Pacing Is a PR Mistake; Cyberattacks Are the Real Risk
Frontier labs packaging safety as pacing pleases no one; the real emergency is CVE weaponization compressing from years to minutes, while enterprises still have no agents, only faster search.
The video won't play here. Listen to the audio instead:
The argument · tap a timestamp to hear it
Pacing is a PR mistake, not a safety strategy
Ali thinks frontier labs packaging "safety" as "pacing" is a textbook PR mistake. Pacing is orthogonal to safety — you can build weapons slowly, and that is no different from building weapons; and these companies have been running full speed and buying more compute, so nobody believes pacing. The result pleases no one: doomers think it is not a pause, policy people think you cannot execute. What they should be saying, he argues, is "secure the frontier," not "pace the frontier."
— Ali GhodsiRSI only counts if four conditions hold at once
Ali gives four criteria for whether recursive self-improvement is happening, and all must hold simultaneously: the next generation of models needs fewer resources (GPUs) to train, takes less time to train, is smarter/more accurate, and these three things can repeat over and over. If any one fails, the system self-limits — hold resources constant, for instance, and you hit a hardware wall. He stresses that "software writing software" is already happening, with over 90% of software at Databricks written by AI, but that is not the same as superintelligence.
— Ali GhodsiThe cost curve for frontier training runs the other way
Sarah points out that the compute bar for training frontier models keeps rising, from 100 million to 1 billion, and now roughly 5 to 10 billion. Ali adds: there are only one or two such training runs a year, and they violate all four criteria — they need more resources, more people, are more fragile, and require building data centers, networking, and better fault tolerance. Several have blown up, and failure means burning enormous sums. So the reality is "slower, more fragile, harder," not "faster, cheaper, smarter."
— Ali Ghodsi / Sarah WangWeaponization time for a vulnerability went from years to hours
Ali gives this curve: in 2018 and 2019, a CVE took roughly two to three years from disclosure to weaponization; by 2022 it was down to eight or nine months; from 2022 to now it has compressed to basically hours, almost no time at all. The reason is that data and AI are merging with the cybersecurity market — companies run large numbers of agents internally, generating massive logs and traces, and the volume of data that needs analysis is orders of magnitude larger than a year or two ago.
— Ali GhodsiSay AI will destroy the world, then ask for IPO allocation
Ali concedes two things can be true at once: some people really are scared by AI risk, and some people want regulation to "pace us" — because slowing down benefits them. He says people can always reconcile self-interest and fear into a harmonious whole in their heads. The industry has long had this marketing move: the moment a new model is trained, shout about how terrifyingly good it is, and the world's attention arrives. But he also gives the other side: the time from CVE to actual weaponized exploit went from years to minutes in three or four years, and cyberattacks are real. So "scary" is both a genuine risk and excellent marketing.
— Ali GhodsiEnterprises have no agents, only faster search
Ali polled the room live: how many people are managing hundreds or thousands of agents coordinating and negotiating with each other? Almost no hands. Most enterprises use Microsoft Copilot, which is essentially a chatbot — "a very, very glorified, efficient Google search." Coding is the only scenario that has truly landed, and even its ROI is debatable. He thinks the reason is not that models are not smart enough, but that models lack the organization's internal context: they have not sat in every meeting, do not know what is in everyone's head, do not know the processes. Every organization has a few employees who know everything, and when you tap them on the shoulder you think, "what if he quits?" Pour that context into today's frontier models and you get enormous productivity, and that does not require a smarter model.
— Ali GhodsiOntology is that employee who has been there five years
Ali explains ontology with a concrete picture: two people equally smart, equally hardworking, with identical educational backgrounds — one on their first day, one who has been there five years. The difference is that the latter knows how the organization runs, who people are, how things get done — "don't look at the org chart, don't ask that guy, he can't get anything done." That is ontology, the tacit knowledge scattered across everyone's heads. He contrasts it with the state of agents today: the agentic loop today looks up resources one at a time, like Google crawling ten sites live on every search, taking ten minutes, and then handing you ten blue links — expensive, slow and bad. Google's answer was the index, and AI also needs that index computed offline, only harder — because of permission constraints, data I can access is not necessarily data you can access, and the object types go far beyond web pages.
— Ali GhodsiSame model, different harness, nearly 2x the cost
Databricks's answer is a full cost governance stack: Unity Gateway provides token capacity for OpenAI, Anthropic, Gemini, Grok and open-source models, sets budget caps and alerts by person and by group, does cost forecasting analytics, and adds intelligent routing to switch to cheaper models when near budget or when the question is simple. Ali gives a concrete number: the same model, the same version, changing only the harness, can differ in actual cost by nearly 2x. Their in-house harness is called Omnigent, which can multiplex across different harnesses. The result is token usage keeps rising while AI cost stays roughly flat.
— Ali GhodsiIn their own words · checked verbatim
First off, it's orthogonal to safety and security. Like you can slowly build a weapon. That's not different than building a weapon.
Ali Ghodsi6:16
there's so much infrastructure that's insecure right and if you're going to unleash these agents they're going to find loopholes they're going to find exploits they're going to break in here and there
Ali Ghodsi20:39
I do think that there are people saying like, hey, if there was a regulation that would pace us, sorry to use the word, that would be good for us. Right. That would be good for us.
Ali Ghodsi32:44
But at the same time, also, as I said, the time from CVE to actually weaponize exploit has like been going down from years down to like minutes now, just in like three, four years. So it's real. The cyber attacks are real. And this is, but there's also a great marketing ploy to, you know, whenever you train a new model, make lots of noise around how much of a, you know, crazy risk it is to the world.
Ali Ghodsi33:45
One has an ontology of how that organization works, who the people are, how you get stuff done. Don't look at the org chart. Don't go ask that person. He will not get anything done.
Ali Ghodsi47:01
So how do they do it? They have an index, right? You never leave Google servers. You search for, it hits the index, the reverse index immediately gets you the 10 blue links within, you know, less than 100 milliseconds. We need to do the same thing for the AI.
Ali Ghodsi49:02
Turns out actually the harness itself matters. Like if you use the same model but different harnesses, there's almost 2x different cost difference. Even exactly the same model. You know, same version but different harnesses. You get 2x difference in actual cost.
Ali Ghodsi56:08
So, by dollar, open source is like 5%. It's very little, but by token count, it's over 60%.
Ali Ghodsi59:09
Figures
| Share of software at Databricks written by AI | over 90% | 13:24 |
| Compute cost of training a frontier model | 5 billion to 10 billion dollars | 15:24 |
| Time from CVE disclosure to weaponization (2018-2019) | two to three years | 24:40 |
| Time from CVE disclosure to weaponization (2022) | eight to nine months | 24:40 |
| Time from CVE to weaponized exploit | from years down to minutes, within three or four years | 33:45 |
| Rate at which the price of intelligence falls | roughly one tenth every six months | 41:52 |
| Cost difference for the same model with a different harness | nearly 2x | 56:08 |
| Open-source model share | about 5% by dollars, over 60% by token count | 59:09 |
| Share of databases created by agents on Neon/Lakebase | over 90% | 1:06:27 |
| Neon database startup/clone time | well under one second | 1:04:22 |
Glossary
- pacing
- The framing frontier labs use to package safety issues, arguing for deliberately slowing the pace of AI development.
- RSI
- AI that can improve the next generation of AI, forming a self-accelerating loop.
- CVE
- The numbering system that publicly records software security vulnerabilities.
- ontology
- The tacit knowledge structure inside an organization about people, processes and permissions.
- harness
- The software layer that wraps a model and handles tool dispatch and context.
- branching
- Lightly spinning up multiple branches on the same database so agents can experiment in parallel.
How to listen
Founders, investors and engineers tracking AI safety narratives, enterprise agent adoption and cost governance, especially anyone building agent products.
The pacing PR discussion from 0:00-7:17 can be fast-forwarded; the core mechanics are in the back half.