For anyone running a business
Do you already have a plan for the vulnerabilities AI is bringing inside your company?
Two concrete questions serve as a test. Could someone at your company paste the ERP or SaaS password into a tool they built alone with AI? And does your company already have a written policy, spelling out limits and rules for AI use, that explicitly forbids that? Capability and autonomy are separate things: a system being capable of doing something doesn't mean it should be authorized to do it alone, especially with a password to access and operate legacy systems unsupervised. Autonomy is a deployment decision, and it's yours. On the other side of the counter, attackers are using the same tools to move faster, and that asymmetry is what the week laid bare.
The Astra pause is one of the clearest cases yet of a frontier lab halting internal activity because a model may have hit the top of its own risk scale. On the company's scale, "Critical" means being able to find and exploit flaws in well-protected systems on its own, without human help. The assessment is preliminary, according to OpenAI itself.
In Sanders's letter, the method matters more than the ask: he didn't propose a new principle, he demanded the companies live up to commitments they themselves had already published. It's the first time a lab's voluntary commitment has become a tool for political pressure, and that changes the calculus for whoever publishes commitments next.
There's a layer the coverage missed that changes the nature of the episode. On June 4, Anthropic itself published "When AI Builds Itself," signed by Marina Favaro and Jack Clark, arguing the world should have the option to temporarily pause frontier model development. The condition is decisive: the company argued a pause would only make sense if coordinated across multiple countries and companies, with verifiable rules, and warned that a unilateral slowdown would leave everyone less safe, because it would hand an advantage to whoever cares least about safety. Sanders is asking each company, separately, for exactly what Anthropic said, two months earlier, doesn't work separately. This isn't Congress versus industry: it's two diagnoses that agree on the risk and disagree on the instrument.
Z.ai's claim closes out the week on the racing side. The company says it has come close to Anthropic's most advanced model on cybersecurity, beating it on one vulnerability-identification benchmark while trailing well behind on attack construction. These are figures from the vendor itself about a competitor's model, without independent verification, and should be read that way. What matters isn't the scoreboard: it's that frontier cyber-capability became a sales pitch in the same week it became a reason to hit the brakes.
And a note on proximity: in the same week it paused a model over cyber risk, OpenAI moved frontier cyber-capability closer to market. These aren't contradictory positions, one deals with capability that isn't yet well understood how to measure, the other with capability already assessed and fenced in, but the gap between the two shows just how narrow the line is that the industry is walking.