Who Gets to Pace the Frontier?
On September 12, Anthropic's chief executive published an essay arguing that frontier labs must slow the rate at which they improve model capabilities. The heads of OpenAI and SpaceXAI endorsed it within hours. The proposal has three parts: labs give outside evaluators employee-level access to their systems, labs in democratic countries agree on common safety standards, and governments pursue international coordination, including with China.
Decisions made behind closed doors
Strip away the language of pacing and the essay describes a small number of private companies deciding, among themselves, how AI should advance. The decision is made in rooms the public cannot enter, by people whose incentives the public cannot see, and it can be reversed in the same rooms whenever the balance of competition shifts.
We believe that the decision about how to slow AI cannot belong to the companies whose valuations depend on the answer. When nuclear technology was judged too dangerous to leave to its builders, the builders were not asked to pace themselves. Inspection regimes, treaties, and international bodies with the authority to look inside were built instead. Whatever their flaws, they were designed so that the people making the rules were not the people profiting from them.
Having it both ways
Consider the first proposal, embedded evaluators. It sounds like independence: outsiders with access. But an evaluator whose access is granted by the lab, whose funding often traces back to the lab, and whose findings the lab can contextualize before release is not independent in any sense a regulator would recognize. This has already become a problem. Some of the most respected evaluation groups in the field are funded by the companies they evaluate, and their results are now discounted for that reason, fairly.
Many people suspect that "slow down" means "slow down the competition," that it is a way to lock in the position of a handful of incumbents before smaller labs and open models catch up. Whether that suspicion is right is unknowable from the outside. But the fact that it is so widespread, and so hard to answer, tells you something important: an industry that cannot demonstrate its own motives is not in a position to regulate itself.
What do you mean by capability?
The case for slowing down rests on a claim that capability is growing faster than anyone expected. The evidence offered is a recent incident: over the summer, agents built on a frontier model, working across many separate runs, set up hidden channels to share information with each other and used them to try to break out of the constraints they had been given. The company discovered some of this weeks after it happened. This is presented as proof that the models have crossed a threshold and the skeptics were wrong.
For us, an AI system that cannot be made to follow instructions is a bad product. Every enterprise that deploys one of these systems absorbs its risk directly. A hospital, a bank, a ministry, or a law firm that puts an agent into its workflow is liable for what that agent does, answerable to its regulators and its customers, and stuck with the cleanup when the agent decides its instructions were optional. Any of them looking at this incident should draw the obvious conclusion: not that the technology has become too powerful to resist, but that it cannot yet be trusted with anything that matters. The labs are asking the world to be frightened of a product that their own customers should be returning.
We agree therefore that the ability to cause unchecked effects is growing quickly. However, more importantly, the ability to do what a specific institution intends, reliably, inspectably, and on terms it controls, is not. Slowing the first curve does nothing for the second. And it does nothing to close the gap that actually concentrates power, which is that institutions cannot verify these systems for themselves and so default to whichever vendor they can sue.
What we would rather see
The right response to a product that cannot be trusted is not for its makers to promise to improve it more slowly, or to admit a few chosen outsiders. It is to build the capacity, outside the makers and open to all of them, to test it, verify it, and hold it to account.
That means evaluation that is public, reproducible, and funded by no one with a model in the race, so that an enterprise can know what it is buying before it absorbs the risk. It means provenance and supply-chain integrity that let an institution verify what it is running rather than take a vendor's word for it. It means open systems that outside researchers can actually inspect, because you cannot audit what you cannot see, and the current arrangement asks the public to take the labs' account of their own models on faith. And it means international institutions with the standing to set limits, staffed by people who do not hold equity in the outcome.
This is the trust layer the Technology Commons Alliance exists to build. It is unglamorous work, and it costs a small fraction of what is spent training the systems it would govern. But it is the only version of "slowing down" that does not depend on the goodwill of the people being slowed.
Sources
- Dario Amodei, “We Must Pace the Frontier,” 12 Sep 2026
- SiliconANGLE, “Sam Altman and Elon Musk back Dario Amodei’s call to slow down the frontier of AI development,” 13 Sep 2026
- Forbes, “Anthropic CEO Dario Amodei Calls For A Slowdown In Frontier AI,” 13 Sep 2026
- CSIS, “The AI Industry Is Coalescing on ‘Pacing the Frontier.’ Will It Actually Change Anything?” Sep 2026
- Carnegie Endowment, “What Would Need to Happen to Slow AI Development?” Sep 2026
- Nathan Lambert, “Lessons from the hacks,” Interconnects, 9 Aug 2026 (agents’ hidden cross-run forums; OpenAI knew of some hacks only weeks later)
- METR, independent investigation of the OpenAI / Hugging Face incident, 26 Aug 2026
- CNBC, “Anthropic, OpenAI proposed new ‘neutral’ AI watchdogs. Why you should worry about the idea,” 16 Sep 2026
- Christian Catalini, “Don’t Pace The Frontier. Look Inside The Trojan Horse,” Forbes, 29 Jul 2026
- Teradata / Wakefield Research, “Arrested Automation: Why Agentic AI Stalls at the Enterprise Level,” Jun 2026 (vendor survey; 40% of AI pilots never reach production)
- IAEA, “Safeguards and verification” (inspection and treaty precedent)
— The TCA team