Analysis frame
Primary-source evidence
The proposal should be judged as an incentive and verification design: whether outside access can detect capability acceleration and force action when commercial or geopolitical pressure rewards continued speed.
- Frontier AI laboratory employees and safety teams working inside capability races
- Independent evaluators asked to verify internal processes and incidents
- Governments balancing catastrophic-risk claims against national competition
- Public institutions and network operators exposed to failures from capable agents
- Which capability measurements would trigger a slowdown or temporary stop
- Whether embedded evaluators will have protected reporting and meaningful enforcement power
- How coordination can avoid antitrust violations or exclusion of smaller developers
- Whether international rivals would accept verification strong enough to detect secret development
- Continuous external access could shift AI safety from selective model testing toward supervision of training pipelines and operational controls
- Large laboratories could turn shared safety requirements into barriers that entrench their own market position
- Public disagreement over threat timelines may harden if forecasts are not paired with observable thresholds
- A credible pacing regime could redirect competition from raw capability toward verifiable control and incident transparency
The proposal has three layers
The first layer is unilateral and operational: continuous access for embedded third-party evaluators. The second asks companies and governments in democratic countries to coordinate common safety standards and limits on unchecked progress. The third seeks increasingly ambitious global agreements, beginning with narrow dangerous uses and pre-release testing.
The plan explicitly distinguishes pacing from stopping all model training. Its stated purpose is to buy time for interpretability, alignment, operational security, and more credible verification while retaining potential benefits from AI.
The forecasts are warnings, not measurements
The essay warns that AI-assisted AI development could accelerate capability growth and that future agent swarms could cause vastly greater cyber harm. Those claims come from an informed industry participant, but they are not independently calibrated probabilities or demonstrated timelines.
A useful pacing framework should therefore translate warnings into observable indicators: which cyber abilities, autonomy behaviors, monitoring failures, or training efficiencies change the allowed pace, and who verifies that change.
Test the evaluator before trusting the brake
An embedded evaluator needs access to models, training records, tool-use logs, safety-policy decisions, and relevant incidents. It also needs a protected route to report obstruction or material risk beyond the company paying for access.
Without those conditions, a laboratory can display scrutiny without surrendering control over the evidence. The first public benchmark for the proposal should be the evaluator charter itself.
- Publish the capability thresholds that change development or deployment plans.
- Protect evaluator independence, budget, access, and escalation rights.
- Disclose material incidents and attempts to limit inspection.
- Precommit to consequences when a threshold or safety policy is breached.
Go to the source
Read the evidence behind this analysis. External links open in a new tab.
Frontier AI pacing proposal — We Must Pace the Frontier Pacing the Frontier — Public framework


