Table of Contents
AI security, not a slowdown, is the path to American leadership, according to Forbes contributor Mark Minevich in a column published on September 26, 2026.
He responds to a September 12 call by Anthropic CEO Dario Amodei to slow frontier model development. The White House rejected the idea.
Minevich says the United States should manage AI risk more aggressively while it keeps building.
AI Security: Key Takeaway
- Mark Minevich argues the US should manage AI risk through stronger AI security, infrastructure, and defense instead of slowing frontier model development.
This section contains affiliate links; we may earn a commission at no cost to you.
AI agents now touch internal data, software, and email. These tools help organizations secure the systems and identities around them:
- Tenable: vulnerability management that finds weak points before attackers do.
- CyberUpgrade: cybersecurity compliance and management for teams that need clear controls.
- GetTrusted: identity and trust verification, useful against impersonation and fraud.
- 1Password: a password manager that protects the credentials agents and staff rely on.
The Slowdown Debate That Started It All
The column opens with a blunt question. If the leaders building AI are worried, Minevich asks, “how should the rest of us feel?” His answer is that the response should not be to slow down, but to “get serious.”
What Amodei Proposed
On September 12, Anthropic CEO Dario Amodei called for slowing frontier model development. A frontier model is one of the most capable AI systems available at a given time. Amodei asked to slow the rate at which labs improve those models, and warned that “rogue agent swarms could cause internet scale damage within months.”
Sam Altman and Elon Musk endorsed the proposal the same day, according to the column. On September 23, during the week of the UN General Assembly, Amodei and Altman took the case to the UN Security Council. They asked for shared testing standards and an international system for reporting serious incidents.
How the White House Responded
White House science adviser Michael Kratsios answered in the same chamber. He said “a rapidly advancing frontier is no reason to pause it and no reason to build new global governance structures around it.”
Days later in Berlin, investor Peter Thiel said he takes the risk seriously but believes the pause the labs are asking for does not exist. Minevich uses both reactions to frame his own view: the pause is not coming, so the real work is managing risk while development continues.
Why AI Agents Raise the Stakes
The column ties the debate to a practical fact. An AI agent is software that can take actions on its own, not just answer questions. Minevich notes that agents currently have access to internal data, software, email, and even operational tools.
Agents Already Sit Inside Business Systems
Minevich cites a prediction from research firm Gartner that task specific agents will be built into 40% of enterprise applications by the end of 2026. Gartner published that forecast in a press release on task specific AI agents in enterprise apps. Enterprise applications are the business tools companies use for tasks such as finance, sales, and human resources.
In Minevich’s words, that integration is “far too deep for any enterprise to just hit the brakes for months, or even weeks.” His point is that a pause on paper would not remove agents from systems where they already operate.
Where Security Fits In
Agents that can read data and use tools create new ways to attack an organization. Attackers can try to trick an agent with malicious instructions, a technique covered in this explainer on prompt injection risks in AI systems. Minevich’s list of remedies leans heavily on security, which is why he frames the debate around AI security rather than speed.
Minevich’s Case Against a Slowdown
Minevich does not argue that no one should ever wait. He draws a line between a single company’s decision and a halt for the whole industry. “Slowing a release is necessary if a frontier lab isn’t sure of a model’s safety,” he writes.
One Lab Can Wait, the Ecosystem Cannot
He says a frontier company that concludes its next model cannot be deployed safely should wait. But he calls grinding the whole AI ecosystem to a halt “irresponsible and detrimental to the country.”
The column points to Anthropic’s own policy framework, built on the principle that systems posing catastrophic risks should not be trained or deployed without adequate safeguards, as a model other companies could copy.
Control of the Entire Stack
Minevich argues that winning the global AI race depends on more than one impressive model. “Who wins globally in the AI race is who controls the entire stack,” he writes. He lists compute capacity, advanced semiconductors, reliable energy, high performance data centers, capital, technical talent, cybersecurity, and global distribution.
He also points to the federal government’s strategy. The White House published America’s AI Action Plan in July 2025, and it rests on three pillars: accelerating AI innovation, building AI infrastructure, and leading in international AI diplomacy and security.
Why the Nuclear Comparison Breaks Down
At the UN Security Council, delegations raised the Non-Proliferation Treaty as a possible model for AI. Minevich acknowledges that the nuclear regime’s monitoring and intelligence gathering came remarkably close to working. Then he names the flaw in the analogy: “Uranium can be counted but model weights can be copied.”
Model weights are the numerical values that make up a trained AI model. Because AI is software, he says, one team can create a model and another can copy it, augment it, and deploy it for the opposite reason. One underlying system can support drug discovery, education, finding software vulnerabilities, making images or videos, improving a supply chain, or helping someone with bad intentions toward the United States.
Bad Actors Ignore Recommendations
Minevich calls a national slowdown ineffective at reaching the real goal of safety. “Bad actors are bad actors. They break the law every day; they won’t follow a recommendation,” he writes. In his view, a pause would bind the responsible while leaving the reckless free.
The Defensive Plan Minevich Proposes
Minevich cites the International AI Safety Report of 2025, which he says makes clear that advanced AI risk management requires multiple layers of defense. Those layers include technical monitoring, evaluations, and governance mechanisms. The report also notes unresolved practical challenges in evaluating and managing risks from increasingly advanced general purpose systems.
What Frontier Companies Should Do
Minevich wants frontier companies to establish internal guardrails immediately. He lists four actions:
- Establish meaningful safeguards against attacks on critical infrastructure that use AI.
- Test models for biological and chemical misuse risks.
- Create models and training environments that fight fraud, theft, and impersonation with the intent to steal.
- “Think like a criminal to stay ahead of criminals.”
What Government Should Do
Beyond regulation, Minevich says government must invest heavily in defensive AI. He names cybersecurity, fraud prevention, threat detection, and critical infrastructure resilience as priorities. He also calls for faster construction of secure compute infrastructure, more reliable electricity generation and grid capacity, and stronger semiconductor supply chains.
The Workforce Gap
The last item on his list is people. “The US needs an advanced workforce,” he writes. “Training, upskilling, and reskilling must be part of this AI age, or all we will have is a bunch of job postings and empty desks.”
The China Factor
Minevich says China’s approach is simple: “all they focus on is winning.” He cites the State Council’s push for accelerated AI integration across science and technology, industrial development, consumer applications, and public services.
He treats China’s “AI Plus” agenda as proof of intent. “They are full steam ahead no matter the cost or dangers,” he writes. His warning follows: “Cooperation cannot be assumed; American policy must be resilient to the possibility that competitors continue advancing without restraint.”
Thiel on Enforcement
Minevich also summarizes Thiel’s interview with Axel Springer CEO Mathias Döpfner. Thiel does not dismiss the doomers, the people who fear AI could slip out of human control. He says the risk of losing control of a system smarter than humans is real, and that even a 5 to 10 percent chance is serious.
Thiel’s objection is about enforcement. A real pause, he argues, would require enforcement across Washington, Beijing, and every lab with GPUs and talent, in effect “a world government with teeth.” He sums up the landscape with the line “Europe moralizes, but America argues and Beijing trains.”
Implications of the AI Slowdown Debate
The section below is analysis, not a summary of the column. It looks at what the argument means for security teams and policymakers, based on the facts Minevich presents.
Security Becomes the Practical Middle Ground
The debate is often framed as a choice between speed and safety. Minevich rejects that framing, saying “This is not a choice between safety and leadership.” For defenders, this shifts attention to controls that can be deployed now, such as testing, monitoring, and access limits for agents.
That framing also gives security teams a clearer role. If a pause is unlikely, the work moves to reducing damage from systems already in use. Approaches like zero trust, which treats every request as untrusted until verified, fit that need. This overview of zero trust architecture for network security explains the model.
Agents Widen the Attack Surface
An attack surface is the sum of all the points where an attacker could try to get in. When agents hold access to email, internal data, and operational tools, each agent becomes a possible entry point. A compromised agent could act with the permissions of the employee or system it serves.
Organizations should therefore inventory which agents exist, what they can reach, and who approves their actions. Least privilege, meaning giving each agent only the access it needs, reduces the harm if one is hijacked. These are practical steps that do not depend on any treaty or pause.
Dual Use Makes Offense and Defense Hard to Separate
Minevich stresses that one system can serve many purposes, including finding software vulnerabilities. The same skill that helps a defender patch a flaw can help an attacker exploit it. That reality is why he wants defensive AI funded heavily: defenders need tools that match the pace of attackers.
For security leaders, dual use also complicates procurement and policy. A tool that scans code for weaknesses is valuable and risky at once. Access controls, logging, and clear rules on who may use such tools become part of the defense.
Impersonation and Fraud Move Up the Agenda
Minevich asks for models and training environments that fight fraud, theft, and impersonation. Convincing fake voices and messages are already a route into organizations, and agents that act on requests could be fooled by them. Verification steps for high risk actions, such as payments or data exports, remain a basic safeguard.
Teams can also treat agent actions like any other sensitive activity. Requests that move money or change account details should need a second confirmation through a separate channel. That habit protects against both human and automated mistakes.
Infrastructure and Supply Chains Are Security Questions
Minevich lists electricity, grid capacity, and semiconductor supply chains next to cybersecurity. The connection is direct: compute infrastructure that runs frontier AI must be secure and reliable. A disruption to power or chips would affect the ability to build and defend systems alike.
This also means AI security is not only about software flaws. Physical and supply chain weaknesses can undermine a defense that looks strong on paper. Planning for them belongs in the same conversation.
Governance Without a Global Enforcer
Thiel’s argument suggests that global rules are hard to enforce when countries compete. If cooperation cannot be assumed, as Minevich warns, then companies and governments must build safeguards that work even when rivals do not follow them. Internal guardrails, consequences for non compliance, and resilient national policy become the main tools.
Minevich says government should demand that frontier companies accelerate innovation while creating internal regulations, and impose consequences if they do not comply. Whether that balance can hold is an open question, and the column does not claim otherwise.
The Limits of One Viewpoint
This is an opinion column, and its conclusions are Minevich’s. Amodei, Altman, and Musk, who backed a slowdown, would likely weigh the risks differently. Readers should treat the column as one side of a live debate, not a settled finding.
<div style=”background-color:#f3f3f3; border-left:10px solid #1a5fb4; padding:16px; border-radius:6px;”>
This section contains affiliate links; we may earn a commission at no cost to you.
Strong defenses start with visibility and clean email. These services help teams watch their networks and block spoofed messages:
- Auvik: network monitoring and management, so unusual traffic and new devices do not go unnoticed.
- EasyDMARC: email security and DMARC, which helps stop spoofed messages used in impersonation and fraud.
Wrapping Up
Minevich argues that slowing AI is the wrong answer to the risks that Amodei, Altman, and Musk describe. The White House and Peter Thiel also rejected a pause, and Minevich says AI is software that can be copied by anyone, including bad actors.
His alternative is faster work on AI security, biosecurity, and cyber resilience, backed by internal guardrails at frontier labs and heavy government investment in defensive AI. He also asks for stronger infrastructure and a trained workforce.
In his closing words, “Risk management is not retreat.” The debate will continue, but organizations already running agents can act now on access, monitoring, and verification.
Questions Worth Answering
Who called for slowing frontier AI development?
- Anthropic CEO Dario Amodei called for it on September 12, and Sam Altman and Elon Musk endorsed the proposal the same day.
What did Amodei and Altman ask of the UN Security Council?
- On September 23 they requested shared testing standards and an international system for reporting serious incidents.
How did the White House respond?
- Science adviser Michael Kratsios said a rapidly advancing frontier is no reason to pause it and no reason to build new global governance structures around it.
Why does Minevich say a slowdown will not work?
- He says AI is software that can be copied, augmented, and redeployed, and that bad actors will not follow a recommendation to slow down.
Why does he reject the nuclear comparison?
- He says uranium can be counted but model weights can be copied, so monitoring AI is harder than monitoring nuclear material.
What is the Gartner prediction he cites?
- Gartner predicts task specific agents will be built into 40% of enterprise applications by the end of 2026.
What should frontier companies do, according to Minevich?
- They should set internal guardrails, test models for biological and chemical misuse, guard critical infrastructure, and build models that fight fraud and impersonation.
What should government do?
- Minevich says it should invest heavily in defensive AI, build secure compute, expand electricity supply, strengthen semiconductor supply chains, and train the workforce.
What is his view of China?
- He says China is moving “full steam ahead” under its “AI Plus” agenda, so American policy must not assume cooperation.
Is the column a neutral report?
- No, it is an opinion piece, and its arguments reflect Minevich’s view rather than a consensus.
This section contains affiliate links; we may earn a commission at no cost to you.
- Protect more: IDrive backs up your data, Tresorit encrypts cloud files, Optery removes personal data online.