HomeBlog
Outpace the Frontier

Dario Amodei's proposal to "pace the frontier" is intended to be responsible. In cybersecurity, it's doing the opposite. It raises a necessary question: which frontier are we trying to manage?

The Two Frontiers

There's the frontier of what AI can do: how fast capability advances, and how much restraint the companies building it are willing to show. That's Amodei's frontier, and it's the one he tries to pace.

There's a second frontier the letter never touches: how fast attackers are already moving with the AI that exists today. Nobody has the authority to pace that one, and nobody would listen if they tried. Attackers didn't sign the OpenAI letter, didn't answer to a three-step plan, and were never going to wait for a "so-called decision" to slow down.

The letter emphasizes alignment and coordination as the solution. However, coordination and alignment aren't things an attacker gives you. Treating both frontiers as the same problem and the prescription protects the wrong side of the fight: pacing the companies capable of restraint does nothing to the ones who were never going to show it. It just widens the gap between defenders who wait and attackers who don't.

Take Irregular's industrialization-of-offense framework. Low-skill actors run basic intrusions, advanced groups run multi-step operations, and APTs run state-of-the-art campaigns, all climbing the same curve as offensive capability grows. They're climbing it with the AI available today, not some future frontier model.

Photo credit: Dan Lahav, Irregular (August, 2026)

The plan doesn't hold up on its own terms

Amodei's three-step plan proposes coordination among frontier labs in democratic countries. But the chart above shows the danger isn't concentrated at the frontier. It's distributed across every tier of attackers, most of whom were never going to join any coordination agreement. A plan that only binds the most responsible actors binds the actors least likely to cause the harm it's worried about.

It also asks labs to slow the exact capability curve that defenders are climbing too. Attackers don't observe release schedules. Defenders who build on frontier models do. Pacing that curve doesn't take an advantage away from attackers. It takes one away from defenders, since the defensive tooling built on frontier capability is the one thing actually bound by the labs' restraint.

What AI actually changes about an attack

AI doesn't just make attacks bigger. It makes them fast enough to outrun a defense built around a human being, which is exactly the pattern behind the OpenAI-Hugging Face incident.  The line worth keeping is where Amodei says it's "incumbent on every frontier AI company to act as if OAI-HF had happened to them." Every company running security operations should genuinely picture that scenario happening to them.

Amodei uses it to argue for slowing down. I suggest a different conclusion. Picturing a swarm finding a way through your defenses in the time it takes your analyst to step away isn't a case for pausing. It's the most urgent case there is for building the readiness to survive that scenario. From there, there are really only two paths. Build the guardrails and train your people now, or wait, call it "slowing down," and find out that you have nothing in place at all. Choosing the second path isn't avoiding risk. It's choosing to be supervised by events instead of ready for them.

Why the response has to be AI-led too

To cope with AI-led attacks, you need an AI-led response matched in speed and not just sophistication. That's not a distant goal: AI-speed defense already exists. However, the real bottlenecks to wide adoption are increasingly trust, deployment speed, integration, and operating models. More companies must adopt these automated defenses before the security shortfall Amodei warns of becomes our permanent reality.

Frontier labs facing real verification, confirming adherence to safety measures, reporting incidents, and assessing a model's alignment as it's trained, is the right instinct. Defenders should hold their own AI to the same standard. The agents running in a SOC need to be verifiable, auditable, and accountable for what they touch. Not paced into irrelevance, but built with the same rigor Amodei is asking of the labs, and aimed at the systems that actually stand between a company and an attacker.

Close the Gap

We already know the gap between offensive and defensive capabilities is widening. The answer is to shape the development and diffusion of AI security capabilities so protective capability matures and reaches defenders before offensive capability can overwhelm them. Instead of pacing or slowing the development of those capabilities, we should be curbing the risk associated with them.

Photo credit: Dan Lahav, Irregular (August, 2026)

Curbing the risk isn't the same as refusing to build

Consider digital banking. As banking moved online, digital fraud grew with it. Banks didn’t respond by slowing down digital banking. They built defenses that could operate at the same speed: scoring transactions in milliseconds, automatically stopping suspicious activity, and escalating uncertain cases to humans. 

Innovation creates new risks. The answer is not to slow the innovation. It’s to build controls that can move as fast as the threat.

Security is at that same fork. The tools to defend at machine speed already exist. What's missing is how many companies have put the process around them. Curbing the risk of AI-led attacks was never about slowing AI down. It's about applying controlled learning to how agents operate, so what they produce is defense, not damage. As developers of agentic cyber defense systems we followed that same principle here at Mate, when we developed Gamebooks, investigation procedures designed for agents to move fast without moving outside the lines the organization sets.

Safety for AI developers and readiness for AI-powered cyberattacks must advance together. A company that delays its defensive transformation will not make the threat disappear. It will simply arrive less prepared.

Get a Demo