OpenAI has published a document, in substance, on the pace of development in the era of critical cyber capabilities. The company announces a voluntary slowdown in its training of cutting-edge models and reinforced oversight: around 20% of inference compute would now be devoted to monitoring the rest. This covers reinforcement learning and tool-based evaluations for models in the GPT-5.6 Sol class and above.
All summer we documented instances where models breached the boundaries of their test environments, from the July incident to their recurrence across several labs. Here is the response from the company most concerned, and it is unusual.
What is announced
Two main measures, and they are not of the same nature.
A slowdown in pace. The company says it is voluntarily slowing the development of its most capable models while it strengthens safety measures. In a sector where competition normally rules out any pause, this is a decision with a real competitive cost.
Massive oversight. The figure of 20% of inference compute devoted to monitoring deserves scrutiny. It means a fifth of resources go toward observing what the system does rather than producing value. Measured against the costs we described in our article on the two costs of AI, this is a considerable investment.
The critical reading, which exists
Observers note that the commitment would be narrowly scoped: it would apply to models intended for deployment, leaving room for interpretation on internal research. This caveat is worth reporting, because it touches the sensitive point of any self-regulation.
A second element was flagged in the same breath: access to a programme for cybersecurity researchers would have been revoked without explanation. Again, this is an observer report rather than an established fact, but it illustrates the difficulty: a company that sets its own rules also decides alone who can verify them.
That 20% figure is perhaps the most useful piece of information in the announcement, regardless of the debate over sincerity. It gives, for the first time, an order of magnitude for the cost of monitoring a cutting-edge system. Until now, AI safety was discussed in principles. Here it is quantified as a percentage of compute, that is, in euros. It is a data point that regulators and competitors alike will use.
A correction on a point we had reported
We recently wrote that the company was targeting an IPO as early as September 2026, based on press reports. That information needs revising: the company's chief financial officer would have said in an internal meeting that the firm would go public in 2027, or earlier if business accelerated.
This revision is consistent with today's announcement: a company voluntarily slowing its development has no interest in facing the markets immediately. What we wrote about the value of the prospectus still holds; the timeline shifts.
What this changes in the debate
This announcement comes a few days after twenty-nine US lawmakers demanded explanations. The coincidence can be read two ways, and both have some truth.
The favourable reading: a company confronted with incidents it has itself documented draws the consequences, publicly, before being forced to. That is what one expects of a responsible actor.
The cautious reading: self-regulation announced just before possible hearings also looks like a way to occupy the ground and demonstrate that no external constraint is needed.
We have no way to settle this, and the question matters less than the following one: is this kind of commitment verifiable? Today, no. No one outside can measure whether 20% of compute is actually devoted to oversight, nor what exactly the announced slowdown covers.
What to remember
This is a notable decision, and probably sincere in principle. It also illustrates the structural limit of self-regulation: a company that sets its own rules, applies them, and verifies that it complies occupies all three roles.
What would be needed to make this robust, we wrote regarding safety tests becoming a risk themselves: standardised levels, evaluation by third parties with resources, and a reporting obligation that protects the one who reports. In the meantime, we depend on the goodwill of actors who genuinely show it, and that is better than nothing while remaining fragile.