On Tuesday 29 September, six AI companies signed a one-page accord at the White House: Google, Anthropic, Meta, OpenAI, xAI and Nvidia. Its opening line says every company is responsible for developing its own technology safely "and in a way that builds trust with customers and the public."
Then it builds four layers of control: internal controls on what the models can do, an internal team to make sure those controls work, an independent external auditor or evaluator to assess them, and an independent committee of the board to receive the reports and see that problems get fixed.
Follow the reports. Controls feed the team. Team and auditor both report to the board committee, and that committee sits inside the company it oversees. As written, nothing in the accord sends a finding, a summary or even the auditor's name to a customer, a regulator or the public, and it sets no date for any of it. A few lines later it says these steps "will give each company, its customers, and the public confidence that the technology is operating as intended." The accord gives two of those three nothing to read.
I don't think that makes the accord worthless. Four layers of control is real work, and a board committee puts named directors in the line of responsibility. But the document makes one specific promise in its first line, and then routes every line of accountability so that it stops short of the people that promise names.
Trust gets granted, by people who could have checked and decided to rely on you. A customer cannot rely on an audit they have no right to see. The audit may well produce better controls. On its own it cannot deliver what the first sentence promises, because the accord gives the people it names no way to look.
Four floors, a lock on each, and every report climbs to the top floor. On the street, the one window an outsider could look through has its shutters closed.
The Decoder
In audit, independence has two halves. The first half is who does the checking. A listed US company's audit committee is "directly responsible for the appointment, compensation, and oversight" of its auditor, under 15 U.S.C. 78j-1(m)(2). A company choosing its own auditor is normal, and I would not hang the critique on it. It works in finance partly because a separate board, the PCAOB, writes the audit standards. Under the accord, the signatories will write their own.
Then there is who reads the result. For a listed US company, the auditor's report goes into the annual filing on Form 10-K, where any investor can read it. That public half is what lets a stranger rely on numbers they never helped produce. Of the two, the accord kept the first and left out the second.
The Steelman
The best case for the accord is that voluntary is how this always starts, and the 2023 White House commitments began the same way. Its own text says that over time it may make sense to codify these steps into law. There is also a real security argument for keeping frontier audit findings private: a published list of what a model's controls failed to catch doubles as a map for anyone trying to get past them. And six companies that compete on everything signed the same structure on the same day. Lawyers would add that published findings become evidence, which can teach a company to look less hard.
An audit that only your own board can read will protect the company. It cannot earn trust from the people who were never allowed to look.
I once signed off on a municipal agency's final financial report without knowing that its autonomous procurement agent had correctly flagged several unauthorized cross-department data pulls, because the alerts went to a compliance inbox nobody had watched since a restructuring.
I wrote the fix into the Ledger in July: state the hard line where those affected can see it.
That rule is the closing guardrail in the Agentic Work-Unit Ledger: five lines for pricing an agent like a hire, and one paragraph on who gets to see the hardest number.
The Playbook
Public-reporting language in the 2023 commitments and the 2026 accord.
Ask your vendors which layers they run. You buy from these companies or from someone built on them. Ask whether an external evaluator has assessed their controls, who it was and what it covered. A vendor that has done the work can usually say who did it. If nobody outside has looked, that tells you something about the contract you are about to sign.
Ask to see something, even a summary. Full findings may be confidential. A page on what was tested, what failed and what got fixed rarely is. Cloud providers already work this way: customers get the detailed SOC 2 report, and a shorter SOC 3 version can be freely distributed. Put the request in your next renewal, where it has weight.
Turn the accord on yourself. Draw your own AI controls as boxes, with an arrow from each to whoever reads its report. If every arrow ends inside the building, you have the accord's gap at your own scale.
Give the affected party one window. For customers, that can be a published summary of how a decision about them is made and checked. For staff, it is the Ledger's line 4, redeploy or reduce, said out loud in the operating review.
Get ahead of codification. The accord itself says it may make sense to write these steps into law. A company that already publishes its evaluator's name will find that day cheap.
The Signal
At least one signatory, Anthropic, has already let US and UK government testers publish an evaluation of one of its models. Watch for the first to name the auditor of its controls, with a scope and a one-page summary of what was found. Nothing in the accord asks for that, which is why doing it unasked would mean something.
The opening line promised trust to people outside the building. I think the company that first lets those people see the check is the one that will collect it. Everyone else will have signed the same page and earned less from it.
The Correction
As reported: CoinDesk headlined the accord on 30 September: "OpenAI, Google and Meta pledge independent AI safety audits under voluntary White House deal."
What the source says: The accord commits each company to "partner with an independent external auditor or evaluator" and sends the findings to "an independent committee of the board of directors" of that same company. It requires no publication of findings, no naming of the auditor and no date. The audit is real. The accord sends none of it outside the company. White House Accord on Super Intelligence, 29 September 2026
The Framework
This is exactly why I built the Agentic Work-Unit Ledger.
The Ledger closes on a guardrail: state the hard line out loud, where the board and the affected function can both see it. The accord builds the board half and leaves out the affected half, which makes it the last case in this run.
Your Agent Isn't a Feature. It's a Hire. Measure It Like One. →On My Radar
- The 2023 voluntary commitments included "publicly reporting their AI systems’ capabilities, limitations, and areas of appropriate and inappropriate use". The 2026 text has no matching line, which leaves that choice with each signatory.
- The signatories also say they "will meet regularly to establish standards and best practices", which is the natural place for a disclosure standard to start.
- Sundar Pichai, posting on the day, called the accord "a solid basis for moving forward" that "contains real tangible steps to promote safe development".
Four layers is a decent start. The fifth, a window someone outside can look through, is the one that earns the trust. If your own AI controls only report inward, that is this fortnight’s work.
Know someone who needs this? Forward it to the board member who chairs your audit or risk committee.
Ajay's views, from 15 years in the field. Not legal or compliance advice. See full disclaimers →