Pular para o conteúdo
← Back to Skalablog

Published article

AI slowdown: what the frontier labs actually agreed

Software EngineeringAnthropicOpenAIClaude

If you build on frontier models, the AI slowdown debate matters mainly because it might change your release schedule. It will not, at least not on the evidence available now. The September 2026 agreement buys outside observers inside the labs. The coordination and open-weights levers that would reduce the training rate remain unsigned, unfunded and blocked on an antitrust exemption that does not exist.

What the September 2026 AI slowdown agreement actually committed to

The AI slowdown agreed on September 12-13, 2026 committed four labs to a direction, not a rate limit. Anthropic, OpenAI, xAI and Google DeepMind endorsed Dario Amodei's proposal to pace frontier development. Only Anthropic wrote down an obligation with a cost: it started granting a team of outside evaluators physical access and the right to publish findings without Anthropic editorial control.

Amodei's essay, published on September 12, 2026, proposed three escalating steps. First, every frontier lab gives ongoing employee-like access to outside evaluators. Second, labs in democratic countries agree common safety standards and limits on the rate of unchecked progress. Third, those governments attempt the same arrangement with authoritarian ones. He named MITRE as an example evaluator.

Anthropic written offer covers workspaces, tools and permissions mostly comparable to what internal risk assessment teams have, including desks in its offices, access badges and company laptops. Evaluators can publish on risk levels, incidents, practices and the access they received or did not receive. OpenAI committed to matching within hours, according to the transcript's account.

The commitment has a limit in the fine print. Anthropic retains the right to redact material it considers security sensitive, legally privileged, commercially sensitive or confidential to a third party. A reviewer can disclose that a redaction removed something important, but not what it was. Step one buys a witness. It does not buy a slower training run.

Why the coordination step needs an antitrust waiver nobody has granted

The coordination step cannot proceed without an antitrust exemption that no government has issued. Competitors agreeing to limit output is the textbook definition of a cartel. Amodei asked the US government for a narrow waiver covering certain kinds of safety conversations, and the essay states that request directly.

Leave coordination voluntary instead and the incentive problem Amodei's essay describes returns. The first lab to defect wins. A signature on a principles document creates no verification mechanism, no penalty and no third-party check. The transcript's verdict is blunt: these agreements are cheap because they do not bind behavior.

OpenAI's own contribution to the weekend followed this pattern. Sam Altman said he agreed on pacing the frontier, then said OpenAI's confidentially filed IPO would not happen in 2026 because going public during a safety debate would be ill-advised. Deferring a listing is a real decision, but it does not cap a training run or a release date.

The American Economic Liberties Project's Matt Stoller has made a related argument about corporate concentration in technology and the ways dominant firms shape the rules that govern them. That framing matters here because the second step asks competitors to write the limits on their own competition.

The compute proposal that put numbers on pacing

A research group at AI Futures published a numerical version of pacing on August 5, 2026, five weeks before Amodei's essay. Their proposal keeps at least 70% of a lab's compute serving models that already exist, devotes roughly 25% to safety work published for outside review, and leaves about 5% for making the next model smarter.

Their second lever is the one with real bite. Labs could only use models at least nine months old to do AI research. A lab may ship whatever it likes; it just cannot point the current generation at building the next one. That constraint targets the recursion that makes frontier progress compounding rather than linear.

None of the four labs that endorsed Amodei's direction signed this compute proposal. The authors concede the timeline themselves: notice-and-comment rulemaking runs 12 to 24 months, and full implementation takes four to six years. By the time any of it binds, the models in question will be several generations old.

The FT has reported separately on how AI compute buildouts and export controls interact with national policy, a reminder that compute allocation is already a government lever in some jurisdictions. That does not make the AI Futures numbers binding anywhere. A published proposal and an enforced rule are different objects.

The open-weights counter-proposal that landed five hours later

Jake Gold's open letter reached Hacker News roughly five hours after Amodei's essay and argued that the only uncapturable slowdown is mandatory open weights. Any model a company offers to the public would have to be released as open weights, while internal and research models stay untouched.

The mechanism is financial rather than regulatory. Valuations rest on those weights being proprietary, and those valuations pay for training runs. Publish the weights on anything sold, and the training money contracts across every lab at once. No regulator picks a number, and there is nothing to game in the text.

Gold's argument about regulatory capture is that rules written with help from the largest labs land hardest on the smallest ones. He also notes that every incident adds a rule and no rule gets removed, so the regulatory surface only grows. On that reading, openness points toward slower capability diffusion, not faster.

Amodei's essay points the same variable in the opposite direction. It asks for crackdowns on unauthorized distillation and for preventing model weight theft. Tighter versus looser, applied to the same weights. Both authors want AI slowed and disagree completely about which way openness moves the rate.

The distillation report that sharpened the timing

Anthropic published a report two days before the essay documenting what it called distillation campaigns against Claude, its AI assistant. The report described five campaigns and about 200 million exchanges in total, with Alibaba's campaign running 151 million exchanges from May to July 2026.

The same report said Alibaba's activity peaked near 3 million exchanges a day across 3,500 accounts. It described Moonshot's campaign as shorter and smaller, roughly 300,000 requests over 10 days. Those are Anthropic own numbers, published by the lab whose model was targeted, so they belong in the vendor-reported category rather than the independently verified one.

The report carries two claims that matter for this debate. First, that copying frontier models is a security problem worth a public writeup. Second, that pacing the frontier means cracking down on that copying. Gold's position treats mandatory dissemination as the only slowdown a regulator cannot capture. Hugging Face, which runs the largest open-weights repository, took neither side and asked for a seat at the evaluator table.

What each lever actually changes about AI speed

Three levers are in play, and they produce different outcomes. The evaluator lever is the one actually being pulled, and its output is visibility rather than restraint. Outsiders sit inside the buildings and publish. Release timing may get more careful because someone can document that a lab shipped anyway. The training rate does not change.

The coordination lever would slow releases and gate capabilities in the US and Europe while leaving labs elsewhere unaffected. The open-weights lever would put public model weights onto repositories and contract training budgets everywhere at once, which is the only mechanism described that touches the rate itself. Its cost is that the distillation report becomes policy.

LeverWho signs itEffect on training rateMain blocker
Embedded evaluatorsAnthropic, OpenAI matchingNone measuredRedaction rights
Coordinated pacingNeeds government actionSlower in US and Europe onlyNo antitrust waiver granted
Mandatory open weightsNo frontier labContracts training moneyConflicts with lab business models

Labs outside the agreement keep shipping on their own schedule. DeepSeek, Alibaba and Moonshot were not asked to join. A weekend of statements from four Western labs says nothing about the training rate of a lab that never signed anything.

How to read the agreement without overreacting to it

Treat the September 2026 AI slowdown weekend as a news cycle with a small institutional footprint. Four names on one side of a weekend reads like policy and behaves like a news cycle. The test is not who agreed but who wrote a numeric threshold down. So far the only written numbers belong to a research group with no signatures on it and a developer whose proposal would cost the four labs their valuations.

For anyone building on these models, the practical effect is narrow. Nothing in the agreement delays access to a model. What changes is that an outside party can publish findings about a lab before the lab decides how to frame them. That is a real improvement in public information and a negligible change in model availability.

The near-term prediction is explicit: better visibility into the frontier worldwide over the following year and about the same speed at it. One test would falsify that reading. If two of the four labs publish a shared threshold by September 12, 2027, whether a capability line, a compute floor, a rate cap or anything a third party can verify, the assessment was wrong.

FAQ

  • Did the four labs actually agree to slow down AI? They agreed on a direction, not a rate. Anthropic committed physical access and publishing rights for outside evaluators, and the other three endorsed the proposal in public statements. No signed threshold caps training compute or release timing.
  • What is the difference between pacing and halting? Amodei's essay defines pacing as taking enough time to align and safeguard a model before the next one lands, and states explicitly that training does not stop. A halt would be a moratorium on development, which none of the four labs endorsed.
  • Why does the coordination step need an antitrust waiver? Competitors agreeing to limit output is a cartel under existing competition law. Amodei asked the US government for a narrow waiver for safety conversations. Until a government grants one, labs that coordinate on capability limits expose themselves to antitrust liability.
  • What would mandatory open weights do to training budgets? Proprietary weights underpin the valuations that fund training runs. If every publicly offered model had to ship as open weights, the training money contracts across the industry at once, which is why no frontier lab has endorsed the idea.
  • Which labs were not part of the agreement? DeepSeek, Alibaba and Moonshot were not asked. Anthropic distillation report from September 2026 described campaigns against Claude attributed to Alibaba and Moonshot, so the labs most affected by copying rules were not in the conversation about them.
  • Does the agreement affect access to frontier models for developers? Nothing in the committed step changes API access or release timing for outside developers. The evaluator arrangement governs what outside observers can inspect and publish inside a lab, not who can call which model.
  • What would count as evidence the agreement is more than a statement? A shared numeric threshold from at least two of the four labs that a third party can verify, such as a capability line, compute floor or rate cap. Statements of principle and posts are not verifiable in that sense.
  • Who proposed the compute split with published safety work? A group at AI Futures published it on August 5, 2026, five weeks before Amodei's essay. The proposal keeps at least 70% of compute serving existing models, about 25% on published safety work and roughly 5% on making models smarter.

Turning a fast-moving safety debate into a written article

The hard part of this story is not reporting it. It is deciding what survives Saturday and still matters on Monday. The distinctions that hold up are the ones written down: who has a badge, who signed nothing, which numbers came with a source, and which lever was never pulled.

If you carry that kind of explanation in a video, the same distinctions are already in your recordings. Skala blog turns a YouTube URL into a transcript and then an article, so a filmed breakdown of a policy weekend can become a written piece readers can search, quote and check.

Skala Blog

Source video