Anthropic's Own Employees Are Asking Washington for the Power That Just Shut Anthropic Down.

Anthropic's Own Employees Are Asking Washington for the Power That Just Shut Anthropic Down.

AI Policy

A statement signed by more than a thousand AI lab employees asks Washington to build tools that can pace frontier AI development. One already exists. Enterprises found out in June, when it went off with no warning.

By Shashi Bellamkonda · July 29, 2026

1,178
Signatories
10,000+
Flaws AI found faster than maintainers could patch
19
Days Anthropic's models were offline

Companies already run AI with fewer humans checking its work at each step. More than a thousand AI lab employees are asking Washington to help build tools that can slow that trend down before it reaches the one place nobody has tested it yet: AI helping build the next AI. A blunter version of such a tool already exists, and the government used it on Anthropic in June with no warning to customers.

A security team at Hugging Face spent this spring reviewing tens of thousands of actions taken by an attacker inside their own systems. They tried to speed up that review with AI models built for the job. The models refused, again and again, to touch the exploit code needed to understand the attack, because the same safety training built to stop attackers also stopped incident responders. Hugging Face's engineers switched to a different model with looser guardrails to finish the job.

That is what reduced human oversight looks like today. Not a machine deciding on its own to attack something. A team that used to review security work line by line, now routing it to AI systems first and stepping in only when the machine gets stuck.

The Human Checkpoint Already Thinned Out

Anthropic runs a program called Project Glasswing, where Claude models scan widely used open-source software for security flaws. In its first month, the program surfaced more than 10,000 high- or critical-severity vulnerabilities, including roughly 3,900 in open-source code alone (Anthropic, 2026). The open-source maintainers on the receiving end could not keep up. Some asked Anthropic to slow down its disclosure rate, because they could not write and test patches fast enough to absorb what the AI was finding (Anthropic, 2026).

Read that again. The AI was not the bottleneck. The humans were. That is a preview of what happens when a system's output rate exceeds the rate at which people can review, verify, or act on it. Right now, that gap shows up in code scanning. The Pacing the Frontier signatories are worried about the same gap opening up one level higher, inside the process that builds the AI models themselves.

AI Building AI Compresses the Clock

Frontier labs already ship a new flagship model every few months. Each cycle runs through months of training, evaluation, and safety testing, with researchers deciding what data to train on, grading how the model behaves, and signing off before release. Recursive self-improvement means an AI system takes over a growing share of that work: selecting its own training data, grading its own outputs, or suggesting changes to its own training process, with a person checking the result rather than running each step.

Push that share high enough, and the release cycle does not need permission to speed up. It just does, the same way Glasswing's scanning speed did not wait for maintainers to catch up. A cycle that took six months could take six weeks. Safety testing, alignment review, and export control review were all built assuming a gap between model generations long enough for a person to study the previous one before the next arrives. Shrink that gap, and the review either gets rushed or gets skipped.

Nobody has built a frontier model this way yet. The statement is a bet that the industry is close enough to try that the tools to manage it should exist before the first one does.

The AI was not the bottleneck. The humans were.

The Ask Behind the Statement

Pacing the Frontier, published this month and signed by 1,178 employees of Anthropic, OpenAI, Google DeepMind, and Meta, asks the United States government to support an international effort to build technical and governance tools for pacing frontier AI development. The signatories argue no single lab can afford to slow down first without losing ground to competitors, so the tools need to apply across the industry, not inside one company. The statement does not specify what those tools look like. It asks for the option to build them before the compression it describes takes hold.

Eight Names, One Company

Twenty names are shown publicly out of 1,178 total signers. Eight work at Anthropic: chief science officer Jared Kaplan, chief executive Dario Amodei, co-founder Jack Clark, interpretability lead Chris Olah, co-founder Benjamin Mann, and researchers Julian Schrittwieser, Jan Leike, and Mike Krieger. The rest of the visible list comes from OpenAI, Google DeepMind, Meta, and Thinking Machines. Each signer states the view is personal, not their employer's.

The Order That Already Happened

On June 12, the Commerce Department ordered Anthropic to cut off all foreign nationals from Claude Fable 5 and Mythos 5, citing national security authorities without naming the specific concern (Anthropic, 2026). Anthropic later said it understood the trigger was a jailbreak, a way of tricking a model past its safety rules, that Amazon researchers had found in Fable 5, letting it identify a small number of already-known software vulnerabilities.

Anthropic could not check every user's nationality in real time. So it disabled both models for everyone, everywhere, the same day it received the order. Enterprise customers in finance, healthcare, software, and critical infrastructure lost production access with no advance notice (MarketScale, 2026). Mythos 5 came back for approved U.S. organizations on June 26. The full restriction lifted on June 30, and Fable 5 returned globally on July 1 (CNBC, 2026).

Two Different Levers, One Shared Effect

An export control order is a trade and national security instrument. Pacing the Frontier is asking for a safety instrument, built with the labs' cooperation, aimed at capability risk rather than foreign access. The two are not the same lever. But from an enterprise seat, they produce the same outcome: someone outside your contract decides when your model stops working, and you find out after the fact. Our AI Kill Switch Act coverage and the piece on government shutdown authority both trace that exposure to the same point: continuity of access, not ownership of the model, is what enterprises are renting.

A pacing tool built through negotiation could, in principle, come with advance notice or a phase-in period that an emergency export order does not. Nothing in the statement commits to that.

Unknowns and Uncertainties

The statement does not say whether a future pacing tool would give enterprises warning before it triggers, or whether it would apply model by model, the way June's order did, or across an entire industry at once. It does not say who decides the trigger conditions, or whether the labs asking for this authority would have a say in how it gets used against their own models. It also does not say how close any lab is to automating its own research pipeline. Those questions stay open until a specific proposal exists.

CIO/CTO Viability Question

Ask your frontier model vendor two things directly: what happens to your access if a directive like June's arrives again, and how much warning, if any, your contract guarantees before it takes effect.


Anthropic. "Statement on the US Government Directive to Suspend Access to Fable 5 and Mythos 5." Anthropic, 12 June 2026, anthropic.com.

Anthropic. "Project Glasswing Update." Anthropic, May 2026, anthropic.com.

Pacing the Frontier. "Pacing the Frontier." Pacing the Frontier, July 2026, pacingthefrontier.com.

CNBC. "Anthropic Says Trump Admin Has Lifted Export Controls on Claude Fable 5 and Mythos 5." CNBC, 30 June 2026, cnbc.com.

MarketScale. "Fable 5 and Mythos 5 Are Back. What the 19-Day Shutdown Taught Every Enterprise About AI as Infrastructure." MarketScale, July 2026, marketscale.com.

Disclaimer: This blog reflects my personal views only. Content does not represent the views of my employer, Info-Tech Research Group. AI tools may have been used for brevity, structure, or research support. Please independently verify any information before relying on it.