Microsoft Launches Global AI Red Team Alliance to Bolster AI Safety
Microsoft establishes the External Red Team Alliance (EXTRA), a global network of academic and security researchers, to enhance AI safety testing and address complex failure modes.

Microsoft has announced the formation of the External Red Team Alliance (EXTRA), a significant initiative aimed at enhancing the safety and security of artificial intelligence systems. This program formalizes a global network of researchers and practitioners, recognizing that the most critical AI failure modes often require specialized expertise, multilingual context, and regional understanding that no single internal team can possess. As AI models become more sophisticated, their attack surfaces expand, necessitating a broader, more diverse approach to security testing beyond traditional methods like prompt injection.
The core challenge addressed by EXTRA is the inherent limitation of internal AI safety testing. Microsoft's own AI Red Team has observed that testing advanced AI systems effectively requires input from experts operating outside corporate security boundaries. These experts can bring unique perspectives on security operations, misuse scenarios, multilingual harms, alignment failures, and domain-specific abuse patterns that vary greatly across different geographies and languages. EXTRA seeks to bridge this gap by actively engaging external talent.
The initiative comprises two key components. Firstly, it supports a global academic network through unrestricted gifts to 18 university labs across six continents. These funds are intended to empower researchers already investigating complex AI safety questions, enabling them to continue their work independently. Participating institutions include prominent universities like Carnegie Mellon University, Harvard University, University College London, and the University of Melbourne, among others, fostering a broad base of academic inquiry.
Secondly, EXTRA focuses on operational collaboration by building a distributed network of specialists. This network will include researchers, practitioners, and regional experts who can contribute directly to red teaming efforts in highly specialized areas. Their deep understanding of specific attack classes, languages, cultural contexts, or technical domains will complement the capabilities of internal teams, leading to more comprehensive security evaluations.
Beyond expanding participation, EXTRA aims to advance the very science of AI safety evaluation. By bringing together diverse experts from academia, industry, and various geographical regions, the initiative seeks to develop more robust methodologies and testing practices for increasingly capable AI systems. This collaborative approach mirrors the established cybersecurity ecosystem, which relies on coordinated vulnerability research, responsible disclosure, and independent researcher communities.
Microsoft emphasizes that the research areas funded through EXTRA align with emerging threats identified by their AI Red Team. These include examining the cybersecurity implications of AI systems themselves, such as how models can be attacked or manipulated, and exploring the potential for AI to be used in novel ways to bypass security measures. The initiative also highlights the importance of addressing risks in low-resource settings and ensuring that AI safety research has broader global impact.
The establishment of EXTRA signifies a proactive step by Microsoft to address the evolving landscape of AI security. By fostering a global, collaborative ecosystem of AI safety researchers and practitioners, the company aims to build more resilient and secure AI systems for the future, acknowledging that collective intelligence is key to navigating the complex challenges posed by advanced artificial intelligence.