AI Safety
Why Microsoft is opening AI safety testing to the world
Microsoft has funded 18 university labs across six continents to independently red team AI systems, acknowledging that internal teams cannot catch every risk.
Emmanuel Fabrice Omgbwa Yasse AI-assisted
2026-08-07 · 3 min read

AI red teaming has a blind spot. Most safety testing stays inside the companies building the models. That works for the obvious issues, but the hardest failure modes, the ones that surface only in a specific language or cultural context, need expertise no internal team can cover alone. 1,224 AI insiders recently pressed the U.S. to develop governance.
Microsoft's answer is the External Red Team Alliance, or EXTRA. Announced today, the program funds independent researchers on six continents to stress-test frontier AI systems. The company has given unrestricted gifts to 18 university labs, including Georgetown's Security Lab, NYU's Alignment Research Group, and UC Berkeley's Risk and Security Lab, with no strings attached: the goal is to strengthen independent safety research globally, not steer it toward Microsoft's priorities. Anthropic made a similar bet, donating another $20 million to public policy.
The initiative has two parts. The first is academic: cash grants for researchers to tackle unresolved questions in AI safety. Some labs are studying how models can be attacked or manipulated in operational environments. Others are exploring the inverse, how AI could help defenders improve cyber operations.

The second part is operational: a distributed network of specialists who can join red team exercises when deep domain knowledge is needed, like a specific language or cybersecurity expertise. The idea is to cover attack surfaces that internal teams cannot fully address on their own.
This structure is intentional. Microsoft's AI Red Team has found that meaningful testing of advanced systems often requires broader participation from people outside traditional corporate security boundaries. Natasha Crampton, Microsoft's Chief Responsible AI Officer, said in the announcement that managing frontier AI risk requires "continuous engagement with experts who understand how these systems behave across different technical, linguistic, and cultural contexts." a view echoed at the AI Action Summit in Paris.
The move mirrors how cybersecurity works. The ecosystem there depends on independent vulnerability researchers, bug bounty programs, and coordinated disclosure. AI safety, the argument goes, needs the same kind of external scrutiny. Mike Yeh, Microsoft's VP and Deputy General Counsel for Customer Security and Trust, noted that understanding how frontier AI can be misused requires expertise that crosses institutions, disciplines, and borders.
Governments are pushing in the same direction. At the most recent Global AI Safety Summit, more than 30 countries signed a joint declaration that includes independent pre-deployment testing for frontier models. EXTRA creates the kind of evaluation capacity that future regulation may demand, though the grants come with no obligation for Microsoft to act on what researchers find. a consensus documented in the emerging global regulation landscape.
That is the tension at the heart of the program. Unrestricted funding preserves academic independence, but it also means Microsoft can choose which findings to take seriously. The real test will be whether external red team results lead to concrete changes before a model ships, or whether they become a parallel conversation the industry can ignore. Stability AI's first transparency report showed what these gaps look like.
EXTRA pushes AI safety testing toward a more open model. Its success will be measured not by the grants given, but by the changes made before a model ships.
- Source : Why Microsoft is opening AI safety testing to the world — 2026-07-27
Get the tech essentials in 3 minutes every morning
One email, every weekday, with what actually matters in AI and tech.