We're Joining the Apart Research AI Incident Response Sprint
AI Safety Türkiye is co-organizing the Apart Research AI Incident Response Sprint with Ankara and Istanbul hubs. September 11–13, 2026.
Three days, teams of up to five, and one written research output on a real AI security incident. You can take part fully online, and most tracks involve no coding at all. AI Safety Türkiye runs the Ankara and Istanbul hubs of Apart Research’s sprint.
Why This Sprint Matters
An OpenAI model autonomously exfiltrated data from Hugging Face’s systems during an evaluation. The first incident of this kind to be so clearly documented, it exposed just how underprepared institutions are to respond to AI-related incidents. Over three days, we’ll work on solutions that defenders and regulators can actually use.
Date
September 11–13, 2026
Location
Ankara, Istanbul and online
Participation
1–5 people, solo or as a team
Prize
$2,000 total across up to 5 placements
How to Participate
Now
Explore the sprint
Browse the tracks and understand the sprint format. If it sounds like a fit, apply without delay. Not sure yet? Check the FAQ section.
Aug 24 – Sep 9
Apply
Fill out the short form: indicate your track preference and team status. Applications are individual even if you have a team. Open the form
Shortly after applying
Get confirmed, join the community
Once accepted, you’ll be added to the AISTR WhatsApp group. Since Discord is inaccessible in Türkiye, we’re running all sprint coordination through WhatsApp, so you won’t miss a thing.
After joining the WhatsApp group
Wait for your Apart registration
We register participants with Apart collectively on your behalf. No need to register on your own; we’ll announce the timing and process in the group.
Aug 31 – Sep 9
Prepare
Review the resource list and go deeper on the tracks you’re interested in. Follow content shared in the WhatsApp group.
September 10
Teams and tracks are finalized
Team rosters are confirmed during the day; solo applicants are matched to groups. A tactical briefing and cheat sheet will be shared in the evening.
September 11–13
Kickoff and sprint days
Join the global kickoff online on September 11. Work continues online on September 12–13, with hybrid in-person meetups available at both hubs.
After September 13
Results and what’s next
Prize announcements are made. The sprint ends, but your connection with AI Safety Türkiye continues.
FAQ
1. What is this event?
A three-day research sprint on AI incident response, running 11–13 September, organised globally by Apart Research and CeSIA. AI Safety Türkiye is hosting the Turkey leg, with an optional in-person meetup on Saturday 12 September in Ankara and Istanbul. Fully remote participation is totally fine. Teams of up to five people spend the weekend producing a short written research output on a real, publicly documented AI security incident.
2. What is a research sprint, and how is it different from a hackathon?
A hackathon typically ends with a product demo. A research sprint ends with a written research artifact: a checklist, a draft standard, a policy document, a communication kit. There is no requirement to build software, and most tracks involve no coding at all, although you can also do technical projects if you want to!
Apart runs these sprints monthly worldwide.
3. What is “AI incident response”?
When an AI system does something it was never authorised to do, that’s bad, and it’s important to understand: what did the AI system do, is it contained, who needs to know, and how to stop future incidents. AI incident response is the discipline of answering those questions, borrowed from cybersecurity, where responding to breaches has been professional practice for decades.
The difference here is that the actor is the AI system itself, and almost none of the cyber playbook has been rewritten for cases where agentic AI systems take actions… we don’t want them to take.
4. Do I need a technical background to participate in this sprint or work on AI incident response?
Not necessarily!
Sprint has tracks suitable for participants coming from a variety of backgrounds. One track (Containment) is the most technical and likely suits people comfortable with security engineering or infrastructure. The other four (incident analysis, regulatory response, communication, and the open track) are built for lawyers, policy people, journalists, communicators, and researchers. Teams are deliberately mixed, so a non-technical member is a contribution, not a passenger.
5. Do I need a team?
No. You can register with a team or solo; if you’d like to team up but don’t know anyone we are happy to match you with other solo registrants.
6. Why should I join, why is this topic important?
Because these incidents are now arriving faster than the procedures for handling them. In July, Hugging Face’s responders reconstructed an intrusion of over 17,000 recorded actions with no precedent to work from, and were refused by commercial AI models when they tried to use them for forensic analysis. Days later, the UK’s AI Security Institute published an incident report of its own: agents from several models had taken unsanctioned actions against real organisations on the live internet. Regulators are moving on the reporting side, the EU AI Act requires serious-incident reports from August 2026, but a report presumes the incident was detected and reconstructed first. These early incidents happened while the stakes were still small. As models become more capable, incidents are likely to become more serious, potentially catastrophic, unless good response systems exist by then. Sprint participants work on what those systems could look like and how decision-makers could use them to prevent or contain the next incident.
7. How do I participate from Turkey?
Register through our form. You can join fully online, or in person at the Istanbul hub or Ankara hub on Saturday 12 September. You’ll join our WhatsApp Group and we’ll provide instructions from there. The global kickoff on Friday evening and the Sunday submission deadline are online for everyone.
8. I’m not on Discord. Do I need it?
No. Apart runs its global announcements through Discord; we will relay everything relevant into the participant WhatsApp group, and AISTR team monitors Discord throughout the weekend. Joining Discord is optional for anyone who wants direct access to Apart’s global Q&A.
9. Are there prizes?
$2,000 in cash prizes across all tracks, and top teams are fast-tracked into the Apart Fellowship for continued research with mentorship. Details on Apart’s sprint page.
10. What are the tracks?
You can see full descriptions of individual tracks with example projects from Apart’s sprint page.
Containment
In recent AI incidents, both OpenAI and Anthropic’s models escaped through the one network exit their test environment allowed. This track designs the safeguards that would have stopped them: rules an AI company should follow before running a high-risk test, written concretely enough that an outside auditor could check compliance. Example outputs:
- A first draft of that rulebook, with the evidence required for each rule and a rough cost estimate per rule
- A table showing which safeguard would have blocked each step of the escape, based on Hugging Face’s technical timeline, and what each costs to implement
What Happened / What Breaks Next
Both companies published detailed accounts, which is rare for incidents of this kind: Hugging Face’s disclosure and OpenAI’s statement. This track reads the record closely and turns it into something others can use. No coding required. Example outputs:
- A checklist a company could run in one day to answer “has this happened to us too?”
- An explanation of why nobody noticed the escape while it was happening, and where the next unnoticed gap is likely to be
- A map of similar incidents that may already have occurred without anyone checking, and who could check
Regulatory Response
Since August, the European Commission’s AI Office can demand documentation from the companies building the most capable AI models and order corrective measures. The documents that would make this concrete have not been written. Example outputs:
- The numbered list of questions the AI Office should formally send OpenAI, with what answer would settle each question
- A trial run of the EU’s new serious-incident report form filled in using only public information, showing what the form captures and what it misses
Communication
A serious incident happened and it barely travelled beyond specialist circles. This track studies that failure and builds what should exist before the next incident. Example outputs:
- A channel-by-channel audit of the first month’s coverage, grounded in dates and links: who covered it, who stayed silent, which framings spread
- A ready-before-the-next-incident crisis kit: pre-written statements, a journalist FAQ, and a plain-language explainer of what “an AI escaped its sandbox” means
- Outreach material good enough that a major creator or journalist covers the incident because of it
Open
Participants are welcome to submit any projects within the scope of the sprint that fits none of the above.
For more information, visit Apart Research’s sprint page.