The network of national AI safety institutes is among the more substantive things to come out of the international AI governance process, and it is routinely described in terms that overstate what it can do.
What it has actually achieved
Shared methodology. Before the network, each institute risked developing its own evaluation approach, producing findings that could not be compared and duplicating expensive work. Joint testing exercises and shared protocols address that, and it is a real achievement that would not have happened by itself.
It has also created a channel for findings that individual institutes would be reluctant to publish alone — a conclusion published jointly by bodies answering to different governments is considerably harder for any one of them to quietly withdraw.
What it has not addressed
Most of these institutes evaluate under voluntary arrangements. A developer grants access because it chooses to, and can decline. The cost of declining is currently reputational and modest.
This means the institutes' influence depends on continued cooperation from the organisations they exist to scrutinise — a position with well-known failure modes. The evaluations conducted are real and useful; the set of evaluations conducted is determined substantially by the evaluated.
Independence and where an institute sits
Institutes housed within economic or industrial ministries inherit an institutional interest in the sector's success. Those housed within security establishments inherit a different one, and different constraints on what they can publish. Neither is disqualifying and both shape output in ways worth knowing when reading a finding.
What would change the picture
Statutory access powers in at least one significant jurisdiction. Once one institute can compel access, the voluntary arrangements elsewhere acquire a fallback that changes the negotiation. Nothing else on the current agenda alters the underlying asymmetry.