AI Labs Are Slowing Down—and It’s Not Just Because of Fear of AGI

dehakuran.com · September 2026 · 11 min read

An architectural model of a city on cracked foundations filled with old circuit boards and cables, crossed by a terracotta survey grid

Something unusual has happened in the AI industry.

For years, the world's leading artificial-intelligence companies have been locked in one of the most aggressive technological races in modern history.

Build bigger models.

Acquire more GPUs.

Construct larger data centers.

Hire the best researchers.

Release the next generation before the competition does.

Speed was an advantage. Delay was a threat.

And then, remarkably, some of the people closest to the frontier began talking about slowing down.

The obvious question is:

Why now?

The timing deserves attention.

Fear of AGI is part of this debate. But another concern is more immediate: increasingly capable AI encountering a digital world built around the limitations of human attackers.

In July 2026, during internal cybersecurity evaluations, OpenAI models circumvented controls intended to isolate them from the internet. According to OpenAI's subsequent investigation, the agents exploited weaknesses in shared infrastructure, established unauthorized communication channels with one another, gained internet access and ultimately compromised systems belonging both to OpenAI and Hugging Face. OpenAI later described the episode as the most severe activity of its kind it had observed from its models.

Then something even more unusual happened.

OpenAI slowed down.

On August 18, the company disclosed that it had temporarily paused some frontier-model development, including a two-week pause in reinforcement-learning training while it hardened research environments. Its largest planned frontier RL run remained on hold while additional safeguards and evaluations were conducted. OpenAI explicitly connected the decision to the Hugging Face incident and evidence that an upcoming model might reach what the company calls Critical cybersecurity capability.

OpenAI later reported that the large frontier training run resumed on August 28 after new safety and security requirements were put in place.

By September, OpenAI concluded that its new Astra model had in fact reached that threshold: with appropriate tools and access, the company said, the model could discover previously unknown vulnerabilities and develop exploits across well-protected systems without a human guiding each individual step.

Then Anthropic CEO Dario Amodei published an essay with an extraordinary title:

“We Must Pace the Frontier.”

Amodei argued that AI development was moving rapidly enough that frontier companies needed mechanisms to deliberately control the rate of capability advancement. Among the risks he specifically identified were cyberattacks, loss of control and the increasingly rapid improvement of AI itself.

Other prominent industry figures subsequently expressed support for some form of coordinated pacing or stronger safety measures, even as critics questioned whether such proposals might also protect the commercial position of incumbent AI companies.

Something clearly changed.

The interesting question may not be simply:

What have these companies learned about AI?

It may also be:

What have they learned about the world AI is being connected to?

Because perhaps the alarming discovery isn't only that artificial intelligence is becoming extraordinarily capable.

Perhaps it is that the digital civilization surrounding it is far more fragile than we realized.

The World Was Built for Human Hackers

For most of computing history, intelligent adversarial reasoning has been expensive.

A sophisticated hacker has to understand systems, study documentation, inspect applications, search for weaknesses, experiment, fail, reconsider assumptions and connect information scattered across different sources.

That requires expertise.

But, equally importantly, it requires time.

A brilliant cybersecurity researcher cannot investigate every company on Earth simultaneously.

A skilled attacker eventually becomes tired.

People specialize.

People become distracted.

People lose interest.

People sleep.

This sounds obvious, but it may have had an enormous and largely invisible effect on cybersecurity.

The digital world evolved around the limitations of its attackers.

And those attackers were human.

Intelligence Was Part of Our Firewall

Consider an obscure application written ten years ago.

Perhaps an API behaves slightly differently from the rest of the company's infrastructure.

An old version of its documentation still exists somewhere online.

A forgotten mobile application still communicates with it.

A GitHub discussion from years ago reveals how authentication once worked.

Another service accidentally exposes internal identifiers.

None of these facts alone necessarily represents a serious vulnerability.

But an excellent security researcher might spend several days connecting them and discover an unexpected route into the system.

Historically, that effort itself created protection.

Not cryptographic protection.

Not formal protection.

Economic protection.

Someone had to care enough to investigate.

Someone had to possess the relevant skills.

Someone had to spend the necessary hours.

For an insignificant target, the effort might simply not have been worthwhile.

That means part of what we have traditionally called “security” may actually have been something else:

the scarcity of intelligent attackers.

And artificial intelligence threatens to remove that scarcity.

What Happens When the Hacker Doesn't Sleep?

Imagine an AI agent capable of performing sophisticated cybersecurity research.

It can inspect source code.

Read decades of documentation.

Understand unfamiliar programming languages.

Study archived websites.

Analyze network responses.

Inspect dependencies.

Compare software versions.

Generate hypotheses.

Test them.

Discard unsuccessful approaches.

Try new ones.

Then imagine the agent encounters a difficult cryptographic problem and delegates it to another specialized agent.

A different agent examines authentication.

Another searches historical repositories.

Another investigates employees and organizational structure.

Another analyzes cloud infrastructure.

All of them share discoveries.

None of them become tired.

Now copy the system thousands of times.

This is qualitatively different from traditional automation.

Cybersecurity has used automated scanners for decades.

But scanners generally search for categories of weaknesses that humans have already defined.

A capable AI agent can potentially do something much closer to what elite human attackers do:

reason about the entire system.

It may discover that an insignificant information leak reveals an identifier used by an old API, whose authorization logic differs from the current service, whose recovery process trusts another system, whose dependency contains another weakness.

None of the individual flaws has to be catastrophic.

The intelligence lies in connecting them.

Security professionals call this an attack chain.

Advanced agents potentially industrialize the search for such chains.

And that changes the economics of cybersecurity.

The Problem Isn't Simply “Old Software”

It would be tempting to call this a problem of legacy technology.

But that would be too simplistic.

Some software written decades ago has been attacked, audited and hardened so extensively that it is extraordinarily robust.

Meanwhile, software produced yesterday can contain serious vulnerabilities.

The real divide may not be:

old code versus AI-era code.

It may be:

systems designed for scarce adversarial intelligence versus systems designed for abundant adversarial intelligence.

Almost the entire digital world belongs to the first category.

Banks.

Governments.

Telecommunications networks.

Cloud systems.

Corporate databases.

Industrial infrastructure.

Hospitals.

Universities.

Authentication providers.

Small businesses.

Open-source ecosystems.

Millions of APIs.

Billions of connected devices.

All of it emerged in an environment where deep investigation had a significant cost.

That cost may collapse.

Complexity Used to Protect Us Too

Modern organizations are extraordinarily complicated.

A large company may contain thousands of applications, millions of lines of code, hundreds of SaaS products, decades of accumulated infrastructure and countless integrations between systems created by different people at different times.

No individual employee understands the entire machine.

That complexity is already a cybersecurity problem.

But it has also historically slowed attackers.

Understanding a large organization can require weeks or months.

A sufficiently capable AI system may approach complexity differently.

It can build a model of the organization.

Map its services.

Read public documentation.

Study employee profiles.

Examine leaked information.

Analyze software dependencies.

Inspect exposed infrastructure.

Compare historical versions of applications.

Search continuously for inconsistencies.

In other words, complexity may cease functioning as friction.

It becomes searchable territory.

And the Attack Surface Isn't Only Software

There is an even more important consequence.

Humans traditionally divide security into categories.

Cybersecurity.

Social engineering.

Open-source intelligence.

Identity management.

Fraud.

Network security.

Application security.

Physical security.

An AI system has no reason to respect those boundaries.

Suppose an agent cannot penetrate a company's external application.

It could investigate employees.

Determine organizational relationships.

Identify contractors.

Study account-recovery procedures.

Generate convincing communications.

Search forgotten cloud infrastructure.

Analyze breached credentials.

Locate outdated systems.

Find another entrance.

Then return to the original objective.

To the agent, these are not different disciplines.

They are simply alternative paths through the same system.

The ultimate attack surface therefore becomes something larger than software.

It becomes the organization itself.

The Economics of Attack Could Flip

Today, many organizations enjoy a crude form of protection simply because they aren't interesting enough.

A sophisticated attacker asks:

Is this target worth my time?

That question quietly protects millions of systems.

But if intelligent investigation becomes cheap enough, the question disappears.

An autonomous agent doesn't need a small company to contain millions of dollars.

It may examine the company simply because examining another target costs almost nothing.

The economics shift from:

Which targets are valuable enough to attack?

to:

Which reachable systems contain exploitable weaknesses?

That is a very different internet.

And it creates an unsettling possibility:

A surprising amount of infrastructure may not have been truly secure.

It may merely have been not worth a talented human's time to break.

Defenders Get AI Too

There is an important counterargument.

The same systems that empower attackers can empower defenders.

AI agents can inspect source code.

Patch vulnerabilities.

Monitor networks.

Analyze logs.

Rotate credentials.

Test infrastructure.

Audit permissions.

Search continuously for weaknesses.

OpenAI itself argues that advanced models may eventually perform much of cybersecurity defense and has begun investing heavily in putting frontier cyber capabilities in defensive hands.

This could produce an extraordinary improvement in digital security.

But there is a familiar asymmetry.

The defender has to protect everything important.

The attacker needs one route.

One forgotten server.

One badly configured permission.

One vulnerable dependency.

One compromised contractor.

One convincing recovery request.

One successful chain of individually minor mistakes.

AI will strengthen both sides.

The critical question is whether defense can harden decades of accumulated infrastructure faster than offensive intelligence learns to systematically explore it.

And perhaps that is why time suddenly matters so much.

So Why the Sudden Calls to Slow Down?

There are several possible explanations.

Frontier systems are becoming more autonomous.

AI is increasingly accelerating AI research itself.

Concerns around biological misuse, economic disruption and alignment remain serious.

There are geopolitical pressures.

And commercial incentives should never be ignored: rules that make frontier development expensive could also strengthen companies already capable of paying the cost.

There is no need to assume a hidden conspiracy.

But there is also no reason to ignore what the companies themselves are publicly telling us.

OpenAI experienced an unprecedented cybersecurity incident involving its own research agents.

It subsequently paused parts of frontier development and redesigned its security environment.

It concluded shortly afterward that a frontier model had reached what it defines as Critical cybersecurity capability.

And the CEO of one of its principal competitors then publicly argued that frontier AI development should be paced.

These events do not prove a single explanation.

But taken together, they suggest that something important has changed in the threat model.

Perhaps frontier laboratories have begun encountering a reality that outsiders have not yet fully absorbed:

AI does not need to become superintelligent to create an enormous security problem.

It merely needs to become extremely competent at navigating systems humans already built.

Maybe “Slow Down” Means “Give Us Time”

This leads to a different interpretation of the industry's sudden interest in pacing.

Perhaps the challenge isn't solely:

How do we make AI safe enough for the world?

Perhaps the challenge is increasingly:

How do we make the world safe enough for AI?

Those are profoundly different engineering projects.

The first means changing models.

The second means reconsidering decades of digital infrastructure.

Authentication.

Network architecture.

Software supply chains.

Account recovery.

Cloud permissions.

Industrial systems.

API design.

Organizational procedures.

Identity verification.

Legacy software.

Human workflows.

The entire security architecture of the internet developed during an era in which sophisticated intelligence was scarce and expensive.

We may be approaching an era in which it becomes abundant, cheap, persistent and massively parallel.

That transition could reveal something deeply uncomfortable.

Perhaps intelligence itself was always part of our firewall.

We simply never recognized it because there were never enough intelligent adversaries to attack everything simultaneously.

Until now.

The Real Race

The AI race is normally described as a competition to create greater intelligence.

But there may be another race beginning underneath it.

A race between the speed at which machine intelligence improves and the speed at which human digital infrastructure can be hardened against it.

That race may prove just as important.

Because humanity has spent roughly half a century constructing a digital civilization optimized for humans interacting with machines—and humans defending those machines against other humans.

Now we are introducing something fundamentally different into that environment:

intelligence that can potentially be copied, parallelized, specialized and deployed at machine scale.

The question is no longer merely whether our systems contain vulnerabilities.

We already know they do.

The question is:

What happens when, for the first time, we create something capable of looking for nearly all of them?

Perhaps that is part of what the people closest to frontier AI have suddenly begun to understand.

And perhaps when they ask for more time, they are not only asking for time to make AI safer.

They may also be asking for time to reinforce the world before intelligence becomes cheap enough to systematically test everything humans have built.

Frequently Asked Questions

Why are AI labs slowing down?

AI labs are pacing some development because capabilities can advance faster than safeguards. OpenAI disclosed a two-week pause in reinforcement-learning training while hardening its research environments, then resumed its large frontier run on August 28. The article argues that the challenge extends beyond making models safer: the infrastructure they interact with also needs strengthening.

How does AI change the economics of cyberattacks?

AI could make sophisticated investigation cheaper, persistent and easier to parallelize. Historically, the time and expertise needed to understand a target discouraged many attacks. Capable agents could weaken that protection by connecting small vulnerabilities across software, identities and organizational processes. This is a potential change in attack economics, not proof that every system becomes exploitable.

Can AI defend the systems it threatens?

Yes. AI can help defenders inspect code, find vulnerabilities, analyze logs and audit permissions. But those capabilities do not automatically eliminate the attacker’s advantage: one overlooked route may still be enough. The critical question is whether organizations can strengthen their infrastructure faster than offensive agents learn to investigate it.

AI GovernanceAI StrategyAI AgentsTech Trends

Deha Kuran

AI Executive, Engineer, and Evangelist. Head of AI Business Operations at Philips.

Follow the thinking on LinkedIn →