In late September 2026, the leaders of Google, Anthropic, Meta, OpenAI, xAI (now xSI) and Nvidia gathered in the East Room of the White House. Together with the President, they signed the "White House Accord on Super Intelligence". The document runs to just over three hundred words. It was not published on a government website. It appeared as a post on Truth Social.
The President called it morally binding. It contains no penalties for a breach. A company that walks away loses nothing but reputation.
I do not want to be unfair to this document. For the first time, the heads of the leading labs have committed in writing to having their systems assessed by an independent external auditor. That is more than existed before. This is exactly why that single commitment deserves full attention. Whether the rest of the accord is worth anything depends on it.
Four Layers, One Gap
The accord describes four layers of control. Each company runs its own safety processes. An internal team reviews them. An external auditor confirms that they work. An independent committee of the board receives the reports. It is meant to oversee the correction of deficiencies.
Anyone who has ever dealt with corporate accounts will recognise the pattern at once. This is how listed companies control their books. Even the vocabulary is borrowed from financial auditing.
Something decisive is missing, however. The company under audit chooses its auditor. It pays the auditor. It defines what the auditor looks at. The audit does not ask whether a model is safe. It asks whether the controls work the way the company itself intended them to.
The report goes to the company's own board. No regulator sees it, and neither does the public. There are no common requirements for selecting auditors. There is no duty to publish. A poor finding has no consequences.
We know this construction. Over the past twenty-five years it has failed three times on a grand scale. Each time the audit was formally external. Each time it was in fact dependent.
Enron: The Auditor Who Was Paid Twice
Around the turn of the millennium, Enron was celebrated as one of the most innovative companies in America. Its books were audited by Arthur Andersen, then one of the five largest accounting firms in the world. Andersen did not earn from Enron through the audit alone. Its consulting fees were of the same order as its audit fees.
An auditor who loses such a client therefore loses twice. Nobody had to bribe Andersen. It was enough that every uncomfortable finding put its own business at risk.
At the end of 2001, Enron collapsed. Losses had vanished from the balance sheet into a web of special-purpose entities. Andersen had signed off on the accounts. Shortly afterwards, Andersen itself ceased to exist. Tens of thousands of people lost their jobs. Many lost their retirement savings at the same time, because those savings were held in Enron shares.
2008: The Rating the Seller Pays For
Six years later the pattern returned, this time at the scale of the world economy. Moody's, Standard & Poor's and Fitch rated mortgage securities that banks were selling around the globe. The agencies were paid by the issuers. In other words, they were paid by the very people who wanted to offload the securities. This model is known as "issuer pays". It has been the norm since the 1970s.
An agency that judged too harshly lost the mandate to a competitor. The issuer could effectively choose its rating. Securities worth trillions of dollars received top grades. When they fell, they dragged the financial system down with them.
Here too, malice was not the cause. The structure rewarded the accommodating verdict. It punished the strict one.
Boeing: Certification From Inside the House
The third case is not about money. It is about human lives.
For years, the US Federal Aviation Administration had delegated parts of its certification work to the manufacturers themselves. Boeing engineers, acting on behalf of the regulator, assessed Boeing aircraft. The arrangement was meant to save time. The agency lacked expert staff of its own.
The 737 MAX introduced a new flight control system called MCAS. Its full significance was not disclosed to the regulator. Pilots were initially told nothing about it. In October 2018, a Lion Air jet crashed into the Java Sea. In March 2019, an Ethiopian Airlines jet followed. 346 people died.
The inspectors were technically capable. But they were on the payroll of the company whose product they were meant to approve.
One Pattern, Three Industries
Balance sheets, bonds, aircraft: the cases could hardly be more different. Their blueprint is the same. The audited party pays the auditor. It selects the auditor or employs them outright. This gives the auditor an economic interest in the goodwill of the audited.
No individual has to be corrupt for this to happen. That is precisely the danger. Such a construction runs quietly for years. It produces sign-offs, top ratings and certifications in large numbers. Only when the damage is done does it become clear that independence existed on paper alone.
The accord adopts this construction. It adopts the organisational chart of financial auditing. The lessons drawn from it after Enron are left behind.
Why the Pattern Weighs More Heavily in AI
One could object that financial auditing, despite all its scandals, broadly works. In artificial intelligence, however, the problem grows sharper at a point that existed in none of the three cases.
A financial auditor needs records. An AI auditor needs the model itself. They need insight into weights, training data and internal test results. Only the lab can grant that access. It can withdraw it at any time. The auditor therefore depends not only on the fee. They depend on the key to the door. Whoever delivers uncomfortable findings risks being left outside for the next model.
From this dependence follows the next. Worldwide, only a handful of organisations can seriously assess a frontier model. Many of their experts come from the labs. Some later return there. When six companies choose from so few auditors, there is no competition for rigour. There is competition for goodwill.
Finality weighs heaviest of all. A doctored balance sheet can be corrected the following year. A wrongly certified aircraft can be grounded. A model whose weights have been published or leaked once cannot be recalled. Here the damage of an accommodating audit does not merely grow larger. It may become irreversible.
The Procedure Is Audited, Not the Model
The clause has a second weakness that is easy to miss. The external auditor is to confirm that the company's controls operate as intended. That is the logic of financial auditing. It makes sense there, because the rules of accounting are set from outside.
In AI, the company sets the rules itself. It decides which capabilities to test. It determines the threshold at which a result counts as dangerous. It decides what happens next. The auditor then certifies that these self-written rules were followed.
Imagine a carmaker that writes its own crash standard. An inspector of its choosing then confirms that the standard was met. Formally, everything would be in order. About the safety of the car, the certificate would say nothing.
An independent audit must therefore reach further. It examines the lab's procedures. It also examines the model itself, with its own tests and by standards that do not come from the lab. Specialists distinguish here between an auditor of controls and an evaluator of capabilities. The accord mentions both. Only the first is addressed.
The Answer Was Once Ready on the Table
What strikes me is that nobody needs a new idea. After each of the three crises, answers were developed. Some were built. The most effective one was left lying.
After Enron, the US Congress created the Public Company Accounting Oversight Board, the PCAOB. Since then it has supervised the auditors of listed companies. It is funded through a mandatory levy on those companies. As a result, no single company pays its own supervisor. At the same time, auditors were barred from selling most consulting services to the clients they audit. Andersen's second till was closed.
Europe reached for a different lever. Since 2016, public-interest entities must change their statutory auditor after ten years at most, with limited extensions. The United Kingdom has kept this rule. Rotation cuts through the familiarity that grows over long engagements.
The boldest step after 2008 came from two senators on opposite sides of the aisle. Democrat Al Franken and Republican Roger Wicker wanted to create an independent board. That board would decide which agency rates a new security. Issuers would no longer have been allowed to choose their own rater.
In the legislative process, the proposal was watered down. What remained was a mandate for the Securities and Exchange Commission to study the idea. The SEC produced its study. It held a roundtable in 2013. There it stopped. The assignment system was never introduced.
A bipartisan, fully worked-out answer to exactly the construction the accord now repeats has therefore been sitting in the files for more than a decade. Nobody built it.
How an Independent AI Audit Would Be Built
Applied to AI, these experiences yield a design that needs no new invention. It begins with money.
All labs training models above a defined compute threshold pay into a common pool. Contributions are based on the compute used. Every audit is paid from this pool. No lab transfers money to the auditor who judges its model.
Separating the money is not enough, however, as long as the lab still chooses. An independent body therefore keeps the list of qualified auditors. It assigns an auditor to each new model, by lot if necessary. A lab may reject an assignment. It must give reasons. It may do so only once per model.
Even an assigned auditor grows used to their subject over time. Auditors therefore rotate after a fixed number of models. Anyone who has audited a lab may not move there for a cooling-off period.
That leaves the dependence unique to AI: access. It has to be freed from goodwill. Every lab commits in advance to giving the assigned auditor the insight they need. If it refuses, the audit counts as failed. The key to the door loses its value as leverage.
Rigour only pays, finally, when a finding has consequences. A summary of every audit is published. Trade secrets stay protected. The verdict does not. If an auditor overlooks a recognisable risk, they are liable for it. The same liability would once have forced Arthur Andersen to be careful.
What the Labs Will Object
There are serious objections to such a design. They deserve an answer.
The most obvious concerns trade secrets. An auditor the lab did not choose would see weights and training data worth billions. Yet financial auditors have always seen figures that move share prices. For that there are confidentiality duties, security clearances and secure audit rooms. Nobody has yet explained why this should not work for models.
Another objection concerns quality. The lot might assign a weak auditor to a leading model. That risk exists only if the list is badly kept. Anyone who wants onto the list must prove they can assess a frontier model. The lot then merely chooses among the capable.
The objection that carries most weight is speed. New models appear within months of one another. An additional audit costs time. But the labs already test before every release, only with auditors of their own choosing. The design does not lengthen the audit. It changes who carries it out.
Anyone who still says there is no time for an independent audit is really saying something else. They are saying that a lead in the race matters more than proof of safety. That is a trade-off one may make. It should then be stated openly.
One Pool Across the Atlantic
A model trained in California runs the same day in London, Berlin and Toronto. An audit that is valid in only one country therefore checks too little. An assignment system for auditors becomes more credible the more states recognise it.
The building blocks already stand on both sides of the Atlantic. The United States has its own centre for evaluating AI models. The United Kingdom runs the AI Security Institute. The European Union has its AI Office. None of these bodies would have to carry out the audits themselves. Together they could keep the list of approved auditors. They could oversee the assignment. They could ensure that a finding means the same thing in every participating country.
I do not consider this utopian. Auditors have long worked to internationally agreed standards. Aircraft are certified through mutual recognition agreements. AI would be the third field in which states trust one another's controls, because they trust the construction.
What the Signatories Could Do Themselves
None of this requires a law. The six signatories could build this design on their own. They would have to set up a common pool. They would have to give up choosing their auditors. They would have to guarantee access by contract.
They would not even all need to start at once. A single lab could announce that its next frontier model will go to an auditor it does not choose. It could pay the costs into a pool managed by a neutral body. It could publish the result, whatever it turns out to be.
That would win something no advertising budget can buy. That lab alone could prove what the others merely claim. The competition now waged for goodwill would turn into a competition for credibility. The other five would have to explain why they still pick their own auditors.
The accord itself foresees that its steps might one day become law. That makes what emerges in the meantime all the more important. A voluntary commitment that creates genuinely independent audits could be adopted by a future legislator. A voluntary commitment that produces only commissioned audits hands that legislator nothing more than another organisational chart.
This would turn a pledge into proof. So far, the labs declare their models safe. They commission the confirmation themselves. An auditor they neither pay nor choose would, for the first time, make that promise verifiable.
Enron, the rating agencies and Boeing showed what a commissioned audit costs. Each time, the bill was paid by people other than those who had commissioned it. In AI, it might be paid by everyone.
How much is an auditor worth to a lab when it is not allowed to choose one?
| The Planet Futures Organization, the first multiplanetary NGO.
Homepage: https://planet-futures.org