Almost everyone I know in AI safety wants the same thing, whether they work at a frontier lab, a university, a nonprofit or a startup like mine: a world where what we learn about how models fail spreads faster than the failures themselves. This month that shared hope ran into antitrust law, and I have watched colleagues wonder whether an honest conversation with a peer at another lab could one day be read aloud in a courtroom. Vivian Dong of Legal Advocates for Safe Science and Technology (LASST) has addressed this question directly, concluding that employees at AI companies may talk with one another about safety, but may not act as intermediaries who coordinate their companies' conduct [1]. I want to explain why that line matters, what the law around it actually says, and what I believe the safety community should build because of it.

Sharing safety knowledge into a public commons is generally fine; relaying "we'll do X if you do" from one lab to another is the risk. Based on V. Dong, LASST (2026). Not legal advice.
How we got here
On September 12, Dario Amodei published "We Must Pace the Frontier," a three-step plan that begins with embedded third-party evaluators, who would have ongoing, employee-like access to verify safety practices and report incidents, and then moves to coordination on common safety standards among frontier companies in democratic countries [3]. Amodei acknowledged the legal difficulty himself, writing that for antitrust reasons the government would need to mediate or enable these discussions, or at least issue a narrow waiver for certain kinds of safety conversations [3]. Sam Altman, Demis Hassabis and Elon Musk voiced support, and Altman said OpenAI would join Anthropic in embedding third-party evaluators [5]. Days later, OpenAI's Chris Lehane told reporters that OpenAI, Anthropic and Google DeepMind had been talking about AI safety for several weeks, and said the firms do not need the waiver Amodei proposed [5].
Then came the lawsuit. The complaint, filed in the U.S. District Court for the Northern District of California, argues that the companies violated antitrust law by agreeing to coordinate slowdown efforts, which the plaintiffs say reduces the value consumers get from paid AI subscriptions [4]. The complaint does not challenge any company's decision to slow its own development on its own [6]. It is a proposed class action at its earliest stage, and I take no position on how it should come out. I would caution anyone in our community against treating the complaint as either proof of wrongdoing or proof of bad faith.
What the law actually says
Dong's earlier analysis for LASST lays out the framework clearly [2]. The relevant law is Section 1 of the Sherman Act, which prohibits agreements between companies that unreasonably restrain trade. Either an explicit or a tacit agreement can violate it, but mere conscious parallelism, where firms act alike while aware of one another, does not [2].
The analysis is candid about where the hard line sits. It would be unambiguously illegal for the leading companies to agree to pause AI development, however earnest their motives, because that is an agreement to restrict output, and an express agreement to slow down would likely meet the same fate [2]. The Supreme Court has held that competitors cannot defend an agreement not to compete by arguing that competition itself is unsafe [2].
The same analysis also shows how much room remains. Public disclosure generally raises no antitrust problem because any competitor can access it, so an agreement to publish system cards or safety frameworks is unlikely to raise concerns, and sharing genuine safety and security information, such as vulnerabilities, jailbreak techniques and CSAM hashes, is also generally fine [2]. Joint efforts to petition the government for regulation are shielded as well [2]. Dong's newer piece applies this framework to individual employees: researchers at competing companies may discuss AI safety, share research and policy ideas, and even organize advocacy aimed at persuading their own employers to adopt safer practices [1]. Her rule of thumb is the clearest summary I have seen. Employees may agree among themselves about what they hope their companies will do, but they must never become the channel through which the companies coordinate with each other [1].
I read these lines as a map rather than a wall. They separate two activities that can look alike from the outside but differ in substance: building shared knowledge about risk, which the law generally welcomes, and agreeing on what each company will do, which the law examines closely.
A policy landscape still in motion
Speaking in New York on September 17, Associate Attorney General Stanley Woodward said existing guidelines spell out how far companies can coordinate on hacking risks without breaking competition rules. He added that no frontier lab had yet asked his office for a meeting [7]. The Justice Department and the FTC are also working to replace the 2000 Guidelines for Collaborations Among Competitors, which were withdrawn in December 2024 and left businesses without guidance in this area [8]. Congress, meanwhile, is sceptical of special treatment: Senator Hawley has said AI companies should not receive antitrust exemptions [10]. Until clearer guidance arrives, the safest assumption for everyone is that transparent, well-documented, public-facing practices matter more than ever.
The concern our community should take seriously
Safety researchers sometimes treat antitrust worries as a distraction from the real risks. I think that is a mistake, because the competition concern points at something we care about too. A Bloomberg Law commentary warned this year that safety frameworks can look impossible to argue against on their own terms while still leaving the firms that designed them better positioned than those that did not, noting that compliance costs rarely fall evenly across market participants [9]. Critics quoted by NPR this month made a similar point: a slowdown among the largest companies could consolidate the power of the frontier labs just as others are trying to catch up [11].
If safety becomes a club that only the largest labs can join, we will have traded one risk for another. Much of the next wave of deployment will run on open-weight and smaller models, where the safety layer that came with a frontier API does not come with the weights. When my team tested 21 open-weight models against our psychological safety protocol, none of them passed. A safety regime that ignores those systems is not a safety regime for the world people actually live in.
Toward a public safety commons
Put the legal map and the competition concern side by side, and a clear design emerges. The most useful and most defensible form of safety cooperation is a public safety commons: a shared, openly accessible body of evidence that every lab, academic group and independent evaluator can contribute to and learn from, while each company still decides for itself how to act on it.
Such a commons would hold what the law already treats as low-risk: published evaluations, disclosed vulnerabilities and jailbreak techniques, incident reports, research findings and open taxonomies of harm. Independent evaluators are central to it. Amodei's proposal would give external reviewers the right to publish key findings about risk levels, incidents and practices without the company's editorial control [3], which is exactly how knowledge moves into a commons. Dong's analysis points to a further possibility: companies could argue that an agreement to have the same third party evaluate every model on standardized benchmarks is reasonably necessary, because it lets customers compare models directly [2]. Evaluators who apply one published methodology to every system, publish their results and never carry confidential information between clients create shared knowledge rather than shared agreements, and they can include the smaller labs and open-weight developers that closed standards bodies may leave out.
At ioLite Labs, we hold ourselves to that standard: one methodology for every system, results anyone can read, and strict walls between clients. We do not see ourselves as a channel between competitors; we see ourselves as one contributor to a commons that no single company should own.
What I would suggest to researchers
None of this is legal advice, and anyone weighing cross-company conversations should speak with their own counsel. Still, a few habits follow naturally from the analysis. Talk about evidence rather than plans: what you found, how you measured it and what it means, rather than what your company intends to do next. Stay away from confidential commercial plans, such as pricing, the scale of planned training runs, release timing, unreleased features and compute capacity, and never pass along a message like "our company will do X if yours does too" [1]. Prefer public channels, such as papers, shared benchmarks, disclosed vulnerabilities and open datasets, since public information is available to every competitor. And route anything closer to standard setting through neutral, openly governed bodies that welcome newcomers.
Closing
The lawsuit may or may not succeed, but it has already done the safety community a service by forcing a clear question: what kind of cooperation do we want? My answer is cooperation that makes evidence public, keeps decisions independent and lets anyone, from the largest lab to a two-person startup, pick up the same yardstick. Share the evidence, not the playbook.
References
- V. Dong, "Talking AI Safety Across Company Lines," LASST, Sept. 24, 2026.
- V. Dong, "How Antitrust Law Applies to AI Safety Coordination," LASST, Aug. 28, 2026.
- D. Amodei, "We Must Pace the Frontier," Sept. 12, 2026.
- Associated Press, "Lawsuit says Anthropic, OpenAI, SpaceXAI and Google made illegal agreement on AI slowdown," via ABC News, Sept. 19, 2026.
- TechCrunch, "OpenAI, Anthropic, Google have been in talks on AI safety for weeks," Sept. 15, 2026.
- Quartz, "Anthropic, OpenAI, Google, and SpaceXAI illegally agreed on an AI slowdown, lawsuit says," Sept. 20, 2026.
- Bloomberg, "US Weighs Antitrust Guidance on AI Safety, Top DOJ Official Says," Sept. 17, 2026.
- U.S. Department of Justice, "Justice Department and Federal Trade Commission Seek Public Comment for Guidance on Business Collaborations," Feb. 23, 2026.
- Bloomberg Law, "AI Industry's Cooperation on Safety Raises Antitrust Questions," 2026.
- The Washington Times, "Foxes guarding the server room? Senators smell a rat as Big Tech begs Washington to regulate AI," Sept. 21, 2026.
- NPR, "How an 'AI freeze' could make big AI companies bigger and hurt smaller firms," Sept. 23, 2026.