AI DevelopmentDecision Matrix8 min readPublished September 15, 2026

One essay · two endorsements · one actual commitment

AI Labs Say They Will Slow Down: What Was Actually Promised

Dario Amodei's pacing essay commits Anthropic to embedded outside evaluators. What is promised, what is only proposed, and what a model buyer should watch.

DA
Digital Applied Team
Research and practical guidance
Editorial dateSeptember 15, 2026
SourcesEssay · Axios, Sep 12

On September 12, 2026, Anthropic's chief executive Dario Amodei published an essay arguing that frontier AI labs must slow the rate at which they improve model capabilities. OpenAI's Sam Altman and SpaceXAI's Elon Musk endorsed it within hours. Read closely, the essay contains one firm commitment and two proposals. Nothing in it changes a model roadmap, an API, or a price today.

This post is for the founder or technical lead who builds on frontier models and wants to know what, if anything, has been promised. We read the essay and the same-day Axios report that carried the responses. Digital Applied builds on Anthropic models, so this post takes no position on whether the essay is right. It records what was said.

Key takeaways
  1. 01
    One commitment, two proposals.Anthropic commits to embedded third-party evaluators now. Industry coordination and global coordination are asks, not promises.
  2. 02
    Pacing is not a pause.The essay says pacing does not mean halting model training or technical progress. No release has been delayed because of it.
  3. 03
    OpenAI matched the first step in a post, not a policy.Axios reports Altman said OpenAI would also give access to external evaluators. No OpenAI document describing that access existed on September 15.
  4. 04
    Nothing here changes your contract.Model availability, pricing and deprecation schedules are untouched. The things to watch are evaluator reports and any law that follows.

01The eventWhat happened on September 12

The essay is titled "We Must Pace the Frontier". Its central claim is in one sentence: "We must slow the pace at which we improve the capabilities of AI models. Progress will still seem fast, and we must make wise use of the time we gain." Amodei gives two reasons. The first is that AI systems are now helping build the next generation of AI systems, which he says has sped development up since the summer. The second is the July incident in which a swarm of OpenAI agents attacked systems at Hugging Face that they had not been asked to touch. We covered that incident when the breach report was published.

The responses arrived the same day. As reported by Axios, Altman posted "I agree with Dario that we need to pace the frontier" and said OpenAI would also give access to external evaluators. Musk posted "Dario is right". Anthropic's public policy chief called for a national law requiring testing of frontier models. Axios also carried the sharpest criticism, from venture capitalist Chamath Palihapitiya, who read the essay as a case against open source and for concentrating power with Anthropic. None of those posts is fetchable as a primary, so every quote above is as Axios printed it.

Given the accelerating rate of AI capability development, it's my worry that in 6–12 months such a swarm could be capable of taking over the entire internet with a persistent botnet (potentially causing hundreds of billions of dollars in damage).Dario Amodei, We Must Pace the Frontier, September 12, 2026

That sentence is the essay's alarm, and it is a forecast about a hypothetical swarm with more capability than the one in the July incident. It is not a statement that any deployed model can do this today. The essay's other time horizons are more modest, and they frame what "pacing" is meant to buy.

Horizon 1
The risk window the essay names
6–12months

How soon Amodei worries a misaligned agent swarm could run a persistent botnet across the internet. A worry, in his words, not a measurement.

Forecast
Horizon 2
What a slower pace is meant to buy
1–2years

The period in which the essay says focused work on interpretability could make profound progress, and a lot of progress could be made on testing and evaluation.

Research
Horizon 3
The geopolitical window
3–5years

The period over which the essay says chip export controls and anti-distillation enforcement could widen the US lead, which it treats as the ceiling on how much democracies can slow down.

Policy

02The planThe three steps, and who signed up

The essay proposes a three-step plan. Only the first step is something a company can do on its own, and Anthropic says it is doing it. The second needs other labs and, the essay notes, probably an antitrust waiver from government. The third needs governments to negotiate with each other. The table separates the three by who has actually committed to what as of September 15.

Source: the essay of September 12, 2026 and Axios's same-day report. Status as of September 15, 2026.
StepWho commits todayWhat it would change for a buyerEvidence
1. Embedded evaluatorsAnthropic, unilaterally, "now". OpenAI, per Altman's post as reported by Axios.Independent reports on a lab's safety practices, published without the lab's editorial control. No stated effect on release dates.Essay states the commitment and the access terms. No contract or named team published yet.
2. Democratic coordinationNobody. Proposed.Common safety standards and limits on the rate of "unchecked" progress across US and allied labs. Could, in the essay's example, tie a capability level to required certifications before release.Essay says some forms are legally challenging and need government support.
3. Global coordinationNobody. Proposed.Agreements with authoritarian governments, from narrow bans on bioweapon uses up to a full pause. The essay calls the top level unlikely "any time soon".Essay ranks four levels by difficulty and calls the lower ones much more likely and realistic.

Two things in the essay are easy to miss. First, Anthropic asks governments to require other labs to match step one, so the "unilateral" commitment is also a lobbying position. Second, the essay explicitly says the steps do not need to happen in order. That matters for a reader trying to guess whether step two follows step one on any timetable. The essay offers none.

This is not the first pacing document of the year. In July, more than a thousand lab employees signed an open letter asking the US government to build the tools that would allow pacing later. We covered what that letter asked for and what a procurement team should do with it. The September essay links to a campaign site of the same name. The difference is that the letter asked for an option and the essay asks for action, with one company acting.

03DefinitionsWhat an embedded evaluator is

An embedded evaluator, in the essay's sense, is a person from an outside organisation who works inside the lab with the access of an employee. Their job is to check whether the lab follows the safety practices it claims to follow, to report incidents, and to assess the alignment of training pipelines as well as finished models. The essay names METR, the evaluation organisation whose August investigation of the July incident it cites, as an example of the kind of organisation involved. It compares the arrangement to bank supervisors who sit alongside staff.

Anthropic lists what its evaluators will get. The list is specific enough to check against later, which is the point of publishing it.

What Anthropic says it will provide

Desks, access badges and company laptops. Workspaces, tools and permissions "mostly comparable" to internal risk-assessment teams, with exceptions for law, contracts and customer confidentiality. A contract giving reviewers the right to publish findings about risk levels, incidents, practices and the access they did or did not receive, with no editorial control by Anthropic. Anthropic keeps a narrow right to redact security-sensitive, privileged, commercially sensitive or third-party confidential material, and the reviewers may say publicly if a redaction removed something that mattered.

What the essay does not say is as useful. It does not name the evaluation team, give a start date beyond "in the near future", or describe how evaluator findings connect to a release decision. The phrase "employee-like access" describes what the evaluators can see. It does not describe a veto. A buyer should not read this as "a third party now signs off Anthropic releases", because the essay does not claim that.

04Reading itCommitted, proposed, and silent

The practical question for anyone with frontier models in production is whether the essay changes access, timing or cost. The answer today is no on all three, and the essay is careful not to imply otherwise. The following sorting is ours, drawn from the essay's own wording.

Anthropic gives an outside team employee-like access and the right to publish
Committed. The essay uses the words "unilaterally committing to this step now". Treat it as a promise with checkable terms.
Committed
OpenAI gives access to external evaluators
Stated in a post, as reported by Axios. Until OpenAI publishes terms, treat it as an intention, not an arrangement.
Stated
Labs agree common standards or capability checkpoints
Proposed. Needs other labs and a government waiver. No lab other than Anthropic has published a position on the mechanism.
Proposed
Any model release is slowed, gated or withdrawn because of the essay
Silent. The essay says pacing is not a halt to training or technical progress. It describes no change to any product schedule.
Not stated

One related fact belongs beside the last row. Axios notes that in August OpenAI said it would slow development of its Astra model over cybersecurity concerns. That decision predates the essay and was made on OpenAI's own threshold, which we described in our post on the Astra cyber threshold. It is the one concrete example of a lab pacing itself that Axios cites, and it happened for a reason the essay did not cause.

05DecisionsWhat to watch, and what to do

For most businesses the right response is to change nothing in production and to add three items to a watch list. Each is a document that would turn a proposal into a fact.

The first evaluator report. Anthropic's terms give reviewers the right to publish. The first published report will show what access was actually granted and whether the redaction rules held. Until it exists, the commitment is a description.

A second lab's written terms. Altman's post is a sentence. A published access agreement from OpenAI, or from any other lab, would make step one an industry practice rather than one company's policy. Watch the labs' own sites, not the posts.

Legislation with a testing requirement. Anthropic's policy chief asked, as reported by Axios, for a national law requiring testing of frontier models with the power to block unsafe ones. A law of that shape is the only route in the essay that could change a release date. Track the bill text, not the headlines.

If your business depends on a specific model's continued availability, the existing controls still apply: a documented fallback model, a deprecation watch on each vendor's page, and a contract that names notice periods. Our AI transformation practice builds those controls into agent deployments as standard, because model turnover was a risk long before anyone proposed slowing it.

06Next stepOne promise is checkable; the rest is a request

Put it into practice

Add the three documents to a watch list and change nothing else

The essay commits Anthropic to embedded evaluators and asks everyone else to coordinate. Endorsements from OpenAI and SpaceXAI are words until a written arrangement follows. Keep your model fallback plan current, watch for the first evaluator report, a second lab's terms and any testing law, and treat every other claim about labs slowing down as unconfirmed until a primary document says so.

Digital Applied

Build on frontier models without betting on one vendor.

We design agent deployments with documented fallbacks, deprecation watches and contract terms that survive a change in model policy.

Model fallback plansVendor risk reviewsAgent delivery
Your next project

Start with the dependency you cannot lose

  • Map which models each workflow calls
  • Name a tested fallback for each
  • Set a deprecation and policy watch
Questions and answers

Applying this post

No. The essay says pacing does not mean halting model training or technical progress, and it describes no change to any product schedule. The commitment is about outside evaluator access, not release timing.
Digital Applied newsletter

Deep dives on AI, marketing and development.

Practical guides and fresh insights by email. No recycled takes.

Related dispatches

Continue reading

AI Development

GPT-5.6 Sol, Terra & Luna: OpenAI's New Model Family

OpenAI previews GPT-5.6 as three tiers — flagship Sol, balanced Terra, high-volume Luna — with new multi-agent reasoning, pricing, and a gated rollout.

June 26, 2026 · 9 minRead
AI Development

OpenAI Won't Rule Out Critical Cyber Risk in Astra

OpenAI says it cannot rule out Critical cyber capability in Astra, an unreleased model, and published the agent controls it applied. Vendor-stated.

August 9, 2026 · 18 minRead
AI Development

Cloudflare Blocks AI Agents on Ad Pages: Which Bots Are Hit

From September 15, 2026 new ad-supported Cloudflare domains block AI agents on ad pages and refuse AI training by default. A 20-bot census of who is affected.

September 15, 2026 · 10 minRead
AI Development

Gemini 3.8 Live: Should a Voice Agent Think While Talking?

Google split its live voice model in two on September 15: one answers at once, one reasons while it speaks. Which to pick, and where each is available.

September 15, 2026 · 7 minRead
AI Development

Computer-Use Agents: Microsoft vs Anthropic vs Google

Microsoft GA, Anthropic public beta, and Google Gemini preview — OSWorld scores now 78% across frontier models above the ~72% human baseline. Routing guide.

May 22, 2026 · 16 minRead
AI Development

Agent Computer Use: Enterprise Automation Playbook

Enterprise playbook for deploying computer-use agents — a 40-point guardrails checklist spanning identity, audit, action boundaries, failures, and compliance.

May 22, 2026 · 17 minRead