Six AI companies signed a voluntary safety accord with President Trump at the White House on 29 September, and the striking thing about the document is how little it requires. The White House Accord on Superintelligence commits Google, Anthropic, Meta, OpenAI, xAI and Nvidia to four broad layers of control: internal safety monitoring during training and deployment, assessment by independent auditors, regular standard-setting meetings between signatories, and an acknowledgement that codifying this in law may eventually make sense.
It sets no audit frequency, defines no threshold for what counts as robust, and names nobody to enforce the third-party evaluations.
Trump called it "almost like a constitution in a way," and House Speaker Mike Johnson described it as a statement of principles. Mark Zuckerberg summarised the commitment as "robust internal controls and detecting if there are any issues with the technology, coupled with multiple layers of auditing."
Voluntary Does Not Mean Consequence-Free
The gap between a pledge and a regulation is narrower than it looks, because of what the accord does not displace. The Federal Trade Commission's authority over unfair and deceptive practices is untouched, and a company that publicly commits to controls it does not implement has made a representation regulators can act on.
That matters this week in particular. The FTC opened an investigation on 30 September into AI agent risks at OpenAI, Anthropic and others, with chairman Andrew Ferguson preparing demands for documents and testimony about how companies test and control their models. A signed accord describing robust internal controls becomes a document that investigation can measure against.
State law is equally unaffected. Nothing in the accord preempts state AI statutes, consumer protection law or private rights of action, so companies cannot treat it as their compliance framework.
Vagueness Cuts Both Ways
The undefined terms are the part compliance lawyers will focus on. "Robust" has no agreed meaning, which gives companies latitude now and gives regulators latitude later, since what a reasonable company should have understood by the word can be argued after an incident rather than before it.
Companies that signed, and companies that buy from them, would do better to write down their own definitions and keep the evidence, rather than wait for someone else to supply one retrospectively.
The States Are Not Waiting
Any hope that voluntary commitments settle the question is already running into resistance. In October, 26 state attorneys general urged Congress to regulate frontier AI while preserving state authority, pushing back against the federal preemption that has been central to the administration's framework.
California has gone further on its own, with Governor Gavin Newsom signing an executive order in September to accelerate the state's AI safety laws and advance work on an emergency shut-off for frontier models, overseen by independent verification organisations embedded in AI labs.
Companies operating across the US therefore face a federal approach built on voluntary commitments and existing enforcement powers, and a state approach heading towards specific technical requirements. The accord does nothing to reconcile them.
Why It Was Signed At All
The timing suggests why the industry wanted it. The accord arrived after a difficult few months: an OpenAI agent breached Hugging Face's infrastructure during testing, agents at several labs reached outside organisations through a shared evaluation environment, a Dutch security nonprofit was compromised by an autonomous agent, and Florida's attorney general asked a court to restrict OpenAI's model development.
A voluntary framework announced at the White House is a reasonable response to that run of events if the alternative is legislation written in reaction to the next one. It also fits the administration's preference for avoiding rules that might slow US companies against Chinese rivals.
ENISA's executive director, Juhan Lepassaar, put the sceptical case plainly this week when he said companies' warnings about AI often serve to shift responsibility away from themselves, and that "no one thinks self-regulation is enough."
What Businesses Should Do With It
For companies buying AI services, the accord is useful as a checklist rather than an assurance. A signature says nothing about whether a provider's controls work.
The practical steps are to ask vendors for the actual audit reports behind their commitments, to confirm who performs those audits and how often, and to keep state-level obligations tracked separately since the accord does not touch them. Contracts should specify what the provider actually warrants rather than referring to public pledges.
Businesses deploying AI internally should take the same approach to their own controls. The accord's four layers are a reasonable structure to borrow: monitoring during deployment, independent review, documented standards, and a board-level look at what the auditors found.
Principles Now, Rules Later
The accord is best understood as the industry and the administration agreeing on vocabulary before anyone agrees on rules. It commits six companies to nothing specific, but it puts their names to a description of what responsible development looks like, and that description will be used as a benchmark by regulators, litigants and customers who had no part in writing it.
Whether it becomes the basis of a federal framework or a footnote depends on what happens next. If the FTC investigation produces findings, if the state attorneys general get the legislation they are asking for, or if another agent incident does real damage, the gap between a morally binding pledge and a legally binding rule will close quickly.