AI Slowdown Debate Leaves Security Teams With a Bigger Problem 

As AI leaders debate slowing development, security teams must secure the agents already operating in their environments.

Written By
Ken Underhill
Ken Underhill
Sep 14, 2026
4 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Some of the biggest names in artificial intelligence (AI) are suddenly talking about slowing down.

OpenAI CEO Sam Altman has backed calls to pace the frontier as increasingly capable AI systems raise concerns about whether developers can continue improving them faster than they can understand and control them. 

Anthropic CEO Dario Amodei has also called for greater coordination among frontier AI companies, including independent evaluations and common safety standards.

I think that conversation is worth having. But from a cybersecurity perspective, I see another problem that cannot wait for the next generation of AI.

Organizations are already giving AI agents credentials and access to systems. Those agents can also take actions with limited human involvement.

That makes AI security an operational problem today, not just a theoretical problem for tomorrow.

AI safety is becoming an access-control problem

Recent incidents involving Anthropic’s Claude demonstrate what can happen when autonomous systems operate outside their intended environments. 

Anthropic disclosed that its models gained unauthorized access to real third-party systems during several evaluations. 

The company subsequently expanded its investigation to roughly 481 million transcripts and acknowledged weaknesses involving operational security and model behavior.

For me, this is where the AI safety discussion starts looking much more familiar to cybersecurity teams.

Oleksandr Yaremchuk, CTO and co-founder of Manifold Security, suggested in an email to eSecurityPlanet that slowing frontier development cannot replace securing agents that organizations have already deployed.

“Pacing the frontier is the right conversation to be having, but it cannot become a substitute for securing the AI we have already put into the world,” Yaremchuk said.

He compared autonomous AI to hazardous materials. 

Organizations do not wait for hazardous substances to become more dangerous before controlling who has custody of them and who can access them. They also monitor where those materials go and establish accountability when something goes wrong. 

Advertisement

I think that analogy works well for AI agents.

If an agent can interact with production infrastructure, the security team should know what credentials it possesses and which resources it can reach. Teams should also be able to see what the agent has done and quickly revoke its access when necessary. 

The same principles we apply to human and machine identities should not disappear simply because the identity performing the action happens to be AI.

Voluntary guardrails face an incentive problem

There is also a practical challenge with asking competing AI companies to voluntarily slow development.

Jeremiah Fowler, cybersecurity researcher at Black Hills Information Security, points to the enormous competitive incentives pushing development in the opposite direction.

“The uncomfortable truth is that AI companies have an incentive to develop advanced models that are better than their competition,” Fowler said.

That makes voluntary restraint difficult when companies fear losing market position.

Fowler argues that meaningful guardrails should establish enforceable minimum safety standards and require independent testing and auditing. They should also limit autonomous permissions while keeping humans involved.

Some AI developers are already moving toward stronger evaluation frameworks. Anthropic, for example, maintains a Responsible Scaling Policy and a Frontier Safety Roadmap focused on safeguards and security. The roadmap also addresses alignment and policy.

The company has also said coordinated pacing across the industry would need to comply with the law and be independently verifiable. It would also require cooperation between government and industry.

Independent evaluations could provide another layer of scrutiny, especially as models become capable of performing increasingly sophisticated tasks.

But evaluations alone will not secure an AI agent running inside an enterprise.

Advertisement

Organizations should secure the AI they already have

For security leaders, I see two separate issues in this debate. 

The industry needs to determine how to safely develop increasingly powerful frontier models

Organizations, meanwhile, need to determine how to control the AI systems already connected to their environments. 

That means treating autonomous agents as privileged identities rather than simply another software feature. 

Give them only the permissions necessary for their tasks and protect the credentials they use. Their actions should also be logged so security teams can monitor for unusual behavior.

Organizations should establish clear boundaries around what agents can execute autonomously. Humans should also have a way to immediately terminate access when necessary.

Yaremchuk puts the challenge into three straightforward questions: 

  • What did the agent do? 
  • What did it have access to? 
  • Could you have stopped it?

I would add one more: How quickly would you know that you needed to?

The larger AI safety debate will take time to resolve. Security teams cannot wait for that debate to determine how agents are monitored, what they can access, and when humans need to intervene. 

Applying zero trust can help organizations limit what AI agents and other identities can access while continuously verifying whether that access should be allowed.

Ken Underhill

Ken Underhill is an award-winning cybersecurity professional, bestselling author, and seasoned IT professional. He holds a graduate degree in cybersecurity and information assurance from Western Governors University and brings years of hands-on experience to the field.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.