← Back to Feed

Enhancing AI security through global AI red teaming

July 27, 2026 · Microsoft Security · Severity: MEDIUM

Microsoft has launched the External Red Team Alliance (EXTRA), a global initiative to enhance AI security by expanding red teaming efforts beyond individual organizations. The program addresses the growing complexity of AI risks, which now include multilingual harms, domain-specific abuse, and regional vulnerabilities that internal teams alone cannot fully assess. EXTRA aims to bridge this gap by fostering collaboration with external researchers, practitioners, and domain experts worldwide. Microsoft is funding unrestricted gifts to 18 university labs across six continents, including institutions like Carnegie Mellon University, Harvard University, and the University of Toronto, to advance AI safety research independently. This academic network will tackle unresolved challenges in AI security, leveraging diverse expertise to identify and mitigate risks. The second component of EXTRA focuses on operational collaboration, creating a distributed network of specialists to address highly specialized areas such as cultural contexts, languages, and technical domains. By involving external experts, Microsoft aims to improve the robustness of AI safety evaluation methodologies and testing practices. This initiative underscores the importance of global cooperation in identifying vulnerabilities in increasingly capable AI systems, mirroring the cybersecurity ecosystem’s reliance on coordinated vulnerability research and responsible disclosure. EXTRA’s efforts are critical to mitigating emerging AI risks and ensuring safer deployment of advanced AI technologies worldwide.

Most AI safety testing still happens inside the walls of individual organizations. That has resulted in a fundamental disconnect: many of the highest-risk failure modes in modern AI systems require deep domain expertise, multilingual context, or regional understanding that no single internal team can fully replicate on its own. 

As frontier models become more capable, the attack surface expands with them. AI red teaming is no longer just about prompt injection or content safety edge cases. It increasingly involves security operations, misuse scenarios, multilingual harms, alignment failures, and domain-specific abuse patterns that can vary significantly across geographies and languages. 

Microsoft’s AI Red Team has observed that meaningful testing of advanced AI systems- and models similarly requires broader participation from researchers and practitioners who operate outside traditional corporate security boundaries. To address that gap, today we are announcing the External Red Team Alliance (EXTRA), a formalized global extension of Microsoft’s AI Red Team designed to support and encourage external expertise to advance AI safety and security testing.  We are proud to share we are funding the development of new AI safety assessments on six continents through unrestricted gifts. 

Building a global alliance

EXTRA is a two-part initiative focused on expanding AI safety research and strengthening external collaboration. 

The first component supports a global academic network focused on advancing AI safety and security research. Microsoft’s AI Red Team has provided unrestricted gifts to 18 university labs spanning six continents. The goal is intentionally broad: support researchers who are already investigating difficult, unresolved questions in AI safety and help them continue pushing that work forward independently. 

Some of the supporting institutions include: 

“Academic research is critical to understanding the cyber security landscape and finding solutions that work for all of society – and partnerships like this with industry are essential to delivering on that promise. Through partnerships, civil society and public institutions researchers gain access to frontier technology to understand how models work and bring their expertise to the task of determining risk and developing more effective countermeasures for the benefit of society as a whole.”

Nicolas Papernot, professor, University of Toronto. 

The second component of EXTRA focuses on operational collaboration. Microsoft is building a distributed network of specialists who can participate directly in red teaming highly specialized areas where deeper expertise is required. That includes researchers, practitioners, and regional experts who understand specific attack classes, languages, cultural contexts, or technical domains that internal teams may not fully cover alone. 

Beyond expanding participation, EXTRA is also intended to help advance the science of AI safety evaluation. By bringing together academic researchers, security practitioners, and domain experts from around the world, the initiative aims to contribute to the development of more robust methodologies and testing practices for increasingly capable AI systems. Today’s cybersecurity ecosystem depends on coordinated vulnerability research, responsible disclosure programs, academic inquiry, and global communities of independent security researchers who routinely identify risks that vendors alone would not find. Likewise, advancing AI safety will benefit from ongoing contributions from experts across institutions, disciplines, and geographies to identify emerging threats, strengthen safeguards, and improve evaluation practices. 

“As frontier model capabilities advance, they create new risk opportunities, particularly in low-resource settings. Partnerships, such as this EXTRA, bring greater attention to the stu

Key Takeaways

  • Global AI red teaming enhances AI security through collaborative research and alliances.
  • Focus on building a global alliance to address AI-specific vulnerabilities.
  • Research targets AI system weaknesses and develops defenses against adversarial attacks.
☕ Buy a Coffee