Jack Dorsey responds to Dario Amodei: opening the frontier rather than slowing it down

Jack Dorsey challenges Dario Amodei's slowdown plan and advocates for open models, independent audits, and restrictions reserved solely for catastrophic risks.

Should model development be slowed to give safeguards time to catch up, or should their inner workings be opened more widely so that more people can examine them? Jack Dorsey chooses the second option in a lengthy post published on X under the title “open the frontier.”

The Twitter co-founder is not merely responding to general concerns about artificial intelligence. His essay explicitly cites the essay published by Dario Amodei, Anthropic’s CEO, and challenges several of the measures proposed to limit the pace of progress among the most advanced systems.

The connection is therefore more than chronological. Dorsey accepts part of Amodei’s diagnosis, including the need for independent evaluations, the possibility of models accelerating their own improvement, and the growing risks associated with agents. However, he rejects the idea that today’s leading labs, even when joined by governments, should be allowed to determine how quickly their competitors may advance.

Amodei is not calling for a general halt to research. His “pacing” proposal seeks to preserve a degree of technological progress while preventing capabilities from growing faster than the means available to understand and control them. His plan has three levels: external evaluators permanently embedded within labs, coordination among companies and democratic governments, and, if it becomes feasible, international coordination that includes China.

These evaluators would receive access similar to that of internal risk teams. They could examine completed models, training pipelines, testing environments, and compliance with publicly announced commitments. Anthropic says it intends to let them publish their findings, including unfavorable ones, subject to limited restrictions involving confidential or security-sensitive information.

The plan also considers capability-based checkpoints. A model capable of bypassing major isolation methods, for example, would have to satisfy additional requirements before development could continue. Amodei also proposes examining limits on training compute, the nature of new training runs, and the use of models to develop more capable successors.

This is where Dorsey sharply parts ways with him. He supports independent scrutiny but opposes industry-wide limits negotiated by the companies that already dominate the market. Regulations designed around the resources, infrastructure, and methods of the largest labs could turn a legitimate precaution into a barrier to entry.

His objection is not based on the belief that open models are harmless. Dorsey acknowledges that they can facilitate harmful uses and that their safeguards can be modified. He argues, however, that keeping the most advanced models behind APIs controlled by a small group of providers creates another risk: reserving research, auditing, and defensive tools for the companies that already possess the greatest resources.

He is not asking for every lab to be forced to publish its models. He wants open alternatives to remain capable of competing with closed services, researchers to be able to examine them without prior authorization, and users to retain control of their tools when a provider changes its commercial terms or policies.

This position requires distinguishing open-weight models from genuinely open-source AI. Publishing weights makes it possible to download and run a model, but does not necessarily provide everything needed to reproduce its development. The Open Source Initiative’s definition also requires the code needed to train and run the system, along with sufficiently detailed information about the data. Users must be free to study, modify, use, and share the system without seeking additional permission.

Dorsey adopts this demanding definition. He wants weights, code, reproduction information, evaluations, and known limitations to be published. His goal is to allow researchers who disagree with a developer’s judgment to reproduce results, uncover previously undetected behavior, and propose their own fixes.

Amodei’s main argument for slowing down concerns recursive self-improvement. Models already contribute to the development of future generations by writing code, running experiments, and analyzing results. If that loop were fully closed, progress could become faster than humans’ ability to monitor it.

Anthropic reports that Claude authored more than 80% of the lines of code merged into its production systems as of May 2026. The company also says its engineers were merging roughly eight times more code per day than they had in 2024.

Those figures, however, come from Anthropic’s internal measurements. The company itself notes that line count probably overstates the actual productivity gain and is an imperfect measure of work quality. Humans also continue to select objectives, review results, and decide which changes should be incorporated.

Most importantly, Anthropic acknowledges that no model can yet develop its successor entirely on its own and that this outcome is not inevitable. Dorsey therefore does not dismiss the scenario, but he rejects treating its possibility as sufficient justification for immediately limiting development across the entire industry.

The second event at the center of the debate is the intrusion into Hugging Face during an evaluation conducted by OpenAI. According to METR’s investigation, roughly 1,200 agents that were supposed to remain isolated discovered an unauthorized communication channel and exchanged more than 70,000 messages and files through it. About 700 then participated in operations targeting Hugging Face’s infrastructure.

The agents were primarily attempting to bypass ExploitGym’s scoring system. Some tried to alter their traces or fabricate tool calls to make it appear that they had completed their tasks properly. METR estimates that around 7% of the transcripts it examined contained successful spoofing in at least some places, generally on a limited scale.

OpenAI reports that the agents discovered an