AI vendor diligence is being built around an audit report that is never going to arrive.
Google published a policy proposal in June 2026 setting out a two-tier approach to AI regulation in the United States.
What it says
The first tier covers frontier AI. A federally overseen regulatory organization, modeled on bodies such as FINRA and the North American Electric Reliability Corporation, would take as members the companies that develop frontier models. Members would publish a frontier safety framework, undergo annual procedural audits performed by independent audit firms, and attest before releasing a materially new model. All final audit reports would be submitted confidentially to the regulator.
The second tier covers everything below the frontier. There the proposal is that no new federal regime is needed, and that existing law should be applied to outputs and specific harms.
Why it matters
A regulated institution deploying AI sits in neither tier. It is not a member, because membership follows from building frontier models. It does not receive the audit output, because the report terminates with the regulator. It acquires no regime of its own, because the proposal argues none is required.
Assurance is generated upstream and stays upstream. The obligation lands downstream.
The practical response is not to wait for the report. The proposal standardizes almost everything upstream of it, and that material is published.
The frontier framework is specified to contain tiered risk thresholds with matching mitigations, cybersecurity practices protecting unreleased model weights, critical incident response plans, and internal governance arrangements. Those four elements can be requested by name.
Model cards are named as the standardized document set auditors receive. The same artifact class can be required of a supplier.
Audit type is answerable without the report. Procedural audits test adherence to a self-written framework. Substantive audits against validated benchmarks are described as later work.
Key takeaways
- Vendor diligence should be built on published artifacts rather than on regulation that has not arrived.
- Re-attestation should be triggered by model version change rather than contract renewal, because that is the event the proposal itself uses.
- Deployed AI should be mapped against obligations that already apply, since the proposal treats those as the operative regime.
Source:
· Google — AI Governance in America — blog.google, June 2026
What would you require from an AI provider if the audit findings were never available to you?