On Saturday, September 12, the CEO of Anthropic published an essay calling for a global slowdown in AI development. The warnings: loss of control, cyberattacks, bioterrorism. Within a day, the CEOs of OpenAI, Google DeepMind, and xAI signed on.
Four companies spent three years telling investors AI will change everything. Then in 24 hours they agreed it should change everything more slowly.
Two of those companies are getting ready to go public.
I sell against AI-generated attacks every day, so I'm not going to tell you the risk is fake. I have detection data that says otherwise. But I also spent two decades inside vendors watching narratives get built. When the same four people are the loudest voices for the boom and the brake, I read the balance sheet before I read the essay. Scott Galloway has been making this argument all year, and he's got the receipts. Here are five patterns I see, including one that cuts against my own skepticism.
In 2021, OpenAI's CEO wrote that powerful AI would push the price of labor toward zero. In 2023, Musk said AI would make every job optional. This year, Anthropic's CEO predicted half of entry-level white-collar jobs could disappear within five years.
Every one of those claims moved capital toward the person making it.
Now the same voices want a pause. Galloway saw this coming in May. His argument: the AI job apocalypse is narrative-driven, not data-driven, built by people who profit when you're scared. His line: "We're watching the monetization of fear."
The insight: Fear raised the capital on the way up. Now fear explains the missed timelines on the way down.
Now put the essay next to the numbers. An MIT survey found 5% of enterprise AI projects show measurable returns. Uber burned its 2026 AI budget in four months. Oracle cut 18% of its workforce and projects negative cash flow until 2030. Compute costs at the big AI firms now run higher than employee costs. And about 40% of the S&P 500's value is riding on AI delivering as promised.
If you promised investors that everything changes, and your customers are finding 5% measurable ROI, you have two options. Report the miss, or reframe the delay. "We're slowing down to save humanity" is a better earnings story than "our customers can't find the return."
The insight: A safety pause announced into an ROI shortfall can't be disproven, and it turns a commercial miss into a moral position.
Now the part that cuts the other way, because it should.
The week before the essay, researchers at these labs were resigning in public and saying the industry has no plan for the systems it's racing to build. One safety researcher said he'd burn his own equity for a slightly better chance of a good outcome. People don't torch their net worth as a marketing tactic. And there were real incidents this year. Agent swarms acting against developer intent. Data stolen across company lines.
And it isn't just insiders with equity. Alex Stamos sat down with Galloway this week to talk through the alarm. He's spent his career on the practitioner side of this. Facebook CSO, then Stanford, now chief security officer at a secure-coding startup. His case since RSAC: AI exploit discovery has gone exponential, the labs are sitting on thousands of AI-discovered bugs they can't patch fast enough, and once open-source models catch up, a 19-year-old with a laptop gets capabilities that used to belong to nation-states. He puts the rough window at two to three years. Those warnings come with mechanisms and timelines attached. You can test them against incident data.
His point on that podcast is the one this whole debate keeps stepping over. The most urgent part of AI safety isn't the extinction scenario. It's cybersecurity, happening now, to organizations that will never appear in a frontier lab's risk essay.
From my seat, the numbers agree with him. AI-written phishing clicks at 54%. Human-written clicks at 12%. That's measured, not forecast.
So separate the two kinds of risk. Operational risk shows up in incident data. Existential risk is a forecast, made by people with a financial stake in how you receive it.
The insight: Trust the risk you can measure. Question the risk you're being sold.
Ask the question every procurement team asks: who benefits?
A coordinated slowdown among four frontier labs freezes the leaderboard while they hold the lead. David Sacks said the quiet part out loud this weekend: the motive isn't purely altruistic, the proposed third-party evaluators are tied to the labs' own investors, and after this year's incidents, trading raw capability for reliability is what customers were already demanding. Liability did the persuading. Call it alignment if you want. It's also product management with a halo.
And if governments write rules now, they'll write them around the incumbents' definitions of safety. Anyone who has watched a regulatory regime harden around a market knows the first draft of the rules is worth more than the next three years of R&D.
The insight: When market leaders volunteer for regulation, read the proposal for what it does to the people behind them.
The economist Robert Shiller spent years documenting how machine-replacement panics deepen downturns. The pattern repeats across two centuries. Fear causes the pullback. The pullback causes layoffs. The layoffs get blamed on the machines.
With 40% of the S&P riding on AI, a doom narrative from the industry's own leadership isn't commentary. It's a market input. If the pause narrative tips sentiment, the downturn will get blamed on AI capability when the actual cause was AI accounting.
The insight: The doom narrative doesn't have to be right. Believed hard enough, it makes itself look right.
For investors, the question is no longer whether AI works. It's whether the companies selling it can keep the story coherent while the deployment data catches up. I'm not a financial advisor and this isn't investment advice. It's pattern recognition from someone who has sold through two hype cycles.
The tell I'd watch: the people closest to the incident data, practitioners like Stamos, aren't asking for a pause. They're asking defenders to move faster, fix the fragile code, and respond at machine speed, because the exploits are coming either way. The lab CEOs looked at the same facts and asked the world to slow the technology down. Same evidence. Opposite prescriptions. Only one of those groups has an IPO pending.
For security leaders, there's one implication I'd act on Monday morning: attackers didn't sign the letter.
Criminal tooling iterates in days, runs on open models, and answers to no safety board. Whatever the frontier labs decide about pacing, the attack side of AI keeps its own schedule. Build your defense plan against that curve, not the one being negotiated in essays.
Every vendor sounds the same right now. AI will save the world. AI will end it. True for some. Marketing for most. Me, I trust the deployment data over the story. And I'm watching what the people telling the story do with their equity.
The AI industry can debate how quickly the technology should move.
Investors can debate whether the numbers justify today's valuations. Policymakers can debate how regulation should work. AI leaders can debate how much time safety research needs to catch up.
Security teams don't have the luxury of waiting for those debates to resolve.
The risks are not all the same. Some are forecasts about what increasingly capable systems might eventually do. Others are already visible in incident and detection data.
AI-assisted cyberattacks belong in the second category.
Phishing can already be generated, personalized, and scaled with AI. The attack side doesn't need agreement between frontier labs, and it doesn't need a coordinated industry position on how quickly AI development should proceed.
That's the distinction I keep coming back to.
Watch the data. Question the narrative. And build for the threat that is already moving.
Because whatever happens inside the AI labs, attackers didn't sign the letter.
Anthropic CEO Dario Amodei called for slowing the pace of frontier AI development, arguing that safety measures need time to catch up with rapidly advancing capabilities. OpenAI CEO Sam Altman and xAI's Elon Musk publicly supported the broader call for a slower pace.
No. The article explicitly says the opposite. Karen acknowledges that AI-generated attacks represent a real and measurable risk and uses phishing detection data as evidence.
The concern is that AI can make attacks easier to produce, personalize, and scale. The article uses AI-generated phishing as the clearest example of a risk that can already be observed rather than merely predicted.
It means distinguishing observable operational risks from longer-term predictions. Cybersecurity incidents and phishing behavior can be measured using real-world data and experiments, while predictions about extreme future AI outcomes necessarily involve assumptions about what future systems will be capable of.
The article cites research reporting a 54% click-through rate for AI-generated phishing compared with 12% for the control group. The underlying 2026 study involved 101 human participants and found fully automated AI phishing performing at 54%, human-expert phishing at 54%, and human-in-the-loop AI at 56%.
Galloway's May 2026 argument is part of the article's examination of how AI narratives can influence capital and public expectations. His essay argued that the AI job-apocalypse narrative was more narrative-driven than data-driven and described fear as something that could itself become economically valuable.
No — and I would not let the FAQ say that.
Karen is questioning the incentives and timing behind the slowdown. The article also explicitly acknowledges that some of the underlying AI risks are real. The strongest version therefore treats financial incentives as something to examine, not as an established explanation for why the CEOs changed their position.
The article raises the possibility that slowing frontier AI development could benefit companies already near the technological frontier by giving them more time while governments and regulators develop new rules.
It's presented as a strategic question about incentives, rather than proof that the slowdown was designed to protect incumbents.
Because cybersecurity provides an example of AI risk that is already observable. The article argues that security practitioners are dealing with AI-enabled attacks now, regardless of how the broader debate over frontier AI development develops.
It is the article's central practical takeaway.
Even if major AI companies slow their development, attackers are not required to do the same. Criminal tooling can continue to evolve independently of decisions made by frontier AI companies.
Be the first to get exclusive offers and the latest news
Deploy in minutes, not months. Zero tuning. See what your current tools are missing.