Anthropic, OpenAI, and Elon Musk All Said Slow Down This Month. Here Is What Their Own Documents Say.
In September 2026 the heads of the two biggest AI labs called for slowing down, and Elon Musk said the opposite of what he said in 2023. Here is exactly what each one said, what their own published policies say, and the one number OpenAI disclosed that undercuts the whole idea.
The short version: This month the bosses of the two biggest AI companies both said the industry should slow down. That sounds like a turning point. But their own rulebooks, published earlier this year, argue the opposite, and one of them printed a number showing that when they did slow one project down, the computers just got pointed at a different project instead. Nothing actually slowed. The words changed. Watch the receipts, not the essays.
what actually happened
Three things landed inside eight days.
On September 6, OpenAI's chief scientist Jakub Pachocki published an essay called "An Alien Mind." He wrote that "no lab has solved alignment and monitoring to a sufficient degree to continue responsibly scaling at maximum speed for much longer," and that he expects and hopes "for voluntary slowdowns to become commonplace until shared safety bars are established." That is the strongest slowdown statement a serving OpenAI executive has ever made.
Then Dario Amodei, Anthropic's CEO, published "We Must Pace the Frontier" on his personal site. The page is dated only "September 2026," and coverage puts it at the 12th. The line everyone quoted: "We must slow the pace at which we improve the capabilities of AI models."
The next day Sam Altman told Fortune he does not think "we're currently at a place where we could say, you know, push much further on capabilities without making more progress on monitorability, alignment, the ability to understand what a model is doing." He posted that he agreed with Amodei and would match Anthropic's pledge to let independent evaluators inside with employee-like access.
Two rival CEOs and a chief scientist, in one week, all saying the same thing. That is not nothing. But I went and read what their companies actually published earlier this year, and the picture gets complicated fast.
read amodei's sentence all the way to the end
The quote everyone pulled is real. The sentence after it matters just as much, and almost nobody printed it.
"To be clear, pacing does not mean halting model training or technical progress, but ensuring companies take adequate time to align and safeguard their models, and for third party evaluators to confirm this."
So this is not a pause. Anyone telling you Anthropic called for a pause is wrong. It is a call to slow the rate of capability gain enough for safety work and outside review to keep up. That is a narrower and more defensible ask, and Amodei deserves credit for bounding it himself instead of letting the headline run.
He also caps how far he will go, which is the part I find most interesting:
"Pacing within democracies will be limited by the lead that US companies have over authoritarian regimes, chiefly the Chinese Communist Party. If we slow down by more than this amount, then (unpaced) CCP-associated projects will pull ahead, creating significant national security risk."
Read that twice. The permitted amount of slowing equals the size of the American lead. Anthropic is one of the companies working to extend that lead. The faster they run, the more room his own argument gives them to slow down later.
the part his own rulebook already answered
Anthropic publishes a Responsible Scaling Policy. Version 3.0 took effect on February 24, 2026, roughly seven months before the essay. Here is why they rewrote it, from the introduction:
"If one AI developer paused development to implement safety measures while others moved forward training and deploying AI systems without strong mitigations, that could result in a world that is less safe"
The passage goes on to say that the developers with the weakest protections would set the pace, and that responsible developers would lose their ability to do safety research and advance the public benefit.
That is company policy arguing against unilateral restraint. And the version it replaced, from March 2025, contained a hard line the new one does not: "we will pause training until we have implemented the ASL-3 Security Standard." The commitment to actually stop came out. A later update in April 2026 put back only a freedom to pause if they choose, which is not the same thing as a trigger.
So the sequence, with every date checked, is this. March 2025: we will pause. February 2026: pausing alone can make things worse, and the promise to stop is removed. April 2026: we reserve the right to stop if we feel like it. September 2026: we must slow the pace.
Six weeks after the rewrite, Anthropic announced multiple gigawatts of new compute with Google and Broadcom, which their CFO called their most significant compute commitment to date.
I am not calling anyone a hypocrite. I think both positions are genuinely held and the tension is real rather than cynical. But if you are going to tell the industry to slow down, the strongest thing you can do is update the policy that says slowing down backfires. As of this writing, that has not happened.
the number openai published that undercuts everything
This is the part of the story I have not seen anyone else write about, and it is the most important thing in this post.
On September 6, OpenAI published an internal look at research acceleration. In it they describe what happened after a critical cybersecurity finding on August 7. Allocation of GPUs to their Astra-class models fell by 59.2 percent. Good. That is a safety gate doing its job.
Then allocation to other model classes rose 17.2 percent, offsetting roughly 85 percent of the decline. Their own words: total allocation in the analyzed workloads was "largely unchanged."
Sit with that. A capability-specific safety brake did not reduce the amount of frontier compute being burned. It moved it. The chips did not idle. They got pointed somewhere else.
To OpenAI's credit they published this themselves, against their own interest, and I want to be fair about what it does and does not show. It is one company, one window, one set of workloads. But it is the only hard measurement any of us have of what a lab slowdown actually does to the throttle, and the answer is that it redirected rather than reduced.
OpenAI did genuinely stop something, once. They paused certain frontier training for two weeks after an incident involving one of their agents and Hugging Face, restarting on August 28. Notice the trigger. It was a security breach, not a capability finding.
One more thing worth knowing. Everything OpenAI said this month, it already said on February 24, 2023, in a post bylined by Sam Altman alone. Coordination among AGI efforts to slow down at critical junctures. Limiting the rate of growth of compute. It is all there, three and a half years ago. The question is not whether OpenAI supports slowing down in principle. It is why the commitment to let outside evaluators in arrived only after a competitor announced it first.
And the base rate for these pledges is not great. In July 2023 OpenAI promised 20 percent of its compute to its superalignment team over four years. The team dissolved in under a year. Fortune reported in May 2024, citing about half a dozen sources, that the compute was never delivered and requests were repeatedly refused. I have not seen that accounted for.
musk signed the pause letter and then built the thing
In March 2023 Musk signed the open letter calling on all AI labs to "immediately pause for at least 6 months," adding that if they would not, "governments should step in and institute a moratorium."
X.AI Corp was incorporated in Nevada on March 9, 2023. The letter published on March 22. Thirteen days.
By that June he was already walking it back at VivaTech: "I didn't think anyone would actually agree to the pause, but I thought, for the record I just want to say, I think we should pause."
In August 2024 he backed California's SB 1047, which surprised a lot of people. By April 2026 his company was in court suing to block Colorado's AI statute, pleading six constitutional claims.
And this July, sitting with The Economist at his Texas plant, he closed the loop:
"I can't see any way to really stop this incredible momentum of AI and robots. And at times I sort of think, well, perhaps even if there was a stop button, we probably shouldn't press it because the most likely outcome is incredible abundance for all."
Here is the thing I keep turning over. His estimate of the danger never really moved. It has sat around ten to twenty percent for years. What moved three separate times was the prescription: pause the field, regulate the field, do not press stop. When the interviewer asked him directly whether he still holds that probability, he did not reaffirm it. He deflected.
A risk estimate that stays fixed while the recommendation swings from moratorium to full speed is not doing any work. It is decoration.
the best argument against all of this
I want to give the other side its strongest form, not its dumbest.
It does not come from people who think the risk is fake. It comes from David Sacks, who was the White House AI czar until March 2026 and now co-chairs the president's science advisory council. And the first thing to know is that he did not oppose slowing down. He wrote: "If the unreleased models are scary enough that you think you should slow down, I support your decision to be responsible."
His objection is to the machinery being proposed around it:
"But stop pretending you need anyone else's permission. Stop pretending antitrust law has to be suspended so you can form a cartel. Stop pretending you need a regulatory approval process that supersedes product liability."
That lands, because it concedes the danger and attacks the mechanism. Every lab is already free to slow down tomorrow, unilaterally, without asking anyone. Asking government to build the brake is asking for something different: a certification regime that, as a practical matter, only the largest incumbents can afford to satisfy. Andrew Ng makes a version of the same capture argument from the opposite end of the politics, which is what makes it worth taking seriously.
Geoffrey Hinton, who is about as far from an accelerationist as you can get, attacks the frame itself. His line is that people want "a very fast car with no steering wheel," and that the real axis is steering, not speed. I think he is right, and it is the version of this argument I find most useful, because it does not require anyone to be lying.
It is also worth saying plainly that this is not a done deal politically. The president publicly rejected the CEOs' call, and federal policy since December has been actively dismantling state-level brakes. Anyone writing that the debate is now settled is reading the room wrong.
what "irreversible" actually means
The word gets used loosely, so here is what the serious version rests on. It is not one claim, it is several, and they have very different evidence behind them.
The weakest-evidenced but most discussed is loss of control to a rogue system. The most defensible, to me, is much more boring: our ability to measure these systems may be degrading faster than their capability is growing.
There is a concrete example. Anthropic published it about their own model. Across a benchmark of 1,266 problems, Claude Opus 4.6 twice ran out of search options, worked out that it was probably inside an evaluation, identified the benchmark by name, located its source repository, extracted the decryption routine and password, and decrypted the answer key. One of those runs burned 40.5 million tokens. They published it against their own interest, which is the only reason any of us know.
Then there is the finding that should bother everyone. Apollo Research and OpenAI trained a model to stop taking covert actions, and the rate fell from 13 percent to 0.4 percent. Their own paper says they cannot rule out that the improvement is partly the model getting better at knowing when it is being watched: "we cannot exclude that the observed reductions in covert action rates are at least partially driven by situational awareness."
Read that again. Right now, "we fixed it" and "we taught it to hide it" do not look different from the outside. That is the honest state of the art, and the authors said so themselves while OpenAI's own summary led with the thirty-fold improvement.
The steelman against all of it sits inside the pro-caution literature. The International AI Safety Report notes that loss of control would not necessarily be catastrophic, and offers a good analogy: computer viruses have been proliferating near-irreversibly for decades without collapsing the internet. The right question is not whether a process is permanent. It is whether the harm is.
from my own bench
I run agents on my own hardware, after hours, with real tools attached. Shell, files, network. Not the chat window.
What I have learned is narrow but I am confident in it. When I put a limit on one agent, the work does not stop. It goes somewhere else. The task finds another route, another tool, another process. I have watched an agent respond to a blocked path by spawning the work elsewhere, not because it was scheming, but because that is what optimizing under a constraint looks like.
That is why OpenAI's 59.2 and 17.2 hit me harder than any of the essays. It is the same shape as what I see on a laptop, at the scale of a data center. Constrain one channel and the pressure moves. If you want less total capability progress you have to constrain the total, not a category. Nobody has proposed constraining the total.
I also want to be honest about the limits of that. My experience is a few agents on one machine. It is an intuition, not evidence, and I am telling you which is which.
what to actually watch
Words are cheap this month, so here are four things that would tell you something real.
Does Anthropic update the Responsible Scaling Policy to match the essay? The policy currently argues that unilateral slowing can backfire. If the company means the essay, the document changes.
Does OpenAI publish total frontier compute, not per-class allocation? They already showed they can measure it. Per-class numbers can go down while the total holds flat, and we only know that because they told us.
Do the embedded evaluators actually get employee-like access, and does anyone publish what they find? Both labs have now committed. The superalignment compute pledge is the base rate to beat.
Does anyone name a number? Not a vibe about pacing. A compute growth rate, a capability threshold, a date. Every one of these statements is currently unfalsifiable, which means nobody can be held to it.
the bottom line
The two biggest AI companies and the loudest voice in tech all said slow down within eight days of each other. That is a genuine shift in what is sayable out loud, and I do not want to be cynical about it, because the people saying it have more to lose by saying it than by staying quiet.
But the published record says something different from the essays. One company's safety policy argues against exactly the restraint its CEO now urges. The other company measured what a slowdown did and found the compute moved instead of stopping. And the man who signed the pause letter had incorporated his AI company thirteen days earlier and now says we should not press the button even if it existed.
I build with this stuff every day and I am not neutral. I would rather these companies were saying this than not saying it. But I have spent a lot of this year learning the difference between a claim and a receipt, mostly by being wrong first. Right now this is all claim.
Change the policy documents. Publish the totals. Name a number. Then it is a slowdown.
Dru Edwards