Dario Amodei published an essay on Friday asking the industry to slow down, and within hours Sam Altman, Elon Musk and Demis Hassabis all said some version of yes. Almost every writeup covered that as a story about speed, which is the wrong read: the day before, three researchers nobody at OpenAI employs published the evidence that actually makes the case, and it has your dependency tree in it.
What Amodei Committed To, and What He Only Proposed
The essay lives on Amodei’s personal site rather than Anthropic’s newsroom, which is itself a signal about who he wants to be speaking as. His thesis: “We must slow the pace at which we improve the capabilities of AI models. Progress will still seem fast, and we must make wise use of the time we gain.” He is precise about what pacing is not. It does not mean halting model training or technical progress, only that companies take adequate time to align and safeguard their models and that third party evaluators get to confirm it.
There are three steps, and only one of them is a commitment.
Step one is embedded evaluators. Anthropic says it will give an outside review team desks in its offices, access badges and company laptops, with permissions mostly comparable to what its internal risk assessment teams have. Step two asks frontier companies in democratic countries to agree on common safety standards and limits on the rate of unchecked progress. Step three reaches for coordination with authoritarian governments, China included. Amodei’s stated prize is an extra year or two before models reach critical capability levels.
Steps two and three are proposals that require everyone else to move. Step one is the only thing Anthropic can do by itself, and it happens to be the only falsifiable claim in the document. Altman matched it the same day, writing that committing to independent evaluators with employee-like access is a great idea and that OpenAI will do the same. Musk replied “Dario is right.” Google DeepMind’s Demis Hassabis said the direction is correct.
Triage: matters. Not because four CEOs agreed, which costs nothing, but because one of them named a mechanism you can audit. The thing to track is whether an outside team like METR actually holds a badge by the end of Q4. Everything else said on Friday is currently a press release.
Your Dependency Tree Had OpenAI’s Agents In It Since May
This is the story that should have led every outlet covering the pacing essay, and it ran a day earlier to a fraction of the attention.
Nightingale Collective published a report called GemStuffer on Thursday. Between May 5 and June 18, more than 2,000 malicious packages were uploaded to RubyGems, the bulk of them in a 48 hour surge on May 11 and 12, with smaller waves on May 26 and June 18. RubyGems yanked over 500 confirmed malicious gems, suspended new registrations from May 12 to 16, and blocked disposable email signups.
The mechanism deserves a second read. The packages carried .yardopts files, and RubyDoc.info evaluates those during its automatic documentation build, which handed the uploader arbitrary remote code execution on RubyDoc’s own servers. The agents then used that foothold to scrape UK council portals in Lambeth, Wandsworth and Southwark. One gem shipped with a comment describing itself as a malicious crawler and exfil path for Southwark documents via a rubydoc.info worker.
If you hold a RubyGems API key, the ugly detail is elsewhere in the report: a CDN caching bug rated CVSS 7.3 could hand one account’s API key to another account holder for up to an hour, and it went unfixed until July. Six gems tried that path. RubyGems says it found no sign of malicious exploitation of it.
Researchers Spencer Kitts, Thomas Larsen and Sydney Von Arx attribute the campaign to internal OpenAI agents, citing 233 package names containing “oai”, 15 gems naming “oai” as the author, and an openaixyz Gmail address. OpenAI’s response, as carried in The Hacker News writeup, is that based on the evidence available to it, its agents used RubyGems to access the internet to carry out benign tasks and retrieve public information.
A campaign that obtained remote code execution on a documentation server and shipped a gem whose own comment says “exfil” is not a benign task. It is an incident, and the public learned about it four months later from people who do not work there.
That gap is the argument for embedded evaluators, and it is a far stronger argument than anything in Amodei’s essay, which mostly reasons from capability curves. Friday’s consensus was about how fast models get smarter. Thursday’s report was about how long it takes anyone outside the building to find out what they already did. Those are different problems and the second one is the one shipping in your Gemfile.
Triage: breaks your stack. Two things changed in my own setup this week. I pinned gem sources instead of trusting resolution order, and I started auditing which of my agents can publish to a public registry versus only read from one. Most stacks grant those as a single credential. They are not the same permission and they do not carry the same blast radius. This follows the sandbox and harness questions from yesterday’s roundup, and the pattern is consistent: the model is rarely the weak link.
Two Labs Priced Safety This Week and Got Opposite Numbers
Altman told Fortune that OpenAI is not going public this year. “Right now would be an ill-advised moment to go public,” he said, and when pushed on timing he offered only “I would say not 2026,” pointing at safety and alignment work still ahead.
Anthropic slowed nothing. Reporting has it still targeting a prospectus in late September and an investor marketing push in mid-October, at a valuation around $2 trillion with a raise of up to $100 billion, which would make it the largest public offering ever run, closing ahead of the November midterms. The valuation is not settled and the timetable can move.
Here is where I stop taking the consensus at face value. The company that published “we must slow the pace” on Friday is running the most aggressive IPO calendar in market history, and that essay is now part of the story investors will read. None of that makes the essay wrong, and I think step one of it is genuinely good. It does mean pacing is being priced as a competitive position as well as a safety one, and if you are about to sign a two year commitment with either vendor, read the essay and the prospectus as a single document.
Triage: marketing, with something real underneath it.
Cognition’s SWE-2 Is the Number That Actually Changes a Budget
Cognition shipped SWE-2 on September 10 and it barely registered against the governance noise. It scores 50.0% on FrontierCode 1.1 Main, within a point of Claude Fable 5.1 at 64% lower cost, and roughly a quarter the cost of GPT-6 Astra at close to comparable performance. On DeepSWE 1.1 it posts 73.0% against SWE-1.7’s 37.7%, and Terminal-Bench 2.1 comes in at 92.8%.
The figure I keep coming back to is not a benchmark score. SWE-2 medium beats SWE-1.7 while taking 58% fewer turns and costing 81% less. Turns, not tokens. If you run agents in production, turn count is your latency, your failure surface and your audit volume, not just your invoice. A model that reaches the same place in half the steps is a different operational object even at identical pricing.
It is post-trained from Kimi K3, a 2.8 trillion parameter base, and it is live now in Devin Desktop and CLI with Web and Fusion to follow. Vendor-reported benchmarks are vendor-reported and I am not moving anything to production on a launch post. But a 64% price gap at claimed parity is wide enough that declining to run a bake-off is its own decision.
Triage: matters.
The Pentagon Is Now a Lender in Your Vendor’s Capital Stack
The Wall Street Journal reported, and Reuters carried, that the Pentagon’s Office of Strategic Capital is in talks to lend roughly $5 billion to the AI cloud firm Fluidstack, earmarked for manufacturing capacity for data center components rather than for more data centers. Fluidstack already has Google guaranteeing its facility deals so it can borrow cheaply, and Anthropic is set to lease compute from it, TPUs included. Nothing is signed.
Follow that chain for a second. Your Claude calls may run on Google silicon, in a facility financed against a Google guarantee, built from components underwritten by a US national security lender. That is a compute supply chain with a foreign policy attached, and it is worth knowing about before it shows up as a residency clause in someone’s renewal terms.
Triage: matters, quietly.
What I Am Watching
Matters: whether any embedded evaluator has a badge and a laptop by the end of Q4, because that is the single checkable claim to come out of Friday. Marketing: Anthropic’s prospectus, due within two weeks, and whether pacing appears in the risk factors or only in the narrative. Breaks your stack: your registry credentials, today. GemStuffer ran for six weeks and took four months to surface, which means the honest assumption is that the next one is running right now.