This is not another open letter
The 2023 pause campaign asked frontier labs to stop for six months and left enforcement largely to goodwill. This working group starts from the failure of that approach. It asks a narrower question: if major powers had already decided to pause, could they make the commitment mutually verifiable?
That distinction matters. The paper does not establish the case for a pause, predict that Washington and Beijing will accept one, or offer a treaty ready for signature. Its authors deliberately bracket those questions. What they supply is an engineering and governance study of a hypothetical ten-year stop.
That makes the report more serious than a petition and less immediate than a policy plan. Its value is in forcing the pause debate out of slogans and into inventories, supply chains, inspection rights and replacement hardware.
The pause lives in hardware
The core design freezes frontier training while preserving access to approved existing models. Participating states would prohibit new frontier training, create a whitelist of models judged safe enough for deployment, and allow those models to run on chips that are efficient at inference but impractical for training a new frontier system.
The report points to model-specific integrated circuits as a proof of concept. These chips hardwire a model's architecture and weights into silicon. Their lack of flexibility is normally a drawback. Under a pause, that limitation becomes the security property: stealing the chip gives an actor a fast way to run the approved model, not a general accelerator for training the next one.
Production of flexible training accelerators would stop or fall sharply. Governments would conduct a global census of the installed base, monitor remaining chips, and recover large fleets through transfer, trade-in or buy-back programmes. In the report's staged transition, inference-only hardware gradually displaces the training-capable stock.
Why the chip swap is the strongest idea here
Software controls are easy to change after the inspector leaves. Hardware supply chains have factories, packaging plants, power demands and a small number of firms that can make frontier accelerators. Those chokepoints are what the paper tries to govern.
The swap also gives the pause a product story instead of only a prohibition. Existing services can continue. Manufacturers can sell a new class of inference hardware. Operators get cheaper, more efficient chips for a model list that is no longer changing every few months. The authors argue that the economics of specialization become better once the frontier is frozen.
Their cost sketch is enormous but not abstract. The paper estimates about 25 million AI accelerators in the existing fleet at an average purchase price of roughly $20,000, or $500 billion in acquisition value. It doubles that to $1 trillion as an illustrative buy-back budget to cover missing inventory and premiums. That is not a quote or a forecast. It is an order-of-magnitude admission that a serious pause means compensating owners, not simply issuing a ban.
The sentence that keeps the report honest
The working group did not assess whether a pause is desirable or likely. It imagines a leader saying international counterparts already want one and asking advisers to make it work.
That assumption clears away the hardest political problem: getting rivals to believe the frozen frontier benefits them more than a secret sprint. Verification can reduce fear of cheating. It cannot create the original preference to stop.
The plan also concentrates unusual power in the institutions that manage the whitelist, inspect facilities and govern strategic compute. A chip census avoids monitoring every prompt, which is a genuine advantage over content surveillance. But controlling who can manufacture, own and operate advanced accelerators is still a deep intervention in industry and research. The paper treats that as a design problem; governments would experience it as a sovereignty problem.
The loopholes are dynamic
A ten-year pause is a long time in compute. Training methods get more efficient. Old chips spread. Small clusters become more capable. A model-specific chip can safely serve only the model it was designed around, while demand, vulnerabilities and deployment rules can change.
The report recognizes these pressures. It proposes censuses, inspections, controlled scientific preserves, monitoring of residual flexible chips and procedures for overt breakout or covert evasion. It also argues that choking off commercial frontier training would slow the research effort devoted to making training cheaper.
That may be true, but it is not a lock. The regime's durability depends on detecting undeclared hardware and adapting faster than algorithmic efficiency improves. The physical bottleneck buys observability. It does not remove competition.
A blueprint for after the political earthquake
The headline claim is feasibility. A more precise reading is conditional feasibility: if major powers want a long pause, if they accept intrusive verification, if they can inventory the flexible hardware, and if the transition to restricted inference chips works at scale, then today's AI products need not vanish when frontier training stops.
That is still useful work. Policy debates often fail because the emergency brake has no mechanism attached. This report draws the mechanism in detail.
But the chip swap is not the agreement. It is what an agreement would operate. The hard part remains the moment when every serious actor decides that keeping the next model untrained is safer than being the only one that stopped.
Sources
- [1] Working Group on AI Pause Feasibility — “The Feasibility of a Hardwired Pause of Frontier AI Training” (v1.0.1, Oct 10, 2026)Read source
- [2] UC Berkeley News — “A global, hardwired pause of frontier AI training is feasible, says new report” (Oct 9, 2026)Read source