AI Pacing Isn’t One Policy. It’s a Set of Different Brakes.
The real question isn’t whether AI slows down. It’s where the brake goes.Momentum is not a standing permission. (Image generated by author using AI — ChatGPT)The misleading part of “slow down AI” is not slow. It is the singular.The phrase makes it sound as if frontier AI has one shared throttle and…
The real question isn’t whether AI slows down. It’s where the brake goes.Momentum is not a standing permission. (Image generated by author using AI — ChatGPT)The misleading part of “slow down AI” is not slow. It is the singular.The phrase makes it sound as if frontier AI has one shared throttle and the policy argument is about how far to turn it down. But the proposals now being grouped under pacing do not reach for the same control.One can hold a training workload. Another can make capability progression conditional on stronger verification. Another can put the gate at deployment. A fourth can call for restraint until shared safety bars exist without specifying machinery at the same level.Those differences are not semantic trivia.They determine what can actually stop, what evidence causes it to stop, who gets to inspect that evidence, and what has to become true before progress continues.The current language also has a short memory. September 2026 is a visible convergence point for “pacing,” not the beginning of the idea. The public Pacing the Frontier statement was circulating in July; Demis Hassabis’s standards-body proposal predates the September cluster; and OpenAI described an operational slowdown in August.The useful development is not that everyone suddenly discovered the same policy. It is that several different control mechanisms are now being discussed with the same word.That is where the comparison gets interesting.Four places restraint can enter the systemA pacing proposal becomes much easier to inspect once the control surface is visible. In the current source set, four distinct versions show up.1. Training and workload holds.OpenAI provides the strongest implementation evidence here. In August, after the OpenAI-Hugging Face incident and preliminary evidence that its Astra model might meet a Critical cybersecurity capability threshold, the company described temporarily slowing scaling.Its account included paused frontier work, tighter research-environment controls, expanded monitoring, smaller-scale training and evaluation, and selective resumption as safeguards improved.The important feature is that the constrained object can be narrow. A lab does not need to declare that “AI development” has stopped in the abstract. It can hold a particular training run, research workload, inference path, or deployment decision because the risk evidence has moved beyond what the current safeguards comfortably cover.OpenAI’s Frontier Governance Framework gives that kind of decision a broader risk-assessment structure, drawing on internal research, model evaluations, outside experts, government input, and third-party evaluation where appropriate. In this source set, that is the clearest case where pacing is more than an argument about what a lab should do. There is evidence of an implemented control.There is still judgment inside it. OpenAI has not published one fixed numerical restart threshold that applies across every hold. Its public account ties continuation to stronger evidence about model behavior, safeguards, alignment, security, and residual risk.2. Capability-progression constraints.Dario Amodei’s proposal moves the brake outward. In We Must Pace the Frontier, he explicitly distinguishes pacing from halting training or technical progress. The object of concern is the rate of frontier capability advancement when safety, alignment, interpretability, security, and operational rigor are not keeping up.His first mechanism is embedded third-party evaluation: frontier companies would give external evaluators ongoing, employee-like access so they can inspect training pipelines and processes, verify safety commitments, and report incidents. Anthropic commits to that step in the essay. The next steps involve coordination among frontier companies in democratic countries and, eventually, international coordination.This is not a more elaborate version of a two-week training pause. It is an attempt to make capability progression conditional on a wider verification and coordination architecture.That distinction also exposes an authority problem. Evaluator access is not the same thing as final stop-or-restart authority. METR’s May Frontier Risk Report shows that external evaluators can receive unusually direct access to capable internal models and non-public information, with more editorial independence than in many earlier arrangements, without becoming the final decision-maker for a lab.Amodei’s proposal strengthens the evaluator’s position, but the relevant sources do not establish a fully independent regulator-like team inside Anthropic with final authority over development.3. Deployment gates.Hassabis places the strongest lever somewhere else. His frontier-AI framework centers on a standards body that would define what counts as a frontier-class model using dynamic benchmarks, develop assessment protocols, and coordinate testing.Labs would initially submit models voluntarily before release; if the process proved robust, he proposes formalizing it so frontier models would have to pass the assessment before deployment in the U.S. market.Here, the system can continue producing models while the gate sits closer to release and market access. A model crosses a frontier classification, enters an assessment regime, and can be withheld from deployment if it does not pass. The framework also leaves room for stronger escalation, including a coordinated slowdown among frontier labs if conditions warrant it.That proposal is materially different from holding a particular workload and from conditioning capability progression on a broader safety architecture. It is also still a proposal. I would not treat it as adopted Google DeepMind policy or as an operating U.S. regulatory regime.4. Restraint principles without equally specified machinery.Jakub Pachocki’s September essay belongs in the comparison, but not as if it were a fourth control architecture with the same level of detail.He argues that no lab has solved alignment and monitoring well enough to continue responsibly scaling at maximum speed for much longer, and says he expects and hopes voluntary slowdowns will become common until shared safety bars exist.That is meaningful evidence of convergence around restraint.The object is broad: continued maximum-speed scaling. The trigger is broad too: alignment and monitoring are not yet sufficient. The release principle is visible in the idea of shared safety bars.What is not equally specified is the machinery. The essay does not define the same kind of verifier architecture, institutional owner, or detailed restart process. Treating it as though it did would make the comparison tidier by adding precision the source does not contain.The four cases therefore do not line up as four labs offering interchangeable versions of the same policy. They occupy different control surfaces, and they arrive with different levels of implementation detail.The harder question starts after the brake is appliedStopping is only half a decision rule. The second half is who gets to release the brake, and on what evidence.This is where the proposals become less symmetrical:OpenAI’s operational account ties further progress to improved evidence about safeguards, model behavior, alignment, security, and residual risk.Amodei’s proposal makes pacing useful only if the gained time produces better alignment, interpretability, security, operational rigor, and verification.Hassabis would make deployment conditional on passing an evolving assessment regime once such a regime were formalized.Pachocki points to shared safety bars without specifying the same verifier or institutional owner.What this source set does not establish is a common cross-lab threshold of the form: when metric X reaches value Y, everyone restarts.That absence should not be confused with having no release logic. There is release logic. It is just different across proposals, differently specified, and often dependent on judgment.That matters because a pause can be genuine and still be weakly governed. If the continuation rule is vague, the pause can drift into symbolism. If the continuation rule is easy for the same decision-maker to satisfy, the control can become cosmetic. And if an evaluator can see the evidence but cannot determine what happens next, access alone does not settle the authority question.So the difficult part of pacing is not only designing a trigger. It is defining what evidence earns continuation, who can challenge that evidence, and who has the final say.A clear control can still be difficult to runEven a coherent pacing rule has to survive incentives, law, verification, and substitution effects.Amodei’s coordination step acknowledges that some forms of inter-company pacing may need government support. On September 15, Reuters reported that FTC chair Andrew Ferguson was skeptical of calls for antitrust exemptions tied to AI-company coordination, while other participants argued that existing law may already permit some safety information sharing.That dispute does not settle whether coordination is desirable or legally workable. It shows why “the labs should coordinate” is not yet an operating mechanism. A rule can make sense technically and still run into competition law, conflicting incentives, weak verification, or governments that do not trust one another’s compliance.There is a narrower implementation issue too. A targeted hold does not necessarily reduce total frontier progress one-for-one. Researchers, compute, or experimentation can move into work that remains unconstrained.OpenAI has described substitution and reallocation effects around its own pacing decision, but that should stay an OpenAI-specific observation. The current source set does not support generalizing the same effect across labs at the same scale.That is another reason the single speed metaphor breaks down. A brake can constrain one part of the system while pressure moves somewhere else.What should a reader be able to answer?When the next pacing proposal appears, the useful test is not whether it sounds cautious enough. A reader should be able to work out what the proposal would actually do.The questions I would hope the proposal makes answerable are:What can actually be stopped, delayed, withheld, or conditioned?What observed capability, incident, evaluation result, or risk judgment activates restraint?Who receives the evidence, who can challenge it, and what independence or access do they have?What new evidence is sufficient to continue, and who decides that it is sufficient?What is the scope: one workload, one lab, frontier-class models, an industry, or multiple countries?What is the status: an implemented control, an internal framework, a public proposal, or a restraint principle?Those questions do not choose a policy for the reader. They make the policy legible enough to argue about.The frontier does not have one speed setting.The practical question is where restraint enters the system, who controls it, and what has to be true before it comes off again.This story is published under the Generative AI publication. Connect with us on LinkedIn and follow Zeniteq to stay in the loop with the latest AI stories. Let’s shape the future of AI together!AI Pacing Isn’t One Policy. It’s a Set of Different Brakes. was originally published in Generative AI on Medium, where people are continuing the conversation by highlighting and responding to this story.Source: Generative AI Pub — Published — Category: Image AI