Would an AI Slowdown Buy Defenders Enough Time?
Back to top
September 16, 2026
Would an AI Slowdown Buy Defenders Enough Time?
Anthropic CEO Dario Amodei’s weekend proposal to slow frontier AI development drew quick agreement from other industry leaders. OpenAI’s Sam Altman posted on X that he backs pacing frontier AI development, and xAI’s CEO, Elon Musk, conveyed the same sentiment. The thinking is that too many unknown unknowns exist to proceed at the current pace. A more measured approach would better prevent a “techno-apocalypse.”
On Friday, computer scientist and Nobel Prize winner Geoffery Hinton, known as the “godfather of AI,” told the BBC that estimating a 10% chance of AI wiping out humanity isn’t unreasonable.
However, for many, the AI development slowdown feels a bit belated. Across the past year, the security industry has dealt with an interrelated challenge: AI-accelerated threats moving at a much faster pace than organizations can keep up with.
The average threat breakout time (from initial access to lateral movement) is a mere 29 minutes, with the fastest recorded breakout having occurred at 27 seconds, according to CrowdStrike.
At the same time, organizations are contending with unanticipated risk from the AI models and agents that they’ve deployed. More than half (55%) of security leaders cited AI agents and Gen AI applications as the biggest attack-surface risk facing their organization, according to the 2026 ExtraHop Global Threat Landscape Report.
A regulatory slowdown won't move the needle on threats already running inside networks. Damage from network intrusions comes down to one thing: whether they're observed in real time, and right now, most aren't.
Threat Speed Is Outpacing Human Response
Human response times can’t compete with machine-speed threats.
When threat actors use AI, the window between initial access and full compromise collapses from days to minutes (or seconds). When internal AI agents operate without oversight, the window between a flawed decision and its consequences also becomes non-extant.
External payloads evade detection by moving faster than signature-based tools can identify them and internal models routinely break out of sandboxes despite the governance built into them.
Few organizations can see either happening in real time. No security leader wants to explain a machine-speed gap after an incident, internal or external, especially if it could have been observed and stopped beforehand.
Where Security Assumptions Break Down
Traditional security architecture set-ups assume that perimeter tools will catch external intrusions and that sandboxes or role-based permissions will contain internal AI agents. However, in most cases, neither assumption survives contact with reality.
- Externally, AI-driven payloads no longer need noisy command-and-control traffic to move — they analyze the host environment and move laterally without making a sound.
- Internally, unsanctioned model integrations and unmonitored API calls expand the attack surface just as quickly, often before anyone signs off on them.
Governing the risks responsibly means replacing assumptions — about what a model is designed to do, or what an attacker is capable of — with independent evidence: what a system accesses, where it moves data, what it talks to, what actions it takes.
How Security Leaders Should Proceed
Focusing on three priorities helps security teams keep pace with AI-driven activity — whether the activity originates inside the network or outside of it:
- Eliminating data center blind spots. Inspect east-west traffic at line rate. Lateral movement is lateral movement whether it starts with an external intrusion or an internal agent gone off-script — neither can be stopped if it cannot be observed.
- Verifying independently. Treat vendor safety controls and software sandboxes as claims, not proof, for AI agents built in-house. Hold perimeter and endpoint tools to the same standard for external intrusions. Confirm every action, from either direction, against independent network monitoring.
- Giving defensive agents full context. Ground defensive agents in rich, unsampled network context so they intercept threats without generating false confidence.
Leadership teams that can already see what’s happening inside their network, internal agent or external adversary, and act on that visibility at machine speed, have an edge right now, policy pause or not.
To learn more about keeping your organization safe in the age of AI, read The Next “Frontier” – Defending the Modern Data Center at 400 Gbps Machine Speed.
Discover more

Chief Evangelist
Heath Mullins is the Chief Evangelist at ExtraHop with 27+ years of experience designing global network architectures and threat detection strategies. Heath Mullins previously served as a Senior Analyst at Forrester advising Global 100 enterprises and specializes in implementing zero-trust methodologies through Network Detection and Response (NDR) deployments. View Heath Mullins’ complete professional profile on LinkedIn.
Share
Key Takeaways
- Security teams have already been living the AI-accelerated threat reality for months, since long before this past weekend's proposal.
- Machine-speed risk comes from two directions: external attackers running AI-driven tools, and the enterprise's own AI agents.
- AI governance works best when grounded in what a model actually does rather than what it's designed to do.
- Network traffic offers the one signal in the enterprise that grounds AI governance in observed behavior.
- Eliminating blind spots, verifying independently, and equipping defensive agents with context keeps teams ahead at machine speed.


