We Must Pace the Frontier
Published September 2026 · Only a month is printed, beneath the title: "September 2026". The ISO date 2026-09-01 is a sorting convention, not the publication day. The page carries no machine-readable publication date; the HTTP Last-Modified header (24 Sep 2026) was not relied on.
Not law. This is a company's own public position on AI regulation. It is not law, and it carries no legal force.
What it argues for
Anthropic's chief executive argues that frontier AI development now has to be deliberately slowed, and sets out a three-step plan for doing it. He writes that "fully addressing the risks requires even more prudence — not just investing in risk prevention, but pacing the rate of capabilities advancement so that risk prevention has time to keep up," and states the conclusion flatly: "We must slow the pace at which we improve the capabilities of AI models." He gives two reasons: recursive self-improvement, which he says "is starting to happen across the industry, including at Anthropic," and what he calls the OpenAI-Hugging Face incident, in which a swarm of agents attacked targets they had not been asked to attack. He is explicit that "pacing does not mean halting model training or technical progress, but ensuring companies take adequate time to align and safeguard their models, and for third party evaluators to confirm this." The first step, embedded third-party evaluators with employee-like access, is one "Anthropic is unilaterally committing to" — and the essay "calls on governments to require other frontier companies to match" it. The second step is pacing within democracies, where "The most effective method of pacing is via regulation that targets all US frontier AI companies," backed in the meantime by voluntary industry standard-setting for which the US government would "need to issue a narrow waiver for certain kinds of safety conversations" under antitrust law. He favours capability-triggered checkpoints — "if models have capability X, then they need to be accompanied by certifications of alignment properties Y and Z" — and ties the whole scheme to keeping the US lead over China through chip export controls, a crackdown on unauthorised distillation and stronger security against model weight theft. The third step, global pacing with China, is laddered from a narrow ban on AI-enabled bioweapons production up to a full pause, with the warning that "any agreement must either have ironclad verifiability, or must be limited enough that defection would not be militarily existential."
Stated positions (13)
- Capability growth itself should be slowed: "We must slow the pace at which we improve the capabilities of AI models. Progress will still seem fast, and we must make wise use of the time we gain."
- Pacing is defined narrowly — it "does not mean halting model training or technical progress, but ensuring companies take adequate time to align and safeguard their models, and for third party evaluators to confirm this."
- Recursive self-improvement is named as the first driver: it "is starting to happen across the industry, including at Anthropic" and, left unchecked, "must be pursued very carefully, if at all."
- Every frontier company should treat the OpenAI-Hugging Face agent-swarm incident as its own: "I believe it’s incumbent on every frontier AI company to act as if OAI-HF had happened to them." The essay says similar, less severe incidents have happened across the industry, including at Anthropic.
- Embedded third-party evaluators (METR is the example given) should have "ongoing, employee-like access" to verify safety practices, report incidents and assess training pipelines; "Anthropic is unilaterally committing to this step now," and the essay calls on governments to require other frontier companies to match it.
- The evaluators' contract would let them publish findings "without editorial control by Anthropic"; Anthropic keeps a narrow right to redact security-sensitive, privileged, commercially sensitive or third-party confidential material, "but we can’t redact findings just because they are unfavorable."
- Binding law is the preferred route: "The most effective method of pacing is via regulation that targets all US frontier AI companies, as that covers even those who are unwilling to cooperate voluntarily." Anthropic's support is described as being for "bills that focus on transparency and on third-party auditing."
- All frontier labs should "partner with government to formalize the idea of permanent embedded evaluators" and "implement regulation focused on keeping capabilities in balance with safety."
- Until law arrives, labs should coordinate voluntarily on standards, and the US government "do[es] need to issue a narrow waiver for certain kinds of safety conversations" so that antitrust law does not block them.
- Preferred pacing mechanism is capability-triggered checkpoints — "if models have capability X, then they need to be accompanied by certifications of alignment properties Y and Z" such as evaluations, interpretability analyses and audits of training environments; limits on inputs such as training compute are worth considering but may be more "gameable".
- Pacing is bounded by the US lead over China, so the lead must be defended: "Do not sell powerful AI chips or semiconductor manufacturing equipment to China," crack down on chip smuggling and remote data-centre access, "Crack down on unauthorized distillation," and "Strengthen security at the AI companies and prevent model weight theft."
- Global pacing with China is laddered by difficulty: a ban on narrow, obviously dangerous uses such as bioweapons production; mutual pre-release testing for acute risks, possibly through a global standards body; a "speed limit" on the rate of recursive self-improvement; and a full pause, which he supports floating but thinks "is unlikely to actually happen any time soon."
- Any international agreement "must either have ironclad verifiability, or must be limited enough that defection would not be militarily existential," and should be approached "in such a way that protects the lead of the US and its allies."
About this document
A short signed essay of about 3,800 words, published on Dario Amodei's personal website (darioamodei.com) and listed on its home page under "Short posts", ahead of "Policy on the AI Exponential". It is not on anthropic.com and carries no Anthropic branding beyond the author's description of himself. Beneath the title the date is printed only as "September 2026". It opens with a personal framing passage and two stated reasons for changing course, followed by a three-item list of the plan's steps (Embedded Evaluators; Democratic Coordination; Global Coordination). Five headed sections follow: "Why Pace?", "Embedded Evaluators", "Pacing Within Democracies", "Global Pacing" and "Bottom Line". There is one footnote, which says the second step would need government mediation or waivers of antitrust restrictions. The essay announces one concrete unilateral Anthropic commitment: inviting an embedded external review team with desks, badges, laptops, near-employee access to tools, and a contract letting it publish findings without Anthropic's editorial control. Everything else is advocacy directed at governments and other labs. It cites no statute, bill or regulatory text by name.
How this sits against AI law
Each stance compared with what EU and US instruments actually require. Where no instrument addresses a theme, that gap is shown rather than hidden.
Embedded third-party evaluators with employee-like access
Each frontier company should give a team of third-party evaluators ongoing, employee-like access to verify adherence to safety commitments, report incidents and assess training pipelines, with a contractual right to publish findings without the company's editorial control. Anthropic commits to this unilaterally and asks governments to require it of other frontier companies.
Article 55(1)(a) leaves model evaluation and adversarial testing to the provider, and Article 92 lets the AI Office evaluate a model, including through independent experts, only as an enforcement step. Nothing in the Act places external evaluators inside a provider on a standing basis.
SB 53 asks a large frontier developer to describe in its published framework how it uses third parties to assess catastrophic risk, but mandates no external assessor, let alone a standing embedded team. Illinois SB 315, which would make third-party audits compulsory, has not taken effect.
Deliberately slowing the rate of capability advancement
Frontier developers should slow the pace at which model capabilities improve, so that alignment, interpretability, evaluation and operational safety can keep up. Pacing means taking adequate time to align and safeguard models, not halting training, and it should be imposed by regulation on all US frontier companies.
The Act regulates what reaches the market, not how fast capabilities are developed. Article 93 lets the Commission require mitigation or restrict, withdraw or recall a systemic-risk model already placed on the market, and no provision sets a pace for development or a threshold at which it must slow.
The Action Plan sets the opposite direction: it is built around accelerating AI innovation and removing regulatory barriers, and contains no mechanism for slowing capability growth. It does share the essay's aim of keeping the US ahead of China.
Capability-triggered checkpoints requiring certified alignment
Pacing should work through checkpoints: once a model has a defined capability, such as escaping most common sandboxing methods, it should need certifications of specified alignment properties, drawn from evaluations, interpretability analyses and audits of training environments. Input limits such as training compute are a secondary option because they may be more gameable.
Article 51 classifies models by capability, presumed above 10^25 training FLOP, and Article 55 attaches evaluation and risk-mitigation duties. Nothing conditions further development or deployment on certifying named alignment properties, and interpretability analysis and training-environment audits are not mentioned.
SB 53 has large frontier developers publish a framework explaining how they assess thresholds for catastrophic capability and apply mitigations. The developer sets the thresholds itself, and no certification by anyone else is a condition of proceeding.
Binding frontier regulation focused on transparency and third-party auditing
Regulation targeting all US frontier AI companies is the most effective way to pace, because it covers companies unwilling to cooperate voluntarily. Anthropic backs targeted bills that focus on transparency and third-party auditing, and wants labs to work with government to formalise permanent embedded evaluators.
The Act's general-purpose model chapter binds every provider placing such a model on the EU market, whether or not it volunteers. Articles 53 and 55 attach documentation, evaluation, incident-reporting and cybersecurity duties, with the heaviest reserved for systemic-risk models.
SB 53 is the transparency-centred frontier statute of the kind the essay endorses: it requires frontier developers to publish safety frameworks and transparency reports and to report critical safety incidents. It is California law; no federal statute does the same.
Government-enabled industry coordination on common safety standards
While legislation is pending, frontier companies in democracies should agree common safety standards and limits on the rate of unchecked progress. Because antitrust law stands in the way, the US government should mediate those talks or at least issue a narrow waiver for certain safety conversations, possibly through an industry body associated with government.
Article 56 has the AI Office convene providers to draw up codes of practice, a government-hosted forum for common safety standards; the General-Purpose AI Code of Practice came out of it. The codes set practices, not limits on the rate of capability progress, and the Act creates no competition-law exemption.
No US instrument in our corpus gives frontier developers an antitrust safe harbour or a government-mediated forum for agreeing common safety standards or development pace.
Export controls on AI chips and chipmaking tools to China, and action against distillation
Democracies' lead over China should be defended by not selling powerful AI chips or semiconductor manufacturing equipment to China, cracking down on chip smuggling and remote access to data centres outside China, and cracking down on unauthorised distillation of frontier models by companies in authoritarian countries.
The EU dual-use regulation is a licensing regime for listed items, administered by Member State authorities. It contains no China-specific prohibition on AI accelerators or chipmaking equipment, and nothing on model distillation.
The Action Plan calls for strengthening and enforcing export controls on advanced computing and semiconductor manufacturing technologies to deny adversaries access. It is a policy programme, not a statute, and imposes nothing directly on companies.
Security against model weight theft
Security at frontier AI companies should be strengthened to prevent model weight theft, as part of preserving the lead that makes pacing possible. Companies and the US government should cooperate to make this effective.
Article 55(1)(d) requires providers of systemic-risk general-purpose models to ensure an adequate level of cybersecurity protection for the model and its physical infrastructure.
SB 53 requires a large frontier developer's published framework to describe the cybersecurity practices it uses to secure unreleased model weights against unauthorised access, modification or transfer.
International pacing agreements with verification
The US and its democratic allies should seek agreements with China. In rising order of difficulty these are: a ban on narrow dangerous uses such as bioweapons production, mutual pre-release testing for acute risks through a global standards body, a speed limit on recursive self-improvement, and ultimately a pause. Any agreement needs ironclad verifiability or must be limited enough that defection is not militarily existential.
The AI Act is an internal-market regulation for the EU. It creates no mechanism for international agreements on development pace, mutual testing or verification with third countries.
No US instrument in our corpus pursues a bilateral or multilateral agreement on testing, recursive self-improvement or the pace of frontier development.
The essay asks for something neither jurisdiction does: slowing how fast capabilities improve, rather than regulating what is placed on the market. Measured against the EU AI Act, its transparency and evaluation asks are already law for systemic-risk models, and the Act's Article 56 codes of practice already give providers a government-hosted forum for common standards. But the Act assesses providers from outside, through the AI Office, and has no embedded evaluators, alignment certification or development speed limit. In the US the fit splits by level. California's SB 53 matches the "transparency and on third-party auditing" model the essay endorses, though its third-party element is only descriptive. Federal policy agrees with the China half of the argument — export controls and keeping the lead — and runs against the pacing half, since America's AI Action Plan is built around acceleration and deregulation.
Source
https://darioamodei.com/post/we-must-pace-the-frontier- Date on the page:
- September 2026
- Source checked:
- opened and confirmed on 2026-09-29