Government research and commercial reuse agreement
AISI attacks and safeguards contract (September 2024)
£459,875 award for research feeding government AI evaluations, with public redacted contract terms.
Background
The 17 September 2024 award hires Pattern Labs Tech Inc. for attacks, mitigations and related research with weekly AISI researcher contact. Schedule 20 says the work will feed AISI evaluations and threat models. The initial term is six months, with a three-month extension option.
DSIT retains final research-output sign-off and the decision whether and how to publish. Special Term 1 reserves the supplier’s underlying IP, know-how and improvements, and allows related evaluation products to be developed and sold. The supplier’s detailed tender is commercially redacted and has precedence for deliverables.
The purchased work
The 17 September 2024 award hires Pattern Labs Tech Inc. for attacks, mitigations and related research with weekly AISI researcher contact. Schedule 20 says the work will feed AISI evaluations and threat models. The initial term is six months, with a three-month extension option.
DSIT retains final research-output sign-off and the decision whether and how to publish. Special Term 1 reserves the supplier’s underlying IP, know-how and improvements, and allows related evaluation products to be developed and sold. The supplier’s detailed tender is commercially redacted and has precedence for deliverables.
Order form names Pattern Labs Tech Inc. Special Term 1 retains supplier know-how and permits commercialization of related evaluation products. Permission to commercialize does not identify a later sale.
Schedule 20 commissions technical inputs for AISI evaluations and threat models, with weekly researcher collaboration. Specification and intended use; specific accepted outputs remain unavailable.
Schedule 20 assigns buyer sign-off and final decision on whether and how research outputs are published. Terms of this 2024 engagement, not evidence of authority over separate 2026 incidents.
Schedule 9 requires a security management plan, incident notification and remediation; buyer approval does not relieve supplier obligations. The approved plan and evidence of performance were not obtained.