AI Policy Wiki
Dashboard

The Bletchley Declaration (AI Safety Summit, 1–2 November 2023)

high confidence · updated 2026-07-26

The declaration agreed by 28 countries and the EU at the UK's Bletchley Park AI Safety Summit. Establishes 'frontier AI' as the object of international coordination, defining it as 'highly capable general-purpose AI models, including foundation models, that could perform a wide variety of tasks' matching or exceeding today's most advanced models, and sets a two-pillar agenda: a shared scientific and evidence-based understanding of risks, and risk-based national policies that may differ by jurisdiction.

Agreed at the AI Safety Summit held at Bletchley Park on 1–2 November 2023, published by the UK Prime Minister's Office, the Foreign, Commonwealth & Development Office, and the Department for Science, Innovation & Technology. See Bletchley Declaration (AI Safety Summit, 2023).

Signatories

Twenty-eight countries plus the European Union: Australia, Brazil, Canada, Chile, China, the European Union, France, Germany, India, Indonesia, Ireland, Israel, Italy, Japan, Kenya, the Kingdom of Saudi Arabia, the Netherlands, Nigeria, the Philippines, the Republic of Korea, Rwanda, Singapore, Spain, Switzerland, Türkiye, Ukraine, the United Arab Emirates, the United Kingdom, and the United States. New Zealand joined the commitment on 23 October 2024.

The inclusion of both China and the United States is the declaration's most-cited political feature, and the reason it is treated as the high-water mark of the summit series before the coalition fragmented.

The frontier-AI definition

The declaration supplies the definition that subsequent instruments build on:

"Particular safety risks arise at the 'frontier' of AI, understood as being those highly capable general-purpose AI models, including foundation models, that could perform a wide variety of tasks - as well as relevant specific narrow AI that could exhibit capabilities that cause harm - which match or exceed the capabilities present in today's most advanced models."

Two features of the drafting matter. The threshold is relative — "match or exceed the capabilities present in today's most advanced models" — so it moves as the frontier moves rather than fixing a capability level. And it reaches beyond general-purpose systems to "relevant specific narrow AI that could exhibit capabilities that cause harm," which keeps narrow but dangerous systems in scope.

The risk account

Risks are attributed to two sources: "potential intentional misuse or unintended issues of control relating to alignment with human intent." The declaration grounds the difficulty in an epistemic claim rather than a capability one — "these issues are in part because those capabilities are not fully understood and are therefore hard to predict" — and names cybersecurity, biotechnology, and disinformation amplification as the domains of particular concern, holding that there is "potential for serious, even catastrophic, harm, either deliberate or unintentional."

Alongside the frontier framing it also records a broad present-harms list: "the protection of human rights, transparency and explainability, fairness, accountability, regulation, safety, appropriate human oversight, ethics, bias mitigation, privacy and data protection," together with "the potential for unforeseen risks stemming from the capability to manipulate content or generate deceptive content." Signatories "affirm the necessity and urgency of addressing them" — text that lets both the frontier-risk and present-harms constituencies read the declaration as endorsing their framing.

Developer responsibility

The declaration places asymmetric responsibility on frontier developers: "actors developing frontier AI capabilities, in particular those AI systems which are unusually powerful and potentially harmful, have a particularly strong responsibility for ensuring the safety of these AI systems, including through systems for safety testing, through evaluations, and by other appropriate measures." It encourages "context-appropriate transparency and accountability on their plans to measure, monitor and mitigate potentially harmful capabilities."

The commitment is hortatory throughout — "encourage," "resolve to," "affirm" — with no obligations, thresholds, or enforcement.

The two-pillar agenda

The declaration's operative content is an agenda with two limbs:

  1. "identifying AI safety risks of shared concern, building a shared scientific and evidence-based understanding of these risks, and sustaining that understanding as capabilities continue to increase."
  2. "building respective risk-based policies across our countries to ensure safety in light of such risks, collaborating as appropriate while recognising our approaches may differ based on national circumstances and applicable legal frameworks."

The division is the declaration's structural achievement and its structural limit: it seeks convergence on the evidence base while expressly permitting divergence on policy. The first limb produced the International AI Safety Report and the AI Safety Institute network; the second is what allowed the EU, US, UK, and China to sign the same text while regulating differently.

The second limb carries the declaration's only gesture toward instruments: it "includes, alongside increased transparency by private actors developing frontier AI capabilities, appropriate evaluation metrics, tools for safety testing, and developing relevant public sector capability and scientific research." Evaluation and testing appear here as national capacities to be built, not as obligations attached to any developer — the commitment to independent testing of specific models came from the separate summit outcomes rather than the declaration itself.

The declaration also commits signatories to "support an internationally inclusive network of scientific research on frontier AI safety" spanning "multilateral, plurilateral and bilateral collaboration," and to "sustain an inclusive global dialogue that engages existing international fora." Its governance framing endorses "a pro-innovation and proportionate governance and regulatory approach."

The closing line — "We look forward to meeting again in 2024" — established the recurring summit format, continued at Seoul (Republic of Korea, May 2024), Paris (France, February 2025), and the AI Impact Summit hosted by India.

Relationships