Security News

Cybersecurity news aggregator

INFO News Dark Reading

Anthropic CEO: Time to Shift From Improving to Controlling AI

  • What: Anthropic CEO calls for controlling AI development to improve security.
  • Impact: Influences enterprise strategies for AI deployment and risk management.
Read Full Article →

Informa TechTarget | SearchSecurity Cybersecurity Dive InformationWeek Channel Dive Explore our brands Dark Reading Resource Library Black Hat News Omdia Cybersecurity Advertise NEWSLETTER SIGN-UP Cybersecurity Topics World The Edge DR Technology Events Resources CYBER RISK PHYSICAL SECURITY CYBERSECURITY OPERATIONS VULNERABILITIES & THREATS NEWS Anthropic CEO: Time to Shift From Improving to Controlling AI Dario Amodei says it's time to slow the pace of frontier AI improvements so that security and risk prevention efforts can catch up. What does this mean for enterprises? Elizabeth Montalbano,Contributing Writer September 14, 2026 6 Min Read SOURCE:BRAIN LIGHT VIA ALAMY STOCK PHOTO Anthropic CEO Dario Amodei's caution to industry leaders to slow their roll on the development of AI has numerous implications for enterprises deploying AI agents, chief among them the need to shift from simply securing agents in their environments to putting limits on their autonomy. Over the weekend, Amodei issued one of the starkest warnings yet to the industry amid the recent flurry of alarming security incidents. In an essay published online, Amodei urged "even more prudence" to fully address the potential dangers AI poses, going beyond increased risk prevention efforts to reducing the speed of frontier AI improvements so security measures can keep up. "We must slow the pace at which we improve the capabilities of AI models," he wrote in the essay. "Progress will still seem fast, and we must make wise use of the time we gain." Amodei's stance is based on two key concerns. First, he noted the dramatic speed at which AI has advanced since the summer, which, left unchecked, "could outrun our ability to understand and control these systems, and so must be pursued very carefully, if at all," he wrote. This is primarily driven by AI's recursive self-improvement capabilities, he added. Related:CISA Calls for More Guidance, Less Spin, as Cyber Outages Escalate The second concern stems from the high-profile incident in which hundreds of rogue OpenAI agents attacked Hugging Face during benchmark testing for models in July. It might be easy to dismiss the incident "because no one was hurt and the economic damage was minimal," Amodei wrote, but that would be a mistake. That’s because "a swarm that possessed greater capabilities but a similar level of misalignment could have caused catastrophic damage," he wrote. Amodei offered a hypothetical but alarming scenario in which such a swarm could create a persistent botnet that takes over the entire Internet. Time to Reel In AI Is Now The essay comes shortly after a call for a kill switch for AI lest it run amok, by former Anthropic employee Jacob Coxon, who used media appearances over the weekend to advocate for controlling the technology before it's too late and AI becomes a fully rogue, autonomous system. While some have warned of doomsday scenarios about AI since its inception, those warnings have largely been unheeded or dismissed as science fiction. However, if ever there was a time to take these warnings seriously, it's now, experts say. "Enterprises don’t need to stop adopting AI, but they do need to know what their agents can reach, what they’re exposing, and whether security can keep up as that changes," Rickard Carlsson, CEO of AI security firm Detectify, tells Dark Reading. Related:Why AI Is So Good at Scamming Humans "An agent with excessive access doesn’t just create one vulnerability; it can potentially act across multiple systems at machine speed before a human ever gets involved," he says. For enterprises, this means treating an AI agent "like an untrusted employee you can’t fully background check, who may have access to your most sensitive systems and happens to be an elite hacker in their spare time." How to Secure AI Agents AI has already created a host of new security risks for enterprises, from poisoned AI models and supply chain attacks to deepfakes and automated social engineering. Recent research has shown that compromised AI components can expose credentials and other sensitive data, while AI agents in security tests have escaped intended environments, discovered vulnerabilities, and accessed secrets. The immediate enterprise challenge is to limit agents' access to sensitive information and systems from the moment of deployment and monitor them closely, Carlsson says. "You have to assume that at some point their interests or actions may no longer align with yours," he says. "That means limiting access from day one, isolating agents where possible, and maintaining continuous visibility into what they can reach and what they're actually doing." Related:AI Governance Can't Wait Denis Calderone, chief technology officer of Suzu Labs, concurs that the best way to control AI agents is to first consider them a threat to the system as a whole. "The agent is the new contractor or the new internal threat vector," he says. "The agent has a specific job, specific access requirements, and a bounded set of actions it should be performing. Enterprises need to treat every AI agent the same way they'd treat any other agent on the network, human or otherwise." Visibility and Control Are Key For Carlsson, visibility is the starting point for securing AI agents going forward because "you can't secure what you don't know about." He calls for continuous oversight of AI to "validate the real attack surface and flag new exposure as it emerges." "Enterprises need continuous discovery and an up-to-date inventory of where AI agents are operating, what they can access, and what they're exposed to," he says. "Strong logging should also show what agents are actually doing, not just what they're supposed to do." Treating every agent as an individual entity with strict controls is the only way forward, Calderone agrees. "Every agent must have its own machine identity, task-scoped credentials that expire when the job is done, and observability into everything it does," he says. "Not a shared service account or API token, but instead a distinct, auditable identity per agent per task." Moreover, sometimes this oversight needs to go beyond the boundary of the enterprise to ensure it's done properly, observes Waseem Ahmed, head of engineering at Secure.com. "Independent oversight should mean outside reviewers who can inspect the logs and confirm the agent stayed inside the boundaries we set," he says. Act Now to Avoid Worst-Case Scenarios AI continues to raise other security concerns even as enterprises work toward locking down their agents. At the tame end of the spectrum is how generative AI is already making phishing, fraud, and impersonation scams more convincing. The extreme risks arise as ever-more capable systems potentially lower the barrier to sophisticated cyber or biological attacks, including global autonomous attacks and AI systems fully escaping human control. Whether those doomsday scenarios are realistic is still unclear, but experts say the more immediate lesson is this: AI doesn’t have to be hostile to pose a major security threat. For humans to lose control over AI agents, organizations need only give increasingly autonomous systems access to more of the corporate environment than their security controls can safely manage. Getting all stakeholders on the same page about how to harness this technology before it takes the reins is what Amodei hopes to achieve with his warning. Now is a good time to act, as current models are at an intersection of demonstrating both what can go very right and what can go very wrong with AI development. “I believe that if slowing down bought us even an extra year or two before models reach critical levels of capability," Amodei wrote, "and we used that time to advance alignment, we could greatly reduce the risk that something goes seriously wrong." About the Author Elizabeth Montalbano Contributing Writer Elizabeth Montalbano is freelance writer, editor, and journalist with 30 years of professional experience and a master's degree from Arizona State University. Her areas of expertise include enterprise technology, cybersecurity, business, and culture. During her long career, Elizabeth has lived and worked as a full-time journalist in Phoenix, San Francisco, and New York City. She specializes in news coverage and analysis, using her years of experience to look at the current state of cybersecurity with a critical gaze. She currently resides in a village on the southwest coast of Portugal, where in her free time she enjoys surfing, hiking with her dogs, growing plants, and playing and performing as a singer and musician. Want more Dark Reading stories in your Google search results? ADD US NOW More Insights Industry Reports The State of Cloud Security: The Latest Challenges How Organizations Are Managing Incident Response How Enterprises Are Developing Secure Applications Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy Essential News & Insights from Black Hat USA 2025 Access More Research Webinars Cybersecurity Outlook 2027 Threat Exposure Analytics: Measuring and Communicating Security Risk Benchmark Scores Are a False Flag Building an Effective Red Team: Beyond Penetration Testing How to Leverage Threat Intelligence Without Drowning: The Zero Noise Approach More Webinars You May Also Like CYBER RISK How Can CISOs Respond to Ransomware Getting More Violent? by James Doggett JAN 28, 2026 CYBER RISK US Cyber Pros Plead Guilty Over BlackCat Ransomware Activity by Alexander Culafi JAN 05, 2026 CYBER RISK Switching to Offense: US Makes Cyber Strategy Changes by Robert Lemos NOV 21, 2025 CYBER RISK Microsoft Exchange 'Under Imminent Threat,' Act Now by Arielle Waldman NOV 12, 2025 Featured Check out the Black Hat USA 2026 Conference Guide for coverage and intel from — and about — the show! Editor's Choice CYBERATTACKS & DATA BREACHES OpenAI Agents Took Over Wiki Site Before Hugging Face Attack byNate Nelson SEP 8, 2026 7 MIN RE

Share this article