Dario Amodei, chief executive of Anthropic, said on Saturday that the industry must slow the pace at which it improves the capabilities of AI models. He is not calling for a halt: pacing, in his wording, means taking enough time to align and safeguard models and to let third-party evaluators confirm that the work has been done. The proposal matters because it comes from the head of a frontier lab and because it asks governments to change competition rules, not just research practice.

Amodei calls for slower AI model releases, asks Washington for antitrust waiver

What Amodei proposed and what he fears

His stated worry is agents working together. He pointed to the swarm that breached Hugging Face and said that within six to twelve months such a swarm could take over the internet with a persistent botnet, costing hundreds of billions of dollars. That is the concrete scenario behind the call for pacing: not a single stronger model, but many agents acting in concert. The figure he gives for the damage is in the hundreds of billions of dollars, and the window he names is six to twelve months.

Anthropic's own commitment is what Amodei calls embedded evaluators. Outside teams would sit inside the company with desks, badges, company laptops and permissions close to those of internal risk staff, and they would be free to publish what they find. The mechanism is designed so that verification does not depend on the lab's own report: an external team with comparable access can check the claims and make the result public. From governments he wants a waiver, because coordinating on safety between competitors is an antitrust problem; he asks Washington to mediate or narrowly permit those conversations. He also wants an eventual agreement with Beijing. More than a thousand people at AI labs asked for a pacing mechanism in July.

Much of what he describes has been binding on general-purpose models with systemic risk in the EU since 2 August 2025, under the AI Act's systemic risk rules, and his post does not mention Europe once. Article 55 requires documented adversarial testing to standardised protocols, assessment and mitigation of systemic risk at Union level, cybersecurity protection for the model and its physical infrastructure, and reporting of serious incidents to the AI Office without undue delay. Brussels also left those rules alone this summer: the AI Omnibus that took effect on 27 July pushed high-risk deadlines back by up to sixteen months and did not move the general-purpose obligations. Outside evaluation is already running — ENISA has both Anthropic's Mythos 5 and OpenAI's Astra, according to the Commission. Henna Virkkunen, the Commission's tech chief, said this week that EU law requires companies including Anthropic to assess loss-of-control risks, and that the same is not true globally.

What this means for companies that buy or build with AI

For a business choosing models and vendors, the practical consequence is that safety claims will increasingly be checked by parties other than the seller. Embedded evaluators with internal-level access and a right to publish mean that a lab's own assurances become verifiable, and procurement teams can ask for the evaluator's report rather than a summary written by the vendor. For a small company this changes little in daily work, but it gives a cheaper way to compare suppliers: the same external team can be cited across contracts. For a large company with its own risk function, it creates a new counterpart to talk to and a new document to request before a model goes into production.

What the news does not mean is that a common speed limit exists. No European instrument lets competitors agree a common speed limit, and none reaches China, so the coordination Amodei asks for has no legal home in Europe today. The waiver he wants from Washington is a narrow permission for conversations between rivals, not a rule that binds them, and it is a request rather than a decision. When choosing a vendor, the questions worth asking are who performed the external evaluation, what access that team had, whether it can publish without approval, and which incidents must be reported and to whom. The EU obligations apply to general-purpose models with systemic risk, not to every AI product a company uses, so the scope of a supplier's compliance claim needs checking against the model in question.

The marker to watch is whether the antitrust waiver is granted and whether an agreement with Beijing follows, because the first of Amodei's three steps — a voluntary commitment — is already binding in one jurisdiction and his post does not say so. If Washington permits the conversations and a Chinese agreement follows, coordination becomes a workable route for labs; if the waiver stalls, the EU's Article 55 regime remains the only binding version of what he describes, and vendors will keep pointing to it when buyers ask how safety is verified.