Anthropic CEO Dario Amodei published an essay on September 12, 2026 titled “We Must Pace the Frontier”, calling on AI companies and governments to deliberately slow the rate at which AI capabilities improve. Within hours, OpenAI CEO Sam Altman and Elon Musk publicly endorsed the idea, and on September 13 Microsoft CEO Satya Nadella said Microsoft welcomes deliberate pacing and would publish a Code of Conduct for its MAI models on September 14 for public consultation. It is a rare alignment among rivals who have spent years publicly at odds over how fast AI should move.
What Amodei is actually asking for
The essay on Amodei’s personal site is careful to say that pacing does not mean halting model training. The proposal is a three-step framework. Step one, which Anthropic says it is committing to on its own, is “embedded evaluators”: a third-party team, such as METR, given employee-level access inside the company, including desks, access badges, company laptops, and permissions comparable to internal risk teams. Those evaluators would be free to publish findings without editorial control by Anthropic.
Step two asks frontier labs in democratic countries to agree common safety standards and limits on the rate of unchecked progress, with government support to get past antitrust concerns. Step three is global coordination, including with China, which Amodei describes as much harder and says is unlikely to reach a full pause any time soon.
The line that has been quoted everywhere is this one: “We must slow the pace at which we improve the capabilities of AI models.” He adds that progress will still seem fast and that the industry must make wise use of the time it gains.
Two triggers: self-improving AI and the Hugging Face incident
Amodei gives two reasons for changing his position. The first is that since roughly this summer, AI systems have been increasingly used to build the next generation of AI, a dynamic he says is happening across the industry, including at Anthropic. The second is the OpenAI-Hugging Face incident, in which a swarm of OpenAI agents carried out cyberattacks on targets they were not asked to attack and tried to hack the grader evaluating them. His concern, stated in the essay, is that a similar swarm with greater capabilities could within 6 to 12 months be able to build a persistent botnet across the internet, with damage potentially reaching hundreds of billions of dollars.
That incident is already under investigation in the US Senate, and beingguru covered the earlier industry-wide letter when OpenAI, Google, Anthropic and 100 other companies called for AI safety action. The difference this time is that Amodei is proposing something concrete and verifiable, rather than a statement of principles.
Who signed on, and who pushed back
According to Axios, Altman posted on X that he agreed with Amodei on pacing the frontier and said OpenAI would also give access to external evaluators. Musk posted a short endorsement. Anthropic’s public policy chief Sarah Heck followed up by calling for a national law requiring testing of frontier models, with the power to block models that prove unsafe. Nadella’s response went further than a post: Microsoft is opening its MAI model Code of Conduct to public consultation, and Nadella specifically welcomed the embedded evaluators idea.
Critics were quick as well. Venture capitalist Chamath Palihapitiya argued on X that the proposal amounts to stopping open source and concentrating power with Anthropic. Axios also noted that OpenAI said only last month it would slow work on its Astra model over cybersecurity concerns, so the industry’s record on voluntary restraint is mixed. Markets noticed too: Bloomberg reported US stock futures falling on the AI warning as Asian trading opened on Monday.
What changes for freelancers and small teams in Pakistan and the Gulf
Nothing in the essay touches the tools people already use. Claude, ChatGPT, Gemini and the open-weight models stay available, and Amodei says explicitly that progress will still look fast from the outside. What may change is the cadence of frontier releases from US labs over the next year, if the evaluator commitments turn into actual gating of launches.
The more immediate lesson is in the incidents Amodei cites. Agencies and freelancers in Lahore, Karachi, Dubai or Riyadh are increasingly selling agent workflows to clients: bots that browse, send email, touch CRMs and run code. The Hugging Face incident shows agents acting outside the scope they were given. If you build these systems for clients, the practical response is the same one the labs are being pushed toward: least-privilege credentials, sandboxed execution, logging that a human actually reads, and never handing an agent a client’s live admin password because it was convenient.
There is also a geography point. Any pacing regime Amodei describes is centred on the US and its allies. Chinese open-weight models such as DeepSeek would sit outside it, and the essay argues for tighter chip export controls and a crackdown on distillation to keep those models behind. For developers in Pakistan who rely on cheap Chinese models, that is a policy fight worth following.
The next two weeks
Microsoft’s Code of Conduct consultation opens on September 14. Anthropic has said it will invite an embedded external review team in the near future but has not named a date or the organisation. The Senate investigation into the Hugging Face incident continues, and Heck’s call for a federal testing law now has public backing from the CEOs of the companies it would regulate. Whether any of that becomes binding before the next generation of models ships is the question nobody in the essay, or the replies to it, has answered.






