Control
Large frontier developer without an independent third-party compliance audit
A large frontier developer has an independent, conflict-free third party audit its compliance with its frontier-AI safety obligations every year, gives the auditor the access it needs, and publishes and reports the audit results.
Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.
Reach
enacted, not yet applying in Illinois (US-IL); next date 2028-01-01.
The guard to add
Engage an independent auditor on non-contingent fees each year to audit frontier-safety obligations, then publish, transmit, and retain the signed report.
A yearly audit cycle owned by the developer's governance or legal lead and tracked as a calendared task with evidence links. It covers: an engagement letter recording the auditor's independence (no financial interest either way) and a fee that does not depend on findings; auditor access to the materials it needs, including unredacted versions, under security protocols; a signed report on obligations met, material deviations with recommendations, internal controls and accountable senior staff, audit personnel, conflicts, and methodology; publication of a summary and redacted report; transmittal to the regulators; and retention of the unredacted copy. This is an organizational record, not a code change; the repository can hold the evidence index for each year.
Where it goes: 12 repository artifacts, 14 user-facing text.
What reviewers look for: for each audit year, an engagement letter with independence and fee terms, the signed report, a public summary and redacted report link, transmittal receipts, and a retention entry for the unredacted report.
Organizational control: the evidence is a kept record, its owner and its upkeep, not code.
Example (Audit evidence index (repo record)), before:
# governance/frontier-audit.yaml
2028: internal self-assessment doneAfter:
# governance/frontier-audit.yaml
2028:
auditor: Example Assurance LLP
engagement_letter: evidence/2028/engagement.pdf # independence + non-contingent fee clauses
signed_report: evidence/2028/report-signed.pdf
report_date: 2028-11-20
public_summary_url: https://example.ai/safety/audit-2028
redacted_report_url: https://example.ai/safety/audit-2028-redacted.pdf
transmittal_receipts: [evidence/2028/receipt-agency.pdf, evidence/2028/receipt-ag.pdf]
unredacted_retention: records-vault://frontier-audit/2028 (retain_until set by legal)Engineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.
Upcoming dates
- : Large frontier developers must obtain and publish an annual independent compliance audit from 2028 (Illinois SB 315) (Illinois (US-IL); first application)
Every rule this guard addresses
Binding law — not yet in force or stayed (1)
- Illinois (US-IL)
- Large frontier developers must obtain and publish an annual independent compliance audit from 2028 (Illinois SB 315) IL PA 104-0538, Sec. 10(d) · applies from 2028-01-01