The debate over AI lab coordination has collapsed into a false binary. There are at least four paths forward.
In “We Must Pace the Frontier,” Anthropic CEO Dario Amodei asked for something seemingly narrow: an antitrust waiver that would allow competing AI labs to discuss joint limits on the pace of frontier development. Within hours, Sam Altman of OpenAI, Elon Musk of xAI, and Demis Hassabis of Google DeepMind endorsed variations on the idea. Altman went further, suggesting that OpenAI does not believe it needs to wait for permission to coordinate.
The backlash was immediate and unusually bipartisan. Former FTC Commissioner Alvaro Bedoya argued that existing antitrust doctrine already permits legitimate safety collaboration and warned against a broad waiver. FTC Chair Andrew Ferguson and David Sacks, President Trump’s former AI czar, reached a similar conclusion. Cohere’s Aidan Gomez put the objection more sharply: Who writes the standard? Who conducts the review? Who gets a seat at the table when there is no comment period, consultation, or vote? One commentator repurposed Facebook’s old mantra into a barb aimed at the proposal: “move slow and collude.”
But the debate has lost an important distinction.
Competitors coordinating to prevent catastrophic misuse of a powerful technology can be socially valuable. Antitrust law has accommodated such collaboration before. And the choice confronting policymakers is not simply between granting the largest AI labs an antitrust exemption and forbidding them from working together.
There are at least four pathways for AI lab coordination. They offer different degrees of legal protection, public oversight, and permissible restraint. Understanding those differences matters because the hardest question is not whether the labs may coordinate. It is what they want to coordinate about, and who gets to supervise them when they do.
It is worth noting that the economic critique raised by former and current FTC commissioners and others is straightforward and supported. The firms seeking an antitrust shield are incumbents. Safety compliance is often a fixed cost, which can fall disproportionately on smaller developers, while a coordinated slowdown may be cheapest for the firm that already holds the largest technological or commercial lead.
That concern is real. But it is principally an objection to one institutional arrangement: a durable statutory shield granted to a small group of incumbents. It does not answer the broader question of whether (and to what degree) competitors can collaborate on AI safety. To answer that question, it helps to walk through the four paths that actually exist.
Path One: The Rule of Reason
Critics of Amodei’s request for an antitrust waiver are right about the starting point: much of the collaboration Amodei describes is already lawful today.
Antitrust law generally evaluates competitor collaborations under one of two frameworks. A narrow class of agreements—price fixing, market allocation, and certain other naked restraints among competitors—are condemned per se, without an inquiry into their claimed economic benefits. Most other collaborations are evaluated under the rule of reason, which asks whether an agreement’s competitive benefits outweigh its anticompetitive effects.
That distinction leaves substantial room for genuine AI safety collaboration. Properly structured, joint safety evaluations, shared red-teaming methodologies, threat-information exchanges, and common technical benchmarks fall within antitrust law’s more flexible treatment of competitor collaboration.
Congress reinforced that approach through the National Cooperative Research and Production Act (“NCRPA”). The statute expressly directs courts to evaluate covered joint research-and-development ventures and standards-development organizations under the rule of reason. For qualifying collaborations that file notice with the DOJ and FTC, it also limits damages to actual rather than treble damages and permits prevailing defendants to recover attorneys’ fees in certain circumstances. The DOJ Antitrust Division’s recently revived business review letter program provides another tool: firms contemplating a collaboration can ask the Division for a written statement of its present enforcement intentions.
In other words, much of the technical core of AI safety work—sharing vulnerability information, developing common evaluations, testing for chemical, biological, radiological, and nuclear (“CBRN”) uplift, and coordinating red-team methodologies—already rests on relatively firm antitrust ground.
But the rule of reason has an important limitation: it is a standard of adjudication, not a safe-harbor checklist.
It tells a federal judge how to evaluate conduct after the fact. It does not necessarily tell an in-house lawyer whether to approve tomorrow morning’s meeting with five direct competitors. And in the United States, the government has recently removed some of the guidance companies once used to make that judgment. The Competitor Collaboration Guidelines were withdrawn in December 2024; previously recognized information-sharing safe harbors had already been withdrawn. No comparable replacement has yet filled the gap.
The resulting chilling effect is not merely theoretical. In September 2019, the Antitrust Division opened an investigation into Ford, Honda, BMW, and Volkswagen over their voluntary emissions framework with California. The investigation closed without action in February 2020, and an Antitrust Division whistleblower later described it to Congress as an abuse of enforcement authority. But the public investigation reportedly deterred at least one additional automaker that had been considering joining the framework.
So when AI labs say antitrust uncertainty can chill legitimate collaboration, they are identifying a genuine concern. The harder limit comes when “safety collaboration” becomes an agreement about output.
The NCRPA itself excludes certain agreements restricting production or sales from its protections. More fundamentally, there is a large legal difference between sharing threat intelligence and agreeing that competitors will delay, throttle, or withhold deployment. A naked agreement among horizontal rivals to restrict output sits near the core of what antitrust law prohibits.
The rule of reason therefore provides considerable space for labs to make AI safer. It is a far shakier foundation for an agreement among the labs to develop AI more slowly.
Path Two: Noerr-Pennington
A second path is both broader and often overlooked.
Under the Noerr-Pennington doctrine, competitors may jointly petition the government for policies that could raise serious antitrust problems if the competitors simply imposed them on the market themselves. The doctrine is rooted in the First Amendment right to petition and provides broad protection for genuine efforts to influence governmental action.
That covers a surprising amount of the territory in the current debate.
The labs can jointly draft model legislation establishing capability checkpoints. They can jointly petition agencies for binding deployment restrictions. They can testify together before Congress and urge the government to impose a mandatory pace limit on frontier development.
If the industry believes frontier AI needs a speed limit, its members are free to stand together and ask the government to implement one.
This path also responds directly to one of the strongest criticisms of private coordination: transparency. Governmental decisionmaking can occur through public processes, with published proposals, competing viewpoints, political accountability, and—depending on the forum—notice and an opportunity for public participation. The labs can make their case, but they do not get the final word.
The limitation is equally important. Noerr-Pennington protects the asking, not the doing. Competitors can jointly ask the government to install a red light. They cannot necessarily agree among themselves to stop at the intersection while the light is still green.
Path Three: A Statutory Exemption
The third path is the one driving much of the current debate: legislation specifically protecting certain AI safety coordination.
S. 5105, the Collaboration on Adversarial Threats and Security Risks Act, introduced by Senators Adam Schiff and Jim Banks, would create such a framework. Importantly, the bill does not simply confer blanket antitrust immunity on the largest AI companies. It creates an affirmative defense, leaves the burden on defendants invoking that defense, preserves private rights of action for conduct outside the exemption, and gives the Attorney General authority to seek injunctive relief. That is a more constrained architecture than the word “waiver” might suggest.
But two features deserve reconsideration.
First is transparency. Filings made to the Antitrust Division under the bill would be shielded from FOIA, without a corresponding requirement for a public notice identifying the participants and the general scope of their collaboration. That choice unnecessarily strengthens the critics’ argument.
There are models for doing this differently. The NCRPA uses Federal Register notices to identify participating firms and the general nature of covered ventures. Defense Production Act voluntary agreements likewise operate within a framework of governmental supervision and public notice. A safety exemption need not disclose vulnerabilities, model weights, threat intelligence, or other sensitive technical information. But the public can reasonably be told who is coordinating, under what authority, and about what general category of restraint.
Second, the bill lacks a sunset. That matters because antitrust exemptions have a tendency to survive the circumstances that originally justified them. Their benefits are concentrated among identifiable participants; their competitive costs are dispersed among potential entrants, customers, and innovators who may not yet exist.
The Y2K experience offers a better model. In the Year 2000 Information and Readiness Disclosure Act, Congress temporarily protected certain information sharing undertaken to address a discrete technological threat and gave the protection an expiration date. The law addressed the emergency and then disappeared with it.
AI risk is obviously not Y2K. But the institutional lesson is this: extraordinary permission to coordinate should come with an obligation to periodically justify why that permission remains necessary. That safeguard is particularly important where legislation identifies bodies such as the Frontier Model Forum as potential vehicles for coordination. A regulation designed around today’s frontier firms can easily become tomorrow’s barrier to entry.
A statutory exemption may ultimately be justified. But if Congress creates one, it should be transparent, bounded, reviewable, and temporary unless affirmatively renewed.
Path Four: Defense Production Act Section 708
There is a fourth path, and it has existed since 1950. Section 708 of the Defense Production Act authorizes the federal government to sponsor voluntary agreements among private firms in circumstances tied to national defense. Its architecture is strikingly well suited to the central problem in the AI debate.
A sponsoring federal agency develops the voluntary agreement in consultation with the Attorney General and the FTC Chair. Before the agreement takes effect, the Attorney General must determine that its purpose cannot reasonably be achieved through less anticompetitive means. The plan operates under governmental supervision. Notices and plans are published in the Federal Register. Government representatives may attend meetings. And participating firms receive an antitrust defense only for conduct that remains within the authorized plan.
In short, Section 708 does something a private agreement cannot: it puts a public principal in the room.
Despite its age, the provision is not a historical curiosity. FEMA used Section 708 during the COVID-19 pandemic to coordinate medical supply chains. The Department of Energy used the authority in 2026 in connection with domestic nuclear-fuel coordination.
And the jurisdictional fit for at least some AI risks is substantial. The Defense Production Act defines “national defense” broadly enough to encompass homeland security and critical-infrastructure protection—categories that overlap with the threats AI labs themselves emphasize, including cyber capabilities, CBRN uplift, and attacks on critical systems.
There are, however, two significant caveats.
First, Section 708 fits the security agenda better than the pace agenda. Coordination to address model theft, weapons uplift, cyber threats, or other national-security risks maps naturally onto the statute. A generalized agreement to slow capability development is a more aggressive use of the authority and may invite precisely the legal uncertainty the labs are trying to escape.
Second, Section 708 requires a willing government convener. The current administration has framed AI development largely as a geopolitical race, particularly against China, and has shown little appetite for a generalized slowdown in frontier development. In short, the statute exists but the current administration appears reluctant to use it.
Still, Section 708 illustrates an important point. We do not have to choose between unsupervised private coordination and no coordination at all. Federal law already contains institutional designs for allowing rivals to cooperate against genuine national threats while retaining governmental oversight.
The Binary is False
The labs say they need room to coordinate against catastrophic risk. Their critics say they should not be allowed to form an anticompetitive cartel.
The distance between them is not principally a question of whether coordination is “allowed.” It is a question of what is being coordinated, how much competitive discretion the firms surrender, and who ultimately makes the decision. Joint research, safety evaluation, red teaming, and threat exchange can proceed under ordinary antitrust principles. The revived business review process offers another mechanism for obtaining enforcement guidance, if the DOJ is willing to entertain such requests. Joint advocacy for government-imposed capability restrictions is broadly protected by Noerr-Pennington. And the Defense Production Act offers yet another path for industry coordination with government involvement. Frontier AI companies therefore have considerably more room for collective safety work than the current debate suggests, and the prudent approach is most likely a convergence of multiple of these paths.