The artificial intelligence industry is entering a new phase in which the development of increasingly capable AI systems is being accompanied by a stronger focus on safety, monitoring and containment. OpenAI and Anthropic, two of the leading companies developing advanced AI models, continue to pursue systems capable of performing increasingly complex tasks, while their executives are also discussing how quickly frontier AI development should proceed.
OpenAI has long described artificial general intelligence, or AGI, as an important part of its mission. Anthropic has similarly focused on developing highly capable AI systems while emphasizing the need to understand and manage the risks associated with increasingly powerful models.
The latest debate is not about abandoning AI development. Instead, the discussion is increasingly focused on whether safety research, evaluation and security measures can keep pace with rapidly improving model capabilities.
OpenAI's Increasingly Capable Models
OpenAI's recent development of GPT 6 Astra illustrates the change in the capabilities being evaluated by AI companies.
In September 2026, OpenAI said Astra had become the first model it had classified at the Critical level of cybersecurity capability under its Preparedness Framework. According to OpenAI, a model at this level, when provided with appropriate tools and access, can identify previously unknown security vulnerabilities and develop methods to exploit vulnerabilities across well-protected systems without requiring a person to guide every individual step.
OpenAI said the capability required stronger safeguards during development and before deployment. The company described additional security measures, including stricter isolation, monitoring and alignment evaluations.
The development is significant because it demonstrates how AI safety concerns are increasingly connected to capabilities that already exist in advanced systems rather than only to hypothetical future scenarios.
OpenAI has also said that increasingly capable models require stronger security measures throughout the development process. In an August 2026 publication, the company said rapid progress in its research, together with cybersecurity concerns and a previously reported OpenAI Hugging Face incident, had increased the urgency of improving monitoring, alignment and containment safeguards.
What the Critical Cybersecurity Level Means
The Critical designation does not mean that Astra is independently capable of carrying out unrestricted cyberattacks in the real world. OpenAI's assessment specifically refers to what the model can accomplish when provided with suitable tools and access.
The distinction is important because the capabilities of an AI model and the permissions granted to that model are separate issues. A system may have the ability to identify a vulnerability, for example, while security controls can restrict whether it has access to a target system or whether it can execute an action.
OpenAI says its safety measures are designed to address both misuse and the possibility of harmful behavior from the model itself. Its GPT 6 Astra safety documentation describes stronger protections intended to reduce the risk of harmful cyber activity.
Anthropic Calls for Pacing AI Development
Anthropic CEO Dario Amodei has taken a similar position on the need to balance AI capability development with safety work.
In September 2026, Amodei called for a slowdown, or pacing, of frontier AI development. His argument was that companies should give safety research, security measures, monitoring and independent evaluation enough time to keep pace with rapidly improving models.
The proposal does not amount to a call to stop AI research altogether. Instead, the focus is on managing the rate at which the most advanced systems become more capable.
Anthropic has also proposed greater involvement from independent evaluators. The company says it plans to provide third party evaluators with access to internal processes, systems and data so that they can assess safety practices, report incidents and monitor measurements associated with AI development.
Sam Altman Supports Pacing
OpenAI CEO Sam Altman has also acknowledged the need to pace frontier AI development.
Following Amodei's comments, Altman said he agreed that the frontier needs to be paced and that safety had been an important topic of discussion at OpenAI. He also supported the idea of independent evaluators receiving substantial access to assess AI safety practices.
This does not mean OpenAI and Anthropic have identical approaches to AI safety. The companies continue to compete in model development and differ in their technical approaches, products and policies.
However, the public comments from their leaders show that safety and development speed have become increasingly connected issues.
From Human Level Intelligence to AI Autonomy
For several years, much of the AI industry's attention was focused on improving models so they could perform tasks that previously required human expertise.
Modern AI systems can already generate software, analyse documents, use tools, browse websites and complete multi-step tasks. The development of AI agents has further increased the importance of controlling what systems can access and what actions they are permitted to take.
This changes the nature of the safety challenge.
A chatbot that simply responds to a question has a different risk profile from an autonomous agent that can access software, execute code, communicate with external systems and continue working through multiple steps.
As AI systems become more autonomous, developers have to consider not only whether a model produces an appropriate response but also what it might do when connected to external tools and given permission to act.
Why Containment Matters
Containment has become an important part of the AI safety discussion because advanced models can potentially be connected to sensitive systems.
OpenAI's recent safety work includes stronger isolation and monitoring measures. The company has said that it is strengthening security around both its internal development environments and deployed models.
The goal is to ensure that increased model capability does not automatically translate into unrestricted access to computers, networks, data or other resources.
This is also why AI safety is increasingly being treated as an engineering problem. Model training and alignment remain important, but companies also need infrastructure-level controls, monitoring systems, access restrictions and independent evaluations.
A Changing AI Race
The developments at OpenAI and Anthropic illustrate a broader change in the AI industry.
The competition to build more capable systems has not stopped. New models continue to be developed and released, and companies remain focused on improving reasoning, coding, scientific research and autonomous task completion.
At the same time, the definition of progress is becoming broader. Companies are increasingly measuring not only what an AI model can accomplish but also how reliably it can be monitored, restricted and evaluated.
OpenAI's Astra assessments and Anthropic's proposals for independent evaluation are examples of this wider approach.
The debate over pacing is also likely to involve governments, researchers, businesses and other AI developers. Questions include how quickly frontier models should be developed, what safety standards should be required before deployment, how independent evaluations should operate and how incidents involving advanced AI systems should be reported.
What This Means for Users
For ordinary users, the immediate effect is likely to be seen through changes in how advanced AI products are tested and deployed.
As models become more capable, companies may introduce additional restrictions on high-risk capabilities, stronger monitoring systems and more extensive testing before providing access to certain features.
Users may also see greater separation between general-purpose AI capabilities and specialized tools that can interact with external systems.
The underlying objective is to ensure that AI systems can become more useful without giving them unrestricted access to sensitive environments.
The current debate therefore represents a shift in emphasis rather than an end to the AI race. OpenAI and Anthropic continue to pursue increasingly capable systems, but their recent public statements show that the ability to control, evaluate and secure those systems is becoming a central part of the development process.
The coming period is likely to focus increasingly on whether safety research and technical safeguards can advance at a pace comparable to the capabilities of frontier AI models.





