Last week Canberra promised to legislate mandatory AI standards by early 2027. Washington and Brussels are further down the same road and no nearer a working answer. You cannot out-legislate a technology that improves every few months, and you cannot ban an arms race. Here is the regulation that can actually keep pace.
Last Wednesday the Australian Prime Minister stood up at the University of Sydney and told the country that artificial intelligence is a bigger challenge, and a bigger opportunity, than social media ever was. He announced a new Office of AI inside his own department, and committed to legislating mandatory AI standards by early 2027, alongside power and water obligations on large data centres and copyright protection for creators.1
Credit where it is due. That is a real step, more candid than the wait-and-see we have run for five years. But notice what the announcement does not contain. It regulates the electricity going into the data centre and says almost nothing verifiable about the capability coming out of it. Australia is not alone in that. Washington and Brussels have the same gap. I have spent 30 years on both sides of an audit, as a Big Four advisory partner and then a CISO signing the attestations, and I can tell you where all three regimes are heading: by the time a standard is drafted, consulted on, legislated and commenced, the thing it describes has changed underneath it.
I do not think conventional regulation can win this race. I think there is exactly one approach that can, and we already trust it with the entire financial system. We audit it.
You cannot legislate a moving target. And nothing has ever moved like this.
You cannot ban what you cannot stop
Start with the thing most policy debates tiptoe around. You are not going to stop frontier AI. Not by prohibition, not by moratorium, not by any law a single country can pass.
The reason is structural. If one lab pauses, another keeps going. If one nation legislates a hard ceiling, a rival treats it as a strategic opening. This is an arms race, and the people who build these systems say so out loud. A United States congressional commission recommended in late 2024 that Congress fund "a Manhattan Project-like program dedicated to racing to and acquiring" artificial general intelligence.2 When a government body reaches for the Manhattan Project as its model, the argument about whether to race is over.
The natural analogy is nuclear weapons, and it is worth being clear-eyed about how far it carries. It holds for the strategic logic: catastrophic dual-use risk, great-power competition, nobody willing to disarm first. It breaks on the physics. Fissile material is scarce, detectable and held by states. Model weights are none of those. As the Bulletin of the Atomic Scientists notes, safety guardrails on an openly released model are "easy and inexpensive to remove by fine-tuning", and in one recent year 51 notable models were built by companies against just two by governments.3 You cannot embargo mathematics.
So the lesson of the nuclear age is not the bomb. It is the inspection regime around it. You cannot un-invent the capability, so you verify what is done with it. That is the pivot this debate needs: from stop it to verify it.
The rules are obsolete before they pass
Here is the problem in one number. METR, an independent research group, measured how long a task an AI can reliably complete on its own and found the frontier roughly doubling every seven months from 2019 to 2025, tightening to closer to four or five months in the most recent period.4
A rule written in 2026, for a model that exists in 2026, commenced in 2027, is describing a system two or three capability doublings out of date on the day it takes effect.
The ink is dry and the assumptions are already wrong.
This is not hypothetical. The European Union chose the hardest, most prescriptive path available, a binding AI Act with risk tiers and detailed obligations, and in 2026 it delayed its high-risk obligations to December 2027, a sixteen-month slip, after more than a hundred companies said the rules could not be met on time.5 The lesson is not that Europe got it wrong, but that prescriptive rules for a fast-moving, general-purpose technology are very hard to land, even when a serious government throws its full weight behind them.
The United States is the sharpest illustration, because there the machinery has not merely been slow, it has been thrown into reverse. Washington's flagship AI executive order was signed in October 2023, rescinded on the new President's first day in January 2025, and replaced with a deregulatory action plan pointed the opposite way.6 When Congress tried to stop individual states filling the vacuum, the Senate voted 99 to 1 to strip a ten-year moratorium on state AI laws out of the bill.7 The executive then threatened to withhold federal broadband funds from states with "onerous" AI laws.8 Colorado, the one state to pass a hard, European-style risk law, gutted it and replaced it with a narrower disclosure regime before it ever took effect.9 And the laws that survived, in California, New York and Texas, rest on the same quiet foundation: disclosure, transparency and incident reporting.10
Even the jurisdictions fighting hardest keep landing on the same instrument. Not prohibition, but disclosure of what the developer is doing. Which is one short step from the thing that actually works.
The arms-control lesson is verification, not prohibition
If you cannot stop the capability and cannot out-run it with rules, what is left? Verify it. Move the object of regulation off the technology and onto the people building it, and check what they tell you.
This is not my idea. The frontier labs reached for it themselves the moment they got scared. In May 2023 OpenAI's own leadership wrote that the world will "likely eventually need something like an IAEA for superintelligence efforts", an authority that can "inspect systems, require audits, test for compliance with safety standards".11 Note the verbs. Inspect. Audit. Test. That is verification, offered by the company with the most to lose from being left alone.
The harder question is whether you can verify a claim about software from the outside. You can, and the reason is compute. AI-relevant computing power is, in the words of one governance study, "detectable, excludable, and quantifiable", produced through an extremely concentrated supply chain.12 You cannot inspect every line of code, but you can meter the chips. Newer work goes further: a tamper-resistant "guarantee processor" on an AI accelerator could produce cryptographically verifiable claims about what a system has and has not done, adding under one percent to a high-end chip's die area, without ever exposing the model weights.12 The backbone largely exists; what is missing is the mandate to require it.
Audit the assertions, not the algorithm
Here is where my own trade comes in, because we solved this exact shape of problem a century ago. None of this is exotic. We already do it, every day, across the entire economy. Every listed company makes assertions about itself. This is our position. These are our controls. This is our outlook. Nobody takes management's word for it. An independent, accredited, legally accountable auditor tests those assertions against evidence, forms an opinion, and reports it to the market and the regulator. The board signs, the auditor verifies, the market relies on it. Modern capital markets run on that one idea: trust, but verify, by someone independent of the people making the claim.
It is not rocket science. We are simply proposing to hold the most powerful technology ever built to the same standard we already demand of an ASX-listed retailer.
It is not perfect. Enron happened. Every time auditors failed, we tightened independence, rotation and liability rather than throwing the mechanism away, because a fund manager in Melbourne still needs to put money into a company he will never visit. Apply that machinery to the frontier. An AI audit would test management's assertions, independently, on three things.
Capability. What the model can actually do, measured, not what the launch blog claims. Dangerous-capability evaluations, red-team results, how far the system can be pushed when someone is genuinely trying. The labs run these tests now. The difference is that an auditor would verify them rather than accept the summary on faith.
Roadmap. What is coming, and the thresholds that would trigger a pause. The labs already publish so-called if-then commitments: if the model crosses this line, we will do that. Good idea. The problem is that the lab writes the commitment, decides when it has been triggered, and marks its own homework. An audit puts an independent signature next to the threshold.
Guardrails. The safety controls built into the system, tested for whether they actually operate, not whether they exist on paper. A financial auditor does not read your controls policy and tick a box. They test whether the control worked. AI guardrails deserve that standard, and almost none of them get it today.
I am not inventing this from a standing start. It is a real and fast-growing school. Anthropic conceded in 2024 that its own responsible-scaling policy "is insufficient as it relies on self-governance decisions made by single, private sector actors", and proposed testing "similar to how accounting firms audit the books of private companies".13 A January 2026 research paper on frontier AI auditing treats a model's system card as the analogue of a financial statement, and its safety measures as internal controls an auditor should test.14 Miles Brundage, once head of AGI-readiness policy at OpenAI, now argues the same: regulate the organisations, not the individual models, on a ladder from baseline transparency to treaty-grade verification.15 The plumbing is arriving too. ISO/IEC 42001, the first AI management-system standard, is already certifiable by accredited bodies, and the United Kingdom is openly building an "AI assurance profession", with chartered accountants moving in.16
We even have the technical engine half-built. Australia's AI Safety Institute began testing frontier models this year, following the UK and US institutes.17 But those bodies test voluntarily and cannot enforce anything. We have stood up the inspectors and withheld the mandate to inspect.
The hole this fills
Because right now, the entire safety story rests on the labs grading their own work.
The lab designs the evaluation, runs it, interprets the result, decides whether its own threshold was met, and writes the report.
Sixteen companies signed the Frontier AI Safety Commitments in Seoul in 2024, and they matter. But they are self-referential. The labs define what safety means, test themselves against it, and interpret the result. When one major developer shipped a frontier model in 2025 with no public safety report at all, nothing happened. An independent index of company safety practices could not place a single lab above a D grade on existential safety, and named the absence of independent oversight as the reason.18 The commitments are management's assertions with no auditor attached.
The objections, and why they do not sink it
I have argued this enough times to know the pushback, so let me take it head on.
Audit gets captured. Enron proves it is theatre. No. Enron proves audit without independence is theatre. It did not end audit. It produced Sarbanes-Oxley: mandatory independent attestation, a dedicated oversight board, and a ban on the consulting conflicts that had corrupted the work.19 The answer to weak verification has never been no verification. It is verification with teeth, which is the regime I am arguing for.
AI audit is immature. The auditors could not understand the models. Partly true, today. Which is the investment case, not the objection. Financial audit did not begin with specialists in valuations, actuarial risk and IT systems. It built them, because the assurance was worth building. The measurement infrastructure, the standards, the profession and the hardware verification are being built right now.
You still need enforcement and liability. Yes, you do, and that is the point of verification, not an argument against it. You cannot penalise, license or litigate what you cannot measure. Audited assertions create the evidentiary record that hard enforcement then bites on. Verification and enforcement are complements, not alternatives.
And to be fair to the other side: serious people, including some of the field's founders, argue that an audit only checks compliance with a standard, and that we still need binding red lines for the genuinely unacceptable.20 They are not wrong to want a floor. But a binding rule still needs someone to verify the facts it binds to. Audit is not the alternative to hard regulation. It is the enforcement mechanism our regulation is currently missing.
What good looks like
If you sit on a board, an audit committee or a policy desk, this is what to demand of any AI regime worth the name, ours or anyone else's.
- Make it mandatory at the frontier, not voluntary. Voluntariness is the failure mode every previous mechanism has shared.
- Make the auditor independent and accredited, the way we accredit the firms that sign off on banks. Paid to be right, not to be re-hired.
- Point it at the three assertions that matter: capability, roadmap and guardrails. Test the assertion, not the press release.
- Give it real access, to evaluations, model internals and compute records. An audit that sees only what it is shown is not an audit.
- Make it continuous and forward-looking, closer to how a prudential regulator supervises a bank than how accounts are signed once a year. Capability jumps do not wait for the annual cycle.
- Require it to report, to the regulator, and to the public wherever it is safe to do so.
The only thing that scales
The capability to audit these companies at this level does not fully exist yet. That is not an argument against doing it. It is the argument for building it, and building it fast. I am not certain audit alone is sufficient, and frontier AI may prove harder to verify than a balance sheet. But I am certain it is the only approach I have seen that can keep pace, and the reason is almost paradoxical. It keeps pace because it does not try to. It does not chase the technology with rules that are stale on arrival. It verifies the people who can keep up, and holds them to what they said.
We do not regulate what a bank's books say. We audit them. It is time we did the same for the most powerful technology any of us will ever work with. Canberra, Washington and Brussels are all reaching for the same lever and missing the same one. Last week's announcement is the right moment to build it in.
Sources and references
- Prime Minister Anthony Albanese, address at the University of Sydney, 15 July 2026: new Office of AI in the Prime Minister's department, mandatory AI standards to be legislated by early 2027, data-centre power and water obligations, and copyright protection for creators. Reporting across Forbes Australia, CommBank Newsroom, The New Daily, The Conversation, and Gilbert + Tobin and White & Case client updates.
- US-China Economic and Security Review Commission, 2024 Annual Report to Congress (November 2024): recommendation that Congress "establish and fund a Manhattan Project-like program dedicated to racing to and acquiring an Artificial General Intelligence (AGI) capability".
- Kevin Klyman and Raphael Piliero, "AI and the A-bomb: What the analogy captures and misses", Bulletin of the Atomic Scientists, 9 September 2024.
- METR, "Measuring AI Ability to Complete Long Tasks" (19 March 2025) and "Time Horizon 1.1" (29 January 2026): frontier task-completion time horizon doubling roughly every seven months across 2019 to 2025, accelerating to roughly every four to five months in the most recent period.
- Council of the EU, "Artificial Intelligence: Council and Parliament agree to simplify and streamline rules" (7 May 2026); Morgan Lewis client alert. High-risk obligations pushed to 2 December 2027 (a sixteen-month delay) following pushback including a call from more than 110 companies (Airbus, ASML and Mistral among them) to delay enforcement.
- Executive Order 14110 "Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence" (30 October 2023), rescinded 20 January 2025; EO 14179 "Removing Barriers to American Leadership in Artificial Intelligence" (23 January 2025); "Winning the Race: America's AI Action Plan" (White House, 23 July 2025).
- US Senate vote of 99 to 1 on 1 July 2025 to strip the ten-year state-AI moratorium from the budget reconciliation package. Reporting: Time; Goodwin Law and Baker Botts client alerts.
- Executive Order 14365 "Eliminating State Law Obstruction of National Artificial Intelligence Policy" (11 December 2025): directs an AI Litigation Task Force and instructs Commerce to treat states with "onerous" AI laws as ineligible for remaining BEAD broadband funds. Commentators (Gibson Dunn, Ropes & Gray) stress an executive order cannot itself pre-empt state law.
- Colorado SB 24-205 (the EU-style Colorado AI Act, signed May 2024) was delayed twice and then repealed and replaced by SB 26-189 (signed 14 May 2026) with a narrower automated-decision disclosure framework effective 1 January 2027, dropping the duty of care, risk-management programmes and impact assessments before the original ever took effect. Hunton and National Law Review analyses.
- California SB 53, the Transparency in Frontier Artificial Intelligence Act (signed 29 September 2025, effective 1 January 2026); New York RAISE Act (signed December 2025, effective 1 January 2027); Texas Responsible Artificial Intelligence Governance Act, TRAIGA (signed 22 June 2025, effective 1 January 2026). All are built on disclosure, transparency, framework publication and incident reporting rather than prescriptive prohibition; several anchor safe harbours to the NIST AI Risk Management Framework and ISO/IEC 42001.
- Sam Altman, Greg Brockman and Ilya Sutskever, "Governance of superintelligence", OpenAI, 22 May 2023: the world will "likely eventually need something like an IAEA for superintelligence efforts", an international authority that can "inspect systems, require audits, test for compliance with safety standards".
- Girish Sastry, Lennart Heim, Haydn Belfield, Markus Anderljung, Miles Brundage et al., "Computing Power and the Governance of Artificial Intelligence" (14 February 2024): AI-relevant compute is "detectable, excludable, and quantifiable, and is produced via an extremely concentrated supply chain". On hardware-enabled verification: FlexHEG (Flexible Hardware-Enabled Guarantees), a tamper-resistant "guarantee processor" estimated to add under one percent to the die area of an NVIDIA H100 while producing cryptographically verifiable claims about what an AI system has or has not done, without exposing model weights. See also Yonadav Shavit, "What does it take to catch a Chinchilla? Verifying Rules on Large-Scale Neural Network Training via Compute Monitoring" (March 2023).
- Anthropic, "Third-party testing as a key ingredient of AI policy", 25 March 2024: its Responsible Scaling Policy "is insufficient as it relies on self-governance decisions made by single, private sector actors", and testing should work "similar to how accounting firms audit the books of private companies".
- Miles Brundage, Noemi Dreksler, Yoshua Bengio, Markus Anderljung, Stephen Casper and others, "Frontier AI Auditing: Toward Rigorous Third-Party Assessment of Safety and Security Practices at Leading AI Companies", arXiv 2601.11699 (January 2026): proposes external auditors verifying developer assertions, treating system cards as the analogue of financial statements and safety, security and compute measures as internal controls.
- Miles Brundage (formerly head of AGI-readiness policy at OpenAI; now AVERI, the AI Verification and Evaluation Research Institute), "Why AI Needs Independent Auditors", Lawfare, 14 April 2026: shift the object of regulation from individual models to the organisations building them, graded on an assurance ladder from baseline transparency to treaty-grade verification.
- ISO/IEC 42001:2023, the first AI management-system standard, certifiable by accredited bodies (UKAS, ANAB, JAS-ANZ for Australia and New Zealand), with the Big Four accounting firms now certifying and building AI-assurance practices. UK Department for Science, Innovation and Technology, "Trusted Third-Party AI Assurance Roadmap" (September 2025): sets out to build an "AI assurance profession", noting a market of about GBP 1.01 billion GVA with 524-plus firms in 2024, projected to about GBP 18.8 billion by 2035, with the accounting profession (ICAEW) engaged.
- Australia's AI Safety Institute (AISI), Department of Industry, Science and Resources: began pre-deployment testing of frontier models in 2026 using red teaming and capability elicitation, following the UK and US institutes. Testing is voluntary and the institute does not enforce compliance.
- Frontier AI Safety Commitments, AI Seoul Summit 2024 (sixteen companies), GOV.UK; Future of Life Institute AI Safety Index (2025 editions), judged by an independent expert panel, which found no company scoring above a D on existential safety and cited the absence of independent oversight. Reporting on the Seoul commitments identified one major developer that shipped a frontier model in 2025 without a public safety report.
- Sarbanes-Oxley Act of 2002, enacted after the Enron and Arthur Andersen collapse: mandatory independent attestation of internal controls (Section 404(b)), the Public Company Accounting Oversight Board (PCAOB), and restrictions on auditors providing conflicting consulting services to audit clients.
- The counter-case for binding rules: the "Global Call for AI Red Lines" (launched September 2025, more than 300 signatories including Nobel laureates); Geoffrey Hinton and Yoshua Bengio, who argue self-regulation is insufficient ("the invisible hand is not going to keep us safe"); and the International AI Safety Report, chaired by Yoshua Bengio, which finds that risk-management measures exist but their real-world effectiveness is uncertain and hard to verify.
