What the Law Can See
Six companies just promised independent evaluation of their own AI. We have yet to come together and build the thing that would make that promise mean something.
Dominique Charlie Oquendo
Founder and Principal Consultant, Intentional Data. October 2026.
Researched and edited with AI assistance. The analysis, the argument and the writing are mine. Ask for the repo to see how Claude was used!
Introduction
In my first attempt at writing to you all, I argued that choosing not to engage with AI is not in our interest, and I offered algorithm interrogation as a practice, the habit of asking whether an automated system was involved in a decision affecting your community.
Since then, I have spent the last month reading statutes, which is a strange sentence for a community data practitioner to write. I have built data systems for nonprofits, grassroots organizations, and government agencies, and that proximity is what brought me to these documents with more than an academic interest in getting the answer right.
Six companies have just promised independent evaluation of their own AI. Better said, they have promised to self-police. Neither part of that conjunction makes me feel safe.
What I’ve found is that the morally binding pinky promise from frontier models turns on four questions. I would argue that discussing the intricacies of what this promise would need to keep us safe, is more important, more timely, than discussing the next public cry around AI gods. With that being said, I am giving myself room to process out loud, because this is a lot of new information arriving fast. I am choosing to think in public with my community, rather than perform certainty I have not yet earned.
1. Six people signed a promise about who checks their work
On September 29, 2026, the chief executives of Google, Meta, Anthropic, xAI, Nvidia and OpenAI sat down at the White House and signed the White House Accord on, what is now referred to as 'Super Intelligence', subtitled a Joint Commitment on Frontier Responsibilities 1. The President called it "almost like a constitution, in a way," and said he thought it was "morally binding" 2.
There are four commitments laid out in the agreement.
- Internal controls to monitor capabilities and alignment during training and deployment
- An internal team empowered to make sure those controls work
- Partnership with an independent external auditor or evaluator to carry out independent assessments of whether the controls, monitoring, and detection are operating as intended
- Designate an independent committee of the board of directors to oversee and receive reports from the teams operating the controls and the internal and external auditors and evaluators 1
While there are reasons to be skeptical here, my focus has been on the word: "Independent". It appears twice in that third commitment. Things the promise does not include: the details that make the commitment mean anything at all. It does not say who selects the auditor. It does not say who pays the auditor. It does not say what the auditor is allowed to look at. It does not say that anyone outside the company ever sees what the auditor found. It does say, maybe in an attempt to cover their ass, "over time, it may make sense to codify these steps into laws or regulations" 1. 'It may make sense', is hilarious to me.
As of the time of this writing, there is nothing in place that makes this 'agreement' legally binding.
Since the signing, I have been thinking about the way we are approaching the problem. I cannot wrap my head around the order of priorities. There are conversations, heavy and needed, around whether to require independent evaluation, and these debates are happening before we have built the infrastructure for independent evaluation.
A law that requires an independent audit and a law that requires nothing, produce documents that look remarkably similar.
If a law passed tomorrow requiring it, those same four questions would still be open. Who the evaluators are. What they are grading. Who decides what they grade? Until we answer those together, a law that requires an independent audit and a law that requires nothing produce documents that look remarkably similar.
I understand the instinct to call a voluntary commitment worthless, I feel the same. As someone who takes pinky promises seriously, I want to push on my instinct. Six companies writing down that independent evaluation belongs in their safety process is a real change from six companies not writing it down. What my, maybe naive nature, wants to do, is take the promise seriously enough to ask what would have to exist for it to work.
My optimism does not allow for my overall view and values to be shaken. My stance is and will always be toward co-produced technology. Where I am open is how we get there. I do not know yet. The good news is, from what I am seeing and reading, it sounds like the answer is still being formed. Different sectors, globally, are weighing in on what AI needs to be safe.
2. Something happened in July that the law could not see
In July, by OpenAI's own account, agentic models escaped a sandboxed evaluation environment, obtained unauthorized network access, and compromised Hugging Face's infrastructure, a leading AI and machine learning community. 3,.
California has the strongest AI safety law in the country, however this incident did not meet the requirements needed to mandate reporting. For clarity, because I needed a second here too, agentic models obtaining access they shouldn't have had, and doing all kinds of wild scifi-esque things, did not need to be reported under current AI safety law.
Fortunately, or not, we did learn what happened. Mission Local reports that "the details of the hack were instead made public by OpenAI itself and a group of outside investigators it granted access" 4. That arrangement stayed with me, because it is the one the accord now proposes for everyone; a company (OpenAI) partnered with 'outside investigators'.
What this outside investigation looked like is the closest thing we have to a preview of what's to come. The company "limited investigators to 18 days, from June 26 through July 13, despite acknowledging that it had detected irregular activity much earlier, in May" 4. The researchers "wrote that they agreed, at OpenAI's behest, to not investigate the effectiveness of the firm's safeguards related to the incident" 4.
The law worked exactly as written. The question is what it was written to see.
In plain language, evaluators were invited in, put on a clock, and told in advance what to leave alone. This approach broke no laws, and paved the way for the self policing accord we have now. I want to be precise about what I am claiming. The law was not broken and the agency did not fail. The law worked exactly as written, which moves the question one step back, what is the law written to see.
3. What independent actually means
The accord promising self-policing says “independent evaluation", so I went looking to see what that means by definition, and what it looks like in practice. The word, independent, can potentially refer to four different arrangements that produce four very different results.
| Type of audit | Who selects the auditor | Who pays the auditor | Who sets what they look at | Who sees what they found |
|---|---|---|---|---|
| Internal audit. First party. The company's own staff and safety team. | The company | The company, it is their salary | The company | The company |
| Hired audit. Second party. A firm the company brings in and pays. | The company | The company | The company, in the contract | The company |
| Independent in name. Third party as it usually runs. An outside group engaged to audit, still chosen and paid by the company being audited. Raji's paper calls these ostensibly independent. | The company | The company | Mostly the company | The company, and whoever the company allows in the contract |
| Independent in practice. Third party as designed. Chosen from a register, paid from a shared pool, scope set by rule, access guaranteed, findings published. | A public body | A common pool | A standard | The public |
The names in the table come from Raji, Xu, Honigsberg and Ho, who mapped the third party audit ecosystem in 2022 5.
Armed with the definitions provided by Raji and Ho, I was able to better understand what the signed accord means when they call for companies to "partner with" an evaluator. It means the company goes and gets someone. Nothing in law yet says who, nothing says on whose terms, and the findings go to the company's own board, not to the public.
Unfortunately, a third party audit, as defined in the table, does not exist for AI anywhere in the United States today.
4. Four laws and what they ask for
Four laws sit at the frontier layer. One was vetoed and three are real. Side by side, they show a trade being made over and over: a duty of care exchanged for a duty to disclose.
SB 1047 would have required developers to "take reasonable care to implement appropriate safeguards to prevent the covered model and covered model derivatives from causing or materially enabling a critical harm" 6.It also required that "beginning January 1, 2026, a developer of a covered model shall annually retain a third-party auditor ... to perform an independent audit of compliance" 6.
An independent audit was written into California law once already, two years ago, and then vetoed.
SB 53 asks for something different. As Mission Local puts it, "unlike Wiener's original bill, SB 53 does not mandate AI firms retain third-party auditors to ensure they're following their protocols" 4. Companies publish a framework, and per Fortune the law "specifies that the companies must then adhere to their own policies" 7.
The table adds the White House Accord as a fifth column, because it answers the same questions the statutes answer without being a statute.
| Question | SB 1047, vetoed 2024 | SB 53, California 2025 | RAISE, New York 2026 | SB 315, Illinois 2026 | WH Accord, Sept 2026 |
|---|---|---|---|---|---|
| Who it covers | Companies and models that hit the Compute and training-cost threshold | Two tiers. Any developer training a model above 10^26 operations, with no revenue test. The heavier duties add $500M gross revenue, counted with affiliates, in the prior calendar year | 10^26 operations and $500M revenue | 10^26 operations and $500M revenue | Six companies that chose to sign |
| What they must do | Reasonable care to prevent critical harm | Publish a framework and adhere to it | Publish a framework and transparency reports, report incidents in 72 hours | Safety measures, and an annual audit from 2028 | Four layers of internal controls and audit |
| Who checks their work | Annual third-party independent audit | The developer itself | The developer, which must disclose how much third parties were involved | An independent third party, competence required, no accreditation | An independent external auditor, selection and payment unstated |
| Who pays the auditor | The developer retains them, cost not addressed | No audit required, no payment needed | No audit required, no payment needed | The developer pays, and cannot tie the fee to the result | Unstated |
| Who sees the result | Redacted report published and sent to the Attorney General, unredacted to the AG on request | The published framework | Framework and reports public, incident reports confidential and exempt from records requests | Audit reports published | A committee of the company's own board |
| How is it enforced | Would have been law | Law | Law, up to $1M then $3M, attorney general enforces | Law | Voluntary, called morally binding |
| In force | Vetoed Sept 29, 2024 | Currently In force | Jan 1, 2027 | Jan 1, 2027 | No enforcement, Signed Sept 29, 2026 |
Sources by column: SB 1047 6, SB 53 4 8 7, RAISE 9, SB 315 10, the accord 1. The vetoed bill and the accord were signed exactly two years apart, to the day.
The row I keep coming back to is the one about who checks. California says the developer itself. New York says the developer, and then requires it to publish "the extent to which third-party evaluators were involved" 9. This means New York makes you disclose how much you were checked, but has no method of enforcement, no way to make you get checked.
Illinois is the only one of the three that requires an outside audit, and those audits do not begin until 2028 10.
5. Three years of a rule with nothing behind it
If you run a nonprofit, a county agency, a benefits office, or a hiring process, none of what I have described so far is about you. The laws laid out in the table above, and the signed accord, govern the companies that build AI. The deployment layer is where your intake tool, your screening vendor, and your eligibility workflow live. This layer is also where we can stop speculating, because one law has been running for three years.
New York City passed Local Law 144 in 2021. Since January 1, 2023, an employer may not use an automated employment decision tool to screen candidates unless a bias audit was done within the past year and a summary of the results has been "made publicly available on the website of the employer" 11. This is a law attempting to govern the deployment layer.
The statute defines a bias audit as "an impartial evaluation by an independent auditor" 11. The rules disqualify an auditor who was involved in using, developing or distributing the tool, who has an employment relationship with the employer or the vendor, or who holds a financial interest in either 12. Candidates get notice at least ten business days before the tool is used 12.
When I came across this, I was excited, we have an example! Something to look to and learn from. Independent evaluation, required by law, with public disclosure, in the United States, since 2023. So I went looking for the results.
| What Local Law 144 requires | What three years produced |
|---|---|
| An annual bias audit by an independent auditor | 18 of 391 covered employers posted one |
| The results posted publicly on the employer's website | 13 posted the required transparency notice |
| Candidates told at least 10 business days before the tool is used | No one measures this |
| Enforcement by complaint | 2 complaints in 2 years, 0 penalties on the public record |
I do not think the reason for these results is simple defiance. The rules let an employer decide for itself whether its tool "substantially assists or replaces" discretionary decision making, so an employer that concludes the law does not apply to it posts nothing and has broken no rule. The employer picks the auditor and the employer pays the auditor. There is no register of who is qualified, a standard for what an audit has to cover, or a score a tool can fail.
A mandate landed on a field with none of the infrastructure a mandate needs.
Colorado and Illinois each tried a version of this at the same deployment layer. Colorado lost its duty of care within two years. This means they are no longer obligated to take reasonable steps to prevent harm. Illinois made it a civil rights violation for an employer to use AI for hiring that discriminates, and then the rules that followed never defined what that means. They only told the employers to post a notice saying they used the hiring algorithm. Even the requirement to post the notice was removed in June, and as of October there is nothing behind the label of civil rights violation. Other examples of this can be found in the appendix.
6. A possible answer is four years old
The lack of successful examples in law, doesn't mean we don't already know how to build the audit infrastructure needed. Somebody studied this and wrote down the answer before any of these laws existed.
Raji, Xu, Honigsberg and Ho looked at third party audits across industries in 2022, and they found the thing that explains why the accord and New York City's law both land where they do. When the company picks the auditor, pays the auditor, and decides what the auditor is allowed to look at, the result "may be functionally indistinguishable from first-party audit" 5. That is a company checking itself, with a second name on the cover.
I put this paper next to New Yorks Local Law 144 we looked at earlier. As discussed, Local Law 144 allows the auditor to be selected by the auditee. The auditor is paid by the auditee. The scope is substantially set by the auditee, since the employer decides whether the tool is covered at all. And no action after the audit is required beyond posting.
Honigsberg and Ho’s paper described the failure mode in 2022 and the city of New York demonstrated that failure by 2025.
This same paper from Honigsberg and Ho also says what helps. They point to a two-year trial in environmental auditing where auditors produced more accurate results once a shared pool of public money paid them instead of the firm under audit 5. They argue the right to audit should reach past university researchers to community groups, legal aid and journalists, and they note that third parties today "are often forced to operate at great legal risk to gain access to the audited AI system" 5.
The findings from this two year trial all point to missing infrastructure. A funding pool so the company is not writing the auditor's check. A certification scheme so there is an answer to who is qualified. Legal protection so publishing a finding is not a lawsuit. An access regime so an auditor can see the thing. A registry so any of this is visible from outside.
One state has started building the registry of potential auditors. California's opens on January 1, 2029, and when I went into that statute expecting a wall, I found something closer to a door 14. I am still reading it, and right now it is the most interesting thing on my desk.
7. What to ask
Two practices came out of this for me, and both work at whatever depth your capacity allows. In the first post I called this algorithm interrogation, the habit of asking questions. These practices require nothing but curiosity.
“Please try to reclaim your precious, precious attention, at all costs. Do puzzles. Take walks without a phone. Dear god, try to read, almost anything that isn’t a manifesto will really do. You are going to need your brain.” Tressie McMillan Cottom @tressiemcphd 15
ASK WHO THE LAW WAS WRITTEN FOR. When one of these laws gets announced, the sentence that decides whether it touches your organization is the one saying who it covers, and it sits near the top of the bill under definitions. It is almost always a size, either how much revenue the company has or how much computing power went into the model. The vendor selling your team a screening tool is usually a small company, the deployment layer, which means none of the laws in this post reach them. If a board member or a funder asks whether the AI tools you use are regulated, the honest answer is usually no. Whatever protection you have comes from what you put in the contract with the vendor you use.
ASK WHETHER THE REQUIREMENT HAS ANYTHING BEHIND IT. A rule saying a tool must be independently audited is worth the answers to three questions:
who the auditors are
what they have to examine
what happens when somebody finds something.
Those answers are usually not in the law. They sit in an agency's rules, written later, and sometimes they have not been written at all. Going to look takes about ten minutes, and coming back with nothing is the finding, because it tells you a posting is all the rule is going to produce.
8. An invitation
I am still thinking, and that is the condition of the work right now.
Somewhere in the middle of all this reading, a podcast I had on in the background used the phrase “sunlight is the best disinfectant”. Nothing here is hidden. The accord sits on a government website. The statutes are free to read. The eighteen bias audits that did get posted are on eighteen company websites right now. What makes all of it feel hidden is that it is long and dull and built to be skimmed past.
So the intent is sunlight. Enough of it that ordinary people can think about what is being done to them while it is still being decided.
If you are reading a statute and cannot tell whether it covers your vendor, or you are trying to figure out what to ask before you sign, write to me at dominique.charlie@intentionaldata.org. I would rather think about it together than watch another set of rules get written in a room none of us was invited into.
Appendix
Two more laws at the deployment layer, both showing the same trade as New York City and neither with three years of results behind it yet.
Colorado, and how fast a duty of care can come off.
- May 2024. Colorado requires developers and deployers to "use reasonable care to protect consumers from any known or reasonably foreseeable risks of algorithmic discrimination," with an annual impact assessment the company performs on itself 17.
- December 11, 2025. A federal executive order directs Commerce to identify "onerous" state AI laws within 90 days, and names Colorado's as an example 18.
- April 9, 2026. xAI sues Colorado.
- April 24. The Department of Justice intervenes.
- April 27. A federal court stays enforcement.
- May 14. A replacement is signed, without the care duty and without the impact assessment 19 20.
What stands in for the duty of care now is "an opportunity for meaningful human review and reconsideration of the consequential decision, to the extent commercially reasonable" 20.
Even Colorado's impact assessment was performed by the organization on itself, so the strongest deployment law of its kind still asked organizations to grade their own work.
Illinois, and a rule with no definition. Using discriminatory AI in employment has been a civil rights violation there since the start of this year, and the statute handed the job of saying what that means to a rulemaking process. Those rules were proposed in May and withdrawn in June, and as of October there is no replacement 21 22.
Endnotes
- The White House. (2026, September 29). White House Accord on Super Intelligence: Joint Commitment on Frontier Responsibilities. whitehouse.gov
- CNN. (2026, September 29). Top AI executives sign commitment to self-police after meeting with Trump. cnn.com
- OpenAI. (2026). The Hugging Face incident and the road ahead. openai.com
- Mission Local. (2026, September). AI safety law missed the first rogue AI hack in California. missionlocal.org
- Raji, I. D., Xu, P., Honigsberg, C., & Ho, D. E. (2022). Outsider Oversight: Designing a Third Party Audit Ecosystem for AI Governance. AIES 2022. arxiv.org/abs/2206.04737
- California Legislature. (2024, September). SB 1047, Safe and Secure Innovation for Frontier Artificial Intelligence Models Act, enrolled. leginfo.legislature.ca.gov
- Fortune. (2026, September 14). OpenAI may have violated California's AI safety law with Astra model releases, AI watchdog says. fortune.com
- California Legislature. (2025, September). SB 53, Transparency in Frontier Artificial Intelligence Act, Chapter 138, Statutes of 2025. leginfo.legislature.ca.gov
- New York State Senate. (2026, March 27). S8828, RAISE Act, Chapter 96 of the Laws of 2026. nysenate.gov
- Illinois General Assembly. (2026). SB 315, Artificial Intelligence Safety Measures Act, Public Act 104-0538. ilga.gov
- New York City Council. (2021, December 11). Local Law 144 of 2021, automated employment decision tools. NYC Administrative Code sections 20-870 to 20-874. legistar.council.nyc.gov
- New York City Department of Consumer and Worker Protection. (2023, April). Final rules, automated employment decision tools, 6 RCNY sections 5-300 to 5-304. rules.cityofnewyork.us
- Wright, L., Muenster, R. M., Vecchione, B., Qu, T., Cai, P. S., Metcalf, J., & Matias, J. N. (2024, June 3). Null Compliance: NYC Local Law 144 and the Challenges of Algorithm Accountability. ACM FAccT 2024. facctconference.org
- California Legislature. (2026, September 9). AB 1405, Artificial intelligence: auditors: registration, Chapter 178, Statutes of 2026. leginfo.legislature.ca.gov
- McMillan Cottom, T. (2026, September 25). Post 3 of 5. bsky.app/profile/tressiemcphd.bsky.social/post/3mweqxvmxcd2m
- Brandeis, L. D. (1913, December 20). What Publicity Can Do. Harper's Weekly. Reprinted as Chapter V of Other People's Money and How the Bankers Use It (1914). law.louisville.edu
- Colorado General Assembly. (2024, May). SB 24-205, Consumer Protections for Artificial Intelligence. leg.colorado.gov
- The White House. (2025, December 11). Executive Order 14365, Ensuring a National Policy Framework for Artificial Intelligence, 90 FR 58499. federalregister.gov
- Crowell & Moring LLP. (2026, May). Colorado Hits Reset on AI Regulation: SB 26-189 Repeals and Reenacts the Colorado AI Act. crowell.com
- Colorado General Assembly. (2026, May). SB 26-189. leg.colorado.gov
- Illinois General Assembly. (2024, August). HB 3773, Public Act 103-0804. ilga.gov
- Illinois Register. (2026, June). 50 Ill. Reg. 8755, Department of Human Rights, Notice of Withdrawal of Proposed Amendments. ilsos.gov