Third-Party AI Audits: What's Actually Mandatory, What's Only Proposed, and How to Get Audit-Ready
An FAA-style AI certification regime made headlines this week — but it isn't law. The third-party AI audits that actually bind businesses today, with dates.
The Week “FAA for AI” Hit the Headlines
On June 10, 2026, Anthropic published a policy framework arguing that frontier AI models, like airplanes, should be required to pass technical testing and independent auditing before release — and that government should hold legal authority to block or reverse deployments that fail (Anthropic, “Policy on the AI Exponential,” June 10, 2026). Within a day, the coverage had compressed to a phrase: an FAA-style certification regime for AI.
If you manage operations at a company that deploys AI — in HR screening, compliance documentation, production scheduling, quality control — the question that lands on your desk is practical: does this mean someone is going to audit our AI, and what do we need to have ready when they do?
The honest practitioner answer has two halves. The FAA-style regime does not exist, is not a bill, and would not apply to you if it did. And separately: third-party AI audit requirements already exist, more are scheduled, and the largest source of audit demand for most businesses isn’t a regulator at all. Sorting those two halves apart is the entire job of this post.
What Is the “FAA-Style” AI Certification Proposal — and Is It Law?
It is a vendor policy proposal, not legislation. Anthropic’s Advanced AI Framework, published alongside CEO Dario Amodei’s essay, proposes mandatory pre-deployment testing for four catastrophic-risk categories — biological, cyber, loss of control, and automated AI R&D — with at least one qualified independent evaluator publishing a review of each developer’s evaluations and risk reports, and civil penalties tied to global annual revenue (Anthropic Advanced AI Framework, June 10, 2026).
Read the thresholds before reading the headlines. The framework applies only to models trained on more than 10^25 floating-point operations, built by companies with more than $500 million in AI-related revenue or more than $1 billion in AI R&D spending (Anthropic, June 10, 2026). That is a list of fewer than a dozen companies on earth. If your business deploys AI rather than trains frontier models, this proposal — even if Congress enacted it verbatim tomorrow — would regulate your vendor, not you.
As of this writing, it has no congressional sponsor, no bill number, and no legislative vehicle. That is important context, not a dismissal: the same week produced real legislative movement pointing the same direction.
Is Congress Actually Building an AI Audit Regime?
Pieces of one — all aimed at developers, none yet binding.
The closest thing to the FAA model on paper is the Great American AI Act, a bipartisan House discussion draft circulated in early June 2026 by Reps. Jay Obernolte (R-CA) and Lori Trahan (D-MA). Section 112 of the draft would have the federal CAISI Director license “independent verification organizations” — IVOs — that large frontier model developers must retain to perform audits and assessments (DLA Piper, “Unpacking the Great American AI Act,” June 2026). That is a genuine third-party audit architecture: licensed auditors, mandatory retention, federal oversight. It is also a discussion draft that has not been formally introduced.
The bill that has been introduced is narrower. The VET AI Act (S.2615, 119th Congress), from Sens. Hickenlooper (D-CO) and Capito (R-WV), directs NIST to develop voluntary specifications and a certification pathway for the people and organizations who would perform third-party AI assurance (S.2615, congress.gov). It standardizes the auditors; it does not mandate that anyone be audited. Its predecessor died in committee in the 118th Congress, and the reintroduced version sits in Senate Commerce.
The states moved faster. On May 27, 2026, the Illinois General Assembly passed SB 315 — the Artificial Intelligence Safety Measures Act — 110-0 in the House and 52-5 in the Senate, making it the first US law to mandate annual independent third-party audits of AI safety practices (Transparency Coalition, May 2026). Gov. Pritzker signed it on July 6, 2026. But note the target and the clock: it applies to frontier model developers, not businesses that deploy AI, and its audit obligations don’t begin until January 1, 2028 (McDermott Will & Schulte analysis, 2026).
The pattern across all three: the emerging audit regime is converging on the companies that build frontier models. The audits that reach deployers come from somewhere else.
Which Third-Party AI Audits Are Mandatory for Deployers Today?
Exactly one US law currently forces an ordinary business to hire an independent AI auditor: New York City Local Law 144.
If your company uses an automated employment decision tool — AI-driven resume screening, candidate scoring, algorithmic ranking — for jobs based in New York City, the tool must undergo a bias audit by an independent auditor within one year of each use. You must publish a summary of the audit results on your website, post a notice about the tool’s data sources, and notify candidates before use. Enforcement began July 5, 2023 (NYC Department of Consumer and Worker Protection, AEDT program page). The auditor cannot be your employee and cannot hold a financial interest in the tool being audited (DCWP AEDT rules). Penalties run $500 for a first violation and up to $1,500 for each subsequent one — and each day a non-compliant tool is used counts as a separate violation, so exposure compounds daily (NYC Admin. Code § 20-872).
The other binding regime is European. Under the EU AI Act (Regulation (EU) 2024/1689), high-risk AI systems must pass a conformity assessment before they reach the EU market (Art. 43). For certain categories — remote biometric identification chief among them — that assessment involves a notified body, an accredited third-party assessor; for most Annex III high-risk categories, providers may self-assess under internal control where harmonized standards exist (Art. 43; EU AI Act Service Desk). The fine scale is the largest in any AI regulation: up to €35 million or 7% of global annual turnover for prohibited practices, and €15 million or 3% for high-risk violations (Art. 99, Regulation (EU) 2024/1689).
The dates, however, just moved — and that matters as much as the requirements. On May 7, 2026, EU negotiators reached agreement on the Digital Omnibus package — formally adopted in June 2026 (Parliament June 16, Council June 29) and published in the Official Journal in July — deferring the Annex III high-risk obligations from August 2, 2026 to December 2, 2027, a 16-month slip (Gibson Dunn, EU AI Act Omnibus analysis, May 2026). The stated reasons are telling: harmonized technical standards arrived late, and notified-body capacity — the supply of qualified third-party assessors — remained too thin across member states to audit everyone the law covered.
For a US manufacturer or service firm, the practical screen is short. Do you use AI to screen candidates for NYC-based roles? LL144 applies now. Do you place AI systems on the EU market, or supply EU customers who flow AI Act obligations into contracts? The conformity-assessment clock now runs to December 2027. Neither? No statute currently compels a third-party audit of your AI — which is not the same as saying no one will ask for one.
Who Audits the Auditors? ISO 42001, ISO 42006, and the Certification Track
Outside the mandates, a voluntary certification regime is professionalizing fast — and for most US businesses it will arrive through procurement, not regulation.
ISO/IEC 42001:2023 defines an auditable AI management system: governance structure, risk processes, and controls around how an organization develops or deploys AI. Certification against it is performed by third-party certification bodies, the same model as ISO 9001 or 14001. What changed recently is the layer above: ISO/IEC 42006:2025, published in July 2025, sets the requirements for the bodies that audit and certify AI management systems — auditor competence, audit-time calculation, even liability provisions (ISO/IEC 42006:2025, iso.org). Accreditation bodies including ANAB in the US and the Standards Council of Canada are now transitioning certification bodies onto the new standard (SCC transition bulletin, 2025).
Translation for a buyer: “AI audit” is becoming a defined discipline with accreditation behind it, and the gap between an accredited ISO 42001 certificate and a consultant’s letterhead “AI assessment” is about to be visible to your customers. Enterprise procurement teams and insurers are already writing AI assurance language into MSAs. For the majority of businesses with no NYC hiring footprint and no EU market exposure, the first third-party AI audit will be triggered by a contract clause — and that obligation is enforceable today, no act of Congress required.
Whichever route the audit arrives by, it examines substantially the same evidence: an inventory of the AI systems in use; a written AI use policy with named accountability; per-system risk assessments; data governance and provenance records; logging and retention; documented human oversight checkpoints and override records; testing and validation evidence; and vendor management documentation. A bias audit under LL144 adds statistical specifics — selection and scoring rates with impact ratios by sex and race/ethnicity (DCWP AEDT FAQ). EU Annex VII assessments add technical documentation review. ISO 42001 wraps it all in management-system discipline. Build the file once and every regime gets easier.
The Counter-Current: Why a Federal Audit Mandate Isn’t Coming Soon
A credible read of this landscape has to include the evidence running the other way, because there is plenty of it.
Start with Washington’s actual posture. On December 11, 2025, the White House issued an executive order directing the Department of Justice to stand up an AI Litigation Task Force to challenge state AI laws, ordering Commerce to catalog “onerous” state AI provisions, and pushing the FCC and FTC toward federal standards that would preempt state rules (Executive Order, “Ensuring a National Policy Framework for Artificial Intelligence,” whitehouse.gov, Dec. 11, 2025). A federal government suing states over AI regulation is not a federal government about to impose mandatory AI audits on deployers. Illinois SB 315 — now signed law — and even NYC’s bias audit law operate under preemption-litigation risk.
Colorado is the cautionary tale in the other direction. Its 2024 AI Act — the first comprehensive state law, with deployer impact assessments and mandatory risk-management programs — was delayed twice and then repealed outright on May 14, 2026, replaced by a narrower disclosure framework that eliminates the impact-assessment obligations companies had spent two years preparing for (SB 26-189; Seyfarth analysis, May 2026). Businesses that built Colorado-specific compliance programs watched the requirement evaporate before it ever took effect.
And the one mandatory deployer audit on the books has an enforcement record worth reading skeptically. The New York State Comptroller audited DCWP’s enforcement of Local Law 144 and found that while DCWP’s review of 32 companies surfaced a single compliance issue, the Comptroller’s own team found at least 17 instances of potential non-compliance in the same group — and the agency had received only two complaints in two years of enforcement (Office of the NY State Comptroller, audit released Dec. 2, 2025). The EU delayed its dates partly because there weren’t enough notified bodies to perform the assessments. NYC doesn’t license or approve bias auditors at all (DCWP FAQ). The audit regime’s ambitions are currently ahead of its infrastructure — auditor supply, accreditation, and enforcement muscle are all still being built.
None of that means audit-readiness is wasted effort. It means the driver is shifting: less “the government will fine you,” more “your customer, your insurer, and your own liability exposure will ask for evidence.” The court sanctions and verification failures documented in our companion analysis of AI output verification land on deployers regardless of what any audit statute says.
How Do You Prepare for a Third-Party AI Audit?
The preparation is the same whether the auditor shows up under LL144, an EU conformity assessment, an ISO 42001 certification, or a customer’s MSA clause — because they all ask for the same file.
- Inventory every AI system in use — including the AI features embedded in software you already license. Most organizations underestimate this list, and an audit that starts with an incomplete inventory fails on page one.
- Run the jurisdiction screen. NYC-based hiring with algorithmic screening means a bias audit obligation now. EU market placement or EU customer flow-downs means conformity-assessment preparation against the December 2, 2027 date. Everyone else: check what your enterprise customers’ contracts already require.
- Write the governance layer. An AI use policy with named accountability, per-system risk assessments, and defined human-review checkpoints. Every regime examined here — enacted, proposed, and contractual — audits these same documents.
- Generate the records auditors sample: logs, retention, oversight and override documentation, testing evidence, vendor documentation. A policy without records is a finding, not a control.
- Vet anyone selling you an audit. Ask whether they work to ISO/IEC 42006-accredited methods, what independence they can document, and what their report format supports — because an audit that can’t survive your customer’s scrutiny was an expensive PDF.
The split-screen of 2026 — Illinois signing an audit mandate into law weeks after Colorado gutted its AI act, a frontier-lab CEO demanding FAA-style certification while the federal government sues states over AI rules — is genuinely confusing, and anyone claiming certainty about where it lands is selling something. What a deployer can control is the audit file: the inventory, the governance documents, the records. Those pay off under every scenario on the table.
iSi’s AI compliance services cover exactly this ground for EHS firms, manufacturers, and producers — audit-readiness setup, gap assessments against the frameworks above, and periodic spot checks that keep the file current as the rules move. If you’d rather find the gaps before an auditor does, talk to us.
Sources
- Anthropic, “Policy on the AI Exponential” and Advanced AI Framework: https://www.anthropic.com/policy-on-the-ai-exponential (verified 2026-06-11)
- VET Artificial Intelligence Act, S.2615, 119th Congress: https://www.congress.gov/bill/119th-congress/senate-bill/2615/text (verified 2026-06-11)
- DLA Piper, “Unpacking the Great American AI Act”: https://www.dlapiper.com/en-us/insights/publications/2026/06/unpacking-the-great-american-ai-act (verified 2026-06-11)
- NYC Department of Consumer and Worker Protection, Automated Employment Decision Tools: https://www.nyc.gov/site/dca/about/automated-employment-decision-tools.page and FAQ: https://www.nyc.gov/assets/dca/downloads/pdf/about/DCWP-AEDT-FAQ.pdf (verified 2026-06-11)
- NY State Comptroller, Enforcement of Local Law 144 audit (Dec. 2, 2025): https://www.osc.ny.gov/state-agencies/audits/2025/12/02/enforcement-local-law-144-automated-employment-decision-tools (verified 2026-06-11)
- Regulation (EU) 2024/1689 (EU AI Act), Arts. 43 and 99: https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng (verified 2026-06-11)
- Gibson Dunn, “EU AI Act Omnibus Agreement — Postponed High-Risk Deadlines”: https://www.gibsondunn.com/eu-ai-act-omnibus-agreement-postponed-high-risk-deadlines-and-other-key-changes/ (verified 2026-06-11)
- ISO/IEC 42006:2025: https://www.iso.org/standard/42006 (verified 2026-06-11); Standards Council of Canada transition bulletin: https://scc-ccn.ca/accreditation/bulletins/transition-isoiec-420062025-bodies-providing-audit-and-certification
- Transparency Coalition, Illinois SB 315 passage: https://www.transparencycoalition.ai/news/illinois-lawmakers-send-significant-ai-frontier-model-safety-bill-to-gov-pritzker (verified 2026-06-11); McDermott Will & Schulte analysis: https://www.mcdermottlaw.com/insights/illinois-advances-frontier-ai-transparency-audit-requirements/
- Executive Order, “Ensuring a National Policy Framework for Artificial Intelligence” (Dec. 11, 2025): https://www.whitehouse.gov/presidential-actions/2025/12/eliminating-state-law-obstruction-of-national-artificial-intelligence-policy/ (verified 2026-06-11)
- Colorado SB 24-205 history: https://leg.colorado.gov/bills/sb24-205 ; Seyfarth, “Colorado’s AI Reset”: https://www.seyfarth.com/news-insights/colorados-ai-reset-two-weeks-a-white-house-callout-and-a-pivot-away-from-the-eu-model.html (verified 2026-06-11)
- NYC LL144 penalty provisions (NYC Admin. Code § 20-872): https://legalclarity.org/nyc-local-law-144-bias-audit-requirements-and-penalties/ (verified 2026-06-11)