As we contemplate a slow-down on model progress. I think it's important to ask what a pause would mean for cyber defence.
As the co-founder of a cyber defence company, I personally think there's years of progress we could make in elicitation and diffusion if we froze at Fable-level capabilities.
For example, looking at one type of work security teams need to do on the regular: evidence collection and control mapping. Organisations have a bank of controls that they use to regulate what is permissible e.g. "all privileged accounts must have MFA" or "all development work must be done on a remote VM with a secure OS". Practitioners then need to manually assess whether this control is enforced across all of the relevant assets an organisation owns or across all of the people that work there.
Today there are too many assets, people and programs for these teams to assess, so they sample a controls' effectiveness or use deterministic rules. However, this work is relatively easy for an AI model, it involves some multi-modal understanding but primarily reasoning across textual inputs. On our evals, this sort of work is easily handled by the Opus 5 and Terra 5.6 class of models.
It would be a phase change for cyber defence if controls were assessed at a population level not by sampling. That is by looking at everything an organisation is doing.
This is just one example, but there are countless others where a pause wouldn't impact progress.