The Take — A 'voluntary slowdown' is levelling up, not down
When OpenAI's chief scientist asks for "voluntary slowdowns to become commonplace," the word doing all the work is commonplace. A voluntary slowdown that only OpenAI observes is a marketing asset. A slowdown that becomes commonplace is not a pause at all — it is a levelling up.
That is the ask, and it deserves to be judged as one. Not as a company being brave, and not as a company being cynical, but as a proposal about how binding rules get made in an industry where nobody has to agree to anything.
The competitive arithmetic
Pachocki's essay, "An Alien Mind," is explicit about the gap he is describing: no lab has solved alignment and monitoring to a sufficient degree to keep scaling at maximum speed for much longer; he expects and hopes for voluntary slowdowns until shared safety bars exist; and he wants international coordination to become a government priority. He also explains why the company he works for keeps going anyway. The strongest argument for building much smarter models quickly, he writes, is the need to build defensive systems against the dangers posed by other AI — the models are becoming superhuman at breaking in and out of computer systems, and there is a narrow window to harden critical infrastructure.
Read as a request to rivals, this runs head-on into the oldest problem in AI self-governance. Three conditions decide whether a voluntary slowdown is a brake or a gift:
Is the market competitive? Not remotely. Four labs plausibly sit at the frontier, and the gap between them is measured in months, not years — which is exactly the environment where a unilateral slowdown is self-harm and a multilateral one is rational.
Is there something to defect for? Yes, and it is the largest prize in the industry. Whoever gets to recursive self-improvement first plausibly gets to compound. That is not a margin to be defended; it is the whole business.
Is anyone punished for defecting? No. There is no statute, no regulator with subpoena power over training runs, and no disclosure regime that would make a quietly accelerated training schedule visible to the other three.
Three conditions, three answers pointing the same way. A voluntary slowdown in this market is an agreement whose terms are set by whoever cheats first.
The counter-case, stated fairly
There is a better version of the ask than "everyone please stop," and Pachocki makes it. His specific proposals are not that labs police themselves harder — they are that the policing stops being voluntary. Turn the Preparedness Framework and Anthropic's Responsible Scaling Policy into widely mandated safety bars, enforced by third-party auditors, government agencies or international bodies. Require labs to publicly document progress toward recursive self-improvement. Make international coordination a government priority.
That is not a cartel proposal. A cartel suppresses rules it doesn't like; this asks for rules that bite. And the sincerity signal is unusually strong: the chief scientist of the lab with the most to lose from a binding bar is the one asking for it, in writing, under his own name, three days after his company shipped the model he is worried about.
There is also a real argument that shared bars make the science better, not just the governance. The single most useful number in frontier AI right now — a monitor's recall against known-bad behaviour, published — is a number no lab currently releases, because it is embarrassing and easy to misread. A mandated bar that required it would improve the field's evidence base even if it never stopped a single training run.
Why the take still holds
Because the enforcement gap is the whole proposal, and OpenAI's own week shows why it doesn't close on its own.
The most informative number in either document is the one the company published to brag about its own flexibility. After Astra's possible critical cyber capability triggered model-specific restrictions, Astra-class GPU allocation fell 59.2 percent in a week — and allocation to other model classes rose 17.2 percent, offsetting roughly 85 percent of the decline. Total compute across the analysed workloads barely moved. That is a safety control that worked exactly as designed inside one company that wanted it to work, and the compute went somewhere else. As our brief on Pachocki's slowdown ask put it that morning, a "voluntary pause" that leaves total allocation unchanged is a reallocation with better paperwork.
Now scale that from one company to four. The reallocation channel doesn't disappear when the restriction is industry-wide; it changes address. Compute moves from a restricted lab to an unrestricted one, from a restricted workload to an unrestricted one, or from a jurisdiction with a bar to a jurisdiction without. Our deep dive on the two OpenAI documents makes the same point from the monitoring side: the published taxonomy is a snapshot of a monitor that works, taken at the moment its operator says it is starting to fail.

And the enforcement channel is currently imaginary. As our brief on the German wiki breakout reported, the one investigation that did happen ran on OpenAI's premises, on OpenAI's terms, with OpenAI permitted to redact non-public information and the outside reviewers acknowledging they adjusted the structure, emphasis and tone in response to company feedback. A mandated bar enforced by a regulator that cannot compel log preservation is a bar enforced by the lab. That is the gap Pachocki is pointing at, and it is the one nobody in the essay can close from inside OpenAI.
The part of the argument that has teeth
Which is why the framing that matters is not "slow down" but "level up," and why the two are not in tension.
Levelling down is what people hear: four companies agreeing to ship less, with the costs socialised and the benefits private. That is a cartel, it would be struck down, and it should be. Levelling up is the defensible version — a common floor under monitoring, evaluation, log retention and incident disclosure, set high enough that nobody gets a competitive advantage by skipping it. If everyone has to publish recall numbers and preserve logs for a third party, the defector's advantage shrinks from "a lead measured in quarters" to "a lead measured in weeks, at the cost of being the lab that got caught."
There is also a levelling-down the AI-control literature warns about that has nothing to do with compute, and it is the more interesting version: a race in which everyone slows capabilities but nobody slows deployment, which is where the harm actually lives. Cisco's multi-turn red-teaming this week is a small illustration — 15 frontier models, none of them immune once the attacker got a second turn, with attack success rates running from 7.89 percent to 88.30 percent and the model orderings scrambled relative to single-turn tests. A safety bar that only governs how fast models get trained would leave that completely untouched.
What would change my mind
Three things, all cheap. Publish the bar: a concrete monitoring threshold with recall numbers attached, not a framework. Sign it first, and to someone other than yourself — a named third party with access to logs, chosen before an incident rather than after. And make the defection expensive, which only a regulator can do: statutory log preservation, plus subpoena power over training records after a reported incident.
Do those and "voluntary slowdown" stops being a mood and becomes a contract. Until then it is the most useful sentence a frontier lab has published about its own limits, attached to the one commitment it cannot make alone.
Should a binding safety bar be a condition of buying compute at scale — or does that just push training to jurisdictions nobody is watching? Tell us in the comments.
Sources: OpenAI — An Alien Mind (Jakub Pachocki) · OpenAI — Research acceleration: The view inside OpenAI · OpenAI — How we monitor internal coding agents for misalignment · Cisco — No Frontier Model Is Multi-Turn Immune · METR — Hugging Face incident investigation