Hewlett Is Putting $100 Million Into AI, Bio, and Quantum Security — and There Is No Application Form. Here Is How That Money Actually Gets Allocated.
September 21, 2026 · 7 min read
Granted Research Team · Editorial policy
There is a category of philanthropic money that most grantseekers never learn to pursue, because it does not behave like a grant program. It has no portal, no deadline, no RFP, and no published eligibility criteria. It moves through relationships, field convenings, and program officer judgment. And it is often larger per grant than anything with an application form attached.
The Hewlett Foundation's Emerging Technology and Security Initiative — announced July 16, 2026, committing $100 million through 2031 — is a textbook instance. It is also unusually legible right now, because the foundation has published enough about its strategy and its first grantees to reverse-engineer how the money is being allocated.
If your organization works on AI safety, biosecurity, quantum security, critical infrastructure protection, or technology governance, this is worth thirty minutes of attention. Not because you can apply. Because you can position.
The structure
The commitment breaks down cleanly:
- $100 million total, over a five-year initiative term
- $20 million in exploratory grants during 2026 — of which $10 million was announced in February 2026 and roughly $10 million is planned for the remainder of the year
- $20 million per year as the standing annual budget once the five-year term formally begins in 2027
That structure is itself the most useful signal in the announcement, and it is worth pausing on. Hewlett is spending a full year — and a full year's budget — on exploratory grantmaking before the initiative formally starts. Foundations do that when they intend to let the first cohort of grantees define the field map that later grantmaking follows.
Leadership sits with Eli Sugarman, the foundation's Director of Special Projects, who previously ran Hewlett's decade-long Cyber Initiative. That lineage is not decorative. The Cyber Initiative spent roughly ten years building an academic and policy field that barely existed when it started — funding university centers, fellowships, and convenings rather than discrete projects. The new initiative explicitly builds on that work, plus the foundation's older lines in nuclear security and conflict resolution.
Expect the same playbook: institution-building over project funding, multi-year over one-year, and a strong preference for organizations that can produce independent expertise the field currently lacks.
The four objectives, and what each one is actually buying
The program describes four priorities. Read them as procurement categories.
1. Critical infrastructure defense. Protecting power grids, water systems, hospitals, and the information ecosystem from AI-enabled threats, globally. This is the most concrete of the four and the most likely to fund operational work — not just research about threats, but capacity to counter them.
2. Emerging technology safeguards. Addressing security risks from biotechnology and quantum computing "while intervention windows remain open." That phrase is load-bearing. The foundation is expressing a theory that safeguards have to be built before a technology reaches deployment scale, which means it is disposed toward work that looks early — arguably premature — relative to demonstrated harm.
3. Governance development. Supporting U.S. states, allied governments, and other capable actors in building rules, norms, and frameworks. Note "U.S. states" appearing first. With federal technology regulation fragmented, state-level policy capacity is a named target. Organizations working with state legislatures and state attorneys general on AI, biotech, or data governance sit squarely inside this objective and are probably under-represented in the current grantee set.
4. Cross-sector collaboration. Convening government, industry, and civil society to balance innovation and safety. This funds the connective tissue — workshops, standards processes, track-two dialogues — that is notoriously hard to fund elsewhere because it produces no discrete deliverable.
The foundation says it invests in civil society organizations, universities, think tanks, and standards bodies, and emphasizes "pragmatic, empirically grounded solutions to near-term security challenges" alongside support for "independent institutions that can counterbalance concentrated technical power."
That last clause is the thesis. Hewlett is not primarily funding technical safety research — the labs have capital for that. It is funding the institutional capacity to evaluate, govern, and check the labs from outside. If your pitch is that you will build a better model, this is the wrong funder. If your pitch is that you will build the independent capability to assess someone else's model, you are in the right place.
Who got the first $10 million
The February 2026 exploratory cohort is the single most informative document in this story, because grantee selection reveals strategy more reliably than strategy statements do. The named institutions:
- Stanford's Hoover Institution
- Vanderbilt University's Institute of National Security
- AI Now Institute
- The Aspen Institute
- The Atlantic Council
- Carnegie Endowment for International Peace
- Council on Foreign Relations
- Georgetown University
- Global Network Initiative
- Institute for Security and Technology
- Observer Research Foundation America
- RAND
- Sentinel Bio
Three things jump out.
The ideological spread is deliberate. Hoover and AI Now do not agree about much. Funding both in the same cohort is a statement that the initiative is buying analytic capacity across the spectrum rather than advancing a single position. For an applicant, this means your policy orientation is less determinative than your independence and rigor.
The center of gravity is Washington foreign-policy institutions. Atlantic Council, CFR, Carnegie, RAND, Aspen, Georgetown. This initiative is being framed as a security program more than a technology program, and the institutional vocabulary it rewards is national-security vocabulary: threat models, deterrence, escalation, alliance coordination, governance regimes.
There is one operator in the list. Sentinel Bio stands out among think tanks and universities as an organization doing biosecurity work rather than writing about it. Observer Research Foundation America extends reach into India-linked policy networks. Both look like deliberate tests of whether non-think-tank models belong in the portfolio — and both are the kind of exploratory bet that a $20 million year is designed to run.
The $10 million still to be deployed in 2026 is where any remaining experimentation happens before the five-year term locks in. That is the live window.
How you actually get considered when there is no application
This is the part that generalizes to every large foundation operating without an open call, and it is worth stating plainly because the alternative — sending an unsolicited letter of inquiry into a general inbox — has a near-zero base rate.
1. Produce the artifact before you ask for the money. Institutional funders in this mode discover organizations through published work, not through pitches. A well-argued report on quantum migration risk to state government systems, or an empirical assessment of hospital AI procurement security, does more to open a door than any introductory email. The cohort above consists almost entirely of organizations known for a body of public output.
2. Show up where the field convenes. Convening is an explicit funding objective, which means the foundation's staff are in rooms. Institute for Security and Technology workshops, Carnegie and Atlantic Council programming, standards body proceedings — these are the observation posts.
3. Get introduced by a current grantee. Exploratory cohorts become referral networks. A collaboration with a named grantee that produces joint work is the most reliable on-ramp available, and it is one you can initiate unilaterally by proposing to do something useful for them.
4. Fill a named gap rather than duplicating a strength. The portfolio is thin on state-level governance capacity, thin on operational infrastructure defense outside Washington, and thin on non-U.S. implementation partners beyond ORF America. Those are the openings. Proposing to do national-level AI policy analysis alongside RAND and Carnegie is proposing to be the fourth-best option in a crowded category.
5. Match the time horizon. Hewlett's Cyber Initiative ran roughly a decade. This one runs five years with a $20 million annual budget. Organizations that pitch a twelve-month project are misreading the vehicle. Pitch what your institution will be able to do in 2031 that nobody can do now.
6. Be genuinely independent — and be able to show it. "Independent institutions that can counterbalance concentrated technical power" is a screen. Organizations with substantial frontier-lab funding will face a harder question about whether they can supply the independence the initiative is buying. Have a clear answer about your funding composition and your governance.
The strategic read for the broader sector
There is a larger point here that extends past one foundation.
Private philanthropy is moving into technology security at meaningful scale precisely as federal science funding contracts and federal grant terms become more conditional. The Hewlett initiative's $20 million a year is not large against a federal agency budget — but it is unrestricted, it is multi-year, it carries no priority conditions attached to an administration's agenda, and it can fund the kind of institutional independence that federal money increasingly cannot.
For organizations that have spent 2026 absorbing federal grant terminations, cross-cutting award conditions, and shifting eligibility criteria, that combination is worth more than the headline number suggests. A $500,000 unrestricted multi-year grant from a foundation that wants you to be independent is not equivalent to $500,000 in federal money that arrives with a termination-for-convenience clause and a set of priority certifications.
The practical implication is a portfolio one. Organizations working at the intersection of technology and public interest should be treating initiatives like this one as a distinct category in their funding mix — not a smaller version of federal grantseeking, but a different activity requiring different inputs: published output, field presence, peer relationships, and patience measured in years rather than deadline cycles.
The $10 million remaining in Hewlett's 2026 exploratory budget will be allocated in the next few months. The five-year term begins in 2027. Organizations that want to be in the second cohort should be visible in the field by then — which means the work that gets them there needs to be underway now.
Sources: Hewlett Foundation announcement, July 16, 2026, Emerging Technology and Security program page, Hewlett Foundation February 2026 grant announcement.