Notes · Security
You cannot pace anyone else. You can shrink what one stolen credential reaches.
Anthropic asked the whole industry to slow down this week. Its own threat report says one crew reached more than forty corporate tenants in thirty-four hours.
Anthropic asked the whole industry to slow down this week. Its own threat report says one crew reached more than 40 corporate tenants in 34 hours.
Dario Amodei published “We Must Pace the Frontier” on September 12. The part worth reading is not the slogan, it is embedded evaluators: outside people with employee level access inside a lab, able to see training pipelines and report incidents.
Two days earlier Anthropic published its September threat report, covering December 2025 through August 2026. The numbers in it:
- One financially motivated group reached 40+ corporate tenants in 34 hours
- Another compromised 20+ organizations and stole drone SDKs
- One influence operation published 8,913 articles across roughly 70 fake sites in 20 languages
Read together they say something uncomfortable. The defense side of this is a policy proposal that needs governments to agree. The offense side already ships at machine speed.
You cannot pace anyone else. You can shrink what one stolen credential reaches.
Three checks worth an hour this week:
- What can one leaked agent token in your stack read, and when does it expire
- Whether any automated job can enumerate a whole tenant instead of its own scope
- Whether 34 hours of abnormal API volume would page a human at your company
If someone worked your systems at machine speed over a weekend, what would notice first?