CAISI and the Department of Commerce: who tests U.S. AI models
If you work in security or compliance, it helps to know who inside the U.S. government actually tests the AI models your organization may soon depend on. That job now sits with the Center for AI Standards and Innovation (CAISI). A common question is whether CAISI competes with the Department of Commerce — it does not. CAISI operates directly underneath Commerce, as a specialized technical center. Here is how the pieces fit together.
The organizational hierarchy
- The U.S. Department of Commerce is the cabinet-level federal agency, led by Secretary Howard Lutnick.
- NIST (the National Institute of Standards and Technology) is a sub-agency housed within the Department of Commerce.
- CAISI is a specialized center housed within NIST.
So there is no turf conflict by design: Commerce sets the agenda, NIST provides the standards home, and CAISI does the hands-on technical work.
How they work together
Governance and mandate. The Commerce Department sets the overarching political and economic agenda for CAISI. When the previous “U.S. AI Safety Institute” was overhauled into CAISI, the change was officially executed and announced by the Department of Commerce, aligning the center with its goals of promoting commercial competitiveness and reducing excessive regulation.
Model vetting and operations. While Commerce handles broad administrative policy, CAISI acts as the technical “startup within government.” It is the entity that signs voluntary testing agreements with major AI companies — including Google DeepMind, Microsoft, and xAI — to perform hands-on red-teaming, security evaluations, and baseline testing on new AI models before public release.
Inter-bureau collaboration. CAISI frequently coordinates with other arms of Commerce — notably the Bureau of Industry and Security (BIS) — to monitor foreign AI adversaries, evaluate international competition, and track potential national security threats such as biosecurity and cybersecurity vulnerabilities.
Why this matters for security practitioners
- Baseline expectations. The red-teaming and evaluation practices CAISI applies to frontier models increasingly shape what “reasonable” AI security testing looks like across industry.
- Supply-chain awareness. Knowing which models have been through voluntary government testing — and what that testing does and does not cover — is part of evaluating AI you adopt.
- Standards to watch. CAISI’s guidance and NIST’s broader AI standards work are becoming reference points for AI governance, procurement, and compliance programs.
Understanding how AI is governed, tested, and secured at this level is part of what we cover in the AI for Cybersecurity Practitioners program — applying AI to threat analysis and secure enterprise adoption, with an eye on the standards landscape shaping it.
Sources
- Voices for Innovation — Commerce Department announces the Center for AI Standards and Innovation
- Technical.ly — coverage of the AI Safety Institute overhaul under Secretary Lutnick
- ASME — Commerce Department launches new center to guide AI standards and security
- NIST — CAISI (nist.gov/caisi)
- FAS — “A National AI Laboratory at Commerce”
- ExecutiveGov — CAISI AI testing agreements (Google DeepMind, Microsoft, xAI)
- MeriTalk / SSTI — reporting on the AISI-to-CAISI rebrand
This article summarizes publicly reported information for educational purposes and is not legal or compliance advice.
