Congress wants AI audited. The profession that invented the audit should read this bill.

On July 23, six members of Congress, three from each party, introduced a bill about artificial intelligence that contains two words this readership knows something about: independent audits.

The FRONTIER Act, sponsored by Representatives Jay Obernolte and Lori Trahan, would build a national, risk-based oversight regime for the most advanced AI systems: model cards describing what a system is and does, risk-management frameworks developers must actually run, incident reporting when something goes seriously wrong, and, for the most powerful models, independent audits. Obernolte’s framing is the whole pitch in one sentence: the bill focuses on the largest developers and most advanced models, “requiring transparency, independent evaluation, and timely reporting of serious safety incidents.” It would also override the growing patchwork of state AI laws, a preemption fight we will leave for another day. The bill was just introduced, and most bills die; its ideas are what matter here, because some version of them is coming, in Washington or, as we covered this month, from Brussels first.

Notice what Congress reached for when it wanted the public to trust a powerful, opaque, systemically important technology: not a ban and not a licensing office, but an audit, somebody outside the company checking the claims, on the record. The sponsors say the regime would focus on the handful of companies building the most powerful models, which makes the examiner’s role even more concentrated: a small number of signatures standing between frontier labs and public trust. The bill even names the somebody: a new category of “independent verification organizations,” licensed by the Commerce Department, required to demonstrate independence from the industry they examine, assessing the largest developers at least every six months. What the text does not build is everything the profession learned the hard way: the technical standards those examiners would follow, who inspects the inspectors, and the liability that lands on a signature that turns out to be false. The hardest parts of this regime are still blank, and the profession reading this newsletter is the one with a century of experience filling exactly those blanks.

The 1933 rhyme

The last time the United States confronted a complex, systemically dangerous machine it did not understand, the machine was the securities market. The answer Congress landed on in the 1930s was not to run companies itself. It was disclosure, verified: public financial statements, attested by independent outside accountants, as the price of access to public capital. The modern accounting profession, its standards, its licensure, its liability, grew out of that public commission. Attestation is not a service line the profession added along the way. It is the founding product.

The bargain was never that audited statements would be perfect. They were not, and every generation’s fraud proved it. The bargain was that an independent examination makes deception expensive, error detectable, and trust rational enough for strangers to transact, and each failure refined the machinery instead of discrediting it. That is what a working attestation regime looks like from the inside: imperfect, self-correcting, and load-bearing.

Frontier AI in 2026 sits roughly where public markets sat then: enormous private power, public consequences, information asymmetry so large that trust cannot be established by the companies’ own statements. And Congress, feeling its way toward an answer, has landed on the same instrument: the independent examination. The FRONTIER Act is, among other things, an admission that self-certification is not going to be enough. A profession whose entire identity is built on that admission should be paying closer attention than it is.

A CPA already marked up the bill

At least one accountant has. Jim Germer, a Florida CPA, argued in Accounting Today this month that the FRONTIER Act is meaningful progress that misses two things any auditor would flag on day one.

The first is contemporaneous records. A report filed after the fact describes what a company chooses to remember; in Germer’s words, “it’s a paper trail assembled once the trouble’s already started.” His point, basic audit hygiene applied to AI, is that the record has to be created when the decision is made, not reconstructed later to satisfy a reporting deadline. Training and deployment decisions should generate timestamped, tamper-resistant logs at the moment they happen, because everything downstream, the model card, the risk report, the audit itself, is only as good as the record it examines.

The second is independence with teeth. Germer, who credits the bill’s public registry of frontier developers, wants its examiners funded through pooled assessments rather than paid directly by the companies they examine, “staffed under real restrictions on moving between the examiner’s office and the companies it oversees,” and “protected from removal by anyone with a stake in a favorable outcome.” His sharpest line travels well beyond AI: “An examiner’s funding source shapes what that examiner is willing to find.”

Honesty requires the next sentence too. The accounting profession is in no position to deliver that line smugly, because the client-pays-the-auditor conflict is the profession’s own oldest wound. It is why an entire regulator exists to inspect the inspectors, the one whose own results we examined last week. What the profession can offer AI oversight is not purity. It is a century of scar tissue: every failure mode of attestation, from captured examiners to checkbox reviews, has already happened in accounting, and most of the guardrails that answer them, inspection regimes, independence rules, rotation, liability, were invented here. Building AI audit without that institutional memory means rediscovering each failure live, on a technology with less forgiving failure modes.

The market is not waiting for the bill

The assurance industry has noticed the blank space. The Journal of Accountancy spent a feature last November on CPAs as AI system evaluators, with the AICPA exploring what it calls assurance over AI and its senior manager for AI assurance innovation, Carrie Kostelec, arguing that “CPAs are really well positioned to fill that need because of the credibility and skill sets.” The push is coming from inside the AI world too: in January, OpenAI’s former policy chief Miles Brundage launched a nonprofit institute, AVERI, to argue for exactly this, rigorous independent safety audits of frontier labs. EY is building AI assurance frameworks; PwC markets an assurance-for-AI practice; the scaffolding being reached for is familiar, SOC-style examinations adapted to AI, plus external frameworks like NIST’s AI Risk Management Framework and ISO/IEC 42001. The same JofA piece concedes the catch: comprehensive US standards for this work do not yet exist. Criteria are being improvised engagement by engagement. And the demand side is not waiting on Washington either: Europe’s regime, whose deadlines we mapped this month, brings conformity assessment for high-risk AI systems onto the calendar from late 2027, and every multinational deploying those systems will need someone competent to get them through it.

That improvisation phase is precisely when a service line’s reputation gets set. SOC 2 became an industry because a real trust gap met a disciplined attestation format. It also became, in its worst corners, a commodity checkbox, and AI assurance will face the same commercial pressure at higher stakes. An AI audit that a vendor can buy for its marketing deck is worse than no audit, because it spends the profession’s credibility to launder someone else’s risk. The profession’s moat in this market is the willingness to say no, and the moat only holds if firms price it in from the start.

What it means for you

If you run a firm with controls and attestation work, SOC practices, IT audit, compliance, this is the adjacent market forming in real time. The transferable assets are the ones you already have: independence discipline, evidence standards, sampling, an opinion with a name attached. The realistic entry point is not auditing frontier models in San Francisco; it is assurance over how ordinary companies, your clients, govern the AI they deploy, the inventory-consent-oversight questions our readers have seen us return to all summer. Learn NIST’s AI framework and ISO 42001 now, the way early SOC practitioners learned the trust services criteria.

If you are earlier in your career, “AI evaluator” is about to be a job title with a licensure debate attached. The people who can read a management assertion skeptically and read a model card at all will be rare for years.

If you sit on a board or an audit committee, the buyer’s side of this market is yours already. When a critical vendor waves an AI assurance report at you, read it the way you would read any attestation: who issued it, against what published criteria, under what independence rules, with what opinion actually expressed. A glossy PDF with no criteria and no accountable signer is marketing wearing audit’s clothes, and the whole point of this edition is that the difference is checkable.

And whoever you are, when AI assurance engagements start crossing your desk, apply Germer’s two tests before you sign anything: was the evidence generated contemporaneously, and does the fee structure let you afford to find problems? If either answer is no, the engagement is not an audit. It is a costume.

The bottom line

Strip the acronyms and the FRONTIER Act is Congress rediscovering, for machines, the thing accounting figured out about markets a century ago: powerful systems get trusted when someone independent examines them and signs. That is the profession’s founding technology, more durable than any of the tools that pass through these pages. AI can do the work. It cannot sign the work, and now the United States government is groping toward the same conclusion about AI itself: the models cannot self-certify, someone accountable has to look. The profession can meet that moment, or it can watch consultants without standards, inspection, or liability take the franchise and devalue the word audit while doing it. The century-old asset is the signature that means something. Defend the meaning, and the market takes care of itself.

Footnote

Footnote is an independent publication. It is not professional accounting, tax, or legal advice, and not legislative prediction; the FRONTIER Act is a newly introduced bill whose provisions and prospects may change. Descriptions of the bill are based on its sponsors’ materials and reporting linked above; views attributed to individuals and organizations are their own published statements. Our historical characterizations are simplified. We have no relationships with any organization named here. Details are current as of August 25, 2026.