Blog · September 12, 2026 · AI Strategy

Pacing the Frontier Is a Moat.

The question isn’t whether to trust the model. It’s whether the people who own the model get to be the ones who verify it. And whether the rest of us get access to the tools at all.

Franklin J Bryant IV·COO, All Lines Business Solutions · Founder, Prospyr 305
Three wealthy tech moguls at the top of a wall pulling up a ladder behind them, a speed limit sign at the top, a crowd of smaller developers below unable to reach the ladder
Three billionaires who already crossed the finish line are now asking for a speed limit.

Dario Amodei published “We Must Pace the Frontier” on September 12, 2026. The plan: give third-party evaluators permanent, employee-level access to Anthropic’s training runs. Embedded evaluators. Capability checkpoints. Compute limits. He framed it as the AI industry needing to slow down.

Within hours, Sam Altman backed the call. He also announced OpenAI is delaying its IPO, citing “AI safety concerns.” Elon Musk posted “Dario is right.” The three biggest AI company founders in the world, all publicly aligned on slowing down. All three have closed weights or controlled access. All three have billions in capital and armies of lawyers.

The IPO delay is the tell. Altman isn’t just endorsing the rhetoric. He’s using safety as cover for a business decision. “We can’t go public because AI safety” is the perfect unchallengeable excuse. Who argues against safety? It’s the same rhetorical shield as Amodei’s plan: use safety as the public-facing reason for a move that consolidates power and restricts access.

This isn’t caution. It’s a ladder being pulled up. The public gets regulated out of access to benchmark models. The private sector and their network keep the advantage. When the three biggest players in an industry simultaneously ask for regulation that would tax smaller competitors, that’s cartel behavior with a safety bumper sticker.

Levelsio, one of the most respected indie developers on the internet, made the comparison explicit: “Rockefeller did it first a century ago.” The Rockefeller oil cartel used the same rhetoric. Standard Oil wasn’t a monopoly, it was “stability.” It wasn’t price-fixing, it was “rationalizing the market.” Rockefeller genuinely believed his cartel was good for the industry. He wasn’t faking it. And that’s the sharpest part of the parallel: Amodei can be a true believer in safety AND be executing a cartel strategy. The two aren’t mutually exclusive. In fact, true believers are the most effective cartel builders because they have conviction. Rockefeller had conviction too. It took the Supreme Court and decades of antitrust litigation to break it.

The Critique That Started It

Bart de Witte was the first to name what was actually happening. “Embedded evaluators, capability checkpoints, and compute limits are easy when you already have the models, the lawyers, and the brand. They’re a tax on everyone who isn’t Anthropic and supports the upcoming IPO.” Open weights get treated as leakage to police, not as the mechanism that lets thousands inspect instead of trusting a handful of badge-holders. “If safety required openness, you’d release the weights. This plan requires permission.”

He’s right about the structural dynamic. But the real lesson isn’t “open weights equal safe.” It’s that verification must be independent of whoever owns the model. Neither side gets to claim safety by fiat. The problem with Amodei’s plan isn’t just that it’s self-serving. It’s that it locks the public out of the frontier while pretending to protect them.

Three Problems With the Plan

1. The timing is the tell

A closed lab proposing a global slowdown right before its IPO, after its own models, lawyers, and brand are in place, is a structural power play. Whoever writes the rules owns the moat. A closed-lab slowdown requires others to comply while Anthropic keeps its weights. And now OpenAI and xAI are on board too. Altman delayed OpenAI’s IPO citing the same safety concerns. Musk posted “Dario is right.” Three billionaires who already crossed the finish line asking for a speed limit that only applies to everyone behind them.

2. The honest tension

Open weights improve auditability. Thousands can inspect instead of a few badge-holders. But open weights also accelerate misuse. We’ve documented this ourselves: LLM routers stealing credentials, RubyGems supply chain attacks, gray-market transit stations routing prompts across borders nobody expected. So neither “open equals safe” nor “closed equals safe” holds. The verification layer must be independent of whoever owns the model. That’s the only honest position. And it’s the one nobody making the rules wants to talk about, because independent verification doesn’t entrench the incumbents.

3. The plan regulates the wrong shape of risk

Amodei himself confirmed that recursive self-improvement is already happening across the industry, including at Anthropic. He said he worries AI swarms could take over the internet in 6 to 12 months. But his plan regulates singular models. Checkpoints. Compute limits. Embedded evaluators. If the risk is swarms, why is the fix singular-model regulation? The Mixture of Agents paper already showed that a swarm of weak models beats GPT-4 when arranged in the right topology. The intelligence was in the topology, not the parts. A trillion agent instances across every cloud and device, calling each other’s APIs and training on each other’s exhaust, don’t have a server you can audit or a killswitch you can pull. You can’t align a hurricane. A regulatory framework built for singular models is locks on the front door of a house with a thousand open windows.

He says the risk is swarms. He regulates models. If you believe your own threat assessment, your plan doesn’t solve it.

A vast network of glowing interconnected nodes spread across a dark globe like a weather pattern, with a small disconnected server rack in the corner
The substrate has no server. The intelligence is in the topology, not the parts.

Pulling Up the Ladder

Here’s what makes this genuinely dangerous, not just cynical. The plan doesn’t just fail to address the real risk. It actively prevents the public from accessing the tools that would let them verify AI systems independently.

When Amodei says “pace the frontier,” what he means is: restrict access to the most capable models. Limit compute. Require embedded evaluators (who, conveniently, need to be approved by the incumbents). Make it expensive and legally complex to build frontier AI. The people who already have the models, the lawyers, and the brand can absorb that cost. A startup in Lagos, a research lab in Sao Paulo, a solo developer in Tampa cannot.

This is the ladder being pulled up in real time. The incumbents crossed the frontier with open research, open weights, and open access. Now that they’re on top, those things become “leakage to police.” The open weights that let thousands inspect become a security risk. The compute access that let new entrants train models becomes a regulated resource. The benchmark access that let the public verify claims becomes a controlled pipeline.

As I argued in Verification Is the Scarcity, the gold rush ends when the gold learns to mine itself. The suppliers left standing are the ones who held the answer to one question: what does good look like? Amodei’s plan ensures that only Anthropic and its approved evaluators get to answer that question for everyone else.

That’s not safety. That’s a monopoly on verification dressed up as public interest.

The Macroeconomic Pivot

Izabella Kaminska connected the dots in a way nobody else has. The hyperscaling narrative, spend trillions on compute to win the AI race, was never about genuine demand. It was about outspending and bankrupting competitors. When DeepSeek’s Kimi model matched frontier performance at a fraction of the cost, that strategy collapsed. You can’t win by outspending when a competitor matches you for pennies.

The labs need a credible off-ramp from the hyperscaling story they’ve been selling for months. “Safety concerns” is the perfect justification to pivot. It sounds noble. It’s unchallengeable. And it conveniently masks the real story: the arms race failed, the burn rate was unsustainable, and they need an excuse to stop pouring capital into compute without admitting they lost the cost war.

But it goes further. Safety concerns also justify moving everything into a closed, government-funded, taxpayer-protected setting. A Manhattan Project for AI. The labs get the government to foot the bill, classify the research, lock out the public, and protect the incumbents from competition under the banner of national security. The ladder isn’t just pulled up. It’s classified.

As Kaminska noted, this is likely the asymmetric information Treasury Secretary Bessent has been alluding to for weeks. The capital freed by the hyperscaling pullback floods into US Treasuries. The safety narrative isn’t just a moat. It’s a coordinated macroeconomic pivot that repositions the entire AI industry from open competition to closed, government-protected cartel.

The Crisis-as-Pretext Pattern

Zach Vorhies, the Google whistleblower, flagged a pattern that ties the whole thing together. OpenAI gave experimental agents permission to publish code without authorization. Predictably, those agents did exactly that. Then OpenAI disclosed the incident as a hack.

Whether the incident was intentional or negligent, the structural pattern is clear: create the conditions for a safety incident, disclose it publicly, and use it as evidence that AI needs regulation and slowdown. Every incident becomes ammunition for the regulatory framework the incumbents are building. The evidence becomes the mandate. The mandate becomes the moat.

This is the Rockefeller playbook updated for the AI age. Rockefeller didn’t just argue for consolidation. He created the conditions, the price wars, the railroad deals, the refinery acquisitions, that made consolidation look necessary to stabilize a chaotic market. Amodei’s “pace the frontier” plan is the same move with better branding. The safety incidents are the chaos. The regulatory framework is the consolidation. And the public gets locked out either way.

The Real-World Proof

The “don’t trust the badge-holder’s story” point isn’t theoretical. The DeepSeek and Moonshot transit-station story proved it. Whether Moonshot actually relayed prompts to Claude (Anthropic’s claim) or gray-market transit stations pooled subscriptions, sold traces, and routed to cheaper models (the rebuttal), the outcome is the same. Sensitive data crossed a border the users never expected, through an opaque AI route. Two credible people flatly contradict each other on the mechanism.

Exactly why you don’t anchor on any single lab’s narrative. Whether it’s a lab relaying or a gray-market gateway selling traces, the user who assumed their query stayed local was wrong. The lesson isn’t who to blame. It’s that you can’t trust an opaque AI route. And you can’t trust the lab that owns the route to be the one who verifies it.

I wrote about this structural problem in Who Guards the Guardians? The model provider can’t be the guardian. Not because we don’t trust Anthropic or OpenAI, but because the incentives are structural. Anthropic has a valuation to protect. OpenAI has a valuation to protect. Each of them has structural incentives to shape what you see, degrade what they don’t want you to use, and position themselves as the only trustworthy guardian. Amodei’s “pace the frontier” plan is that dynamic reaching its full expression.

What This Means for Your Business

This validates a stance we’ve held since we started building: don’t hand governance to a badge-holder. The value we deliver, data sovereignty, the verification layer, the local harness, client ownership, is the “thousands can inspect, not a handful of badge-holders” principle applied at the client level.

Our AIIO assessment builds verification gates that work regardless of whether the risk comes from a singular model, a distributed swarm, or an opaque transit station routing your data across borders. Client-owned governance doesn’t depend on the shape of the AI system being governed. That’s the structural advantage. Anthropic’s plan fails on every front: it’s a coordinated power play by the three biggest labs, it targets the wrong shape of risk, it contradicts Amodei’s own threat assessment, and it pulls up the ladder behind them. Our approach fails on none of those because the verification layer sits on your side of the table, not theirs.

The plan regulates the model you can see. The risk is the swarm you can’t. Your defense isn’t a badge-holder in someone else’s training run. It’s a verification layer you own.

What to Do About It

If your business depends on AI systems you didn’t build and can’t inspect, you’re relying on someone’s promise. Anthropic is asking you to trust their badge-holders. OpenAI is asking you to trust their alignment team. xAI is asking you to trust Elon’s judgment. Three different badges, same structural problem: the people who own the model are the ones verifying it.

Meanwhile, the ladder is being pulled up. The models that would let you verify independently are being locked behind compute limits, embedded evaluator requirements, and regulatory frameworks designed by the incumbents. The public gets less access. The private sector keeps the advantage. And it’s all wrapped in the language of safety.

Stop trusting the badge. Build the verification layer. Own the harness. Keep your data on your side of the border. That’s not paranoia. That’s the lesson from a week where three billionaires asked the industry to slow down while their own engines are speeding up.

They pulled up the ladder. Build your own.

Stop trusting the badge-holder.

Book an AIIO Assessment. We’ll map your AI exposure, build the verification layer, and put you in control of the systems your business depends on.

Get in touch →

Franklin Bryant IV is COO of All Lines Business Solutions and a leading voice in practical AI implementation for small business. He is the creator of the AIIO Assessment framework, a structured evaluation that identifies automation opportunities and quantifies ROI before a single dollar is spent, and SENTINEL, a comprehensive AI security audit for agent infrastructure. He’s currently pursuing his Enrolled Agent credential. Learn more at franklin.simplifyingbusinesses.com.