A new audit framework says the phrase "independent audit" doesn't mean much when the auditor is another AI system.
The paper argues that independence for agentic AI audits should be graded, not treated as a yes-or-no checkbox. It defines three separate axes: who controls the auditor, whether the auditor shares the same foundation-model family or toolchain as the system it is checking, and whether the audit evidence is verifiable rather than self-reported. The authors borrow the beta-factor model from reliability engineering to formalize how shared failure points weaken an audit, then lay out a seven-step protocol a third party can check. They test it on a procurement-controls agent audited at three different independence grades, and run a Monte Carlo simulation comparing a conventional internal audit setup, a human audit team, a second AI agent, and provider logs, against the full set of faults it should be able to catch.
The headline result is blunt: that conventional setup surfaces just 5.9% of the faults it could in principle detect, and misses entire categories of faults completely. That's a warning for any organization currently trusting "we had it audited" as a safety signal, especially as agents start auditing other agents with minimal human involvement. The authors map their framework onto the amended EU AI Act, ISO/IEC 42006, and UK public-sector risk guidance, suggesting regulators are already circling this gap.
It's one arXiv paper, not yet peer-reviewed policy, but the core point is hard to argue with: an audit run by a system that shares its blind spots with the thing it's auditing isn't really independent, it's a mirror.