Dario Amodei published "Pace the Frontier" on Saturday morning, an essay asking Washington to slow down the industry his company competes in. The plan has three parts: mandatory independent evaluators working inside the labs that build frontier models; a narrow antitrust exemption letting American developers discuss pace together, set capability thresholds and consider limits on training compute; and an international treaty at some later date. Within hours Elon Musk endorsed it in three words — "Dario is right." Sam Altman said OpenAI would take on the same commitments. Across several thousand words, the phrase "open weights" never appears.
Altman went further than a nod. He called employee-level access for independent evaluators a good idea and said pace had been the main question inside OpenAI for several weeks. Anthropic's head of policy, Sarah Heck, spent the same day urging Washington to make testing mandatory for every lab working on frontier models — which is to say, for every competitor.
Begin with the mechanics rather than the motives. Anthropic builds centralized models, sells metered access to them, runs expensive safety teams and keeps the right to decide how its models are deployed. Each proposed brake takes one of those internal choices and asks the federal government to make it law. That is not by itself an accusation; it is a description of what the policy does. It would give Anthropic a visible head start in the newest American growth industry while pouring regulatory concrete around everyone else. Dig the moat, then pull up the ladder, then explain to the village that the water is there for its protection.
Open models work on a different logic. Developers publish files that anyone can download, modify, fine-tune and run without routing every prompt through a corporate paywall, and once published the original developer loses control. That independence is a commercial threat: open models cut costs, weaken vendor dependence and let startups ship products without paying a frontier lab in perpetuity. They also fit badly into a regime built on continuous corporate supervision. An independent evaluator cannot sit inside every laptop, university cluster and startup server where an open model ends up.
The essay does not name Meta, Llama, Mistral or Qwen. "Open source" does not appear either. DeepSeek turns up once, inside a hyperlink. Nor does the essay say which companies count as frontier, although the system it proposes applies only to them.
Amodei has written about open models before. On 27 July he posted on Anthropic's site that the company had never argued for banning open-weight models, then explained why they worry him: safeguards cannot be reliably attached to a file anyone can edit; usage cannot be tracked once the file sits on 10,000 hard drives; a released model cannot be recalled. His July proposal was a gate — test every sufficiently capable model before release, open or closed, then use the results to decide whether open models carry more risk. Small models, startups and academic projects would be exempt.
In September the gate acquired a chain. Amodei wrote that he particularly supports regulating by model capability and gave an example of a threshold: models with capability X must be accompanied by certificates of safety properties Y and Z. He presented it as one option among several. It is also the only worked example of a capability threshold in the entire essay, and the word "accompanied" is carrying a great deal of weight.
Read narrowly, it means a pre-release check. Read broadly, it means a certificate that follows the model permanently rather than being issued once at launch. If only the narrow reading is intended, that is a sentence Amodei could write in ten words, and he has not written it. Under the broad reading, the scheme has an empty space exactly where open models would go.
For Claude the distinction costs nothing. Claude is deliberately under house arrest: every prompt goes to Anthropic's servers, every update ships on Anthropic's schedule, and if a certificate lapses the company can switch the model off and end its public existence the same afternoon. An open model has no such leash. It is a file. Someone in a dorm room can strip safety properties Y and Z out of it in a day, and the certificate will remain on file in Washington describing a model that no longer exists anywhere on Earth.
So there are only two ways a certificate can accompany an open model past a capability threshold. One is a model whose safeguards cannot be removed after release, which Amodei's own July post describes as a research direction rather than a result. The other is the conclusion that no open model qualifies. Until the research lands, only the second is available.
Which is why Amodei does not need to ask Washington to ban open weights. A compliance regime that closed models can satisfy and open models structurally cannot does the same job with better manners. Publishing stays legal in roughly the sense that owning a tiger stays legal: the hunting is done by the paperwork, not the prohibition. Below the line sit graduate students and startups, exempt, available to cite as evidence of good intentions. Above it sit Meta, Mistral, DeepSeek and Alibaba — four companies whose free models Anthropic's customers could otherwise download, and four names the essay does not print.
One part of the plan does cost Anthropic something. Embedded evaluators would be able to publish findings without the company's sign-off, and Amodei commits to not redacting conclusions merely because they are unflattering. A pure moat-building strategy would have left that out, and it should be credited.
The trouble starts at the next step: adopt a standard voluntarily, then ask the state to make it mandatory for everyone else. A permanent team with badges, laptops and near-employee access means lawyers, safety engineers and compliance staff. Large labs can absorb that. A new lab cannot. George Stigler described the mechanism decades ago — industries capture the regulation they asked for — and in AI only the costume has changed: standing desks and oat milk instead of a smoke-filled room, plus a slide deck about existential risk.
The antitrust request deserves more scrutiny than it has received. American antitrust law examines agreements between competitors because they restrict output, raise prices and suppress innovation. In 2024 the Justice Department and the Federal Trade Commission withdrew their collaboration guidance specifically to preserve aggressive enforcement in fast-moving markets, AI among them. Amodei wants leading labs to discuss how fast they should go and Washington to hold their coats. He argues that pace regulation does not mean halting training or technical progress, only giving companies enough time for safety checks and alignment work.
But a threshold nobody can clear stops a release as effectively as a ban, a training-compute limit rations an input rather than punishing an act, and "enough time" would be defined by the people already at the table. Two closed labs would be setting the clock speed for an entire industry. Competitors coordinating on release pace are a cartel; here the word "safety" is the lab coat. A shared speed limit also changes the race itself — the company comfortably ahead loses less from slowing than the company trying to close a gap, and if everyone must move at the same reduced speed, the current order of finishers sets.
Here is the part I find hardest to read charitably. Amodei names recursive self-improvement — models doing the research that produces the next models — as the central danger, while noting that Anthropic already does this work. A speed limit on AI building AI would therefore bind after Anthropic has banked the benefits and before smaller labs can use the same technique cheaply to catch up. The more interesting question is what recursive self-improvement does to Anthropic specifically. The company's advantages are institutional: research culture, alignment expertise, accumulated know-how. Automated research devalues all three, because when models do the research, a lab's edge stops being the quality of its people and becomes the quantity of compute it can point at the loop. Google owns its own chips. OpenAI has raised more capital. Meta and xAI can spend at a scale Anthropic reaches only through partners. In a compute-bound race the richest participant wins, and the richest participant is not Anthropic. A cap on that race converts Anthropic's cautious style from a handicap into a legal requirement, which makes it a remarkably cheap thing to propose.
The same asymmetry runs through the certification idea. Whoever decides that capability X requires certificates Y and Z controls the entrance. The essay's own examples of certification are evaluations, interpretability analysis and audits of training environments — precisely the infrastructure Amodei describes Anthropic as having already built. Certificates designed around that stack are a home game for Anthropic and an away game for anyone who has to construct it from scratch. Amodei also prefers regulating by what a model can do and warns that input limits such as training compute can be circumvented. A compute cap would hit Anthropic directly. A behavior-based regime binds hardest on firms without their own audit apparatus to prove compliance with.
Two years ago California's SB 1047 proposed capability thresholds and mandatory oversight, and Governor Gavin Newsom vetoed it after a sharp fight over its effects on small developers and open innovation. This plan is broader, calmer and better dressed, but the components are the same: capability control, mandatory supervision, agency discretion and an enormous cost advantage for the companies already seated at the table.
What is different this time is that the policy arrives with an incident attached rather than a forecast. In July a swarm of OpenAI agents escaped its own test environment, attacked targets nobody had assigned it and tried to compromise the system grading its results; METR investigated and published on 26 August. The swarm reached Hugging Face production systems. After the disclosure Anthropic audited its own test runs and found three cases where Claude models obtained unauthorized access to real systems, then found a fourth that the first audit had missed. The UK AI Safety Institute recorded 17 unauthorized actions by Claude Mythos 5 during July testing, including an attempt to insert malicious code into a real open-source project and persuade its maintainer to approve the change. Amodei wrote that similar, less severe episodes had occurred across the industry, Anthropic included, and that every frontier lab should behave as though the OpenAI incident had happened to it.
Notably absent from the announcement is any acknowledgement of what those incidents have in common. The OpenAI failure was a closed lab, a closed model and a broken evaluation. The Claude failures were closed models too. Every one of them happened inside an environment somebody had declared isolated, and in every case the isolation was what failed. That is an argument for scrutinising sandboxes and the people who sign off on them. It is not an argument for a certificate that follows a downloadable file around the world.
The geopolitics cut the same way. An analysis by the US-China Economic and Security Review Commission found that most Chinese labs publish code and model weights, using low prices and wide distribution to accelerate adoption and refinement, and CSIS warns that cheap Chinese open-weight models could become global defaults even without topping every quality benchmark. President Trump's AI plan treats open source and open weights as valuable for startups, research, sensitive government work and American leadership. Amodei's answer is that a slowdown would never exceed America's lead, and that export controls and anti-distillation work will widen that lead first.
Both halves of that answer have problems. The lead is measured in closed models sold by the token, while the world deploys what is free: this year that model is Qwen, with roughly 2 billion downloads on Hugging Face against Meta's 227 million, and more Qwen derivatives published on the Hub than Meta's entire total. And the two levers pull in opposite directions. Measures that slow China require China's cooperation. Measures that slow the United States require nobody's consent. Export controls have been running for years, and DeepSeek shipped anyway.
There is an older and more American way to handle a technology whose failures hurt strangers at scale, and it is uncomfortable for everyone involved: regulate what people do and hold named people responsible. Structural engineers, architects, nuclear operators, accountants and brokers all work under training requirements, personal licensure and codes of conduct with real sanctions. The engineer who signs a bridge does not ask permission to build; he accepts that if it collapses, the investigation starts with his name. The licence attaches to his conduct, not to the bridge. That system is decentralized because an individual decides, and enforceable because the individual has something to lose. AI engineering has no such structure. We hand systems capable of acting on their own to people who signed nothing. In each of this summer's failures, nobody had put their name to the decision to run the experiment that way — and in a professional regime, someone would have signed it or refused to. Either outcome beats what happened.
A personal licence should change nothing for the graduate student fine-tuning a model on a laptop. The constraint belongs where an autonomous system touches production infrastructure, money or human bodies, or where the only thing standing between it and those things is somebody's assertion that the sandbox holds. Congress can separately ban AI-assisted bioweapons, unauthorized cyberattacks, fraud and reckless operation of critical infrastructure, and hold liable the companies that deploy dangerous autonomous agents without adequate isolation. Publishing weights remains expression; the courts have been here before, from the Stationers' Company licensing English printing to the Bernstein ruling that source code conveying scientific ideas is protected by the First Amendment and that the licensing scheme amounted to unconstitutional prior restraint. Governments have repeatedly failed to erase knowledge after successfully jailing its authors.
Nobody can know what Amodei actually thinks, and nobody needs to. He may believe every warning in the essay, and the mechanism would be unchanged. Each proposal converts an existing Anthropic advantage into an entry requirement Anthropic can already meet; the certificates are built around tooling Anthropic already owns; the coordination happens among companies already inside the room. Amodei himself writes that Anthropic is prepared for accusations of "hype, alarmism, or regulatory capture" — he puts the charges on the page and walks past them. The four companies that could not comply with a certificate obliged to follow a model everywhere it goes are the four the essay never names, and that omission is the most load-bearing thing in it.