A new agreement requires participating companies to implement four distinct layers of controls and audits to manage emerging technological risks. The framework specifically targets capabilities related to cybersecurity, biosecurity, and chemical threats, aiming to prevent models from hacking or accessing technical systems in unintended ways.
The first layer involves robust internal controls designed to monitor model alignment and capabilities. Companies must also establish an internal team responsible for ensuring these controls operate effectively and that any issues are remediated promptly. To verify this process, the accord mandates the engagement of an independent external auditor to assess the overall effectiveness of the implemented safeguards.
Oversight is further reinforced by the requirement for companies to form an independent board of directors committee. This body will provide high-level supervision of the safety protocols. The structure ensures that monitoring, remediation, external assessment, and board-level governance are all formally integrated into corporate operations under the new rules.