
Last week, amid a global furore over AI safety and reports of AI agents from OpenAI and others hacking government and corporate websites, the White House summoned the heads of the major AI labs. The goal was to agree common rules for AI. I call it Bretton Woods, Part Two.
Ignore the doomsday headlines. I think it was a big win for humanity and for the AI industry, and the reasons may surprise you. Stay with me.
The AI industry has spent heavily lobbying Washington on two issues. It lost on both.
First, it did not get regulatory capture. Regulatory capture happens when compliance costs are set so high that no new competitor can afford to enter the market. Every company wants a monopoly, and the AI giants are no different. Lock out the challengers and you can charge whatever you like. That door is now closed.
Second, it did not get a liability waiver. Section 230, the 1996 US law that underpins the internet, shields technology platforms from liability for what their users post. Back then, those platforms were chatrooms and forums. The AI labs wanted the same protection for their models. They did not get it.
So if a model drives someone to suicide, or harms children or young women, the company behind it is liable. If a swarm of AI agents hacks a website, as has happened several times now, the company can face criminal and civil charges under existing cybercrime law. This is not theoretical. Meta has already been found liable for $12 billion over an algorithm that harmed children. That is just the beginning.
Nothing focuses a boardroom like the threat of being sued out of business. That fear is the strongest incentive these companies have to build proper guardrails.
It may be a coincidence, but Google has just voluntarily submitted its newest model, Gemini 4 Argon, for review by the US government and the industry before releasing it.
This is the part nobody is talking about. Worse, the media, NGOs and even the White House are framing it as the AI firms "policing themselves". That misses the point. Every company polices itself to some degree. The difference now is that outsiders and the board check the work, just as they do with tax and financial audits.
Frontier AI developers have agreed to bring in independent, third-party auditors. These auditors will not simply read a safety policy and tick a box. They will test whether the safety and control systems work. They will try to break them.
That is a big shift. Until now, the labs have marked their own homework. A model card and a polished blog post were enough. Now someone from outside the building checks the work.
The second requirement puts those findings in front of the board. Each firm commits to setting up an independent board committee that receives every audit finding, internal and external, and makes sure the problems are fixed.
Read that again. The findings do not stop with the product team. Nobody in communications gets to soften them. They go straight to the board, and the board has to act.
In our governance work with boards, we see the same pattern every time. Writing a policy is easy. Proving it works is hard. Holding someone accountable when it fails is harder still.
This agreement tackles all three. Combine it with real liability exposure and the incentives finally line up. If a lab ignores an audit finding and someone gets hurt, the board cannot claim it did not know.
You do not need to be Google or OpenAI to adopt the same discipline. Test your controls. Get an outside view. Put the findings in front of your board. Then make sure someone owns the fix.
The biggest AI companies in the world have just been told to prove their systems are safe. Your customers will soon expect the same from you.
My prediction: within a year, annual AI audits will be standard practice, and law in most countries, just like financial audits. This quarter is the best time to set up your AI audit process.
PS: We can help. AAAI helps boards set up their AI governance and audit processes. By popular demand, we have also launched a live online AI course series: AI Foundations, Copilot Automations and Agents, AI Governance, and AI and Copilot in Excel. Find out more about the online courses.