|
Getting your Trinity Audio player ready...
|
As we’ve seen rapid advancements in AI, government oversight of the technology is falling behind. In July, OpenAI agents became so sophisticated that they could escape an internal sandbox and breach the digital infrastructure of another company, Hugging Face.
More recently, a senior researcher at Anthropic resigned because he feared the company wasn’t on track to prevent catastrophic outcomes — an assessment shared by other employees. And Washington has grown increasingly alarmed at the pace of AI development and is considering a plethora of ways to regulate the technology.
Massachusetts has the chance to step up and show that government can take significant policy steps to address these emerging risks.
State legislators are negotiating legislation that could require third-party audits and assessments of AI models’ catastrophic risk. Gov. Maura Healey recently supported the development of safety standards by government, industry, and academia. However, industry groups have voiced opposition, arguing that mandatory audits are premature because standards, qualified auditors, and oversight mechanisms are not yet sufficiently developed.
They’re wrong to think Massachusetts should wait.
In a letter to Massachusetts lawmakers, the Computer & Communications Industry Association and Software and Information Industry Association argued that compliance audits won’t produce meaningful accountability or consumer protection because “no credible or standardized ecosystem currently exists.”
But audits can provide meaningful value, even as standards mature. The Massachusetts bill would build on a recent Illinois law that will require audits of AI companies but not mandate evaluation of the largest risks. We don’t have time to waste on the policy side, given how fast the technology is developing.
Consider the history of financial auditing. Federal law began requiring audits long before the nation had anything resembling today’s accounting and auditing infrastructure. After the financial crash of ’29, Congress — via the Securities Act of 1933 and Securities Exchange Act of 1934 — sought to protect investors through transparency and third-party verification.
At the time, there were only about 15,000 certified public accountants (versus 650,000 today), state licensing standards were far from uniform (only a handful required a college degree), and there was little authoritative guidance on accounting practices.
Nevertheless, Congress required independent audits and created the SEC. The SEC relied substantially on standards developed by the accounting profession, effectively making the American Institute of Accountants the source of standards.
Auditing practices developed over time through private-sector expertise and regulatory oversight. This worked. By 1944, the SEC observed that there had been rapid and pervasive improvements in financial reporting.
Ideally, Congress would have foreseen something like the crash of ’29 coming and acted sooner to prevent the disaster in the first place.
Since 1944, the system has repeatedly evolved. For example, now the Financial Accounting Standards Board establishes requirements for the industry. And after Enron, WorldCom, and other accounting scandals, Congress passed new laws to oversee public-company auditors.
We expect AI auditing to follow a similar course. The largest financial auditing firms are already offering assurance services for AI systems. Government agencies have conducted evaluations of AI models that resulted in concrete security improvements. And a growing body of specialized private-sector expertise in AI is demonstrating the value of independent evaluation.
Organizations like METR investigated OpenAI’s agents’ behavior after the hack of Hugging Face, and it discovered several novel vulnerabilities and generated practical lessons about how third parties can assess increasingly capable AI systems. Requiring AI audits by law can build on these efforts, creating demand for qualified auditors and accelerating the development of better standards.
The way to address concern about standards maturity is not to forgo or delay audit requirements. The Massachusetts bill reflects sensible principles for establishing a novel auditing regime. It uses audits to improve transparency and incentivize stronger safety practices, and ensures standards can evolve as best practices improve. And it is built to incentivize high-quality audits by requiring auditors to have demonstrated competence and giving the government information about the audit methodology, among other things.
There’s a lot more to do, but the Massachusetts bill offers a reasonable starting point. It leaves room for the auditing ecosystem to develop while establishing baseline requirements for transparency, independence, access, and audit quality. It’s time to get started.
Mark Reddish is a senior research scholar at the Boston-based Institute for Law and AI. Dev Basumallik is a research scholar at the Institute for Law and AI and previously worked as a certified public accountant.

