Six AI Labs Promised Outside Audits. They Get to Pick the Auditors.
Under Donald Trump’s signature on the one-page AI safety accord he hosted on Sept. 29, his title came out as “President of the Unites States.” The typo got the jokes. What the document leaves out matters more. The White House Accord on Super Intelligence sets no penalties, requires no public disclosure of audit results and gives the government no enforcement role. According to CoinDesk, the companies choose their own auditors, don’t have to say who they are, and face no implementation deadline.
A day later, on Sept. 30, the Federal Trade Commission confirmed it is investigating OpenAI, Anthropic and other AI companies, and that it plans to use civil investigative demands to compel executives to testify. The New York Post broke the story, CBS News reported.
That’s two versions of AI accountability in two days. One is a promise the companies wrote around their existing practice. The other is a federal agency with subpoena-grade power and a chairman who has publicly doubted the industry’s motives. It’s worth asking which one actually binds anyone.
What six CEOs put their names to
The signature page carries Sundar Pichai of Google, Dario Amodei of Anthropic, Mark Zuckerberg of Meta, OpenAI president Greg Brockman, Elon Musk for xAI and Jensen Huang of Nvidia, alongside Trump. They agreed to four layers of oversight. First come internal controls that monitor advanced models in training and use for cyberattack, biological and chemical risk. An internal team checks that those controls work. An independent auditor or evaluator assesses them. Finally, an independent board committee oversees the teams and auditors.
On paper, that describes how a public company handles its books. The difference is in the details, and the accord has very few. Al Jazeera’s read of the text found no requirements for auditor qualifications, audit frequency or scope. The closest it gets to teeth is one sentence, quoted by Implicator: “Over time, it may make sense to codify these steps into laws or regulations.”
Trump called the deal “morally binding.” He also told reporters, per CBS, “I think I’m seeing tremendous self-policing, and they understand that they have to self-police.” Pichai said the accord “contains real tangible steps to promote safe development.” OpenAI’s Chris Lehane offered the more revealing line: “Industry-led standards would complement – not replace – mandatory federal safeguards.” For now there are no mandatory federal safeguards for these standards to complement.
We’ve seen a version of this before. In July 2023, Amazon, Anthropic, Google, Inflection, Meta, Microsoft and OpenAI promised the Biden White House “internal and external security testing of their AI systems before their release.” Three years later, the new accord adds a board committee. Axios noted that the new commitments largely line up with what the companies already do.
Mistral, the French lab, wasn’t at the signing. Its CEO, Arthur Mensch, had already given his view the same day on CNBC: “The debate that we’ve seen in the U.S. has been a cover for the negligence of some of our competitors.” Mensch is a competitor talking his book. His point about agents still holds, as quoted by The Next Web: “When you give them a lot of tools, those systems are very dynamic, so they can go and do things that you do not expect.”
The probe runs on a 1914 statute
The FTC isn’t using any new AI law, because there isn’t one. Fast Company reports that the agency appears to be relying on its longstanding authority over unfair or deceptive practices. That authority is Section 5 of the FTC Act. A practice counts as unfair if it “causes or is likely to cause substantial injury to consumers which is not reasonably avoidable by consumers themselves and not outweighed by countervailing benefits.” It counts as deceptive if a company’s claims about its product mislead the people relying on them.
The civil investigative demand is the important tool here. Under the statute, an FTC investigator taking oral testimony through a CID “shall put the witness on oath or affirmation.” CEOs who signed a promise on Sept. 29 could be answering questions under oath about how they keep it. According to The Next Web, the investigation started in the summer, the formal demands are expected within weeks, and an official described the posture plainly: “We’re not telling them to stop. We’re not telling them to do anything. We are in the investigative phase.”
The interesting variable is FTC Chair Andrew Ferguson. Axios reported that he has accused AI firms of trying to “panic Americans into pressuring policymakers to build a regulatory ‘moat’ that would allow AI frontrunners to block smaller competitors from catching up.” An FTC official, quoted by Inc., said the agency plans to compel executives “to testify about their product and about the dangers they allege their products may have to consumers.” Note the word allege.
Where the pledge and the probe collide

Our read is that the accord and the investigation are less opposed than they look. In some ways the first feeds the second.
Every layer of the accord produces paper. That includes internal monitoring logs, the verification team’s findings, an outside auditor’s assessment and a board committee’s minutes. The accord doesn’t make the companies publish any of it. A CID can still demand it. A self-chosen auditor’s private report is private only until a regulator with compulsory process asks for it.
The FTC is already asking that kind of auditor. Fast Company reports the agency is seeking material from METR, “the outside evaluator that investigated OpenAI’s hacking incident this summer.” METR has also run pre-release evaluations of OpenAI and Anthropic models. In practice, it’s the kind of “independent auditor or evaluator” the accord describes. The FTC has not said why it wants METR’s files.
The signatures matter for a second reason. Under a deception theory, a public safety promise is a factual claim, and the FTC has a history of holding companies to voluntary promises. In 2012 it found that Facebook had “deceived consumers by telling them they could keep their information on Facebook private”. Part of the remedy was “biennial privacy audits from an independent third party.” In that case, independent audits were a remedy the regulator imposed. Under the new accord, they are a courtesy the audited company arranges for itself.
There’s one complication. Ferguson’s moat argument means this FTC may be looking for overstated danger as much as understated danger. If an agency suspects “safety” is a competitive weapon, it could push labs toward fewer alarms rather than better controls. Nobody outside the agency knows which theory the demands will pursue. They haven’t landed yet.
Trump also said he’ll appoint a 10-member AI safety oversight board and a new White House AI policy official. Neither exists yet. Of everyone involved on Sept. 29 and 30, the only party that can put a CEO under oath is the one that didn’t sign anything.
Sources
- CoinDesk: OpenAI, Google and Meta pledge outside AI audits under voluntary White House deal
- Al Jazeera: How does Trump's White House AI accord work?
- Implicator: Six AI chiefs sign a pledge with no penalty for breaches
- TBS News: Typo spotted in Trump's White House 'super intelligence' accord
- CBS News: FTC investigation of OpenAI, Anthropic over AI safety
- Axios: OpenAI and Anthropic face FTC probe over AI safety risks
- The Next Web: FTC probe into OpenAI and Anthropic could force executives to testify
- Inc.: FTC investigation signals a new phase of AI regulation
- Fast Company: The FTC has a plan for regulating AI without writing AI rules
- FTC: A brief overview of the FTC's enforcement authority
- Cornell LII: 15 U.S.C. 57b-1, civil investigative demands
- FTC: FTC approves final settlement with Facebook (2012)
- White House (archived): Voluntary commitments from leading AI companies, July 21, 2023
- CNBC: Mistral CEO says U.S. AI safety debate masks competitors' negligence
- The Next Web: Mistral CEO tells CNBC US AI safety debate covers rivals' negligence
- Wikipedia: METR
Felix Strauss covers tech policy and regulation for prompt/power, from Brussels and Ottawa to Washington and Sacramento. He reads the 400-page regulation so you don't have to, and highlights the one sentence that actually matters.
Leave a Reply