The shared lesson is simple: a control label is not the same as demonstrated coverage.
An Audit, a School Agreement and an AI Worker All Need the Same Question: What Does the Control Cover?
California has begun regulating who may present as an AI auditor. A new school agreement turns privacy, human review and provider accountability into adoptable contract terms. A security paper argues that identifying an AI Worker does not prove that its action still matches the human’s intent.[4] [5] [6] [7]
California formalises AI-auditor independence.
The laws create future criteria, registration and reporting duties, but they do not make every system audited or certify that an audited system is safe.[4] [5]
School AI guardrails move into contracts.
The AFT/UFT/Microsoft agreement gives participating districts a route to adopt data, oversight and transparency protections, but it is not a universal national law and adoption does not itself prove compliance.[6]
AI Worker identity is not human authorisation.
The Closed Intent Loop offers a useful design hypothesis, but it has not yet been implemented or adversarially tested.[7]
Human-centred assurance asks not whether a control exists, but whether its evidence covers the decision, system and consequence in front of us.
Evidence in practice
Read the signal. Keep the decision human.
This fixed reader guide is drawn from the already-published edition. It does not add a score, prediction, recommendation or automatic next step.
What changed
California has begun regulating who may present as an AI auditor. A new school agreement turns privacy, human review and provider accountability into adoptable contract terms. A security paper argues that identifying an AI Worker does not prove that its action still matches the human’s intent.[4] [5] [6] [7]
What leaders should review
Human-centred assurance asks not whether a control exists, but whether its evidence covers the decision, system and consequence in front of us.
What remains a human decision
Whether this signal is relevant to your organisation, which assumptions need challenge, and whether any operating change is justified. An AI briefing can make evidence visible; a responsible person decides what follows.