Four times in
Congress has finally started moving. The Frontier Risk Oversight, National Transparency, Independent Evaluation and Reporting Act, introduced last month by Rep. Jay Obernolte, R-California, and Lori Trahan, D-Massachusetts, would require the largest AI developers to publish risk-management frameworks, undergo audits from independent verification organizations, and report critical safety incidents within a matter of days of discovery. That's real progress, and I don't want to understate it.
The
The remaining gap, in my view, is this: The FRONTIER Act's entire architecture responds to things after they're discovered. An incident happens, and the clock starts on a reporting window measured in days, not months, which is real progress over earlier drafts. But a reporting deadline only starts once someone knows something went wrong. If nothing requires the underlying record to exist at the moment a decision was made, there's no guarantee anyone ever finds the problem in time to start that clock. The deadline assumes discovery. It doesn't require it.
Congress seems to realize that the question of independence isn't fully solved. The
From an accounting perspective, Congress should require something our profession has understood for a century: the record has to be created when the decision is made, not reconstructed afterward to satisfy a reporting deadline. When an AI company trains a system, someone decides which data to feed it. That decision should generate a timestamped, unchangeable record the moment it happens, the same way a transaction generates an entry on the day it occurs, not the day someone remembers to write it down.
I think that record needs to be checked against something specific, not just described in a general framework. Congress should require companies to compare their training data against a registry of protected material before that data is ever used, and to log the result of that check as part of the same contemporaneous record. A framework that says, "we have a policy for this," is not the same as a log that shows the check actually happened, on a specific date, with a specific result.
I think the auditor doing the checking has to be independent in a much stronger sense than the FRONTIER Act currently requires. Verification organizations licensed by the state and paid directly by the companies they examine are a real improvement over nothing. Accounting learned this lesson the hard way: An examiner's funding source shapes what that examiner is willing to find. A truly independent AI examiner needs to be funded through pooled assessments that aren't tied to any single company's payment, staffed under real restrictions on moving between the examiner's office and the companies it oversees, and protected from removal by anyone with a stake in a favorable outcome.
And I think findings need consequences that don't depend on the company's cooperation. A recommendation is not a consequence. An audit finding that simply gets logged and left to the company's discretion is not a consequence. Congress should specify automatic consequences when independent examiners verify material violations, just as a failed safety inspection grounds an aircraft regardless of what the airline would prefer.
None of this requires Congress to solve the hardest question in AI policy, which is trying to define what makes a system dangerous or how capable is too capable. That fight never ends, and it's usually won by whoever benefits most from the confusion. What I'm describing doesn't touch that question at all. It asks something narrower and more answerable: Was a record created at the time, was it checked against something specific, and can an independent party who isn't beholden to the company confirm the answer?
I spent the past two months developing exactly this architecture, including the funding structure that keeps an examiner honest and the specific evidentiary standard that makes findings hold up. To test whether these ideas could actually work together in statutory form, I built a complete model statute, the
The FRONTIER Act is a genuine step forward, and I'd rather see it pass than see nothing pass at all. But our profession has spent a hundred years learning that oversight built around after-the-fact disclosure isn't oversight. It's a paper trail assembled once the trouble's already started. If Congress wants this to actually work the first time, the record has to exist before anyone needs it, not after.








