The White House AI accord is a buyer test, not a compliance certificate
The September 29 White House accord asks major AI companies to use four layers of controls and audits. Here is how a small team can test the promise before a vendor turns a voluntary standard into your risk.

The most useful thing in Tuesday's White House AI meeting was not the phrase "super intelligence." It was a short list of control layers that buyers can ask vendors to make real.
President Donald Trump and House Speaker Mike Johnson hosted leading AI executives on September 29. After the lunch, the White House released a one-page accord on super intelligence. CBS News reports that the companies committed to four layers of controls and audits: internal evaluations, an audit by an external firm, review by each company's board, and regular meetings to establish safety standards and best practices. The document says those steps are voluntary and that they may eventually be codified into laws or regulations.
That is a material change from an afternoon of speeches, but it is not a finished compliance regime. The accord does not give a small business a shared control catalog, a testing score, an incident-reporting deadline, or a way to compare one vendor's audit with another's. It gives you a question set.
What the accord actually says
The distinction matters because a signed principle is easy to repeat and hard to operationalize.
Here is the reported structure:
- Internal evaluations. Each company is expected to test whether its systems act as intended.
- An outside audit. An external firm is supposed to examine the controls, rather than leaving every claim inside the vendor's own walls.
- Board review. The board of directors gets a formal oversight role.
- Shared standards work. The companies plan to meet regularly to improve safety practices.
CBS quotes the accord's position that these controls are critical regardless of whether the government eventually requires them. Trump called the commitment "morally binding," and Johnson described it as a joint commitment and statement of principles. The same report says Trump discussed a 10-person committee to watch over the enterprise and planned to name an AI czar within days.
Those statements are worth tracking separately. The four layers appear in the document. The committee and czar are reported plans. Neither is a substitute for an auditable control that protects your data or customer work today.
Reuters' account, republished by Investing.com, likewise describes a one-page accord with internal and external evaluation plus board oversight. The Associated Press reports the executive meeting and the industry's voluntary self-policing posture. The source trail is consistent on the existence of the accord; it is not evidence that every named company has already produced identical audit artifacts.

Four layers are not four answers
For a buyer, each layer still needs a scope, an owner, an artifact, and a consequence.
1. Internal evaluation: evaluated what?
Ask the vendor to name the capabilities covered by its internal evaluation. A chatbot that drafts an email is not the same risk as a cloud agent that can browse, call APIs, write to a shared drive, or run code overnight.
Ask for the release gate, not a marketing adjective:
- Which models, tools, and agent modes were tested?
- Were tests run against the production configuration you buy, including connectors and memory?
- Did the evaluation include prompt injection, excessive permissions, data exfiltration, and unauthorized actions?
- What threshold would have held a release back?
OpenAI's decision this week to hold back GPT-6.1 Astra after its safety team said the model did not meet the bar for staying within scope and authorization is a useful example of the kind of decision a buyer should want to understand. A vendor does not need to publish every red-team prompt. It should be able to explain the boundary it tests and the event that stops shipment.
2. External audit: independent and useful to whom?
"External" can mean several things. It could be an independent assessor with a defined scope, a consultancy checking a control description, or a report that the vendor summarizes for customers. Those are not interchangeable.
Ask:
- Who performed the review, and what could the reviewer inspect?
- What period and product version did it cover?
- Were the findings tested, sampled, or merely described?
- Will customers receive a report, an executive summary, or only a trust-center badge?
- What exceptions remain open, and when will they be retested?
The answer does not have to be public to everyone. It does have to be specific enough for your risk owner to decide whether the report applies to the service you actually use.
3. Board review: oversight or ceremony?
Board review is valuable when it creates a record of risk acceptance and follow-up. It is weak when it is just a quarterly slide.
Ask whether the board committee sees unresolved high-severity findings, model-release exceptions, serious incidents, and missed remediation dates. Ask who can stop a release or require additional controls. Keep the answer with the vendor's contract and security review. A board's existence is not proof that a board challenged a particular agent capability.
4. Regular standards work: what changes for your contract?
Industry standards work can improve consistency. It can also produce language that sounds shared while each company's implementation remains different.
Ask vendors to map their own controls to the promises they make in your contract. Get dates for the next review. More importantly, ask what they will tell you when a material change affects the model, connector, retention policy, or authorization boundary.
The buyer's evidence card
Put the following fields in the vendor file before you approve a new agent:
- Covered service. Record the model, agent mode, connectors, data locations, region, and version or release channel.
- Evaluation evidence. Capture the test categories, release threshold, date, and what was excluded.
- Audit evidence. Record the assessor, scope, period, exceptions, report type, and next review date.
- Oversight owner. Name the vendor contact and your internal owner. Note who receives a serious-incident notice.
- Change promise. Write how much notice you get before a material capability or retention change.
- Customer controls. Keep your own permission map, egress allowlist, retention setting, logging, and human approval gates beside the vendor's claims.
The last line is the one companies skip. The White House accord addresses what the AI companies say they will control. It does not configure your tenant, revoke an overbroad token, stop a connector from exporting a customer file, or approve an agent's outbound email. Those remain your controls.
What to do this week
Choose one consequential AI workflow and run the evidence card against it. Prefer a workflow with a real boundary: an agent that can write code, send messages, touch a shared drive, or access customer data.
Then test the smallest failure you can observe safely. Remove one permission, block one outbound destination, and require human approval for one irreversible action. Keep the logs. If the workflow cannot explain what it attempted and why it was allowed, a vendor's four-layer pledge will not fill the gap.
Finally, ask the vendor five direct questions:
- What internal evaluation covered this exact capability?
- What external review examined it, and what exceptions remain?
- Which board or committee sees serious findings?
- How fast will you notify us about an incident or material change?
- Which protections are yours, and which must we configure?
The September 29 accord is worth reading because it makes those questions easier to ask in plain language. It is not worth treating as a certificate you can file and forget. Voluntary controls may become customer requirements, state requirements, federal requirements, or simply the standard your insurer and largest client expect. A vendor file that names the evidence and the gaps survives all four possibilities.

The companies at the White House can decide how to police themselves. Your team still has to decide what an AI system is allowed to do on your behalf. If you want help turning that decision into a vendor file, permission map, and operating checklist, DefendResolutions does that kind of practical operator work.
Sources
- CBS News: Trump and major AI executives sign voluntary controls (September 29, 2026)
- Reuters via Investing.com: Trump releases AI accord with tech executives (September 29, 2026)
- Associated Press: Trump says top tech firms have signed an accord to self-police AI development (September 29, 2026)
- Associated Press: Altman unveils an always-on AI agent after OpenAI shelves a model over safety concerns (September 30, 2026)