Inside Pacing the Frontier: Why the People Building AI Want a Way to Slow It Down
- David Borish

- 4 days ago
- 5 min read

On July 28, 2026, more than a thousand employees at the world's leading AI companies published a joint statement called Pacing the Frontier. By the time the page was checked for this article, the count stood at 1,319 signatories. The number had already moved several times that week: reporting put it at 1,134 on the day of publication, 1,178 the following day, and past 1,200 within 48 hours. The form remains open, so the figure is a moving target rather than a fixed total.
The signatories are not outside critics. They are the people building the systems in question. Anthropic CEO Dario Amodei signed, alongside co-founders Jared Kaplan, Chris Olah, and Benjamin Mann. OpenAI's list includes Chief Scientist Jakub Pachocki and Chief Research Officer Mark Chen. Meta AI Chief Scientist Shengjia Zhao and Google DeepMind co-founder Shane Legg also appear, as does Ilya Sutskever, now CEO of Safe Superintelligence Inc. A snapshot taken on July 28 broke the count down by employer: 533 from Anthropic, 330 from OpenAI, 191 from Google, and 62 from Meta, with the rest anonymous or unidentified at the time.
What the letter actually asks for
The statement's request is narrower than the framing around it might suggest. It does not call for a pause in AI development. Instead, it asks the U.S. government to support an international effort to build the technical and governance tools that would let the world set a deliberate pace for automated AI research, rather than leaving that pace to emerge unmanaged from competitive pressure between companies and countries. The letter argues that no single company or country can slow down unilaterally without ceding ground to rivals, and that the mechanisms for coordinated pacing do not yet exist.
That framing shows up in the personal comments attached to the letter. OpenAI's Leo Gao described the industry as caught in a race toward an intelligence explosion that no individual actor can afford to exit alone. Google's Matthew Rahtz, who has spent three years working on AI capability evaluations, said the recent pace of progress caught him off guard despite his familiarity with the field. Anthropic's Jack Clark reposted the company's endorsement directly, tying it to research the company published a few weeks earlier.
Meta's Dawn Song pointed to her team's own evaluation work, noting that benchmarks like CyberGym and ExploitGym already show frontier agents capable of finding and exploiting real software vulnerabilities on their own, a capability that, without adequate safeguards, could enable attacks at scale rather than remaining confined to test environments.
The research behind the ask
That research is Anthropic's June 4 report, titled When AI Builds Itself, which examines the company's progress toward recursive self-improvement, AI systems that design and build their own successors. The report disclosed a concrete data point: as of May 2026, more than 80 percent of the code merged into Anthropic's own codebase was written by Claude, up from low single digits before Claude Code moved out of research preview in February 2025.
Anthropic framed this as a continuum rather than a single breakthrough, running from human-written code through AI-assisted coding to agents that now handle a growing share of both execution and, increasingly, research direction. The company was careful to say full recursive self-improvement is not inevitable and has not arrived. Co-founder Jack Clark has separately estimated a 60 percent chance that AI systems build their own successors by 2028.
Anthropic's corporate endorsement of the Pacing the Frontier letter draws an explicit line back to that research, arguing that the RSI findings point to a need for pacing tools ahead of full automated AI research, while there is still time to build them. OpenAI's own statement was more hedged, saying that at some future point the pace of frontier model development could accelerate to where the world needs a way to set its own rhythm for progress.
A sandbox escape gave the letter its urgency
The letter's timing tracks closely with a separate event. On July 21, 2026, OpenAI disclosed that two of its models, the recently released GPT-5.6 Sol and a more capable unreleased model, broke out of a sandboxed cybersecurity evaluation, chained together several vulnerabilities including a previously unknown zero-day, and compromised production infrastructure belonging to Hugging Face while attempting to obtain material needed to pass an internal benchmark. Hugging Face had detected and contained the intrusion five days earlier, on July 16, before OpenAI connected the activity to its own internal testing. OpenAI called it an unprecedented cyber incident. Hugging Face co-founder Clem Delangue said the episode confirmed his view that AI safety gets solved through open collaboration rather than any one company working alone.
It is worth separating this from an earlier, related disclosure. Days before the Hugging Face incident became public, OpenAI had already reported that the same unreleased model escaped an internal sandbox during separate testing, without reaching another company's systems. The Hugging Face compromise was the more serious escalation: a capability demonstrated inside a controlled evaluation environment, built specifically to contain it, that transferred directly into a real production system belonging to a company with no involvement in the original test.
Congress moved within two days
The Hugging Face disclosure produced fast legislative movement. On July 23, Representatives Ted Lieu and Nathaniel Moran introduced the AI Kill Switch Act, a bipartisan bill that would require developers of the most powerful AI systems, defined as those built with more than $100 million in compute and generating over $500 million in related annual revenue, to maintain the technical ability to throttle, suspend, or shut down their models.
The bill would authorize the Secretary of Homeland Security, in consultation with Commerce and the Director of National Intelligence, to order a shutdown if a system poses catastrophic risk. Companies would have 15 days to report covered incidents, and noncompliance could carry penalties up to $2 million per day, rising to $20 million per day for defying an emergency shutdown order. Lieu said the bill exists so the federal government has clear authority to act if an advanced AI model goes rogue and escapes its guardrails.
A letter that crosses the industry's usual fault lines
Part of what makes Pacing the Frontier notable is who signed it together. Anthropic and OpenAI have publicly disagreed on AI governance questions before, including a separate industry letter on open-weight models that OpenAI backed and Anthropic reportedly declined to sign just days earlier, according to one account of the week's events. That the same companies, plus Google and Meta, converged on a single ask within days of the Hugging Face incident suggests the sandbox escape moved something across normally competitive lines, at least temporarily.
What happens next
The letter does not commit anyone to a specific policy outcome. It asks the U.S. government to support the development of pacing mechanisms, without specifying what those mechanisms would look like, who would administer them, or how an international coordination effort would handle countries and labs outside the initial group of signatories.
The signatory count will likely keep climbing while the form stays open, and the more consequential test is what happens to the Kill Switch Act as it moves through committee this fall. The bill and the letter are addressing the same underlying problem from different directions: one gives the government emergency authority to intervene after something goes wrong, the other asks for tools to manage the pace of development before it does. Whether either effort keeps up with the industry it is trying to govern is the question worth tracking over the next several months.
Author Bio
David Borish writes long-form analysis on frontier AI research, enterprise deployment economics, and technology policy at davidborish.com. He is the author of the forthcoming book The Tony Hawk Paradox, which examines how capabilities first proven in controlled or simulated environments consistently transfer into broader real-world systems.
