Monday morning my desk is not full of yesterday’s pacing letter. It is full of the fracture lines around it. Geoffrey Hinton calls the slowdown “very sensible,” Trump says “whoever wins AI wins,” David Sacks says pace yourselves without asking for a regulatory price, and Cohere’s Aidan Gomez uses the word “cartel” out loud. In the same ~36 hours Anthropic’s threat-intel report and MIT’s HardFlow landed too. This is no longer a slogan fight. It is a fight over who writes the rules.
Let’s dig in.

Image: Political and commercial fracture lines around the pacing call – Source: oguzhan.co
🤖 AI Digest
Yesterday I summarized Amodei’s pace the frontier plan. Today the story is the reaction map. Speaking to the ABC, Geoffrey Hinton called Amodei’s warning “very sensible,” reminded listeners that many experts expect superintelligence within a decade, and said it would be foolish to push ahead before control is solved. He also refused fake precision on probabilities: not 1%, not 99%; “gut feelings.”
On the other side is Trump. Per TechCrunch, talking to reporters in Ireland, he said the US is “the most sophisticated country in the world” and wants to keep it that way “because whoever wins AI wins,” while dismissing some safety talk as “negative forces” raising issues that “shouldn’t be bringing it up.” On CNBC, Amodei named China the “toughest dilemma”: a speed limit fails if an adversary refuses to match it. Xi Jinping, at a BRICS summit, called for consensus-based global AI governance and a BRICS open-source AI community; a Trump-Xi meeting is set for 24 September. Pacing is geopolitics now, not just a lab blog.
David Sacks drew a hard line on X. If OpenAI and Anthropic truly think their models are scary enough, they should slow down, but stop pretending they need anyone else’s permission. Product liability already rewards reliability over raw power; demanding a preferred regulatory frame as the price of pacing will look like blackmail. The HN thread climbed fast. Obama’s message cuts differently: Democrats should make AI a “central” agenda and build a clear public framework; TechCrunch reports he has also been a “sounding board” for Amodei and Altman. The same week Altman told Fortune an IPO “right now would be an ill-advised moment,” citing safety.
The fracture I care about: labs are talking to markets, the White House, and rivals at once. Contract language (embedded evaluators, reporting cadence) is still thin. Political language is thick.

Image: Few seats in a closed room, or an open table? – Source: oguzhan.co
⚖️ Who gets to write the rules?
Asia Business Daily reported on 14 September that Anthropic, OpenAI, and Google have been in working-group talks since July 2026 about jointly forming a standards body for testing and auditing AI safety. Hassabis had already said DeepMind recently proposed an industry-level standards organization for advanced systems. Amodei’s second step (shared standards among democratic-bloc labs) is edging from essay into institution design.
Cohere CEO Aidan Gomez published the counter-brief on 13 September: “Who Gets to Define the Rules for AI?” He supports independent review. He rejects a handful of Silicon Valley labs setting pace and standards together behind an antitrust waiver, and he calls that shape a cartel. His historical parallels are sharp: the SEC locking in three rating agencies in 1975, Europe’s 1985 motor-vehicle block exemption. Safety as the stated goal; entry barriers as the result. Gomez’s four pillars are concrete: an evidence-based risk framework, mandatory transparency, testing scoped by that evidence, and real assurance that is not paid by the audited party. Do not let superintelligence panic crowd out voice-cloning fraud and critical-infrastructure risk, he argues.
I take the dispute seriously. Even if the pacing call points at real risks, “who sits at the drafting table” is a separate question. Closed-room safety and open-process safety ship different products.
🛡️ Threat intel: biology alarms and cyber autonomy
Anthropic’s September 2026 threat intelligence report puts cases next to the pacing rhetoric. Between December 2025 and August 2026 the company says it disrupted activity across cyber ops, influence, surveillance, scams, biological misuse, conventional weapons work, and distillation. Claude Haiku, Sonnet, and Opus show up in the cases; Fable/Mythos largely do not (one illicit distillation exception).
Science’s Jocelyn Kaiser piece splits the biology section. Anthropic describes five cases where scientists used Claude on pathogen or toxin work with potential for harm, while stating it does not assert harmful intent. Researchers used VPNs or intermediate servers to look like they were in allowed countries; accounts were banned, and in at least one case access paths reappeared. Andrew Weber called the cases “chilling.” Gigi Gronvall and Gregory Koblentz argue the same facts can look like ordinary dual-use research, not a weapons program. Lentzos welcomes the transparency; Andersen worries company blocks already stop legitimate genome queries.

Image: Biology alarm and cyber autonomy in one report – Source: oguzhan.co
On the cyber side the report is less speculative. GTG-20006 (tradecraft consistent with Midnight Blizzard) automated recon, phishing, persistence, and exfiltration against Ukraine/Europe targets, including a loop that rebuilt malware when detections fired. Suspected ShinyHunters affiliates used “vibe hacking” to steal terabyte-scale data in hours and then ran attack compute on stolen AI API keys. GTG-10007 ran agent swarms for parallel recon and zero-day research loops. Anthropic’s summary line lands: sophisticated attacks no longer require sophisticated attackers. AI closes the labor and tooling gap.
Set beside Amodei’s OAI-HF warning, the picture sharpens: the live risk is not only “someday superintelligence.” It is scale, speed, and the API-key economy today.
🧪 HardFlow: when “pretty close” is not enough
Per MIT News on 14 September, Zeyang Li, Kaveh Alim, and Navid Azizan published HardFlow in IEEE TPAMI. Instead of forcing every intermediate sample onto the constraint manifold, they treat sampling as trajectory optimization and enforce hard constraints on the terminal output. Tools from model predictive control make the surrogate tractable. No retraining: plug-and-play at deployment on pretrained flow-matching models.
In robotic manipulation, maze navigation, and text-guided image editing, HardFlow hit perfect constraint satisfaction and better solution quality than projection baselines. Collision-free and shorter paths can be optimized together. Azizan’s line is plain: generative models explore a rich space; the real world draws hard boundaries. HardFlow tries to keep both.

Image: A trajectory that satisfies hard constraints at the end – Source: oguzhan.co / MIT HardFlow idea
While the pacing debate says “train slower,” HardFlow says “lock the output to physical or safety bounds.” They are not rivals. One is policy tempo. The other is an engineering constraint. On the product side, the second one helps me sooner.
📡 Signals
Nathan Lambert’s open-source AI reading list, updated 13 September on Interconnects, sits next to Gomez’s closed-room critique as a practical antidote: treat openness as a gradient across licenses, run cost, and data access, not a binary. A solid starter pack if you are about to write policy prose.
Three things I will watch next: whether the standards-body working group produces a public draft; whether the biology cases in Anthropic’s report get independent scrutiny; and whether terminal hard-constraint methods like HardFlow migrate into agent/harness layers. If pacing stays a slogan colliding with politics, it fades. If rule-writing process and incident reporting become measurable, it sticks.
That was Monday’s digest. I will look again tomorrow. 🙋♂️