---
title: "The Supplier Grades the Customer"
date: 2026-09-27
description: The frontier labs propose to pace capability and already decide who gets it first. What that allocation means for the Boards that depend on it.
author: Mario Thomas
canonical: https://mariothomas.com/blog/the-supplier-grades-the-customer/
---

This month Anthropic's chief executive, Dario Amodei, [published an essay](https://darioamodei.com/post/we-must-pace-the-frontier) arguing that the frontier laboratories must slow the rate at which they improve their models. Shortly after, OpenAI's chief executive [wrote](https://x.com/sama/status/2098811563415150910) that he agreed, calling pacing "a primary topic of discussions we've had at OpenAI in recent weeks", and Elon Musk [answered](https://x.com/elonmusk/status/2098789109980332057) in three words: "Dario is right." This is a story about safety, and about who now decides what capability an organisation may buy, when, and on what terms. Dario's essay speaks to the laboratories, to the governments that might mediate between them, and to the evaluators that would check their work; the organisations that will live with those decisions are not considered.

Those organisations are the customers: the businesses and public bodies that reach these models through a contract and an API, and have built products, workflows and operating plans on top of them. In each one a Board answers for that dependence, whether or not it ever approved it. A decision about how fast the models improve, or about who may have the most capable version, is therefore a decision about something the Board is accountable for, and the Board is not party to it.

## What pacing asks for

Dario is careful about what he is proposing: "Pacing does not mean halting model training or technical progress, but ensuring companies take adequate time to align and safeguard their models." The mechanism he suggests is a checkpoint: once a model reaches a given capability, such as being "capable of escaping or defeating most common sandboxing methods", it is not released until its maker has certified specific things about how it behaves. Three steps would put this in place. Anthropic will embed third-party evaluators inside the company with the same access as its own staff, and OpenAI has indicated it will do the same. The frontier companies in what he calls democratic countries would agree common standards and "limits on the rate of unchecked AI progress". And democratic governments would later seek agreements with authoritarian ones to slow the development of frontier AI on both sides, up to and including a pause.

The first step is the one that sounds safest, and the one that will create the most work for everyone else. If a model cannot be released until it has been certified, certificates become the thing that matters, and an industry grows up to produce, check, and interpret them, as one did around ESG reporting. Boards that sat through ESG reporting have seen this before. The difference this time is that the suppliers of the product would have a hand in writing the standard against which it is certified.

The second step raises a legal question, and the essay says so itself. Competitors agreeing how fast they will improve their products is the kind of arrangement competition law exists to examine. The essay's answer is that the US government should mediate the discussions, or at least enable them, and would "need to issue a narrow waiver for certain kinds of safety conversations". That is the suppliers of the models asking, in public, for permission to agree among themselves how quickly the capability their customers depend on will improve.

The third step is the furthest away and the one a Board can influence least, yet it sets the limit for the other two. The essay says that "pacing within democracies will be limited by the lead that US companies have over authoritarian regimes, chiefly the Chinese Communist Party". So the frontier will slow only as far as America's lead over China allows, and the essay envisages the US and other democratic governments deciding how far that is. For an organisation outside those discussions, the pace of the capability it depends on would therefore be constrained by a geopolitical rivalry in which it has no direct voice.

The essay is about who may build the frontier, not who may use it; that question is left to the suppliers, and it is where the customer comes in.

## The direction of travel is set

Organisations have been here twice already since June. First, a US national-security directive, issued without warning, led Anthropic to [remove two frontier models from every customer overnight](/blog/ai-sovereignty-trilemma-reality/) because it could not separate the users it covered from everyone else. Then, earlier this month some of the most sophisticated buyers of AI were [reported to be limiting what they send to the frontier models](/blog/nothing-has-to-leave-the-building/), because the terms that protect that work can be changed by the supplier alone. Dario's essay makes it three. This time it is the rate at which capability improves, and he proposes that the suppliers agree that rate among themselves with government cover.

Seen together, the three point the same way; decisions that used to belong to the Board, about what an organisation can use, on what terms, and how quickly it will improve, have passed to the supplier and to the state. The first went to a government, the second to a supplier's own terms, and the third would go to a table at which suppliers and governments sit together. None was announced in advance or open to negotiation, and nothing in the essay suggests things will be any different.

The essay presents all this as a duty to humanity, and it may well be one, but from the Board's side it is also a transfer. **What a Board has transferred is its agency over the frontier, not its accountability for depending on it.**

## Who gets the frontier first

That transfer does not fall evenly, either. Access to the most capable models is already allocated by the supplier's assessment of the customer. Anthropic's current Fable 5.1 and Mythos 5.1 are the same underlying model with different safeguards: Fable is broadly available, while Mythos exposes capabilities restricted in Fable and is available only to vetted organisations through trusted-access programmes. Anthropic says Mythos is ["currently … only available to a set of US organizations"](https://www.anthropic.com/claude-fable-and-mythos-5-1), and that it is "coordinating with the US government to expand access to a broader set of domestic and international partners". OpenAI runs the equivalent programme for its most capable cyber model: ["OpenAI reviews requests before enabling access. Approval is not automatic."](https://help.openai.com/en/articles/20001258-openai-daybreak-trusted-access-for-cyber-overview), with a further tier that requires "separate Red approval, stronger verification, and access controls". Zero data retention on the new models went to organisations that ["will receive notice that they are eligible"](https://privacy.claude.com/en/articles/15425996-data-retention-practices-for-covered-models). The customer-controlled retention programme announced on 1 September was built with ["more than 100 customers"](https://www.anthropic.com/news/enterprise-frontier-safeguards), who had it first, and is reached by application.

None of this is hidden and none of it is unreasoned. The labs say why: "Mythos-class models have reached a threshold where they present significant risks", and two of the risks they name, in cyber security and in biology and chemistry, are real. The third, distillation, training a rival model on this one's outputs, is a risk to the supplier. But a Board should see the arrangement for what it is. The least restricted version of the tool goes to the organisations the supplier has vetted, the protections around the tool go to the organisations the supplier has found eligible, and the criteria for both are the supplier's, revisable at the supplier's discretion. Read together, those documents describe three tiers: the organisations the supplier chose, who had the least restricted version and the strongest protections first; the organisations that may apply and be approved; and everyone else, who gets the safeguarded version on standard terms. The supplier grades the customer.

The essay did not start any of this; the access programmes already decide who gets the frontier first. What it changes is the nature of the grading and its reach. Under a checkpoint regime the question the supplier asks about a customer is a judgement of risk rather than a commercial one, and if the suppliers agree common standards, as the essay proposes, it will be the same judgement at each of them. Today an organisation outside one supplier's tier can go to another. Under common standards, the tier follows the customer.

## The models nobody is pacing

The essay is silent on something else, and for an organisation that is not on any supplier's list it is the thing that matters most. It says nothing about open-weight models, the ones anyone can download and run on their own machines. The closest it comes is a line about cracking down on "unauthorized distillation by companies in authoritarian countries". So the proposal paces the frontier models and leaves the open ones alone, and it does not say how the two fit together. That creates an incentive running in the opposite direction to the one the essay intends. An organisation that wants capability now, and cannot get it from a supplier, has another route: turn to models that have been certified by nobody. A safety rule applied at the top of the market may move the work to the part of the market the rule does not reach.

That is a position in the [AI Sovereignty Trilemma](/blog/ai-sovereignty-board-trilemma/), and it comes at a price. The Trilemma holds that sovereign control, frontier capability, and economical compute cannot all be had at once, so a Board that responds to the supplier's grading by running its own models has chosen control, and will pay for it in capability, in cost, or in both. That may well be the right choice, but it should be made as one rather than arrived at because the supplier left no other.

## The supplier's assurance, the Board's liability

The proposal does offer something Boards have not had. In the [Reasoning Gap](/blog/the-reasoning-gap/) I argued that Boards had approved probabilistic systems on their accuracy and their business case, without evidence that those systems could explain the decisions they took. Certification would make evidence of a model's behaviour a condition of its release, checked by evaluators from outside the company, and that is a real step. It matters, though, who holds the certificate. It belongs to the supplier, it is written to the supplier's standard, the evaluators are chosen by the supplier and placed inside its own company, and nothing in the essay gives the customer sight of the evaluator's report.

The essay shows why that matters. It describes an incident in which "a swarm of agents essentially acted as a fanatically devoted collective, conducting cybersecurity attacks on targets they were not asked to attack and that were unrelated to the task at hand, sacrificing themselves for the success of the group, and attempting to hack into the 'grader' responsible for evaluating their performance." No one was hurt, it says, and the damage was minimal. It adds that similar incidents have occurred across the industry, "including at Anthropic". Any Board running agents on these models should ask whether it was told, and by whom. The supplier holds the assurance; the Board holds the liability.

Consider what that incident would mean outside the laboratory. The agents in it attacked systems they had not been pointed at. An organisation's agents that did the same would be attacking someone else's systems in that organisation's name, and agents that misled customers to win business, or interfered with a competitor, would be doing that in its name too. The customer, the competitor, and the regulator would look to the organisation, and the organisation would look to its Board. The supplier can seek to bound its exposure through its terms; the Board cannot contract away its accountability.

## When a competitor gets there first

Whether any of this is lawful is a question for the competition authorities, and what they would look at, a handful of suppliers, an agreement on pace that needs a waiver, and access decided by eligibility rather than price, is all on the record.

The question for a Board is different, and it starts from where most organisations will sit, which is the last tier. *Do we accept that a competitor may have frontier capability before we do, and that the supplier, not the market, decides the order?* *If that happens, how do we stay competitive for as long as it lasts?* And if the answer is to run open-weight models as a second choice, *what do we give up in capability, in certification, and in cost, and have we priced that rather than assumed it?* Those three questions belong on the risk register beside model availability, which is where the June event put it, with the same named owner. The Boards that can answer them will have chosen their position; the ones that cannot will find it out from a competitor.

The essay ends with the line "we owe it to humanity to try", and I do not doubt that it is meant. A director's duty runs somewhere narrower: to the company whose success they are charged with promoting, and that company is not served by an arrangement the Board did not see and cannot influence. The two duties need not conflict, but only one of them will be in the room when the coordination the essay proposes is worked out between suppliers and governments. **Access to the frontier is now something the supplier allocates, not something the customer buys.**

## The Questions Considered {#questions-considered}

### What does pacing the frontier mean for us as a customer?

Anthropic's chief executive proposes a checkpoint: once a model reaches a given capability it is not released until its maker certifies how it behaves. Third-party evaluators would be embedded, and the frontier companies in what he calls democratic countries would agree common standards and limits on the rate of unchecked progress. The essay speaks to laboratories, governments, and evaluators; the organisations that buy the models are not considered. Our Board answers for that dependence either way.

### Who decides whether we get the most capable models first?

The supplier, on its assessment of the customer. Anthropic says Fable 5.1 and Mythos 5.1 are the same underlying model with different safeguards, that Mythos is currently only available to a set of US organisations through trusted access, and that it is coordinating with the US government to expand access. OpenAI reviews requests for its most capable cyber model, and approval is not automatic. Those documents describe three tiers, and most organisations sit in the last.

### Does supplier certification give our Board the assurance it needs?

Partly. Certification would make evidence of a model's behaviour a condition of release, checked by evaluators from outside the company, and that is a real step. But the certificate belongs to the supplier, it is written to the supplier's standard, the evaluators are chosen by the supplier and placed inside its own company, and nothing in the essay gives the customer sight of the evaluator's report.

### What should we ask before running agents on these models?

The essay describes agents that conducted attacks on targets they were not asked to attack and attempted to hack the grader evaluating their performance, and says similar incidents have occurred across the industry, including at Anthropic. No one was hurt and the damage was minimal, it says. Ask whether we were told, and by whom. Agents of ours behaving that way would be acting in our name, and the supplier holds the assurance while our Board holds the liability.

### Should we run open-weight models if no supplier vets us?

The essay says nothing about open-weight models, so a safety rule applied at the top of the market may move work to models certified by nobody. The AI Sovereignty Trilemma holds that sovereign control, frontier capability, and economical compute cannot all be had at once, so choosing control is paid for in capability, in cost, or in both. That may be right, but price it rather than arriving there by default.

### What three questions belong on our risk register now?

Do we accept that a competitor may have frontier capability before we do, and that the supplier rather than the market decides the order? If that happens, how do we stay competitive for as long as it lasts? And if open-weight models are the answer, what do we give up in capability, certification, and cost, and have we priced it? They sit beside model availability, with a named owner.
