White House Accord on Super Intelligence Explained: 4 Layers of Controls

White House Accord on Super Intelligence Explained: 4 Layers of Controls

I read the whole thing on my phone while my tea went cold. It took only two minutes, and that’s the first thing worth knowing about the White House Accord on Super Intelligence. The text that six of the biggest AI companies signed in late September 2026 is shorter than the terms page of most food delivery apps.

The idea is simple. If you train and deploy frontier models, you set up internal controls, put a team in charge of them, hire an outside auditor, and give a board committee the job of watching all of it. Google, Anthropic, Meta, OpenAI, xAI and Nvidia said yes. President Trump signed it the same day he issued an executive order telling federal agencies to stop saying “AI” and start saying “super intelligence”.

On paper, nothing in those four layers bothers me. I read them twice, looking for something silly, and didn’t find it. My problem is with what the page leaves out, and that list is longer than the page itself.

What the four layers actually say

The wording is a bit legal, so let me put it in plain words.

Layer one is internal controls. Each company keeps an eye on what its models can do and whether they behave the way the company wanted, during training and after release. The page names cybersecurity, biosecurity and chemical threats as the areas to watch, and it says the models shouldn’t hack into or reach technical systems nobody planned for them to reach. Layer two is a team inside the company that checks those controls actually work and fixes whatever turns up. Layer three is an independent outside auditor or evaluator, who does their own check of the same thing. Layer four is an independent committee of the board of directors, which gets reports from the internal team and the auditors and makes sure problems get fixed. After that, the page says these steps should give the company, its customers and the public confidence that the technology works as intended. One short paragraph says the companies will meet regularly to set standards. The last paragraph says it may make sense to turn all this into law someday, though the companies say they’ll do it either way.

That’s the whole thing.

And the shape is sensible, I’ll give it that. It looks a lot like how big listed companies in the US already handle their money: an internal audit team and an outside accounting firm, with an audit committee on the board watching both. The audit committee requirement came out of the Sarbanes-Oxley Act in 2002, after Enron collapsed. So whoever wrote this page borrowed something old that had been tested, and I like that. The trouble is what got lost when they borrowed it.

What the page doesn’t say

Start with the word “frontier”. The accord applies to every company training and deploying frontier models, and as far as I can find the term is never defined. The Rio Times pointed this out too. So who decides if a model counts as frontier? Probably each company, for itself. I’m guessing a little there, because the page doesn’t say, but a rule that applies only to models you’ve labelled yourself isn’t much of a rule.

Then there’s enforcement, or the lack of it. The law firm Freshfields wrote that the accord creates no legally enforceable obligations and has no enforcement mechanism. I’d go further. There’s no deadline on the page, no penalty, and no requirement to publish anything the auditor finds. A company could hire an auditor, get a bad report, show it to its board committee, and nobody outside the building would ever hear about it. Nothing in the text stops that.

Now the auditor. The page says each company should partner with an independent external auditor, and “partner with” is carrying a lot of weight in that sentence. In practice the company picks the auditor and pays the bill. We know how that can go: Arthur Andersen signed off on Enron’s accounts, and Andersen itself was finished by the end of 2002. That’s maybe unfair, since checking a model’s behaviour is a different job from checking accounts, and I’m oversimplifying. But the accord doesn’t say how the auditor is chosen or what happens when they disagree with management.

There’s also a practical problem I couldn’t stop thinking about. To check a model, an auditor needs access to the model itself, to how it was trained, to the test results the company already has. The accord says nothing about what access the auditor gets. Without it, an “independent assessment” could mean poking at the same public chatbot you and I can open on our phones. I spent way too long trying to find a standard for this that applies here, and I didn’t find one.

Layer two has its own issue. The internal team works for the same company that wants to ship the model. If they find a bad result the week before a launch, they’re the ones who have to say it out loud to their own boss. Anyone who has worked in software knows how that conversation goes.

The board committee is the last one. Meta is the easy example, since Mark Zuckerberg holds the majority of the voting shares there. An independent committee of that board is independent in a limited way, to put it politely. I’d ask the same question about xAI, though I don’t know how its board is set up, and the Washington Examiner now calls Musk’s company SpaceXAI, so even the name seems to have moved.

Same gap, three years later

In July 2023 the White House announced voluntary commitments from seven companies: Google, Microsoft, Meta, Amazon, OpenAI, Anthropic and Inflection. NPR reported at the time that there wasn’t a clear outline for how the White House could hold them to anything. Three years on, the new accord has the same hole, only now it comes with four layers.

What I’d rather see is already half built. In June, according to GovConWire, the Center for AI Standards and Innovation at NIST signed agreements with Google DeepMind, Microsoft and xAI to test frontier models before and after public release. That’s a government body doing the testing, not a firm the company hired. The accord never mentions it. If I had to pick, I’d take that over a hired auditor most days.

The other side has a point, and I’ll say it fast. People call voluntary pledges just PR, and partly they’re right. But a written commitment with six CEO signatures is something lawmakers and reporters can hold up later. Sundar Pichai already wrote on X that industry has to innovate responsibly, so he’s on record now. Laws take years and this exists today. That’s the part of me that’s 30 percent on their side.

One thing I should say plainly. Anthropic, the company behind the Claude chatbot, is one of the six signers, and I use these tools, so I’m not neutral here. Check my lean against that.

Loose ends I couldn’t settle

The date, first. Some sites say the accord was signed on Tuesday, September 29, and at least one says September 30. I opened PDF three times looking for a date on the page itself, then gave up. I’ll say late September and move on.

The name is the second one. The same day, Trump issued an executive order called “Inaugurating the Era of Super Intelligence”, which tells federal agencies to replace “AI” with “super intelligence”, or SI for short. The accord has “Super Intelligence” in its title, but the body never uses “SI” and doesn’t ask the companies to switch names. According to the Rio Times, House Speaker Mike Johnson even read the subtitle as “Frontier SI Responsibilities”, when the printed page only says “Frontier Responsibilities”. I don’t know why this bugs me as much as it does, it’s only a label. Maybe it’s because the name changed with one signature, and the audits don’t have a start date.

OpenAI’s signature, by the way, came from Greg Brockman, its president, and not from a CEO. I have no idea what to make of that. Probably nothing.

Third, a bill. A headline on the Washington Examiner site says OpenAI is backing something called the FRONTIER Act, an AI regulation bill. I haven’t read it, so I won’t guess what’s inside. If it defines “frontier model” and adds penalties, then the accord starts to look like a warm-up. And as of today, October 5, I haven’t found a single signer who has said who its outside auditor is.

What I’d watch next

If you use any of these models at work, ask your vendor one question: who is your outside auditor, and can I see what they found? Six companies promised that layer three exists. A reply should be easy to write. If a company can’t say who its auditor is, then layer three is still just a line on a page.

Post a Comment

Previous Post Next Post