Calls to slow frontier AI development surged over the weekend, sharpening a more immediate question for security teams: how quickly can they fix the vulnerabilities AI already found?
Anthropic CEO Dario Amodei called Saturday for AI companies to slow the advancement of their most capable models, citing concerns about misuse and safety. OpenAI CEO Sam Altman and Google DeepMind Cofounder Demis Hassabis also backed the push.
For Dave McGinnis, Vice President and Senior Partner for Global Cyber Threat Management at IBM, any slowdown could give companies more reason to focus on systems already in use.
“I think pumping the brakes a bit is a good thing,” McGinnis told IBM Think in an interview. “When the researchers themselves do it, I think the industry should heed the warning and adjust accordingly.”
Companies should pay closer attention to governance, visibility and traceability around existing AI deployments while continuing to strengthen their defenses, McGinnis said. He also warned against assuming every model developer would slow down.
“The open-source models, some from non-trusted sources, are not pausing,” McGinnis said.
That makes securing the open-source software ecosystem especially important, he said. IBM and Red Hat launched Lightwell in May as part of a USD 5 billion commitment to improve open-source software security. IBM said the effort would use AI-assisted vulnerability review, triage and prioritization along with patch development, dependency hardening and release engineering.
The project expanded in June when IBM, Red Hat and Palo Alto Networks combined vulnerability discovery, virtual patching and software remediation capabilities. The companies said the approach could help reduce the time between finding a vulnerability and protecting systems from exploitation.
Current AI systems could already help companies find advanced vulnerabilities and attack paths, accelerate patching and mitigation, investigate security alerts and manage security controls, McGinnis said. The 2026 Cost of a Data Breach report found that only 18% of security teams are using AI agents for vulnerability scans and management, though agent adoption and investment in this area are expected to increase in the coming year.
A broader slowdown could prove difficult to coordinate, according to Bruce Schneier, a security technologist, Harvard Kennedy School lecturer and fellow and Chief of Security Architecture at Inrupt.
“If we are assuming some sort of world government that collectively slows AI development across the board, then the best thing they could do from a societal perspective is to prioritize security and safety,” Schneier told IBM Think in an interview.
Companies should pursue multiple safeguards rather than choose among evaluations, access controls, monitoring and red teaming, Schneier said.
For McGinnis, defenders do not need to wait for the broader debate to be settled.
“Companies should use the current models to bolster their defenses,” he said.
Stay up to date on the most important—and intriguing—industry trends on AI, automation, data and beyond with the Think newsletter. See the IBM Privacy Statement.