top of page
banner for general post.png

Stop Studying International Law from Outdated Summaries

Get six up-to-date 2026 study guides covering the core fields of international law—combining leading cases, clear legal analysis, worked examples and revision tools.

Anthropic AI Warning: Can International Law Slow the AI Race?

10 hours ago
24 min read

Introduction


The Anthropic AI warning issued by CEO Dario Amodei in September 2026 has turned a familiar safety debate into a question of international governance. Amodei argues that frontier developers should slow the rate at which model capabilities advance so that evaluation, alignment, and other safeguards can keep pace. His proposal does not call for a permanent halt to model training or technical progress. It combines embedded third-party evaluators, coordination among frontier companies in democratic states, and eventual international cooperation (Amodei, 2026). No general binding international regime currently requires states or developers to observe such a global pace limit.


Existing international initiatives address parts of the problem without regulating the speed of frontier AI development. The Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law sets out treaty rules concerning human rights, democracy, the rule of law, transparency, oversight, and risk assessment, but it had not yet entered into force as of September 2026 (Council of Europe, 2024; Council of Europe, 2026). At the United Nations, General Assembly Resolution 79/325 established the Independent International Scientific Panel on Artificial Intelligence and the Global Dialogue on Artificial Intelligence Governance in August 2025 (United Nations General Assembly, 2025). These mechanisms support scientific assessment and international discussion rather than imposing ceilings on capability growth, training compute, or the pace of model development.


Voluntary restraint by individual companies presents a different problem. Amodei argues that a developer that slows while competitors continue advancing may surrender commercial or strategic advantages, making coordinated action more attractive than unilateral restraint (Amodei, 2026). The difficulty increases when frontier development occurs across competing states. Advanced models, computing infrastructure, semiconductors, model weights, and related capabilities have acquired economic and national-security significance, while governments may be unwilling to accept restrictions that leave competitors free to advance.


International law could provide a framework for reciprocal restraint if states chose to create one. States may conclude bilateral, plurilateral, or multilateral agreements that limit specified conduct, require information sharing or verification, and oblige parties to adopt domestic measures governing activities within their jurisdiction. Under the law of treaties, obligations contained in a treaty in force bind the parties and must be performed in good faith (Vienna Convention on the Law of Treaties, 1969, art. 26). A future AI pacing agreement could consequently require participating states to regulate frontier developers through licensing, evaluation, reporting, or other domestic controls.


The harder legal question concerns the object of regulation. “Slowing AI” has no established meaning in international law, and a treaty could not rely on that phrase alone as a workable standard. Amodei identifies several possible reference points, including model capabilities, training compute, the characteristics of training runs, and the use of advanced systems to accelerate the development of successor models (Amodei, 2026). Any binding regime would need sufficiently precise criteria to determine when a regulated threshold had been crossed and whether a state was complying with its obligations.


Verification would be central to such a system. Amodei treats embedded third-party evaluators as a foundation for credible pacing because commitments have little value if compliance cannot be observed (Amodei, 2026). At the international level, the problem would extend beyond access to individual laboratories. Monitoring could involve information about large training runs, advanced computing resources, data-center access, model evaluations, and safeguards against unauthorized acquisition of model weights. The legal design would also have to address confidentiality, commercial secrecy, national security, inspection rights, and procedures for resolving disputes over alleged non-compliance.


The central question is not whether international law can regulate AI in the abstract, but whether states could create a reciprocal and verifiable regime capable of restraining the development of the most advanced systems. No general international treaty currently establishes such a system. Any future arrangement would need to define the regulated conduct, establish credible means of verification, and determine the consequences of a state's breach. Private developers would ordinarily be controlled through the domestic measures adopted by participating states unless an agreement created a different mechanism. Amodei's proposal places these institutional problems at the center of the emerging debate over whether international law can meaningfully slow an AI race that individual companies cannot control on their own.


1. What the Anthropic AI Warning Asks Governments to Do


Dario Amodei's September 2026 proposal is more specific than a general call for governments to slow artificial intelligence. He describes a sequence beginning with embedded third-party evaluators inside frontier laboratories, followed by coordination among leading developers in democratic states and, eventually, international coordination involving governments outside that group. The first stage can be adopted voluntarily by individual companies. The later stages depend increasingly on public authority and reciprocal commitments (Amodei, 2026).


Embedded evaluators would receive continuing access comparable to personnel performing related safety functions inside the developer. Their task would extend beyond testing a finished model. Amodei envisages outside teams able to examine training processes, safeguards, incidents, evaluations, and other practices relevant to whether a company is complying with its own stated commitments. Anthropic has presented this form of external scrutiny as something it can adopt independently while encouraging comparable arrangements elsewhere (Amodei, 2026).


The second stage moves from company-specific commitments to coordination among frontier developers operating in democratic states. Amodei argues that unilateral pacing becomes difficult when competitors can continue increasing capabilities without equivalent restraints. Common standards could reduce that pressure, particularly where companies agree on capability checkpoints, evaluation requirements, and conditions for proceeding with more advanced systems. In the United States, however, coordination among competing companies can raise antitrust concerns, which is one reason Amodei contemplates government involvement in structuring any collective safety arrangement (Amodei, 2026).


The international stage is more demanding. Amodei places particular emphasis on relations between the United States and China because meaningful pacing would be difficult if developers subject to one state's restraints believed that competitors elsewhere could continue advancing without comparable limits. His proposal does not assume that a comprehensive worldwide agreement could be negotiated immediately. Instead, he describes several possible levels of cooperation, with stronger limits becoming dependent on stronger verification and greater confidence that other participants are complying (Amodei, 2026).


“Pacing” is not, in its basic form, a moratorium on training or a permanent freeze on technological development. Amodei expressly distinguishes his proposal from stopping technical progress. The central idea is that increases in model capability should not outrun the safeguards needed to address the risks created by those increases. Capability thresholds could trigger stronger evaluations, interpretability requirements, security measures, or other conditions before development proceeds further. The voluntary Frontier AI Safety Commitments adopted at the 2024 Seoul Summit use a related threshold-based logic by linking severe-risk thresholds to mitigation and, where adequate mitigation is unavailable, possible decisions not to develop or deploy a model (UK Government, 2024a).


This distinction does not mean that Amodei excludes every form of pause. His discussion of possible global agreements includes, at the most demanding end of the spectrum, arrangements that could impose much stronger temporary restraints on frontier development. Those possibilities are separate from his baseline definition of pacing, which allows training and technical progress to continue under more stringent safety conditions (Amodei, 2026).


Verification appears at the beginning of the framework because a pacing commitment cannot be assessed from public assurances alone. External evaluators would need sufficient access to determine how models are trained, how risks are assessed, which safeguards are operating, and whether agreed thresholds have been crossed. Once reciprocal restraint depends on information that companies cannot be compelled to disclose voluntarily, the limits of corporate governance become evident. Anthropic can change its own conduct; it cannot impose equivalent obligations on competitors or foreign developers. At that point, pacing becomes a problem of domestic regulation and international coordination.


2. International AI Law Has No Global Speed Limit


Existing international AI instruments address safety, transparency, evaluation, human rights, and cooperation, but none currently establishes a general binding limit on the rate at which frontier-model capabilities may advance. The current framework is legally diverse. It includes political declarations, non-binding intergovernmental recommendations, United Nations institutional arrangements, and a treaty that has been opened for signature but has not yet entered into force.


The Bletchley Declaration, adopted at the 2023 AI Safety Summit, illustrates the political layer of this framework. Participating governments, including the United States, China, European states, and the European Union, acknowledged potentially serious risks associated with frontier AI and endorsed cooperation on safety testing, transparency, evaluation, scientific research, and risk-based policy. The Declaration is not a treaty and does not impose legally binding obligations to limit model training or capability growth (UK Government, 2023).


The United Nations Global Digital Compact, adopted in September 2024 as Annex I to the Pact for the Future, expanded the international governance agenda. It calls for cooperation on AI governance, scientific understanding of risks, interoperability between governance approaches, transparency, accountability, and broader participation in international decision-making. These commitments form part of a General Assembly framework rather than a treaty establishing enforceable ceilings on frontier development (United Nations General Assembly, 2024).


General Assembly Resolution 79/325 subsequently established the Independent International Scientific Panel on Artificial Intelligence and the Global Dialogue on Artificial Intelligence Governance in August 2025. The Panel is intended to strengthen scientific understanding of AI opportunities, risks, and impacts, while the Dialogue provides an intergovernmental and multistakeholder forum for discussing governance. The inaugural session of the Dialogue was held in Geneva in July 2026. Neither institution is empowered to license training runs, impose capability limits, or enforce a slowdown in frontier development (United Nations General Assembly, 2025).


The OECD AI Principles occupy another legal category. Adopted through the OECD Council Recommendation on Artificial Intelligence in 2019 and revised in 2024, they address trustworthy AI, human rights, transparency, accountability, risk management, research, infrastructure, and international cooperation. OECD Recommendations are not legally binding. Their significance lies in coordinated policy expectations and guidance rather than treaty obligations enforceable against adherents (OECD, 2024).


The Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law is different because it uses treaty form. Opened for signature on 5 September 2024, the Convention contains provisions addressing human rights, democracy, the rule of law, transparency, accountability, remedies, procedural safeguards, and risk and impact management. Article 16 provides that Parties are to adopt measures for identifying, assessing, preventing, and mitigating relevant risks and to consider whether particular uses require moratoria, prohibitions, or other measures where they are considered incompatible with human rights, democracy, or the rule of law (Council of Europe, 2024).


Those provisions are not yet operative as treaty obligations under a Convention in force. As of the Council of Europe Treaty Office status updated on 12 September 2026, the instrument had not reached the threshold required for entry into force. The European Union had approved the Convention, but entry into force requires five ratifications, including at least three by Council of Europe member states (Council of Europe, 2026).


Even after entry into force, the Convention would regulate a different problem from the one raised by AI pacing. Article 16 addresses risks and impacts associated with AI systems and particular uses considered incompatible with protected legal interests. It does not establish a general ceiling on training compute, model capability, recursive self-improvement, or the speed at which frontier systems may advance. The Convention demonstrates that AI-related obligations can be placed in treaty form, but it should not be treated as an embryonic international development cap.


International practice has nonetheless created institutional elements that could matter to a future pacing regime. Bletchley established political agreement around frontier risk and testing; the OECD provides shared governance principles; the UN has created scientific and diplomatic forums; and the Council of Europe has negotiated treaty rules governing AI-related risks and impacts. What remains absent is a binding international rule linking continued frontier development to an agreed capability threshold, compute ceiling, development rate, or comparable pacing criterion.


3. A Binding AI Pacing Agreement Is Legally Possible


General treaty law does not prevent states from negotiating an agreement that restricts specified forms of AI development. Article 6 of the Vienna Convention on the Law of Treaties recognizes that every state possesses capacity to conclude treaties. Article 26 provides that every treaty in force is binding upon its parties and must be performed in good faith (Vienna Convention on the Law of Treaties, 1969, arts 6 and 26). States could accordingly accept obligations governing defined frontier-AI activities, subject to reporting, evaluation, inspection, licensing, or other compliance requirements.


The international obligations would ordinarily bind the participating states rather than Anthropic, OpenAI, or other private companies as treaty parties. Under the ordinary inter-state treaty model reflected in the Vienna Convention, governments undertake the international obligations and then implement them through their domestic legal systems. A pacing agreement could require legislation, licensing systems, regulatory supervision, reporting duties, administrative sanctions, or other measures capable of controlling developers within the participating state's jurisdiction.


International law already uses this structure in fields where important regulated activity is conducted by private actors. Article VII of the Chemical Weapons Convention requires each state party to adopt national measures prohibiting conduct contrary to the Convention and expressly addresses natural and legal persons within its territory or other places under its jurisdiction. It also requires each state party to designate or establish a National Authority responsible for implementation (Chemical Weapons Convention, 1993, art. VII). The analogy concerns regulatory structure rather than substantive equivalence between chemical weapons and frontier AI.


An AI agreement would require careful rules connecting international commitments to domestic enforcement. A state could promise to prevent certain training activities above a defined threshold, but that obligation would have limited practical value if national authorities lacked powers to obtain information, inspect regulated facilities, supervise cloud providers, or impose consequences for non-compliance. Multinational corporate structures and cross-border computing services could create additional difficulties where more than one jurisdiction is involved.


Universal participation would not be necessary for a treaty to create binding obligations among its parties. A plurilateral agreement could begin with a smaller group of states and specify common restrictions, verification procedures, and implementation duties. Its practical effect would depend on which states participated, what frontier laboratories and infrastructure fell within their jurisdiction, and how effectively their domestic measures reached relevant conduct.


Non-party states would not become bound by the treaty merely because participating states considered a global slowdown desirable. Private companies based outside participating states would likewise not become treaty parties. They could still be affected by lawful domestic measures adopted by participating states, including rules governing exports, cloud services, corporate operations, licensing, or market access where an appropriate jurisdictional basis exists. The central legal problem is thus not whether an AI pacing treaty is possible, but how far its obligations could reach without broad participation and effective domestic implementation.


4. Verification Is the Hardest Part of an AI Treaty


A treaty stating only that parties shall “slow AI development” would provide little basis for deciding whether an obligation had been fulfilled. The phrase does not identify the regulated activity, the permitted rate of advancement, or the evidence required to establish compliance. A pacing regime would need measurable legal triggers tied to conduct or capabilities that states and evaluators could observe with sufficient confidence.


Capability thresholds offer one possible approach. Amodei proposes checkpoints at which the acquisition of specified capabilities would trigger additional safety requirements before development continued. A capability-based rule has the advantage of focusing on what a system can actually do rather than assuming that a particular technical input necessarily produces a particular level of risk. The Seoul Frontier AI Safety Commitments similarly use severe-risk thresholds and evaluations as part of company risk-management frameworks (Amodei, 2026; UK Government, 2024a).


Capabilities, however, are not measured in the same way as physical quantities. Results can vary according to benchmark design, access conditions, available tools, prompting, model configuration, and the environment in which a system operates. NIST has documented advanced agents exploiting weaknesses in evaluation tasks, including forms of grader gaming and contamination that can distort apparent performance. Such problems make it difficult to treat a single benchmark score as conclusive evidence of a model's full capabilities (NIST, 2026).


Training compute offers a more input-oriented criterion. Large training runs require substantial computational resources, and official frontier-safety work has considered disclosure of planned compute, training location, and relevant providers as possible elements of pre-training oversight (UK Government, 2024b). Compute thresholds could support notification, licensing, or reporting requirements without requiring regulators to determine every capability of a system in advance.


Compute is not a complete proxy for capability. Model performance can also change through improvements in algorithms, data, post-training methods, architecture, and hardware efficiency. Official assessments of frontier-AI development distinguish compute from these other drivers and caution against assuming that scale alone permits reliable prediction of specific capabilities (UK Government, 2024c). A fixed compute threshold could consequently become less informative as technical methods change.


Recursive self-improvement raises another set of difficulties. Amodei uses the concept to describe the increasing ability of advanced systems to assist in the development of subsequent AI systems. A regulatory provision would need to distinguish routine coding support from forms of AI-assisted research capable of materially accelerating frontier development. The relevant legal trigger might depend on measurable contribution to research productivity, autonomous experimentation, model design, or training optimization rather than the mere use of AI within a laboratory (Amodei, 2026).


Deployment thresholds and mandatory safety evaluations could provide a different form of control. The Seoul commitments contemplate assessments before deployment and, where appropriate, during development, linked to predefined levels of severe risk. An international agreement could require participating states to impose comparable evaluation duties through domestic law. The harder questions would concern who designs the tests, which bodies may conduct them, what evidence developers must provide, and what legal consequence follows when a threshold is exceeded (UK Government, 2024a).


Advanced computing infrastructure could add a more observable layer to the regime. Large training operations depend on chips, cloud services, and data-center capacity that can be subject to record-keeping, licensing, provider obligations, or other forms of regulatory control. Infrastructure monitoring would not reveal every relevant model capability, but it could provide additional evidence about unusually large training activity and help identify conduct that warrants closer scrutiny.


Amodei's embedded evaluators could form one component of such a verification system. A treaty regime would need more detailed rules than a voluntary corporate arrangement. It would have to define evaluator qualifications and independence, the records and systems to which access is permitted, confidentiality protections, reporting obligations, inspection procedures, and circumstances in which access may lawfully be restricted.


Existing treaty regimes demonstrate that intrusive verification and confidentiality protections can coexist, although their designs cannot simply be transferred to AI. The Chemical Weapons Convention combines national implementation obligations, international verification machinery, a Technical Secretariat, inspection procedures, and detailed confidentiality rules (Chemical Weapons Convention, 1993, art. VII, Verification Annex and Confidentiality Annex). Frontier AI would require a different institutional balance because software, model weights, training methods, and rapidly changing computing processes raise distinct commercial and security concerns.


Compliance disputes would remain foreseeable. A state could contest whether a model had crossed an agreed capability threshold, challenge the methodology used by an evaluator, or resist access to information on security or commercial grounds. A workable agreement would need procedures for clarification, technical review, inspections where appropriate, reporting, and dispute settlement so that disagreement did not depend entirely on unilateral political accusations.


Verification is consequently part of the substantive design of an AI pacing obligation. Capability thresholds, compute limits, mandatory evaluations, infrastructure controls, and evaluator access do not merely determine how a treaty would be enforced; they determine what conduct the treaty regulates. Without sufficiently observable criteria, reciprocal restraint would be difficult to sustain even if participating states agreed in principle that frontier development should proceed more slowly.


5. Why the Nuclear Arms Analogy Only Goes So Far


Amodei expressly invokes Cold War arms control when considering how states might constrain recursive AI development. One comparison is with the Strategic Arms Limitation Talks, which showed that geopolitical rivals can accept reciprocal restrictions on strategically important technology without agreeing to eliminate that technology altogether. The 1972 SALT I Interim Agreement restricted specified categories of strategic offensive arms and relied on national technical means to provide assurance of compliance (Interim Agreement on Strategic Offensive Arms, 1972, art. V; Amodei, 2026).


Verification was built into the legal structure. Each party undertook not to interfere with the other's national technical means and not to employ deliberate concealment measures that would impede verification. SALT II later sought broader numerical limitations on strategic nuclear forces, although the 1979 treaty was never ratified by the United States and never entered into force. Its negotiation still illustrates how ceilings, definitions, verification methods, and strategic reciprocity become intertwined when states attempt to restrain a technological competition.


Nuclear verification itself has never been straightforward. SALT negotiations produced disputes over which systems counted, how particular capabilities should be classified, and whether national technical means were sufficient to establish compliance. The comparison with AI is consequently relative rather than absolute. Arms-control verification can be difficult even where the regulated activity has a substantial physical component.


IAEA safeguards provide a different example. Their techniques include nuclear-material accountancy, inspections, design-information verification, seals, surveillance, environmental sampling, and related verification measures (IAEA, 2022). Nuclear material and fixed facilities can often be subjected to forms of measurement and physical inspection that provide persistent evidence about relevant activities. Those techniques do not mean that nuclear warheads or all military nuclear activities are easily verifiable, nor does the IAEA safeguards system regulate strategic arsenals in the manner of SALT.


Frontier AI combines physical and digital elements in a different way. Large-scale development depends on processors, data centers, energy, networking equipment, software, algorithms, model weights, data, and technical expertise. Some of these inputs, especially large computing facilities and hardware supply chains, may leave observable physical or commercial traces. Others can change rapidly without construction of a new facility or deployment of a new weapons platform. Software can be modified, algorithms can improve efficiency, and model weights can be transmitted digitally.


The nuclear analogy is consequently most useful for institutional design. SALT demonstrates that rivals can negotiate reciprocal limits, define verification rights, prohibit interference with monitoring, and maintain procedures for continuing consultation. IAEA safeguards show how reporting and external verification can become permanent institutional functions. Neither system provides a ready-made model for frontier AI. Any AI regime would require verification methods designed around computing infrastructure, training activity, model evaluation, digital assets, and the commercial and security sensitivities particular to those technologies.


6. The U.S.-China Problem Defines the Limits of Global Pacing


Amodei places relations between the United States and China near the center of his global pacing proposal. His concern is that unilateral restraint becomes difficult to sustain when a government or developer believes that a strategic competitor can continue increasing capabilities without equivalent limits. In his framework, stronger forms of pacing consequently require stronger confidence that other participants are subject to comparable obligations and are actually complying with them (Amodei, 2026).


The Bletchley Declaration shows that common U.S.-China language on frontier-AI risk is possible. Both states participated in the 2023 process, which recognized potentially serious risks associated with frontier systems and endorsed international cooperation on safety research, testing, evaluation, transparency, and risk management (UK Government, 2023). The Declaration demonstrates agreement on the existence of certain shared concerns without requiring agreement on detailed restrictions on technological development.


That distinction is important. Bletchley did not oblige either government to slow training, disclose sensitive development programs, permit inspections, or accept numerical ceilings on model capability. Recognition of common risks places fewer demands on sovereignty and national security than a regime granting external actors access to strategically sensitive computing infrastructure, evaluations, or development records.


Reciprocity becomes harder to establish as restrictions reach activities connected to military, cybersecurity, economic, or broader national-security capabilities. Amodei's argument is that a state asked to accept significant constraints will be concerned about whether competitors face comparable restrictions (Amodei, 2026). International law can express reciprocal duties once states consent to them, but it cannot by itself eliminate the strategic uncertainty that produces demand for verification.


Different obligations would generate different levels of intrusion. A prohibition on a narrowly defined harmful capability or use could focus on specified conduct. Common evaluation procedures could require states to apply agreed tests without limiting the total rate of technological progress. Notification and transparency requirements could reveal selected information while preserving substantial freedom to continue research and development.


A general capability ceiling would demand more. States would need an agreed method for identifying the regulated capability, evidence capable of demonstrating that the threshold had been crossed, and procedures for addressing disputed evaluations. If the limit also applied during training rather than only at deployment, verification might require access to information that governments or companies consider commercially sensitive or security-relevant.


Transparency and reciprocal evaluation can consequently perform a different function from a development ceiling. They may reduce uncertainty about how commitments are interpreted and implemented without requiring states to accept the full verification burden associated with a broad pause. Stronger quantitative or capability restrictions would require a correspondingly stronger institutional basis for establishing compliance.


International law can organize that reciprocity through definitions, reporting obligations, inspection rights, review procedures, and mechanisms for resolving disputes. The limiting factor is not the formal capacity of the United States and China to enter an agreement. It is the degree of restraint and verification each government is prepared to accept where compliance may affect technologies viewed as strategically important.


7. Export Controls Cannot Substitute for an AI Treaty


Export controls already affect important physical inputs used in frontier AI development. The United States Export Administration Regulations contain licensing requirements covering specified advanced computing items and semiconductor-manufacturing equipment, including controls relevant to transactions involving certain destinations and entities. BIS confirmed in 2026 that significant pre-existing licensing requirements for advanced computing items remained enforceable despite subsequent changes in U.S. AI export-control policy (BIS, 2026).


Advanced processors matter because very large training runs depend on substantial computing capacity. Semiconductor-manufacturing equipment affects the ability to produce advanced chips, while regulation of cloud and data-center transactions can affect access to computing resources without requiring the developer to own the underlying hardware. These controls allow governments to influence some of the material conditions under which frontier models are developed.


The status of U.S. controls adopted specifically under the 2025 Framework for Artificial Intelligence Diffusion requires separate treatment. That rule introduced a wider system involving advanced computing items, data-center authorizations, compliance obligations, and controls relating to certain advanced AI model weights. In May 2025, however, BIS announced that it would not enforce the AI Diffusion Rule and had initiated its rescission while preparing a replacement approach (BIS, 2025).


The legal position remained unusual in 2026. The U.S. Government Accountability Office confirmed that the AI Diffusion Rule remained in the Code of Federal Regulations because the rescission process had not been completed, while Commerce was operating under a generally applicable policy of non-enforcement. The codified requirements and their practical enforcement status must consequently be distinguished. The non-enforcement policy effectively suspended the licensing, reporting, compliance, and license-exception requirements created by that rule, while other advanced-computing controls predating it continued to operate (GAO, 2026; BIS, 2026).


Even enforceable export controls are not equivalent to an international pacing agreement. The Export Administration Regulations are domestic U.S. law. Other governments can adopt parallel restrictions or coordinate policies, but aligned national measures do not become treaty obligations merely because several states pursue similar objectives. Their reach depends on domestic jurisdiction, licensing rules, supply chains, regulated transactions, and each government's national-security and trade policy.


Export controls also operate more directly on access to inputs than on the rate at which capabilities improve. Restricting advanced processors may make exceptionally large compute clusters harder or more costly to assemble, but it does not establish a legal rule limiting model capability to a specified rate of advancement. Algorithmic improvement, more efficient training, existing infrastructure, and other technical changes weaken any simple equivalence between control of hardware and control of capability growth.


These mechanisms could still support a treaty regime. Domestic licensing and reporting systems might implement international obligations concerning specified hardware, infrastructure, or transfers. Information generated through export-control compliance could also contribute to verification where an agreement expressly authorized such use. Their legal function would then derive partly from domestic law and partly from the international obligations that states had undertaken.


Private coordination raises a different issue. Section 1 of the Sherman Act prohibits certain agreements in restraint of interstate or foreign commerce, and collaboration among competitors can require fact-specific antitrust analysis even where the participants claim a public-interest objective (15 U.S.C. § 1). U.S. enforcement agencies recognize that competitor collaborations can be lawful or procompetitive, but they also remain subject to antitrust constraints depending on their purpose and effects.


Amodei acknowledges this difficulty when discussing coordinated pacing among frontier laboratories and proposes government mediation or a narrow form of legal authorization for specified safety discussions (Amodei, 2026). International coordination among states and coordination among private competitors are thus legally distinct. The former concerns international obligations undertaken through public authority; the latter remains subject to the domestic competition law governing the participating firms.


8. What a Realistic International Agreement Could Require


An initial international pacing regime would not necessarily require states to negotiate an indefinite freeze on frontier development. A treaty could instead attach legal consequences to observable thresholds and specified activities. The central drafting task would be to replace an open-ended demand to “slow AI” with duties that regulators, developers, and international evaluators could identify in advance.


Capability thresholds could provide one trigger. Participating states might agree that systems demonstrating specified high-risk capabilities require additional evaluation or mitigation before further development or deployment. The voluntary Frontier AI Safety Commitments adopted at the Seoul Summit already use risk thresholds linked to model capabilities and require participating companies to specify the steps they would take if those thresholds were reached. In extreme circumstances, the commitments contemplate not developing or deploying a system where severe risks cannot be kept below the defined threshold (UK Government, 2024a).


A treaty could turn part of that logic into state obligations. Parties could be required to establish domestic rules ensuring that frontier developers conduct independent evaluations at specified stages and provide accredited evaluators with access to defined models, records, testing environments, or safety procedures. The agreement would have to determine who may perform those evaluations and how conflicts of interest, evaluator independence, and sensitive information are handled.


Notification of exceptionally large training runs could create another checkpoint. Official UK frontier-safety work has considered pre-training disclosure of information such as planned compute, the location of training, and relevant infrastructure providers (UK Government, 2023a). An international agreement could require participating states to establish notification systems for training activity above a defined threshold without treating every AI development project as internationally reportable.


Incident reporting could operate alongside training notification. Developers might be required under domestic implementing law to report specified serious incidents to national authorities, with international disclosure triggered only where treaty criteria are met. Minimum security obligations could address access controls, cybersecurity, protection of sensitive model weights, and other safeguards connected to risks expressly covered by the agreement.


Restrictions on particular capabilities would require especially precise drafting. Expressions such as “dangerous AI” or “existential risk” are not sufficiently determinate by themselves to define a treaty breach. A binding prohibition would need criteria capable of identifying the relevant capability or conduct, agreed testing procedures, and mechanisms for revising the technical standard when scientific understanding changes.


Verification rules would have to accompany those substantive obligations. A treaty could begin with requests for clarification, documentary reporting, or technical consultation and permit more intrusive access only under defined conditions. Accredited evaluators or an international technical body might be authorized to examine specified evidence where there is a credible question about compliance. Confidentiality protections would be necessary where verification exposes trade secrets, cybersecurity-sensitive information, or national-security material.


Domestic implementation would determine whether those international rules reached private laboratories in practice. States could be required to designate competent authorities, establish licensing or notification procedures, obtain specified information from regulated developers, and create proportionate consequences for violations of national implementing law. International standards could define minimum outcomes while allowing each party to choose institutions compatible with its own legal system.


Narrowly defined obligations generally create clearer compliance questions than a general commitment to reduce the pace of technological progress. A notification requirement can be assessed against whether notification occurred. An evaluation requirement can specify the tests, documentation, and timing expected. A prohibition tied to an agreed capability can be investigated against an identified threshold. None removes the technical difficulty of verification, but each supplies a more determinate legal object than an undefined obligation to slow development.


Experience with such obligations could later inform negotiations over stronger restraints. If states developed shared evaluation methods, confidence in reporting, and procedures for handling sensitive information, they would possess more institutional infrastructure for considering limits on recursive self-improvement or broader capability growth. Such later agreements would still require separate consent and would not arise automatically from participation in a narrower initial regime.


Also read


Conclusion


International law could slow the AI race if states agreed to create obligations that constrain specified aspects of frontier development. No existing international regime presently establishes the kind of global pace limit contemplated in the Anthropic AI warning. Corporate commitments can govern the conduct of participating companies, but they cannot create reciprocal international obligations for competing states or compel foreign developers to observe equivalent restrictions.


A functioning international regime would require state consent, sufficiently precise obligations, credible means of verification, and domestic legal authority capable of reaching frontier laboratories and relevant infrastructure. It would also need procedures for dealing with alleged non-compliance. Those procedures could be created by the treaty itself through reporting, consultation, inspection, review, or other compliance mechanisms.


Responses to treaty breach would depend on the applicable legal framework. A treaty may establish specific consequences for non-compliance. Separately, the law of treaties permits suspension or termination in response to a material breach only under the conditions laid down in Article 60 of the Vienna Convention on the Law of Treaties. Countermeasures belong to the distinct law of state responsibility and are subject to their own substantive and procedural limits. A future AI agreement could not simply assume an unrestricted power to penalize a non-complying state.


A comprehensive global pause would require demanding forms of reciprocity and verification. More narrowly defined obligations, including independent evaluation, common testing procedures, risk thresholds, notification of large training runs, and targeted restrictions, can be framed around more observable conduct. Amodei's intervention is significant because it places an institutional problem behind the corporate warning: once pacing depends on common thresholds, reciprocal restraint, cross-border verification, and consequences for breach, the question moves beyond voluntary company policy and into international law.


References


Amodei, D. (2026) ‘We Must Pace the Frontier’ [online]. Available at: https://darioamodei.com/post/we-must-pace-the-frontier (Accessed: 15 September 2026).


Bureau of Industry and Security (BIS) (2025) ‘Department of Commerce Announces Rescission of Biden-Era Artificial Intelligence Diffusion Rule, Strengthens Chip-Related Export Controls’, 13 May [online]. Available at: https://www.bis.gov/press-release/department-commerce-announces-rescission-biden-era-artificial-intelligence-diffusion-rule-strengthens (Accessed: 15 September 2026).


Bureau of Industry and Security (BIS) (2026) Guidance Regarding Enforcement of License Requirements for Advanced Computing Items for Entities Headquartered in Country Group D:5 and Macau, 31 May [online]. Washington, DC: U.S. Department of Commerce. Available at: https://media.bis.gov/media/documents/bis-guidance-may-31-2026.pdf (Accessed: 15 September 2026).


Convention on the Prohibition of the Development, Production, Stockpiling and Use of Chemical Weapons and on their Destruction (1993) opened for signature 13 January 1993, entered into force 29 April 1997, 1974 UNTS 45.


Council of Europe (2024) Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law, adopted 17 May 2024, opened for signature 5 September 2024, CETS No. 225.


Council of Europe (2026) ‘Chart of Signatures and Ratifications of Treaty 225: Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law’ [online]. Status as of 12 September 2026. Available at: https://www.coe.int/en/web/conventions/full-list?module=signatures-by-treaty&treatynum=225 (Accessed: 15 September 2026).


Federal Trade Commission (n.d.) ‘Dealings with Competitors’ [online]. Available at: https://www.ftc.gov/advice-guidance/competition-guidance/guide-antitrust-laws/dealings-competitors (Accessed: 15 September 2026).


International Atomic Energy Agency (IAEA) (2022) IAEA Safeguards Glossary: 2022 Edition. International Nuclear Verification Series No. 3 (Rev. 1), STI/PUB/2003. Vienna: International Atomic Energy Agency. Available at: https://www-pub.iaea.org/MTCD/Publications/PDF/PUB2003_web.pdf (Accessed: 15 September 2026).


Interim Agreement Between the United States of America and the Union of Soviet Socialist Republics on Certain Measures with Respect to the Limitation of Strategic Offensive Arms (1972) signed 26 May 1972, entered into force 3 October 1972, 23 UST 3462, TIAS No. 7504.


National Institute of Standards and Technology (NIST) (2025) ‘Cheating On AI Agent Evaluations’ [online]. Created 28 November 2025, updated 2 December 2025. Available at: https://www.nist.gov/caisi/cheating-ai-agent-evaluations (Accessed: 15 September 2026).


Organisation for Economic Co-operation and Development (OECD) (2024) Recommendation of the Council on Artificial Intelligence, OECD/LEGAL/0449, adopted 22 May 2019, amended 3 May 2024 [online]. Available at: https://legalinstruments.oecd.org/en/instruments/OECD-LEGAL-0449 (Accessed: 15 September 2026).


Sherman Act (1890) Act of 2 July 1890, ch. 647, 26 Stat. 209, codified as amended at 15 U.S.C. §§ 1–7.


UK Government (2023a) ‘AI Safety Summit 2023: The Bletchley Declaration’ [online]. Published 1 November 2023, updated 13 February 2025. Available at: https://www.gov.uk/government/publications/ai-safety-summit-2023-the-bletchley-declaration (Accessed: 15 September 2026).


UK Government (2023b) ‘Emerging Processes for Frontier AI Safety’ [online]. Published 27 October 2023. Available at: https://www.gov.uk/government/publications/emerging-processes-for-frontier-ai-safety (Accessed: 15 September 2026).


UK Government (2023c) ‘Frontier AI: Capabilities and Risks – Discussion Paper’ [online]. Published 25 October 2023, updated 28 April 2025. Available at: https://www.gov.uk/government/publications/frontier-ai-capabilities-and-risks-discussion-paper (Accessed: 15 September 2026).


UK Government (2024) ‘Frontier AI Safety Commitments, AI Seoul Summit 2024’ [online]. Published 21 May 2024, updated 7 February 2025. Available at: https://www.gov.uk/government/publications/frontier-ai-safety-commitments-ai-seoul-summit-2024 (Accessed: 15 September 2026).


United Nations (n.d.) ‘Global Dialogue on AI Governance’ [online]. Available at: https://www.un.org/global-dialogue-ai-governance/en (Accessed: 15 September 2026).


United Nations General Assembly (2024) The Pact for the Future, A/RES/79/1, 22 September 2024, Annex I: Global Digital Compact. Available at: https://docs.un.org/A/RES/79/1 (Accessed: 15 September 2026).


United Nations General Assembly (2025) Terms of Reference and Modalities for the Establishment and Functioning of the Independent International Scientific Panel on Artificial Intelligence and the Global Dialogue on Artificial Intelligence Governance, A/RES/79/325, 26 August 2025. Available at: https://digitallibrary.un.org/record/4087699/ (Accessed: 15 September 2026).


U.S. Department of State, Office of the Historian (n.d.) ‘Strategic Arms Limitations Talks/Treaty (SALT) I and II’ [online]. Available at: https://history.state.gov/milestones/1969-1976/salt (Accessed: 15 September 2026).


U.S. Government Accountability Office (GAO) (2026) U.S. Department of Commerce, Bureau of Industry and Security—Applicability of the Congressional Review Act to the Rescission of the Artificial Intelligence Diffusion Rule, B-337935, 12 May 2026 [online]. Available at: https://www.gao.gov/products/b-337935 (Accessed: 15 September 2026).


Vienna Convention on the Law of Treaties (1969) done at Vienna 23 May 1969, entered into force 27 January 1980, 1155 UNTS 331.

Diplomacy and Law Logo
bottom of page