P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

The AI slowdown lasted one weekend before it reached markets, Washington and Beijing

Dario Amodei asked frontier labs to give safeguards time to catch up. Sam Altman, Elon Musk and Demis Hassabis agreed with the direction, technology shares fell, Beijing objected, and the White House chose competition. The unresolved question is what anyone has actually agreed to slow.

By Parminder Kumar Sharma · · 6 min read

A glowing AI data centre between semiconductor wafers, falling market charts and opposing geopolitical centres.

A safety argument became a price signal

A warning about artificial intelligence crossed three boundaries in less than forty-eight hours. It began as an argument inside frontier laboratories, became a political dispute between the United States and China, and reached the market price of companies financing the AI build-out.

Anthropic chief executive Dario Amodei argued that the industry should deliberately pace the frontier so safeguards have time to catch up. OpenAI's Sam Altman, xAI's Elon Musk and Google DeepMind's Demis Hassabis publicly agreed with the direction. The agreement was striking because these companies compete for the same researchers, chips, customers and claims to technical leadership.

Investors did not wait for a policy document. SoftBank, one of OpenAI's most exposed financial backers, closed 10.7% lower in Tokyo on Monday after falling more than 13% during trading. SK Hynix lost 6.4%, Samsung Electronics 4.1% and TSMC 1.2%, according to Associated Press market reporting. One trading day cannot establish why every investor sold, and the wider market had other forces moving it. It does establish that a discussion once treated as philosophy is now material enough to enter a valuation.

The important development is not that several chief executives said "slow down". It is that nobody has yet defined a shared unit of speed.

Slow can mean four different things

The public language compresses several different proposals into one word. A laboratory can slow a training run, hold a trained model from deployment, restrict particular capabilities, or continue normal work while investing more in tests. Those choices have very different effects.

Four policies that can all be described as pacing, with very different commercial and safety consequences.

What is pacedWhat changesThe unresolved test
TrainingA larger or more capable model is delayed before the runWhich forecasted capability is serious enough to stop compute already booked?
DeploymentThe model exists but customers do not receive it yetWho independently verifies that safeguards are adequate?
CapabilitiesSelected cyber, biological, autonomy or weapons functions are restrictedCan the restriction survive fine-tuning, tools and open-weight alternatives?
EvaluationDevelopment continues while tests, monitors and incident controls receive more timeWhat happens when the evaluation fails close to launch?

The cooperation problem is inside the proposal

The proposal becomes harder at the national boundary. Amodei argued both that global pacing would require cooperation with China and that the United States should maintain restrictions on advanced chips and chipmaking equipment supplied to China. Beijing sees those positions as incompatible.

China's foreign ministry said confrontation and fear would damage global AI governance. A state newspaper described the proposal as containment presented in safety language. The United States sees the same controls as a way to prevent an authoritarian competitor from gaining a decisive capability. Both governments can therefore support "AI safety" while disagreeing about whether access to compute is part of cooperation or the prize being contested.

This is more than diplomatic wording. Imagine two runners asked to agree on a speed limit while one controls the other's shoes. The runner facing the restriction will treat the limit as an attempt to preserve the existing lead. The runner ahead will regard equal access as removing the leverage needed to keep the race safe.

Donald Trump made the competing US position explicit by saying that whoever wins AI wins. His comments allowed for unspecified guardrails but rejected measures that might surrender the American lead. The planned Trump-Xi meeting on 24 September may therefore contain two conversations under one heading: preventing catastrophic loss of control and preventing the other country from controlling the technology.

An agreement needs a trigger, a referee and a consequence

A credible pacing arrangement needs at least three things.

First, it needs a measurable trigger. Model size is a poor proxy because architecture, data, tools and test-time compute can change capability without a neat jump in training compute. A capability trigger is better, but only if evaluations resist gaming and reflect real deployment.

Second, it needs a referee with access to evidence. Company self-attestation is useful for speed and weak for conflicts of interest. Government-only testing risks moving too slowly or becoming a national advantage programme. Independent evaluation requires secure access to models, methods and incident data that firms currently guard.

Third, it needs a consequence. A failed evaluation could require mitigation, a narrower release, monitored access or a temporary hold. Without an agreed consequence, evaluation becomes publication rather than control.

OpenAI's policy statement on 9 September supported mandatory US rules based on capability and serious-incident reporting. That is more concrete than a general call for caution. It still leaves the international problem: a national rule binds the laboratories inside one jurisdiction while frontier research, open weights and compute supply chains cross borders.

The minimum structure required to turn public agreement into an operating control.

ElementQuestion it must answerWeak version
TriggerWhich demonstrated capability starts the pacing rule?A vague reference to models becoming more powerful
RefereeWho can inspect the evidence across competing labs?Each developer grades its own model
ActionWhat release, access or training change follows a failed test?Publish the risk and continue unchanged
CoverageWhich countries, open models and compute providers are included?Rules that apply only to willing US companies

The P.K. view

The agreement among rival AI leaders deserves attention, but agreement on a direction is not yet a brake. A brake has a threshold, an operator and a measurable effect on motion.

The market response may fade. The governance problem will not. Boards, investors and public buyers now have to ask whether a laboratory's safety commitments can delay the product in which they invested. If the answer is no, the commitment is reputational. If the answer is yes, safety has become a financial assumption and should be disclosed and modelled like any other release dependency.

The right question this week is not whether the industry should move fast or slow. It is which capability would make a laboratory stop, who would be allowed to verify that capability, and whether the same rule applies to the competitor the laboratory fears most. Until those three answers exist, frontier pacing remains an important warning without an operating mechanism.

Sources

  1. PrimaryThe AI policy window is open. We need to act.OpenAIaccessed 2026-09-14
  2. Reported byNew warnings about the risks of AI to humanity revive a long-running debateAssociated Pressaccessed 2026-09-14
  3. Reported byBeijing hits back at Anthropic CEO's call to curb China's AI developmentAssociated Pressaccessed 2026-09-14
  4. Reported byTrump downplays the need to check AI developmentAssociated Pressaccessed 2026-09-14

Share this briefing

Know someone who owns this problem? Send it to them.

Related briefings

The briefing, in your inbox

Practitioner analysis of cyber and AI security news. No vendor noise.

One email per briefing. Unsubscribe any time.