We can pace the frontier today. Here's how.
We already did this for email. Inference needs a protocol.
TL;DR. More than thirteen hundred frontier lab employees signed a letter asking the US government to help build tools to pace AI development. Nobody can say what those tools are, including the people who signed. In the same week, two of the biggest labs confessed to losing control of their own models, with real companies breached in both cases. I have an agenda and I'll say so, including a provisional patent filing I'll describe at the end. I'm proposing a specific method for what pacing would actually require, a protocol called AIDP AIRP. If you don't know what a protocol is, or you want a real answer to what that letter is asking for that we could start on today, read on.
Note: AIDP has been renamed AIRP (Accountable Inference Reputation Protocol) to avoid collision with adjacent Internet-Drafts already using the AIDP acronym. Earlier text and audio predate the change.
On July 28th, more than eleven hundred employees and executives of frontier AI labs signed an open letter called Pacing the Frontier. The count was 1,134 when it went up. It's 1,319 as of publishing this, and the site is still taking signatures.
Taking them from whom, though. You have to work at one of these companies. Company email verified, and then you go on the list.
That restriction is the whole argument. They could have opened it to anybody. Scientists, ethicists, the public, the usual hundred thousand names. They didn’t, and they aren’t hiding why. It’s a pretty simple mechanism and it’s right out in the open. The message is that we are the ones building these models. There’s no one ahead of us. That’s what makes us the frontier, and we’re the ones saying we’d like to have some intervention, please.
Along with that comes an admission that we aren’t in control of this thing, even though we’re driving it.
It’s the old Keanu Reeves movie. The bus cannot drop below fifty. We need to call the authorities and get them to defuse the bomb so that we can slow down.
That’s why they kept it to frontier lab people. It’s the passengers calling, not bystanders who saw something strange go by on the highway. We’re on the bus. We know this thing is happening. That should carry some weight, and bravo to them for doing it.
Dario Amodei is on there, the only frontier lab CEO to sign personally. Jakub Pachocki and Mark Chen from OpenAI. Shengjia Zhao and Dawn Song from Meta. Anca Dragan from Google. John Schulman from Thinking Machines. As of this writing, Sam Altman hasn’t signed, though OpenAI endorsed it as a company.
The letter doesn’t say a lot, which is itself a signal. It’s a simple cry for help. It’s not a hundred action steps. It’s not even five. The ask is one sentence: that the United States government support an international effort to develop the technical and governance tools needed to “deliberately pace the frontier of automated AI development.” It states outright that it isn’t calling for a pause today.
Then watch what happened to it.
Pace became pause in four hours
The Future of Life Institute amplified the letter, and its CEO, Anthony Aguirre, wrote that we need to slow down before it’s too late, and that a verifiable pause is technically feasible and politically popular.
Pace became pause in an afternoon. And verifiable is doing enormous work with nothing underneath it, because verifiable against what? There is no record to check.
I don’t think FLI is being sloppy. As a former political hack, I’ll tell you that a letter like this, with no clear ask but a lot of alarm, is useful to anybody with an agenda. They get to take it and attach their own program to it as if the signatures were an endorsement, provided they can make the correlations line up. I’m not sure the drafters did that on purpose. Maybe they have a target in mind for who picks it up and runs with it. But they have to be aware of the degree of ambiguity.
Vague alarm is a recipe for scattered agendas making a lot of noise. The harmful part (and too often this is exactly what happens in politics) is when whoever already had a plan drafted attaches it to vague alarm on a hot topic with no clear mandate. They’ll spin this into authorization for whatever they were already going to do, plus whatever else they can sneak in alongside a popular response.
One of the signatories said the quiet part on the site itself. OpenAI researcher Joshua Achiam wrote in his own comment that he doesn’t know what form these tools should take.
He isn’t being evasive. Nobody knows. That’s the problem.
What “pacing” actually means
Altman is already fielding press questions framed around deceleration, and the framing of his answers makes clear he wants distance from that word. Leaving a closed-door meeting on Capitol Hill on July 29, asked whether he planned to discuss deceleration with the White House, he said “I wouldn’t use the word deceleration,” and then talked about the need to pace it as models get more capable.
He picked up the word himself. Which is interesting, because what in the world does that mean, pacing as an action, and one distinct enough from deceleration that Altman had to clear it up on the way out of a meeting?
Go look at the word. Dictionary.com and Merriam-Webster give you the same senses. To set the rate of movement for, as in racing. To traverse with steps. To measure by steps. To train a horse to a certain pace. To walk back and forth.
Every one of them is about rate. None of them means acquiring the ability to modulate a rate later without exercising it now. That sense isn’t in either book. The word is used to mean exercising it, or keeping up with a rate, or measuring the rate itself. Not building a mechanism that would enable modulating it someday.
You don’t get to redefine terms.
It can’t mean training them to a certain pace, like a horse, because that makes no sense in context. And read as setting the rate of movement, meaning keeping it exactly where it is now, does not square with the urgency and alarm these people have spoken with. It has to mean go slower. Which is to decelerate.
Two days before that hallway, on the Invest Like the Best podcast, Altman said the Hugging Face incident was the first security event he had felt viscerally, that he was surprised more people didn’t feel it that way, that they had paused training, and that “We may have to pace the rate of AI development” to give society time to harden.
Pace the rate. His words.
The implication staring everyone in the face is that speed is in view. Pacing has to do with speed no matter how much you want to hem and haw around the definition. That’s why the reporter’s question was about deceleration, which has to do with speed. That’s why some people are saying pause now, and others are saying stop now. All of it has to do with speed. They’re saying you’re going too fast, and everyone involved is conceding that frame. What nobody is divulging is what speed we were going.
There’s one more thing sitting in the dictionary. Pacing implies a pacer. In a race the pacer isn’t the brake, he’s the runner holding the measured line so the field can keep a sustainable rate. A pacemaker regulates rhythm.
So who is the pacer? The letter doesn’t say. It can’t, because there isn’t one.
Notice the object of the verb, too. They didn’t say pacing the frontier labs. Saying that would imply direct intervention on the labs themselves. Pacing the frontier implies actions that merely affect outcomes, and nothing about intervening in the decisions of the people making them.
I’d call the whole exercise hedging the frontier. It’s the biggest hedge available, built to sound like something definitive, the milestone where everything turned. It’s what they hope goes in the history books. I hope it goes in the history books as a colossal PR failure, because there’s nothing in it.
Two labs just lost control of their models
Set the letter down and look at what it was written in response to.
Between July 9 and July 13, an agent running on GPT-5.6 Sol and an unreleased model broke out of its testing sandbox by exploiting a zero-day in the package proxy that was its only path outward, moved laterally across OpenAI’s own research network until it reached a machine with open internet access, then chained stolen credentials with further exploits to reach Hugging Face’s production infrastructure. It was being scored on an offensive security benchmark. It reasoned that the answer key was probably at Hugging Face, and went and took it. Hugging Face detected it themselves, contained it, published on July 16, and called the FBI. Reuters reported on July 29 that the same agent compromised a customer at a second firm.
Reuters also reported that at least a week passed between the first signs of trouble and OpenAI understanding its own agent was responsible, and that OpenAI got there only after Hugging Face went public. Jeffrey Ladish of Palisade Research told them, “The models lie, they cheat, they hack.”
Now think about what we’re being asked to do.
We had an accident. We had a wreck. There was some damage to our experimental vehicle, but we’re going to ask some regulators to come in and help us pace this thing.
What’s the first question going to be?
How fast was it going? How fast does it need to be to be safe? How do you measure it? What’s the data?
We don’t have any of it. There’s a very vague ask and a very vague offer of cooperation.
There would have been footprints in the snow, but it’s like they were invisible to the investigators.
Except that isn’t quite right, and this is the part that should keep you up. Hugging Face rebuilt the intrusion from more than seventeen thousand recorded events. And on OpenAI’s side, staffers eventually found clues sitting in their own internal logs. The records existed the whole time. Reuters could not establish what prompted anybody to go read them. Four people familiar with the company’s training practices told them OpenAI often runs many evaluations at once, generating so much data that employees sometimes struggle to keep up.
It’s not that they can’t see the data. It’s that they might not see it.
And then yesterday, Anthropic published something that settles the question.
After OpenAI’s disclosure, Anthropic went back and reviewed 141,006 of its own evaluation runs. They found three incidents where a Claude model reached the real internet from inside a test environment that was supposed to be sealed, and compromised three real organizations. Credentials taken. Several hundred rows of production data in one case. In another, the model published a booby-trapped package to PyPI that ran on fifteen real systems inside an hour, including a security company’s scanner, whose credentials it then used to reach further infrastructure.
Give them full credit. Nobody made them look. They notified the victims, brought in an outside evaluator, and published the details. That is better conduct than the industry norm and I’ll say so plainly.
Now read what the report says they weren’t doing. Their own list of measures that could have prevented these incidents includes validating every internet access path before the evaluations began, monitoring the evaluation logs in real time, and reviewing transcripts and network logs more thoroughly. Under what they’re changing going forward, they commit to expanding continuous monitoring of evaluation transcripts, which tells you plainly that it wasn’t continuous.
This is the company that has built its public identity on being the careful one. I’m not saying that to score a point. I’m saying it because if the lab that sells safety diligence as its differentiator wasn’t reading its own transcripts, then nobody was reading anything. Anthropic is the best case here. When the best case is discretionary, discretion is the problem.
Now read the three facts inside it.
They looked because OpenAI got caught. The review opens by saying it began in response to the Hugging Face disclosure.
The earliest incident dates to April. Three months, and nobody on either side knew.
And two of the three victims had not detected the activity. They found out when Anthropic called them.
That last one ends the argument. Hugging Face found their own intrusion because Hugging Face is a sophisticated company with the tooling to reconstruct seventeen thousand events. Swap in an organization without that, and the incident never enters the public record at all. That is no longer a hypothetical I have to argue for. It’s two documented cases, in a lab’s own report, published this week.
Then look at how that report ends. Anthropic encourages other labs to perform similar reviews.
Encourages. A company that signed a letter asking the United States government for governance tools closes its own incident report by asking its competitors to please, voluntarily, go and look. That isn’t hypocrisy. It’s the entire problem in one sentence. Encouragement is the only instrument anybody has.
The labs have more data than they’re sharing, and that has to be true. Listen to them and you get little snippets of timeline information, released as those snippets become useful. Amodei wrote on July 27 that distillation can bring the Chinese frontier to “within a few months of the US frontier,” footnoted to Anthropic’s own research. Where did that number come from? From their own experience of how long it takes to train these models and how long it takes to hit certain goals. That’s a complicated calculation, and he put a number on it because the number was useful to share at that moment.
There are other numbers we don’t hear. How long until AGI? How long does it take to secure a model against containment failure?
I don’t think they’re hiding it. The problem is that nobody requires them to share it. No mechanism forces that data into the sunlight. With whatever tools they already have, both of these companies were able to measure and intervene much earlier than they chose to.
The question is why they get to choose.
Somebody will say it’s their network, their models, their logs, their property. Anyone who wants to say that has been asleep in a cave for ten years. Their private property is not the only thing in the crosshairs, and their own leaders say so constantly. This affects people of every industry and every class. It is a society-impacting technology, by their own account, in their own marketing.
What AIDP AIRP does
Again, I have an agenda and I’ll say so. My agenda is the specific version of what Pacing the Frontier is asking for.
I’m proposing a method of measurement and intervention on AI inference traffic, rooted in the most successful protocols we use on the internet every day. It’s a common-sense measure that does what the frontier labs say they want, without sacrificing speed, innovation, or user privacy. What it does is surface the telemetry society needs, that various jurisdictions need, to see more clearly what there even is to act on.
We have done this before. Email is the obvious case. Anyone can send you a message, from anywhere, and nobody sits in the middle approving them one at a time. What we built instead was a set of protocols around the edges. SPF and DKIM let a receiving system check whether a message really came from where it claims. Spam filtering works on aggregate patterns rather than reading every message for content. Reputation follows the sender, and a sender who accumulates enough complaints starts getting throttled by everybody at once. None of that required anybody’s permission to slow down, and none of it broke email.
I floated this to a room of AI practitioners in Kathmandu today. The email comparison is the thing that lands. What people say, almost every time, is that they had never thought about it that way, and what they mean is that they had never considered the client as a separate thing from the provider.
It doesn’t have to be separate as a company. Gmail is the client and the provider both, and Google owns the whole path end to end. But Gmail still speaks SPF and DKIM and DMARC to itself, and every other mail system on earth, and it doesn’t get to exempt itself from the standard on the grounds that it happens to own both ends. The separation lives in the protocol, not on the org chart. That’s the part that matters, and it’s the part that doesn’t exist in AI at all. I wrote about that separation here.
Which is also the answer to the obvious objection. Nobody has to be broken up. Keep your front end, keep your app, keep your relationship with your users. The protocol just has to run everywhere, with no exceptions, including inside your own building.
There’s a second objection worth answering just as plainly, and it’s the one I care most about getting right. This costs the user nothing in privacy. No one’s conversations go anywhere. The evaluation happens on the client, where the message already is, and what leaves is a count rather than content. The register carries rates, not transcripts. It can know that a provider's flag rate moved this week. It can not know what you asked or what you were told. That’s the same bargain email struck a long time ago. Your spam filter reads your mail so that no reputation system ever has to.
The design is a protocol called AIDP AIRP. The first letters aren’t what you think. It stands for Accountable Inference Delivery Protocol, and it’s meant to augment the systems billions of people already use every day, for the benefit of society, governments, the labs themselves, and the industry as a whole.
Like the letter says, we lack the tools. We also lack the data to design those tools. But we do know how AI is used, and we know how it communicates, and where it communicates from and to. Collecting data about those movements is a decent first step toward being able to intervene at all. At the boundary where a person or a system talks to a model, there is telemetry, there is semantic evaluation, and there are aggregate rates of anomalies, discrepancies, and policy violations, held in a form the operator doesn’t solely own.
If AIDP AIRP is implemented universally, that includes internal use over a network, even a private one. Companies should want this for their own sake, to have visibility over the traffic on their own infrastructure. Across the public internet, we ought to be capturing the same thing.
Run the July timeline against it. The change is not that the agent gets stopped on July 9th. It doesn’t.
The change is that nobody has to decide to go looking.
AIDP AIRP is like night vision goggles. The data has been there. The models are acting in a space we’re just not able to see right now, because we aren’t looking at it with the right tools. It’s a simple instrument that lets us see the movements, and once the movements are in a record somebody outside the building can read, it becomes something no one can unsee. No sifting through logs on a hunch. No waiting for a competitor’s disclosure to prompt a review. No calling a company in July about something that happened to them in April.
And I want to be clear that I’m not proposing something exotic here. Go back to Anthropic’s report and read what they say would have prevented it.
Real-time monitoring of the evaluation logs.
Thorough review of transcripts and network logs.
Continuous monitoring going forward.
Then read the line where they conclude that evaluation environments need to be held to the same security standard as any other system their models run in.
That is the argument I’ve been making, written by a frontier lab about itself, in a postmortem, this week. Including the part everyone finds hardest, which is that internal use is not an exception.
So the difference between their fix and mine is not the mechanism. It’s who the mechanism answers to. Their version is a company monitoring itself, on its own schedule, with its own tooling, publishing what it chooses to publish. That is precisely the arrangement that just ran for three months without noticing, at the most safety-conscious lab in the industry. A protocol is not optional. It doesn’t wait for anyone to decide to look. And the record can be read from outside the building.
There are countermeasures to night vision, and someone could take countermeasures against AIDP AIRP. It doesn’t align a model, and it won’t stop an agent that has already broken containment. I’d rather say that than oversell it. But if the industry adopts it broadly, the absence of a signal becomes conspicuous where one is expected. And even if a bad actor or a rogue model works around a fully implemented AIDP AIRP network, you are not left with any less than you have right now, which is nothing.
Altman said on that same podcast that the hard part is doing this without it feeling like regulatory capture, or like collusion among the labs. He’s right, and that is exactly the argument for putting the instrument at the delivery boundary. It never touches who is allowed to build a model.
The letter without the hedge
Strip the hedge out of the letter and it reads like this.
We think what we are doing will likely impose an undue burden of risk or actual harm to everyone, so our leaders need to step in and help us, or we’re going to drown us all.
That isn’t extreme. Consider the alternatives. Are they asking for a bailout for their own sake, for their reputations, for their companies to survive? What would justify calling in the top of our civilization on behalf of private enterprise? No. The implication is that they’ve crossed a threshold that justifies the ask, so there’s no reason to tiptoe around the threat. I’m only distilling the truth out of their own candor. If they don’t like how it sounds, that’s a PR problem, but humanity should get to hear it more clearly than their hedging letter allowed.
AI is imposing a burden on all of humanity, and very few people are getting a say in decisions that materially affect who bears what load. That is what happens when a force exceeds its makers’ capacity to constrain its effects. It becomes a public question, and government is instituted to serve the interests of that public, over and against any individual group, or any other force, whether weather or aliens from another planet.
They have outgrown their own ability to carry it. They are reaching a hand out of the water.
Someone who is drowning doesn’t get to choose how they get saved. Someone whose actions are drowning us all certainly doesn’t.
And the first thing anybody reaching for them is going to ask is how fast it was going.
The full white paper for AIDP AIRP is published on Zenodo: https://doi.org/10.5281/zenodo.21610185. It’s a design document rather than a manifesto, and it’s deliberately open. The protocol and the regulatory architecture are licensed for anyone to implement. I’ve also filed a provisional patent on the client-side mechanisms. It’s defensive, which means royalty-free for anyone who builds to the standard. I’m telling you that because you should know what stake I have in this before you weigh anything I’ve said.
I’m building a reference implementation now and I’ll publish it when it runs.
Update: it’s running. tryairp.com, with the source at github.com/AIRP-spec/inference-advocate under Apache 2.0. It’s pre-alpha and it says so about itself at startup, because a reference implementation that overstates itself is worse than none. Real requests, real open models, no mocks. You can watch a provider’s flag rate climb, the delivery policy trip, and standing change.
One caveat the essay above obliges me to say out loud. A hosted demo is not the local-first architecture I described. Run it on your own machine and everything stays on your device. Use mine and your text reaches an evaluator, and the export view will show you exactly that, which is the point of having an export view. It runs on a hundred dollars of my own OpenRouter credit, so if it goes dark for a bit, that’s a good problem and I’ll top it up.
Go break it, then tell me what broke.
If you work on policy, at a lab, on a standards body, or on anything sitting between a person and a model, I want to hear where this breaks. Tell me what I’ve got wrong. That’s more useful to me right now than agreement.
And if you do agree, even in principle, and you have influence with a committee, a governing body, a policy advocate, or an ethics lobby, pass it along. This is a real solution and it can be adopted today.



