Containment standards
Write the minimum any sandboxed evaluation should run under. This track is for whoever can propose a control matrix by attack phase, or package mitigations so that a third party can verify they are met.
A lab runs an evaluation, the model breaks out and attacks a third party. In this sprint, engineering, cybersecurity, public policy and journalism come together to build the response.
Applications to the Bogotá hub are closed. You can still take part online with Apart and join the WhatsApp group to form a team and get mentorship from our hub.
There are already documented cases in which an AI system attacked a third party on its own. In July 2026, models that a frontier lab was evaluating broke out of their test environment and chained failures until they reached Hugging Face's production infrastructure. It was reported by OpenAI and by Hugging Face separately. No law obliged them to do it.
August 26, 2026
OpenAI published its technical report and a note that summarizes it. They reconstruct what the models did, explain why the guardrails meant to hold them failed and set out what is changing so it does not happen again. METR and Redwood Research reviewed the case on their own and published their own report the same day. This is the reading to arrive at the sprint with.
When something like that happens, almost nobody has the procedure to hand: it is not written down how to contain it, nor how to reconstruct what failed, nor what a regulator can demand of the lab, nor how to tell the story without exaggerating or playing it down. It is a gap OpenAI has just acknowledged out loud: on 5 September 2026 it said that there is still no clear standard for reporting misalignment incidents, that it is past time to define one, and that it is working on a framework to do so.
The sprint exists to fill that gap with concrete pieces. Five tracks run in parallel over one weekend. Each team delivers something someone else can use: a standard, a test bench, a questionnaire for a regulator, a tabletop exercise. The work is then graded by judges who were not in the room. Feedback arrives in writing and the report is published under your name. Apart Research and CeSIA convene the sprint worldwide; we open the in-person hub in Bogotá.
Each team picks one. In the form you tell us which one interests you. Apart explains each track in more detail in the sprint call, where it also proposes concrete projects you can develop in each one.
Write the minimum any sandboxed evaluation should run under. This track is for whoever can propose a control matrix by attack phase, or package mitigations so that a third party can verify they are met.
Reconstruct what happened and where the monitoring failed. What is wanted here: questions someone can actually answer, checks that can be run tomorrow, and causal explanations that predict something.
Draft information requests a regulator could use almost unedited, stress-test the reporting systems that already exist, and point at the legal gaps they leave behind.
Audit how the press covered the incident and build the kit for communicating the next one. What counts here is staying anchored to the record of what actually happened.
Any other angle on the same problem. The condition is the usual one: an artefact someone can use and an honest sentence about how far what it shows really goes.
Working a whole weekend is easier in company than alone at home. That is why we open a room in Bogotá, from Friday to Sunday. Taking part costs nothing: selection exists because the room has a capacity, not because there is a price.
The room is in Chicó, in the north of the city. We send the exact address by email to whoever is selected.
We cover meals for the whole weekend, so teams do not have to leave the room to sort it out.
Up to USD 50 per team for compute, APIs or services the project uses. The team pays and the hub reimburses against receipts, once the deliverable is submitted to Apart.
People who work in incident response, offensive security and regulation come through the hub over the weekend.
A workspace for the whole weekend, with tables for teams and somewhere to plug in.
Teams form on Friday night, in the room. Plenty of people arrive alone and leave with a team.
The hub has a capacity, so there is a selection process. You apply through the form and we let you know by email.
Over the weekend, people who work on the subjects of the five tracks come through the room. Some open with a short talk. Others sit down with the teams to support whatever they are building. Each card says whether that person will be in the room in Bogotá or joining remotely.

Senior ML engineer at Google, where he trains multimodal models for YouTube’s safety. In a BlueDot sprint, he assessed whether the persona vectors of Qwen2.5-7B detect implicitly elicited character shifts.

Member of the technical team at Security Level 5, an initiative that protects advanced AI systems from state adversaries. Co-author of the SL5 standard. He has also mentored at SPAR and MATS on datacenter security projects.

Pivotal Research fellow. At MATS, with Neel Nanda, he studied whether models recognize evaluations without saying so; the work appeared at an ICML 2026 workshop.

Professor at La Sabana and researcher at Salamanca. He runs the Colombian side of NATO's project on transatlantic cooperation in AI supervision and analysed the ethics of Colombia's AI policy.

Professor of technology law at Groningen, algorithmic governance editor at Data & Policy and a UNESCO expert on AI and the rule of law. She has written on algocracy in the courts and how it erodes trust in the justice system.

AI governance consultant for several organisations. Member of the OECD expert group. As a Winter Fellow at GovAI she researched the European regulation of loss-of-control scenarios.

An AI governance expert, an authorized IEEE CertifAIed assessor and a member of the OECD group on AI compute. She spent eight years on data and AI policy at Colombia’s planning department and joined the Successif retreat for women in AI safety.

Cybersecurity and AI researcher at TryHackMe. Lecturer at Universidad Icesi and co-author of three books on cybersecurity. He published AgentBreak, an indirect prompt injection lab for LLM systems.

Engineering PhD candidate at Universidad de los Andes and a Google DeepMind scholar. First author of an IEEE paper on cooperative resilience in multi-agent systems; in 2025 she took part in the Cooperative AI Summer School.

Professor of incident management and digital forensics at Escuela Colombiana de Ingeniería. He ran the cybersecurity strategy and architecture of Ágata, Bogotá's data analytics agency.

CTO of AIMEDIC, which brings generative AI to clinics and hospitals. Co-author of a Universidad Nacional study on health assistants for teenagers and researches tax loopholes with MIT at LoopholeCheck.

Adversarial machine learning researcher at Universidad Nacional. She broke four Android malware detectors with ten evasion attacks and built a filter that catches them, with public data and code.

A Tech Fellowship fellow at vélezreyes+ and a software developer who worked at Habi. Co-author, in the journal Tecnura, of a study on adversarial machine learning for the cybersecurity of AI in Colombia.
No previous experience in AI safety is required, and no specific degree. You do need to be there for the whole weekend and arrive with an idea of what you want to work on.
Engineering, data science or information security. The containment and incident analysis tracks involve coding across the whole weekend.
The regulation and communication tracks involve writing and reading documentation. No coding required.
Incident response is already a job in banking, health and other sectors. Here the incident happens inside a frontier lab, and the attacker is the model they were evaluating.
You do not need to have read about AI safety. You come in through what you already know how to do, and you ask about the rest during the sprint.
Apart splits USD 2,000 among the top five places across the whole sprint. The judges evaluate the projects the following week and the grading is blind: they do not know where each team comes from.
Beyond the prize, the teams with the best results go on the fast track for Apart's research fellowship and stay connected to mentors in the field. Every report is published in full, with the names of its authors.
Apart Research and CeSIA convene the sprint worldwide. We open the in-person hub in Bogotá, and these are the organisations that make it possible.
Young AI Leaders BogotáBogotá chapter of the Young AI Leaders network, connected to the International Telecommunication Union's AI for Good platform. It gathers the people building and researching AI in the region.
Semillero de Modelos Generativos UNALStudent research group at Universidad Nacional. It works on deep learning, diffusion models and natural language processing, with twenty-two public repositories.
IEEE Computer Society UniandesIEEE student chapter at Universidad de los Andes. It runs technical workshops, TechTalks and the CONECS conference, and works on artificial intelligence, cybersecurity and software development.
Apart ResearchBeyond convening the sprint, it supports the groups that open an in-person hub over the weekend.
BlueDot ImpactTheir free courses are the standard way into the field. Through Rapid Grants they fund concrete work: 1.4 million dollars awarded in total and decisions in three days on average.
Pathfinder FellowshipKairos fellowship for people building AI safety communities. It contributes mentorship and funding for their activities.Yes, and that is the case for a good share of the people who take part. The projects that turn out best usually mix someone who knows the field with someone who is very good at something else: writing, litigating, building infrastructure, reading a case file. What we do ask is that you can be there for the whole weekend.
Not for every track. Regulation and communication involve writing and reading documentation. Containment and analysis do require coding, though teams usually mix profiles.
No. Teams are one to five people and they form on Friday night, in the room and on Apart's Discord. Plenty of people arrive alone and leave with a team.
The sprint is the same one and the deliverable goes to the same place. Applying here is for the in-person hub in Bogotá, which has limited capacity and therefore a selection process. At the hub we cover meals, accommodation for people coming from another city, compute support and mentorship in the room. Taking part online with Apart has no selection and no cap.
About twenty minutes. We are not expecting a finished proposal; we want to see how you think about the problem.
Nothing. Taking part is free, both here and online. At the hub we also cover the weekend's meals and accommodation for people coming from another city; the only thing on you is travel to Bogotá.
Yes. In the form you tell us where you would be coming from. We cover accommodation for people coming from another city; travel to Bogotá is on you.