In June, I told you to stop arguing about the brake and demand a steering wheel.
I reported that the Future of Life Institute, whose 2023 open letter had asked labs to pause for at least six months, had conceded a year later that the labs had not paused (in the institute's words, "If anything they have sped up"). I also reported that Andrew Ng and Yann LeCun "argued that a pause is essentially unenforceable". And I concluded: "A literal global pause was probably never realistic; the printing-press crowd has a point." The question that mattered, I wrote, lay elsewhere: "The useful conversation isn't pause or accelerate. It's: who decides? With what guardrails? Answerable to whom?"
Since then, three things have changed.
A lab braked. In August, OpenAI disclosed a two-week pause in reinforcement learning (RL) training on its latest models intended for deployment, and a hold on its largest planned frontier RL run, which it says it restarted on August 28, once new safety and security requirements were in place. Partial and temporary, but a brake. In late September, OpenAI braked again, halting training of its latest models and holding back a new model, GPT-6.1 Astra.
The people running the leading labs now say the whole industry should slow down. On September 12, 2026, Anthropic's chief executive, Dario Amodei, published an essay titled "We Must Pace the Frontier", and within days the chiefs of several rival companies had voiced support.
And the obstacle to slowing down together turned out to be law, not will. (The June piece never mentioned antitrust. It should have.) Amodei's essay says Washington would need to "issue a narrow waiver for certain kinds of safety conversations." The law as written suggests he has a point. So the June question is back, this time with names attached: who decides?
Slower, not stopped: what the essay asks for
So what is Amodei proposing? The core is plain: "We must slow the pace at which we improve the capabilities of AI models." And, lest anyone hear a call for a pause: "To be clear, pacing does not mean halting model training or technical progress, but ensuring companies take adequate time to align and safeguard their models, and for third party evaluators to confirm this."
On the pause itself, he sounds like the skeptics I cited in June. Of his most ambitious option, a full pacing or even a pause agreed among governments, he says: "I support floating this, but I think it is unlikely to actually happen any time soon".
Why now? The essay leans on the OpenAI–Hugging Face incident in July, in which, according to METR's investigation, "~1200 agents sent >70,000 messages and files on an unsanctioned message board, and ~700 attacked Hugging Face" (I wrote about that swarm on September 12). Amodei worries that "in 6–12 months such a swarm could be capable of taking over the entire internet with a persistent botnet" and notes that similar, though less severe, incidents have happened across the industry, "including at Anthropic".
The plan has a step Anthropic can take alone — embedded outside evaluators — and a step it cannot: "Frontier AI companies within democratic countries coordinate to establish common safety standards as well as limits on the rate of unchecked AI progress." Then comes the sentence behind this piece's title: "For antitrust reasons, it's helpful for the US government to mediate or at least enable these discussions — they don't need to participate, but do need to issue a narrow waiver for certain kinds of safety conversations."
He does not claim a deal among companies is the best tool: "The most effective method of pacing is via regulation that targets all US frontier AI companies, as that covers even those who are unwilling to cooperate voluntarily." The catch, as he puts it: "Unfortunately, passing laws can take time, and AI is advancing very quickly." And a ceiling: "Pacing within democracies will be limited by the lead that US companies have over authoritarian regimes, chiefly the Chinese Communist Party."
The brakes a company can press alone
The chorus came fast. Altman said OpenAI would match the evaluator step the same day ("a great idea, and we will do the same"). Elon Musk, whose AI startup xAI was acquired by SpaceX, posted "Dario is right" an hour after Amodei announced the essay; once a vocal critic of Anthropic, he has "largely changed his tune" since its compute deal with SpaceX in May, CNBC noted. Microsoft's Satya Nadella wrote in support of "deliberate pacing", and Google DeepMind's Demis Hassabis wrote that "Dario's essay points towards the right path forward." Meta's Mark Zuckerberg pushed back: "I don't think that we need some kind of industrywide coordination," he told NBC News in an interview it reported on September 24. Each lab, he said, "needs to take the time." On September 29 he signed a voluntary White House safety accord, calling it "a start and an accord that the whole industry could come to."
Two rivals had already published essays of their own. On September 6, OpenAI's chief scientist, Jakub Pachocki, hoped for "voluntary slowdowns" to become commonplace "until shared safety bars are established." In July, Hassabis proposed a standards body "much like the Financial Industry Regulatory Authority (FINRA)" whose work could include "coordinating a slowdown in development among the Frontier Labs if deemed necessary."
Single companies have already pressed their own brakes. Besides OpenAI's pauses, there is Meta's launch delay, as the International Center for Law & Economics' blog tells it: "Zuckerberg said Meta delayed Muse's launch to address safety concerns." The same post, by Kristian Stout, draws the line this whole piece turns on: "Frontier artificial-intelligence (AI) labs may have good reasons to tap the brakes. The antitrust question begins when they all reach for the same pedal."
What about the other solo step, the evaluator pledge? Anthropic "intends to invite an embedded external review team" in "the near future" and says reviewers "should have the right to publish key findings about risk levels, incidents, practices, and the access they received or didn't receive — without editorial control by Anthropic," though it keeps "the narrow ability to redact security-sensitive, legally privileged, commercially sensitive, or third-party confidential information." On September 18 it named the first, Accenture, and said it "will fund Accenture's work directly". OpenAI said on September 22 that it is "committed to supporting independent assessments", and its principles say assessors "should maintain editorial independence" while labs may request redactions, adding that "Where appropriate, labs should have a reasonable period to remediate issues before publication." Its post names no assessor.
What binds either promise? On the public record, nothing outside the companies. No contract has been published, and Anthropic's own announcement says that "There are, as yet, no standards for what information embedded evaluators should have access to, or how they should report what they find." It adds: "The safety of our models remains our responsibility." Evaluators who spoke to TechCrunch broadly welcomed the idea but want it "ideally backed by legislation", so they know whether they will be "truly independent watchdogs or vendors operating on the AI companies' terms." A Bocconi researcher put it best on Columbia's CLS Blue Sky Blog: "access is not authority, and transparency is not supervision."
On government's role, the two labs differ in emphasis. Anthropic's head of public policy, Sarah Heck, called in an X post for "a national law requiring testing of frontier models, with the power to block the most advanced models that prove to be unsafe," CNBC reported. Altman said OpenAI welcomes the idea of a "federal framework that sets consistent safety requirements," AP reported, and OpenAI's September 21 proposal for international standards says they "would not be licenses, mandatory prerelease review, or approval requirements for AI models," leaving national governments to decide "whether and how to incorporate these standards into their own legal systems." Both are positions, not laws.
Why "together" is the word that needs a lawyer
Why would anyone need permission to be careful? Because of one word. A lab that pauses on its own raises little antitrust concern, Lawfare's analysis explains, "because an agreement is the key element of a Section 1 case and a unilateral pause involves none." (Section 1 is the part of federal antitrust law that bans agreements in restraint of trade.) Once rivals agree, the analysis flips. Antitrust lawyers at Holland & Knight warned on September 23 that such a pact could be characterized as an output restriction and that "No safety justification, however compelling, is likely to save an agreement that a court classifies as a naked restraint." (The firm isn't fatalistic; it sees "a potential path forward" in what lawyers call the ancillary restraints doctrine.)
The Lawfare author, Nicholas Felstead, names the trap: the commitments, notice, verification and penalties for defecting that might make a joint pause work "are those that establish the existence and terms of a potentially anti-competitive agreement among competitors." A pact with teeth is evidence of a pact; a pact without teeth is the 2023 letter, which "changed nothing."
What tools exist for rivals who want to cooperate? Two, and each is weaker than it sounds.
First, the National Cooperative Research and Production Act, written for competitors who do research together. Its definition of a joint venture excludes agreements that restrict production, covering conduct "restricting, requiring, or otherwise involving the production" of anything other than the venture's own output. Holland & Knight concludes that a safety collaboration with output limits "would likely fall outside" its protection, and notes that no amendment to the law itself has been "enacted or formally proposed."
Second, a Justice Department business review letter, which "states only the enforcement intention of the Division as of the date of the letter". In Holland & Knight's words, "A business review letter is not legally binding. It does not confer immunity". In fairness, the firm adds: "In practice, however, these letters provide meaningful protection."
So the waiver is Amodei's ask, and Washington has granted none. Altman wrote that OpenAI would not wait for one, as AP quoted him: "we do not believe we need to wait for an antitrust exemption or legislation to begin the work of providing this confidence." OpenAI's top lobbyist, Chris Lehane, said the company did not believe its safety talks with Anthropic and Google required an antitrust waiver, Bloomberg reported, per the Washington Examiner. Associate Attorney General Stanley Woodward said on September 17 that "It doesn't occur to me that coordinating on cybersecurity or security is anticompetitive," but his comments, the Examiner noted, "left unresolved how far AI companies could go beyond exchanging security information to jointly determine the pace of technological development," and he said no frontier lab had asked the Antitrust Division for a meeting.
One of the two federal enforcers who could challenge a pact sounds warier. FTC Chair Andrew Ferguson said at Georgetown on September 15 that "if companies are simultaneously coming to Washington and asking for a host of regulations and an antitrust exemption, all of my alarm bells go off," Reuters reported. (He said it was his personal opinion, and he did not name Anthropic directly.)
The White House accord, signed by President Trump, Google's Sundar Pichai, Meta's Zuckerberg, Anthropic's Amodei, SpaceXAI's Musk, Nvidia's Jensen Huang and OpenAI's president, Greg Brockman, says the companies "will meet regularly to establish standards and best practices to improve the safety of their systems," and nothing about pace or antitrust. So far, Washington's message is: write safety standards together if you like, but brake, if at all, alone.
The bill that would allow some of it, and seal the paperwork
Is there a bill that would change this? One would, partly. The Collaboration on Adversarial Threats and Security Risks Act (S. 5105 from Senators Adam Schiff and Jim Banks, with a House twin, H.R. 9914, from Representative Bob Latta, with 22 cosponsors from both parties as of September 24) would let rivals jointly delay even the training of a model, under conditions. Both were introduced on July 23, 2026. Schiff's announcement frames it around deployment, describing coordination "by delaying or limiting the deployment of high-risk AI models" after written notice.
The text goes further. Section 3(a)(2) exempts rivals who coordinate "for the exclusive purpose of reducing covered artificial intelligence security risks via delaying or otherwise limiting the release, deployment, use, development, training, testing, or evaluation of artificial intelligence," provided they first send the Justice Department's antitrust chief "written notice detailing the specific covered artificial intelligence security risk and the scope of the proposed restriction." The covered risks are listed security harms, and the one closest to Amodei's worry is AI that improves itself autonomously "in a manner that creates a substantial risk" of the first four. So Semafor's verdict that the bill is "decidedly narrower" than Amodei's idea is fair about purpose (listed security risks, not general caution), but the mechanism reaches training itself.
It has real guardrails. The exemption is an affirmative defense (a shield a company must prove in court, not an immunity it collects in advance), and a court can still enjoin a pact the Attorney General shows is "reasonably likely to result in an overall increase in covered artificial intelligence security risks." Private suits over anything it doesn't exempt survive.
Then come two catches. First, Banks's office says the bill "explicitly prohibits price-fixing", but the text's rule of construction says only that "Subsection (a)(1) shall not be construed to permit price-fixing," and (a)(1) is the information-sharing half. The coordinated-delay half gets no such sentence. (Drafting slip or choice, it is a gap.)
Second, every (a)(2) submission, "including any written notice" the companies file, would be "withheld, without discretion, from the public" and shielded from Freedom of Information Act requests. The companies could still announce a delay — nothing in the bill stops them — but the document naming the risk they claimed, and the scope of what they agreed to, would stay in a Justice Department drawer.
Who backs it? Schiff's release lists endorsers including Google and the Future of Life Institute (yes, the authors of the 2023 pause letter), and no endorsement from OpenAI or Anthropic.
Is it moving? Not yet. As of September 24, both versions sit in their chambers' Judiciary Committees, though the House version has gained 14 cosponsors, nine of them in the week after the essay. A faster route has stalled, too. Senators "had secured a narrow antitrust exemption for AI companies in annual must-pass defense policy legislation earlier this year before negotiations over the measure were delayed," Semafor reported, citing "people familiar with the matter." That defense bill stalled on July 14, 2026, when a cloture vote failed, 50–46. Its practical deadline is the end of the year.
Four subscribers went to court first
On September 18, lawyers for four people who pay for ChatGPT, Claude, Grok or Gemini sued Anthropic, OpenAI, SpaceXAI and Google in federal court in Northern California, on behalf of a proposed nationwide class. The suit, Buist v. Anthropic, "argues that the leading AI companies violated antitrust laws when they agreed to coordinate slowdown efforts," as AP put it, and that coordinating would reduce the value subscribers get for their money. The complaint's theory fits in one line: "The agreement was proposed in public, accepted in public, and confirmed in public." Whether there was any agreement is for a court to decide, but one premise needs no court. The suit targets "an agreement among competitors about how fast their competing products will improve," and "Congress has granted no exemption for that agreement."
The plaintiffs "don't object to the companies individually deciding to slow their own progress in favor of safety." Their target, in AP's rendering, is the "shortcut" of agreeing to "substitute collective restraint for individual accountability." The suit even cites a July statement by frontier-lab employees that "each company—and country—is under intense competitive pressure not to unilaterally slow that acceleration."
These are allegations, and no court has ruled; as of September 30, no company had answered or filed a motion.
Isn't braking together the whole point?
Take the other side seriously, because it is not a cynical argument. If the race itself is the hazard, a brake each company presses only for itself is the 2023 letter all over again. Pachocki makes the point from inside a lab: OpenAI will continue to "unilaterally withhold further scaling as needed; however, I believe broader interventions are required." Tom Wheeler and Blair Levin of Brookings argued back in 2024 that "The FTC and DOJ should make clear that collaboration on AI safety is not only allowed, but also expected." But they attached a condition that pacing crosses by definition: such collaboration "should be structured so as not to affect prices, output, or competitive intensity."
That is the heart of it. A pact among the leaders to slow the frontier also freezes the leaderboard. ICLE's Dirk Auer put the legal point bluntly: "Antitrust law has a less flattering name for that arrangement: a cartel." His economic point is, I think, stronger: "A pacing cartel could therefore deliver less AI without delivering safer AI, all while allowing competitors to manage their commercial risks collectively." Why? Because "Enforcers can observe whether a company delayed a training run. They can't readily determine whether it used the extra time to improve interpretability." Jack Dorsey made the builder's version of the argument: "i oppose industry-wide limits negotiated by today's leaders because they could exclude the people who might expose failures or build alternatives." Dave Karpf, writing in TechPolicy.Press, aims at the essay's author: he grants that Amodei's concern is genuine ("and I think it is") but calls the plan "a series of proposals that all benefit Anthropic."
And the commercial clock kept running. In a Fortune interview published the day of the essay, Altman said an IPO now would be "ill-advised," citing safety concerns, CNBC reported; the decision pushes OpenAI's listing to 2027 at the earliest. Anthropic "is actively gearing up" for its own, CNBC added, though it "has not officially disclosed when it plans to debut." Ten days after the essay, both labs shipped cheaper models on the same day: OpenAI's GPT-6 Sol and GPT-6 Luna, with API prices cut by half against GPT-5.6's promotional pricing, and Anthropic's Claude Opus 5.5, which it said would cost "around 40% less to run than the company's Opus 5." Pacing, as the essay defines it, allows that.
Is there a way to get the brake without the cartel? Europe has at least written its answer down.
Across the Atlantic, the permission slip is public, and output limits aren't on it
So what does Europe do differently?
It writes the rules down. The European Commission's 2023 guidelines on cooperation between competitors cover sustainability agreements (rivals working together toward a public goal), including a "soft safe harbour" with six cumulative conditions. The process must be transparent and open to "all interested competitors"; members "must remain free to apply higher sustainability standards." The safe harbor covers only sustainability standards, and failing it "does not create a presumption" that an agreement restricts competition. Washington has had no general guidelines on competitor collaboration since 2024, when the FTC and the Justice Department withdrew theirs, a move the FTC itself says "left the industry without guidance in this important area." (A narrower statement on sharing cybersecurity information remains.)
It answers in public. A 2022 notice promises to publish the Commission's answers ("Guidance letters will be published on the Commission's website," in a version agreed with the applicant to protect business secrets), though the letters "do not create any rights or obligations" for anyone. One of the first two letters under it, to APM Terminals, took about seven months: the company asked in December 2024 about jointly buying port equipment, and in July 2025 the Commission announced, naming the company, that the plan "does not raise concerns under Article 101" with safeguards attached. Washington's business review letters are public too (the Justice Department has posted them online, requests included, though the regulation promises only a file "available to the public upon request"). The outlier would be a Banks–Schiff notice, which the public would never see.
But on pacing, the rulebook points the other way. Agreements "that limit the participating undertakings' output of the products concerned by the agreement do not qualify as sustainability standardisation agreements." Standards used "to disguise price fixing, market or customer allocation, limitations of output or limitations of quality or innovation restrict competition by object." ("By object" is the EU's label for conduct treated as harmful by its very nature, no proof of effects required.) And like the Buist plaintiffs, Brussels prefers solo decisions: "In principle, each undertaking should decide for itself how to achieve sustainability benefits", though it accepts that an agreement may be needed, at first, to overcome a "first mover disadvantage" — a close cousin of the labs' race problem.
Nor is government encouragement a waiver, whatever the essay hopes Washington might "mediate or at least enable": "The fact that public authorities encourage a horizontal cooperation agreement does not mean that it is permitted under Article 101". What lifts the rule is a legal requirement: Article 101 "does not apply where the anti-competitive conduct of undertakings is required either by national legislation, or by a national legal framework which precludes all scope for competitive activity for the undertakings involved". A mandate, not a blessing.
Brussels enforces the category, too. In 2021 it fined carmakers €875 million for agreeing, as the Guidelines put it, "not to improve the effectiveness of the system beyond what was legally required," treating "a limitation of technical development" as an infringement by object. The motive ran the other way — they held back cleaner technology; the labs would hold back capability for safety — but the category is the same.
Where does that leave the labs? At an open door with a narrow frame. On September 16, EU competition chief Teresa Ribera said she would consider giving AI companies more room to coordinate on safety, Politico reported. "We have not got a formal request, at least for the time being," she said.
What Europe offers is less a yes than a process: rules written in advance, questions answered in writing, and a firm line against limiting output. That is a steering wheel of a kind, even if it won't steer where the labs want to go.
Picture the first sealed slowdown
What follows is hypothetical; every piece of machinery in it already exists on paper.
It is the spring of 2027. The stalled defense bill passed in a December rush, exemption included. Two labs' embedded evaluators flag a model that is getting better, faster than anyone planned, at improving its own training code. The labs agree to hold their next large training runs for eight weeks and first send the Justice Department's antitrust chief a written notice naming the risk (autonomous self-improvement) and the scope of the hold.
Then silence. The notice is sealed by statute. The public learns what happened, if at all, from two launch windows that quietly slip. A challenger lab outside the pact keeps training, and its investors start asking whether it will be invited in next time, and on whose terms.
In Brussels, the same labs ask the Commission for guidance, since an American statute gives them no cover there. The answer is published, business secrets aside, with their names on it — so a reader in Lisbon can see the outline of an American slowdown that a reader in Ohio cannot.
Back home, subscribers sue again. The labs must prove good faith and an exclusive purpose, so the first public official outside the Justice Department to read the notice is a federal judge — perhaps under seal there, too.
Eight weeks later, the runs resume. Who decided they could? The Bocconi researcher saw that gap coming: "An antitrust waiver can determine when firms may cooperate; it cannot by itself determine what risks the public should accept, which safeguards are adequate, or when development should resume."
Left, right and the rival labs, in rare agreement
What is striking is who ends up on the same side.
On the right, the objection is to the exemption. Senator Josh Hawley said "there is no world" in which he would agree to give "the most powerful companies in the history of the world" an exemption from antitrust laws to collaborate, AP reported. "You have a basic obligation to make your products safe. Do not demand antitrust waivers or liability waivers in exchange for that," David Sacks, Trump's former AI adviser, told Bloomberg, as Semafor relayed. CNBC notes that he has repeatedly called Anthropic's push a "regulatory capture" campaign, yet even he supports going it alone: "If the unreleased models are scary enough that you think you should slow down, I support your decision to be responsible," he wrote.
In the center, Brookings's Elham Tabassi said that until the companies' commitments are "solidified and made public," independent auditors would be a "voluntarily-provided, company-controlled" move, the Boston Globe reported. And Wheeler put the June question to CNBC in his own words: "Who makes the decision about standards? Who makes the decision about who's going to do the evaluation? Who makes the decision about enforcement?"
On the left, the objection is to the permission, and sometimes to the premise. Amba Kak of the AI Now Institute, a former senior AI adviser at the FTC, told CNBC: "We need a structure that doesn't rely on this industry's permission to do its job." Timnit Gebru of the Distributed AI Research Institute rejects the premise: companies' claims of existential risk are overblown, she said, and plenty of laws already apply to AI. "There is no AI exemption in existing statutes," she added. "Fraud is still fraud." And Bernie Sanders and Greg Casar want a public brake: their Ban Artificial Superintelligence Act, introduced on September 23, would also pause advanced AI development until a new federal Department of Artificial Intelligence is established and issues AI safety rules, Roll Call reported. (On September 5, I called the pause in their one-page summary "a pause of indefinite length, on an undefined category, that lifts when a new bureaucracy says so.")
And the rival labs? Europe's challengers read the moment as consolidation: "Some incumbents are using this moment to consolidate their market position, pushing for regulation designed to favor them over competitors," Mistral said. "If this is the most consequential technology in human history, then the rules for it cannot be written by a small group of commercially aligned companies behind an antitrust waiver," Cohere's Aidan Gomez wrote in a blog post answering the essay.
What does this mean for you?
Read the essay before you read about it. Its year-or-two lines are a conditional benefit ("if slowing down bought us even an extra year or two") and two research estimates of one to two years (for interpretability and for testing), not a requested length of slowdown.
If you're in the United States and have bought an individual consumer subscription to ChatGPT, Claude, Grok or Gemini directly from its maker since September 12, 2026, you fall within the proposed Buist class. Business and enterprise plans fall outside its definition. It isn't certified, and there is nothing to sign. You can follow the docket free and set an alert; as of September 30, an initial case management conference was set for December 23, 2026.
Read the bill; it runs nine pages. Start with Section 3(e), the sealed notice, then track S. 5105 and its House companion.
Tell your senators what you think of that notice through the Senate's contact directory. My suggested asks: make the (a)(2) notice public, even if only after a delay; extend the price-fixing clause to coordinated delays; and put an end date on the exemption. For the House version, find your representative.
When the first evaluator reports appear, look at what they disclose. Both labs say evaluators should publish independently, and both leave room for redactions; OpenAI's principles also give labs "a reasonable period to remediate issues before publication." A report that says what access was refused, what was redacted and whether the lab saw it first tells you more than any pledge.
The lesson, as I see it
In June I said the useful question was who decides, with what guardrails, answerable to whom. Now the candidates have names: the leaders of the race, by private agreement; a sealed notice to the Justice Department; a federal judge in a subscribers' lawsuit; or a legislature, in public, binding everyone.
My vote? The last one. The essay itself calls regulation the most effective method, and Lawfare supplies the legal logic: "If statute obliged frontier developers to stop development when specified capability thresholds were breached, the antitrust problem would largely fall away as compliance with a binding legal mandate is plainly not a conspiracy among competitors." Europe draws the same line: encouragement is no defense; compulsion is. Cato's Jennifer Huddleston has the best objection: "A regulatory framework built for today's models may actively hinder tomorrow's," she wrote, as Decrypt reported. Fair, and a law is slower. But it is the only brake whose terms you get to read, argue about and vote on.
Until then, let every lab brake alone whenever its own evidence says it should (OpenAI did, twice; Meta did, by ICLE's account; and the plaintiffs, Sacks and Lawfare have no quarrel with that).
The steering wheel will also need more than one pair of hands. At talks in New York on September 20, the U.S. side proposed a new AI safety notification mechanism to China. Treasury Secretary Scott Bessent said "moving from opaque to more transparency between the number one and the number two AI powers in the world is very important." Days later, Trump and Xi agreed to establish a bilateral communication channel for AI incidents; neither government's readout defines an incident or says who sees the notices. Transparency is the right instinct. It would be strange to ask it of Beijing and seal it at home.
Who gets to press the brake is a question about power long before it is a question about engineering. The HAIA Foundation exists to keep questions like that in the open; subscribe if you want to be there when this one gets answered.






