Class: where the framework offers safeguards but not sufficient protection — and, operationally, one of its weakest areas. See the hard standard below.
The threat
This may be the hardest scenario politically, because nearly everyone can see the danger and keep accelerating anyway. The structure is simple and brutal: each actor knows the race is dangerous, but slowing unilaterally may hand a decisive advantage to a rival — and this holds between firms, states, military blocs, even research teams. The problem is not ignorance; it is incentive incompatibility. That is precisely why it is hard for this framework: the framework is much stronger at describing a healthy ecology than at solving a prisoner’s-dilemma race among powerful actors who distrust one another.
The NWG end state
In the framework’s terms, runaway competition is a failure of shared traversability: each actor sees only its own road — if we slow, they pass us — and so every participant rationally accelerates locally even as the ecology globally becomes less safe. It is the textbook case where local viability produces global fragility — the mechanism worked out in full. The framework can name the damage precisely: standing is threatened because losers may lose strategic autonomy; capacity expands but in a destabilizing way; jurisdiction concentrates in whoever wins; dissent becomes expensive; safety costs are externalized; and correctability shrinks because no one feels able to stop and reconsider.
The mature state does not abolish rivalry — it bounds it by shared survival constraints. Some things must sit above the competition: no actor may externalize catastrophic risk onto everyone else; safety-critical capabilities require common verification; certain thresholds trigger shared pacing or review; and strategic advantage cannot justify destroying the ecology all actors depend on. Compressed into a principle, this is the shared-viability constraint: no participant may pursue local advantage by consuming the field conditions everyone else needs to keep participating. It is the strategic-scale sibling of the framework’s defection test and of commensurate pace — restraint that stays viable only if others can be seen to restrain too.
Which is why the central difficulty is not values but trust. We will slow if you slow, say both sides, and neither believes the other, so voluntary restraint is unstable. The framework does not solve this by moral appeal; it needs verification architecture — restraint made observable through shared capability thresholds, third-party evaluation, audit access, and incident reporting, so that a promise becomes something a rival can check rather than merely believe. This is the same conclusion the framework reaches in its pacing and absorption work: pacing that cannot be verified is brittle, and embedded, independent evaluation is what makes it hold.
The transition gap
The gap is that verification architecture barely exists, and the tools that could build it are entangled with the very rivalry they would constrain. Firms avoid coordination for antitrust reasons; states avoid it for sovereignty reasons; and every actor has private incentive to hide its incidents and overstate its restraint. Meanwhile the clock is set by capability, not diplomacy: the dangerous threshold is the point where capability acceleration outruns institutions’ ability to verify each other’s restraint — beyond which the race becomes self-reinforcing, because no one can afford to be the one who paused. And the realism the framework has to swallow is that unilateral restraint can be simply fatal, so pacing must often preserve enough strategic margin that restraint does not feel existential — an uncomfortable constraint it should not pretend away.
Transition projects
Because trust cannot be assumed, the program is built around making restraint observable and making defection less rewarding. The full set is on its own page: the transition program — verifiable pacing and minimum safety floors (not ideal harmonization), crisis-communication channels and a shared incident database, competition-safe coordination that avoids cartelization, capability-triggered checkpoints, strategic-lead buffers, mutual-vulnerability recognition, anti-winner-take-all infrastructure that lowers the payoff to being first, and protected internal dissent — sequenced from the safeguards that are urgent now to the verification and coordination regimes that must exist before recursive capability growth accelerates.
Capture risks
This scenario’s capture risk is unusually severe because every safeguard is dual-use in the geopolitical arena. “AI safety” can be used to cripple a rival; regulation to entrench an incumbent; verification to conduct espionage; safety coordination to run a cartel; export controls to pursue economic domination. So the framework has to keep asking the recurring drift question of every safeguard here: is this actually preserving the shared field, or has it become another instrument of strategic advantage? — because in a race, the language of safety is exactly what advantage will wear.
The limits
This is, plainly, one of the framework’s weakest areas operationally. It can diagnose the ecology and name what a healthy arrangement must preserve, and it cannot make hostile actors trust one another, verify secret programs, resolve intelligence asymmetry, enforce a treaty, stop cheating, or set a deterrence posture. Those belong to diplomacy, intelligence, arms control, verification technology, national-security policy, and technical safety — the mechanism layer this scenario leans on more heavily than any other in the strong or safeguards classes. The framework contributes the target and the accounting; it cannot supply the coordination, and where cooperation fails this scenario feeds directly toward loss of control.
The hard standard
Standing is defended where the framework can reach — protected opposition and distributed governance hold the line against “we can’t afford dissent, we’re in a race” — but that reach stops at the border between rivals. Ecological capacity is steadily degraded by the race itself: corners cut, costs transferred, renewability spent for position, with the framework’s real instrument being to make that erosion visible rather than to prevent it. Ontological correctability is what a race attacks most directly, because it destroys the time to stop and check — the right to pause and protected opposition are the defenses, and they are weak against a genuine arms race that reads every pause as surrender.
The verdict is second class, at its lower bound: the framework addresses the internal drivers of a race — concentration, suppressed dissent, hidden costs, winner-take-all payoffs — and cannot solve the external coordination failure among rivals that defines it. Its cleanest principle is easy to state and hard to realize: no participant may gain strategic advantage by degrading the shared conditions required for all participants to remain viable. Saying it is easy; making rivals believe everyone else will obey it is the entire game — which is why, here more than anywhere, the framework’s job is to build the verification and lowered stakes that let restraint become believable, and to be clear that it cannot manufacture the trust itself.
No participant may gain strategic advantage by degrading the shared conditions required for all participants to remain viable. You do not need friendship to hold that line — you need overlapping fear, and a way to see that others are holding it too.