On 29 September 2026, President Donald Trump and the leaders of six AI companies signed a voluntary accord at the White House in which the companies pledged, among other things, to use “independent external auditors” to verify that their safeguards work. Three weeks earlier, California had signed the first state laws deciding who is allowed to be called an independent AI auditor. The two documents use the same phrase. Only one of them defines it, and California’s definition does not take effect until 2028 at the earliest.

What the accord says, and what it leaves out

Al Jazeera reports that the accord is titled the Joint Commitment on Frontier Responsibilities and was announced at a White House luncheon. It names six signatory executives alongside Trump: Dario Amodei of Anthropic, Greg Brockman of OpenAI, Sundar Pichai of Google, Mark Zuckerberg of Meta, Elon Musk of xAI and Jensen Huang of Nvidia. Tech Policy Press, in its September roundup, lists the same six companies but calls one of them SpaceXAI, so the corporate naming of Musk’s company differs between sources. Both agree on the commitments: internal controls, dedicated oversight teams to confirm that monitoring and detection work as intended, and independent external auditors. Tech Policy Press adds an independent committee to review the companies’ findings; the Al Jazeera account does not mention one.

Neither report says who the auditors would be, how they would be chosen, what they would examine, or whether their findings would be published. Al Jazeera describes the accord as voluntary and nonbinding and reports no enforcement mechanism. Tech Policy Press, by contrast, reports Trump calling it “morally binding” while also praising “tremendous self-policing”; Al Jazeera gives his remark as a belief that there should be tremendous self-regulation. The wording differs between outlets, so neither phrasing should be treated as a verbatim quotation of the president. Al Jazeera also reports a line from the companies themselves, stating that they believe the controls and audits are critical whether or not any law requires them. Neither outlet published the accord’s full text, and it was not available for this article.

Reaction split along familiar lines. Al Jazeera reports that former Trump AI adviser David Sacks called the accord far better than an international agreement that would probably never happen. Alvin Wang Graylin of the Asia Society Policy Institute welcomed the pledge but noted that the companies drafted the principles and would hire the auditor, and that the commitment is voluntary. David Krueger of the University of Montreal called the approach “regulate without regulating.” The criticism that matters here is Graylin’s: it is about who writes the definition of “independent”.

What California actually built

California’s answer comes from two bills Governor Gavin Newsom signed on 9 September 2026, according to the governor’s office. SB 813, by Senator Jerry McNerney, creates a framework for independent verification organizations that can assess AI systems for compliance with state law. AB 1405, by Assemblymember Rebecca Bauer-Kahan, creates a state registry of AI auditors with independence and integrity standards. The governor’s release quotes Bauer-Kahan saying that industry cannot be expected to grade its own homework.

The details come from secondary summaries of the bill texts, namely PYMNTS and a blog from Pebblous, and the chaptered text on the legislature’s website should be checked before anyone relies on them. They are consistent with each other on the main points. Under SB 813, the Government Operations Agency must set criteria for verification organizations by 1 January 2028. Applicants disclose their qualifications, methodologies and testing tools, and the agency weighs technical expertise and conflict-of-interest controls. An auditor may take reasonable payment from the company it assesses, but the payment cannot depend on the findings. The auditor must stay operationally and managerially independent and control its own conclusions. The criteria are to align with national and international audit standards where practical.

Under AB 1405, an online AI Auditor Registry must exist by 1 January 2029. After that date an unregistered person or organisation generally cannot offer, sell or conduct an AI audit required to show compliance with state law. Auditors cannot evaluate systems or controls they materially designed or operated, and an employee generally cannot audit an area for which they held material responsibility at that client in the previous 12 months. Reports must describe scope, findings and limitations, including material gaps in evidence or access. Violations can lead to removal from the registry and referral to the attorney general. The Pebblous summary adds a ten-year record-keeping requirement and says an audit performed under an identified standard is relevant to, but not conclusive of, a lawsuit over harm from an AI system; it also says an earlier draft carried a liability shield that was removed. That is a single secondary source and should be read as such.

The timeline gap

Here is the arithmetic neither source set out. From the accord on 29 September 2026 to the 1 January 2028 deadline for verification criteria is 459 days, about 15 months. To the 1 January 2029 registry date is 825 days, about 27 months. Measured from California’s signing on 9 September 2026, the intervals are 479 and 845 days. In practical terms, any audit commissioned in response to the accord during its first year or more would happen before the state has decided what qualifies, and for roughly two years before the registry exists.

That does not make those audits worthless, and nothing in California law forbids a company from hiring an auditor in the meantime. It means the word “independent” in the accord has no legal anchor during that period. A firm paid by a developer, using methods the developer helped to choose, could describe itself as an independent external auditor and still be in compliance with the pledge as written. The accord’s silence on selection and scope is what makes that possible.

There is also a scope limit. The Pebblous summary reports SB 813 as saying that no developer, deployer or operator must engage a verification organization or undergo a covered audit in order to do business in California, and PYMNTS likewise says the law does not require every AI company to use a state-designated verifier. The laws regulate who may perform an audit where state law calls for one. They do not themselves create a general audit duty. A Cloud Security Alliance research note describes one place where such a duty exists: SB 1119, signed on 10 September 2026 as part of a child-safety package, which requires operators of AI companion chatbots to submit to independent third-party audits, with the first audit due by 1 January 2029 or before first availability in California, whichever is later. That is also a single secondary source, but the date alignment with the registry is notable. It suggests the registry’s first real customers will be chatbot operators, not frontier model developers.

Where the design could fail

The strongest objection is structural, and it applies to both documents. Gabriel Weil, writing for AI Frontiers on 29 July 2026 about an earlier text of the California approach, argued that the verification-organization model resembles credit-rating agencies before 2008, because the issuer chooses and pays the rater. He proposed mandatory liability insurance instead, and argued that state licensing and revocation of verifiers reintroduces the problem the model was meant to solve. The Pebblous summary reports that the signed version moved partway toward the approach Weil preferred, which is a reminder that the final text and the earlier critique may not match. Payment that is merely not contingent on findings is a weaker safeguard than payment from a third party, and the law permits the former.

The defence is that some independence rules are better than none, and that registries and removal powers give regulators something to enforce. Supporters of the accord make a different argument: Sacks’s point is that a voluntary commitment signed by six companies is achievable now, whereas binding international rules are not. That argument has force on its own terms. It also explains why the details matter, since a voluntary pledge is only as strong as the definitions used to measure it.

A third body is relevant. DrafterDaily reported on 26 September that Google, OpenAI and Anthropic were reportedly designing an industry standards body, tentatively called SAFA, whose functions would include qualifications for independent auditors. That plan rested on unnamed sources and had no on-record confirmation. If it proceeds, a company could face three non-identical meanings of independent auditor: an undefined one in the accord, an industry-written one from SAFA, and a statutory one from California. Which one a company relies on will depend on whether anyone is checking.

What the evidence does not establish

The accord’s text was not reviewed, so claims about auditor selection and scope rest on press accounts that agree on silence rather than on detail. Whether a review committee exists is reported by one outlet and not mentioned by another. The California deadlines are from secondary summaries of the bills. The legal-effect and record-keeping points come from one blog. And nothing yet shows whether any signatory has commissioned an audit under the accord, who it hired, or whether California’s criteria will resemble what those auditors do.

For readers in compliance, risk and audit, the sensible reading is conditional. The accord is a commitment to a category of assurance whose rules do not exist yet. California is writing those rules on a timeline that runs well past the accord, and only where state law calls for an audit. Until the 2028 criteria and 2029 registry arrive, the phrase “independent external auditor” describes a promise, not a status.