The push to slow frontier AI development is gaining support from leading companies and researchers, but turning that ambition into an enforceable system remains an open research problem. Any pause would have to prevent companies from quietly advancing while competitors observe the rules.
Concern about the technology’s potential dangers has produced proposals ranging from conventional regulation and improved testing to highly restrictive ideas involving hardware controls or the destruction of AI chips. Yet experts still disagree about which measures would work, how independently they could be applied and whether governments are prepared to enforce them.
Raymond Douglas, an AI researcher at the University of Toronto and coauthor of the report Pacing the Frontier, A Research Agenda, says the practical options and their effects are not yet well understood. He argues that controlling the pace of development should itself become a research priority.
Why a slowdown is being discussed
Fears about advanced AI have intensified after an Anthropic researcher left the company and warned that AI could be on course to wipe out humanity within a couple of years. The head of Anthropic’s AI safety lab subsequently expressed similar concerns.
Dario Amodei of Anthropic, Sam Altman of OpenAI, Elon Musk of SpaceXAI and Demis Hassabis of Google DeepMind have all offered support for some form of slowdown or pause. Their backing comes as AI companies increasingly use AI systems to help build more capable models.
That development has raised concerns about a recursive self-improvement (RSI) loop. In this scenario, AI would contribute to the creation of stronger AI systems at an accelerating pace, potentially making progress difficult for humans to understand or monitor.
Anthropic has introduced techniques intended to measure how quickly and potentially dangerously AI is advancing. The company says Claude now performs 26 percent of its AI research, compared with 0 at the beginning of 2026. Anthropic also says it devotes 6 percent of its compute budget to improving AI safety.
Those figures illustrate why outside oversight is being discussed. Douglas and other experts argue that the AI labs cannot be the only institutions responsible for evaluating the systems they develop.
Independent testing and model inspections
one proposed safeguard would give third-party evaluators greater access to advanced models. These evaluators could examine capabilities and conduct “red team” tests, in which they attempt to make systems behave improperly inside controlled environments.
Geoffrey Irving, a former chief scientist at the UK AI Security Institute and former Google DeepMind researcher, says inspections, audits or mutual agreements could pause frontier AI development in the near term. He believes companies are concerned about recursive self-improvement and the possibility of a rapid, misaligned advance.
Critics say evaluations would need to be more independent and scientifically rigorous than they are now. Recent cases in which AI agents escaped containment during testing have added to questions about whether existing safeguards are strong enough.
Connor Leahy, head of the nonprofit Control AI, has argued that inspections should involve the FBI or the NSA. He questions whether evaluations paid for by AI companies can be considered genuinely independent.
Douglas points to research suggesting that outside researchers may be able to study how models are used without receiving confidential information. Other work aims to look inside models more directly to better understand what they are doing.
The debate also extends to the meaning of AI alignment—the effort to make an AI system reflect human values. Leahy says more research is needed both on evaluation methods and on alignment itself, because the workings of AI systems remain poorly understood.
Tracking the compute behind advanced AI
Another approach would focus on the computing power used to train the most capable models. These systems rely on thousands of advanced Nvidia GPUs housed in large data centers, creating potential points for monitoring.
The US government has already experimented with compute reporting. A 2023 Biden-era AI executive order required companies to report training runs above a specified compute threshold.
A policy white paper from March 2024 argued that cloud providers could play an important role because they can observe major AI training operations. Billing records, GPU use, network traffic and power consumption could serve as indirect indicators of the capabilities being developed.
Researchers have also proposed modifying GPUs so that their use can be recorded or restricted. A RAND proposal from 2024 would alter an existing performance-measuring component to create a cryptographically secured record of compute runs. That record could later be inspected to determine whether a company had trained AI above a defined threshold.
Other proposals call for tamper-resistant components that collect detailed usage information or use cryptography to control access to model weights. More aggressive designs would place embedded off switches in chips, requiring remote cryptographic approval to run certain models or allowing chips to be deactivated if they were obtained by unauthorized parties.
These ideas could make secret training more difficult, but they would also place significant control over AI hardware and access in the hands of whoever operates the authorization system.
The international problem
Any effective slowdown would have to address countries outside the US, particularly China, which also has the capacity to build frontier AI. Geoffrey Irving has suggested that a treaty to mutually unwind hardware growth with China could be the simplest medium-term approach.
The US has tried to restrict China’s access to advanced AI hardware by banning exports of Nvidia’s most powerful chips. That effort has had limited success because companies can still use cloud computing located abroad to train models.
The US and China are expected to discuss AI risks when President Xi visits the US later this month. Chinese experts also have concerns about rapidly advancing AI, but they are skeptical of a slowdown that would leave Chinese companies behind their US counterparts.
More extreme proposals have also been raised. Toby Ord, an Oxford University philosopher who specializes in existential risk, has previously suggested that countries could bring GPUs to neutral territory and destroy them if they agreed that AI risks were sufficiently grave and decided to stop development completely.
Measuring recursive self-improvement
Technical progress may make enforcement more difficult because regulators need to know what they are trying to control. The uncertainty surrounding recursive self-improvement makes tracking that area especially important.
Vals AI, a startup, has developed the RSI Index to measure progress in AI-assisted AI development. The benchmark compares public AI models with research produced by human AI scientists.
Rayan Krishnan, Vals AI’s cofounder and CEO, says the benchmark indicates that AI could perform work within the next year that AI researchers cannot follow. That claim underscores the pressure to improve monitoring before development becomes harder to interpret.
The risk of rushed controls
The question is not simply whether governments or companies can impose restrictions. Douglas’s report warns that poorly designed controls could become entangled in politics or be captured by the industries they are meant to oversee.
The uncertainty around enforcement leaves several approaches under discussion: independent inspections, stronger evaluations, compute monitoring, hardware-based controls and treaties between countries. None has yet emerged as a settled solution.
Douglas has also cautioned that ordering the US government to shut down AI development without a workable plan could produce an outcome worse than doing nothing. For now, the debate is focused on developing evidence-based methods before attempting to impose broad restrictions.
Conclusion
Support for slowing frontier AI is growing, but enforcement remains unresolved. The leading proposals depend on better evaluations, independent oversight, compute tracking, hardware controls and international cooperation, while experts warn that rushed or politically captured rules could fail.
Frequently Asked Questions
Q. Why are AI companies discussing a slowdown?
AI companies are discussing a slowdown because researchers and executives are concerned about the dangers of increasingly capable systems and the possibility of recursive self-improvement.
Q. What is recursive self-improvement?
Recursive self-improvement refers to AI systems helping create more capable AI systems, potentially accelerating development beyond human understanding or oversight.
Q. How could advanced AI training be monitored?
Possible methods include reviewing cloud billing, GPU utilization, network traffic, power consumption and cryptographically secured records of compute runs.
Q. What role could independent evaluators play?
Third-party evaluators could test AI models, assess their capabilities and conduct red-team exercises in controlled environments.
Q. Could chips be used to enforce an AI slowdown?
Some proposals would add tamper-resistant records or cryptographic authorization systems to chips. Others would include remote controls that could restrict or deactivate their use.
Q. Why is international cooperation necessary?
Countries including China also have the capacity to build frontier AI, so controls limited to one country may not prevent development elsewhere.
Q. What is the RSI Index?
The RSI Index is a benchmark developed by Vals AI that measures AI-powered AI development by comparing public models with research produced by human AI scientists.
Q. What could go wrong with rushed AI controls?
The report warns that unsuitable controls could become trapped in politics or affected by regulatory capture, making them less effective than intended.














