
It is not often that the people building a technology ask for it to be built more slowly. Yet that is what Anthropic CEO Dario Amodei did on 12 September, publishing an essay urging the AI industry to deliberately moderate the pace of frontier development. “We must slow the pace at which we improve the capabilities of AI models,” he wrote.
Amodei’s warning was stark. Pointing to a recent rogue-agent incident involving OpenAI and Hugging Face, he argued that within six to twelve months, swarms of autonomous AI agents could become capable of establishing a persistent botnet across the internet, with damage potentially running into the hundreds of billions of dollars. Alongside the call to slow down, he said Anthropic would unilaterally give external evaluators employee-level access to verify its safety procedures and report incidents, urged other labs to follow suit, and called for democratic nations to coordinate on safety standards. Anthropic’s policy team followed up by calling for a national law requiring testing of frontier models.
The response from peers was swift. OpenAI CEO Sam Altman said he agreed the industry needs to pace the frontier and committed OpenAI to a similar evaluator arrangement, later clarifying that “when we talk about ‘pacing,’ we do not mean ‘stopping.’” Elon Musk also publicly endorsed the call. Not everyone was persuaded: some investors argued the essay was as much about competitive positioning as safety, and White House figures were openly sceptical about the need for government involvement.
The essay did not arrive in a vacuum. In July, more than 1,100 employees at frontier AI companies, Amodei among them, signed an open letter asking the US government to help build tools for pacing automated AI development should it become necessary. But a CEO of a leading lab making the case so publicly has moved the debate into new territory, and security leaders are paying close attention.
A rare request from the builders
For Dipto Chakravarty, Chief Product & Technology Officer (CPTO) at Black Duck, the significance of the moment lies partly in who is making the request, and partly in who won’t be listening. “This weekend, a rare event occurred in our industry. The builders were asked to slow down. Dario Amodei calling for pacing the frontier so that our ability to control AI itself keeps up with the pace in this race. Throttling the pace of progress by its builders is a rarity. Even if progress were to slow down, the adversaries won’t. This is the tax we pay for innovation.”
Chakravarty nonetheless takes a long view of the relationship between innovation and risk, arguing that history favours progress even when it is disruptive. “From my vantage point, having been an AI builder for a decade, and being in the industry for two decades, progress has out-innovated threats in the long run, despite creating chaos in the short term.”
The regulatory question
Amodei’s essay stops short of prescribing a full regulatory regime, but it has reopened the question of what oversight of frontier AI should look like. Chakravarty argues the answer lies in the model already applied to other safety-critical industries. “AI must be regulated like planes, trains, and automobiles. Regulated industries must embrace ‘responsible AI’ with guardrails. New entrants and builders of frontier models must add board-level accountability for AI, secure defaults, incident disclosure, and risk prioritisation in production runtime where rubber meets the road, to earn trust and keep systems safe.”
How should AI progress be measured?
Dom Glavach, CISO at Black Duck, sees in the pacing debate a more fundamental question about what the industry counts as progress in the first place. “Amodei’s call to pace the frontier raises a broader CISO question: How should we measure AI progress? Increasing model capability is certainly one measure. But the ability to turn that capability into reliable secure business outcome deserves equal attention. Faster, more capable models are only part of the picture; stronger testing, fewer security failures, and more dependable deployment are equally important.”
Like Chakravarty, Glavach is clear that defenders cannot build their plans around the hope that the industry will actually slow down. “Pacing could give safeguards more time to mature. However, security strategies can’t depend on an industry-wide slowdown. The software deployed and the agents operating today already require protection.”
Collaboration in the post-Mythos era
If a slowdown does materialise, both executives argue the time should be spent strengthening defences collectively. The stakes have risen with Anthropic’s Claude Mythos Preview, a frontier model currently available only to a small number of trusted organisations through Project Glasswing. Chakravarty points to industry collaboration as the way forward. “This calls for a situational leadership where vendors must collaborate to bring the best outcomes for our customers. For instance, via Project Athena, Black Duck is helping customers find, fix, and block software flaws before hackers can exploit them by sharing vulnerability intelligence in risks hidden deep inside open-source supply chains. Also, via Project Glasswing, Black Duck is helping secure the threats in the post Mythos era. Tomorrow, there will be more and more sophisticated frontier models out there. The key is to build durable harnesses via which one can future-proof the attack surfaces and offer resilience against the headwind.”
Glavach frames any breathing room in similar terms, arguing that layered defences will matter regardless of which way the frontier moves. “Any time gained through pacing can help close the gap between offensive AI capabilities and dependable security at scale. Defence in depth is central to this effort. Pairing AI reasoning with deterministic analysis, dependency analysis, and runtime testing give us different ways to identify and verify vulnerabilities. These methods stay complementary whether frontier advancement slows or accelerates.”
A new kind of threat
Part of what makes the current moment different, Chakravarty argues, is the speed at which frontier capability now spreads and the implications that has for traditional security models. “Unlike earlier advanced persistent threat vectors, a frontier model is software that replicates, ships, and scales in matter of hours, thanks to GenAI democratising it. Beyond the zero-trust model, one must apply context to combat AI. AI is exploiting codebases as fast as AI is finding exploits. More than ever before, the ‘I’ matters more than ‘AI’ or ‘AGI’.”
Raising the bar
Whether Amodei’s call translates into concrete action across the industry remains an open question. The commercial stakes are enormous, competitive pressure is intense, and there is no guarantee that every lab, or every nation, will choose restraint. What the debate has done is force a broader conversation about what responsible progress looks like, and who is accountable for it.
For Glavach, the answer is that the definition of progress itself needs to evolve. “The standard for progress should rise alongside AI capability. Progress is measured by how much more AI can do, how confidently we can deploy it, and how effectively we can contain and respond when something goes wrong.”


