In this report, the authors extend a framework to provide the first systematic roadmap for protecting algorithmic insights, the novel techniques, methods, and design know-how that materially improve artificial intelligence (AI) systems, which are among the most strategically valuable assets in the AI ecosystem. With this new framework, organizations can make informed decisions about which insights warrant which security investments.

Algorithmic insights—the techniques, methods, and design know-how that materially improve artificial intelligence (AI) systems—can confer substantial commercial and strategic advantages. Unlike model weights, algorithmic insights generally cannot be isolated as a single digital artifact. They reside across source code, documentation, communications, experimental systems, and human expertise, and some can be conveyed through only a brief conversation or an observed screen. Their unauthorized disclosure could erode technological leads and, in some cases, lower barriers to dangerous AI capabilities.

This report adapts the framework developed in Securing AI Model Weights to algorithmic insights. The authors identify 44 attack vectors across nine categories and propose five cumulative insight security levels (ISLs) matched to five levels of adversary operational capacity. The framework is conditional rather than prescriptive: It describes the security posture likely required to protect a specified insight against a specified class of adversary while leaving organizations to determine which insights warrant protection.

The report identifies compartmentalization as the central organizing principle for insight security. Lower security levels largely extend established enterprise controls and need-to-know practices. Higher levels require increasingly isolated systems and facilities, more-intensive personnel security, and substantial restrictions on ordinary research practices.

Algorithmic insights can reside in code, documents, communications, devices, and people’s knowledge. Some can be conveyed through only a few lines of code, a brief conversation, or an observed screen, so cyber controls alone are insufficient.

Organizations can reduce the consequences of compromise by limiting where complete insights reside, restricting access to personnel with a need to know, and progressively strengthening separation between insight domains.

ISL1 and ISL2 largely extend security fundamentals and established enterprise practices. ISL3 adds formal classification and compartmentalization, insider-risk controls, network segmentation, and supply chain assurance.

Protecting insights against highly capable state adversaries could require isolated facilities, intensive personnel vetting, compartmentalized supply chains, and restrictions on remote work, travel, and communication. Some measures might require government support and years of preparation.