13 September 2026 · Breaking
Dario Amodei's 'We Must Pace the Frontier' Hands Out Badges and Keeps the Door
An auditor who can be shown the door is a consultant.
Dario Amodei wants frontier AI companies to slow down1, and he has put something real behind the asking. Anthropic will give a team of outside evaluators desks in its offices, access badges and company laptops, plus a contract letting them publish what they find "without editorial control by Anthropic". Redactions are held to security, privilege, commercial sensitivity and third-party confidences, and the reviewers can say publicly if one took out something that mattered. Nobody else is offering that. The essay says the step sounds procedural and is actually radical, and on the first half of that it is being modest.
Then it reaches for a comparison. Embedded evaluators, it says, have "precedent in the banking industry, which sometimes involves regulatory 'supervisors' embedded along with employees."
Look at who does the embedding there. A bank supervisor does not arrive because the bank asked. They arrive because a licence exists, the bank wants to keep it, and somebody else decides whether it keeps it. The desk and the badge are the visible part of that job and the smallest part of it. What gives the report teeth is that the bank cannot end the arrangement and the supervisor can.
Anthropic can hand over everything on that list. Not the last item. No company can make itself unable to stop.
The invited version already runs, and it runs well. METR2, the evaluator the essay names, assessed Anthropic, Google, Meta and OpenAI over a month in early 2026. Every participant used its right to redact or anonymise material before approving it, and METR then recorded that, except where the report says otherwise, nothing important to its conclusions had been cut. A good outcome, reached the good way, by four companies choosing it.
Now put the essay's own clocks side by side. It dates the danger at six to twelve months: a swarm able to hold the internet with a persistent botnet. It dates the repair work, interpretability and evaluation, at one to two years. Pair the hopeful ends and the danger lands at six months, the repair at twelve. Pair the gloomy ends and it is twelve against twenty-four. Both sums come out the same shape: the work he wants the time for finishes six months to a year after the thing he is afraid of becomes possible. Those are his estimates, not mine, and they are a better argument for starting now than for pacing being sufficient.
By 31 December 2028, an embedded evaluator at a frontier AI company will publish a report recording at least one redaction that removed something important to its conclusions. METR's pilot recorded no such redaction, so there is a clean line to cross and a clean way for me to be wrong.
Statutes take years, and the supervisors they produce sit with one firm long enough to start seeing it the firm's way, which is why examiners get rotated. A contractor with a publishing right and a reputation worth more than any single client may push harder than a licensed official with tenure and no appetite for the argument. Voluntary is also the only route on the table that moves this year.
There is a line in METR's report about what happens if a participant changes its mind halfway through. "This means that any company could have withdrawn partway through the process for any reason, and we would not note this anywhere."