SecurityTechInsider AI security & governance
EN/ NL
Governance

Slowing frontier AI: which governance mechanisms you must now demonstrate per workflow

AI leaders ask government for tools to slow frontier AI. What does that pacing call mean for your AI governance and what do you record per workflow?

14 September 2026 4 min
Illustration for this article: which governance mechanisms you must now demonstrate per workflow. A ventilation grille in deep shadow, cold air distorting the light passing through it.
Organisations must now document frontier model use, external evaluators and capacity thresholds per workflow to demonstrate compliance with pacing governance requirements. Image: SecurityTechInsider — original editorial illustration

You must now be able to demonstrate, per sensitive workflow, which frontier models you use, which external evaluators assess them, and which capacity thresholds or incident protocols apply to each one. This is no longer optional documentation — it is the operational consequence of the pacing governance shift.

An analysis of 14 September 2026 of frontier AI pacing governance mechanisms argues that the call to slow frontier AI development requires governance to move from recording to enforcing: independent model evaluations with authority, recorded capacity thresholds that trigger delay, and coordinated incident reporting across labs. The concrete case is the "Pacing the Frontier" statement signed by over 1,200 employees of leading AI labs in July 2026, endorsed at company level by OpenAI and Anthropic, which diagnoses a tooling gap rather than calling for an ideological pause. In our assessment, this represents the pivot point where frontier AI governance becomes operational rather than aspirational — the signatories are asking for infrastructure that makes slowdown possible when evidence justifies it, not for a political vote on whether to proceed.

What has changed in the governance instruments available?

The pacing campaign identifies three concrete strategies: independent evaluators with access to frontier models, capacity thresholds tied to measurable benchmarks that trigger mandatory delay, and coordinated incident reporting across labs. These are governance instruments with enforcement teeth, not advisory principles. General frameworks such as risk management, transparency and incident reporting already exist — the EU AI Act, for instance, establishes these as baseline expectations — but they operate primarily as recording mechanisms. They do not slow anything. The shift now required is to make these principles operational at three specific points: evaluators must have genuine access and authority, thresholds must be tied to concrete capacity measures rather than vague risk assessments, and incident findings must feed into decisions about whether to proceed with new capability releases.

Which failure modes and duties does pacing governance address?

  • Uncontrolled frontier capability release — models deployed without independent assessment of their capacity for harm.
  • Invisible model deployment in sensitive workflows — frontier models in use without documented agreements or evaluator oversight.
  • Incident findings that do not trigger action — red team results or safety evaluations that inform but do not delay deployment.
  • Uncoordinated lab responses to safety findings — each provider acting independently rather than sharing incident data that would justify coordinated slowdown.
  • Capacity thresholds without measurement — risk management language that lacks the benchmarks needed to trigger mandatory delay.
  • Evaluator access without authority — external assessments that inform but carry no weight in deployment decisions.

What must you record and verify per workflow?

  1. Identify the frontier model and its source — document which frontier model each sensitive workflow uses and whether it comes from a lab or via a vendor such as Microsoft.
  2. Record the legal basis and data scope — establish which lawful basis applies to the data the workflow touches and which external agreements govern the model's use.
  3. Document external evaluators and standards — name which independent evaluators assess the model and which capacity benchmarks or safety standards it must meet.
  4. Establish capacity thresholds and delay triggers — record which measurable thresholds, if breached, require delay or escalation before the workflow proceeds.
  5. Log incident findings and responses — maintain a record of red team results, safety evaluations and your documented decision on whether to proceed, delay or restrict the workflow.

How does pacing governance translate to your organisation?

Once frontier models sit in legal, financial, healthcare or government workflows, you must be able to demonstrate those agreements at workflow level. This is the practical translation for professionals who work with confidential information. The EU AI Act and broader oversight expectations already establish principles around AI governance and accountability; pacing governance makes those principles operational by requiring you to show, per workflow, not only that you have assessed risk but that you have recorded which external evaluators or standards apply and which capacity thresholds would trigger mandatory delay. On the operational side, it helps to set up verification per workflow and to conduct red teaming for AI agents in multiple layers, so that capacity and incident findings actually feed into your decisions rather than sitting in a report.

What tooling can support this, and what remains your judgement?

A verification layer can support this as a visibility mechanism: it can help show, per workflow, which frontier models and agents are active, which external evaluators or standards they are subject to and which control steps have been recorded. Such tooling makes control possible by making verification steps, corrections and sources inspectable. It does not assure the correctness of an answer, and the final judgement on whether to proceed, delay or restrict a workflow remains with you. The pacing governance shift is real; the tools that help you demonstrate it are aids to your own professional oversight, not replacements for it.

Sources: This article draws on reporting and guidance from Fortune, The Verge, TechCrunch, Cloud Security Alliance and DigitalApplied.

Marit Halversen

Written by

Marit Halversen

Covers AI governance and regulatory design, with a focus on how compliance obligations land on architecture rather than on paperwork.