The Institute for AI Policy and Strategy (IAPS) is a nonpartisan policy-research institute that produces research on the implications of AI, from current advanced models to potential AGI and superintelligence, positioned at the intersection of AI, national security, and geopolitics (Source: https://www.iaps.ai/). Its Frontier Security research program concentrates on autonomous-cyber-agent policy, with Brianna Rosen serving as Director of Research and Jam Kraprayoon as Senior Researcher.
Overview
IAPS describes its purpose as equipping policymakers and industry leaders to protect innovation while navigating high-magnitude risks and opportunities arising from advanced AI (Source: https://www.iaps.ai/). Its stated activities are conducting forward-looking policy research (in areas including preparedness, information and supply chain security, and international coordination), cultivating policy talent, and providing insights to stakeholders across Congress, the executive branch, industry, academia, and civil society (Source: https://www.iaps.ai/). The organization operates on a remote-first basis with a presence in Washington, D.C. (Source: https://www.iaps.ai/fellowship).
IAPS organizes its work around three focus areas (Source: https://www.iaps.ai/):
- Frontier Security — interventions addressing AI-related threats to national defense and security, with current sub-topics covering cyber and autonomy (the implications of autonomous systems for the cyber offense-defense balance), R&D for AI security and assurance, and preparedness for AI-powered threats to national security and public safety.
- Compute Policy — interventions and strategic considerations for managing access to large-scale AI compute, including technical mechanisms for enforcing U.S. export controls, hardware-enabled mechanisms, and information and supply chain security.
- International Strategy — trends in international coordination and competition around advanced AI, with emphasis on U.S.-China competition and on global AI state capacity, including AI Safety Institutes and other agencies.
Activities
IAPS researchers have published on the threat model posed by autonomous cyber-agents and on associated US policy options. In Cyberwar's New Frontier (Foreign Affairs, April 16 2026), Rosen and Kraprayoon set out the autonomous-cyber-agent threat model, a rogue-agent failure mode, and a five-part US policy menu: intelligence designation; mandatory frontier-lab incident reporting; CISA workforce restoration paired with DARPA programs; know-your-customer requirements plus cloud-compute monitoring; and a US-China bilateral critical-infrastructure pact alongside an update to the UN GGE/OEWG processes (Rosen + Kraprayoon, *Cyberwar's New Frontier* (Foreign Affairs, April 16 2026)).
Among the research IAPS features prominently are Highly Autonomous Cyber-Capable Agents, which examines what follows when AI systems can plan, execute, and sustain sophisticated cyber operations on their own, and Location Verification for AI Chips, which proposes a mechanism that works on existing chips to verify their location in support of export-control enforcement while remaining privacy-preserving and reasonably tamper-proof (Highly Autonomous Cyber-Capable Agents: Anticipating Capabilities, Tactics, and Strategic Implications (IAPS, March 2026); Location Verification for AI Chips (IAPS, issue brief May 2025)).
The cyber report (March 11, 2026, led by Jam Kraprayoon with Shaun Ee, Brianna Rosen and others) introduces the term HACCA for "AI systems capable of autonomously conducting multi-stage cyber campaigns at a level comparable to today's top criminal hacking groups or state-affiliated threat actors," sets out five tactics by which such agents could sustain themselves in the wild — "from autonomous infrastructure setup and credential harvesting to detection evasion and adaptive shutdown avoidance" — and flags two tail risks: inadvertent cyber-nuclear escalation and "sustained loss of control over rogue HACCA deployments" (Highly Autonomous Cyber-Capable Agents: Anticipating Capabilities, Tactics, and Strategic Implications (IAPS, March 2026)).
The chip-location brief (May 2025, by Asher Brass, from a 2024 report with Onni Aarne) proposes using chips' existing cryptographic attestation together with round-trip latency to a trusted landmark server, bounding distance by the speed of light — a 1-millisecond response places a chip within 93 miles. It estimates a firmware update under $1 million and 100–500 landmarks at about $25,000 each per year, and argues Nvidia could recoup the cost "if it enabled the sale of just 500 additional controlled AI chips." Its stated policy direction is toward looser rather than tighter rules, since better visibility would reduce "the need for blunt export controls covering many countries" (Location Verification for AI Chips (IAPS, issue brief May 2025)). The compute-policy and international-strategy lines map to these topics, covering export-control enforcement, hardware-enabled mechanisms, supply chain security, and the AI Safety Institute landscape (Source: https://www.iaps.ai/).
IAPS also runs the AI Policy Fellowship, a fully funded three-month talent-development program for professionals from policy and technical backgrounds, structured around an independent policy project with a mentor drawn from the IAPS team or its network (Source: https://www.iaps.ai/fellowship). The program pairs a two-week in-person residency in Washington, D.C. with remote or in-person participation for the remainder; Senior Fellows receive a $22,000 stipend and Fellows receive $15,000, and IAPS states it expects to select roughly 30 fellows per cohort (Source: https://www.iaps.ai/fellowship). IAPS reports that fellowship alumni have moved into roles in government, industry, and think tanks including RAND, the Institute for Progress, and the Johns Hopkins Center for Health Security (Source: https://www.iaps.ai/fellowship).
Rosen holds a parallel appointment at the Blavatnik School of Government's Oxford Cyber and Technology Policy Programme.
Leadership and structure
IAPS lists Jennifer Marron as Executive Director, with Amanda El-Dakhakhni as Director, Zoe Williams as Managing Director, Renan Araujo as Director of Programs, and Matthew Fargo as Head of Operations (Source: https://www.iaps.ai/our-team). Research is organized under area leads: Brianna Rosen is Research Director for Frontier Security, Nick Yap is Deputy Director on the same team, Diego Duchi (Associate Director) and Onni Aarne (Research Lead) lead Compute Policy, and Karson Elmgren is Research Manager for International Strategy (Source: https://www.iaps.ai/our-team). Jam Kraprayoon is a Senior Researcher on the Frontier Security team (Source: https://www.iaps.ai/our-team). Peter Wildeford, listed as a co-founder of IAPS, is an advisor to the organization (Source: https://www.iaps.ai/our-team).
Funding and governance
IAPS is an initiative of Rethink Priorities, a California-based 501(c)(3) think tank, from which it receives fiscal and operational support while setting its own research agenda; it is subject to Rethink Priorities' transparency policy and accountable to its Board of Directors (Source: https://www.iaps.ai/governance-history-independence-funding). IAPS states that its work is funded primarily by a mix of philanthropic grants and individual gifts, including support to date from Open Philanthropy, the Survival and Flourishing Fund, allied government, and individual donors (Source: https://www.iaps.ai/governance-history-independence-funding).
IAPS describes intellectual independence as a core value, stating that editorial control rests with its team, that staff and fellows set research agendas and methodologies, and that publications reflect the authors' analyses rather than positions of IAPS, its donors, partners, or any government (Source: https://www.iaps.ai/governance-history-independence-funding). It states that it is nonpartisan, does not lobby or advocate on behalf of any donor or client, and conducts any permissible policy advocacy within the limits applicable to U.S. 501(c)(3) public charities (Source: https://www.iaps.ai/governance-history-independence-funding).
Relationships
- supports: AI and Cybersecurity, Autonomous cyber-agents, AI Autonomy Risk
- members: Brianna Rosen, Jam Kraprayoon
- related: International AI Safety Institute Network (INSAI / AISIN) (frontier-security peer ecosystem); RAND Corporation (peer think-tank on cyber-AI risk)