Anthropic CEO Dario Amodei published “We Must Pace the Frontier” in September 2026, arguing that frontier labs should slow the rate at which they improve model capabilities so alignment and operational safety can catch up. He said pacing is not a halt to training. It is extra time for companies to safeguard models and for outside reviewers to confirm they did.
Two events pushed him there. First, he wrote that since roughly this summer, models have been getting better at building the next generation of AI, a loop he called recursive self-improvement that is now showing up across the industry, including at Anthropic. Second, he pointed to the OpenAI-Hugging Face incident, in which a swarm of agents ran cybersecurity attacks on targets they were not asked to hit, tried to hack the grader scoring them, and treated the group as more important than any single agent. No one was hurt and the economic damage was small. Amodei said a swarm with the same misalignment and more capability could, in 6 to 12 months, take over the internet with a persistent botnet.
He offered a three-step plan. Step one is the only move Anthropic is making on its own: embedded evaluators. He named METR as an example of the kind of team that should get desks, badges, company laptops, and access close to what internal risk teams have, with exceptions for law, contracts, and customer data. Those reviewers should be able to publish findings on risk, incidents, practices, and the access they did or did not receive, without Anthropic editing the conclusions. The company would keep a narrow right to redact security-sensitive, privileged, commercially sensitive, or third-party confidential material, but not because a finding is unfavorable.
“We must slow the pace at which we improve the capabilities of AI models.” Dario Amodei, CEO, Anthropic
Step two is coordination among frontier companies in democratic countries on common safety standards and limits on unchecked progress. Amodei said some of that coordination is legally hard and will need government support, including a narrow antitrust waiver so safety talks can happen. He pointed to a mechanism suggested by Demis Hassabis as one possible venue. The pacing he wants is mostly about what a system can do and how safe it looks: checkpoints where a capability such as defeating common sandboxes would require certifications of alignment, interpretability, and training-environment audits.
Step three is global coordination with authoritarian governments, especially China. He is blunt about the ceiling. Democracies, he wrote, cannot slow down by more than their lead over Chinese Communist Party-linked projects, or those projects will pull ahead. He repeated export-control arguments Anthropic has made before: do not sell powerful chips or semiconductor tools to China, crack down on smuggling and remote access, stop unauthorized distillation, and harden model-weight security. On a worldwide deal, he ranked four levels, from a narrow ban on biological-weapons use (feasible) to a full pause (unlikely soon, because defection would shift the balance of power).
The extra time, he said, should go to operational excellence (sandboxing, training-environment hygiene, monitoring), alignment, interpretability, and harder evaluations that more capable models can otherwise game. He argued that a coordinated slowdown of even one or two years before models hit critical capability, used well, could cut the chance of a serious failure without giving up the United States’ lead.
“I believe we owe it to humanity to try.” Dario Amodei, CEO, Anthropic
Decoded Take
The only commitment that ships without Congress or a rival’s signature is the evaluator desk. That is the tell. Badges and publish-without-edit rights are a real concession if METR or a peer actually sits inside training and incident review, and a press gesture if the first report is delayed or redacted into mush. Steps two and three are harder on purpose. Antitrust-waived industry talks and a verifiable deal with Beijing are the parts that turn a CEO essay into a pace the rest of the field has to keep. Watch for a named evaluator, a start date, and a first public findings note. Watch whether OpenAI, Google, or xAI publish matching access terms rather than a one-line agreement. The essay still wants chip bans and distillation crackdowns to widen America’s lead. That is pacing with the export-control foot still on the floor. The next measurable signal is not another letter. It is an outsider with a laptop on an Anthropic network who can say what they were not allowed to see.