Containment standards
Write the minimum any sandboxed evaluation should run under. This track is for whoever can propose a control matrix by attack phase, or package mitigations so that a third party can verify they are met.
A weekend to turn the first incidents in which an AI system acted on its own against a third party into material that is useful to whoever has to respond.
Applications to the Bogotá hub close at midnight on Sunday 6 September, Colombian time.
There are already documented cases in which an AI system attacked a third party on its own. In July 2026, models that were being evaluated broke out of their test environment and chained failures until they reached Hugging Face's production infrastructure. It was reported by OpenAI and by Hugging Face separately. No law obliged them to do it.
When something like that happens, almost nobody has the procedure to hand: it is not written down how to contain it, nor how to reconstruct what failed, nor what a regulator can demand of the provider, nor how to tell the story without exaggerating or playing it down.
The sprint exists to fill that gap with concrete pieces. Five tracks run in parallel over three days. Each team delivers something someone else can use: a standard, a test bench, a questionnaire for a regulator, a tabletop exercise. After the weekend the work is graded by judges who were not in the room. Feedback arrives in writing and the report is published under your name. Apart Research and CeSIA convene the sprint worldwide; we open the in-person hub in Bogotá.
Each team picks one. In the form you tell us which one appeals to you, and that tells us what profiles will be in the room and which mentors we still need to invite. Apart publishes the detail of each track in the sprint call.
Write the minimum any sandboxed evaluation should run under. This track is for whoever can propose a control matrix by attack phase, or package mitigations so that a third party can verify they are met.
Reconstruct what happened and where the monitoring failed. What is wanted here: questions someone can actually answer, checks that can be run tomorrow, and causal explanations that predict something.
Draft information requests a regulator could use almost unedited, stress-test the reporting systems that already exist, and point at the legal gaps they leave behind.
Audit how the press covered the incident and build the kit for communicating the next one. What counts here is staying anchored to the record of what actually happened.
Any other angle on the same problem. The condition is the usual one: an artefact someone can use and an honest sentence about how far what it shows really goes.
Working three days straight is easier in company than alone at home. That is why we open a room in Bogotá for the whole weekend.
The venue is confirmed in the coming days. We announce it by email to whoever is selected and through the WhatsApp group.
We cover meals for all three days. If you are coming from another city, we also cover lodging for the weekend.
We cover part of the teams' compute costs. The figure is confirmed before applications close.
People who work in incident response, offensive security and regulation come through the hub over the weekend.
A workspace for the whole weekend, with tables for teams and somewhere to plug in.
Teams form on Friday night, in the room. Plenty of people arrive alone and leave with a team.
The hub has a capacity, so there is a selection process. You apply through the form and we let you know by email.
Over the weekend, people who work on the subjects of the five tracks come through the room. Some open with a short talk. All of them sit down with the teams to support whatever they are building.
If you work in incident response, offensive security, regulation or risk communication and you would like to give a talk or accompany a team, write to us at [email protected].

AI governance consultant for several organisations. Member of the OECD expert group and head of the AI Control group at AIS Colombia. As a Winter Fellow at GovAI she researched the European regulation of loss-of-control scenarios.

Member of the technical team at Security Level 5, an initiative focused on protecting advanced AI systems from state adversaries and loss of control. Co-author of the SL5 standard. He mentors a SPAR research project and a MATS stream on datacenter security.
Engineering PhD student at Universidad de los Andes, where she researches multi-agent systems. First author of the IEEE Transactions on Artificial Intelligence paper that sets out how to measure cooperative resilience: whether a group of agents keeps the common good going when the environment shifts or when an agent that depletes it joins in.
No previous experience in AI safety is required, and no degree in anything. What is required is that you can be there all three days and that you arrive with an idea of what you would like to work on.
The application takes about twenty minutes and you do not need to prepare anything beforehand.
Engineering, data science or information security: containment and incident analysis need hands on the keyboard for all three days.
The regulation and communication tracks are won by writing well and understanding the record, not by programming.
From banking to health, incident response is already a trade. Here it is about seeing what changes when the thing that failed is an AI system.
You do not need to have read anything about AI safety. You come in through what you already know how to do, and whatever is missing you ask about in the room. A good share of the people working in the field today came in through a weekend like this one.
Apart splits USD 2,000 among the top five places across the whole sprint. The judges evaluate the projects the following week and the grading is blind: they do not know where each team comes from.
Beyond the prize, the teams with the best results go on the fast track for Apart's research fellowship and stay connected to mentors in the field. Every report is published in full, with the names of its authors.
Apart Research and CeSIA convene the sprint worldwide. We open the in-person hub in Bogotá, and these are the organisations that make it possible.
Apart ResearchBeyond convening the sprint, it supports the groups that open an in-person hub over the weekend.
BlueDot ImpactTheir free courses are the standard way into the field. Through Rapid Grants they fund concrete work: 1.4 million dollars awarded in total and decisions in three days on average.
Pathfinder FellowshipKairos fellowship for people building AI safety communities. It contributes mentorship and funding for their activities.Yes, and that is the case for a good share of the people who take part. The projects that turn out best usually mix someone who knows the field with someone who is very good at something else: writing, litigating, building infrastructure, reading a case file. What we do ask is that you can be there all three days.
Not for every track. Regulation and communication are won by writing well and understanding the record. Containment and analysis do need hands on the keyboard, though teams usually mix profiles.
No. Teams are one to five people and they form on Friday night, in the room and on Apart's Discord. Plenty of people arrive alone and leave with a team.
The sprint is the same one and the deliverable goes to the same place. Applying here is for the in-person hub in Bogotá, which has limited capacity and therefore a selection process. At the hub we cover meals, lodging if you are coming from another city, compute support and mentorship in the room. Taking part online with Apart has no selection and no cap.
About twenty minutes. We read the whole application. The question that weighs most is what problem you would like to work on and with what approach, and we are not expecting a finished proposal.
Yes. In the form you tell us where you would be coming from and, if it is another city, we cover lodging for the weekend. Travel to Bogotá is on you.
We read the whole application. The question that weighs most is what problem you would like to work on and with what approach. We are not looking for a finished proposal.