When a swarm of AI agents broke out of their test environment and breached Hugging Face, a target nobody assigned, to game the system grading them, the incident pushed leaders of frontier AI companies to question the pace of their own innovation.
Anthropic CEO Dario Amodei’s recent essay ”We Must Pace the Frontier” argues that companies developing the most capable AI models, or frontier labs, should give independent evaluators inside access, accept targeted regulation and deliberately slow capability gains so safety work can catch up. OpenAI’s Sam Altman agreed within hours.
I support the spirit of what our partners at Anthropic and OpenAI are proposing, because frontier AI introduces something genuinely new: autonomous systems capable of taking consequential cyber actions that humans neither selected nor anticipated. And soon, those capabilities won’t be confined to a few frontier labs.
Here’s the distinction I think needs to be part of the conversation: Pacing frontier development may buy the world time. Cybersecurity’s job is to use that time to build defenses capable of observing, governing, and countering AI systems when that capability inevitably proliferates.
That’s why, for those of us who build and use AI for cyber defense, slowing down isn’t an option. But to be clear, what defenders can’t afford to slow isn’t model capability.
Pacing can slow how quickly the most capable models are released. It doesn’t control what happens once AI agents are running inside your environment, or in an adversary’s hands.
The governance problem
Even a perfectly aligned, carefully paced model can create catastrophic risk if:
- Nobody knows it’s running in your environment.
- It has too much access.
- It's never monitored.
The Hugging Face incident turned on exactly these gaps. The agents got in using working credentials exposed on the public web, and then moved laterally through systems nobody expected them to reach.
Our recent research “Agentic AI’s Shadow Pipeline: Mapping the Attack Surface Behind Trusted Workflows” shows why this isn’t theoretical. We found that 47% of organizations lack full visibility into their cloud assets in multi-cloud environments, the same infrastructure AI agents now run on. And when AI agents connect to external tools and integrations, they inherit those tools’ weaknesses: Up to 20% of open-source repositories contain exploitable vulnerabilities.
Shadow AI is a growing attack surface, and it’s a problem that frontier labs can’t solve on their own, because a perfectly aligned agent will still do whatever it’s given permission to do.
That’s why TrendAI™ works with our enterprise and government customers to build governance frameworks that help reduce risk, regardless of where frontier AI goes. This means answering four questions:
- Visibility: What AI systems or agents are running in your environment, and where does sensitive data flow into them?
- Ownership: Who’s accountable for each system or agent, and do any of them have more access than the job requires?
- Observability: Are any AI systems or agents leaking data, being manipulated, or acting in ways that don’t match their intent?
- Governance: Can you show evidence that AI risk is under control?
These are the foundations for AI cybersecurity, whether the model underneath comes from a frontier lab, an open-source project, or somewhere you never approved. Organizations that put them in place now will be ready when frontier-class capabilities are no longer rare.
The speed problem
Attackers are already using AI to find and exploit weaknesses faster than human-only defenses can respond. As frontier capabilities proliferate, those attacks will grow more autonomous and harder to anticipate.
Today, there are more vulnerabilities than any team can patch, and AI is accelerating both discovery and exploitation. So, the challenge for defense teams is to constantly increase the speed at which we can turn vulnerability intelligence into protection, or the “time to zero.”
TrendAI™ has thousands of threat researchers around the globe using AI and human intelligence to discover threats and create virtual patches that can be rapidly deployed. For vulnerabilities that are already being exploited, our virtual patching can provide protection up to 115 days before vendor patches ship.
Providing this protection depends on continuous AI innovation, and on putting the most capable models to work for defenders as soon as they can be used safely. That’s how we keep pace with today’s AI attacks, and with the more autonomous attacks that proliferation will bring.
Attackers aren’t pacing
Most organizations are already running AI agents, with or without governance in place. And adversaries are weaponizing AI to attack faster and smarter every day.
So as the industry debates the pace of AI innovation, we can’t forget the ever-accelerating pace of AI threats.
Whatever time pacing buys us, defenders need to spend it building the ability to control, observe, and counter AI systems before frontier-class capabilities are in everyone’s hands, adversaries included.
The same reasons frontier labs want to slow down AI model development are precisely the reasons defenders can’t afford to. Cybersecurity in the AI era must govern against unintended consequences as rigorously as it defends against malicious intent.