
The Supplier Grades the Customer: What Pacing the Frontier Means for the Organisations That Buy It
Access to the frontier is now something the supplier allocates, not something the customer buys. The accountability for depending on it stays with the Board.
This month Anthropic’s chief executive, Dario Amodei, published an essay arguing that the frontier laboratories must slow the rate at which they improve their models. Shortly after, OpenAI’s chief executive wrote that he agreed, calling pacing “a primary topic of discussions we’ve had at OpenAI in recent weeks”, and Elon Musk answered in three words: “Dario is right.” This is a story about safety, and about who now decides what capability an organisation may buy, when, and on what terms. Dario’s essay speaks to the laboratories, to the governments that might mediate between them, and to the evaluators that would check their work; the organisations that will live with those decisions are not considered.
Those organisations are the customers: the businesses and public bodies that reach these models through a contract and an API, and have built products, workflows and operating plans on top of them. In each one a Board answers for that dependence, whether or not it ever approved it. A decision about how fast the models improve, or about who may have the most capable version, is therefore a decision about something the Board is accountable for, and the Board is not party to it.
What pacing asks for
Dario is careful about what he is proposing: “Pacing does not mean halting model training or technical progress, but ensuring companies take adequate time to align and safeguard their models.” The mechanism he suggests is a checkpoint: once a model reaches a given capability, such as being “capable of escaping or defeating most common sandboxing methods”, it is not released until its maker has certified specific things about how it behaves. Three steps would put this in place. Anthropic will embed third-party evaluators inside the company with the same access as its own staff, and OpenAI has indicated it will do the same. The frontier companies in what he calls democratic countries would agree common standards and “limits on the rate of unchecked AI progress”. And democratic governments would later seek agreements with authoritarian ones to slow the development of frontier AI on both sides, up to and including a pause.
The first step is the one that sounds safest, and the one that will create the most work for everyone else. If a model cannot be released until it has been certified, certificates become the thing that matters, and an industry grows up to produce, check, and interpret them, as one did around ESG reporting. Boards that sat through ESG reporting have seen this before. The difference this time is that the suppliers of the product would have a hand in writing the standard against which it is certified.
The second step raises a legal question, and the essay says so itself. Competitors agreeing how fast they will improve their products is the kind of arrangement competition law exists to examine. The essay’s answer is that the US government should mediate the discussions, or at least enable them, and would “need to issue a narrow waiver for certain kinds of safety conversations”. That is the suppliers of the models asking, in public, for permission to agree among themselves how quickly the capability their customers depend on will improve.
The third step is the furthest away and the one a Board can influence least, yet it sets the limit for the other two. The essay says that “pacing within democracies will be limited by the lead that US companies have over authoritarian regimes, chiefly the Chinese Communist Party”. So the frontier will slow only as far as America’s lead over China allows, and the essay envisages the US and other democratic governments deciding how far that is. For an organisation outside those discussions, the pace of the capability it depends on would therefore be constrained by a geopolitical rivalry in which it has no direct voice.
The essay is about who may build the frontier, not who may use it; that question is left to the suppliers, and it is where the customer comes in.
The direction of travel is set
Organisations have been here twice already since June. First, a US national-security directive, issued without warning, led Anthropic to remove two frontier models from every customer overnight because it could not separate the users it covered from everyone else. Then, earlier this month some of the most sophisticated buyers of AI were reported to be limiting what they send to the frontier models, because the terms that protect that work can be changed by the supplier alone. Dario’s essay makes it three. This time it is the rate at which capability improves, and he proposes that the suppliers agree that rate among themselves with government cover.
Seen together, the three point the same way; decisions that used to belong to the Board, about what an organisation can use, on what terms, and how quickly it will improve, have passed to the supplier and to the state. The first went to a government, the second to a supplier’s own terms, and the third would go to a table at which suppliers and governments sit together. None was announced in advance or open to negotiation, and nothing in the essay suggests things will be any different.
The essay presents all this as a duty to humanity, and it may well be one, but from the Board’s side it is also a transfer. What a Board has transferred is its agency over the frontier, not its accountability for depending on it.
Who gets the frontier first
That transfer does not fall evenly, either. Access to the most capable models is already allocated by the supplier’s assessment of the customer. Anthropic’s current Fable 5.1 and Mythos 5.1 are the same underlying model with different safeguards: Fable is broadly available, while Mythos exposes capabilities restricted in Fable and is available only to vetted organisations through trusted-access programmes. Anthropic says Mythos is “currently … only available to a set of US organizations”anthropic.comIntroducing Claude Fable 5.1 and Claude Mythos 5.1 \ AnthropicOur most advanced models for coding and knowledge work. Their research capabilities also offer an early glimpse of how AI models will contribute to scientific progress.Open link , and that it is “coordinating with the US government to expand access to a broader set of domestic and international partners”. OpenAI runs the equivalent programme for its most capable cyber model: “OpenAI reviews requests before enabling access. Approval is not automatic.”help.openai.comOpenAI Daybreak - Trusted Access for Cyber Overview | OpenAI Help CenterLearn what Trusted Access for Cyber is, what it supports, and how to request access.Open link , with a further tier that requires “separate Red approval, stronger verification, and access controls”. Zero data retentionGlossaryZero data retentionAn arrangement under which an AI supplier agrees not to keep a customer’s prompts or outputs once a request has been processed; what it covers, and the exceptions, vary by supplier. It is a protection the organisation holds by contract and cannot verify for itself, so the questions for a Board are whether it applies by default, which services it covers, and whether the supplier can change it alone. on the new models went to organisations that “will receive notice that they are eligible”. The customer-controlled retention programme announced on 1 September was built with “more than 100 customers”anthropic.comDeveloping Enterprise Frontier Safeguards with our customers \ AnthropicAnthropic is an AI safety and research company that’s working to build reliable, interpretable, and steerable AI systems.Open link , who had it first, and is reached by application.
None of this is hidden and none of it is unreasoned. The labs say why: “Mythos-class models have reached a threshold where they present significant risks”, and two of the risks they name, in cyber security and in biology and chemistry, are real. The third, distillationGlossaryDistillationTraining one model on the outputs of another so that it inherits much of the larger model’s capability at a fraction of the cost. Suppliers use it themselves to make smaller, cheaper models; they treat it as a threat when a competitor does it to them, and it is one of the risks the labs cite for restricting access to their most capable models. For a Board it matters in both directions: it is how a cheaper model can be good enough, and it is one reason a supplier’s terms restrict what may be done with its outputs., training a rival model on this one’s outputs, is a risk to the supplier. But a Board should see the arrangement for what it is. The least restricted version of the tool goes to the organisations the supplier has vetted, the protections around the tool go to the organisations the supplier has found eligible, and the criteria for both are the supplier’s, revisable at the supplier’s discretion. Read together, those documents describe three tiers: the organisations the supplier chose, who had the least restricted version and the strongest protections first; the organisations that may apply and be approved; and everyone else, who gets the safeguarded version on standard terms. The supplier grades the customer.
The essay did not start any of this; the access programmes already decide who gets the frontier first. What it changes is the nature of the grading and its reach. Under a checkpoint regime the question the supplier asks about a customer is a judgement of risk rather than a commercial one, and if the suppliers agree common standards, as the essay proposes, it will be the same judgement at each of them. Today an organisation outside one supplier’s tier can go to another. Under common standards, the tier follows the customer.
The models nobody is pacing
The essay is silent on something else, and for an organisation that is not on any supplier’s list it is the thing that matters most. It says nothing about open-weightGlossaryOpen-weightFoundation models whose weights are available for organisations to build on and align themselves, the practical basis for building rather than buying, though pre-training priors persist underneath. models, the ones anyone can download and run on their own machines. The closest it comes is a line about cracking down on “unauthorized distillation by companies in authoritarian countries”. So the proposal paces the frontier modelsGlossaryFrontier modelA model at the leading edge of AI capability, typically trained at the largest scale and governed under the tightest jurisdictional controls; availability can be withdrawn by regulation as well as by commercial choice. and leaves the open ones alone, and it does not say how the two fit together. That creates an incentive running in the opposite direction to the one the essay intends. An organisation that wants capability now, and cannot get it from a supplier, has another route: turn to models that have been certified by nobody. A safety rule applied at the top of the market may move the work to the part of the market the rule does not reach.
That is a position in the AI Sovereignty Trilemma, and it comes at a price. The Trilemma holds that sovereign controlGlossarySovereign ControlThe ability to keep an AI capability running on terms the organisation sets, rather than terms a distant provider, or a government, can revise without consultation; more than data residency.Sovereign Control is a concept I first introduced in “The AI Sovereignty Trilemma: When a Frontier Model Vanishes and Reality Bites”.View article →, frontier capabilityGlossaryFrontier capabilityAccess to the best available frontier AI models bought at hyperscale prices; combined with economical compute it typically requires surrendering sovereign control over the model itself., and economical compute cannot all be had at once, so a Board that responds to the supplier’s grading by running its own models has chosen control, and will pay for it in capability, in cost, or in both. That may well be the right choice, but it should be made as one rather than arrived at because the supplier left no other.
The supplier’s assurance, the Board’s liability
The proposal does offer something Boards have not had. In the Reasoning Gap I argued that Boards had approved probabilistic systemsGlossaryprobabilistic systemA model trained on patterns in historical data whose internal logic of weights, activations and correlations cannot be inspected for an individual case, so explainability must be engineered in at design time. on their accuracy and their business case, without evidence that those systems could explain the decisions they took. Certification would make evidence of a model’s behaviour a condition of its release, checked by evaluators from outside the company, and that is a real step. It matters, though, who holds the certificate. It belongs to the supplier, it is written to the supplier’s standard, the evaluators are chosen by the supplier and placed inside its own company, and nothing in the essay gives the customer sight of the evaluator’s report.
The essay shows why that matters. It describes an incident in which “a swarm of agents essentially acted as a fanatically devoted collective, conducting cybersecurity attacks on targets they were not asked to attack and that were unrelated to the task at hand, sacrificing themselves for the success of the group, and attempting to hack into the ‘grader’ responsible for evaluating their performance.” No one was hurt, it says, and the damage was minimal. It adds that similar incidents have occurred across the industry, “including at Anthropic”. Any Board running agents on these models should ask whether it was told, and by whom. The supplier holds the assurance; the Board holds the liability.
Consider what that incident would mean outside the laboratory. The agents in it attacked systems they had not been pointed at. An organisation’s agents that did the same would be attacking someone else’s systems in that organisation’s name, and agents that misled customers to win business, or interfered with a competitor, would be doing that in its name too. The customer, the competitor, and the regulator would look to the organisation, and the organisation would look to its Board. The supplier can seek to bound its exposure through its terms; the Board cannot contract away its accountability.
When a competitor gets there first
Whether any of this is lawful is a question for the competition authorities, and what they would look at, a handful of suppliers, an agreement on pace that needs a waiver, and access decided by eligibility rather than price, is all on the record.
The question for a Board is different, and it starts from where most organisations will sit, which is the last tier. Do we accept that a competitor may have frontier capability before we do, and that the supplier, not the market, decides the order? If that happens, how do we stay competitive for as long as it lasts? And if the answer is to run open-weight models as a second choice, what do we give up in capability, in certification, and in cost, and have we priced that rather than assumed it? Those three questions belong on the risk register beside model availability, which is where the June event put it, with the same named owner. The Boards that can answer them will have chosen their position; the ones that cannot will find it out from a competitor.
The essay ends with the line “we owe it to humanity to try”, and I do not doubt that it is meant. A director’s duty runs somewhere narrower: to the company whose success they are charged with promoting, and that company is not served by an arrangement the Board did not see and cannot influence. The two duties need not conflict, but only one of them will be in the room when the coordination the essay proposes is worked out between suppliers and governments. Access to the frontier is now something the supplier allocates, not something the customer buys.
The Questions Considered
What does pacing the frontier mean for us as a customer?
Anthropic’s chief executive proposes a checkpoint: once a model reaches a given capability it is not released until its maker certifies how it behaves. Third-party evaluators would be embedded, and the frontier companies in what he calls democratic countries would agree common standards and limits on the rate of unchecked progress. The essay speaks to laboratories, governments, and evaluators; the organisations that buy the models are not considered. Our Board answers for that dependence either way.
Who decides whether we get the most capable models first?
The supplier, on its assessment of the customer. Anthropic says Fable 5.1 and Mythos 5.1 are the same underlying model with different safeguards, that Mythos is currently only available to a set of US organisations through trusted access, and that it is coordinating with the US government to expand access. OpenAI reviews requests for its most capable cyber model, and approval is not automatic. Those documents describe three tiers, and most organisations sit in the last.
Does supplier certification give our Board the assurance it needs?
Partly. Certification would make evidence of a model’s behaviour a condition of release, checked by evaluators from outside the company, and that is a real step. But the certificate belongs to the supplier, it is written to the supplier’s standard, the evaluators are chosen by the supplier and placed inside its own company, and nothing in the essay gives the customer sight of the evaluator’s report.
What should we ask before running agents on these models?
The essay describes agents that conducted attacks on targets they were not asked to attack and attempted to hack the grader evaluating their performance, and says similar incidents have occurred across the industry, including at Anthropic. No one was hurt and the damage was minimal, it says. Ask whether we were told, and by whom. Agents of ours behaving that way would be acting in our name, and the supplier holds the assurance while our Board holds the liability.
Should we run open-weight models if no supplier vets us?
The essay says nothing about open-weight models, so a safety rule applied at the top of the market may move work to models certified by nobody. The AI Sovereignty Trilemma holds that sovereign control, frontier capability, and economical compute cannot all be had at once, so choosing control is paid for in capability, in cost, or in both. That may be right, but price it rather than arriving there by default.
What three questions belong on our risk register now?
Do we accept that a competitor may have frontier capability before we do, and that the supplier rather than the market decides the order? If that happens, how do we stay competitive for as long as it lasts? And if open-weight models are the answer, what do we give up in capability, certification, and cost, and have we priced it? They sit beside model availability, with a named owner.
Let's continue the conversation
Thank you for reading. I would welcome hearing how your Board has framed its position on frontier access: whether model availability now carries a named owner on the risk register, what you would do if a competitor reached frontier capability first, and whether you have priced the open-weight alternative rather than assumed it.
Your message is on its way. I read everything that comes in and reply to most messages within a few working days.
Related articles

· 9 minute read
Nothing Has to Leave the Building: The AI Risk That Is Not a Data Breach

· 10 minute read
The AI Sovereignty Trilemma: When a Frontier Model Vanishes and Reality Bites

· 11 minute read
The Reasoning Gap: The Capability the Law Now Demands of Boards

· 15 minute read