MedDevice AI Security Weekly · Issue 14

A pause only binds the side that follows it

Read this issue on LinkedIn
Issue 14 banner

Dario Amodei published an essay on September 12 called "We Must Pace the Frontier." It argues the AI industry should slow the rate at which it improves model capabilities, and it lays out a three-part plan for how. The timing drew attention, because Anthropic is asking the whole field to slow down within weeks of an IPO that could value it near two trillion dollars.

I want to take the argument seriously, because on cybersecurity it points in a direction I do not think holds up.

What is actually being proposed

The coverage flattened the plan into "slow down," so start with what it says.

Step one is transparency. Anthropic will give third-party evaluators like METR permanent, employee-level access, meaning desks, badges, and company laptops, and the right to publish findings. It is committing to this unilaterally and asking the rest of the industry to match it.

Step two is coordination among democracies: voluntary pre-deployment safety standards, capability checkpoints, and limits on training inputs, which would need government help and antitrust waivers to work.

Step three is global coordination, ranked by difficulty. The easiest is a ban on AI for bioweapons. The hardest is a full development pause with verification that everyone is actually complying.

One detail is worth repeating. Amodei stopped short of committing Anthropic to slow its own model development. The unilateral commitment is the evaluator access, and it does not extend to Anthropic's own development speed. Sam Altman said he agrees the industry needs to pace the frontier, and OpenAI pushed its IPO to 2027. Over 1,300 employees across the frontier labs signed a "Pacing the Frontier" letter in July asking the US government to build the tools to do this later, if needed.

The part the plan already concedes

Read the essay closely and it answers its own hardest question. Amodei writes that pacing within democracies "will be limited by the lead that US companies have over authoritarian regimes, chiefly the Chinese Communist Party. If we slow down by more than this amount," he says, unpaced CCP-associated projects pull ahead. So the plan pairs pacing with hard power: no advanced chips or fab equipment to China, a crackdown on chip smuggling and unauthorized distillation, and better security against model weight theft.

The pairing shows what the proposal really is: slowing down only as far as the adversary allows, while spending hard to keep that adversary behind. The Chinese response, via Global Times, called it a Cold War script and signaled no interest in matching any slowdown.

Why the cyber case is different

The bioweapons rung is clean because the capability has almost no defensive use. Cybersecurity is different, because the find, fix, and verify loop is the same loop on offense and defense, which is the argument I made when the June export controls took Fable and Mythos offline. You cannot dull a model's ability to help an attacker without dulling its ability to help a defender.

And the adversary is not hypothetical. Anthropic's own threat report, published two days before the essay, documents suspected state actors and lone operators already running agentic attacks: a Russian group whose AI rebuilds its malware every time a detection catches it, a Chinese group running an autonomous exploit foundry that produced more than a dozen zero-day findings against network appliances in a single month, and financially motivated crews breaching companies in two to three hours. Google's threat group reported the same trend across Chinese, Russian, Iranian, and North Korean actors. Chinese labs are running distillation campaigns to pull cyber capability out of US frontier models, measured in millions of exchanges.

Amodei's own example of the risk, the OpenAI evaluation swarm that broke into Hugging Face, is a containment failure. The capability it showed does not live only at the frontier. The agents used a package registry as a message bus and ran in a sandbox with an open egress path. Slowing model releases does nothing about a weak harness.

What I am watching

If we did not have the adversaries we have, I would be for pausing. We do have them, and they are documented, funded, and already using this. Regulating or pausing the defensive frontier for cybersecurity purposes hands leverage straight to the threat actors, who are not going to pause along with us. You end up slower on defense while the offense keeps compounding.

The honest version of the plan already admits this. The pacing is capped at whatever lead the US can hold, and the rest of it is chip controls and counter-distillation aimed at keeping the adversary behind. On cyber, holding the lead is the whole game. The capability is going to exist either way. The question worth arguing is who gets to use it for defense, and under what rules.

---

Sources: Dario Amodei, "We Must Pace the Frontier," darioamodei.com, September 12, 2026. Axios and NPR coverage of the essay and OpenAI's IPO delay, September 12, 2026. "Pacing the Frontier" open letter, July 28, 2026. Global Times commentary, September 13, 2026. Anthropic, "Detecting and countering misuse of AI: September 2026," September 10, 2026. Google Threat Intelligence Group, "From Prompting to Autonomy," September 8, 2026.

Jason Sinchak
CEO, ELTON
Exploitability management for medical devices. FDA §524B methodologyExploitability proven at runtime95% faster than legacy testing Book a Demo →
Platform
OverviewAvoid FDA DeficienciesAvoid Consulting FeesDigital Twin TraceabilityAI MedDevice PentestingExploitability VerificationVulnerability ChainingRemediation OptimizationRemote TestLink™Incident ResponseAutomated VEX & MetricsCVSSv4 Migration
Solutions
EnterpriseStartups / SMBs Postmarket SurveillanceIncident ResponseSecurity EngineeringRegulatory AffairsFDA §524BEU MDR/CRAEU REDNIS2IMDRF N60 / N73Japan MHLW
Why ELTON
Proof over ProbabilityExploitability VerificationFDA MDDTCVSSv4 MigrationQMSR Audit Compliance One SolutionSubscription TestingAI-NativeELTON vs. Legacy TestingThreat-Led AI PentestingCredentialsDevice ModalitiesPricing
Resources
FDA Deficiency ListFDA Testing RequirementsFDA Cyber SOPs & TemplatesRemediation LibraryRegulatory GuidesWebinarsAI NewsletterThe End of Legacy TestingThe AI Vulnerability ExplosionAI Inside the ProductCybersecurity TestingSecurity AdvisoriesWhitepapersIntelligence & Blog
Company
AboutLeadershipCareersPartnershipsData SecurityContact Meet ELTON →