DoorDash's AI Ordering Agent Is the First Real Test of Agentic Commerce at Consumer Scale
On October 5, 2026, OpenAI, Anthropic, Google, and Meta testified under oath before all 51 NYC Council members. When asked to raise a hand if their company carries catastrophic liability insurance, none did. Here is what that means for enterprise AI.
On October 5, 2026, executives from OpenAI, Anthropic, Google DeepMind, and Meta testified under oath before all 51 members of the New York City Council, in what Council Speaker Julie Menin described as the first time a legislative body had compelled the four major frontier AI labs to appear simultaneously, under oath, to account for the risks their technology poses. The hearing lasted several hours. Witnesses included Logan Graham, head of Anthropic's Frontier Red Team; Morgan Dwyer, OpenAI's head of policy development and operations; Alice Friend, Google's director of AI and emerging tech policy; and Shane Cahill, Meta's AI policy director for legislation.
At one point in the hearing, Speaker Menin asked the witnesses to raise their hands if their company carries insurance against catastrophic AI risks. None raised a hand.
"So then the public, I assume, will be asked to absorb the costs," Menin said.
That exchange — four executives representing the most powerful AI companies on Earth, none able to affirm that their company carries catastrophic liability coverage — encapsulates the accountability gap that October 5 made visible. The gap between the capability claims AI companies make in investor presentations and product launches, and the accountability structures they are willing to accept for downstream consequences, is not new. The NYC Council hearing is significant because it put that gap on the public record, under oath, in a form that legislative action at every level can now reference.
For enterprise AI buyers, technology leaders, and legal and compliance teams evaluating AI deployments, October 5 is a useful timestamp: it is the moment the frontier AI governance debate shifted from policy white papers and voluntary commitments to sworn testimony before elected officials with subpoena power.
How a City Council Forced AI's Biggest Labs Into the Room
The October 5 hearing did not happen because OpenAI, Anthropic, Google, and Meta chose to appear voluntarily. The Council warned that subpoenas would follow if the companies declined to participate. Meta had agreed beforehand. OpenAI, Google, and Anthropic agreed only after the Council made its subpoena authority clear.
This procedural detail is significant. Voluntary appearances before policy bodies — Senate hearings, EU parliamentary discussions, White House roundtables — allow companies to control the framing, send junior policy representatives, and decline to address specific questions by citing legal privilege or competitive sensitivity. A sworn appearance compelled by subpoena threat creates a different accountability structure: representatives answer under oath, inconsistencies with prior public statements become legally relevant, and the record is a formal legislative document rather than a press event.
The Council's subpoena authority over AI companies operating in New York is grounded in the commercial reality that OpenAI, Anthropic, Google, and Meta all have significant New York operations — offices, employees, and commercial relationships with New York-based enterprises. Every frontier AI company of scale operates in New York City, and a city council's subpoena authority extends to entities doing business within its jurisdiction. This is the same legal hook that state attorneys general have used to investigate technology companies: territorial jurisdiction over entities operating locally, even when those entities are headquartered elsewhere.
The EU AI Act enforcement framework established the first regulatory precedent for AI companies facing binding requirements in major commercial jurisdictions; the NYC Council's compelled hearing applied a similar territorial logic at the city level, months before federal legislation in the United States has produced comparable enforcement tools. The implication for AI companies is that governance exposure is not limited to federal regulatory relationships — local and state legislative bodies with territorial jurisdiction are an active and credible enforcement vector.
What the Witnesses Said — and What They Refused to Say
The testimony on October 5 covered three broad areas: company safety practices, risk assessment for catastrophic outcomes, and responsiveness to proposed legislative requirements.
On safety practices, all four representatives pointed to existing internal programs. Graham from Anthropic described the company's model evaluation frameworks and its published safety commitments. Dwyer from OpenAI cited the company's preparedness team and published safety policies. Friend from Google DeepMind described Gemini's evaluation pipeline and internal red-teaming. Cahill from Meta outlined Meta's responsible AI infrastructure and its open-source model release governance.
What none of the representatives could confirm under questioning were answers to two specific questions: whether their company carries catastrophic liability insurance, and whether an independent external validator has reviewed their current-generation frontier models with access to model weights and training procedures. The SAFA framework for frontier AI self-regulation — which OpenAI, Google, and Anthropic have nominally endorsed — commits signatories to third-party safety assessments, but the witnesses were unable to confirm that independent validators have access to current-generation model internals rather than limited post-deployment evaluations. The practical gap between a commitment to third-party review in principle and a confirmed external validator in practice with access to model weights is the governance gap that the NYC bill is attempting to close.
The insurance question is the most legally significant point from the hearing. Catastrophic liability insurance — coverage for low-probability, high-consequence outcomes including AI-enabled attacks on critical infrastructure or AI system failures causing mass casualties — does not currently exist as a standard commercial product for AI companies. No frontier AI company carries it, because no such product is available at commercially viable terms.
Speaker Menin's Kill-Switch Bill: What It Actually Proposes
The proximate occasion for the October 5 hearing was Speaker Menin's proposed legislation, which would require any AI model sold or deployed in New York City to satisfy two conditions: an independent third-party validator must review the model before deployment, and a natural person must have the technical capability to shut it down.
The kill-switch requirement is technically simpler than it sounds for standard enterprise AI deployments — a single enterprise application running on Claude or GPT-5 can be shut down by terminating API access — but becomes practically complex for distributed multi-agent systems operating across cloud regions, with autonomous decision loops, parallel tool calls, and external service integrations. Agentic workflows that handle financial transactions, healthcare record updates, or infrastructure configuration changes cannot be halted mid-execution without service disruption or data integrity risk. The bill's kill-switch requirement will need to distinguish between point-in-time shutdown capability for active transactions and architectural guarantees that no AI system component operates beyond human override authority — these are different engineering requirements with different implementation costs.
The validator requirement raises a structural challenge about scope and access. Meaningful third-party validation of a frontier AI model requires access to model weights, training data characteristics, evaluation protocols, and internal red-team results. AI labs treat all of these as proprietary competitive intelligence. There is currently no certified validator ecosystem — no entity analogous to a financial auditor — with the technical capability, legal standing, and confidentiality infrastructure to conduct frontier model assessments that are independent, technically comprehensive, and publicly credible without requiring full proprietary disclosure.
The bill, as presented at the October 5 hearing, does not specify validator certification criteria, assessment methodology, required assessment frequency, or what a validator finding would trigger in terms of deployment restrictions or public disclosure. These are the legislative details that determine whether the law would be operationally meaningful or function primarily as a political statement. Council staff acknowledged that the hearing was intended to build the legislative record for subsequent drafting, not to finalize the bill's provisions.
The Insurance Non-Answer and What It Reveals
Fortune's coverage of the hearing highlighted an additional dimension: Jacob Coxon, an Anthropic whistleblower who testified independently before the Council, described AI safety measures as "duct tape that will fall off" as capabilities scale. He stated: "On the current path, I think it is more likely than not that humanity loses control to these AIs, and it could end in human extinction."
These are not fringe positions within the AI safety research community. They reflect a genuine ongoing debate about whether current alignment and interpretability techniques are sufficient to guarantee safe operation of frontier models as capabilities continue to increase. The empirical question of whether alignment research is adequate is contested. The policy question of whether AI companies should carry liability insurance commensurate with their own stated risk assessments is not.
The insurance gap is economically rational from the perspective of individual companies but represents risk externalization at scale. If a company's internal risk assessment concludes that the probability of catastrophic outcomes from its technology is meaningful — even at one percent over a decade — standard actuarial logic would price that risk at significant insurance premiums. The absence of any catastrophic AI liability insurance product in the commercial market reflects a combination of factors: the novelty of the risk category, the difficulty of modeling correlated AI system failures across interconnected infrastructure, and the absence of any regulatory requirement that would force AI companies to internalize tail-risk costs rather than leave them with governments and the public.
The "none raised a hand" moment at the October 5 hearing is a quotable fact that will recur in future legislative discussions at the federal, state, and local levels. It is the clearest possible illustration of the gap between AI companies' capability narratives and their accountability structures — captured under oath, in a formal public record, before a legislative body.
Enterprise AI Governance After the Hearing
For enterprise technology leaders managing AI deployments, October 5 has several actionable implications.
The most immediate is contractual. Enterprise AI vendor agreements typically include data processing terms, confidentiality provisions, and service level commitments. Few currently include any provision for catastrophic liability allocation — what happens if an AI system in enterprise production contributes to a significant adverse outcome for the enterprise's customers, employees, or counterparties. The hearing's insurance non-answer is a prompt for legal and procurement teams to examine whether existing AI vendor agreements address tail-risk liability and to begin asking that question in new contract negotiations. This will not immediately produce commercially available catastrophic liability coverage, but it will surface whether AI vendors are willing to accept any contractual risk allocation for the scenarios their own executives have described as plausible under oath.
The kill-switch requirement, if enacted in New York, creates a compliance track for enterprise legal teams alongside the EU AI Act obligations they are already managing. The EU AI Act enforcement actions that began in 2026 established that enterprise AI governance is a structured compliance function, not a policy interest. NYC-level legislation would add a city-jurisdiction compliance layer. Even if the NYC bill does not pass in its current form, the trajectory of state and local AI regulation in the United States is toward more requirements, not fewer — analogous to how state privacy laws created a patchwork compliance landscape that preceded and shaped the federal privacy debate.
The validator requirement, viewed as a direction of travel rather than a specific pending requirement, points toward a near-term future in which third-party validation of AI models before enterprise deployment is standard procurement practice. Enterprise procurement teams at financial services firms, healthcare systems, and government contractors are already asking vendor questionnaires about internal red-teaming and safety evaluations. The NYC hearing accelerates the timeline on which comprehensive third-party validation — not internal evaluation described to a questionnaire, but independent assessment with meaningful access — becomes a purchase-blocking requirement in high-stakes enterprise procurement.
Here is where major AI governance frameworks stand as of October 2026:
| Framework | Jurisdiction | Binding? | External Validation? | Kill-Switch Required? | Insurance Required? |
|---|---|---|---|---|---|
| EU AI Act | European Union | Yes (high-risk tiers) | Yes (conformity assessment) | No explicit | No |
| White House AI EO | United States (federal) | Partial | Voluntary for frontier | No | No |
| NYC Proposed Bill | New York City | Proposed | Yes (any deployed AI) | Yes | No |
| SAFA Framework | Voluntary (US labs) | No | Nominally committed | No | No |
| UK AI Safety Institute | United Kingdom | Advisory | Voluntary | No | No |
The NYC bill, if enacted, would be the most sweeping mandatory AI governance requirement in any US jurisdiction — covering validation and kill-switch capability for any deployed AI model, not just high-risk categories. The gap between the NYC bill's breadth and its current operational specificity is large and will narrow significantly in legislative drafting. What will not change is the direction: toward external accountability for AI deployments, not just internal commitments.
Federal-Local Regulatory Gap and What Fills It
The White House frontier AI model review framework represents the federal-level response to the same concerns the NYC Council addressed on October 5. The gap between these frameworks — the federal framework is primarily advisory; the NYC bill would be mandatory and locally binding — reflects the same regulatory dynamic that has characterized early-stage technology governance in the United States throughout the internet era.
Federal technology regulation moves slowly, for structural reasons: the Senate confirmation process slows agency staffing; federal preemption questions complicate state and local action; and the bipartisan nature of frontier AI concerns makes both restrictive and permissive regulatory positions politically available. State and local governments, facing none of these constraints, tend to move faster — and their actions create facts on the ground that shape federal legislation by establishing compliance precedents that enterprises navigate before federal rules arrive.
For enterprise AI strategy, the key signal from October 5 is not whether the NYC bill passes in its current form. It is that the combination of factors documented in the hearing — no catastrophic insurance, no confirmed independent validation of frontier models, a whistleblower testimony about loss-of-control risk — now has a formal public record under oath. Future legislative action at any level of government can cite that record directly. The political environment for frontier AI governance is not becoming less demanding over time, and the enterprises best positioned for the regulatory direction of travel are those that treat governance infrastructure as a competitive investment rather than a compliance cost.
What Enterprise AI Leaders Should Build Now
The October 5 hearing is a prompt for enterprise AI governance programs to address several specific gaps:
1. Map your AI deployment inventory against kill-switch feasibility. For every AI system in production, assess the actual technical capability to halt execution in a defined time window. Distinguish between API-level kill switches (service termination) and system-level kill switches (state management and graceful rollback). Flag any agentic workflow where mid-execution termination creates data integrity risk.
2. Audit your vendor contracts for tail-risk liability allocation. Review whether any existing AI service agreements address what happens if the AI system contributes to a significant adverse outcome. Begin asking tail-risk liability questions in new vendor negotiations, and track whether any frontier AI vendors are willing to accept contractual risk allocation for the scenarios they describe as plausible in their own published risk assessments.
3. Build an external validation procurement requirement. For AI deployments in high-stakes contexts — healthcare, financial services, hiring, infrastructure — begin requiring that vendors provide evidence of meaningful external safety assessment, not just internal evaluation described in a questionnaire. This creates procurement pressure toward the third-party validator ecosystem that the NYC bill is trying to mandate legislatively.
4. Track state and local AI legislation as a compliance category. Assign responsibility for monitoring state and city-level AI legislation to your compliance function, the same way state privacy law monitoring was added to compliance programs in the early 2020s. NYC is not the only jurisdiction with active AI legislation; California, Illinois, Colorado, and a growing list of states have AI-specific bills in committee.
5. Evaluate enterprise AI insurance products as they emerge. The October 5 hearing will accelerate the development of AI liability insurance products as insurers sense legislative and market demand. As products become available, evaluate whether catastrophic AI liability coverage makes sense for your organization's risk profile and your AI deployment footprint.
Takeaway: The NYC City Council AI hearing on October 5, 2026 is significant not because of the legislation that may or may not follow, but because it produced a formal public record — under oath — of four frontier AI companies unable to confirm catastrophic liability insurance or confirmed independent model validation. For enterprise AI buyers, the hearing is a prompt to examine whether existing AI vendor contracts address tail-risk liability, to build governance frameworks with explicit kill-switch capabilities, and to treat external validation requirements as near-term procurement standards rather than future regulatory hypotheticals. The direction of the regulatory environment is clear: mandatory external accountability for AI deployments is coming, and the enterprises that build governance infrastructure ahead of that requirement will face lower compliance costs and lower regulatory risk than those that wait for the mandate before acting.
Frequently Asked Questions
What happened at the NYC City Council AI hearing on October 5, 2026?
On October 5, 2026, the New York City Council's Committee of the Whole held an AI-risk oversight hearing in which executives from OpenAI, Anthropic, Google DeepMind, and Meta testified under oath before all 51 Council members. The hearing was called by Council Speaker Julie Menin as part of the Council's review of proposed AI legislation that would require independent third-party validation and human kill-switch capability for any AI model deployed in New York City. Google, OpenAI, and Anthropic agreed to appear only after the Council warned that subpoenas would follow if they declined; Meta had agreed beforehand. Witnesses included Logan Graham, head of Anthropic's Frontier Red Team; Morgan Dwyer, OpenAI's head of policy development and operations; Alice Friend, Google's director of AI and emerging tech policy; and Shane Cahill, Meta's AI policy director for legislation. Jacob Coxon, an Anthropic whistleblower, also testified separately. The most widely reported moment from the hearing came when Speaker Menin asked witnesses to raise their hands if their company carries insurance against catastrophic AI risks. None of the four company representatives raised a hand. The hearing did not produce new rules but provided the formal public record that subsequent legislation will draw on.
What does NYC's proposed AI kill-switch bill require?
Council Speaker Julie Menin's proposed legislation would impose two requirements on any AI model sold or deployed in New York City. First, an independent third-party validator must review the model before commercial deployment. Second, a natural person — a human being — must have the technical capability to shut down the AI model. The "kill-switch" requirement sounds straightforward for standard enterprise AI applications but becomes technically complex for distributed multi-agent systems that span multiple cloud regions, involve autonomous decision loops, and connect to external tools and services. A single enterprise chatbot running on a commercial API can be shut down by terminating API access; a production agentic workflow involving multiple AI models, parallel tool calls, and automated state management across systems is considerably harder to halt coherently without service disruption. The validator requirement raises separate issues of scope and methodology: meaningful third-party validation of a frontier AI model requires access to model weights, training data, and internal red-team results — information labs treat as proprietary. As of the October 5 hearing, the bill had not specified validator certification standards, assessment methodology, required assessment frequency, or what a validator finding would trigger. These details are in legislative drafting. The bill's direction of travel — toward mandatory external validation and human oversight capability — is clear regardless of how specific provisions are ultimately resolved.
Why does it matter that AI companies have no catastrophic liability insurance?
When Speaker Menin asked the October 5 witnesses to raise their hands if their company carries insurance against catastrophic AI risks and none did, the implication was explicit and commercially significant: if a catastrophic AI-related outcome materialized — an AI-enabled cyberattack at critical infrastructure scale, an AI system failure causing mass casualties, or a mass coordination failure in AI-dependent financial or medical systems — there is no private insurance backstop. The costs fall to governments, businesses, and individuals, not to the companies whose products contributed to the outcome. This risk externalization is economically rational from the perspective of individual companies: catastrophic AI liability insurance does not currently exist as a standard commercial product, partly because the risk category is novel, partly because correlated AI failures across interconnected systems are difficult to model actuarially, and partly because no regulatory requirement has yet forced AI companies to internalize tail-risk costs. But the absence of insurance is informative about risk perception: insurance markets are efficient at pricing risk when the risk is quantifiable. The inability to purchase catastrophic AI liability coverage suggests either that the risk is currently unquantifiable, that it is too large to insure at commercially viable premiums, or that the insurance industry does not believe AI companies would be held liable for catastrophic outcomes under current legal frameworks. Each of those interpretations has different governance implications, and the October 5 hearing put the question on the public record for the first time under oath.
What does the NYC AI hearing mean for enterprise AI governance?
For enterprise technology leaders deploying AI systems, the October 5 hearing has several immediate implications. The most actionable is contractual: enterprise AI vendor contracts typically include data processing agreements, confidentiality terms, and service level commitments, but few currently address catastrophic liability allocation — what happens if an AI system deployed in an enterprise context contributes to a significant adverse outcome. The hearing's insurance non-answer is a prompt for legal and procurement teams to examine whether their AI vendor contracts address tail-risk allocation and, if not, to begin asking that question in vendor negotiations. The kill-switch requirement, if enacted in New York, becomes a compliance requirement for any AI deployment in the city, adding a New York compliance track to the EU AI Act obligations enterprises are already managing. Even if the NYC bill does not pass in its current form, its direction signals that city and state-level AI regulation is an active category — analogous to how state privacy laws created a patchwork compliance landscape before federal privacy legislation materialized. Enterprise compliance teams should be tracking state and local AI legislation the same way they track state privacy laws. For enterprises with AI deployments in New York City, the practical recommendation is to conduct an audit of deployed AI systems, map their kill-switch capabilities (the actual ability to terminate each system quickly), and evaluate whether vendor agreements address tail-risk liability in terms that a risk committee can review.
How does NYC's AI oversight approach compare to the EU AI Act?
The NYC proposed legislation and the EU AI Act share a direction — both push toward external validation and human oversight requirements for AI systems — but differ significantly in scope, binding force, and specificity. The EU AI Act, now in enforcement, applies across all EU member states and creates risk-tiered requirements: high-risk AI systems in healthcare, critical infrastructure, employment, and law enforcement face the most stringent obligations, including conformity assessments, technical documentation requirements, human oversight obligations, and registration in a EU-wide database. Enforcement actions began in mid-2026. The NYC proposed bill is more sweeping in one respect — it would require validator review and kill-switch capability for any AI model deployed in the city, not just high-risk categories — but covers only one city and, as of October 5, lacks the operational specificity of the EU Act. The EU Act took several years to develop that specificity through technical standards bodies; the NYC bill is in early legislative stages. Both frameworks reflect the same underlying governance concern: that voluntary self-regulation by frontier AI companies is insufficient for managing risks that the companies themselves acknowledge as potentially catastrophic, and that external oversight — through validators, conformity assessments, or independent auditors — is necessary. The practical convergence for enterprises is that multi-jurisdictional AI governance compliance is becoming a structured operational requirement, not a one-time checklist. Organizations deploying AI in both the EU and New York City will need to manage overlapping but non-identical compliance tracks.