Skip to content
PhiloCyber logo
AI SecurityField report

My week at the AI Security Bootcamp in London (AISB)

An intense week spanning model internals, reinforcement learning, backdoors, adversarial ML and AI control. What I could follow, what challenged me and why I came home with a much broader view of AI security.

Download Markdown
Cite this article

Ricardo Prieto. “My week at the AI Security Bootcamp in London (AISB).” PhiloCyber, Sep 14, 2026. https://www.philocyber.com/en/blogs/aisb-london-2026-experience

My week at the AI Security Bootcamp in London (AISB)Open full-resolution image

I heard about the bootcamp with very little time to spare. Graciela Pataro, one of my professors in UBA’s Master’s in Information Security, sent me the call for applications shortly before the deadline. I read about the programme, thought it was an enormous opportunity and applied.

From 30 August to 5 September 2026, I was in London studying AI security with people from very different backgrounds. I was already working in AI security and had years of experience in offensive security and AppSec. I brought that experience with me, along with the certainty that I needed to understand much more about what happens inside models, how their behaviour changes and how we evaluate whether a control actually works.

I came home with a much broader perspective, more clarity about everything I still need to learn and, above all, a great deal of gratitude. The week was intense, challenging and deeply rewarding.

The GovAI office where the AI Security Bootcamp took place during a reinforcement learning session, with the Bellman equation projected and notes on the whiteboard
One of the reinforcement learning sessions, taught by David Quarel (PhD student at the Australian National University). The week combined foundations, discussion and hands-on work.

Arriving with experience and becoming a beginner again

My security experience gave me a foothold. I am used to thinking about trust boundaries, attack surfaces, permissions, abuse cases and evidence. That framework helped me put some moments into context, but it did not replace the machine learning foundations I needed to follow certain topics at the programme’s pace.

Honestly, there were classes I could not follow all the way through. The coding exercises also stretched my knowledge of ML, and the way forward was to ask more questions, whether of tutors, classmates or AI. My classmates brought very different strengths and backgrounds: some had a deep understanding of models, others of evaluation or practical security, some came from academia and others were more connected to public institutions. Learning together helped me see more clearly what I could already contribute and, above all, where I need to grow to improve in this field.

For me, this was one of the most valuable parts of the week. I was nowhere near leaving with the idea that I had mastered all of these AI topics. For better or worse, I left with a much more precise map and a clearer understanding of how much I do not know. That is a difficult feeling to deal with, but I had to sit with it.

From model internals to control

The programme traced a chain of problems that I had previously kept separate. It started with how models are trained and represented, moved through reinforcement learning, adversarial ML and backdoors, and reached monitoring, threat modelling and AI control.

In model internals, for example, serialisation and tokenisation appeared as parsing boundaries. A demo with control tokens could show how a representation changes the meaning of an input, but it did not prove on its own that a real API was vulnerable. That distinction between a useful idea and the evidence needed to support a claim felt very familiar from offensive security.

For backdoors, the material presented a teaching example based on a poisoned sentiment analysis dataset with the trigger “James Bond”. The goal was to measure two things at once: how well the model preserved its normal accuracy and how often the hidden behaviour was activated. It was the exercise I enjoyed the most. In adversarial vision, another exercise pushed a model towards a chosen classification and then compared the attack’s effectiveness with how much the image changed under L2 and L∞ metrics. These were bounded experiments, useful for learning how to measure, not tests of the overall robustness of frontier models.

The reinforcement learning classes were among the most demanding parts for me. The public reading on training covers SFT, DPO, RLVR and RLHF with PPO, and it remains material I want to keep studying as I deepen my understanding of how optimisation objectives connect with training decisions.

Monitoring and control connected most directly with my previous experience. If a system can act, a monitor can observe part of its behaviour, but difficult questions remain. What do we audit, and when do we defer an action? What do we resample? How much performance are we willing to trade for security? A small exercise cannot answer those questions for production, but it forces us to make the balance between security and usefulness explicit.

When governance stopped feeling like science fiction

Before the bootcamp, some conversations about AI safety and governance could feel distant to me. I had even taken the TAISE exam (the Cloud Security Alliance’s Trusted AI Safety Expert Certification) a few months earlier, and I came away feeling that there was a lot of theory, little practice and therefore little impact... In London, I began to see these questions as a concrete extension of security problems.

A technical control does not exist in isolation. Someone defines what authority it has, what evidence is needed to intervene and what happens if stopping an action costs time or performance. An evaluation does not make a decision by itself either. People need to agree on how its result will be used, who responds to a signal and how teams, companies and institutions coordinate.

That brought together topics I had thought about separately: evaluation, authority, control and coordination. I did not come home with a settled answer. I came home with better questions and the desire to investigate them.

Seeing that work up close

During the week, the UK AI Security Institute hosted the group and shared some of its research. Seeing an institution dedicated to evaluating capabilities and risks made a field that can feel abstract from a distance much more concrete. GovAI also provided its offices for part of the programme, but honestly, I would have liked more talks from them or more context.

Ricardo having a fan moment in front of the UK AI Security Institute sign during the AISB group visit
During the group visit to the UK AI Security Institute in London.

The learning did not happen only in front of a screen. Questions continued during breaks, meals and conversations with classmates. Their generosity made asking for help feel like part of the work, rather than like falling behind.

I especially want to thank Pranav Gade, who created AISB and spent the week teaching and supporting us; David Quarel and Jan Michelfeit, for teaching and helping me connect complex ideas; and Rhita Ameziane, for the organisation and care that held this wonderful experience together.

I also want to thank Jannis Kirschner, Emma Liddell, Chang Shiau Huei, Fernando Smith and David Williams-King for their talks and guidance; BlueDot Impact and Constellation Institute; the UK AISI for hosting us and sharing its research; and GovAI for opening its offices and sharing such a beautiful space. And, of course, my dear Legal Framework, Ethics and Privacy (PSI) professor, Graciela Pataro, for sharing the opportunity with me just in time.

Financial support matters

Financial support was essential for me to attend. Without it, travelling to London for a week of training would not have been a realistic option for me.

Making these opportunities accessible matters because talent and valuable questions are not concentrated in a single city, country or professional path. Financial support changes who can be in the room, learn and then carry those ideas into other communities.

What I brought home

I came home grateful and with a much broader view of AI security. I also came back with a clear list of foundations I want to strengthen and new research questions that I am only beginning to formulate.

I will continue sharing what I learn in future posts and videos. In this other essay, I explain why the experience also changed PhiloCyber’s direction. Here, I wanted to leave something more concrete: what the week felt like, what I found difficult and why it was worth it.

The door remains open to researching with other people, collaborating on projects, talking about job opportunities and receiving feedback. If you are working on AI safety, AI security, evaluations or control and think we could learn together, get in touch or contact me on LinkedIn.

Frequently asked questions

Do I need a machine learning background to benefit from AISB?

I can only answer from my own experience: my security background helped a great deal, but it did not replace the foundations of ML. Some parts were difficult for me, and I made the most of them by asking questions, studying and learning from classmates with different strengths. The requirements for each cohort are on the official website, and the organisation also sends out four weeks of excellent, extensive preparatory material.

What made this week different from a conference?

The continuity. An idea would appear in a class, become concrete in a coding exercise and come up again later that day or the next in a conversation about evaluation or control. Spending several days with the same group also allowed us to ask questions in greater depth, get to know one another better and learn from other people’s experiences.

Sources you can check

Official poster for the December 2026 AI Security Bootcamp cohort in London
The next London cohort will run from 6 to 12 December 2026.
Perspective

Applications for London, December 2026

The cohort I wrote about took place in late August and early September. The next one will run from 6 to 12 December 2026, and applications close on 1 October at 11:59 pm, from anywhere in the world.

If the programme interests you but you are hesitating because you have not mastered the entire curriculum, go for it and apply!! I also arrived with gaps I needed to work on and uncertainty, and the week helped me see much more clearly where I could grow. Learn about the programme and apply here.

If you don't try, the answer is already no. Give it a shot!

Richie

Follow the work from ideas to usable resources.

Browse the full writing archive, or inspect the guides and project records that put the methods into practice.

Explore writing
My week at the AI Security Bootcamp in London (AISB) | PhiloCyber