The Feasibility of a Hardwired Pause of Frontier AI Training
Executive Summary
The coordination problem
The risks associated with rapid advances in AI capabilities have led to calls for a pause of frontier AI training. Yet companies and governments may be unwilling to unilaterally pause for extended periods of time, for strategic reasons: they may fear that other companies or governments will not pause and that those who do pause may then suffer a commercial or geopolitical disadvantage. Thus, companies and governments face a coordination problem in pausing frontier AI training.
However, such problems are not insoluble. Coordination is possible if the decision makers care enough about future, not just immediate, payoffs, and if monitoring is adequate to support credible consequences for defections. Humanity has faced similar coordination problems before and responded with international agreements, as with efforts to control nuclear technology or address damage to Earth’s ozone layer. Whether humanity can coordinate to regulate the unique, dual-use dynamics of AI has become one of the most significant questions of the 21st century.
This report studies the feasibility of an international agreement to pause frontier AI training, where the agreement is designed to overcome the coordination problem for companies and governments. It does not study the desirability of a pause relative to other policy options or the probability that a pause will be implemented.
We consider a scenario in which world leaders would prefer pausing to not pausing if they could be confident that others were also pausing or that defections from a pause would be detected within a reasonable timeframe. In such a pause-willing scenario, is a pause for at least a decade feasible?
A hardwired pause
Frontier AI training requires AI chips, which states can govern. The supply chain for AI chips is highly concentrated with several chokepoints, bolstering governments’ abilities to enforce rules on the production of such chips. In addition, bypassing existing supply chains is extraordinarily difficult. An international prohibition on frontier AI training can take advantage of these facts about the hardware needed for AI training.
We focus on the feasibility of what we call a hardwired pause. A hardwired pause would stop the production of training-capable AI chips, which are needed to develop more powerful AI models. Over time a hardwired pause would also phase out most or all of the pre-pause stock of such chips. It would replace them with inference-only AI chips, which are capable of fast, energy-efficient AI inference on approved models but are not practically useful for training new frontier AI models, even if stolen or seized, due to the way the chips are constructed. During the process of replacement, training-capable AI chips would provide transitional inference service, with verification measures preventing their use for frontier AI training. If successful, this replacement—together with other mitigations against harms from deployed AI systems—would allow states to reap the economic benefits of diffusing AI inference across their economies without continuing an AI training race that may threaten to overwhelm states with disruptions to their social and economic stability or to their national security.
Technologies needed for inference-only AI chips are already being developed for purely economic reasons, as firms develop model-specific inference chips that serve AI inference much more efficiently than general-purpose chips do. The training capacity of these model-specific inference chips is much lower than that of general-purpose chips and could be made even lower through intentional design. Currently, the economic attractiveness of model-specific chips is limited by the rapid turnover of new models. However, by prohibiting the training of new frontier models, a hardwired pause would increase the economic advantages of these specialized chips and spur innovation in the development of other inference-only chips.
The political palatability of a hardwired pause could be enhanced by its ability to keep delivering key affordances that training-capable chips currently provide, such as commercial inference service on existing models, beneficial scientific and medical research, and strategic insurance against being left behind by defecting states. We discuss ways it might do so, for example by constructing internationally governed scientific preserves where training-capable chips could be used for declared, transparent research workloads, or by permitting states to hold declared and monitored stockpiles of powered-off chips under seal. Another beneficial palatability feature would be the new chips’ lower resource demands, both reducing their environmental impact and ameliorating domestic frictions in the U.S. between data center operators and local communities.
Short-term feasibility of a hardwired pause
Because training new models requires large numbers of training-capable chips, the feasibility of verification is an inherently quantitative question: while it is next to impossible to detect an evader who is using a single computer to train a small AI model, it is far easier to detect an evader who is training a frontier-scale AI model using hundreds of thousands or millions of chips.
Over the last half decade, the computing budgets dedicated to frontier-scale AI research and training have grown at a rapid exponential rate, rising by an order of magnitude every 18 months and already straining the available stock of AI chips, which has also grown exponentially. Consequently, the number of AI chips required to continue that frontier scaling trajectory even into 2028 or 2029 far outstrips the current stock, which itself dwarfs the stock that existed only a few years ago. To research and train a new model that would significantly advance the frontier after a hardwired pause, absent an unforeseen methodological breakthrough, an evader would need to marshal a significant fraction of the world’s total computing capacity for months or years at a time—while pretending to use the same chips for compute-intensive inference service.
As a result, we assess that implementing reasonably effective verification methods would likely be more than sufficient in the short term to guard against covert evasion: secretly training new frontier models while ostensibly adhering to verification procedures. More sophisticated verification methods under development could be implemented as they became available, for added security.
However, verification methods could not by themselves guard against the risk of overt breakout: a state amassing a very large fleet of chips, openly abrogating the pause agreement, and resuming the AI race at a faster pace than before, in an attempt to build and deploy a strategically decisive model before other states could respond.
Because a breakout fleet would likely need to be larger than today’s total world stock of AI chips, overt breakout would not be an immediate threat. But if the stock of AI chips were allowed to continue growing exponentially during a frontier pause, it would fill the world with destabilizing “dry tinder” that could fuel a resumed race. A hardwired pause would defuse this risk by preventing the accumulation of AI training capacity, while permitting a continued rise in inference capacity on approved models.
Durability of a hardwired pause
For a frontier pause to last for a decade or more, it would need to be robust against the possibility of erosion via gains in training efficiency: advances in algorithms and data that have made each unit of computing capacity grow more effective at AI training over time. If these advances continue, they will make it possible to train more capable models with today’s level of training capacity. Thus, a lasting pause could eventually require a reduction over time of the AI training capacity available for covert evasion or overt breakout, at a rate that keeps pace with gains in training efficiency.
To durably guard against covert evasion, states could collaborate to conduct a global census of pre-pause training-capable chips, both to minimize the total amount of undeclared training capacity and to estimate the distribution of unaccounted-for chips. This census would be supported by commercial incentives, as declaration of training-capable chips would be a precondition of using them for transitional inference service. Because AI chips are expensive capital goods that generate a variety of documentary evidence, we assess that it would be possible for a well-conducted census to locate the vast majority of pre-pause chips in agreement states.
To durably guard against overt breakout, states could reduce the amount of total training capacity within their borders, for example by moving most of their pre-pause chips offshore or transferring them to the custody of neutral states or scientific preserves, with the understanding that if they defected other states would prevent them from recovering that training capacity. Once inference-only chips became available, states would be able to reduce their breakout capacity without risking their inference capacity, which could remain within their own territory.
Quantitative assessment
While many states would play important roles in establishing and maintaining a hardwired pause, we focus on the key strategic dynamic between the U.S. and China, the two states that are currently home to the leading AI developers.
We examine various potential sources of post-pause training capacity and estimate the threat posed by each source, for both covert evasion and overt breakout. We assess that the most important potential source of covert evasion risk would be undeclared pre-pause AI chips controlled by either state, and the most important source of overt breakout risk would be the pre-pause stock of training-capable chips retained commercially for transitional inference service. Thus, the most important political determinants of durability would be these states’ eventual success in completing the global census and their eventual willingness to retire or transfer most of their declared pre-pause stock outside their territory. Phasing out the pre-pause stock without disrupting commercial inference service would in turn require the timely production of inference-only chips.
Provided the two challenges identified above could be met before training efficiency advanced by one order of magnitude (meaning that present-day models could be trained with a tenth as much compute), we assess that a hardwired pause would likely be robust to a second order of magnitude of training efficiency gains.
It follows that a hardwired pause, if implemented in the near future, could likely endure for at least a decade, provided that efficiency gains for training models at or near the paused frontier scale did not accrue faster than one order of magnitude every five years (for reference, this rate would approximately match the rate of progress associated with the famous 18-month doubling time of Moore’s Law). Empirical evidence from controlled experiments places the historical rate of efficiency gains at fixed training scale roughly at or below that rate, with more dramatic historical gains unlocked by two breakthroughs (the transformer architecture and Chinchilla balancing) that were complementary to rapid scaling. Because scaling would stop after a pause, as would researchers’ ability to test ideas at frontier scale, post-pause gains could be slower relative to currently prevailing AI race conditions.
Economic implications
An important component of the feasibility of a hardwired pause is its economic palatability. It has been claimed that a pause of frontier AI training would cause serious problems for the economy. In our assessment, a hardwired pause need not do so. The continuing diffusion of existing models could sustain significant AI-related spending and productivity gains even with a pause on frontier training. If the valuations of AI companies decline, the macroeconomic effects could be cushioned by monetary policy. There are concerning signs in the debt financing of the data center build-out, which regulators will need to address regardless of other policy choices. But provided that inference demand sustains data center revenues during a hardwired pause, the pause would not substantially increase the risk of serious financial problems. A hardwired pause could also bring economic benefits by incentivizing companies to further reduce inference costs, leading to savings that are at least partially passed on to consumers. Scaling up inference-only hardware would require upfront development costs, but for certain types of inference-only chips such costs could be more than offset by lower lifetime inference costs.
Remaining governance challenges
A hardwired pause is not a panacea for AI governance. Misuse, malfunction, and societal risks of allowed models would remain issues for governance. Nonetheless, a successful AI training pause could mitigate some of the most severe risks posed by more powerful AI models, including misuse, loss of control, disempowerment, and concentration of power. This includes the risk of frontier AI enabling ubiquitous surveillance—or being used to justify such surveillance as necessary to prevent catastrophic misuse. A hardwired pause also has costs and limitations. It would create new requirements for monitoring hardware production and deployment. Depending on its implementation, it could entrench the market positions of leading companies, requiring regulation of AI developers as government-created oligopolies. On the technical front, under a prohibition of large-scale AI training, security vulnerabilities in models would have to be dealt with in ways other than large re-training runs. Outdated knowledge cutoffs could entrench values and ideological or other biases in models; on the other hand, they could also mitigate risks of loss of control or human disempowerment by ensuring that humans remain more situationally aware than AI systems and by reducing human overreliance on AI systems for moral guidance. Finally, even if a hardwired pause successfully prevented further frontier AI training, it would not address all harms and risks related to current and future AI. Addressing these would require other measures to be adopted, but a pause could at least complement these measures by giving governments and societies more time to do so.
Why states might agree to a pause
The pause willingness assumed in our feasibility analysis could come about in multiple ways. For example, states may eventually judge that the costs of trying to avoid—or of incurring—disruptions or disasters from increasingly capable AI outweigh the perceived strategic benefits of continuing a mutual AI race. Or they may find that the growing cost of advancing the frontier is not worth maintaining a few months’ lead in capabilities over fast followers. If pause willingness were to emerge, the feasibility analysis of the hardwired pause in this report could inform decision making about the type of pause to implement.
Summary: feasibility of a hardwired pause
We assess a durable hardwired pause of a decade or more to be feasible if (1) states cooperate to govern the manufacture of AI chips, (2) states share information to locate pre-pause chips, (3) inference-only chips are developed and manufactured in time to allow for training-capable chips to be phased out, and (4) the rate of training efficiency gains after a pause remains at or below the pre-pause rate.