SPAR Fall 2026 — Application Prep Plan

Companion to the project catalogue. Covers the six tier-1 and tier-2 projects in depth, tier 3 as a reuse map. Tier 4 gets one line; tier 5 is out.

Assumption I’m working from: policy / law / writing lead, no ML engineering, ~20 hrs/week available. If that’s wrong the P06 and P07 sections change most.

The clock

DateWhat
28 Jul 2026Mentee applications opened
18 Aug 2026Applications close — 20 days from today
4 Sep 2026Decisions released
14 Sep – 14 Dec 2026Research period
19 Dec 2026Demo Day

Mentors may reach out for interviews or trial tasks before Sept 4, so anything you publish between now and mid-August is still working for you after you submit.

Five decisions that shape everything else

1. Apply to 8–10 projects, not 6. SPAR’s own Fall 2025 numbers: 1–2 applications → 13% acceptance; 3–5 → 20%; 6–10 → 33%. Each application is evaluated independently by its own mentor. The six below are the ones worth building for; three or four tier-3 projects should be bolted on in the last week using material you’ve already written. Ranking is submitted separately, so applying widely doesn’t dilute your stated preferences.

2. Two writing tracks, six applications. Nearly every application question in your tier 1/2 set is a variation on “show me you can write about governance with real sources.” Rather than writing six disconnected sets of answers, write two substantial pieces and let each feed three applications. Details in The two writing tracks.

3. Your structural advantage is Poland. Poland is, alongside Lithuania, one of only two EU states to designate a single body as sole market-surveillance authority for the AI Act — and the only one building an entirely new institution (KRiBSI) to do it, while NASK separately runs an AI safety research centre. That is a live, under-documented natural experiment that sits directly on top of P20’s second application question and P14’s whole premise. Almost no other applicant will have it. Use it.

4. Front-load the two heaviest applications. P15 (500-word doctrinal critique + 300-word research question + academic writing sample) and P20 (two 300-word answers that need primary-source work) are where the marginal hour pays most. P14 is the cheapest strong application in the set — its second question is explicitly capped at ~15 minutes of research.

5. Don’t cold-email mentors. Nothing in this round is off-cycle, and SPAR routes everything through the form. The exception: if a genuine ambiguity in a listing affects whether you apply, a short factual question is fine — see the note under P07.

The two writing tracks

Both are aimed at a single deadline: something publishable by ~10 August, so you can link it in the applications.

Track A — the Poland / middle-power file

Flagship (~2,500 words): What a Polish AI Safety Institute would actually do — and what KRiBSI won’t.

The argument to make: Poland answered the “why not just give it to the market-surveillance regulator?” question by building a new regulator — but built it as a compliance body, not an evaluation body. Those are different functions with different staffing, different independence requirements and different costs. Separate them explicitly, work out what the evaluation function would minimally cost, and say where it should sit (KRiBSI? NASK’s safety centre? neither?).

This single piece is:

  • the evidence base for P20 (a) and (b) — question (b) is literally the minister’s objection, and you’d have a worked national case study instead of an abstract answer;
  • the “what version of this project excites you” answer for P14 (1);
  • a demonstration of primary-source work (draft act, NASK materials, budget documents) which is P20’s stated core prerequisite.

Supporting short posts (600–900 words each):

  • “KRiBSI, explained” — write it to P13’s Q1 spec exactly: one governance instrument, explained to a smart non-specialist, sources cited, one place marked where you’d add a figure. That post is the P13 answer, and it becomes the P13 Q3 link.
  • “Agentic flooding at ZUS” — take Schmitz’s “agentic flooding” concept (surges in citizen submissions as AI makes filing cheap) and apply it to one concrete Polish institution. This is the P14 Q2 answer in embryo.
  • A response to Anton Leicht’s How AI Safety Is Getting Middle Powers Wrong — he argues the safety movement should abandon “middle powers as lever on US development” for national-interest deployment work. P20’s mentors are AI Safety Poland; they will have read it. Disagreeing well with it is a strong signal.

Track B — the law & liability file

Flagship (~2,500–3,000 words): Can a circuit be evidence? Mechanistic interpretability and the mens rea problem.

Structure it as: (i) what the law currently requires to prove intention/knowledge/recklessness; (ii) what SAEs, circuit tracing, attribution graphs and CoT monitoring actually produce; (iii) the evidentiary gap — admissibility standards (Daubert/Frye in the US; expert-evidence rules in England & Wales), reliability, and the contested faithfulness of chain-of-thought; (iv) one honest concession about why this probably doesn’t work yet.

This feeds:

  • P15 Q1 and Q2 almost directly, and can double as the academic writing sample if it’s properly cited;
  • P06 RQ2 (the legal question) by demonstrating you can do doctrinal analysis of a novel technical object;
  • P13 as a second link, if the KRiBSI post doesn’t fit the reviewer’s taste.

Supporting short post: “The hole where the AI Liability Directive was.” The Commission withdrew the AILD in its February 2025 work programme; the recast Product Liability Directive (EU) 2024/2853 must be transposed by 9 December 2026, and treats software and AI systems as products under strict liability. So the EU’s AI liability regime is now the AI Act plus a product-liability directive that was never designed for agents. That’s current, checkable, and exactly the kind of “frontier doctrinal issue” P15 asks you to enunciate.

Three-week schedule

Week 1 (29 Jul – 4 Aug) — reading and drafting

  • Read the per-project core lists below for P15, P20, P14 (the three highest-fit).
  • Pull Poland primary sources: draft Act on AI Systems, KRiBSI provisions, NASK safety centre materials, any published budget figures.
  • Draft Track A flagship to a full first draft.
  • Draft Track B flagship outline + section (i).

Week 2 (5–11 Aug) — publish and convert

  • Finish and publish Track A flagship + “KRiBSI, explained”.
  • Finish Track B flagship; publish.
  • Write P20, P14, P13 application answers directly out of the published material.
  • Draft P15 Q1 and Q2.

Week 3 (12–18 Aug) — breadth and submit

  • Finish P15 (including writing sample selection) and P07.
  • Decide on P06 — answer RQ2 only, or skip.
  • Add 3–4 tier-3 applications using existing material (see Tier 3 — reuse map).
  • Submit ranking. Submit by 16 Aug, not 18 — leave slack.

Tier 1

P07 — Catastrophic Risks of AI in Space

Catalogue entry · Stefano Vergani (KCL Physics postdoc; GovAI) · 12 hrs/wk · team 3–4

Fit. Good, with a caveat. The mentor explicitly wants one mentee with a scientific background and the rest generalists from policy, economics, social science or law — so the generalist slots are the target. He says he values “interest in the project, independence, and reliability” above credentials, and the application questions are imaginative rather than credential-gated. That’s an unusual opening.

One thing to check: the listing says 12 hrs/week, but the “what you’ll do” text says he expects ~8. Worth a one-line clarifying email — it’s a legitimate question and a low-risk first contact.

Core reading

  • Will we really put data centers in space? — Forethought. Cited by the mentor; read first.
  • 3 stages of competition for the long-term future — also cited by the mentor.
  • SPARTA (Aerospace Corporation, currently v3.2) — the space-systems attack taxonomy. Single highest-leverage thing you can read for question 1: it gives you the vocabulary (ground segment, link segment, space segment; reconnaissance → initial access → execution → persistence → impact) that separates a serious answer from a sci-fi one. Two techniques are already AI-specific — EX-0012.13 Poison AI/ML Training Data and DE-0003.12 Poison AI/ML Training for Evasion. Citing those by ID shows you did more than skim.
  • The Viasat / AcidRain incident (Feb 2022) — the canonical real-world case: a misconfigured VPN into the ground management network, wiper malware pushed to modems. Note the lesson: it was a ground segment attack, no spacecraft compromised.
  • Orbital data centers’ feasibility gap is a governance risk — Brookings.
  • The Next Frontier of AI Infrastructure Is in Orbit, and Nobody Is Governing It — UCL STEaPP.
  • Skim the Outer Space Treaty Arts. VI–VIII (state responsibility for national activities; jurisdiction over registered objects) and the Liability Convention — the legal spine of any “who is responsible for an orbital agent” argument.

What to write / do. Nothing new needs publishing for this one. Instead, spend one session building a one-page attack tree from SPARTA covering ground segment, uplink/downlink, supply chain and model-level compromise — that is your answer to question 1. For question 2 (“we strand a rogue AI in orbit — what could go wrong?”), the strong answers are not sci-fi: Kessler-syndrome debris from an uncontrolled asset, the satellite still having a functioning downlink to someone, no legal mechanism to deorbit another state’s registered object, and the precedent value of a state unilaterally disabling orbital infrastructure. He says you may use an LLM but must justify what you write — so keep a citation for every claim.

Honest risk. Three-to-four person team, 12 hrs/week, and a mentor whose day job is particle physics. The topic is genuinely neglected, which cuts both ways: less competition, but also less existing literature to stand on.


P15 — Reading the Machine’s Mind

Catalogue entry · Elija Perrier (Cambridge Law affiliate; UTS) · 10 hrs/wk · team 1–2 · Co-working, 5+ hrs/week/mentee

Fit. Potentially the best in the set, and the most demanding application. Team of 1–2 with 5+ hours of mentor co-working per week is an unusually high-touch arrangement, and the output is a publication-quality manuscript with a named collaborator. He explicitly welcomes “exceptional applicants from philosophy, computer science, public policy, or related disciplines,” so a law background is preferred but not gating.

Know your mentor. Perrier is a 20-year practising lawyer and a quantum-ML PhD — the rare person who will notice if you fudge either side. Read at least:

  • Operationalising Extended Cognition: Formal Metrics for Corporate Knowledge and Legal Accountability (arXiv:2510.16193) — his ACM CS&Law 2026 paper. Closest to this project’s core.
  • Position: Stop Acting Like Language Model Agents Are Normal Agents (arXiv:2502.10420, with M. Bennett).
  • Agent Identity Evals (arXiv:2507.17257) and Typed Chain-of-Thought (arXiv:2507.02541) — skim; they show how he thinks about formalising agency and verifying reasoning.

Core reading — law

  • Salib & Goldstein, AI Rights for Human Safety — you already know this one from the last round; it’s still the sharpest instrumental argument for legal status.
  • The Ethics and Challenges of Legal Personhood for AI — Forrest, Yale LJ Forum. Good critique target.
  • Artificially Intelligent Persons, 58 Hous. L. Rev. 537 (2021) — the actus reus / mens rea framing.
  • Recast Product Liability Directive (EU) 2024/2853 + the withdrawn AI Liability Directive. Current doctrinal state of play in the EU; the mentor asks specifically about US or UK, so treat the EU as contrast.
  • Evidence law: Daubert/Frye admissibility for novel scientific evidence (US); expert-evidence rules in England & Wales.

Core reading — interpretability

  • Anthropic’s circuit-tracing / attribution-graph work and the sparse-autoencoder feature literature — enough to describe honestly what these methods do and don’t establish.
  • The chain-of-thought monitorability debate — specifically the argument that CoT is not guaranteed faithful. This is the technical limitation to name in Q2.

Application notes. Q1 wants a critique with “a clear enunciation of current and frontier doctrinal issues” in US or UK law — pick one jurisdiction and stay in it. Q2 asks whether interpretability could ever be legally persuasive evidence of mens rea: the strongest answer is a qualified no-for-now with a specific mechanism for what would have to change (e.g. validated error rates, adversarial robustness of the probe, an evidentiary standard for “the model’s internal state at time t”). Q3 wants an academic writing sample — this is the one project where the Track B flagship needs proper footnotes rather than blog styling.

Honest risk. The heaviest application in the set by a wide margin. If time runs short in week 3, this is the one to protect, not the one to drop.


P20 — A Design Blueprint for Middle-Power AI Safety Institutes

Catalogue entry · Michał Kubiak; Daniel Polak (AI Safety Poland) · 8 hrs/wk · team 3–4

Fit. The strongest expected value in the set. Explicitly “a research-and-writing project, not a technical one” — no ML or programming required. Larger team (3–4) means more slots. Polish mentors, and you have the Polish case.

Core reading

Application notes. Question (b) — “why not just give the existing market-surveillance regulator an AI safety mandate?” — is where you win or lose this. The generic answer talks about independence and technical staffing. Your answer names a country that faced exactly this choice, built a new body anyway, and built it for conformity assessment rather than dangerous-capability evaluation — then explains why that distinction matters and what it costs. Give the minister’s argument real force first (he’s right about duplication, hiring, and the fact that most AI harms in a mid-sized state are consumer-protection harms), then draw the line at frontier evaluation.

For (a), the function that a network can’t substitute for is the one that has to run on nationally deployed systems under national legal authority and feed advice into a national emergency chain of command. Networks share methods; they don’t hold your government’s hand at 3am.

Honest risk. Polish mentors may attract a Polish applicant pool, so your national angle is less unique here than it is in P14. Compensate by being the person who has actually read the draft act.


Tier 2

P06 — Token taxes as a mechanism for reducing AI-driven power concentration

Catalogue entry · Lucas Irwin (GovAI; Oxford Martin AIGI) · 5 hrs/wk · team 2–3

Fit. The weakest on paper of the six — the prerequisites are stated as hard credentials (PhD/Master’s in Law or Political Science for RQ2; PhD/Master’s in Economics for RQ3). But the application is structured so you answer only the RQ you want. Answer RQ2 only. Ignore RQ1 and RQ4 entirely; they need Python, transformers and formal verification.

Core reading

  • Irwin, Wu & Barez, Position: Token Taxes Can Mitigate AI’s Economic Risks (arXiv:2603.04555) — his own paper, and the spine of the project. Read the staged audit pipeline (black-box token verification → norm-based rates → white-box audits) carefully.
  • Token Taxes — Windfall Trust policy atlas entry.
  • Background on the comparators: OECD Pillar One/Two and the digital services tax standstill, EU VAT Directive constraints on new turnover taxes, and the state-aid angle.

RQ2 answer skeleton (the legal issues). Nexus and permanent establishment — where does an inference “occur” when the model is hosted abroad and consumed domestically? Characterisation — is a token tax a turnover tax (and therefore potentially caught by Art. 401 of the VAT Directive in the EU), an excise, or a services tax? Trade law — GATS national-treatment and non-discrimination exposure if incidence falls mainly on foreign providers, plus the US retaliation precedent from DST disputes. Double taxation and treaty override. Enforcement against non-cooperative providers and the compute-governance chokepoints that would be needed. Definitional risk — “token” is a provider-defined unit, which creates both an avoidance surface and a measurement problem.

Honest risk. 5 hrs/week and detailed mentor guidance make this a cheap, pleasant project if you get it — but the stated credential bar is the highest in your set. Treat it as a stretch application, not a core one. Cost to apply: one 300-word answer, if the Track B flagship has already warmed you up on doctrinal writing.


P13 — Writing a textbook for AI Governance

Catalogue entry · Markov Grey; Charbel-Raphaël Segerie (CeSIA) · 10 hrs/wk · team 2–4

Fit. Very good, and the selection criterion is stated outright: “Strong expository writing… This is the main thing we screen for.” You have a public writing surface, which most applicants don’t. The output is a published standalone paper and a chapter of the AI Safety Atlas, which is already used as a course textbook.

Core reading

Application notes. Q1 (explain one governance mechanism to a smart non-specialist, 400–500 words, sources cited, mark one place for a figure) is the screen. Write the KRiBSI post to this spec and you get the answer and the Q3 link out of the same work. For Q2 (what stays durable vs. what’s the current-events layer), the good answer separates mechanisms — thresholds, conformity assessment, auditing, liability allocation, compute chokepoints — from instances — which threshold, which act, which institute. Say which you’d teach and why.

Pick your target area deliberately in the application: regulation and law or international policy and institutions fit you; compute governance and technical AI governance don’t.


P14 — [Jurisdiction-specific] Public-Sector AI Resilience Agenda

Catalogue entry · Chris Schmitz (Centre for Digital Governance, Hertie School) · 5 hrs/wk · team 3–4

Fit. Excellent, and the cheapest strong application in the set. “No must-have prerequisites.” 5 hrs/week. Team of 3–4. The mentor is “most excited about US, UK, EU, or an EU member state” — that’s an open invitation for a Poland-focused memo, and it’s the version of the project fewest applicants will pitch.

Core reading

  • Schmitz et al., Oversight Structures for Agentic AI in Public-Sector Organizations — his own paper; the five governance dimensions (cross-departmental implementation, comprehensive evaluation, security protocols, operational visibility, systematic auditing) are the frame he’ll be reading your answer through.
  • His Hertie profile and Scholar page — his thesis is on how AI uptake reshapes bureaucratic institutions.
  • The project description itself is unusually rich: “agentic flooding,” the mandate gap (UK AISI can’t set cross-government cyber policy), and the crowding-out effect where creating a dedicated unit dis-incentivises everyone else from thinking about the problem. Quote these back with a concrete instance.

Application notes. Q1 is 100 words on which version you’d want — say jurisdiction-specific policy memo, Poland, and name the ministry or agency. Q2 asks you to pick one AI risk and one government and assess the response, capped at ~15 minutes of research; the discipline is to pick something specific and verifiable (e.g. how KRiBSI’s mandate does or doesn’t cover incident reporting into the national CSIRT structure) rather than a general “Poland is behind” take.

Honest risk. Almost none. This is the highest ratio of fit-to-effort in the set. If you only finish two applications, make them this and P20.


Tier 3 — reuse map

These are worth bolting on in week 3 with material you’ll already have. Don’t build for them.

ProjectReuseCost
P18 — Middle Powers & frontier computeTrack A wholesale — same middle-power frame, compute instead of institutesLow
P01 — US extraterritorial surveillance & allied trustTrack A’s “what does a middle power actually need from the US stack” argument; asks for a writing sample you’ll haveLow
P17 — Strategic stability when states delegate to AITrack A’s national-interest framing; P07’s loss-of-control-at-distance materialMedium
P11 — Helpful persuasion vs. harmful manipulationTrack B’s doctrinal method; same mentors as P13, so one strong writing sample serves bothLow
P03 — Interoperability standards for agentic AITrack B’s agent-identity and accountability-chain material; Perrier’s Agent Identity Evals is directly on pointMedium
P19 — Normalization of Deviance in AI DevelopmentNothing much reuses; but 5 hrs/wk and a short applicationLow
P05 — AI strategy and futurismFive personal-background questions, no research required — cheapest application on the entire listVery low
P08 — Simulating AI PoliciesRequires Python + HuggingFace. Skip unless that’s wrong about you.
P16 — AI ConsciousnessPhilosophy-of-mind reading you don’t currently haveHigh

Suggested week-3 additions, in order: P05, P14 is already core, P18, P01, P11. That takes you to 9–10 applications.

Tier 4: only P09 (Wikipedia contributions) is worth a glance — 4–7 person team, limited mentor involvement, and a genuinely low bar to entry. Add it if you have a spare hour on 16 August.


Shared assets checklist

Build these once; paste them everywhere.

  • Writing sample, academic register — Track B flagship with proper citations (for P15, P06)
  • Writing sample, public register — KRiBSI explainer (for P13, P14, P20)
  • Background paragraph — concrete tools, jurisdictions, and named papers. SPAR’s advice page is explicit: “Instead of stating ‘ML experience,’ describe the tools, models, and projects”; “rather than ‘I follow discussions and read papers,’ cite concrete papers.”
  • Hours commitment — decide your real number before you write it. P08 wants 15, P07 wants 12, P06 and P14 want 5. The matching algorithm allocates against your stated availability, so overstating it doesn’t help and understating it can knock you out of the heavier projects.
  • Reading log — keep one line per source as you go; it makes the “cite concrete papers” answers write themselves.

Verification pass before you submit

  • Every claim in a published piece has a source you’ve actually opened
  • Poland figures (KRiBSI structure, NASK remit, any budget numbers) checked against the primary document, not a secondary summary
  • Word limits respected exactly — several of these are hard caps
  • Each application answers every part of the prompt (SPAR’s advice page flags this specifically)
  • Ranking submitted, honestly ordered
  • Submitted by 16 August

Sources: SPAR program FAQ and timeline, SPAR advice for applying, and the project listings in fall2026-projects.