Webmasters LDN
Contact
← Blogs

September 30, 2026 · Blogs

AI self-regulation: what the White House accord does and does not do

On 29 September 2026, Donald Trump and six tech leaders signed a voluntary AI safety accord. Here is what it commits firms to, what it leaves out and how it compares with EU and UK rules.

On Tuesday 29 September 2026, President Donald Trump hosted leaders of several of the biggest US technology companies at a private White House lunch. Afterwards, standing beside them, he told reporters that he and the executives had signed an agreement on AI safety. Asked whether it was binding, he said he thought it was "morally binding". He also called it "almost like a constitution" and "a form of protection", and posted the signed text on his Truth Social account later that day.

The meeting came after both OpenAI and Anthropic had reported cases of their models getting into other organisations' systems without permission.

What was signed

The document is titled the White House Accord on Super Intelligence, with the subtitle "Joint Commitment on Frontier Responsibilities". Super Intelligence is Trump's preferred name for AI, and the same day he ordered federal agencies to use it in place of "artificial intelligence".

The accord runs to roughly 300 words and bears seven signatures:

  • Donald Trump, US president
  • Sundar Pichai, Google
  • Dario Amodei, Anthropic
  • Mark Zuckerberg, Meta
  • Greg Brockman, OpenAI president
  • Elon Musk, xAI (now part of SpaceX)
  • Jensen Huang, Nvidia

Microsoft's Satya Nadella and Amazon founder Jeff Bezos also attended the lunch, but their names are not among the signatures.

What it commits the companies to

The accord's starting point is that each company must answer for the safety of what it builds and earn the confidence of its customers and the wider public. It then sets out four "layers of controls and audits" that every company should adopt:

  • Internal controls that track each model's capabilities and alignment in training and in use, in areas such as cybersecurity, biosecurity and chemical threats, and that make sure models do not "hack or access technical systems in unintended ways".
  • An internal team that checks those controls and detection tools work and that problems get fixed.
  • External review by an independent auditor or evaluator, working with the company, to test whether the safeguards do their job.
  • Board oversight by an independent committee of the board, which receives the internal and external reports and makes sure issues are put right.

The companies will also meet regularly to agree safety standards and best practice. Looking ahead, the text allows that these measures may later be made legally binding, but says each firm is committed to them regardless.

Zuckerberg called it a first step that the whole industry could get behind. Amodei said the technology carries "very real risks" and that how to handle them is still under discussion.

What it does not do

House Speaker Mike Johnson, who co-hosted the lunch, described the accord's commitments as "voluntary on behalf of the industry". None of it is enforceable in law, and it does not say what happens if a company falls short.

The text also leaves details open. As the Guardian pointed out, regulators play no part in any of the four layers, and there is no promise to publish what outside evaluators find. The accord names no auditors, defines no standards for them and sets no timetable. AP reported that the companies already take, or had previously promised, some of these measures.

All six companies had already signed an earlier voluntary pledge, the Frontier AI Safety Commitments, which the UK and South Korean governments announced at the AI Seoul Summit in May 2024 and which included publishing safety frameworks.

Trump also floated a committee of roughly 10 people to oversee the industry, without saying who would sit on it, and said he would name an "AI czar" within days.

Reactions were mixed. According to AP, Shri Narayanan of the University of Southern California said the accord tries to balance room for innovation against the need for regulation, while his colleague Robin Jia questioned placing "so much faith in self-policing". Kimberlee Weatherall, a law professor at the University of Sydney, called it "deeply unimpressive", the BBC reported. Democratic senator Mark Warner urged Congress to make testing, evaluation and incident reporting mandatory for the most advanced models, according to CBS News.

How it compares with the EU and the UK

In the European Union, similar safeguards are a legal requirement. Under the EU AI Act, providers of general-purpose AI models have had legal obligations since 2 August 2025, including a duty to give technical information to businesses that build the models into their own systems. Providers of the most advanced models must also assess and mitigate risks and report incidents. Enforcement began on 2 August 2026, when the European Commission's AI Office gained powers to request documentation, evaluate models and require corrective measures, up to restricting a model's availability. Fines can reach €15 million or 3% of worldwide annual turnover, whichever is higher, and the rules cover providers placing models on the EU market, including those established outside the EU.

Reuters has described the UK's approach as light-touch and closer to the US than the EU. Britain has no single AI regulator, leaving oversight to existing bodies, and the King's Speech in May 2026 announced no standalone AI bill. The AI Security Institute tests frontier models before release under voluntary agreements with OpenAI, Anthropic, Google and others. In an interview with Reuters in August, AI minister Kanishka Narayan said the government would consider regulation if that voluntary system stopped protecting the public adequately. On 30 September, the Guardian reported Bank of England governor Andrew Bailey's view that authorities must keep the "right to intervene" in AI, though he argued regulation is not the place to start.

What it may mean for businesses

The accord places no obligations on organisations that use these companies' AI tools, and it gives customers no route to enforce the developers' commitments. In the EU, by contrast, a business that builds another provider's general-purpose model into its own AI system can complain to the AI Office about that provider's compliance. Nor does the accord change the rules UK organisations already follow, such as data protection law, on which the Information Commissioner's Office publishes AI guidance.

The accord presents the four layers as reassurance for customers and the public, but the details needed to check that are not yet public. Points to watch include:

  • whether the companies name their external auditors and publish what they find
  • what standards come out of the companies' regular meetings
  • who sits on the proposed oversight committee, and what powers it has
  • whether any of the steps become US law, as the accord itself suggests could happen

This article summarises documents and news reports published up to 30 September 2026 and is not legal advice.

Sources