On 9 September Governor Gavin Newsom signed two bills that give California the first state-run system in the country for checking artificial intelligence from the outside. Senate Bill 813, from state senator Jerry McNerney, and Assembly Bill 1405, from assemblymember Rebecca Bauer-Kahan, do different jobs that fit together: one decides who gets to audit, the other decides what an audit has to look like.
Two laws, one audit chain
SB 813, now Chapter 179 of the Statutes of 2026, creates the California Artificial Intelligence Standards and Safety Commission and a voluntary framework of Independent Verification Organizations, IVOs for short: outside experts who assess an AI system or model against state law, using methods the state itself can check for rigour and for independence from the company being reviewed. The Government Operations Agency, which will run the framework, has until 1 January 2028 to start certifying IVOs.
AB 1405 builds the accountability layer underneath that framework. It creates a public registry of AI auditors, with standards for independence, transparency and integrity, and a ten-year duty to keep audit records. The agency must open an enrolment channel on its website by 1 January 2027. From 1 January 2029, anyone who runs what the law calls a covered AI audit in California without being enrolled will not be doing it lawfully.
Who this reaches
The scope is companies that build or deploy AI systems operating in California, and the legislature's own framing points at models and systems already embedded in critical parts of the economy and of public life: hiring, health, finance, public services. That is a wider net than the frontier-model debate that usually dominates AI-safety headlines, and it is the net our clients tend to sit inside.
Three years a firm can plan around
The dates give a firm room to move rather than a reason to react. 2027 is when the enrolment channel opens for anyone who wants to be an AI auditor under California law, worth watching for firms with the technical and legal bench to build that practice, in the way audit and advisory firms once built compliance practices around Sarbanes-Oxley or around the data-protection-officer role. 2028 is when the state starts certifying the independent bodies that will sit above individual auditors. 2029 is when the obligation bites: doing a covered AI audit in California without enrolment stops being an option.
For firms that advise AI developers and deployers rather than plan to audit them, the more immediate task is smaller and starts now: work out whether any client's product would fall inside a covered AI audit, and add California's audit exposure to the same risk map that already tracks the EU AI Act's own conformity-assessment route for high-risk systems. The two regimes are not identical, but both rest on the same idea: a company should not be the only one grading its own AI.
Sources
- Governor Newsom signs first-in-the-nation AI safeguards — Office of Governor Gavin Newsom
- California changes the rules for auditing artificial intelligence: the two new laws signed by Newsom — La Nación
- Bill Text — AB-1405 Artificial intelligence: auditors: enrollment — California Legislative Information