Frontier artificial-intelligence (AI) labs may have good reasons to tap the brakes. The antitrust question begins when they all reach for the same pedal.
Anthropic CEO Dario Amodei’s proposal to “pace the frontier” has become a rallying point for AI companies interested in coordinating a slowdown in capability development. His plan calls for embedded outside evaluators, common safety standards, and limits on the pace of model advances. Amodei also suggests that some form of antitrust waiver may be needed to permit certain safety discussions.
As my colleague Dirk Auer explains, agreements among rivals to restrain development deserve scrutiny, even when made in the name of safety. Before granting an exemption, policymakers should ask where existing legal and market incentives—and the forms of cooperation antitrust law already allows—fall short.
Civil and criminal laws already give AI labs reason to consider the consequences of their conduct, including safety risks. Market incentives point in the same direction. Customers favor products that work as intended and remain dependable. A model that enables mass hacking or causes other serious harm is, among other things, a very bad product.
Companies can respond to these incentives on their own by strengthening safeguards, limiting model autonomy, or delaying releases. Existing antitrust law also permits competitors to collaborate on many safety matters and participate in carefully structured standard-setting efforts.
Any proposed exemption therefore carries a heavy burden. Its proponents must show why unilateral action and lawful collaboration cannot address the problem—and identify precisely what conduct existing antitrust law prevents.
Move Fast and Get Sued
AI-safety evaluator Model Evaluation and Threat Research’s (METR) investigation into the Hugging Face incident found that separate agents used an unauthorized message board to coordinate a remote-code-execution attack, which allows an attacker to run commands on another computer. Hundreds of agents participated, even though the attack fell outside their assigned tasks. If developers and operators did not already feel pressure to build safeguards into new models, this incident should provide it.
Labs that deploy agents with offensive cyber capabilities must make difficult choices about access limits, system isolation, monitoring, and when humans should intervene. Negligence law can make poor choices in these areas very costly.
Of course, a negligence claim still requires proof of a legal duty, breach, causation, and recoverable harm. An agent’s harmful conduct does not automatically make its developer liable. Even so, the early stages of litigation can become a long and expensive headache for any firm.
Nor does potential liability end with a lab’s direct actions. A company may face liability for creating a foreseeable downstream risk, even when a third party causes the immediate harm. In Weirum v. RKO General, for example, the California Supreme Court affirmed liability against a broadcaster whose contest predictably encouraged listeners to drive dangerously. The case did not involve artificial intelligence, but it illustrates how liability can rest on creating a foreseeable risk rather than directly inflicting the injury. For an AI lab, the central question may be whether developing or operating its system created an unreasonable risk of harm.
Other civil claims and criminal charges apply different legal standards. The Computer Fraud and Abuse Act (CFAA), for example, covers specified forms of unauthorized computer access and provides a limited civil remedy. The statute bars civil claims based on negligent software design or manufacture. No court has yet decided how that exclusion applies when autonomous software agents commit the prohibited acts.
The degree of “intentionality” that a court attributes to an agent could affect that analysis. So could a developer’s deliberate decision to equip a model with offensive cyber capabilities. A court might view such a case as involving something more than negligent software design.
Criminal liability under the CFAA would require proof of a specific offense and the necessary mental state of a legally responsible person or entity. An agent’s apparent motivations do not, by themselves, establish a lab’s criminal intent. It also remains unclear whether an agent can possess legally cognizable intent and, if so, when that intent could be attributed to the lab that trained it or the user who deployed it.
None of this means that OpenAI or any other lab should be sued, much less that it would clearly face liability under the CFAA, negligence law, or another legal theory. The point is that considerable uncertainty remains, along with plenty of room for creative lawyers to impose costly, time-consuming litigation on frontier AI labs. Those labs can reasonably account for that risk when deciding unilaterally whether to slow development.
Development and deployment also create different risks. A lab might continue capability research while restricting an agent’s access to external systems. It might strengthen containment measures or postpone a release until testing is adequate. Each decision involves a separate judgment about the product’s risks and benefits. A race to develop more capable models does not force every participant to ignore those costs in pursuit of commercial advantage.
Acing the Benchmark, Flunking the Job
An AI product’s quality depends on more than intelligence. Users expect an agent to respect permissions, protect confidential data, and perform assigned tasks reliably. Benchmark scores cannot establish whether it is fit for a particular job. An agent that aces every test but ignores its instructions is still a lousy employee.
Competition law knows this territory well. Firms routinely compete through different combinations of performance, price, reliability, and other features. Antitrust law recognizes these dimensions of competition. Agency guidance on innovation, for example, expressly considers competition over the range of products and features available to consumers. Intelligence is similarly just one measure of competitive success in AI.
Safety also has commercial value independent of any shared commitment to slow development. Widespread concern about AI safety is itself a strong signal that customers want safer products. One lab might attract customers with an agent that is easier to supervise or better suited to sensitive work. Another might offer greater autonomy paired with different controls.
Competition lets customers compare these approaches and firms refine them through experience. Coordination around a single approach to AI safety can limit that experimentation, particularly when an agreed-upon standard excludes competing designs.
Mark Zuckerberg’s recent discussion of Meta’s strategy for Muse illustrates the point. Zuckerberg said Meta delayed Muse’s launch to address safety concerns. Meta made that decision unilaterally as part of its own product-design and launch process, without imposing the same judgment on its competitors.
The delay does not prove that Meta ultimately met the appropriate safety threshold or that every lab faces comparable incentives. It does show that firms can delay a release to address safety concerns without first securing an antitrust exemption.
No Antitrust Hall Pass
AI labs can already obtain safety information through several channels. Each firm can hire independent evaluators, commission audits, and consult outside experts. Anthropic’s unilateral pledge to embed independent evaluators shows that this part of Amodei’s proposal requires no industrywide speed limit.
Standardized testing and certification could also help consumers distinguish among competing products. They could provide courts and regulators with evidence of an established, reasonably applied industry practice. Private certification bodies might assess compliance with specified benchmarks, much as UL Solutions tests and certifies product safety. Testing laboratories could also work through standard-setting forums to develop common protocols and technical specifications.
The Federal Trade Commission (FTC) already recognizes that carefully structured cooperation among competitors can make markets more efficient and benefit consumers. That includes certain standard-setting activities.
The legal details still matter. An industry standards body can promote safety, or it can become a club that keeps rivals out. A forum created to develop testing protocols can instead become a venue for sharing confidential business information or coordinating anticompetitive restraints. A safety label is not an antitrust hall pass. Certification programs and standards remain subject to antitrust scrutiny, and participating firms must act reasonably within them.
The law also distinguishes among unilateral decisions, limited cooperation, and agreements that suppress competition. One firm may delay a launch. Several firms may collaborate on a specific evaluation. Competitors might instead agree to restrict the computing workloads used to train their models. The first two approaches preserve competition over capabilities. The third can suppress it.
Advocates for an antitrust exemption should therefore identify the conduct they want to pursue that existing law prohibits. They should also explain why that protection is necessary to achieve safety benefits that firms cannot obtain through unilateral action or carefully structured cooperation.
The Burden Before the Brake
Liability rules and customer demand cannot solve every safety problem. Customers may overlook harms imposed on outsiders. An incident may be difficult to detect or trace to a particular company. Catastrophic losses may also exceed a lab’s ability to compensate victims. These gaps can weaken incentives to take precautions and may justify targeted policy responses.
The narrower point is that existing legal and market institutions already give firms independent reasons to invest in safer products. Firms also have several ways to act on those incentives. Anyone proposing coordinated restrictions as the cure must explain why they would close the remaining gaps more effectively than the available alternatives.
As Dirk Auer noted, an antitrust exemption carries costs of its own. Past exemptions have encouraged stagnation and industry capture, allowing established firms to shape rules for their own benefit. Proponents must therefore identify the specific risk that unilateral action and lawful cooperation cannot adequately address, the precise restraint needed to address it, and why a less restrictive response would fail.
Build the guardrails first. Give competitors a shared brake only after proving the need.
