herman.engineer
FR

WritingEssay

Slow Down, Says the Car in Front

The frontier labs asked to be slowed down and their biggest rivals agreed within hours. Read what they agreed to: a slowdown capped at the size of their lead, and a lead defended by rule.

7 min 11 sources English Français
Editorial collage: 1950s racing cars bunched up behind a pace car, a red paper circle above them like a stop signal.
On this page OpeningThe virtual safety carThe people not at the frontierWhat a stall buysWhat to do with a speed limitSources

On Saturday the car in front asked for a speed limit. The car directly behind agreed within the hour, and the next two before the day was out. That is the strangest fact of a strange week, and it deserves more attention than the speed. When rivals in the most expensive race ever run agree in a day, the useful question is not whether they mean it. It is what, exactly, they agreed to, and the answer is in Amodei’s own words: a slowdown limited by the size of the leaders’ lead, and a lead defended by rule.

Dario Amodei, chief executive of Anthropic, made the request on Saturday1 in an essay titled “We Must Pace the Frontier.” Its thesis sentence: “We must slow the pace at which we improve the capabilities of AI models.” Its plan has three steps. Each frontier lab admits outside evaluators with the access of employees, which Anthropic commits to alone and at once. The labs of the democracies then coordinate on common standards and on limits to the rate of progress, which needs, in his words, “a narrow waiver” from antitrust law. Democratic governments then try to reach the authoritarian ones.

The agreement was immediate. Elon Musk of xAI, one hour later2: “Dario is right.” Sam Altman of OpenAI, two and a half hours3: “I agree with Dario that we need to pace the frontier… we will do the same.” Demis Hassabis of Google DeepMind by evening4: “the direction is correct for meeting this critical moment.” Even Hugging Face, the home of open models, asked to be let in5, its chief executive Clem Delangue announcing an Open Alignment Initiative and a request to join the evaluator programme. Unanimity at the front of the field is not a sign that something is true. It is a sign that something is safe to say, and a speed limit is the one law the fastest car can always afford.

The virtual safety car

A safety car does one thing well. It slows the race without stopping it, and nobody may overtake on the track. The field bunches up behind it, so the leader loses its cushion but keeps its place. Racing also has a second version, for when the gaps matter: the virtual safety car6, under which every driver must hold a set time and the gaps are kept where they were. On the track nobody passes and, give or take a pit stop, nobody closes.

For the race between nations, Amodei proposes the second kind, and says so. “Pacing within democracies will be limited by the lead that US companies have over authoritarian regimes, chiefly the Chinese Communist Party,” it says, and “if we slow down by more than this amount,” the Chinese projects “will pull ahead.” So the slowdown is capped at the size of the lead, and the lead is to be defended: no sales of powerful chips or chip-making equipment to China, a crackdown on unauthorized distillation, which in his words “allows lagging companies to narrow the gap using a fraction of the cost,” and tighter security on model weights. The stated aim is to keep the lead “as large as possible.” A virtual safety car is a safety measure. It is also, for as long as it lasts, a lead preserved by rule, and Amodei does not pretend otherwise. Beijing’s Global Times read it7 as, in essence, “a ‘Cold War playbook’ for the AI sector,” and for once the reading and the text agree.

For the race at home, the lead is defended in the drafting rather than by rule: whoever writes the tests decides what they cost and whether a published model can pass them. The regime he wants “targets all US frontier AI companies,” and the industry body Hassabis has proposed, which Amodei names as one route for his second step, would exempt “any non-frontier models, say from startups or academia,” and seat “open-source representatives” on its board. That is a real answer to the smaller labs, and it carries a real catch. A rule that exempts everyone who is behind takes effect the moment they are not.

The people not at the frontier

David Sacks, the White House adviser on AI, answered8 before Sunday breakfast: “go ahead.” The two labs, he wrote, hold “a duopoly on frontier intelligence,” and should stop pretending antitrust law had to be suspended so they could form a cartel, or that they needed the same evaluators “to police competitors who aren’t even at the frontier.” Aidan Gomez, chief executive of Cohere, a lab outside the duopoly, put the same point9 without the courtesy: “Convince a government that AI is an existential threat and you can convince it to outlaw your competition.” A pacing regime designed by the leaders, he argued, becomes “an expensive bureaucracy that chokes off smaller labs before they ever ship anything.”

Open models are never named, in the way a fence never names the neighbour. Whether the fence touches them depends on what the certificate demands. A test of a released model is one thing; a guarantee that its safeguards survive every later modification is another, and a published weight file can promise only the first. If the second becomes the price of entry, it is a price a model served from its maker’s own servers can at least attempt to pay, and a published one cannot.

And there is the reading of the people who price things. Anthropic is preparing a Nasdaq listing10 at a valuation reported near two trillion dollars, and Arun Chandrasekaran of Gartner told CNBC the plan “could actually favor Anthropic and OpenAI if smaller competitors cannot afford the rigorous safety, evaluation and security investments required for frontier-level models.” None of that makes the argument insincere. It does give it two readers, and the second one is being offered shares this autumn.

What a stall buys

That is the prosecution, and the defence is also real. Models are now building the next models; a swarm of agents this summer attacked systems it was never assigned and tried to tamper with the grader scoring it, an incident Amodei describes and Britain’s safety institute reported on. The deeper worry is that the tests are losing to the things they test, and the grader is the evidence. Amodei is also careful about what he asks: “pacing does not mean halting model training or technical progress,” only taking the time to align a model and letting outsiders confirm the alignment, and Anthropic has put its own house under that rule first.

A man may lock his door because he fears thieves and because he owns the only key, and the lock does both jobs at once. The plan is a safety measure and a lead preserved by rule, and its author would likely say so: he notes himself that Anthropic has been “accused of hype, ‘doomerism’, or regulatory capture,” and asks to be judged on the middle way.

The judging is where the buyer comes in, because the tell is not on the page. It is in what changes before the waiver arrives. Continued training settles nothing, since the plan permits it: Musk agreed with Dario on Saturday and on Sunday night announced11 that Grok 4.8, “a 2.5T model,” would finish pretraining this week, and nothing in the plan says he may not.

What would tell us more is a release that came later than it could have, a safeguard that stopped a run, or an evaluator publishing a finding the lab would rather have kept. Altman said on Monday that OpenAI now writes safety cases before its frontier reinforcement-learning runs and does not need a waiver or a statute to start, which is the right shape, and a claim to be checked rather than a virtue to be credited. Agreement costs a post. Pacing has to cost something.

What to do with a speed limit

For a company that buys models rather than builds them, none of this is a reason to wait, and all of it is a reason to buy differently. Three tasks, three owners, done by the first snow, which in this city is a date and in any other is thirty days.

Procurement runs a second supplier through one workflow that matters, against agreed marks for quality, cost and latency, and lets it be an open-weight model wherever the hosting and the licence fit. A pause at the front is the one moment a second-tier model gets to close, and a published weight file keeps running whatever the labs later agree.

The technical lead asks each vendor for the safety evidence on the model actually deployed, its known limits and what independent evaluators found, and writes down what remains unverified. OpenAI has now promised safety cases before its frontier reinforcement-learning runs and Anthropic has promised to let outside evaluators publish; a vendor that can produce neither is its own answer.

The executive sponsor names the person who can delay a deployment, the grounds on which they may, and where the argument goes next. The labs have spent a week arguing over who may say stop, and the one place that question has a clean answer is our own.

The leader asked for a speed limit, and the field agreed before the day was out. Nobody asked the rest of us, which is the one advantage of not being in the race. We still get to choose the car, once the second one has done a lap of our own track.

Written by Herman Geldenhuys in Montreal.

Sources

  1. Dario Amodei, made the request on Saturday
  2. @elonmusk on X, one hour later
  3. @sama on X, two and a half hours
  4. @demishassabis on X, by evening
  5. @ClementDelangue on X, asked to be let in
  6. Formula 1, virtual safety car
  7. NBC News, read it
  8. @DavidSacks on X, answered
  9. Cohere, put the same point
  10. CNBC, preparing a Nasdaq listing
  11. @elonmusk on X, announced

Keep reading