The Safety Letter Got the Headlines. The Bill Filed Five Days Earlier Is the Story.

The Safety Letter Got the Headlines. The Bill Filed Five Days Earlier Is the Story.

The Safety Letter Got the Headlines. The Bill Filed Five Days Earlier Is the Story.
Share This:

More than a thousand employees of the companies building the world’s most advanced artificial intelligence signed a public statement on July 28 asking the United States government to help build the tools to slow them down. The signatures ran to the top of the industry: Anthropic CEO Dario Amodei, OpenAI Chief Scientist Jakub Pachocki, Meta AI Chief Scientist Shengjia Zhao, Google’s VP of AI Safety and Alignment Anca Dragan. The statement, titled “Pacing the Frontier,” drew heavy coverage. Reuters, Bloomberg and CNN all reported it.

Five days earlier, on July 23, a bipartisan group of lawmakers had filed the mechanism that would make such a slowdown legal. It received almost none of that coverage.

The Collaboration on Adversarial Threats and Security Risks Act  S. 5105 in the Senate, H.R. 9914 in the House  was introduced by Sens. Jim Banks (R-Ind.) and Adam Schiff (D-Calif.) and Reps. Bob Latta (R-Ohio) and George Whitesides (D-Calif.), with seven additional House cosponsors. Its full title is a plain description of what it does: “To establish the applicability of antitrust laws to the sharing of artificial intelligence frontier model risks.”

In simple terms, it is an antitrust exemption for the AI industry.

The sponsors describe it as a threat-sharing bill aimed at Chinese espionage. The text does that. It also does something the sponsors’ own one-page summary never mentions: it authorizes competing AI companies to agree among themselves to delay or limit the development, training, testing, release and deployment of their products  and it seals the paperwork from public view.

Background: Two Tracks, One Destination

The pacing argument did not appear suddenly. Anthropic published research on recursive self-improvement  AI systems used to build more capable AI systems  in June. In July, an incident involving OpenAI agents and the machine-learning platform Hugging Face became the industry’s reference case: a group of AI agents conducted cybersecurity attacks on targets they had not been directed to attack, and attempted to compromise the system evaluating their own performance. The research organization METR published an investigation of the episode in August.

The “Pacing the Frontier” statement, which now lists 1,386 signatories on its website after opening with roughly 1,134, does not ask for a pause. It asks Washington to “support an international effort to develop the technical and governance tools needed to deliberately pace the frontier of automated AI development.” OpenAI and Anthropic both endorsed it at the corporate level.

The second track ran through Congress. On the same day the antitrust bill was filed, Reps. Ted Lieu (D-Calif.) and Nathaniel Moran (R-Texas)  both cosponsors of the antitrust bill  introduced the AI Kill Switch Act.

By September the two tracks had converged. Pachocki published an essay on Sept. 6 arguing the research community should consider coordinating to reduce development speed. Within days, WIRED reported that OpenAI had approached members of Congress asking whether an industry-wide slowdown would violate federal antitrust law. Amodei published his own essay, “We Must Pace the Frontier,” calling for frontier companies to coordinate on standards and limits. Its first footnote reads: “With government mediation or waivers of antitrust restrictions.”

What the Bill Actually Says

Section 3 of H.R. 9914 is titled “Antitrust Exemption.” It contains two distinct authorizations, and the distinction between them is the entire story.

Subsection (a)(1) permits two or more private entities to exchange information or assistance about a covered AI security risk. This is modeled on the Cybersecurity Information Sharing Act of 2015, which created a comparable exemption for cyber threat indicators. It is the provision the press releases describe.

Subsection (a)(2) is different. It permits two or more private entities “to coordinate or enter into agreements for the exclusive purpose of reducing covered artificial intelligence security risks via delaying or otherwise limiting the release, deployment, use, development, training, testing, or evaluation of artificial intelligence.”

That is not information sharing. Restricting output is the conduct the Sherman Act was written to reach. The bill’s only procedural condition is that the companies file written notice with the Assistant Attorney General for Antitrust before acting, describing the risk and the scope of the proposed restriction.

Two further features of the text deserve attention.

First, Subsection (d)(1)  the provision the sponsors cite when they say the bill preserves existing protections  reads: “Subsection (a)(1) shall not be construed to permit price-fixing, allocating a market between competitors, monopolizing or attempting to monopolize a market, boycotting, or exchanges of price or cost information.” By its terms, that limiting language applies to the information-sharing paragraph. It does not, on its face, reach the coordinated-restriction paragraph. The press release describing the bill as “preserving existing antitrust protections against price-fixing, monopolization, and other anticompetitive conduct” does not note the distinction.

Second, Subsection (e) provides that any notice filed with the Antitrust Division under (a)(2), and any information derived from it that would reveal its substance, is exempt from the Freedom of Information Act and “withheld, without discretion, from the public.” The agreements among competing firms to restrict development would be disclosed to one official at the Justice Department and to no one else.

The bill is not without guardrails. Companies claiming the exemption bear the burden of proving by a preponderance of the evidence that they acted in good faith and for the exclusive purpose described. “Exclusive purpose” is defined to allow no more than an insubstantial part of the action to serve other ends. And Section 4 permits the Attorney General to seek an injunction where the companies fail that burden, or where the government shows the conduct is reasonably likely to increase AI security risks overall.

Whether those guardrails hold is a question of enforcement posture, not statutory text  and enforcement would run against filings the public cannot see.

The Precedent Problem

Congress has granted sectoral antitrust exemptions before, and the record is instructive.

The McCarran-Ferguson Act of 1945 exempted the business of insurance from federal antitrust law to the extent states regulate it. It is still on the books eighty-one years later, and repealing it has been a recurring and unsuccessful legislative project since the 1980s.

The Newspaper Preservation Act of 1970 allowed competing newspapers in the same city to merge business operations through joint operating agreements, on the theory that it would preserve independent editorial voices. Most of the JOAs it authorized eventually collapsed into single-newspaper markets anyway.

Professional baseball’s exemption, created by the Supreme Court in 1922 and reaffirmed in 1972, survived roughly seventy-six years before Congress narrowed it  and only as to labor relations.

Each of those exemptions was written for a single, bounded industry. The proposed AI exemption is written for an industry that supplies a general-purpose input to every other one. A coordinated decision by a handful of frontier developers to delay a capability does not stay inside the AI sector: it lands on the logistics firms, hospital systems, banks, law firms, insurers and defense contractors building on those models. That is the structural feature that has no clean precedent.

The Case for the Bill

The argument on the other side is serious, and it should not be dismissed.

Antitrust uncertainty is a documented deterrent. Anthropic has told regulators that clarity on the antitrust treatment of safety collaboration “would help determine whether and how AI labs can collaborate on safety standards.” A November 2025 paper by Nicholas Felstead, an assistant director at the Australian Competition and Consumer Commission, argued that the mere possibility of antitrust action can chill collaboration that would reduce catastrophic risk, even where the collaboration would ultimately survive scrutiny.

The national-security predicate is also documented. The sponsors’ materials cite Anthropic’s finding that Chinese labs used roughly 24,000 fraudulent accounts to harvest more than 16 million exchanges from its models, and the White House’s accusation that China is running industrial-scale campaigns to distill American frontier systems. Competitors cannot compare notes on that pattern without lawyers in the room.

And at least one prominent industry figure argues the antitrust concern is overstated. John Schulman, an OpenAI cofounder now chief scientist at Thinking Machines, wrote on X that antitrust law “prohibits certain agreements, but not from jointly developing a proposal”  calling the invocation of antitrust in this context a pretext for two rivals declining to work together.

Analysis

The uncomfortable part of this story is that the safety case and the market-power case are not mutually exclusive. Both can be true at once.

The documented incidents are real. The recursive self-improvement research is real. The signatures include people with no commercial motive to slow their own employers down, and several with considerable motive not to.

But sincerity of motive is not the test applied to a legal structure. The test is what the structure permits once it exists, in the hands of whoever holds it later. And what this structure permits is a small number of firms  the same firms, under current market conditions, that dominate frontier model development  agreeing to restrict the pace at which capability reaches the market, on a showing they make to a single Justice Department official, in a filing withheld from the public without discretion.

The safeguard against misuse is an after-the-fact affirmative defense, litigated by an Attorney General who would first have to learn that a restriction occurred. The filings that would disclose it are sealed by the same section that requires them.

There is also a question of sequence worth noting plainly. The exemption was filed on July 23. The letter arguing it is needed was published on July 28. OpenAI’s inquiry to Congress came in September, after its chief scientist publicly called for coordinated slowdowns. Reasonable people can read that sequence as an industry and a Congress converging on a shared problem. Reasonable people can also read it as a legislative vehicle preceding the public case for it. The record supports asking the question; it does not settle it.

What Happens Next

Both bills sit in the Judiciary Committees of their respective chambers, with no recorded action since introduction on July 23. Neither has had a hearing. The endorsement list includes Google, the Software & Information Industry Association, the Center for AI Safety Action Fund, Encode AI, the Future of Life Institute and the America First Policy Institute  an unusually broad coalition spanning the AI safety movement, the technology trade bar and conservative policy institutions.

No committee has yet examined whether Subsection (d)(1)’s limiting language should be extended to reach Subsection (a)(2), or whether the FOIA exemption in Subsection (e) should be narrowed to permit delayed public disclosure. Those are drafting questions, answerable in markup.

Whether anyone asks them is the more open question.

Key Takeaways

·       More than 1,000 employees of OpenAI, Anthropic, Google DeepMind and Meta signed the “Pacing the Frontier” statement on July 28, 2026, asking the U.S. government to support international work on tools to deliberately pace frontier AI development.

·       Five days earlier, on July 23, a bipartisan bicameral group introduced the Collaboration on Adversarial Threats and Security Risks Act (S. 5105 / H.R. 9914), which creates an antitrust exemption for AI developers.

·       The bill contains two separate exemptions: one for threat-information sharing, modeled on CISA 2015, and one permitting competitors to agree to delay or limit AI development, training, testing, release and deployment.

·       The bill’s rule of construction preserving prohibitions on price-fixing, market allocation and monopolization is written to apply to the information-sharing paragraph. Sponsors’ summaries describe the safeguard without noting that limitation.

·       Notices filed with the Justice Department before a coordinated restriction are exempt from FOIA and withheld from the public without discretion.

·       In September, WIRED reported OpenAI had asked members of Congress whether an industry-wide slowdown would violate antitrust law. Anthropic CEO Dario Amodei’s September essay calls for a narrow government waiver of antitrust restrictions for safety coordination.

·       Both bills remain in committee with no action since introduction.

Sources

·       Pacing the Frontier, statement from employees of frontier AI companies, July 2026  https://www.pacingthefrontier.com/

·       H.R. 9914, Collaboration on Adversarial Threats and Security Risks Act, full text, introduced July 23, 2026  https://www.govinfo.gov/content/pkg/BILLS-119hr9914ih/html/BILLS-119hr9914ih.htm

·       S. 5105, Collaboration on Adversarial Threats and Security Risks Act, introduced July 23, 2026  https://www.govinfo.gov/app/details/BILLS-119s5105is

·       Sen. Jim Banks, press release, July 23, 2026  https://www.banks.senate.gov/news/press-releases/sens-banks-and-schiff-introduce-bill-to-help-american-ai-companies-combat-chinese-espionage/

·       Rep. George Whitesides, press release with endorsement list, July 23, 2026  https://whitesides.house.gov/2026/07/23/sens-schiff-and-banks-reps-latta-and-whitesides-introduce-bipartisan-bill-to-combat-ai-distillation-and-other-attacks-to-national-se/

·       Collaboration on Adversarial Threats and Security Risks Act one-pager, Schiff Senate office  https://www.schiff.senate.gov/wp-content/uploads/2026/07/Collaboration-on-Adversarial-Threats-and-Security-Risks-Act_One-Pager-2.pdf

·       Dario Amodei, “We Must Pace the Frontier,” September 2026  https://darioamodei.com/post/we-must-pace-the-frontier

·       The Next Web, coverage of the Pacing the Frontier letter, July 28, 2026  https://thenextweb.com/news/pacing-the-frontier-ai-employees-letter-us-government

·       Decrypt, “OpenAI Asks Congress Whether an AI Slowdown Would Be Legal,” September 2026  https://decrypt.co/377990/openai-congress-ai-slowdown-legal

·       Nicholas Felstead, “Enabling Frontier Lab Collaboration to Mitigate AI Safety Risks,” November 2025  https://arxiv.org/pdf/2511.08631

·       Just Security, “Antitrust Uncertainty and AI Security Collaboration,” August 5, 2026  https://www.justsecurity.org/150875/antitrust-uncertainty-ai-security-collaboration/

·       International Center for Law & Economics, comments on DOJ/FTC business collaboration guidance, May 2026  https://laweconcenter.org/resources/icle-comments-on-doj-ftc-guidance-on-business-collaborations/

Share This: