
I took a weekend off. One weekend!!!
Before I could get pen to paper on the Jacob Coxon “whistleblower” story, Dario Amodei said, ‘Hold My Beer,’ and published We Must Pace the Frontier.
Let me lay out the week, because the sequencing is the story.
September 8. Jacob Coxon resigns from Anthropic. Three years of pretraining research across OpenAI and Anthropic, four months into an Anthropic tenure with a six-month vesting cliff, and he walks before a dollar of it lands. Both labs are “gambling with our lives.” Ninety million views in a day.
September 12. The CEO of the company he just left publishes a policy framework that agrees with him. Altman endorses it within hours. Musk, who is currently in litigation with Altman, endorses it within the hour.
September 13. Satya Nadella backs it too, with conditions, and announces Microsoft will publish a Code of Conduct for its MAI models the following day.
September 14. Coxon goes on Meet the Press and argues that Congress should let the frontier labs regulate themselves in the interim.
So the man who set fire to his own equity to warn us about the labs spent his national television debut recommending we let the labs handle it. Five days, one whistleblower, three CEOs and the richest man alive, all arriving at the identical conclusion: the people who already hold the frontier should decide how fast the frontier moves.
Quite a week for the people who already hold the frontier.
The plan, or: please regulate me, gently
It is a serious document, and I am not going to pretend otherwise. The load-bearing sentence has no hedge in it. Amodei writes that “we must slow the pace at which we improve the capabilities of AI models.”
Three steps:
- Embedded evaluators. Third-party reviewers like METR get desks, badges, laptops, and employee-grade permissions inside frontier labs. Anthropic commits unilaterally and calls on governments to make everyone else match.
- Democratic coordination. Labs in democratic countries agree on common safety standards and limits on the rate of unchecked progress.
- Global coordination. Try the same with China, graded across four levels from bioweapon prohibitions up to a full pause.
Step one is real and I will say so. Desks, badges, laptops, publication rights without editorial control. That is further than anyone else has gone. It is also the cheapest accountable-looking thing available: the auditors can publish, the auditors cannot stop anything, and the company being audited drafted the contract.
Step two is where the mask slips. Competitors agreeing to limit the rate of output is a cartel. The essay knows it, which is why it asks Washington to mediate or, at minimum, issue a narrow antitrust waiver so that safety conversations are legal. That request sits in a footnote. In any other industry, that footnote is an exhibit.
The pushback came in fast and mostly from the right places. Chamath Palihapitiya read it as a case for killing open source and parking the power with whoever wrote the terms. Brian Merchant called it regulatory capture in action. Emad Mostaque called it structurally hollow and followed with a piece titled “Intelligence isn’t a crime.” David Sacks has spent a year calling Anthropic’s regulatory posture a DMV for AI and saw no reason to update. Paul Graham’s replies are filled with the startup version: permanent embedded evaluator infrastructure is a fixed cost a well-capitalized incumbent absorbs and a two-person team eats.
Zvi Mowshowitz wrote the only line anyone needed, which is that there are two wolves inside Dario Amodei. Both wolves are real. You do not have to allege bad faith to run the capture argument. You only have to read the bill and check who pays it.
Then Satya wrote my brochure for me
Nadella’s reply is the input almost nobody read properly, and it is the one that matters most if you are the person signing the PO.
He opens by agreeing. AI not under human control and not helping humanity is not worth pursuing. Microsoft welcomes deliberate pacing. Microsoft welcomes embedded evaluators.
Then the conditions, which are a sovereignty manifesto with a Redmond letterhead:
- Governance of this cannot be controlled by a handful of entities. It needs countries, fields, and academia in the room.
- Benefits must be shared across countries, communities and companies, which requires a frontier ecosystem where closed and open source both thrive.
- Enterprises must retain full control over their unique and tacit knowledge.
- Every organization should build its own continuous learning loop without depending on any single model provider.
- That knowledge should live in models and weights under the organization’s own control.
I have been writing that list for a year. It took the CEO of Microsoft one post to say it louder than I ever will.
And he brought receipts, which I will credit because they are earned. The seven MAI models shipped in June go out across Foundry, OpenRouter, Fireworks, and Baseten, and for the first time developers can tune the weights themselves. Microsoft has put forth the most sovereignty-positive thing any hyperscaler has done this year. Jensen’s Nemotron has a similar posture but: 1) neither Microsoft’s nor Nvidia’s open models are comparable to the most capable open models available today; and 2) more importantly, neither get an automatic pass on sovereignty…If you are subject to the US Cloud Act, running on a hyperscale cloud and are outside of the USA – it’s a sovereignty exposure that you need to bake into your risk tolerance model.
It is also the only one of the three responses that costs the speaker nothing.
Three CEOs, three balance sheets, one very convenient consensus
Nobody here is lying. Everybody here is describing the world in which their own margin survives. Here’s what it means to the leaders welcoming pumping the brakes.
Anthropic sells frontier tokens. Its version of safety gates capability behind a certification regime that four companies can clear and nobody else can.
OpenAI sells frontier tokens. Altman matched the evaluator pledge in hours, which cost him nothing he was not already spending, and bought the moral high ground at a discount.
Microsoft sells the platform underneath everybody’s tokens. Its version of safety is diffusion, open and closed coexistence, and enterprise-controlled weights, because Azure bills you either way and bills you more when you are not welded to one model vendor.
Nadella reached the sovereignty argument because sovereignty sells Azure. That does not make it wrong. It makes it strong enough that the largest enterprise software company on the planet is now running my thesis as go-to-market, which is a better endorsement than anything I could write.
Now the asterisk. I wrote an entire issue of this post about ecosystem lock-up, and Microsoft was Exhibit A. “Without depending on any single model provider” is a beautiful sentence. Read it aloud to your Copilot renewal desk and see who laughs first. The right response to Nadella is not cynicism; it is a contract. Tunable weights, learning-loop portability, and a written exit path, in the MSA, not the blog post. He said it in public. Make him sign it.
The China argument everyone is getting wrong
The loudest criticism is that pacing hands China the race. The essay pre-empts that so thoroughly that most of the people shouting it clearly stopped at the headline. Amodei bounds pacing by the size of the US lead and pairs it with chip export controls, a crackdown on distillation and weight theft, and a stated goal of widening America’s lead over three to five years.
Dario did not ignore China. He described a race that already finished in the layer you actually buy.
Kimi K3 sits at the top of the open-weight field. DeepSeek V4, Qwen 3.8, GLM 5.3, and Hunyuan ship under MIT and Apache with million-token context windows at a fraction of closed frontier pricing. CAISI puts the gap between the leading US models and DeepSeek V4 Pro at roughly eight months. On routed token share, Chinese open-weight models went from low single digits to the majority of global consumption in eighteen months, with DeepSeek alone outranking every US lab.
Pacing constrains the closed American frontier. It cannot touch the open-weight layer, because there is no front desk at which to seat an evaluator in a distributed weights community. Amodei has since said Anthropic’s preferred implementation modulates the very best models while leaving the ones catching up alone, and frames that as a cost his own company absorbs. Fine. Take him at his word. The outcome is identical.
The premium tier gets slower and dearer. The commodity tier keeps compounding and stays downloadable.
That is not geopolitics. That is your Q1 procurement cycle.
The litmus test
Territorial. Pacing says nothing about geography, which is the point. It changes who decides which capability is available in your jurisdiction and when. Put frontier access behind evaluator-certified capability checkpoints, and that calendar gets set in Washington and San Francisco. Weights you hold on infrastructure you control do not care about the calendar. Nadella’s line about knowledge living in weights you own is the same observation, billed differently.
Operational. This is the pillar the essay quietly detonates. Embedded evaluators mean a third party you never contracted with, never vetted, and cannot indemnify now holds employee-grade permissions inside the company running your inference. Excellent transparency measure. Terminal operational sovereignty claim. If you have been telling your board you control the operations of a hosted frontier model, your vendor just seated a stranger at the next desk, and you found out from a blog post.
Technological. The checkpoint regime is the moat. Capability X requires certifications Y and Z, plus interpretability analyses, plus training environment audits. Anthropic can staff that. So can OpenAI, Google, and Microsoft. A national champion lab, a university consortium, a sovereign-fund-backed startup, a two-person team in Tel Aviv or Bangalore or Munich, cannot. That is how a safety regime becomes a price of admission without one person in the room intending it. Everybody stays sincere. The barrier stays load-bearing. The honest counterweight is Microsoft shipping tunable MAI weights across four channels, and I will keep saying so until they stop doing it.
Legal. The waiver is the tell, and Nadella named the disease without naming the cure: this cannot be controlled by a handful of entities. Strip the framing off Dario’s ask, and it is a US-government-blessed forum in which American companies coordinate the rate of capability release. Congratulations: if you are a European bank, a Gulf sovereign fund, an Israeli defense contractor, or a Japanese manufacturer, your 2027 roadmap is now an output of a conversation held in San Francisco, in English, between four companies you do not fund, under a waiver from a government you do not elect. Put it in the risk register under its real name.
Financial. My standing rule holds and gets sharper. A hosted frontier model anywhere in the request path is an automatic fail on Territorial and Financial. Pacing adds a line item most CFOs have never modeled: cadence risk. Not price volatility, which you can hedge. Schedule uncertainty on capability you have already sold into a roadmap, set by a process you cannot forecast, influence, or appeal. You cannot put a number on that in a three-year plan, which is a polite way of saying you do not have a three-year plan.
The executive view
No unit economics today. Three sentences.
The frontier premium is a payment for delta over the open weight baseline. Pacing compresses the delta and widens the variance on delivery. You are being asked to pay more for less certainty at the exact moment the open-weight baseline is eight months behind and closing.
So the strategy does not change; it just stops being optional. Baseline your costs on open weights you can run yourself. Burst to the frontier for the tokens that genuinely need frontier intelligence. Make that boundary an architectural decision instead of an accident of whichever API you integrated first.
Thank you, Dario
Every argument I have made in these posts for a year got made for me this week, from the other side of the table, by people with vastly more authority than I will ever have.
That the frontier is dangerous enough to need brakes. That the people building it cannot be trusted to mark their own homework, which is why invigilators are being invited in. That capability access should be gated. That the gating should be coordinated between a handful of American companies under a government waiver. And then, from Redmond, that none of this should be controlled by a handful of entities and that you should own your own weights.
Every one of those is reasonable from inside a frontier lab or a hyperscaler. Every one of them, read from the buyer’s chair, is a description of dependency you never agreed to.
Dario did not make the case that AI is dangerous. Plenty of people made that case. He made the case that your access to it is contingent on decisions taken by other people, in other jurisdictions, for reasons that have nothing to do with your business. Satya then obligingly published the remedy: own your learning loop, own your weights, do not depend on a single model provider.
That is the whole sovereignty thesis, delivered by the best messengers money cannot buy.
Own the core. Stay movable at the edges. Identity, audit logs, agent memory and context, evals, control plane: that layer is yours, and it survives whatever cadence the frontier settles into. The models are edges. Keep them interchangeable, and this week is interesting rather than existential.
If you cannot say today which of your systems fail closed when a frontier release slips two quarters, you do not have a sovereignty posture. You have a subscription.
Action Item: What to do on Monday
Start with the free diagnostic. It costs you an afternoon.
Take your three highest-value agentic workflows. Assume the frontier model behind each one ships its next capability two quarters late, under a certification regime you do not control, at a price set by four companies in a room you are not in. Write down what breaks, what degrades, and what simply stops. If you cannot finish that exercise before Friday, pacing already happened to you, and nobody sent the memo.
Then use the negotiating position Satya published for free. Take his five sentences into your next renewal and ask for them in writing:
- Weights you can tune and hold.
- A learning loop that runs without a single named provider.
- Tacit knowledge that stays yours on exit.
- A written exit path that does not depend on the vendor’s cooperation.
Four clauses. If your account team says yes, you have a partner. If they start explaining why it is more complicated than that, you have your answer, and it cost you one meeting.
That is the free version.
The paid version is a Sovereignty Assessment. We run your vendor estate through the five pillars, name the risks you are actually carrying, and tell you which to accept and which to price. No pass-or-fail theatre. Agency Labs builds the crown jewels layer, and you own it outright. Not licensed. Not hosted on our terms.
Contact info@agentcylabs.com to book a Sovereignty Assessment scoping call.
Amit
Sources
METR, OpenAI-Hugging Face incident investigation, Aug 26 2026. https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/
Dario Amodei, “We Must Pace the Frontier,” September 12 2026. https://darioamodei.com/post/we-must-pace-the-frontier
Satya Nadella on X, September 13 2026. https://x.com/satyanadella/status/2099220712024408084
Unite.AI, “Nadella Announces Public Consultation on Microsoft’s MAI Model Rules,” Sept 13 2026. https://www.unite.ai/nadella-announces-public-consultation-on-microsofts-mai-model-rules/
Microsoft AI, “Building a hill-climbing machine: launching seven new MAI models,” June 2 2026. https://microsoft.ai/news/building-a-hillclimbing-machine-launching-seven-new-mai-models/
Sam Altman on X, September 12 2026. https://x.com/sama/status/2098811563415150910
TIME, “He Helped Build Powerful AI at OpenAI and Anthropic. Now He’s Afraid It Could Kill Us,” Sept 9 2026. https://time.com/article/2026/09/09/ai-anthropic-openai-jacob-coxon/
Axios, “Anthropic whistleblower gave up his equity to leave the company,” Sept 9 2026. https://www.axios.com/2026/09/09/anthropic-researcher-ai-warning-interview
NBC News, “Anthropic whistleblower says Congress should let AI companies police themselves,” Sept 13 2026. https://www.nbcnews.com/tech/security/anthropic-whistleblower-congress-ai-companies-regulation-rcna597465
The Register, “Big AI sets out its terms for regulatory capture and calls it ‘Pace the frontier’,” Sept 14 2026. https://www.theregister.com/ai-and-ml/2026/09/14/big-ai-sets-out-its-terms-for-regulatory-capture-and-calls-it-pace-the-frontier/5296067
MarkTechPost, “Anthropic’s 3-Step ‘Pace the Frontier’ Plan Wins OpenAI, xAI and Microsoft Support,” Sept 13 2026. https://marktechpost.com/2026/09/13/anthropics-3-step-pace-the-frontier-plan-wins-openai-xai-and-microsoft-support-is-it-too-late-to-slow-ai-down
CSIS, “What to Know About Chinese AI Models.” https://www.csis.org/analysis/what-know-about-chinese-ai-models
Wing VC, “China’s Open-Weight Takeover.” https://www.wing.vc/content/chinas-open-weight-takeover

