AT Think

The accounting lesson Congress still hasn't applied to AI

Four times in this space, I've made a case I believe is airtight and uncomfortable: AI systems cannot verify their own alignment, their own safety and their own compliance, and neither can the companies that build them. Self-certification is exactly the failure our profession exists to catch, and I tracked that pattern across banking, aviation, pharmaceuticals and our own history. Meaningful oversight, every time, arrived only after the damage was already done.

Processing Content

Congress has finally started moving. The Frontier Risk Oversight, National Transparency, Independent Evaluation and Reporting Act, introduced last month by Rep. Jay Obernolte, R-California, and Lori Trahan, D-Massachusetts, would require the largest AI developers to publish risk-management frameworks, undergo audits from independent verification organizations, and report critical safety incidents within a matter of days of discovery. That's real progress, and I don't want to understate it. 

The bill also includes provisions I think are valuable, such as creating a public registry of frontier developers with beneficial-ownership disclosure, so the public finally knows who's actually operating at this scale. But on the core question—whether the record exists in time to matter—is still, in a way that should sound familiar to anyone in our profession, a step behind where it needs to be.

The remaining gap, in my view, is this: The FRONTIER Act's entire architecture responds to things after they're discovered. An incident happens, and the clock starts on a reporting window measured in days, not months, which is real progress over earlier drafts. But a reporting deadline only starts once someone knows something went wrong. If nothing requires the underlying record to exist at the moment a decision was made, there's no guarantee anyone ever finds the problem in time to start that clock. The deadline assumes discovery. It doesn't require it.

Congress seems to realize that the question of independence isn't fully solved. The bill tells the Government Accountability Office to check every year if the auditors are still independent from the companies they review. This is a good step, but it's also a sign that the system doesn't make independence a built-in feature from the beginning. Our field learned long ago that checking honesty once a year isn't the same as designing the system so the watchdog can't easily lose its independence.

From an accounting perspective, Congress should require something our profession has understood for a century: the record has to be created when the decision is made, not reconstructed afterward to satisfy a reporting deadline. When an AI company trains a system, someone decides which data to feed it. That decision should generate a timestamped, unchangeable record the moment it happens, the same way a transaction generates an entry on the day it occurs, not the day someone remembers to write it down.

I think that record needs to be checked against something specific, not just described in a general framework. Congress should require companies to compare their training data against a registry of protected material before that data is ever used, and to log the result of that check as part of the same contemporaneous record. A framework that says, "we have a policy for this," is not the same as a log that shows the check actually happened, on a specific date, with a specific result. 

I think the auditor doing the checking has to be independent in a much stronger sense than the FRONTIER Act currently requires. Verification organizations licensed by the state and paid directly by the companies they examine are a real improvement over nothing. Accounting learned this lesson the hard way: An examiner's funding source shapes what that examiner is willing to find. A truly independent AI examiner needs to be funded through pooled assessments that aren't tied to any single company's payment, staffed under real restrictions on moving between the examiner's office and the companies it oversees, and protected from removal by anyone with a stake in a favorable outcome.

And I think findings need consequences that don't depend on the company's cooperation. A recommendation is not a consequence. An audit finding that simply gets logged and left to the company's discretion is not a consequence. Congress should specify automatic consequences when independent examiners verify material violations, just as a failed safety inspection grounds an aircraft regardless of what the airline would prefer.

None of this requires Congress to solve the hardest question in AI policy, which is trying to define what makes a system dangerous or how capable is too capable. That fight never ends, and it's usually won by whoever benefits most from the confusion. What I'm describing doesn't touch that question at all. It asks something narrower and more answerable: Was a record created at the time, was it checked against something specific, and can an independent party who isn't beholden to the company confirm the answer?

I spent the past two months developing exactly this architecture, including the funding structure that keeps an examiner honest and the specific evidentiary standard that makes findings hold up. To test whether these ideas could actually work together in statutory form, I built a complete model statute, the Independent AI Provenance and Examination Act, using AI-assisted drafting under close human review. It's live now at thinkingsovereignty.ai/ai-governance-model-act for anyone in this profession to read it the way we'd read a client's workpapers.

The FRONTIER Act is a genuine step forward, and I'd rather see it pass than see nothing pass at all. But our profession has spent a hundred years learning that oversight built around after-the-fact disclosure isn't oversight. It's a paper trail assembled once the trouble's already started. If Congress wants this to actually work the first time, the record has to exist before anyone needs it, not after.


For reprint and licensing requests for this article, click here.
Technology Practice management Artificial Intelligence Audit
MORE FROM ACCOUNTING TODAY
Load More