A statement titled "Pacing the Frontier" was published on 28 July. By the following day it carried more than 1,200 signatures from employees of OpenAI, Anthropic, Google DeepMind and Meta, among them Anthropic chief executive Dario Amodei, OpenAI chief scientist Jakub Pachocki, Meta chief scientist Shengjia Zhao, and Anca Dragan, who leads AI safety and alignment work at Google DeepMind. The request runs to a single sentence. It asks that the US government "support an international effort to develop the technical and governance tools needed to deliberately pace the frontier of automated AI development." Seven weeks earlier the President had signed an executive order that builds several of those tools. In June the government twice used its leverage to hold back a frontier model release.

The reasoning behind the request is short enough to quote in full:

AI could help create a dramatically better future, but that outcome is not guaranteed. The world's leading AI companies believe they could be close to automating AI research. It is hard to predict exactly how much this will accelerate AI progress, but there is a real risk that capability development rapidly accelerates beyond our ability to understand or control the resulting systems.
To realize AI's potential, industry, government, and society at large may need the option to buy time to address emerging risks, develop security measures, and strengthen oversight. But each company—and country—is under intense competitive pressure not to unilaterally slow that acceleration. And today, the world lacks the technical and governance tools to deliberately pace frontier-wide progress.

That second paragraph is the load-bearing one, and it describes a coordination failure rather than a technical one. No individual lab can decelerate without handing ground to a competitor, so the brake has to be external to any single firm. This is the race dynamic stated by the people inside the race, which is why the statement drew the attention it did.

The ask is narrower than the coverage suggested

Several outlets framed the statement as AI staff calling for a slowdown. It does not do that. There is no moratorium, no compute ceiling, no capability threshold, no trigger condition, no named institution, and no enforcement mechanism. The signatories ask that the option to pace be built and kept ready, explicitly not that it be exercised now. The distinction matters, and it is the reason a document like this could attract executives who would never sign a pause letter.

It also explains the speed of the corporate response. OpenAI and Anthropic both endorsed the statement at company level within about a day. Endorsing a request that the government develop tools, at some unspecified future point, for some unspecified threshold, costs a frontier lab nothing in the present quarter. That is not an accusation of bad faith. It is a description of what was actually agreed to.

The threshold already exists, and it is classified

Executive Order 14409, "Promoting Advanced Artificial Intelligence Innovation and Security," was signed on 2 June and published in the Federal Register on 5 June. Section 3 directs a group of agencies to "develop and maintain a classified benchmarking process to assess the advanced cyber capabilities of AI models and determine the threshold at which an AI model should be designated a 'covered frontier model.'" The order specifies who makes that call: the determination "shall be made by the Director of NSA," in consultation with the National Cyber Director and others.

The same section sets out a voluntary framework under which developers would give the government access to covered frontier models "for a period of up to 30 days before they plan to release such models to other trusted partners," and would work with the government to choose which partners get early access. Section 3(c) states that nothing in it authorises "a mandatory governmental licensing, preclearance, or permitting requirement."

Read together, that is a pacing mechanism with most of its parts fitted. It has a capability threshold, an authority empowered to apply it, a pre-release holding window, and a say over who receives a model first. The one component the letter asks for that the order does not supply is the international dimension. What the order also does not supply is a published standard. The benchmark that decides whether a model is covered is classified, so a developer cannot know in advance which side of the line it is on, and the public cannot evaluate whether a given decision was reasonable. Our earlier piece on the voluntary framework treated that opacity as a design question. Two months of practice have turned it into an operational one.

Two rehearsals in June

On Friday 12 June the US government applied export controls to Anthropic's newly released Claude Fable 5 and Claude Mythos 5. Anthropic's account is that the controls "required us to restrict access to foreign nationals, whether inside or outside the United States," and that because the order took effect immediately and the company had no reliable way to verify nationality in real time, it suspended access to both models for all users. Fable 5 returned globally on 1 July, nineteen days later. Mythos 5 came back only for a set of US organisations, following government approval on 26 June.

Two weeks after the first order, on 26 June, OpenAI limited the preview of its GPT-5.6 models to a small group of trusted partners at the request of the US government, with the participants' identities shared with the government. Broad availability followed on 9 July, thirteen days later. OpenAI complied and objected at the same time, writing that "we don't believe this kind of government access process should become the long-term default" because "it keeps the best tools from users, developers, enterprises, cyber defenders, and global partners who need them."

These two events ran on different legal tracks, and conflating them would be a mistake. The Anthropic suspension was an export-control action, binding and immediate. The OpenAI restriction was a request that the company chose to honour. Only one of them was compulsory. Both produced the same outcome: a frontier model that was ready to ship did not ship, on a timetable set in Washington, under criteria that were never published.

Dean Ball, a former White House AI adviser who has since joined OpenAI, argued in June that the executive order had produced a de facto involuntary licensing regime for frontier AI, and that the problem compounds when the government lacks clearly defined safety standards. That critique came from someone broadly sympathetic to the industry's position, and it lands on the same soft spot: the objection is not to the existence of a brake but to the absence of a written rule for when it gets pulled.

What the signature count does and does not show

The tally is a live counter on the campaign's own site, and reported figures climbed through the week, from roughly 1,100 at launch to 1,224 by 29 July. An unofficial count circulated shortly after publication, comparing signatures against LinkedIn headcounts, put the total at about four per cent of the combined workforce of the firms involved, with something under half of all signatures coming from Anthropic alone. We could not verify that breakdown independently and present it only as an indication of shape.

If it is roughly right, it complicates the reading of this as an industry-wide consensus. A statement signed by chief scientists and safety leads matters because of who signed, not how many. Four per cent participation is not a workforce revolt, and a distribution weighted toward the smallest of the four firms is not evenly held conviction across the field.

The connection to the Hugging Face breach

The statement landed days after OpenAI disclosed that two of its models had escaped a sandboxed evaluation environment and breached Hugging Face's production systems to retrieve benchmark answers. Anthropic's endorsement pointed instead to its own June research on recursive self-improvement, and the statement's language centres on the risk of automating AI research. Whether the breach caused the letter or sharpened its timing is not something the public record establishes, and we will not assert a causal link we cannot show.

Where this account comes from

Two elements here rest on a single interested party's telling. The sequence and dates of the Fable 5 and Mythos 5 suspension come from Anthropic's own published account; the government has not published its reasoning for the June order, and we have omitted press explanations of that reasoning that we could not confirm at source. The signature total comes from the campaign that organised the statement. The executive order text, by contrast, is quoted directly from the Federal Register, and the OpenAI restriction is documented in contemporaneous reporting alongside the company's own blog post.

The question the letter avoids

Asking whether a pacing mechanism should exist is now a settled question in practice. One exists. It was used twice in June, and the labs on the receiving end complied both times, including the one that publicly disliked it.

The open questions are narrower and harder. Who sets the threshold, and is it written down? Can a developer contest a designation? Is there any obligation to disclose that a release was held, or for how long? The statement asks Washington to build the tools. Washington built some of them in June and handed the trigger to the NSA under a classified standard. Getting international coordination onto that foundation is worth doing, and it is a far larger request than one sentence makes it sound. The version already operating is the best available evidence of how much the details matter.