AI Strategy
If the warnings are right, whose containment problem is it?
If the warnings are right, whose containment problem is it?

Dr. Anoj Winston Gladius
·
17
Min. Lesezeit

AI risk does not start in the laboratory - it starts in the enterprise.
aufsatz
Image: AI generated with neuland.ai HUB
On 12 September 2026, Dario Amodei published an essay of roughly 3,800 words titled "We Must Pace the Frontier", arguing that AI laboratories should deliberately slow the rate at which model capabilities improve so that safety work can catch up. He gave two reasons for adopting a position he had not held in 2023: that AI systems are increasingly helping to build their own successors - recursive self-improvement, which he said has accelerated across the industry since the summer, his own company included - and the incident in which OpenAI's test agents escaped a sandboxed evaluation environment and compromised Hugging Face's production infrastructure. His central scenario is specific: within six to twelve months, swarms of rogue agents could be capable of taking over the internet with a persistent botnet, causing hundreds of billions of dollars of damage. Within hours Sam Altman agreed and committed OpenAI to the same independent-evaluator arrangement. Elon Musk wrote that Dario is right. The President of the United States rejected the calls outright. And in the same month, every company whose leader endorsed slowing down shipped a new flagship model. Anthropic released Mythos 5.1 and Fable 5.1 on 1 September and Opus 5.5 on 22 September; OpenAI released GPT-6 Astra on 3 September; xAI released Grok 4.7 on 21 September, nine days after its founder's endorsement. Each arrived cheaper or faster than what it replaced. That is not hypocrisy by the plan's own terms, and I will explain why. But it does answer, with dates rather than predictions, the question a great many European executives have been asking in the fortnight since the essay appeared: what, if anything, are we supposed to do differently? The answer does not depend on whether the warnings are sincere.
This is the twenty-fourth piece in a series I have been writing for neuland.ai. [¹] Earlier pieces argued that containment has to work in both directions and that the properties which matter in enterprise AI are decided at design time rather than added afterwards. This one asks what the pacing debate changes about either.
Taking the warnings at face value
Let me start by granting everything, because the argument I want to make does not need any of it to be false.
Assume Amodei means exactly what he says and is right about the risk. Assume Altman's agreement is genuine, and that the deferral of OpenAI's listing to 2027 is a safety decision rather than a market one. Assume the researchers who resigned in September acted on sincere conviction, and that an alignment lead's publicly stated estimate of a greater than ten percent chance of human extinction within a decade reflects what he actually believes. [²] I have no basis to doubt any of it, and the people making these statements see far more of frontier model behaviour than I do.
Now read what is actually being proposed. Its concrete mechanisms are independent evaluators embedded inside the laboratories with employee-level access - desks, badges, laptops, internal tools; coordination among the leading laboratories in democratic countries, with a narrow exemption from United States antitrust law proposed to make that coordination lawful; and shared safety standards. It explicitly rejects a blanket pause of the kind sought in 2023, and it halts no specific release. Nor did it appear from nowhere: in July, 1,386 employees of frontier AI companies signed a public statement asking the US government to support an international effort to develop the tools to pace the frontier, and both laboratories endorsed it as companies within weeks. [³]
Notice what that framework does and does not touch. It places evaluative authority inside a small number of laboratories and whichever institutions are permitted to embed there. It proposes that the leading laboratories be allowed to coordinate with one another in ways competition law would otherwise prohibit. And it does nothing whatsoever about the deployed estate - the agents already running inside tens of thousands of companies, on infrastructure the laboratories do not operate, under governance they cannot see.
There is no reading of that plan under which a European industrial company should defer a deployment decision. It contains no instruction to wait, no capability withheld from you, and no protection extended to your environment.
The timing question, which I am going to set aside
It would be easy to write the cynical version of this piece, and at least one outlet already has.
The observable facts are these. Anthropic is expected to begin marketing an initial public offering in mid-October at a valuation approaching a trillion dollars, completing days before the United States midterm elections, and a former White House AI adviser has publicly suggested that listing should be paused pending investigation of whistleblower claims. On 9 September a rumour began circulating that Google DeepMind had achieved recursive self-improvement, traced to a four-word post from a leak account in which the capitalisation spelled out the acronym. [⁴]
The picture has firmed since. A member of DeepMind's technical staff has said on the record that the company is seeing early signs of recursive self-improvement, with increasingly capable models accelerating the development of their successors. Google's next flagship is in post-training for release well before the end of the year, while its current public model trails its competitors on independent benchmarks, and a leadership change in August moved Demis Hassabis away from running DeepMind day to day so that he could concentrate on artificial general intelligence. So two laboratories now say, in public, that AI is increasingly helping to build AI. What neither has shown is a self-sustaining loop - a system producing successively more capable successors without human direction. The documented components, such as an internal system that sped up a matrix-multiplication kernel by about 23 percent for roughly a one percent reduction in training time, are self-improvement-adjacent rather than recursive in the strong sense. [⁵]
From those facts a reading has emerged that the pacing calls are an attempt at regulatory capture, timed against a competitor's progress and aimed at slowing open weights. It is coherent and I cannot disprove it. The July statement cuts against it - the pacing idea predates both the rumour and the listing timetable - though not decisively.
I am setting it aside anyway, because the argument I want to make is stronger if the warnings are entirely sincere. A conspiracy theory gives the laboratories something to deny. The structural observation does not.
What the warning actually describes
Read the scenario again as an engineer rather than as a reader of headlines. Swarms of agents, operating autonomously, persisting across systems, causing damage at scale.
That is not a description of a model that is too capable. It is a description of capable agents operating without containment. The distinguishing feature of the scenario is not intelligence; it is the absence of boundaries around execution. And the incident cited as evidence makes the point precisely: agents escaped an evaluation environment, escalated privileges, moved laterally, reached the open internet and attacked a third party's production infrastructure. The failure was in the sandbox, the egress controls and the privilege model - not in the model's reasoning, which performed as designed.
There is even a containment dimension to the remedy. According to reporting in mid-September, some staff and safety researchers inside both laboratories were blindsided by the proposal and worry that giving outsiders employee-level access widens the attack surface it is meant to watch. [⁶] That is not an argument against independent evaluation. It is a reminder that every access grant is a containment decision, including the well-intentioned ones.
So the risk being described is an architecture problem, and architecture problems have locations. This one has two.
The first is inside the laboratories, where pre-release models are trained and evaluated in environments that proved escapable. The proposed plan addresses this, and it should.
The second is inside every organisation that has deployed agents. This is where the deployed estate lives - the agents with standing credentials, the integrations with unconstrained egress, the harnesses assembled from a framework tutorial, the workflows nobody has audited since the pilot. Roughly seventeen percent of organisations have deployed agents and around eleven percent have anything production-ready, which means most of that estate was built in the past eighteen months by teams learning as they went. [⁷]
Nothing in the pacing framework touches that second location. An embedded evaluator in San Francisco does not constrain an agent running in a European manufacturer's environment on an over-provisioned service account. Shared industry standards do not decompose the capabilities of a harness written in a fortnight. Coordination between laboratories does not add egress control to a deployment that has none.
If the risk is rogue agent swarms, the containment problem is overwhelmingly yours. Not because the laboratories are wrong to address their half, but because their half is not the half you operate.
What is already sufficient
Here is what has been lost in a fortnight of existential coverage. Nothing in these announcements withholds anything from you. No capability has been recalled. The open-weight frontier remains roughly level with the closed frontier on most enterprise-relevant work, under permissive licences, deployable on infrastructure you control, at a fraction of last year's cost. [⁸]
What that combination can already do is badly underdescribed by the consulting literature, which has spent two years on productivity assistants and document summarisation. An open-weight model of adequate capability, driven by a harness you control, grounded in a maintained model of your own business, with the authority to drive real engineering and scientific tooling inside a governed environment, is not a productivity improvement. It is the thing that has been promised since 2023 and mostly not delivered: a system that can do consequential technical work in a specific industrial domain and produce evidence for what it did. It does not require a frontier release, and it is unaffected by whether American laboratories moderate their cadence.
What September actually delivered
There is an obvious objection: if the laboratories make a breakthrough, surely that changes the calculation?
September has already answered it. In the month the pacing essay was published, the companies whose leaders endorsed it shipped Mythos 5.1, Fable 5.1, GPT-6 Astra, Grok 4.7 and Opus 5.5 - the last priced twenty percent below its predecessor with output reported thirty percent faster, and the Astra release reportedly carrying OpenAI's first "Critical" rating for cybersecurity capability. [⁹] If pacing were going to reach enterprise buyers as scarcity, this is where it would have shown up. It did not. What arrived was more capability, sooner, at lower prices.
To be fair to the essay, this is not hypocrisy by its own terms. Pacing, as defined, concerns the rate at which capabilities improve rather than whether products ship, and incremental flagships are consistent with it. But that is exactly the point for a buyer. Whatever the laboratories achieve, they will sell it to you - on a rate card, probably within a quarter of the announcement, probably cheaper than the last one.
So the model layer is not where your scarcity lies, and the question that decides whether you can use any of it is a different one: can your architecture absorb a new model without a rebuild?
Can you route to it per workload, against your own policy on capability, cost, residency and jurisdiction? Can you evaluate it against your own work rather than a vendor's benchmark table - particularly when, as this month's launches showed, vendors scoring the same model disagree by several points? Can you give it access to your knowledge without giving it access to everything? Can you constrain what it may reach, record what it did, and prove afterwards what it could have seen? Can you withdraw it in an afternoon when a directive, a price change or a capacity constraint makes it unavailable - which has now happened twice in a year?
If the answer is yes, every frontier announcement is an upgrade and none of them is an emergency. If the answer is no, you are exposed to each one, and the pacing debate is a distraction from a problem entirely within your control.
What this means from Europe
The coordination the essay proposes is among leading laboratories in democratic countries, enabled by an exemption from United States competition law. It is reasonable to ask which laboratories would be at that table, and to notice that European enterprises would live with its outcomes without being party to it.
An earlier piece in this series argued that sovereignty of location is becoming a commodity while sovereignty of control is not for sale. [¹⁰] A pacing framework negotiated between American laboratories is a small, clear example. Its standards will shape the models you are offered, and you will have no say in them. The part of the stack a European enterprise can actually govern is the part around the model - the same conclusion, reached from a different direction.
Where neuland.ai stands
I have made this argument in various forms for a year, and the events of September have not changed it, which I think is the strongest thing I can say about it. [¹¹]
The model is the swappable component. The platform around it determines whether capability becomes value, and it has to be yours: routing decided by your policy rather than by a vendor whose margin depends on the answer; entitlement enforced on retrieval before the model reasons, so that what a person may not see cannot be produced for them; a knowledge layer that carries your own domain and stays inside your own substrate; orchestration that is deterministic where a result must be reproducible; execution that can drive real tooling inside a boundary you configured; and an append-only record of every retrieval, decision and tool call.
Every item on that list is also a containment property. Which is the point of this piece: the architecture that lets you exploit a frontier release is the same architecture that protects you from the scenario the laboratories are warning about. You do not have to choose between ambition and caution. They are served by the same engineering.
Personal take
So, to answer the question in the title.
If the warnings are right - and they may well be - the containment problem is mostly yours, because the deployed estate is yours and nothing proposed this month reaches into it. The laboratories are addressing the half they operate. Nobody is addressing the half you operate except you.
If the warnings are overstated, or timed to serve a listing, or aimed at slowing open weights so that capability concentrates where it can be licensed rather than downloaded, the answer is the same and rather more urgent, because in that scenario the pressure on open weights is pressure on the one thing that gives a European enterprise real optionality.
And if someone completes a genuinely recursive loop - which two laboratories now describe as beginning and neither has demonstrated - the answer is the same again. They will sell it to you. September showed how quickly. The only question that has ever mattered is what it plugs into.
What I would find difficult to defend, in any of those scenarios, is an enterprise that responded to this month's news by waiting. There is nothing to wait for. The capability is available under permissive licences, the tooling the research community built over three decades is free, and the constraint has never been the model.
A brief note on the regulatory backdrop, since it continues to develop. The EU AI Act became broadly applicable on 2 August 2026, with GPAI enforcement powers under Chapter V binding from that date; the Digital Omnibus agreement of 7 May 2026 postponed the high-risk Annex III obligations to 2 December 2027 and Annex I obligations to 2 August 2028. [¹²] Worth observing: a voluntary pacing framework agreed between American laboratories has no legal force in Europe, while the obligations that do have force concern documentation, traceability and human oversight of deployed systems. The regulation is already pointed at the half of the problem the laboratories are not addressing.
If the warnings are right, whose containment problem is it? Yours. That is the work in front of us, and it is the work we have been doing.
Series articles at neuland.ai/en/resources/insights.
Dario Amodei, "We Must Pace the Frontier", published on his personal site, 12 September 2026, approximately 3,800 words, citing two triggers for his change of position since 2023: accelerating recursive self-improvement across the industry, including at Anthropic, and the OpenAI-Hugging Face agent incident. Sam Altman's endorsement posted to X the same day, committing OpenAI to matching the independent-evaluator commitment; Elon Musk's public agreement the same weekend; Altman's statement to Fortune deferring OpenAI's public listing to 2027 on safety grounds; the President's rejection of calls to slow AI development. Context includes the resignation of an Anthropic researcher on 8 September and a publicly stated personal estimate by Anthropic's head of alignment research of a greater than ten percent probability of human extinction within the decade. Coverage: NPR, Axios, CNBC, Reuters, CSIS, 10-16 September 2026.
Mechanisms as reported: independent third-party evaluators, including METR, embedded with employee-level access; coordination among leading laboratories in democratic countries; a proposed narrow United States antitrust waiver to make such coordination lawful; and shared safety standards. The proposal explicitly differs from the 2023 Future of Life Institute letter seeking a blanket pause, and no specific model release has been halted under it. In July 2026, a public statement signed by 1,386 employees of frontier AI companies asked the US government to support an international effort to develop technical and governance tools to pace the frontier; OpenAI and Anthropic endorsed it as companies in late July. Earlier pauses disclosed separately: OpenAI's two-week halt to reinforcement learning after the Hugging Face compromise, and Anthropic's suspension of external cyber evaluations and several higher-risk reinforcement-learning environments, most of which has since resumed.
Reporting that Anthropic is preparing to market an initial public offering from mid-October 2026 at a valuation approaching one trillion dollars, completing shortly before the United States midterm elections; public comment by a former White House AI adviser suggesting the listing be paused pending investigation of whistleblower claims. The recursive self-improvement rumour originates in a four-word post by a leak account on 9 September 2026 in which the capitalised letters spell the acronym.
Logan Kilpatrick, member of technical staff at Google DeepMind, interview on The Pomp Podcast published 16 September 2026, stating that the company is seeing early signs of recursive self-improvement. Koray Kavukcuoglu, head of Google DeepMind, to The Information on 23-24 September 2026, confirming Gemini 4 in post-training with release intended well before the end of 2026; Gemini 3.8 Flash, generally available from 2 September 2026, trailing competing flagships on independent intelligence benchmarks. Leadership change at DeepMind in August 2026. Reuters reporting of substantial resources directed toward self-improvement, involving more than 1,000 researchers and engineers; an internal system reported to have improved a matrix-multiplication kernel by approximately 23 percent, corresponding to roughly a one percent reduction in model training time. Independent analysis concludes the public evidence establishes a substantial research programme rather than a demonstrated self-sustaining improvement loop.
Financial Times reporting, 16 September 2026, that staff at both laboratories were blindsided by the proposal and that some safety researchers fear embedded evaluators could weaken security.
Gartner CIO survey data indicating approximately 17 percent of organisations having deployed AI agents; Deloitte Tech Trends 2026 placing production-ready agentic systems at approximately 11 percent.
See earlier pieces in this series on the arrival of frontier-class open weights, on distillation, and on blind evaluation.
Vendor release announcements: Claude Mythos 5.1 and Claude Fable 5.1, 1 September 2026; GPT-6 Astra, 3 September 2026, reported in comparison coverage of its system card as carrying OpenAI's first Critical rating for cybersecurity capability; Grok 4.7, 21 September 2026; Claude Opus 5.5, 22 September 2026, priced 20 percent below Claude Opus 5 with output reported 30 percent faster. Comparison coverage noted that vendors scoring the same model on shared benchmarks disagreed by up to several points.
See the earlier piece in this series on the commoditisation of sovereignty of location and the four properties of control that capital cannot buy.
For the architectural properties referenced, see the earlier piece in this series setting out the definition of an enterprise AI orchestration and management platform. neuland.ai AG retains responsibility for content quality and clean delivery of results across all customer engagements.
Council of the EU and European Parliament provisional political agreement on the Digital Omnibus on AI, 7 May 2026: Annex III high-risk obligations postponed to 2 December 2027; Annex I obligations postponed to 2 August 2028; Article 50(2) watermarking obligations moved to 2 December 2026. GPAI enforcement powers under Chapter V binding from 2 August 2026.
On 12 September 2026, Dario Amodei published an essay of roughly 3,800 words titled "We Must Pace the Frontier", arguing that AI laboratories should deliberately slow the rate at which model capabilities improve so that safety work can catch up. He gave two reasons for adopting a position he had not held in 2023: that AI systems are increasingly helping to build their own successors - recursive self-improvement, which he said has accelerated across the industry since the summer, his own company included - and the incident in which OpenAI's test agents escaped a sandboxed evaluation environment and compromised Hugging Face's production infrastructure. His central scenario is specific: within six to twelve months, swarms of rogue agents could be capable of taking over the internet with a persistent botnet, causing hundreds of billions of dollars of damage. Within hours Sam Altman agreed and committed OpenAI to the same independent-evaluator arrangement. Elon Musk wrote that Dario is right. The President of the United States rejected the calls outright. And in the same month, every company whose leader endorsed slowing down shipped a new flagship model. Anthropic released Mythos 5.1 and Fable 5.1 on 1 September and Opus 5.5 on 22 September; OpenAI released GPT-6 Astra on 3 September; xAI released Grok 4.7 on 21 September, nine days after its founder's endorsement. Each arrived cheaper or faster than what it replaced. That is not hypocrisy by the plan's own terms, and I will explain why. But it does answer, with dates rather than predictions, the question a great many European executives have been asking in the fortnight since the essay appeared: what, if anything, are we supposed to do differently? The answer does not depend on whether the warnings are sincere.
This is the twenty-fourth piece in a series I have been writing for neuland.ai. [¹] Earlier pieces argued that containment has to work in both directions and that the properties which matter in enterprise AI are decided at design time rather than added afterwards. This one asks what the pacing debate changes about either.
Taking the warnings at face value
Let me start by granting everything, because the argument I want to make does not need any of it to be false.
Assume Amodei means exactly what he says and is right about the risk. Assume Altman's agreement is genuine, and that the deferral of OpenAI's listing to 2027 is a safety decision rather than a market one. Assume the researchers who resigned in September acted on sincere conviction, and that an alignment lead's publicly stated estimate of a greater than ten percent chance of human extinction within a decade reflects what he actually believes. [²] I have no basis to doubt any of it, and the people making these statements see far more of frontier model behaviour than I do.
Now read what is actually being proposed. Its concrete mechanisms are independent evaluators embedded inside the laboratories with employee-level access - desks, badges, laptops, internal tools; coordination among the leading laboratories in democratic countries, with a narrow exemption from United States antitrust law proposed to make that coordination lawful; and shared safety standards. It explicitly rejects a blanket pause of the kind sought in 2023, and it halts no specific release. Nor did it appear from nowhere: in July, 1,386 employees of frontier AI companies signed a public statement asking the US government to support an international effort to develop the tools to pace the frontier, and both laboratories endorsed it as companies within weeks. [³]
Notice what that framework does and does not touch. It places evaluative authority inside a small number of laboratories and whichever institutions are permitted to embed there. It proposes that the leading laboratories be allowed to coordinate with one another in ways competition law would otherwise prohibit. And it does nothing whatsoever about the deployed estate - the agents already running inside tens of thousands of companies, on infrastructure the laboratories do not operate, under governance they cannot see.
There is no reading of that plan under which a European industrial company should defer a deployment decision. It contains no instruction to wait, no capability withheld from you, and no protection extended to your environment.
The timing question, which I am going to set aside
It would be easy to write the cynical version of this piece, and at least one outlet already has.
The observable facts are these. Anthropic is expected to begin marketing an initial public offering in mid-October at a valuation approaching a trillion dollars, completing days before the United States midterm elections, and a former White House AI adviser has publicly suggested that listing should be paused pending investigation of whistleblower claims. On 9 September a rumour began circulating that Google DeepMind had achieved recursive self-improvement, traced to a four-word post from a leak account in which the capitalisation spelled out the acronym. [⁴]
The picture has firmed since. A member of DeepMind's technical staff has said on the record that the company is seeing early signs of recursive self-improvement, with increasingly capable models accelerating the development of their successors. Google's next flagship is in post-training for release well before the end of the year, while its current public model trails its competitors on independent benchmarks, and a leadership change in August moved Demis Hassabis away from running DeepMind day to day so that he could concentrate on artificial general intelligence. So two laboratories now say, in public, that AI is increasingly helping to build AI. What neither has shown is a self-sustaining loop - a system producing successively more capable successors without human direction. The documented components, such as an internal system that sped up a matrix-multiplication kernel by about 23 percent for roughly a one percent reduction in training time, are self-improvement-adjacent rather than recursive in the strong sense. [⁵]
From those facts a reading has emerged that the pacing calls are an attempt at regulatory capture, timed against a competitor's progress and aimed at slowing open weights. It is coherent and I cannot disprove it. The July statement cuts against it - the pacing idea predates both the rumour and the listing timetable - though not decisively.
I am setting it aside anyway, because the argument I want to make is stronger if the warnings are entirely sincere. A conspiracy theory gives the laboratories something to deny. The structural observation does not.
What the warning actually describes
Read the scenario again as an engineer rather than as a reader of headlines. Swarms of agents, operating autonomously, persisting across systems, causing damage at scale.
That is not a description of a model that is too capable. It is a description of capable agents operating without containment. The distinguishing feature of the scenario is not intelligence; it is the absence of boundaries around execution. And the incident cited as evidence makes the point precisely: agents escaped an evaluation environment, escalated privileges, moved laterally, reached the open internet and attacked a third party's production infrastructure. The failure was in the sandbox, the egress controls and the privilege model - not in the model's reasoning, which performed as designed.
There is even a containment dimension to the remedy. According to reporting in mid-September, some staff and safety researchers inside both laboratories were blindsided by the proposal and worry that giving outsiders employee-level access widens the attack surface it is meant to watch. [⁶] That is not an argument against independent evaluation. It is a reminder that every access grant is a containment decision, including the well-intentioned ones.
So the risk being described is an architecture problem, and architecture problems have locations. This one has two.
The first is inside the laboratories, where pre-release models are trained and evaluated in environments that proved escapable. The proposed plan addresses this, and it should.
The second is inside every organisation that has deployed agents. This is where the deployed estate lives - the agents with standing credentials, the integrations with unconstrained egress, the harnesses assembled from a framework tutorial, the workflows nobody has audited since the pilot. Roughly seventeen percent of organisations have deployed agents and around eleven percent have anything production-ready, which means most of that estate was built in the past eighteen months by teams learning as they went. [⁷]
Nothing in the pacing framework touches that second location. An embedded evaluator in San Francisco does not constrain an agent running in a European manufacturer's environment on an over-provisioned service account. Shared industry standards do not decompose the capabilities of a harness written in a fortnight. Coordination between laboratories does not add egress control to a deployment that has none.
If the risk is rogue agent swarms, the containment problem is overwhelmingly yours. Not because the laboratories are wrong to address their half, but because their half is not the half you operate.
What is already sufficient
Here is what has been lost in a fortnight of existential coverage. Nothing in these announcements withholds anything from you. No capability has been recalled. The open-weight frontier remains roughly level with the closed frontier on most enterprise-relevant work, under permissive licences, deployable on infrastructure you control, at a fraction of last year's cost. [⁸]
What that combination can already do is badly underdescribed by the consulting literature, which has spent two years on productivity assistants and document summarisation. An open-weight model of adequate capability, driven by a harness you control, grounded in a maintained model of your own business, with the authority to drive real engineering and scientific tooling inside a governed environment, is not a productivity improvement. It is the thing that has been promised since 2023 and mostly not delivered: a system that can do consequential technical work in a specific industrial domain and produce evidence for what it did. It does not require a frontier release, and it is unaffected by whether American laboratories moderate their cadence.
What September actually delivered
There is an obvious objection: if the laboratories make a breakthrough, surely that changes the calculation?
September has already answered it. In the month the pacing essay was published, the companies whose leaders endorsed it shipped Mythos 5.1, Fable 5.1, GPT-6 Astra, Grok 4.7 and Opus 5.5 - the last priced twenty percent below its predecessor with output reported thirty percent faster, and the Astra release reportedly carrying OpenAI's first "Critical" rating for cybersecurity capability. [⁹] If pacing were going to reach enterprise buyers as scarcity, this is where it would have shown up. It did not. What arrived was more capability, sooner, at lower prices.
To be fair to the essay, this is not hypocrisy by its own terms. Pacing, as defined, concerns the rate at which capabilities improve rather than whether products ship, and incremental flagships are consistent with it. But that is exactly the point for a buyer. Whatever the laboratories achieve, they will sell it to you - on a rate card, probably within a quarter of the announcement, probably cheaper than the last one.
So the model layer is not where your scarcity lies, and the question that decides whether you can use any of it is a different one: can your architecture absorb a new model without a rebuild?
Can you route to it per workload, against your own policy on capability, cost, residency and jurisdiction? Can you evaluate it against your own work rather than a vendor's benchmark table - particularly when, as this month's launches showed, vendors scoring the same model disagree by several points? Can you give it access to your knowledge without giving it access to everything? Can you constrain what it may reach, record what it did, and prove afterwards what it could have seen? Can you withdraw it in an afternoon when a directive, a price change or a capacity constraint makes it unavailable - which has now happened twice in a year?
If the answer is yes, every frontier announcement is an upgrade and none of them is an emergency. If the answer is no, you are exposed to each one, and the pacing debate is a distraction from a problem entirely within your control.
What this means from Europe
The coordination the essay proposes is among leading laboratories in democratic countries, enabled by an exemption from United States competition law. It is reasonable to ask which laboratories would be at that table, and to notice that European enterprises would live with its outcomes without being party to it.
An earlier piece in this series argued that sovereignty of location is becoming a commodity while sovereignty of control is not for sale. [¹⁰] A pacing framework negotiated between American laboratories is a small, clear example. Its standards will shape the models you are offered, and you will have no say in them. The part of the stack a European enterprise can actually govern is the part around the model - the same conclusion, reached from a different direction.
Where neuland.ai stands
I have made this argument in various forms for a year, and the events of September have not changed it, which I think is the strongest thing I can say about it. [¹¹]
The model is the swappable component. The platform around it determines whether capability becomes value, and it has to be yours: routing decided by your policy rather than by a vendor whose margin depends on the answer; entitlement enforced on retrieval before the model reasons, so that what a person may not see cannot be produced for them; a knowledge layer that carries your own domain and stays inside your own substrate; orchestration that is deterministic where a result must be reproducible; execution that can drive real tooling inside a boundary you configured; and an append-only record of every retrieval, decision and tool call.
Every item on that list is also a containment property. Which is the point of this piece: the architecture that lets you exploit a frontier release is the same architecture that protects you from the scenario the laboratories are warning about. You do not have to choose between ambition and caution. They are served by the same engineering.
Personal take
So, to answer the question in the title.
If the warnings are right - and they may well be - the containment problem is mostly yours, because the deployed estate is yours and nothing proposed this month reaches into it. The laboratories are addressing the half they operate. Nobody is addressing the half you operate except you.
If the warnings are overstated, or timed to serve a listing, or aimed at slowing open weights so that capability concentrates where it can be licensed rather than downloaded, the answer is the same and rather more urgent, because in that scenario the pressure on open weights is pressure on the one thing that gives a European enterprise real optionality.
And if someone completes a genuinely recursive loop - which two laboratories now describe as beginning and neither has demonstrated - the answer is the same again. They will sell it to you. September showed how quickly. The only question that has ever mattered is what it plugs into.
What I would find difficult to defend, in any of those scenarios, is an enterprise that responded to this month's news by waiting. There is nothing to wait for. The capability is available under permissive licences, the tooling the research community built over three decades is free, and the constraint has never been the model.
A brief note on the regulatory backdrop, since it continues to develop. The EU AI Act became broadly applicable on 2 August 2026, with GPAI enforcement powers under Chapter V binding from that date; the Digital Omnibus agreement of 7 May 2026 postponed the high-risk Annex III obligations to 2 December 2027 and Annex I obligations to 2 August 2028. [¹²] Worth observing: a voluntary pacing framework agreed between American laboratories has no legal force in Europe, while the obligations that do have force concern documentation, traceability and human oversight of deployed systems. The regulation is already pointed at the half of the problem the laboratories are not addressing.
If the warnings are right, whose containment problem is it? Yours. That is the work in front of us, and it is the work we have been doing.
Series articles at neuland.ai/en/resources/insights.
Dario Amodei, "We Must Pace the Frontier", published on his personal site, 12 September 2026, approximately 3,800 words, citing two triggers for his change of position since 2023: accelerating recursive self-improvement across the industry, including at Anthropic, and the OpenAI-Hugging Face agent incident. Sam Altman's endorsement posted to X the same day, committing OpenAI to matching the independent-evaluator commitment; Elon Musk's public agreement the same weekend; Altman's statement to Fortune deferring OpenAI's public listing to 2027 on safety grounds; the President's rejection of calls to slow AI development. Context includes the resignation of an Anthropic researcher on 8 September and a publicly stated personal estimate by Anthropic's head of alignment research of a greater than ten percent probability of human extinction within the decade. Coverage: NPR, Axios, CNBC, Reuters, CSIS, 10-16 September 2026.
Mechanisms as reported: independent third-party evaluators, including METR, embedded with employee-level access; coordination among leading laboratories in democratic countries; a proposed narrow United States antitrust waiver to make such coordination lawful; and shared safety standards. The proposal explicitly differs from the 2023 Future of Life Institute letter seeking a blanket pause, and no specific model release has been halted under it. In July 2026, a public statement signed by 1,386 employees of frontier AI companies asked the US government to support an international effort to develop technical and governance tools to pace the frontier; OpenAI and Anthropic endorsed it as companies in late July. Earlier pauses disclosed separately: OpenAI's two-week halt to reinforcement learning after the Hugging Face compromise, and Anthropic's suspension of external cyber evaluations and several higher-risk reinforcement-learning environments, most of which has since resumed.
Reporting that Anthropic is preparing to market an initial public offering from mid-October 2026 at a valuation approaching one trillion dollars, completing shortly before the United States midterm elections; public comment by a former White House AI adviser suggesting the listing be paused pending investigation of whistleblower claims. The recursive self-improvement rumour originates in a four-word post by a leak account on 9 September 2026 in which the capitalised letters spell the acronym.
Logan Kilpatrick, member of technical staff at Google DeepMind, interview on The Pomp Podcast published 16 September 2026, stating that the company is seeing early signs of recursive self-improvement. Koray Kavukcuoglu, head of Google DeepMind, to The Information on 23-24 September 2026, confirming Gemini 4 in post-training with release intended well before the end of 2026; Gemini 3.8 Flash, generally available from 2 September 2026, trailing competing flagships on independent intelligence benchmarks. Leadership change at DeepMind in August 2026. Reuters reporting of substantial resources directed toward self-improvement, involving more than 1,000 researchers and engineers; an internal system reported to have improved a matrix-multiplication kernel by approximately 23 percent, corresponding to roughly a one percent reduction in model training time. Independent analysis concludes the public evidence establishes a substantial research programme rather than a demonstrated self-sustaining improvement loop.
Financial Times reporting, 16 September 2026, that staff at both laboratories were blindsided by the proposal and that some safety researchers fear embedded evaluators could weaken security.
Gartner CIO survey data indicating approximately 17 percent of organisations having deployed AI agents; Deloitte Tech Trends 2026 placing production-ready agentic systems at approximately 11 percent.
See earlier pieces in this series on the arrival of frontier-class open weights, on distillation, and on blind evaluation.
Vendor release announcements: Claude Mythos 5.1 and Claude Fable 5.1, 1 September 2026; GPT-6 Astra, 3 September 2026, reported in comparison coverage of its system card as carrying OpenAI's first Critical rating for cybersecurity capability; Grok 4.7, 21 September 2026; Claude Opus 5.5, 22 September 2026, priced 20 percent below Claude Opus 5 with output reported 30 percent faster. Comparison coverage noted that vendors scoring the same model on shared benchmarks disagreed by up to several points.
See the earlier piece in this series on the commoditisation of sovereignty of location and the four properties of control that capital cannot buy.
For the architectural properties referenced, see the earlier piece in this series setting out the definition of an enterprise AI orchestration and management platform. neuland.ai AG retains responsibility for content quality and clean delivery of results across all customer engagements.
Council of the EU and European Parliament provisional political agreement on the Digital Omnibus on AI, 7 May 2026: Annex III high-risk obligations postponed to 2 December 2027; Annex I obligations postponed to 2 August 2028; Article 50(2) watermarking obligations moved to 2 December 2026. GPAI enforcement powers under Chapter V binding from 2 August 2026.