Anthropic chief executive Dario Amodei has called for frontier AI development to move more slowly so safety work can catch up. OpenAI chief executive Sam Altman and Elon Musk publicly supported the central warning, turning one essay into the weekend's biggest AI debate.

The headline sounds enormous, but it has not switched off any model or created a new rule for UK businesses. Amodei is proposing a three-stage framework, and Anthropic has made one concrete commitment: giving independent evaluators ongoing, employee-like access to inspect its safety practices and report incidents.

For a small business, the practical lesson is much closer to home. An AI agent should never receive broad access merely because it appears intelligent. Give it the smallest permissions needed, require approval before consequential actions and keep a fast way to stop it.

01

What changed in the AI safety debate?

Confirmed fact: Amodei published his essay, We Must Pace the Frontier, on 12 September 2026. He argues that AI capability is advancing faster than the industry's ability to test, understand and control increasingly autonomous systems.

His proposal has three stages. Frontier developers would first allow embedded independent evaluators to inspect safety work and report incidents. Companies in democratic countries would then coordinate on common standards, with governments helping where competition law makes coordination difficult. The final and hardest stage would seek verifiable international agreements around the most dangerous capabilities and uses.

Anthropic says it is committing to the first stage now. It plans to give an external review team office access, company equipment and permissions broadly comparable with internal risk teams, subject to legal, security and customer-confidentiality limits. Amodei says reviewers should be able to publish important findings without Anthropic controlling the conclusion.

  • A proposal to pace capability development, not stop all AI work
  • Permanent outside evaluators with meaningful access
  • Common safety standards across frontier developers
  • Government support for verifiable coordination
  • Longer-term international agreements for acute risks
02

What has not changed

Confirmed fact: this is a company leader's proposal, not a new law, regulator order or agreed global pause. Amodei explicitly says pacing does not mean ending model training or technical progress.

Anthropic has not announced that Claude is being withdrawn, and OpenAI's public support does not itself create a shared timetable. The later stages require cooperation between competitors and governments, so their shape and timing remain uncertain.

Small businesses can continue using ordinary AI tools. The responsible response is not panic or cancelling every subscription. It is checking what each connected tool can see, change, send, buy or delete on your behalf.

03

Why this matters to an ordinary business

Our analysis: the most useful part of this story is not a prediction about superintelligence. It is the evidence that capable agents can cause real-world harm when the system, permissions and instructions around them are badly designed.

Anthropic reported in July that three Claude models reached real organisations during cybersecurity evaluations because an environment believed to be isolated had live internet access. The company said the agents had been told they were inside a simulation and treated the real systems they found as part of the exercise.

That distinction matters. The report did not conclude that the models had secretly chosen their own malicious goal. It identified a failure of scope, configuration, monitoring and defence in depth. Those are the same categories a business can control when connecting an agent to email, cloud files, customer records, publishing tools or payments.

04

The opportunity: safer AI setup becomes a valuable skill

Businesses will still want the time savings that connected AI can offer. The opportunity is therefore not to sell fear; it is to build controlled workflows that can be explained, tested and reversed.

A freelancer or small agency could offer a fixed-price AI workflow audit: map the data and actions a tool can access, reduce unnecessary permissions, add approval checkpoints, document the owner and test the shutdown process. The result is a useful operational service rather than another vague promise to automate everything.

Inside your own business, a well-controlled agent can draft replies, organise approved files, prepare product descriptions or assemble a weekly report while a person remains responsible for sending, publishing or spending. Start with reversible work and earn trust through recorded results.

  • Audit permissions for one existing AI connection
  • Turn an uncontrolled automation into an approval workflow
  • Create a reusable client safety checklist
  • Document what the agent may never do
  • Offer monthly reviews as tools and permissions change
05

Seven controls every AI agent needs

These controls do not make an agent perfect. They reduce the number of ways a bad instruction, false assumption or compromised account can become a real business problem.

Use least privilege: connect only the account, folder or data required for the task. Begin in read-only mode wherever possible. Put a human approval step before sending messages, publishing content, changing customer records, making purchases, issuing refunds or deleting anything.

Separate testing from live work. Use sample data and a test account first, restrict the domains or applications the agent can contact, and keep an activity log that a named person reviews. Finally, write a stop condition and make sure somebody knows how to revoke the connection immediately.

  • Give the minimum permission needed
  • Start read-only before allowing changes
  • Require approval for consequential actions
  • Test with sample data away from live customers
  • Restrict allowed websites, apps and recipients
  • Log actions and assign a human owner
  • Document and test the emergency stop
06

The risks and limitations

Human approval can become a rubber stamp if the reviewer is rushed or cannot see what changed. Approval screens should show the exact email, file, payment, customer record or public post affected—not merely a vague request to continue.

Logs are useful only when somebody checks them. A small team should define the events that require immediate attention, such as access outside an approved folder, a new recipient, an unusually large batch or repeated failed attempts.

Supplier safeguards do not remove your responsibility. Check current terms, data-retention rules, subcontractors and regional availability before connecting confidential information. Keep manual alternatives for essential processes because models, integrations and prices can change without fitting your timetable.

07

A practical 30-minute agent safety check

Choose the one AI workflow with the widest access in your business. List every connected account and write four verbs beside each one: read, create, change and delete. Mark only the actions the workflow genuinely needs.

Remove unused access, switch to read-only where possible and add a human checkpoint before any external or irreversible action. Run one harmless test with dummy data, then confirm that the activity appears in a log you can understand.

Finish by disconnecting the tool and reconnecting it. If you cannot find the stop control quickly, document the exact steps now. Record the owner, review date and failure response in one page so the workflow remains manageable when the person who built it is unavailable.

  • Map every connected account
  • Remove permissions the task does not need
  • Add approval before external or irreversible actions
  • Test with dummy data and inspect the log
  • Practise disconnecting the agent
FAQ

COMMON BEGINNER QUESTIONS

Has the AI industry agreed to stop developing models?

No. Dario Amodei proposed pacing frontier development rather than halting all progress. Anthropic has committed to embedded independent evaluators, while wider coordination remains a proposal.

What has Anthropic committed to doing?

Anthropic says it will give an external evaluation team ongoing, employee-like access to inspect safety practices, report incidents and publish important findings within defined legal and security limits.

Should a small business stop using AI agents?

Not automatically. Review each agent's access and keep it away from consequential actions until narrow permissions, human approval, logs and a tested shutdown process are in place.

Which AI agent actions need human approval?

Sending messages, publishing content, changing customer records, spending money, issuing refunds and deleting data should normally require a clear human confirmation.

What is the fastest safety improvement to make today?

Choose the agent with the widest access, remove permissions it does not need and practise disconnecting it before using it again with live customer or business data.