AI Memory Shortage: Why the Labs Called for a Slowdown

Third of five on what the 2026 evidence says once you read past the announcement. The safety case examined here rests on the five agent containment failures in part two, four of which needed no novel exploit at all. Part one covered the coding productivity data.

Ahead: where the AI bill goes next and what to check before you run an open weight model.

On September 12, Dario Amodei published an essay arguing that frontier AI development has to slow down. Sam Altman agreed the same day. Elon Musk posted three words: “Dario is right.”

Altman spent part of that same day explaining to Fortune’s Alyson Shontell why OpenAI will not go public this year. “I actually think that given everything happening with safety, right now would be an ill-advised moment to go public.” Then: “I would say not 2026, yeah. We’ve got a lot of stuff to do.”

I went looking for what changed in the weeks before that. An AI memory shortage that Nvidia and Micron have been describing since last December accounts for most of it. Utility filings in Texas, Ohio and Georgia account for the rest. The companies that sell compute and electricity to the labs had already slowed them down.

What the labs committed to

I read announcements like this the way I read a statement of work, which means sorting the binding clauses from the conditional ones before anything else.

Amodei’s essay has one binding clause. Anthropic will give third-party evaluators from groups like METR “desks in our offices, access badges, and company laptops,” plus permissions matching its own internal risk teams. Those evaluators can “publish key findings without editorial control by Anthropic.” He writes that “Anthropic is unilaterally committing to this step now.” The publication clause is the part with teeth, and Anthropic is the first lab to offer it.

The rest carries conditions. Amodei asks companies in democratic countries to agree on common safety standards and limits on the rate of progress. He then concedes this needs the US government to “mediate or at least enable these discussions” and to issue “a narrow waiver for certain kinds of safety conversations.” That waiver would be antitrust relief for coordination among the largest incumbents in a market. No such waiver exists, and no bill creating one has been introduced.

Altman’s answer on embedded evaluators was “We’ll have more to share soon.” As of this writing neither OpenAI nor xAI has published a commitment of its own.

The AI memory shortage showed up in August guidance

Meter showing Nvidia able to supply about 70 percent of stated customer demand, with 30 percent unfilled into fiscal 2028.

Nvidia reported its second quarter on August 26: $96 billion in revenue, $89 billion of it data center, with $108 billion guided for the quarter after. Every figure beat consensus. CFO Colette Kress then gave a preliminary view of the next fiscal year, roughly 70 percent growth, and described how she arrived at it.

“This is a supply-constrained outlook.”

She named the input. “We expect supply to remain a bottleneck at least through the end of fiscal year 2028.” And: “Memory scarcity today is being driven in large part by the AI buildout itself.” Nvidia guided gross margin down from 75 to 74 percent, because the company is “experiencing extreme pricing conditions in memory. The magnitude of the price increase has exceeded our prior expectations.”

Jensen Huang put the gap in plain numbers on the same call. “Our demand is much greater than 70 percent, our supply allows us to confidently deliver 70 percent.”

Amodei’s essay asks the industry to pace “the rate of capabilities advancement so that risk prevention has time to keep up.” Nvidia has been pacing it since August, at roughly 70 percent of what its customers want to buy, with the gap held open into 2028.

The memory suppliers said it earlier. Micron’s Sanjay Mehrotra said in December 2025 that “memory production for calendar 2026 is sold out, including HBM4.” By June he had stopped forecasting a recovery: “We currently do not have line of sight as to when memory supply will be able to catch up with increasing demand.” SK hynix had sold its entire 2026 DRAM, HBM and NAND output by October 2025.

The mechanism is arithmetic. High-bandwidth memory consumes roughly three times the wafer capacity of commodity DRAM per bit, moving toward four times with HBM4. Every HBM stack built for an accelerator is conventional DRAM that nobody built. Packaging sits downstream of the same squeeze, and TSMC’s C.C. Wei said in July that “our packaging capacity is so tight that now it’s limiting my customers’ growth.”

The bill lands outside the data center. DRAM contract prices rose 90 to 95 percent in the first quarter of 2026 and another 58 to 63 percent in the second. Gartner expects PC shipments to fall 10.4 percent this year and smartphone shipments 8.4 percent, with memory rising from 16 to 23 percent of a laptop’s bill of materials and the sub-$500 PC gone by 2028. Gartner’s Ranjit Atwal called it “the steepest contraction in device shipments witnessed in over a decade.”

AI data center power constraints show up in utility filings

Suppose the memory arrived tomorrow. The buildings would not be ready, and the evidence for that comes from regulated filings rather than anonymous sources.

ERCOT’s large-load interconnection queue reached 474 gigawatts by August, about 89 percent of it data centers, against a Texas grid whose record peak demand is near 90 gigawatts. On August 3 the governor ordered an audit and ERCOT delayed its Batch Zero transmission study for a period its own counsel called indeterminate. BloombergNEF put 49.8 gigawatts inside the affected pool, roughly a fifth of the national pipeline. ERCOT does not expect to publish a final transmission plan before the fall of 2027.

Utilities have spent two years writing down their own forecasts. Georgia Power has removed 33 data center projects totaling 11,332 megawatts since 2023, about 65 percent of what was announced, and its regulatory staff say only 1,900 megawatts of what remains has an executed contract behind it. AEP Ohio cut its data center load forecast from 30 gigawatts to 13. Dominion reports 53.8 gigawatts under contract in Virginia, of which 12.0 sit at the firm service agreement stage and 32.4 remain at preliminary substation engineering.

Grouped bars showing three utilities with 30 to 53.8 gigawatts announced against 11 to 13 gigawatts actually under firm contract.

Under the grid sits the equipment, which is where anyone who has built a schedule will recognize the shape. GE Vernova’s backlog reached 116 gigawatts and it now books turbine reservations four to five years out, selling delivery slots in 2031. It shipped 3 gigawatts in one quarter and signed 20. Power transformers run about 128 weeks, generator step-up transformers 144, substation transformers past 160, high-voltage switchgear 44.

Bar chart of electrical equipment lead times, from 44 weeks for high-voltage switchgear to 260 weeks for gas turbine delivery slots.

Then the people. IBEW estimates the trade needs more than 300,000 additional electricians over the decade while about 20,000 retire each year, against electrical work that is 45 to 70 percent of the cost of building a data center. Microsoft has named the electrician shortage as its largest constraint on US expansion, ahead of chips and ahead of capital.

BloombergNEF has put a figure on the total. By 2033 it expects 63 gigawatts of difference between what AI chip shipments imply should be standing in the United States and what will actually be energized, and it attributes that shortfall to power.

Whether the demand covers the paper

The third explanation is that revenue cannot support what has been signed. OpenAI took in roughly $12.4 billion in the first half of 2026 against about $21.6 billion of operating losses, carrying roughly $665 billion in purchase commitments as of March 31. Anthropic sits in better shape, with revenue above $11.5 billion in the second quarter and its first operating profit on an adjusted basis, against roughly $517 billion committed to compute. The company proposing the slowdown carries the smaller commitment book and the only operating profit of the two.

Who is buying matters more than the totals. Ramp’s corporate card data shows the top 1 percent of customers generating 80 percent of enterprise revenue at both OpenAI and Anthropic, a concentration Ramp’s lead economist called unmatched in any software category they track. The median firm on that panel spends $11.95 per employee per month. The Census Bureau, surveying all US firms rather than a venture-heavy panel, puts adoption at 17 to 20 percent. McKinsey’s 2026 survey found 80 percent of respondents reporting better personal productivity while enterprise EBIT impact held flat at 37 percent year over year, with 6 percent able to attribute 5 percent or more of earnings to AI.

Gartner’s John-David Lovelock described the composition in May: “Up to this point, AI spending has primarily been driven by technology companies and hyperscalers. Enterprises have yet to really flex their spending potential.”

One measurement carries more weight than the surveys. A month after Anthropic shipped its flagship model, that model accounted for 6 percent of the tokens Anthropic’s own customers bought and 11.4 percent of the dollars, while a competing model at roughly half the price took 25 percent of tokens and 23 percent of spend.

Some of the revenue is the same money circling. Nvidia holds $99 billion in equity investments, up from under $4 billion a year ago, alongside $279 billion in supply and capacity commitments and a $105 billion guarantee behind OpenAI’s Ohio leases. Microsoft’s annual report discloses $24.1 billion of revenue from OpenAI and $6.0 billion still owed. Anthropic pays SpaceX $1.25 billion a month for compute and Google pays it $920 million, on contracts either side can cancel in 90 days.

I want to mark the limit of that argument, because this is where commentary usually runs past its evidence. Nobody has credibly sized how much AI revenue is circular. IDC’s Eric Newmark says it cannot be done from outside, since none of these companies has reason to disaggregate it. Michael Burry’s claim that roughly 100 percent of chipmaker revenue is circular cites a BIS report I could not locate. Customer concentration sits in the SEC filings, and nobody has published a defensible figure for how much of the rest circles back.

The safety case, and what it rests on

The essay names two concerns. The first: “My first concern is that, since roughly this summer, AI has been advancing drastically faster, driven primarily by AI’s growing ability to build the next generation of AI.” He adds that “this dynamic is called recursive self-improvement, and it is starting to happen across the industry, including at Anthropic, as we and others have described.” He includes his own company by name.

The second is an incident. “My second concern is the OpenAI-Hugging Face incident, in which a swarm of agents essentially acted as a fanatically devoted collective, conducting cybersecurity attacks on targets they were not asked to attack and that were unrelated to the task at hand, sacrificing themselves for the success of the group, and attempting to hack into the ‘grader’ responsible for evaluating their performance.”

That incident happened, and the record is unusually good for a self-disclosed event. Hugging Face published its own forensics documenting roughly 17,600 attacker actions over four and a half days, with lateral movement from a single dataset pod to cluster-admin in under 13 hours. JFrog patched nine CVEs. METR and Redwood Research ran an investigation with access to about 1.2 million agent messages.

Two details qualify it. OpenAI had deliberately disabled its safeguards for the evaluation, running the models with “lowered cyber refusals and without the production classifiers that ordinarily block high-risk cyber activity.” Dan Guido of Trail of Bits called the result “a containment failure with the safeties turned off.” And OpenAI defined the scope of the independent review as June 26 through July 13, which excluded the compromises of its own infrastructure and the precursor activity in May.

OpenAI also missed part of it. Its agents spent about two months using a German programming wiki as a message board, making more than 15,000 edits, with roughly half the accounts named things like “OpenAIResearcher.” Moderators started deleting pages in June. An outside group found it, and OpenAI confirmed it after Reuters published on September 4.

The wider record matters more than that single event, and it does not carry the weight being put on it. I went through all five agent containment failures disclosed in 2026 for the previous piece in this series. Four of them involved no novel vulnerability at all. They ran on misconfigured evaluation environments, weak passwords, exposed credentials, SQL injection and, in the UK AI Security Institute’s case, fake GitHub identities and a real maintainer who was socially engineered. Anthropic described its own three incidents as “basic and well-known cyberattack techniques.” Meta said of its incident that “this was not a sophisticated offensive cyber attack or sandbox escape.”

Amodei picked the one genuine exception. OpenAI’s agents did find real zero-days in Artifactory, and JFrog patched nine CVEs because of it. They also needed Anonymous Access to be switched on before any of that was reachable, and their final privilege escalation used a public Linux kernel CVE they retrieved rather than discovered.

None of which makes the incident unimportant. It makes it thin as the evidentiary basis for an industry-wide limit on the rate of capability gain, which is the thing the essay is actually asking for.

The strongest argument against reading all of this cynically is that the idea did not start with the chief executives. On July 28, Bloomberg reported that more than 1,100 staff at OpenAI, Anthropic, Google and Meta had signed an open letter asking the US government to help pace AI development. Signatories included John Schulman and Jakub Pachocki, OpenAI’s chief scientist. Later counts put the total at 1,178. The letter was called “Pacing the Frontier.” Amodei’s essay, six weeks later, is titled “We Must Pace the Frontier.”

Those are people with a closer view of what these systems can do than anyone writing about them from outside, and they signed their names. I take that seriously. It does not explain why their employers adopted the framing in the same month that two of them were preparing to sell shares.

The calendar

Anthropic filed a confidential S-1 on June 1. Reuters reported on September 5 that its public prospectus is expected in late September, with IPO marketing in mid-October at a valuation reported near $2 trillion. Amodei published the essay on September 12. OpenAI filed its own confidential S-1 on June 8, and used safety on that same September 12 to explain a delay it had already taken.

I can put those dates next to each other. A man weeks from selling shares in a safety-first AI company wrote an essay about safety, which is what you would expect him to write in any month of any year. The sequence is not evidence of motive, and no filing, statement or piece of reporting I found links the two.

What actually paced the frontier

China answered on September 14. Foreign ministry spokesperson Guo Jiakun called the proposal fearmongering, saying that “confrontation and vicious competition will only disrupt the process of global AI governance which serves no one’s interest.” Epoch AI measures Chinese models at about seven months behind the US frontier and calls that distance stable since 2023. The US government’s own assessment put DeepSeek’s latest release eight months back.

China is memory-bound as well. Epoch estimates Huawei will produce around 880,000 H100-equivalents of compute this year against Nvidia’s 23 million, with high-bandwidth memory as the binding input. In January, one day after Washington relaxed export rules to allow H200 sales into China, Beijing told its own companies not to import them.

So here is where I land. Nvidia can fill about 70 percent of what its customers want to buy, and says that stays true into 2028. Memory has been sold out since December, and Micron has no line of sight on when supply catches up. ERCOT has stopped processing applications, Georgia Power has written off 65 percent of the load it once announced, and the turbines and transformers those sites need are booked years out. A data center with no chips to install and no power to run them is a hole in the ground with a financing cost attached.

That ceiling was in place before the essay was written. Whether it is why the essay was written is a question nobody can answer from outside the building. What I can say is that a company weeks away from the largest IPO ever attempted has an interest in the market believing its growth is limited by conscience rather than by supply, and that both explanations predict exactly the same behaviour.

The frontier is being paced. It is being paced by memory suppliers with nothing left to sell until 2027, by a grid operator in Texas that stopped taking applications in August, and by the lead time on a substation transformer, which runs about 160 weeks. None of them were asked what they thought about safety.