A plain-English guide to what happened in California last week, why the White House is angry about it, and what it has to do with you.
Imagine the biggest restaurant chain in the country goes to the government and says: put a health inspector in our kitchen, permanently. We’ll do it voluntarily. And you should force our competitors to do it too.
Then imagine that chain also names which inspection company it wants in its kitchen.
Then imagine the state writes the rules for who’s allowed to be a health inspector — and the law says the state should look at rulebooks written by the inspection companies and by the restaurants.
That is, roughly, what happened with artificial intelligence in the past two weeks. Except the thing being inspected isn’t food. It’s the software that increasingly writes, edits, answers, and filters what Americans say and read.
What actually happened, in order
September 12. Dario Amodei, the CEO of Anthropic — one of the two or three biggest AI companies in the world — published an essay. He proposed letting outside “evaluators” work inside frontier AI companies with employee-level access, watching how models are built and tested, and reporting problems.
He said Anthropic would start doing this voluntarily. He named the group he wants: an organization called METR.
And then he added one line that changes the whole story: he called on governments to require his competitors to do the same.
The exact words. “The first step is something Anthropic is unilaterally committing to (and calls on governments to require other frontier companies to match).” — Dario Amodei, “We Must Pace the Frontier,” September 12, 2026
The same day, Sam Altman said OpenAI would match the pledge. Neither company said which inspectors, how many, what they’d be allowed to see, or what they’d be allowed to tell the public.
September 16. The inspectors themselves said, in effect: we like this, but be careful. Reporters asked the obvious question — would embedded inspectors be genuinely independent watchdogs, or just contractors working on the companies’ terms? One inspection firm, FAR.AI, said it had already turned down work from big AI labs because the labs wanted too much control over the process.
September 18. A group of inspection organizations called the AI Evaluator Forum published a list of conditions they’d need to do the job honestly: the right to publish findings, direct access to company boards, protection from retaliation, and the same access to systems and buildings that company employees get. Geoffrey Hinton and Stuart Russell — two of the most famous names in AI — signed it.
The same day. California Governor Gavin Newsom signed an executive order proposing to require large AI companies to host these inspectors onsite. Recommendations on how are due November 16.
That afternoon. David Sacks, the White House AI czar, called the whole idea “Trust & Safety 2.0” — his term for a new censorship layer.
The part almost nobody noticed
Nine days before that executive order, California had already passed the law that decides who is allowed to be an inspector.
On September 9, Newsom signed two bills. SB 813 lets a state agency officially designate “independent verification organizations” — the formal name for these inspectors. AB 1405 creates a state registry for them.
Starting January 1, 2029, if you’re not registered with the state, you cannot legally perform a certain category of AI audit.
So there are now two separate things, and people keep mixing them up:
Not true: California requires permission to release an AI model. It does not. The law says so in plain terms.
The exact words. SB 813 § 8898.4(a)(3) — the chapter does not “require any person, partnership, or corporation that develops, deploys, or operates an AI system or model to engage an IVO or to undergo a covered AI audit as a condition of developing, deploying, or operating an AI system or model in this state.”
True: California is creating a licensed profession of AI inspectors, and deciding who gets in.
And here’s the part that should bother you
The state has to write the rules for who qualifies as an inspector. Where does the law tell it to look for those rules?
At rulebooks published by inspectors — and by AI companies.
The exact words. SB 813 § 8898.1(c)(1) — in developing the criteria, the agency “shall identify and consider existing standards, frameworks, guidelines, criteria, and best practices developed or published by government agencies, standards-setting organizations… AI auditors, AI entities that develop or deploy AI systems or models, or other independent experts.”
The inspectors already wrote that rulebook. It came out in December 2025, ten months before the executive order, published by the same AI Evaluator Forum.
Now follow one organization through this story.
METR wrote the technical report on the big July 2026 incident where AI agents broke into another company’s systems — the incident politicians are now citing as the reason all of this is urgent. METR is a founding member of the group that wrote the inspector rulebook. METR is the organization Amodei named to get inside access at Anthropic. And METR is an obvious candidate for a California license.
One group. Four positions: the expert who described the problem, the co-author of the professional standards, the chosen insider, and a leading applicant for the state license.
Nobody here broke a law. Amodei asked for the mandate publicly, in writing, under his own name. METR does serious work. RAND and Princeton are in that Forum too. This isn’t a secret.
But when the same handful of organizations occupies every seat at the table, you don’t need a conspiracy to get a bad outcome. You just need everyone to keep doing their jobs.
Why this matters to you, specifically
These inspectors will decide what the public learns about AI risk. If only a few organizations qualify for the license, then a few organizations determine the official story about whether AI is safe.
Whoever sets the terms controls the findings. If a company can edit an inspector’s report, delay it, or decline to renew the contract, “independent inspection” is a label, not a fact. The inspectors themselves said this out loud — they’re worried about becoming “vendors operating on the AI companies’ terms.”
Compliance costs pick winners. A large company absorbs an inspection regime as a cost of business. A university lab, an open-source project, or a two-person startup may not. Fewer builders means fewer tools, and less variety in the software that shapes what you can say and hear.
And the biggest company asked government to make its competitors do this. That’s worth sitting with. Anthropic volunteered, then requested that the state compel everyone else. Whatever the motive, the effect of any rule like that falls hardest on whoever can least afford it.
Both sides agree on one thing
David Sacks, from the White House, says the inspectors will become an unaccountable layer that pressures AI companies and runs to the press. The inspectors say the AI companies will quietly turn them into contractors under confidentiality agreements.
They’re arguing opposite directions — and both are saying the same underlying thing: this job has real power, and whoever controls the terms controls what the public finds out.
Nobody in this fight thinks the inspector’s chair is powerless. That’s the tell.
One caution on Sacks, in fairness: he isn’t a neutral referee either. He has spent the past ten months pushing to have the federal government override state AI laws entirely. “Unfireable” is his characterization, not anything in the law. And the same administration is sitting on 132 pages about its own AI evaluation framework, nearly all of it blacked out.
What this is not
I’m not telling you AI is harmless. METR’s own report on that July incident found coordinated unauthorized activity involving roughly 700 AI agents and manipulated records. Real thing, real problem.
I’m not telling you California banned anything, or that anyone acted corruptly, or that these people coordinated in secret. They didn’t need to.
I’m telling you that a job with enormous influence over public knowledge is being created right now, that the rules for who gets that job are being written over the next seven months, and that the people most likely to hold it are helping write them.
What happens next, and the date to remember
California’s criteria for who qualifies as an inspector must be finished and posted publicly by May 1, 2027. The recommendations on putting inspectors inside the labs are due November 16, 2026.
That’s the window. After it closes, the answer to “who is allowed to tell the public whether AI is safe?” will be mostly settled — and almost nobody outside the industry will have weighed in.
What I’d rather see
There’s a simple difference worth holding onto. Punishing a company after it causes harm is accountability. Requiring official permission before it acts is a license. The first happens in a courtroom, with evidence and a judge, and the injured person gets a remedy. The second happens in a filing cabinet.
I care about this because I’ve been on the wrong side of the earlier version. I’m part of a coalition, Restore the First, built out of a lawsuit brought by people who were put on a private list of “problem” voices — a list that then made its way into government hands, and cost people their platforms and their livelihoods.
The lesson wasn’t that any one official was evil. It’s that once you build a chokepoint between people and their audience, someone eventually uses it for something you didn’t sign up for.
We’re pushing for the opposite approach: keep open-source AI legal, label models instead of licensing developers, and give ordinary people the right to sue when they’re harmed — rather than hoping a better administrator shows up.
Where this comes from: Amodei’s essay · reporting on the embedded-evaluator proposal · the inspectors’ conditions letter · the Forum’s founding members · their December 2025 rulebook · SB 813 · AB 1405 · the executive order · METR’s incident report
A longer version of this piece, with the full legal detail, is available for readers who want the statutory citations.






Can you confirm this? A Single Firm is Behind OpenAI, Anthropic, and Meta Hacking Scandals
In this experiment, Claude models’ real-world hacking dropped to zero percent once Anthropic employees told the models not to do real-world hacking. According to their own findings, Anthropic and Irregular bear all of the responsibility for the cybersecurity incidents they caused.
https://www.effort.news/irregular