The Cartel in the Lab Coat
Dario Amodei did not need to write open weights into his "Pace the Frontier" proposal. When an industry's dominant players gather under an antitrust waiver to set speed limits and mandate third-party evaluations, the exclusion of open-weight development happens naturally without a single line mentioning source code.
The proposal rests on three pillars: mandatory third-party evaluators stationed inside frontier labs, a narrow antitrust waiver allowing American developers to coordinate output and capability checkpoints, and eventually, an international treaty. Elon Musk quote-tweeted agreement within hours. Sam Altman announced OpenAI would match the commitment, calling employee-level access for independent evaluators a sensible step. Anthropic’s policy team was simultaneously in Washington asking regulators to make testing mandatory for every frontier lab—which is to say, every competitor.
Every proposed brake fits Anthropic’s corporate chassis like a bespoke glove. Anthropic builds centralized, hosted models, sells managed access, retains deployment control, and employs deep internal safety teams. Turning those business choices into statutory mandates hands frontier incumbents a regulatory moat. A company that believes it leads loses less from a slowdown than a challenger trying to catch up. When everyone is forced to march at the same reduced speed, the competitive leaderboard freezes in stone, cementing the current hierarchy under the banner of civic responsibility.
Why Certification Checkpoints Squeeze Open Weights
The fatal flaw for open-weight models lies in the certification machinery itself. Amodei’s blueprint imagines evaluations, interpretability analyses, and training environment audits—the exact compliance apparatus Anthropic has spent years building for its own hosted API ecosystem.
You cannot bolt that architecture onto an open-weight release. Once model weights are downloaded to a researcher's laptop, a university cluster, or a foreign startup's servers, ongoing oversight vanishes. There is no API gateway to monitor, no closed loop to inspect, and no third-party evaluator who can sit inside an unhosted deployment.
Certification requires a custodian. By tying lawful operation to continuous third-party supervision of training environments and hosted execution, pacing proposals make unhosted models legally untenable. That is not an oversight in the text; it is the entire mechanism. A regime that defines safety as centralized containment automatically outlaws distributed code. A researcher fine-tuning an open-weight model in a garage cannot satisfy a certification check designed for a thousand-person lab with an embedded audit team.
The Myth of Recursive Self-Improvement Controls
Amodei points to recursive self-improvement—models performing the research that builds subsequent generations, as the ultimate existential hazard. It is a striking warning, especially given that Anthropic already engages in advanced automated research loops.
Yet the timing of a speed limit on recursive self-improvement is awfully convenient. A cap on AI-built AI arrives precisely after well-funded labs have banked their initial algorithmic gains, but right as smaller competitors and open-source communities look to leverage RSI to close the efficiency gap.
When models handle research, competitive advantage stops depending on human research culture and starts depending on brute compute. Google owns specialized silicon. OpenAI commands immense capital. Meta and xAI outspend Anthropic by orders of magnitude. A speed limit on RSI converts Anthropic’s methodical, human-heavy research style from a vulnerability into the legally mandated industry standard. It protects an incumbent's lead by outlawing the shortcuts challengers need most.
Engineering Accountability Over Regulatory Permission Slips
Proponents argue these slowdowns are necessary to prevent catastrophic risks, pointing to export controls and national security. Yet export controls have been federal law for years, and DeepSeek shipped competitive models anyway. One hand waves a water pistol at geopolitical rivals while the other pours concrete over domestic startup ecosystems.
Real risk management does not look like a boardroom cartel or a pre-approval committee. Every other high-stakes engineering discipline, civil architecture, aviation, nuclear power, and structural engineering, manages catastrophic risk through individual professional accountability. Civil engineers sign their bridge designs. If a bridge collapses, the investigation starts with a named person who carries personal liability.
AI engineering currently operates without any such structure. Dangerous containment failures, such as evaluation swarms reaching production systems or autonomous agents probing critical infrastructure, happen inside supposedly secure test environments where nobody's personal license is on the line.
A workable policy framework would abandon pre-approved model monopolies and focus instead on liability and professional conduct where autonomous systems touch live infrastructure, financial networks, or human bodies. Publishing weights remains protected speech. Deploying dangerous agents without adequate containment must carry strict civil and criminal liability.
Congress should keep research and publication legal, deny antitrust immunity for release coordination, and stop incumbent laboratories from drafting the rulebook for their challengers. Amodei’s pacing plan is marketed as saving humanity from runaway machines. In practice, it builds a tollbooth for an oligopoly, starves American open-source AI, and hands global technological leadership to whoever decides not to wait.