Summary
- Jade Leung will become vice-chair of the AI Security Institute and security adviser to the AI Taskforce at the end of September.
- She will step back from her full-time roles as Prime Minister’s AI adviser and AISI chief technology officer, with the government planning a new appointment for the former role.
- The transition retains Leung within the UK’s AI-security structure while separating some technical research, central advice, and taskforce responsibilities.
One of the senior officials shaping Britain’s approach to advanced AI is moving out of two full-time government positions while retaining roles around security and institutional direction, changing the leadership structure around the UK’s technical AI-policy operation.
The AI Security Institute’s chief technology officer Jade Leung will become its vice-chair and also serve as security adviser to the government’s AI Taskforce. She will step back from her current full-time jobs as the Prime Minister’s adviser on AI and AISI chief technology officer at the end of September.
The Cabinet Office said the transition is being made because of personal circumstances and provided no further detail. Leung will also become a part-time distinguished visiting fellow at Stanford University’s Hoover Institution, while the government says a new AI adviser to the Prime Minister will be appointed.
Leung has been involved with the institute since its development and previously worked on governance at OpenAI. Her government roles have crossed frontier-model research, security, public-sector adoption, and central AI policy, meaning the new structure affects how some of those functions are divided rather than simply replacing one job title with another.
AISI itself has developed from the organisation created around the UK’s early frontier-AI safety agenda into a technical research body examining the capabilities and risks of increasingly powerful models. Its work covers areas including cyber capabilities, safeguards, autonomous behaviour, model control, monitoring, and methods for evaluating systems before and after deployment.
AISI occupies an unusual place inside government
The institute is not a conventional economic regulator and does not grant general permission determining whether an AI product may be sold in Britain. Instead, it develops evaluation methods, tests advanced systems, researches mitigations, and supplies evidence that can inform decisions elsewhere in government.
That role requires unusually technical capability for a public body because questions around cyber misuse, autonomous agents, safeguards, or model control cannot be answered solely through policy analysis. Researchers have to design tests that reveal what a system can actually do, including where laboratory performance may differ from behaviour in a more realistic environment.
The arrangement also creates an important distinction between measurement and policymaking. AISI can produce evidence about model capabilities and weaknesses, but decisions about regulation, procurement, economic policy, national security, and public-sector use sit across ministers, departments, regulators, and other government organisations.
That separation becomes more significant as AI capabilities change between policy cycles. A system that performs poorly on a technically demanding task one year may improve rapidly through later model releases, while an evaluation designed around one generation of models can become less informative as agents gain access to tools, memory, and longer task horizons.
The institute’s work has consequently expanded beyond static model testing towards areas concerned with how AI behaves when connected to software or operating over several steps. Those research questions increasingly overlap with systems being considered for real public-sector and enterprise deployments.
The transition separates overlapping responsibilities
Leung’s existing positions placed her inside both the Prime Minister’s advisory operation and the technical leadership of AISI. Moving to vice-chair and AI Taskforce security adviser retains her involvement around institutional direction and security while opening the two full-time responsibilities to a different leadership structure.
The government has said a new Prime Minister’s AI adviser will be appointed, although the announcement does not name that person. It likewise does not identify a successor chief technology officer for AISI, leaving the eventual division between technical management, strategic oversight, and central policy advice to be completed through later appointments.
The AI Taskforce adds another organisational layer. The government’s current ministerial structure places responsibility for the taskforce and AISI within the Cabinet Office portfolio of the Minister for Artificial Intelligence, alongside wider work on AI strategy, public-sector adoption, and the AI Economics Institute.
Advanced AI policy increasingly touches areas that do not fit neatly inside one department. Economic policy is concerned with investment, infrastructure, and adoption; national-security bodies focus on misuse and strategic dependence; public-service teams are considering operational deployment; and technical researchers are trying to establish how capable the underlying systems have become.
How those functions are separated affects more than organisational charts because technical findings can be interpreted differently depending on the policy question being asked. Evidence that a model performs well on a cyber evaluation, for example, may be relevant to defensive adoption, misuse risk, procurement controls, or national-security planning without implying the same policy response in each case.
Security research is moving closer to deployment
The wider AI-security agenda is also moving beyond laboratory discussion as governments and businesses give models access to code, data, software tools, and operational systems. An assistant generating a draft creates one category of risk, while an autonomous system capable of executing commands or altering records creates another.
That places more emphasis on research into monitoring, permissions, control, and the behaviour of agents over longer sequences of actions. The questions become practical: whether an organisation can identify what the system is doing, interrupt it where necessary, limit access to tools, and reconstruct its decisions after an incident.
AISI’s work therefore increasingly intersects with the same deployment issues appearing in commercial agent-security products, cybersecurity operations, and public-sector AI programmes. The institute’s contribution remains research and evidence rather than operational ownership of every system government deploys.
Leung’s new security-adviser role places her near that boundary between technical evidence and government preparation, while the vice-chair position preserves continuity inside an institute she helped establish. It should not be read as concentrating UK AI policy in one individual because formal responsibilities remain distributed across ministers and institutions.
The more revealing development will be the appointments that follow. They will show how the government intends to divide day-to-day technical leadership at AISI from central advice and the security work of the AI Taskforce as advanced models move further from research environments into public services, cybersecurity, and the wider economy.












