Report Aug. 3, 2026

White Paper in collaboration with the Paris Peace Forum to accelerate cybersecurity and AI safety.

By Niharika Chaubey, Pauline Charazac & Charbel-Raphaël Ségerie

A new white paper co-chaired with the Paris Peace Forum finds that for every $400 spent advancing AI capabilities, roughly $1 goes to AI safety and security research, and almost none of it reaches the cyber intersection. Drawing on a year-long consultation across ten countries, it maps who's funding AI-driven cyber risk, and who isn't.

Foreword

This white paper opens the second pillar of the Paris Peace Forum's Integrated Network for Trusted AI in Cyberspace (INTAiC), a global, multistakeholder effort to address gaps in our shared, evidence-based understanding of how advanced artificial intelligence (AI) is being, or could be, misused by adversaries in cyberspace. Where the initiative's parallel line of effort seeks to examine how such misuse — already occurring "in the wild" — can be reported, this one turns to the question that sits immediately upstream: who produces the public-interest research that anticipates what these systems make possible before misuse occurs, who funds that work, and why the current answer falls short of the need. Our critical infrastructure — from energy grids to hospitals, financial systems and communications — now rests on lines of code, and what it takes to attack that code is changing faster than anyone can track. On that front, we are still moving in fog.

It draws on a structured consultation process conducted jointly by the Paris Peace Forum and the Centre pour la Sécurité de l'IA (CeSIA) with researchers and funders across ten countries, opened by a thematic roundtable convened in Paris in February 2026, alongside the second annual conference of the International Association for Safe & Ethical AI. Their contributions, quoted anonymously throughout these pages, ground the paper's findings in the daily experience of those who conduct and support this research.

This effort does not duplicate what exists — it lifts the fog in which today's investments are made. It builds on the research priorities articulated by the scientific community, on the work of AI safety and security institutes, and on the programmes of the philanthropic and public funders discussed in these pages. It acts where no funder, agency, or lab can act alone: aligning fragmented investments with the questions policymakers most need answered.

As the workstream's co-leads, the Paris Peace Forum and CeSIA are grateful to every respondent and participant whose insight informed this document. INTAiC remains open to all stakeholders who share the conviction that trusted evidence on AI-enabled cyber risk is a public good worth funding together.

Charbel-Raphaël Segerie, Executive Director, CeSIA

Pablo Rice, Head of Programme, Paris Peace Forum

Executive Summary

This white paper examines what keeps public-interest researchers, and the funders behind them, from anticipating AI-enabled cyber risks early enough for governments to act. We ask how investment in independent research at the intersection of AI security and cybersecurity is currently distributed, where the structural obstacles lie, and what those obstacles mean for aligning investments and organising research programmes more effectively.

The paper approaches the evidence gap in AI-cybersecurity from the angle of research infrastructure. In under a month, Claude Mythos identified more than a thousand serious vulnerabilities in the software we all use every day — some of which had gone unnoticed for more than twenty years despite rigorous human review. A year ago, such discoveries were the preserve of a handful of states and highly specialised groups. That scarcity is ending, and the research that would tell governments what comes next is nobody's budget line. Research investment at this intersection remains fragmented across governments, philanthropies, and borders. No shared map exists of what is funded, what is not, and where the most consequential gaps lie. Established funding instruments were not designed for a field that needs both long-term capacity and answers within months.

Independent evaluation of AI cyber capabilities, in particular, emerges as a precondition for any credible governance framework. For most governments, the exposure is double: their infrastructure faces threats born of technologies developed beyond their borders, and they depend on those same technologies, and on their developers' goodwill, to understand the risk, let alone to defend against it. Findings cannot be compared, challenged, or carried forward when every team evaluates on its own benchmarks, its own model access, and its own compute. The constraint this paper identifies is not so much a shortage of money as an architecture of allocation: for every four hundred dollars invested each year in advancing AI capabilities, roughly one goes to philanthropically funded AI safety and security research, and almost none of that reaches the cyber intersection.

The paper closes with what this workstream proposes to do about it. The consultation that grounds these pages has opened a standing dialogue between researchers and the funders who support them. The next step is turning this dialogue into a joint research roadmap to guide public and philanthropic funding toward shared goals. The first results of that work will be brought to the ninth Paris Peace Forum in November 2026. The priorities it serves are being defined now, and they will bear the mark of those who help define them. AI can become an instrument of cyberdefense at least as powerful as of attack. It will not happen by default, and neither will the evidence base that makes it possible.

The essentials of AI safety, every two weeks.

Get our selection of AI safety analysis and news in your inbox every two weeks.