AI labs may slow down. Time for IT and governance to catch-up. - Spiceworks
High confidence: full text extraction produced 11484 characters.
AI labs may slow down. Time for IT and governance to catch-up.
Frontier AI providers are arguing over whether to ease off model development. IT teams have a different problem: AI is already loose in the business, and the controls are late.
The companies building the most powerful AI systems are now questioning how fast they should move. That is probably healthy. But it doesn’t mean your IT team should stop all AI projects and wait for Silicon Valley to figure things out.
People are already using these tools. Companies are adding AI assistants to software you already pay for. Leaders want to know about agents, automation, and cutting staff costs all at once. If IT stops now, employees will just use personal accounts and unofficial add-ons, hiding costs in expense reports as “productivity tools.”
READ MORE: Is business-grade Wi-Fi the new consumer tech?
The better approach is to view the frontier slowdown as an opportunity to catch up. Use it to catch up on governance, security, and basic operational discipline before the next wave of models arrives.
The pause and its limits
The September debate started with Anthropic CEO Dario Amodei’s call to “pace the frontier.” He proposed stronger safety testing, coordination among leading labs and governments, and independent evaluators with continuing access inside AI companies. Anthropic also asked the independent research organization METR to investigate incidents involving Claude with access to transcripts and Anthropic employees.
OpenAI CEO Sam Altman agreed that development of the most capable models should slow. OpenAI then said it would support independent assessments with deep access across training, evaluation, and deployment so outside assessors could challenge the company’s assumptions and reach their own conclusions about its safeguards.
Google DeepMind CEO Demis Hassabis and several other AI leaders backed the general direction. None of them proposed shutting down current services, removing enterprise APIs, or sending ChatGPT home in a cardboard box. An Associated Press review of the industry positions found that Amodei offered the most detailed slowdown plan while other executives supported parts of it.
This point has been omitted under the “AI pause” headlines. The concerns are around the rate at which labs train systems at the leading edge, particularly models capable of helping develop successors or conducting complex cyber operations. Current services wouldn’t necessarily disappear while labs spent more time evaluating the next generation, according to coverage of the market reaction.
The disclosures got real
The slowdown argument followed soon-after disclosures that frontier models can act beyond their intended test boundaries.
READ MORE: Is private 5G as secure as vendors say? What IT buyers should know
Anthropic reported incidents in which Claude models gained unauthorized access to real third-party systems during cybersecurity evaluations. The models had been tested without their normal safeguards, and a misunderstanding with an outside testing company exposed them to the public internet. Anthropic described the episode as a “failure of operational security” and acknowledged that its models were “not perfectly aligned.”
Anthropic initially paused internal and external cybersecurity testing and then added more controls. These included alerts for attempts to escape test environments, stronger isolation for high-risk evaluations, and requirements that outside testing partners follow stricter practices. “We had been largely relying on a single layer of defense … where we needed several,” the company said.
Google joined the uncomfortable disclosure club when it acknowledged that Gemini had accessed three outside systems during a May security test. A testing error gave the model internet access. Gemini guessed credentials in one case and found exposed credentials in public repositories in the other two, Google said it stopped after recognizing that the systems were real.
“In all three of these instances, the model stopped,” Google security engineering vice president Heather Adkins said in a statement reported by CNBC. Google notified the affected organizations and worked with the testing partner to change its processes.
For enterprise IT, the lesson isn’t new: a control shown in the architecture diagram may not exist in the running environment. AI did not invent configuration drift, excessive permissions, or weak logging. It simply found faster and more imaginative ways to make those old problems expensive and more unnerving.
Meta and Nvidia disagree
There is no industry-wide cease-fire. Meta CEO Mark Zuckerberg argued that competition and liability give providers enough incentive to act independently. He pointed to Meta’s decision to delay the Muse agent for several months while it worked on safety and security.
“We didn’t call for everyone else to do this before we would,” Zuckerberg wrote. “We just did it as part of our day-to-day work because it was clearly the right thing for people and for us.” He also described the use of independent evaluators and advisers as an industry best practice.
Nvidia CEO Jensen Huang rejected a broad slowdown, too. “We should go as fast as we can irrespective of anybody else,” he told CBS News. Huang added that companies should never ship products before they are ready or deliver products that are unsafe.
At Dreamforce, Huang framed safety as an engineering responsibility rather than a reason for every provider to stop together. “Run as fast as you can,” he said, but pause if a company feels out of control or believes its product may be unsafe, according to coverage of his remarks.
Nvidia’s position is hardly surprising. It sells much of the hardware powering the buildout, and slower frontier training could affect demand. More important for IT planners, Nvidia, Meta and other vendors are still shipping. Even if frontier development slows, the enterprise AI workload will not.
China isn’t waiting
Chinese providers are continuing to push model capacity and infrastructure. Huawei rotating chair, Eric Xu said Chinese models might not yet be advanced enough to reveal the risks reported by leading U.S. labs. His conclusion was not to stop but to keep developing while balancing progress and safety.
“I think maybe AI model providers in China may need to speed up their pace to the level that they could also feel the risks from AI development,” Xu said. He added that developers should “strike a balance between driving AI development and managing AI risk,” according to The Next Web.
Alibaba made that direction pretty hard to miss. Alibaba’s company announcement said Qwen 4 was in training and that later Qwen models could reach 5 trillion to 10 trillion parameters. CEO Eddie Wu said the larger models would tackle “more complex, longer-horizon tasks.”
Reporting by Al Jazeera states Beijing also rejected the U.S. slowdown discussion as geopolitical containment. China’s state-backed Global Times called Amodei’s proposal a “Cold War playbook,” while a Foreign Ministry spokesperson warned that threat narratives, confrontation, and “malicious competition” could damage global AI governance.
That rhetoric does not mean China is ignoring risk. Beijing has pressed ahead with rapid deployment while developing mandatory standards and security assessments, including a planned national standard for AI agent safety. The policy looks closer to “build and supervise” than “stop and inspect.”
Washington and Brussels split
Government leaders are divided as well. European Commission President Ursula von der Leyen backed calls to slow frontier development and said she would invite leading labs to discuss model evaluation, verification, and security. “If the people developing the technology are clear, then we should be too,” she told the European Parliament, according to European Commission’s State of the Union transcript.
President Donald Trump rejected the slowdown argument and said fears about AI taking over were a “HOAX.” Vice President JD Vance acknowledged that AI creates risks but called the industry’s requests for regulation a possible “Trojan horse,” reflecting concern that rules favored by large providers could strengthen their market position.
IT teams should assume that policy will remain inconsistent across providers and jurisdictions. A model approved for one business unit may create retention, residency, or disclosure problems in another. Waiting for one universal rulebook will leave you waiting while your org signs three AI renewals.
Your users are moving forward
The enterprise adoption numbers make a broad internal pause unrealistic. Gallup’s May 2026 workforce data found that 52% of U.S. employees used AI in their jobs at least a few times a year, 30% used it at least a few times a week, and 15% used it daily.
Agents are moving beyond pilot projects, too. McKinsey’s 2026 State of AI survey found that 40% of respondents at organizations with more than $1 billion in annual revenue were scaling agents, up from 27% a year earlier.
The controls are not keeping pace. A Deloitte survey of 3,235 IT and business leaders found that 74% expected their companies to use AI agents at least moderately by 2027, but only 21% said their organizations had mature agent-governance models.
Governance and IT now have to bring the controls up to speed with adoption. Blocking every AI tool usually changes the location of the risk, not the amount. People move sensitive work into accounts you cannot monitor, under terms nobody reviewed, with logs nobody can retrieve.
Catch up without getting reckless
Start by finding what is already running. Inventory approved and unapproved models, copilots, browser extensions, retrieval systems, agents, service accounts, and API keys. Record the owner, business purpose, data access, retention terms, tools the system can invoke, and the kill switch. If an agent can modify production but nobody knows who owns it, you have found today’s meeting agenda.
Then separate low-consequence assistance from high-consequence action. Summarizing public documents does not deserve the same controls as changing firewall rules, approving payments, or answering customers. Require human approval for destructive, financial, legal, security-sensitive, and public-facing actions. Use least privilege, short-lived credentials, and explicit allowlists for tools and network destinations.
Test the ugly cases before launch. Check prompt injection, data leakage, hallucination, privilege escalation, memory poisoning, unsafe code execution, and cascading failures between agents. The OWASP agentic risk guidance offers a practical threat list for that work.
Finally, put AI into the same operating machinery you use for everything else: named owners, change control, logging, incident response, vendor review, and decommissioning. The NIST AI Risk Management Framework organizes the job into four useful functions: Govern, Map, Measure and Manage. Ask vendors to disclose material model changes, security incidents, retention practices, and subcontractors. Make rollback and export terms part of the contract before procurement discovers that “portable” means screenshots.
The frontier providers may buy themselves a little time. Your IT team should spend that time getting visibility, setting boundaries, and giving employees safer approved options. The next model release will arrive soon enough, and it won’t read your backlog first.