September 13, 2026
'Pace the Frontier': What the AI Slowdown Plan Would Do
Dario Amodei's three-part AI slowdown plan won backing from Altman and Musk. Here's how it would work, what could stop it, and why critics still doubt it.
Article focus
Anthropic's CEO proposed a three-part plan to slow frontier AI, and rival CEOs backed it within a day. Here are the mechanics, the obstacles, the skeptics, and what embedded evaluators would mean for teams building AI.
Section guide
Two days after AI researchers publicly called for the industry to slow down, the head of one of the biggest labs published an actual plan for doing it, and his two biggest rivals agreed within a day. That's unusual in any industry, let alone one built on racing. This piece skips the debate we've already covered and focuses on what's new: the mechanics of the plan, the obstacles in its way, and the skeptics who doubt both its sufficiency and its motives.
Key Takeaways
- Anthropic CEO Dario Amodei published "We Must Pace the Frontier" on September 12, 2026, a roughly 3,800-word essay with a three-part plan to slow frontier AI.
- Step one, which Anthropic says it will adopt unilaterally, gives independent evaluators permanent, employee-level access to its systems; OpenAI's Sam Altman pledged to do the same.
- Steps two and three need outside help: US antitrust exemptions so labs can coordinate, and eventually coordination with China, which Amodei calls the toughest dilemma.
- Critics question sufficiency and motive: David Krueger says the plan doesn't reduce risk to an acceptable level, and David Sacks points to product-liability exposure and Anthropic's upcoming IPO context.
- For builders, the durable idea is evaluation as a standing, independent function with real access, which scales down to how any team should make its AI systems auditable.
What Is the AI Slowdown Plan?
The AI slowdown plan is a three-part proposal from Anthropic CEO Dario Amodei, published September 12, 2026 in an essay called "We Must Pace the Frontier." It starts with independent evaluators getting permanent, employee-level access inside AI labs, extends that oversight across leading US companies under federal rules, and ends with international coordination. Sam Altman, Elon Musk, and Demis Hassabis backed the direction. Critics question both its sufficiency and its motives.
The core ask is simple to state. In Amodei's words, "we must slow the pace at which we improve the capabilities of AI models. Progress will still seem fast, and we must make wise use of the time we gain." He argues that building AI "too fast is reckless," and that the pace since roughly this summer has accelerated because AI is increasingly helping to build the next generation of AI.
What makes this different from the researcher warnings earlier in the week is specificity. Those were alarms. This is a proposal with named steps, a named first mover, and named asks of government. That makes it something you can actually evaluate, which is what the rest of this piece does.
How Would the AI Slowdown Plan Work?
In three stages, each needing a wider circle of cooperation than the last. Here's the structure as reported across coverage of the essay, step by step.
| Step | What it involves | Who has to act | Main obstacle |
|---|---|---|---|
| 1. Embedded evaluators | Independent evaluators with permanent, employee-level access to verify safety, report incidents, and assess alignment during training | Individual labs; Anthropic unilaterally, OpenAI pledged | Independence, scope, and trust |
| 2. Industry-wide oversight | Similar oversight across the leading US AI companies, backed by federal regulation | Top US labs plus the US government | Antitrust law; needs a waiver to coordinate |
| 3. International coordination | Pacing agreements that extend beyond the US | The US, China, and other AI powers | China may not follow; verification is hard |
The first step is the only one fully within a single company's control, which is why it's the only one already committed to. Anthropic says it will provide "third-party evaluators with permanent, employee-level access to our systems, so that they can verify adherence to our safety measures, report on incidents, and assess models' alignment during training." Altman responded that "committing to having independent evaluators with employee-like access is a great idea, and we will do the same."
The honest read: step one is concrete and genuinely novel, because most external AI evaluation today is episodic, a test before release rather than a presence during development. Steps two and three are where the plan becomes a policy agenda, and policy agendas depend on governments that haven't signed on. Judge the plan by step one's execution first; the rest is aspiration until someone outside the labs commits.
What Would Embedded Evaluators Actually Change?
Potentially a lot, if the independence is real. It would be one of the more meaningful changes to how frontier AI gets built, if it holds. It's worth unpacking, because this is the part with the clearest implications for anyone building AI systems.
Today, outside safety review usually looks like an audit: a team gets access for a window, runs tests, writes a report, and leaves. Embedded evaluators with employee-level access would be closer to a permanent inspector on site, seeing training runs as they happen, reading internal tools, and talking to researchers. That changes three things.
- Timing. Problems could be caught during training, not after a model is finished and the pressure to ship is highest.
- Visibility. Evaluators could see what a lab actually does, not only what it chooses to present in a pre-release evaluation.
- Incident reporting. A standing presence makes it harder to quietly handle a serious incident, like the Hugging Face agent breach, without outside eyes.
The obvious questions are the ones the plan doesn't yet answer in public detail:
- Who picks the evaluators? Selection decides whether they're genuinely independent or quietly friendly.
- Who pays them? Funding from the lab being evaluated creates an obvious tension.
- Can they publish findings a lab dislikes? An evaluator who can't disclose is closer to a consultant.
- What stops a lab from narrowing access? "Employee-level access" can be limited in practice without being revoked on paper.
Independence is the whole value of an evaluator, and it's also the easiest thing to erode quietly.
What Could Stop the AI Slowdown Plan?
Law, geopolitics, and incentives, roughly in that order of difficulty to resolve. Each is a serious obstacle rather than a detail.
Antitrust. Rival companies agreeing to jointly limit how fast they develop products can look like collusion. Amodei's plan asks the US government for a waiver so frontier labs can coordinate without being punished for it. David Sacks, a co-chair of the president's science and technology advisory council, pushed back: "Stop pretending you need anyone else's permission." His point is that any company can slow its own work unilaterally, which makes the waiver a convenience rather than a necessity.
China. Amodei called this the toughest dilemma. If US labs slow and Chinese labs don't, the US risks falling behind in a strategically critical technology. He argues US companies shouldn't slow unilaterally while Chinese labs keep advancing, and that a lasting slowdown will eventually require coordination between Washington and Beijing. That's diplomatically hard and, like any arms-control effort, hard to verify.
Incentives. The companies involved are in an intense commercial race, and one of them is preparing what's expected to be the largest IPO ever. Voluntary restraint is only as durable as each participant's belief that the others are also restraining.
Why Do Critics Doubt the Plan?
For two different reasons, and it's worth keeping them separate: some doubt it's enough, and some doubt the motives behind it.
On sufficiency, David Krueger, an AI professor and former founding director of the UK government's AI Security Institute, said: "This plan does not reduce the risk to an acceptable level, and Dario is careful not to say that it would." That's a notable critique, because it accepts the premise of risk while arguing the response is too modest.
On motive, Sacks argued the labs should "stop pretending the motivation to slow down is purely altruistic," adding: "You face massive product-liability exposure if your products enable a truly damaging cyber-attack." The timing also invites scrutiny. Anthropic is reportedly preparing to market a planned IPO valued at more than $2 trillion, and a public commitment to safety can be both sincere and commercially useful at once.
Some experts also disputed specific claims in the essay. Amodei warned that a more capable but similarly misaligned agent swarm could cause hundreds of billions of dollars in damage by "taking over the entire internet with a persistent botnet," within roughly a year. That scenario was described by some AI experts as not particularly plausible and something to treat with skepticism.
The honest read: a proposal can be self-interested and still correct, or altruistic and still inadequate. The motive critique doesn't refute the plan, and the endorsements don't validate it. What would actually settle the question is execution: whether evaluators are truly independent, whether findings become public, and whether the pace of releases measurably changes. Those are observable, which is more useful than arguing about intentions.
If you want to track whether this becomes real rather than rhetorical, a few signals will tell you more than any statement:
- Named evaluators. Who the independent evaluators are, and whether they're genuinely unaffiliated with the labs.
- Published findings. Whether evaluation results reach the public, including the unflattering ones.
- Release cadence. Whether the gap between frontier model releases actually lengthens.
- Government movement. Whether an antitrust waiver or federal oversight framework is formally proposed.
- Other labs signing on. Whether Google, Meta, and xAI commit to evaluators, not just agreement in principle.
What Does the AI Slowdown Plan Mean for Builders?
Less about frontier labs, more about a governance pattern that's worth copying at any scale. You won't host government-grade evaluators, but the principle behind them applies to every team shipping AI.
- Make safety claims verifiable. An evaluator with access is only useful if there's something to inspect. Log agent actions, tool calls, and decisions so claims about behavior can be checked, a practice we cover in AI agent evaluation.
- Treat evaluation as continuous. A one-time pre-launch review misses drift and new failure modes. Standing evaluation catches problems while they're cheap to fix.
- Build independent review in. Someone other than the builders should be able to test and challenge the system, the same separation of duties behind sound AI governance.
- Prepare for regulation that looks like this. Oversight backed by federal rules would echo regimes already arriving elsewhere, like the audit and documentation duties in EU AI Act compliance.
- Document incidents honestly. A culture that records and reviews failures, rather than burying them, is what makes outside oversight workable at all.
The honest read: whether or not the industry actually slows down, the direction of travel is toward AI systems being inspectable by people who didn't build them. Teams that design for auditability now will find that shift cheap. Teams that don't will find it expensive, whether the pressure comes from regulators, enterprise customers, or their own incidents. Auditability is also becoming a sales advantage, since enterprise buyers increasingly ask for evidence rather than assurances.
How Van Data Team Helps Teams Get Audit-Ready
We help teams build AI systems that an independent reviewer could actually verify. That means structured logging of agent behavior, continuous evaluation rather than launch-day testing, clear separation between the people who build a system and the people who assess it, and incident processes that produce records rather than rumors.
The frontier-lab debate will keep moving, and reasonable people will disagree about whether this plan goes far enough or means what it says. For teams shipping real systems, the practical move is the same either way: our work on governing agentic AI at scale and AI agent evaluation is about making your safety claims something you can prove, not just something you can state.
Article FAQ
Questions readers usually ask next.
These short answers clarify the practical follow-up questions that often come after the main article.
Need a similar system?
If this article maps to a workflow your team already operates, the next step is usually a scoped review of the system, constraints, and rollout path.
Book your free workflow review here.
Related articles
View allGemini 4 Pro Leaks: What's Verified and What's Hype
OpenAI's Navier-Stokes AI Agent Swarm: What It Shows

