Skip to main content
Live
Main content

How an AI slowdown could actually be enforced, from GPU tracking to treaties

Claude now does 26% of Anthropic's AI research, up from zero in early 2026. Researchers say the tools to slow that curve don't yet exist.

Jaeden Schafer
Editor in Chief · · 5 min read
Anthropic logo

A new research agenda out of the University of Toronto argues that the AI industry has spent years talking about slowing down frontier development without actually building the tools to do it. The report, Pacing the Frontier, A Research Agenda, lands as Anthropic disclosed that Claude now performs 26% of its internal AI research, up from 0% at the beginning of 2026, and that the company spent 6% of its compute budget on safety work. The gap between what labs can measure and what regulators could enforce is the story.

Coauthor Raymond Douglas says the mechanics of a pause remain unsolved. The paper catalogs options that range from third-party audits and interpretability research to cryptographically locked GPUs, embedded off-switches, and a US-China treaty to unwind hardware growth. Most have never been tested at scale.

The urgency comes from the CEOs themselves. Dario Amodei of Anthropic, Sam Altman of OpenAI, Elon Musk of xAI, and Demis Hassabis of Google DeepMind have all in recent weeks endorsed some form of AI slowdown or pause. The fear driving the conversation is recursive self-improvement — AI systems building better AI systems faster than humans can audit them.

Key facts

  • 01[Claude](/claude) now performs 26% of Anthropic's AI research, up from 0% at the beginning of 2026.
  • 02Anthropic said it spent 6% of its compute budget on AI safety work this year.
  • 03A 2023 Biden-era executive order already requires companies to report training runs above a set compute threshold.
  • 04A 2024 RAND proposal would modify existing GPU components to keep a cryptographic record of compute runs for periodic inspection.
  • 05Vals AI's new RSI Index suggests AI could, within the next year, perform research that human AI scientists cannot follow.

The most immediate lever is third-party evaluation. Geoffrey Irving, former chief scientist at the UK AI Security Institute and previously at Google DeepMind, argues that inspections and audits, or even mutual agreements between labs, could hold the line in the near term. He says the labs themselves are afraid of a misaligned takeoff.

Not everyone thinks current audits qualify. Connor Leahy of Control AI, a nonprofit pushing for stricter controls, dismisses the existing evaluator ecosystem as a friends-and-roommates arrangement and argues real inspections should involve agencies like the FBI or NSA. He also rejects the framing that current evaluation methods are scientifically grounded, noting that the field does not yet have a working theory of how alignment actually works.

The second lever is compute. The 2023 Biden-era executive order already requires companies to report training runs above a set compute threshold, and a March 2024 policy white paper argued cloud providers could extend that visibility by tracking billing records, GPU utilization, network traffic, and power draw as proxies for capability. Those signals exist today; nobody is systematically collecting them.

Chip-level enforcement goes further. A 2024 RAND proposal would modify an existing performance-monitoring component on Nvidia GPUs to keep a cryptographically secured log of compute runs, inspectable on a schedule. Other proposals go harder still: tamper-proof usage recorders, cryptographic gating on model weights, and remotely authorized off-switches that would let a regulator or vendor deactivate chips that fall into unauthorized hands. None of this hardware exists in production.

In the medium term, the simplest way is to unwind the hardware growth mutually with China, via a treaty.
Geoffrey Irving, Former chief scientist at the UK AI Security Institute

International coordination is the piece nobody has solved. US export controls on Nvidia's most powerful chips have slowed Chinese labs only partially, since cloud compute abroad remains a workaround. Irving's preferred medium-term answer is a bilateral treaty with China to unwind hardware growth on both sides, a topic likely to come up when President Xi visits the US later this month. Chinese researchers share concerns about the risks of rapid AI progress but are unwilling to accept a pause that locks in a US lead.

Related · from this week
Scientists push back on AI bioweapon doom scenarios
Jaeden Schafer · 5 min read →

Progress tracking itself is becoming its own subfield. Vals AI has launched the RSI Index, a benchmark that measures how well public AI models can reproduce work published by human AI researchers. Cofounder and CEO Rayan Krishnan says the benchmark suggests that within the next year AI could perform work that AI researchers cannot follow — the exact threshold that would make external oversight structurally harder.

The counterweight in the report is that badly designed controls could be worse than none. Douglas warns that rushing enforcement risks regulatory capture or political entrenchment, and that telling the US government to shut everything down without a workable plan could backfire. The critique cuts both directions: labs want to control their own evaluators, and regulators lack the technical grounding to write rules that survive first contact with the technology.

What the Pacing the Frontier report exposes is that the AI slowdown conversation has been running on vibes. The industry's stated fears — recursive self-improvement, misaligned takeoff, agents escaping test containment — have not been matched by investment in the plumbing that would let anyone act on them. Anthropic's 6% safety spend and Claude's 26% research contribution are useful data points precisely because they are numbers; almost nothing else in the enforcement debate is. Until GPU-level attestation, cryptographic training logs, and independent evaluator credentials exist as products rather than white papers, any pause the CEOs endorse will run on the honor system — and honor systems tend to break the moment the RSI curve steepens.

ShareXLinkedInEmail
AI Box

Every AI model. One chat.

The latest models from ChatGPT, Claude, Gemini, Sora, ElevenLabs — 80+ models in a single chat. Compare answers side by side. Pick the best one every time.

  • ChatGPT, Claude, Gemini, Grok, DeepSeek — in one chat
  • Generate images & video with Sora, Veo, Ideogram
  • Compare any two models side by side
  • From $8.99/mo · 80+ models, all included
Try AI Boxaibox.ai
Trusted by 3,000+ teams
Got a tip?

Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.

Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.

AI Box Daily briefingFree · Daily · No fluff

Stay ahead of everyone in AI.

The tightly edited AI news email engineers, founders, and investors actually open. One email. Every weekday. Five minutes to finish.

Loved by 10,000+ AI professionals
Free forever. Unsubscribe with one click.

The briefing read inside teams at

Keep reading

More from Security

Anthropic logo
Security

Scientists push back on AI bioweapon doom scenarios

Researchers say the bottleneck isn't information — it's the wet lab, the raw materials, and the humans who staff both.

Jaeden Schafer5 min read
Anthropic logo
Security

Google's SynthID watermarking can weaken LLM safety guardrails, study finds

Lasso Security tested 6 open-weight models and found watermarking made some more likely to comply with harmful prompts under injection attacks.

Jaeden Schafer5 min read
Anthropic logo
Security

Anthropic accuses Alibaba of 28.8M-query distillation attack on Claude

A letter to the Senate Banking Committee calls it the largest known distillation attack on Anthropic to date.

Jaeden Schafer5 min read