We Need to Pace More Than the AI Frontier

What studying cybersecurity leaders is teaching us about the human cost of accelerating faster than we can adapt

Eighteen months ago, I thought I was studying burnout in cybersecurity.

I don't anymore.

I spent nearly 20 years working in cybersecurity before leaving the corporate world and eventually founding Green Shoe. I had experienced burnout myself more than once, and when we began our research, I wanted to better understand what was happening to cybersecurity leaders operating under extraordinary and sustained pressure.

Burnout was the obvious place to start.

But the more CISOs we interviewed, the more leaders I coached, and the more cybersecurity teams we worked with, the more I began to think burnout was only part of the story.

The bigger question became:

What allows human beings to sustain high performance inside systems that continuously increase the demands placed upon them?

AI may make that one of the defining organizational questions of the next decade.

That's why Dario Amodei's recent essay, We Must Pace the Frontier, caught my attention.

Amodei's argument is about frontier AI development. As AI capabilities advance at extraordinary speed, he argues that the systems responsible for understanding, evaluating and safeguarding those capabilities need sufficient time to keep pace.

He's not arguing that progress should stop.

He's asking whether capability can safely continue accelerating when the systems surrounding it cannot adapt at the same rate.

That's a question we've increasingly found ourselves asking at Green Shoe.

Except we're asking it about people.

The Other Frontier

One observation in Amodei's essay particularly struck me.

Writing about the enormous demands facing frontier AI companies, he acknowledges that these organizations employ some of the most capable people in the world. Yet, as he puts it, "there is simply too much to do all at once."

That sentence could have come from one of our conversations with cybersecurity leaders.

Our original Green Shoe research began with stress and burnout among CISOs. In our 2025 study, 41% of the CISOs surveyed rated their burnout between 6 and 9 on a 10-point scale.

But another number may have told us even more.

Ninety-four percent reported having little or no recovery time following periods of intense stress.

These weren't incapable people who simply needed to become tougher or "more resilient."

They were accomplished leaders operating in environments characterized by relentless demands, rapidly changing threats, enormous responsibility, organizational friction, limited recovery and very little margin for error.

That distinction changed the direction of our work.

We moved from studying burnout to studying stress and recovery.

From stress and recovery to leadership under pressure.

And from leadership under pressure toward the larger question of human performance.

Instead of asking only, Why are people burning out?, we began asking:

What are the conditions required for people to perform under pressure repeatedly and sustainably?

AI makes that question much more urgent.

When Capability Outruns Capacity

The principle underneath Amodei's argument extends beyond AI models:

What happens when capability advances faster than the surrounding system's capacity to adapt?

At the AI frontier, the concern is that model capability could outpace alignment, interpretability, evaluation and safety.

Inside organizations, there is a parallel question.

What happens when technological capability, organizational expectations and environmental complexity advance faster than the humans responsible for those systems can learn, adapt, recover and perform?

Consider what cybersecurity leaders are currently being asked to absorb.

AI is changing the threat landscape. It's changing security tools. It's changing software development. It's changing workforce expectations. It's changing what boards expect their CISOs to understand. And it's changing the skills leaders believe they and their teams will need tomorrow.

Meanwhile, the existing demands haven't disappeared.

Breaches still happen.

Regulators still regulate.

Boards still want answers.

Technical debt remains.

Budgets remain constrained.

Cybersecurity leaders remain responsible for protecting increasingly complicated organizations.

We're increasing the capability of the system.

We're increasing its velocity.

We're increasing expectations.

But are we increasing the human capacity required to operate it?

The Pace–Capacity Gap

I've started thinking about this as the Pace–Capacity Gap.

The Pace–Capacity Gap occurs when the rate at which demands, complexity and change increase exceeds the capacity of the people or systems responsible for absorbing them.

At the AI frontier, the gap might exist between rapidly increasing model capability and our capacity to understand and safeguard it.

Inside a cybersecurity organization, it can emerge when escalating demands exceed the ability of leaders and teams to learn, prioritize, make good decisions, communicate, recover and continue performing effectively.

At the individual level, it becomes even more personal.

What happens when the pace at which someone is expected to learn, decide, respond and perform continuously exceeds their available energy, recovery, control or perceived competency?

Eventually, something gives.

And that's where organizations can make a critical mistake.

We see the person experiencing the consequences and conclude that the person needs to become more resilient.

Maybe the system needs to become more intelligent about the demands it creates.

That's a very different conversation.

Pacing Isn't the Opposite of Performance

One reason I find the idea of "pacing" so interesting is that we often interpret slowing down as a failure to perform.

Human performance tells us otherwise.

Athletes don't become elite by training at maximum intensity every waking hour. Adaptation happens partly through recovery.

Military organizations understand the importance of operational tempo and readiness.

High-performing teams create periods for preparation, execution, reflection and recovery.

The objective isn't to avoid stress.

Stress is necessary for adaptation.

The objective is to create a system capable of absorbing stress, adapting to it and performing again.

That distinction has become central to Green Shoe's work.

Recovery isn't the absence of performance.

Recovery is part of performance.

The same principle applies at an organizational level.

Sometimes deliberately reducing velocity in one part of a system allows the entire system to develop the capacity required to operate faster later.

Pacing isn't the opposite of performance.

Done intentionally, pacing enables sustained performance.

The Human Side of "Keep Up"

There is another consequence of AI acceleration that I don't think we're discussing enough.

Identity.

Imagine being a cybersecurity leader right now.

You're being told that AI will fundamentally transform cybersecurity.

Your adversaries are using it.

Your vendors are embedding it into their products.

Your employees are experimenting with it.

Your board wants to understand it.

Your CEO wants to know how the organization will benefit from it.

And every few weeks, another capability appears that seems to change what you thought you understood six months ago.

The implicit message is difficult to miss:

Keep up.

For some leaders, that's exhilarating.

For others, I wonder whether it produces a much quieter question:

What happens if I can't?

That question is becoming part of Green Shoe's 2026 research.

This year's State of Stress study expands beyond traditional measures of stress and burnout to examine seven areas surrounding sustained human performance: demands; energy and recovery; psychological safety and voice; role clarity and control; competency growth and feedback; belonging and relational support; and professional identity and AI pressures.

For the first time, we're explicitly examining how AI may be affecting professional identity and the perceived pressure to keep pace.

And we're exploring an uncomfortable human experience that isn't discussed very often in cybersecurity leadership:

Shame.

Not simply embarrassment about not knowing something.

Something deeper.

The fear of being exposed as someone who doesn't know enough.

The fear of falling behind.

The fear that everyone else understands what's happening and you don't.

Perhaps even the fear of becoming irrelevant.

We don't yet know what the data will tell us.

That's precisely why we're asking the questions.

But if AI is accelerating the pace at which professionals must continually redefine what it means to be competent, we should understand the human consequences of that acceleration.

Human Adaptation Debt

There may also be a hidden cost when organizations continually increase the pace of change without creating sufficient capacity for people to absorb it.

Technology leaders understand technical debt.

Cybersecurity leaders understand accumulated risk.

I think organizations may also accumulate something we could call Human Adaptation Debt.

Human Adaptation Debt is the accumulated gap between how quickly an organization changes its technology, expectations and operating environment and how quickly its people can meaningfully absorb those changes.

And "absorb" is important.

It doesn't mean attending another webinar.

Or reading another AI briefing.

Or adding another tool.

It means developing competency.

Changing behavior.

Building confidence.

Integrating new ways of working.

Learning from mistakes.

Recovering.

And becoming capable of performing effectively in the new environment before that environment changes again.

Organizations can carry Human Adaptation Debt for a surprisingly long time.

Highly motivated people compensate for it.

They work longer.

They learn at night.

They sacrifice recovery.

They hide uncertainty.

They push harder.

And because the organization continues producing results, the system appears healthy.

Until it doesn't.

The interest on Human Adaptation Debt may eventually appear as exhaustion, cynicism, turnover, deteriorating judgment, communication breakdowns, reduced psychological safety, competency anxiety and leaders who increasingly feel that no matter how fast they run, they're falling farther behind.

Maybe Resilience Isn't About Running Faster

There is tremendous optimism surrounding AI, and much of it is justified.

The potential benefits are extraordinary.

But perhaps one lesson from the AI frontier is that responsible acceleration requires us to pay attention to everything that must accelerate with it.

Amodei is asking whether alignment, evaluation, interpretability, safety and operational systems can keep pace with AI capability.

Cybersecurity leaders should be asking another question:

Can our people?

And if the answer is no, our response cannot simply be to tell them to run faster or become more resilient.

We need to understand the demands we're creating.

We need to protect opportunities for recovery.

We need environments where people can admit what they don't know without fearing that doing so makes them irrelevant.

We need enough role clarity and control for leaders to prioritize rather than simply absorb.

We need to help people develop competency without making perpetual inadequacy the price of technological progress.

And occasionally, we may need to deliberately pace the system so the humans responsible for it have time to adapt.

Eighteen months ago, Green Shoe began by asking why so many cybersecurity leaders appeared to be burning out.

Today, we're asking something bigger:

How do we design environments where humans can continue to perform as the world around them accelerates?

Our 2026 State of Stress research won't answer that question by itself. But we're hoping it helps us understand another piece of it.

Over the coming weeks, cybersecurity leaders participating in the study will help us examine the relationship between demands, recovery, control, competency, belonging, professional identity and the emerging pressures created by AI.

If you're a cybersecurity leader, I hope you'll participate.

Because as organizations race to understand what AI can do, we should spend just as much time understanding what the humans responsible for these systems need in order to keep performing.

The AI frontier isn't the only frontier we need to protect.

There is a human one, too.

Next
Next

The Race Just Got Faster