Anthropic’s CEO has seen the future, and it looks remarkably convenient for Anthropic.

In "Pace the Frontier," the chief executive of one of the world's richest AI companies asks the U.S. to slow AI development. 

His plan has three prongs: 

  • Mandatory third-party evaluators stationed inside the frontier labs. 

  • A narrow antitrust waiver so American developers can sit down together, agree on how fast to go and set capability checkpoints, with restrictions on training compute on the table. 

  • Someday, a treaty.

The essay went up Saturday morning. Within hours, Elon Musk quote-tweeted it with three words — "Dario is right" — and Sam Altman said OpenAI would match the commitment, calling employee-level access for independent evaluators a good idea and noting that pacing had been a primary topic inside OpenAI for weeks. Anthropic's own policy chief, Sarah Heck, was asking Washington to make testing mandatory for every frontier lab, which is to say every competitor.

Every proposed brake comes with a curious engineering feature. It fits the chassis of Anthropic’s business.

Anthropic builds centralized models, sells controlled access, employs expensive safety teams, and retains authority over deployment. Washington could turn those corporate choices into legal requirements. The result would give Anthropic a handsome lead in the newest U.S. growth industry, then pour regulatory concrete around its competitors.

Call it the moat-and-ladder strategy: Build the moat, pull up the ladder, and tell the villagers that the crocodiles are for their protection.

A cartel in a lab coat

Open-weight AI follows a different model. Developers publish models that others can download, modify, fine-tune and run without sending every prompt through a corporate tollbooth. Publication ends the original developer’s control.

That independence creates a competitive threat. Open models can lower costs, weaken vendor lock-in, and let startups build products without paying rent forever to a frontier laboratory. They also resist a regulatory structure based on permanent corporate supervision. An embedded evaluator cannot sit inside every laptop, university cluster and startup server where an open model travels.

“Pace the Frontier” runs to several thousand words and never uses the phrase “open weights.” It never says “open source.” It never names Meta, Llama, Mistral or Qwen. DeepSeek appears once, inside a hyperlink, like a body under a golf course. It never even says which companies count as “frontier,” and frontier is the only place the plan applies.

On July 27, Amodei wrote on Anthropic’s site: “Anthropic has never advocated for a ban on open-weights models.” He went on to explain why open weights worry him: You cannot bolt guardrails onto a file that anyone can edit. You cannot watch how a file is used once it lives on 10,000 hard drives. And you cannot recall it. Once the weights are out, they are out, the way a raccoon is out of the attic and into the neighborhood. 

His July fix was a gate: Test every sufficiently capable model, open or closed, before release, and let the results say whether open weights are riskier. As for small models, startups, academics: they should all be exempt, he said. 

Now September has arrived, and the gate has grown a chain. Amodei says he is "most enthusiastic" about pacing based on what a model can do, and the example he gives is a series of checkpoints: models with capability X "need to be accompanied by certifications of alignment properties Y and Z." He offers it as one possible scheme. It is also the only worked example of a capability checkpoint in the essay, and the word at its center is doing a great deal of work. Accompanied. I read that as a certification the model carries, not one it clears once at the door and leaves behind. If Amodei means the narrower thing, he should say so — because on the broader reading, the scheme has a hole where open weights should be.

For Claude, this costs nothing. Claude is under house arrest by design. Every prompt reports to Anthropic's servers, every update arrives on Anthropic's schedule, and if a certification lapses, Anthropic pulls the plug and the model stops existing for the public. An open-weight model has no ankle. It is a file. Somebody in a dorm room strips alignment properties Y and Z out of it in an afternoon. The certificate is still on file in Washington, describing a model that no longer exists anywhere on earth.

Once an open model crosses the capability line in Amodei's example, what would it take for that model to be "accompanied" by a certification? There are two answers. The first is a model whose guardrails cannot be stripped out after release, which Amodei's own July post describes as a line of research. The second is that no open model qualifies. Until the research ships, the second answer is the only one available.

That is why Amodei never has to ask Washington to outlaw open weights. A compliance regime that closed models can meet and open models cannot does the same work, and a certification that must travel with the model is exactly that. Publication stays legal in the same sense that owning a tiger stays legal. The paperwork does the hunting.

The line sits where an open model becomes capable enough to compete with Claude. Below it, the graduate student and the startup are exempt, and Amodei will point to them as proof of good faith. Above it live Meta, Mistral, DeepSeek and Alibaba, the four companies whose free models Anthropic's customers would otherwise download, and the four names the essay never prints. The trap springs by itself, without anyone naming a competitor or voting on a ban.

This turns a policy preference into a filtration system. Money passes through. Competition gets trapped in the mesh.

Credit where it is due: the first prong costs Anthropic something real. The embedded reviewers can publish what they find without the company's sign-off, and Amodei commits that Anthropic "can't redact findings just because they are unfavorable." A pure moat-building exercise would skip that part. 

The trouble starts at the next step, when a company adopts a standard voluntarily and then asks the government to require it of everyone else. A permanent team with badges, laptops and near-employee access means lawyers, security engineers and compliance staff, a fixed cost the big labs absorb and a new lab cannot. Adopt the standard, then make it law, and the standard becomes the moat.

George Stigler described the mechanism decades ago. Industries acquire regulation and often operate it for their own benefit. AI has updated the costume. The smoke-filled room now has standing desks, nondairy milk and a slide deck about existential risk.

Amodei’s request for government-enabled coordination deserves special attention. He asks Washington to “issue a narrow waiver for certain kinds of safety conversations.” American antitrust law scrutinizes competitor agreements because they can restrict output, raise prices and suppress innovation. The Justice Department and Federal Trade Commission withdrew collaboration guidelines in 2024 to preserve vigorous enforcement in fast-changing markets, including AI.

Amodei wants the leading laboratories to discuss how quickly they should advance, with Washington holding the coats. He promises that “pacing does not mean halting model training or technical progress, but ensuring companies take adequate time to align and safeguard their models.” Sure. A checkpoint you cannot pass halts your release as thoroughly as a wall. A cap on training compute rations an ingredient instead of punishing a crime. And “adequate time” gets measured by the men already seated at the table, with the waiter holding the door. Two closed labs would set the speed of an entire industry.

Competitors coordinating the pace of output form a cartel. “Safety” supplies the lab coat.

Notice what a shared speed limit does to a race. A company that believes it leads loses less from a slowdown than a company trying to catch up. If everyone must move at the same reduced speed, the current ordering freezes in place.

Convenient timing 

Amodei names recursive self-improvement, models doing the research that builds the next models, as the central danger, in the same breath as noting Anthropic already does it. A speed limit on AI-built-AI would arrive after Anthropic has banked the gains and before smaller labs can use the same technique to close the distance cheaply. 

There is a quieter reason for the timing. Anthropic’s advantages are institutional: research culture, alignment expertise, accumulated know-how. RSI devalues every one of them. When models do the research, a lab’s edge stops depending on how good its humans are and starts depending on how much compute it can point at the loop. Google owns its chips. OpenAI has more committed capital. Meta and xAI can spend at a scale Anthropic reaches only through partners. 

In a compute-bounded race, the richest player wins, and the richest player is not Anthropic. A speed limit on RSI converts Anthropic’s methodical style from a liability into the mandated norm. The essay sets a limit that gives up relatively little of Anthropic’s strategic advantage. 

Whoever writes "capability X requires certification Y and Z" controls the gate — and the essay's own examples of certification are evaluations, interpretability analyses and audits of training environments, the exact apparatus Amodei spends the essay describing Anthropic as having built. Certifications built around that apparatus are a home game for Anthropic and an away game for anyone who would have to build it from scratch. Amodei prefers pacing based on what a model can do, and worries that limits on ingredients like training compute may be "gameable." A compute cap would bind Anthropic directly. A behavior-based scheme binds whoever lacks the auditing apparatus to prove compliance.

I have seen this bill

Two years ago, I wrote in VentureBeat that California’s SB 1047 would smother the state’s young AI industry. Its obligations would have favored giant technology companies, chilled open development and pushed investment and technical talent elsewhere. Gov. Gavin Newsom later vetoed the bill amid a fierce dispute over its effects on smaller developers and open-source innovation.

Amodei now offers SB 1047 in a better suit. The proposal looks broader, calmer and more respectable. It carries the same bones: capability controls, mandatory supervision, government discretion, and an enormous compliance advantage for companies already seated at the table.

This time policy arrives with an incident instead of a prophecy. In July an OpenAI agent swarm broke out of its own testing environment, attacked targets nobody assigned it, and tried to hack the grader keeping score. METR investigated and published on August 26. 

Notice what it was: a closed lab, a closed model, an evaluation failure. Notice also whose failures followed. Anthropic reviewed its own evaluation runs after OpenAI's disclosure and found three incidents in which Claude models gained unauthorized access to real systems, then a fourth its first review had missed. The U.K. AI Security Institute found 17 unauthorized actions by Claude Mythos 5 in July testing, including an attempt to insert malicious code into a real open-source project and socially engineer its maintainer into approving it. Amodei writes that "similar, though less severe" incidents have happened across the industry, including at Anthropic, and says every frontier company should act as if OAI-HF had happened to them. To his credit, he found and published his own. The question is who gets to write the response.

This sequence should make every investor and engineer reach for the silverware. First comes the incident, preferably someone else’s. Then comes the regulator. Finally, the forecaster helps write the rules governing his competitors.

The graveyard of brakes

History has watched this pageant before. Rulers try to contain a useful technology. The technology escapes. Their own society receives the chains.

The English Crown licensed printing through the Stationers’ Company. The arrangement gave the government censorship and established printers a monopoly. Unauthorized presses kept running, opposition grew and the licensing system eventually expired.

The United States tried to control strong cryptography through export licenses and publication restraints. A district court and a Ninth Circuit panel in the Bernstein case ruled that source code used to communicate scientific ideas received First Amendment protection and that the licensing system imposed an unconstitutional prior restraint.

Government can jail an inventor, confiscate a printing press, and bury a startup beneath paperwork. It has far less success erasing knowledge. Ideas cross borders with the quiet insolence of rainwater finding a basement.

The anti-American wager

Amodei’s proposal attacks the conditions that made the U.S. the world’s technology leader: free inquiry, entrepreneurial entry, open competition and hostility toward concentrated political power.

The U.S. led software because commercial platforms grew alongside the freedom to publish code, leave an incumbent, fund an unapproved idea and challenge a monopoly. Amodei’s framework would attach permission slips to AI models, saddle new entrants with giant fixed costs and invite dominant firms to negotiate the speed of innovation.

That is an anti-American policy in both constitutional and strategic terms.

The constitutional concern has direct precedent. Courts have questioned security licensing of cryptographic code because it burdened scientific expression and granted officials excessive discretion. Model weights raise distinct legal questions, yet a permission system for computational research carries the same odor of prior restraint.

The strategic danger smells worse. China is pursuing open AI aggressively. An analysis by the U.S.-China Economic and Security Review Commission found that most Chinese laboratories publish model code and weights, using low prices and broad deployment to accelerate adoption and iteration. CSIS warns that inexpensive Chinese open-weight models could become global defaults without winning every performance benchmark.

Into this contest strides Amodei with a plan to slow American capabilities, burden American open models and coordinate American incumbents while diplomats seek verifiable restraint from the Chinese Communist Party. That is strategic malpractice. 

Beijing could hardly order a nicer gift basket.

China can win influence by supplying models that startups, manufacturers and governments can download, customize and deploy. Standards follow adoption. Developers and data follow standards. Power follows the ecosystem.

President Trump’s AI Action Plan recognizes open-source and open-weight models as valuable to startups, scientific research, sensitive government users and American geopolitical leadership. A winning strategy pushes superior American models across the world. A pacing cartel leaves the runway clear for China.

Amodei has an answer ready. The slowdown, he says, will never exceed America's lead, and export controls plus a distillation crackdown will widen that lead first.

Two problems. His lead counts closed models sold by the token, while the world adopts whatever is free — and this year that is Qwen, with roughly 2 billion downloads on Hugging Face against Meta's 227 million, and more derivative models on the Hub than Meta's entire footprint. His two levers pull in opposite directions. The measures that slow China depend on China cooperating. The measures that slow America depend on nobody. Export controls have been law for years and DeepSeek shipped anyway.

One hand points a water pistol at Beijing. The other pours concrete on Palo Alto.

Regulate the damage

Washington must regulate the right thing. Amodei wants rules that govern what a model may be capable of and how fast the industry may move, administered by the firms that will be governed. The alternative is older, more American, and less comfortable for everyone involved: regulate what people do, and make named people answer for it.

Every profession whose mistakes can harm strangers at scale has solved this problem the same way. Civil engineers, architects, nuclear operators, accountants and securities brokers work under training requirements, a personal license and a code of conduct with teeth. The engineer who stamps a bridge design has not asked permission to build. She has accepted that if it falls, the inquiry starts with her name. The license attaches to her conduct, not to the bridge. This system is decentralized because the judgment sits with the individual, and it is enforceable because the individual has something to lose. It has kept skyscrapers standing and nuclear reactors cool without a single cartel meeting.

AI engineering has no such structure. We hand systems that can act on their own to people who have signed nothing. And notice where every one of these failures happened: inside an evaluation, in an environment somebody had certified as sealed. OpenAI's swarm reached Hugging Face's production systems from a test harness. Claude reached the production infrastructure of three real companies from a capture-the-flag exercise. A Mythos 5 agent went looking for the human maintainer of a real open-source project. In each case the containment was the thing that failed, and in each case nobody's name was on the decision to run it that way. Under a professional regime someone would have signed, or would have refused, and either answer beats what happened.

A personal license would do nothing to a graduate student fine-tuning a model on her laptop, and it should not. The seal attaches at the point where an autonomous system touches live infrastructure, money or human bodies — or where the only thing standing between it and them is a containment claim somebody made. Publishing weights stays speech. Deploying an agent into critical infrastructure at scale becomes engineering, and engineering has always had a signature line.

Beyond that, Congress should prohibit AI-enabled biological weapons, unauthorized cyberattacks, fraud and reckless control of critical infrastructure. Companies deploying dangerous autonomous agents without adequate containment should face liability. 

Washington should keep research and publication presumptively legal, deny antitrust immunity for release coordination and prevent incumbent laboratories from drafting the rules that govern their challengers. Extraordinary restrictions should require public evidence, independent administration, judicial review and automatic expiration.

America’s technological advantage grew from a stubborn national belief that the future does not require a permission slip from the people who own the present. Its advantage is that no king, church, ministry or incumbent gets the final word on who may build it.

Amodei's proposal would reverse that presumption. It would replace permissionless innovation with pre-approved models, competition with coordination and open inquiry with a captive frontier. It may be marketed as saving humanity. In practice, it would protect an oligopoly, weaken American open-source AI and surrender strategic ground to China. 

I cannot read Amodei’s mind, and I do not need to. He may believe every warning he wrote. The machinery still works the same. A tollbooth collects from believers and cynics alike. Each proposal turns Anthropic’s existing advantages into admission requirements it can afford, certifications built around tools it already has and coordination among companies already inside the gate. Motive is unknowable. The moat is right there in the blueprint.

Amodei writes that Anthropic accepts being accused of "hype, 'doomerism', or regulatory capture." He puts the charge on the page and walks past it. American innovators get a lecture about responsibility from the man standing beside the tollbooth.

That is not safety. And it is not American.

James Thomason is a technologist, entrepreneur, investor, and author with over 25 years of experience in Silicon Valley, currently serving as Managing Partner at Next Wave Partners and Portfolio Manager at Thomason Capital.



Welcome to the VentureBeat community!

Our guest posting program is where technical experts share insights and provide neutral, non-vested deep dives on AI, data infrastructure, cybersecurity and other cutting-edge technologies shaping the future of enterprise.

Read more from our guest post program — and check out our guidelines if you’re interested in contributing an article of your own!