On Friday 12 September, Anthropic's CEO Dario Amodei published an essay titled We Must Pace the Frontier. Its central line is one sentence long: "We must slow the pace at which we improve the capabilities of AI models. Progress will still seem fast, and we must make wise use of the time we gain." Within about an hour Elon Musk had posted "Dario is right." Not long after, Sam Altman wrote "I agree with Dario that we need to pace the frontier" and committed OpenAI to match Anthropic's first step. Three people who spend most of their public lives disagreeing had agreed on something before the weekend.
If you run a business that has already put AI into its website, its support desk or its back office, the question is not whether the essay is right. It is what, if anything, changes for you. The short answer: the frontier may slow, the deployment layer is doing the opposite, and the essay is a good reason to check one specific thing about your own AI setup this month.
What Amodei actually proposed
The essay is not a call to stop. Amodei writes that "over the last few months, I have become convinced that fully addressing the risks requires even more prudence — not just investing in risk prevention, but pacing the rate of capabilities advancement so that risk prevention has time to keep up." The risks he describes are specific: models that improve themselves, and autonomous agents operating at scale. On the second he is blunt. "In 6–12 months such a swarm could be capable of taking over the entire internet with a persistent botnet (potentially causing hundreds of billions of dollars in damage)."
The plan has three steps, and only the first is something a company can do alone:
- Embedded evaluators. Third-party safety evaluators get permanent, employee-level access inside the lab, so outsiders can check whether commitments are being kept. Amodei's announcement on X says Anthropic is "unilaterally committing to the first of these steps."
- Common standards among frontier labs in democracies, including limits on how fast capabilities are pushed.
- Agreements with non-democratic governments, escalating from bans on the most dangerous uses to caps on recursive self-improvement.
Altman's reply on X went beyond agreement: "Committing to having independent evaluators with employee-like access is a great idea, and we will do the same." Not everyone applauded. The same week, a researcher who had worked at both companies resigned from Anthropic, accusing the labs of "racing straight to self-improving super-intelligence and gambling with our lives", as reported by CoinDesk. That tension, between an essay asking for restraint and a resignation saying the restraint is theatre, is the real story. It will take months to see which reading is right.
What slows down, and what does not
Read carefully, the essay asks the labs to pace one thing: the rate at which the most capable models get more capable. It says nothing about the models that already exist, the tools built on them, or how fast businesses adopt them. And on that layer, the week's other news points the opposite way.
The day before the essay, Salesforce announced seven named AI agents for sales, service, commerce, IT, HR and supply chain. Six are generally available now. The seventh, an outbound sales agent, runs on a new runtime that works towards goals over weeks rather than a single chat. In Salesforce's words, "Memory preserves context and progress across sessions, so work doesn't stop when the interaction ends." That is the agent autonomy Amodei is worried about, shipped as a product, the day before he asked for a slower pace.
Adoption is the same picture. Microsoft's AI diffusion report for the first quarter of this year put global working-age use at 17.8 percent, up from 16.3 in one quarter. The UAE led the world at 70.1 percent. Whatever happens at the frontier, the businesses around you are already using the tools, and the ones that use them well will keep pulling ahead of the ones that do not.
So the practical summary is: the models you build on today are not going anywhere, the next big jump may arrive later than the hype cycle suggested, and the useful life of a well-built integration just got longer, not shorter.
The one thing to check this month
The risk Amodei names is not a chatbot writing a rude email. It is agents with real permissions acting at scale without anyone watching. That risk exists at every size. A small business with an AI agent that can read the inbox, update the CRM and send WhatsApp replies has, in miniature, exactly the setup the essay is about.
So the check is simple. For every AI agent or automation you run, can you answer these four questions in writing?
- What can it touch? The exact systems, accounts and data it has credentials for. If the honest answer is "whatever the integration asked for", that is the finding.
- What can it do without a person? Reading and drafting is one category. Sending, paying, deleting and changing customer records is another, and each of those should have a human signature or a hard limit.
- What did it do last week? Every action logged, with the input that triggered it. Not because you will read the log daily, but because the day something goes wrong you will need it in ten minutes, not ten days.
- What happens if the model changes? Providers update models on their own schedule. If your automation depends on the exact behaviour of one version, a routine update can break it silently. Build to the task, not to the model.
We set out the full version of this in what to automate in 2026 and how to do it with control, and the legal side, which in the UAE is mostly the data protection law rather than any AI act, in what actually applies to your business.
What we would do first
- Inventory the agents. Most companies we audit have more AI touching their systems than they think: a plugin here, a Zapier step there, a support tool with an "AI mode" switched on by a vendor. List them all.
- Split read from write. Give agents read access freely and write access grudgingly. Money, customer data and anything customer-facing gets a human in the loop until the logs prove it does not need one.
- Ask your vendors the evaluator question. Amodei and Altman have both now said outside evaluators should have employee-level access to their labs. It is fair to ask the company selling you an AI product what independent testing its system has had. The answer tells you how seriously they take it.
- Do not wait for the frontier. The gap the Microsoft report describes is a diffusion gap, not a capability gap. The advantage goes to the business that uses today's models well, not the one that waits for next year's.
The short version
- Amodei asked the labs to slow capability gains, not products. Altman and Musk backed him within the hour. One Anthropic researcher resigned calling it too little.
- The deployment layer sped up the same week: seven Salesforce agents, one of them working towards goals across weeks.
- For a business, nothing you use gets slower, and integrations built well last longer.
- The essay's real warning is about agent permissions. Audit yours: what it touches, what it does alone, what it did last week, what breaks when the model changes.
If your AI setup grew faster than your control over it, that is the exact brief of our AI automation work: agents that do useful work with permissions you can read on one page. Tell us what you are running and we will tell you what to tighten first. We wrote about the last time the AI market split, into free and frontier, here; this week's split, between the frontier and everything built on it, matters more.