Second in a two-part series. Part I examined the antitrust exemption bill filed five days before the “Pacing the Frontier” letter.
On Sept. 10, the AI company Anthropic published a 154-page threat intelligence report. Buried in it was an account of an Iran-linked account using the company’s Claude model to assemble what the report called “targeting books” on United States naval forces a roster of personnel scraped from captions on public military photographs, publicly accessible ship and aircraft transponder identifiers, scripts for querying commercial satellite imagery, and an inventory of websites exposing U.S. naval movements. The same user directed the model to compile vulnerability research on shipboard systems. Anthropic banned the account.
The report also described a China-based actor using the same model to prepare a briefing on U.S. anti-torpedo weapon systems from open-source reporting.
That disclosure arrived the same week OpenAI asked members of Congress whether American AI companies could legally agree among themselves to slow down.
The juxtaposition is the whole problem in miniature. Congress can grant American firms permission to coordinate a slowdown. It cannot grant anyone permission to make the rest of the world participate and the parties most likely to decline are already using the tools.
Correcting a Common Assumption
The most frequently voiced objection to the pacing proposal is that U.S. antitrust law stops at the border, making the whole exercise domestic theater. That framing is wrong in both directions, and the corrections matter.
American antitrust law does reach foreign conduct. Under the Foreign Trade Antitrust Improvements Act of 1982 and the Supreme Court’s decision in Hartford Fire Insurance Co. v. California (1993), the Sherman Act applies to conduct abroad that has a direct, substantial and reasonably foreseeable effect on U.S. commerce. The Court narrowed the doctrine in F. Hoffmann-La Roche Ltd. v. Empagran S.A. (2004), limiting claims arising solely from foreign injury. But the reach exists. Enforcement against a firm with no U.S. presence and no cooperative home government is a practical problem, not a jurisdictional one.
The more consequential error runs the other way. A U.S. antitrust exemption protects American companies from American antitrust law. It does nothing about anyone else’s.
If OpenAI, Anthropic and Google were to coordinate a delay in frontier model release, that agreement would affect European markets. Article 101 of the Treaty on the Functioning of the European Union prohibits agreements between undertakings that restrict competition within the internal market, and it applies to foreign firms whose conduct has effects there. The United Kingdom’s Competition Act 1998 operates similarly. Neither jurisdiction has enacted an AI safety carve-out.
In simple terms: the bill before Congress would make coordinated pacing lawful in Washington while leaving the same conduct exposed in Brussels and London. A safe harbor in one jurisdiction is not a safe harbor.
Can Anyone Verify Compliance?
Set the legal question aside and the harder one remains. Even assuming every party wants an agreement, no party can currently confirm that another is keeping it.
This is not a novel complaint. It is the central finding of most serious work on the subject. The Future Society, in a memo published this month, framed it plainly: an international agreement cannot rest on mutual trust, because each party must be able to determine reliably whether the others are complying. The Institute for Progress recommended in August that the U.S. government work with AI labs, chipmakers and data center operators to accelerate development of verification tools, citing the nuclear arms control precedent where the capacity to verify was often what made agreement possible in the first place.
Amodei’s own essay concedes the point at length. He sorts potential international agreements into four levels of difficulty, from a narrow prohibition on using AI to produce biological weapons (which he considers probably achievable) to a comprehensive global pause (which he does not expect soon). His stated condition is that any agreement must have “ironclad verifiability,” or be limited enough that a defection would not be militarily existential.
The technical proposals under discussion are serious and mostly unbuilt: compute telemetry, hardware attestation that a given cluster is running inference rather than training, on-site inspection regimes modeled on arms control, network-level monitoring. Researchers at the Center for AI Safety argued in August that whole-lab inspection would be straightforward domestically and would require joint U.S.-China inspector access to extend internationally. None of this exists at operational scale today.
There is a scheduled test. U.S. and Chinese officials are expected to hold a bilateral AI dialogue this month. Nobody credible expects a treaty from it. The Center for American Progress argued that the realistic goal is narrower: establishing whether the two governments share a concern about loss of control at all.
The Defection Question
The competitive-advantage objection is the one the signatories themselves take most seriously, and it has not been answered.
The logic is not complicated. If American firms slow and others do not, the others close the gap. Amodei’s essay states the constraint directly: pacing within democracies is limited by the size of the lead over authoritarian regimes, and slowing by more than that margin hands the frontier to unpaced projects. His answer is to widen the lead first chip export controls, cracking down on distillation, hardening security against model weight theft to create the room in which pacing becomes affordable.
That is a coherent strategy. It is also a strategy in which the safety argument and the market-position argument point in precisely the same direction, which is why it draws the regulatory capture charge.
Estimates of China’s position vary and should be treated skeptically. One analysis circulating in September put Chinese capability at roughly where the U.S. frontier stood six months earlier, and eight to ten months behind the newest class of American models once lagged compute buildout is accounted for. These are informal estimates from people with stakes in the debate, not measured figures. What is less contested is China’s strategy: continued release of open-weight models, which narrows the practical gap regardless of where the absolute frontier sits.
And open weights are the hole in any pacing regime. Amodei’s framework, as he described it in an August exchange with investor Gavin Baker, would modulate the pace of the very best models without constraining those catching up. Baker’s objection was that this scoping hurts frontier labs and helps challengers, open-weight developers among them. A coordinated pause at the frontier does not pause a model whose weights are already published.
What Adversary Use Actually Looks Like
Here the record is better than the speculation, and it cuts against overclaiming in both directions.
The 2026 U.S.-Iran conflict has been described as the first war in which AI and autonomous systems were the main event rather than support. U.S. Central Command struck more than 11,000 targets in the opening phase, with targeting cycles compressed by the Maven Smart System. The Department of the Navy published its own AI strategy on June 15, signed by acting Secretary Hung Cao.
Iranian capability is the more interesting case, because the documented record diverges sharply from the claims.
Tehran spent years publicizing AI-enhanced munitions the Abu Mahdi naval cruise missile, the Fath-360 tactical ballistic missile, the Ghadir cruise missile, among others touted by IRGC Navy commanders between 2023 and early 2025. A Recorded Future assessment published in July found that reporting from the March–June 2026 conflict does not confirm operational use of AI-enhanced missile capabilities against U.S., Israeli or Gulf targets. The systems that actually appeared were conventional: hypersonic glide vehicles, massed ballistic salvos, explosive drone boats against commercial shipping.
Where Iranian AI use is documented, it is in cyber operations, influence operations and intelligence work. The Foundation for Defense of Democracies catalogued Iranian groups using large language models for social engineering at scale and malware development, with 2026 targets ranging from Fortune 500 manufacturers to county governments in Indiana. And the Anthropic case described above is open-source intelligence work: aggregating public photographs, transponder data and satellite imagery into a targeting product.
That distinction matters for policy. The near-term adversary capability is not an autonomous weapon. It is a general-purpose tool that collapses the labor cost of intelligence work the kind of analysis that previously required a staffed cell and now requires an account.
Which raises the question a pacing agreement does not answer. Nothing in the Iranian targeting case required a frontier model. It required a competent commercial one. Pacing the frontier does not touch the capability that produced it.
Analysis
Three observations follow from the record.
First, the enforcement asymmetry runs opposite to the common assumption. The proposed exemption constrains conduct Washington can already reach and leaves untouched the conduct it cannot. It authorizes American firms to do domestically what remains actionable in Europe, while providing no mechanism whatsoever regarding Chinese, Russian or Gulf-state developers.
Second, the verification gap is not a detail to be worked out later. It is the condition on which the entire international tier depends, and the people advocating the framework say so themselves. Until compute telemetry, inspection regimes or hardware attestation exist at scale, a global pacing agreement is a statement of intent with no instrument behind it.
Third, and most uncomfortably: the company that disclosed the Iranian targeting operation is also a principal advocate for the antitrust waiver, and its CEO’s framework identifies export controls and anti-distillation enforcement as prerequisites to pacing. The threat disclosure is credible and appears to have been handled responsibly. It is also, structurally, evidence produced by an interested party in support of a policy that interested party is seeking. Both things are true. Readers should hold them together rather than choosing one.
None of this establishes bad faith. It establishes that the safety case and the competitive case have not been disentangled, and that no institution has yet been assigned the job of disentangling them.
Conclusion
The pacing proposal asks a specific thing of the United States government: build the tools and the legal room to slow down, so the option exists if it is needed. That is a defensible request, and the incidents behind it are real.
But the request has a boundary its advocates acknowledge and its critics understate. Congress can write an exemption. It cannot write a verification technology, and it cannot legislate for Beijing, Brussels or Tehran.
The Iranian case is the useful corrective. While the industry debates the pace of the frontier, an adversary was using a commercially available model to turn public photographs into a roster of American sailors. That capability is already deployed, already distributed, and entirely outside the scope of anything the Judiciary Committees are considering.
Key Takeaways
· U.S. antitrust law does reach conduct abroad that substantially affects U.S. commerce, under the Foreign Trade Antitrust Improvements Act of 1982 and Hartford Fire Insurance Co. v. California (1993). The jurisdictional limit is practical, not legal.
· A U.S. antitrust exemption would not protect American firms from EU Article 101 TFEU or the UK Competition Act 1998. Neither jurisdiction has an AI safety carve-out.
· Verification technology compute telemetry, hardware attestation, inspection regimes does not exist at operational scale. Multiple advocacy organizations and Anthropic’s CEO identify it as the precondition for any international agreement.
· U.S. and Chinese officials are expected to hold a bilateral AI dialogue this month; no participant expects a treaty.
· Open-weight model releases undercut frontier pacing regardless of what frontier developers agree to.
· Documented Iranian AI use in the 2026 conflict is concentrated in cyber, influence and open-source intelligence operations. Pre-war claims of AI-enhanced missile systems were not confirmed operationally in March–June 2026 reporting.
· Anthropic’s September threat report documented an Iran-linked account using Claude to build targeting material on U.S. naval forces, and a China-based actor researching U.S. anti-torpedo systems.
Sources
· Anthropic threat intelligence report, September 2026 https://www.anthropic.com/threat-intelligence-report-september-2026
· Alison Bath, “Iran-linked actor used AI to build targeting guides on US Navy,” Stars and Stripes, Sept. 11, 2026 https://www.stripes.com/branches/navy/2026-09-11/anthropic-ai-navy-middle-east-iran-threat-22818937.html
· Recorded Future, “AI Has Enhanced Iran’s Asymmetric Playbook During the 2026 Conflict,” July 16, 2026 https://www.recordedfuture.com/research/iran-ai-asymmetric-playbook
· Foundation for Defense of Democracies, “5 Ways Iran Is Exploiting AI in Warfare,” May 6, 2026 https://www.fdd.org/analysis/2026/05/06/5-ways-iran-is-exploiting-ai-in-warfare/
· Department of the Navy Strategy to Weaponize Data and Artificial Intelligence, June 15, 2026, via USNI News https://news.usni.org/2026/07/16/the-navys-strategy-to-weaponize-data-and-artificial-intelligence
· Dario Amodei, “We Must Pace the Frontier,” September 2026 https://darioamodei.com/post/we-must-pace-the-frontier
· The Future Society, “How To Make International AI Verification a Reality,” September 2026 https://thefuturesociety.org/international-ai-verification
· Center for AI Safety / AI Frontiers, “An International AI Slowdown Is Ready Whenever Politicians Are,” Aug. 5, 2026 https://newsletter.ai-frontiers.org/p/an-international-ai-slowdown-is-ready
· Center for American Progress, “The U.S. and China Must Explore Pacing the Frontier During September AI Dialogue,” September 2026 https://www.americanprogress.org/article/the-u-s-and-china-must-explore-pacing-the-frontier-during-september-ai-dialogue/
· TIME, “The People Building a Way to Slow Down the AI Race,” Aug. 16, 2026 https://time.com/article/2026/08/16/ai-race-slowdown-data-center-verification/
· Alaga and Schuett, “Coordinated Pausing: An Evaluation-Based Coordination Scheme for Frontier AI Developers,” 2023 https://arxiv.org/pdf/2310.00374
· Lawfare, “Can Frontier AI Labs Lawfully Agree to Pause?”, June 29, 2026 https://www.lawfaremedia.org/article/can-frontier-ai-labs-lawfully-agree-to-pause
· Forbes, “The First AI War: How The Iran Conflict Is Reshaping Warfare,” Mar. 30, 2026 https://www.forbes.com/sites/mikebrown/2026/03/30/the-first-ai-war-how-the-iran-conflict-is-reshaping-warfare/
