The strategic-competition scenario is the one the framework is weakest at, because it turns on trust the framework cannot manufacture. So the program does not ask rivals to be good; it tries to make restraint observable and defection less rewarding, which is the only footing on which cautious actors can act cautiously without being punished for it. It leans on the framework’s pacing and absorption work — verifiable pacing, the defection test, and embedded independent evaluation — and is clear that the hardest pieces belong to diplomacy and arms control, not to social architecture.
1. Verifiable pacing
The first concrete project, because everything else rests on it: not everyone promises to be careful but shared capability thresholds, third-party evaluation, audit access, incident reporting, measurable safety requirements, and rules triggered by specific capability levels. The aim is to make restraint observable — without that, cooperation is brittle, because a promise a rival cannot check is a promise a rival will not trust.
2. Safety floors, not ideal harmonization
A realistic early goal is not that all actors converge on one AI philosophy but a minimum shared floor — no deployment past a capability threshold without specified testing, no autonomous cyber system above a certain capability without containment. The framework can live with plural systems as long as the basic ecology stays intact, which makes a floor far more achievable than harmony.
3. Crisis communication channels
If powerful systems behave unexpectedly — autonomous action, propagating cyber incidents, model theft, a military system misclassifying an event — rival states and firms need ways to talk before they read an incident as an attack. The analogy is the nuclear hotline: unglamorous, and potentially decisive in the minutes that matter.
4. Shared incident database
Actors need a way to report serious failures — misalignment incidents, major cyber escapes, dangerous autonomous behavior, model theft, bio-risk breaches — without automatically surrendering all competitive advantage. The obvious difficulty is that companies and states will hide incidents, which is exactly why protected reporting channels and embedded evaluators matter here as much as anywhere.
5. Competition-safe coordination
Firms avoid coordination for antitrust reasons and states for sovereignty reasons, so a distinct project is the legal architecture that permits narrow safety coordination without cartelization. It is a mundane-sounding barrier that blocks a great deal of otherwise-possible restraint, and clearing it is a precondition for most of the projects above.
6. Capability-triggered checkpoints
Regulate capability thresholds rather than calendar dates: when systems can defeat common sandboxes, autonomously run sophisticated cyber operations, materially accelerate AI research, manipulate large populations, or design dangerous biological agents, specific restrictions or verification requirements activate. This handles deep uncertainty far better than by 2028 do X, and it is the strategic-competition form of the framework’s readiness clock.
7. Strategic lead buffers
The uncomfortable, real one: if a bloc believes slowing means losing decisive advantage, it will not slow. So pacing may require enough strategic margin that restraint does not feel existential — the framework should not pretend this geopolitical dimension away. It is the collective form of the defection test: a safeguard that makes its adopter fatally vulnerable will not be adopted.
8. Mutual-vulnerability recognition
When all major actors recognize that certain failure modes harm everyone — uncontrolled autonomous cyber systems, bioweapon design, runaway self-improvement, infrastructure attacks — a basis for shared restraint appears. This is how arms-control agreements often become possible in the first place: you do not need friendship, you need overlapping fear, and a clear-eyed map of what no one can survive.
9. Anti-winner-take-all infrastructure
Races worsen the more enormous the payoff to being first, so a longer-term project is to reduce the degree to which frontier success confers total downstream jurisdiction — open technical standards, shared safety infrastructure, interoperability, public compute, distributed ownership, limits on vertical control. If winning the race does not mean controlling everything after it, the race becomes less existential; this is the ownership-concentration program pointed at the incentive structure of competition itself.
10. Protected internal dissent
Firms and governments need people who can say this is moving too fast without being treated as disloyal, because runaway competition is at its most dangerous when internal dissent is suppressed with the rival won’t wait — a phrase that can justify almost anything. Protecting whistleblowers, safety teams, internal review bodies, and dissenting scientists keeps a source of correction alive inside the actors that most need it.
The timeline
This scenario is already active, so the earliest phase is not preparation for a future problem but response to a present one. The dangerous threshold is the point where capability acceleration outruns the ability to verify each other’s restraint.
| Period | Transition objective |
|---|---|
| 2026–27 | The urgent floor — embedded evaluators, shared incident reporting, common safety floors, crisis communication, capability thresholds, and the legal room for safety coordination. |
| 2027–29 | The regimes — stronger national coordination, verification regimes, international standards, model and compute monitoring, and negotiated limits on the most dangerous capabilities. |
| 2029 onward | If recursive self-improvement or highly autonomous systems become materially important, competition may move faster than diplomacy — so the agreements have to be already in place before this phase, not begun during it. |
Guarding the safeguards
Every safeguard here is dual-use in the geopolitical arena, which makes this the most capturable program in the set. “AI safety” can cripple a rival; regulation can entrench an incumbent; verification can become espionage; safety coordination can become a cartel; export controls can become economic domination. So the recurring drift question has to be asked of each one — is this preserving the shared field, or has it become another instrument of strategic advantage? — because in a race, advantage will always reach for the language of safety. And the framework is candid about the boundary of the whole program: it can build the target, the accounting, and the observability, and it cannot make hostile actors trust one another, verify their secret programs, or enforce a treaty. Those belong to diplomacy, intelligence, arms control, and verification technology — the mechanisms this scenario depends on more than any other, and without which its principle stays true and unenforced.