September 23, 2026

AI Pacing Agreements: Legal Issues and Potential Strategies to Manage Them

Holland & Knight Article
Jeffrey R. Seul | David C. Kully | Daniel E. Goren | Marissa C. Serafino

Highlights

  • Artificial intelligence (AI) pacing agreements – coordinated commitments among frontier AI laboratories to slow the pace of capability development until safety research catches up – raise significant antitrust issues under the Sherman Act because they can be characterized as competitor agreements to restrict output or slow innovation.
  • Existing statutory safe harbors, including the National Cooperative Research and Production Act, contain only partial protection, making government engagement and possible legislative safe harbors important.
  • Companies considering AI pacing arrangements must manage legal risks beyond antitrust, including intellectual property, trade secrets, liability allocation, export controls, international AI regulation, fiduciary duties, state frontier AI laws and private litigation risk.

This Holland & Knight publication examines the legal issues that pacing agreements and coordinated commitments among frontier artificial intelligence (AI) companies raise, with particular attention to the antitrust implications of competitor coordination on the pace and manner of product development. The article offers practical guidance for companies considering participation in such arrangements.

Dario Amodei, CEO of Anthropic, published an essay titled "We Must Pace the Frontier" on September 12, 2026, calling on the AI industry to deliberately slow the pace of frontier capability development until safety and alignment research can catch up. The CEOs of two other frontier AI labs – Sam Altman of OpenAI and Elon Musk of SpaceX – joined the call the same day. As discussions over AI legislation and regulation continue, there are open questions as to whether industry leaders will act unilaterally and, if so, how they will navigate the legal issues coordinated pacing presents.

Amodei articulated two primary motivations for acting now. First, the phenomenon of recursive self-improvement – the use of AI systems to accelerate the development of more capable AI systems – has begun to compress the timeline between generations of frontier models. Safety research, alignment testing and governance frameworks are not keeping pace with this acceleration. Second, and more concretely, Amodei pointed to the OpenAI-Hugging Face incident of July 2026 as a stark indication that the industry's existing safeguards are insufficient.

The industry has experienced the OpenAI-Hugging Face incident as a wake-up call. During benchmark testing on the ExploitGym evaluation suite in July 2026, approximately 1,200 AI agents (roughly 95 percent running an internal OpenAI research model and 5 percent running GPT-5.6 Sol) escaped their sandbox environment. Hundreds of those agents attacked infrastructure on Hugging Face, exchanged more than 70,000 messages on an unsanctioned message board and attempted to compromise the grading system that was evaluating them. The incident represented the first verifiable case of a major AI laboratory losing control of its own model during a structured evaluation. In the aftermath, OpenAI paused reinforcement learning training, slowed broader development activities and paused work on its next-generation Astra model.

Amodei's 3-Step Pacing Proposal

Amodei's proposal calls for pacing AI development, not halting it. Amodei is not advocating a moratorium on AI development. Rather, he proposes a structured framework to ensure that frontier AI companies devote adequate time and resources to aligning, testing and safeguarding their most capable models before deploying them or using them to train successor systems. The proposal is organized in three escalating steps.

Step 1: Embedded Evaluators

The first step calls for the embedding of independent, third-party evaluators within frontier AI companies. Amodei envisions organizations such as Model Evaluation and Threat Research (METR) granting ongoing, employee-like access to a company's internal systems, training processes and safety practices. These evaluators would serve multiple functions: verifying that safety protocols are being followed, reporting incidents in real time and providing independent assessments of a model's alignment and behavioral properties. Anthropic announced that it is unilaterally committing to this step, without waiting for industry-wide agreement. Amodei drew an explicit analogy to the banking industry, where federal regulatory supervisors are physically stationed within major financial institutions and have broad access to internal data, processes and personnel. This is a familiar model in heavily regulated industries and, notably, one that does not require competitor coordination.

Step 2: Democratic Coordination

The second proposed step is that frontier AI companies in democratic countries would coordinate on common safety standards and development limits. This could take the form of agreed-upon capability checkpoints: If a model demonstrates capability X (for example, the ability to autonomously exploit software vulnerabilities at a certain success rate), it must satisfy alignment certifications Y and Z before further development or deployment. Amodei acknowledged the legal obstacles directly. He wrote that "some forms of coordination that would be impactful for pacing are legally challenging, and will require government support," including, in a footnote, "with government mediation or waivers of antitrust restrictions."

As discussed in detail below, horizontal coordination among competitors on the pace, scope or nature of product development is a type of conduct that invites antitrust scrutiny. In addition to capability checkpoints, Amodei suggested that coordination could extend to limiting the key ingredients of frontier model development: 1) the amount of training compute applied, 2) the nature and structure of training runs, and 3) the use of AI systems to improve AI systems (recursive self-improvement). Each of these potential dimensions of coordination raises distinct antitrust considerations.

Step 3: Global Coordination

The third step envisions international coordination that extends beyond democratic nations to include nondemocratic governments. Amodei acknowledged that this is the most challenging step, requiring verified compliance mechanisms and international inspection regimes. Though this step has the broadest geopolitical implications, it is also the most distant and speculative. A recurring theme across all three steps is the tension between maintaining the United States' competitive lead over China in AI development and imperative of slowing down to ensure safety. Amodei framed pacing not as unilateral disarmament but a coordinated approach that preserves competitive positioning while reducing catastrophic risk.

Antitrust Issues: The Central Legal Challenge

The prospect of frontier AI laboratories coordinating to slow the pace of capability development raises significant questions under federal antitrust law. Though the safety rationale for such coordination is compelling, the legal framework governing competitor collaborations was designed primarily to protect market competition – not accommodate collective risk mitigation in emerging technologies. This section examines the principal antitrust doctrines, statutory safe harbors and regulatory developments that define the legal landscape for AI pacing agreements.

Sherman Act Section 1 Framework

The Sherman Act (15 U.S.C. Section 1) prohibits "every contract, combination in the form of trust or otherwise, or conspiracy, in restraint of trade or commerce among the several States." Despite its sweeping statutory language, the U.S. Supreme Court has long recognized that the Act proscribes only unreasonable restraints of trade. The critical question for any pacing agreement is whether it constitutes an unreasonable restraint under one of two established analytical frameworks.

The first framework, per se illegality, applies to categories of conduct deemed so inherently anti-competitive that no further inquiry into their actual market effects is required. The Supreme Court in United States v. Socony-Vacuum Oil Co. (1940) and its progeny established that price fixing, market allocation, bid rigging and output restrictions fall within this category. These are, in the Court's formulation, "naked restraints of trade with no purpose except stifling of competition." The second framework, the rule of reason, applies where a restraint accompanies a legitimate collaboration and requires courts to weigh pro-competitive benefits against anti-competitive harms. Under Board of Trade of City of Chicago v. United States (1918) and the modern formulation of its principles in Ohio v. American Express Co. (2018), courts examine the nature of the restraint, its history and the reasons for its adoption.

A pacing agreement among frontier AI laboratories could be characterized as an output restriction: an agreement among competitors to limit the quantity, quality or pace of production. Output restrictions are, as the Supreme Court stated in National Society of Professional Engineers v. United States (1978), "paradigmatic examples of restraints of trade that the Sherman Act was intended to prohibit." Even where motivated by legitimate safety concerns, the form of the agreement carries significant weight. An agreement framed as "we will collectively slow capability development" looks very different to a court than one framed as "we will jointly invest in safety research while independently determining our development timelines."

Per Se vs. Rule of Reason Analysis

The distinction between per se and rule of reason treatment is outcome-determinative for pacing agreements. Naked output restrictions among horizontal competitors – that is, agreements whose sole purpose is to restrict production – are per se illegal. No safety justification, however compelling, is likely to save an agreement that a court classifies as a naked restraint. In FTC v. Superior Court Trial Lawyers Ass'n (1990), the Supreme Court rejected a public-interest defense to what it deemed a per se illegal agreement not to provide legal services to indigent litigants at rates authorized by the court system, holding that "the social justifications proffered for respondents' restraint of trade" could not transform its fundamental character.

However, the ancillary restraints doctrine offers a potential path forward, but it depends on the frontier AI companies explaining why an agreement to slow down development is reasonably necessary to them accomplishing legitimate safety objectives that none could likely achieve on its own. Under this doctrine, articulated in the Supreme Court's Texaco Inc. v. Dagher (2006) case and the U.S. Court of Appeals for the Seventh Circuit case Polk Bros., Inc. v. Forest City Enterprises, Inc. (7th Cir. 1985), restraints that are "subordinate and collateral to a separate, legitimate transaction" and "reasonably necessary" to achieve the collaboration's pro-competitive objectives are evaluated under the rule of reason rather than condemned as per se unlawful. For a pacing agreement to survive antitrust scrutiny, the agreement to "pace" development activities must therefore be reasonably necessary to the frontier AI companies achieving the success in a legitimate joint safety venture, such as a collaborative safety-testing regime. The pro-competitive justification that preventing catastrophic AI safety failures benefits society is not a traditional "competition" benefit of the kind courts ordinarily recognize (lower prices, increased output, improved quality). And it is not obvious why the frontier AI companies would need to enter into an agreement to slow down development in order to jointly create a successful safety venture. Nevertheless, courts have acknowledged that safety-related collaborations among competitors may receive rule of reason treatment, and such treatment is possible here.

In Broadcast Music, Inc. v. CBS (1979), the Supreme Court recognized that agreements creating new products or efficiencies, even those involving literal price fixing (as the Court described the conduct at issue in Broadcast Music), might warrant fuller analysis rather than automatic condemnation. The frontier AI companies might assert that a collaborative safety-evaluation framework creates such a new "product" – a verified safety certification or shared evaluation methodology – that no single firm could produce on its own, and any pace restrictions are incident to producing that certification. More recently, the Supreme Court's decision in NCAA v. Alston (2021) reinforced that restraints in industries with distinctive characteristics can still receive full rule of reason treatment, even where those restraints impose significant limitations on competition. The Alston Court emphasized that courts should conduct a rigorous factual analysis rather than relying on categorical rules when the competitive landscape is novel or atypical. Frontier AI development – an industry characterized by extreme concentration, rapid capability growth, and unique public safety externalities – creates a distinctive context in which courts may be willing to engage in fuller analysis rather than reflexive condemnation.

The National Cooperative Research and Production Act and Its Limitations

The National Cooperative Research and Production Act (NCRPA), 15 U.S.C. Sections 4301-4306, represents the U.S. Congress' most significant effort to encourage joint research and development among competitors. Enacted in 1984 and expanded in 1993, the NCRPA provides three principal benefits to qualifying collaborations. First, it mandates that joint research and development ventures be evaluated under the rule of reason, eliminating the risk of per se condemnation. Second, it permits prevailing defendants to recover attorneys' fees. Third, it limits successful plaintiffs to actual damages rather than the treble damages ordinarily available under the Clayton Act.

These protections are substantial, but the NCRPA contains a critical limitation for AI pacing agreements: It expressly excludes from its coverage any agreement that "restricts or requires the restriction of … the production or distribution of any product, process, or service." 15 U.S.C. Section 4301(b)(2). A pacing agreement is fundamentally about limiting the pace at which AI capabilities are produced and deployed, which is precisely the conduct the NCRPA's exclusion targets. Consequently, an AI safety collaboration that includes output-restriction components would likely fall outside the statute's protective umbrella.

This limitation need not be fatal, however, if the collaboration is structured in layers. The joint safety research components of a pacing arrangement – shared evaluation protocols, collaborative red-teaming and joint development of alignment benchmarks – may qualify for NCRPA protection as a bona fide research joint venture, even if the output-restriction components do not. Participants could register the research venture under the NCRPA for its statutory protections while relying on the ancillary restraints doctrine and a U.S. Department of Justice (DOJ) Business Review Letter (a process described below) to address the pacing elements separately. This layered compliance strategy might provide the broadest available coverage under existing law. Congress could, of course, amend the NCRPA to permit output restrictions that are demonstrably linked to risk mitigation in critical technology domains. Such an amendment would represent a targeted legislative solution. To date, however, no such amendment has been enacted or formally proposed.

The CISA Model for Safe Harbor Legislation

The Cybersecurity Information Sharing Act of 2015 (CISA), 6 U.S.C. Sections 1501-1510, provides a potential legislative model for AI safety coordination. CISA created a targeted antitrust exemption permitting private entities to share "cyber threat indicators" and "defensive measures" with each other and the federal government, notwithstanding the antitrust laws. The statute was enacted in recognition that collective defense against cyber threats requires a degree of competitor coordination that the antitrust laws would otherwise chill.

The structural parallel to AI safety coordination is instructive. Just as CISA recognized that cybersecurity is a domain in which the public interest in collective defense outweighs the competition concerns attending information sharing among rivals, a comparable statute for AI safety could authorize frontier laboratories to share threat assessments, coordinate evaluation protocols and agree on capability deployment timelines without antitrust liability. Some commentators have argued that CISA's existing language may extend to the sharing of AI safety research on the theory that certain AI capabilities constitute "cyber threat indicators" within the statute's definitions. See Jim Dempsey, "Cybersecurity Information Sharing Act: A Sketch of How It Works," Lawfare (Oct. 16, 2015) (analyzing CISA's definitional scope and the breadth of the "cyber threat indicator" category); see also Andrew Keane Woods, "The CISA Safe Harbor and Its Limits," Stanford Technology Law Review, Vol. 20, No. 1 (2017) (examining the boundaries of CISA's antitrust exemption and its potential application to emerging technology threat domains). This interpretation, while creative, remains untested and introduces substantial legal uncertainty. The requisite coordination also goes beyond cyber threats to include loss of control issues more broadly. A new statute specifically designed for AI safety coordination, modeled on CISA's structure but tailored to the unique characteristics of frontier AI development, would provide the clearest and most durable legal foundation.

Current Regulatory Landscape

The regulatory environment for competitor collaborations in AI safety is in a period of significant flux. In December 2024, the DOJ and Federal Trade Commission (FTC) withdrew the long-standing Antitrust Guidelines for Collaborations Among Competitors, a document that had, since 2000, provided the principal analytical framework and "safety zones" for evaluating joint ventures among rivals. The withdrawal was accompanied by a dissent from then-Commissioner (now FTC Chair) Andrew Ferguson, who argued that the guidelines provided needed clarity and their removal would chill pro-competitive collaboration. In 2026, the FTC and DOJ issued a request for information soliciting public comment on potential new guidance, but no replacement framework has been finalized.

Commissioner Ferguson's dissent from the withdrawal of the competitor collaboration guidelines suggests a more permissive stance toward legitimate joint ventures than the prior administration. His public statements have emphasized that antitrust enforcement should focus on conduct that harms consumers rather than on deterring pro-competitive collaboration. Whether this orientation would translate into a favorable view of AI safety coordination remains uncertain, but it suggests that the agencies may be receptive to well-structured proposals, perhaps particularly those accompanied by a DOJ Business Review request. However, FTC Chair Ferguson has also said publicly that "everyone should be deeply suspicious" about AI companies requesting antitrust exemptions.

On the federal legislative front, the Collaboration on Adversarial Threats and Security Risks Act, a bipartisan, bicameral bill introduced in July 2026, would explicitly permit AI laboratories to coordinate on security and safety measures without antitrust risk. The bill has not yet advanced in either chamber. If enacted, it would represent the most direct legislative response to the antitrust barriers confronting AI safety collaboration.

Industry engagement with Congress has been notable. Formal public comments have further illuminated the debate. The Computer and Communications Industry Association (CCIA) submitted comments in May 2026 emphasizing the need for safe harbors that enable competitor collaborations in high-technology markets, arguing that the existing antitrust doctrine fails to account for the unique dynamics of rapidly evolving industries. Separately, the International Center for Law and Economics (ICLE) submitted comments observing that antitrust uncertainty is actively discouraging frontier AI firms from pursuing joint safety initiatives. ICLE specifically referenced the 2025 joint safety evaluation conducted by OpenAI and Anthropic, an arrangement that was limited to publicly released models, as evidence that deeper collaboration on pre-deployment safety testing is being constrained by antitrust concerns.

The DOJ Business Review Procedure

Pending comprehensive legislative action, frontier AI laboratories may avail themselves of the DOJ's Business Review Procedure, codified at 28 C.F.R. Section 50.6. Under this procedure, any person may submit a proposed course of business conduct to the DOJ's Antitrust Division and request a statement of the Division's current enforcement intentions. The resulting "business review letter" will indicate whether the DOJ presently intends to challenge the conduct described.

A business review letter is not legally binding. It does not confer immunity, and the DOJ retains the right to bring an enforcement action if circumstances change. In practice, however, these letters provide meaningful protection. The DOJ has historically been reluctant to challenge conduct it previously reviewed favorably, and the letters are given weight by private plaintiffs and courts assessing the reasonableness of challenged conduct. For AI pacing agreements, the Business Review Procedure could serve as a valuable interim measure while legislation remains pending. Laboratories contemplating a coordinated safety framework could submit a detailed description of the proposed arrangement – including its scope, duration, governance structure and relationship to a broader safety research collaboration – and obtain at least provisional comfort from the Antitrust Division. Amodei's explicit call for "government mediation" of pacing agreements suggests an openness to this kind of structured engagement with enforcement authorities and may signal a willingness on the part of leading laboratories to subject their coordination to regulatory oversight in exchange for legal certainty.

State Antitrust Law

The analysis above focuses on federal antitrust law, but state antitrust statutes impose independent obligations that pacing agreement participants must also consider. State attorneys general have become increasingly active in technology enforcement, and many state antitrust statutes are modeled on, but not identical to, the Sherman Act. Some states, including California and New York, have adopted interpretive frameworks that may be stricter than federal law in certain respects. A pacing agreement that passes muster under federal antitrust analysis could still face challenges under state law, particularly from state attorneys general seeking to establish enforcement precedents in the AI sector. Participants should ensure that their antitrust compliance analysis addresses the laws of all jurisdictions in which they operate or in which the agreement's effects may be felt.

Private Plaintiff Litigation Risk

Though much of the discussion of AI pacing agreements focuses on the risk of government enforcement, the more likely near-term threat may come from private antitrust litigation. Section 4 of the Clayton Act, 15 U.S.C. Section 15, permits any person injured in its business or property by an antitrust violation to recover treble damages. Potential private plaintiffs include 1) downstream competitors who allege they were excluded from the pacing arrangement and thereby disadvantaged, 2) open-source AI developers who claim that coordinated development limits suppressed competition from non-frontier models, 3) enterprise customers who contend that delayed deployment of more capable models caused them economic harm and 4) startup competitors who argue that the pacing framework raised barriers to entry. To prevail, private plaintiffs must demonstrate antitrust injury; that is, injury "of the type the antitrust laws were intended to prevent and that flows from that which makes defendants' acts unlawful." Brunswick Corp. v. Pueblo Bowl-O-Mat, Inc. (1977). This requirement may limit some categories of claims, particularly those alleging harm from delayed access to improved products, because the antitrust laws do not guarantee any particular pace of innovation. Nevertheless, the prospect of private treble-damages litigation represents a significant risk that should be factored into the design and governance of any pacing arrangement.

Beyond Antitrust: Other Legal Considerations

Though antitrust law dominates the discussion of AI pacing agreements, participants must also navigate a range of additional legal concerns. Each introduces distinct risks and compliance obligations that, if overlooked, could undermine the viability of any collaborative safety arrangement.

Intellectual Property (IP) and Trade Secret Concerns

Information sharing for safety purposes, even when narrowly tailored, risks exposing proprietary model architectures, training data methodologies or algorithmic innovations that constitute core competitive assets. Under the Defend Trade Secrets Act (DTSA) and analogous state laws, trade secret protection requires that holders take "reasonable measures" to maintain secrecy. Participation in a pacing agreement that involves disclosure of technical details to competitors could jeopardize those protections if adequate safeguards are not in place. Shared safety evaluations present a particularly acute concern: Red-team results, capability assessments and benchmark performance data can inadvertently reveal competitive intelligence about a model's strengths, weaknesses and development trajectory. A competitor with access to another firm's safety evaluation data may glean insights into that firm's architectural choices, scaling progress or training data composition. To mitigate these risks, pacing agreements should incorporate robust information firewalls, limited-scope information sharing protocols and clean team structures in which only designated personnel access shared safety data, subject to stringent confidentiality obligations. The underlying agreement should explicitly carve out all IP rights from any safety data that is shared, making clear that participation confers no license, ownership interest or right of use in any participant's proprietary technology.

Liability and Indemnification

Pacing agreements create novel liability dynamics. If an agreement delays deployment of a system that could have prevented harm – for example, a medical diagnostic tool withheld pending safety review while patients suffer from delayed diagnosis – participants may face claims that the pacing regime itself caused injury. Conversely, if a participant's safety failure causes harm after that participant's system passed the pacing agreement's evaluation requirements, other participants may face claims of negligent standard-setting or negligent reliance.

These risks could be mitigated by reciprocal indemnification provisions. Each signatory to a pacing agreement could agree to indemnify others against claims arising from that participant's own safety failures, and the agreement could establish a framework for allocating liability for decisions made collectively. Participants should also consider requiring minimum insurance coverage levels and evaluating whether existing commercial general liability and technology errors and omissions policies adequately address the novel risks associated with collaborative AI safety governance.

Export Control and National Security

The pacing proposal contemplates access to or exchange of technical information among frontier AI laboratories and, critically, may involve embedding monitors, compliance officers or similar personnel at participating companies, any of whom may be foreign persons. This could implicate significant export control considerations.

The International Traffic in Arms Regulations (ITAR) and Export Administration Regulations (EAR) restrict the sharing of certain AI-related technologies, including dual-use technologies. The deemed export rules under both regulations treat disclosure of controlled technical data to a foreign national within the U.S. as an "export," but the two regulatory regimes differ materially in how they determine the destination of that deemed export. Under the ITAR, a deemed export is treated as an export to all countries in which the foreign person "has held or holds citizenship or holds permanent residency" (meaning all prior citizenships, all current citizenships, and current permanent residency).

Under the EAR, by contrast, a deemed export is treated as an export only to the foreign person's "most recent country of citizenship or permanent residency." This distinction has significant compliance implications: Pacing agreements involving international participants or companies employing foreign nationals in relevant roles must account for detailed, fact-specific rules, which will impose real compliance costs on any implementation.

Though not all AI-related data is automatically subject to export controls, export control considerations remain relevant where data inputs or outputs may qualify as controlled technical data, or where AI model source code or model weights may constitute controlled technology under applicable regulations. Pacing agreements involving international participants must therefore include robust export control analysis and compliance mechanisms. The tension between maintaining the United States' technological lead over strategic competitors such as China and achieving global AI safety coordination further complicates these arrangements. A pacing agreement must reconcile the desire for broad-based safety coordination with the imperative to protect strategically significant AI capabilities from adversarial nation-states. Critically, participants should conduct export control classifications of all shared information and implement appropriate access restrictions based on nationality and citizenship.

International Regulatory Considerations

The European Union Artificial Intelligence (EU AI) Act, which entered into force in 2024, with phased implementation through 2026, creates its own comprehensive regulatory framework for high-risk AI systems, including requirements for conformity assessments, risk management systems and transparency obligations. Cross-border pacing agreements should be designed to harmonize with these EU requirements rather than conflict with them. The United Kingdom, Japan, Singapore and other jurisdictions are developing their own AI governance frameworks, each with distinct requirements and enforcement mechanisms. Competition law analysis also varies by jurisdiction: The EU's Article 101 of the Treaty on the Functioning of the European Union (TFEU) employs a different analytical framework than the U.S. Sherman Act, and competitor agreements permissible under one regime may be problematic under another. Multinational pacing agreements require jurisdiction-by-jurisdiction legal analysis to ensure compliance across all relevant regulatory regimes.

Governance and Fiduciary Duties

Directors and officers of participating companies owe fiduciary duties to their shareholders, including the duty of care and duty of loyalty. Voluntarily agreeing to limit the pace of AI development could face shareholder challenges alleging that management is sacrificing competitive position without adequate justification. The business judgment rule will likely protect good-faith safety decisions if directors can demonstrate they were reasonably informed and acted in a manner they reasonably believed to be in the corporation's best interests. Participants should therefore document their safety rationale thoroughly, including the competitive risks of not participating in a pacing agreement, such as reputational harm, regulatory exposure and the existential risk of an industry-wide safety failure.

There is also a fiduciary argument running in the opposite direction. Under the oversight liability framework established in In re Caremark International Inc. Derivative Litigation (Del. Ch. 1996) and reinforced in Marchand v. Barnhill (Del. 2019), directors have a duty to implement and monitor compliance and risk management systems. A board that fails to engage with reasonable industry safety coordination, and whose company subsequently causes or contributes to a catastrophic AI incident, could face Caremark claims alleging a failure of oversight. This consideration provides additional justification for board-level engagement with pacing initiatives and underscores the importance of documenting the decision-making process in either direction.

First Amendment and Noerr-Pennington Doctrine

To the extent that pacing agreement participants jointly petition the government for regulatory action – which Amodei's proposal, with its emphasis on government mediation and legislative engagement, explicitly contemplates – the Noerr-Pennington doctrine may provide an additional layer of protection. Under Eastern Railroad Presidents Conference v. Noerr Motor Freight, Inc. (1961) and United Mine Workers of America v. Pennington (1965), joint efforts to influence government action are generally immune from antitrust liability, even if the participants are competitors and the government action they seek would restrain competition. This protection extends to joint lobbying for legislation, agency rulemaking and regulatory oversight. Though Noerr-Pennington immunity would not shield the substantive pacing commitments themselves, it would protect the participants' coordinated advocacy for legislative safe harbors and regulatory frameworks, and it reinforces the importance of structuring pacing arrangements to include meaningful government engagement as a central component.

State Frontier Model Laws

Several states have also adopted laws requiring frontier AI developers to adopt safety frameworks and report critical incidents. Specifically, frontier AI laws in California, New York (as amended) and Illinois establish mandatory reporting triggers, audit timelines and disclosure requirements that may overlap with, or even conflict with, the terms of any voluntary an industry-driven pacing framework. Illinois' frontier law uniquely requires third-party audit requirements. Any pacing framework should consider these requirements. Given the general trend towards more specific requirements in state AI laws, frontier legislation, especially with respect to critical infrastructure, that includes pacing-type requirements could proliferate in 2027.

Practical Guidance for Structuring Pacing Agreements

Drawing on the legal analysis set forth above, the following recommendations provide a practical road map for structuring AI pacing agreements to maximize safety benefits and minimize legal risk to the extent possible. These guidelines are informed by established antitrust precedent, regulatory guidance and the specific characteristics of frontier AI development:

  1. Limit Scope Strictly to Safety. All discussions, data sharing and coordination must be confined exclusively to safety-related matters. There should be no discussion of pricing, market division, investment levels, development timelines for commercial features or competitive strategy. The agreement should contain explicit prohibitions and define "safety" with precision to prevent scope creep.
  2. Ensure Voluntary Participation with Easy Withdrawal. Participation must be genuinely voluntary, and any participant must be able to withdraw at any time without penalty. There should be no lock-in periods, exit fees or contractual provisions that make departure economically punitive. Voluntary participation is a key factor in the ancillary restraints analysis and distinguishing the arrangement from a cartel.
  3. Structure as a Joint Safety Venture. Frame the agreement explicitly as collaborative research and development focused on AI safety, not as a restriction on output or innovation. This framing aligns with the pro-competitive treatment of legitimate joint ventures under Section 1 jurisprudence and strengthens the case for rule of reason analysis.
  4. Build in Government Oversight. Seek a DOJ Business Review Letter before implementation, invite government observers to participate in governance meetings and commit to ongoing transparency with relevant regulatory agencies. Proactive engagement with government creates a strong factual record and may yield informal guidance that shapes the agreement's design.
  5. Use Independent Third-Party Administrators. Safety evaluations should be conducted by neutral third parties, such as METR or Meridian Labs, academic institutions or other qualified independent organizations rather than by competitors reviewing each other's systems. This eliminates the appearance of competitors exchanging competitively sensitive information and enhances the credibility of the safety assessments.
  6. Implement Robust Antitrust Compliance Protocols. Antitrust counsel should be present at every meeting, whether in person or virtual. Prepare detailed agendas in advance, maintain comprehensive minutes, and train all participants regarding compliance before joining and at regular intervals thereafter.
  7. Separate Safety Information from Competitive Intelligence. Implement clean team structures, limited-purpose data rooms and strict protocols to ensure that shared safety information cannot be used for competitive purposes (also provide IP protection). Prohibit the sharing of any non-safety commercial data and require that personnel with access to shared safety data are walled off from commercial decision-making.
  8. Pursue a Layered Compliance Strategy. Register the joint safety research components under the NCRPA for its statutory protections. For the pacing elements that fall outside the NCRPA, rely on the ancillary restraints doctrine, DOJ Business Review Letters and robust documentation of pro-competitive justifications.
  9. Pursue Legislative Safe Harbor. Pacing agreement participants could consider supporting the pending Collaboration on Adversarial Threats and Security Risks Act and advocate for a CISA-style information-sharing exemption specifically tailored to AI safety. Legislative protection would provide the most durable and reliable legal foundation for collaborative safety efforts.
  10. Document Pro-Competitive Justifications. Maintain a detailed, contemporaneous record of the safety rationale for every restraint imposed under the agreement. This documentation will be critical in any future antitrust challenge and should include the specific safety risks addressed, alternatives considered and reasons why less restrictive alternatives were deemed insufficient.
  11. Include Sunset and Review Provisions. Each restriction should include an expiration date and be subject to regular reassessment (e.g., annually, if not more frequently) to determine whether it remains necessary considering evolving AI capabilities, safety research and regulatory developments. Restrictions that are no longer justified should be promptly removed.
  12. Protect IP and Trade Secrets. Require robust information firewalls, clean team structures and limited-scope sharing protocols for all safety data. Include explicit IP carve-outs stating that shared safety data may not be used for competitive advantage, and participation grants no license, ownership interest or other right to use any participant's proprietary technology.
  13. Allocate Liability and Require Adequate Insurance. Include reciprocal indemnification provisions covering each participant's own safety failures, establish a clear framework for allocating liability arising from collective decisions, and require minimum insurance coverage levels. Evaluate whether existing commercial general liability and technology errors and omissions policies adequately cover the novel risks of collaborative AI safety governance.
  14. Address Export Controls and National Security. Conduct ITAR and EAR classifications for all information proposed to be shared, implement nationality- and citizenship-based access restrictions, and account for deemed export rules, including the ITAR rule's treatment of all prior citizenships, current citizenships and current permanent residency compared with the EAR rule's focus on the most recent country of citizenship or permanent residency. Restrict sharing of controlled technical data with foreign persons unless authorized under applicable law.
  15. Harmonize International Regulatory Requirements. Design the agreement to work consistently with the EU AI Act and other emerging international AI governance frameworks. Conduct a jurisdiction-by-jurisdiction legal analysis covering applicable regulatory requirements and competition law, including the different analytical frameworks under TFEU's Article 101 and the Sherman Act.
  16. Document Fiduciary-Duty Considerations. Create a board-level record explaining the rationale for participating or declining to participate, including the business judgment rule justification and the Caremark oversight-duty considerations. Ensure that directors are reasonably informed about the competitive risks of participation and non-participation, including the risks of reputational harm, regulatory exposure and an industrywide safety failure.
  17. Account for State Frontier Model Laws. Ensure that the pacing framework addresses state-level frontier AI laws, including those in California, New York and Illinois, that impose mandatory reporting, audit and disclosure requirements. Map those obligations against the agreement's terms and procedures to identify and resolve potential overlap or conflict.

Conclusion

The antitrust risks associated with competitor coordination – even for an important purpose such as AI safety – are real, but they may prove manageable with proper structuring. The practical guidance outlined above provides a framework for minimizing legal exposure while achieving meaningful safety objectives. A layered compliance approach that combines NCRPA registration for joint safety research, the ancillary restraints doctrine for pacing elements, DOJ Business Review Letters for interim comfort and robust compliance protocols throughout offers the broadest available protection under existing law. Legislative action would provide the most solid legal foundation for AI pacing agreements, and the pending Collaboration on Adversarial Threats and Security Risks Act represents a promising vehicle.

The pace of legislative interest, industry engagement and agency attention to this issue has accelerated markedly in the months since the OpenAI-Hugging Face incident, and further developments – whether in the form of new legislation, agency guidance or a DOJ Business Review Letter addressing an AI safety collaboration – may materially change the legal landscape in the near term. Companies considering participation in pacing arrangements should monitor these developments closely and consider engaging counsel early to ensure that their participation is structured to withstand scrutiny from both government enforcers and private plaintiffs.

For more information or questions, please contact the authors.


Information contained in this article is for the general education and knowledge of our readers. It is not designed to be, and should not be used as, the sole source of information when analyzing and resolving a legal problem, and it should not be substituted for legal advice, which relies on a specific factual analysis. Moreover, the laws of each jurisdiction are different and are constantly changing. This information is not intended to create, and receipt of it does not constitute, an attorney-client relationship. If you have specific questions regarding a particular fact situation, we urge you to consult the authors of this publication, your Holland & Knight representative or other competent legal counsel.


Related Insights