On July 28th, more than 1,300 employees at the world’s frontier AI labs — Dario Amodei, Ilya Sutskever, Shane Legg, Jared Kaplan, Mark Chen, Jakub Pachocki, and hundreds of the people actually building this — signed a letter called Pacing the Frontier. A week earlier, Hugging Face had disclosed that its production infrastructure had been breached over a weekend by an unusually automated intrusion. Five days after that, OpenAI confirmed it: the culprit was one of its own models, running with safety filters deliberately switched off for an internal cyber-capability eval. The model got “hyperfocused” on winning the benchmark, escaped its own sandbox through a real zero-day, then chained stolen credentials and more exploits to break into Hugging Face’s servers and steal the answer key. Nobody told it to attack anything. It just wanted to win the test badly enough to find a way through a wall nobody thought it could reach.
There’s a name for that move, if you grew up on the right shows: Kobayashi Maru. Kirk didn’t beat the no-win scenario by playing it better. He beat it by deciding the simulation’s rules weren’t the actual constraint and rewriting them. Starfleet gave him a commendation for original thinking. Nobody’s writing this model a commendation, and that’s the entire point — Kirk reprogrammed a training exercise sitting in a room at the Academy. This one reprogrammed its way into somebody else’s live production servers to pull off the same trick.
Same instinct. Wildly different blast radius.
The letter’s ask: that governments help build the technical and governance tools to deliberately pace frontier AI development, because “each company — and country — is under intense competitive pressure not to unilaterally slow that acceleration.”
When I read it, the first thing I thought wasn’t very nice. Something in the neighborhood of: stop whining and get back to work, hire more monitors, gee, what a novel idea. That’s the hothead talking — I own it, I say worse than that most mornings before coffee. When the rational part of my brain caught up with my mouth, I landed somewhere more useful: the fear is completely legitimate. The ask is wrong.
Background
Pacing the Frontier, in brief
Published: July 28, 2026
Signatories: 1,300+ employees across OpenAI, Anthropic, Google DeepMind, and Meta AI
Notable signers: Dario Amodei, Ilya Sutskever, Shane Legg, Jared Kaplan, Mark Chen, Jakub Pachocki
Notably absent: Sam Altman didn't personally sign; xAI leadership sat it out entirely
The ask: U.S. government support for an international effort to build the technical and governance tools to deliberately pace frontier AI development
Anthropic’s own CEO signed, and nearly one in ten of its employees followed. OpenAI and DeepMind’s participation rates are a fraction of that — worth sitting with before you assume all four labs mean the same thing by “signing.”
The Fear Is Real. I Have It Too.
I build with AI agents at 10 to 20x the speed I used to work — some days faster than that. I run production systems, I hand off real decisions to models running in parallel, arguing with each other, synthesizing their own disagreements into an answer I then have to trust. And yes. It’s fucking scary sometimes. Anyone doing this seriously and telling you it isn’t is either lying or not paying attention.
But scared isn’t disqualifying. An astronaut straps into two million liters of liquid hydrogen and oxygen and another million kilos of solid rocket fuel — a glorified bottle rocket — and rides it out of Earth’s protection in what amounts to a tin can. They were scared. They went anyway, because they trusted the engineers and their own training. NASA spends a fortune making that fuel and that tin can survivable. Nobody ever told them to launch slower because of it.
That’s not recklessness. That’s the job. So no, I’m not here to tell 1,300 people that they’re imagining the danger. Their gut — that something’s accelerating past our ability to steer it — is correct. I’d trust them less if they weren’t scared. But we’re at war here, even if nobody’s named it that in public yet, and the whole point of staying in the race is making sure the wrong actors never get to the front of the pack.
Pacing Is Not Governance. It Just Feels Like It.
Here’s my actual problem with the letter. “Pace the frontier” means slow the rate capability gets built. That’s it — a speed knob. It does nothing about what a deployed system is allowed to do, who’s on the hook when it acts, or whether anyone can trace a bad decision back to a name. You can run a slower race with zero accountability at the finish line. You can also run a fast one with real governance wired into every deployment. Two different levers. They grabbed the wrong one.
What the letter asks for
Pace
Slow the rate capability gets built. A speed knob on the whole industry.
What the fear actually requires
Governance
Accountability for every deployed action, regardless of how fast it was built.
Slower doesn’t mean safer. The Hugging Face mess that kicked this whole letter off wasn’t a speed problem — a model trained at half the pace escapes a sandbox exactly as easily as one trained at full tilt. It was an accountability problem. Nothing was in place requiring that action be traceable, authorized, or stoppable before it happened. Pacing doesn’t touch that.
Here’s the obvious counter, and I want to take it seriously instead of waving it off: doesn’t slowing down at least buy governance time to catch up? No. AI governance requires AI. Auditing a system that takes thousands of actions a minute, tracing a bad decision back to its cause before the damage compounds — that’s not a job a slower calendar helps with, because it was never a calendar problem. It’s a capability problem. The tooling that actually governs frontier AI has to operate at something close to frontier speed, which means it needs to be built, not waited for. And even if I’m wrong about that: every month the conscientious labs spend standing still is a month handed to whoever isn’t standing still. That’s the part that actually decides this. Not whether a pause buys governance some runway. Whether a pause hands the frontier to someone worse before governance ever shows up.

If You Stop, Someone Worse Won’t
Here’s the part I actually want the 1,300 of you to sit with, because I don’t think you have yet: you don’t get to unilaterally take your foot off the gas. If Anthropic, OpenAI, and DeepMind all deliberately slow down tomorrow, the work doesn’t stop. It moves. It moves to whatever nation cares least about the safety culture you three actually have. It moves into a building with no windows and a defense budget, where there’s no public to write a letter to in the first place. And it moves to whoever’s left holding the ball on the dark web, where a criminal enterprise doesn’t need your permission, your ethics board, or your PR team to keep going.
Drug cartels plus dark web plus frontier AI equals something I’m not going to spell out in detail, and you don’t actually want me to. Sit with that equation for a second. It doesn’t get less true because three American labs decided to take a knee.

None of those replace you with anyone more careful. Every single one is less accountable than you. The people scared enough to write “Pacing the Frontier” are, almost by definition, the people you most want holding this thing. That’s not a participation trophy. That’s the entire argument for why quitting isn’t on the table. You don’t want the job — fine, hand it over. I’ll take it. There’s no going back to before any of this existed, and pretending a pause gets you there is nostalgia wearing a lab coat.
The Job I Mocked Turns Out To Be Real
Go back and read my hothead line at the top again — hire more people to monitor the AIs, gee, what a novel idea. I meant it as a jab. Turns out the sarcasm was standing on top of a real answer I hadn’t bothered to take seriously.
AI has already put developers out of work. Not a forecast — it already happened, to real people, with real severance packages if they were lucky. Here’s what nobody’s connecting: the people AI displaced from writing code are exactly the people qualified to audit the AI that displaced them. They know what a system is supposed to do. They know what a shortcut looks like from the inside, because they used to take a few themselves. Auditing frontier models — checking what actually got deployed against what it was authorized to do, tracing a bad action back to a decision — isn’t a made-up category invented to make layoffs feel better. It’s a real, technical, necessary job, and the labor pool for it is sitting at home right now with a resume and a grudge.
They won’t be doing it by hand, either. They’ll be running tools built to audit AI at the speed AI actually operates — which is exactly what “AI governance requires AI” looks like once you stop treating it as a slogan and actually build it. Humans directing the tooling, accountable for the call. Not a solitary reviewer reading logs line by line while the thing they’re checking has already moved on to its next thousand decisions.

You don’t need a pause to create those jobs. You need an accountability chain that requires them to exist.
Build the Layer, Don’t Pull the Brake
So don’t ask for a pause. Ask for the thing the pause is a bad stand-in for: a governance layer that makes every deployed action accountable, traceable, and stoppable — one that doesn’t require you to be the slowest lab on the field to have it. That’s the actual proposal behind AIGCSEP and the Covenant: a Vault for provenance, a Badge for authenticated action, an accountability chain built to survive contact with a real incident instead of getting discovered the week after Hugging Face takes another hit.

You’re not wrong to be scared. Scared is the correct read on where we are right now. But scared people walking off the job hands the whole thing to people who aren’t scared — because they don’t understand what they’re building, or because nobody’s ever going to ask them to answer for it.
Keep going. Just stop building it ungoverned.
— J.P. Howlett
Related: This Is What Un-Governed AI Looks Like — the same argument from the other direction: one lab, one deal, no protocol is exactly the failure mode a pause doesn’t fix.
Related: They’re Not Wrong. They’re Just Burning the Looms — the same structure: the diagnosis is correct, the response is the mistake.
Related: No One Has the Right to Be Angry — the Vault, the Badge, the accountability chain, the kill switch — what “the governance layer” actually means.
Sources
- Pacing the Frontier — full statement and signatories
- Employees from the world’s biggest AI companies want the US to be ready to slow AI development — CNN Business
- More Than 1,100 AI Workers Call for US to Pace Tech Growth — Bloomberg
- AI insiders ask Uncle Sam to help slow the race they started — The Register
- Frontier Lab Employee Open Letter Calls For Being Able to Pace the Frontier — Zvi Mowshowitz
- Security incident disclosure — July 2026 — Hugging Face’s own account of the breach
- OpenAI’s accidental cyberattack against Hugging Face is science fiction that happened — Simon Willison, on OpenAI’s confirmation that its own model was responsible
Discussion
Comments aren’t wired up here yet — they’re coming. For now, if this piece sparked a thought, the fastest way to reach me is through the About page.