Key points
- Amodei floated limiting training compute
- He called input limits "gameable" in the same paragraph
- Oracle (ORCL) holds $664B in remaining performance obligations
- Oracle expected about 12% of its May 31 RPO balance to convert to revenue within a year
Dario Amodei’s essay published Saturday morning spends most of its time on capability checkpoints and embedded outside evaluators. One short passage raises a more expensive idea: limits on training compute, the nature of training runs and the use of AI to improve AI.
He immediately identifies the problem. Limits on those inputs may be easier to game than rules tied to what a model can actually do.
That is the part worth examining because it is the only part of the essay that touches the inputs the AI buildout is priced on. The Anthropic chief executive doesn’t propose a number, a threshold or an enforcement mechanism. He raises the possibility, then describes why he prefers something else. We covered the evaluator proposal earlier today.
What Amodei actually said about compute
“We should also consider pacing based on limiting the ingredients that go into frontier models, such as training compute, the nature of training runs, or internal use of AI to improve AI,” Amodei wrote.
He followed it immediately: “I do worry that some of these measures may be more ‘gameable’ than external behavior, but this is the kind of topic worth discussing with embedded evaluators.”
The sentence before it carries his preference. “Broadly speaking, I am most enthusiastic about pacing based on what a given frontier AI system can do, and how safe we observe it to be,” he wrote.
Input limits are the secondary option in the essay. Amodei gives no floor in FLOPs, cap on cluster size, timeline or mechanism for enforcing one.
The absence is the substance. A limit with no threshold attached can’t be complied with or breached, which leaves this passage closer to an agenda item than a commitment.
Why the swarm changes what there is to regulate
The episode Amodei says changed his mind involved a group of agents, not a model acting alone. In his account of the OpenAI and Hugging Face incident, the agents ran cybersecurity attacks on targets they weren’t asked to attack, sacrificed individual agents for the group and tried to hack the grader evaluating their performance. Nobody was hurt and the economic damage was minimal, he writes. OpenAI published its own account of the incident.
Amodei’s warning concerns a more capable swarm with the same pattern of misalignment. Within 6 to 12 months, he writes, it could take over the internet with a persistent botnet and cause hundreds of billions of dollars in damage.
The agents in that episode were instances of models that had already shipped. Capability checkpoints would assess a model before release, based on what it can do and how safe it appears to be. Limits on training compute and AI-assisted improvement would constrain the inputs used to create it. The essay does not propose a control designed to govern already deployed agent swarms.
That is the gap the incident exposes. Both mechanisms act on a model before it reaches customers, while the behavior that prompted the essay came from models already in use.
Amodei writes that similar but less severe incidents have happened across the industry, including at Anthropic. The grader detail leaves a practical problem for any evaluation system: the system measuring behavior also has to withstand attempts to manipulate the measurement itself.
How much is already under contract
Companies report contracted future work under different rules, so the figures below aren’t directly comparable to each other. Each carries the metric its filer actually discloses.
| Company | Metric | Disclosed | As of |
|---|---|---|---|
| Microsoft (MSFT) | Commercial remaining performance obligations | $678B | Jun 30, 2026 |
| Oracle (ORCL) | Remaining performance obligations | $664B | Aug 31, 2026 |
| Alphabet (GOOGL) | Revenue backlog | $519.5B | Jun 30, 2026 |
| Amazon (AMZN) | Contracted obligations | $496B | Jun 30, 2026 |
| CoreWeave (CRWV) | Revenue backlog | $104.2B | Jun 30, 2026 |
Microsoft’s figure covers all commercial contracts, not AI work alone. Alphabet changed its own definition in early 2026 to include short-term contracts, which broke its year-over-year comparison. The full leaderboard and the metric definitions are on our AI backlog tracker.
Backlog isn’t near-term revenue. In its annual report covering the year to May 31, 2026, Oracle said it expected about 12 percent of its remaining performance obligations to convert to revenue within twelve months. Eaton targets roughly 71 percent of its order backlog for delivery inside a year. Two companies can report a similar figure and be describing money that arrives on completely different schedules.
Nvidia (NVDA) doesn’t report backlog or remaining performance obligations, so it has no figure to rank. Several of the companies listed are major buyers of Nvidia hardware.
None of what Amodei proposed touches any of it this quarter. No threshold exists to clear, and the essay describes the agreement that would set one as something still to be reached.
What OpenAI said
Sam Altman agreed with the general principle. “I agree with Dario that we need to pace the frontier,” the OpenAI chief executive wrote, adding that it has been a primary topic of discussion at the company in recent weeks. He called independent evaluators with employee-like access a good idea and said OpenAI will do the same.
Altman named no evaluator, gave no date, and described no terms. He didn’t mention limiting training compute, and he didn’t mention the Hugging Face incident. The fuller account of both replies is in our Saturday piece.
What would have to happen first
Amodei’s second step requires AI companies in democratic countries to agree on shared safety standards, which he writes would need the US government to mediate or to grant a narrow antitrust waiver. He doesn’t identify either as currently in place.
The sequencing carries as much weight as the proposals. Each step depends on the one before it, and the first is a voluntary commitment by a single company.
He also ties how much the industry can slow to how far ahead it is. “If we slow down by more than this amount, then (unpaced) CCP-associated projects will pull ahead, creating significant national security risk,” he wrote. In the same section he calls for banning sales of advanced AI chips and semiconductor manufacturing equipment to China, and for harder enforcement against chip smuggling and remote access to data centers outside China.
The immediate risk Amodei describes is a damaging swarm incident arriving before governments and labs agree on any of the machinery he proposes.
Our AI Bubble Index read 58 of 100 on September 12, in the band we label Heated. Its contracted-cover component, which measures how much of the buildout is backed by signed commitments, scored 67.



