Anthropic chief executive Dario Amodei has called on artificial-intelligence developers to slow the rate at which they expand the capabilities of frontier models, pairing that appeal with a concrete promise: outside evaluators will receive enduring, employee-level access to Anthropic systems to inspect whether its safety practices work.
The proposal drew public support on September 12 from OpenAI chief executive Sam Altman, who said his company would adopt the evaluator idea, and from xAI leader Elon Musk, who endorsed Amodei’s position. The alignment is notable in an industry defined by competition for computing power, researchers and customers. It is not, however, a three-company agreement to stop or cap AI development. No shared timetable, technical threshold or enforcement mechanism has been announced.

One implemented proposal, two much harder ambitions
Amodei’s essay, described in reporting by the Guardian, sets out three levels of action. First, individual companies should pace capability gains so their safety work does not lag behind. Second, frontier labs should coordinate their approach. Third, governments should seek international coordination around the most powerful systems.
Only the first layer carries a stated implementation step. Anthropic said third-party evaluators would have permanent access comparable to that of employees. Their remit would include checking the company’s adherence to its own safety measures, reviewing incidents and assessing alignment work during training. In practical terms, the proposal goes beyond inviting an auditor to review a polished report or conduct a short, supervised test. It suggests continuous access to internal development and safety processes.

The details that would determine how meaningful that access becomes have not yet been made public. The reports do not identify the evaluators, say who would select or pay them, describe what information could be withheld for security reasons, or explain whether their findings would be published. Employee-like access can make external assessment more informed, but it does not automatically establish independence, public accountability or a power to halt deployment.
Altman’s response was more specific than a general endorsement. According to the BBC, he agreed that frontier development should be paced, called the embedded-evaluator approach a strong idea and said OpenAI would do the same. Musk’s response was shorter: he said Amodei was right. That leaves three different levels of commitment in the public record: Anthropic’s announced access arrangement, OpenAI’s promise to follow it, and xAI’s expression of support.
What “pacing” does and does not mean
Amodei did not call for an outright freeze on AI research or model training. His argument is that developers should avoid pushing capabilities forward faster than they can understand, test and control the resulting systems. The distinction is important because “slowdown” can obscure the actual policy debate: whether safety evaluations, incident reporting, model-security protections and governance rules should become conditions for moving to a more capable generation of model.
His case rests partly on forecasts about systems that can improve their own performance and operate as autonomous agents over long periods. Amodei warned that such advances could exceed developers’ ability to manage them and described severe cyber risks from more capable but poorly aligned agent systems. Those are risk assessments, not established forecasts. The available reporting does not provide underlying technical documentation for alleged agent-related security episodes, so those episodes should not be treated as independently verified demonstrations of autonomous AI escaping control.
The warning also arrived after public criticism from former Anthropic researcher Jacob Coxon, who argued that Anthropic and OpenAI were pursuing highly advanced systems without adequately managing the risks. The criticism, reported by both the Guardian and the Los Angeles Times, sharpens a recurring problem for the labs: voluntary safety commitments are being made amid pressure from current and former staff who question whether voluntary governance can keep pace with commercial incentives.
Coordination collides with competition policy and geopolitics
Industry-wide pacing is the most consequential part of Amodei’s proposal and the least developed. If rival AI developers collectively agreed to limit capability advances, they would face obvious questions about who is included, what counts as a frontier system and how compliance is measured. They could also encounter antitrust scrutiny: competitors ordinarily cannot jointly decide how fast to develop products or when to introduce them.
Amodei suggested that narrowly tailored US antitrust exemptions could be necessary for certain safety coordination, the Los Angeles Times reported. Such an exemption would itself require lawmakers and regulators to decide what kind of joint action is legitimate safety governance rather than a cartel-like restriction on competition. It would also need safeguards against incumbents using safety language to lock out smaller rivals.
Global coordination is harder still. A US-only pause or threshold regime could shift investment and deployment elsewhere unless other leading AI powers participated. Amodei has pointed to cooperation with China as part of the challenge. Yet AI policy now intersects with export controls on advanced chips, national-security competition and sharply different approaches to state oversight. Those conditions make a globally enforceable limit far more demanding than a corporate pledge.
The immediate test is therefore narrower than the rhetoric surrounding a collective slowdown. Anthropic has committed to an unusually deep form of outside access, and OpenAI says it will match it. Their credibility will depend on operational choices still to come: who gets inside, what they can examine, whether serious findings reach the public and whether the evaluators have a meaningful route to challenge a company that decides to release a more capable model anyway.
