AI
Miles Brundage’s AVERI AI Audit Conflict Explained
Miles Brundage’s call for AI audits overlaps with AVERI’s mission. Its OpenAI ties and disclosures show what independence must require.

On August 21, former OpenAI policy researcher Miles Brundage used a Guardian opinion column to argue that frontier AI companies should prepare for a possible slowdown. His first prescription was independent safety and security auditing. The link attached to that proposal led to the work of the AI Verification and Evaluation Research Institute, or AVERI, the nonprofit Brundage leads.
That overlap prompted a blunt reaction online: is an advocate for AI auditing also creating demand for his own organization?
The public record supports a more precise conclusion than the accusation of secret profiteering. Brundage openly identifies AVERI, and the institute publishes unusually detailed conflict disclosures. But the conflict does not disappear because it is disclosed. AVERI is advocating rules, standards and demand for the same field it was founded to build, while retaining financial, personal and institutional ties to frontier AI companies.
That is not proof that Brundage's policy argument is false. It is a test of whether the people defining "independent AI auditing" will accept scrutiny as demanding as the scrutiny they want to impose on AI labs.
The overlap between the Guardian column and AVERI is explicit
Brundage's Guardian column offered four steps for companies preparing for a possible slowdown: invite independent audits, build cross-industry governance bodies, invest in verification technology, and support legislation creating stronger oversight.
The first recommendation links directly to AVERI's work on frontier AI auditing. A second, support for audit-related legislation, also falls within AVERI's public policy and advocacy program. By simple count, one of the four recommendations, 25 percent, sends readers directly to the organization Brundage runs.
Brundage made the relationship even clearer in the X post promoting the column. He said competitive pressure was part of why he founded AVERI and described his goal as making frontier AI auditing effective and universal.
NEW from me in the Guardian. I agree with AI company employees that government should step in, but companies could do more already.
— Miles Brundage (@Miles_Brundage) August 21, 2026
This is advocacy for AVERI's mission, not a hidden connection uncovered by critics. The Guardian's contributor note says Brundage leads AVERI and previously worked at OpenAI. His X post names AVERI. The institute's website describes him as the executive director who sets strategy and builds partnerships.
The legitimate question is not whether he concealed the overlap. It is whether a disclosure at the bottom of an opinion column gives readers enough context to judge a policy recommendation that would expand the role of organizations like his.
Why calling AVERI an audit firm overstates the evidence
A Chinese-language reply visible in a screenshot of the X discussion accused Brundage of using the slowdown debate to promote his own auditing organization. The core observation, that his recommendation advances AVERI's mission, is verifiable. The broader implication that he is selling conventional audit services for personal gain is not established by the available evidence.
AVERI describes itself as a US 501(c)(3) nonprofit. Its stated work includes audit research, technical tools, pilot projects, standards, and policy advocacy. Its public materials say it wants to make third-party auditing effective and universal. That is broader than operating as a commercial firm paid to certify clients.
No public source reviewed for this article shows Brundage receiving a commission for audits, selling an audit contract through the Guardian column, or personally profiting each time an AI company adopts an audit. Treating those claims as proven would replace scrutiny with insinuation.
Yet nonprofit status does not remove institutional self-interest. An organization can sincerely pursue a public-interest mission while benefiting from greater attention, funding, influence, hiring and demand for its chosen field. The relevant conflict is not necessarily cash in Brundage's pocket. It is AVERI's role in defining the problem, advocating the policy, shaping the standards, building the supply and potentially participating in the resulting work.
AVERI's own disclosures show why independence is difficult
AVERI deserves credit for publishing a detailed conflict-of-interest section. It says Brundage earned OpenAI equity while employed there, sold all shares he was eligible to sell, and plans to sell the remainder when eligible. It also says he has investments in venture funds with exposure to AI companies and personal relationships with employees at frontier labs.
The institute says Brundage is recused from directly auditing OpenAI for at least two years after leaving, with a possible extension depending on when his remaining direct equity is sold. It also acknowledges that team members have held shares in major technology companies, worked at OpenAI and Microsoft, and maintain relationships that can create actual or perceived conflicts.
The funding picture creates a second layer. AVERI lists foundations, individuals, an AI underwriting company, a venture firm, and several non-executive employees and alumni of frontier AI companies among its funders. It says no donor provides a majority of its funding. It has also been offered API credits by Amazon, Anthropic, Google DeepMind, Microsoft, OpenAI and Thinking Machines Lab.
There is also a visible board-funder connection. AVERI lists Halcyon Futures as a funder. Its team page identifies board member Mike McCormick as Halcyon's founder and chief executive. That arrangement is not evidence of misconduct, and funder representation is common in nonprofits. It is relevant when an organization asks the public to rely on its independence, because board oversight and financial support are not fully separate in this instance.
These facts make "independent" a governance claim that must be demonstrated engagement by engagement. It cannot be inferred from the word nonprofit.
A disclosed conflict is not a resolved conflict
AVERI's own policy analysis makes the strongest case for applying a tougher standard to AVERI. In an April review of US audit legislation, Brundage wrote that company self-assessment cannot fully resolve the inherent conflict involved in judging its own safety work. The institute also argues that auditors should publish credentials and conflict disclosures.
The same logic applies one level up. An organization dedicated to expanding AI auditing cannot be the sole judge of whether its disclosure and recusal rules are sufficient. If a lab cannot grade its own homework, an audit advocate should not grade its own independence.
AVERI has taken the first step by identifying conflicts and setting a recusal rule. It has not publicly answered every question a mature assurance system would need to answer. Its funder page does not give contribution amounts or concentration bands. Its API-credit disclosure does not value the in-kind support. Its public pages do not provide a searchable log of recusals, declined engagements or completed audit roles. It is also unclear from those pages how responsibility would be divided when AVERI helps design a standard, advocates for its adoption and participates in a pilot using it.
None of those omissions proves improper conduct. They identify the distance between transparency and verification, the same distance AVERI says frontier AI companies must close.
The Guardian disclosed the affiliation, but readers needed it sooner
The Guardian did not hide Brundage's role. The contributor note names AVERI, and the first audit link goes to AVERI's site. The piece is clearly labeled opinion. Those are meaningful disclosures.
Still, placement matters. A reader encounters the recommendation before the contributor note. A concise sentence beside the first audit proposal could have stated that Brundage leads a nonprofit established to advance frontier AI auditing. That would frame the recommendation at the moment readers evaluate it, rather than after they finish the argument.
This is especially important because the column criticizes AI companies that call for brakes while failing to build them. Brundage's answer is that AVERI is helping build the brakes. The response from skeptics is that the brake builder is also lobbying for brakes. Both descriptions can be true.
The reaction was mostly supportive, which makes the criticism useful
The public replies returned with the X post were largely brief approval. AVERI colleague Patricia Paskov praised the piece, Gary Marcus wrote "nice," and other visible responses were emoji or agreement. The sharper criticism in the supplied screenshot was not representative of those top replies, but it raised the question the supportive responses did not address: who benefits institutionally from turning auditing into the default answer?
That question should not be dismissed as cynicism. Nor should it be stretched into a claim that the safety case is fabricated. Independent audits may be valuable even when advocates have institutional incentives. Financial audits, security testing and product certification all involve paid experts and organizations with an interest in continued demand. Their legitimacy comes from enforceable standards, rotation, accreditation, liability and transparent conflict controls, not from pretending incentives do not exist.
The same distinction answers another criticism in the screenshot, which treated auditing as a muzzle placed on AI models. AVERI presents auditing as a way to verify claims and permit more confident deployment, not simply a mechanism for slowing every model. Whether that framework becomes meaningful inspection or expensive compliance theatre depends on how access, standards and accountability are designed.
Five tests for genuinely independent frontier AI auditing
AVERI and other organizations entering this field can make independence measurable with five basic commitments:
- Publish funding concentration bands. Naming donors is useful, but readers should know whether a lab-connected donor provides 2 percent or 40 percent of annual support.
- Disclose in-kind support at a reasonable value. API credits, compute and data access can create dependence even when no cash changes hands.
- Publish engagement-level conflicts before work begins. The disclosure should name relevant equity, past employment, personal ties, funders and any role in designing the standard being applied.
- Separate advocacy, standard-setting and assessment. No organization should control all three functions for the same engagement without independent oversight.
- Create an external recusal and complaints process. A public record of recusals, declined work and adjudicated complaints would let outsiders test whether the policy operates in practice.
Government rules should also avoid anointing one nonprofit or one school of AI safety thought as the universal gatekeeper. A competitive, accredited ecosystem with common minimum standards is more credible than a system built around personal trust in former industry insiders.
The verdict on the alleged hypocrisy
Calling Brundage's Guardian column a covert advertisement is inaccurate. The affiliation is disclosed, AVERI is named in the post, and the institute publishes conflicts that many organizations would leave buried. There is no evidence in the reviewed sources that Brundage personally profits from each audit or that AVERI is merely a commercial certification shop.
Calling the situation conflict-free would be equally inaccurate. Brundage advocates a policy that advances his institution's mission. AVERI has OpenAI alumni ties, remaining OpenAI equity disclosed by its executive director, support from people connected to frontier labs, offered credits from those labs, and a board member who leads a listed funding organization.
The sharpest fair conclusion is simple: a disclosed conflict is not a resolved conflict. AVERI's argument for independent verification is strongest when the institute submits its own independence to comparable external checks. Until then, readers should evaluate Brundage's case on its merits while keeping the institutional incentives in full view.
Cover image: U.S. Capitol at sunrise, U.S. House of Representatives, public domain.
About the author
Gavin Foss
**Gavin Foss** is the editor-in-chief at *Tech Forum*, covering the Canadian technology landscape with a focus on AI and emerging technologies. His technical depth and industry connections make him one of Canada's most respected tech journalists.