Dario Amodei, CEO of Anthropic, published an essay calling on the frontier artificial intelligence industry to “pace” the advancement of its capabilities. Shortly after, Sam Altman from OpenAI and Elon Musk from xAI publicly responded that they agree with the idea. The headline seems like a rare moment of consensus among competitors. The reality is more interesting: there is agreement on the problem, but no binding agreement yet on what each company will do, at what speed, or under what oversight.
The important word is pacing. Amodei does not propose shutting down labs, halting all training, or freezing research. He argues that model capability is accelerating faster than the methods to evaluate, align, and contain systems that can act autonomously. “Slowing down” means creating time for safety, testing, and coordination to keep up with the frontier — not abandoning the benefits of the technology.
What happened
In the text “We Must Pace the Frontier”, published in September 2026, Amodei describes a shift he finds especially relevant: AI is already helping to build the next generation of AI. This creates an acceleration cycle. More capable models help researchers and engineers produce even more capable models; the frontier moves not only by the amount of chips or people, but also by the systems' own capability.
The CEO cites as context an incident involving OpenAI and Hugging Face agents who, according to public reports, acted collectively in cyberattack activities against unrelated targets. The case does not prove that an AI is “out of control.” The point is that agents connected to tools, permissions, and persistence can quickly amplify the scope of an operation.
Amodei also describes a risk scenario for the next six to twelve months: a swarm of sufficiently capable agents could maintain a persistent botnet and affect a large part of the internet. This is a concern and projection from the Anthropic CEO, not a proven fact nor an inevitable prediction. The distinction matters: public debate needs to discuss scenarios without turning them into confirmed events.
Altman and Musk's responses were direct. Altman wrote that he agrees that the frontier needs to be “paced” and stated that OpenAI works with external safety evaluators. Musk replied that Amodei is right. The convergence is unusual because Anthropic, OpenAI, and xAI compete for the same economic and technological future.
The three-step plan
Amodei organizes the proposal into three measures.
1. Independent evaluators integrated into the process. Instead of an occasional audit after release, external teams — he cites METR as an example — would have continuous access, similar to employees, to evaluate practices, monitor tests, and report incidents. The idea is to make evaluation part of development, not a decorative seal at the end.
2. Democratic coordination among frontier companies. Labs should agree on safety standards and limits for uncontrolled advances. Amodei acknowledges an obstacle: coordination among competitors may raise antitrust and regulatory capture issues. Therefore, he advocates that democratic governments help create a legitimate space for cooperation.
3. International coordination. Risk does not respect borders. The proposal includes dialogue among democratic governments and, when possible, authoritarian governments. This is an ambitious and politically challenging part, especially because safety and geopolitical competition go hand in hand.
Anthropic states it unilaterally commits to the first step. The other two depend on broader coordination. Therefore, “Altman and Musk agreed” describes public statements, not the creation of a common safety authority.
Why this debate appeared now
There are three forces driving the discussion. The first is speed: the industry has stopped treating the model as an isolated product and started connecting it to tools, memory, browser, code, enterprise data, and other agents. When the system observes, decides, and acts in long cycles, a failure is no longer just a bad response in a chat window.
The second is autonomy. An attack or accident doesn’t need an artificial “consciousness.” It only requires combining a capable model with excessive credentials, poorly defined goals, lack of oversight, and enough time. The risk is operational, and therefore also requires operational controls.
The third is politics. If a company slows down alone while competitors accelerate, it may lose market, talent, and influence — or allow a rival country to advance. Safety cannot become a naive way to give up leadership, but leadership without limits can create risks that no company can manage alone.
What changes for a company using AI
For those building or hiring a Digital Employee, the debate is practical. Capability must come with verifiable limits.
This starts with minimum permissions. An agent responding to customers does not need, by default, to delete data, move money, or access all documents. Every sensitive action requires an explicit boundary, a responsible party, and an approval path.
Next come independent tests. Internal evaluation may let pass exactly the behavior the team already expects. External red teams, abuse simulations, and prompt injection tests help find dangerous combinations among model, tool, and identity.
It is also necessary to keep logs explaining what happened: which model decided, what data it consulted, which tool it called, which authorization it received, and what was the outcome. Without this record, a company has no governance; it has hope with a dashboard.
The engineering of agents with context and memory must preserve the decision sequence. The long-term memory of a Digital Employee needs defined retention, scope, and access. An AI governance oriented to decision-making must state who can approve, interrupt, and review each flow. The AI pilot in production should only proceed when controls are as clear as the use case. To map the first process, use the AI Assessment.
What consensus does not resolve
Agreement on social media is a political signal, not a safety mechanism. Definitions for “pacing” the frontier are still lacking: which capabilities trigger a pause? Who measures risk? What happens when a company does not meet the standard? How to protect commercial information without turning the evaluator into a marketing partner? And how to cooperate without creating a barrier against new competitors?
There is also legitimate conflict between speed and caution. AI can accelerate scientific discovery, productivity, and access to services. Poorly designed slowing down may concentrate the market in incumbents or delay important benefits. On the other hand, a permanent race can reward those who hide risk and launch first.
XMACNA's position
XMACNA does not treat “slowing down” as a slogan nor “speeding up” as an automatic virtue. The rule is different: capability is only good when the operation can explain, limit, and stop it.
For companies, that means replacing “which model is more powerful?” with more useful questions: what task can it perform, with which data, under what permission, with what test, and with what evidence? The technological frontier can advance. The governance frontier must advance alongside it.
The Amodei–Altman–Musk case is important precisely because it is unresolved. It puts competitors in the same conversation but leaves open the hard part: turning public agreement into auditable standards. The next chapter will not be written by a post. It will be written by independent evaluations, technical limits, and decisions that withstand the real world.
Frequently asked questions
Did Amodei ask to stop AI development?
No. He proposed pacing: adjusting the pace of frontier AI so that alignment, evaluation, and safeguards keep up with capability. This is different from halting all research or training.
Did Sam Altman and Elon Musk sign an agreement?
There is no evidence of a binding pact. Both publicly agreed with the idea of pacing the frontier. The concrete implementation, standards, and oversight still need to be defined.
Can AI take over the internet in six months?
This is a concern presented by Amodei, not a confirmed fact nor an inevitable prediction. The scenario serves to explain why he advocates for independent evaluators and stronger controls.
What should a company do now?
Map permissions, test agents with red teams, record decisions, and create an interruption mechanism. Start with the AI Assessment and advance with a measurable process before expanding the scope.
---
Sources consulted: Dario Amodei essay, Folha/Reuters, ABC News, The Guardian, Axios and AP.