THE AI INSTITUTE / RESEARCH FOR LEADERS
Ask What the AI Safety Audit Actually Tested
Before relying on an audit, ask what it covered, how hard it looked and whether the failures were fixed.
An AI audit should support a specific operating decision with evidence of its scope, testing effort and remediation—not stand in for a general promise of safety.
Key points
What this paper means for leaders
- Specify the decision the audit must support.
- Ask what was excluded and how much testing was attempted.
- Separate a voluntary commitment from a legal obligation.
- Require evidence that material failures were fixed and retested.
The decision
Do not approve an adjective
Before accepting an AI supplier’s claim that its system has been independently audited, ask for the decision the audit supports. Permission to run a limited trial, expand a workflow and remove a human checkpoint are different decisions. A reassuring label cannot tell a board which one the evidence justifies.
On 29 September, six AI companies signed a voluntary White House safety accord. Infosecurity Magazine reports commitments to internal controls, internal review, independent external assessment and board oversight. Its 30 September account describes an agreement, not new regulatory requirements. 1 That distinction belongs near the top of any executive briefing about it.
The useful response is to improve what your organisation asks of an audit. Specify the system and operating conditions, the effort spent looking for failures, and the evidence that material findings were addressed. This is the Institute’s proposed commissioning discipline, not a claim that the accord itself supplies those details.
Continue reading
Register once. Keep reading every Institute article.
Read all Institute research on this device with your name and work email. No password needed.