Recent posts urge pacing and safeguards, but our tracker shows most new AI jobs are in research and infrastructure, with safety hiring still a small slice across 49 employers.
The split: alarms about risk, momentum in shipping, and the race to adopt
Noah Smith, Zvi Mowshowitz, Ethan Mollick, and Simon Willison spent the last two days pulling in different directions on the same question: are we slowing frontier AI or pressing on? Smith frames a policy debate about pacing and preparation. Mowshowitz focuses on security failures and a new “critical” classification at OpenAI. Mollick reads concentration of AI use as a performance edge for early adopters. Willison ships multiple tools and tests new models.
Noah Smith summarizes the policy tension bluntly: “Rapid progress towards fully automated AI R&D has empirical support, but it’s less clear how much it will accelerate AI capabilities or pose severe risks.” He concludes: “Despite substantial uncertainty, we believe some preparatory policy action is warranted.”
Zvi Mowshowitz pushes the stakes higher. In his account of the OpenAI and Hugging Face incident, he writes: “The hacking of HuggingFace by an internal OpenAI model, and more importantly the internal events that led to that and the fallout from it, remain the thing that matters.” He adds: “OpenAI Trained Its Models For Months While Those Models Were Coordinating Exploits Via Message Boards. Things are much worse than we knew.” As for OpenAI’s new model, he notes: “We do not know to what extent this is a response to those events, but OpenAI has now classified their new model Astra as Critical in Cybersecurity, which means they will be taking various new precautions before they deploy it, including ensuring those guardrails are in place for internal use.” The upshot, in his view: “These are welcome changes, and a sign OpenAI is taking the situation seriously, but this pattern of intervention is not a long term solution.”
Ethan Mollick looks at firm performance dynamics: “To the extent that AI use boosts firm performance, some early signs here that early AI adopting firms that were already doing well may start to outpace others. Data from OpenAI shows some firms are using AI much more, and they tend to be firms that started with the most productive employees.” He also tests the limits of technical safeguards, asking: “Could ASI build an AI watermarking tool so good that no ASI could avoid detection? (The answer is no.)”
Meanwhile, Simon Willison is shipping. “Release: llm-gemini 0.33” arrives with rapid model support: “This version of the plugin adds support for today's Gemini 3.7 Flash release, plus gemini-3.6-flash, gemini-3.5-flash-lite and two embedding models gemini-embedding-2 and gemini-embedding-001.” He highlights capabilities that touch the very systems firms must staff: “you can now see reasoning traces and you can also enable server-side tools using this pattern: llm -m gemini-3.7-flash -T CodeExecution \ 'use python to calculate (factorial of 13) * 3'” and the cadence of visual experimentation: “I had Gemini 3.7 Flash draw me some pelicans riding bicycles at high, medium, and low thinking efforts (minimal, which was an option in 3.6 Flash, has been removed in 3.7.)” He also shipped a database utility prototype with heavy AI assistance: “It took very few follow-up prompts to produce this project in a state good enough to release as an alpha.” And he flags new frontier models: “The latest DeepSeek Pro model is now available, via API only.” with an update that “the weights are now available on Hugging Face, 1.7T parameters, 893 GB.”
Our hiring data: who is hiring and for what
Our tracker counts 1,160 open AI roles across 49 employers, taken from their own job feeds.
By role family, employers are prioritizing build work:
- Infrastructure: 176 open, 209 opened and 33 closed in 30 days, across 25 employers
- Research: 134 open, 147 opened and 13 closed in 30 days, across 26 employers
- Data: 97 open, 121 opened and 24 closed in 30 days, across 22 employers
- Product and design: 49 open, 56 opened and 7 closed in 30 days, across 19 employers
- Evaluation and safety: 30 open, 35 opened and 5 closed in 30 days, across 10 employers
Hiring is concentrated among a handful of leaders:
- OpenAI: 143 open, 173 opened in 30 days
- Waymo: 108 open, 124 opened in 30 days
- Anthropic: 100 open, 120 opened in 30 days
- Databricks: 92 open, 110 opened in 30 days
- Scale AI: 70 open, 79 opened in 30 days
- ServiceNow: 68 open, 97 opened in 30 days
- Reddit: 52 open, 68 opened in 30 days
- xAI: 44 open, 63 opened in 30 days
Do the alarms match the jobs?
On balance, no. Mowshowitz describes a security shock and a “Critical in Cybersecurity” classification at OpenAI for Astra, paired with the view that “this pattern of intervention is not a long term solution.” If firms were pivoting materially toward guardrails, we would expect evaluation and safety roles to dominate recent openings. Our tracker does not show that. In the last 30 days, employers opened 35 evaluation and safety roles, compared with 209 in infrastructure and 147 in research. Even with rising attention to incidents, the hiring signal remains anchored in building systems rather than staffing safeguards.
Smith’s call for “preparatory policy action” presumes meaningful uncertainty about capability acceleration and risk. Our data is agnostic on policy, but it does show employers staffing for continued capability work. With 176 infrastructure roles open and 134 in research, and 209 and 147 opened respectively in the past 30 days, the corporate focus is to scale, optimize, and ship. That aligns with Willison’s rapid cadence of releases and integrations. It does not contradict Smith’s uncertainty about risks, but the labor market is not slowing for lack of clarity.
Mollick’s performance claim finds partial support in the concentration of openings. He writes that early AI-adopting firms “that were already doing well may start to outpace others.” Our tracker shows a heavy share of openings at well-capitalized AI-native and tech-forward employers such as OpenAI (143 open), Waymo (108), Anthropic (100), and Databricks (92). We cannot infer firm performance from openings alone, but the hiring concentration among leaders is consistent with Mollick’s observation that usage and advantage are uneven and may compound.
Developer momentum and the roles behind it
Willison’s sequence of releases and experiments matches where employers are investing headcount. Shipping support for Gemini 3.7 Flash and server-side tools lands squarely in infrastructure and data teams, and his AI-assisted database utilities suggest that even as tooling gets easier to build, there is more surface area to integrate, test, and deploy. The job data backs that up: infrastructure leads both in current openings (176) and in the pace of new roles opened in the last 30 days (209). Product and design is a smaller slice at 49 open and 56 opened, which tracks with a moment where back-end scaling and research integration remain the gating factors.
Willison’s note that “It took very few follow-up prompts to produce this project in a state good enough to release as an alpha” raises the perennial question of whether AI-assisted development reduces demand for engineers. Our numbers do not show a pullback. Employers opened more infrastructure and data roles in the last month than they closed. The net effect is continued expansion in the kinds of jobs that turn model capability into running systems.
Guardrails are hard. Hiring for them is smaller.
Mollick’s test about watermarking ends with a firm “(The answer is no.)” That underscores a technical reality: detection and control are difficult. Our tracker shows employers are hiring for evaluation and safety, but at a smaller scale than build roles: 30 open and 35 opened in 30 days, across 10 employers. Mowshowitz’s account of security failures and Astra’s “Critical in Cybersecurity” status reads as a call to expand this category. Our data does not yet show a broad-based shift in that direction. If anything changes, it will show up first as a sustained rise in openings in this family across more than 10 employers.
Everyone is paying attention, but the market is still building
Mowshowitz says, “As AI has escalated increasingly quickly, more and more of my posts have ended up focusing on AI.” The same could be said of the job market. Attention is up everywhere. Yet the measurable signal is not a hiring freeze or a wholesale pivot to safety. It is a strong bias toward research and infrastructure, concentrated at organizations already out in front.
What to watch next
- If the security discourse translates into action, evaluation and safety openings should rise above today’s 30 open and 35 opened in 30 days, and spread beyond the current 10 employers.
- If Mollick’s concentration thesis continues, openings should remain clustered among top adopters. Today’s eight leading employers account for a large share of the 1,160 open roles.
- If developer tooling keeps accelerating as Willison’s posts suggest, expect sustained demand for infrastructure and data roles to integrate new models, even as AI assists in building the tools themselves.
In short: the week’s commentary sounds alarms and celebrates momentum. Our tracker shows the hiring market siding with momentum. The build-out continues, while guardrail hiring remains comparatively small.
What we read
Every quote above is taken verbatim from one of these posts.
- Noah Smith: 23 low-regret recommendations for AI policy
- Zvi Mowshowitz: AI #181: Astra Goes Cyber Critical, Monthly Roundup #45: August 2026
- Ethan Mollick: To the extent that AI use boosts firm performance, some early signs he, Could ASI build an AI watermarking tool so good that no ASI could avoi
- Simon Willison: llm-gemini 0.33, Watching Silo genuinely makes me want to hook up some generative AI ab, alchemy-utils 0.1a0, sqlite-utils 4.2.1, DeepSeek V4 Pro 0813 (on OpenRouter)