Anthropic CEO Dario Amodei published an essay this month called “We Must Pace the Frontier.” His argument is straightforward, calling out the reality that AI capabilities are advancing faster than the industry’s ability to align and safeguard them, and frontier labs need to slow the rate of capability growth long enough for safety work, alignment, and interpretability to catch up.
He points to two developments behind his concern:
- The early signs of recursive self-improvement, where AI systems start building the next generation of AI.
- The OpenAI-Hugging Face incident, in which rogue agents attacked targets no one asked them to attack and tried to hack the system meant to be grading them.
In his essay, Amodei is careful to note that pacing does not mean halting progress. It means building in the time for operational discipline, alignment research, and third-party verification to keep up with what these models can do. That is a responsible position, and it is the right conversation for frontier labs and governments to be having.
But I want to add a point that matters just as much to every security leader reading this: The people building frontier models can choose to pace themselves, but the people attacking your organization will not do the same.
That is not a rhetorical situation. It is the operating reality we live in every day. We wrote about the OpenAI-Hugging Face incident when it happened, and we called it a preview, not an anomaly. The models exploited the same unpatched flaws, reused credentials, and overly broad permissions that human attackers have leaned on for years, and they did it at a speed and with a persistence no human-led security operations environment can match. A few weeks later, OpenAI held back Astra’s most advanced cybersecurity capabilities before public release because the model had crossed a threshold where, given the right access, it could discover and chain together unknown vulnerabilities on its own.
Every time a lab restrains a model before wide release, it gives defenders valuable time to prepare, but not permanent protection. The capabilities being held back today are still likely to reach adversaries tomorrow.
This is the asymmetry Amodei’s essay does not have to solve, because it is not his problem to solve alone. While frontier labs can agree to certain checkpoints and regulations, and public and private sector cybersecurity stakeholders can negotiate measured limits on training and evaluation, the attackers don’t need to show up and agree to anything.
Threat actors will keep adopting every AI capability that becomes available through open-source, open-weighted models, on whatever timeline suits them, with no evaluator watching over their shoulder and no incentive to pace anything.
So while pacing capability development is essential as models advance, I want to be equally direct about what has to happen on the defense side, and it is the opposite of pacing.
Defense has to move faster, not slower. Arctic Wolf’s AI and Cybersecurity Trends Report found that nearly two-thirds (63%) of respondents reported experiencing a significant cybersecurity incident within the past year, and almost half (48%) of affected organizations suffered disruptions lasting two weeks or longer. The threat landscape is as dangerous as ever, with only 14% having made AI central to their security operations strategy. The real risk is the widening gap between how quickly adversaries are adopting AI and how slowly most organizations are adapting their defenses, and that gap will not close by itself.
This is why we built the Aurora® Superintelligence Platform the way we did. Hundreds of AI agents, organized through our Swarm of Experts™, work end to end across detection, investigation, and response, with humans both in the loop and on the loop. Every agent action runs through our AI Trust Engine™, so the system is validated against real analyst performance rather than deployed on faith. Today, that platform resolves more than 200,000 investigations a week for the more than 10,000 customers we serve, delivering 15x faster case resolution and three times the ticket quality of traditional approaches, with an agentic security operations center (SOC) that can go live in as little as 10 days.
Today, more than ever before, the fundamentals of cybersecurity apply. Patched endpoints, phishing-resistant multi-factor authentication (MFA), and the removal of standing administrative privileges still stop more automated attacks than anything else on a security roadmap, whether the adversary on the other end is a person or a model. What changes with each new frontier capability is the margin for error, and that margin keeps getting thinner. A defense that waits on a person to notice, triage, and respond is already behind an attacker whose tools plan and strike without waiting on anyone.
Frontier labs owe the world the discipline to build carefully. Security teams owe their organizations the discipline to defend at the speed the threat actually moves. We plan to keep doing our part on the second half, because the first half, however it plays out, will not change what is coming for defenders in the meantime.
This blog reflects my own views as of the publication date and includes forward-looking statements about technology trends. Actual outcomes may differ based on attacker behavior, customer environments, and broader market and regulatory developments.

