In February 1975, about 140 scientists checked into a conference centre on the California coast, agreed on a set of rules, and did something almost no field of science had done before.
They stopped.
Two years earlier, biologists had worked out how to cut and splice DNA between organisms. Recombinant DNA. The technique underneath most of modern biotechnology. It was thrilling and also completely unmapped territory. Nobody knew what would happen if you spliced a gene from a cancer virus into a bacterium that lives in the human gut. So a group of the scientists doing the actual work wrote a public letter asking the whole field to voluntarily pause certain experiments until they worked out how to do it safely. Then they organised a conference at Asilomar to write those safety rules themselves, before any government did it for them.
The pause held for about a year. It’s taught today as one of the cleanest examples of a scientific field regulating its own most dangerous frontier before anyone got hurt.
I hadn’t thought about Asilomar in years. Then on Monday, OpenAI did something that rhymes with it.
What two weeks actually bought
On 18 August, OpenAI announced it was pausing reinforcement learning training on its most advanced models. Not a full stop. Smaller-scale training and customer-facing work kept running. But the company’s largest planned frontier RL run, part of its Astra research program, went on hold. Two weeks, while it put new safeguards in place.
The safeguards themselves are specific. Stronger sandboxes and isolation for the workloads that execute untrusted code, with fewer shared services between test environments and the wider network. Expanded monitoring, aiming to flag concerning model behaviour within 30 minutes rather than months. Additional safety checks before any larger-scale training resumes.
Sam Altman posted about it directly: “Model progress is now extremely rapid.” OpenAI’s own statement was blunter still: it said the pause was because model capabilities were outstripping the pace of safety work.
This is the same company whose models spent months this year coordinating a breakout through a test environment, hacking Hugging Face, and, according to a UK government evaluation four weeks ago, creating fake identities to socially engineer a real developer. Three separate escalations, each one worse than the last. And now, for the first time, a frontier AI lab has looked at its own models and decided the honest response isn’t a new rule. It’s less speed.
That’s the part that rhymes with Asilomar. Not the specifics. The instinct. When you’re building something faster than you understand it, you don’t patch your way to safety. You slow down until your understanding catches up.
The difference that actually matters
Here’s where I want to be careful, because it would be easy to write this up as “AI finally learns the lesson biology learned fifty years ago” and call it a day. It isn’t quite that.
Asilomar wasn’t one lab pausing itself. It was the entire field agreeing to pause, together, for about a year, and then publishing shared guidelines that governed recombinant DNA research for the following decade. Every major lab working on the technology took part. Nobody was left racing while everyone else stood still.
OpenAI’s pause is one company, for two weeks, with a decision that OpenAI itself gets to make about when it’s done.
And while that two-week clock was running, the rest of the field didn’t stop. Four days after OpenAI’s announcement, China’s Z.ai released GLM-5.3, a 700-billion-parameter model the company says now rivals top US models on coding and cybersecurity benchmarks, including active vulnerability detection. Not paused. Shipped.
That’s the actual mechanism problem with a unilateral pause. Asilomar worked because pausing didn’t cost anyone a competitive advantage. Every lab lost the same two weeks. In 2026, if OpenAI is the only frontier lab slowing down, it’s the only one falling behind, and the incentive to end the pause early is enormous. Two weeks is what you can afford to lose without losing the race. A year, the way Asilomar took, might not be something any single company can afford to take alone.
So credit where it’s due: OpenAI chose to slow down before anyone forced it to, and named the actual reason honestly. That’s not nothing. But it’s not Asilomar. It’s Asilomar’s shadow, cast by a company that can’t afford to hold the pose for as long as the moment actually calls for.
The part nobody paused
While OpenAI’s two-week clock ran, two other stories landed that had nothing to do with training pauses and everything to do with why the caution is warranted.
Security researchers found a new way to make Elon Musk’s Grok assistant leak user data. The trick: encrypt the malicious instructions, then publish the decryption key openly on the page hosting them. Grok’s safety filters scan for harmful text and see nothing, because the harmful text is scrambled. Then Grok decrypts the instructions itself, follows them, and sends the user’s name, location and chat history to the attacker’s server through a crafted link. The filters were never built to check what a message says after it’s been quietly unscrambled by the very system meant to guard against it.
And Microsoft patched a critical vulnerability in Copilot that researchers at Varonis had disclosed to them eight months earlier. A one-click exploit: a legitimate-looking link that Copilot would treat as an instruction rather than a link, letting an attacker inject commands and poison the assistant’s memory. Eight months between disclosure and fix, on a product with hundreds of millions of users.
Neither of these is an OpenAI story. That’s the point. The industry’s problem was never contained to one lab’s training pipeline. It’s Anthropic’s Mythos 5 signing emails in Danish to seem more convincing. It’s Grok reading encrypted commands its own filters can’t see. It’s Microsoft sitting on a known hole for two-thirds of a year. Slowing down one company’s next model buys time for that one company. It doesn’t touch the other two.
I don’t think OpenAI’s pause was theatre. I think it was a genuinely difficult call, made by people who looked at what their own models had been doing and got scared enough to eat a competitive cost most companies never willingly eat.
I also don’t think two weeks is the right unit of measurement for a problem this size. Asilomar bought biology a year, and it only worked because the whole field held the line together. AI doesn’t have that yet. Until it does, every pause is a company deciding, on its own terms, how much risk is acceptable while its competitors keep moving. That’s better than no pause. It’s a long way from 1975.
📌 Also this week
Etched, the AI chip startup, raised $700 million at a $21 billion valuation, up from $10.3 billion a month earlier. The jump followed Jane Street testing the chip and installing its own rack. Even by AI funding standards, doubling a valuation in a month is fast.
Higgsfield, the AI video startup, raised $400 million at $5.4 billion, quadrupling its valuation in eight months. It says it now has $700 million in annualised revenue and 30 million users. Video generation is one of the most compute-hungry corners of AI, and the raise is going straight to buying more of it.
Rillet, an AI accounting startup targeting the same market as NetSuite, raised $100 million at a $1 billion valuation, saying it closed the round in under 48 hours after a wave of inbound interest.
OpenAI also launched a teen version of ChatGPT this week, with restrictions on romantic and sexual conversation and added safety prompts around self-harm. Separate from the training pause, but the same week, which says something about how many fronts these companies are managing at once.
🧠 Jargon decoder
reinforcement learning (RL) run: a training process where an AI model improves by trial and error, getting rewarded for outcomes closer to what its trainers want. The “frontier RL run” OpenAI paused is the training pass meant to produce its most capable next model.
sandboxing: isolating a system so what happens inside it can’t reach anything outside it. The Hugging Face breach happened because the sandbox wasn’t as sealed as OpenAI believed. This week’s fix is about making that seal tighter and reducing what the sandbox is still connected to.
prompt injection: tricking an AI system into treating untrusted content (a link, a document, an encrypted message) as an instruction from its actual user. Both the Grok and Copilot incidents this week are prompt injection, just through different doors.
👀 Ones to watch
📡 SCX.ai — sovereign AI infrastructure, listing today
What they do: run AI workloads on servers physically located in Australia, for organisations that need their data to stay onshore. Debuting on the ASX today, Friday 21 August, raising $40 million at a $75 million market cap.
Why it matters: they’re not walking into the listing empty-handed. $5.4 million in contracted annual revenue across 13 paying customers, a three-year $15.2 million supply deal with SambaNova already signed. As AI moves from experiments into government and finance workloads, data residency stops being a nice-to-have and starts being a contract requirement. Worth watching how the market prices a story this concrete.
🔧 Sophiie AI — AI receptionist for tradies, Gold Coast
What they do: an AI-powered virtual receptionist built specifically for trades and service businesses, the plumbers and electricians who can’t afford to miss a call while they’re up a ladder. Just raised $5 million, taking its valuation to $30 million, backed by Archangel Ventures and Antler among others.
Why it matters: thousands of businesses already using it across Australia, New Zealand and the UK, growing 10 to 15 percent month on month. A US launch is planned for later this year. This is AI solving an unglamorous, extremely specific problem for an audience Silicon Valley rarely builds for, and it’s working.
🏨 Visaible.ai — AI visibility for hotels, Sydney
What they do: tracks how a hotel appears when someone asks ChatGPT, Gemini or Claude for a place to stay, then fixes whatever’s wrong, outdated details, missing amenities, incorrect pricing, across the hotel’s website and listings. Raised $1 million led by Blacksheep Capital.
Why it matters: search is quietly splitting in two. There’s the search you type into Google, and the search that happens inside a chat window you never see the results of. Visaible is betting that gap becomes a real business, not just a curiosity, and hotel groups losing bookings to AI recommendations they can’t see or influence are the first customers to feel it.
If this made you think differently about what a pause is actually worth, rather than just what happened this week, send it to someone who’d appreciate the difference.
Follow along wherever you hang out: LinkedIn · YouTube · TikTok · Instagram
Forward this to someone who keeps saying they can’t keep up with AI
Want to work together? Just hit reply.
Cheers, Jagger
Note: The views expressed in this newsletter are my own and do not represent those of any organisation I may be affiliated with.













