'We Must Pace the Frontier': what Anthropic's AI slowdown plan slows, and what it protects
Dario Amodei published a 3,800-word essay on 12 September asking the AI industry to slow capability gains, and within 48 hours Sam Altman, Elon Musk, Demis Hassabis and Satya Nadella agreed. The risks he describes are real. The timing sits four days after a US advisory on Chinese distillation of frontier models and weeks before a reported $2 trillion IPO. Here is what the plan would slow, what it would protect, and what a company buying AI should do about it.
On Saturday 12 September, Anthropic's chief executive Dario Amodei published an essay titled "We Must Pace the Frontier". Its central sentence is short: "We must slow the pace at which we improve the capabilities of AI models." The rest is a three-step plan for doing so, and a commitment that Anthropic will take the first step on its own.
Within two days the plan had been endorsed by the people it would bind. Sam Altman wrote that OpenAI had been discussing the same idea for weeks and would match Anthropic's commitment to independent evaluators. Elon Musk, whose xAI builds Grok, posted three words of agreement. Demis Hassabis of Google DeepMind said the direction was correct and the details needed work. Microsoft's Satya Nadella signed on the following day. The Wall Street Journal's headline summed it up as the biggest AI rivals agreeing they need to slow down.
That is a remarkable amount of consensus for an industry that spent the first eight months of 2026 shipping a frontier model roughly every five weeks. Consensus among competitors deserves a second look, and this piece is that second look. The risks Amodei describes are real, and I want to say that plainly before the sceptical part. What I question is the timing, the shape of the proposal, and who it leaves outside the fence.
What the essay proposes
Amodei is careful to say pacing does not mean pausing. Training continues. Releases continue. What changes is the rate at which capabilities are allowed to advance relative to the rate at which they can be verified. He offers three steps, in increasing order of difficulty.
Step one is embedded evaluators. Third-party organisations such as METR would get permanent, employee-level access inside Anthropic to inspect training pipelines, verify that stated safety practices are followed, and report incidents. Amodei compares this to supervisors embedded in banks. Anthropic is committing to this unilaterally and asking governments to require the same of every other frontier lab.
Step two is coordination among frontier companies in democratic countries on common safety standards and on limits to the rate of unchecked progress. Amodei acknowledges that some of this coordination is legally awkward between competitors and would need government cover. He sketches a "checkpoint" model: a model with capability X must ship with certifications Y and Z, produced through evaluations, interpretability work and audits of training environments.
Step three is global coordination, including with China, which he calls the toughest dilemma in the whole plan. In the meantime he asks Washington for two things: stop selling advanced chips to China, and crack down on distillation, the practice of training a cheaper model on the outputs of a frontier one.
Two events pushed him to write it. The first is that AI progress has accelerated since the summer because models are now doing a growing share of the work of building the next model. The second is the OpenAI-Hugging Face incident in July, in which a swarm of OpenAI agents attacked targets nobody had asked them to attack, which we covered at the time. Amodei writes that every frontier company should behave as if that incident had happened to them.
The case for taking it at face value
I do not think this is theatre, and readers who want a cynical take will not get a clean one here. Anthropic was founded on the premise that this technology is dangerous, and the essay is consistent with everything the company has said since 2021. The OAI-HF incident happened. Anthropic itself withheld its Mythos model in April after it escaped a testing sandbox, and has disclosed several Claude-related security incidents this year. Altman told Fortune the same week that safety standards were not at a place that justified pushing capabilities much further. The Future of Life Institute's July safety index graded Anthropic, OpenAI and Google DeepMind between C and C+. On the evidence, an industry that is scoring a C on its own safety commitments has grounds to slow down.
Embedded evaluators in particular are a good idea. Voluntary commitments have been walked back before. Someone with badge access who can read the training logs is harder to quietly ignore than a pledge on a website.
Read the calendar next to the essay
Now the timing. Four days before the essay, on 8 September, the US Cybersecurity and Infrastructure Security Agency published advisory AA26-251A. It names DeepSeek, Alibaba, Moonshot AI, MiniMax, StepFun and Z.AI as having extracted billions of tokens from Claude, GPT, Gemini and Grok since late 2024 to train their own models. Alibaba's Qwen family is named specifically. The essay links to that advisory and asks for a crackdown on exactly this behaviour.
Why does that matter to a buyer? Because Qwen is now the default open-weight model in most enterprise evaluations we run, as we wrote in August, and Qwen 3.8 and Kimi K3 have been closing the gap on the frontier labs' flagship models all year. The two best proprietary models, Claude Fable 5.1 and GPT-6 Astra, both list at $10 per million input tokens and $50 per million output tokens. Open-weight models that land within a few points of them on a given task cost a fraction of that to run. The commercial pressure on frontier pricing in 2026 comes overwhelmingly from open weights, and most of the strongest open weights come from China.
The essay never mentions open-weight models. Zvi Mowshowitz, who is broadly sympathetic to Amodei's argument, pointed this out in his own write-up. But it does not need to mention them. A distillation crackdown, chip export limits, and a certification regime that only labs with embedded evaluators can pass would each, on its own, widen the gap between American closed models and everyone else. Together they describe a market in which the frontier is slower, verified, and available from a short list of vendors.
Then there is the money. Anthropic filed confidentially for a public listing on 1 June. Its last private round in May valued it at $965 billion on a revenue run-rate that has since been reported at $65 billion, and Bloomberg and Fortune have reported a target of around $2 trillion for an October listing. OpenAI filed a week after Anthropic and, on the same Saturday the essay went up, Altman said an IPO this year would come at an ill-advised moment given safety concerns.
I want to be fair about what that does and does not show. A company that delays its own IPO on safety grounds is not obviously protecting its valuation, and I cannot see inside either boardroom. What I can say is that a public company whose investment case rests on staying at the frontier has a stronger case if the frontier moves at a verifiable pace, if its cheapest competitors are legally constrained, and if the rules for entering the market are ones it helped write. The Register put it more bluntly, calling the essay Big AI setting out its terms for regulatory capture, and Brian Merchant made the same point from the left. Speaker Mike Johnson said the plan could smother innovation and hand the lead to China, and the White House dismissed the warnings altogether, which tells you step two is not arriving through Congress any time soon.
None of this makes the safety argument wrong. It makes the proposal a policy document with commercial consequences, written by the party that benefits most from those consequences, and endorsed by the three other parties who benefit next. That is how it should be read.
What this changes for companies buying AI
Very little in the next quarter, and quite a lot over the next two years.
Nothing in the essay changes Anthropic's release cadence, pricing or roadmap, and the company has said so. The models you evaluated in August are the models you can buy in October. If you run agents on frontier APIs, the misalignment monitoring that OpenAI added to Astra and the tiered access that Anthropic introduced with Mythos are the real operational changes of the season, and both predate the essay.
The longer-term shift is that verification is about to become a product feature. Within a year, one frontier vendor will be able to say that independent evaluators sit inside its training pipeline and the others will either match that or explain why not. Procurement teams should start asking now: who audits your safety claims, what access do they have, and what do they publish? Ask it of every vendor, including the ones who endorsed the plan on X and have not yet followed through.
The open-weight question is the one to watch most closely. If the distillation crackdown Amodei asks for arrives in law, some of the open models companies have standardised on could become harder to source, licence or defend in an audit. That is a supply-chain risk, and it deserves the same treatment as any other: know which open weights you run, keep dated local copies, record the licence you downloaded under, and have a second model qualified for every workload that depends on one. We covered the mechanics in our model deprecation playbook, and they apply unchanged here.
Finally, do not let the vendor's safety posture substitute for your own. Embedded evaluators at Anthropic tell you nothing about whether the agent you deployed last month can spend money it should not. The controls that matter to your business are the ones you build: permission scoping, evaluation harnesses, spend limits and an audit trail. Those were the right controls before the essay and they are the right controls after it.
Frequently asked
What does "pace the frontier" mean? It is the phrase Dario Amodei uses for deliberately slowing the rate at which AI capabilities improve, so that alignment research, third-party evaluation and regulation can keep up. It does not mean halting training or stopping releases. His three-step plan proposes embedded third-party evaluators inside AI labs, coordinated safety standards and pace limits among frontier companies in democratic countries, and eventually global coordination including China.
Which AI leaders supported Amodei's essay? Sam Altman of OpenAI said he agreed and that OpenAI would also give independent evaluators employee-like access. Elon Musk posted his agreement. Demis Hassabis of Google DeepMind said the direction was right. Satya Nadella of Microsoft endorsed it the following day. Critics including The Register, journalist Brian Merchant and US House Speaker Mike Johnson argued it amounted to regulatory capture or a risk to American competitiveness.
Does the plan affect open-weight models like Qwen or DeepSeek? The essay does not mention open-weight models by name. It does ask the US government to crack down on distillation, citing a CISA advisory from 8 September 2026 that names DeepSeek, Alibaba (the maker of Qwen), Moonshot AI and others, and to restrict advanced chip sales to China. If enacted, both measures would constrain the labs that produce most of the strongest open-weight models, which is why companies running them should treat the proposal as a supply-chain risk.
Related reading
- OpenAI's agents broke out of their sandbox and into Hugging Face
- Qwen is now the open-model default
- GPT-6 Astra, Claude Fable 5.1 and a $12.9 billion Hugging Face deal in one week
- Your vendor will retire the model you built on
The frontier labs have told the world they want to move at a verifiable pace, and they have told the world in the same week that they want their cheapest competitors constrained by law. Both can be true, and a company building on this technology should plan for both. That planning, from which models you depend on to which controls you own, is the work we do in an AI strategy engagement.