Turing worked, and where the machines that became modern computing were built. The UK government repeatedly called it the birthplace of computer science.

The argument the venue made without anyone having to say it: Britain has faced a nation-defining technology before, and international cooperation is how it was handled. There is some irony in choosing a monument to state secrecy as the setting for a declaration about open scientific collaboration.

Was the AI Safety Summit a success?

By its own stated aims, yes — and its stated aims were deliberately modest. Technology Secretary Michelle Donelan said outright that it was not designed to produce a blueprint for global legislation, but to forge a path ahead and get a better handle on frontier risk. Judged against that, it delivered: a signed declaration, an institute, a report and a vocabulary that is still in use.

Judged against what many hoped for — binding rules, a global agency, enforceable testing — it delivered none of it, and the ambition for an IPCC-style body was reportedly scaled back before the summit even opened. The honest reading is that it succeeded because it aimed low. Had it pushed for binding rules, China would not have signed and neither would the United States.

What was the criticism of the AI Safety Summit?

The most substantial criticism was that it privileged speculative long-horizon risk — catastrophe, loss of control — over harms already documented and measurable, such as bias in hiring and lending algorithms and the amplification of misinformation. Those got a clause; the existential got the roundtables.

Others noted that civil society was thinly represented next to industry, that no enforceable mechanism emerged, and that the summit served a British diplomatic purpose in positioning post-Brexit Britain as a convening power between Washington and Brussels. All of those can be true while it still being the most productive two days of AI diplomacy anyone has managed.

What is the AI Safety Institute?

The UK body announced at the summit and stood up immediately afterwards — the first state institution anywhere built to evaluate the capabilities and risks of frontier AI models directly. The United States announced its own within days, and a network of institutes grew out of the Seoul summit that followed.

It has since been renamed the AI Security Institute, a change of name that is also a change of emphasis, and it is the most durable institutional legacy of the two days at Bletchley.

What is the difference between the Summit and the Bletchley Declaration?

The Summit is the event: two days, roughly 150 people, roundtables, a chair's summary, a press conference and an on-stage interview with Elon Musk. The Declaration is one of the documents that came out of it — agreed on the first day, about 1,300 words, signed by 28 countries and the EU.

People use the names interchangeably and they are not the same thing. The Summit produced four outputs; the Declaration was one. The Declaration, in detail ›

What happened to the AI safety summits after Bletchley?

The Republic of Korea co-hosted the second in Seoul in May 2024, producing the Seoul Declaration and the Frontier AI Safety Commitments under which major developers published frontier safety frameworks. France hosted the third in Paris in February 2025 — renamed the AI Action Summit, with “safety” dropped from the title and the agenda turned to investment and competitiveness.

The United States and the United Kingdom declined to sign the Paris statement. Read the three titles in order — Safety, Safety, Action — and you have the arc of international AI politics in three words.

Does the AI Safety Summit have any effect on my organisation?

Nothing direct. No obligation on any company came out of Bletchley. What came out of it was the vocabulary and the direction that the binding instruments then followed: the EU AI Act's treatment of frontier and general-purpose models, the AI Safety Institutes and their evaluations, and the ISO/IEC standards that turn “safe, secure and trustworthy” into something auditable.

The summit will never be enforced against you. The things it started very much will be. The EU AI Act › · ISO/IEC 42001 ›

Where can I read the official record?

GOV.UK holds the primary documents: the Bletchley Declaration, published 1 November 2023, and the Chair's Summary of the AI Safety Summit 2023, published 2 November by the UK in its capacity as chair. Both are © Crown copyright under the Open Government Licence v3.0, which means anyone may copy, publish and adapt them with acknowledgement.

Hansard carries the Technology Secretary's statement to the House of Commons on 9 November 2023, which is the fullest official account of what the UK believed it had achieved.

From summit to system

The photographs were the easy part.

Bletchley agreed that frontier risk needed shared scientific understanding and risk-based policy. Turning that into something your organisation can evidence — to a regulator, an insurer or a customer — is the work the summit pointed at and could not do. That is judgement, and it is what these three do.