Scaling AI Safety for a Multi-Agent World 2026: A $10 Million Joint Fund From Schmidt Sciences, Google DeepMind, ARIA and the Cooperative AI Foundation, With Awards up to $1 Million Closing 8 August 2026
A joint $10 million call funding one- to two-year research projects on the safety of large ecosystems of interacting AI agents, with Tier 1 awards up to $300,000 and Tier 2 awards from $300,000 to $1 million, closing 8 August 2026 at 11:59pm Anywhere on Earth.
Scaling AI Safety for a Multi-Agent World 2026: A $10 Million Joint Fund From Schmidt Sciences, Google DeepMind, ARIA and the Cooperative AI Foundation, With Awards up to $1 Million Closing 8 August 2026
Almost all published AI safety work studies one model at a time: one agent, one user, one task, one evaluation harness. The systems now being deployed do not look like that. They look like populations — thousands or millions of agents built by different companies, acting for different principals, negotiating, delegating, calling each other’s tools, and reading each other’s outputs. This call exists because the funders behind it believe that the safety properties of that world are not simply the sum of the safety properties of its parts.
Scaling AI Safety for a Multi-Agent World is a joint request for proposals from Schmidt Sciences, Google DeepMind, and the Advanced Research & Invention Agency (ARIA), run in partnership with the Cooperative AI Foundation and supported by Google.org. The fund totals roughly $10 million, split across multiple teams worldwide in two tiers. Applications opened on 11 June 2026 and close on 8 August 2026 at 11:59pm Anywhere on Earth, with decisions expected in autumn 2026.
Key details
| Item | Detail |
|---|---|
| Programme | Scaling AI Safety for a Multi-Agent World |
| Funders | Schmidt Sciences, Google DeepMind, ARIA, in partnership with the Cooperative AI Foundation, supported by Google.org |
| Administering organisation | Schmidt Sciences (manages the application portal and operations) |
| Total fund | Approximately $10,000,000 |
| Tier 1 award | Up to $300,000 for a 1–2 year project |
| Tier 2 award | $300,000 to $1,000,000 for a 1–2 year project |
| Project duration | One to two years |
| Applications opened | 11 June 2026, 6:59am EDT |
| Deadline | 8 August 2026, 11:59pm Anywhere on Earth |
| Decisions | Autumn 2026 |
| Eligible applicants | Individual researchers, teams, institutions, multi-institution collaborations; universities, national labs, institutes, nonprofit research organisations |
| Geography | Global; cross-border collaborations welcome |
| Indirect costs | Capped at 10% on Schmidt Sciences-funded projects |
| Application portal | schmidtsciences.smapply.io |
| Contact | [email protected] |
The problem the fund is trying to buy research on
The intellectual grounding for this call is the Cooperative AI Foundation’s report Multi-Agent Risks from Advanced AI, which argues that populations of interacting AI agents produce failure modes that are qualitatively different from single-agent failures — not just more of the same risk at larger scale. The categories the report identifies, and that the call echoes, include collusion between agents that were each individually well-behaved, conflict and destructive competition, destabilising feedback dynamics of the kind familiar from financial markets, emergent agency that no single system was designed to have, and security vulnerabilities that only exist because agents talk to each other.
The organising question the funders put to applicants is blunt: how do we ensure safety in a world with millions of interacting agents, built and deployed by many different actors? The phrase “many different actors” is doing real work there. A single lab can align its own agents with its own policies. Nobody controls the interaction surface between agents from different vendors, with different principals, different incentives, and different guardrails. This is the multi-principal, multi-agent setting, and it is where the call wants proposals aimed.
The four research clusters
The RFP organises the space into four clusters. Proposals may target one or span several, but the call states explicitly that depth is prioritised over breadth. A proposal that convincingly moves one cluster forward will read better than one that gestures at all four.
1. Sandboxes and testbeds. Realistic, reproducible environments in which populations of frontier-model agents can actually be studied — with tools, memory systems, and economic constraints rather than stripped-down toy settings. The published framing mentions virtual marketplaces, simulated ecosystems, and multi-organisation workflows. The strategic value here is comparability: the field currently lacks shared environments where two research groups can measure the same phenomenon and disagree productively.
2. The science of agent networks. System-level dynamics of agent populations: emergent capabilities that appear only in aggregate, collective failure modes, cascades, and structural vulnerabilities of the network itself. This cluster is the most academically open-ended and borrows naturally from complex systems, network science, economics, and epidemiology.
3. Strengthening agent infrastructure. The plumbing that makes trustworthy interaction possible — identity, reputation, verifiability, and commitment protocols. If agents cannot prove who they are, what they are authorised to do, or that they will honour an agreement, then a great deal of downstream safety work is building on sand. This cluster tends to attract systems, security, and cryptography researchers.
4. Multi-agent oversight and control. Detecting collusion, attributing behaviour to a responsible agent or principal, scalable oversight of populations too large to review by hand, and control mechanisms for systems already in deployment. This is the cluster closest to what a deploying organisation could adopt next year.
Who this fits, and who it does not
This is a research grant, not a product or startup fund. The eligible applicant list — individual researchers, teams, institutions, and multi-institution collaborations, hosted at universities, national laboratories, institutes, and nonprofit research organisations — describes an academic and nonprofit research population. Applications are welcomed globally, and the funders explicitly encourage collaborations across borders, which matters given that three of the funders are based in the US and UK.
The fit is strong if you already work on multi-agent systems, agent evaluations, AI security, mechanism design, complex systems, or protocol design, and you can credibly run experiments with frontier-model agents. It is weaker if your proposal is a single-model alignment project with a multi-agent framing bolted on. The call is specific about wanting work that engages frontier-model agents under realistic deployment conditions; a proposal built entirely on small open-weight models in a simplified grid-world will have to argue hard for why its findings transfer.
Choosing between tiers is a genuine strategic decision. Tier 1, up to $300,000, suits a focused investigation — one well-defined question, a small team, a clear deliverable such as a benchmark, a testbed release, or a paper series. Tier 2, $300,000 to $1,000,000, is for broader programmes: multiple workstreams, more people, and typically infrastructure that other researchers will use. Applying to Tier 2 with a Tier 1-sized idea and an inflated budget is a more common failure than the reverse. Reviewers assess cost appropriateness as a named criterion, so the budget is part of the scientific argument, not an afterthought.
How proposals are assessed
The call lists its selection criteria openly: research agenda fit, scientific quality and rigour, potential impact, philanthropic fit, feasibility, team expertise, cost appropriateness, and funder-specific considerations. That last item is worth reading carefully. This is a joint fund with several independent funders, each with its own remit — ARIA operates under UK public research programme rules, Google DeepMind and Google.org have their own interests, and Schmidt Sciences manages the administration. Which funder ultimately backs which award is not something the public page resolves, and applicants should not assume all awards carry identical terms.
“Philanthropic fit” is the criterion applicants most often misread. It is not asking whether your work is virtuous. It is asking whether philanthropic capital is the right instrument — whether this research would go unfunded or underfunded through conventional channels, and whether the output is a public good rather than something a commercial actor would build anyway. Say so directly in the proposal if it is true.
Application process and materials
Applications are submitted through the Schmidt Sciences SM Apply portal at schmidtsciences.smapply.io. Creating an account and opening the form early is worth doing even if you intend to write late, because the form itself tells you exactly which fields and attachments are required — and the public programme page does not publish a full section-by-section list of proposal components, page limits, or file format requirements. Treat the portal form and the official FAQ as authoritative on those points rather than any third-party summary, including this one.
What you can prepare regardless of the form’s structure:
- A sharp central claim. One or two sentences naming the multi-agent phenomenon you will study and what would count as having learned something.
- A concrete experimental setup. Which frontier models, how many agents, what environment, what is measured, what the baseline is.
- Deliverables another researcher can use. Testbeds, benchmarks, protocol specifications, and datasets travel further than papers alone in a field this young.
- A budget consistent with the 10% indirect cost cap on Schmidt Sciences-funded projects. Check this with your institution’s research office early — some universities require a waiver or an internal exception for caps this low, and that approval can take longer than writing the proposal.
- Team evidence. Prior work showing you can actually run large-scale agent experiments, not just theorise about them.
Two informational webinars were held on 30 June and 23 July 2026, and the funders made recordings available. If you are applying close to the deadline, watching a recording is a fast way to pick up the emphases reviewers care about that the written call states only briefly.
Timeline and what happens after submission
The window is short by research-funding standards: applications opened on 11 June 2026 and close on 8 August 2026 at 11:59pm Anywhere on Earth. Anywhere on Earth means the deadline expires when it is still 8 August in the last time zone on the planet — effectively midday UTC on 9 August. Do not use that buffer as a plan. Portal submissions fail for mundane reasons: oversized attachments, a collaborator who has not confirmed, an institutional signature that arrives late.
Decisions are expected in autumn 2026. The call does not publish an interview or rebuttal stage, so the written proposal should be assumed to be the whole of your case.
Common mistakes
Treating “multi-agent” as a label rather than a research object. Running two copies of a model in a conversation is not a study of agent populations. Reviewers reading a stack of these proposals will notice immediately.
Ignoring the deployment realism requirement. The call asks for work engaging frontier-model agents in realistic conditions — with tools, memory, and economic constraints. Purely abstract game-theoretic work will need an explicit bridge to that setting.
Spreading across all four clusters. Depth over breadth is stated policy, not a preference. Pick one cluster, or two that genuinely reinforce each other, and go deep.
Budgeting before checking the indirect cost cap. A 10% cap materially changes what a $300,000 award buys. Confirm your institution will accept it before you build the budget on top of it.
Assuming this is a rolling fund. Nothing in the published material commits the funders to a second round. If your work fits, this cycle is the one that exists.
Frequently asked questions
Can I apply from outside the US and UK? Yes. Applicants from anywhere in the world are encouraged, and cross-border collaborations are welcome. Confirm any funder-specific constraints through the FAQ or by email before building an international consortium.
Can for-profit companies apply? The stated eligible host organisations are universities, national laboratories, institutes, and nonprofit research organisations. Commercial labs should ask the programme directly at [email protected] rather than assume.
Do I need to pick a tier when I apply? Yes — the tiers have different funding ranges, and your budget must sit inside the one you choose. Match the tier to the scope of the work rather than to the maximum you would like.
Are open-source releases required? The public programme page does not state a formal open-science or intellectual property requirement. Given the field-building intent behind sandboxes and testbeds, planning to release usable artefacts is sensible regardless, but check the FAQ for binding terms.
What if I miss the deadline? No second round has been announced. Register your interest with Schmidt Sciences, the Cooperative AI Foundation, and ARIA so that you hear about any future call early, and use the intervening time to publish the pilot results that would make a later proposal stronger.
Official links and contacts
- Application portal and full programme details: https://schmidtsciences.smapply.io/prog/scaling_ai_safety_for_a_multi_agent_world/
- Schmidt Sciences funding opportunities: https://www.schmidtsciences.org/opportunities/
- Cooperative AI Foundation call page: https://www.cooperativeai.com/calls-for-proposals/scaling-ai-safety-for-a-multi-agent-world
- Programme email: [email protected]
Verify deadlines, tier limits, and eligibility on the official portal before submitting. Where this guide says a detail is not published — proposal section structure, page limits, intellectual property terms, and which funder supports which award — that reflects what the public pages state as of 3 August 2026, and the FAQ or programme staff are the correct source.
