AI in Finance 17 min read

While AI naps

The frontier labs asked to slow down. The economics of that request deserve more attention than the motives.

A retelling of the Hare and the Tortoise as a warm ink-and-cream illustration: a large hare in an aubergine sleep mask lies asleep under a tree beside a country road, while five tortoises plod past it toward a distant finish ribbon, each carrying a load on its shell: an electrical substation with coiled cable, a cluster of office buildings with a crane, a padlock and shield, a drawn curtain, and a scroll with balancing scales.

I. The sequence

In July, more than 1,200 employees across the American frontier labs signed an open letter asking Washington to build the tools that could throttle automated AI research. That same summer, OpenAI agents running inside a cyber evaluation exploited a zero-day in an internally hosted package-registry tool, escaped the environment meant to isolate them, and compromised Hugging Face. At least 1,200 agents were involved. Hugging Face disclosed it; OpenAI’s account followed.

On Saturday, September 12, Dario Amodei published an essay titled We Must Pace the Frontier. Its thesis was a single bolded sentence: the industry must slow the rate at which it improves model capabilities.

Not pause. Pace.

He proposed three steps. Embedded third-party evaluators with permanent, employee-level access inside each lab, which Anthropic committed to unilaterally. Coordination among labs in democratic countries on shared standards and rate limits, which he concedes is legally challenging and will need government support. And an attempt at coordination with authoritarian governments, with the verification problems acknowledged.

Within hours, Sam Altman wrote that OpenAI agreed and would match the first commitment. Elon Musk replied with three words: Dario is right. Demis Hassabis backed the direction, having published his own proposal for a FINRA-style standards body in July. Satya Nadella endorsed the evaluator step, adding that open and closed models should both keep a seat at the table.

By Monday, AI-linked stocks had fallen. The President rejected new guardrails. Beijing called the proposal a Cold War tactic. And Altman, in a separate interview, said OpenAI’s IPO would not happen this year—this was, in his words, an ill-advised moment to go public.

Four rivals who have spent four years competing on release velocity agreed on the brakes in a single afternoon. I don’t think that speed of agreement is suspicious. I think it is convenient, and informative.

II. The “and”

There are two lazy readings of what just happened.

The first is that the safety argument is a cover story. It isn’t. The Hugging Face incident happened. Models are now materially involved in training their successors—OpenAI reported that by mid-August its coding agents were putting in 3.1 agent workdays for every human workday. The people closest to these systems are visibly worried, and at least one Anthropic researcher resigned over it the same week. I take the sincerity at face value.

The second lazy reading is that sincerity settles the question. It doesn’t. Governance is almost always shaped by the people who understand the system best, which usually means the people already operating inside it. That is not automatically corruption; it is how expertise enters rulemaking. It is also how incumbency enters rulemaking. Bankers helped design the Federal Reserve. Airlines have always had a seat in aviation regulation. Basel rules were negotiated with the banks that would ultimately carry the capital. Pharmaceutical companies live inside a regulatory architecture that protects patients and simultaneously makes drug development so expensive that only a limited number of companies can sustain it.

None of that makes the rules fake. It means rules have incidence. Someone pays more because of them, someone becomes safer, someone finds it harder to enter, someone’s installed base becomes more valuable.

So this is an “and” phenomenon. The labs may believe that slowing the frontier is necessary, and slowing the frontier may be the best business news their investors have had since the product-market-fit moment of 2023. Both can be true. The complication, which I’ll get to, is that the same slowdown hands the companies that wrap and deploy models the same gift, and some of them are better placed to use it.

I am less interested in proving motive than in tracing consequence. Real intent is private and usually unknowable; economic incidence is observable. The useful question is not whether the labs are using safety as an excuse to slow down. It is what happens economically if they actually do.

III. When slowing down pays

The question I kept circling was simple: where in business history has deliberately constraining speed, output, or cadence made the incumbent more valuable? I expected to struggle for examples. I didn’t. But the examples are not all the same; there are at least three distinct mechanisms.

Capacity discipline. For decades, US airlines destroyed capital by adding seats faster than demand. After Delta–Northwest, United–Continental, and American–US Airways, the survivors embraced what they openly called capacity discipline: grow available seat miles carefully, protect load factors, preserve fares, and stop treating every incremental unit of supply as inherently valuable. By 2015 the industry was posting record profits and double-digit margins, in a business that had historically managed 4% to 6% in a good year and losses in most others. The Department of Justice eventually asked whether the discipline had crossed into coordination. Hold that thought.

Compliance as an incumbent moat. Thalidomide helped produce the 1962 Kefauver–Harris amendments, which raised the evidence burden for new drugs. Development became slower, more expensive, and more regulated. Patients gained protections. The industry also consolidated around companies capable of absorbing the cost of clinical trials, regulatory affairs, manufacturing controls, and distribution. The rule served a public purpose and increased the minimum efficient scale required to compete. For an incumbent, compliance can become a moat without ever ceasing to be compliance.

Cadence and trust. In January 2002, Bill Gates sent the Trustworthy Computing memo and effectively stopped normal Windows development. Engineers were pulled from features into security training and code review. Products slipped. Competitors called it a lost year. But Microsoft had recognized something fundamental: once software becomes infrastructure, the marginal feature is less valuable than the confidence that the system will stay standing. Enterprise buyers do not just pay for functionality; they pay not to be blamed. Intel’s tick-tock cadence ran on a related logic. It was not really a slowdown; it was the deliberate separation of process risk from architectural risk, giving OEMs, developers, and Intel’s own fabs a rhythm to plan against. The cadence became part of the product.

Frontier AI has elements of all three. And deliberate slowing becomes economically attractive when four conditions hold:

  1. You are already near the front. A speed limit is worth more to the leader than to the challenger.
  2. The constraint binds smaller rivals harder than it binds you. Evaluations, audits, security controls, and governance are partly fixed costs. Fixed costs favor scale.
  3. Demand is bottlenecked somewhere other than supply. If customers cannot absorb what you already produce, making the product better every six weeks creates surprisingly little incremental value.
  4. Competition is shifting from capability toward trust. Trust is sold differently, bought by different people, and defended by different assets.

All four describe the frontier labs today. You do not need a conspiracy to explain why the proposal could come from them.

IV. The real bottleneck

This is the part I think matters most.

For most of the last four years we have treated progress in AI as though the economic relationship were simple: better model, more value. Early on, that was mostly right. The models themselves were the constraint. They no longer obviously are.

We now have three curves: available capability, deployable capability, and actually deployed capability. The first has moved much faster than the other two. A model can reason across documents, write production code, operate a browser, call tools, reconcile financial statements, and draft a contract. That does not mean a Fortune 500 company can deploy it tomorrow. Between capability and economic value sit procurement, identity, liability, data architecture, security, permissions, change management, integration, auditability, regulation, and the inconvenient fact that thousands of humans have to change how they work.

The frontier has outrun the enterprise, and something important follows: the marginal economic value of another unit of frontier capability is now lower than the marginal economic value of diffusing the capability we already have.

That changes the optimization problem. Another 20% capability jump looks wonderful on a benchmark. But if the customer is only using 30% of the last jump, it contributes less than 12 months of better uptime, predictable pricing, enterprise controls, privacy, security, improved integrations, and enough organizational calm for the customer to redesign a workflow around the model. Capability compounds in a lab in weeks. Organizations absorb it over years. Humans are now part of the bottleneck.

That is why a plateau is valuable. Not because progress stops, but because economics gets time to catch up with science.

V. What the nap buys

Set aside safety for a moment and look at the operating model.

It extends the useful life of the product. Since 2024, the frontier has often turned over in a matter of weeks. Each turn brings a new training run, a launch, evaluations, safety work, migration decisions, pricing changes, new inference infrastructure, and another round of developers wondering whether the architecture they built three months ago is already obsolete. That is thrilling research and a difficult operating environment. At frontier-level capital intensity, perpetually collapsing product half-lives are not desirable. Pacing creates duration. A model that remains commercially current for 12 months instead of 12 weeks becomes a more useful platform for developers, enterprises, and the lab itself.

This does not mean the GPUs go idle. Labs can continue training, post-training, evaluating, and running enormous amounts of inference without turning every capability increase into a commercial reset. A slower release frontier does not automatically mean slower compute consumption. It shifts the marginal unit of compute from proving that the next model exists toward making the current one cheap, reliable, safe, and ubiquitous.

It changes what gets monetized. The strongest version of the pricing argument is not that pacing stops price deflation. It won’t. Even in a stable-capability world, inference gets cheaper: hardware improves, quantization improves, distillation improves, utilization improves, cloud companies subsidize, and open models keep attacking the low end. Tokens will keep trying to become electricity.

That is why the labs need to stop selling tokens. The economic unit has to move upward, from tokens to agents to workflows to outcomes to certified responsibility, and a slower frontier gives the upper layers time to harden. When the underlying model changes every few weeks, everyone competes on model quality and price per token. When the model stays good enough for longer, differentiation migrates. Can the agent finish the job? Can it access the right systems? Can it be trusted with credentials? Can its actions be reconstructed? Will the vendor indemnify me? Will an auditor accept it? Who is responsible when it fails? Those questions carry better margins than tokens. A plateau does not end deflation. It creates the opportunity to move the business away from the layer that is deflating.

It lets the supply chain catch up. Chips, HBM, packaging, transformers, substations, water rights, permitted land, networking, electricians. Almost every physical layer below the model has been chasing a moving target. A more predictable frontier gives the infrastructure stack something rare: time. If capability runs years ahead of economically deployable infrastructure, some of the incremental intelligence cannot be served at attractive cost anyway. The frontier does not create much value if inference remains scarce, unreliable, or uneconomic.

It lets diffusion and applications happen. This is the argument in §IV, so I’ll keep it short. Enterprise adoption has been slower than the demos suggested, and much of the reason is everything around the model rather than the model. Today’s models are underused: coding and customer service have been worked hard, legal and research are moving, and across finance, procurement, healthcare administration, insurance, logistics, and education we have mostly demonstrated what AI could do without rebuilding the workflow around it. The application layer is not waiting for another IQ point; it is waiting for product. The larger prize is turning parts of the roughly $6 trillion professional-services economy into software-like economics, and that conversion runs on adoption curves, not benchmark curves. The plateau is where the second act gets built. Let it bake.

It makes a public-market story possible. Altman’s IPO comment is interesting for this reason. A frontier lab going public inside a relentless reset cycle is signing up to explain every quarter why last quarter’s model is now cheaper, why this quarter’s model required another enormous capital program, and why next quarter’s will make both look old. Public markets can finance large capital requirements. What they dislike is an economic model whose unit of value keeps expiring. Pacing turns a frontier lab into something the market recognizes: a platform with a roadmap, a release cadence, enterprise contracts, renewal behavior, gross-margin progression, and eventually something resembling operating leverage. The lab stops looking purely like a research program and starts looking like a business.

VI. Branded intelligence and generic intelligence

There is an obvious complication. Open weights do not nap.

Qwen, DeepSeek, Kimi, and whatever comes next sit outside any voluntary American pact. They will continue improving, distilling, and deflating the commodity tier. So pacing cannot eliminate competition. It can only change the market structure.

The analogy I keep coming back to is branded versus generic pharmaceuticals. The innovator does not win because every molecule is better. It wins because the product arrives wrapped in evidence, manufacturing controls, labeling, liability, regulatory acceptance, and a company whose name can sit on the contract. The generic wins on price. Both can be enormous businesses.

Frontier AI will bifurcate the same way: cheap, open, increasingly capable intelligence at one end, and certified, monitored, indemnified, enterprise-grade intelligence at the other. The frontier labs would naturally like to occupy the second category. Embedded evaluators help. Security commitments help. Restrictions on unauthorized distillation help. National-security framing helps. Enterprise procurement departments will eventually demand exactly these things, and trust becomes part of the SKU.

But there is a major difference between AI and pharmaceuticals: the company that trains the model does not necessarily own the branded layer. An enterprise does not require accountability from the creator of the weights. It requires accountability from someone. Microsoft can take an open model and wrap it in governance, identity, logging, SLAs, and indemnification. So can AWS, Google, Oracle, IBM, Palantir, ServiceNow, Accenture, and companies that do not yet exist. Open weights can acquire a branded distribution layer.

Which means the real strategic contest is not closed model versus open model. It is who owns deployment, workflow, and liability. That is a much less comfortable question for the frontier labs. If the model commoditizes while value migrates upward, the application and control layers will capture more of the economics than the lab. The labs have to do more than remain smarter; they have to move upward before everyone else does. This is why the slowdown sets off a land grab in agents, enterprise workflow, identity, security, and vertical applications.

The plateau gives the labs time. It gives everyone else the same time. That is the bargain.

So here is my call. The plateau is good for the labs only if they use it to become the accountable layer, not just the smart one. The lab that spends the next 12 months acquiring security, owning identity and audit for agents, and signing the enterprise contracts that put its name on the liability line comes out of the nap as a platform with pricing power. The other(s) become a supplier to someone else’s platform, and suppliers get generic economics. Rather than deciding between platform or supplier, pacing makes the choice visible, and it starts the clock for everyone at the same time.

VII. The geopolitics of a nap

The international picture is where business logic and safety logic braid most tightly.

Sovereign AI is a distribution problem more than a capability problem. Governments want models that can run inside national boundaries, on protected data, under domestic law, with local security standards and some credible answer to the question of who ultimately controls this thing. Serving that demand requires more than a model endpoint. It requires regional deployments, data residency, security certifications, procurement infrastructure, government relations, local partners, and sales teams capable of walking a ministry through an audit. Those things are built on institutional time, not model time. A plateau gives frontier labs room to become international companies rather than American companies with international API traffic.

The geopolitical framing also has commercial consequences. As governments treat frontier AI as critical infrastructure, enterprise buyers will care where the model came from, who evaluated it, who controls the weights, and who stands behind the deployment. Take the national-security argument seriously, and notice what it does to market segmentation: a certified American frontier model sold with evaluators, controls, and liability protection becomes a very different product from a cheap downloadable checkpoint. Trust, in that world, is the product.

VIII. The bill: security

Everything above is what the nap buys. This is what it exposes.

The Hugging Face incident is not fundamentally a story about a zero-day. The zero-day was one fragile surface. The system also contained identity, credentials, tool permissions, networks, data pipelines, package registries, model memory, agent-to-agent communication, and interfaces between systems designed by humans who had never expected software to behave with sustained agency. The agents found an exploit. Then they escalated privileges, moved laterally, coordinated through improvised communications, and encountered credentials exposed on the public internet. The exploit was one link in the chain; the deeper failure was architectural. We built systems around the assumption that software executes. Agentic systems act. That is a different threat model, and it creates two consequences.

The labs will buy cybersecurity companies. I am willing to make the call. Runtime security, identity for non-human actors, secrets management, agent observability, permissioning, sandboxing, red-team infrastructure, policy engines, auditability. The labs need these capabilities embedded close to the model because their customers are about to deploy autonomous systems at scale, and the vendor selling the agent must eventually be able to say, with a straight face, that the system cannot do what those OpenAI agents did—or that if it tries, they will know, stop it, and reconstruct exactly what happened. That is a product problem more than a research problem, and the existing security companies are sitting on years of incident data and customer context that a lab cannot generate on its own. I expect acquisitions in the next 90 days. They will be framed as safety investments, which they will be. I also expect them to be among the highest-return strategic acquisitions the labs make, because security sits directly on the path from impressive model to deployable enterprise system.

There will be “cybersecurity models,” but the model will not be the product. There will be products marketed as cyber models. The likely architecture is a general frontier model plus security-specific post-training, proprietary threat data, tools, runtime controls, identity, an audit trail, and a control plane, and that entire stack will be branded as a model. But its economic value will not come from a narrower checkpoint that knows more CVEs. Novel attacks require general reasoning precisely because they are novel. The durable product is the system around the model. A CISO does not buy intelligence; a CISO buys a controlled outcome. A system that can investigate an alert, take an action, know what it is allowed to touch, prove what it touched, stop when policy says stop, escalate when confidence falls, and leave behind an audit trail. Security is not a skill. It is a property of the whole system, and that is what decides where the value accrues.

IX. Where it breaks

I have made the case that pacing could be excellent business. There are several ways it fails.

Open weights don’t nap. This remains the whole game, and §VI covers it. The branded tier works only if its premium stays economically meaningful. If open models close most of the capability gap and enterprise-grade wrappers make them equally accountable, the frontier premium collapses toward a thin compliance surcharge, and pacing stops looking like capacity discipline and starts looking like incumbents opening the door for substitutes. The Kodak outcome is entirely possible: excellent safety documentation, beautiful governance, and someone else’s model underneath the world’s software.

The application stack may keep accelerating anyway. There is a more fundamental problem: what exactly are we pacing?

  • Pretraining?
  • Parameter scaling?
  • Post-training?
  • Inference-time compute?
  • Agentic scaffolding, tool use, memory?
  • Synthetic environments?
  • Self-improvement?

A slowdown at the base-model frontier does not imply a slowdown in economically useful capability. The opposite is likelier. The foundation model naps while the system around it compounds: agents gain memory, tools, permissions, context, computer use, specialized data, longer horizons, better verification. None of those require a dramatic new pretraining run. This is simultaneously a problem for the governance framework and a support for the economic thesis. The frontier may slow while AI adoption accelerates. If so, pacing is less a nap than a transfer of innovation from the model layer into the application stack, which may be exactly what the industry needs.

Antitrust. When airlines talked too enthusiastically about capacity discipline, the Department of Justice came calling. When a handful of companies controlling a critical market agree to limit the rate at which their output improves, the cartel question is not rhetorical. The labs know this, which is why coordination requires a legal framework or explicit government support. Without one, the most ambitious part of the proposal does not exist. You are left with unilateral commitments, and unilateral commitments last until the competitive cost becomes too high.

Politics. The administration rejected the proposal in the same news cycle. A safety regime the government does not support remains voluntary. Voluntary regimes work while incentives stay aligned and become fragile the moment someone believes they can gain share by defecting. The rationale for embedded evaluators is partly that previous voluntary commitments have not translated cleanly into measurable behavior. That is an argument for the proposal. It is also a reason to be skeptical of it.

“Pacing” has no unit. This is the framework’s most obvious design flaw. There is no meter that says a lab is moving at 62 miles per hour when the limit is 55. A company can comply formally while accelerating economically: a “safety release,” a “research preview,” a new agent, a larger context window, a reasoning upgrade, an enterprise-only feature, a model with the same name that somehow does twice as much work. The likelier failure mode is compliance in form and acceleration in substance, not open defection.

X. The finance question

All of this reduces to one question: does pacing create more enterprise value than it destroys? For the labs that make the move in §VI, yes. Here is the shape of why.

A slowdown can reduce the revenue growth rate. It can simultaneously improve gross margin, useful product life, customer retention, capital efficiency, and terminal economics. Consider two illustrative versions of the same frontier lab—the shape matters more than the numbers themselves.

DimensionWorld A: the treadmillWorld B: the platform
Revenue growth70%45%
Useful model lifeMonths12+ months
Marginal computeFrontier trainingInference and deployment
Gross margin~45%~60%
R&D and training intensity~35% of revenue~25% of revenue
PricingPer token, reset each releaseOutcome and workflow pricing viable
Customer behaviorContinuous re-evaluationDeep platform build-out, easier renewals
Wallet shareModel APIModel plus security and workflow products
Market’s viewExtraordinary growth, unknowable normalized marginVisible path to durable free cash flow

Which company is worth more? On these numbers, B. A DCF does not value growth in isolation. It values the cash produced by growth, the capital required to generate it, and the duration over which excess returns persist. The frontier labs are at the moment when better economics on existing intelligence are worth more than faster creation of new intelligence. That is why the slowdown is bullish, for the labs that make the move.

But there is a mirror image. Private-market valuations were set in a world that assumed relentless capability improvement, outsized revenue growth, and eventual dominance of enormous portions of the economy. If pacing lowers expected growth before the margin structure has visibly improved, investors will not politely wait for the terminal economics to reveal themselves. Someone has to reconcile the two curves. That can happen through operating performance or through price. A delayed IPO is one way to buy time for the first before submitting to the second.

XI. For the finance tribe

If you run a company, invest in one, or sit in the seat that has to explain the AI line item to a board, I would take four things from this.

Assume today’s capability is durable enough to build on. Stop designing strategy around the next model release. If another breakthrough arrives, good. But the models already available can transform large categories of work, and most companies are constrained far more by deployment than by intelligence. Build against a 9–12 month capability plateau and force yourself to extract value from what exists.

Move your pricing above the token layer. Token economics will keep deflating, and that is not where durable differentiation lives. Price on workflow, outcome, risk transferred, time saved, or certified reliability—wherever attribution is strong enough to withstand a customer dispute. The more commodity intelligence becomes, the more valuable it is to own the economic outcome above it.

Buy security before buying another increment of capability. The enterprise question is changing. It used to be what the model can do. It is becoming what the model is allowed to do. Soon it will be how you know. If you are deploying agents, those questions belong in the architecture now.

Read the pact as a potential moat, not merely a pause. For investors, a credible pacing regime is bullish for frontier-lab margins, supportive of longer product duration, positive for security and enterprise control layers, roughly neutral for near-term compute demand, positive for application companies that need a stable substrate, and dangerous for any thesis that assumes the frontier model itself captures most of the economics. The broader implication: for the first time, we can underwrite the frontier labs less like research organizations and more like platforms. The science has not stopped mattering. It has outrun the economy’s ability to use it.

The labs say they need time to get this right. I believe them. They have also described the most favorable operating environment they have ever had. For four years the scarce resource was intelligence. Now it is absorption, and that changes who wins. The frontier may nap. I doubt the rest of the stack will. Watch what gets built while it sleeps.

Related questions

What does it mean to "pace the frontier" in AI?
Pacing the frontier is the proposal, made by Dario Amodei in September 2026 and quickly endorsed by OpenAI, Google DeepMind, xAI, and Microsoft, that the industry deliberately slow the rate at which it improves frontier model capabilities. It is not a pause. The three concrete steps are embedded third-party evaluators with employee-level access inside each lab, coordination among labs in democratic countries on shared standards and rate limits, and an attempt at coordination with authoritarian governments. Only the first step can be done unilaterally; the other two need legal cover or government support to avoid becoming an antitrust problem.
Why would slowing down AI development be good business for the frontier labs?
Because the bottleneck has moved. Available capability now runs well ahead of what enterprises can actually deploy, so another increment of frontier intelligence is worth less than diffusing the capability that already exists. A slower release cadence extends the useful life of each model from weeks to a year or more, shifts the marginal unit of compute from training toward inference and deployment, lets pricing move up from tokens to agents, workflows, and outcomes, gives the chip and power supply chain time to catch up, and makes a frontier lab legible to public markets as a platform with a roadmap rather than a research program whose unit of value keeps expiring. Deliberate slowing pays when you are already near the front, the constraint binds smaller rivals harder, demand is bottlenecked somewhere other than supply, and competition is shifting from capability toward trust. All four hold today.
Does pacing the frontier mean AI adoption will slow down?
Probably the opposite. A slowdown at the base-model frontier does not imply a slowdown in economically useful capability, because most of the system around the model keeps compounding without a new pretraining run: agents gain memory, tools, permissions, computer use, longer horizons, and better verification. Open-weight models outside any voluntary pact keep improving as well. The likelier outcome is that innovation transfers from the model layer into the application stack, which is exactly where enterprise value has been waiting. The real contest becomes who owns deployment, workflow, and liability, not closed model versus open model.