Slowing down AI is harder than it seems: Who will ultimately pay for the pause?

Anthropic CEO Dario Amadei has proposed slowing the pace of AI development. But how can safety concerns be reconciled with competitive goals? Photo: Solen Feyissa / Unsplash.com
It is in the interest of all developers to slow down the development of AI—and, along with it, the spending race—but this is not the case for each individual company. Therefore, the key question is whether market participants will be able to agree not only on the rules for collaboration but also on how to ensure compliance with them. At the same time, China may turn out to be one of the main beneficiaries of such a slowdown. For more details, see this article by Vadim Novikov, an advisor to the president of Almaty Management University (AlmaU).
Safety vs. Competition
On September 12, Anthropic CEO Dario Amodei called for slowing the pace of AI development in an essay titled “We Must Pace the Frontier.” He noted that he is not suggesting a halt to the industry’s development: “Slowing down does not mean stopping model training or technical progress.”
Amodei’s plan consists of three parts. It begins with external oversight. Independent evaluators must have access to tests, incidents, and model training. Laboratories could jointly assess cyber and biological risks. A more stringent option would be to restrict computations, training runs, or the use of AI to create new models.
Anthropic’s competitors supported Dario Amodei’s call. In particular, OpenAI CEO Sam Altman promised to “bring in independent experts who will have the same access to the system as employees.” Microsoft, for its part, published a set of rules for AI—with specific restrictions outlined. So far, Nvidia CEO Jensen Huang—the leading supplier of chips for the AI sector—and Meta CEO Mark Zuckerberg have spoken out against slowing down the development.
But so far, no one has proposed a standard measure of speed, a method for detecting violations, or consequences for violators.
And this is no trivial matter. Here, security becomes a matter of competition. Laboratories and companies participating in the AI race need to enter into an agreement that, in essence, it would be in everyone’s interest to violate. Without government involvement, it is essentially impossible to enforce.
It’s beneficial to slow down together, but not to pause
To understand the risks facing companies and laboratories—which, by the way, are preparing for an IPO—we need to figure out why they all need this break.
Training the model requires specialized chips, a network, and electricity. The trained model also consumes energy as it responds to users. According to estimates by Our World in Data based on data from the International Energy Agency, in 2025, AI data centers accounted for about 2% of electricity consumption in the United States. This is already a significant portion of the energy system.
Physical scale translates into financial pressure. According to the Financial Times, OpenAI’s net loss for 2025 amounted to approximately $39 billion. Part of this is due to a non-cash revaluation of investor equity. At the same time, the company spent $34 billion. It does not yet fund its development with current revenues.
A coordinated slowdown would not nullify obligations under signed contracts, but it could curb the growth of new commitments and affect the growth trajectory of capital expenditures by companies participating in the AI race. This metric has long been a source of concern for investors.
However, potential cost savings do not eliminate the competitive risk. For a lab to slow down on its own is almost suicidal: while it delays the next training cycle, a competitor could release a more powerful model and attract users and capital.
An agreement to slow down collectively seems like a solution. But the shared benefit alone is not yet enough to ensure that everyone adheres to the agreement.
To understand how this works, consider the OPEC oil cartel. It is in the countries’ collective interest to limit production, but it is better for each country individually to sell more while the others adhere to their quotas. Laboratories face the same conflict: it’s more beneficial for everyone to slow down spending, but for each one individually, it’s better to continue the race once the others have stopped. This is cartel logic, not a definitive legal assessment of Amodei’s plan.
Reach an agreement, identify the deception, and punish the offender
Stable coordination—which it pays to disrupt—rests on three things: agreeing on a rule, detecting cheating, and making it unprofitable. This framework is called “consensus–detection–punishment.” Louis Kaplow of Harvard and Carl Shapiro of the University of California, Berkeley, summarize the standard model of sustainable collusion as follows.
Let's examine Amodea's plan in light of these conditions.
— Consensus: What to Agree On
Participants are in different positions in the race, so they may want different rates of deceleration. It is more advantageous for the leader to pause the release of new models: this preserves their lead. A company catching up may prefer to limit only the next major training cycle, but retain the right to release an improvement that has already been prepared. Computational limits also affect companies differently: different data and methods can yield different results on the same hardware. This means that, first, they need to agree on exactly what to slow down and how to measure the pace. Finally, the participants will need to share a common understanding of security. Protecting against cyberattacks and protecting people from risks they consciously choose to take are two different tasks.
— Detection: How to Spot a Violation
The absence of a new product does not prove that development has been halted. Therefore, external evaluators need access to the training data, internal tests, and incident reports—not just the finished model.
— Punishment: How to Make Violations Unprofitable
Amodei did not present a finalized sanctions plan. However, the government could require that models be reviewed before release or make obtaining government approval a condition for accessing customers.
That would give the agreement a force that companies seeking to reduce competition do not have.
But first, the government needs to determine what kind of coordination among competitors is lawful. Joint testing and the exchange of information about threats are not the same as an agreement not to train or not to release certain models.
The U.S. National Cooperative Research and Production Act —a federal law enacted in 1993 that regulates joint projects between companies from an antitrust perspective—provides for special treatment for this type of research and standards. Therefore, Amodei is requesting government mediation or a narrow exemption for security negotiations. However, permission to negotiate does not yet guarantee implementation.
The United States and China determine the reality of the common limit
Even if U.S. law allows for an agreement, it would cover only part of the global race.
The overall limit depends primarily on two development centers. According to the AI Index 2026, in 2025 the U.S. released 59 notable models, China released 35, and South Korea, which ranked third, released 8. Therefore, the positions of Washington and Beijing are more important than the consensus among company executives.
Washington is now opting to accelerate the pace. On September 14, U.S. President Donald Trump rejected a call from major American laboratories to slow down AI development, calling any attempts to restrict the technology “part of a sick conspiracy.”
At the same time, the U.S. government has already demonstrated—using Anthropic as an example—that it can control specific dangerous capabilities, as it did in June when it demanded that access to Fable 5 and Mythos 5 be blocked for foreign nationals. Unable to immediately verify the citizenship of every user, the company disabled the models for everyone. Mythos later became available to verified organizations. This is how the government regulates dual-use models: not only their release, but also their user base.
There’s a simple explanation for why Trump reacted so negatively to the initiative to slow down the pace: he doesn’t want to cede leadership in AI to China. This is yet another problem in and of itself: U.S. regulations won’t apply to Chinese laboratories.
Shortly after Amadei called for a slowdown in AI development, Chinese President Xi Jinping also delivered a speech. But his speech contained a contrary call to the BRICS countries: to “firmly maintain the initiative,” expand research, encourage knowledge sharing, and promote the development of open-source models. According to Jinping, China will establish an open AI community for BRICS to facilitate such exchanges. Meanwhile, on Monday, September 14, Chinese authorities published the third version of their AI security governance framework.
Thus, Beijing is not choosing between security and growth, but is trying to balance the two.
Joint testing and the exchange of threat intelligence are part of this course of action. There is no overall speed limit, as one could maintain the advantage of U.S. leaders. Therefore, inspections are possible even while the race continues, and a uniform speed limit remains unlikely.
The restrictions will affect the next order sooner than the existing infrastructure
Suppliers of chips and equipment for the AI race need not worry about a "slowdown" clause in existing agreements. Validating a finished model does not reverse the computational resources already spent and does not terminate signed contracts for existing data centers.
The main risk here is not a sharp decline in the use of existing equipment, but a slowdown in the growth of demand. As a result, what matters to investors here is not the general question of “will AI come to a halt?” but a more specific one: which project will be next to come under scrutiny, and what will happen to it—will it be delayed or canceled?
Supplies of accelerators, networking equipment, and new data center capacity may be affected ahead of the next major training cycle. Existing models will continue to serve users, and some of the capacity may be repurposed for other tasks.
Who will keep an eye on the guards?
This concludes the investment analysis. However, the practical question of inspection timelines boils down to a regulatory one: what exactly should inspectors consider to be safe? Amodei speaks not only of cyber and biological risks, but also of “alignment”—ensuring that the model’s behavior aligns with the values and rules set by humans.
It’s difficult to verify whether a model can carry out a cyberattack, but at least it’s clear what exactly you’re testing. Values are more complicated: the controller will have to decide which values the machine should protect and from which decisions the person themselves needs to be protected.
We fear that a machine will start making decisions for us, supposedly for our own good. But the government is capable of doing the same thing and doesn't listen to individual requests.
This slowdown may give us time to define the limits of power—of machines and of the state. But even that will not answer the age-old question: “Who will guard the guards?”
This article was AI-translated and verified by a human editor






