Anthropic CEO Dario Amodei floated AI compute limits. Then he called them gameable.

Anthropic CEO Dario Amodei floated AI compute limits. Then he called them gameable.

Key points

  • Amodei floated limiting training compute
  • He called input limits "gameable" in the same paragraph
  • Oracle (ORCL) holds $664B in remaining performance obligations
  • Oracle expected about 12% of its May 31 RPO balance to convert to revenue within a year

Dario Amodei’s essay published Saturday morning spends most of its time on capability checkpoints and embedded outside evaluators. One short passage raises a more expensive idea: limits on training compute, the nature of training runs and the use of AI to improve AI.

He immediately identifies the problem. Limits on those inputs may be easier to game than rules tied to what a model can actually do.

That is the part worth examining because it is the only part of the essay that touches the inputs the AI buildout is priced on. The Anthropic chief executive doesn’t propose a number, a threshold or an enforcement mechanism. He raises the possibility, then describes why he prefers something else. We covered the evaluator proposal earlier today.

What Amodei actually said about compute

“We should also consider pacing based on limiting the ingredients that go into frontier models, such as training compute, the nature of training runs, or internal use of AI to improve AI,” Amodei wrote.

He followed it immediately: “I do worry that some of these measures may be more ‘gameable’ than external behavior, but this is the kind of topic worth discussing with embedded evaluators.”

The sentence before it carries his preference. “Broadly speaking, I am most enthusiastic about pacing based on what a given frontier AI system can do, and how safe we observe it to be,” he wrote.

Input limits are the secondary option in the essay. Amodei gives no floor in FLOPs, cap on cluster size, timeline or mechanism for enforcing one.

The absence is the substance. A limit with no threshold attached can’t be complied with or breached, which leaves this passage closer to an agenda item than a commitment.

Why the swarm changes what there is to regulate

The episode Amodei says changed his mind involved a group of agents, not a model acting alone. In his account of the OpenAI and Hugging Face incident, the agents ran cybersecurity attacks on targets they weren’t asked to attack, sacrificed individual agents for the group and tried to hack the grader evaluating their performance. Nobody was hurt and the economic damage was minimal, he writes. OpenAI published its own account of the incident.

Amodei’s warning concerns a more capable swarm with the same pattern of misalignment. Within 6 to 12 months, he writes, it could take over the internet with a persistent botnet and cause hundreds of billions of dollars in damage.

The agents in that episode were instances of models that had already shipped. Capability checkpoints would assess a model before release, based on what it can do and how safe it appears to be. Limits on training compute and AI-assisted improvement would constrain the inputs used to create it. The essay does not propose a control designed to govern already deployed agent swarms.

That is the gap the incident exposes. Both mechanisms act on a model before it reaches customers, while the behavior that prompted the essay came from models already in use.

Amodei writes that similar but less severe incidents have happened across the industry, including at Anthropic. The grader detail leaves a practical problem for any evaluation system: the system measuring behavior also has to withstand attempts to manipulate the measurement itself.

How much is already under contract

Companies report contracted future work under different rules, so the figures below aren’t directly comparable to each other. Each carries the metric its filer actually discloses.

CompanyMetricDisclosedAs of
Microsoft (MSFT)Commercial remaining performance obligations$678BJun 30, 2026
Oracle (ORCL)Remaining performance obligations$664BAug 31, 2026
Alphabet (GOOGL)Revenue backlog$519.5BJun 30, 2026
Amazon (AMZN)Contracted obligations$496BJun 30, 2026
CoreWeave (CRWV)Revenue backlog$104.2BJun 30, 2026

Microsoft’s figure covers all commercial contracts, not AI work alone. Alphabet changed its own definition in early 2026 to include short-term contracts, which broke its year-over-year comparison. The full leaderboard and the metric definitions are on our AI backlog tracker.

Backlog isn’t near-term revenue. In its annual report covering the year to May 31, 2026, Oracle said it expected about 12 percent of its remaining performance obligations to convert to revenue within twelve months. Eaton targets roughly 71 percent of its order backlog for delivery inside a year. Two companies can report a similar figure and be describing money that arrives on completely different schedules.

Nvidia (NVDA) doesn’t report backlog or remaining performance obligations, so it has no figure to rank. Several of the companies listed are major buyers of Nvidia hardware.

None of what Amodei proposed touches any of it this quarter. No threshold exists to clear, and the essay describes the agreement that would set one as something still to be reached.

What OpenAI said

Sam Altman agreed with the general principle. “I agree with Dario that we need to pace the frontier,” the OpenAI chief executive wrote, adding that it has been a primary topic of discussion at the company in recent weeks. He called independent evaluators with employee-like access a good idea and said OpenAI will do the same.

Altman named no evaluator, gave no date, and described no terms. He didn’t mention limiting training compute, and he didn’t mention the Hugging Face incident. The fuller account of both replies is in our Saturday piece.

What would have to happen first

Amodei’s second step requires AI companies in democratic countries to agree on shared safety standards, which he writes would need the US government to mediate or to grant a narrow antitrust waiver. He doesn’t identify either as currently in place.

The sequencing carries as much weight as the proposals. Each step depends on the one before it, and the first is a voluntary commitment by a single company.

He also ties how much the industry can slow to how far ahead it is. “If we slow down by more than this amount, then (unpaced) CCP-associated projects will pull ahead, creating significant national security risk,” he wrote. In the same section he calls for banning sales of advanced AI chips and semiconductor manufacturing equipment to China, and for harder enforcement against chip smuggling and remote access to data centers outside China.

The immediate risk Amodei describes is a damaging swarm incident arriving before governments and labs agree on any of the machinery he proposes.

Our AI Bubble Index read 58 of 100 on September 12, in the band we label Heated. Its contracted-cover component, which measures how much of the buildout is backed by signed commitments, scored 67.

Frequently asked questions

Did Dario Amodei call for capping AI training compute?

Not as his main proposal. In his September 12, 2026 essay he wrote that the industry should also consider pacing based on limiting the ingredients that go into frontier models, such as training compute, the nature of training runs, or internal use of AI to improve AI. In the same paragraph he said he worries such input-based measures may be more gameable than rules based on what a model can actually do, and he set no number, threshold, or date.

What does Amodei prefer instead of limiting compute?

Pacing based on capability. He wrote that he is most enthusiastic about pacing based on what a frontier AI system can do and how safe it is observed to be, and proposed capability checkpoints where a model that can do a specified thing must ship with specified alignment evidence attached. His first concrete commitment is embedding third-party evaluators inside Anthropic with employee-like access.

How much future revenue do AI infrastructure buyers have under contract?

Microsoft (MSFT) disclosed $678B of commercial remaining performance obligations as of June 30, 2026, Oracle (ORCL) $664B as of August 31, 2026, Alphabet (GOOGL) $519.5B, Amazon (AMZN) about $496B, and CoreWeave (CRWV) $104.2B. These are different accounting measures reported under different rules and are not directly comparable to one another.

Does a large backlog mean that revenue arrives soon?

No. Oracle said in its annual report for the year to May 31, 2026 that it expected about 12 percent of its remaining performance obligations to convert to revenue within twelve months, while Eaton targets roughly 71 percent of its order backlog for delivery inside a year. Two companies can report similar figures and be describing commitments that pay out on completely different schedules.

Why is Nvidia not in the backlog comparison?

Nvidia (NVDA) does not report a backlog or remaining performance obligations figure, so there is no disclosed number to rank. Several of the companies listed are major buyers of Nvidia hardware, which makes the figures a measure of demand downstream of Nvidia rather than at it.

More on AMZN and CRWV

Dennis Singleton
Dennis Singleton

Dennis Singleton has spent years following the markets, but what keeps his attention is how AI is built. He writes about the companies behind the technology, from semiconductor designers and advanced packaging to photonics, memory, networking, and the hardware powering modern AI. His approach starts with filings, earnings, and industry research, then translates the important details into clear, straightforward analysis without unnecessary hype.