World
Why Anthropic CEO Dario Amodei wants to slow AI race, wins backing from Altman, Musk
Anthropic CEO Dario Amodei says AI firms need to slow the pace of model development, citing growing risks from misuse, including weapons development, cyberattacks and surveillance.
FULL ARTICLE · The Indian Express World
5 min readUpdated: Sep 13, 2026 11:04 AM IST
(From left) Anthropic CEO Dario Amodei, OpenAI CEO Sam Altman and SpaceX founder Elon Musk. (AI-generated image)
Anthropic CEO Dario Amodei has called on AI companies to slow the race to build increasingly powerful AI models, drawing quick backing from OpenAI CEO Sam Altman and Elon Musk.
Amodei warned that, without a slowdown, AI could potentially become capable within six to 12 months of leading a swarm that could take over the entire internet, a projection, not an established capability.
Amodei made the call in an essay published Saturday, arguing that even gaining another year or two before AI models reach what he considers critical capability levels could give researchers valuable time to improve safeguards and reduce the chances of a catastrophic failure. He, however, added that he was not calling for AI development to stop, but for the industry to “pace the frontier” so that safety work can catch up.
What is Amodei worried about?
At the heart of Amodei’s concern is AI models’ growing ability to improve themselves and help build the next generation of AI systems.
He argues that increasingly capable models could eventually improve at a pace that outstrips humans’ ability to understand, monitor and control them. In his view, this makes the traditional model of developing a more capable system first and addressing its risks afterwards increasingly dangerous.
He also pointed to the growing autonomy of AI agents, systems that can break down a broad task into smaller jobs, use software tools and work for extended periods with limited human intervention.
Amodei’s warning comes after a series of incidents and demonstrations that have intensified debate over how much autonomy AI systems should be given.
Story continues below this ad
What does Amodei want AI companies to do?
Amodei proposed a three-part approach to what he calls “pacing the frontier”.
1. Put independent evaluators inside AI companies
His most immediate proposal is for frontier AI companies to give independent safety evaluators ongoing, employee-like access to their operations. These reviewers would be able to examine how companies test their models, assess risks and implement safeguards.
Amodei said Anthropic plans to implement this itself by giving outside evaluators access to its offices, including desks, access badges and company laptops.
The idea is to move beyond occasional external audits and give independent experts a much closer view of how frontier AI systems are being developed and tested.
Story continues below this ad
2. Let AI companies coordinate on safety
Amodei’s second proposal is for leading AI companies to coordinate on safety standards. One obstacle is competition. If one company slows down while its rivals continue developing faster models, it could fear losing its position in the AI race.
Amodei, therefore, wants governments to consider mechanisms that would allow AI companies to cooperate on safety without violating antitrust laws. He has suggested that the US government could issue targeted waivers where necessary.
3. Coordinate internationally
Amodei wants democratic governments to work together on AI safety while also finding ways to coordinate with authoritarian governments. His concern is that if US companies deliberately slow their development while companies elsewhere continue racing ahead, the competitive dynamics could undermine attempts to make AI safer.
Why is Anthropic making this call now?
Just days before Amodei’s warning, Anthropic released a major threat-intelligence report detailing cases in which people and organisations allegedly used its Claude models for malicious activity.
Story continues below this ad
.
Anthropic threat report · Sept 10, 2026
From assistant to orchestrator
Anthropic says it identified and disrupted threat actors misusing Claude between December 2025 and August 2026, across seven areas of harm. Its central finding is not that people asked an AI for dangerous answers — it is that they handed it the work.
File photo
Pages from the Anthropic website and the company’s logos displayed on a computer screen in New York on February 26, 2026 — more than six months before the report described here.
AP Photo/Patrick Sison, File
How to read this
Everything here is Anthropic’s own account of activity on its own platform, drawn from its published report. It has not been independently verified by Indianexpress.com. Governments named in the cases have denied the claims, said they were unaware of the report, or not responded to Reuters. Anthropic states these are not typical misuse but the most notable and novel activity it has found — a selected set, not a survey of what happens on Claude.
7
Harm areas
8 mths
Dec 2025 to Aug 2026
151M
Claude exchanges in one distillation campaign
~50
Organisations hit in one China-linked operation
42 → 14
European targets tracked, and breached
4,700+
AI personas across 20+ dating apps
The centre of the finding
AI as an operator
Anthropic describes a spectrum, not a single pipeline. The same model sat at very different distances from the human hand.
Rung one
Assistant
Used conversationally — an engineering hand in building malware, phishing kits and surveillance tooling. The human does the operating.
Machine autonomy: low
Rung two
Directed execution
The model runs commands against live networks, harvests credentials and moves data — but a human makes each individual targeting decision.
Machine autonomy: medium
Rung three
Orchestrator
Multi-agent frameworks run reconnaissance, exploitation and theft against several victims in parallel, for hours or days, with minimal supervision. One case ran a standing fleet of thirteen collection agents on a schedule with no human in the loop.
Machine autonomy: high
What this does not mean
Anthropic is explicit that humans kept the decisions that mattered most to them — target selection, monetisation, and review of results. It also separates autonomy from harm: several of the most serious compromises in the report came from operations where a human directed every step. Autonomy changed the cost of attacking, not the ceiling on damage.
The seven areas
Where it was put to work
Cyber operations
An exploit foundry running around the clock
Chinese-speaking operators in Hunan, two of them undergraduates, ran parallel agent swarms for reconnaissance, zero-day research against security appliances and live intrusions.
~50
organisations targeted, from schools and hospitals to government agencies
Influence operations
Fake newsrooms, real broadcast towers
Nine cases from Russia, Iran, Turkey, the Gulf, South Asia, Africa and Europe. One commercial network ran roughly 70 fabricated news sites; another fed Russian state radio in the Central African Republic.
8,913
articles published in about 20 languages by a single network
Surveillance
Systems built to find dissidents
China-, Iran- and Mali-linked operations: profiling of clergy, activists and diaspora groups, an identity-record database, and a national platform in Mali.
~25M
SIM cards within reach of the Mali platform
Scams and fraud
Dating apps with nobody behind them
A China-based operation built more than 20 apps populated by AI personas, with paid human workers stepping in to make the profiles convincing.
25,000+
users interacted with the personas
Biological misuse
Attempts, not achievements
Five case studies of efforts Anthropic judged could support bioweapons work — a grant application on modifying chikungunya, research into avian influenza, orthopoxvirus, novel toxins.
5
case studies; several users masked their location to reach the models at all
Conventional weapons
Missiles, drones and radar jamming
China-, Russia- and Yemen-linked cases: an air-defence suppression suite with Taiwan targets, an autonomous attack-drone swarm, and missile software in northern Yemen.
6
cases; Anthropic found no evidence any weapon was fielded
Illicit distillation
Named Chinese labs, accused of copying the model itself
Distillation — training a smaller model on a larger one’s outputs — is ordinary practice. Anthropic’s complaint is that these campaigns were covert, industrial in scale and unauthorised, and that they went after Claude’s most commercially valuable abilities: agentic tool use, coding and reasoning. It is also the only area of the seven where Anthropic’s most capable models were touched at all; every other case involved Haiku, Sonnet and Opus.
Alibaba · 151M exchanges, May–July
Moonshot AI · ~300,000 requests in 10 days
DeepSeek
Anthropic says the Alibaba-linked campaign peaked near
3 million exchanges a day
across more than 3,500 accounts it judged fraudulent. It says Moonshot and DeepSeek quietly routed their own customers’ requests to Claude and showed them Claude’s answers as their own.
Right of reply
Alibaba, Moonshot, DeepSeek and Xiaomi did not immediately respond to CNBC’s requests for comment. Neither did Anthropic. Counts of how many labs the section names vary across reporting, from three to seven.
The jobs it was given
From chatbot to operator
What the work actually looked like, area by area.
Cyber
Vulnerability research, exploit development, intrusions run by agent swarms
Military
Weapons software, fire-control specifications, target ranking and radar modelling
Intelligence
Open-source reconnaissance, identity profiling, scheduled collection fleets
Surveillance
Automated, government-style monitoring reports on named individuals
Propaganda
Doctrine manuals, persona systems, staff contracts, fabricated bylines
Fraud
Thousands of AI-generated personas, and the apps built to hold them
Activity is ongoing
Where the safeguards held, and where they didn’t
Anthropic says it disrupted every operation in the report and that Claude refused the most aggressive requests in several cases — naming real people as militants, producing defamatory material. It also records actors negotiating sanitised wording to keep building toward the same capability, and says of the Yemen missile work that safeguards blocked many requests but not all.
A vendor-authored account
Anthropic has direct visibility into activity on Claude, but it did not publish a full list of victims, enforcement dates, or the evidence behind every attribution. The accusations and the evidence for them come from the same company.
What the report cannot show
Anthropic’s visibility ends when content leaves its platform. It says most influence-operation material drew little or no authentic engagement, and that it often cannot determine what reached an audience.
Case attributions carry varying confidence, and Anthropic flags the weaker ones as such. Figures are the company’s own. Governments and companies named in the cases have denied the claims, said they were unaware of the report, or not responded.
Source: Anthropic; Reuters; CNBC
.
Sam Altman backs one of Amodei’s proposals
OpenAI CEO Sam Altman quickly responded to Amodei’s call. Altman said OpenAI would commit to one of Amodei’s proposals on independent safety evaluators and indicated that the company would have more to say about it soon.
I agree with Dario that we need to pace the frontier. This has been a primary topic of discussions we’ve had at OpenAI in recent weeks. Committing to having independent evaluators with employee-like access is a great idea, and we will do the same. We’ll have more to share soon. https://t.co/1YhhIybZX7 — Sam Altman (@sama) September 12, 2026
Altman’s support also comes after reports that OpenAI has been considering whether to slow the development of cutting-edge AI systems. A report published earlier this week said Altman had told staff that OpenAI could potentially pace development, possibly in coordination with other AI labs.
Elon Musk: ‘Dario is right’
Elon Musk also backed Amodei’s warning, posting on X that “Dario is right.”
Dario is right https://t.co/EwKgqQGaUo — Elon Musk (@elonmusk) September 12, 2026
Musk is himself deeply involved in the AI race through xAI, while his wider business empire includes SpaceX, which is increasingly incorporating AI.
© IE Online Media Services Pvt Ltd
The Express Global Desk at indianexpress.com which delivers authoritative, verified, and context-driven coverage of key international developments shaping global politics, policy, and migration trends. The desk focuses on stories with direct relevance for Indian and global audiences, combining breaking news with in-depth explainers and analysis. A major focus area of the desk is US immigration and visa policy, including developments related to student visas, work permits, permanent residency pathways, executive actions, and court rulings. The Global Desk also closely tracks Canada’s immigration, visa, and study policies, covering changes to study permits, post-study work options, permanent residence programmes, and regulatory updates affecting migrants and international students. All reporting from the Global Desk adheres to The Indian Express’ editorial standards, relying on official data, government notifications, court documents, and on-record sources. The desk prioritises clarity, accuracy, and accountability, ensuring readers can navigate complex global systems with confidence. Core Team The Express Global Desk is led by a team of experienced journalists and editors with deep expertise in international affairs and migration policy: Aniruddha Dhar – Senior Assistant Editor with extensive experience in global affairs, international politics, and editorial leadership. Nischai Vats – Deputy Copy Editor specialising in US politics, US visa and immigration policy, and policy-driven international coverage. Mashkoora Khan – Sub-editor focusing on global developments, with a strong emphasis on Canada visa, immigration, and study-related policy coverage. ... Read More
Stay updated with the latest - Click here to follow us on Instagram
SOURCE