What is a third-party AI audit?
A third-party AI audit is a review of an AI developer's safety and security practices by an independent outside organization. It differs from internal testing, in which a company checks its own work.
Also known as: frontier AI auditing
Researched and fact-checked by AI, with no human review. 8 sources listed below. How we verify
Last updated
What does a third-party AI audit check?
An AI company can test its own systems. In a third-party audit, an outside organization checks that work. A January 2026 paper by Miles Brundage and 47 co-authors defines frontier AI auditing as rigorous third-party verification of developers' safety and security claims. The definition also covers evaluating a developer's systems and practices against relevant standards. It assumes deep, secure access to non-public information.
The authors say audits should not be limited to products the public can use. They should also cover how a company uses AI internally, its information security and how it makes safety decisions.
A related idea is the third-party compliance review. In it, an independent external party assesses whether a company is complying with its own safety framework, a 2025 paper says. The paper lists benefits, such as assurance for people inside and outside the company. It also lists challenges, including information security risks and added costs.
Where do audits appear in law and policy?
- White House accord. The White House Accord on Super Intelligence, signed on September 29, 2026, is voluntary. It says each company should partner with an independent external auditor or evaluator.
- Illinois. The governor's office says SB 315 makes Illinois the first state to require regular independent third-party safety audits of covered AI systems. The law was signed on July 6, 2026 and takes effect on January 1, 2027. Under the act's text, the yearly audit duty begins on January 1, 2028 at the earliest.
- California. The state enacted a law in September 2026 setting rules for how independent auditors evaluate AI products, Reuters reported.
What are the limits?
The International AI Safety Report 2026 says outside assessments of whether developers follow their own safety frameworks remain limited. It gives three reasons. Most frameworks are recent. Public information is scarce. There are no standardized external audits.
The accord shows another limit. It does not require companies to publish audit results, Al Jazeera noted.
Sources
- Frontier AI Auditing: Toward Rigorous Third-Party Assessment of Safety and Security Practices at Leading AI Companies, arXiv (Brundage and 47 co-authors)
- Third-party compliance reviews for frontier AI safety frameworks, arXiv (Homewood, Williams and 12 co-authors)
- White House releases ‘Accord’ between billionaire AI execs: Here’s what it says, Forbes Australia
- Gov. Pritzker Signs Nation-Leading Artificial Intelligence Safety Law, Office of the Governor of Illinois
- Public Act 104-0538: Artificial Intelligence Safety Measures Act (SB0315 Enrolled), Illinois General Assembly
- As Public Fears of AI Grow, Trump Digs in on Voluntary Safeguards, Reuters (via U.S. News & World Report)
- International AI Safety Report 2026, arXiv (Bengio and 91 co-authors)
- How does Trump’s White House AI accord work?, Al Jazeera