NIST researcher proves finite AI guardrails can always be bypassed as agency retools its AI consortium
A NIST senior researcher published a mathematical proof that no finite set of AI guardrails can block every adversarial prompt, while the agency separately reorganised its AI Safety Institute Consortium around measurement, innovation and adoption.

A mathematical proof by NIST senior researcher Apostol Vassilev argues that an AI system protected by a finite set of rules can never be defended against every adversarial prompt, the U.S. National Institute of Standards and Technology said in a June 9, 2026, item on work published in IEEE Security & Privacy in May 2026 (DOI 10.1109/MSEC.2026.3678214).
The argument builds on Kurt Gödel’s incompleteness theorems of 1931 and concludes that for any AI guardrail made up of a finite rule set there will always exist a prompt that circumvents it. AI developers embed constraints intended to stop models from producing prohibited content such as deepfakes, malicious code and instructions for making biological weapons or illicit drugs. Because the inputs are human language, Vassilev argues, rule-based compliance checking becomes indefinitely ambiguous. Successful jailbreaks, NIST said, create real-world risks including cyberattacks, data leakage and highly personalised phishing.
Vassilev proposes a three-part response: continuous red-teaming, continuous hardening of guardrails against newly discovered adversarial prompts, and operational resilience focused on limiting damage and recovering quickly. NIST said the proof itself does not hand attackers any new method of finding exploits, and that the aim is an economic equilibrium in which the cost of an attack exceeds the resources available to the attacker.
Separately, on May 29, 2026, NIST announced that it is renaming its AI Safety Institute Consortium the NIST Artificial Intelligence Consortium and recruiting new members, resetting the group’s scope around AI measurement, innovation and adoption. The consortium was established in 2023 and drew more than 280 participating organisations, which have worked with NIST for two years on science-based guidance and standards for AI measurement.
Under the new scope, the consortium will concentrate on building an AI evaluation ecosystem, investing in AI-driven science, and promoting the use of American-made AI technologies and systems, according to the agency. NIST Associate Director Craig Burkhardt called for participation from organisations with relevant technical capabilities. Organisations that submit a letter of interest will be selected on a first-come, first-served basis among complete submissions, and existing members do not need to reapply but must sign an amended agreement consenting to the changes. Members enter into a Cooperative Research and Development Agreement with NIST. The agency cited its Strategy for American Technology Leadership in the 21st Century, the National Artificial Intelligence Initiative Act of 2020, Executive Order 14179 of 2025 and America’s AI Action Plan as the basis for the work, with submission instructions posted on the project website and in a Federal Register notice.