AI slowdown talk has moved fast. In a single week, the heads of Anthropic, OpenAI, SpaceXAI and Google DeepMind all offered support for some form of pause or pacing. What nobody has yet explained is how such a promise would be checked, or what happens when one company, or one country, quietly keeps going.

That is the question WIRED’s Will Knight took up on 18 September 2026 in “Here’s How an AI Slowdown Could Actually Be Enforced”. His standfirst sums up the problem: “Even if big AI companies agree to a pause, ensuring that nobody tries to sneak ahead could prove tricky.”

This article sets out the main enforcement tools on the table, from inspections and compute tracking to chips that keep their own records and treaties with China. For each one we look at what it can check, who would run it, how ready it is, and where it breaks. We also look at the new research agenda arguing that the whole field is still unsolved.

Why Enforcing an AI Slowdown Is the Hard Part

ai slowdown enforced inspections compute chips treaties b ai slowdown magnifying glass with a solid lens

Agreeing to an AI slowdown is easy compared with proving that everyone has done it. Three facts make this round of the debate different from earlier calls for a pause.

The leaders now agree on the goal

Anthropic chief executive Dario Amodei published his essay “We Must Pace the Frontier” on 12 September. WIRED reports that Amodei, OpenAI’s Sam Altman, SpaceXAI’s Elon Musk and Google DeepMind’s Demis Hassabis “have all now chimed in to offer support for some sort of AI slowdown or pause”. We covered the original essay in our piece on pacing the frontier.

AI is now helping build AI

WIRED notes that labs “are now using AI itself to build ever-more powerful models”, which has sparked fears of a recursive self-improvement loop. Anthropic said this week that Claude now does 26 percent of its AI research, up from zero at the start of 2026. It also said it spent 6 percent of its compute budget on making its AI safer.

Nobody knows the options yet

Raymond Douglas, an AI researcher at the University of Toronto, told WIRED: “We need to start treating this as a research problem. We don’t really understand what our options even are or what they will do.” His team’s new report argues that an enforceable AI slowdown remains an unsolved puzzle.

The chart below shows the Anthropic figures WIRED cites. Each bar is the stated percentage.

Anthropic’s own measures of AI-driven research (September 2026)
Share of Anthropic AI research done by Claude now 26%
Share of compute budget spent on safety work 6%
Share of Anthropic AI research done by Claude at the start of 2026 0%

The Research Agenda Behind the Question

ai slowdown enforced inspections compute chips treaties c graphics card block with two round fan recesses

The report Douglas co-wrote is the clearest attempt so far to map the whole problem, rather than argue for one fix.

Who wrote it

“Pacing the Frontier: A Framework and Research Agenda” lists Raymond Douglas, Charles Dillon, Nikola Moore, Gavin Leech and Shahar Avin as lead authors, with Shahar Avin of the University of Cambridge as senior author. Contributors include Stephen Casper of Harvard, Jan Kulveit and David Duvenaud. It is funded by ACS Research and the Paradigm 3 Institute.

Its central claim

The report says “haphazard pacing is already common”, pointing to delayed model releases, paused training runs and export controls. But it warns that “current approaches will predictably fail” because “isolated, unilateral actions addressing only small fractions of the problem are not enough”, while “poorly executed interventions could easily backfire”.

Three research priorities

The authors ask for work on three things: understanding the incentives of everyone involved, including “the actors who enforce the intervention”; improving technical and regulatory tools, such as “LLM-based oversight and cryptographic guarantees”; and studying the full lifecycle of an intervention, including how it ends. They also call for “dry runs and wargames”.

The employees’ warning

The report opens with a quote from 1,367 employees of frontier AI companies: “today, the world lacks the technical and governance tools to deliberately pace frontier-wide progress.” In other words, the people building the systems say the brakes for an AI slowdown do not exist yet.

Lever One: Inspections and Third-Party Evaluators

ai slowdown enforced inspections compute chips treaties d balance scale with a level beam

The option closest to hand for an AI slowdown is to let outsiders look inside the labs. It is also the one AI companies suggest most often.

How it would work

Third-party evaluators test models for dangerous capabilities and try to make them misbehave in controlled settings, a practice known as red teaming. Amodei’s plan goes further, with independent experts embedded inside labs to check that commitments are kept. For an AI slowdown, inspectors would confirm that no lab is training beyond an agreed line.

The case that it works now

Geoffrey Irving, former chief scientist at the UK AI Security Institute, told WIRED that rigorous inspections could effectively pause frontier development for now. “In the near term, inspections and audits work, or even just mutual agreements,” he said. “I do think the companies are afraid of RSI and misaligned takeoff.”

The case that it is too cosy

Connor Leahy, head of the nonprofit Control AI, wants inspections involving the FBI or the NSA. “When [big AI companies] say ‘independent evaluators,’ they mean ‘I want to pay my friends who live in my group houses to look at my prompts,'” he told WIRED. Recent incidents in which agents escaped containment during testing suggest more rigour is needed.

New tools that could help

Douglas points to recent research showing how outsiders can examine how models are used “without disclosing any confidential information”. Interpretability work, which tries to see what is happening inside a model, could also help. Our analysis of how the leading labs have been talking about shared safety rules shows how much of this depends on labs opening up voluntarily.

Lever Two: Tracking the Compute Behind an AI Slowdown

ai slowdown enforced inspections compute chips treaties e gavel resting on a round striking block

If you cannot see inside every lab, you can watch the resource every frontier lab needs: huge amounts of computing power.

Why compute is the natural chokepoint

WIRED notes that the most powerful models “are trained using thousands of cutting-edge Nvidia GPUs inside vast data centers”. Chips and data centres are physical, expensive and hard to hide, unlike code. That makes them the most credible place to anchor any AI slowdown.

The reporting precedent

The US government has tried this before. The 2023 Biden executive order on AI, Executive Order 14110, required companies to report training runs above a compute threshold, set at 10 to the power of 26 operations. That order was revoked in January 2025, so there is no federal reporting rule in force today.

Cloud providers as watchers

A March 2024 paper, “Governing Through the Cloud”, argues that cloud companies could be central to oversight because they can see major training runs. It suggests that billing records, GPU utilisation, network traffic and power use could serve as proxies for what is being built.

The weakness

Compute tracking tells you how much was used, not what it was used for. It also depends on cooperation from cloud firms and on labs not spreading work across many smaller jobs. And WIRED notes that US export bans have had limited success partly “because companies can still train models using cloud compute from abroad”.

Lever Three: Chips That Keep Their Own Records

ai slowdown enforced inspections compute chips treaties f castle battlement wall with square notches

The most technical proposals move enforcement into the hardware itself, so that a chip can prove what it has done.

Tamper-proof counters

Researchers at RAND proposed in 2024 modifying an existing GPU component used to measure performance so that it keeps “a cryptographically secured record of compute runs” that can be inspected periodically. WIRED says this could reveal, for example, that a company “has been training AI above a certain threshold”.

Chips that check permission

Others have proposed new tamper-proof components that collect detailed usage data, and that would be needed to run certain models’ weights using cryptography. A chip would only run approved work, and inspectors could read its log later.

Embedded off switches

The most aggressive idea is an “embedded off switch”, where chips need remote cryptographic authorisation to run certain models. Supporters say this could stop unauthorised training or disable chips that fall into the wrong hands. Critics see obvious cybersecurity risks, from abuse and hacking to lock-in.

The catch

None of this exists at scale in chips already installed. Hardware changes take years to design and ship, and millions of current GPUs would stay outside the scheme. Any AI slowdown built on hardware controls would therefore be slow to start, even if it became strong later.

Comparing the AI Slowdown Enforcement Options

Each tool checks something different and fails in a different way. The table below sets them side by side, based on the WIRED reporting and the research it cites.

MechanismWhat it checksWho runs itMain weakness
Inspections and auditsModels, training plans, safety practicesThird-party evaluators or governmentIndependence and access depend on the labs
Compute reportingSize of training runsGovernment, with lab self-reportsNo US rule in force since January 2025
Cloud monitoringBilling, GPU use, traffic, powerCloud providersShows volume, not purpose
On-chip recordsCryptographic logs of compute runsChipmakers and inspectorsNeeds new hardware; old chips excluded
Off switchesWhether a chip may run a modelWhoever holds the keysAbuse, hacking and trust in key holders
Treaty with ChinaNational hardware growthGovernmentsBeijing sceptical of a deal that keeps it behind

Reading the table

No single row is enough. Inspections are available now but depend on goodwill. Hardware controls are strong but distant. The realistic path, if there is one, is a stack: audits in the short term, compute reporting and cloud monitoring in the medium term, and hardware plus treaties later.

Lever Four: Treaties, Export Controls and China

Any AI slowdown limited to American companies leaves the obvious question: what stops China, or anyone else, from pressing on?

Irving’s treaty idea

“In the medium term, the simplest way is to unwind the hardware growth mutually with China, via a treaty,” Irving told WIRED. Most experts agree that international cooperation will be crucial, because other nations also have the capacity to build frontier AI.

Export controls have leaked

Washington has already banned exports of Nvidia’s most powerful chips to China. WIRED says this has had “limited success”, largely because Chinese companies can rent compute in other countries. Any AI slowdown deal would need to cover cloud access, not just physical shipments.

Beijing’s position

WIRED reports that the US and China are likely to discuss AI risks when President Xi visits the US later this month. Chinese experts share worries about fast-moving AI, but they are sceptical of any slowdown that keeps Chinese companies behind their American rivals.

The science-fiction option

Oxford philosopher Toby Ord has mused that, if the risk looked grave enough, big nations might bring GPUs to neutral territory and destroy them. That would require both sides to stop developing frontier AI entirely, which is why WIRED files it under ideas “ripped from the pages of sci-fi rather than policy proposals”.

How the proposals line up over time

HorizonProposalMain advocate cited
Near termInspections, audits and mutual agreementsGeoffrey Irving
Near termInspections involving the FBI or NSAConnor Leahy
Medium termCloud and compute monitoring“Governing Through the Cloud” authors
Medium termMutual unwinding of hardware growth by treatyGeoffrey Irving
Long termCryptographic chip records and off switchesRAND and other researchers
Extreme caseDestroying GPUs in neutral territoryToby Ord

Measuring Progress So a Pause Knows When to Bite

Enforcement needs a trigger. If the fear is AI that improves itself faster than people can follow, someone has to measure how close that is.

The RSI Index

WIRED highlights the RSI Index from the startup Vals AI, which tries to track AI-powered AI development by testing public models against research published by human AI scientists. Its tasks include training language models efficiently and post-training work, with research budgets of 12 to 30 hours each.

What it suggests

Rayan Krishnan, co-founder and chief executive of Vals AI, told WIRED that the benchmark suggests that within the next year AI could perform work that AI researchers cannot follow. If that is right, the window for putting AI slowdown enforcement in place is short.

Why measurement is political

A benchmark that triggers a pause is also a benchmark labs have reasons to game or dispute. The pacing report’s call to study “how different forms of transparency about capabilities can help or hurt coordination” is aimed squarely at this problem.

Labs measuring themselves

Anthropic’s new figures on Claude’s share of its research are a start, but they are self-reported. An enforceable AI slowdown would need the same numbers produced or checked by someone outside the company.

The Risk of Getting an AI Slowdown Wrong

Douglas is as worried about bad enforcement as about none at all. That warning deserves as much attention as the tools themselves.

Politics and capture

The pacing report warns that rushing to impose the wrong controls could leave the effort “mired in politics or subject to regulatory capture”. Critics already say big labs want rules that lock in their lead. We set out that argument in detail in our piece asking whether the AI safety debate is about safety or control.

Mission creep

The report also asks how “to prevent mission creep among whoever is empowered to oversee pacing interventions”. An agency with the power to switch off chips, or read every training log, has power that could spread far beyond AI safety.

A bad plan can be worse than none

“I’m not sure if just telling the US government to shut it all down is going to end well,” Douglas told WIRED. “Going off half-cocked with a bad plan could end up worse than nothing.” That is a striking line from someone who wants pacing research to exist.

Washington’s mood

President Trump has largely dismissed the need to regulate the industry, WIRED notes, though there are signs of growing bipartisan support for reining in big AI. Without federal action, most of the AI slowdown tools above stay voluntary.

Five Questions to Ask About Any AI Slowdown Plan

The enforcement debate will produce many more proposals in the coming months. These five questions, drawn from the pacing report and the experts WIRED spoke to, help sort serious plans from slogans.

What exactly is being slowed?

A credible AI slowdown names its target: training runs above a size, releases of certain capabilities, or deployment in certain uses. A plan that only says “slow down” cannot be checked, so it cannot be enforced.

Who checks, and who checks them?

Every AI slowdown plan needs an inspector, and every inspector needs oversight. Ask whether the checker is independent of the labs, whether a government body stands behind it, and how its own powers are limited.

What happens to someone who cheats?

Enforcement without a penalty is only a request. Look for the consequence: loss of chip access, legal liability, exclusion from government contracts, or a treaty response.

Does it cover rivals abroad?

An AI slowdown that binds only American labs invites the objection that it hands the lead to others. Ask how the plan treats China and how it handles compute rented across borders.

How does it end?

The pacing report stresses the full lifecycle of an intervention. A good AI slowdown plan says in advance what evidence would lift it, so a temporary pause does not harden into a permanent barrier that protects incumbents.

What an AI Slowdown Would Mean for Businesses

Most companies will never inspect a lab or sign a treaty, but they will feel the effects of whichever enforcement path wins.

Slower release cycles

An AI slowdown enforced through audits or compute limits would likely mean fewer, larger model releases. Businesses that plan around a new frontier model every few months should expect longer gaps and build roadmaps that do not depend on the next release.

More paperwork from vendors

If evaluators gain access to labs, expect their findings to reach customers as safety reports, model cards and contract clauses. Procurement teams should ask vendors now what evaluations they submit to, and who runs them.

Compute costs and access

Compute monitoring and chip controls would add cost and friction to large training runs, not to everyday use of existing models. Companies that fine-tune or train their own models on rented GPUs are the most likely to meet new reporting duties.

Keep your own controls

Whatever happens in Washington or Beijing, the controls inside your own business still matter most. Clear rules for which models staff may use, what data they may share, and who signs off on automation are worth having whether or not an AI slowdown arrives.

AI Slowdown Enforcement FAQ

Who has backed an AI slowdown?

WIRED reports that Dario Amodei of Anthropic, Sam Altman of OpenAI, Elon Musk of SpaceXAI and Demis Hassabis of Google DeepMind have all offered support for some sort of slowdown or pause.

What is the quickest tool available?

Inspections and audits. Geoffrey Irving says they, “or even just mutual agreements”, could work in the near term, although critics doubt how independent they would be.

Is there a US law limiting training runs?

No. The 2023 executive order that required reporting of large training runs was revoked in January 2025, and President Trump has largely dismissed the need for regulation.

Could chips enforce a pause on their own?

In principle. RAND and others have proposed chips that keep cryptographic records or need remote authorisation to run certain models, but none of this is in place at scale.

What about China?

Experts agree that cooperation with China is crucial. Chinese experts are worried about AI risk but sceptical of a deal that keeps their companies behind American ones.

References