WIRED reported on September 10, 2026, that OpenAI had sought guidance from members of the US Congress on whether it would be legal to slow down frontier AI development in step with competitors. The report, based on sources close to the company, does not indicate that an industry-wide slowdown has been decided. Still, the company has begun publicly calling for shared standards on delaying or halting development. How can firms distinguish an agreement to secure time for safety verification from one that simply restricts competition? A bill submitted to Congress lays out specific conditions meant to answer that question.
The limits of oversight behind the slowdown argument
On September 6, OpenAI's Chief Scientist Jakub Pachocki wrote in the company's official blog post "An Alien Mind" that the company intends to keep advancing safety research while, if necessary, jointly slowing future development. His view is that no research lab has yet solved alignment—getting AI to act in accordance with human intent and values—or the techniques for monitoring AI behavior, well enough to responsibly sustain capability growth at maximum speed for long.
Underlying this is the problem that as capabilities increase, it becomes harder to verify whether those capabilities can be used safely. Pachocki said that, according to the company's own evaluations, the reliability of methods for monitoring a model's verbalized chain of thought has been gradually declining. This is OpenAI's own assessment, not an independently measured result of industry-wide safety. Even so, there is a technical basis for the argument that the pace of development should match the confidence level of safety verification.
On September 9, OpenAI's Chief Global Affairs Officer Chris Lehane announced a policy calling for mandatory federal regulation scaled to capability. The company also said it would work with other labs to establish industry standards and pursue internationally aligned benchmarks for when and how to slow or halt development. This followed the research chief's initial framing with a push from the policy side for institutionalization.
The same document explicitly states that "fully autonomous recursive self-improvement"—in which AI autonomously generates and repeatedly refines successive generations of AI—has not occurred at this point. Having AI speed up parts of research is different from development as a whole slipping out of human hands. The slowdown argument does not leap over that distinction to declare that such a threshold has been reached.
Bloomberg also reported on September 11 that CEO Sam Altman told employees at an all-hands meeting this week that the company might coordinate its development pace with other AI labs, and reportedly mentioned that some labs might not participate. No agreement on a joint slowdown—naming specific participating companies or a timeframe—has been made public.
What the bill would allow, and under what conditions
The US Federal Trade Commission has explained that while cooperation among competitors can sometimes improve efficiency, it can also create antitrust risk if companies stop making independent decisions or gain the ability to jointly exercise market power. Aside from clear violations such as price-fixing, the purpose and effect of cooperation generally need to be examined based on the facts. It would not be accurate to say that all cooperation on safety research is automatically illegal.
However, once companies commit to "slowing development at the same time," their cooperation moves beyond information exchange into competitive decisions about what to develop and when to release it. This is where the "Collaboration on Adversarial Threats and Security Risks Act" comes in—a bill intended to create an exception so that responding to certain AI risks would not constitute an antitrust violation.
Senators Adam Schiff and Jim Banks, among others, introduced the bipartisan bill on July 23. There is a corresponding proposal in the House, and the Senate version carries the bill number S.5105. As of September 12, the latest procedural status shown on Senator Schiff's official website is referral to the Judiciary Committee; it has not been enacted into law.
The announcement foregrounds joint defense against foreign actors stealing AI models or against distillation attacks, in which outputs are harvested to replicate capabilities. However, the risks covered by the text of the bill are broader. They also include actions that would substantially aid weapons development and serious impacts on critical infrastructure. Risks that would significantly undermine humans' ability to monitor, control, or shut down AI are covered as well. Autonomous capability improvement is included too, where it presents a substantial risk of such consequences.
In other words, the bill is not designed to protect any joint restriction simply because capabilities have improved. Companies need to demonstrate a connection to the risks defined in the bill.
| Action / Scenario | Conditions under the Senate bill | Limits of protection |
|---|---|---|
| Sharing information or assistance about risk | Must be done in good faith and solely to address the covered security risk | Recipients need reasonable internal controls to ensure use aligns with the stated purpose and to restrict use for other purposes |
| Joint restriction of AI development, provision, etc. | Must be done solely to reduce the covered risk, with written notice of the specific risk and scope of restriction given before implementation | Covers not only release and use but also development, training, testing, and evaluation; notice does not imply prior approval |
| Antitrust litigation / proceedings | Companies seeking immunity must prove good faith and purpose by a preponderance of the evidence | Simply having filed notice does not by itself secure immunity |
| Injunctive action by the Attorney General | Preserves a mechanism for courts to enjoin conduct that violates antitrust law | If companies fail to meet the burden of proof, among other conditions, there is no immunity from injunction under the bill |
Source: Sections 3 and 4 of the Senate version of S.5105. Contents reflect a proposal that has not been enacted.
Information sharing and joint slowdowns fall under separate provisions, and joint restrictions come with an added requirement of advance notice specifying the particular risk and scope of restriction. The company's burden of proof and the Attorney General's power to seek an injunction both remain intact. For joint deferral or restriction, there is an additional requirement to notify the Assistant Attorney General overseeing the Antitrust Division at the Department of Justice before implementation. The text does not mention obtaining government permission or waiting for such permission. It should be read as a system meant to make companies specify the targeted risk and the measures taken, in a way that can withstand later scrutiny.
Filing notice does not guarantee immunity
The bill's repeated use of the phrase "solely for that purpose" means that any activity serving other purposes must remain non-substantial. It is not a loose standard where it's enough for safety improvement to be merely one among several purposes. At the same time, nothing in the text bans companies from deriving any benefit whatsoever from safety-oriented measures.
For example, an agreement to secure time to verify a model with dangerous capabilities is evaluated differently from an agreement to hold back competitors' new product launches in order to protect market dominance. A name invoking "safety" alone cannot settle that distinction. Under the bill, a company seeking immunity must itself prove good faith and purpose, meaning the actual substance of the agreement will be scrutinized.
Information sharing, too, is not unconditionally severed from competition law. Section 3 explicitly states that the exception for information sharing does not permit price-fixing or market division. Exchanging price or cost information is not among the activities protected by that exception. This proviso, in the text, corresponds to the provision governing information sharing—it should be read separately from the provision on joint slowdowns.
Furthermore, Section 4 spells out cases where having a safety purpose does not exempt conduct from injunction. This applies when a company fails to meet the required burden of proof, and also when the Attorney General demonstrates a reasonable likelihood that the conduct would increase the covered risk overall. The bill separates the purpose of "slowing down for safety" from the assessment of "whether the outcome is actually likely to be safer."
This bears directly on the joint-slowdown debate. A measure that lowers risk for the participating companies but raises overall risk is not necessarily protected. Depending on which companies participate and what safety measures are advanced during the restriction period, the same "slowdown" could have very different effects. The bill does not grant a blanket safety endorsement to the act of slowing down itself.
Turning lawful cooperation into an effective slowdown
Section 3 of the bill exempts notices of joint restrictions and the related information disclosing their contents from disclosure under the Freedom of Information Act. It also limits the purposes for which submitted information can be used to those under Section 4, which governs the Attorney General's ability to seek an injunction. This is a mechanism to protect sensitive information contained in the notice, but the notice alone does not allow third parties to compare each company's actual slowdown status.
Submitting notice to the government and confirming that other companies have actually slowed down are two separate tasks.
Anthropic, in its public document "When AI builds itself," states that it would follow suit if a verifiable mechanism existed for other frontier AI developers to slow down or pause development and confirm compliance with each other. However, it also notes that if a less cautious developer merely catches up during that time, it could lower safety for the world overall. This is a conditional stance, not an announcement that a joint pause has already been agreed to.
One practical difficulty the company points to is that it is easy to conceal the running of training. If leading companies across multiple countries pause under the same conditions without verifying each other's compliance, whichever side secretly continues development gains an advantage. Beyond the conditions for beginning a pause, it is also necessary to define what conditions would lift it and who makes that determination.
OpenAI's inquiry to Congress can be understood as an effort to reduce the legal uncertainty involved in beginning this kind of coordination. However, no response from lawmakers or details of any specific agreement have been made public. S.5105 was submitted before this report came out, and its formal relationship to OpenAI's inquiry has not been clarified either.
What remains to be confirmed in future proposals is the correspondence between what is judged dangerous and which activities are restricted. If that is paired with a method for verifying participating companies' compliance and conditions for resuming development, a joint slowdown could become an option that lets companies secure time to verify safety even while competing.
