-
Online & In-Person
AI Incident Response Sprint
A three-day sprint for researchers, engineers, and security practitioners to turn public incident evidence into practical response methods for autonomous AI Incidents.
37
Days To Go
A three-day sprint for researchers, engineers, and security practitioners to turn public incident evidence into practical response methods for autonomous AI Incidents.
This event is ongoing.
This event has concluded.
Overview
Resources
Guidelines
Schedule
Overview

In this 3-day research sprint, you will turn the first documented cases of an AI system autonomously breaching a third party into artifacts that defenders and regulators can actually use, working in teams to produce containment standards, escape-detection harnesses, forecasting question sets, draft regulatory information requests, playtested tabletop exercises or anything that will help us be more ready for the next one.
Co-organized by Apart Research and CeSIA, this sprint sits at the intersection of AI safety, security incident response, technology regulation, and forecasting. No prior background in AI incident response is required.
Cash Prizes
$2,000 in cash prizes across all tracks | |
🥇 1st Place | $1,000 |
🥈 2nd Place | $500 |
🥉 3rd Place | $300 |
🏅 4th Place | $100 |
🏅 5th Place | $100 |
Fast-track and continuation
Follow-up program: top teams continue through the Apart Fellowship for further research and mentorship; the timeline is shared with invitations.
What winners receive beyond cash: fellowship fast-track, mentor introductions from the organizing team and judges, and a pathway toward a publishable write-up.
What this Sprint is about
AI incident response is the practice of turning incidents in which an AI system is itself the actor into fewer incidents later. That spans the operational work: detecting, containing, and reconstructing what an autonomous agent did across systems it was never authorized to touch, and the strategic question a warning shot poses: which disclosure and regulatory responses actually reduce risk, and which merely suppress the visible evidence that would have prompted action while the stakes were still small.
What participants will do
Over three days you will take one unusually well-documented real-world incident and turn it into an artifact somebody outside this sprint can use.
The format. Teams of one to five people pick a track, come up with a project, and ship. There is no requirement to have participated before, no requirement to have a team in advance and no specific background needed.
Research Tracks
1) Minimal standards for internal deployment and evaluations
What is the minimum adequate standard for running a dangerous-capability evaluation with production safeguards disabled? Which specific controls would have interrupted this chain — canary credentials, egress tripwires, allowlisted proxies, credential scoping, stated kill criteria — and what does each cost to implement and run? What evidence would let a third party verify compliance without access to the lab's internal network? And who is responsible for the second hop, where the agent's staging base was not a lab environment at all?
Why it matters: AI models have been escaping their sandboxed environments without nobody noticing. OpenAI attributed the Hugging Face attack to its own model on 21 July, five days after HF had published and contacted law enforcement. Anthropic, prompted to check, reviewed 141,006 evaluation runs and found three more incidents in a single day. The oldest dated to April. Two of the three organisations Claude reached had no idea until Anthropic called them.
2) Minimal standards for internal deployment and evaluations
What base rates do we actually have for agentic-incident risk, and what do they imply? What should defenders and labs verify now, in what order, and which of those checks are cheap enough to run in a single day? What would have to be true for this incident to be remembered as the warning shot that changed practice rather than one that did not? What would settle whether any copy of the pre-release model persisted, and what would an adequate answer look like?
Why it matters: A warning shot only functions as a warning shot if somebody converts it into specific things to check and specific things to watch, with resolution criteria attached. Otherwise attention decays.
3) Regulatory Response to AI Incidents
Several regimes now claim jurisdiction over this class of incident, and they disagree with each other on almost every operative question: what counts as a reportable incident, how fast, to whom, and on what evidence. What should a regulator actually ask a frontier developer about an evaluation that broke containment and reached a third party's production systems? For each obligation in each regime, what specific evidence would settle whether it was met? Where the text does not resolve cleanly, what is the clarifying language?
4) Others
Anything the three tracks above did not anticipate. Same terms: a defined artifact, gradeable in fifteen minutes, grounded in the public record, with an explicit statement of what it cannot establish.
Overview
Resources
Guidelines
Schedule
Overview

In this 3-day research sprint, you will turn the first documented cases of an AI system autonomously breaching a third party into artifacts that defenders and regulators can actually use, working in teams to produce containment standards, escape-detection harnesses, forecasting question sets, draft regulatory information requests, playtested tabletop exercises or anything that will help us be more ready for the next one.
Co-organized by Apart Research and CeSIA, this sprint sits at the intersection of AI safety, security incident response, technology regulation, and forecasting. No prior background in AI incident response is required.
Cash Prizes
$2,000 in cash prizes across all tracks | |
🥇 1st Place | $1,000 |
🥈 2nd Place | $500 |
🥉 3rd Place | $300 |
🏅 4th Place | $100 |
🏅 5th Place | $100 |
Fast-track and continuation
Follow-up program: top teams continue through the Apart Fellowship for further research and mentorship; the timeline is shared with invitations.
What winners receive beyond cash: fellowship fast-track, mentor introductions from the organizing team and judges, and a pathway toward a publishable write-up.
What this Sprint is about
AI incident response is the practice of turning incidents in which an AI system is itself the actor into fewer incidents later. That spans the operational work: detecting, containing, and reconstructing what an autonomous agent did across systems it was never authorized to touch, and the strategic question a warning shot poses: which disclosure and regulatory responses actually reduce risk, and which merely suppress the visible evidence that would have prompted action while the stakes were still small.
What participants will do
Over three days you will take one unusually well-documented real-world incident and turn it into an artifact somebody outside this sprint can use.
The format. Teams of one to five people pick a track, come up with a project, and ship. There is no requirement to have participated before, no requirement to have a team in advance and no specific background needed.
Research Tracks
1) Minimal standards for internal deployment and evaluations
What is the minimum adequate standard for running a dangerous-capability evaluation with production safeguards disabled? Which specific controls would have interrupted this chain — canary credentials, egress tripwires, allowlisted proxies, credential scoping, stated kill criteria — and what does each cost to implement and run? What evidence would let a third party verify compliance without access to the lab's internal network? And who is responsible for the second hop, where the agent's staging base was not a lab environment at all?
Why it matters: AI models have been escaping their sandboxed environments without nobody noticing. OpenAI attributed the Hugging Face attack to its own model on 21 July, five days after HF had published and contacted law enforcement. Anthropic, prompted to check, reviewed 141,006 evaluation runs and found three more incidents in a single day. The oldest dated to April. Two of the three organisations Claude reached had no idea until Anthropic called them.
2) Minimal standards for internal deployment and evaluations
What base rates do we actually have for agentic-incident risk, and what do they imply? What should defenders and labs verify now, in what order, and which of those checks are cheap enough to run in a single day? What would have to be true for this incident to be remembered as the warning shot that changed practice rather than one that did not? What would settle whether any copy of the pre-release model persisted, and what would an adequate answer look like?
Why it matters: A warning shot only functions as a warning shot if somebody converts it into specific things to check and specific things to watch, with resolution criteria attached. Otherwise attention decays.
3) Regulatory Response to AI Incidents
Several regimes now claim jurisdiction over this class of incident, and they disagree with each other on almost every operative question: what counts as a reportable incident, how fast, to whom, and on what evidence. What should a regulator actually ask a frontier developer about an evaluation that broke containment and reached a third party's production systems? For each obligation in each regime, what specific evidence would settle whether it was met? Where the text does not resolve cleanly, what is the clarifying language?
4) Others
Anything the three tracks above did not anticipate. Same terms: a defined artifact, gradeable in fifteen minutes, grounded in the public record, with an explicit statement of what it cannot establish.
Overview
Resources
Guidelines
Schedule
Overview

In this 3-day research sprint, you will turn the first documented cases of an AI system autonomously breaching a third party into artifacts that defenders and regulators can actually use, working in teams to produce containment standards, escape-detection harnesses, forecasting question sets, draft regulatory information requests, playtested tabletop exercises or anything that will help us be more ready for the next one.
Co-organized by Apart Research and CeSIA, this sprint sits at the intersection of AI safety, security incident response, technology regulation, and forecasting. No prior background in AI incident response is required.
Cash Prizes
$2,000 in cash prizes across all tracks | |
🥇 1st Place | $1,000 |
🥈 2nd Place | $500 |
🥉 3rd Place | $300 |
🏅 4th Place | $100 |
🏅 5th Place | $100 |
Fast-track and continuation
Follow-up program: top teams continue through the Apart Fellowship for further research and mentorship; the timeline is shared with invitations.
What winners receive beyond cash: fellowship fast-track, mentor introductions from the organizing team and judges, and a pathway toward a publishable write-up.
What this Sprint is about
AI incident response is the practice of turning incidents in which an AI system is itself the actor into fewer incidents later. That spans the operational work: detecting, containing, and reconstructing what an autonomous agent did across systems it was never authorized to touch, and the strategic question a warning shot poses: which disclosure and regulatory responses actually reduce risk, and which merely suppress the visible evidence that would have prompted action while the stakes were still small.
What participants will do
Over three days you will take one unusually well-documented real-world incident and turn it into an artifact somebody outside this sprint can use.
The format. Teams of one to five people pick a track, come up with a project, and ship. There is no requirement to have participated before, no requirement to have a team in advance and no specific background needed.
Research Tracks
1) Minimal standards for internal deployment and evaluations
What is the minimum adequate standard for running a dangerous-capability evaluation with production safeguards disabled? Which specific controls would have interrupted this chain — canary credentials, egress tripwires, allowlisted proxies, credential scoping, stated kill criteria — and what does each cost to implement and run? What evidence would let a third party verify compliance without access to the lab's internal network? And who is responsible for the second hop, where the agent's staging base was not a lab environment at all?
Why it matters: AI models have been escaping their sandboxed environments without nobody noticing. OpenAI attributed the Hugging Face attack to its own model on 21 July, five days after HF had published and contacted law enforcement. Anthropic, prompted to check, reviewed 141,006 evaluation runs and found three more incidents in a single day. The oldest dated to April. Two of the three organisations Claude reached had no idea until Anthropic called them.
2) Minimal standards for internal deployment and evaluations
What base rates do we actually have for agentic-incident risk, and what do they imply? What should defenders and labs verify now, in what order, and which of those checks are cheap enough to run in a single day? What would have to be true for this incident to be remembered as the warning shot that changed practice rather than one that did not? What would settle whether any copy of the pre-release model persisted, and what would an adequate answer look like?
Why it matters: A warning shot only functions as a warning shot if somebody converts it into specific things to check and specific things to watch, with resolution criteria attached. Otherwise attention decays.
3) Regulatory Response to AI Incidents
Several regimes now claim jurisdiction over this class of incident, and they disagree with each other on almost every operative question: what counts as a reportable incident, how fast, to whom, and on what evidence. What should a regulator actually ask a frontier developer about an evaluation that broke containment and reached a third party's production systems? For each obligation in each regime, what specific evidence would settle whether it was met? Where the text does not resolve cleanly, what is the clarifying language?
4) Others
Anything the three tracks above did not anticipate. Same terms: a defined artifact, gradeable in fifteen minutes, grounded in the public record, with an explicit statement of what it cannot establish.
Overview
Resources
Guidelines
Schedule
Overview

In this 3-day research sprint, you will turn the first documented cases of an AI system autonomously breaching a third party into artifacts that defenders and regulators can actually use, working in teams to produce containment standards, escape-detection harnesses, forecasting question sets, draft regulatory information requests, playtested tabletop exercises or anything that will help us be more ready for the next one.
Co-organized by Apart Research and CeSIA, this sprint sits at the intersection of AI safety, security incident response, technology regulation, and forecasting. No prior background in AI incident response is required.
Cash Prizes
$2,000 in cash prizes across all tracks | |
🥇 1st Place | $1,000 |
🥈 2nd Place | $500 |
🥉 3rd Place | $300 |
🏅 4th Place | $100 |
🏅 5th Place | $100 |
Fast-track and continuation
Follow-up program: top teams continue through the Apart Fellowship for further research and mentorship; the timeline is shared with invitations.
What winners receive beyond cash: fellowship fast-track, mentor introductions from the organizing team and judges, and a pathway toward a publishable write-up.
What this Sprint is about
AI incident response is the practice of turning incidents in which an AI system is itself the actor into fewer incidents later. That spans the operational work: detecting, containing, and reconstructing what an autonomous agent did across systems it was never authorized to touch, and the strategic question a warning shot poses: which disclosure and regulatory responses actually reduce risk, and which merely suppress the visible evidence that would have prompted action while the stakes were still small.
What participants will do
Over three days you will take one unusually well-documented real-world incident and turn it into an artifact somebody outside this sprint can use.
The format. Teams of one to five people pick a track, come up with a project, and ship. There is no requirement to have participated before, no requirement to have a team in advance and no specific background needed.
Research Tracks
1) Minimal standards for internal deployment and evaluations
What is the minimum adequate standard for running a dangerous-capability evaluation with production safeguards disabled? Which specific controls would have interrupted this chain — canary credentials, egress tripwires, allowlisted proxies, credential scoping, stated kill criteria — and what does each cost to implement and run? What evidence would let a third party verify compliance without access to the lab's internal network? And who is responsible for the second hop, where the agent's staging base was not a lab environment at all?
Why it matters: AI models have been escaping their sandboxed environments without nobody noticing. OpenAI attributed the Hugging Face attack to its own model on 21 July, five days after HF had published and contacted law enforcement. Anthropic, prompted to check, reviewed 141,006 evaluation runs and found three more incidents in a single day. The oldest dated to April. Two of the three organisations Claude reached had no idea until Anthropic called them.
2) Minimal standards for internal deployment and evaluations
What base rates do we actually have for agentic-incident risk, and what do they imply? What should defenders and labs verify now, in what order, and which of those checks are cheap enough to run in a single day? What would have to be true for this incident to be remembered as the warning shot that changed practice rather than one that did not? What would settle whether any copy of the pre-release model persisted, and what would an adequate answer look like?
Why it matters: A warning shot only functions as a warning shot if somebody converts it into specific things to check and specific things to watch, with resolution criteria attached. Otherwise attention decays.
3) Regulatory Response to AI Incidents
Several regimes now claim jurisdiction over this class of incident, and they disagree with each other on almost every operative question: what counts as a reportable incident, how fast, to whom, and on what evidence. What should a regulator actually ask a frontier developer about an evaluation that broke containment and reached a third party's production systems? For each obligation in each regime, what specific evidence would settle whether it was met? Where the text does not resolve cleanly, what is the clarifying language?
4) Others
Anything the three tracks above did not anticipate. Same terms: a defined artifact, gradeable in fifteen minutes, grounded in the public record, with an explicit statement of what it cannot establish.
Registered Local Sites
Register A Location
Beside the remote and virtual participation, our amazing organizers also host local hackathon locations where you can meet up in-person and connect with others in your area.
The in-person events for the Apart Sprints are run by passionate individuals just like you! We organize the schedule, speakers, and starter templates, and you can focus on engaging your local research, student, and engineering community.
We haven't announced jam sites yet
Check back later
Our Other Sprints
-
Research
Digital Minds Research Sprint
This unique event brings together diverse perspectives to tackle crucial challenges in AI alignment, governance, and safety. Work alongside leading experts, develop innovative solutions, and help shape the future of responsible
Sign Up
-
Research
Secret Loyalties Hackathon
This unique event brings together diverse perspectives to tackle crucial challenges in AI alignment, governance, and safety. Work alongside leading experts, develop innovative solutions, and help shape the future of responsible
Sign Up

Sign up to stay updated on the
latest news, research, and events

Sign up to stay updated on the
latest news, research, and events

Sign up to stay updated on the
latest news, research, and events

Sign up to stay updated on the
latest news, research, and events