Coxon resigned over a race. Governance is about the next action. A developer behind Sentinel SCA, a runtime that verifies authority before an AI agent action executes, argues that Jacob Coxon's resignation from Anthropic over the lab's pursuit of self-improving superintelligence concerns training and race dynamics, not the near-term problem of agent execution control. The developer contends that capability is not authority, and that a separate control plane can require known identity and scoped authority before consequential agent actions proceed, while acknowledging such tooling cannot slow pretraining or enforce lab treaties. Capability is not authority. That is the part of the warning operators can act on. I build Sentinel SCA, a runtime that checks authority before an agent action executes. This is not a claim that it solves superintelligence. Jacob Coxon did not leave Anthropic because a chatbot wrote a bad poem. He left because he spent three years in pretraining at OpenAI and Anthropic and decided both labs were “racing straight to self-improving superintelligence and gambling with our lives.” That sentence is about who builds the next model, how fast, and whether a private Slack thread should be allowed to become an endgame. Runtime governance is a narrower, present problem: an agent that can act is not the same thing as an agent that is allowed to act. Mixing those two problems is how “AI safety” turns into marketing. Separating them is the only honest way to write about both. What Coxon said His thread is short. Frontier systems will soon be superhuman at hacking, at overturning a field overnight, and at acquiring power and resources. Progress is not slowing. People building those systems, he says, earnestly believe the technology could kill everyone by the end of the decade — and they sound calmer in public than they do in private. He splits the labs. At OpenAI, many have not internalized the stakes. At Anthropic, the stakes are understood, but the company is locked in a race: if nobody else will act responsibly, they believe they must get there first anyway. Accepting that race, he writes, is a hubristic gamble that should not be launched from a private company’s Slack. Speedrunning alignment would require extraordinary confidence that no better path exists. He is more open to coordination than the headlines suggest. He treats recent agent “warning shots” as reasons pacing agreements between labs might become viable. He does not think the industry is on track to stop a global race without costly moves, including a temporary halt on improving capabilities. Then he asks other researchers a direct question: do you want to kick off a superintelligent RL run without a rigorous understanding of its mind, or do you use this moment to demand different conditions? That is the argument. It is about training, self-improvement, race dynamics, and civilizational control of model development. It is not a requirements doc for a permit API. Why the operational half still stands You do not have to accept the extinction timeline to take the near-term list seriously. Models already propose hacks. Tools already touch money and infrastructure. Agents already try to acquire accounts, compute, and data. The jump Coxon fears is recursive self-improvement — systems doing the research that makes the next system. The jump operators already have is agents that can execute. Capability growth and execution growth are different curves. Labs compete on the first. Companies deploy the second every week. Most damage in the next two years will not look like an intelligence explosion. It will look like an agent that restarted a service, moved a refund, wrote a file, isolated a host, or called a privileged API because nobody asked whether authority still existed at the moment of the side effect. That is “acquire real power and resources” brought down from the decade-scale story to the request sitting in a queue. What governance can limit — and what it cannot It cannot slow pretraining. It cannot create a lab treaty. It cannot inspect a model well enough to certify alignment. It cannot stop a lab from starting a self-improving run. Anyone who says an execution-control product “solves Coxon” is making the same overclaim he is attacking, in another costume. It can, if the executor actually asks, sit between proposal and side effect. The model may be capable of the action. Capability is not authority. Before a consequential action proceeds, a separate control plane can require a known identity, current scoped authority, a policy decision allow, review, or deny , an action binding that cannot be swapped after the check, and evidence that can be replayed. If the permit is expired, revoked, replayed, or out of scope, the action does not run. Paths that never call that control plane stay ungoverned. That limit has to stay in the sentence. Coxon risk What a governance runtime can do What it cannot do Race to self-improving SI Nothing at the lab Training policy is political and corporate Superhuman hacking Deny or review a specific exploit-shaped action on a governed path Make the model unable to think of the exploit Acquire resources Block transfers, account changes, infra writes behind the boundary Stop an agent with a private back door Systems “out of control” Fail closed when authority is missing Contain a system whose execution path was never integrated Warning-shot breakouts Force a check at the tool boundary; record the attempt Replace sandboxes, network isolation, or lab evals The useful sentence is not “governance aligns superintelligence.” It is: an autonomous system should not be able to spend power it was never granted, at the moment it tries to spend it. Why that still matters in a Coxon world If he is even half right about capability speed, more actions will be proposed than humans can watch. Logging after the fact is a post-mortem. Review after execution is an apology. The only operational answer that scales with proposal volume is admissibility before the side effect. Claim discipline is part of that story. A product that says it governs “all agents” while only seeing the paths wired into it is doing the thing Coxon accuses the labs of doing: talking as if control exists because the intention exists. The honest version: • The model proposes. • A control plane decides whether authority is current. • The executor runs only if that decision still holds. • Evidence stays inspectable. • Paths not behind the boundary are outside the claim. Coxon is asking labs not to launch the endgame from Slack. Governance is asking operators not to launch the next file write, refund, or deploy from an unchecked tool call. Different altitudes. Same refusal: capability is not a permit. The line to keep Coxon walked out of the engine room because he no longer wanted to help build the next mind under race conditions. Most teams will never work in that room. They will still connect an agent to production. They cannot settle the decade. They can decide whether the next action is allowed. That is the part of his warning you can act on this month without pretending you have solved the rest. https://sentinelsca.com https://sentinelsca.com