I think it's not just model releases but also model training.
For example, [1] discusses allowing all frontier labs to pause training the next generation model while being able to verify that their competitors have done the same, or agreeing to not undertake recursive self-improvement. This could involve using the remote attestation features [2] that some chips already bake in to determine whether they are being used for inference or training.
[1]: https://blog.peterwildeford.com/p/pacing-the-frontier
[2]: https://www.nvidia.com/en-us/data-center/solutions/confident...