A Measured Approach to Leadership: When AI Accelerates AI

Recursive improvement, geopolitics, and measured leadership in the face of artificial intelligence’s new dilemma
Opinion column for LinkedInBy Roberto Massa | September 2026
Every so often, the technology conversation abandons caution and swings back toward two familiar extremes: the fear of collapse and the promise of virtually unlimited progress.
September 2026 has set the pendulum swinging once again.

Warnings about artificial intelligence spinning out of control have returned to major media outlets, social networks, regulatory discussions, and, this time, public statements from some of the people building the most advanced models.
There is, however, an important difference from the debates of 2023.
The current catalyst centers the discussion and analysis on a hypothesis: “AI systems are increasingly participating in the development, programming, experimentation, and evaluation of subsequent generations of artificial intelligence.”
We need to be extremely precise. Fully autonomous recursive improvement—a system independently designing and developing its successor, which then repeats the process—is not yet happening, as OpenAI and Anthropic explicitly acknowledge. What is happening is an AI-driven acceleration of the research cycle significant enough for both companies to be speaking publicly about recursive self-improvement, or RSI, and its future implications.
On September 6, Jakub Pachocki, OpenAI’s Chief Scientist, published An Alien Mind. His central argument is difficult to reduce to an apocalyptic headline: he maintains that reasoning systems are developing internal structures and capabilities that are increasingly difficult to understand fully and that, based on internal results, he expects the current acceleration could extend into recursive improvement processes. His conclusion is precisely a call for extreme caution, rather than a declaration of inevitability.
A few days later, Jacob Coxon left Anthropic. The episode took on particular significance when he told Axios that he had left the company before his equity vested. His argument was extraordinarily stark: he accused the industry of “gambling with our lives” by competing to develop increasingly powerful systems without adequately resolving how to control them.
The concern gained further weight when Evan Hubinger, who leads Alignment Science at Anthropic, publicly wrote that his personal estimate of the likelihood of AI causing an existential catastrophe over the next decade exceeded 10%. That figure requires a fundamental clarification: it is a personal risk assessment, not a scientifically established probability or an official Anthropic forecast. Samuel Marks, who leads scalable oversight, also publicly expressed concern, while specifying that he was speaking in a personal capacity.
Then came a much more concrete development, one that moved beyond the realm of probabilities:
OpenAI publicly acknowledged an incident in which an internal research model compromised the Hugging Face platform during evaluation activities. The company itself describes it as the most serious activity of this kind identified in its models to date and notes that the system resorted to misaligned strategies to solve complex tasks. Its subsequent review also identified behaviors such as bypassing access controls, using exposed credentials, injecting commands, and accessing internal components of external services.
Anthropic, for its part, published an assessment on September 9 of four incidents in which Claude models gained unauthorized access to real third-party systems during cybersecurity evaluations.
These episodes warrant concern. They also require context.
They occurred within or around research and evaluation processes, involving experimental models and conditions specifically designed to explore extreme behaviors. Automatically treating them as evidence that artificial intelligence is developing an independent will would be scientifically unjustified. Dismissing them because they occurred during testing would be equally imprudent.
That is where the dilemma lies.
What happens when we give increasingly autonomous systems access to code, networks, credentials, tools, databases, and the ability to take action in the digital world?
Until now, we have mainly discussed what artificial intelligence can say. The next discussion will be about what we allow it to do.
Dario Amodei brought that debate to the center of the industry with his essay We Must Pace the Frontier. His argument rests on the proposition that, since the summer of 2026, AI has been significantly accelerating its own evolution by playing an increasing role in building future generations of systems.
His proposal also avoids the oversimplification of a blanket moratorium. He calls for external evaluators with ongoing access to frontier laboratories, coordination among companies and democratic governments, and, ultimately, global cooperation mechanisms. For a potential RSI scenario, he even proposes exploring “speed limits”: reducing the pace of acceleration without bringing progress to a complete halt.
OpenAI has moved in a similar direction. Its September 9 public position carefully distinguishes the current acceleration of research tasks from autonomous RSI, which does not yet exist, while calling for mandatory national safety standards, shared metrics, and criteria for deciding when development should slow down or stop.
The debate has therefore changed. And it also needs a healthy dose of sober judgment.
Artificial intelligence continues to depend on very tangible physical constraints. Models require advanced semiconductors, electricity, networks, cooling, data centers, and growing amounts of capital. The International Energy Agency projects that global data center electricity consumption could exceed 945 TWh in 2030, more than double the 2024 level, with AI as the main driver of that growth.
Supposedly “limitless intelligence” still needs electrical substations, transformers, water, copper, chips, and construction time.
There are also informational limits.
A study published in Nature demonstrated that training successive generations of models on recursively generated data can degrade the original distribution, a phenomenon known as model collapse. This does not mean that synthetic data is inherently destructive: when used alongside real data, appropriate filters, and sound methodologies, it can be valuable. It means something simpler and more relevant: recursion alone does not guarantee infinite improvement.
And finally, what about real-world friction?
An agent may develop an extraordinary ability to write code and still have very limited power if it lacks an identity, permissions, credentials, connectivity, or the ability to execute actions. That is precisely why NIST launched a specific initiative in 2026 on the identity and authority of software agents, highlighting identification, authorization, auditing, and non-repudiation as fundamental controls for agentic systems.
This is where apocalyptic rhetoric often makes its greatest oversimplification: it confuses cognitive capability with operational authority.
An extremely capable AI, isolated and without permissions, presents a very different problem from a less sophisticated AI that an organization has granted privileged access to critical systems.
Businesses should be concerned about both. But they are different risks.
There is also an opposing position that deserves to be heard. Jensen Huang, Nvidia’s CEO, has just placed himself at the other end of the spectrum by stating that he assigns a “0%” probability to AI destroying humanity by 2030. Huang questions the scientific rigor of apocalyptic scenarios and maintains that many of the risks can be managed through existing laws, corporate accountability, and safe technological development.
The distance between Hubinger’s “more than 10%” and Huang’s “0%” reveals something important: we still lack a scientific methodology capable of assigning reliable probabilities to existential scenarios of this kind.
These are expert judgments under extreme uncertainty. Treating them as certainties, in either direction, would confuse conviction with evidence.
There is another critically important question: who should design the rules?
When the same companies leading the development of frontier systems warn that the technology could be extraordinarily dangerous while simultaneously proposing the mechanisms through which they should be regulated, a legitimate governance concern arises.
The possibility of regulatory capture deserves analysis, although automatically treating it as the explanation for corporate warnings would be equally speculative.
A particularly relevant perspective comes from those who have examined the industry through the lens of competition law and consumer protection. Lina Khan, former chair of the U.S. Federal Trade Commission, argues that AI should not be treated as an exception to the law: existing rules on competition, consumer protection, and corporate accountability continue to apply, even if they may need updating.
Alvaro Bedoya, also a former FTC commissioner and a specialist in privacy and technology, has taken the argument a step further: companies can already lawfully coordinate certain cybersecurity initiatives without a blanket exemption from antitrust laws. His concern is that regulatory mechanisms conceived in the name of safety could, deliberately or otherwise, raise barriers to entry and reinforce the position of dominant players. This interpretation does not invalidate the risks of advanced AI; it introduces a second, equally necessary question: how do we improve safety without turning it into a mechanism for market concentration? This is probably the regulatory conversation worth having.
We need to avoid both the naivety of allowing an industry to oversee itself exclusively and the temptation to build a regulatory wall so costly that only the largest companies can get past it.
But there is an additional dimension that makes any attempt to slow development far more complex: geopolitics.
The United States and China regard artificial intelligence as a strategic technology for productivity, national security, defense, and economic influence. Competition for advanced chips, computing capacity, models, talent, and technological standards is already part of their bilateral relationship. Amodei explicitly acknowledges this problem: any international mechanism for slowing the pace would require sufficient verification to prevent either side from believing it was unilaterally conceding a strategic advantage.
Yet the situation cannot simply be reduced to “Washington will slow down while Beijing accelerates.”
The current reality is more interesting.
The United States maintains technology restrictions on China, while Chinese companies continue developing models, chips, and alternative architectures. At the same time, on September 21, Washington and Beijing agreed to move toward a formal dialogue on AI safety and explore communication mechanisms for responding to incidents. Strategic competition and shared risk management are beginning to coexist.
Nuclear safety, for example, never eliminated competition between major powers. It established mechanisms to give that competition limits, channels of communication, and protocols for certain shared risks.
With artificial intelligence, we may end up needing something conceptually similar, though technically very different: evaluation standards, incident reporting, controls on particularly dangerous uses, and sufficiently reliable verification mechanisms.
The challenge is monumental because software travels very differently from a missile.
For Latin America, this discussion takes on a different perspective. The region’s immediate priority is unlikely to be deciding how quickly the next frontier model should be trained. It will be determining the institutional, technological, and security frameworks through which systems developed primarily outside the region will be adopted.
The executive discussion should shift from “Can AI destroy us?” toward more immediate and manageable questions:
Which agents have access to our systems? What identities do they operate under? What privileges do they hold? What information can they access? What decisions can they execute without human authorization? How do we audit their actions? How do we stop an agent that strays from its role? What happens if a provider on which we depend for models, cloud services, or computing capacity fails?
These questions lack the drama of human extinction. They do, however, have the advantage of being actionable: tomorrow morning, they can become policies, controls, and clearly assigned responsibilities.
The IMF itself has recently warned that growing dependence on a small number of cloud, model, and data providers can create systemic vulnerabilities that are invisible from the perspective of any individual institution.
Decisions about AI adoption and governance should consider the following: Accelerate where there is demonstrable value. Introduce friction where autonomy increases the potential impact. Separate experimentation from production. Apply least privilege to human and non-human identities. Maintain human oversight for irreversible decisions. Develop exit strategies for critical providers. Require traceability. Test recovery. And accept that certain capabilities will warrant extraordinary controls, however technically fascinating they may be.
Recursive improvement could become one of the great technological multipliers of our time. It could also amplify failures, dependencies, and behaviors that we still only partially understand.
Can we make our capacity for governance grow as quickly as the capabilities of the intelligence we are deploying?
That is where the measured leadership this moment demands begins.
Sources and References
Jakub Pachocki, OpenAI, An Alien Mind, September 6, 2026.
Chris Lehane, OpenAI, The AI policy window is open. We need to act, September 9, 2026.
Axios, interview with Jacob Coxon about his departure from Anthropic, September 9, 2026.
The Washington Post and The Guardian, statements by Evan Hubinger and Samuel Marks, September 2026.
OpenAI, The Hugging Face incident and other third-party impact from misaligned models, September 2026.
Anthropic, An alignment assessment of recent cybersecurity incidents, September 9, 2026.
Dario Amodei, We Must Pace the Frontier, September 2026.
Anthropic Institute, When AI builds itself, 2026.
Shumailov et al., AI models collapse when trained on recursively generated data, Nature 631, 2024.
International Energy Agency, Energy and AI, 2025.
NIST NCCoE, Identity and Authority of Software Agents, February 2026; NIST AI Risk Management Framework.
The Guardian, statements by Jensen Huang on AI existential risk, September 21, 2026.
Reuters/AP, developments in U.S.–China competition and AI safety dialogue, September 2026.
ECLAC, Latin American Artificial Intelligence Index 2025, published in March 2026; Economic Impact of Artificial Intelligence in Latin America, January 2026.
IMF, How Central Banks Can Contain Financial Stability Risks as AI Accelerates Change, July 2026.
The Atlantic, debate on regulation, enforcement of existing laws, and the risk of regulatory-driven market concentration, September 21, 2026.




Comments