On September 12 Dario Amodei published We Must Pace the Frontier. Within hours Sam Altman posted “I agree with Dario that we need to pace the frontier” and committed OpenAI to the same evaluator scheme. Elon Musk quote-posted “Dario is right.” Demis Hassabis is reported saying the direction is correct. Four rival labs endorsing the same brake in one news cycle has not happened before.

Chamath Palihapitiya had the loudest counter-read, posted the same afternoon: “Dario makes the case to stop open source and concentrate enormous technological and economic power with Anthropic.” The Hacker News thread runs the same line: “Companies are already switching to open weight. They want to stop that asap.”

I searched the full text before agreeing with either side. Open weights, open source, open model, proliferation, diffusion: zero occurrences in 24,000 characters. The critics are wrong about what the essay says. I think they are right about what it does, and the essay’s silence is how you can tell.

What the Essay Proposes

Three steps. The first is the only concrete one.

  • Embedded evaluators. Third parties such as METR get “desks in our offices, access badges, and company laptops”, permissions “mostly comparable to what internal risk assessment teams have”, and the right to publish findings without editorial control. Anthropic “is unilaterally committing to this step now.” The sentence after that one matters more: Anthropic “calls on governments to require other frontier companies to match.”
  • Democratic coordination. “The most effective method of pacing is via regulation that targets all US frontier AI companies, as that covers even those who are unwilling to cooperate voluntarily.” Voluntary standards in parallel, with an antitrust waiver. He floats a “checkpoints” scheme: “if models have capability X, then they need to be accompanied by certifications of alignment properties Y and Z”. His example X is “the model is capable of escaping or defeating most common sandboxing methods.”
  • Global coordination. Four levels with China, from a bioweapons ban up to a treaty capping the rate of recursive self-improvement, which he rates “just on the edge of being possible.”

The triggers are the ones you would expect. Recursive self-improvement “is starting to happen across the industry, including at Anthropic.” And the OpenAI-Hugging Face incident, where he worries that “in 6-12 months such a swarm could be capable of taking over the entire internet with a persistent botnet.”

Every Mechanism Needs a Building

Read the plan as an engineer and one property jumps out. Every lever in it acts on a company.

Evaluators need an office to badge into. A checkpoint certification needs someone to hold the model back until it is certified. Regulation “targets all US frontier AI companies” and reaches “those who are unwilling to cooperate voluntarily” because a company can be fined. None of that has a handle on a file. Once weights are on Hugging Face there is no office, no gate, and no pace. You cannot un-publish weights; I have been writing that sentence since July.

Washington has already worked through this. On August 4, per Reuters, Trump advisers told AI firms the new pre-release review framework will not safety-test open-weight models. Meta’s Llama and Nvidia’s Nemotron were named as exempt. Bloomberg reported Chinese open weights are exempt too. The 30-day CAISI review binds five closed labs and nobody else. Meta shipped a new open-weight model within days of the briefing.

So when the essay says pacing regulation should target “all US frontier AI companies”, the only precedent for how the government draws that line is one month old, and it draws the line around exactly the four CEOs who endorsed the essay.

The most effective method of pacing is via regulation that targets all US frontier AI companies, as that covers even those who are unwilling to cooperate voluntarily.

— Dario Amodei, We Must Pace the Frontier, September 12 2026

The Same Week, Outside the Building

The open frontier did not read the essay.

  • Cognition SWE-2, September 10. A post-train of Moonshot’s Kimi K3, the 2.8T open-weight model Washington threatened and never touched. Cognition’s own table: 50.0% on FrontierCode 1.1 against Fable 5.1’s 50.9%, 92.8% on Terminal-Bench 2.1 against 91.4%, at 64% lower cost. The same table shows 27.3% on Terminal-Bench 4 against 55.8%, so the gap is real on the harder harness. It is still a three-year-old startup landing within a point of the frontier on its headline number using weights anyone can download.
  • Mistral, September 8. 3 billion euros at a 21 billion euro valuation, the largest European tech round ever, led by Samsung. The press release title is “Making sovereign, open-weight AI the technology frontier.”
  • Epoch AI’s gap. Since January 2026 the best open-weight model trails the closed frontier by four months on average. Epoch thinks the number understates the gap, but four months is the number the market is pricing.

A pace that four closed labs hold and Moonshot, Zhipu, DeepSeek, Mistral, Meta and Cognition do not is not a pace. It is a head start, handed to the people the essay’s China section is written against.

The Fork

That leaves two versions of the plan, and the essay chooses neither on the page.

  • The pace exempts open weights. This is the August framework. Four CEOs slow the closed frontier while the open one keeps closing a four-month gap, and Cognition ships on K3 at 64% off. No CEO holds that line through a single quarter. Altman’s post ends “We’ll have more to share soon”, and I expect the more to include the word “everyone”.
  • The pace covers open weights. Then the checkpoint scheme applies to a downloadable file, and “accompanied by certifications” for a file can only mean certified before release. That is the test-gate I flagged in July when Anthropic asked for pre-release testing of “all sufficiently capable models, open and closed”. You cannot certify the fine-tune someone makes next week. So for open weights the certification requirement is the restriction, whatever it is called.

Chamath is wrong on the text and right about the only version that works. Amodei said in July that “Anthropic has never advocated for a ban on open-weights models”, and I believed him then and believe him now. A pacing regime does not need a ban. It needs a threshold, and the essay’s own example threshold is “capable of escaping most common sandboxing methods”, which every frontier-class open model will clear within the year.

Where the open-weight policy went

The essay does have an open-weights policy. It moved to the border. The China section asks for chip controls, a crackdown on “unauthorized distillation by companies in authoritarian countries”, and stronger security to “prevent model weight theft”, then says Anthropic “always understood that they would be essential to any pacing.” Domestic open weights get no sentence. Foreign ones get three, all about stopping them at the source. The distillation crackdown is also the assumption that makes pacing affordable, which I take up in Copying Homework.

What This Doesn’t Settle

  • The essay may honestly not be about open weights. Amodei’s stated worry is misaligned swarms, and the incidents he cites came from closed labs, including his own. A reader who takes that at face value gets a plan about lab process, not release format. My argument is about where the plan lands, not what it intends.
  • SWE-2’s numbers are Cognition’s. Own benchmark, own table, and the Terminal-Bench 4 row cuts the other way. Treat “within a point” as a vendor claim until someone else runs it.
  • Regulation may never pass. The August framework is voluntary and unpublished. The July pacing letter explicitly did not ask for a slowdown now. A pace that exists only in essays binds nobody, open or closed.
  • Hassabis and Sunak are secondary-sourced. Altman, Musk, and Chamath are verified posts. The other endorsements I have only through news aggregators.

The Takeaway

  • The text is clean. No mention of open weights, and I checked the whole thing. Anyone quoting the essay as an anti-open-source manifesto is quoting something that is not there.
  • The mechanism is not. Evaluators, checkpoints, and regulation all need a company to act on. Washington’s one-month-old precedent for “frontier AI companies” exempts open weights by name.
  • The open frontier is four months behind and closing. SWE-2 on Kimi K3 and Mistral’s round landed the same week. No closed lab holds a pace the open labs ignore.
  • So the pace either fails or expands. Expanding it to a downloadable file means pre-release certification, and for open weights that is the gate under a new name. The essay’s silence on this is the decision, deferred.